Re: Reseed testing in the FIPS DRBG implementation

2011-08-22 Thread David Jacobson
From: Henrik Grindal Bakken Sent by: owner-openssl-...@openssl.org Date: 08/16/2011 05:50PM Subject: Re: Reseed testing in the FIPS DRBG implementation "Dr. Stephen Henson" writes: > The OpenSSL DRBG implementation tests all variants during the POST > and also

Re: Reseed testing in the FIPS DRBG implementation

2011-08-20 Thread Peter Waltenberg
en Sent by: owner-openssl-...@openssl.orgDate: 08/16/2011 05:50PMSubject: Re: Reseed testing in the FIPS DRBG implementation"Dr. Stephen Henson" writes:> The OpenSSL DRBG implementation tests all variants during the POST> and also tests specific versions on instantiation. That incl

Re: Reseed testing in the FIPS DRBG implementation

2011-08-18 Thread Henrik Grindal Bakken
"Dr. Stephen Henson" writes: > The OpenSSL DRBG implementation tests all variants during the POST > and also tests specific versions on instantiation. That includes an > extensive health check and a KAT. So in that sense there will be two > KATs before a reseed takes place but no KAT immediately

Re: Reseed testing in the FIPS DRBG implementation

2011-08-03 Thread Dr. Stephen Henson
On Wed, Aug 03, 2011, Henrik Grindal Bakken wrote: > "Dr. Stephen Henson" writes: > > > On Wed, Aug 03, 2011, Henrik Grindal Bakken wrote: > > > >> > >> Hi. I'm working on FIPS-validating a product using OpenSSL (but with > >> a crypto module spanning wider, so we can't easily use the OpenSSL

Re: Reseed testing in the FIPS DRBG implementation

2011-08-03 Thread Henrik Grindal Bakken
"Dr. Stephen Henson" writes: > On Wed, Aug 03, 2011, Henrik Grindal Bakken wrote: > >> >> Hi. I'm working on FIPS-validating a product using OpenSSL (but with >> a crypto module spanning wider, so we can't easily use the OpenSSL >> crypto module). During code review, some questions about the R

Re: Reseed testing in the FIPS DRBG implementation

2011-08-03 Thread Dr. Stephen Henson
On Wed, Aug 03, 2011, Henrik Grindal Bakken wrote: > > Hi. I'm working on FIPS-validating a product using OpenSSL (but with > a crypto module spanning wider, so we can't easily use the OpenSSL > crypto module). During code review, some questions about the RNG > tests have come up. Most specifi

Reseed testing in the FIPS DRBG implementation

2011-08-03 Thread Henrik Grindal Bakken
Hi. I'm working on FIPS-validating a product using OpenSSL (but with a crypto module spanning wider, so we can't easily use the OpenSSL crypto module). During code review, some questions about the RNG tests have come up. Most specifically, from what I can read, SP 800-90 requires that (in 11.3.