Skip to content
Discussion options

You must be logged in to vote

The answer to questions 1 and 2 are "you need to ask your validation lab". The openssl security policy expressly states that the fipsinstall command must be used to generate the fipsmodule.cnf file. It would be a determination for your lab to make as to weather or not re-implementing that command within your application is sufficiently non-intrusive to avoid any needed retesting.

As to question (3), assuming the answer from your lab to (1) and (2) is "sure, thats ok", is found in the fipsinstall_main function in the apps folder of your source tree. That function contains the needed operations to implement what the fipsinstall command does.

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by paulidale
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants