Re: FIPS_selftest_rng fails on Solaris10 x86

2009-02-13 Thread Steve Marquess
Thomas Francis, Jr. wrote: ... The fastest way to get something that works for "FIPS" is to just follow the instructions in the user's guide (which is based on the security policy). Those instructions have worked for me every time on several different UNIX platforms. Thanks, that makes my day

Re: FIPS_selftest_rng fails on Solaris10 x86

2009-02-13 Thread Dr. Stephen Henson
On Thu, Feb 12, 2009, RussMitch wrote: > > No, the test/fips_test_suite does not run correctly, here's the results: > > FIPS-mode test application > > 1. Non-Approved cryptographic operation test... > a. Included algorithm (D-H)...successful > ERROR:2d072065:lib=45,func=114,reas

RE: FIPS_selftest_rng fails on Solaris10 x86

2009-02-13 Thread Thomas Francis, Jr.
I'm not convinced this is a problem with making a normal FIPS build, though. A while back, I compiled openssl-fips-1.2 following the security policy, then compiled openssl-0.9.8j to make use of the fips canister built from openssl-fips-1.2 (again, following the security policy). This was all on S

Bug 1478 (Compile error on AIX 4.3 with zlib and IBM C-Compiler)

2009-02-13 Thread Bruce Stephens
We've just been hit by this (not on AIX---the bug is quite general, I think). The problem looks real (the ZLIB_INCLUDE flag is set but never used), and the patch looks plausible. Is there some reason the bug is still open? __ Ope