Re: Need to check on compatibility issue
"'Ladd, Watson' via openssl-users" <[email protected]>
| Newsgroups | gmane.comp.encryption.openssl.user |
|---|---|
| Message-ID | <DM6PR17MB397988C2D7C7384295FBD4C0C140A@DM6PR17MB3979.namprd17.prod.outlook.com> |
I do not understand how this works: * The fips provider is supposed to be self contained * The interface to the provider is supposed to be very forward and backward compatible so third parties can target it Is the issue that future fips.so may require additional calls from libcrypto to enable some things to work, in addition to the operations happening today? ________________________________ From: Neil Horman <[email protected]> Sent: Friday, June 27, 2025 6:11 AM To: omi jha <[email protected]> Cc: openssl-users <[email protected]> Subject: Re: Need to check on compatibility issue All of our openssl releases are backwards compatible with older fips providers, no issues are currently known. To be clear, the above means that libcrypto. so from openssl 3. 5 will work with the fips. so library from 3. 4 and earlier releases. ZjQcmQRYFpfptBannerStart This Message Is From an External Sender This message came from outside your organization. ZjQcmQRYFpfptBannerEnd All of our openssl releases are backwards compatible with older fips providers, no issues are currently known. To be clear, the above means that libcrypto.so from openssl 3.5 will work with the fips.so library from 3.4 and earlier releases. It does not imply any forward compatibility, i.e. the fips.so file from 3.5 is not guaranteed to work with the libcrypto.so library from 3.4 and earlier. Best Neil On Fri, Jun 27, 2025 at 7:00 AM omi jha <[email protected]<mailto:[email protected]>> wrote: Hi, Just wanted to check, Is openssl 3.5 (non-FIPS) compatible with FIPS 3.0.9 (FIPS 140-2) or any issues? Thanks, Om -- You received this message because you are subscribed to the Google Groups "openssl-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe-MCmKBN63+BlAfugRpC6u6w@public.gmane.org<mailto:openssl-users+unsubscribe-MCmKBN63+BlAfugRpC6u6w@public.gmane.org>. To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/ae62da4f-d165-4e7c-af92-718abb73e158n%40openssl.org<https://urldefense.com/v3/__https://groups.google.com/a/openssl.org/d/msgid/openssl-users/ae62da4f-d165-4e7c-af92-718abb73e158n*40openssl.org?utm_medium=email&utm_source=footer__;JQ!!GjvTz_vk!WdB8D2mt9mLrDfRFolHmCm2P1KHt42EWNwtFtv87I2MijWKu0JGvfvGvVOl4Wzjo1CZP9kpmXN4K8A$>. -- You received this message because you are subscribed to the Google Groups "openssl-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe-MCmKBN63+BlAfugRpC6u6w@public.gmane.org<mailto:openssl-users+unsubscribe-MCmKBN63+BlAfugRpC6u6w@public.gmane.org>. To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/CAJbOq17RByMrWOJ%3Dq%2BcHp5NH6HfxUNMXmwQLFf1_0KN-c-yBzg%40mail.gmail.com<https://urldefense.com/v3/__https://groups.google.com/a/openssl.org/d/msgid/openssl-users/CAJbOq17RByMrWOJ*3Dq*2BcHp5NH6HfxUNMXmwQLFf1_0KN-c-yBzg*40mail.gmail.com?utm_medium=email&utm_source=footer__;JSUl!!GjvTz_vk!WdB8D2mt9mLrDfRFolHmCm2P1KHt42EWNwtFtv87I2MijWKu0JGvfvGvVOl4Wzjo1CZP9kphGcPw6Q$>. -- You received this message because you are subscribed to the Google Groups "openssl-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/DM6PR17MB397988C2D7C7384295FBD4C0C140A%40DM6PR17MB3979.namprd17.prod.outlook.com.