OpenSSL Communities
Wed 30 Jul 2025 1:45PM

FIPS self-test refactoring

DB Dmitry Belyavsky Public Seen by 21

OpenSSL 3.5 brings post-quantum algorithms in FIPS provider.
Unfortunately, it means significant slow-down of FIPS startup (especially because of SLH-DSA variants).

The way forward we see is refactoring of FIPS POST so the algorithms would be tested on demand (on fetch). I would like to get feedback from the distro and large business communities and put it to the TAC agenda