Re: How to test a build of the FIPS provider

Igor Ustinov <[email protected]> Thu, 22 Jan 2026 08:10:15 +0100
Newsgroups gmane.comp.encryption.openssl.user
Message-ID <CACdz_dF0SDhu5N5myAQ-LcdBG9pe5FSfpp9n7XO4vj6OD6EPow@mail.gmail.com>
There are two OpenSSL directories: the build directory where you build
OpenSSL, and the install directory where OpenSSL will be installed if you
call
make install.
Viktor and I describe two different approaches: Viktor prefers to link an
application directly with the library in the build directory, and I prefer
to install OpenSSL first and then link an application with the installed
library. You can choose one of these approaches that you like more.
If you choose Viktor's way, follow his instructions.
If you choose my way, set the install directory by Configure with parameters
--prefix=$MYPATH --libdir=lib --openssldir=$MYPATH -Wl,-rpath,$MYPATH/lib
(change $MYPATH to the desired install directory path or set MYPATH
variables in advance),
build and install OpenSSL,
link your application with the installed library by using parameters
-L$MYPATH/lib -Wl,-rpath=$MYPATH/lib -lcrypto


On Thu, 22 Jan 2026 at 00:16, Ken Goldman <kgoldman-r/[email protected]> wrote:

> When I do a build (configure, make), there is no
> /home/openssl/lib.
>
> The top level /home/openssl has libcrypto.so.
>
> The fips library is in /home/openssl/providers/fips.so
> but I don't know how to link to it.
>
>
>
> On 1/21/2026 2:23 AM, Igor Ustinov wrote:
> > The linker options should be
> > -L/home/openssl/lib -Wl,-rpath=/home/openssl/lib -lcrypto
> > (providing /home/openssl is the correct path).
> >
> > On Tue, 20 Jan 2026 at 23:26, Ken Goldman <kgoldman-r/[email protected]
> > <mailto:kgoldman-r/[email protected]>> wrote:
> >
> >     Could you describe "its API".
> >
> >     I build in /home/openssl.
> >
> >     I set these to point there:
> >
> >     LD_LIBRARY_PATH
> >     LIBRARY_PATH
> >     CPATH
> >     PATH
> >
> >     I set the linker to:
> >
> >     -L/home/openssl -Wl,-rpath,. -lcrypto
> >
> >     These all fail:
> >
> >           fips = OSSL_PROVIDER_load(NULL, "fips");
> >           sha256 = EVP_MD_fetch(NULL, "SHA2-256", "fips=yes");
> >           sha256 = EVP_MD_fetch(NULL, "SHA2-256", "provider=fips");
> >
> >
> >     On 1/20/2026 4:22 PM, Igor Ustinov wrote:
> >      > It is not expected that an application will be linked with a
> >     provider
> >      > directly; instead, link your application with libcrypto and use
> the
> >      > provider via its API.
> >      >
> >      > On Tue, 20 Jan 2026 at 20:30, Ken Goldman <kgoldman wrote:
> >      >
> >      >     I know I can install there, but how does my C application and
> >     makefile
> >      >     point to it.
> >      >
> >      >     E.g., the fips provider is fips.so, not libfips.so, so I
> >     cannot simply
> >      >     link with -lfips.
> >      >
> >      >     On 1/20/2026 3:09 AM, Igor Ustinov wrote:
> >      >      > You can build OpenSSL to be installed in a separate
> >     directory, e.g.
> >      >      > $HOME/openssl, by calling Configure with parameters --
> >     prefix=$HOME/
> >      >      > openssl --libdir=lib --openssldir=$HOME/openssl -Wl,-
> >     rpath,$HOME/
> >      >     openssl/lib
> >      >      >
> >      >      > On Tue, 20 Jan 2026 at 00:49, Ken Goldman <kgoldman wrote:
> >      >      >
> >      >      >     Fedora 42, x86 - I built openssl 3.6.1 with enable-
> >     fips and
> >      >     got fips.so
> >      >      >
> >      >      >     I'd like to test it locally, as non-root, but not
> >     install it
> >      >     in the
> >      >      >     system area. Are there instructions for this?
> >      >      >
> >      >      >     I want to test the EVP API, not TLS or the command
> line.
> >      >      >
> >      >
> >
>
>
>
> --
> You received this message because you are subscribed to the Google Groups
> "openssl-users" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org
> To view this discussion visit
> https://groups.google.com/a/openssl.org/d/msgid/openssl-users/10krmnf%24ano%241%40ciao.gmane.io
> .
>


-- 
*Igor Ustinov*
Senior Software Engineer, OpenSSL Foundation
<http://openssl-foundation.org/>

Join the Code Protectors <https://openssl-foundation.org/donate/corporate/>
| Support us on Github Sponsors <https://github.com/sponsors/openssl>

-- 
You received this message because you are subscribed to the Google Groups "openssl-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org
To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/CACdz_dF0SDhu5N5myAQ-LcdBG9pe5FSfpp9n7XO4vj6OD6EPow%40mail.gmail.com.