The OMC has approved working with the FIPS lab to include a number of additional algorithms in the upcoming FIPS validation. One slated for inclusion turns out to be beyond the time available for the fellows and the two others working on 3.0.
This is the X9.42 KDF. What it needs is the X509 and CMS calls removed from the KDF and the various structures constructed piecemeal using calls that already exist within the FIPS provider. If somebody is willing to take this work on, it will likely be included in the FIPS validation for 3.0. If not, it won’t be. Pauli -- Dr Paul Dale | Distinguished Architect | Cryptographic Foundations Phone +61 7 3031 7217 Oracle Australia