Hello,

In appendix B of the openssl FIPS security policy it is stated that the module 
must be built with a particular tar file (openssl-fips-1.1.2.tar.gz) and a hmac 
hash value for the tar file is specified. Furthermore it is stated that there 
shall be no additions, deletions, or alterations of the set of files in the tar 
file as used during module build.

The way I read this is that if you modify for instance the ASN.1 or SSL code 
(in order to fix a bug), then the FIPS validation is canceled. This does not 
make sense to me. Why can't higher level code be bug fixed without FIPS 
validation being canceled?

/Roger
_________________________________________________________________
Var sommaren för kort? Här hittar du solen!
http://resor.se.msn.com/______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    openssl-users@openssl.org
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to