Page MenuHome GnuPG

Update fipsdrv and cavs_driver.pl
Open, NormalPublic

Description

For FIPS 140-3 support, we need to update things.
At least, we need:

  • fipsdrv
    • DSA with smaller Q is obsolete
    • Need to support DSA2VS with Q and hashalgo specified for FIPS 186-4 (update from FIPS 186-2 and 186-3)
  • cavs_driver.pl needs to be updated to support update of fipsdrv

Revisions and Commits

Event Timeline

gniibe triaged this task as Normal priority.Aug 3 2021, 4:46 AM
gniibe created this task.

SUSE has patches and version 3235 of cavs_driver.pl, bud it seems that it doesn't support DSA with Q+HASHALGO yet.

The CAVS driver can be safely removed. The certification goes through the ACVP these days so it does not make sense to keep this.

werner moved this task from Backlog to Next on the FIPS board.