We do zero some sensitive data, but could be reviewed for completeness. Cheers, Will
> On Jan 2, 2022, at 1:33 PM, Daniel Stenberg via libssh2-devel > <libssh2-devel@lists.haxx.se> wrote: > > On Sun, 2 Jan 2022, Andreas Schneider wrote: > >> FIPS 140-2: 4.7.6 Key Zeroization > > The cryptographic module must do this, yes (apparently also according to > 140-3 which is the current FIPS version). It just confuses me, since libssh2 > isn't a crypto module. Clearly there are details here I'm not educated in. > I'll just leave it. -- libssh2-devel mailing list libssh2-devel@lists.haxx.se https://lists.haxx.se/listinfo/libssh2-devel