]> git.ipfire.org Git - thirdparty/openssl.git/blame - README.wishlist
Add "wishlist" of desired but possibly unobtainable fixes/improvements
[thirdparty/openssl.git] / README.wishlist
CommitLineData
fe36a698
SM
1A "wish list" of changes we'd like to make to the FIPS module if we could.
2Note the CMVP requires retesting of all previously tested platforms
3("Operational Environments") to implement any changes considered "cryptographically
4significant". Since the OpenSSL FIPS module v2.0 has some 250 such formally
5tested platforms (and counting), retesting just isn't logistically or economically
6feasible.
7
8--------
9https://github.com/openssl/openssl/pull/4157
10From 2017-08-14, Fix GCM MAC computation for AES-GCM by srahul123
11cryptographically significant, not fixable
12
13--------
14Andy Polyakov: harmonize with __thumb__ clause in FIPS_ref_point() (#3354),
15https://patch-diff.githubusercontent.com/raw/openssl/openssl/pull/3354.patch
16https://github.com/openssl/openssl/pull/3354#pullrequestreview-36086406
17May be possible to introduce in future change letter
18
19--------
20CVE-2016-0701
21cryptographically significant, not fixable
22
23--------
24CVE-2014-0076
25cryptographically significant, not fixable
26
27--------
28"Lucky 13", CVE-2013-0169
29cryptographically significant, not fixable
30
31--------