Re: [External]Re: Migration from 1.1.1 to 3.x
Tomas Mraz <[email protected]>
| Newsgroups | gmane.comp.encryption.openssl.user |
|---|---|
| Message-ID | <[email protected]> |
Please read this manual page. It should explain how loading the fips provider and changing the default properties to enforce the fips property relate. https://docs.openssl.org/master/man7/fips_module/ Tomas Mraz, Public Support and Security Manager, OpenSSL Foundation On Mon, 2025-06-02 at 08:34 +0000, Mody, Darshan Arvindkumar (Darshan) wrote: > > > > Thanks for the response. > > However the original question remains unanswered. Can you help me > understand whether we need to use both OSSL_PROVIDER_load(NULL, > "fips"); EVP_default_properties_enable_fips > > If we directly use the EVP_default_properties_enable_fips will FIPS > be enabled. > > Warm Regards > Darshan > > > > > > > From: [email protected] <[email protected]>On Behalf > Of Viktor Dukhovni > Sent: Monday, June 2, 2025 12:04 PM > To: [email protected] > Subject: [External]Re: Migration from 1.1.1 to 3.x > > [External Sender] > > > > > On Mon, Jun 02, 2025 at 11: 36: 49AM +0530, madhu bajpai wrote: > > Need an additional clarification on: > > OSSL_PROVIDER_load(NULL, > "fips"); EVP_set_default_properties(NULL, > "fips=yes"); > > Are > above two functions adequate > > On Mon, Jun 02, 2025 at 11:36:49AM +0530, madhu bajpai wrote: > > > Need an additional clarification on: > > > > OSSL_PROVIDER_load(NULL, "fips"); EVP_set_default_properties(NULL, > > "fips=yes"); > > > > Are above two functions adequate for FIPS compliance or if we need > > additional changes? Like APIs to explicitly mention "fips=yes” e.g. > > EVP_MD_fetch(NULL, "SHA2-256", "fips=yes"); > > > > Is there any reference checklist to ensure FIPS compliance? > > > > We have recently built FIPS module for iOS and since we had to > > generate the install-mac at runtime, had to enable default provider > > via openssl.cnf. Should be disable it for any accidental fallback? > > Quoting README-FIPS.md: > > > https://urldefense.com/v3/__https://github.com/openssl/openssl/blob/master/README-FIPS.md__;!!AlswS5g!no6ebcGfxc24lR6R5lGYBcLb2L_ChCmr0m982N3boorZyXVwUIG5A2y84KEU_T35nWkGHZjOXcNtA-4A423krqF-tY_u$ > > If you need a FIPS validated module then you must ONLY generate a > FIPS provider using OpenSSL versions that have valid FIPS > certificates. A FIPS certificate contains a link to a Security > Policy, and you MUST follow the instructions in the Security > Policy > in order to be FIPS compliant. > > The security policy for the 3.0 module: > > > https://urldefense.com/v3/__https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/4282__;!!AlswS5g!no6ebcGfxc24lR6R5lGYBcLb2L_ChCmr0m982N3boorZyXVwUIG5A2y84KEU_T35nWkGHZjOXcNtA-4A423krqowM9Dt$ > > Can be found in: > > > https://urldefense.com/v3/__https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/security-policies/140sp4282.pdf__;!!AlswS5g!no6ebcGfxc24lR6R5lGYBcLb2L_ChCmr0m982N3boorZyXVwUIG5A2y84KEU_T35nWkGHZjOXcNtA-4A423kriFjBppw$ > > You may want to consider the 3.1 (FIPS 140-3)module: > > > https://urldefense.com/v3/__https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/4985__;!!AlswS5g!no6ebcGfxc24lR6R5lGYBcLb2L_ChCmr0m982N3boorZyXVwUIG5A2y84KEU_T35nWkGHZjOXcNtA-4A423krii6ajZ3$ > > > https://urldefense.com/v3/__https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/security-policies/140sp4985.pdf__;!!AlswS5g!no6ebcGfxc24lR6R5lGYBcLb2L_ChCmr0m982N3boorZyXVwUIG5A2y84KEU_T35nWkGHZjOXcNtA-4A423krk6u71mj$ > > Any informal answers you get on this list are unauthoritative and > should > nto be used as a basis for deciding whether your deployment is > FIPS-compliant. > > -- > Viktor. > > -- > You received this message because you are subscribed to the Google > Groups "openssl-users" group. > To unsubscribe from this group and stop receiving emails from it, > send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org > To view this discussion visit > https://urldefense.com/v3/__https://groups.google.com/a/openssl.org/d/msgid/openssl-users/aD1F1h-Ay_nGkxkP*40chardros.imrryr.org__;JQ!!AlswS5g!no6ebcGfxc24lR6R5lGYBcLb2L_ChCmr0m982N3boorZyXVwUIG5A2y84KEU_T35nWkGHZjOXcNtA-4A423krrEI69F7$ > . > -- > You received this message because you are subscribed to the Google > Groups "openssl-users" group. > To unsubscribe from this group and stop receiving emails from it, > send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org > To view this discussion visit > https://groups.google.com/a/openssl.org/d/msgid/openssl-users/PH0PR15MB45266050072403C60BA026C3A762A%40PH0PR15MB4526.namprd15.prod.outlook.com > . -- Tomáš Mráz, Public Support and Security Manager, OpenSSL Foundation Join the Code Protectors or support us on Github Sponsors https://openssl-foundation.org/donate/ -- You received this message because you are subscribed to the Google Groups "openssl-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/eea0e7c20fff9abcc9609cb86607e4822cee74b1.camel%40openssl.org.