openssl 1.0.1 and FIPS

2011-05-13 Thread The Doctor
What is happening? No Fips in the Openssl 1.0.1 STABLe. -- Member - Liberal International This is doc...@nl2k.ab.ca Ici doc...@nl2k.ab.ca God, Queen and country! Never Satan President Republic! Beware AntiChrist rising! http://twitter.com/rootnl2k http://www.facebook.com/dyadallee Stop

Re: openssl 1.0.1 and FIPS

2011-05-13 Thread Steve Marquess
What is happening? No Fips in the Openssl 1.0.1 STABLe. Correct, and you won't be seeing the FIPS capable support there for some time. We're concentrating on the validation of the module (OpenSSL FIPS Object Module 2.0) now. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc

Re: openssl 1.0.1 and FIPS

2011-05-13 Thread John Foley
Steve, It looks like the FIPS 2.0 code has been going into HEAD. When do you plan to pull a branch for the FIPS Object Model 2.0? On 05/13/2011 12:24 PM, Steve Marquess wrote: What is happening? No Fips in the Openssl 1.0.1 STABLe. Correct, and you won't be seeing the FIPS

Re: openssl 1.0.1 and FIPS

2011-05-13 Thread Steve Marquess
Steve, It looks like the FIPS 2.0 code has been going into HEAD. When do you plan to pull a branch for the FIPS Object Model 2.0? We don't. The source tarball for the eventual validated module will be generated with make -f Makefile.fips dist which extracts the relevant subset of code.

Re: openssl 1.0.1 and FIPS

2011-05-13 Thread John Foley
OK, I'm still a bit confused on the version labeling. Is it safe to assume the next stable label pulled off HEAD (e.g. 1.0.2) will include support for make -f Makefile.fips dist. Or to put the question another way, what stable label should be used to generate the FIPS Object Model 2.0 source

Re: openssl 1.0.1 and FIPS

2011-05-13 Thread Steve Marquess
OK, I'm still a bit confused on the version labeling. Is it safe to assume the next stable label pulled off HEAD (e.g. 1.0.2) will include support for make -f Makefile.fips dist. Or to put the question another way, what stable label should be used to generate the FIPS Object Model 2.0

Re: openssl 1.0.1 and FIPS

2011-05-13 Thread Dr. Stephen Henson
On Fri, May 13, 2011, The Doctor wrote: What is happening? No Fips in the Openssl 1.0.1 STABLe. It never was in 1.0.1-stable. A bug with the snapshot generation meant that HEAD was incorrectly being tared as 1.0.1 in shapshots in fact it was tared as 1.0.0 and 0.9.8 too. That is fixed now

Re: openssl 1.0.1 and FIPS

2011-05-13 Thread The Doctor
On Fri, May 13, 2011 at 12:24:25PM -0400, Steve Marquess wrote: What is happening? No Fips in the Openssl 1.0.1 STABLe. Correct, and you won't be seeing the FIPS capable support there for some time. We're concentrating on the validation of the module (OpenSSL FIPS Object Module 2.0