Important News:SafeLogic's CryptoComply Achieves FIPS 140-3 Validation for 28 OEs and Receives Certificate #4781! Read the blog post!
The SafeLogic Blog
CryptoComply OpenSSL 3.0 FIPS Provider Delivers OpenSSL 3.0 + TLS 1.3 + FIPS Validated Cryptography
December 5, 2022 •Evgeny Gervis
Today, SafeLogic announced the general availability of CryptoComply OpenSSL 3.0 FIPS Provider, a new software product that allows organizations to implement OpenSSL 3.0 and TLS 1.3 with a FIPS-validated cryptographic module. This new software is available today from SafeLogic. FIPS 140 validation is required for products containing cryptography to be used by government agencies. It is also required by security regulations including FedRAMP, Common Criteria, CyberSecurity Maturity Model Security (CMMC) 2.0, and DoD APL among others.
Why Organizations are Moving to OpenSSL 3.0
OpenSSL is a widely used cryptographic library and OpenSSL 3.0 is the latest version of this library. It includes support for Transport Layer Security (TLS) version 1.3 by default. Many organizations are looking to implement OpenSSL 3.0 because it incorporates the newest architecture, latest APIs, most recent security bug fixes, and support for critical functions such as TLS 1.3.
One of the main benefits of using OpenSSL 3.0 with TLS 1.3 is its ability to improve connection speeds by up to two times over previous versions in some cases, making it ideal for websites or applications that need to provide users with fast load times and responsive performance under heavy loads. Additionally, OpenSSL 3.0 offers increased security thanks to its support for the latest generation of encryption algorithms.
Why Organizations Are Moving to TLS 1.3
TLS, or Transport Layer Security, is a protocol used to encrypt data as it traverses the internet. TLS 1.3 is the latest version of this protocol and includes many improvements over previous versions. Some of the key enhancements in TLS 1.3 include stronger encryption, faster time-to-key exchange that allows connections to be established more quickly than before, and support for modern transport protocols like QUIC that work well with mobile devices and other hardware without slowing down performance or increasing latency.
Overall, TLS 1.3 offers several substantial improvements over previous versions that make it faster and more secure than ever before. Therefore, if a website or application needs to establish encrypted connections with clients, it’s important to use the latest version of TLS to ensure maximum security and performance.
Using CryptoComply OpenSSL 3.0 FIPS Provider
Given NIST’s ongoing transition from FIPS 140-2 to FIPS 140-3 and other factors, the availability of FIPS-validated encryption modules for TLS 1.3 and OpenSSL 3.0 is extremely limited. As a result, organizations seeking to use OpenSSL 3.0 APIs and/or TLS 1.3 with a FIPS-validated cryptographic module have had limited options. With this new product, SafeLogic is giving companies in this situation a new alternative.
For existing SafeLogic CryptoComply customers, the new software is available as an optional upgrade. To use it, they will need to migrate to the OpenSSL 3.0 architecture and then use the CryptoComply OpenSSL 3.0 FIPS Provider as a drop-in replacement. CryptoComply customers can use this provider with their existing FIPS 140-2 certificate. Current CryptoComply customers not interested in upgrading to OpenSSL 3.0 / TLS 1.3 architecture do not need to take any action on this announcement.
For companies that are not existing CryptoComply for Server (CCS) customers yet want to use OpenSSL 3.0 / TLS 1.3 with a FIPS-validated module, CryptoComply OpenSSL 3.0 FIPS Provider is also a good option. With SafeLogic’s RapidCert program, companies can obtain a FIPS-validated encryption module and a listing on the NIST FIPS 140 certification website in as little as two months. Furthermore, their FIPS-validated encryption module will work with OpenSSL 3.0 and TLS 1.3
To learn more about SafeLogic’s CryptoComply OpenSSL 3.0 FIPS Provider or obtain a download, click on this link to request a consultation with a SafeLogic encryption expert.
Evgeny Gervis
Evgeny is the CEO of SafeLogic.
Popular Posts
Search for posts
Tags
- FIPS 140 (111)
- FIPS validation (85)
- Encryption (70)
- cryptography (68)
- NIST (62)
- CryptoComply (60)
- SafeLogic (58)
- Industry News (54)
- cryptographic module (51)
- Conversations (49)
- CMVP (48)
- RapidCert (46)
- compliance (41)
- Ray Potter (33)
- SafeLogic News (33)
- Event (27)
- federal (27)
- CAVP (23)
- Cybersecurity (23)
- FIPS 140-3 (18)
- OpenSSL (16)
- government (14)
- FedRAMP (13)
- CryptoCompact (12)
- Cryptology (12)
- DoD (12)
- RSA (12)
- healthcare (12)
- partners (12)
- NSA (11)
- post-quantum cryptography (11)
- Cloud (9)
- PQC (9)
- security (9)
- CMMC (8)
- Suite B (8)
- testing (8)
- whitepaper (8)
- Approved Products List (APL) (6)
- HITECH (6)
- ICMC (6)
- lab (6)
- CEO (5)
- NIST 800-171 (5)
- NIST 800-53 (5)
- OpenSSL 3.0 (5)
- iOS (5)
- procurement (5)
- C3PAO (4)
- Common Criteria (4)
- HITECH Act (4)
- deadline (4)
- encrypt (4)
- innovation (4)
- procure (4)
- public sector (4)
- Air Force (3)
- BSAFE (3)
- DFARS (3)
- HIPAA Safe Harbor (3)
- HITECH Safe Harbor (3)
- OpenSSL 1.1.1 (3)
- OpenSSL 3.x (3)
- POA&M (3)
- TLS 1.3 (3)
- magazine (3)
- queue (3)
- transition (3)
- 3PAO (2)
- ACVP (2)
- BAA (2)
- CIO (2)
- CSP (2)
- Cyber Defense Magazine (2)
- Defense Industrial Base (2)
- HIPAA security controls (2)
- Historical Status (2)
- MFA (2)
- OpenSSL 1.0.2 (2)
- SPRS (2)
- StateRAMP (2)
- entropy (2)
- excellence (2)
- finance (2)
- founder (2)
- gold (2)
- leader (2)
- maturity (2)
- overlap (2)
- pilot (2)
- rsa conference (2)
- solution (2)
- sponsors (2)
- sunset (2)
- vendor (2)
- year (2)
- Active Status (1)
- Alliance for Digital Innovation (1)
- Android (1)
- CIO Prime Views (1)
- DHS (1)
- DIU (1)
- DIUx (1)
- DOJ (1)
- DoDIN APL (1)
- Entropy Source Validation (1)
- FCA (1)
- FIPS Compliance (1)
- FISMA (1)
- GSA (1)
- HITRUST (1)
- Matt Cornelius (1)
- Matthew Cornelius (1)
- Maturity Model (1)
- NCCoE (1)
- OMB (1)
- SLED (1)
- SP800-131A (1)
- SP800-90A (1)
- TLS 1.1 (1)
- background (1)
- best (1)
- co-founder (1)
- codies (1)
- congress (1)
- cybertech (1)
- education (1)
- elliptic curve cryptography (1)
- extended (1)
- faq (1)
- fintech (1)
- fiscal (1)
- fiscal year (1)
- fraud (1)
- globee (1)
- hill (1)
- interview (1)
- kratos (1)
- libgcrypt (1)
- national cybersecurity strategy (1)
- opportunities (1)
- parallel (1)
- profile (1)
- public (1)
- representatives (1)
- reseller (1)
- senate (1)
- senators (1)
- simplify (1)
- state (1)
- stealth mode (1)
- story (1)
- terminology (1)
- trophy (1)
- whistleblower (1)
- whistleblowing (1)