Re: Openssl 3.0 fips usage

2020-02-04 Thread Salz, Rich via openssl-users
* If both default and fips provider are loaded and application generate Rsa key pair(2048 bits) from fips provider and try to use default provider to sign with sha1, is this allowed? The application will have to explicitly “export” the key from the FIPS provider and “import” it into the

Openssl 3.0 fips usage

2020-02-04 Thread Manish Patidar
Hi, Can some one clarify if below usage is allowed by fips According to FIPS 140-2 IG document, CSP defined in approved mode of operation shall not be accessed or shared with non-approved mode of operation. If both default and fips provider are loaded and application generate Rsa key pair(2048