OpenSSL Library FIPS Module Support Policy

1. Principle

FIPS validated cryptography is delivered by the OpenSSL Library FIPS provider (the “module”), which is validated independently of the OpenSSL Library. A validated module is built from the source of the release it was validated against. It may be used, unchanged, together with a library built from any supported OpenSSL Library release from version 3.0 onwards: provider compatibility is maintained backward and forward across these releases, including future major release series, for as long as the module remains supported under this policy. The support status of an OpenSSL Library release version and the support status of an OpenSSL Library FIPS module are therefore distinct: a module can remain supported after its OpenSSL Library release version has reached end of life.

See the FIPS module guide, fips_module(7), and README-FIPS.md, which is included in every OpenSSL Library source distribution.

2. Commitment

Every OpenSSL Library FIPS module holding an active NIST CMVP certificate is supported for the lifetime of that certificate, up to the certificate’s end date, regardless of the support status of the OpenSSL Library release version it was built from.

For each such module:

  1. Every OpenSSL Library security issue (CVE) is assessed for impact within the module’s validated boundary.
  2. The assessment is disclosed publicly (Section 3).
  3. Maintenance source releases containing the relevant fixes are produced. While the module’s OpenSSL Library release version is publicly supported, the fixes ship in the ordinary OpenSSL Library releases. After public support for that release version has ended, the decision to produce a maintenance release, including its timing and which accumulated fixes it carries, is made at the discretion of the OpenSSL Corporation.
  4. Certificate updates are pursued via the CMVP CVE re-validation path, at the discretion of the OpenSSL Corporation, adding the fixed module version to the existing certificate while keeping previously validated versions valid wherever possible.

This work is funded and performed by the OpenSSL Corporation.

Support for a module ends on its certificate’s end date. This is a fixed calendar date, not subject to extension under this policy. For certificate #4985 (FIPS provider 3.1.2), the end date is 10 March 2030. The currently validated modules and their certificate end dates are published on the FIPS and CVEs page and in the NIST CMVP database.

3. Disclosure

4. Availability

5. The base library

This policy covers only code within the OpenSSL Library FIPS module boundary. The base OpenSSL library (code outside the boundary) must be built from a supported release train, publicly supported or covered by a support agreement, to receive security fixes and other improvements. Use of an end-of-life OpenSSL Library version is not covered by this policy; availability of a module maintenance release does not constitute extended support.

6. Going forward

Every OpenSSL Library minor release, including non-LTS releases, is kept in a state suitable for FIPS validation. Which releases undergo validation is decided by the OpenSSL Corporation, with the goal of keeping at least two validated modules overlapping at all times, so customers always have a validated target to move to. The 3.1.2 module is governed by this policy until certificate #4985 reaches its end date on 10 March 2030.