4 ms·
The problem with OpenSSL is that it's really problematic to simply fix and refactor stuff given their FIPS certification.
by thirsteh 13y ago
The problem with OpenSSL is that it's really problematic to simply fix and refactor stuff given their FIPS certification.
- leoc 13y agoOoh, OpenSSL's FIPS certification. The fellows who've been fighting for years to take it away http://www.itnews.com.au/News/65016,openssl-in-a-fips-flap.aspx http://www.itnews.com.au/News/65016,openssl-in-a-fips-flap.a... must be crowing right now. (Regardless of whether their own stuff is any better or no.) Another decertification incoming?
- crashandburn4 13y agoHi, can someone help me understand what the significance of FIPS certification is? ( beyond the wikipedia page: http://en.wikipedia.org/wiki/FIPS_140-2 http://en.wikipedia.org/wiki/FIPS_140-2 )
- leoc 13y agoAFAIK the US federal government (excluding the military, which obviously has its own hoops to jump through) generally can't use your hardware/software unless it has the appropriate FIPS certification(s). https://en.wikipedia.org/wiki/Federal_Information_Processing_Standards https://en.wikipedia.org/wiki/Federal_Information_Processing...