On 6 August 2014 14:35, Gayathri Manoj <gayathri.an...@gmail.com> wrote:
> Hi Matt,
>
> Is there any solution to compile openssl-0.9.8za without -no-ec option. Or
> do we have any patch available to fix the fips breakage issue.
> Known issues in OpenSSL 0.9.8za:
>
> FIPS capable link failure with missing symbol BN_consttime_swap. Fixed in
> 0.9.8zb-dev. Workaround is to compile with no-ec: the EC algorithms are not
> FIPS approved in OpenSSL 0.9.8 anyway.
>

0.9.8zb is being released later today. So probably your best bet is to
wait for that.

Although this does beg the question why you need a FIPS build if
you're going to be using non FIPS approved algorithms anyway?

Matt
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    openssl-users@openssl.org
Automated List Manager                           majord...@openssl.org

Reply via email to