OpenSSL and PQC/FIPS support

Raghu Chidambaram <[email protected]> Wed, 15 Apr 2026 06:43:17 -0700 (PDT)
Newsgroups gmane.comp.encryption.openssl.user
Message-ID <[email protected]>
------=_Part_44338_1342187503.1776260597324
Content-Type: multipart/alternative; 
	boundary="----=_Part_44339_228041768.1776260597324"

------=_Part_44339_228041768.1776260597324
Content-Type: text/plain; charset="UTF-8"

Hi Team,

Our organization is planning to go for PQC support so that application is 
quantum safe.
we are already FIPS 140-2 compliant and we are also in the process of 
making it FIPS 140-3 compliant as 140-2 will be sunset by Sep 2026.

FIPS
- Our application is FIPS 140-2 and with FIPS provider 3.0.9. We made this 
possible with the help of lot of to and fro discussions over the OpenSSL 
Forum for good amount of time :) :) .

For 140-3 we did analysis and understood that with OpenSSL version say 
3.5.x we need to bundle the FIPS provider version 3.1.2 ( 140-3 compliant ) 
instead of 3.0.9( 140-2) compliant. Hope this is correct.

PQC
- For PQC we just started analysis and checking which all algorithms we 
need to use in order to make it PQC compliant. As part of this we want to 
understand which of OpenSSL supports PQC and is there any doc / list which 
conveys like from algorithm A we need to move to algorithm, means how to 
migrate from current set to PQC safe set is what we are checking mainly. 

- one more point what we understood from the discussions internally and 
with the teams who are handling inside our organization that FIPS and PQC 
cant go hand in hand, like if we are in FIPS 140-3 version we cant claim 
for PQC as algo's are different and if we are going to be PQC safe then we 
can't claim FIPS 140-3 support, is this correct statement? or our 
assumption is wrong?

Need your help and inputs to proceed on these aspects 

Thank you,
Raghu

-- 
You received this message because you are subscribed to the Google Groups "openssl-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org
To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/9d605db8-9220-491c-9424-12b42ed92948n%40openssl.org.

------=_Part_44339_228041768.1776260597324
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Hi Team,<div><br /></div><div>Our organization is planning to go for PQC su=
pport so that application is quantum safe.</div><div>we are already FIPS 14=
0-2 compliant and we are also in the process of making it FIPS 140-3 compli=
ant as 140-2 will be sunset by Sep 2026.</div><div><br /></div><div>FIPS</d=
iv><div>- Our application is FIPS 140-2 and with FIPS provider 3.0.9. We ma=
de this possible with the help of lot of to and fro discussions over the Op=
enSSL Forum for good amount of time :) :) .</div><div><br /></div><div>For =
140-3 we did analysis and understood that with OpenSSL version say 3.5.x we=
 need to bundle the FIPS provider version 3.1.2 ( 140-3 compliant ) instead=
 of 3.0.9( 140-2) compliant. Hope this is correct.<br /><br />PQC</div><div=
>- For PQC we just started analysis and checking which all algorithms we ne=
ed to use in order to make it PQC compliant. As part of this we want to und=
erstand which of OpenSSL supports PQC and is there any doc / list which con=
veys like from algorithm A we need to move to algorithm, means how to migra=
te from current set to PQC safe set is what we are checking mainly.=C2=A0<b=
r /><br />- one more point what we understood from the discussions internal=
ly and with the teams who are handling inside our organization that FIPS an=
d PQC cant go hand in hand, like if we are in FIPS 140-3 version we cant cl=
aim for PQC as algo's are different and if we are going to be PQC safe then=
 we can't claim FIPS 140-3 support, is this correct statement? or our assum=
ption is wrong?</div><div><br /></div><div>Need your help and inputs to pro=
ceed on these aspects=C2=A0</div><div><br /></div><div>Thank you,</div><div=
>Raghu</div>

<p></p>

-- <br />
You received this message because you are subscribed to the Google Groups &=
quot;openssl-users&quot; group.<br />
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to <a href=3D"mailto:openssl-users+unsubscribe-MCmKBN63+BlAfugRpC6u6w@public.gmane.org">openssl-us=
[email protected]</a>.<br />
To view this discussion visit <a href=3D"https://groups.google.com/a/openss=
l.org/d/msgid/openssl-users/9d605db8-9220-491c-9424-12b42ed92948n%40openssl=
.org?utm_medium=3Demail&utm_source=3Dfooter">https://groups.google.com/a/op=
enssl.org/d/msgid/openssl-users/9d605db8-9220-491c-9424-12b42ed92948n%40ope=
nssl.org</a>.<br />

------=_Part_44339_228041768.1776260597324--

------=_Part_44338_1342187503.1776260597324--