diff options
author | Dr. Stephen Henson <steve@openssl.org> | 2011-02-23 17:06:50 +0100 |
---|---|---|
committer | Dr. Stephen Henson <steve@openssl.org> | 2011-02-23 17:06:50 +0100 |
commit | 8aa6cff40fa392c993929a1661cc4ca66f3f5a8f (patch) | |
tree | e16a6ec44150128093ffc711308e3ada677d0c56 /README.FIPS | |
parent | Stop warnings. (diff) | |
download | openssl-8aa6cff40fa392c993929a1661cc4ca66f3f5a8f.tar.xz openssl-8aa6cff40fa392c993929a1661cc4ca66f3f5a8f.zip |
Update status information.
Diffstat (limited to 'README.FIPS')
-rw-r--r-- | README.FIPS | 21 |
1 files changed, 17 insertions, 4 deletions
diff --git a/README.FIPS b/README.FIPS index 2829bf789b..5e3b5ab79c 100644 --- a/README.FIPS +++ b/README.FIPS @@ -28,13 +28,26 @@ Run test vectors: 4. It should say "passed all tests" at the end. Report full details of any failures. +Run symbol hiding test: + +./config fipscanisteronly -DOPENSSL_FIPSSYMS +make + +This time only the fips utilities should be built. + +Examine the external symbols in fips/fipscanister.o they should all begin +with FIPS or fips. One way to check with GNU nm is: + +nm -g --defined-only fips/fipscanister.o | grep -v -i fips Known issues: -No Windows support. Algorithm tests are pre-2011. +The fipslagtest.pl script wont auto run new algorithm tests such as DSA2. +No ECDH. +No primitives tests for ECDH/DH +Selftests need updating with larger key sizes in some cases and redundant +tests pruned. No SP800-90 PRNG. -No ECDSA2 support. -No DSA2 support: work in progress. -No GCM. No CMAC. +No CCM. |