As long as you compile the linked openssl with a fipscanister that's
created in accordance with the Security Policy, yes.

Remember, FIPS was developed around non-software crypto.  You're
creating and delivering a black box piece of code for delivery to the
customer.

-Kyle H

On 7/18/2014 8:48 AM, Arthur Tsang wrote:
> Hi all,
>
> My team is using Nodejs and we just released an instruction on how to
> compile nodejs with openssl with the object module.  A customer
> doesn't want to do that and my question is, if we are shipping a
> custom nodejs compiled with openssl with fips mode on, does it still
> compliant to the security policy?  
>
> -- 
> Thanks,
> Arthur


Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

Reply via email to