Erez Pasternak wrote:
Hi
Does anyone here knows
1) Which versions of Open SSL are FIPS 140-2 certified on Linux?
Which versions of Linux?
2) Which versions of Open SSL are FIPS 140-2 certified on
Windows? Which versions of Windows?
Thanks
Erez Pasternak
There is currently only one validated version of the OpenSSL FIPS Object
Module, v1.1.2 with certificate #918:
http://csrc.nist.gov/groups/STM/cmvp/documents/140-1/140val-all.htm#918.
Note it's "validation", not "certification". Also please note that
OpenSSL itself (the distro we all know and love) is not and presumably
never will be FIPS 140-2 validated. The OpenSSL FIPS Object Module is a
separate distinct software component derived from, and designed to
interoperate with, OpenSSL proper.
The v1.1.2 module supports Linux/Unix and Windows (most versions, sort
of), but without assembler optimizations. It is based on and compatible
with OpenSSL 0.9.7+.
I'm expecting two more validations for the 0.9.8+ based v1.2 Real Soon Now.
-Steve M.
--
Steve Marquess
Open Source Software Institute
[EMAIL PROTECTED]
______________________________________________________________________
OpenSSL Project http://www.openssl.org
Development Mailing List openssl-dev@openssl.org
Automated List Manager [EMAIL PROTECTED]