RE: [EXTERNAL] Re: OpenSSL and PQC/FIPS support
"'Martin Bonner' via openssl-users" <[email protected]> Wed, 15 Apr 2026 14:12:32 +0000
| Newsgroups | gmane.comp.encryption.openssl.user |
|---|---|
| Message-ID | <PH3PPF7A88A980A2C6575139EACF6159C72F3222@PH3PPF7A88A980A.namprd11.prod.outlook.com> |
--_000_PH3PPF7A88A980A2C6575139EACF6159C72F3222PH3PPF7A88A980A_ Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable My reading of the original email is that Raghu=E2=80=99s organization achie= ved FIPS compliance by using the FIPS-approved OpenSSL provider. This is g= ood, because I would have said that it while it is touch-and-go whether Ope= nSSL 3.5.4 is going to be FIPS-approved before Sep 2026, it is very unlikel= y that a submission made today by Raghu=E2=80=99s organization would be app= roved by then. There is also a question of whether Raghu=E2=80=99s organization needs =E2= =80=9CFIPS approved=E2=80=9D, or whether =E2=80=9CFIPS pending=E2=80=9D is = good enough. It is almost inconceivable to me that 3.5.4 won=E2=80=99t be = eventually approved, it=E2=80=99s just a matter of bureaucracy. OTOH, if F= IPS approved is a contractual requirement (e.g. because the US Government i= s a customer), then until 3.5.4 is approved, FIPS and PQC are mutually excl= usive with OpenSSL (and FIPS is impossible between Sep 2026 and the approva= l of 3.5.4). On =E2=80=9CPQC equivalents for classical algorithms=E2=80=9D, don=E2=80=99= t forget that if you are using AES128 you need to switch to AES256 (but AES= 256 is already considered acceptable). Martin Bonner From: Neil Horman <[email protected]> Sent: 15 April 2026 14:53 To: Raghu Chidambaram <[email protected]> Cc: openssl-users <[email protected]> Subject: [EXTERNAL] Re: OpenSSL and PQC/FIPS support Raghu- PQC algorithms approved by FIPS include FIPS 203 (ML-KEM), FIPS 204 = (ML-DSA) and FIPS 205 (SLH-DSA). These are supported currently only by the = 3.=E2=80=8A5.=E2=80=8A4 FIPS provider and later versions. Currently 3.=E2= =80=8A5.=E2=80=8A4 is undergoing review with our lab and Raghu- PQC algorithms approved by FIPS include FIPS 203 (ML-KEM), FIPS 204 (M= L-DSA) and FIPS 205 (SLH-DSA). These are supported currently only by the 3= .5.4 FIPS provider and later versions. Currently 3.5.4 is undergoing revie= w with our lab and NIST: https://csrc.nist.gov/projects/cryptographic-module-validation-program/modu= les-in-process/modules-in-process-list<https://urldefense.com/v3/__https:/c= src.nist.gov/projects/cryptographic-module-validation-program/modules-in-pr= ocess/modules-in-process-list__;!!FJ-Y8qCqXTj2!bZut-uZon_VIGux_15WX7wQQlDCz= 2htlQH38Q5r93kD1FyyfFNGBYigp6MnOcctxqdvCUvGlZbPhhLscJuPv$> FIPS and PQC are definitely _not_ mutually exclusive, you can definitely us= e both PQC algorithms and be FIPS-140-3 compliant. The only current barrie= r is that our provider has not yet been certified by NIST. That need not b= e a barrier for you however, if you are planning on doing a full submission= of openssl through your own lab (though the time effort on that is constra= ined by your lab and NIST). Neil On Wed, Apr 15, 2026 at 9:43=E2=80=AFAM Raghu Chidambaram <pcraghu.prasad@g= mail.com<mailto:[email protected]>> wrote: Hi Team, Our organization is planning to go for PQC support so that application is q= uantum safe. we are already FIPS 140-2 compliant and we are also in the process of makin= g it FIPS 140-3 compliant as 140-2 will be sunset by Sep 2026. FIPS - Our application is FIPS 140-2 and with FIPS provider 3.0.9. We made this = possible with the help of lot of to and fro discussions over the OpenSSL Fo= rum for good amount of time :) :) . For 140-3 we did analysis and understood that with OpenSSL version say 3.5.= x we need to bundle the FIPS provider version 3.1.2 ( 140-3 compliant ) ins= tead of 3.0.9( 140-2) compliant. Hope this is correct. PQC - For PQC we just started analysis and checking which all algorithms we nee= d to use in order to make it PQC compliant. As part of this we want to unde= rstand which of OpenSSL supports PQC and is there any doc / list which conv= eys like from algorithm A we need to move to algorithm, means how to migrat= e from current set to PQC safe set is what we are checking mainly. - one more point what we understood from the discussions internally and wit= h the teams who are handling inside our organization that FIPS and PQC cant= go hand in hand, like if we are in FIPS 140-3 version we cant claim for PQ= C as algo's are different and if we are going to be PQC safe then we can't = claim FIPS 140-3 support, is this correct statement? or our assumption is w= rong? Need your help and inputs to proceed on these aspects Thank you, Raghu -- You received this message because you are subscribed to the Google Groups "= openssl-users" group. To unsubscribe from this group and stop receiving emails from it, send an e= mail to openssl-users+unsubscribe-MCmKBN63+BlAfugRpC6u6w@public.gmane.org<mailto:openssl-users+unsubscr= [email protected]>. To view this discussion visit https://groups.google.com/a/openssl.org/d/msg= id/openssl-users/9d605db8-9220-491c-9424-12b42ed92948n%40openssl.org<https:= //urldefense.com/v3/__https:/groups.google.com/a/openssl.org/d/msgid/openss= l-users/9d605db8-9220-491c-9424-12b42ed92948n*40openssl.org?utm_medium=3Dem= ail&utm_source=3Dfooter__;JQ!!FJ-Y8qCqXTj2!bZut-uZon_VIGux_15WX7wQQlDCz2htl= QH38Q5r93kD1FyyfFNGBYigp6MnOcctxqdvCUvGlZbPhhPVv707z$>. -- You received this message because you are subscribed to the Google Groups "= openssl-users" group. To unsubscribe from this group and stop receiving emails from it, send an e= mail to openssl-users+unsubscribe-MCmKBN63+BlAfugRpC6u6w@public.gmane.org<mailto:openssl-users+unsubscr= [email protected]>. To view this discussion visit https://groups.google.com/a/openssl.org/d/msg= id/openssl-users/CAJbOq16tR2n_U1tWtzbCUzt57PjEZQbiJRjvM-3vPQ3gkrGyXA%40mail= .gmail.com<https://urldefense.com/v3/__https:/groups.google.com/a/openssl.o= rg/d/msgid/openssl-users/CAJbOq16tR2n_U1tWtzbCUzt57PjEZQbiJRjvM-3vPQ3gkrGyX= A*40mail.gmail.com?utm_medium=3Demail&utm_source=3Dfooter__;JQ!!FJ-Y8qCqXTj= 2!bZut-uZon_VIGux_15WX7wQQlDCz2htlQH38Q5r93kD1FyyfFNGBYigp6MnOcctxqdvCUvGlZ= bPhhA0Qq6iv$>. Any email and files/attachments transmitted with it are intended solely for= the use of the individual or entity to whom they are addressed. If this me= ssage has been sent to you in error, you must not copy, distribute or discl= ose of the information it contains. Please notify Entrust immediately and d= elete the message from your system. --=20 You received this message because you are subscribed to the Google Groups "= openssl-users" group. To unsubscribe from this group and stop receiving emails from it, send an e= mail to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org To view this discussion visit https://groups.google.com/a/openssl.org/d/msg= id/openssl-users/PH3PPF7A88A980A2C6575139EACF6159C72F3222%40PH3PPF7A88A980A= .namprd11.prod.outlook.com. --_000_PH3PPF7A88A980A2C6575139EACF6159C72F3222PH3PPF7A88A980A_ Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr= osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" = xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:= //www.w3.org/TR/REC-html40"> <head> <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dutf-8"> <meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)"> <style><!-- /* Font Definitions */ @font-face {font-family:"Cambria Math"; panose-1:2 4 5 3 5 4 6 3 2 4;} @font-face {font-family:Calibri; panose-1:2 15 5 2 2 2 4 3 2 4;} @font-face {font-family:Aptos;} @font-face {font-family:"Arial Black"; panose-1:2 11 10 4 2 1 2 2 2 4;} @font-face {font-family:"Gotham Book";} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal {margin:0cm; font-size:12.0pt; font-family:"Aptos",sans-serif;} a:link, span.MsoHyperlink {mso-style-priority:99; color:blue; text-decoration:underline;} span.EmailStyle19 {mso-style-type:personal-reply; font-family:"Aptos",sans-serif; color:windowtext;} .MsoChpDefault {mso-style-type:export-only; mso-fareast-language:EN-US;} @page WordSection1 {size:612.0pt 792.0pt; margin:72.0pt 72.0pt 72.0pt 72.0pt;} div.WordSection1 {page:WordSection1;} --></style><!--[if gte mso 9]><xml> <o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" /> </xml><![endif]--><!--[if gte mso 9]><xml> <o:shapelayout v:ext=3D"edit"> <o:idmap v:ext=3D"edit" data=3D"1" /> </o:shapelayout></xml><![endif]--> </head> <body lang=3D"EN-GB" link=3D"blue" vlink=3D"purple" style=3D"word-wrap:brea= k-word"> <div class=3D"WordSection1"> <p class=3D"MsoNormal"><span style=3D"mso-fareast-language:EN-US">My readin= g of the original email is that Raghu=E2=80=99s organization achieved FIPS = compliance by using the FIPS-approved OpenSSL provider. This is good,= because I would have said that it while it is touch-and-go whether OpenSSL 3.5.4 is going to be FIPS-approved before Sep 2026, it is = very unlikely that a submission made today by Raghu=E2=80=99s organization = would be approved by then.<o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"mso-fareast-language:EN-US"><o:p>&nbs= p;</o:p></span></p> <p class=3D"MsoNormal"><span style=3D"mso-fareast-language:EN-US">There is = also a question of whether Raghu=E2=80=99s organization needs =E2=80=9CFIPS= approved=E2=80=9D, or whether =E2=80=9CFIPS pending=E2=80=9D is good enoug= h. It is almost inconceivable to me that 3.5.4 won=E2=80=99t be <i>eventually</i> approved, it=E2=80=99s just a matter of bureaucracy. = ; OTOH, if FIPS approved is a contractual requirement (e.g. because the US = Government is a customer), then until 3.5.4 is approved, FIPS and PQC are m= utually exclusive with OpenSSL (and FIPS is impossible between Sep 2026 and the approval of 3.5.4).<o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"mso-fareast-language:EN-US"><o:p>&nbs= p;</o:p></span></p> <p class=3D"MsoNormal"><span style=3D"mso-fareast-language:EN-US">On =E2=80= =9CPQC equivalents for classical algorithms=E2=80=9D, don=E2=80=99t forget = that if you are using AES128 you need to switch to AES256 (but AES256 is al= ready considered acceptable).<o:p></o:p></span></p> <p class=3D"MsoNormal"><span style=3D"mso-fareast-language:EN-US"><o:p>&nbs= p;</o:p></span></p> <table class=3D"MsoNormalTable" border=3D"0" cellspacing=3D"0" cellpadding= =3D"0" style=3D"border-collapse:collapse"> <tbody> <tr> <td width=3D"265" valign=3D"top" style=3D"width:198.8pt;padding:0cm 5.4pt 0= cm 5.4pt"> <p class=3D"MsoNormal" style=3D"margin-bottom:2.7pt;text-autospace:none"><s= pan lang=3D"EN-US" style=3D"font-size:14.0pt;font-family:"Arial Black&= quot;,sans-serif;color:#6F2176">Martin Bonner</span><span lang=3D"EN-US" st= yle=3D"font-size:14.0pt;font-family:"Gotham Book";color:#6F2176;m= so-fareast-language:EN-US"><o:p></o:p></span></p> </td> </tr> </tbody> </table> <p class=3D"MsoNormal"><span style=3D"font-size:11.0pt"><o:p> </o:p></= span></p> <p class=3D"MsoNormal"><span style=3D"mso-fareast-language:EN-US"><o:p>&nbs= p;</o:p></span></p> <div style=3D"border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0cm = 0cm 0cm"> <p class=3D"MsoNormal"><b><span lang=3D"EN-US" style=3D"font-size:11.0pt;fo= nt-family:"Calibri",sans-serif">From:</span></b><span lang=3D"EN-= US" style=3D"font-size:11.0pt;font-family:"Calibri",sans-serif"> = Neil Horman <[email protected]> <br> <b>Sent:</b> 15 April 2026 14:53<br> <b>To:</b> Raghu Chidambaram <[email protected]><br> <b>Cc:</b> openssl-users <[email protected]><br> <b>Subject:</b> [EXTERNAL] Re: OpenSSL and PQC/FIPS support<o:p></o:p></spa= n></p> </div> <p class=3D"MsoNormal"><o:p> </o:p></p> <div> <p class=3D"MsoNormal" style=3D"mso-line-height-alt:.75pt"><span style=3D"f= ont-size:1.0pt;color:white">Raghu- PQC algorithms approved by FIPS include = FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA). These are supp= orted currently only by the 3.</span><span style=3D"font-size:1.0pt;font-fa= mily:"Arial",sans-serif;color:white">=E2=80=8A</span><span style= =3D"font-size:1.0pt;color:white">5.</span><span style=3D"font-size:1.0pt;fo= nt-family:"Arial",sans-serif;color:white">=E2=80=8A</span><span s= tyle=3D"font-size:1.0pt;color:white">4 FIPS provider and later versions. Currently 3.</span><span style=3D"font-s= ize:1.0pt;font-family:"Arial",sans-serif;color:white">=E2=80=8A</= span><span style=3D"font-size:1.0pt;color:white">5.</span><span style=3D"fo= nt-size:1.0pt;font-family:"Arial",sans-serif;color:white">=E2=80= =8A</span><span style=3D"font-size:1.0pt;color:white">4 is undergoing review with our lab and<o:p></o:p></span></p> </div> <div> <p class=3D"MsoNormal" style=3D"mso-line-height-alt:.75pt"><span style=3D"f= ont-size:1.0pt;color:white"><o:p></o:p></span></p> </div> <div> <p class=3D"MsoNormal">Raghu-<o:p></o:p></p> <div> <p class=3D"MsoNormal"> PQC algorithms approved by FIPS = include FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA). = These are supported currently only by the 3.5.4 FIPS provider and later ver= sions. Currently 3.5.4 is undergoing review with our lab and NIST:<o:p></o:p></p> </div> <div> <p class=3D"MsoNormal"><a href=3D"https://urldefense.com/v3/__https:/csrc.n= ist.gov/projects/cryptographic-module-validation-program/modules-in-process= /modules-in-process-list__;!!FJ-Y8qCqXTj2!bZut-uZon_VIGux_15WX7wQQlDCz2htlQ= H38Q5r93kD1FyyfFNGBYigp6MnOcctxqdvCUvGlZbPhhLscJuPv$">https://csrc.nist.gov= /projects/cryptographic-module-validation-program/modules-in-process/module= s-in-process-list</a><o:p></o:p></p> </div> <div> <p class=3D"MsoNormal"><o:p> </o:p></p> </div> <div> <p class=3D"MsoNormal"><o:p> </o:p></p> </div> <div> <p class=3D"MsoNormal">FIPS and PQC are definitely _not_ mutually excl= usive, you can definitely use both PQC algorithms and be FIPS-140-3 co= mpliant. The only current barrier is that our provider has not yet be= en certified by NIST. That need not be a barrier for you however, if you are planning on doing a full submission of openssl= through your own lab (though the time effort on that is constrained by you= r lab and NIST).<o:p></o:p></p> </div> <div> <p class=3D"MsoNormal"><o:p> </o:p></p> </div> <div> <p class=3D"MsoNormal">Neil<o:p></o:p></p> </div> <div> <p class=3D"MsoNormal"><o:p> </o:p></p> </div> </div> <p class=3D"MsoNormal"><o:p> </o:p></p> <div> <div> <p class=3D"MsoNormal">On Wed, Apr 15, 2026 at 9:43<span style=3D"font-fami= ly:"Arial",sans-serif">=E2=80=AF</span>AM Raghu Chidambaram <<= a href=3D"mailto:[email protected]">[email protected]</a>>= wrote:<o:p></o:p></p> </div> <blockquote style=3D"border:none;border-left:solid #CCCCCC 1.0pt;padding:0c= m 0cm 0cm 6.0pt;margin-left:4.8pt;margin-right:0cm"> <p class=3D"MsoNormal">Hi Team,<o:p></o:p></p> <div> <p class=3D"MsoNormal"><o:p> </o:p></p> </div> <div> <p class=3D"MsoNormal">Our organization is planning to go for PQC support s= o that application is quantum safe.<o:p></o:p></p> </div> <div> <p class=3D"MsoNormal">we are already FIPS 140-2 compliant and we are also = in the process of making it FIPS 140-3 compliant as 140-2 will be sunset by= Sep 2026.<o:p></o:p></p> </div> <div> <p class=3D"MsoNormal"><o:p> </o:p></p> </div> <div> <p class=3D"MsoNormal">FIPS<o:p></o:p></p> </div> <div> <p class=3D"MsoNormal">- Our application is FIPS 140-2 and with FIPS provid= er 3.0.9. We made this possible with the help of lot of to and fro discussi= ons over the OpenSSL Forum for good amount of time :) :) .<o:p></o:p></p> </div> <div> <p class=3D"MsoNormal"><o:p> </o:p></p> </div> <div> <p class=3D"MsoNormal">For 140-3 we did analysis and understood that with O= penSSL version say 3.5.x we need to bundle the FIPS provider version 3.1.2 = ( 140-3 compliant ) instead of 3.0.9( 140-2) compliant. Hope this is correc= t.<br> <br> PQC<o:p></o:p></p> </div> <div> <p class=3D"MsoNormal">- For PQC we just started analysis and checking whic= h all algorithms we need to use in order to make it PQC compliant. As part = of this we want to understand which of OpenSSL supports PQC and is there an= y doc / list which conveys like from algorithm A we need to move to algorithm, means how to migrate from curren= t set to PQC safe set is what we are checking mainly. <br> <br> - one more point what we understood from the discussions internally and wit= h the teams who are handling inside our organization that FIPS and PQC cant= go hand in hand, like if we are in FIPS 140-3 version we cant claim for PQ= C as algo's are different and if we are going to be PQC safe then we can't claim FIPS 140-3 support, is thi= s correct statement? or our assumption is wrong?<o:p></o:p></p> </div> <div> <p class=3D"MsoNormal"><o:p> </o:p></p> </div> <div> <p class=3D"MsoNormal">Need your help and inputs to proceed on these aspect= s <o:p></o:p></p> </div> <div> <p class=3D"MsoNormal"><o:p> </o:p></p> </div> <div> <p class=3D"MsoNormal">Thank you,<o:p></o:p></p> </div> <div> <p class=3D"MsoNormal">Raghu<o:p></o:p></p> </div> <p class=3D"MsoNormal">-- <br> You received this message because you are subscribed to the Google Groups &= quot;openssl-users" group.<br> To unsubscribe from this group and stop receiving emails from it, send an e= mail to <a href=3D"mailto:openssl-users+unsubscribe-MCmKBN63+BlAfugRpC6u6w@public.gmane.org" target=3D"_blank">= openssl-users+unsubscribe-MCmKBN63+BlAfugRpC6u6w@public.gmane.org</a>.<br> To view this discussion visit <a href=3D"https://urldefense.com/v3/__https:= /groups.google.com/a/openssl.org/d/msgid/openssl-users/9d605db8-9220-491c-9= 424-12b42ed92948n*40openssl.org?utm_medium=3Demail&utm_source=3Dfooter_= _;JQ!!FJ-Y8qCqXTj2!bZut-uZon_VIGux_15WX7wQQlDCz2htlQH38Q5r93kD1FyyfFNGBYigp= 6MnOcctxqdvCUvGlZbPhhPVv707z$" target=3D"_blank"> https://groups.google.com/a/openssl.org/d/msgid/openssl-users/9d605db8-9220= -491c-9424-12b42ed92948n%40openssl.org</a>.<o:p></o:p></p> </blockquote> </div> <p class=3D"MsoNormal">-- <br> You received this message because you are subscribed to the Google Groups &= quot;openssl-users" group.<br> To unsubscribe from this group and stop receiving emails from it, send an e= mail to <a href=3D"mailto:openssl-users+unsubscribe-MCmKBN63+BlAfugRpC6u6w@public.gmane.org">openssl-users+unsu= [email protected]</a>.<br> To view this discussion visit <a href=3D"https://urldefense.com/v3/__https:= /groups.google.com/a/openssl.org/d/msgid/openssl-users/CAJbOq16tR2n_U1tWtzb= CUzt57PjEZQbiJRjvM-3vPQ3gkrGyXA*40mail.gmail.com?utm_medium=3Demail&utm= _source=3Dfooter__;JQ!!FJ-Y8qCqXTj2!bZut-uZon_VIGux_15WX7wQQlDCz2htlQH38Q5r= 93kD1FyyfFNGBYigp6MnOcctxqdvCUvGlZbPhhA0Qq6iv$"> https://groups.google.com/a/openssl.org/d/msgid/openssl-users/CAJbOq16tR2n_= U1tWtzbCUzt57PjEZQbiJRjvM-3vPQ3gkrGyXA%40mail.gmail.com</a>.<o:p></o:p></p> </div> <i>Any email and files/attachments transmitted with it are intended solely = for the use of the individual or entity to whom they are addressed. If this= message has been sent to you in error, you must not copy, distribute or di= sclose of the information it contains. <u>Please notify Entrust immediately and delete the message from your syste= m.</u></i><br> <br> </body> </html> <p></p> -- <br /> You received this message because you are subscribed to the Google Groups &= quot;openssl-users" group.<br /> To unsubscribe from this group and stop receiving emails from it, send an e= mail to <a href=3D"mailto:openssl-users+unsubscribe-MCmKBN63+BlAfugRpC6u6w@public.gmane.org">openssl-us= [email protected]</a>.<br /> To view this discussion visit <a href=3D"https://groups.google.com/a/openss= l.org/d/msgid/openssl-users/PH3PPF7A88A980A2C6575139EACF6159C72F3222%40PH3P= PF7A88A980A.namprd11.prod.outlook.com?utm_medium=3Demail&utm_source=3Dfoote= r">https://groups.google.com/a/openssl.org/d/msgid/openssl-users/PH3PPF7A88= A980A2C6575139EACF6159C72F3222%40PH3PPF7A88A980A.namprd11.prod.outlook.com<= /a>.<br /> --_000_PH3PPF7A88A980A2C6575139EACF6159C72F3222PH3PPF7A88A980A_--