Linux in Government: In Spite of Endorsements, Government Linux Projects Still Treading Water

Tom Adelstein <[email protected]> Fri, 29 Oct 2004 10:26:01 -0500
Newsgroups gmane.linux.usage.government
Message-ID <[email protected]>
In the government units I monitor and on projects on which I work, some of which have have disclosure restrictions, I'm finding hesitation to break over to Linux. In spite of the fact that the project have approval. So, I'm pleased to see all the press about the UK initiative, but the news reports do not mean the work is over. 
I especially look at Munich. Many people still consider it a success. When will it start?

I also want to point out a message from the Open Source Software Institute that prompted this article, this week.

http://www.linuxjournal.com/article.php?sid=7872

I hope this will bring you closer to the issues.


> DATE:   WED, OCT. 27, 2004
> 
> TO:     OSSI OpenSSL Update List
> 
> From:   jmw, OSSI Executive Director
> 
> RE:    Please Contact NIST/CSE, Voice Your Support of OpenSSL/FIPS
> 140-2
> 
> --------------------------------------------------------------------
> 
> As you are all aware, OSSI has been working with various DoD and
> industry organizations to secure the FIPS 140-2 validation for
> OpenSSL.
> We have been engaged in this process for nearly two years, and now we
> are patiently waiting (nearly six (6) months) a decision from NIST and
> CSE on the final validation or rejection of the FIPS 140-2 validation
> for OpenSSL.
> 
> We receive inquiries daily from government and industry
> representatives
> asking for an update on the process. However, OpenSSL has been
> "stalled"
> in the "Coordination" stage since early summer. 
> 
> http://csrc.nist.gov/cryptval/140PreVal.pdf
> 
> 
> We have reason to believe that NIST/CSE are being lobbied by some
> established vested interests opposed to this validation because of the
> impact it would have on their existing revenue model.  
> 
> Therefore, we would like for you, as representatives of industry,
> government and concerned community members, to let your voices be
> heard
> and demonstrate to NIST/CSE that there are many more commercial and
> governmental entities that stand to benefit from the validation of
> OpenSSL than the special interest that currently enjoy a stranglehold
> on
> this process.
> 
> 
> NIST has provided preliminary approval for all algorithms, so the bulk
> of the validation process has been completed and approved.  Below are
> links to the NIST/CSE certifications received: 
> 
> Advanced Encryption Standard (AES) Algorithm: Certification #146 
> http://csrc.nist.gov/cryptval/aes/aesval.html
> 
> Data Encryption Standard (DES) Validated Implementations: Cert #258 
> http://csrc.nist.gov/cryptval/des/desval.html
> 
> Triple Data Encryption Algorithm (TDEA, a.k.a. "Triple DES"): Cert
> #256 
> http://csrc.nist.gov/cryptval/des/tripledesval.html
> 
> Digital Signature Algorithm (DSA) Validation System: Cert #108  
> http://csrc.nist.gov/cryptval/dss/dsaval.htm
> 
> Secure Hash Algorithm (SHS) Validation System: Cert #235
> http://csrc.nist.gov/cryptval/shs/shaval.htm
> 
> 
> WE NEED YOUR SUPPORT -- NOW -- PLEASE LET YOUR VOICE BE HEARD
> 
> We would like for you, as representatives of industry and government
> (where appropriate), to contact NIST/CSE directly and express your
> support for the approval of the FIPS 140-2 Validation for OpenSSL.
> 
> NIST has been EXTREMELY professional and heads up during the entire
> process, but we wish for them to see the huge demand for the
> validation
> of OpenSSL. 
> 
> The NIST contacts are:
> 
> Randall (Randy) J. Easter
> Director, CMVP
> National Institute of Standards and Technology
> 100 Bureau Drive, Stop 8930
> Gaithersburg, MD 20899-8930
> [email protected]
> (301) 975-4641 (voice)
> (301) 975-4964 (fax)
> 
> 
> His counterpart at the CSE 
> 
> Jean Campbell
> Director, CSE CMVP
> Canadian Central Facility (T1B)
> Communications Security Establishment
> P.O. Box 9703, Terminal
> Ottawa, Canada. K1G 3Z4
> [email protected]
> (613) 991-8121
> 
> 
> Please contact them (notes on letterhead and email) and express your
> support for this project.  It is critical that they see the demand
> hear
> from a wide variety of sources how important this validation is to the
> government and industry.
> 
> 
> Again, NIST/CSE are doing a great job, but they need to hear your
> desires and concerns regarding this project.  Now is the time to let
> them know.
> 
> Thank you for your continued support.
> 
> Regards,
> jmw
> 
> 
> 
> 
> -- 
> John M. Weathersby, Jr.
> Executive Director
> Open Source Software Institute