Government agency dragging its heels on OpenSSL validation (NewsForge)
[Posted January 20, 2006 by ris]
NewsForge
covers
an agency created by the US and Canadian governments to validate security
software. The agency has spent about two years reviewing the OpenSSL
project. "
According to CMVP director Randy Easter, a typical testing
cycle runs from several weeks to a few months, and the goal for NIST is to
process reports generated by the labs after testing within six to nine
weeks. Once processed, NIST either sends additional questions back to the
testing lab or moves forward with granting validation. The process
typically takes less than a year. Because testing on OpenSSL has now taken
more than twice that long, some have begun questioning the review process
and whether the open source toolkit is getting a fair shake by the
agency."
(
Log in to post comments)