Flaw in OpenSSL FIPS Object Module v1.1.1 - Corrected Update

2007-12-03 Thread Steve Marquess
. -Steve M. -- Steve Marquess Open Source Software Institute [EMAIL PROTECTED] __ OpenSSL Project http://www.openssl.org User Support Mailing Listopenssl-users@openssl.org

Re: Fingerprinting FIPS Object Module Vulnerabilities

2007-12-10 Thread Steve Marquess
approves the revised version that was submitted last Thursday. That will take perhaps another week, then the software vendors will need to rework their applications accordingly. Only then will you have patches to apply. -Steve M. -- Steve Marquess Open Source Software Institute [EMAIL PROTECTED

Preview release of OpenSSL FIPS Object Module v1.1.2

2007-12-13 Thread Steve Marquess
with the new algorithm and FIPS 140-2 certificate numbers and the digest given above, but the build/install instructions will not change. -Steve M. -- Steve Marquess Open Source Software institute [EMAIL PROTECTED] __ OpenSSL

Re: FIPS Module on Mac OS X (Intel)

2007-12-19 Thread Steve Marquess
for the purpose of modifying the default OpenSSL FIPS Object Module build is not going to be considered acceptable. -Steve M. -- Steve Marquess Open Source Software Institute [EMAIL PROTECTED] __ OpenSSL Project

Re: FIPS on Linux

2008-01-22 Thread Steve Marquess
be used as-is, only that the integrity of fipscanister.o be verified at application link time with respect to fipscanister.o.sha1. So yes, you can perform that double link in another equivalent fashion. -Steve M. -- Steve Marquess Open Source Software Institute [EMAIL PROTECTED

Re: FIPS 1.1.2/1.2 validation progress

2008-01-29 Thread Steve Marquess
Kyle Hamilton wrote: As has been mentioned numerous times by Steve Marquess, the FIPS validation process is fraught with peril. It is entirely, from what I gather, rather like playing Chutes Ladders with a constantly-changing board. I have been holding off on making any announcements

Re: About the fips openssl testsuite

2008-01-30 Thread Steve Marquess
very much!! Please see http://www.openssl.org/docs/fips/ for the User Guide (appendix B in particular) and sample test vectors. -Steve M. -- Steve Marquess Open Source Software Institute [EMAIL PROTECTED] __ OpenSSL Project

comment on donations

2014-04-11 Thread Steve Marquess
for the show of support as the monetary value. 100% of all donations (minus the hefty PayPal fees) will go directly to OpenSSL team members. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu

Re: comment on donations

2014-04-11 Thread Steve Marquess
/Mastercard) merchant account, but the recurring fees for that would eat up much of what is typically received in donations (and I don't expect the current volume of donations to continue indefinitely). I am looking into the suggestions for Bitcoin payments. -Steve M. -- Steve Marquess OpenSSL

donation update

2014-04-11 Thread Steve Marquess
are obviously suspect, others will need to be carefully vetted. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/pgp key: http://openssl.com

Re: comment on donations

2014-04-11 Thread Steve Marquess
. If there was enough money at stake then I would run not walk to said attorney and accountants and pay them to create/convert an appropriate non-profit legal entity. I don't see that making financial sense though, even with the recent boost in donations. -Steve M. -- Steve Marquess OpenSSL Software

Re: comment on donations

2014-04-12 Thread Steve Marquess
professional services, I can tell you that you don't just set up a corporation for $500-$750. Not a real functioning entity with real clients and real revenues, insurance, employees, subcontractors, etc. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD

Re: Who uses heartbeat?

2014-04-13 Thread Steve Marquess
, refactoring, documentation, the backlog of worthy patch contributions, etc. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/pgp key: http

corporate donation from Acano Ltd.

2014-04-14 Thread Steve Marquess
work we are doing for them. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/pgp key: http://openssl.com/docs/0xCE69424E.asc

donation from Brennan Vincent

2014-04-14 Thread Steve Marquess
of necessary OpenSSL development and maintenance activities. I still believe that to be the case, but am reminded by all of these donations that the OpenSSL team members are not the only ones who feel a responsibility for electronic security and privacy around the world. -Steve M. -- Steve

Re: Could openssl foundation give itself rules not to accept money from intelligence agencies?

2014-04-15 Thread Steve Marquess
the issue of perceptions does matter, we don't need that distraction, 2) U.S. export controls make it challenging for U.S. citizens to work on cryptography (BTDT myself), 3) it gives me a handy excuse to avoid admitting that I'm not smart enough to work on the code. -Steve M. -- Steve Marquess

unacknowledged donations

2014-04-17 Thread Steve Marquess
them manually or throwing together something automagical. So apologies again for my negligence in keeping up with those. I'll get there eventually. I hope. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874

Donation from Paessler AG

2014-04-18 Thread Steve Marquess
as well as Paessler AG. Total donations for April are about US$23,000; more than all previous donations combined. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com

donation thank you - Hitomi Kimura

2014-04-30 Thread Steve Marquess
. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/pgp key: http://openssl.com/docs/0xCE69424E.asc

donation - Nokia, our first Platinum Sponsor

2014-04-30 Thread Steve Marquess
-direct-to-the-openssl-project -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/pgp key: http://openssl.com/docs/0xCE69424E.asc

graphic arts help needed

2014-05-08 Thread Steve Marquess
file of that logo too, but not the skill to use it. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/pgp key: http://openssl.com/docs

Re: graphic arts help needed

2014-05-08 Thread Steve Marquess
duplicating effort. I will make a note though just in case those first two don't work out for any reason. Thanks, -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com

Re: graphic arts help needed

2014-05-08 Thread Steve Marquess
asked for volunteers willing to bask in the warm glow of accomplishment and gratitude in lieu of any tangible remuneration. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu

Re: graphic arts help needed

2014-05-08 Thread Steve Marquess
consider a new logo for OpenSSL that's a bit more modern and representative of what you guys do. Any bonus points for doing it all in GIMP or Inkscape? Yes, extra bonus points for open source tools :-) -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road

Re: graphic arts help needed

2014-05-13 Thread Steve Marquess
the prospective user of our first OpenSSL Sponsor logo and they chose this one: http://opensslfoundation.com/testing/data/openssl-platinum-sponsor-logo.jpg from JAaron Anderson. Thanks to everyone who sent a logo. I was thrilled to have so many choices. -Steve M. -- Steve Marquess OpenSSL Software

Donation from Nick Shapley of Pen Test Partners

2014-05-13 Thread Steve Marquess
The OpenSSL project recently received a donation of US$500 from Nick Shapley on behalf of Pen Test Partners (http://www.pentestpartners.com/). Thank you Nick and Pen Test Partners! -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1

Re: Linux Foundation's Core Infrastructure Initiative progress?

2014-05-13 Thread Steve Marquess
cautiously optimistic that we'll be able to announce something in about a week. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/pgp key

Corporate donation from Globalsign

2014-05-14 Thread Steve Marquess
The OpenSSL Software Foundation. Thank you Globalsign. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/pgp key: http://openssl.com/docs

Donation from Smartisan Technology

2014-05-27 Thread Steve Marquess
and maintained. This donation is some pretty significant support :-) Thank you Smartisan Technology, and Mr. Yonghao Luo. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu

Platinum Sponsorship by Huawei

2014-05-28 Thread Steve Marquess
of many years should not go unnoticed and unrecognised. Please accept our thanks as you have saved us a lot of time and money. A platinum sponsorship is a truly excellent way to say thanks :-) Thank you Huawei! -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road

Re: Platinum Sponsorship by Huawei

2014-05-28 Thread Steve Marquess
On 05/28/2014 05:18 PM, Frans de Boer wrote: On 05/28/2014 10:05 PM, Steve Marquess wrote: Please accept our thanks as you have saved us a lot of time and money Yes, quite an understatement :\ Now a state sponsored company is sponsoring openssl.org? The bigger the country, the higher

Linux Foundation Core Infrastructure Initiative fellowships

2014-05-29 Thread Steve Marquess
and revitalize OpenSSL. I hope we'll have some detailed plans to share publicly in a week or two. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg

Re: Linux Foundation Core Infrastructure Initiative fellowships

2014-05-29 Thread Steve Marquess
On 05/29/2014 11:39 AM, Steve Marquess wrote: I am very pleased to announce that the Linux Foundation Core Infrastructure Initiative (CII), http://www.linuxfoundation.org/programs/core-infrastructure-initiative, has extended full time fellowships to Stephen Henson and Andy Polykov ... Oops

Sponsorship by Milton Security Group

2014-05-29 Thread Steve Marquess
funding of this sort is especially useful as it allows for long range planning. In the aggregate such sustainable funding will allow us to embark on major long term objectives. Thank you Milton Security Group and Jim McMurry! -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount

Expansion of the OpenSSL team

2014-06-12 Thread Steve Marquess
of coherence. In the meantime we greatly appreciate the patience and support shown by so many of you in the OpenSSL community. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu

Donation from VT Enterprise

2014-06-13 Thread Steve Marquess
^11+2^8 dollars ($2,304). Thank you Victor and VT Enterprise! -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/pgp key: http

Expansion of the OpenSSL team

2014-06-19 Thread Steve Marquess
I am pleased to announce the addition of Emilia Kasper to the OpenSSL team (see https://www.openssl.org/about/). This brings us up to twelve active team members and adds some strong cryptographic skills. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road

Expansion of the OpenSSL Team

2014-06-21 Thread Steve Marquess
I am pleased to announce the addition of Rich Salz and Kurt Roeckx to the OpenSSL team (see https://www.openssl.org/about/). They both bring a long record of past contributions. This brings the count up to fourteen. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount

Removal of Dual EC DRBG from the OpenSSL FIPS module

2014-06-30 Thread Steve Marquess
to retroactively remove Dual EC DRBG from that as well. If that approval is not given we'll be in the odd position of re-introducing Dual EC DRBG with revision 2.0.7 when that is eventually approved. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD

OpenSSL roadmap

2014-07-01 Thread Steve Marquess
to this point, but that's not for lack of vigorous activity on the part of the team. We're keenly aware that we have a long haul ahead of us and wanted to be sure we started off in the right direction with the right objectives. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount

Donation from AirVPN

2014-07-02 Thread Steve Marquess
weeks poll. The most voted project is awarded a donation (https://airvpn.org/topic/10122-guidelines). The OpenSSL project was the top contender for all the proposed May projects with a poll held in June. Thank you AirVPN, and AirVPN community! -Steve M. -- Steve Marquess OpenSSL Software

Re: TPM support with OpenSSL FIPS Object Module

2014-07-04 Thread Steve Marquess
management folks make the call. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/pgp key: http://openssl.com/docs/0xCE69424E.asc

Re: TPM support with OpenSSL FIPS Object Module

2014-07-04 Thread Steve Marquess
) is no longer usable as-is for copycat validations. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/pgp key: http://openssl.com/docs

Re: OpenSSL engine support in OpenSSL FIPS Object Module

2014-07-05 Thread Steve Marquess
securely). A new validation will be necessary. You will find such a validation a significant challenge even without the source code mods you contemplate. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874

Two new versions of the OpenSSL FIPS Object Module v2.0: 2.0.6 and 2.0.7

2014-07-07 Thread Steve Marquess
of that document. That error has been reported and should be corrected in a few days. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/pgp key: http://openssl.com

Re: Making Open SSH FIPS compliant

2014-07-16 Thread Steve Marquess
(this is available in patches from Roumen Petrov). -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/pgp key: http://openssl.com/docs

Re: FIPS change letter process

2014-07-21 Thread Steve Marquess
done at once). Anything running Linux *probably* qualifies as uncomplicated. If you can afford to wait long enough there is always the chance that someone else will sponsor the specific platform that you want. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road

Re: Open SSL version with FIPS Certified code and TLS 1.2 Support

2014-07-22 Thread Steve Marquess
upgrade to OpenSSL 1.0.1 and the 2.0 FIPS module, the most current revision of which is 2.0.7. The *combination* of that FIPS module and OpenSSL, the FIPS capable OpenSSL, will support TLS 1.2 and (if properly built) contain a FIPS 140-2 validated cryptographic module. -Steve M. -- Steve Marquess

Re: openssl-fips-1.2.4

2014-09-01 Thread Steve Marquess
On 09/01/2014 06:55 AM, Gayathri Manoj wrote: Hi All, Please let me know how can I see the FIPS certificate for openssl-fips-1.2.4. Thanks, Gayathri http://csrc.nist.gov/groups/STM/cmvp/documents/140-1/140val-all.htm#1051 -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc

OpenSSL FIPS Object Module 2.0.8 now available - Dual EC DRBG removed (again)

2014-09-13 Thread Steve Marquess
unless you feel removal of Dual EC DRBG warrants such an upgrade. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/pgp key: http

The ascension of Matt Caswell

2014-11-04 Thread Steve Marquess
in particular. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/pgp key: http://openssl.com/docs/0x6D1892F5.asc

Re: Where to download OpenSSL FIPS v2.0.9

2014-11-21 Thread Steve Marquess
similar change letter approvals take as little as a few weeks (though that was years ago) and as long as six months. My best guest is perhaps three months (taking into account the slowdown over the upcoming holiday season), so I hope to see 2.0.9 out sometime in mid February. -Steve M. -- Steve

Re: Differences between openssl-fips-2.0.7 and 2.0.8

2014-11-21 Thread Steve Marquess
problem. I have discussed that issue in a personal blog entry: http://veridicalsystems.com/blog/immutability-of-fips/ for those who care to stare into that abyss. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s

[openssl-users] Call for HP Proliant wizard

2014-12-15 Thread Steve Marquess
. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/pgp key: http://openssl.com/docs/0x6D1892F5.asc

[openssl-users] OpenSSL mail outage tomorrow 1200-1400UTC

2014-12-22 Thread Steve Marquess
We've been experiencing some issues with the system that handles @openssl.org E-mail and the mailing lists. The hardware vendor will be swapping the system board Tuesday Dec. 23 beginning at 1200UTC. The outage is expected to take approximately two hours. -Steve M. -- Steve Marquess OpenSSL

[openssl-users] Another record-breaking donation from Smartisan Technology

2014-12-30 Thread Steve Marquess
. Thank you Smartisan Technology, and CEO Mr. Yonghao Luo. I hope that in roughly a year from now with the release of OpenSSL 1.1 you will be pleased with what we have accomplished. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673

[openssl-users] Platinum Sponsorship by Oracle

2015-01-14 Thread Steve Marquess
of that module would not have been possible. Thank you Oracle! -Steve M. -- Steve Marquess OpenSSL Software Foundation Inc. 20-22 Wenlock Road London N1 7GU United Kingdom +44 1785508015 +1 301 874 2571 direct marqu...@opensslfoundation.org ste...@openssl.org

Re: [openssl-users] FIPS, continuous tests, and error reporting

2015-02-19 Thread Steve Marquess
have worse problems than a non-functioning FIPS module. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/pgp key: http://openssl.com

Re: [openssl-users] OpenSSL FIPS mode system integration

2015-02-19 Thread Steve Marquess
to pay and wait for your own custom validation of the modified code). -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/pgp key: http

Re: [openssl-users] Using FIPS mode and modifying apps

2015-01-27 Thread Steve Marquess
On 01/26/2015 06:21 PM, jone...@teksavvy.com wrote: On Fri, 16 Jan 2015 10:16:48 -0500 Steve Marquess marqu...@openssl.com wrote: On 01/15/2015 05:52 AM, Marcus Meissner wrote: On Linux usually triggered by /proc/sys/crypto/fips_enabled containing 1 or the environment variable

Re: [openssl-users] Using FIPS mode and modifying apps

2015-01-28 Thread Steve Marquess
it easier for vendors like you to pursue private proprietary validations would be of interest to a far smaller subset. We have enough demands on our limited resources as it is to expend them on such a limited constituency. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount

Re: [openssl-users] OpenSSL FIPS (0.9.8) coexisting with non-FIPS (1.0.1)

2015-01-20 Thread Steve Marquess
certification? (Is this written up anywhere?) The OpenSSL FIPS Object Module v2.0, validation certificate #1747, remains available for use with (to date) 102 formally tested platforms: http://csrc.nist.gov/groups/STM/cmvp/documents/140-1/140val-all.htm#1747 -Steve M. -- Steve Marquess OpenSSL

Re: [openssl-users] Using FIPS mode and modifying apps

2015-01-27 Thread Steve Marquess
On 01/26/2015 06:21 PM, jone...@teksavvy.com wrote: On Fri, 16 Jan 2015 10:16:48 -0500 Steve Marquess marqu...@openssl.com wrote: On 01/15/2015 05:52 AM, Marcus Meissner wrote: On Linux usually triggered by /proc/sys/crypto/fips_enabled containing 1 or the environment variable

Re: [openssl-users] Using FIPS mode and modifying apps

2015-01-27 Thread Steve Marquess
On 01/27/2015 11:09 AM, jonetsu wrote: Steve Marquess marqu...@openssl.comwrote on 01/27/15 09:18: Thank you (and Tom) for your comments - much appreciated. Tom Francis nailed the answer to this one. We did design the FIPS module + FIPS capable OpenSSL combination to make it possible

Re: [openssl-users] Using FIPS mode and modifying apps

2015-01-28 Thread Steve Marquess
it easier for vendors like you to pursue private proprietary validations would be of interest to a far smaller subset. We have enough demands on our limited resources as it is to expend them on such a limited constituency. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount

[openssl-users] OpenSSL FIPS module breaks the century mark

2015-01-04 Thread Steve Marquess
preferable to use the latest revision as that will be valid for all tested platforms. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/pgp

Re: [openssl-users] OpenSSL source reformat

2015-01-06 Thread Steve Marquess
with declarations and import duties for computer gear; I have no idea what's involved with recuperative beverages. But I volunteer to drink it and tell my colleagues how good it was :-) -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877

Re: [openssl-users] SP800-90 DRBG in OpenSSL FIPS 140 for SP800-90A?

2015-03-22 Thread Steve Marquess
://csrc.nist.gov/groups/STM/cmvp/documents/140-1/140sp/140sp1747.pdf which is worth referencing for any does the OpenSSL FIPS Object Module have X questions. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571

[openssl-users] FIPS 140-2 hostage rescue underway

2015-03-18 Thread Steve Marquess
paperwork will require some careful attention to the multiple validations which will overlap the same module (the downside). Confusion is inevitable, feel free to post questions to this list. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710

Re: [openssl-users] FIPS: ECC licensing

2015-03-16 Thread Steve Marquess
. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/pgp key: http://openssl.com/docs/0x6D1892F5.asc

Re: [openssl-users] FIPS: Common method executed in case of error

2015-03-10 Thread Steve Marquess
. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/pgp key: http://openssl.com/docs/0x6D1892F5.asc ___ openssl

Re: [openssl-users] FIPS: Which DRBG ?

2015-03-24 Thread Steve Marquess
standards and also from the OpenSSL FIPS Object Module). Now the code for the OpenSSL FIPS module can no longer be used as-is for new private label or copycat validations, but that's for different reasons and not because of the DRBGs. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc

Re: [openssl-users] FIPS: Which DRBG ?

2015-03-24 Thread Steve Marquess
. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/pgp key: http://openssl.com/docs/0x6D1892F5.asc

Re: [openssl-users] FIPS Linux kernel documentation ?

2015-03-25 Thread Steve Marquess
. - thanks. I wasn't aware the Linux kernel (the real one, not proprietary commercial derivatives) had a FIPS mode. Please enlighten me. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu

Re: [openssl-users] FIPS Linux kernel documentation ?

2015-03-26 Thread Steve Marquess
. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/pgp key: http://openssl.com/docs/0x6D1892F5.asc

Re: [openssl-users] FIPS Linux kernel documentation ?

2015-03-27 Thread Steve Marquess
On 03/27/2015 04:45 AM, Henrik Grindal Bakken wrote: Steve Marquess marqu...@openssl.com writes: If the CMVP bureaucracy insists on a specific kernel version for the platform number, this should be one of the Long Term Support kernel releases to maximize longevity (assuming that regular OS

Re: [openssl-users] End of the line for the OpenSSL FIPS Object Module?

2015-02-27 Thread Steve Marquess
the platform validation costs. The hard part has always been funding the initial new validation. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com

Re: [openssl-users] End of the line for the OpenSSL FIPS Object Module?

2015-02-27 Thread Steve Marquess
;DR crowd. Make it clearer may not be enough as I've already attempted and failed at that. Specific suggested edits perhaps? -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu

Re: [openssl-users] 1.0.2 FIPS help

2015-03-05 Thread Steve Marquess
as documented. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/pgp key: http://openssl.com/docs/0x6D1892F5.asc

Re: [openssl-users] FIPS methods and symlinks

2015-02-25 Thread Steve Marquess
On 02/24/2015 10:26 PM, Tom Francis wrote: ... Steve Marquess: Is the document (which IIRC, you published back before the first validation) on how/why the FIPS Object Module was coded still available somewhere? If so, that’d probably be a good starting point for people who post questions

[openssl-users] End of the line for the OpenSSL FIPS Object Module?

2015-02-25 Thread Steve Marquess
up. Feel free to contact me directly for specific suggestions or to coordinate with other stakeholders. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu

Re: [openssl-users] End of the line for the OpenSSL FIPS Object Module?

2015-02-26 Thread Steve Marquess
, and anomalies... -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/pgp key: http://openssl.com/docs/0x6D1892F5.asc

Re: [openssl-users] Blank pages in FIPS 2.0 user guide

2015-02-20 Thread Steve Marquess
unfortunately. At the moment any spare time I have available for FIPS issues is spent addressing yet another existential threat to the open source based validations. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b

Re: [openssl-users] FIPS Linux kernel documentation ?

2015-03-26 Thread Steve Marquess
On 03/26/2015 01:41 PM, Jakob Bohm wrote: On 26/03/2015 16:56, Steve Marquess wrote: On 03/26/2015 11:30 AM, John Foley wrote: We looked at this very briefly a couple of years ago. In theory, there may be a way to achieve the goal as a loadable kernel module (a.k.a. device driver). The idea

Re: [openssl-users] FIPS: Which DRBG ?

2015-03-24 Thread Steve Marquess
On 03/24/2015 01:27 PM, jonetsu wrote: From: Steve Marquess marqu...@openssl.com Date: 03/24/15 12:38 No, the OpenSSL FIPS module 2.0 code is no longer suitable (as of early 2014) for use as-is in doing copycat validations. Some non-trivial code hacks will be necessary. We'll do

Re: [openssl-users] FIPS Linux kernel documentation ?

2015-03-26 Thread Steve Marquess
On 03/25/2015 06:26 PM, jone...@teksavvy.com wrote: On Wed, 25 Mar 2015 17:03:04 -0400 Steve Marquess marqu...@openssl.com wrote: I wasn't aware the Linux kernel (the real one, not proprietary commercial derivatives) had a FIPS mode. Please enlighten me. It could very well

Re: [openssl-users] FIPS Linux kernel documentation ?

2015-03-26 Thread Steve Marquess
awkward fit in the Linux ecosystem. We'd still consider tackling that, with financial sponsorship, but we have no prospects for such. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu

Re: [openssl-users] FIPS mode restrictions and DES

2015-04-14 Thread Steve Marquess
there, most of those operating systems are neither CC certified nor have any other FIPS 140-2 validated crypto. Keep in mind that at Level 1 the validation applies to the cryptographic module, not the calling application that uses that module nor the operating system that runs it. -Steve M. -- Steve

Re: [openssl-users] FIPS 140-2 on iOS

2015-04-28 Thread Steve Marquess
I'm only discussing Level 1 validations here; Levels 2 and up are different. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/pgp key

Re: [openssl-users] FIPS mode restrictions and DES

2015-04-13 Thread Steve Marquess
. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/pgp key: http://openssl.com/docs/0x6D1892F5.asc

Re: [openssl-users] FIPS mode restrictions and DES

2015-04-14 Thread Steve Marquess
On 04/14/2015 09:42 AM, jonetsu wrote: From: Steve Marquess marqu...@openssl.com Date: 04/14/15 09:31 and note that of the 101 platforms (OEs) appearing there, most of those operating systems are neither CC certified nor have any other FIPS 140-2 validated crypto. Keep in mind

Re: [openssl-users] Is there any plan for FIPS to be supported on Linux-aarch64?

2015-04-06 Thread Steve Marquess
/review the existing code. The code itself is open source, so as Obi-Wan said, use the source, Luke. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu

Re: [openssl-users] Is there any plan for FIPS to be supported on Linux-aarch64?

2015-04-06 Thread Steve Marquess
on Linux-aarch64? When we have a sponsor to cover the non-trivial costs of a platform validation. We're working on some iOS and Android ARMv8 platforms, but have nothing planned for Linux on ARMv8. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown

Re: [openssl-users] Is there any plan for FIPS to be supported on Linux-aarch64?

2015-04-06 Thread Steve Marquess
. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/pgp key: http://openssl.com/docs/0x6D1892F5.asc

[openssl-users] Call for FIPS 140-2 stakeholders

2015-06-22 Thread Steve Marquess
are a such a stakeholder and would like to participate in those discussions please let me know (contact info below) and I'll make the appropriate introductions. -Steve M. [*] see http://openssl.com/fips/aftermath.html -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road

[openssl-users] Provisional FIPS 140-2 casualty list

2015-06-18 Thread Steve Marquess
expect to receive permission from at least some of the directly impacted platform sponsors to supply information for revised platform descriptions. Once those are up, then you can panic. New developments will be noted in this new web page. -Steve M. -- Steve Marquess OpenSSL Software Foundation

Re: [openssl-users] Provisional FIPS 140-2 casualty list

2015-06-22 Thread Steve Marquess
of the challenge of completing any validation action with any kind of predictable budget or schedule. The imposition of retroactive changes on previously approved validations is a disturbing new development. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA

[openssl-users] FIPS 140-2 hostages executed

2015-06-16 Thread Steve Marquess
the latter. Instead they were forced to choose between preserving their platforms and adding new platforms, which led us down the ransom path and months of delay... -Steve M. [*] See http://openssl.com/fips/hostage.html, http://openssl.com/fips/ransom.html -- Steve Marquess OpenSSL Software

Re: [openssl-users] New FIPS 140-2 SE Validation Approved

2015-06-30 Thread Steve Marquess
that the OpenSSL FIPS module already has a Level 1 validation can help. But, FIPS 140-2 is a tricky business so you should consult with your accredited FIPS 140-2 test lab for advice specific to your unique circumstances. -Steve M. -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road

[openssl-users] New FIPS 140-2 SE Validation Approved

2015-06-26 Thread Steve Marquess
://openssl.com/fips/hostage.html [***] http://openssl.com/fips/aftermath.html -- Steve Marquess OpenSSL Software Foundation, Inc. 1829 Mount Ephraim Road Adamstown, MD 21710 USA +1 877 673 6775 s/b +1 301 874 2571 direct marqu...@opensslfoundation.com marqu...@openssl.com gpg/pgp key: http

<    1   2   3   4   5   >