RE: [External] Migration from 1.1.1 to 3.x

"Mody, Darshan Arvindkumar (Darshan)" <darshanmody-gc/[email protected]>
Newsgroups gmane.comp.encryption.openssl.user
Message-ID <PH0PR15MB45265D9781697A514C21B353A76FA@PH0PR15MB4526.namprd15.prod.outlook.com>
Thanks for the response.

With RHEL do we need to make additional changes to the openssl.cnf file?

Thanks and Regards
Darshan

From: Alicja Kario <[email protected]>
Sent: Wednesday, June 4, 2025 6:53 PM
To: Mody, Darshan Arvindkumar (Darshan) <darshanmody-gc/[email protected]>
Cc: [email protected]
Subject: Re: [External] Migration from 1.1.1 to 3.x

For the FIPS module in RHEL to be working in approved configuration, the whole system needs to be switched to FIPS mode. When that is done, the OpenSSL in RHEL will automatically load the fips. so provider and change the default properties to


For the FIPS module in RHEL to be working in approved configuration, the

whole

system needs to be switched to FIPS mode. When that is done, the OpenSSL in

RHEL will automatically load the fips.so provider and change the default

properties to use it automatically.



As long as the application doesn't override the default property query, it

will end up using FIPS certified implementations then.



On Monday, 2 June 2025 16:59:10 CEST, Mody, Darshan Arvindkumar (Darshan)

wrote:

>

> We are doing this in RHEL 9.4. My understanding is RHEL itself

> will be providing the FIPS module

>

> Thanks and Regards

> Darshan

>

> From: The Doctor <doctor-Skx+k2Pw7SMBTvEkyID1hvd9D2ou9A/[email protected]<mailto:[email protected]>>

> Sent: Monday, June 2, 2025 5:35 PM

> To: Mody, Darshan Arvindkumar (Darshan) <darshanmody-gc/[email protected]<mailto:darshanmody-gc/[email protected]>>

> Cc: [email protected]<mailto:[email protected]>

> Subject: [External]Re: Migration from 1.1.1 to 3.x

>

> [External Sender]

> On Mon, Jun 02, 2025 at 04: 28: 33AM +0000, Mody, Darshan

> Arvindkumar (Darshan) wrote: > Hi > > We are migrating from

> 1. 1. 1 to 3. x openssl. We also need to support FIPs cipher and

> FIPs mode. > > My question is do we need to use

> On Mon, Jun 02, 2025 at 04:28:33AM +0000, Mody, Darshan

> Arvindkumar (Darshan) wrote:

>> Hi

>>

>> We are migrating from 1.1.1 to 3.x openssl. We also need to

>> support FIPs cipher and FIPs mode.

>>

>> My question is do we need to use the API the

>> OSSL_PROVIDER_load. If we directly

>> EVP_default_properties_enable_fips what are the implications.

>>

>> Thanks and Regards

>> Darshan

>>

>

> On which OS are you doing this?

>

>>

>> --

>> You received this message because you are subscribed to the

>> Google Groups "openssl-users" group.

>> To unsubscribe from this group and stop receiving emails from

>> it, send an email to openssl-users+unsubscribe-MCmKBN63+BlAfugRpC6u6w@public.gmane.org<mailto:openssl-users+unsubscribe-MCmKBN63+BlAfugRpC6u6w@public.gmane.org>.

>> To view this discussion visit

>> https://urldefense.com/v3/__https://groups.google.com/a/openssl.org/d/msgid/openssl-users/PH0PR15MB4526934B9B0CE1696B7785EEA762A*40PH0PR15MB4526.namprd15.prod.outlook.com__;JQ!!AlswS5g!ntNgs951OKbap3z9-touK-MwKye3Tsw4AyMFSblOBnoz7sRx95tVSLnReJv4R5lhbtvZP7FHQiohv6HDwkPCwUIJ$.<https://urldefense.com/v3/__https:/groups.google.com/a/openssl.org/d/msgid/openssl-users/PH0PR15MB4526934B9B0CE1696B7785EEA762A*40PH0PR15MB4526.namprd15.prod.outlook.com__;JQ!!AlswS5g!ntNgs951OKbap3z9-touK-MwKye3Tsw4AyMFSblOBnoz7sRx95tVSLnReJv4R5lhbtvZP7FHQiohv6HDwkPCwUIJ$.%3e>

><https://urldefense.com/v3/__https:/groups.google.com/a/openssl.org/d/msgid/openssl-users/PH0PR15MB4526934B9B0CE1696B7785EEA762A*40PH0PR15MB4526.namprd15.prod.outlook.com__;JQ!!AlswS5g!ntNgs951OKbap3z9-touK-MwKye3Tsw4AyMFSblOBnoz7sRx95tVSLnReJv4R5lhbtvZP7FHQiohv6HDwkPCwUIJ$.%3e>



--

Regards,

Alicja Kario

Principal Quality Engineer, RHEL Crypto team

Web: https://urldefense.com/v3/__http://www.cz.redhat.com__;!!AlswS5g!kdJ2BxOlLPGQbX7Rdybd4rr-XoG38A-vaZgtgsGJOcE7bYHlRLQTOIkUwCkEyGBK9A-XwUbu6VRktHfl$<https://urldefense.com/v3/__http:/www.cz.redhat.com__;!!AlswS5g!kdJ2BxOlLPGQbX7Rdybd4rr-XoG38A-vaZgtgsGJOcE7bYHlRLQTOIkUwCkEyGBK9A-XwUbu6VRktHfl$>

Red Hat Czech s.r.o., Purkyňova 115, 612 00, Brno, Czech Republic


-- 
You received this message because you are subscribed to the Google Groups "openssl-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org
To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/PH0PR15MB45265D9781697A514C21B353A76FA%40PH0PR15MB4526.namprd15.prod.outlook.com.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.