[110454] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: Flaws in OpenSSL FIPS Object Module

daemon@ATHENA.MIT.EDU (Steven M. Bellovin)
Tue Dec 11 13:23:05 2007

Date: Mon, 10 Dec 2007 19:49:44 +0000
From: "Steven M. Bellovin" <smb@cs.columbia.edu>
To: Vin McLellan <vin@theworld.com>
Cc: cryptography@metzdowd.com
In-Reply-To: <200712101628.lBAGSYqM020475@TheWorld.com>

On Mon, 10 Dec 2007 11:27:10 -0500
Vin McLellan <vin@theworld.com> wrote:

> 
> What does it say about the integrity of the FIPS program, and its
> CMTL evaluation process, when it is left to competitors to point out
> non-compliance of evaluated products -- proprietary or open source --
> to basic architectural requirements of the standard?
> 
"Integrity" or "ability"?  We all know that finding problems in code or
architecture is *very* hard.  


		--Steve Bellovin, http://www.cs.columbia.edu/~smb

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post