RE: OpenSSL FIPS Query

2007-07-21 Thread David McKinley
Ramaniganth, I worked on enhancing net-snmp to work with OpenSSL in FIPS mode a few months ago. After seeming to get it to work, the project was shelved, so the code never got published. But, I can tell you the approach I took. First, I would echo the advice from David Schwartz to carefully r

RE: OpenSSL FIPS Query

2007-07-21 Thread David Schwartz
> NetSNMP is the open source SNMP management Kit which uses OpenSSL Libcrypto. > I would like to know what changes I have to make in the NetSnmp to > access the FIPS compatible OpenSSL Libraries. Go to this web page: http://www.openssl.org/docs/fips/ Download and read the user's guide and securit

OpenSSL FIPS Query

2007-07-21 Thread ramani.ganth
Hi, NetSNMP is the open source SNMP management Kit which uses OpenSSL Libcrypto. I would like to know what changes I have to make in the NetSnmp to access the FIPS compatible OpenSSL Libraries. Thanks Ramaniganth V.S. Nortel : 6-877-8976 Wipro : +91-80-28520408 Xtn: 81109 Mobile: +91-997222709

Re: LDAP instead of /etc/ssl/certs ?

2007-07-21 Thread Bernhard Froehlich
Mark H. Wood schrieb: [...] (think what would happen if you were to look up these certificates somewhere other than locally, and someone were to spoof the DNS entry... since you are looking up these certificates to make a trust decision, it would be possible for an attacker to