Boston Linux & UNIX was originally founded in 1994 as part of The Boston Computer Society. We meet on the third Wednesday of each month, online, via Jitsi Meet.

BLU Discuss list archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Discuss] Good and Bad Crypto



Mike Small wrote:
> Btw. if having source code adds no value for verification, why do the
> FIPS CMVP procedures ask for it for the "Design Assurance" part of their
> review?
> http://csrc.nist.gov/groups/STM/cmvp/documents/CMVPFAQ.pdf

I'm surprised that nobody has chimed in on this one, yet, since quite a 
few of you have experienced ISO 9000 certification procedures. It's the 
same reason: documentation. Part of the validation process is 
examination of documents related to the product to ensure consistency 
with the submitted profiles. This includes comments in the source code.

-- 
Rich P.



BLU is a member of BostonUserGroups
BLU is a member of BostonUserGroups
We also thank MIT for the use of their facilities.

Valid HTML 4.01! Valid CSS!



Boston Linux & Unix / webmaster@blu.org