-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Mark,

On 2/13/12 4:45 PM, Mark Lim wrote:
> Thanks for offering, but we're already in certification.  When 
> recertification comes up we'll certainly consider consolidating
> security modules.

Okay. Well, if you're willing to put our code into testing, it would
give us some good data points. We essentially applied a
heavily-modified set of patches from a contributor who was using an
old version and kind of hacked it together.

I cleaned it up and committed it to Tomcat and tcnative, but I don't
have a good environment in which to test it: all I can verify is that
OpenSSL appears to have gone into FIPS mode and didn't complain. If
you have a battery of tests you could run against it, it would be very
helpful just to validate the work done thus far.

Alternatively, if you have some kind of test suite that could be used,
I wouldn't mind performing the actual testing myself.

Thanks,
- -chris
-----BEGIN PGP SIGNATURE-----
Version: GnuPG/MacGPG2 v2.0.17 (Darwin)
Comment: GPGTools - http://gpgtools.org
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iEYEARECAAYFAk85h08ACgkQ9CaO5/Lv0PDLZACeLn6fY2TGzuflkK5wtgEzau8D
ybkAoIHxmYzgGAtXUna9NGc41yK3P9ow
=7b+d
-----END PGP SIGNATURE-----

---------------------------------------------------------------------
To unsubscribe, e-mail: users-unsubscr...@tomcat.apache.org
For additional commands, e-mail: users-h...@tomcat.apache.org

Reply via email to