Re: Building FIPS-capable OpenSSL as a universal binary on Mac OS X

2010-10-14 Thread aerowolf
On Wed, Oct 13, 2010 at 5:32 PM, Bill Durant wrote: That may not be sufficient, can ldfips be modified(?), it's certainly needed to link static to the fips canister.  I'd put your energies into building a dylib which would give you a smidge more flexibility. fipsld can be modified, as it is

Re: Building FIPS-capable OpenSSL as a universal binary on Mac OS X

2010-10-14 Thread William A. Rowe Jr.
On 10/13/2010 7:22 PM, Bill Durant wrote: > > On Oct 13, 2010, at 5:19 PM, William A. Rowe Jr. wrote: >> On 10/13/2010 3:31 PM, Bill Durant wrote: >>> >>> I am interested in building the static version of the FIPS-capable OpenSSL >>> as an universal >>> binary. >> >> Three builds, per spec, of th

Re: Building FIPS-capable OpenSSL as a universal binary on Mac OS X

2010-10-14 Thread William A. Rowe Jr.
On 10/13/2010 3:31 PM, Bill Durant wrote: > > I am interested in building the static version of the FIPS-capable OpenSSL as > an universal > binary. Three builds, per spec, of the FIPS canister. No tweaks, no exceptions to the security policy. Then it's possible but non-trivial to integrate th

Re: Building FIPS-capable OpenSSL as a universal binary on Mac OS X

2010-10-13 Thread Bill Durant
On Oct 13, 2010, at 5:27 PM, William A. Rowe Jr. wrote: On 10/13/2010 7:22 PM, Bill Durant wrote: On Oct 13, 2010, at 5:19 PM, William A. Rowe Jr. wrote: On 10/13/2010 3:31 PM, Bill Durant wrote: I am interested in building the static version of the FIPS- capable OpenSSL as an universal bi

Re: Building FIPS-capable OpenSSL as a universal binary on Mac OS X

2010-10-13 Thread Bill Durant
On Oct 13, 2010, at 5:19 PM, William A. Rowe Jr. wrote: On 10/13/2010 3:31 PM, Bill Durant wrote: I am interested in building the static version of the FIPS-capable OpenSSL as an universal binary. Three builds, per spec, of the FIPS canister. No tweaks, no exceptions to the security p