Re: [External] Migration from 1.1.1 to 3.x

"'Alicja Kario' via openssl-users" <[email protected]>
Newsgroups gmane.comp.encryption.openssl.user
Organization Red Hat
Message-ID <[email protected]>
For the FIPS module in RHEL to be working in approved configuration, the 
whole
system needs to be switched to FIPS mode. When that is done, the OpenSSL in
RHEL will automatically load the fips.so provider and change the default
properties to use it automatically.

As long as the application doesn't override the default property query, it
will end up using FIPS certified implementations then.

On Monday, 2 June 2025 16:59:10 CEST, Mody, Darshan Arvindkumar (Darshan) 
wrote:
>  
> We are doing this in RHEL 9.4. My understanding is RHEL itself 
> will be providing the FIPS module
>  
> Thanks and Regards
> Darshan
>  
> From: The Doctor <doctor-Skx+k2Pw7SMBTvEkyID1hvd9D2ou9A/[email protected]> 
> Sent: Monday, June 2, 2025 5:35 PM
> To: Mody, Darshan Arvindkumar (Darshan) <darshanmody-gc/[email protected]>
> Cc: [email protected]
> Subject: [External]Re: Migration from 1.1.1 to 3.x
>  
> [External Sender]
> On Mon, Jun 02, 2025 at 04: 28: 33AM +0000, Mody, Darshan 
> Arvindkumar (Darshan) wrote: > Hi > > We are migrating from 
> 1. 1. 1 to 3. x openssl. We also need to support FIPs cipher and 
> FIPs mode. > > My question is do we need to use
> On Mon, Jun 02, 2025 at 04:28:33AM +0000, Mody, Darshan 
> Arvindkumar (Darshan) wrote:
>> Hi
>> 
>> We are migrating from 1.1.1 to 3.x openssl. We also need to 
>> support FIPs cipher and FIPs mode.
>> 
>> My question is do we need to use the API the 
>> OSSL_PROVIDER_load. If we directly 
>> EVP_default_properties_enable_fips what are the implications.
>> 
>> Thanks and Regards
>> Darshan
>> 
>  
> On which OS are you doing this?
>  
>> 
>> -- 
>> You received this message because you are subscribed to the 
>> Google Groups "openssl-users" group.
>> To unsubscribe from this group and stop receiving emails from 
>> it, send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org
>> To view this discussion visit 
>> https://urldefense.com/v3/__https://groups.google.com/a/openssl.org/d/msgid/openssl-users/PH0PR15MB4526934B9B0CE1696B7785EEA762A*40PH0PR15MB4526.namprd15.prod.outlook.com__;JQ!!AlswS5g!ntNgs951OKbap3z9-touK-MwKye3Tsw4AyMFSblOBnoz7sRx95tVSLnReJv4R5lhbtvZP7FHQiohv6HDwkPCwUIJ$.
>  

-- 
Regards,
Alicja Kario
Principal Quality Engineer, RHEL Crypto team
Web: www.cz.redhat.com
Red Hat Czech s.r.o., Purkyňova 115, 612 00, Brno, Czech Republic

-- 
You received this message because you are subscribed to the Google Groups "openssl-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org
To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/e21eb026-ff79-4d13-b2b4-400228b85088%40redhat.com.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.