[openssl-users] SP800-90 DRBG in OpenSSL FIPS 140 for SP800-90A?

xxiao8 xxiao8 at fosiao.com
Sat Mar 21 18:48:15 UTC 2015


At the moment OpenSSL FIPS validation supports ANSI X9.31 with AES128 
for RNG, however it will be outdated in 2015.

Another alternative RNG in OpenSSL FIPS is SP800-90 DRBG, however the 
new requirement is to use DRBG per SP800-90A.

Are the DRBGs in SP800-90/OpenSSL-FIPS-2.0.9 the same as what SP800-90A 
requires? Otherwise how can OpenSSL 2.0 FIPS be used in any new validations?

Thanks,
xxiao



More information about the openssl-users mailing list