Re: [EXTERNAL] Re: OpenSSL and PQC/FIPS support

Raghu Chidambaram <[email protected]> Wed, 29 Apr 2026 07:56:23 -0700 (PDT)
Newsgroups gmane.comp.encryption.openssl.user
Message-ID <[email protected]>
------=_Part_377074_796924974.1777474583217
Content-Type: multipart/alternative; 
	boundary="----=_Part_377075_1701704293.1777474583217"

------=_Part_377075_1701704293.1777474583217
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Thanks Martin Bonner,
Obviously if you want to claim PQ safety, you will need to make sure you=20
use PQ safe algorithms.  (Personally I would strongly consider use hybrid=
=20
algorithms, but that is up to you.)
- yes this is what i m also understanding and it is hybrid but we need to=
=20
use the PQ safe algo which are FIPS certified correct?


On Monday, 27 April 2026 at 13:36:31 UTC+5:30 Martin Bonner wrote:

> The point I was trying to make, is that you will need to ensure you are=
=20
> using the FIPS provider (and not the default provider) if you want to cla=
im=20
> FIPS compliance. Obviously if you want to claim PQ safety, you will need =
to=20
> make sure you use PQ safe algorithms.  (Personally I would strongly=20
> consider use hybrid algorithms, but that is up to you.)
>
> =20
>
> Martin Bonner
>
> =20
>
> =20
>
> *From:* Raghu Chidambaram <[email protected]>=20
> *Sent:* 23 April 2026 08:41
> *To:* openssl-users <[email protected]>
> *Cc:* Raghu Chidambaram <[email protected]>; Martin Bonner <
> [email protected]>
> *Subject:* Re: [EXTERNAL] Re: OpenSSL and PQC/FIPS support
>
> =20
>
> Hi Team, Not quite (or at least, not necessarily). The correct statement=
=20
> is =E2=80=9Call the algorithms (including PQ algorithms) supported by the=
 FIPS=20
> provider in this OpenSSL will be FIPS 140-3 compliant=E2=80=9D. -- As we =
are=20
> claiming for FIPS 140-3 for
>
>
> Hi Team,
>
> =20
>
> Not quite (or at least, not necessarily).  The correct statement is =E2=
=80=9Call=20
> the algorithms (including PQ algorithms) supported by the FIPS provider i=
n=20
> this OpenSSL will be FIPS 140-3 compliant=E2=80=9D.=20
>
> -- As we are claiming for FIPS 140-3 for our application we need to=20
> ourselves make sure that we use only PQC safe algorithms which are approv=
ed=20
> in the OpenSSL 3.5.4 ( once it is done ) to claim both PQC and FIPS=20
> compliant :) :)
>
> =20
>
> is this correct understanding for the both claims?
>
> =20
>
> On Thursday, 16 April 2026 at 12:29:16 UTC+5:30 Raghu Chidambaram wrote:
>
> Thanks Martin Bonner,
>
> =20
>
> Not quite (or at least, not necessarily).  The correct statement is =E2=
=80=9Call=20
> the algorithms (including PQ algorithms) supported by the FIPS provider i=
n=20
> this OpenSSL will be FIPS 140-3 compliant=E2=80=9D.=20
>
> -- As we are claiming for FIPS 140-3 for our application we need to=20
> ourselves make sure that we use only PQC safe algorithms which are approv=
ed=20
> in the OpenSSL 3.5.4 ( once it is done ) to claim both PQC and FIPS=20
> compliant :) :)
>
> =20
>
> Thanks,
>
> Raghu
>
> On Thursday, 16 April 2026 at 11:53:55 UTC+5:30 Martin Bonner wrote:
>
> > then all the PQC algorithms which are part of this OpenSSL will be FIPS=
=20
> 140-3 compliant
>
> =20
>
> Not quite (or at least, not necessarily).  The correct statement is =E2=
=80=9Call=20
> the algorithms (including PQ algorithms) supported by the FIPS provider i=
n=20
> this OpenSSL will be FIPS 140-3 compliant=E2=80=9D. =20
>
> =20
>
> I haven=E2=80=99t checked, but it is perfectly possible that there are un=
approved=20
> PQ algorithms which are supported by the base provider.  In the classical=
=20
> world, the base provider supports CAMELLIA (or at least, it used to), the=
=20
> FIPS provider has never supported CAMELLIA because it isn=E2=80=99t an ap=
proved=20
> algorithm.
>
> =20
>
> Martin Bonner
>
> =20
>
> =20
>
> *From:* Raghu Chidambaram <[email protected]>=20
> *Sent:* 16 April 2026 07:12
> *To:* openssl-users <[email protected]>
> *Cc:* Raghu Chidambaram <[email protected]>; Martin Bonner <
> [email protected]>
> *Subject:* Re: [EXTERNAL] Re: OpenSSL and PQC/FIPS support
>
> =20
>
> HI Team, GM, In https:=E2=80=8A//csrc.=E2=80=8Anist.=E2=80=8Agov/projects=
/cryptographic-module-validation-program/modules-in-process/modules-in-proc=
ess-list=20
> OpenSSL FIPS Provider The OpenSSL Corporation OpenSSL Corporation=20
> corporation@=E2=80=8Aopenssl.=E2=80=8Aorg Voice: 877-673-6775 <(877)%2067=
3-6775> FIPS
>
> HI Team,
>
> =20
>
> GM,
>
> =20
>
> In=20
> https://csrc.nist.gov/projects/cryptographic-module-validation-program/mo=
dules-in-process/modules-in-process-list=20
> <https://urldefense.com/v3/__https:/csrc.nist.gov/projects/cryptographic-=
module-validation-program/modules-in-process/modules-in-process-list__;!!FJ=
-Y8qCqXTj2!cn7ZZT_-25LDzb5jpUAc5H92a_1XhJ9WnBHNw1kBQDMtUMzLCNRxm_pv4KY3dlrt=
uGtkYbjejIR6Wae8qs7qagtrcis$>
>
> =20
>
>
> OpenSSL FIPS Provider
> The OpenSSL Corporation=20
>
>    - OpenSSL Corporation
>    - [email protected]
>    - Voice: 877-673-6775 <(877)%20673-6775>
>
>
> FIPS 140-3
> Pending Review (11/25/2025)
>
> =20
>
> For the above OpenSSL FIPS validation is in progress, that means here wit=
h=20
> OpenSSL 3.5.4 which contains the PQC related algorithms.
>
> so once this get the approval then all the PQC algorithms which are part=
=20
> of this OpenSSL will be FIPS 140-3 compliant and as i mentioned earlier=
=20
> then we can=20
>
> take this OpenSSL 3.5.4 FIPS provider and bundle in our application to=20
> claim both PQC and FIPS compliant ?
>
> =20
>
> please correct me if our understanding is wrong
>
> =20
>
> Thanks,
>
> Raghu
>
> On Wednesday, 15 April 2026 at 22:12:06 UTC+5:30 Raghu Chidambaram wrote:
>
> Thanks Martin Bonner and Neil,
>
> Thanks for the information.
>
> =20
>
>  then until 3.5.4 is approved, FIPS and PQC are mutually exclusive with=
=20
> OpenSSL (and FIPS is impossible between Sep 2026 and the approval of 3.5.=
4).
>
> - [Raghu] so both are mutually exclusive if i understood correctly.
>
> =20
>
> These are supported currently only by the 3.5.4 FIPS provider and later=
=20
> versions.  Currently 3.5.4 is undergoing review with our lab and NIST:
>
> -[Raghu] I have little confusion here, when we are talkin about the=20
> OpenSSL version 3.5.4 is undergoing review means the FIPS provider ( fips=
=20
> modules) inside that 3.5.4 version which also contains the SSL and Crypto=
=20
> libraries am i correct. Just like OpenSSL 3.0.9 got FIPS 140-2 , OpenSSL=
=20
> 3.1.2 version got FIPS 140-3 , similarly OpenSSL 3.5.4 is going for CMVP=
=20
> validation and it will be 140-3 compliant or some other FIPS compliant?
>
> =20
>
> PQC algorithms approved by FIPS include FIPS 203 (ML-KEM), FIPS 204=20
> (ML-DSA) and FIPS 205 (SLH-DSA)
>
> -[Raghu] only above 3 algorithms are FIPS approved as of today? is that=
=20
> correct statement.
>
> =20
>
> FIPS and PQC are definitely _not_ mutually exclusive, you can=20
> definitely use both PQC algorithms and be FIPS-140-3 compliant.
>
> - [Raghu] we have release our application to all the products/customer in=
=20
> Dell saying that we are FIPS compliant, i m part of Dell Organization=20
> previously we were using OpenSSL 1.0.2 FIPS version which was supported b=
y=20
> OpenSSL team for few years later we moved to OpenSSL 3.0.x and now we are=
=20
> at OpenSSL 3.5.5 version in our application.
>
> so we cant use few algorithms which are PQC and few which are FIPS 140-3=
=20
> and claim for both? is that correct? we want to claim FIPS 140-3 as of no=
w=20
> which is in progress and if we move to PQC safe algorithms ( somehow not=
=20
> sure as of now) then we cant claim for FIPS 140-3 right?
>
> =20
>
> Thanks,
>
> Raghu
>
> =20
>
> On Wednesday, 15 April 2026 at 19:42:45 UTC+5:30 Martin Bonner wrote:
>
> My reading of the original email is that Raghu=E2=80=99s organization ach=
ieved=20
> FIPS compliance by using the FIPS-approved OpenSSL provider.  This is goo=
d,=20
> because I would have said that it while it is touch-and-go whether OpenSS=
L=20
> 3.5.4 is going to be FIPS-approved before Sep 2026, it is very unlikely=
=20
> that a submission made today by Raghu=E2=80=99s organization would be app=
roved by=20
> then.
>
> =20
>
> There is also a question of whether Raghu=E2=80=99s organization needs =
=E2=80=9CFIPS=20
> approved=E2=80=9D, or whether =E2=80=9CFIPS pending=E2=80=9D is good enou=
gh.  It is almost=20
> inconceivable to me that 3.5.4 won=E2=80=99t be *eventually* approved, it=
=E2=80=99s just=20
> a matter of bureaucracy.  OTOH, if FIPS approved is a contractual=20
> requirement (e.g. because the US Government is a customer), then until=20
> 3.5.4 is approved, FIPS and PQC are mutually exclusive with OpenSSL (and=
=20
> FIPS is impossible between Sep 2026 and the approval of 3.5.4).
>
> =20
>
> On =E2=80=9CPQC equivalents for classical algorithms=E2=80=9D, don=E2=80=
=99t forget that if you=20
> are using AES128 you need to switch to AES256 (but AES256 is already=20
> considered acceptable).
>
> =20
>
> Martin Bonner
>
> =20
>
> =20
>
> *From:* Neil Horman <[email protected]>=20
> *Sent:* 15 April 2026 14:53
> *To:* Raghu Chidambaram <[email protected]>
> *Cc:* openssl-users <[email protected]>
> *Subject:* [EXTERNAL] Re: OpenSSL and PQC/FIPS support
>
> =20
>
> Raghu- PQC algorithms approved by FIPS include FIPS 203 (ML-KEM), FIPS 20=
4=20
> (ML-DSA) and FIPS 205 (SLH-DSA). These are supported currently only by th=
e=20
> 3.=E2=80=8A5.=E2=80=8A4 FIPS provider and later versions. Currently 3.=E2=
=80=8A5.=E2=80=8A4 is undergoing=20
> review with our lab and
>
> Raghu-
>
>      PQC algorithms approved by FIPS include FIPS 203 (ML-KEM), FIPS 204=
=20
> (ML-DSA) and FIPS 205 (SLH-DSA).  These are supported currently only by t=
he=20
> 3.5.4 FIPS provider and later versions.  Currently 3.5.4 is undergoing=20
> review with our lab and NIST:
>
>
> https://csrc.nist.gov/projects/cryptographic-module-validation-program/mo=
dules-in-process/modules-in-process-list=20
> <https://urldefense.com/v3/__https:/csrc.nist.gov/projects/cryptographic-=
module-validation-program/modules-in-process/modules-in-process-list__;!!FJ=
-Y8qCqXTj2!bZut-uZon_VIGux_15WX7wQQlDCz2htlQH38Q5r93kD1FyyfFNGBYigp6MnOcctx=
qdvCUvGlZbPhhLscJuPv$>
>
> =20
>
> =20
>
> FIPS and PQC are definitely _not_ mutually exclusive, you can=20
> definitely use both PQC algorithms and be FIPS-140-3 compliant.  The only=
=20
> current barrier is that our provider has not yet been certified by NIST. =
=20
> That need not be a barrier for you however, if you are planning on doing =
a=20
> full submission of openssl through your own lab (though the time effort o=
n=20
> that is constrained by your lab and NIST).
>
> =20
>
> Neil
>
> =20
>
> =20
>
> On Wed, Apr 15, 2026 at 9:43=E2=80=AFAM Raghu Chidambaram <pcraghu...@gma=
il.com>=20
> wrote:
>
> Hi Team,
>
> =20
>
> Our organization is planning to go for PQC support so that application is=
=20
> quantum safe.
>
> we are already FIPS 140-2 compliant and we are also in the process of=20
> making it FIPS 140-3 compliant as 140-2 will be sunset by Sep 2026.
>
> =20
>
> FIPS
>
> - Our application is FIPS 140-2 and with FIPS provider 3.0.9. We made thi=
s=20
> possible with the help of lot of to and fro discussions over the OpenSSL=
=20
> Forum for good amount of time :) :) .
>
> =20
>
> For 140-3 we did analysis and understood that with OpenSSL version say=20
> 3.5.x we need to bundle the FIPS provider version 3.1.2 ( 140-3 compliant=
 )=20
> instead of 3.0.9( 140-2) compliant. Hope this is correct.
>
> PQC
>
> - For PQC we just started analysis and checking which all algorithms we=
=20
> need to use in order to make it PQC compliant. As part of this we want to=
=20
> understand which of OpenSSL supports PQC and is there any doc / list whic=
h=20
> conveys like from algorithm A we need to move to algorithm, means how to=
=20
> migrate from current set to PQC safe set is what we are checking mainly.=
=20
>
> - one more point what we understood from the discussions internally and=
=20
> with the teams who are handling inside our organization that FIPS and PQC=
=20
> cant go hand in hand, like if we are in FIPS 140-3 version we cant claim=
=20
> for PQC as algo's are different and if we are going to be PQC safe then w=
e=20
> can't claim FIPS 140-3 support, is this correct statement? or our=20
> assumption is wrong?
>
> =20
>
> Need your help and inputs to proceed on these aspects=20
>
> =20
>
> Thank you,
>
> Raghu
>
> --=20
> You received this message because you are subscribed to the Google Groups=
=20
> "openssl-users" group.
> To unsubscribe from this group and stop receiving emails from it, send an=
=20
> email to [email protected]
> To view this discussion visit=20
> https://groups.google.com/a/openssl.org/d/msgid/openssl-users/9d605db8-92=
20-491c-9424-12b42ed92948n%40openssl.org=20
> <https://urldefense.com/v3/__https:/groups.google.com/a/openssl.org/d/msg=
id/openssl-users/9d605db8-9220-491c-9424-12b42ed92948n*40openssl.org?utm_me=
dium=3Demail&utm_source=3Dfooter__;JQ!!FJ-Y8qCqXTj2!bZut-uZon_VIGux_15WX7wQ=
QlDCz2htlQH38Q5r93kD1FyyfFNGBYigp6MnOcctxqdvCUvGlZbPhhPVv707z$>
> .
>
> --=20
> You received this message because you are subscribed to the Google Groups=
=20
> "openssl-users" group.
> To unsubscribe from this group and stop receiving emails from it, send an=
=20
> email to [email protected]
>
> To view this discussion visit=20
> https://groups.google.com/a/openssl.org/d/msgid/openssl-users/CAJbOq16tR2=
n_U1tWtzbCUzt57PjEZQbiJRjvM-3vPQ3gkrGyXA%40mail.gmail.com=20
> <https://urldefense.com/v3/__https:/groups.google.com/a/openssl.org/d/msg=
id/openssl-users/CAJbOq16tR2n_U1tWtzbCUzt57PjEZQbiJRjvM-3vPQ3gkrGyXA*40mail=
.gmail.com?utm_medium=3Demail&utm_source=3Dfooter__;JQ!!FJ-Y8qCqXTj2!bZut-u=
Zon_VIGux_15WX7wQQlDCz2htlQH38Q5r93kD1FyyfFNGBYigp6MnOcctxqdvCUvGlZbPhhA0Qq=
6iv$>
> .
>
> *Any email and files/attachments transmitted with it are intended solely=
=20
> for the use of the individual or entity to whom they are addressed. If th=
is=20
> message has been sent to you in error, you must not copy, distribute or=
=20
> disclose of the information it contains. Please notify Entrust immediatel=
y=20
> and delete the message from your system.*
>
>

--=20
You received this message because you are subscribed to the Google Groups "=
openssl-users" group.
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org
To view this discussion visit https://groups.google.com/a/openssl.org/d/msg=
id/openssl-users/39f1651d-5785-43d8-bbb1-41bbde296fefn%40openssl.org.

------=_Part_377075_1701704293.1777474583217
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Thanks Martin Bonner,<div>Obviously if you want to claim PQ safety, you wil=
l need to make sure you use PQ safe algorithms.=C2=A0 (Personally I would s=
trongly consider use hybrid algorithms, but that is up to you.)</div><div>-=
 yes this is what i m also understanding and it is hybrid but we need to us=
e the PQ safe algo which are FIPS certified correct?</div><div><br /><br />=
</div><div class=3D"gmail_quote"><div dir=3D"auto" class=3D"gmail_attr">On =
Monday, 27 April 2026 at 13:36:31 UTC+5:30 Martin Bonner wrote:<br/></div><=
blockquote class=3D"gmail_quote" style=3D"margin: 0 0 0 0.8ex; border-left:=
 1px solid rgb(204, 204, 204); padding-left: 1ex;">





<div lang=3D"EN-GB" link=3D"blue" vlink=3D"purple" style=3D"word-wrap:break=
-word">
<div>
<p class=3D"MsoNormal"><span>The point I was trying to make, is that you wi=
ll need to ensure you are using the FIPS provider (and not the default prov=
ider) if you want to claim FIPS compliance. Obviously if you want to claim
 PQ safety, you will need to make sure you use PQ safe algorithms.=C2=A0 (P=
ersonally I would strongly consider use hybrid algorithms, but that is up t=
o you.)<u></u><u></u></span></p></div></div><div lang=3D"EN-GB" link=3D"blu=
e" vlink=3D"purple" style=3D"word-wrap:break-word"><div>
<p class=3D"MsoNormal"><span><u></u>=C2=A0<u></u></span></p>
<table border=3D"0" cellspacing=3D"0" cellpadding=3D"0" style=3D"border-col=
lapse:collapse">
<tbody>
<tr>
<td width=3D"265" valign=3D"top" style=3D"width:198.8pt;padding:0cm 5.4pt 0=
cm 5.4pt">
<p class=3D"MsoNormal" style=3D"margin-bottom:2.7pt;text-autospace:none"><s=
pan lang=3D"EN-US" style=3D"font-size:14.0pt;font-family:&quot;Arial Black&=
quot;,sans-serif;color:#6f2176">Martin Bonner</span><span lang=3D"EN-US" st=
yle=3D"font-size:14.0pt;font-family:&quot;Gotham Book&quot;;color:#6f2176">=
<u></u><u></u></span></p>
</td>
</tr>
</tbody>
</table>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt"><u></u>=C2=A0<u></u=
></span></p>
<p class=3D"MsoNormal"><span><u></u>=C2=A0<u></u></span></p>
<div style=3D"border:none;border-top:solid #e1e1e1 1.0pt;padding:3.0pt 0cm =
0cm 0cm">
<p class=3D"MsoNormal"><b><span lang=3D"EN-US" style=3D"font-size:11.0pt;fo=
nt-family:&quot;Calibri&quot;,sans-serif">From:</span></b><span lang=3D"EN-=
US" style=3D"font-size:11.0pt;font-family:&quot;Calibri&quot;,sans-serif"> =
Raghu Chidambaram &lt;<a href data-email-masked rel=3D"nofollow">pcraghu...=
@gmail.com</a>&gt;
<br>
<b>Sent:</b> 23 April 2026 08:41<br>
<b>To:</b> openssl-users &lt;<a href data-email-masked rel=3D"nofollow">ope=
[email protected]</a>&gt;<br>
<b>Cc:</b> Raghu Chidambaram &lt;<a href data-email-masked rel=3D"nofollow"=
>[email protected]</a>&gt;; Martin Bonner &lt;<a href data-email-masked =
rel=3D"nofollow">[email protected]</a>&gt;<br>
<b>Subject:</b> Re: [EXTERNAL] Re: OpenSSL and PQC/FIPS support<u></u><u></=
u></span></p>
</div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
</div></div><div lang=3D"EN-GB" link=3D"blue" vlink=3D"purple" style=3D"wor=
d-wrap:break-word"><div><div>
<p class=3D"MsoNormal"><span style=3D"font-size:1.0pt;color:white">Hi Team,=
 Not quite (or at least, not necessarily). The correct statement is =E2=80=
=9Call the algorithms (including PQ algorithms) supported by the FIPS provi=
der in this
 OpenSSL will be FIPS 140-3 compliant=E2=80=9D. -- As we are claiming for F=
IPS 140-3 for<u></u><u></u></span></p>
</div></div></div><div lang=3D"EN-GB" link=3D"blue" vlink=3D"purple" style=
=3D"word-wrap:break-word"><div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:1.0pt;color:white"><u></u><=
u></u></span></p>
</div>
<p class=3D"MsoNormal"><br>
Hi Team,<u></u><u></u></p>
<div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
</div>
<div>
<div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Source Sans Pro&quo=
t;,sans-serif;color:#1b1b1b">Not quite (or at least, not necessarily).=C2=
=A0 The correct statement is =E2=80=9Call the algorithms (including PQ algo=
rithms) supported by the FIPS provider in this OpenSSL will be
 FIPS 140-3 compliant=E2=80=9D.=C2=A0</span><span style=3D"color:#500050"><=
u></u><u></u></span></p>
</div>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Source Sans Pro&quo=
t;,sans-serif;color:#1b1b1b">-- As we are claiming for FIPS 140-3 for our a=
pplication we need to ourselves make sure that we use only PQC safe algorit=
hms which are approved in the OpenSSL 3.5.4 (
 once it is done ) to claim both PQC and FIPS compliant :) :)</span><u></u>=
<u></u></p>
</div>
</div>
<div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Source Sans Pro&quo=
t;,sans-serif;color:#1b1b1b">is this correct understanding for the both cla=
ims?</span><u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
</div>
<div>
<div>
<p class=3D"MsoNormal">On Thursday, 16 April 2026 at 12:29:16 UTC+5:30 Ragh=
u Chidambaram wrote:<u></u><u></u></p>
</div>
<blockquote style=3D"border:none;border-left:solid #cccccc 1.0pt;padding:0c=
m 0cm 0cm 6.0pt;margin-left:4.8pt;margin-right:0cm">
<p class=3D"MsoNormal">Thanks Martin Bonner,<u></u><u></u></p>
<div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Source Sans Pro&quo=
t;,sans-serif;color:#1b1b1b">Not quite (or at least, not necessarily).=C2=
=A0 The correct statement is =E2=80=9Call the algorithms (including PQ algo=
rithms) supported by the FIPS provider in this OpenSSL will be
 FIPS 140-3 compliant=E2=80=9D.=C2=A0</span><u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Source Sans Pro&quo=
t;,sans-serif;color:#1b1b1b">-- As we are claiming for FIPS 140-3 for our a=
pplication we need to ourselves make sure that we use only PQC safe algorit=
hms which are approved in the OpenSSL 3.5.4 (
 once it is done ) to claim both PQC and FIPS compliant :) :)</span><u></u>=
<u></u></p>
</div>
<div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Source Sans Pro&quo=
t;,sans-serif;color:#1b1b1b">Thanks,</span><u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><span style=3D"font-f=
amily:&quot;Source Sans Pro&quot;,sans-serif;color:#1b1b1b">Raghu</span><u>=
</u><u></u></p>
</div>
<div>
<div>
<p class=3D"MsoNormal">On Thursday, 16 April 2026 at 11:53:55 UTC+5:30 Mart=
in Bonner wrote:<u></u><u></u></p>
</div>
<blockquote style=3D"border:none;border-left:solid #cccccc 1.0pt;padding:0c=
m 0cm 0cm 6.0pt;margin-left:4.8pt;margin-right:0cm">
<div>
<div>
<p class=3D"MsoNormal">&gt;
<span style=3D"font-family:&quot;Source Sans Pro&quot;,sans-serif;color:#1b=
1b1b">then all the PQC algorithms which are part of this OpenSSL will be FI=
PS 140-3 compliant</span><u></u><u></u></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Source Sans Pro&quo=
t;,sans-serif;color:#1b1b1b">=C2=A0</span><u></u><u></u></p>
</div>
</div>
<div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Source Sans Pro&quo=
t;,sans-serif;color:#1b1b1b">Not quite (or at least, not necessarily).=C2=
=A0 The correct statement is =E2=80=9Call the algorithms (including PQ algo=
rithms)
 supported by the FIPS provider in this OpenSSL will be FIPS 140-3 complian=
t=E2=80=9D.=C2=A0 </span>
<u></u><u></u></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Source Sans Pro&quo=
t;,sans-serif;color:#1b1b1b">=C2=A0</span><u></u><u></u></p>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Source Sans Pro&quo=
t;,sans-serif;color:#1b1b1b">I haven=E2=80=99t checked, but it is perfectly=
 possible that there are unapproved PQ algorithms which are supported
 by the base provider.=C2=A0 In the classical world, the base provider supp=
orts CAMELLIA (or at least, it used to), the FIPS provider has never suppor=
ted CAMELLIA because it isn=E2=80=99t an approved algorithm.</span><u></u><=
u></u></p>
<p class=3D"MsoNormal">=C2=A0<u></u><u></u></p>
<table border=3D"0" cellspacing=3D"0" cellpadding=3D"0" style=3D"border-col=
lapse:collapse">
<tbody>
<tr>
<td width=3D"265" valign=3D"top" style=3D"width:198.8pt;padding:0cm 5.4pt 0=
cm 5.4pt">
<p class=3D"MsoNormal" style=3D"margin-bottom:2.7pt;text-autospace:none">
<span lang=3D"EN-US" style=3D"font-size:14.0pt;font-family:&quot;Arial Blac=
k&quot;,sans-serif;color:#6f2176">Martin Bonner</span><u></u><u></u></p>
</td>
</tr>
</tbody>
</table>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt">=C2=A0</span><u></u=
><u></u></p>
<p class=3D"MsoNormal">=C2=A0<u></u><u></u></p>
<div style=3D"border:none;border-top:solid #e1e1e1 1.0pt;padding:3.0pt 0cm =
0cm 0cm">
<p class=3D"MsoNormal"><b><span lang=3D"EN-US" style=3D"font-size:11.0pt;fo=
nt-family:&quot;Calibri&quot;,sans-serif">From:</span></b><span lang=3D"EN-=
US" style=3D"font-size:11.0pt;font-family:&quot;Calibri&quot;,sans-serif"> =
Raghu
 Chidambaram &lt;<a href data-email-masked rel=3D"nofollow">pcraghu...@gmai=
l.com</a>&gt; <br>
<b>Sent:</b> 16 April 2026 07:12<br>
<b>To:</b> openssl-users &lt;<a href data-email-masked rel=3D"nofollow">ope=
[email protected]</a>&gt;<br>
<b>Cc:</b> Raghu Chidambaram &lt;<a href data-email-masked rel=3D"nofollow"=
>[email protected]</a>&gt;; Martin Bonner &lt;<a href data-email-masked =
rel=3D"nofollow">[email protected]</a>&gt;<br>
<b>Subject:</b> Re: [EXTERNAL] Re: OpenSSL and PQC/FIPS support</span><u></=
u><u></u></p>
</div>
<p class=3D"MsoNormal">=C2=A0<u></u><u></u></p>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:1.0pt;color:white">HI Team,=
 GM, In https:</span><span style=3D"font-size:1.0pt;font-family:&quot;Arial=
&quot;,sans-serif;color:white">=E2=80=8A</span><span style=3D"font-size:1.0=
pt;color:white">//csrc.</span><span style=3D"font-size:1.0pt;font-family:&q=
uot;Arial&quot;,sans-serif;color:white">=E2=80=8A</span><span style=3D"font=
-size:1.0pt;color:white">nist.</span><span style=3D"font-size:1.0pt;font-fa=
mily:&quot;Arial&quot;,sans-serif;color:white">=E2=80=8A</span><span style=
=3D"font-size:1.0pt;color:white">gov/projects/cryptographic-module-validati=
on-program/modules-in-process/modules-in-process-list
 OpenSSL FIPS Provider The OpenSSL Corporation OpenSSL Corporation corporat=
ion@</span><span style=3D"font-size:1.0pt;font-family:&quot;Arial&quot;,san=
s-serif;color:white">=E2=80=8A</span><span style=3D"font-size:1.0pt;color:w=
hite">openssl.</span><span style=3D"font-size:1.0pt;font-family:&quot;Arial=
&quot;,sans-serif;color:white">=E2=80=8A</span><span style=3D"font-size:1.0=
pt;color:white">org
 Voice: <a href=3D"tel:(877)%20673-6775" target=3D"_blank" rel=3D"nofollow"=
>877-673-6775</a> FIPS</span><u></u><u></u></p>
</div>
</div>
</div>
<div>
<div>
<p class=3D"MsoNormal">HI Team,<u></u><u></u></p>
<div>
<p class=3D"MsoNormal">=C2=A0<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">GM,<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">=C2=A0<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">In=C2=A0<a href=3D"https://urldefense.com/v3/__https=
:/csrc.nist.gov/projects/cryptographic-module-validation-program/modules-in=
-process/modules-in-process-list__;!!FJ-Y8qCqXTj2!cn7ZZT_-25LDzb5jpUAc5H92a=
_1XhJ9WnBHNw1kBQDMtUMzLCNRxm_pv4KY3dlrtuGtkYbjejIR6Wae8qs7qagtrcis$" target=
=3D"_blank" rel=3D"nofollow" data-saferedirecturl=3D"https://www.google.com=
/url?hl=3Den-GB&amp;q=3Dhttps://urldefense.com/v3/__https:/csrc.nist.gov/pr=
ojects/cryptographic-module-validation-program/modules-in-process/modules-i=
n-process-list__;!!FJ-Y8qCqXTj2!cn7ZZT_-25LDzb5jpUAc5H92a_1XhJ9WnBHNw1kBQDM=
tUMzLCNRxm_pv4KY3dlrtuGtkYbjejIR6Wae8qs7qagtrcis$&amp;source=3Dgmail&amp;us=
t=3D1777560866398000&amp;usg=3DAOvVaw0Btv7GWLpVeGTx_SSuLhM2">https://csrc.n=
ist.gov/projects/cryptographic-module-validation-program/modules-in-process=
/modules-in-process-list</a><u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">=C2=A0<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Source Sans Pro&quo=
t;,sans-serif;color:#1b1b1b;border:solid #dddddd 1.0pt;padding:4.0pt"><br>
OpenSSL FIPS Provider<br>
The OpenSSL Corporation=C2=A0</span><u></u><u></u></p>
<div>
<ul type=3D"disc">
<li class=3D"MsoNormal" style=3D"color:#1b1b1b">
<span style=3D"font-family:&quot;Source Sans Pro&quot;,sans-serif;border:so=
lid #dddddd 1.0pt;padding:4.0pt">OpenSSL Corporation</span><u></u><u></u></=
li><li class=3D"MsoNormal" style=3D"color:#1b1b1b;box-sizing:inherit">
<span style=3D"font-family:&quot;Source Sans Pro&quot;,sans-serif;border:so=
lid #dddddd 1.0pt;padding:4.0pt"><a href data-email-masked rel=3D"nofollow"=
>[email protected]</a></span><u></u><u></u></li><li class=3D"MsoNormal" =
style=3D"color:#1b1b1b;box-sizing:inherit">
<span style=3D"font-family:&quot;Source Sans Pro&quot;,sans-serif;border:so=
lid #dddddd 1.0pt;padding:4.0pt">Voice:
<a href=3D"tel:(877)%20673-6775" target=3D"_blank" rel=3D"nofollow">877-673=
-6775</a></span><u></u><u></u></li></ul>
</div>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Source Sans Pro&quo=
t;,sans-serif;color:#1b1b1b;border:solid #dddddd 1.0pt;padding:4.0pt"><br>
FIPS 140-3<br>
Pending Review (11/25/2025)</span><u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">=C2=A0<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Source Sans Pro&quo=
t;,sans-serif;color:#1b1b1b">For the above OpenSSL FIPS validation is in pr=
ogress, that means here with OpenSSL 3.5.4 which contains the
 PQC related algorithms.</span><u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Source Sans Pro&quo=
t;,sans-serif;color:#1b1b1b">so once this get the approval then all the PQC=
 algorithms which are part of this OpenSSL will be FIPS 140-3
 compliant and as i mentioned earlier then we can=C2=A0</span><u></u><u></u=
></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Source Sans Pro&quo=
t;,sans-serif;color:#1b1b1b">take this OpenSSL 3.5.4 FIPS provider and bund=
le in our application to claim both PQC and FIPS compliant ?</span><u></u><=
u></u></p>
</div>
<div>
<p class=3D"MsoNormal">=C2=A0<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Source Sans Pro&quo=
t;,sans-serif;color:#1b1b1b">please correct me if our understanding is wron=
g</span><u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">=C2=A0<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-family:&quot;Source Sans Pro&quo=
t;,sans-serif;color:#1b1b1b">Thanks,</span><u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><span style=3D"font-f=
amily:&quot;Source Sans Pro&quot;,sans-serif;color:#1b1b1b">Raghu</span><u>=
</u><u></u></p>
</div>
<div>
<div>
<p class=3D"MsoNormal">On Wednesday, 15 April 2026 at 22:12:06 UTC+5:30 Rag=
hu Chidambaram wrote:<u></u><u></u></p>
</div>
<blockquote style=3D"border:none;border-left:solid #cccccc 1.0pt;padding:0c=
m 0cm 0cm 6.0pt;margin-left:4.8pt;margin-top:5.0pt;margin-right:0cm;margin-=
bottom:5.0pt">
<p class=3D"MsoNormal">Thanks Martin Bonner and Neil,<u></u><u></u></p>
<div>
<p class=3D"MsoNormal">Thanks for the information.<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">=C2=A0<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">=C2=A0then until 3.5.4 is approved, FIPS and PQC are=
 mutually exclusive with OpenSSL (and FIPS is impossible between Sep 2026 a=
nd the approval of 3.5.4).<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">- [Raghu] so both are mutually exclusive if i unders=
tood correctly.<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">=C2=A0<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">These are supported currently only by the 3.5.4 FIPS=
 provider and later versions.=C2=A0 Currently 3.5.4 is undergoing review wi=
th our lab and NIST:<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">-[Raghu] I have little confusion here, when we are t=
alkin about the OpenSSL version 3.5.4 is undergoing review means the FIPS p=
rovider ( fips modules) inside that 3.5.4 version
 which also contains the SSL and Crypto libraries am i correct. Just like O=
penSSL 3.0.9 got FIPS 140-2 , OpenSSL 3.1.2 version got FIPS 140-3 , simila=
rly OpenSSL 3.5.4 is going for CMVP validation and it will be 140-3 complia=
nt or some other FIPS compliant?<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">=C2=A0<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">PQC algorithms approved by FIPS include FIPS 203 (ML=
-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA)<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">-[Raghu] only above 3 algorithms are FIPS approved a=
s of today? is that correct statement.<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">=C2=A0<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">FIPS and PQC are definitely=C2=A0_not_ mutually excl=
usive, you can definitely=C2=A0use both PQC algorithms and be FIPS-140-3 co=
mpliant.<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">- [Raghu] we have release our application to all the=
 products/customer in Dell saying that we are FIPS compliant, i m part of D=
ell Organization previously we were using OpenSSL
 1.0.2 FIPS version which was supported by OpenSSL team for few years later=
 we moved to OpenSSL 3.0.x and now we are at OpenSSL 3.5.5 version in our a=
pplication.<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">so we cant use few algorithms which are PQC and few =
which are FIPS 140-3 and claim for both? is that correct? we want to claim =
FIPS 140-3 as of now which is in progress and if we
 move to PQC safe algorithms ( somehow not sure as of now) then we cant cla=
im for FIPS 140-3 right?<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">=C2=A0<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">Thanks,<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">Raghu<u></u><u></u></p>
<div>
<p class=3D"MsoNormal">=C2=A0<u></u><u></u></p>
</div>
</div>
<div>
<div>
<p class=3D"MsoNormal">On Wednesday, 15 April 2026 at 19:42:45 UTC+5:30 Mar=
tin Bonner wrote:<u></u><u></u></p>
</div>
<blockquote style=3D"border:none;border-left:solid #cccccc 1.0pt;padding:0c=
m 0cm 0cm 6.0pt;margin-left:4.8pt;margin-top:5.0pt;margin-right:0cm;margin-=
bottom:5.0pt">
<div>
<div>
<p class=3D"MsoNormal">My reading of the original email is that Raghu=E2=80=
=99s organization achieved FIPS compliance by using the FIPS-approved OpenS=
SL provider.=C2=A0 This is good, because I would have said that
 it while it is touch-and-go whether OpenSSL 3.5.4 is going to be FIPS-appr=
oved before Sep 2026, it is very unlikely that a submission made today by R=
aghu=E2=80=99s organization would be approved by then.<u></u><u></u></p>
<p class=3D"MsoNormal">=C2=A0<u></u><u></u></p>
<p class=3D"MsoNormal">There is also a question of whether Raghu=E2=80=99s =
organization needs =E2=80=9CFIPS approved=E2=80=9D, or whether =E2=80=9CFIP=
S pending=E2=80=9D is good enough.=C2=A0 It is almost inconceivable to me t=
hat 3.5.4 won=E2=80=99t be
<i>eventually</i> approved, it=E2=80=99s just a matter of bureaucracy.=C2=
=A0 OTOH, if FIPS approved is a contractual requirement (e.g. because the U=
S Government is a customer), then until 3.5.4 is approved, FIPS and PQC are=
 mutually exclusive with OpenSSL (and FIPS is impossible
 between Sep 2026 and the approval of 3.5.4).<u></u><u></u></p>
<p class=3D"MsoNormal">=C2=A0<u></u><u></u></p>
<p class=3D"MsoNormal">On =E2=80=9CPQC equivalents for classical algorithms=
=E2=80=9D, don=E2=80=99t forget that if you are using AES128 you need to sw=
itch to AES256 (but AES256 is already considered acceptable).<u></u><u></u>=
</p>
<p class=3D"MsoNormal">=C2=A0<u></u><u></u></p>
<table border=3D"0" cellspacing=3D"0" cellpadding=3D"0" style=3D"border-col=
lapse:collapse">
<tbody>
<tr>
<td width=3D"265" valign=3D"top" style=3D"width:198.8pt;padding:0cm 5.4pt 0=
cm 5.4pt">
<p class=3D"MsoNormal" style=3D"margin-bottom:2.7pt;text-autospace:none">
<span lang=3D"EN-US" style=3D"font-size:14.0pt;font-family:&quot;Arial Blac=
k&quot;,sans-serif;color:#6f2176">Martin Bonner</span><u></u><u></u></p>
</td>
</tr>
</tbody>
</table>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt">=C2=A0</span><u></u=
><u></u></p>
<p class=3D"MsoNormal">=C2=A0<u></u><u></u></p>
<div style=3D"border:none;border-top:solid #e1e1e1 1.0pt;padding:3.0pt 0cm =
0cm 0cm">
<p class=3D"MsoNormal"><b><span lang=3D"EN-US" style=3D"font-size:11.0pt;fo=
nt-family:&quot;Calibri&quot;,sans-serif">From:</span></b><span lang=3D"EN-=
US" style=3D"font-size:11.0pt;font-family:&quot;Calibri&quot;,sans-serif"> =
Neil
 Horman &lt;<a href data-email-masked rel=3D"nofollow">[email protected]</=
a>&gt; <br>
<b>Sent:</b> 15 April 2026 14:53<br>
<b>To:</b> Raghu Chidambaram &lt;<a href data-email-masked rel=3D"nofollow"=
>[email protected]</a>&gt;<br>
<b>Cc:</b> openssl-users &lt;<a href data-email-masked rel=3D"nofollow">ope=
[email protected]</a>&gt;<br>
<b>Subject:</b> [EXTERNAL] Re: OpenSSL and PQC/FIPS support</span><u></u><u=
></u></p>
</div>
<p class=3D"MsoNormal">=C2=A0<u></u><u></u></p>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:1.0pt;color:white">Raghu- P=
QC algorithms approved by FIPS include FIPS 203 (ML-KEM), FIPS 204 (ML-DSA)=
 and FIPS 205 (SLH-DSA). These are supported currently
 only by the 3.</span><span style=3D"font-size:1.0pt;font-family:&quot;Aria=
l&quot;,sans-serif;color:white">=E2=80=8A</span><span style=3D"font-size:1.=
0pt;color:white">5.</span><span style=3D"font-size:1.0pt;font-family:&quot;=
Arial&quot;,sans-serif;color:white">=E2=80=8A</span><span style=3D"font-siz=
e:1.0pt;color:white">4
 FIPS provider and later versions. Currently 3.</span><span style=3D"font-s=
ize:1.0pt;font-family:&quot;Arial&quot;,sans-serif;color:white">=E2=80=8A</=
span><span style=3D"font-size:1.0pt;color:white">5.</span><span style=3D"fo=
nt-size:1.0pt;font-family:&quot;Arial&quot;,sans-serif;color:white">=E2=80=
=8A</span><span style=3D"font-size:1.0pt;color:white">4
 is undergoing review with our lab and</span><u></u><u></u></p>
</div>
</div>
</div>
<div>
<div>
<div>
<p class=3D"MsoNormal">Raghu-<u></u><u></u></p>
<div>
<p class=3D"MsoNormal">=C2=A0 =C2=A0 =C2=A0PQC algorithms approved by FIPS =
include FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA).=C2=A0 =
These are supported currently only by the 3.5.4 FIPS provider and later
 versions.=C2=A0 Currently 3.5.4 is undergoing review with our lab and NIST=
:<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal"><a href=3D"https://urldefense.com/v3/__https:/csrc.n=
ist.gov/projects/cryptographic-module-validation-program/modules-in-process=
/modules-in-process-list__;!!FJ-Y8qCqXTj2!bZut-uZon_VIGux_15WX7wQQlDCz2htlQ=
H38Q5r93kD1FyyfFNGBYigp6MnOcctxqdvCUvGlZbPhhLscJuPv$" target=3D"_blank" rel=
=3D"nofollow" data-saferedirecturl=3D"https://www.google.com/url?hl=3Den-GB=
&amp;q=3Dhttps://urldefense.com/v3/__https:/csrc.nist.gov/projects/cryptogr=
aphic-module-validation-program/modules-in-process/modules-in-process-list_=
_;!!FJ-Y8qCqXTj2!bZut-uZon_VIGux_15WX7wQQlDCz2htlQH38Q5r93kD1FyyfFNGBYigp6M=
nOcctxqdvCUvGlZbPhhLscJuPv$&amp;source=3Dgmail&amp;ust=3D1777560866398000&a=
mp;usg=3DAOvVaw36Pi8Np9XD7O7r-hD--Kng">https://csrc.nist.gov/projects/crypt=
ographic-module-validation-program/modules-in-process/modules-in-process-li=
st</a><u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">=C2=A0<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">=C2=A0<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">FIPS and PQC are definitely=C2=A0_not_ mutually excl=
usive, you can definitely=C2=A0use both PQC algorithms and be FIPS-140-3 co=
mpliant.=C2=A0 The only current barrier is that our provider has
 not yet been certified by NIST.=C2=A0 That need not be a barrier for you h=
owever, if you are planning on doing a full submission of openssl through y=
our own lab (though the time effort on that is constrained by your lab and =
NIST).<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">=C2=A0<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">Neil<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">=C2=A0<u></u><u></u></p>
</div>
</div>
<p class=3D"MsoNormal">=C2=A0<u></u><u></u></p>
<div>
<div>
<p class=3D"MsoNormal">On Wed, Apr 15, 2026 at 9:43<span style=3D"font-fami=
ly:&quot;Arial&quot;,sans-serif">=E2=80=AF</span>AM Raghu Chidambaram &lt;<=
a href data-email-masked rel=3D"nofollow">[email protected]</a>&gt; wrot=
e:<u></u><u></u></p>
</div>
<blockquote style=3D"border:none;border-left:solid #cccccc 1.0pt;padding:0c=
m 0cm 0cm 6.0pt;margin-left:4.8pt;margin-top:5.0pt;margin-right:0cm;margin-=
bottom:5.0pt">
<p class=3D"MsoNormal">Hi Team,<u></u><u></u></p>
<div>
<p class=3D"MsoNormal">=C2=A0<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">Our organization is planning to go for PQC support s=
o that application is quantum safe.<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">we are already FIPS 140-2 compliant and we are also =
in the process of making it FIPS 140-3 compliant as 140-2 will be sunset by=
 Sep 2026.<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">=C2=A0<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">FIPS<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">- Our application is FIPS 140-2 and with FIPS provid=
er 3.0.9. We made this possible with the help of lot of to and fro discussi=
ons over the OpenSSL Forum for good amount of time
 :) :) .<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">=C2=A0<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">For 140-3 we did analysis and understood that with O=
penSSL version say 3.5.x we need to bundle the FIPS provider version 3.1.2 =
( 140-3 compliant ) instead of 3.0.9( 140-2) compliant.
 Hope this is correct.<br>
<br>
PQC<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">- For PQC we just started analysis and checking whic=
h all algorithms we need to use in order to make it PQC compliant. As part =
of this we want to understand which of OpenSSL supports
 PQC and is there any doc / list which conveys like from algorithm A we nee=
d to move to algorithm, means how to migrate from current set to PQC safe s=
et is what we are checking mainly.=C2=A0<br>
<br>
- one more point what we understood from the discussions internally and wit=
h the teams who are handling inside our organization that FIPS and PQC cant=
 go hand in hand, like if we are in FIPS 140-3 version we cant claim for PQ=
C as algo&#39;s are different and if
 we are going to be PQC safe then we can&#39;t claim FIPS 140-3 support, is=
 this correct statement? or our assumption is wrong?<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">=C2=A0<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">Need your help and inputs to proceed on these aspect=
s=C2=A0<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">=C2=A0<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">Thank you,<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">Raghu<u></u><u></u></p>
</div>
<p class=3D"MsoNormal">--
<br>
You received this message because you are subscribed to the Google Groups &=
quot;openssl-users&quot; group.<br>
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to
<a href data-email-masked rel=3D"nofollow">[email protected]</a>.=
<br>
To view this discussion visit <a href=3D"https://urldefense.com/v3/__https:=
/groups.google.com/a/openssl.org/d/msgid/openssl-users/9d605db8-9220-491c-9=
424-12b42ed92948n*40openssl.org?utm_medium=3Demail&amp;utm_source=3Dfooter_=
_;JQ!!FJ-Y8qCqXTj2!bZut-uZon_VIGux_15WX7wQQlDCz2htlQH38Q5r93kD1FyyfFNGBYigp=
6MnOcctxqdvCUvGlZbPhhPVv707z$" target=3D"_blank" rel=3D"nofollow" data-safe=
redirecturl=3D"https://www.google.com/url?hl=3Den-GB&amp;q=3Dhttps://urldef=
ense.com/v3/__https:/groups.google.com/a/openssl.org/d/msgid/openssl-users/=
9d605db8-9220-491c-9424-12b42ed92948n*40openssl.org?utm_medium%3Demail%26ut=
m_source%3Dfooter__;JQ!!FJ-Y8qCqXTj2!bZut-uZon_VIGux_15WX7wQQlDCz2htlQH38Q5=
r93kD1FyyfFNGBYigp6MnOcctxqdvCUvGlZbPhhPVv707z$&amp;source=3Dgmail&amp;ust=
=3D1777560866398000&amp;usg=3DAOvVaw0i8A3IbtRa20jnwtPsy4cR">
https://groups.google.com/a/openssl.org/d/msgid/openssl-users/9d605db8-9220=
-491c-9424-12b42ed92948n%40openssl.org</a>.<u></u><u></u></p>
</blockquote>
</div>
</div>
</div>
<div>
<div>
<p class=3D"MsoNormal">--
<br>
You received this message because you are subscribed to the Google Groups &=
quot;openssl-users&quot; group.<br>
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to
<a href data-email-masked rel=3D"nofollow">[email protected]</a>.=
<u></u><u></u></p>
</div>
</div>
<div>
<div>
<p class=3D"MsoNormal">To view this discussion visit
<a href=3D"https://urldefense.com/v3/__https:/groups.google.com/a/openssl.o=
rg/d/msgid/openssl-users/CAJbOq16tR2n_U1tWtzbCUzt57PjEZQbiJRjvM-3vPQ3gkrGyX=
A*40mail.gmail.com?utm_medium=3Demail&amp;utm_source=3Dfooter__;JQ!!FJ-Y8qC=
qXTj2!bZut-uZon_VIGux_15WX7wQQlDCz2htlQH38Q5r93kD1FyyfFNGBYigp6MnOcctxqdvCU=
vGlZbPhhA0Qq6iv$" target=3D"_blank" rel=3D"nofollow" data-saferedirecturl=
=3D"https://www.google.com/url?hl=3Den-GB&amp;q=3Dhttps://urldefense.com/v3=
/__https:/groups.google.com/a/openssl.org/d/msgid/openssl-users/CAJbOq16tR2=
n_U1tWtzbCUzt57PjEZQbiJRjvM-3vPQ3gkrGyXA*40mail.gmail.com?utm_medium%3Demai=
l%26utm_source%3Dfooter__;JQ!!FJ-Y8qCqXTj2!bZut-uZon_VIGux_15WX7wQQlDCz2htl=
QH38Q5r93kD1FyyfFNGBYigp6MnOcctxqdvCUvGlZbPhhA0Qq6iv$&amp;source=3Dgmail&am=
p;ust=3D1777560866398000&amp;usg=3DAOvVaw2cVpggFyro1jX2z_H0uU2Y">
https://groups.google.com/a/openssl.org/d/msgid/openssl-users/CAJbOq16tR2n_=
U1tWtzbCUzt57PjEZQbiJRjvM-3vPQ3gkrGyXA%40mail.gmail.com</a>.<u></u><u></u><=
/p>
</div>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><i>Any email and file=
s/attachments transmitted with it are intended solely for the use of the in=
dividual or entity to whom they are addressed. If this message has been sen=
t to you in
 error, you must not copy, distribute or disclose of the information it con=
tains.
<u>Please notify Entrust immediately and delete the message from your syste=
m.</u></i><u></u><u></u></p>
</div>
</blockquote>
</div>
</blockquote>
</div>
</div>
</div>
</blockquote>
</div>
</blockquote>
</div>
</div></div></blockquote></div>

<p></p>

-- <br />
You received this message because you are subscribed to the Google Groups &=
quot;openssl-users&quot; group.<br />
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to <a href=3D"mailto:openssl-users+unsubscribe-MCmKBN63+BlAfugRpC6u6w@public.gmane.org">openssl-us=
[email protected]</a>.<br />
To view this discussion visit <a href=3D"https://groups.google.com/a/openss=
l.org/d/msgid/openssl-users/39f1651d-5785-43d8-bbb1-41bbde296fefn%40openssl=
.org?utm_medium=3Demail&utm_source=3Dfooter">https://groups.google.com/a/op=
enssl.org/d/msgid/openssl-users/39f1651d-5785-43d8-bbb1-41bbde296fefn%40ope=
nssl.org</a>.<br />

------=_Part_377075_1701704293.1777474583217--

------=_Part_377074_796924974.1777474583217--