Re: RHEL rpm and FIPS validation

2013-11-07 Thread Robert W Weaver
Steve Marquess wrote on 11/07/2013 09:02:05 AM: > > Is there a basis for asserting FIPS 140 validation with > > openssl-0.9.8e-26.el5_9.1|(none), or must the original RPM be used? > > You'll need to ask Red Hat; it's their proprietary validation. From a > quick glance it appears to be a knock-of

Re: RHEL rpm and FIPS validation

2013-11-07 Thread Steve Marquess
On 11/07/2013 08:39 AM, Robert W Weaver wrote: > Greetings, > > Apologies if this has been covered before, but I couldn't find it in a > search. > > I'm trying to deploy FIPS 140 validated crypto to a RHEL 5 box as part > of a FISMA covered project. > > I think the relevant policy is > htt

RHEL rpm and FIPS validation

2013-11-07 Thread Robert W Weaver
Greetings, Apologies if this has been covered before, but I couldn't find it in a search. I'm trying to deploy FIPS 140 validated crypto to a RHEL 5 box as part of a FISMA covered project. I think the relevant policy is http://csrc.nist.gov/groups/STM/cmvp/documents/140-1/140sp/140sp1320