openssl / project

Tracking of project related issues
2 stars 1 forks source link

FIPS 140-3 updates #237

Open paulidale opened 1 year ago

paulidale commented 1 year ago

@ ICMC @t8m noted these items in a discussion with KeyPair:

Not noted:

### Tasks
- [ ] https://github.com/openssl/project/issues/245
- [ ] https://github.com/openssl/project/issues/243
- [ ] https://github.com/openssl/project/issues/242
- [ ] https://github.com/openssl/project/issues/223
- [ ] https://github.com/openssl/project/issues/238
- [ ] https://github.com/openssl/project/issues/239
- [ ] https://github.com/openssl/project/issues/240
- [ ] https://github.com/openssl/project/issues/241
paulidale commented 1 year ago

openssl/openssl#22256 adds MAC length enforcement for KMAC. HMAC is problematic because shorter lengths are allowed for legacy verification & we cannot distinguish.

paulidale commented 1 year ago

Also there is a tracker for outstanding items from our lab.

arapov commented 1 year ago

@paulidale, could you provide a ballpark estimate for the work detailed here and possibly break it down into separate tickets?

paulidale commented 1 year ago

Ha ha ha ha ha. Ты, должно быть, шутишь.

paulidale commented 1 year ago

See also this epic covering the FIPS 186-5 changes: openssl/project#263