README.wishlist 1.0 KB

12345678910111213141516171819202122232425262728293031
  1. A "wish list" of changes we'd like to make to the FIPS module if we could.
  2. Note the CMVP requires retesting of all previously tested platforms
  3. ("Operational Environments") to implement any changes considered "cryptographically
  4. significant". Since the OpenSSL FIPS module v2.0 has some 250 such formally
  5. tested platforms (and counting), retesting just isn't logistically or economically
  6. feasible.
  7. --------
  8. https://github.com/openssl/openssl/pull/4157
  9. From 2017-08-14, Fix GCM MAC computation for AES-GCM by srahul123
  10. cryptographically significant, not fixable
  11. --------
  12. Andy Polyakov: harmonize with __thumb__ clause in FIPS_ref_point() (#3354),
  13. https://patch-diff.githubusercontent.com/raw/openssl/openssl/pull/3354.patch
  14. https://github.com/openssl/openssl/pull/3354#pullrequestreview-36086406
  15. May be possible to introduce in future change letter
  16. --------
  17. CVE-2016-0701
  18. cryptographically significant, not fixable
  19. --------
  20. CVE-2014-0076
  21. cryptographically significant, not fixable
  22. --------
  23. "Lucky 13", CVE-2013-0169
  24. cryptographically significant, not fixable
  25. --------