The following appears in the FIPS 140-2 Validation presentation from Linux World Expo. (oss-institute.org/OpenSSL/LWE_040406_BOF.pdf)

 

Page 23: FIPS mode requirements:

* The application must use only OpenSSL for all cryptography.

 

Where can I find this in the security policy?

 

Are there any exceptions?  What if “other crypto” is also FIPS validated?

 

What is the purpose of the requirement?

 

 

Reply via email to