RE: [External] Migration from 1.1.1 to 3.x
"Mody, Darshan Arvindkumar (Darshan)" <darshanmody-gc/[email protected]>
| Newsgroups | gmane.comp.encryption.openssl.user |
|---|---|
| Message-ID | <PH0PR15MB45265D9781697A514C21B353A76FA@PH0PR15MB4526.namprd15.prod.outlook.com> |
Thanks for the response. With RHEL do we need to make additional changes to the openssl.cnf file? Thanks and Regards Darshan From: Alicja Kario <[email protected]> Sent: Wednesday, June 4, 2025 6:53 PM To: Mody, Darshan Arvindkumar (Darshan) <darshanmody-gc/[email protected]> Cc: [email protected] Subject: Re: [External] Migration from 1.1.1 to 3.x For the FIPS module in RHEL to be working in approved configuration, the whole system needs to be switched to FIPS mode. When that is done, the OpenSSL in RHEL will automatically load the fips. so provider and change the default properties to For the FIPS module in RHEL to be working in approved configuration, the whole system needs to be switched to FIPS mode. When that is done, the OpenSSL in RHEL will automatically load the fips.so provider and change the default properties to use it automatically. As long as the application doesn't override the default property query, it will end up using FIPS certified implementations then. On Monday, 2 June 2025 16:59:10 CEST, Mody, Darshan Arvindkumar (Darshan) wrote: > > We are doing this in RHEL 9.4. My understanding is RHEL itself > will be providing the FIPS module > > Thanks and Regards > Darshan > > From: The Doctor <doctor-Skx+k2Pw7SMBTvEkyID1hvd9D2ou9A/[email protected]<mailto:[email protected]>> > Sent: Monday, June 2, 2025 5:35 PM > To: Mody, Darshan Arvindkumar (Darshan) <darshanmody-gc/[email protected]<mailto:darshanmody-gc/[email protected]>> > Cc: [email protected]<mailto:[email protected]> > Subject: [External]Re: Migration from 1.1.1 to 3.x > > [External Sender] > On Mon, Jun 02, 2025 at 04: 28: 33AM +0000, Mody, Darshan > Arvindkumar (Darshan) wrote: > Hi > > We are migrating from > 1. 1. 1 to 3. x openssl. We also need to support FIPs cipher and > FIPs mode. > > My question is do we need to use > On Mon, Jun 02, 2025 at 04:28:33AM +0000, Mody, Darshan > Arvindkumar (Darshan) wrote: >> Hi >> >> We are migrating from 1.1.1 to 3.x openssl. We also need to >> support FIPs cipher and FIPs mode. >> >> My question is do we need to use the API the >> OSSL_PROVIDER_load. If we directly >> EVP_default_properties_enable_fips what are the implications. >> >> Thanks and Regards >> Darshan >> > > On which OS are you doing this? > >> >> -- >> You received this message because you are subscribed to the >> Google Groups "openssl-users" group. >> To unsubscribe from this group and stop receiving emails from >> it, send an email to openssl-users+unsubscribe-MCmKBN63+BlAfugRpC6u6w@public.gmane.org<mailto:openssl-users+unsubscribe-MCmKBN63+BlAfugRpC6u6w@public.gmane.org>. >> To view this discussion visit >> https://urldefense.com/v3/__https://groups.google.com/a/openssl.org/d/msgid/openssl-users/PH0PR15MB4526934B9B0CE1696B7785EEA762A*40PH0PR15MB4526.namprd15.prod.outlook.com__;JQ!!AlswS5g!ntNgs951OKbap3z9-touK-MwKye3Tsw4AyMFSblOBnoz7sRx95tVSLnReJv4R5lhbtvZP7FHQiohv6HDwkPCwUIJ$.<https://urldefense.com/v3/__https:/groups.google.com/a/openssl.org/d/msgid/openssl-users/PH0PR15MB4526934B9B0CE1696B7785EEA762A*40PH0PR15MB4526.namprd15.prod.outlook.com__;JQ!!AlswS5g!ntNgs951OKbap3z9-touK-MwKye3Tsw4AyMFSblOBnoz7sRx95tVSLnReJv4R5lhbtvZP7FHQiohv6HDwkPCwUIJ$.%3e> ><https://urldefense.com/v3/__https:/groups.google.com/a/openssl.org/d/msgid/openssl-users/PH0PR15MB4526934B9B0CE1696B7785EEA762A*40PH0PR15MB4526.namprd15.prod.outlook.com__;JQ!!AlswS5g!ntNgs951OKbap3z9-touK-MwKye3Tsw4AyMFSblOBnoz7sRx95tVSLnReJv4R5lhbtvZP7FHQiohv6HDwkPCwUIJ$.%3e> -- Regards, Alicja Kario Principal Quality Engineer, RHEL Crypto team Web: https://urldefense.com/v3/__http://www.cz.redhat.com__;!!AlswS5g!kdJ2BxOlLPGQbX7Rdybd4rr-XoG38A-vaZgtgsGJOcE7bYHlRLQTOIkUwCkEyGBK9A-XwUbu6VRktHfl$<https://urldefense.com/v3/__http:/www.cz.redhat.com__;!!AlswS5g!kdJ2BxOlLPGQbX7Rdybd4rr-XoG38A-vaZgtgsGJOcE7bYHlRLQTOIkUwCkEyGBK9A-XwUbu6VRktHfl$> Red Hat Czech s.r.o., Purkyňova 115, 612 00, Brno, Czech Republic -- You received this message because you are subscribed to the Google Groups "openssl-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/PH0PR15MB45265D9781697A514C21B353A76FA%40PH0PR15MB4526.namprd15.prod.outlook.com.