1 Dec 2007 02:21
Re: OpenSSL FIPS Object Module v1.2
Kyle Hamilton <aerowolf <at> gmail.com>
2007-12-01 01:21:25 GMT
2007-12-01 01:21:25 GMT
On Nov 30, 2007 11:33 AM, Steve Marquess <marquess <at> oss-institute.org> wrote: > Brad House wrote: > >> Brad, sorry, I didn't mean to come across as negative. The point I was > >> trying to make is that once a validation starts I can't afford to delay > >> it to deal with problems that are discovered in the already frozen > >> baseline, unless those problems are critical to the requirements of the > >> paying sponsors. Hence we don't solicit general public input for > >> in-process validations. ... > > Yes, that is understandable. Any code going through validation at that > > time cannot be touched. I think what Kyle asked for was prior to the > > next validation starting, a 2-week window where people could provide > > patches. Basically a 'last-call', or at least some projected timelines > > for when it would be submitted so we know if the code is 'close-to-final' > > before we try to provide patches (at least portability patches as is > > my selfish concern). ...basically, yes. I don't particularly want in-validation input capability, since (as Steve M points out) it's pointless. However, I am honestly annoyed that there have been two validation cycles past without (still!) a working FIPS-validated module for the Intel Mac. I know that at least HPUX64 had the same issue (I know I've got the tag wrong, but you know to which I refer). This... well, honestly violates my sensibilities. I just want to have the opportunity to know that what is submitted will actually run on the platform I must use. > Well, a single two-week window is reasonable. In thinking through the > issue more I realize there is another reason I've not been anxious to > solicit patches form the whole world. The deadlines in the validation(Continue reading)
> I just want to have the opportunity to know that what is submitted
> will actually run on the platform I must use.
>
You best approach is to report problems (or provide patches) for the
head of OpenSSL-fips-0_9_8-stable. That's where we'll start from when
and it there's another validation.
> ...
>
> Huh. You've just basically admitted that you have given up having any
RSS Feed