Re: [EXTERNAL] Re: OpenSSL and PQC/FIPS support
Raghu Chidambaram <[email protected]> Wed, 15 Apr 2026 23:11:57 -0700 (PDT)
| Newsgroups | gmane.comp.encryption.openssl.user |
|---|---|
| Message-ID | <[email protected]> |
------=_Part_83900_927435634.1776319917688 Content-Type: multipart/alternative; boundary="----=_Part_83901_981260663.1776319917688" ------=_Part_83901_981260663.1776319917688 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable HI Team, GM, In https://csrc.nist.gov/projects/cryptographic-module-validation-program/m= odules-in-process/modules-in-process-list OpenSSL FIPS Provider The OpenSSL Corporation =20 <https://csrc.nist.gov/projects/cryptographic-module-validation-program/mod= ules-in-process/modules-in-process-list#d13323> - OpenSSL Corporation - [email protected] - Voice: 877-673-6775 FIPS 140-3 Pending Review (11/25/2025) For the above OpenSSL FIPS validation is in progress, that means here with= =20 OpenSSL 3.5.4 which contains the PQC related algorithms. so once this get the approval then all the PQC algorithms which are part of= =20 this OpenSSL will be FIPS 140-3 compliant and as i mentioned earlier then= =20 we can=20 take this OpenSSL 3.5.4 FIPS provider and bundle in our application to=20 claim both PQC and FIPS compliant ? please correct me if our understanding is wrong Thanks, Raghu On Wednesday, 15 April 2026 at 22:12:06 UTC+5:30 Raghu Chidambaram wrote: > Thanks Martin Bonner and Neil, > Thanks for the information. > > then until 3.5.4 is approved, FIPS and PQC are mutually exclusive with= =20 > OpenSSL (and FIPS is impossible between Sep 2026 and the approval of 3.5.= 4). > - [Raghu] so both are mutually exclusive if i understood correctly. > > These are supported currently only by the 3.5.4 FIPS provider and later= =20 > versions. Currently 3.5.4 is undergoing review with our lab and NIST: > -[Raghu] I have little confusion here, when we are talkin about the=20 > OpenSSL version 3.5.4 is undergoing review means the FIPS provider ( fips= =20 > modules) inside that 3.5.4 version which also contains the SSL and Crypto= =20 > libraries am i correct. Just like OpenSSL 3.0.9 got FIPS 140-2 , OpenSSL= =20 > 3.1.2 version got FIPS 140-3 , similarly OpenSSL 3.5.4 is going for CMVP= =20 > validation and it will be 140-3 compliant or some other FIPS compliant? > > PQC algorithms approved by FIPS include FIPS 203 (ML-KEM), FIPS 204=20 > (ML-DSA) and FIPS 205 (SLH-DSA) > -[Raghu] only above 3 algorithms are FIPS approved as of today? is that= =20 > correct statement. > > FIPS and PQC are definitely _not_ mutually exclusive, you can=20 > definitely use both PQC algorithms and be FIPS-140-3 compliant. > - [Raghu] we have release our application to all the products/customer in= =20 > Dell saying that we are FIPS compliant, i m part of Dell Organization=20 > previously we were using OpenSSL 1.0.2 FIPS version which was supported b= y=20 > OpenSSL team for few years later we moved to OpenSSL 3.0.x and now we are= =20 > at OpenSSL 3.5.5 version in our application. > so we cant use few algorithms which are PQC and few which are FIPS 140-3= =20 > and claim for both? is that correct? we want to claim FIPS 140-3 as of no= w=20 > which is in progress and if we move to PQC safe algorithms ( somehow not= =20 > sure as of now) then we cant claim for FIPS 140-3 right? > > Thanks, > Raghu > > On Wednesday, 15 April 2026 at 19:42:45 UTC+5:30 Martin Bonner wrote: > >> My reading of the original email is that Raghu=E2=80=99s organization ac= hieved=20 >> FIPS compliance by using the FIPS-approved OpenSSL provider. This is go= od,=20 >> because I would have said that it while it is touch-and-go whether OpenS= SL=20 >> 3.5.4 is going to be FIPS-approved before Sep 2026, it is very unlikely= =20 >> that a submission made today by Raghu=E2=80=99s organization would be ap= proved by=20 >> then. >> >> =20 >> >> There is also a question of whether Raghu=E2=80=99s organization needs = =E2=80=9CFIPS=20 >> approved=E2=80=9D, or whether =E2=80=9CFIPS pending=E2=80=9D is good eno= ugh. It is almost=20 >> inconceivable to me that 3.5.4 won=E2=80=99t be *eventually* approved, i= t=E2=80=99s just=20 >> a matter of bureaucracy. OTOH, if FIPS approved is a contractual=20 >> requirement (e.g. because the US Government is a customer), then until= =20 >> 3.5.4 is approved, FIPS and PQC are mutually exclusive with OpenSSL (and= =20 >> FIPS is impossible between Sep 2026 and the approval of 3.5.4). >> >> =20 >> >> On =E2=80=9CPQC equivalents for classical algorithms=E2=80=9D, don=E2=80= =99t forget that if you=20 >> are using AES128 you need to switch to AES256 (but AES256 is already=20 >> considered acceptable). >> >> =20 >> >> Martin Bonner >> >> =20 >> >> =20 >> >> *From:* Neil Horman <[email protected]>=20 >> *Sent:* 15 April 2026 14:53 >> *To:* Raghu Chidambaram <[email protected]> >> *Cc:* openssl-users <[email protected]> >> *Subject:* [EXTERNAL] Re: OpenSSL and PQC/FIPS support >> >> =20 >> >> Raghu- PQC algorithms approved by FIPS include FIPS 203 (ML-KEM), FIPS= =20 >> 204 (ML-DSA) and FIPS 205 (SLH-DSA). These are supported currently only = by=20 >> the 3.=E2=80=8A5.=E2=80=8A4 FIPS provider and later versions. Currently = 3.=E2=80=8A5.=E2=80=8A4 is=20 >> undergoing review with our lab and >> >> Raghu- >> >> PQC algorithms approved by FIPS include FIPS 203 (ML-KEM), FIPS 204= =20 >> (ML-DSA) and FIPS 205 (SLH-DSA). These are supported currently only by = the=20 >> 3.5.4 FIPS provider and later versions. Currently 3.5.4 is undergoing= =20 >> review with our lab and NIST: >> >> >> https://csrc.nist.gov/projects/cryptographic-module-validation-program/m= odules-in-process/modules-in-process-list=20 >> <https://urldefense.com/v3/__https:/csrc.nist.gov/projects/cryptographic= -module-validation-program/modules-in-process/modules-in-process-list__;!!F= J-Y8qCqXTj2!bZut-uZon_VIGux_15WX7wQQlDCz2htlQH38Q5r93kD1FyyfFNGBYigp6MnOcct= xqdvCUvGlZbPhhLscJuPv$> >> >> =20 >> >> =20 >> >> FIPS and PQC are definitely _not_ mutually exclusive, you can=20 >> definitely use both PQC algorithms and be FIPS-140-3 compliant. The onl= y=20 >> current barrier is that our provider has not yet been certified by NIST.= =20 >> That need not be a barrier for you however, if you are planning on doing= a=20 >> full submission of openssl through your own lab (though the time effort = on=20 >> that is constrained by your lab and NIST). >> >> =20 >> >> Neil >> >> =20 >> >> =20 >> >> On Wed, Apr 15, 2026 at 9:43=E2=80=AFAM Raghu Chidambaram <pcraghu...@gm= ail.com>=20 >> wrote: >> >> Hi Team, >> >> =20 >> >> Our organization is planning to go for PQC support so that application i= s=20 >> quantum safe. >> >> we are already FIPS 140-2 compliant and we are also in the process of=20 >> making it FIPS 140-3 compliant as 140-2 will be sunset by Sep 2026. >> >> =20 >> >> FIPS >> >> - Our application is FIPS 140-2 and with FIPS provider 3.0.9. We made=20 >> this possible with the help of lot of to and fro discussions over the=20 >> OpenSSL Forum for good amount of time :) :) . >> >> =20 >> >> For 140-3 we did analysis and understood that with OpenSSL version say= =20 >> 3.5.x we need to bundle the FIPS provider version 3.1.2 ( 140-3 complian= t )=20 >> instead of 3.0.9( 140-2) compliant. Hope this is correct. >> >> PQC >> >> - For PQC we just started analysis and checking which all algorithms we= =20 >> need to use in order to make it PQC compliant. As part of this we want t= o=20 >> understand which of OpenSSL supports PQC and is there any doc / list whi= ch=20 >> conveys like from algorithm A we need to move to algorithm, means how to= =20 >> migrate from current set to PQC safe set is what we are checking mainly.= =20 >> >> - one more point what we understood from the discussions internally and= =20 >> with the teams who are handling inside our organization that FIPS and PQ= C=20 >> cant go hand in hand, like if we are in FIPS 140-3 version we cant claim= =20 >> for PQC as algo's are different and if we are going to be PQC safe then = we=20 >> can't claim FIPS 140-3 support, is this correct statement? or our=20 >> assumption is wrong? >> >> =20 >> >> Need your help and inputs to proceed on these aspects=20 >> >> =20 >> >> Thank you, >> >> Raghu >> >> --=20 >> You received this message because you are subscribed to the Google Group= s=20 >> "openssl-users" group. >> To unsubscribe from this group and stop receiving emails from it, send a= n=20 >> email to [email protected] >> To view this discussion visit=20 >> https://groups.google.com/a/openssl.org/d/msgid/openssl-users/9d605db8-9= 220-491c-9424-12b42ed92948n%40openssl.org=20 >> <https://urldefense.com/v3/__https:/groups.google.com/a/openssl.org/d/ms= gid/openssl-users/9d605db8-9220-491c-9424-12b42ed92948n*40openssl.org?utm_m= edium=3Demail&utm_source=3Dfooter__;JQ!!FJ-Y8qCqXTj2!bZut-uZon_VIGux_15WX7w= QQlDCz2htlQH38Q5r93kD1FyyfFNGBYigp6MnOcctxqdvCUvGlZbPhhPVv707z$> >> . >> >> --=20 >> You received this message because you are subscribed to the Google Group= s=20 >> "openssl-users" group. >> To unsubscribe from this group and stop receiving emails from it, send a= n=20 >> email to [email protected] >> >> To view this discussion visit=20 >> https://groups.google.com/a/openssl.org/d/msgid/openssl-users/CAJbOq16tR= 2n_U1tWtzbCUzt57PjEZQbiJRjvM-3vPQ3gkrGyXA%40mail.gmail.com=20 >> <https://urldefense.com/v3/__https:/groups.google.com/a/openssl.org/d/ms= gid/openssl-users/CAJbOq16tR2n_U1tWtzbCUzt57PjEZQbiJRjvM-3vPQ3gkrGyXA*40mai= l.gmail.com?utm_medium=3Demail&utm_source=3Dfooter__;JQ!!FJ-Y8qCqXTj2!bZut-= uZon_VIGux_15WX7wQQlDCz2htlQH38Q5r93kD1FyyfFNGBYigp6MnOcctxqdvCUvGlZbPhhA0Q= q6iv$> >> . >> *Any email and files/attachments transmitted with it are intended solely= =20 >> for the use of the individual or entity to whom they are addressed. If t= his=20 >> message has been sent to you in error, you must not copy, distribute or= =20 >> disclose of the information it contains. Please notify Entrust immediate= ly=20 >> and delete the message from your system.* >> >> --=20 You received this message because you are subscribed to the Google Groups "= openssl-users" group. To unsubscribe from this group and stop receiving emails from it, send an e= mail to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org To view this discussion visit https://groups.google.com/a/openssl.org/d/msg= id/openssl-users/6502df5e-c419-4895-b3ee-c9bf7dd37a7bn%40openssl.org. ------=_Part_83901_981260663.1776319917688 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable HI Team,<div><br /></div><div>GM,</div><div><br /></div><div>In=C2=A0https:= //csrc.nist.gov/projects/cryptographic-module-validation-program/modules-in= -process/modules-in-process-list</div><div><br /></div><div><span style=3D"= box-sizing: inherit; border-collapse: collapse; border-spacing: 0px; width:= 1340px; max-width: 100%; margin-bottom: 24px; border: 1px solid rgb(221, 2= 21, 221); color: rgb(27, 27, 27); font-family: "Source Sans Pro",= Helvetica, Arial, sans-serif; font-size: 16px;"><span style=3D"box-sizing:= inherit;"><span style=3D"box-sizing: inherit;"><span style=3D"box-sizing: = inherit; padding: 5px; line-height: 1.5; vertical-align: top; border: 1px s= olid rgb(221, 221, 221); font-size: 1rem;"><br />OpenSSL FIPS Provider</spa= n><span style=3D"box-sizing: inherit; padding: 5px; line-height: 1.5; verti= cal-align: top; border: 1px solid rgb(221, 221, 221); font-size: 1rem;"><br= />The OpenSSL Corporation=C2=A0<a role=3D"button" href=3D"https://csrc.nis= t.gov/projects/cryptographic-module-validation-program/modules-in-process/m= odules-in-process-list#d13323" aria-expanded=3D"true" style=3D"box-sizing: = inherit; background-color: transparent; color: rgb(17, 75, 115); text-decor= ation: underline; cursor: pointer; display: inline-block; margin-bottom: 0p= x; text-align: center; white-space: nowrap; vertical-align: middle; touch-a= ction: manipulation; background-image: none; border: 1px solid transparent;= padding: 6px 12px; line-height: 0.7em; border-radius: 0px; user-select: no= ne; box-shadow: none;"></a><div aria-expanded=3D"true" style=3D"box-sizing:= inherit;"><ul style=3D"box-sizing: inherit; margin-top: 0px; margin-bottom= : 12px; padding-left: 0px; list-style: none;"><li style=3D"box-sizing: inhe= rit;">OpenSSL Corporation</li><li style=3D"box-sizing: inherit;">corporatio= [email protected]</li><li style=3D"box-sizing: inherit;">Voice: 877-673-6775</l= i></ul></div></span><span style=3D"box-sizing: inherit; padding: 5px; line-= height: 1.5; vertical-align: top; border: 1px solid rgb(221, 221, 221); fon= t-size: 1rem;"><br />FIPS 140-3</span><span style=3D"box-sizing: inherit; p= adding: 5px; white-space: nowrap; line-height: 1.5; vertical-align: top; bo= rder: 1px solid rgb(221, 221, 221); font-size: 1rem;"><br />Pending Review = (11/25/2025)</span></span></span></span></div><div><font color=3D"#1b1b1b" = face=3D"Source Sans Pro, Helvetica, Arial, sans-serif"><span style=3D"font-= size: 16px; text-wrap-mode: nowrap;"><br /></span></font></div><div><font c= olor=3D"#1b1b1b" face=3D"Source Sans Pro, Helvetica, Arial, sans-serif"><sp= an style=3D"font-size: 16px; text-wrap-mode: nowrap;">For the above OpenSSL= FIPS validation is in progress, that means here with OpenSSL 3.5.4 which c= ontains the PQC related algorithms.</span></font></div><div><font color=3D"= #1b1b1b" face=3D"Source Sans Pro, Helvetica, Arial, sans-serif"><span style= =3D"font-size: 16px; text-wrap-mode: nowrap;">so once this get the approval= then all the PQC algorithms which are part of this OpenSSL will be FIPS 14= 0-3 compliant and as i mentioned earlier then we can=C2=A0</span></font></d= iv><div><font color=3D"#1b1b1b" face=3D"Source Sans Pro, Helvetica, Arial, = sans-serif"><span style=3D"font-size: 16px; text-wrap-mode: nowrap;">take t= his OpenSSL 3.5.4 FIPS provider and bundle in our application to claim both= PQC and FIPS compliant ?</span></font></div><div><font color=3D"#1b1b1b" f= ace=3D"Source Sans Pro, Helvetica, Arial, sans-serif"><span style=3D"font-s= ize: 16px; text-wrap-mode: nowrap;"><br /></span></font></div><div><font co= lor=3D"#1b1b1b" face=3D"Source Sans Pro, Helvetica, Arial, sans-serif"><spa= n style=3D"font-size: 16px; text-wrap-mode: nowrap;">please correct me if o= ur understanding is wrong</span></font></div><div><font color=3D"#1b1b1b" f= ace=3D"Source Sans Pro, Helvetica, Arial, sans-serif"><span style=3D"font-s= ize: 16px; text-wrap-mode: nowrap;"><br /></span></font></div><div><font co= lor=3D"#1b1b1b" face=3D"Source Sans Pro, Helvetica, Arial, sans-serif"><spa= n style=3D"font-size: 16px; text-wrap-mode: nowrap;">Thanks,</span></font><= /div><div><font color=3D"#1b1b1b" face=3D"Source Sans Pro, Helvetica, Arial= , sans-serif"><span style=3D"font-size: 16px; text-wrap-mode: nowrap;">Ragh= u<br /></span></font><br /></div><div class=3D"gmail_quote"><div dir=3D"aut= o" class=3D"gmail_attr">On Wednesday, 15 April 2026 at 22:12:06 UTC+5:30 Ra= ghu Chidambaram wrote:<br/></div><blockquote class=3D"gmail_quote" style=3D= "margin: 0 0 0 0.8ex; border-left: 1px solid rgb(204, 204, 204); padding-le= ft: 1ex;">Thanks Martin Bonner and Neil,<div>Thanks for the information.</d= iv><div><br></div><div>=C2=A0then until 3.5.4 is approved, FIPS and PQC are= mutually exclusive with OpenSSL (and FIPS is impossible between Sep 2026 a= nd the approval of 3.5.4).</div><div>- [Raghu] so both are mutually exclusi= ve if i understood correctly.</div><div><br></div><div>These are supported = currently only by the 3.5.4 FIPS provider and later versions.=C2=A0 Current= ly 3.5.4 is undergoing review with our lab and NIST:</div><div>-[Raghu] I h= ave little confusion here, when we are talkin about the OpenSSL version 3.5= .4 is undergoing review means the FIPS provider ( fips modules) inside that= 3.5.4 version which also contains the SSL and Crypto libraries am i correc= t. Just like OpenSSL 3.0.9 got FIPS 140-2 , OpenSSL 3.1.2 version got FIPS = 140-3 , similarly OpenSSL 3.5.4 is going for CMVP validation and it will be= 140-3 compliant or some other FIPS compliant?</div><div><br></div><div>PQC= algorithms approved by FIPS include FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) a= nd FIPS 205 (SLH-DSA)</div><div>-[Raghu] only above 3 algorithms are FIPS a= pproved as of today? is that correct statement.</div><div><br></div><div>FI= PS and PQC are definitely=C2=A0_not_ mutually exclusive, you can definitely= =C2=A0use both PQC algorithms and be FIPS-140-3 compliant.</div><div>- [Rag= hu] we have release our application to all the products/customer in Dell sa= ying that we are FIPS compliant, i m part of Dell Organization previously w= e were using OpenSSL 1.0.2 FIPS version which was supported by OpenSSL team= for few years later we moved to OpenSSL 3.0.x and now we are at OpenSSL 3.= 5.5 version in our application.</div><div>so we cant use few algorithms whi= ch are PQC and few which are FIPS 140-3 and claim for both? is that correct= ? we want to claim FIPS 140-3 as of now which is in progress and if we move= to PQC safe algorithms ( somehow not sure as of now) then we cant claim fo= r FIPS 140-3 right?</div><div><br></div><div>Thanks,</div><div>Raghu<br><di= v><br></div></div><div class=3D"gmail_quote"><div dir=3D"auto" class=3D"gma= il_attr">On Wednesday, 15 April 2026 at 19:42:45 UTC+5:30 Martin Bonner wro= te:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 0.8ex;= border-left:1px solid rgb(204,204,204);padding-left:1ex"> <div lang=3D"EN-GB" link=3D"blue" vlink=3D"purple" style=3D"word-wrap:break= -word"> <div> <p class=3D"MsoNormal"><span>My reading of the original email is that Raghu= =E2=80=99s organization achieved FIPS compliance by using the FIPS-approved= OpenSSL provider.=C2=A0 This is good, because I would have said that it wh= ile it is touch-and-go whether OpenSSL 3.5.4 is going to be FIPS-approved before Sep 2026, it is = very unlikely that a submission made today by Raghu=E2=80=99s organization = would be approved by then.<u></u><u></u></span></p> <p class=3D"MsoNormal"><span><u></u>=C2=A0<u></u></span></p> <p class=3D"MsoNormal"><span>There is also a question of whether Raghu=E2= =80=99s organization needs =E2=80=9CFIPS approved=E2=80=9D, or whether =E2= =80=9CFIPS pending=E2=80=9D is good enough.=C2=A0 It is almost inconceivabl= e to me that 3.5.4 won=E2=80=99t be <i>eventually</i> approved, it=E2=80=99s just a matter of bureaucracy.=C2= =A0 OTOH, if FIPS approved is a contractual requirement (e.g. because the U= S Government is a customer), then until 3.5.4 is approved, FIPS and PQC are= mutually exclusive with OpenSSL (and FIPS is impossible between Sep 2026 and the approval of 3.5.4).<u></u><u></u></span></p> <p class=3D"MsoNormal"><span><u></u>=C2=A0<u></u></span></p> <p class=3D"MsoNormal"><span>On =E2=80=9CPQC equivalents for classical algo= rithms=E2=80=9D, don=E2=80=99t forget that if you are using AES128 you need= to switch to AES256 (but AES256 is already considered acceptable).<u></u><= u></u></span></p> <p class=3D"MsoNormal"><span><u></u>=C2=A0<u></u></span></p> <table border=3D"0" cellspacing=3D"0" cellpadding=3D"0" style=3D"border-col= lapse:collapse"> <tbody> <tr> <td width=3D"265" valign=3D"top" style=3D"width:198.8pt;padding:0cm 5.4pt 0= cm 5.4pt"> <p class=3D"MsoNormal" style=3D"margin-bottom:2.7pt;text-autospace:none"><s= pan lang=3D"EN-US" style=3D"font-size:14.0pt;font-family:"Arial Black&= quot;,sans-serif;color:#6f2176">Martin Bonner</span><span lang=3D"EN-US" st= yle=3D"font-size:14.0pt;font-family:"Gotham Book";color:#6f2176">= <u></u><u></u></span></p> </td> </tr> </tbody> </table> <p class=3D"MsoNormal"><span style=3D"font-size:11.0pt"><u></u>=C2=A0<u></u= ></span></p> <p class=3D"MsoNormal"><span><u></u>=C2=A0<u></u></span></p> <div style=3D"border:none;border-top:solid #e1e1e1 1.0pt;padding:3.0pt 0cm = 0cm 0cm"> <p class=3D"MsoNormal"><b><span lang=3D"EN-US" style=3D"font-size:11.0pt;fo= nt-family:"Calibri",sans-serif">From:</span></b><span lang=3D"EN-= US" style=3D"font-size:11.0pt;font-family:"Calibri",sans-serif"> = Neil Horman <<a rel=3D"nofollow">[email protected]</a>> <br> <b>Sent:</b> 15 April 2026 14:53<br> <b>To:</b> Raghu Chidambaram <<a rel=3D"nofollow">[email protected]</= a>><br> <b>Cc:</b> openssl-users <<a rel=3D"nofollow">[email protected]</a>&= gt;<br> <b>Subject:</b> [EXTERNAL] Re: OpenSSL and PQC/FIPS support<u></u><u></u></= span></p> </div> <p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p> <div> <p class=3D"MsoNormal"><span style=3D"font-size:1.0pt;color:white">Raghu- P= QC algorithms approved by FIPS include FIPS 203 (ML-KEM), FIPS 204 (ML-DSA)= and FIPS 205 (SLH-DSA). These are supported currently only by the 3.</span= ><span style=3D"font-size:1.0pt;font-family:"Arial",sans-serif;co= lor:white">=E2=80=8A</span><span style=3D"font-size:1.0pt;color:white">5.</= span><span style=3D"font-size:1.0pt;font-family:"Arial",sans-seri= f;color:white">=E2=80=8A</span><span style=3D"font-size:1.0pt;color:white">= 4 FIPS provider and later versions. Currently 3.</span><span style=3D"font-s= ize:1.0pt;font-family:"Arial",sans-serif;color:white">=E2=80=8A</= span><span style=3D"font-size:1.0pt;color:white">5.</span><span style=3D"fo= nt-size:1.0pt;font-family:"Arial",sans-serif;color:white">=E2=80= =8A</span><span style=3D"font-size:1.0pt;color:white">4 is undergoing review with our lab and<u></u><u></u></span></p> </div></div></div><div lang=3D"EN-GB" link=3D"blue" vlink=3D"purple" style= =3D"word-wrap:break-word"><div> <div> <p class=3D"MsoNormal"><span style=3D"font-size:1.0pt;color:white"><u></u><= u></u></span></p> </div> <div> <p class=3D"MsoNormal">Raghu-<u></u><u></u></p> <div> <p class=3D"MsoNormal">=C2=A0 =C2=A0 =C2=A0PQC algorithms approved by FIPS = include FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA).=C2=A0 = These are supported currently only by the 3.5.4 FIPS provider and later ver= sions.=C2=A0 Currently 3.5.4 is undergoing review with our lab and NIST:<u></u><u></u></p> </div> <div> <p class=3D"MsoNormal"><a href=3D"https://urldefense.com/v3/__https:/csrc.n= ist.gov/projects/cryptographic-module-validation-program/modules-in-process= /modules-in-process-list__;!!FJ-Y8qCqXTj2!bZut-uZon_VIGux_15WX7wQQlDCz2htlQ= H38Q5r93kD1FyyfFNGBYigp6MnOcctxqdvCUvGlZbPhhLscJuPv$" rel=3D"nofollow" targ= et=3D"_blank" data-saferedirecturl=3D"https://www.google.com/url?hl=3Den-GB= &q=3Dhttps://urldefense.com/v3/__https:/csrc.nist.gov/projects/cryptogr= aphic-module-validation-program/modules-in-process/modules-in-process-list_= _;!!FJ-Y8qCqXTj2!bZut-uZon_VIGux_15WX7wQQlDCz2htlQH38Q5r93kD1FyyfFNGBYigp6M= nOcctxqdvCUvGlZbPhhLscJuPv$&source=3Dgmail&ust=3D1776405960413000&a= mp;usg=3DAOvVaw0DhW3T7mNBsrr8PuQB4_T2">https://csrc.nist.gov/projects/crypt= ographic-module-validation-program/modules-in-process/modules-in-process-li= st</a><u></u><u></u></p> </div> <div> <p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p> </div> <div> <p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p> </div> <div> <p class=3D"MsoNormal">FIPS and PQC are definitely=C2=A0_not_ mutually excl= usive, you can definitely=C2=A0use both PQC algorithms and be FIPS-140-3 co= mpliant.=C2=A0 The only current barrier is that our provider has not yet be= en certified by NIST.=C2=A0 That need not be a barrier for you however, if you are planning on doing a full submission of openssl= through your own lab (though the time effort on that is constrained by you= r lab and NIST).<u></u><u></u></p> </div> <div> <p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p> </div> <div> <p class=3D"MsoNormal">Neil<u></u><u></u></p> </div> <div> <p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p> </div> </div> <p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p> <div> <div> <p class=3D"MsoNormal">On Wed, Apr 15, 2026 at 9:43<span style=3D"font-fami= ly:"Arial",sans-serif">=E2=80=AF</span>AM Raghu Chidambaram <<= a rel=3D"nofollow">[email protected]</a>> wrote:<u></u><u></u></p> </div> <blockquote style=3D"border:none;border-left:solid #cccccc 1.0pt;padding:0c= m 0cm 0cm 6.0pt;margin-left:4.8pt;margin-right:0cm"> <p class=3D"MsoNormal">Hi Team,<u></u><u></u></p> <div> <p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p> </div> <div> <p class=3D"MsoNormal">Our organization is planning to go for PQC support s= o that application is quantum safe.<u></u><u></u></p> </div> <div> <p class=3D"MsoNormal">we are already FIPS 140-2 compliant and we are also = in the process of making it FIPS 140-3 compliant as 140-2 will be sunset by= Sep 2026.<u></u><u></u></p> </div> <div> <p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p> </div> <div> <p class=3D"MsoNormal">FIPS<u></u><u></u></p> </div> <div> <p class=3D"MsoNormal">- Our application is FIPS 140-2 and with FIPS provid= er 3.0.9. We made this possible with the help of lot of to and fro discussi= ons over the OpenSSL Forum for good amount of time :) :) .<u></u><u></u></p= > </div> <div> <p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p> </div> <div> <p class=3D"MsoNormal">For 140-3 we did analysis and understood that with O= penSSL version say 3.5.x we need to bundle the FIPS provider version 3.1.2 = ( 140-3 compliant ) instead of 3.0.9( 140-2) compliant. Hope this is correc= t.<br> <br> PQC<u></u><u></u></p> </div> <div> <p class=3D"MsoNormal">- For PQC we just started analysis and checking whic= h all algorithms we need to use in order to make it PQC compliant. As part = of this we want to understand which of OpenSSL supports PQC and is there an= y doc / list which conveys like from algorithm A we need to move to algorithm, means how to migrate from curren= t set to PQC safe set is what we are checking mainly.=C2=A0<br> <br> - one more point what we understood from the discussions internally and wit= h the teams who are handling inside our organization that FIPS and PQC cant= go hand in hand, like if we are in FIPS 140-3 version we cant claim for PQ= C as algo's are different and if we are going to be PQC safe then we can't claim FIPS 140-3 support, is= this correct statement? or our assumption is wrong?<u></u><u></u></p> </div> <div> <p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p> </div> <div> <p class=3D"MsoNormal">Need your help and inputs to proceed on these aspect= s=C2=A0<u></u><u></u></p> </div> <div> <p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p> </div> <div> <p class=3D"MsoNormal">Thank you,<u></u><u></u></p> </div> <div> <p class=3D"MsoNormal">Raghu<u></u><u></u></p> </div> <p class=3D"MsoNormal">-- <br> You received this message because you are subscribed to the Google Groups &= quot;openssl-users" group.<br> To unsubscribe from this group and stop receiving emails from it, send an e= mail to <a rel=3D"nofollow">[email protected]</a>.<br> To view this discussion visit <a href=3D"https://urldefense.com/v3/__https:= /groups.google.com/a/openssl.org/d/msgid/openssl-users/9d605db8-9220-491c-9= 424-12b42ed92948n*40openssl.org?utm_medium=3Demail&utm_source=3Dfooter_= _;JQ!!FJ-Y8qCqXTj2!bZut-uZon_VIGux_15WX7wQQlDCz2htlQH38Q5r93kD1FyyfFNGBYigp= 6MnOcctxqdvCUvGlZbPhhPVv707z$" rel=3D"nofollow" target=3D"_blank" data-safe= redirecturl=3D"https://www.google.com/url?hl=3Den-GB&q=3Dhttps://urldef= ense.com/v3/__https:/groups.google.com/a/openssl.org/d/msgid/openssl-users/= 9d605db8-9220-491c-9424-12b42ed92948n*40openssl.org?utm_medium%3Demail%26ut= m_source%3Dfooter__;JQ!!FJ-Y8qCqXTj2!bZut-uZon_VIGux_15WX7wQQlDCz2htlQH38Q5= r93kD1FyyfFNGBYigp6MnOcctxqdvCUvGlZbPhhPVv707z$&source=3Dgmail&ust= =3D1776405960413000&usg=3DAOvVaw234u-IqU60CJ22NHwl3rf8"> https://groups.google.com/a/openssl.org/d/msgid/openssl-users/9d605db8-9220= -491c-9424-12b42ed92948n%40openssl.org</a>.<u></u><u></u></p> </blockquote> </div> </div></div><div lang=3D"EN-GB" link=3D"blue" vlink=3D"purple" style=3D"wor= d-wrap:break-word"><div><p class=3D"MsoNormal">-- <br> You received this message because you are subscribed to the Google Groups &= quot;openssl-users" group.<br> To unsubscribe from this group and stop receiving emails from it, send an e= mail to <a rel=3D"nofollow">[email protected]</a>.<br></p></div></div><di= v lang=3D"EN-GB" link=3D"blue" vlink=3D"purple" style=3D"word-wrap:break-wo= rd"><div><p class=3D"MsoNormal"> To view this discussion visit <a href=3D"https://urldefense.com/v3/__https:= /groups.google.com/a/openssl.org/d/msgid/openssl-users/CAJbOq16tR2n_U1tWtzb= CUzt57PjEZQbiJRjvM-3vPQ3gkrGyXA*40mail.gmail.com?utm_medium=3Demail&utm= _source=3Dfooter__;JQ!!FJ-Y8qCqXTj2!bZut-uZon_VIGux_15WX7wQQlDCz2htlQH38Q5r= 93kD1FyyfFNGBYigp6MnOcctxqdvCUvGlZbPhhA0Qq6iv$" rel=3D"nofollow" target=3D"= _blank" data-saferedirecturl=3D"https://www.google.com/url?hl=3Den-GB&q= =3Dhttps://urldefense.com/v3/__https:/groups.google.com/a/openssl.org/d/msg= id/openssl-users/CAJbOq16tR2n_U1tWtzbCUzt57PjEZQbiJRjvM-3vPQ3gkrGyXA*40mail= .gmail.com?utm_medium%3Demail%26utm_source%3Dfooter__;JQ!!FJ-Y8qCqXTj2!bZut= -uZon_VIGux_15WX7wQQlDCz2htlQH38Q5r93kD1FyyfFNGBYigp6MnOcctxqdvCUvGlZbPhhA0= Qq6iv$&source=3Dgmail&ust=3D1776405960413000&usg=3DAOvVaw3NUIR0= YQMaeOkULhnxSdvk"> https://groups.google.com/a/openssl.org/d/msgid/openssl-users/CAJbOq16tR2n_= U1tWtzbCUzt57PjEZQbiJRjvM-3vPQ3gkrGyXA%40mail.gmail.com</a>.<u></u><u></u><= /p> </div> <i>Any email and files/attachments transmitted with it are intended solely = for the use of the individual or entity to whom they are addressed. If this= message has been sent to you in error, you must not copy, distribute or di= sclose of the information it contains. <u>Please notify Entrust immediately and delete the message from your syste= m.</u></i><br> <br> </div> </blockquote></div></blockquote></div> <p></p> -- <br /> You received this message because you are subscribed to the Google Groups &= quot;openssl-users" group.<br /> To unsubscribe from this group and stop receiving emails from it, send an e= mail to <a href=3D"mailto:openssl-users+unsubscribe-MCmKBN63+BlAfugRpC6u6w@public.gmane.org">openssl-us= [email protected]</a>.<br /> To view this discussion visit <a href=3D"https://groups.google.com/a/openss= l.org/d/msgid/openssl-users/6502df5e-c419-4895-b3ee-c9bf7dd37a7bn%40openssl= .org?utm_medium=3Demail&utm_source=3Dfooter">https://groups.google.com/a/op= enssl.org/d/msgid/openssl-users/6502df5e-c419-4895-b3ee-c9bf7dd37a7bn%40ope= nssl.org</a>.<br /> ------=_Part_83901_981260663.1776319917688-- ------=_Part_83900_927435634.1776319917688--