Welcome!

Linux Authors: Gilad Parann-Nissany, Maureen O'Gara, Glenn Rossman, Hovhannes Avoyan, RealWire News Distribution

Related Topics: Linux

Linux: Article

OSSI Making Progress on NIST Certification of Open SSL

OSSI Making Progress on NIST Certification of Open SSL

In a press release earlier today, John Weathersby, Executive Director of the Open-Source Software Institute (OSSI) announced progress on getting the core cryptographic module of OpenSSL, which has been designated "OpenSSL Cryptographic Module v1.0," certified by the National Institute of Standards and Technology (NIST). Details and a FAQ are here .

Validation of this code is significant, because it's the first validation applicable at the source code level. By validating this source code, the door is opened to lower cost applications that require cryptography. The validation process is fairly long and complex, but the code has been submitted to the testing lab, and the vendor evidence package is expected to be at NIST at the beginning of the new year.

It's interesting to note that validation requires a certain level of stability for the code, not a feature commonly associated with Open Source projects. However, that issue has been addressed by segregating the relevant crypto algorithms in a special branch of the source tree. That way, the validated code can be maintained separately from the rest of OpenSSL, which is an actively maintained Open Source project.

The validation process is time consuming and expensive by Open Source standards, so the project is being supported by a group of participants, including the Defense Medical Logistics Standard Support Program (a DoD medical logistics program), HP, DOMUS IT Security Laboratory, PreVal Specialists, Inc and representatives from the OpenSSL Project.

More Stories By Dan Bent

Dan Bent, Linux.SYS-CON.com's health care and biotechnology editor, has been a network and operating systems consultant since 1989, including active participation in a leadership role in national organizations. In 1994, Dan joined Benefit Systems, Inc., a third-party administrator of employee benefits, as chief information officer. At Benefit Systems he designed and manages a heterogeneous network that includes Unix, Windows, NetWare, and open source elements in support of corporate objectives. In addition, Dan shares his expertise in using current technologies in the business support of hospitals, insurance companies, and other businesses, primarily in industries related to health care.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.