You are viewing a plain text version of this content. The canonical link for it is here.
Posted to users@tomcat.apache.org by robingandhi21 <ro...@gmail.com> on 2008/01/12 15:15:06 UTC

Is Tomcat FIPS compliant

Please let me know if anybody has an idea about tomcat being FIPS compliant.

Thanks in advance
Robin Gandhi
-- 
View this message in context: http://www.nabble.com/Is-Tomcat-FIPS-compliant-tp14773897p14773897.html
Sent from the Tomcat - User mailing list archive at Nabble.com.


---------------------------------------------------------------------
To start a new topic, e-mail: users@tomcat.apache.org
To unsubscribe, e-mail: users-unsubscribe@tomcat.apache.org
For additional commands, e-mail: users-help@tomcat.apache.org


RE: Is Tomcat FIPS compliant

Posted by Jason Pyeron <jp...@pdinc.us>.
Under proper configuration and installation, yes it can be compliant, we
routinely set it up to handle CAC.

> -----Original Message-----
> From: Mark H. Wood,UL 0115A,+1 317 274 0749, 
> [mailto:mwood@mhw.ulib.iupui.edu] On Behalf Of Mark H. Wood
> Sent: Monday, January 14, 2008 10:00
> To: users@tomcat.apache.org
> Subject: Re: Is Tomcat FIPS compliant
> 
> That probably depends on which FIPS you mean.  There are at least 201
> different U.S. Federal Information Processing Standards.
> 
> -- 
> Mark H. Wood, Lead System Programmer   mwood@IUPUI.Edu
> Typically when a software vendor says that a product is "intuitive" he
> means the exact opposite.
> 
> 



-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
-                                                               -
- Jason Pyeron                      PD Inc. http://www.pdinc.us -
- Sr. Consultant                    10 West 24th Street #100    -
- +1 (443) 269-1555 x333            Baltimore, Maryland 21218   -
-                                                               -
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-

This message is for the designated recipient only and may contain
privileged, proprietary, or otherwise private information. If you
have received it in error, purge the message from your system and
notify the sender immediately.  Any other use of the email by you
is prohibited. 



---------------------------------------------------------------------
To start a new topic, e-mail: users@tomcat.apache.org
To unsubscribe, e-mail: users-unsubscribe@tomcat.apache.org
For additional commands, e-mail: users-help@tomcat.apache.org


Re: Is Tomcat FIPS compliant

Posted by "Mark H. Wood" <mw...@IUPUI.Edu>.
That probably depends on which FIPS you mean.  There are at least 201
different U.S. Federal Information Processing Standards.

-- 
Mark H. Wood, Lead System Programmer   mwood@IUPUI.Edu
Typically when a software vendor says that a product is "intuitive" he
means the exact opposite.


Re: Is Tomcat FIPS compliant

Posted by Bill Barker <wb...@wilshire.com>.
"Christopher Schultz" <ch...@christopherschultz.net> wrote in message 
news:47894074.6080604@christopherschultz.net...
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> Robin,
>
> robingandhi21 wrote:
> | Please let me know if anybody has an idea about tomcat being FIPS
> compliant.
>
> Good question. I would imagine that if your JVM is not (i.e. Sun, etc.)
> FIPS compliant, than Tomcat could not be, either. Any idea if Sun's JVM
> is compliant? And which versions...?
>

Last time I checked (several months ago) it wasn't.  I know that OpenSSL has 
been working towards it, but haven't looked to see if they've released a 
FIPS compliant version.  Awhile back there was some talk on dev@tomcat to 
have a SSLImplementation based on Google's SSL stack (which is FIPS 
compliant), but nothing ever came of it.

> - -chris
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.4.8 (MingW32)
> Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
>
> iEYEARECAAYFAkeJQHQACgkQ9CaO5/Lv0PBP4gCgvKkIkgC8WI7WuqrpsWFM8WB5
> rOsAn1wmtUc+UkSMXRV1RelvhY8Mpj+Q
> =JntD
> -----END PGP SIGNATURE-----
>
> ---------------------------------------------------------------------
> To start a new topic, e-mail: users@tomcat.apache.org
> To unsubscribe, e-mail: users-unsubscribe@tomcat.apache.org
> For additional commands, e-mail: users-help@tomcat.apache.org
>
> 




---------------------------------------------------------------------
To start a new topic, e-mail: users@tomcat.apache.org
To unsubscribe, e-mail: users-unsubscribe@tomcat.apache.org
For additional commands, e-mail: users-help@tomcat.apache.org


Re: Is Tomcat FIPS compliant

Posted by Christopher Schultz <ch...@christopherschultz.net>.
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Robin,

robingandhi21 wrote:
| Please let me know if anybody has an idea about tomcat being FIPS
compliant.

Good question. I would imagine that if your JVM is not (i.e. Sun, etc.)
FIPS compliant, than Tomcat could not be, either. Any idea if Sun's JVM
is compliant? And which versions...?

- -chris
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.8 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iEYEARECAAYFAkeJQHQACgkQ9CaO5/Lv0PBP4gCgvKkIkgC8WI7WuqrpsWFM8WB5
rOsAn1wmtUc+UkSMXRV1RelvhY8Mpj+Q
=JntD
-----END PGP SIGNATURE-----

---------------------------------------------------------------------
To start a new topic, e-mail: users@tomcat.apache.org
To unsubscribe, e-mail: users-unsubscribe@tomcat.apache.org
For additional commands, e-mail: users-help@tomcat.apache.org