The openssl fipsinstall command fails if the default provider is not
enabled. Is it expected or is it a bug?
openssl.cnf:
...
[openssl_init]
providers = provider_sect
[provider_sect]
base = base_sect
[base_sect]
activate = 1
...
LD_LIBRARY_PATH=/usr/local/lib64 /usr/local/bin
Hi,
When I run
openssl ciphers -v -provider fips | grep TLS_CHACHA20_POLY1305_SHA256
it shows this non complain cipher is available. To add '-propquery
fips=yes' argument does not help. IMHO it is not correct behavior.
I have the default and fips providers enabled in openssl.cnf:
ope
up to date.
I'll try to build openssl with gcc and reproduce your issue.
regards,
--
Jan Lana | Systems Security Compliance and Globalization
Phone: +420 221 438 800
Oracle Czech, U Trezorky 921/2, 158 00 Praha 5, Czech Republic