Slashdot Mirror


OpenSSL loses FIPS 140-2 Certification (Or Not)

OhHellWithIt writes "Government Computer News reported on Tuesday that OpenSSL has lost FIPS 140-2 certification, only six months after receiving it. It sounds like bad news for those of us who would like to see open source gain more of a foothold in U.S. federal workplaces." Readers have updated this story with an update saying the certification has shifted again.

1 of 102 comments (clear)

  1. Reasons Not Given? by mr_rattles · · Score: 5, Insightful

    "The CMVP does not provide information regarding the status or reason as in many cases it may be proprietary"

    This is one of the most ridiculous statements I've ever read. How is the problem supposed to be fixed if the vendor is never told what the problem is, and so what if it's proprietary? When I read a statement like this it suggests to me that there's doesn't have to be a method behind how they determine what's rejected and what's not, the person(s) deciding could have simply had a proprietary "I'm in a bad mood today and want to take it out on someone" reason.