Is Explicit self-test needed for openssl 3.1.2 (FIPS 140-3).

24 views
Skip to first unread message

omi jha

unread,
Aug 7, 2025, 1:42:36 AMAug 7
to openssl-users
Hi,
I recently upgraded to from 3.0.9 to openssl 3.1.2 (FIPS 140-3), I was using self test explicitly for FIPS module  in my code. After upgrading to Openssl 3.1.2 (FIPS 140-3) , do we still require explicit self-test or it does internally , shall i remove it  form my code? Any reference/link which talks about this would be helpful.

Thanks,
Om

Tomas Mraz

unread,
Aug 8, 2025, 5:48:16 AMAug 8
to omi jha, openssl-users
It was never necessary to call FIPS self tests explicitly with our FIPS
modules. If you want to use the OpenSSL FIPS module(s) in FIPS
compliant way, please always refer to the respective FIPS Security
Policy document of the particular module that you can find on the NIST
FIPS module web site.

Regards,

Tomas Mraz, Public Support and Security Manager, OpenSSL Foundation
> --
> You received this message because you are subscribed to the Google
> Groups "openssl-users" group.
> To unsubscribe from this group and stop receiving emails from it,
> send an email to openssl-user...@openssl.org.
> To view this discussion visit
> https://groups.google.com/a/openssl.org/d/msgid/openssl-users/afa87e00-6cbf-4290-a14d-f8b3fcc9e064n%40openssl.org
> .

--
Tomáš Mráz, Public Support and Security Manager, OpenSSL Foundation
Join the Code Protectors or support us on Github Sponsors
https://openssl-foundation.org/donate/

Reply all
Reply to author
Forward
0 new messages