Re: How to test a build of the FIPS provider
Ken Goldman <kgoldman-r/[email protected]> Mon, 26 Jan 2026 16:21:53 -0500
| Newsgroups | gmane.comp.encryption.openssl.user |
|---|---|
| Message-ID | <[email protected]> |
My requirement is to NOT install. I'm told that installing a new openssl on Linux can break applications. To summarize: - not as root - not installed in the system area - C EVP API, not command line On 1/22/2026 2:10 AM, Igor Ustinov wrote: > There are two OpenSSL directories: the build directory where you build > OpenSSL, and the install directory where OpenSSL will be installed if > you call > make install. > Viktor and I describe two different approaches: Viktor prefers to link > an application directly with the library in the build directory, and I > prefer to install OpenSSL first and then link an application with the > installed library. You can choose one of these approaches that you like > more. > If you choose Viktor's way, follow his instructions. > If you choose my way, set the install directory by Configure with parameters > --prefix=$MYPATH --libdir=lib --openssldir=$MYPATH -Wl,-rpath,$MYPATH/lib > (change $MYPATH to the desired install directory path or set MYPATH > variables in advance), > build and install OpenSSL, > link your application with the installed library by using parameters > -L$MYPATH/lib -Wl,-rpath=$MYPATH/lib -lcrypto > > > On Thu, 22 Jan 2026 at 00:16, Ken Goldman <kgoldman-r/ > [email protected] <mailto:kgoldman-r/ > [email protected]>> wrote: > > When I do a build (configure, make), there is no > /home/openssl/lib. > > The top level /home/openssl has libcrypto.so. > > The fips library is in /home/openssl/providers/fips.so > but I don't know how to link to it. > > > > On 1/21/2026 2:23 AM, Igor Ustinov wrote: > > The linker options should be > > -L/home/openssl/lib -Wl,-rpath=/home/openssl/lib -lcrypto > > (providing /home/openssl is the correct path). > > > > On Tue, 20 Jan 2026 at 23:26, Ken Goldman <kgoldman-r/ > [email protected] <mailto:kgoldman-r/ > [email protected]> > > <mailto:kgoldman-r/[email protected] > <mailto:kgoldman-r/[email protected]>>> wrote: > > > > Could you describe "its API". > > > > I build in /home/openssl. > > > > I set these to point there: > > > > LD_LIBRARY_PATH > > LIBRARY_PATH > > CPATH > > PATH > > > > I set the linker to: > > > > -L/home/openssl -Wl,-rpath,. -lcrypto > > > > These all fail: > > > > fips = OSSL_PROVIDER_load(NULL, "fips"); > > sha256 = EVP_MD_fetch(NULL, "SHA2-256", "fips=yes"); > > sha256 = EVP_MD_fetch(NULL, "SHA2-256", "provider=fips"); > > > > > > On 1/20/2026 4:22 PM, Igor Ustinov wrote: > > > It is not expected that an application will be linked with a > > provider > > > directly; instead, link your application with libcrypto > and use the > > > provider via its API. > > > > > > On Tue, 20 Jan 2026 at 20:30, Ken Goldman <kgoldman wrote: > > > > > > I know I can install there, but how does my C > application and > > makefile > > > point to it. > > > > > > E.g., the fips provider is fips.so, not libfips.so, so I > > cannot simply > > > link with -lfips. > > > > > > On 1/20/2026 3:09 AM, Igor Ustinov wrote: > > > > You can build OpenSSL to be installed in a separate > > directory, e.g. > > > > $HOME/openssl, by calling Configure with parameters -- > > prefix=$HOME/ > > > > openssl --libdir=lib --openssldir=$HOME/openssl -Wl,- > > rpath,$HOME/ > > > openssl/lib > > > > > > > > On Tue, 20 Jan 2026 at 00:49, Ken Goldman <kgoldman > wrote: > > > > > > > > Fedora 42, x86 - I built openssl 3.6.1 with enable- > > fips and > > > got fips.so > > > > > > > > I'd like to test it locally, as non-root, but not > > install it > > > in the > > > > system area. Are there instructions for this? > > > > > > > > I want to test the EVP API, not TLS or the > command line. > > > > > > > > > > -- You received this message because you are subscribed to the Google Groups "openssl-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/10l8lti%24lvr%241%40ciao.gmane.io.