Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [ISN] OpenSSL gets NIST certifications |
|---|---|
| Date: | Tue, 24 Jan 2006 00:30:20 -0600 (CST) |
http://www.gcn.com/vol1_no1/daily-updates/38074-1.html By Joab Jackson GCN Staff 01/23/06 Agencies setting up sensitive virtual private networks now have an open-source alternative. The National Institute of Standards and Technology has certified OpenSSL, an open-source library of encryption algorithms, as meeting Federal Information Processing Standard 140-2 Level 1 standards, according to the Open Source Software Institute of Hattiesburg, Miss. "This validation will save us hundreds of thousands of dollars," said Debora Bonner, operations director for the Defense Department's Defense Medical Logistics Standard Support program, in a statement. "Multiple commercial and government entities, including [the Defense Department's] Medical Health System, have been counting on this validation to avoid massive software licensing expenditures." Federal agencies must use FIPS-compliant products to secure networks carrying unclassified sensitive data. The FIPS certification of OpenSSL opens the possibility of using an SSL-based VPN to carry sensitive data, according to Peter Sargent, who heads the Severna Park, Md.-based PreVal Specialist Inc., one of the companies that supported the validation process. Traditionally, agencies wishing to set up a VPN for sensitive data would use an approach that involved a secret key implementation of a cryptographic module, which is more expensive to implement and has limited the number of smaller companies that can provide such a product, Sargent said. Sargent added that few agencies would directly deploy OpenSSL FIPS. Rather, they would purchase OpenSSL-based VPN products from vendors. To accompany the release, OSSI has published a guidebook, The OpenSSL Security Policy Version 1.0, describing how the OpenSSL cryptographic module works in relation to FIPS 140-2 requirements. The organization also plans to issue a users' guide within two weeks, according to John Weathersby, executive director of OSSI. Agencies will also find support from a December 2005 update of NIST's Implementation Guidance for FIPS PUB 140-2 and the Cryptographic Module Validation Program. The document addresses how users can deploy a program with FIPS modules across multiple platforms. The cryptographic module of OpenSSL (SSL stands for Secure Sockets Layer) consists of an open-source implementation of SSL encryption - originally created by Netscape Communications Corp. - as well as a Transport Layer Security module. SSL and TLS are security protocols that browsers and other software can utilize to encrypt and decrypt Web pages and sensitive data. In order to be FIPS-approved, it is necessary to limit the SSL-based implementation to the TLS mode, Sargent said. The volunteer-led OpenSSL project oversees the development of OpenSSL. The team has made the module and source code available at the project's Web site under an Apache-style license permitting free noncommercial use. NIST validated the library cryptographic module contained in Version 0.9.7j of OpenSSL-FIPS as a validation process only for encryption modules, not entire software packages. The OpenSSL-FIPS library cryptographic module uses the Advanced Encryption Standard, the Data Encryption Standard, the Digital Signature Algorithm, FIPS-mode RSA for signatures, as well as the FIPS-qualified approved Secure Hash Algorithm-1, or SHA-1. In addition to PreVal, OSSI and DMLSS, Hewlett-Packard Co. of Palo Alto, Calif., and the Domus IT Security Laboratory of Ottawa sponsored the FIPS testing for OpenSSL. _________________________________ InfoSec News v2.0 - Coming Soon! http://www.infosecnews.org
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [ISN] Contractors told to relax about BlackBerry, InfoSec News |
|---|---|
| Next by Date: | [ISN] Oracle no longer a 'bastion of security': Gartner, InfoSec News |
| Previous by Thread: | [ISN] Contractors told to relax about BlackBerry, InfoSec News |
| Next by Thread: | [ISN] Oracle no longer a 'bastion of security': Gartner, InfoSec News |
| Indexes: | [Date] [Thread] [Top] [All Lists] |