Dr. Stephen Henson wrote:

> You need a recent 0.9.7 snapshot to use the 1.1.1 FIPS module, no
official
> release supports it yet. There will be an official release "real soon
> now".


I have tried with openssl-0.9.7-stable-SNAP-20070223.tar.gz,
openssl-0.9.7-stable-SNAP-20070222.tar.gz and openssl-0.9.7m.tar.gz
(which just appeared today).  All fail to build a FIPS capable OpenSSL.

Steps I used are as follows:

cd /usr/src
tar -xvf openssl-fips-1.1.1.tar.gz
cd openssl-fips-1.1.1
./config fips
make
make install
cd ..
rm -rf openssl-fips-1.1.1

tar -xvf openssl-0.9.7m.tar.gz
cd openssl-0.9.7m
./config fips --openssldir=/etc/ssl --prefix=/usr zlib-dynamic shared \
    no-idea no-mdc2 no-rc5
make depend
make MANDIR=/usr/share/man
make MANDIR=/usr/share/man install



Always fails on second last step.  Errors as follows:

fips_desmovs.o: In function `DES_Cipher':
fips_desmovs.c:(.text+0xce): undefined reference to `DES_ecb3_encrypt'
fips_desmovs.c:(.text+0x106): undefined reference to `DES_ecb_encrypt'
fips_desmovs.c:(.text+0x153): undefined reference to
`DES_ede3_cbc_encrypt'
fips_desmovs.c:(.text+0x1c5): undefined reference to
`DES_ede3_ofb64_encrypt'
fips_desmovs.c:(.text+0x23a): undefined reference to
`DES_ede3_cfb64_encrypt'
fips_desmovs.c:(.text+0x265): undefined reference to `DES_ncbc_encrypt'
fips_desmovs.c:(.text+0x2c5): undefined reference to
`DES_ede3_cfb_encrypt'
fips_desmovs.c:(.text+0x2f0): undefined reference to `DES_ofb64_encrypt'
fips_desmovs.c:(.text+0x32e): undefined reference to `DES_cfb_encrypt'
fips_desmovs.c:(.text+0x363): undefined reference to `DES_cfb64_encrypt'
fips_desmovs.o: In function `DESTest':
fips_desmovs.c:(.text+0x432): undefined reference to
`DES_set_key_unchecked'
fips_desmovs.c:(.text+0x545): undefined reference to
`DES_set_key_unchecked'
fips_desmovs.c:(.text+0x55e): undefined reference to
`DES_set_key_unchecked'
fips_desmovs.o: In function `do_mct':
fips_desmovs.c:(.text+0x1092): undefined reference to
`DES_set_odd_parity'
fips_desmovs.c:(.text+0x109e): undefined reference to
`DES_set_odd_parity'
fips_desmovs.c:(.text+0x10aa): undefined reference to
`DES_set_odd_parity'
fips_desmovs.o: In function `main':
fips_desmovs.c:(.text+0x23ce): undefined reference to `FIPS_mode_set'
fips_desmovs.c:(.text+0x25b5): undefined reference to `BIO_new_fp'
fips_desmovs.c:(.text+0x25bd): undefined reference to `ERR_print_errors'
collect2: ld returned 1 exit status
make[1]: *** [fips_desmovs] Error 1
make[1]: Leaving directory `/usr/src/openssl-0.9.7m/test'
make: *** [sub_all] Error 1


Similar results occur for the currently posted Snapshot versions.

Is there a snapshot version that can be used to build a FIPS capable
OpenSSL?

Bill
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    openssl-users@openssl.org
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to