> On 4 Dec 2024, at 15:40, Joe Conway <m...@joeconway.com> wrote: > > On 12/4/24 09:33, Daniel Gustafsson wrote: >> since OpenSSL 1.1.1 cannot operate in FIPS mode. > > I don't think that is correct. The RHEL 8 openssl which was FIPS 140-2 > validated is 1.1.1k. See: > > https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/security-policies/140sp4642.pdf
Does RHEL publish the source of their fork somewhere? In OpenSSL 1.1.1 the code for FIPS_mode is: int FIPS_mode(void) { /* This version of the library does not support FIPS mode. */ return 0; } Do you know if RHEL patched OpenSSL to allow FIPS_mode() to return other than 0 or if that function is useless regardless? -- Daniel Gustafsson