Hacker News new | ask | show | jobs
by snazz 2576 days ago
This is not a priority at all for the OpenBSD developers. Most of them are Canadian anyway, as I understand it.
2 comments

That is actually understating it. The libressl developers purged the code base of the FIPS stuff as part of a policy. From here:

* https://marc.info/?l=openbsd-misc&m=139819485423701&w=2

"Note that FIPS mode isn't just worthless, it's actively harmful."

Unfortunately if you work with the US Government, there are situations where FIPS mode is required. This is why RHEL and CentOS still use OpenSSL...
Canada actually respects FIPS 140-2 certification (and cooperates in certifying implementations!), so this would very much be relevant in a Canadian context.