Re: [openssl-dev] FIPS CAVP tests for WinCE.

2017-06-19 Thread Steve Marquess
eeded until you get the new set of test vectors (which of course cost money). -Steve M. -- Steve Marquess OpenSSL Validation Services, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 301 874 2571 marqu...@openssl.com gpg/pgp key: http://openssl.com/docs/0x6D1892F5.asc -- openssl-dev mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev

[openssl-dev] [openssl-announce] Akamai sponsors TLS 1.3

2017-01-26 Thread Steve Marquess
and support OpenSSL and the OpenSSL user community at the same time; a win-win situation all around. -Steve M. -- Steve Marquess OpenSSL Software Foundation 20-22 Wenlock Road London N1 7GU United Kingdom +44 1785508015 +1 301 874 2571 direct marqu...@opensslfoundation.org ste...@openssl.org

Re: [openssl-dev] About Chinese crypto-algorithms

2016-09-27 Thread Steve Marquess
may also not have the resources to tackle something that would otherwise be of interest (we have a back catalog of nice-to-have cryptography waiting for a rainy day). -Steve M. -- Steve Marquess OpenSSL Validation Services, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 30

Re: [openssl-dev] FIPS validation

2016-09-08 Thread Steve Marquess
algv tests suite to have the algorithms validated > (#3768) using this lab but I cannot see how to use it to "induce" and > error in the FIPS module. > Look at what the "fips_test_suite" option of fips_algv does. That's also discussed in the OpenSSL FIPS module user guide. -Ste

Re: [openssl-dev] FIPS validation

2016-09-05 Thread Steve Marquess
ide: https://www.openssl.org/docs/fips/UserGuide-2.0.pdf Test labs typically just run "fips_algv fips_test_suite" for the functional testing, as it was designed for exactly that purpose. -Steve M. -- Steve Marquess OpenSSL Validation Services, Inc. 1829 Mount Ephraim Road Adamstown,

Re: [openssl-dev] Latest Open SSL and old FIP module

2016-06-17 Thread Steve Marquess
for the #1747 or #2473 validations which stop at revision 2.0.10, in which case that's the newest FIPS module revision with the magical pixie dust of FIPS righteousness, even though the latest revision (2.0.12) functionally supports all platforms for all validations. -- Steve Marquess OpenSSL Validation Se

Re: [openssl-dev] FIPs mode and openssl

2016-05-27 Thread Steve Marquess
Hat FIPS module, not the OpenSSL one, so you'll need to ask that vendor. -Steve M. -- Steve Marquess OpenSSL Validation Services, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@openssl.com gpg/pgp key: http://openssl.com/docs/0x6D1892F5.

Re: [openssl-dev] Where is the sample-comprehensive CAVS test vectors' set with all 259 test vectors

2016-04-14 Thread Steve Marquess
e to reprocess them all, though I usually do given that it's easier to use fipsalgtest.pl on a full test vector set than to manually manipulate individual request files. Note I like to hang on to the test device until the CMVP formally approves the related validation action, as on occasion we've

Re: [openssl-dev] Where is the sample-comprehensive CAVS test vectors' set with all 259 test vectors

2016-04-14 Thread Steve Marquess
est lab. Yes, you have to pay the lab, but welcome to the wonderful world of FIPS 140-2. -Steve M. -- Steve Marquess OpenSSL Validation Services, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@openssl.com gpg/pgp key: http://openssl.c

Re: [openssl-dev] OpenSSL 1.1.0 and FIPS

2016-02-23 Thread Steve Marquess
cious decision to not allow FIPS 140-2 to distort and pervert OpenSSL even more than has already been the case. We'll do a (relatively) clean and sane implementation for 1.1 if and when we can, and nothing otherwise. -Steve M. -- Steve Marquess OpenSSL Validation Services, Inc. 1829 Mount Ephraim Road Ad

Re: [openssl-dev] OpenSSL 1.1.0 and FIPS

2016-02-22 Thread Steve Marquess
IPS 140-2 can be as simple as throwing in a FIPS_mode_set() call. With a stock OpenSSL and hand-jammed FIPS module you'd need to manually vet all application code; the stock OpenSSL won't let you know when your application uses non-allowed cryptography. -Steve M. -- Steve Marquess OpenSSL Valida

Re: [openssl-dev] OpenSSL 1.1.0 and FIPS

2016-02-22 Thread Steve Marquess
). If and when a new FIPS module for 1.1 is developed, it almost certainly will take the form of a new "engine" style modular component. -Steve M. -- Steve Marquess OpenSSL Validation Services, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571

Re: [openssl-dev] Openssl 1.0.2e is compatible with FIPS module openssl-fips-2.0.10

2015-12-09 Thread Steve Marquess
ng 1.1 releases. -Steve M. -- Steve Marquess OpenSSL Software Foundation 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@openssl.com gpg/pgp key: http://openssl.com/docs/0x6D1892F5.asc ___ openssl-d

Re: [openssl-dev] [openssl.org #4115] [PATCH] Remove remaining FIPS code

2015-10-31 Thread Steve Marquess
be unusable absent a matching FIPS 140-2 validation. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/pgp key: http://openssl.com/

Re: [openssl-dev] [openssl.org #4115] [PATCH] Remove remaining FIPS code

2015-10-31 Thread Steve Marquess
lar so the FIPS module and OpenSSL releases would no longer be so tightly coupled. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/p

Re: [openssl-dev] [openssl.org #4055] FIPS Object Module User Guide corrections needed for (*get_entropy)()

2015-10-01 Thread Steve Marquess
opy per byte. Again assume it is uniform (e.g. we don't get 8 bits of entropy in byte 1 and nothing in the next 7). Again lets have a block size of 16 bytes. This time to get 256 bits of entropy the source must provides it in a 256 byte buffer. An extra block is required which makes 272 bytes but b

Re: [openssl-dev] We're working on license changes

2015-08-04 Thread Steve Marquess
of this year it will be renamed. All contemporary references you see to the OpenSSL Software Foundation are for the new non-profit Delaware entity. As Rich has noted we do need to change mentions of the original entity, now confined to FIPS related activities only. -Steve M. -- Steve Marquess

Re: [openssl-dev] PR for OpenSSL FIPS

2015-07-28 Thread Steve Marquess
that modified code validated to claim FIPS 140-2 validation. There is no reason to use the FIPS module code otherwise, so the basic rule is you just have to live with whatever flaws or omissions are present. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road

Re: [openssl-dev] Openssl 1.0.2c include the FIPS 140-2 Object Module

2015-07-01 Thread Steve Marquess
development issues, not for basic usage questions. You might want to start with the OpenSSL FIPS User Guide: https://www.openssl.org/docs/fips/UserGuide-2.0.pdf -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1

Re: [openssl-dev] RSA SigVer (FIPS 186-4) Issue

2015-06-29 Thread Steve Marquess
. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/pgp key: http://openssl.com/docs/0x6D1892F5.asc

Re: [openssl-dev] FIPS support for Mac 64 bit and iOS 64 bit

2015-04-27 Thread Steve Marquess
revision of the pending new salvage edition validation[**]. It will be the same tarball as if we were allowed to update the #1747 validation directly, though. -Steve M. [*] http://openssl.com/fips/hostage.html [**] http://openssl.com/fips/ransom.html -- Steve Marquess OpenSSL Software

Re: Can I still use OpenSSL FIPS v2.0 (#1747) for FIPS 140-2 certified new products?

2014-08-17 Thread Steve Marquess
vendors relative to any alternatives) or cost prohibitive (for the small business). -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg

Re: OpenSSL engine support in OpenSSL FIPS Object Module

2014-07-05 Thread Steve Marquess
securely). A new validation will be necessary. You will find such a validation a significant challenge even without the source code mods you contemplate. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874

Expansion of the OpenSSL team

2014-06-12 Thread Steve Marquess
of coherence. In the meantime we greatly appreciate the patience and support shown by so many of you in the OpenSSL community. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu

Re: Which of HOW TO CONTRIBUTE TO OpenSSL in README is still relevant?

2014-04-28 Thread Steve Marquess
damn hard to be a U.S. citizen and lawfully work on open source cryptography. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/pgp key

Re: The Future of OpenSSL

2014-04-23 Thread Steve Marquess
community for a bit longer. - -Steve M. - -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/pgp key: http://openssl.com/docs/0xCE69424E.asc

Re: Getting patches applied

2014-04-10 Thread Steve Marquess
of discretionary time left over. OpenSSL hangs by a thinner thread than most people realize. Since contributions are as likely to introduce problems or vulnerabilities as code authored directly by the OpenSSL team, I think you can expect even more caution for awhile. -Steve M. -- Steve Marquess

Re: Getting patches applied

2014-04-10 Thread Steve Marquess
, both OpenSSL team members and others. Volunteers? Of course, a process like that wouldn't necessarily prevent future vulnerabilities like the Debian PRNG issue or the heartbeat bug. Even gross bugs are only truly obvious in hindsight. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc

Re: OpenSSL-FIPS - incore and ia32

2014-03-27 Thread Steve Marquess
On 03/26/2014 05:25 PM, Mark Hatle wrote: On 3/26/14, 2:41 PM, Steve Marquess wrote: On 03/26/2014 12:30 PM, Mark Hatle wrote: Looking at the fips_canister.c I see that ia32 (32-bit and 64-bit) systems are not enabled ... Would it be possible to add this change to the fips_canister

Re: OpenSSL-FIPS - incore and ia32

2014-03-26 Thread Steve Marquess
something as trivial as a change to a comment. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/pgp key: http://openssl.com/docs

Re: OpenSSL obsolescence query

2014-02-10 Thread Steve Marquess
Module 2.0, validation certificate #1747, should be used for any new development and careful consideration should be given to upgrading any FIPS 1.2/OpenSSL 0.9.8 based products to FIPS 2.0/OpenSSL 1.0.1. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road

Re: OpenSSL support query

2014-02-07 Thread Steve Marquess
in a text friendly format. Also, the openssl-users list would be more appropriate for this kind of query. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com

Re: FIPS certification

2014-02-03 Thread Steve Marquess
of interest. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/pgp key: http://openssl.com/docs/0xCE69424E.asc

Re: FIPS revalidation after openssl vulnerability fix

2014-01-30 Thread Steve Marquess
. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/pgp key: http://openssl.com/docs/0xCE69424E.asc

Re: FIPS certification

2014-01-30 Thread Steve Marquess
EC DRBG, and the I.G. 9.10 issue (http://opensslfoundation.com/fips/ig95.html) mean that you can't use these test vector formats and the OpenSSL FIPS Object Module 2.0,2.0.1,...,2.0.5 code as-is. So don't say I didn't warn you :-) -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829

Re: FIPS certification

2014-01-30 Thread Steve Marquess
to various requirements. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/pgp key: http://openssl.com/docs/0xCE69424E.asc

Re: FIPS certification

2014-01-30 Thread Steve Marquess
) :-). Our rough cost for the change letter addition of a platform to #1747 is $15K and 2-3 months. Compare that to the cost and time for any type of new validation. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1

Re: FIPS revalidation after openssl vulnerability fix

2014-01-29 Thread Steve Marquess
to that FIPS validation (OpenSSL proper is out of scope). If you've gone to a test lab and obtained some sort of private validation based on OpenSSL code, then you need to consult with that lab. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA

Re: No fips and --with-fipsdir arguments in OpenSSL 1.0.0l configure script.

2014-01-08 Thread Steve Marquess
that paragraph also state Releases other than 1.0.1 cannot be used for this purpose? -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/pgp key

Re: No fips and --with-fipsdir arguments in OpenSSL 1.0.0l configure script.

2014-01-08 Thread Steve Marquess
improve that document I want to know. It's a complex topic. When OpenSSL 1.0.2 is released the User Guide will be updated to state 1.0.1 and 1.0.2 as the current FIPS module will also be compatible with 1.0.2. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road

Re: Openssl integrity checking logic

2013-12-28 Thread Steve Marquess
. That mechanism is of course also fully exposed in the source code: http://www.openssl.org/source/openssl-fips-2.0.5.tar.gz In particular look at fips.c, fips_premain.c, fipsld, and incore (for ELF). -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD

Re: OpenSSL ECCN query

2013-12-09 Thread Steve Marquess
and that I'm not qualified to give legal advice. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/pgp key: http://openssl.com/docs

Re: FIPS verification for AES XTS

2013-11-26 Thread Steve Marquess
code for handling all required FIPS 140-2 algorithm testing. See the FIPS module User Guide: http://www.openssl.org/docs/fips/UserGuide-2.0.pdf Appendix B. That will be the easy part... -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710

Re: Documentation issue?

2013-09-29 Thread Steve Marquess
-DOPENSSL_DRBG_DEFAULT_TYPE=NID_hmac_WithSHA256 \ -DOPENSSL_DRBG_DEFAULT_FLAGS=0 Good catch, thanks. Fixed in revision to be posted soon. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu

Re: [openssl.org #3089] Building OpenSSL 1.0.1e with FIPS on Win64A

2013-07-11 Thread Steve Marquess
. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com __ OpenSSL Project

Re: [openssl.org #3089] Building OpenSSL 1.0.1e with FIPS on Win64A

2013-07-11 Thread Steve Marquess via RT
. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com __ OpenSSL Project

Re: [openssl.org #3074] On PA-RISC, OPENSSL_cleanse() causes crash when called from outside libcrypto, patch included

2013-06-16 Thread Steve Marquess
and thoroughly test a solution PA-RISC is effectively an unsupported platform. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com

Re: [openssl.org #3074] On PA-RISC, OPENSSL_cleanse() causes crash when called from outside libcrypto, patch included

2013-06-16 Thread Steve Marquess via RT
and thoroughly test a solution PA-RISC is effectively an unsupported platform. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com

Re: turning on FIPS mode for different applications- Does POST takes place every time FIPS_mode_set() is called?

2013-04-15 Thread Steve Marquess
which modify that private memory (such as enabling FIPS mode) entirely independently of other processes. The same is true for static linking, of course, as each process has separate copies of both readonly and writable code. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829

Re: [openssl.org #3029] Misspellings in the openssl license document

2013-04-04 Thread Steve Marquess
be misleading. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com __ OpenSSL Project

Re: [openssl.org #3029] Misspellings in the openssl license document

2013-04-04 Thread Steve Marquess via RT
be misleading. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com __ OpenSSL

Re: OCB Authenticated Encryption

2013-04-01 Thread Steve Marquess
or government sponsors that fund such expenses, but in this case I suspect money won't be the deciding factor. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu

Re: OpenSSL Wiki (docbook and...)

2013-03-20 Thread Steve Marquess
to use LyX editor to produce Docbook ? I'm too new at docbook to know yet. I'll start with a regular text editor. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com

Re: OpenSSL Wiki

2013-03-20 Thread Steve Marquess
to. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com __ OpenSSL Project

OpenSSL Wiki

2013-03-19 Thread Steve Marquess
is another complication we don't need right now. There is some content already but new contributions are welcome. We'll be wanting to add some more administrators (sysops) too. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s

Re: OpenSSL Wiki

2013-03-19 Thread Steve Marquess
I have to admit that I feel a little bit intimidated to publish something on this prestigious wiki... Now that made me laugh :-) You're already contributed something with your thoughtful comments, don't stop now. -Steve M. -- Steve Marquess OpenSSL

Re: OpenSSL Wiki

2013-03-19 Thread Steve Marquess
it. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com __ OpenSSL Project

Re: OpenSSL Wiki (docbook and...)

2013-03-19 Thread Steve Marquess
that there are several people contributing content to that document the ODF format is very limiting, hence the ongoing attempt to convert to docbook. That has turned out to be a bit of a challenge but I'm still hoping to pull it off. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829

Re: OpenSSL Wiki

2013-03-19 Thread Steve Marquess
On 03/19/2013 04:59 PM, Matt Caswell wrote: On 19 March 2013 19:38, Steve Marquess marqu...@opensslfoundation.com wrote: I took a quick look to see what utilities might be available to convert between pod and mediawiki markup formats. pod2markdown (CPAN) is close but not quite

Re: OCB Authenticated Encryption

2013-02-06 Thread Steve Marquess
as well as evil, and the licensing situation is muddled enough as it is. Personally I think the existence and unrestricted availability of OpenSSL benefits the good far more than evil. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1

Re: FIPS AES self test

2013-01-17 Thread Steve Marquess
M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com __ OpenSSL Project

Re: OpenSSL openssl-fips-2.0.2 and private label

2012-12-13 Thread Steve Marquess
use OpenSSL. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com __ OpenSSL

Re: OpenSSL openssl-fips-2.0.2 and private label

2012-12-12 Thread Steve Marquess
and a better place to look for size reduction opportunities. In general it will make more sense to use the FIPS module as-is and reference just the specific functionality you need. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877

Re: OpenSSL openssl-fips-2.0.2 and private label

2012-12-12 Thread Steve Marquess
reasons to chose that route; you will have not only the initial difficulty and expense of implementing custom modifications, but also the long term burden of supporting those customizations. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710

Re: FIPS validation process

2012-09-07 Thread Steve Marquess
: fips_premain.c.sha1 fipsld. Also what is process that is taking place in linking with fipsld. Thanks in advance. Regards, Ravi This question would be more appropriate for the openssl-users list. See http://www.openssl.org/docs/fips/UserGuide-2.0.pdf -Steve M. -- Steve

Re: FIPS_mode_set(1) always returns false

2012-09-07 Thread Steve Marquess
to openssl.org yet: http://opensslfoundation.com/testing/validation-2.0/docs/UserGuide-2.0.pdf The instructions are essentially the same as for the 1.2.x module. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874

Re: FIPS Object Module 2.0 - Compliance with 186-3

2012-07-12 Thread Steve Marquess
. The ExtraRandomBits reference is inaccurate. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com

Re: OpenSSL FIPS Object Module 1.2.4 support for Apple iOS and OS X

2012-07-03 Thread Steve Marquess
; to date we have had no sponsors interested in funding OS X for the 2.0 validation. The 2.0 software supports that platform (thanks to the Thursby sponsorship for 1.2.4) and it could still be added via a change letter update. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount

OpenSSL FIPS Object Module v2.0 validation now complete

2012-06-28 Thread Steve Marquess
module, and that document will be maintained in two separate versions for the 1.2 and 2.0 modules: http://www.openssl.org/docs/fips/UserGuide-1.2.pdf http://www.openssl.org/docs/fips/UserGuide-2.0.pdf -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road

OpenSSL FIPS Object Module v2.0 validation -- CD requests

2012-06-28 Thread Steve Marquess
duplicated (at the moment we're burning and printing them one at a time). So please expect some delays in receiving the CDs that have been requested. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct

OpenSSL FIPS Object Module 1.2.4 support for Apple iOS and OS X

2012-06-25 Thread Steve Marquess
. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com __ OpenSSL Project

Re: FIPS 2 mode with shared libs : Clarification needed .....

2012-04-17 Thread Steve Marquess
. The validation is still pending for the 2.0 module (we're engaged in an extended dialog about the precise process used to verify the source tarball). Once a validated module is properly generated you are free to use it with any application, including an OpenSSL shared library. -Steve M. -- Steve Marquess

OpenSSL FIPS Module 2.0 status update

2012-03-06 Thread Steve Marquess
The OpenSSL FIPS Object Module 2.0 is now in coordination status at the CMVP. That's usually a good sign that the formal validation award is imminent (as in a week or three...). -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1

Re: OpenSSL FIPS Module 2.0 status update

2012-03-06 Thread Steve Marquess
64bit on x86, SSE2 optimization AES-NI optimization is not covered, so for instance the module cannot be used with Windows on many Intel Core i5 processors. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874

Re: OpenSSL FIPS Module 2.0 status update

2012-03-06 Thread Steve Marquess
approach. Inquire about purchasing the WhizBang(tm) product from SnakeOil Enterprises and I'll bet they neglect to caution you (for instance) that the validation won't apply to your Core i5 system because AES-NI wasn't included in the validation :-) -Steve M. -- Steve Marquess OpenSSL Software

Re: OpenSSL FIPS Module 2.0 status update

2012-03-06 Thread Steve Marquess
On 03/06/2012 06:47 PM, William A. Rowe Jr. wrote: On 3/6/2012 8:43 AM, Steve Marquess wrote: On 03/06/2012 08:49 AM, Vanden, Michelle CTR USAF AFMC AAC/EBYC wrote: Hello Steve, Will the new certificate support that is has been tested in a Windows 7 That validation will include

Re: OpenSSL validation question

2012-01-26 Thread Steve Marquess
On 01/25/2012 10:00 PM, Thor Lancelot Simon wrote: On Wed, Jan 25, 2012 at 06:35:58PM -0500, Steve Marquess wrote: A rough rule of thumb is that if you create a FIPS module (fipscanister.o) on a formally tested platform (O/S and processor as listed in the Security Policy), and if that binary

Re: FIPS 2.0 validation status, question

2012-01-26 Thread Steve Marquess
enough to a formally tested platform, then the resulting module is validated. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com

Re: OpenSSL validation question

2012-01-25 Thread Steve Marquess
G.5. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com

Re: OpenSSL FIPS Module 2.0 status update

2012-01-09 Thread Steve Marquess
Security Essentials as that which does not appear to trigger this problem. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com

OpenSSL FIPS Module 2.0 status update

2012-01-03 Thread Steve Marquess
/openssl-fips-2.0rc1.tar.gz Note some additional cosmetic changes will be made prior to the formal validation award. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu

Re: FIPS module 2.0 certification status

2011-12-21 Thread Steve Marquess
February. We don't even have the formal submission in yet, though I'm hoping to make an announcement soon. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com

Re: FIPS cross-compile for SH4

2011-12-09 Thread Steve Marquess
directly if you'd like more details. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com

OpenSSL FIPS Module 2.0 status update

2011-11-03 Thread Steve Marquess
are encouraged to reference the OpenSSL-fips-2_0-stable branch in the OpenSSL CVS repository. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com

Upcoming code freeze for the OpenSSL FIPS Object Module v2.0

2011-10-12 Thread Steve Marquess
.tar.gz and later) on their platforms of interest, and report any problems to us. Build and test instructions are given in the ./README.FIPS file. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877-673-6775 marqu

Re: FIPS algorithm testing tools

2011-08-19 Thread Steve Marquess
OpenSSL libraries leads to continuing confusion. For the upcoming 2.0 module we will be releasing the OpenSSL FIPS Object Module source code in a separate tarball (now available as ftp://ftp.openssl.org/snapshot/openssl-fips-2.0-test-2011MMDD.tar.gz snaphots). -Steve M. -- Steve Marquess OpenSSL

Re: Which tar.gz file I need for OpenSSL FIPS Object Module?

2011-07-15 Thread Steve Marquess
with is uniquely identified. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877-673-6775 marqu...@opensslfoundation.com

Re: Call for testing - FIPS object module

2011-07-09 Thread Steve Marquess
to make that compatibility possible. Note as a happy consequence that an existing application that uses OpenSSL for all cryptography can usually be readily converted to use FIPS validated cryptography. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD

Call for testing - FIPS object module

2011-07-07 Thread Steve Marquess
weeks will allow us to easily correct reported problems. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877-673-6775 marqu...@opensslfoundation.com __ OpenSSL

Re: Build Error on 1.0.1 with FIPS

2011-06-29 Thread Steve Marquess
of these test vector sets, but as they are interchangeable there is no point in keeping more than a few representative samples. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877-673-6775 marqu...@opensslfoundation.com

OpenSSL FIPS Module 2.0 status update

2011-06-10 Thread Steve Marquess
) Working but unvalidated code should be available within a month. 2) The formally validated module should be available by Q1 2012. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877-673-6775 marqu...@opensslfoundation.com

New Sponsor for the FIPS Validation (Innominate Security Technologies AG)

2011-05-19 Thread Steve Marquess
platforms will have to be deferred to a later change letter modification process. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877-673-6775 marqu...@opensslfoundation.com

Re: openssl 1.0.1 and FIPS

2011-05-13 Thread Steve Marquess
What is happening? No Fips in the Openssl 1.0.1 STABLe. Correct, and you won't be seeing the FIPS capable support there for some time. We're concentrating on the validation of the module (OpenSSL FIPS Object Module 2.0) now. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc

Re: openssl 1.0.1 and FIPS

2011-05-13 Thread Steve Marquess
. Note we have begun posting FIPS module snapshots at ftp://ftp.openssl.org/snapshot/. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877-673-6775 marqu...@opensslfoundation.com

Re: openssl 1.0.1 and FIPS

2011-05-13 Thread Steve Marquess
and the continued maintenance and development of OpenSSL. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877-673-6775 marqu...@opensslfoundation.com __ OpenSSL Project

Re: TLS 1.2 support

2011-05-13 Thread Steve Marquess
for full implementation is still under consideration. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877-673-6775 marqu...@opensslfoundation.com __ OpenSSL

New Sponsor for the FIPS Validation (Cerebus LLC)

2011-05-07 Thread Steve Marquess
there will be a limited window of opportunity for making changes to the formal baseline -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877-673-6775 marqu...@opensslfoundation.com

New Sponsor for the FIPS Validation

2011-04-29 Thread Steve Marquess
soon, within a few weeks. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877-673-6775 marqu...@opensslfoundation.com __ OpenSSL Project

Re: 1.0.0d or openssl-fips-1.2.2 ?

2011-04-23 Thread Steve Marquess
. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877-673-6775 marqu...@opensslfoundation.com

Re: Please Help I am looking for openssl-fips-1.2.2.tar.gz for Windows 64 Bit

2011-04-22 Thread Steve Marquess
0.9.8+ and the OpenSSL FIPS Object Module v1.2.2 (your only current option), see the User Guide at http://www.openssl.org/docs/fips/UserGuide.pdf. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877-673-6775 marqu

  1   2   >