Dear all, I am working on an embedded product which currently uses OpenSSL 0.9.8w with FIPS support.
We have received a request to support ECC and in particular the following cipher suites for ECC certification TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA and TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA. I can see from the header files for OpenSSL 0.9.8, the ECC ciphersuites from draft-ietf-tls-ecc-01.txt (Mar 15, 2001) have been defined so potentially could be used. However, from the OpenSSL change log, I can see there were many improvements/enhancements for ECC from 0.9.8n to 1.0.0. Have there been any improvements/enhancements on 0.9.8? As the embedded product must support FIPS, does anybody know whether OpenSSL 0.9.8 has sufficient functionality to pass ECC certification with these cipher suites? Or will I have to upgrade to OpenSSL 1.0.0 and wait for FIPS certification on OpenSSL 1.0.0 to be complete? Thank you for your assistance and I look forward to your responses. Thanks.. John John Simner BSc(Hons) MSc CEng. MIET Software Engineer Siemens Enterprise Communications Limited Tel: + 44 (0) 1908 817378 Please Note New Telephone number from 11/09/10: + 44 (0) 1908 817378 Email: john.sim...@siemens-enterprise.com www.siemens.co.uk/enterprise<http://www.siemens.co.uk/enterprise> Communication for the open minded<blocked::blocked::http://www.siemens.co.uk/open> Siemens Enterprise Communications Limited. Registered office: Brickhill Street, Willen Lake, Milton Keynes, MK15 0DJ. Registered No: 5903714, England. Siemens Enterprise Communications Ltd is a Trademark Licensee of Siemens AG. This communication contains information which is confidential and may also be privileged. It is for the exclusive use of the addressee. If you are not the addressee please note that any distribution, reproduction, copying, publication or use of this communication or the information is prohibited. If you have received this communication in error, please contact us immediately and also delete the communication from your computer. We accept no liability for any loss or damage suffered by any person arising from use of this email. P Please consider the environment - do you really need to print this email?