FIPS mode: failure during build-test of shared library: FIPS_check_incore_fingerprint:fingerprint does not match

2013-09-11 Thread TJ
I'm working with the Debian/Ubuntu openssl package for Ubuntu 13.10, Saucy, version 1.0.1e. I'm trying to adapt the Debian package-build to produce a FIPS-linked openssl. I've followed the procedure to download, build and install the FIPS canister v2.0.1 which was successful: $ ../../openssl-f

[openssl.org #2459] ecdsa_method declaration prevents use in implementing a dynamic engine

2013-09-11 Thread Stephen Henson via RT
On Wed Sep 11 17:52:03 2013, deeng...@anl.gov wrote: > > Attached is a patch to move the definition of ecdsa_method > from src/crypto/ecdsa/ecs_locl.h to ecdsa.h > and move the definition if ecdh_method > from src/crypto/ecdh/ech_locl.h to ecdh.h > It's been policy that we should avoiding direct s

Re: [openssl.org #2459] ecdsa_method declaration prevents use in implementing a dynamic engine

2013-09-11 Thread Douglas E. Engert
On 9/11/2013 2:01 PM, Stephen Henson via RT wrote: On Wed Sep 11 17:52:03 2013, deeng...@anl.gov wrote: Attached is a patch to move the definition of ecdsa_method from src/crypto/ecdsa/ecs_locl.h to ecdsa.h and move the definition if ecdh_method from src/crypto/ecdh/ech_locl.h to ecdh.h It

[openssl.org #2459] ecdsa_method declaration prevents use in implementing a dynamic engine

2013-09-11 Thread Douglas E. Engert via RT
Attached is a patch to move the definition of ecdsa_method from src/crypto/ecdsa/ecs_locl.h to ecdsa.h and move the definition if ecdh_method from src/crypto/ecdh/ech_locl.h to ecdh.h These mods expose the EC method definitions similar to how the RSA method (rsa_meth_st) is defined in rsa.h. Thi

Re: [openssl.org #2459] ecdsa_method declaration prevents use in implementing a dynamic engine

2013-09-11 Thread Douglas E. Engert via RT
On 9/11/2013 2:01 PM, Stephen Henson via RT wrote: > On Wed Sep 11 17:52:03 2013, deeng...@anl.gov wrote: >> >> Attached is a patch to move the definition of ecdsa_method >> from src/crypto/ecdsa/ecs_locl.h to ecdsa.h >> and move the definition if ecdh_method >> from src/crypto/ecdh/ech_locl.h to

RE: FIPS and rebasing

2013-09-11 Thread Perrow, Graeme
(Responding to the list so that the solution gets archived with the rest of the thread.) Thanks for your response and the pointer to VMMap, a very useful tool which helped me to figure out the problem. My application allocates a very large chunk of memory, which (usually) included the address t