RE: [EXTERNAL] Re: Can Tomcat 9 be FIPS compliant without OpenSSL?

2020-12-09 Thread Amit Pande
(over PKCS12) for our key stores as it is the only format meeting our FIPS requirements. Thanks, Amit -Original Message- From: George Stanchev Sent: Saturday, December 5, 2020 11:17 AM To: Tomcat Users List Subject: RE: [EXTERNAL] Re: Can Tomcat 9 be FIPS compliant without OpenSSL?

RE: [EXTERNAL] Re: Can Tomcat 9 be FIPS compliant without OpenSSL?

2020-12-05 Thread George Stanchev
Chris -Original Message- From: Christopher Schultz Sent: Friday, December 04, 2020 1:20 PM To: users@tomcat.apache.org Subject: Re: [EXTERNAL] Re: Can Tomcat 9 be FIPS compliant without OpenSSL? > With the pluggability of Java's crypto interface, I seriously doubt > Oracle is

Re: [EXTERNAL] Re: Can Tomcat 9 be FIPS compliant without OpenSSL?

2020-12-04 Thread Christopher Schultz
George, On 12/4/20 14:22, George Stanchev wrote: -Original Message- From: Christopher Schultz Sent: Friday, December 04, 2020 10:58 AM To: users@tomcat.apache.org Subject: Re: [EXTERNAL] Re: Can Tomcat 9 be FIPS compliant without OpenSSL? George, On 12/3/20 21:59, George Stanchev

RE: [EXTERNAL] Re: Can Tomcat 9 be FIPS compliant without OpenSSL?

2020-12-04 Thread George Stanchev
-Original Message- From: Christopher Schultz Sent: Friday, December 04, 2020 10:58 AM To: users@tomcat.apache.org Subject: Re: [EXTERNAL] Re: Can Tomcat 9 be FIPS compliant without OpenSSL? George, On 12/3/20 21:59, George Stanchev wrote: > Java's FIPS mode is "expirmental&

Re: [EXTERNAL] Re: Can Tomcat 9 be FIPS compliant without OpenSSL?

2020-12-04 Thread Christopher Schultz
ande Sent: Tuesday, November 24, 2020 9:31 AM To: Tomcat Users List ; Avik Ray Subject: RE: [EXTERNAL] Re: Can Tomcat 9 be FIPS compliant without OpenSSL? Avik, Did you happen to try out the steps in README https://github.com/amitlpande/tomcat-9-fips here? I am looking for feedback from the comm

RE: [EXTERNAL] Re: Can Tomcat 9 be FIPS compliant without OpenSSL?

2020-12-03 Thread George Stanchev
-Original Message- From: George Stanchev Sent: Thursday, December 03, 2020 7:59 PM To: Tomcat Users List ; Avik Ray Subject: RE: [EXTERNAL] Re: Can Tomcat 9 be FIPS compliant without OpenSSL? Java's FIPS mode is "expirmental" feature that was removed in later Java versions. It

RE: [EXTERNAL] Re: Can Tomcat 9 be FIPS compliant without OpenSSL?

2020-12-03 Thread George Stanchev
-Original Message- From: George Stanchev Sent: Thursday, December 03, 2020 7:59 PM To: Tomcat Users List ; Avik Ray Subject: RE: [EXTERNAL] Re: Can Tomcat 9 be FIPS compliant without OpenSSL? Java's FIPS mode is "expirmental" feature that was removed in later Java versions. It

RE: [EXTERNAL] Re: Can Tomcat 9 be FIPS compliant without OpenSSL?

2020-12-03 Thread George Stanchev
u're stuck with BCKFS or PEMs. George -Original Message- From: Amit Pande Sent: Tuesday, November 24, 2020 9:31 AM To: Tomcat Users List ; Avik Ray Subject: RE: [EXTERNAL] Re: Can Tomcat 9 be FIPS compliant without OpenSSL? Avik, Did you happen to try out the steps in README https://

RE: [EXTERNAL] Re: Can Tomcat 9 be FIPS compliant without OpenSSL?

2020-11-24 Thread Amit Pande
- From: Christopher Schultz Sent: Friday, November 6, 2020 3:40 PM To: Tomcat Users List ; Avik Ray Subject: [EXTERNAL] Re: Can Tomcat 9 be FIPS compliant without OpenSSL? Avik, On 11/6/20 14:50, Avik Ray wrote: > Thanks a lot Anil for the detailed readme, and Martin for pointing me to it. >

Re: Can Tomcat 9 be FIPS compliant without OpenSSL?

2020-11-06 Thread Christopher Schultz
Avik, On 11/6/20 14:50, Avik Ray wrote: Thanks a lot Anil for the detailed readme, and Martin for pointing me to it. We have done most of these configs. Are these steps sufficient to ensure that all incoming and outgoing TLS connections are FIPS compliant? This isn't something that the

Re: Can Tomcat 9 be FIPS compliant without OpenSSL?

2020-11-06 Thread Avik Ray
Thanks a lot Anil for the detailed readme, and Martin for pointing me to it. We have done most of these configs. Are these steps sufficient to ensure that all incoming and outgoing TLS connections are FIPS compliant? Or is there also a need to compile an APR connector with an underlying

Re: Can Tomcat 9 be FIPS compliant without OpenSSL?

2020-11-05 Thread Martin Grigorov
Hi, On Fri, Nov 6, 2020 at 8:57 AM Avik Ray wrote: > Dear team, > Sending this query again after subscribing to the mailing list. Sent > it originally 3 days back, but just saw an error response in the spam > folder asking to subscribe first. > > We are using Tomcat 9.0.37 x64 on Windows Server

Can Tomcat 9 be FIPS compliant without OpenSSL?

2020-11-05 Thread Avik Ray
Dear team, Sending this query again after subscribing to the mailing list. Sent it originally 3 days back, but just saw an error response in the spam folder asking to subscribe first. We are using Tomcat 9.0.37 x64 on Windows Server 2016 OS and the NIO connector with JSSE, without an underlying