Skip to content

recommended way to do created fipsmodule.cnf file on client machine. #21490

Closed Answered by paulidale
aniljadaun asked this question in Q&A
Discussion options

You must be logged in to vote

The README-FIPS.md file is also useful.

As per the security policy, you should create the fipsmodule.cnf file on the client machine. Not doing so isn't strictly FIPS compliant. The instructions for doing this are in the security policy (the latest version should always be linked from the download page). Look in the policy's first appendix. Essentially, you should run the openssl fipsinstall command on the client to do this.

Also note that currently only OpenSSL 3.0.0 and 3.0.8 have had their FIPS provider validated. Any other version will not produce a compliant FIPS provider. However, you can use any version of OpenSSL (3.0.x or 3.1.x) with either of these FIPS providers. Instructions fo…

Replies: 2 comments 3 replies

Comment options

You must be logged in to vote
1 reply
@aniljadaun
Comment options

Answer selected by aniljadaun
Comment options

You must be logged in to vote
2 replies
@aniljadaun
Comment options

@paulidale
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants