We do zero some sensitive data, but could be reviewed for completeness.

Cheers,
Will


> On Jan 2, 2022, at 1:33 PM, Daniel Stenberg via libssh2-devel 
> <libssh2-devel@lists.haxx.se> wrote:
> 
> On Sun, 2 Jan 2022, Andreas Schneider wrote:
> 
>> FIPS 140-2: 4.7.6 Key Zeroization
> 
> The cryptographic module must do this, yes (apparently also according to 
> 140-3 which is the current FIPS version). It just confuses me, since libssh2 
> isn't a crypto module. Clearly there are details here I'm not educated in. 
> I'll just leave it.

-- 
libssh2-devel mailing list
libssh2-devel@lists.haxx.se
https://lists.haxx.se/listinfo/libssh2-devel

Reply via email to