Re: Please Help I am looking for openssl-fips-1.2.2.tar.gz for Windows 64 Bit

2011-04-21 Thread Steve Marquess
, Bhaskar Raju It's the same for all platforms: http://www.openssl.org/source/openssl-fips-1.2.2.tar.gz -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877-673-6775 marqu...@opensslfoundation.com

Re: FIPS and AES NI engine

2011-04-02 Thread Steve Marquess
we'd normally care to do, but it is a reasonable response given the peculiar restrictions imposed by FIPS 140-2. That is our plan for supporting it in our upcoming open source validation, should we find a sponsor interested in support the inclusion of that platform. -Steve M. -- Steve Marquess

Re: FIPS and AES NI engine

2011-03-31 Thread Steve Marquess
in the FIPS 140-2 context (I have a definite opinion but that is irrelevant if your test lab feels differently). You can't of course make changes to the validated code -- any changes at all -- and still call it validated. -Steve M. -- Steve Marquess The OpenSSL Software Foundation, Inc. 1829 Mount

Re: New Sponsor for the FIPS Validation (PKWARE)

2011-03-14 Thread Steve Marquess
is more complex as there is (as yet) no source code to copy, although I anticipate roughly comparable pricing. -Steve M. -- Steve Marquess The OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877-673-6775 marqu...@opensslfoundation.com

New Sponsor for the FIPS Validation (PKWARE)

2011-03-13 Thread Steve Marquess
-64 asm optimization HP-UX 11i on Itanium 32bit with asm optimization HP-UX 11i on Itanium 64bit with asm optimization Any prospective sponsors of platforms not included in that list are encouraged to contact the OSF. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829

New Sponsor for the FIPS Validation (QuintessenceLabs)

2011-03-10 Thread Steve Marquess
sponsors of platforms not included in that list are encouraged to contact the OSF. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877-673-6775 marqu...@opensslfoundation.com

Re: TLS 1.2 protocol implementation

2011-03-09 Thread Steve Marquess
it will just take longer. -Steve M. -- Steve Marquess The OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877-673-6775 marqu...@opensslfoundation.com __ OpenSSL Project

Re: FIPS support in OpenSSL

2011-02-25 Thread Steve Marquess
validation is in process (http://openssl.org/docs/fips/fipsvalidation.html). So far we're on schedule but it could still take up to a year. It's not too late to sign on as a sponsor for your particular platform of interest. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount

New FIPS Validation Status Update

2011-01-31 Thread Steve Marquess
VC++ Win32 on x86 uClinux on ARM Check the file README.FIPS in the source distribution regularly for up-to-date status info. Also see http://www.openssl.org/docs/fips/fipsvalidation.html for more information and updates on this effort. -Steve M. -- Steve Marquess OpenSSL Software

New Sponsor for the FIPS Validation (Opengear)

2011-01-17 Thread Steve Marquess
. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877-673-6775 marqu...@opensslfoundation.com __ OpenSSL Project http://www.openssl.org Development

Re: New Sponsor for the FIPS Validation

2011-01-15 Thread Steve Marquess
William A. Rowe Jr. wrote: On 1/14/2011 10:15 AM, Steve Marquess wrote: To date the following platforms are included in the validation: Android on ARM VC++ WIN32/x86 Clarification please; in the past the source code build has been validated, with specific platforms chosen

Re: New Sponsor for the FIPS Validation

2011-01-15 Thread Steve Marquess
to implement ECC. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877-673-6775 marqu...@opensslfoundation.com __ OpenSSL Project http

New Sponsor for the FIPS Validation

2011-01-14 Thread Steve Marquess
, thereby significantly increasing the value of the resulting validation. To date the following platforms are included in the validation: Android on ARM VC++ WIN32/x86 Any prospective sponsors of platforms not included in that list are encouraged to contact the OSF. -Steve M. -- Steve

Re: New FIPS 140-2 validation underway

2011-01-12 Thread Steve Marquess
Xiao, Ying wrote: Steve, Great news. Will the new PRNG be released by the end of 2011? Yes. -Steve M. -- Steve Marquess The OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877-673-6775 marqu...@opensslfoundation.com

New FIPS 140-2 validation underway

2011-01-11 Thread Steve Marquess
in place. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877-673-6775 marqu...@opensslfoundation.com __ OpenSSL Project http

Re: New FIPS 140-2 validation underway

2011-01-11 Thread Steve Marquess
(that version designation is already in use). v2.0 perhaps; we haven't discussed it yet. -Steve M. -- Steve Marquess The OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877-673-6775 marqu...@opensslfoundation.com

Re: Openssl supports TLS1.2

2010-09-13 Thread Steve Marquess
of work and the team members who could do that work all have day jobs or are currently occupied with unrelated commercial commitments. Now if TLS 1.2 implementation was one of those commercial commitments it could happen quickly (that's a hint!). -Steve M. -- Steve Marquess The OpenSSL Software

Re: fips directory

2010-06-30 Thread Steve Marquess
module per that validation. -Steve M. -- Steve Marquess The OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877-673-6775 marqu...@opensslfoundation.com __ OpenSSL Project

Re: openssl fips 1.2 changes

2010-03-15 Thread Steve Marquess
lab, and wait 9-12 months... -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877-673-6775 marqu...@opensslfoundation.com __ OpenSSL Project

Re: sha256 in FIPS mode.

2009-10-27 Thread Steve Marquess
code will need very substantial modification for new validations. -Steve M. -- Steve Marquess The OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877-673-6775 marqu...@opensslfoundation.com

Re: sha256 in FIPS mode.

2009-10-27 Thread Steve Marquess
and not the future SHA-3. -Steve M. -- Steve Marquess Open Source Software institute marqu...@oss-institute.org __ OpenSSL Project http://www.openssl.org Development Mailing List

Re: Delivering two version of libcrypto - fips and non-fips - correction

2009-09-13 Thread Steve Marquess
Steve Marquess wrote: Thor Lancelot Simon wrote: On Thu, Sep 10, 2009 at 06:10:27PM +0200, Dr. Stephen Henson wrote: On Wed, Sep 09, 2009, Thor Lancelot Simon wrote: On Sat, Aug 29, 2009 at 05:34:04PM -0400, Steve Marquess wrote: That this wasn't the obvious approach from the very

History Note on FIPS Validation

2009-09-13 Thread Steve Marquess
requirements will be changing and the current v1.2 validation will no longer be a rubber stamp template. No post-v1.2 validation is currently planned so there will no longer be a shared model suitable as-is for direct use or as a basis for private label validations. -Steve M. -- Steve

Re: Delivering two version of libcrypto - fips and non-fips

2009-09-02 Thread Steve Marquess
-own situation, same as it was before the first open source based validation. -Steve M. -- Steve Marquess The OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877-673-6775 marqu...@opensslfoundation.com

Re: Delivering two version of libcrypto - fips and non-fips

2009-08-30 Thread Steve Marquess
private label validations based on v1.2 will find that those validations will no longer be rubber stamp formalities as is the case today. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877-673-6775 marqu...@opensslfoundation.com

Re: Delivering two version of libcrypto - fips and non-fips

2009-08-28 Thread Steve Marquess
Steve Marquess wrote: Mark Phalan wrote: ... Due to the way the FIPS Capable OpenSSL is built it ends up with older implementations of ciphers (all the ones that fipscanister.o implements). These cipher implementations are used regardless of being in FIPS mode or not. Ummm, not so. Use

Re: Delivering two version of libcrypto - fips and non-fips

2009-08-27 Thread Steve Marquess
. -- Steve Marquess The OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877-673-6775 marqu...@opensslfoundation.com __ OpenSSL Project http://www.openssl.org

Re: fipsld or libcrypto.so

2009-05-08 Thread Steve Marquess
was an important design goal because it allows software vendors to ship one binary to all customers. -Steve M. -- Steve Marquess Veridical Systems, Inc. marqu...@veridicalsystems.com __ OpenSSL Project

Re: fipsld or libcrypto.so

2009-05-08 Thread Steve Marquess
Steve Marquess wrote: canroc wrote: I am confused with what is required in builiding an application to use encryption functions from a FIPS 140-2 capable openSSL library. If I link the shared library libcrypto.so (0.9.8j) into my application and do a FIPS_mode_set(1) call, is that all

Re: FIPS validation docs

2009-05-05 Thread Steve Marquess
to reveal under non-disclosure restrictions. -Steve M. -- Steve Marquess Veridical Systems, Inc. marqu...@veridicalsystems.com __ OpenSSL Project http://www.openssl.org Development Mailing List

Re: New fips compliance version based on 0.9.8k or later? (UNCLASSIFIED)

2009-04-20 Thread Steve Marquess
, so as to leverage the advantages of the high level API of the latter, but it is a separate and distinct product. See the User Guide (http://www.openssl.org/docs/fips/UserGuide-1.2.pdf) for more details. -Steve M. -- Steve Marquess Veridical Systems, Inc. marqu...@veridicalsystems.com

Re: [PATCH RFC] Add support to Intel AES-NI instruction set for?x86_64 platform

2008-12-11 Thread Steve Marquess
with the best of intentions and IMHO in the beginning served a useful purpose. Other that that, no comment :-) -Steve M. -- Steve Marquess Open Source Software Institute [EMAIL PROTECTED] __ OpenSSL Project

Mea Culpa on FIPS Module v1.2 User Guide and Windows

2008-12-08 Thread Steve Marquess
and another revalidation. I'll gladly incorporate any contributed feedback into the User Guide, but until/if another paying client needs Microsoft specific support I won't be doing any hands-on work with Windows. -Steve M. -- Steve Marquess Veridical Systems, Inc. 1829 Mount Ephraim Road Adamstown

Draft FIPS Module v1.2 User Guide

2008-11-26 Thread Steve Marquess
the next few weeks. Feedback on errors/omissions/improvements will be greatly appreciated. -Steve M. -- Steve Marquess Open Source Software Institute [EMAIL PROTECTED] __ OpenSSL Project http

(Non)status of OpenSSL FIPS Object Module v1.2 Validation

2008-09-26 Thread Steve Marquess
participated in took about three months, the longest over five years. So my current prediction is that this validation will be awarded no later than April 2013. About the time OpenSSL 1.6 is released :-) -Steve M. -- Steve Marquess Open Source Software Institute [EMAIL PROTECTED

Re: ssl teses forbidden in FIPS mode

2008-09-25 Thread Steve Marquess
, fire, aim!). Since there is little practical reason to disable FIPS mode once enabled (reference earlier discussion) we elected to just leave that bug as-is rather than abort and restart the validation process. -Steve M. -- Steve Marquess Open Source Software Institute [EMAIL PROTECTED

Re: ssl teses forbidden in FIPS mode

2008-09-25 Thread Steve Marquess
for which the validation is still pending. -Steve M. -- Steve Marquess Open Source Software Institute [EMAIL PROTECTED] __ OpenSSL Project http://www.openssl.org Development Mailing List

Re: Question regarding openssl fips module

2008-08-26 Thread Steve Marquess
of the Security Policy. The pending OpenSSL FIPS Object Module v1.2 will include some 64 bit platforms. I've been expecting that validation Real Soon Now for weeks. -Steve M. -- Steve Marquess Open Source Software institute [EMAIL PROTECTED

Re: FIPS certification document for OpenSsl

2008-08-20 Thread Steve Marquess
, but it does seem to say that validated modules can be used on what we would consider multi-user, multi-tasking systems. Start asking about threading, forking, multiple cores, etc., though, and you start getting some odd responses. -Steve M. -- Steve Marquess Open Source Software Institute [EMAIL

Re: FIPS certification document for OpenSsl

2008-08-20 Thread Steve Marquess
Prashant Kumar wrote: Hello All, Where can I find the documentation for OpenSsl FIPS certification ? Any help is appreciated. See http://csrc.nist.gov/groups/STM/cmvp/documents/140-1/140val-all.htm#918 and http://www.openssl.org/docs/fips/UserGuide-1.1.1.pdf. -Steve M. -- Steve

Re: FIPS certification document for OpenSsl

2008-08-19 Thread Steve Marquess
multiple explanations, some quite elaborate, that I just don't get. -Steve M. -- Steve Marquess Open Source Software institute [EMAIL PROTECTED] __ OpenSSL Project http://www.openssl.org

Re: FIPS 140-2 Certification

2008-08-12 Thread Steve Marquess
on and compatible with OpenSSL 0.9.7+. I'm expecting two more validations for the 0.9.8+ based v1.2 Real Soon Now. -Steve M. -- Steve Marquess Open Source Software Institute [EMAIL PROTECTED] __ OpenSSL Project

Re: FIPS mode and SSE2

2008-06-05 Thread Steve Marquess
capable processor you'll have to use the no-asm version, sorry. Contributions to defray validation test lab fees are always welcome. -Steve M. -- Steve Marquess Open Source Software institute [EMAIL PROTECTED] __ OpenSSL Project

Re: openssl 0.9.8 with fips

2008-05-31 Thread Steve Marquess
. There is (will be) only one version of the former, while the FIPS capable support will be carried forward in future 0.9.8 releases. -Steve M. -- Steve Marquess Open Source Software institute [EMAIL PROTECTED] __ OpenSSL Project

OpenSSL FIPS Object Module v1.2 snapshots

2007-12-18 Thread Steve Marquess
with the command: cvs -d [EMAIL PROTECTED]:/openssl-cvs co \ -r OpenSSL-fips-0_9_8-stable openssl -Steve M. -- Steve Marquess Open Source Software Institute [EMAIL PROTECTED] __ OpenSSL Project

Re: OpenSSL FIPS Object Module v1.2

2007-12-12 Thread Steve Marquess
Kyle Hamilton wrote: On Dec 2, 2007 4:31 PM, Steve Marquess [EMAIL PROTECTED] wrote: ...big snip... c) I would like to know where to find the formal specification documents for what must be met in a module boundary, ... The module boundary is *the* key concept for FIPS 140-2. It is also

Re: OpenSSL FIPS Object Module v1.2

2007-12-12 Thread Steve Marquess
M. -- Steve Marquess Open Source Software institute [EMAIL PROTECTED] __ OpenSSL Project http://www.openssl.org Development Mailing List openssl-dev@openssl.org Automated

Re: OpenSSL FIPS Object Module v1.2

2007-12-11 Thread Steve Marquess
drink to that... -Steve M. -- Steve Marquess Open Source Software institute [EMAIL PROTECTED] __ OpenSSL Project http://www.openssl.org Development Mailing List openssl-dev

Re: OpenSSL FIPS Object Module v1.2

2007-12-10 Thread Steve Marquess
Kyle Hamilton wrote: On Dec 2, 2007 4:31 PM, Steve Marquess [EMAIL PROTECTED] wrote: Kyle Hamilton wrote: I just want to have the opportunity to know that what is submitted will actually run on the platform I must use. ... big snip ... Kyle, you raise a number of good points

Re: OpenSSL FIPS Object Module v1.2

2007-12-02 Thread Steve Marquess
exchange of views does not play well everywhere, most bureaucracies (not just the CMVP) have very different ways of working and establishing consensus. So please please please direct all flames at me and not at them. -Steve M. -- Steve Marquess Open Source Software institute [EMAIL PROTECTED

Re: OpenSSL FIPS Object Module v1.2

2007-11-30 Thread Steve Marquess
there will spontaneously disappear. -Steve M. -- Steve Marquess Open Source Software institute [EMAIL PROTECTED] __ OpenSSL Project http://www.openssl.org Development Mailing List

Re: OpenSSL FIPS Object Module v1.2

2007-11-30 Thread Steve Marquess
Steve Marquess wrote: Brad House wrote: Ok, guys, let me point out a harsh reality here. As noted in an earlier comment, FIPS 140-2 validation doesn't mesh all that well with the open source world. ... We're a paying OSS member (or at least we were, not sure if we were invoiced

Re: OpenSSL FIPS Object Module v1.2

2007-11-30 Thread Steve Marquess
surrealistic. There is a long you're kidding, right? and WTF? learning curve... -Steve M. -- Steve Marquess Open Source Software Institute [EMAIL PROTECTED] __ OpenSSL Project http://www.openssl.org

Re: OpenSSL FIPS Object Module v1.2

2007-11-30 Thread Steve Marquess
contributors. And Steve Henson is responsive to everyone. -Steve M. -- Steve Marquess Open Source Software Institute [EMAIL PROTECTED] __ OpenSSL Project http://www.openssl.org Development Mailing

Re: OpenSSL FIPS Object Module v1.2

2007-11-29 Thread Steve Marquess
be addressed in validation N+1. But validations are very expensive and our financial sponsorship is erratic so we proceed as resources allow. -Steve M. -- Steve Marquess Open Source Software institute [EMAIL PROTECTED] __ OpenSSL

Re: Windows build of FIPS 1.1.1 is not thread-safe

2007-08-12 Thread Steve Marquess
Windows, thanks to a generous corporate sponsor, but the number of platforms we can test is severely constrained by available funding -- the test lab fees alone are several kilobucks a platform and they don't work on a volunteer basis. That's a hint :-) -Steve M. -- Steve Marquess Open Source

Re: Build FIPS code in openssl?

2007-02-02 Thread Steve Marquess
vendors unable to wait for the source based product. We hope to be announcing the details soon. -Steve M. -- Steve Marquess Open Source Software Institute [EMAIL PROTECTED] __ OpenSSL Project http

Re: OpenSSL FIPS 140 Support

2006-09-08 Thread Steve Marquess
. The lead time for correcting and announcing problems in OpenSSL code is usually measured in days. The lead time for validating changes is measured in many months. Closed source proprietary vendors of course have an enormous incentive to skip the announcement step :-) -Steve M. -- Steve Marquess

Re: FW: OpenSSL FIPS 1.0 AIX using GCC patches

2006-04-14 Thread Steve Marquess
to any validation, the CMVP test lab fee, so it makes sense to try to satisfy as many requirements as possible for each such iteration, and spread that fixed cost among multiple sponsors. The next validation should take a lot less than 3-1/2 years... -Steve M. -- Steve Marquess c/o Open Source

<    1   2