提交 161cc82d 编写于 作者: D Dr. Stephen Henson

updated FIPS status

上级 42bd0a6b
...@@ -44,11 +44,14 @@ Known issues: ...@@ -44,11 +44,14 @@ Known issues:
Algorithm tests are pre-2011. Algorithm tests are pre-2011.
The fipslagtest.pl script wont auto run new algorithm tests such as DSA2. The fipslagtest.pl script wont auto run new algorithm tests such as DSA2.
Usage of ECDH/DH needs review and adding appropriate self tests. Usage of ECDH/DH needs review and whether any KDFs need to be implemented.
Selftests need updating with larger key sizes in some cases and redundant Selftests need updating with larger key sizes in some cases and redundant
tests pruned. tests pruned.
SP800-90 DRBG needs more work: health checks, continuous PRNG test, SP800-90 DRBG needs more work: check for compliance, continuous PRNG test
entropy gathering, security checks in algorithms, add appropriate RAND method when entropy gathering, periodic health tests.
for use by rest of OpenSSL. Some algorithms need to check security strength of PRNG: keygen etc.
No CMAC.
No CCM. No CCM.
No XTS.
The "FIPS capable OpenSSL" is not yet complete: meaning that the rest of
OpenSSL doesn't always use the correct FIPS module APIs and block others
in FIPS mode.
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册