Re: How to test a build of the FIPS provider

Viktor Dukhovni <[email protected]> Thu, 22 Jan 2026 20:23:39 +1100
Newsgroups gmane.comp.encryption.openssl.user
Message-ID <[email protected]>
On Thu, Jan 22, 2026 at 08:10:15AM +0100, Igor Ustinov wrote:

> There are two OpenSSL directories: the build directory where you build
> OpenSSL, and the install directory where OpenSSL will be installed if
> you call make install.
> Viktor and I describe two different approaches:

NO.  I'm answering Ken's question about how to test a candidate FIPS
provider with an existing application.  You've misunderstood his
question and are distracting his attention. :-(

> Viktor prefers to link an application directly with the library in the
> build directory,

No.  I am not suggesting ANY steps to compile a *new* application.  The
existing application linked against **ANY** OpenSSL 3.x version can be
tested with **ANY** version of the FIPS provider.  The instructions
explain how to install a FIPS provider into a suitable test directory
and test the application.  IF all goes well, later that FIPS provider
can be installed into a production "ossl-modules" directory used by
the live application.

> and I prefer to install OpenSSL first and then link an application
> with the installed library.

Which is a distraction.  Please STOP.

-- 
    Viktor.  🇺🇦 Слава Україні!

-- 
You received this message because you are subscribed to the Google Groups "openssl-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org
To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/aXHsmzOHI73oYNnT%40chardros.imrryr.org.