OpenSSL security validation encryption tool uncertain
A joint U.S. and Canadian organization that certifies encryption tools for use by federal government agencies has suspended its validation of OpenSSL cryptographic technology for the second time in less than six months.
The decision means that government agencies cannot purchase the open-source tool for the time being, although those that have already done so will still be allowed to use it. OpenSSL is an open-source implementation of the Secure Sockets Layer (SSL) and Transport Layer security protocols. It is widely used to encrypt and decrypt data on the Internet.
The decision to suspend validation of the tool came just two days after the group doing the validation, Cryptographic Module Validation Program (CMVP), had taken the harsher step of revoking the tool entirely. It backed away from that decision and opted for a suspension of the process instead.