summaryrefslogtreecommitdiffstats
path: root/README.FIPS
diff options
context:
space:
mode:
authorDr. Stephen Henson <steve@openssl.org>2011-02-23 16:06:50 +0000
committerDr. Stephen Henson <steve@openssl.org>2011-02-23 16:06:50 +0000
commit8aa6cff40fa392c993929a1661cc4ca66f3f5a8f (patch)
treee16a6ec44150128093ffc711308e3ada677d0c56 /README.FIPS
parent949c6f8ccf76be7367de4638ae948266179f696e (diff)
Update status information.
Diffstat (limited to 'README.FIPS')
-rw-r--r--README.FIPS21
1 files changed, 17 insertions, 4 deletions
diff --git a/README.FIPS b/README.FIPS
index 2829bf789b..5e3b5ab79c 100644
--- a/README.FIPS
+++ b/README.FIPS
@@ -28,13 +28,26 @@ Run test vectors:
4. It should say "passed all tests" at the end. Report full details of any
failures.
+Run symbol hiding test:
+
+./config fipscanisteronly -DOPENSSL_FIPSSYMS
+make
+
+This time only the fips utilities should be built.
+
+Examine the external symbols in fips/fipscanister.o they should all begin
+with FIPS or fips. One way to check with GNU nm is:
+
+nm -g --defined-only fips/fipscanister.o | grep -v -i fips
Known issues:
-No Windows support.
Algorithm tests are pre-2011.
+The fipslagtest.pl script wont auto run new algorithm tests such as DSA2.
+No ECDH.
+No primitives tests for ECDH/DH
+Selftests need updating with larger key sizes in some cases and redundant
+tests pruned.
No SP800-90 PRNG.
-No ECDSA2 support.
-No DSA2 support: work in progress.
-No GCM.
No CMAC.
+No CCM.