From krishna@bluesky.SFBay.Sun.COM Tue Jun  9 15:25:00 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n59MOxuR017740
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 9 Jun 2009 15:24:59 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n59MOxTc016741;
	Tue, 9 Jun 2009 15:24:59 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KKZ00K0BSXNN000@nwk-avmta-2.sfbay.sun.com>; Tue,
 09 Jun 2009 15:24:59 -0700 (PDT)
Received: from bluesky.SFBay.Sun.COM ([129.146.108.66])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KKZ00FN8SXMW040@nwk-avmta-2.sfbay.sun.com>; Tue,
 09 Jun 2009 15:24:58 -0700 (PDT)
Received: from bluesky.SFBay.Sun.COM (bluesky.local [127.0.0.1])
	by bluesky.SFBay.Sun.COM (8.14.3+Sun/8.14.3) with ESMTP id n59MH4ou005846;
 Tue, 09 Jun 2009 15:17:05 -0700 (PDT)
Received: (from krishna@localhost)
	by bluesky.SFBay.Sun.COM (8.14.3+Sun/8.14.3/Submit) id n59MH4H7005843; Tue,
 09 Jun 2009 15:17:04 -0700 (PDT)
Date: Tue, 09 Jun 2009 15:17:04 -0700 (PDT)
From: Krishna Yenduri <krishna@bluesky.SFBay.Sun.COM>
Subject: cryptoadm(1M) enhancement for FIPS-140 mode [PSARC/2009/347 FastTrack
 timeout 06/17/2009]
To: PSARC-ext@sun.com
Cc: crypto-discuss@opensolaris.org, fips-cf-team@sun.com
Message-id: <200906092217.n59MH4H7005843@bluesky.SFBay.Sun.COM>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 2605


I am sponsoring this fast track for Hai-May Chao. The timer
is set for 06/17/2009. Micro/patch binding is requested.


Template Version: @(#)sac_nextcase 1.68 02/23/09 SMI
This information is Copyright 2009 Sun Microsystems
1. Introduction
    1.1. Project/Component Working Name:
	 cryptoadm(1M) enhancement for FIPS-140 mode
    1.2. Name of Document Author/Supplier:
	 Author: Hai-May Chao
                 Valerie Fenwick
                 Tony Scarpino
    1.3  Date of This Document:
	09 June, 2009

4. Technical Description

4.1 Proposal:

Enhance cryptoadm interface to provide for enabling and disabling
of the FIPS-140 mode of operations in the Cryptographic Framework.

4.2 Description:

The Cryptographic Framework team is planning on obtaining FIPS 140-2
certification. The cryptoadm command is the administrative front-end
interface to the framework. This case is intended to add new features
to cryptoadm(1M) that allow administrators to enable and disable the
FIPS-140 mode in the Cryptographic Framework. Hence, this case
represents the first set of changes to get prepared toward the FIPS
140-2 evaluation process.

There will be two FIPS-140 modes of operations in the framework: enabled
and disabled. The default FIPS-140 mode is disabled.

When FIPS-140 mode is enabled, the Cryptographic Framework is put into
FIPS-140 mode of operations. The non-approved FIPS algorithms provided by
the user-level pkcs11_softtoken provider and the kernel software providers
will not be disabled. It is up to the consumers of the framework to be
responsible for using only FIPS approved algorithms and that will be
documented in the Security Policy. This meets FIPS 140 level 2 requirements.

As we start working with the certification lab, we anticipate there may
be additional changes needed and those changes should be internal to the
framework. The cryptoadm interface changes should stand by itself.

The cryptoadm command will also be modified to display the active
FIPS-140 mode setting.

4.3  Interfaces:

 The following new options are added to cryptoadm(1M) sub-commands
 	cryptoadm list fips-140
 	cryptoadm enable fips-140
 	cryptoadm disable fips-140

 Stability level is "committed".
 Release binding is Micro/Patch.


4.4 Doc Impact:

 The diff-marked cryptoadm(1M) man page is in the case directory.

5. Reference

FIPS 140-2 Spec can be located at:
http://csrc.nist.gov/publications/PubsFIPS.html

6. Resources and Schedule
    6.4. Steering Committee requested information
   	6.4.1. Consolidation C-team Name:
		ON
    6.5. ARC review type: FastTrack
    6.6. ARC Exposure: open


From Glenn.Brunette@sun.com Tue Jun  9 18:39:17 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n5A1dGl5021731
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 9 Jun 2009 18:39:17 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n5A1dDiS029116;
	Wed, 10 Jun 2009 02:39:15 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KL000A031XEUH00@nwk-avmta-2.sfbay.sun.com>; Tue,
 09 Jun 2009 18:39:15 -0700 (PDT)
Received: from brmea-mail-1.sun.com ([192.18.98.31])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KL000FX51XEVQD0@nwk-avmta-2.sfbay.sun.com>; Tue,
 09 Jun 2009 18:39:14 -0700 (PDT)
Received: from fe-amer-10.sun.com ([192.18.109.80])
	by brmea-mail-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n5A1dES8006976; Wed,
 10 Jun 2009 01:39:14 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 id <0KL00050018F0600@mail-amer.sun.com>; Tue, 09 Jun 2009 19:39:14 -0600 (MDT)
Received: from orion.local ([unknown] [68.83.186.208])
 by mail-amer.sun.com (Sun Java(tm) System Messaging Server 7u2-7.02 64bit
 (built Apr 16 2009)) with ESMTPSA id <0KL0002N91XDB640@mail-amer.sun.com>; Tue,
 09 Jun 2009 19:39:14 -0600 (MDT)
Date: Tue, 09 Jun 2009 21:39:12 -0400
From: Glenn Brunette <Glenn.Brunette@sun.com>
Subject: Re: cryptoadm(1M) enhancement for FIPS-140 mode [PSARC/2009/347
 FastTrack timeout 06/17/2009]
In-reply-to: <200906092217.n59MH4H7005843@bluesky.SFBay.Sun.COM>
Sender: Glenn.Brunette@sun.com
To: Krishna Yenduri <krishna@bluesky.SFBay.Sun.COM>
Cc: PSARC-ext@sun.com, crypto-discuss@opensolaris.org, fips-cf-team@sun.com
Message-id: <4A2F0EC0.5060507@sun.com>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200906092217.n59MH4H7005843@bluesky.SFBay.Sun.COM>
User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.5; en-US;
 rv:1.9.1b3pre) Gecko/20090223 Thunderbird/3.0b2
Status: RO
Content-Length: 3210


Given the strong push by U.S. and other governments, financial
services organizations, etc. (inside and outside of the U.S.) to
use FIPS approved algorithms, has there been any consideration
to make FIPS-140 mode enabled by default?  I realize that in a
global marketplace, this is likely a touchy issue, but I at least
wanted to put the question on the table and hear from the project
team and the community.

g

On 6/9/09 6:17 PM, Krishna Yenduri wrote:
> I am sponsoring this fast track for Hai-May Chao. The timer
> is set for 06/17/2009. Micro/patch binding is requested.
>
>
> Template Version: @(#)sac_nextcase 1.68 02/23/09 SMI
> This information is Copyright 2009 Sun Microsystems
> 1. Introduction
>      1.1. Project/Component Working Name:
> 	 cryptoadm(1M) enhancement for FIPS-140 mode
>      1.2. Name of Document Author/Supplier:
> 	 Author: Hai-May Chao
>                   Valerie Fenwick
>                   Tony Scarpino
>      1.3  Date of This Document:
> 	09 June, 2009
>
> 4. Technical Description
>
> 4.1 Proposal:
>
> Enhance cryptoadm interface to provide for enabling and disabling
> of the FIPS-140 mode of operations in the Cryptographic Framework.
>
> 4.2 Description:
>
> The Cryptographic Framework team is planning on obtaining FIPS 140-2
> certification. The cryptoadm command is the administrative front-end
> interface to the framework. This case is intended to add new features
> to cryptoadm(1M) that allow administrators to enable and disable the
> FIPS-140 mode in the Cryptographic Framework. Hence, this case
> represents the first set of changes to get prepared toward the FIPS
> 140-2 evaluation process.
>
> There will be two FIPS-140 modes of operations in the framework: enabled
> and disabled. The default FIPS-140 mode is disabled.
>
> When FIPS-140 mode is enabled, the Cryptographic Framework is put into
> FIPS-140 mode of operations. The non-approved FIPS algorithms provided by
> the user-level pkcs11_softtoken provider and the kernel software providers
> will not be disabled. It is up to the consumers of the framework to be
> responsible for using only FIPS approved algorithms and that will be
> documented in the Security Policy. This meets FIPS 140 level 2 requirements.
>
> As we start working with the certification lab, we anticipate there may
> be additional changes needed and those changes should be internal to the
> framework. The cryptoadm interface changes should stand by itself.
>
> The cryptoadm command will also be modified to display the active
> FIPS-140 mode setting.
>
> 4.3  Interfaces:
>
>   The following new options are added to cryptoadm(1M) sub-commands
>   	cryptoadm list fips-140
>   	cryptoadm enable fips-140
>   	cryptoadm disable fips-140
>
>   Stability level is "committed".
>   Release binding is Micro/Patch.
>
>
> 4.4 Doc Impact:
>
>   The diff-marked cryptoadm(1M) man page is in the case directory.
>
> 5. Reference
>
> FIPS 140-2 Spec can be located at:
> http://csrc.nist.gov/publications/PubsFIPS.html
>
> 6. Resources and Schedule
>      6.4. Steering Committee requested information
>     	6.4.1. Consolidation C-team Name:
> 		ON
>      6.5. ARC review type: FastTrack
>      6.6. ARC Exposure: open
>

From gdamore@sun.com Tue Jun  9 22:33:05 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n5A5X4c0024847
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 9 Jun 2009 22:33:05 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n5A5Wx4O005248;
	Wed, 10 Jun 2009 06:33:03 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KL000B0DCR2RF00@brm-avmta-1.central.sun.com>; Tue,
 09 Jun 2009 23:33:02 -0600 (MDT)
Received: from sca-es-mail-1.sun.com ([192.18.43.132])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KL000LITCR11270@brm-avmta-1.central.sun.com>; Tue,
 09 Jun 2009 23:33:02 -0600 (MDT)
Received: from fe-sfbay-09.sun.com ([192.18.43.129])
	by sca-es-mail-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n5A5X1lH021900;
 Tue, 09 Jun 2009 22:33:01 -0700 (PDT)
Received: from conversion-daemon.fe-sfbay-09.sun.com by fe-sfbay-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 id <0KL000B00CQJVH00@fe-sfbay-09.sun.com>; Tue,
 09 Jun 2009 22:33:01 -0700 (PDT)
Received: from [192.168.251.11] ([unknown] [76.93.15.33])
 by fe-sfbay-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 with ESMTPSA id <0KL0008H1CR0Q7F0@fe-sfbay-09.sun.com>; Tue,
 09 Jun 2009 22:33:01 -0700 (PDT)
Date: Tue, 09 Jun 2009 22:33:00 -0700
From: "Garrett D'Amore" <gdamore@sun.com>
Subject: Re: cryptoadm(1M) enhancement for FIPS-140 mode [PSARC/2009/347
 FastTrack timeout 06/17/2009]
In-reply-to: <4A2F0EC0.5060507@sun.com>
Sender: Garrett.Damore@sun.com
To: Glenn Brunette <Glenn.Brunette@sun.com>
Cc: Krishna Yenduri <krishna@bluesky.SFBay.Sun.COM>, PSARC-ext@sun.com,
        crypto-discuss@opensolaris.org, fips-cf-team@sun.com
Message-id: <4A2F458C.8030809@sun.com>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200906092217.n59MH4H7005843@bluesky.SFBay.Sun.COM>
 <4A2F0EC0.5060507@sun.com>
User-Agent: Thunderbird 2.0.0.18 (X11/20081201)
Status: RO
Content-Length: 4238

Glenn Brunette wrote:
>
> Given the strong push by U.S. and other governments, financial
> services organizations, etc. (inside and outside of the U.S.) to
> use FIPS approved algorithms, has there been any consideration
> to make FIPS-140 mode enabled by default?  I realize that in a
> global marketplace, this is likely a touchy issue, but I at least
> wanted to put the question on the table and hear from the project
> team and the community.

I think enabling FIPS by default is not necessarily a good thing.  While 
I've not looked at this particular implementation, I know a few things 
about FIPS in general:

    1) some perfectly good and useful algorithms will be unavailable in 
FIPS mode (e.g. RC5, Blowfish, etc.)
    2) some algorithms that *should* be avoided, but are still widely 
used (MD5) will be disabled in FIPS mode
    3) there may be performance implications for FIPS mode (e.g. extra 
... um... pointless... key wrapping operations might be performed 
depending on the location of the crypto boundary, extra verification 
tests, etc.)

Unless a piece of equipment/software is being sold primarily as a FIPS 
solution, I think FIPS should not be enabled by default.

Note also that FIPS 140-2 is also endorsed by a number of other 
countries, and is not just a US standard.

    - Garrett
>
> g
>
> On 6/9/09 6:17 PM, Krishna Yenduri wrote:
>> I am sponsoring this fast track for Hai-May Chao. The timer
>> is set for 06/17/2009. Micro/patch binding is requested.
>>
>>
>> Template Version: @(#)sac_nextcase 1.68 02/23/09 SMI
>> This information is Copyright 2009 Sun Microsystems
>> 1. Introduction
>>      1.1. Project/Component Working Name:
>>      cryptoadm(1M) enhancement for FIPS-140 mode
>>      1.2. Name of Document Author/Supplier:
>>      Author: Hai-May Chao
>>                   Valerie Fenwick
>>                   Tony Scarpino
>>      1.3  Date of This Document:
>>     09 June, 2009
>>
>> 4. Technical Description
>>
>> 4.1 Proposal:
>>
>> Enhance cryptoadm interface to provide for enabling and disabling
>> of the FIPS-140 mode of operations in the Cryptographic Framework.
>>
>> 4.2 Description:
>>
>> The Cryptographic Framework team is planning on obtaining FIPS 140-2
>> certification. The cryptoadm command is the administrative front-end
>> interface to the framework. This case is intended to add new features
>> to cryptoadm(1M) that allow administrators to enable and disable the
>> FIPS-140 mode in the Cryptographic Framework. Hence, this case
>> represents the first set of changes to get prepared toward the FIPS
>> 140-2 evaluation process.
>>
>> There will be two FIPS-140 modes of operations in the framework: enabled
>> and disabled. The default FIPS-140 mode is disabled.
>>
>> When FIPS-140 mode is enabled, the Cryptographic Framework is put into
>> FIPS-140 mode of operations. The non-approved FIPS algorithms 
>> provided by
>> the user-level pkcs11_softtoken provider and the kernel software 
>> providers
>> will not be disabled. It is up to the consumers of the framework to be
>> responsible for using only FIPS approved algorithms and that will be
>> documented in the Security Policy. This meets FIPS 140 level 2 
>> requirements.
>>
>> As we start working with the certification lab, we anticipate there may
>> be additional changes needed and those changes should be internal to the
>> framework. The cryptoadm interface changes should stand by itself.
>>
>> The cryptoadm command will also be modified to display the active
>> FIPS-140 mode setting.
>>
>> 4.3  Interfaces:
>>
>>   The following new options are added to cryptoadm(1M) sub-commands
>>       cryptoadm list fips-140
>>       cryptoadm enable fips-140
>>       cryptoadm disable fips-140
>>
>>   Stability level is "committed".
>>   Release binding is Micro/Patch.
>>
>>
>> 4.4 Doc Impact:
>>
>>   The diff-marked cryptoadm(1M) man page is in the case directory.
>>
>> 5. Reference
>>
>> FIPS 140-2 Spec can be located at:
>> http://csrc.nist.gov/publications/PubsFIPS.html
>>
>> 6. Resources and Schedule
>>      6.4. Steering Committee requested information
>>         6.4.1. Consolidation C-team Name:
>>         ON
>>      6.5. ARC review type: FastTrack
>>      6.6. ARC Exposure: open
>>


From anthony.scarpino@sun.com Tue Jun  9 23:01:05 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n5A615r0025583
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 9 Jun 2009 23:01:05 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n5A612eS013957;
	Tue, 9 Jun 2009 23:01:04 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KL000H0VE1Q9100@nwk-avmta-1.sfbay.Sun.COM>; Tue,
 09 Jun 2009 23:01:02 -0700 (PDT)
Received: from usps.sfbay.Sun.COM ([10.6.64.36]) by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KL000C9PE1Q6JD0@nwk-avmta-1.sfbay.Sun.COM>; Tue,
 09 Jun 2009 23:01:02 -0700 (PDT)
Received: from [10.7.251.211] (punchin-izick [10.7.251.211])
	by usps.sfbay.Sun.COM (8.14.3+Sun/8.14.3) with ESMTP id n5A5uVn0005931; Tue,
 09 Jun 2009 22:56:31 -0700 (PDT)
Date: Tue, 09 Jun 2009 22:53:17 -0700
From: Anthony Scarpino <anthony.scarpino@sun.com>
Subject: Re: cryptoadm(1M) enhancement for FIPS-140 mode [PSARC/2009/347
 FastTrack timeout 06/17/2009]
In-reply-to: <4A2F0EC0.5060507@sun.com>
To: Glenn Brunette <Glenn.Brunette@sun.com>
Cc: Krishna Yenduri <krishna@bluesky.sfbay.sun.com>, PSARC-ext@sun.com,
        crypto-discuss@opensolaris.org, fips-cf-team@sun.com
Message-id: <4A2F4A4D.8030508@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200906092217.n59MH4H7005843@bluesky.SFBay.Sun.COM>
 <4A2F0EC0.5060507@sun.com>
User-Agent: Thunderbird 2.0.0.17 (X11/20081023)
Status: RO
Content-Length: 4299

Hi,

The team is enhancing the Cryptographic Framework to support a Security 
Level 2.  That level requires a Common Criteria certified OS.  Having it 
on by default would have to be a special case for that particular release..

Now taking off the project team hat...

In a world with an appetite for performance.  FIPS (regardless of 
Security Level) requires Power-On Self Tests and other tests that will 
degrade performance.  There are also boundaries which have to the 
verified before crypto operations can be performed.  I feel that you 
would see many more unhappy users than happy..

Also a FIPS validation requires a Security Policy that is a 
configuration the user must keep the system in, so no addition crypto 
cards or providers.   And for Level 1 and 2, it's not that the whole 
system is FIPS'ed, but just a set of supported APIs.

In general as FIPS 140-2 is, I don't believe it's practical by default..

Tony


Glenn Brunette wrote:
> 
> Given the strong push by U.S. and other governments, financial
> services organizations, etc. (inside and outside of the U.S.) to
> use FIPS approved algorithms, has there been any consideration
> to make FIPS-140 mode enabled by default?  I realize that in a
> global marketplace, this is likely a touchy issue, but I at least
> wanted to put the question on the table and hear from the project
> team and the community.
> 
> g
> 
> On 6/9/09 6:17 PM, Krishna Yenduri wrote:
>> I am sponsoring this fast track for Hai-May Chao. The timer
>> is set for 06/17/2009. Micro/patch binding is requested.
>>
>>
>> Template Version: @(#)sac_nextcase 1.68 02/23/09 SMI
>> This information is Copyright 2009 Sun Microsystems
>> 1. Introduction
>>      1.1. Project/Component Working Name:
>>      cryptoadm(1M) enhancement for FIPS-140 mode
>>      1.2. Name of Document Author/Supplier:
>>      Author: Hai-May Chao
>>                   Valerie Fenwick
>>                   Tony Scarpino
>>      1.3  Date of This Document:
>>     09 June, 2009
>>
>> 4. Technical Description
>>
>> 4.1 Proposal:
>>
>> Enhance cryptoadm interface to provide for enabling and disabling
>> of the FIPS-140 mode of operations in the Cryptographic Framework.
>>
>> 4.2 Description:
>>
>> The Cryptographic Framework team is planning on obtaining FIPS 140-2
>> certification. The cryptoadm command is the administrative front-end
>> interface to the framework. This case is intended to add new features
>> to cryptoadm(1M) that allow administrators to enable and disable the
>> FIPS-140 mode in the Cryptographic Framework. Hence, this case
>> represents the first set of changes to get prepared toward the FIPS
>> 140-2 evaluation process.
>>
>> There will be two FIPS-140 modes of operations in the framework: enabled
>> and disabled. The default FIPS-140 mode is disabled.
>>
>> When FIPS-140 mode is enabled, the Cryptographic Framework is put into
>> FIPS-140 mode of operations. The non-approved FIPS algorithms provided by
>> the user-level pkcs11_softtoken provider and the kernel software 
>> providers
>> will not be disabled. It is up to the consumers of the framework to be
>> responsible for using only FIPS approved algorithms and that will be
>> documented in the Security Policy. This meets FIPS 140 level 2 
>> requirements.
>>
>> As we start working with the certification lab, we anticipate there may
>> be additional changes needed and those changes should be internal to the
>> framework. The cryptoadm interface changes should stand by itself.
>>
>> The cryptoadm command will also be modified to display the active
>> FIPS-140 mode setting.
>>
>> 4.3  Interfaces:
>>
>>   The following new options are added to cryptoadm(1M) sub-commands
>>       cryptoadm list fips-140
>>       cryptoadm enable fips-140
>>       cryptoadm disable fips-140
>>
>>   Stability level is "committed".
>>   Release binding is Micro/Patch.
>>
>>
>> 4.4 Doc Impact:
>>
>>   The diff-marked cryptoadm(1M) man page is in the case directory.
>>
>> 5. Reference
>>
>> FIPS 140-2 Spec can be located at:
>> http://csrc.nist.gov/publications/PubsFIPS.html
>>
>> 6. Resources and Schedule
>>      6.4. Steering Committee requested information
>>         6.4.1. Consolidation C-team Name:
>>         ON
>>      6.5. ARC review type: FastTrack
>>      6.6. ARC Exposure: open
>>


From Mehdi.Bonyadi@sun.com Wed Jun 10 07:24:34 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n5AEOX0A001369
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 10 Jun 2009 07:24:34 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n5AEOV50013962;
	Wed, 10 Jun 2009 07:24:33 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KL100B171CW3J00@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 10 Jun 2009 07:24:32 -0700 (PDT)
Received: from sca-es-mail-2.sun.com ([192.18.43.133])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KL100I441CVFX90@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 10 Jun 2009 07:24:31 -0700 (PDT)
Received: from fe-sfbay-09.sun.com ([192.18.43.129])
	by sca-es-mail-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n5AEOVe6022492;
 Wed, 10 Jun 2009 07:24:31 -0700 (PDT)
Received: from conversion-daemon.fe-sfbay-09.sun.com by fe-sfbay-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 id <0KL100C0018NY000@fe-sfbay-09.sun.com>; Wed,
 10 Jun 2009 07:24:31 -0700 (PDT)
Received: from [129.145.154.58] ([unknown] [129.145.154.58])
 by fe-sfbay-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 with ESMTPSA id <0KL100B6F1CU6L90@fe-sfbay-09.sun.com>; Wed,
 10 Jun 2009 07:24:31 -0700 (PDT)
Date: Wed, 10 Jun 2009 07:24:30 -0700
From: Mehdi Bonyadi <Mehdi.Bonyadi@sun.com>
Subject: Re: cryptoadm(1M) enhancement for FIPS-140 mode [PSARC/2009/347
	FastTrack timeout 06/17/2009]
In-reply-to: <4A2F4A4D.8030508@sun.com>
Sender: Mehdi.Bonyadi@sun.com
To: Anthony Scarpino <anthony.scarpino@sun.com>
Cc: Glenn Brunette <Glenn.Brunette@sun.com>, PSARC-ext@sun.com,
        Krishna Yenduri <krishna@bluesky.sfbay.sun.com>, fips-cf-team@sun.com,
        crypto-discuss@opensolaris.org
Message-id: <4A2FC21E.80303@sun.com>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200906092217.n59MH4H7005843@bluesky.SFBay.Sun.COM>
 <4A2F0EC0.5060507@sun.com> <4A2F4A4D.8030508@sun.com>
User-Agent: Thunderbird 2.0.0.19 (X11/20090110)
Status: RO
Content-Length: 4927

FIPS 140-3 is still in draft and under review, but since certifications 
can take many months it is a good idea to monitor the situation and be 
prepared. Has anyone heard of any target dates for 14-3 release or do 
they know how it would impact our case?

Mehdi


On 06/09/09 22:53, Anthony Scarpino wrote:
> Hi,
> 
> The team is enhancing the Cryptographic Framework to support a Security 
> Level 2.  That level requires a Common Criteria certified OS.  Having it 
> on by default would have to be a special case for that particular release..
> 
> Now taking off the project team hat...
> 
> In a world with an appetite for performance.  FIPS (regardless of 
> Security Level) requires Power-On Self Tests and other tests that will 
> degrade performance.  There are also boundaries which have to the 
> verified before crypto operations can be performed.  I feel that you 
> would see many more unhappy users than happy..
> 
> Also a FIPS validation requires a Security Policy that is a 
> configuration the user must keep the system in, so no addition crypto 
> cards or providers.   And for Level 1 and 2, it's not that the whole 
> system is FIPS'ed, but just a set of supported APIs.
> 
> In general as FIPS 140-2 is, I don't believe it's practical by default..
> 
> Tony
> 
> 
> Glenn Brunette wrote:
>>
>> Given the strong push by U.S. and other governments, financial
>> services organizations, etc. (inside and outside of the U.S.) to
>> use FIPS approved algorithms, has there been any consideration
>> to make FIPS-140 mode enabled by default?  I realize that in a
>> global marketplace, this is likely a touchy issue, but I at least
>> wanted to put the question on the table and hear from the project
>> team and the community.
>>
>> g
>>
>> On 6/9/09 6:17 PM, Krishna Yenduri wrote:
>>> I am sponsoring this fast track for Hai-May Chao. The timer
>>> is set for 06/17/2009. Micro/patch binding is requested.
>>>
>>>
>>> Template Version: @(#)sac_nextcase 1.68 02/23/09 SMI
>>> This information is Copyright 2009 Sun Microsystems
>>> 1. Introduction
>>>      1.1. Project/Component Working Name:
>>>      cryptoadm(1M) enhancement for FIPS-140 mode
>>>      1.2. Name of Document Author/Supplier:
>>>      Author: Hai-May Chao
>>>                   Valerie Fenwick
>>>                   Tony Scarpino
>>>      1.3  Date of This Document:
>>>     09 June, 2009
>>>
>>> 4. Technical Description
>>>
>>> 4.1 Proposal:
>>>
>>> Enhance cryptoadm interface to provide for enabling and disabling
>>> of the FIPS-140 mode of operations in the Cryptographic Framework.
>>>
>>> 4.2 Description:
>>>
>>> The Cryptographic Framework team is planning on obtaining FIPS 140-2
>>> certification. The cryptoadm command is the administrative front-end
>>> interface to the framework. This case is intended to add new features
>>> to cryptoadm(1M) that allow administrators to enable and disable the
>>> FIPS-140 mode in the Cryptographic Framework. Hence, this case
>>> represents the first set of changes to get prepared toward the FIPS
>>> 140-2 evaluation process.
>>>
>>> There will be two FIPS-140 modes of operations in the framework: enabled
>>> and disabled. The default FIPS-140 mode is disabled.
>>>
>>> When FIPS-140 mode is enabled, the Cryptographic Framework is put into
>>> FIPS-140 mode of operations. The non-approved FIPS algorithms 
>>> provided by
>>> the user-level pkcs11_softtoken provider and the kernel software 
>>> providers
>>> will not be disabled. It is up to the consumers of the framework to be
>>> responsible for using only FIPS approved algorithms and that will be
>>> documented in the Security Policy. This meets FIPS 140 level 2 
>>> requirements.
>>>
>>> As we start working with the certification lab, we anticipate there may
>>> be additional changes needed and those changes should be internal to the
>>> framework. The cryptoadm interface changes should stand by itself.
>>>
>>> The cryptoadm command will also be modified to display the active
>>> FIPS-140 mode setting.
>>>
>>> 4.3  Interfaces:
>>>
>>>   The following new options are added to cryptoadm(1M) sub-commands
>>>       cryptoadm list fips-140
>>>       cryptoadm enable fips-140
>>>       cryptoadm disable fips-140
>>>
>>>   Stability level is "committed".
>>>   Release binding is Micro/Patch.
>>>
>>>
>>> 4.4 Doc Impact:
>>>
>>>   The diff-marked cryptoadm(1M) man page is in the case directory.
>>>
>>> 5. Reference
>>>
>>> FIPS 140-2 Spec can be located at:
>>> http://csrc.nist.gov/publications/PubsFIPS.html
>>>
>>> 6. Resources and Schedule
>>>      6.4. Steering Committee requested information
>>>         6.4.1. Consolidation C-team Name:
>>>         ON
>>>      6.5. ARC review type: FastTrack
>>>      6.6. ARC Exposure: open
>>>
> 
> _______________________________________________
> crypto-discuss mailing list
> crypto-discuss@opensolaris.org
> http://mail.opensolaris.org/mailman/listinfo/crypto-discuss

From gdamore@sun.com Wed Jun 10 07:39:12 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n5AEdCbx001481
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 10 Jun 2009 07:39:12 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n5AEdB7V018190;
	Wed, 10 Jun 2009 07:39:12 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KL100C0321BWF00@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 10 Jun 2009 07:39:12 -0700 (PDT)
Received: from sca-es-mail-1.sun.com ([192.18.43.132])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KL100I2E21AG4D0@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 10 Jun 2009 07:39:10 -0700 (PDT)
Received: from fe-sfbay-10.sun.com ([192.18.43.129])
	by sca-es-mail-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n5AEdA95012787;
 Wed, 10 Jun 2009 07:39:10 -0700 (PDT)
Received: from conversion-daemon.fe-sfbay-10.sun.com by fe-sfbay-10.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 id <0KL100B001UX7U00@fe-sfbay-10.sun.com>; Wed,
 10 Jun 2009 07:39:10 -0700 (PDT)
Received: from [192.168.251.11] ([unknown] [76.93.15.33])
 by fe-sfbay-10.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 with ESMTPSA id <0KL100DTD214N170@fe-sfbay-10.sun.com>; Wed,
 10 Jun 2009 07:39:04 -0700 (PDT)
Date: Wed, 10 Jun 2009 07:39:03 -0700
From: "Garrett D'Amore" <gdamore@sun.com>
Subject: Re: cryptoadm(1M) enhancement for FIPS-140 mode [PSARC/2009/347
	FastTrack timeout 06/17/2009]
In-reply-to: <4A2FC21E.80303@sun.com>
Sender: Garrett.Damore@sun.com
To: Mehdi Bonyadi <Mehdi.Bonyadi@sun.com>
Cc: Anthony Scarpino <anthony.scarpino@sun.com>,
        Glenn Brunette <Glenn.Brunette@sun.com>, PSARC-ext@sun.com,
        Krishna Yenduri <krishna@bluesky.sfbay.sun.com>, fips-cf-team@sun.com,
        crypto-discuss@opensolaris.org
Message-id: <4A2FC587.3020704@sun.com>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200906092217.n59MH4H7005843@bluesky.SFBay.Sun.COM>
 <4A2F0EC0.5060507@sun.com> <4A2F4A4D.8030508@sun.com> <4A2FC21E.80303@sun.com>
User-Agent: Thunderbird 2.0.0.18 (X11/20081201)
Status: RO
Content-Length: 5330

Mehdi Bonyadi wrote:
> FIPS 140-3 is still in draft and under review, but since 
> certifications can take many months it is a good idea to monitor the 
> situation and be prepared. Has anyone heard of any target dates for 
> 14-3 release or do they know how it would impact our case?

If the precedent set by 140-2 holds, then certifications of 140-2 will 
still be valid after 140-3 is approved.  And IIRC, there will probably 
be a transition period where products can still be evaluated as 140-2.

    - Garrett
>
> Mehdi
>
>
> On 06/09/09 22:53, Anthony Scarpino wrote:
>> Hi,
>>
>> The team is enhancing the Cryptographic Framework to support a 
>> Security Level 2.  That level requires a Common Criteria certified 
>> OS.  Having it on by default would have to be a special case for that 
>> particular release..
>>
>> Now taking off the project team hat...
>>
>> In a world with an appetite for performance.  FIPS (regardless of 
>> Security Level) requires Power-On Self Tests and other tests that 
>> will degrade performance.  There are also boundaries which have to 
>> the verified before crypto operations can be performed.  I feel that 
>> you would see many more unhappy users than happy..
>>
>> Also a FIPS validation requires a Security Policy that is a 
>> configuration the user must keep the system in, so no addition crypto 
>> cards or providers.   And for Level 1 and 2, it's not that the whole 
>> system is FIPS'ed, but just a set of supported APIs.
>>
>> In general as FIPS 140-2 is, I don't believe it's practical by default..
>>
>> Tony
>>
>>
>> Glenn Brunette wrote:
>>>
>>> Given the strong push by U.S. and other governments, financial
>>> services organizations, etc. (inside and outside of the U.S.) to
>>> use FIPS approved algorithms, has there been any consideration
>>> to make FIPS-140 mode enabled by default?  I realize that in a
>>> global marketplace, this is likely a touchy issue, but I at least
>>> wanted to put the question on the table and hear from the project
>>> team and the community.
>>>
>>> g
>>>
>>> On 6/9/09 6:17 PM, Krishna Yenduri wrote:
>>>> I am sponsoring this fast track for Hai-May Chao. The timer
>>>> is set for 06/17/2009. Micro/patch binding is requested.
>>>>
>>>>
>>>> Template Version: @(#)sac_nextcase 1.68 02/23/09 SMI
>>>> This information is Copyright 2009 Sun Microsystems
>>>> 1. Introduction
>>>>      1.1. Project/Component Working Name:
>>>>      cryptoadm(1M) enhancement for FIPS-140 mode
>>>>      1.2. Name of Document Author/Supplier:
>>>>      Author: Hai-May Chao
>>>>                   Valerie Fenwick
>>>>                   Tony Scarpino
>>>>      1.3  Date of This Document:
>>>>     09 June, 2009
>>>>
>>>> 4. Technical Description
>>>>
>>>> 4.1 Proposal:
>>>>
>>>> Enhance cryptoadm interface to provide for enabling and disabling
>>>> of the FIPS-140 mode of operations in the Cryptographic Framework.
>>>>
>>>> 4.2 Description:
>>>>
>>>> The Cryptographic Framework team is planning on obtaining FIPS 140-2
>>>> certification. The cryptoadm command is the administrative front-end
>>>> interface to the framework. This case is intended to add new features
>>>> to cryptoadm(1M) that allow administrators to enable and disable the
>>>> FIPS-140 mode in the Cryptographic Framework. Hence, this case
>>>> represents the first set of changes to get prepared toward the FIPS
>>>> 140-2 evaluation process.
>>>>
>>>> There will be two FIPS-140 modes of operations in the framework: 
>>>> enabled
>>>> and disabled. The default FIPS-140 mode is disabled.
>>>>
>>>> When FIPS-140 mode is enabled, the Cryptographic Framework is put into
>>>> FIPS-140 mode of operations. The non-approved FIPS algorithms 
>>>> provided by
>>>> the user-level pkcs11_softtoken provider and the kernel software 
>>>> providers
>>>> will not be disabled. It is up to the consumers of the framework to be
>>>> responsible for using only FIPS approved algorithms and that will be
>>>> documented in the Security Policy. This meets FIPS 140 level 2 
>>>> requirements.
>>>>
>>>> As we start working with the certification lab, we anticipate there 
>>>> may
>>>> be additional changes needed and those changes should be internal 
>>>> to the
>>>> framework. The cryptoadm interface changes should stand by itself.
>>>>
>>>> The cryptoadm command will also be modified to display the active
>>>> FIPS-140 mode setting.
>>>>
>>>> 4.3  Interfaces:
>>>>
>>>>   The following new options are added to cryptoadm(1M) sub-commands
>>>>       cryptoadm list fips-140
>>>>       cryptoadm enable fips-140
>>>>       cryptoadm disable fips-140
>>>>
>>>>   Stability level is "committed".
>>>>   Release binding is Micro/Patch.
>>>>
>>>>
>>>> 4.4 Doc Impact:
>>>>
>>>>   The diff-marked cryptoadm(1M) man page is in the case directory.
>>>>
>>>> 5. Reference
>>>>
>>>> FIPS 140-2 Spec can be located at:
>>>> http://csrc.nist.gov/publications/PubsFIPS.html
>>>>
>>>> 6. Resources and Schedule
>>>>      6.4. Steering Committee requested information
>>>>         6.4.1. Consolidation C-team Name:
>>>>         ON
>>>>      6.5. ARC review type: FastTrack
>>>>      6.6. ARC Exposure: open
>>>>
>>
>> _______________________________________________
>> crypto-discuss mailing list
>> crypto-discuss@opensolaris.org
>> http://mail.opensolaris.org/mailman/listinfo/crypto-discuss


From Valerie.Fenwick@sun.com Wed Jun 10 08:41:19 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n5AFfIJt001717
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 10 Jun 2009 08:41:18 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n5AFf9xb009750;
	Wed, 10 Jun 2009 16:41:13 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KL100K154WN1100@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 10 Jun 2009 08:41:11 -0700 (PDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.63])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KL100GZK4WM6E20@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 10 Jun 2009 08:41:10 -0700 (PDT)
Received: from borg (borg.SFBay.Sun.COM [10.5.240.20])
	by jurassic-x4600.sfbay.sun.com (8.14.3+Sun/8.14.3)
 with ESMTP id n5AFfAI2940289; Wed, 10 Jun 2009 08:41:10 -0700 (PDT)
Date: Wed, 10 Jun 2009 08:41:08 -0700 (PDT)
From: Valerie Bubb Fenwick <Valerie.Fenwick@sun.com>
Subject: Re: cryptoadm(1M) enhancement for FIPS-140 mode [PSARC/2009/347
 FastTrack timeout 06/17/2009]
In-reply-to: <4A2FC587.3020704@sun.com>
Sender: bubbva@borg.SFBay.Sun.COM
To: "Garrett D'Amore" <gdamore@sun.com>
Cc: Mehdi Bonyadi <Mehdi.Bonyadi@sun.com>,
        Anthony Scarpino <anthony.scarpino@sun.com>,
        Glenn Brunette <Glenn.Brunette@sun.com>, PSARC-ext@sun.com,
        Krishna Yenduri <krishna@bluesky.sfbay.sun.com>, fips-cf-team@sun.com,
        crypto-discuss@opensolaris.org
Message-id: <Pine.GSO.4.64.0906100839530.15500@borg>
MIME-version: 1.0
Content-type: TEXT/PLAIN; charset=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200906092217.n59MH4H7005843@bluesky.SFBay.Sun.COM>
 <4A2F0EC0.5060507@sun.com> <4A2F4A4D.8030508@sun.com> <4A2FC21E.80303@sun.com>
 <4A2FC587.3020704@sun.com>
Status: RO
Content-Length: 5790

On Wed, 10 Jun 2009, Garrett D'Amore wrote:

> Mehdi Bonyadi wrote:
>> FIPS 140-3 is still in draft and under review, but since certifications can 
>> take many months it is a good idea to monitor the situation and be 
>> prepared. Has anyone heard of any target dates for 14-3 release or do they 
>> know how it would impact our case?
>
> If the precedent set by 140-2 holds, then certifications of 140-2 will still 
> be valid after 140-3 is approved.  And IIRC, there will probably be a 
> transition period where products can still be evaluated as 140-2.

That is correct, that is what 140-3 stipulates (I think the timer is set by when
you officially enter evaluation).

To answer your question, though, Mehdi. We have been following 140-3, and the lab
we've engaged is watching that very closely.

Valerie

>
>   - Garrett
>> 
>> Mehdi
>> 
>> 
>> On 06/09/09 22:53, Anthony Scarpino wrote:
>>> Hi,
>>> 
>>> The team is enhancing the Cryptographic Framework to support a Security 
>>> Level 2.  That level requires a Common Criteria certified OS.  Having it 
>>> on by default would have to be a special case for that particular 
>>> release..
>>> 
>>> Now taking off the project team hat...
>>> 
>>> In a world with an appetite for performance.  FIPS (regardless of Security 
>>> Level) requires Power-On Self Tests and other tests that will degrade 
>>> performance.  There are also boundaries which have to the verified before 
>>> crypto operations can be performed.  I feel that you would see many more 
>>> unhappy users than happy..
>>> 
>>> Also a FIPS validation requires a Security Policy that is a configuration 
>>> the user must keep the system in, so no addition crypto cards or 
>>> providers.   And for Level 1 and 2, it's not that the whole system is 
>>> FIPS'ed, but just a set of supported APIs.
>>> 
>>> In general as FIPS 140-2 is, I don't believe it's practical by default..
>>> 
>>> Tony
>>> 
>>> 
>>> Glenn Brunette wrote:
>>>> 
>>>> Given the strong push by U.S. and other governments, financial
>>>> services organizations, etc. (inside and outside of the U.S.) to
>>>> use FIPS approved algorithms, has there been any consideration
>>>> to make FIPS-140 mode enabled by default?  I realize that in a
>>>> global marketplace, this is likely a touchy issue, but I at least
>>>> wanted to put the question on the table and hear from the project
>>>> team and the community.
>>>> 
>>>> g
>>>> 
>>>> On 6/9/09 6:17 PM, Krishna Yenduri wrote:
>>>>> I am sponsoring this fast track for Hai-May Chao. The timer
>>>>> is set for 06/17/2009. Micro/patch binding is requested.
>>>>> 
>>>>> 
>>>>> Template Version: @(#)sac_nextcase 1.68 02/23/09 SMI
>>>>> This information is Copyright 2009 Sun Microsystems
>>>>> 1. Introduction
>>>>>      1.1. Project/Component Working Name:
>>>>>      cryptoadm(1M) enhancement for FIPS-140 mode
>>>>>      1.2. Name of Document Author/Supplier:
>>>>>      Author: Hai-May Chao
>>>>>                   Valerie Fenwick
>>>>>                   Tony Scarpino
>>>>>      1.3  Date of This Document:
>>>>>     09 June, 2009
>>>>> 
>>>>> 4. Technical Description
>>>>> 
>>>>> 4.1 Proposal:
>>>>> 
>>>>> Enhance cryptoadm interface to provide for enabling and disabling
>>>>> of the FIPS-140 mode of operations in the Cryptographic Framework.
>>>>> 
>>>>> 4.2 Description:
>>>>> 
>>>>> The Cryptographic Framework team is planning on obtaining FIPS 140-2
>>>>> certification. The cryptoadm command is the administrative front-end
>>>>> interface to the framework. This case is intended to add new features
>>>>> to cryptoadm(1M) that allow administrators to enable and disable the
>>>>> FIPS-140 mode in the Cryptographic Framework. Hence, this case
>>>>> represents the first set of changes to get prepared toward the FIPS
>>>>> 140-2 evaluation process.
>>>>> 
>>>>> There will be two FIPS-140 modes of operations in the framework: enabled
>>>>> and disabled. The default FIPS-140 mode is disabled.
>>>>> 
>>>>> When FIPS-140 mode is enabled, the Cryptographic Framework is put into
>>>>> FIPS-140 mode of operations. The non-approved FIPS algorithms provided 
>>>>> by
>>>>> the user-level pkcs11_softtoken provider and the kernel software 
>>>>> providers
>>>>> will not be disabled. It is up to the consumers of the framework to be
>>>>> responsible for using only FIPS approved algorithms and that will be
>>>>> documented in the Security Policy. This meets FIPS 140 level 2 
>>>>> requirements.
>>>>> 
>>>>> As we start working with the certification lab, we anticipate there may
>>>>> be additional changes needed and those changes should be internal to the
>>>>> framework. The cryptoadm interface changes should stand by itself.
>>>>> 
>>>>> The cryptoadm command will also be modified to display the active
>>>>> FIPS-140 mode setting.
>>>>> 
>>>>> 4.3  Interfaces:
>>>>>
>>>>>   The following new options are added to cryptoadm(1M) sub-commands
>>>>>       cryptoadm list fips-140
>>>>>       cryptoadm enable fips-140
>>>>>       cryptoadm disable fips-140
>>>>>
>>>>>   Stability level is "committed".
>>>>>   Release binding is Micro/Patch.
>>>>> 
>>>>> 
>>>>> 4.4 Doc Impact:
>>>>>
>>>>>   The diff-marked cryptoadm(1M) man page is in the case directory.
>>>>> 
>>>>> 5. Reference
>>>>> 
>>>>> FIPS 140-2 Spec can be located at:
>>>>> http://csrc.nist.gov/publications/PubsFIPS.html
>>>>> 
>>>>> 6. Resources and Schedule
>>>>>      6.4. Steering Committee requested information
>>>>>         6.4.1. Consolidation C-team Name:
>>>>>         ON
>>>>>      6.5. ARC review type: FastTrack
>>>>>      6.6. ARC Exposure: open
>>>>> 
>>> 
>>> _______________________________________________
>>> crypto-discuss mailing list
>>> crypto-discuss@opensolaris.org
>>> http://mail.opensolaris.org/mailman/listinfo/crypto-discuss
>
>


From bhargava.yenduri@sun.com Wed Jun 10 11:30:40 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n5AIUef0011709
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 10 Jun 2009 11:30:40 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n5AIUd5q028795;
	Wed, 10 Jun 2009 11:30:39 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KL100H0VCR2TN00@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 10 Jun 2009 11:30:38 -0700 (PDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.63])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KL100G60CR16OF0@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 10 Jun 2009 11:30:37 -0700 (PDT)
Received: from [129.150.13.181]
 (vpn-129-150-13-181.SFBay.Sun.COM [129.150.13.181])
	by jurassic-x4600.sfbay.sun.com (8.14.3+Sun/8.14.3)
 with ESMTP id n5AIUX0k975341; Wed, 10 Jun 2009 11:30:37 -0700 (PDT)
Date: Wed, 10 Jun 2009 11:31:34 -0700
From: Krishna Yenduri <bhargava.yenduri@sun.com>
Subject: Re: cryptoadm(1M) enhancement for FIPS-140 mode [PSARC/2009/347
	FastTrack timeout 06/17/2009]
In-reply-to: <4A2F0EC0.5060507@sun.com>
To: Glenn Brunette <Glenn.Brunette@sun.com>
Cc: Krishna Yenduri <krishna@bluesky.SFBay.Sun.COM>, PSARC-ext@sun.com,
        fips-cf-team@sun.com, crypto-discuss@opensolaris.org
Message-id: <4A2FFC06.10309@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200906092217.n59MH4H7005843@bluesky.SFBay.Sun.COM>
 <4A2F0EC0.5060507@sun.com>
User-Agent: Thunderbird 2.0.0.12 (X11/20080325)
Status: RO
Content-Length: 785

Glenn Brunette wrote:
>
> Given the strong push by U.S. and other governments, financial
> services organizations, etc. (inside and outside of the U.S.) to
> use FIPS approved algorithms, has there been any consideration
> to make FIPS-140 mode enabled by default?

 This is an interesting suggestion. I agree with Tony that
 there are performance issues with making it the default.

 I believe we can make some requirements of the FIPS 140-2 spec
 the default. We already made one requirement the
 default. See
    6703956 Solaris cryptographic framework needs a FIPS-186-2 
certifiable RNG
 which modified the Solaris RNG to use an algorithm that
 can be FIPS certified. I will note that these kind of changes are at the
 design level and do not impact this case.

Regards,
-Krishna

From Hai-May.Chao@sun.com Wed Jun 10 12:48:16 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n5AJmF1m013039
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 10 Jun 2009 12:48:15 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n5AJm9vR019705;
	Wed, 10 Jun 2009 20:48:11 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KL10073HGCA1400@nwk-avmta-2.sfbay.sun.com>; Wed,
 10 Jun 2009 12:48:10 -0700 (PDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.59])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KL1005D5GC8HT30@nwk-avmta-2.sfbay.sun.com>; Wed,
 10 Jun 2009 12:48:08 -0700 (PDT)
Received: from [129.150.12.28]
 (vpn-129-150-12-28.SFBay.Sun.COM [129.150.12.28])	by
 jurassic-x4600.sfbay.sun.com (8.14.3+Sun/8.14.3) with ESMTP id n5AJm70G992053;
 Wed, 10 Jun 2009 12:48:07 -0700 (PDT)
Date: Wed, 10 Jun 2009 12:48:16 -0700
From: Hai-May Chao <Hai-May.Chao@sun.com>
Subject: Re: cryptoadm(1M) enhancement for FIPS-140 mode	[PSARC/2009/347
	FastTrack timeout 06/17/2009]
In-reply-to: <4A2FFC06.10309@sun.com>
To: Krishna Yenduri <bhargava.yenduri@sun.com>
Cc: Glenn Brunette <Glenn.Brunette@sun.com>, PSARC-ext@sun.com,
        Krishna Yenduri <krishna@bluesky.SFBay.Sun.COM>, fips-cf-team@sun.com,
        crypto-discuss@opensolaris.org
Message-id: <4A300E00.7020706@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200906092217.n59MH4H7005843@bluesky.SFBay.Sun.COM>
 <4A2F0EC0.5060507@sun.com> <4A2FFC06.10309@sun.com>
User-Agent: Thunderbird 2.0b2 (X11/20070227)
Status: RO
Content-Length: 1356

Krishna Yenduri wrote:
> Glenn Brunette wrote:
>>
>> Given the strong push by U.S. and other governments, financial
>> services organizations, etc. (inside and outside of the U.S.) to
>> use FIPS approved algorithms, has there been any consideration
>> to make FIPS-140 mode enabled by default?
>
> This is an interesting suggestion. I agree with Tony that
> there are performance issues with making it the default.
>

Correct - performance degradation  because of the additional Power-Up 
tests including
cryptographic algorithm test and software integrity test at boot time.

> I believe we can make some requirements of the FIPS 140-2 spec
> the default. We already made one requirement the
> default. See
>    6703956 Solaris cryptographic framework needs a FIPS-186-2 
> certifiable RNG
> which modified the Solaris RNG to use an algorithm that
> can be FIPS certified. I will note that these kind of changes are at the
> design level and do not impact this case.
>

For Solaris RNG case, using FIPS 186-2 would be better as it can be FIPS 
certified,
also testing showed no performance regression. So we made it the default RNG
algorithm.

Hai-May




> Regards,
> -Krishna
> _______________________________________________
> crypto-discuss mailing list
> crypto-discuss@opensolaris.org
> http://mail.opensolaris.org/mailman/listinfo/crypto-discuss


From Scott.Rotondo@sun.com Wed Jun 10 15:29:01 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n5AMT1rq017796
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 10 Jun 2009 15:29:01 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n5AMSwLc026712;
	Wed, 10 Jun 2009 15:29:01 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KL10020JNSBNS00@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 10 Jun 2009 15:28:59 -0700 (PDT)
Received: from brmea-mail-2.sun.com ([192.18.98.43])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KL100HLTNS6MEE0@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 10 Jun 2009 15:28:54 -0700 (PDT)
Received: from fe-amer-09.sun.com ([192.18.109.79])
	by brmea-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n5AMSsaH023610; Wed,
 10 Jun 2009 22:28:54 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 id <0KL100F00NQLK700@mail-amer.sun.com>; Wed, 10 Jun 2009 16:28:54 -0600 (MDT)
Received: from CMU-337868.WV.CC.CMU.EDU ([unknown] [10.7.250.178])
 by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 with ESMTPSA id <0KL1009ZZNRXFF10@mail-amer.sun.com>; Wed,
 10 Jun 2009 16:28:46 -0600 (MDT)
Date: Wed, 10 Jun 2009 15:28:41 -0700
From: Scott Rotondo <Scott.Rotondo@sun.com>
Subject: Re: cryptoadm(1M) enhancement for FIPS-140 mode [PSARC/2009/347
 FastTrack timeout 06/17/2009]
In-reply-to: <4A2F0EC0.5060507@sun.com>
Sender: Scott.Rotondo@sun.com
To: Glenn Brunette <Glenn.Brunette@sun.com>
Cc: Krishna Yenduri <krishna@bluesky.SFBay.Sun.COM>, PSARC-ext@sun.com,
        crypto-discuss@opensolaris.org, fips-cf-team@sun.com
Message-id: <4A303399.5050009@sun.com>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200906092217.n59MH4H7005843@bluesky.SFBay.Sun.COM>
 <4A2F0EC0.5060507@sun.com>
User-Agent: Thunderbird 2.0.0.21 (Macintosh/20090302)
Status: RO
Content-Length: 721

>>
>> 4.3  Interfaces:
>>
>>   The following new options are added to cryptoadm(1M) sub-commands
>>       cryptoadm list fips-140
>>       cryptoadm enable fips-140
>>       cryptoadm disable fips-140

Very minor issue: People often refer informally to "FIPS mode" rather 
than the more cumbersome FIPS 140 or FIPS 140-2. Unless you expect other 
FIPS standards to apply to the crypto framework, maybe you could save 
users a little typing:

	cryptoadm list fips
	cryptoadm enable fips
	cryptoadm disable fips

I don't feel strongly about this; just a suggestion.

	Scott

-- 
Scott Rotondo
Principal Engineer, Solaris Security Technologies
President, Trusted Computing Group
Phone/FAX: +1 408 850 3655 (Internal x68278)

From Hai-May.Chao@sun.com Wed Jun 10 15:39:12 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n5AMdBXk017943
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 10 Jun 2009 15:39:12 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n5AMd6kY023270;
	Thu, 11 Jun 2009 06:39:07 +0800 (SGT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KL10000NO96G800@brm-avmta-1.central.sun.com>; Wed,
 10 Jun 2009 16:39:06 -0600 (MDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.59])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KL100M2NO95L3C0@brm-avmta-1.central.sun.com>; Wed,
 10 Jun 2009 16:39:05 -0600 (MDT)
Received: from [129.150.12.28]
 (vpn-129-150-12-28.SFBay.Sun.COM [129.150.12.28])	by
 jurassic-x4600.sfbay.sun.com (8.14.3+Sun/8.14.3) with ESMTP id n5AMd4GL130556;
 Wed, 10 Jun 2009 15:39:04 -0700 (PDT)
Date: Wed, 10 Jun 2009 15:39:11 -0700
From: Hai-May Chao <Hai-May.Chao@sun.com>
Subject: Re: cryptoadm(1M) enhancement for FIPS-140 mode [PSARC/2009/347
 FastTrack timeout 06/17/2009]
In-reply-to: <4A303399.5050009@sun.com>
To: Scott Rotondo <Scott.Rotondo@sun.com>
Cc: Glenn Brunette <Glenn.Brunette@sun.com>,
        Krishna Yenduri <krishna@bluesky.SFBay.Sun.COM>, PSARC-ext@sun.com,
        crypto-discuss@opensolaris.org, fips-cf-team@sun.com
Message-id: <4A30360F.5050200@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200906092217.n59MH4H7005843@bluesky.SFBay.Sun.COM>
 <4A2F0EC0.5060507@sun.com> <4A303399.5050009@sun.com>
User-Agent: Thunderbird 2.0b2 (X11/20070227)
Status: RO
Content-Length: 782

Scott Rotondo wrote:
>>>
>>> 4.3  Interfaces:
>>>
>>>   The following new options are added to cryptoadm(1M) sub-commands
>>>       cryptoadm list fips-140
>>>       cryptoadm enable fips-140
>>>       cryptoadm disable fips-140
>
> Very minor issue: People often refer informally to "FIPS mode" rather 
> than the more cumbersome FIPS 140 or FIPS 140-2. Unless you expect 
> other FIPS standards to apply to the crypto framework, maybe you could 
> save users a little typing:
>
>     cryptoadm list fips
>     cryptoadm enable fips
>     cryptoadm disable fips
>
> I don't feel strongly about this; just a suggestion.
>
>     Scott
>

Hi Scott,

We had "fips" originally, and decided to change it to "fips-140" as we have
other FIPS standard like 186 used in framework.

Hai-May


From Darren.Moffat@sun.com Tue Jun 16 02:30:48 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n5G9UlZH016095
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 16 Jun 2009 02:30:48 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n5G9UWK0027295;
	Tue, 16 Jun 2009 17:30:46 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KLB0070DRRA4900@nwk-avmta-2.sfbay.sun.com>; Tue,
 16 Jun 2009 02:30:46 -0700 (PDT)
Received: from gmp-eb-inf-2.sun.com ([192.18.6.24])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KLB00E7IRR896D0@nwk-avmta-2.sfbay.sun.com>; Tue,
 16 Jun 2009 02:30:45 -0700 (PDT)
Received: from fe-emea-10.sun.com (gmp-eb-lb-1-fe3.eu.sun.com [192.18.6.10])
	by gmp-eb-inf-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n5G9UiAr024540; Tue,
 16 Jun 2009 09:30:44 +0000 (GMT)
Received: from conversion-daemon.fe-emea-10.sun.com by fe-emea-10.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 id <0KLB00500Q9A2300@fe-emea-10.sun.com>; Tue, 16 Jun 2009 10:30:44 +0100 (BST)
Received: from [129.156.173.199] ([unknown] [129.156.173.199])
 by fe-emea-10.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 with ESMTPSA id <0KLB00L92RQSQPA0@fe-emea-10.sun.com>; Tue,
 16 Jun 2009 10:30:29 +0100 (BST)
Date: Tue, 16 Jun 2009 10:30:28 +0100
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: cryptoadm(1M) enhancement for FIPS-140 mode [PSARC/2009/347
 FastTrack timeout 06/17/2009]
In-reply-to: <4A303399.5050009@sun.com>
Sender: Darren.Moffat@sun.com
To: Scott Rotondo <Scott.Rotondo@sun.com>
Cc: Glenn Brunette <Glenn.Brunette@sun.com>,
        Krishna Yenduri <krishna@bluesky.SFBay.Sun.COM>, PSARC-ext@sun.com,
        crypto-discuss@opensolaris.org, fips-cf-team@sun.com
Message-id: <4A376634.3090600@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200906092217.n59MH4H7005843@bluesky.SFBay.Sun.COM>
 <4A2F0EC0.5060507@sun.com> <4A303399.5050009@sun.com>
User-Agent: Thunderbird 2.0.0.18 (X11/20090127)
Status: RO
Content-Length: 951

Scott Rotondo wrote:
>>>
>>> 4.3  Interfaces:
>>>
>>>   The following new options are added to cryptoadm(1M) sub-commands
>>>       cryptoadm list fips-140
>>>       cryptoadm enable fips-140
>>>       cryptoadm disable fips-140
> 
> Very minor issue: People often refer informally to "FIPS mode" rather 
> than the more cumbersome FIPS 140 or FIPS 140-2. Unless you expect other 
> FIPS standards to apply to the crypto framework, maybe you could save 
> users a little typing:

There are other FIPS standards, in particular those that include the 
definitions of particular algorithms or PRNG systems.

>     cryptoadm list fips
>     cryptoadm enable fips
>     cryptoadm disable fips

That is what we had originally and I suggested to the team to change it 
to fips-140 because there are lots and lots of FIPS standards and this 
change to cryptoadm only deals with FIPS 140 not 186 or 86 ... So having 
just "fips" is wrong.

-- 
Darren J Moffat

From huie-ying.lee@sun.com Tue Jun 16 10:38:45 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n5GHcigC026334
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 16 Jun 2009 10:38:45 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n5GHcExO009045;
	Wed, 17 Jun 2009 01:38:36 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KLC00D0RECA0D00@nwk-avmta-2.sfbay.sun.com>; Tue,
 16 Jun 2009 10:38:34 -0700 (PDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.63])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KLC002EMEC9SFE0@nwk-avmta-2.sfbay.sun.com>; Tue,
 16 Jun 2009 10:38:33 -0700 (PDT)
Received: from [129.146.108.12] (comforter.SFBay.Sun.COM [129.146.108.12])
	by jurassic-x4600.sfbay.sun.com (8.14.3+Sun/8.14.3)
 with ESMTP id n5GHcWJS811574; Tue, 16 Jun 2009 10:38:32 -0700 (PDT)
Date: Tue, 16 Jun 2009 10:36:34 -0700
From: Huie-Ying Lee <huie-ying.lee@sun.com>
Subject: Re: cryptoadm(1M) enhancement for FIPS-140 mode [PSARC/2009/347
	FastTrack timeout 06/17/2009]
In-reply-to: <4A376634.3090600@Sun.COM>
To: Darren J Moffat <Darren.Moffat@sun.com>
Cc: Scott Rotondo <Scott.Rotondo@sun.com>, PSARC-ext@sun.com,
        Glenn Brunette <Glenn.Brunette@sun.com>, fips-cf-team@sun.com,
        Krishna Yenduri <krishna@bluesky.SFBay.Sun.COM>,
        crypto-discuss@opensolaris.org
Message-id: <4A37D822.3090407@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200906092217.n59MH4H7005843@bluesky.SFBay.Sun.COM>
 <4A2F0EC0.5060507@sun.com> <4A303399.5050009@sun.com>
 <4A376634.3090600@Sun.COM>
User-Agent: Thunderbird 2.0.0.18 (X11/20081215)
Status: RO
Content-Length: 1420

On 06/16/09 02:30, Darren J Moffat wrote:
> Scott Rotondo wrote:
>>>>
>>>> 4.3  Interfaces:
>>>>
>>>>   The following new options are added to cryptoadm(1M) sub-commands
>>>>       cryptoadm list fips-140
>>>>       cryptoadm enable fips-140
>>>>       cryptoadm disable fips-140
>>
>> Very minor issue: People often refer informally to "FIPS mode" rather 
>> than the more cumbersome FIPS 140 or FIPS 140-2. Unless you expect 
>> other FIPS standards to apply to the crypto framework, maybe you 
>> could save users a little typing:
>
> There are other FIPS standards, in particular those that include the 
> definitions of particular algorithms or PRNG systems.
>
>>     cryptoadm list fips
>>     cryptoadm enable fips
>>     cryptoadm disable fips
>
> That is what we had originally and I suggested to the team to change 
> it to fips-140 because there are lots and lots of FIPS standards and 
> this change to cryptoadm only deals with FIPS 140 not 186 or 86 ... So 
> having just "fips" is wrong.
>
How about making it more flexible as following:

   cryptoadm list fips[=fips_number_list]
   cryptoadm enable fips[=fips_number_list]
   cryptoadm disable fips[=fips_number_list]

 The "=fips_number_list" part is optional.
  The current supported FIPS number is 140, which is the default for now 
also.

Therefore,  "cryptoadm enable  fips" and "cryptoadm enable fips=140" 
refer to the same thing.

Huie-Ying





From gdamore@sun.com Tue Jun 16 10:48:14 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n5GHmEua026965
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 16 Jun 2009 10:48:14 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n5GHmBCQ052769;
	Tue, 16 Jun 2009 11:48:13 -0600 (MDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KLC00L1XESC6800@brm-avmta-1.central.sun.com>; Tue,
 16 Jun 2009 11:48:12 -0600 (MDT)
Received: from sca-es-mail-1.sun.com ([192.18.43.132])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KLC00IF2ESCW4E0@brm-avmta-1.central.sun.com>; Tue,
 16 Jun 2009 11:48:12 -0600 (MDT)
Received: from fe-sfbay-10.sun.com ([192.18.43.129])
	by sca-es-mail-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n5GHmCeT009289;
 Tue, 16 Jun 2009 10:48:12 -0700 (PDT)
Received: from conversion-daemon.fe-sfbay-10.sun.com by fe-sfbay-10.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 id <0KLC00I00EJ34B00@fe-sfbay-10.sun.com>; Tue,
 16 Jun 2009 10:48:11 -0700 (PDT)
Received: from [192.168.251.11] ([unknown] [76.93.15.33])
 by fe-sfbay-10.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 with ESMTPSA id <0KLC00C3FERYGYB0@fe-sfbay-10.sun.com>; Tue,
 16 Jun 2009 10:47:59 -0700 (PDT)
Date: Tue, 16 Jun 2009 10:47:58 -0700
From: "Garrett D'Amore" <gdamore@sun.com>
Subject: Re: cryptoadm(1M) enhancement for FIPS-140 mode [PSARC/2009/347
	FastTrack timeout 06/17/2009]
In-reply-to: <4A37D822.3090407@sun.com>
Sender: Garrett.Damore@sun.com
To: Huie-Ying Lee <huie-ying.lee@sun.com>
Cc: Darren J Moffat <Darren.Moffat@sun.com>,
        Scott Rotondo <Scott.Rotondo@sun.com>, PSARC-ext@sun.com,
        Glenn Brunette <Glenn.Brunette@sun.com>, fips-cf-team@sun.com,
        Krishna Yenduri <krishna@bluesky.SFBay.Sun.COM>,
        crypto-discuss@opensolaris.org
Message-id: <4A37DACE.4080203@sun.com>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200906092217.n59MH4H7005843@bluesky.SFBay.Sun.COM>
 <4A2F0EC0.5060507@sun.com> <4A303399.5050009@sun.com>
 <4A376634.3090600@Sun.COM> <4A37D822.3090407@sun.com>
User-Agent: Thunderbird 2.0.0.18 (X11/20081201)
Status: RO
Content-Length: 2562

Huie-Ying Lee wrote:
> On 06/16/09 02:30, Darren J Moffat wrote:
>> Scott Rotondo wrote:
>>>>>
>>>>> 4.3  Interfaces:
>>>>>
>>>>>   The following new options are added to cryptoadm(1M) sub-commands
>>>>>       cryptoadm list fips-140
>>>>>       cryptoadm enable fips-140
>>>>>       cryptoadm disable fips-140
>>>
>>> Very minor issue: People often refer informally to "FIPS mode" 
>>> rather than the more cumbersome FIPS 140 or FIPS 140-2. Unless you 
>>> expect other FIPS standards to apply to the crypto framework, maybe 
>>> you could save users a little typing:
>>
>> There are other FIPS standards, in particular those that include the 
>> definitions of particular algorithms or PRNG systems.
>>
>>>     cryptoadm list fips
>>>     cryptoadm enable fips
>>>     cryptoadm disable fips
>>
>> That is what we had originally and I suggested to the team to change 
>> it to fips-140 because there are lots and lots of FIPS standards and 
>> this change to cryptoadm only deals with FIPS 140 not 186 or 86 ... 
>> So having just "fips" is wrong.
>>
> How about making it more flexible as following:
>
>   cryptoadm list fips[=fips_number_list]
>   cryptoadm enable fips[=fips_number_list]
>   cryptoadm disable fips[=fips_number_list]
>
> The "=fips_number_list" part is optional.
>  The current supported FIPS number is 140, which is the default for 
> now also.
>
> Therefore,  "cryptoadm enable  fips" and "cryptoadm enable fips=140" 
> refer to the same thing.
>
> Huie-Ying

If you look at how crypto is dealt with, all people care about is "is it 
FIPS certified".  All the time this means FIPS-140.  Nobody (that I've 
ever heard of) cares about enabling subsets of this.  (FIPS-86 mode 
might enable a FIPS-86 compliant RNG, but that should always be enabled 
anyway.  I'm not sure what FIPS-186 would mean in this context, since 
FIPS-186 is just the DSS signing method.)

While I understand that specifying "fips140" might be better (and avoid 
potential ambiguity later), I don't think "fips=<standard number>" is 
terribly useful.

What I *could* imagine is a way to imagine different levels of fips, 
e.g. "fips140=1" for just a level 1 compliance, etc.  Although even that 
seems a stretch since I can't imagine anyone recertifying the framework 
for more than a single level (which would normally be the highest level 
that it can reasonably achieve.)

My vote would just be "enable fips140", (which is shorter than 
"fips-140", and eliminates possible complexity that would never actually 
be used.)

In short, KISS.

    - Garrett
>
>
>
>


From Darren.Moffat@sun.com Tue Jun 16 12:05:24 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n5GJ5NAN012368
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 16 Jun 2009 12:05:23 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n5GJ4bRm023369;
	Wed, 17 Jun 2009 03:05:22 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KLC00D1FICM2600@nwk-avmta-1.sfbay.Sun.COM>; Tue,
 16 Jun 2009 12:05:10 -0700 (PDT)
Received: from gmp-eb-inf-1.sun.com ([192.18.6.21])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KLC002QQICLZK70@nwk-avmta-1.sfbay.Sun.COM>; Tue,
 16 Jun 2009 12:05:10 -0700 (PDT)
Received: from fe-emea-09.sun.com (gmp-eb-lb-1-fe3.eu.sun.com [192.18.6.10])
	by gmp-eb-inf-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n5GJ59rW000094; Tue,
 16 Jun 2009 19:05:09 +0000 (GMT)
Received: from conversion-daemon.fe-emea-09.sun.com by fe-emea-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 id <0KLC00C00I5AQ200@fe-emea-09.sun.com>; Tue, 16 Jun 2009 20:05:09 +0100 (BST)
Received: from [129.156.173.199] ([unknown] [129.156.173.199])
 by fe-emea-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 with ESMTPSA id <0KLC0065VICKIV70@fe-emea-09.sun.com>; Tue,
 16 Jun 2009 20:05:08 +0100 (BST)
Date: Tue, 16 Jun 2009 20:05:08 +0100
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: cryptoadm(1M) enhancement for FIPS-140 mode [PSARC/2009/347
	FastTrack timeout 06/17/2009]
In-reply-to: <4A37D822.3090407@sun.com>
Sender: Darren.Moffat@sun.com
To: Huie-Ying Lee <Huie-Ying.Lee@sun.com>
Cc: Scott Rotondo <Scott.Rotondo@sun.com>, PSARC-ext@sun.com,
        Glenn Brunette <Glenn.Brunette@sun.com>, fips-cf-team@sun.com,
        Krishna Yenduri <krishna@bluesky.SFBay.Sun.COM>,
        crypto-discuss@opensolaris.org
Message-id: <4A37ECE4.2010502@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200906092217.n59MH4H7005843@bluesky.SFBay.Sun.COM>
 <4A2F0EC0.5060507@sun.com> <4A303399.5050009@sun.com>
 <4A376634.3090600@Sun.COM> <4A37D822.3090407@sun.com>
User-Agent: Thunderbird 2.0.0.18 (X11/20090127)
Status: RO
Content-Length: 2096

Huie-Ying Lee wrote:
> On 06/16/09 02:30, Darren J Moffat wrote:
>> Scott Rotondo wrote:
>>>>>
>>>>> 4.3  Interfaces:
>>>>>
>>>>>   The following new options are added to cryptoadm(1M) sub-commands
>>>>>       cryptoadm list fips-140
>>>>>       cryptoadm enable fips-140
>>>>>       cryptoadm disable fips-140
>>>
>>> Very minor issue: People often refer informally to "FIPS mode" rather 
>>> than the more cumbersome FIPS 140 or FIPS 140-2. Unless you expect 
>>> other FIPS standards to apply to the crypto framework, maybe you 
>>> could save users a little typing:
>>
>> There are other FIPS standards, in particular those that include the 
>> definitions of particular algorithms or PRNG systems.
>>
>>>     cryptoadm list fips
>>>     cryptoadm enable fips
>>>     cryptoadm disable fips
>>
>> That is what we had originally and I suggested to the team to change 
>> it to fips-140 because there are lots and lots of FIPS standards and 
>> this change to cryptoadm only deals with FIPS 140 not 186 or 86 ... So 
>> having just "fips" is wrong.
>>
> How about making it more flexible as following:
> 
>   cryptoadm list fips[=fips_number_list]
>   cryptoadm enable fips[=fips_number_list]
>   cryptoadm disable fips[=fips_number_list]
> 
> The "=fips_number_list" part is optional.
>  The current supported FIPS number is 140, which is the default for now 
> also.
> 
> Therefore,  "cryptoadm enable  fips" and "cryptoadm enable fips=140" 
> refer to the same thing.

I don't think that is desirable because the other FIPS standards that 
are relevant to the crypto framework aren't things we would want to 
enable disable based on their FIPS document number - for example they 
define the SHA1 algorithm but we would enable/disable that as a mechanism.

Given that the admin would need to be reading the cryptoadm(1M) man page 
or the equivalent docs.sun.com task to find this and know about it I 
don't think that calling it fips-140 is a problem, I do think that 
having fips=140 or fips is a problem though (the former being 
unnecessary the later being to vague).

-- 
Darren J Moffat

From Darren.Moffat@sun.com Tue Jun 16 12:07:19 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n5GJ7J17027625
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 16 Jun 2009 12:07:19 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n5GJ7IsQ028166;
	Tue, 16 Jun 2009 12:07:19 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KLC00I0PIG4AU00@nwk-avmta-2.sfbay.sun.com>; Tue,
 16 Jun 2009 12:07:16 -0700 (PDT)
Received: from gmp-eb-inf-2.sun.com ([192.18.6.24])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KLC00E9FIG2F140@nwk-avmta-2.sfbay.sun.com>; Tue,
 16 Jun 2009 12:07:15 -0700 (PDT)
Received: from fe-emea-09.sun.com (gmp-eb-lb-1-fe3.eu.sun.com [192.18.6.10])
	by gmp-eb-inf-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n5GJ7Ee1014819; Tue,
 16 Jun 2009 19:07:14 +0000 (GMT)
Received: from conversion-daemon.fe-emea-09.sun.com by fe-emea-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 id <0KLC00B00I26OP00@fe-emea-09.sun.com>; Tue, 16 Jun 2009 20:07:14 +0100 (BST)
Received: from [129.156.173.199] ([unknown] [129.156.173.199])
 by fe-emea-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 with ESMTPSA id <0KLC00663IG2IV70@fe-emea-09.sun.com>; Tue,
 16 Jun 2009 20:07:14 +0100 (BST)
Date: Tue, 16 Jun 2009 20:07:13 +0100
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: cryptoadm(1M) enhancement for FIPS-140 mode [PSARC/2009/347
	FastTrack timeout 06/17/2009]
In-reply-to: <4A37DACE.4080203@sun.com>
Sender: Darren.Moffat@sun.com
To: "Garrett D'Amore" <gdamore@sun.com>
Cc: Huie-Ying Lee <Huie-Ying.Lee@sun.com>,
        Scott Rotondo <Scott.Rotondo@sun.com>, PSARC-ext@sun.com,
        Glenn Brunette <Glenn.Brunette@sun.com>, fips-cf-team@sun.com,
        Krishna Yenduri <krishna@bluesky.SFBay.Sun.COM>,
        crypto-discuss@opensolaris.org
Message-id: <4A37ED61.3060807@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200906092217.n59MH4H7005843@bluesky.SFBay.Sun.COM>
 <4A2F0EC0.5060507@sun.com> <4A303399.5050009@sun.com>
 <4A376634.3090600@Sun.COM> <4A37D822.3090407@sun.com>
 <4A37DACE.4080203@sun.com>
User-Agent: Thunderbird 2.0.0.18 (X11/20090127)
Status: RO
Content-Length: 2824

Garrett D'Amore wrote:
> Huie-Ying Lee wrote:
>> On 06/16/09 02:30, Darren J Moffat wrote:
>>> Scott Rotondo wrote:
>>>>>>
>>>>>> 4.3  Interfaces:
>>>>>>
>>>>>>   The following new options are added to cryptoadm(1M) sub-commands
>>>>>>       cryptoadm list fips-140
>>>>>>       cryptoadm enable fips-140
>>>>>>       cryptoadm disable fips-140
>>>>
>>>> Very minor issue: People often refer informally to "FIPS mode" 
>>>> rather than the more cumbersome FIPS 140 or FIPS 140-2. Unless you 
>>>> expect other FIPS standards to apply to the crypto framework, maybe 
>>>> you could save users a little typing:
>>>
>>> There are other FIPS standards, in particular those that include the 
>>> definitions of particular algorithms or PRNG systems.
>>>
>>>>     cryptoadm list fips
>>>>     cryptoadm enable fips
>>>>     cryptoadm disable fips
>>>
>>> That is what we had originally and I suggested to the team to change 
>>> it to fips-140 because there are lots and lots of FIPS standards and 
>>> this change to cryptoadm only deals with FIPS 140 not 186 or 86 ... 
>>> So having just "fips" is wrong.
>>>
>> How about making it more flexible as following:
>>
>>   cryptoadm list fips[=fips_number_list]
>>   cryptoadm enable fips[=fips_number_list]
>>   cryptoadm disable fips[=fips_number_list]
>>
>> The "=fips_number_list" part is optional.
>>  The current supported FIPS number is 140, which is the default for 
>> now also.
>>
>> Therefore,  "cryptoadm enable  fips" and "cryptoadm enable fips=140" 
>> refer to the same thing.
>>
>> Huie-Ying
> 
> If you look at how crypto is dealt with, all people care about is "is it 
> FIPS certified".  All the time this means FIPS-140.  Nobody (that I've 
> ever heard of) cares about enabling subsets of this.  (FIPS-86 mode 
> might enable a FIPS-86 compliant RNG, but that should always be enabled 
> anyway.  I'm not sure what FIPS-186 would mean in this context, since 
> FIPS-186 is just the DSS signing method.)
> 
> While I understand that specifying "fips140" might be better (and avoid 
> potential ambiguity later), I don't think "fips=<standard number>" is 
> terribly useful.
> 
> What I *could* imagine is a way to imagine different levels of fips, 
> e.g. "fips140=1" for just a level 1 compliance, etc.  Although even that 
> seems a stretch since I can't imagine anyone recertifying the framework 
> for more than a single level (which would normally be the highest level 
> that it can reasonably achieve.)


As you can see from my posts you and I agree on this.

> My vote would just be "enable fips140", (which is shorter than 
> "fips-140", and eliminates possible complexity that would never actually 
> be used.)

I don't care one way or the other other if the '-' is in there or not, 
in fact allowing both is probably a good idea.

-- 
Darren J Moffat

From Darren.Moffat@sun.com Tue Jun 16 12:16:08 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n5GJG8k5028722
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 16 Jun 2009 12:16:08 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n5GJFuc3001476;
	Tue, 16 Jun 2009 20:16:07 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KLC00623IUTWN00@brm-avmta-1.central.sun.com>; Tue,
 16 Jun 2009 13:16:06 -0600 (MDT)
Received: from gmp-eb-inf-2.sun.com ([192.18.6.24])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KLC00LY0IUSBZ50@brm-avmta-1.central.sun.com>; Tue,
 16 Jun 2009 13:16:04 -0600 (MDT)
Received: from fe-emea-10.sun.com (gmp-eb-lb-1-fe3.eu.sun.com [192.18.6.10])
	by gmp-eb-inf-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n5GJG4Mc015233; Tue,
 16 Jun 2009 19:16:04 +0000 (GMT)
Received: from conversion-daemon.fe-emea-10.sun.com by fe-emea-10.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 id <0KLC00B00IPDDM00@fe-emea-10.sun.com>; Tue, 16 Jun 2009 20:16:03 +0100 (BST)
Received: from [129.156.173.199] ([unknown] [129.156.173.199])
 by fe-emea-10.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 with ESMTPSA id <0KLC006W3IURM350@fe-emea-10.sun.com>; Tue,
 16 Jun 2009 20:16:03 +0100 (BST)
Date: Tue, 16 Jun 2009 20:16:03 +0100
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: cryptoadm(1M) enhancement for FIPS-140 mode [PSARC/2009/347
	FastTrack timeout 06/17/2009]
In-reply-to: <4A37ECE4.2010502@Sun.COM>
Sender: Darren.Moffat@sun.com
To: Huie-Ying Lee <Huie-Ying.Lee@sun.com>
Cc: Scott Rotondo <Scott.Rotondo@sun.com>, PSARC-ext@sun.com,
        Glenn Brunette <Glenn.Brunette@sun.com>, fips-cf-team@sun.com,
        Krishna Yenduri <krishna@bluesky.SFBay.Sun.COM>,
        crypto-discuss@opensolaris.org
Message-id: <4A37EF73.9050802@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200906092217.n59MH4H7005843@bluesky.SFBay.Sun.COM>
 <4A2F0EC0.5060507@sun.com> <4A303399.5050009@sun.com>
 <4A376634.3090600@Sun.COM> <4A37D822.3090407@sun.com>
 <4A37ECE4.2010502@Sun.COM>
User-Agent: Thunderbird 2.0.0.18 (X11/20090127)
Status: RO
Content-Length: 271

I approve of the original spec of this project and don't believe it 
needs modifying.

If the project team wishes to take the suggestion of allowing fips-140 
and fips140 as equivalent I'm happy with that too but don't require it.

In other words +1.

--
Darren J Moffat

From Scott.Rotondo@sun.com Tue Jun 16 15:08:33 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n5GM8W1F006780
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 16 Jun 2009 15:08:32 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n5GM8SJZ022181;
	Wed, 17 Jun 2009 06:08:31 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KLC00601QU5OJ00@nwk-avmta-2.sfbay.sun.com>; Tue,
 16 Jun 2009 15:08:29 -0700 (PDT)
Received: from brmea-mail-4.sun.com ([192.18.98.36])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KLC00E5KQU4F5D0@nwk-avmta-2.sfbay.sun.com>; Tue,
 16 Jun 2009 15:08:28 -0700 (PDT)
Received: from fe-amer-10.sun.com ([192.18.109.80])
	by brmea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n5GM8Svx006068; Tue,
 16 Jun 2009 22:08:28 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 id <0KLC00E00Q3ERN00@mail-amer.sun.com>; Tue, 16 Jun 2009 16:08:28 -0600 (MDT)
Received: from viaggio.local ([unknown] [12.175.68.130])
 by mail-amer.sun.com (Sun Java(tm) System Messaging Server 7u2-7.02 64bit
 (built Apr 16 2009)) with ESMTPSA id <0KLC00KOGQTSH2G0@mail-amer.sun.com>; Tue,
 16 Jun 2009 16:08:22 -0600 (MDT)
Date: Tue, 16 Jun 2009 15:08:22 -0700
From: Scott Rotondo <Scott.Rotondo@sun.com>
Subject: Re: cryptoadm(1M) enhancement for FIPS-140 mode [PSARC/2009/347
	FastTrack timeout 06/17/2009]
In-reply-to: <4A37EF73.9050802@Sun.COM>
Sender: Scott.Rotondo@sun.com
To: Darren J Moffat <Darren.Moffat@sun.com>
Cc: Huie-Ying Lee <Huie-Ying.Lee@sun.com>, PSARC-ext@sun.com,
        Glenn Brunette <Glenn.Brunette@sun.com>, fips-cf-team@sun.com,
        Krishna Yenduri <krishna@bluesky.SFBay.Sun.COM>,
        crypto-discuss@opensolaris.org
Message-id: <4A3817D6.2010808@sun.com>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200906092217.n59MH4H7005843@bluesky.SFBay.Sun.COM>
 <4A2F0EC0.5060507@sun.com> <4A303399.5050009@sun.com>
 <4A376634.3090600@Sun.COM> <4A37D822.3090407@sun.com>
 <4A37ECE4.2010502@Sun.COM> <4A37EF73.9050802@Sun.COM>
User-Agent: Thunderbird 2.0.0.21 (Macintosh/20090302)
Status: RO
Content-Length: 610

Darren J Moffat wrote:
> I approve of the original spec of this project and don't believe it 
> needs modifying.
> 
> If the project team wishes to take the suggestion of allowing fips-140 
> and fips140 as equivalent I'm happy with that too but don't require it.

I agree. I suggested changing fips-140 to fips, but I understand and 
accept the argument against doing so. I do like the idea of at least 
optionally allowing fips140 without the hyphen.

	Scott

-- 
Scott Rotondo
Principal Engineer, Solaris Security Technologies
President, Trusted Computing Group
Phone/FAX: +1 408 850 3655 (Internal x68278)

From Hai-May.Chao@sun.com Tue Jun 16 15:48:45 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n5GMmjE2008442
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 16 Jun 2009 15:48:45 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n5GMmgLY008738;
	Tue, 16 Jun 2009 16:48:42 -0600 (MDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KLC00301SP6JF00@brm-avmta-1.central.sun.com>; Tue,
 16 Jun 2009 16:48:42 -0600 (MDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.59])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KLC00LASSP5D450@brm-avmta-1.central.sun.com>; Tue,
 16 Jun 2009 16:48:41 -0600 (MDT)
Received: from [129.146.108.240] (newimage.SFBay.Sun.COM [129.146.108.240])
	by jurassic-x4600.sfbay.sun.com (8.14.3+Sun/8.14.3)
 with ESMTP id n5GMmePb875414; Tue, 16 Jun 2009 15:48:41 -0700 (PDT)
Date: Tue, 16 Jun 2009 15:48:22 -0700
From: Hai-May Chao <Hai-May.Chao@sun.com>
Subject: Re: cryptoadm(1M) enhancement for FIPS-140 mode [PSARC/2009/347
	FastTrack timeout 06/17/2009]
In-reply-to: <4A37EF73.9050802@Sun.COM>
To: Darren J Moffat <Darren.Moffat@sun.com>
Cc: Huie-Ying Lee <Huie-Ying.Lee@sun.com>, fips-cf-team@sun.com,
        crypto-discuss@opensolaris.org,
        Glenn Brunette <Glenn.Brunette@sun.com>, PSARC-ext@sun.com,
        Scott Rotondo <Scott.Rotondo@sun.com>,
        Krishna Yenduri <krishna@bluesky.SFBay.Sun.COM>
Message-id: <4A382136.7050201@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200906092217.n59MH4H7005843@bluesky.SFBay.Sun.COM>
 <4A2F0EC0.5060507@sun.com> <4A303399.5050009@sun.com>
 <4A376634.3090600@Sun.COM> <4A37D822.3090407@sun.com>
 <4A37ECE4.2010502@Sun.COM> <4A37EF73.9050802@Sun.COM>
User-Agent: Thunderbird 2.0.0.18 (X11/20081215)
Status: RO
Content-Length: 355

Darren J Moffat wrote:
> I approve of the original spec of this project and don't believe it 
> needs modifying.
> 
> If the project team wishes to take the suggestion of allowing fips-140 
> and fips140 as equivalent I'm happy with that too but don't require it.
> 
> In other words +1.
> 

Thanks! We would prefer leaving it as it stands now.

Hai-May


From bhargava.yenduri@sun.com Wed Jun 17 16:23:00 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n5HNMxYh009466
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 17 Jun 2009 16:22:59 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n5HNMkcR011999;
	Thu, 18 Jun 2009 00:22:58 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KLE00501OYATU00@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 17 Jun 2009 16:22:58 -0700 (PDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.59])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KLE001P5OYALQ50@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 17 Jun 2009 16:22:58 -0700 (PDT)
Received: from [129.150.13.24]
 (vpn-129-150-13-24.SFBay.Sun.COM [129.150.13.24])	by
 jurassic-x4600.sfbay.sun.com (8.14.3+Sun/8.14.3) with ESMTP id n5HNMsjS123137
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Wed,
 17 Jun 2009 16:22:57 -0700 (PDT)
Date: Wed, 17 Jun 2009 16:22:55 -0700
From: Krishna Yenduri <bhargava.yenduri@sun.com>
Subject: Re: cryptoadm(1M) enhancement for FIPS-140 mode [PSARC/2009/347
 FastTrack timeout 06/17/2009]
In-reply-to: <200906092217.n59MH4H7005843@bluesky.SFBay.Sun.COM>
To: psarc-ext@sun.com
Cc: fips-cf-team@sun.com
Message-id: <4A397ACF.60407@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200906092217.n59MH4H7005843@bluesky.SFBay.Sun.COM>
User-Agent: Thunderbird 2.0.0.21 (X11/20090409)
Status: RO
Content-Length: 65


 This case was approved during today's PSARC meeting.

-Krishna

From Valerie.Fenwick@sun.com Wed Jun 17 16:23:22 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n5HNNLS3009493
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 17 Jun 2009 16:23:22 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n5HNMgbI011963;
	Thu, 18 Jun 2009 00:23:19 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KLE00D09OYU6L00@brm-avmta-1.central.sun.com>; Wed,
 17 Jun 2009 17:23:18 -0600 (MDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.59])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KLE003ZJOYTY680@brm-avmta-1.central.sun.com>; Wed,
 17 Jun 2009 17:23:18 -0600 (MDT)
Received: from jurassic (jurassic.SFBay.Sun.COM [129.146.17.55])
	by jurassic-x4600.sfbay.sun.com (8.14.3+Sun/8.14.3)
 with ESMTP id n5HNNH5I123233; Wed, 17 Jun 2009 16:23:17 -0700 (PDT)
Date: Wed, 17 Jun 2009 16:23:17 -0700 (PDT)
From: Valerie Bubb Fenwick <Valerie.Fenwick@sun.com>
Subject: Re: cryptoadm(1M) enhancement for FIPS-140 mode [PSARC/2009/347
 FastTrack timeout 06/17/2009]
In-reply-to: <4A397ACF.60407@sun.com>
Sender: bubbva@jurassic.Eng.Sun.COM
To: Krishna Yenduri <bhargava.yenduri@sun.com>
Cc: psarc-ext@sun.com, fips-cf-team@sun.com
Message-id: <Pine.GSO.4.64.0906171623120.134469@jurassic>
MIME-version: 1.0
Content-type: TEXT/PLAIN; charset=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200906092217.n59MH4H7005843@bluesky.SFBay.Sun.COM>
 <4A397ACF.60407@sun.com>
Status: RO
Content-Length: 297

On Wed, 17 Jun 2009, Krishna Yenduri wrote:

>
> This case was approved during today's PSARC meeting.

THank you, Krishna!

Valerie
-- 
Valerie Fenwick, http://blogs.sun.com/bubbva/ @bubbva
Solaris Security Technologies, Developer, Sun Microsystems, Inc.
17 Network Circle, Menlo Park, CA, 94025.

From Hai-May.Chao@sun.com Wed Jun 17 17:03:51 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n5I03pno011824
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 17 Jun 2009 17:03:51 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n5I03nC0008732;
	Wed, 17 Jun 2009 17:03:51 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KLE00H05QUEQX00@brm-avmta-1.central.sun.com>; Wed,
 17 Jun 2009 18:03:50 -0600 (MDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.59])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KLE0036BQUEY6C0@brm-avmta-1.central.sun.com>; Wed,
 17 Jun 2009 18:03:50 -0600 (MDT)
Received: from [129.146.108.240] (newimage.SFBay.Sun.COM [129.146.108.240])
	by jurassic-x4600.sfbay.sun.com (8.14.3+Sun/8.14.3)
 with ESMTP id n5I03nAw130233; Wed, 17 Jun 2009 17:03:50 -0700 (PDT)
Date: Wed, 17 Jun 2009 17:03:29 -0700
From: Hai-May Chao <Hai-May.Chao@sun.com>
Subject: Re: cryptoadm(1M) enhancement for FIPS-140 mode [PSARC/2009/347
 FastTrack timeout 06/17/2009]
In-reply-to: <4A397ACF.60407@sun.com>
To: Krishna Yenduri <bhargava.yenduri@sun.com>
Cc: psarc-ext@sun.com, fips-cf-team@sun.com
Message-id: <4A398451.9070209@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200906092217.n59MH4H7005843@bluesky.SFBay.Sun.COM>
 <4A397ACF.60407@sun.com>
User-Agent: Thunderbird 2.0.0.18 (X11/20081215)
Status: RO
Content-Length: 126

Krishna,

Thanks!!

Hai-May


Krishna Yenduri wrote:
> 
> This case was approved during today's PSARC meeting.
> 
> -Krishna


