|
|
|
|
|
by aisio
1854 days ago
|
|
"In OpenSSL 1.0.x, a quirk in certificate verification means that even clients that trust ISRG Root X1 will fail" All current FIPS accredited devices use openssl 1.0.X, so the lets encrypt cross-signing hack will essentially break multiple corporate networks until the next openssl fips module is released at the end of this year. And could take another 6 months to make it into live systems |
|
A FIPS device being unpatched or broken for a few months almost seems like the natural state of things, at this point.