OpenSSL and PQC/FIPS support
Raghu Chidambaram <[email protected]> Wed, 15 Apr 2026 06:43:17 -0700 (PDT)
| Newsgroups | gmane.comp.encryption.openssl.user |
|---|---|
| Message-ID | <[email protected]> |
------=_Part_44338_1342187503.1776260597324 Content-Type: multipart/alternative; boundary="----=_Part_44339_228041768.1776260597324" ------=_Part_44339_228041768.1776260597324 Content-Type: text/plain; charset="UTF-8" Hi Team, Our organization is planning to go for PQC support so that application is quantum safe. we are already FIPS 140-2 compliant and we are also in the process of making it FIPS 140-3 compliant as 140-2 will be sunset by Sep 2026. FIPS - Our application is FIPS 140-2 and with FIPS provider 3.0.9. We made this possible with the help of lot of to and fro discussions over the OpenSSL Forum for good amount of time :) :) . For 140-3 we did analysis and understood that with OpenSSL version say 3.5.x we need to bundle the FIPS provider version 3.1.2 ( 140-3 compliant ) instead of 3.0.9( 140-2) compliant. Hope this is correct. PQC - For PQC we just started analysis and checking which all algorithms we need to use in order to make it PQC compliant. As part of this we want to understand which of OpenSSL supports PQC and is there any doc / list which conveys like from algorithm A we need to move to algorithm, means how to migrate from current set to PQC safe set is what we are checking mainly. - one more point what we understood from the discussions internally and with the teams who are handling inside our organization that FIPS and PQC cant go hand in hand, like if we are in FIPS 140-3 version we cant claim for PQC as algo's are different and if we are going to be PQC safe then we can't claim FIPS 140-3 support, is this correct statement? or our assumption is wrong? Need your help and inputs to proceed on these aspects Thank you, Raghu -- You received this message because you are subscribed to the Google Groups "openssl-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/9d605db8-9220-491c-9424-12b42ed92948n%40openssl.org. ------=_Part_44339_228041768.1776260597324 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Hi Team,<div><br /></div><div>Our organization is planning to go for PQC su= pport so that application is quantum safe.</div><div>we are already FIPS 14= 0-2 compliant and we are also in the process of making it FIPS 140-3 compli= ant as 140-2 will be sunset by Sep 2026.</div><div><br /></div><div>FIPS</d= iv><div>- Our application is FIPS 140-2 and with FIPS provider 3.0.9. We ma= de this possible with the help of lot of to and fro discussions over the Op= enSSL Forum for good amount of time :) :) .</div><div><br /></div><div>For = 140-3 we did analysis and understood that with OpenSSL version say 3.5.x we= need to bundle the FIPS provider version 3.1.2 ( 140-3 compliant ) instead= of 3.0.9( 140-2) compliant. Hope this is correct.<br /><br />PQC</div><div= >- For PQC we just started analysis and checking which all algorithms we ne= ed to use in order to make it PQC compliant. As part of this we want to und= erstand which of OpenSSL supports PQC and is there any doc / list which con= veys like from algorithm A we need to move to algorithm, means how to migra= te from current set to PQC safe set is what we are checking mainly.=C2=A0<b= r /><br />- one more point what we understood from the discussions internal= ly and with the teams who are handling inside our organization that FIPS an= d PQC cant go hand in hand, like if we are in FIPS 140-3 version we cant cl= aim for PQC as algo's are different and if we are going to be PQC safe then= we can't claim FIPS 140-3 support, is this correct statement? or our assum= ption is wrong?</div><div><br /></div><div>Need your help and inputs to pro= ceed on these aspects=C2=A0</div><div><br /></div><div>Thank you,</div><div= >Raghu</div> <p></p> -- <br /> You received this message because you are subscribed to the Google Groups &= quot;openssl-users" group.<br /> To unsubscribe from this group and stop receiving emails from it, send an e= mail to <a href=3D"mailto:openssl-users+unsubscribe-MCmKBN63+BlAfugRpC6u6w@public.gmane.org">openssl-us= [email protected]</a>.<br /> To view this discussion visit <a href=3D"https://groups.google.com/a/openss= l.org/d/msgid/openssl-users/9d605db8-9220-491c-9424-12b42ed92948n%40openssl= .org?utm_medium=3Demail&utm_source=3Dfooter">https://groups.google.com/a/op= enssl.org/d/msgid/openssl-users/9d605db8-9220-491c-9424-12b42ed92948n%40ope= nssl.org</a>.<br /> ------=_Part_44339_228041768.1776260597324-- ------=_Part_44338_1342187503.1776260597324--