Rocksolid Light

Welcome to novaBBS (click a section below)

mail  files  register  newsreader  groups  login

Message-ID:  

Old programmers never die, they just branch to a new address.


computers / comp.os.vms / Re: VSI has released 9.2-1

SubjectAuthor
* VSI has released 9.2-1John Dallman
+* Re: VSI has released 9.2-1Jan-Erik Söderholm
|+- Re: VSI has released 9.2-1Chris Townley
|+* Re: VSI has released 9.2-1Simon Clubley
||`- Re: VSI has released 9.2-1Jan-Erik Söderholm
|`* Re: VSI has released 9.2-1Pizza RAC
| +* Re: VSI has released 9.2-1Johnny Billquist
| |+* Re: VSI has released 9.2-1bill
| ||`* Re: VSI has released 9.2-1<kemain.nospam
| || `- Re: VSI has released 9.2-1Dave Froble
| |`* Re: VSI has released 9.2-1Dave Froble
| | `- Re: VSI has released 9.2-1Pizza RAC
| +* Re: VSI has released 9.2-1Robert A. Brooks
| |+* [OT] USASimon Clubley
| ||`* Re: [OT] USAArne Vajhøj
| || +* Re: [OT] USASimon Clubley
| || |+* Re: [OT] USADave Froble
| || ||+* Re: [OT] USASingle Stage to Orbit
| || |||`* Re: [OT] USADave Froble
| || ||| +* Re: [OT] USAbill
| || ||| |`* Re: [OT] USAChris Townley
| || ||| | +- Re: [OT] USAbill
| || ||| | `- Re: [OT] USADave Froble
| || ||| `- Re: [OT] USAPizza RAC
| || ||`- Re: [OT] USABob Gezelter
| || |`* Re: [OT] USAJohnny Billquist
| || | +- Re: [OT] USADave Froble
| || | `* Re: [OT] USASimon Clubley
| || |  `- Re: [OT] USAJohnny Billquist
| || `* Re: [OT] USAJohn Dallman
| ||  `- Re: [OT] USAChris Townley
| |`* Re: VSI has released 9.2-1Dave Froble
| | `- Re: VSI has released 9.2-1Arne Vajhøj
| `* [OT] USASimon Clubley
|  +* Re: [OT] USAJohnny Billquist
|  |`* Re: [OT] USASimon Clubley
|  | `* Re: [OT] USAJohnny Billquist
|  |  +* Re: [OT] USASimon Clubley
|  |  |`- Re: [OT] USADave Froble
|  |  `- Re: [OT] USAHenry Crun
|  `- Re: [OT] USAArne Vajhøj
+* Re: VSI has released 9.2-1Chris Townley
|`* Re: VSI has released 9.2-1Robert A. Brooks
| +* Re: VSI has released 9.2-1Chris Townley
| |`- Re: VSI has released 9.2-1Single Stage to Orbit
| `* Re: VSI has released 9.2-1David Jones
|  +* Re: VSI has released 9.2-1Arne Vajhøj
|  |`- Re: VSI has released 9.2-1<kemain.nospam
|  `* Re: VSI has released 9.2-1Crni Mrki
|   `* Re: VSI has released 9.2-1Craig A. Berry
|    `- Re: VSI has released 9.2-1David Jones
+* Re: VSI has released 9.2-1Arne Vajhøj
|`* Re: VSI has released 9.2-1Simon Clubley
| +- Re: VSI has released 9.2-1John Reagan
| `* Re: VSI has released 9.2-1Arne Vajhøj
|  `* Re: VSI has released 9.2-1Simon Clubley
|   `* Re: VSI has released 9.2-1Arne Vajhøj
|    +* Re: VSI has released 9.2-1Dave Froble
|    |+* Re: VSI has released 9.2-1Arne Vajhøj
|    ||`* Re: VSI has released 9.2-1Dave Froble
|    || `* Re: VSI has released 9.2-1Arne Vajhøj
|    ||  `* Re: VSI has released 9.2-1Dave Froble
|    ||   `* Re: VSI has released 9.2-1Arne Vajhøj
|    ||    `* Re: VSI has released 9.2-1Dave Froble
|    ||     `- Re: VSI has released 9.2-1Arne Vajhøj
|    |`* Re: VSI has released 9.2-1John Dallman
|    | `- Re: VSI has released 9.2-1Arne Vajhøj
|    `* Re: VSI has released 9.2-1Simon Clubley
|     `* Re: VSI has released 9.2-1Arne Vajhøj
|      `* Re: VSI has released 9.2-1Simon Clubley
|       `* Re: VSI has released 9.2-1Arne Vajhøj
|        +* Re: VSI has released 9.2-1Arne Vajhøj
|        |`* Re: VSI has released 9.2-1Dan Cross
|        | `* Re: VSI has released 9.2-1Arne Vajhøj
|        |  +* Re: VSI has released 9.2-1Dan Cross
|        |  |`- Re: VSI has released 9.2-1Gary Sparkes
|        |  `- Re: VSI has released 9.2-1Gary Sparkes
|        `- Re: VSI has released 9.2-1Dan Cross
`* Re: VSI has released 9.2-1Brian Schenkenberger
 `- Re: VSI has released 9.2-1Simon Clubley

Pages:1234
Re: VSI has released 9.2-1

<u85cd2$fuh$1@reader2.panix.com>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=28706&group=comp.os.vms#28706

  copy link   Newsgroups: comp.os.vms
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!panix!.POSTED.spitfire.i.gajendra.net!not-for-mail
From: cro...@spitfire.i.gajendra.net (Dan Cross)
Newsgroups: comp.os.vms
Subject: Re: VSI has released 9.2-1
Date: Thu, 6 Jul 2023 03:28:34 -0000 (UTC)
Organization: PANIX Public Access Internet and UNIX, NYC
Message-ID: <u85cd2$fuh$1@reader2.panix.com>
References: <memo.20230615232651.16808C@jgd.cix.co.uk> <u84l3q$kcjd$1@dont-email.me> <u8567o$e1g$1@reader2.panix.com> <u859bs$q1h7$1@dont-email.me>
Injection-Date: Thu, 6 Jul 2023 03:28:34 -0000 (UTC)
Injection-Info: reader2.panix.com; posting-host="spitfire.i.gajendra.net:166.84.136.80";
logging-data="16337"; mail-complaints-to="abuse@panix.com"
X-Newsreader: trn 4.0-test77 (Sep 1, 2010)
Originator: cross@spitfire.i.gajendra.net (Dan Cross)
 by: Dan Cross - Thu, 6 Jul 2023 03:28 UTC

In article <u859bs$q1h7$1@dont-email.me>,
Arne Vajhøj <arne@vajhoej.dk> wrote:
>On 7/5/2023 9:43 PM, Dan Cross wrote:
>> In article <u84l3q$kcjd$1@dont-email.me>,
>> Arne Vajhøj <arne@vajhoej.dk> wrote:
>>> On 7/5/2023 4:33 PM, Arne Vajhøj wrote:
>>>> Per:
>>>>
>>>> https://www.openssl.org/docs/fips.html
>>>> https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/4282
>>>>
>>>> then OpenSSL is FIPS 140-2 certified on:
>>>>
>>>> <quote>
>>>>     Debian 11.5 running on Dell Inspiron 7591 with Intel i7(x86) with PAA
>>>>     Debian 11.5 running on Dell Inspiron 7591 with Intel i7(x86)
>>>> without PAA
>>>>     FreeBSD 13.1 running on Dell Inspiron 7591 with Intel i7(x64) with PAA
>>>>     FreeBSD 13.1 running on Dell Inspiron 7591 with Intel i7(x64)
>>>> without PAA
>>>>     macOS 11.5.2 running on Apple i7 Mac Mini with Intel i7(x64) with PAA
>>>>     macOS 11.5.2 running on Apple i7 Mac Mini with Intel i7(x64)
>>>> without PAA
>>>>     macOS 11.5.2 running on Apple M1 Mac Mini with M1 with PAA
>>>>     macOS 11.5.2 running on Apple M1 Mac Mini with M1 without PAA
>>>> (single-user mode)
>>>>     Ubuntu Linux 22.04.1 LTS running on Dell Inspiron 7591 with Intel
>>>> i7(x64) with PAA
>>>>     Ubuntu Linux 22.04.1 LTS running on Dell Inspiron 7591 with Intel
>>>> i7(x64) without PAA
>>>>     Windows 10 running on Dell Inspiron 7591 with Intel i7(x64) with PAA
>>>>     Windows 10 running on Dell Inspiron 7591 with Intel i7(x64) without
>>>> PAA
>>>> </quote>
>>>>
>>>> Maybe VSI want VMS on that list.
>>>
>>> But I wonder.
>>>
>>> How will VSI get FIPS 140-2 certification for VMS x86-64 if they only
>>> support running in VM not on physical hardware??
>>
>> Virtual Machines, by definition, run most of their instructions
>> on the physical hardware, including in kernel mode. Running in
>> a VM does not preclude one from access to high-quality hardware
>> facilitated entropy sources a priori.
>
>No. But that is not the problem.
>
>FIPS 140-2 certification is a certification of hardware
>and software.

Hypervisors are software. The guest OS running on them is also
software. Certifying an OS running on a specific hypervisor on
a specific hardware platform is certainly doable.

>VMS 9.2-1 on a VirtualBox VM setup as ... running on
>RockyLinux 9 running on Dell Inspiron 7591 with Intel i7(x64)????

Sounds pretty bog standard as these things go, but I imagine it
would be more like VMS on ESXi on a Dell Xeon thing. Probably
much of that combination is already at least partially tested
for the US military (ESXi on Dell hardware was very common when
I was a communications officer in the US Marine Corps, which
wasn't _that_ long ago).

- Dan C.

Re: VSI has released 9.2-1

<119b7db4-ea66-4b79-9a03-006b77d82efdn@googlegroups.com>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=28904&group=comp.os.vms#28904

  copy link   Newsgroups: comp.os.vms
X-Received: by 2002:a05:6214:18ec:b0:635:ea4a:29b5 with SMTP id ep12-20020a05621418ec00b00635ea4a29b5mr97958qvb.7.1689749542036;
Tue, 18 Jul 2023 23:52:22 -0700 (PDT)
X-Received: by 2002:a05:6870:1ab0:b0:1b0:271d:29e5 with SMTP id
ef48-20020a0568701ab000b001b0271d29e5mr5462930oab.0.1689749541684; Tue, 18
Jul 2023 23:52:21 -0700 (PDT)
Path: i2pn2.org!i2pn.org!usenet.blueworldhosting.com!diablo1.usenet.blueworldhosting.com!peer02.iad!feed-me.highwinds-media.com!news.highwinds-media.com!news-out.google.com!nntp.google.com!postnews.google.com!google-groups.googlegroups.com!not-for-mail
Newsgroups: comp.os.vms
Date: Tue, 18 Jul 2023 23:52:21 -0700 (PDT)
In-Reply-To: <u859bs$q1h7$1@dont-email.me>
Injection-Info: google-groups.googlegroups.com; posting-host=24.112.128.217; posting-account=lrsA6goAAAD4xKaYqFQ04PLmg_wnS0uk
NNTP-Posting-Host: 24.112.128.217
References: <memo.20230615232651.16808C@jgd.cix.co.uk> <u84cfr$jbut$1@dont-email.me>
<u84k26$k8rl$1@dont-email.me> <u84l3q$kcjd$1@dont-email.me>
<u8567o$e1g$1@reader2.panix.com> <u859bs$q1h7$1@dont-email.me>
User-Agent: G2/1.0
MIME-Version: 1.0
Message-ID: <119b7db4-ea66-4b79-9a03-006b77d82efdn@googlegroups.com>
Subject: Re: VSI has released 9.2-1
From: mok...@gmail.com (Gary Sparkes)
Injection-Date: Wed, 19 Jul 2023 06:52:22 +0000
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
X-Received-Bytes: 3727
 by: Gary Sparkes - Wed, 19 Jul 2023 06:52 UTC

On Wednesday, July 5, 2023 at 10:36:48 PM UTC-4, Arne Vajhøj wrote:
> No. But that is not the problem.
>
> FIPS 140-2 certification is a certification of hardware
> and software.
>
> VMS 9.2-1 on a VirtualBox VM setup as ... running on
> RockyLinux 9 running on Dell Inspiron 7591 with Intel i7(x64)????
>
> Arne

I'll note that certification isn't necessarily required for procurement, and that
it ISN'T a combination of hardware AND software together. You can certify
specific combinations, yes, just as you can certify just hardware alone, or
just software alone.

Note, that windows, with the correct configuration, is considered compliant
on ANY hardware or virtualization solution. You can be validated as Software,
Software-Hybrid, or Hardware. Microsoft's solutions are almost all validated
as SOFTWARE or SOFTWARE-HYBRID. It is compliant when configured
correctly, regardless of hardware.

What you listed above in a previous post is the "tested configuration"
which isn't the actual validation. It's just saying what they used to
validate that specific module meets the requirements and standards in
NIST lab setup.

Take a look at the consolidated certificate, showing the hardware/software
configurations of the actual validations:

https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/August%202022_010922_0715_signed.pdf

Note that the OpenSSL FIPS Provider validation is only referring to the
software version, and has NO hardware data with it. Because the validation is
on the software only.

The important takeaways from the OpenSSL validation you linked is -
"When operated in FIPS mode. No assurance of the minimum strength of
generated keys." and "Module type: SOFTWARE". That means, yes, it's
compliant, with caveats.

Nominally, the software is only considered to be functioning in validated
and compliant mode if configured according to the security policy (usually)
linked on the validation page.

"This is what we tested it on" isn't the same as "it is only validated on".

Side note, CMVP which is no longer accepting submissions for 140-2
certifications - only 140-3. After September 21, 2026 140-2 modules are
considered "historical" and should only be procured in support of existing
deployments.

Re: VSI has released 9.2-1

<4de5b86b-357a-496c-8d01-32f91aecaac0n@googlegroups.com>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=28905&group=comp.os.vms#28905

  copy link   Newsgroups: comp.os.vms
X-Received: by 2002:a05:6214:a14:b0:639:206f:490e with SMTP id dw20-20020a0562140a1400b00639206f490emr103243qvb.9.1689750357420;
Wed, 19 Jul 2023 00:05:57 -0700 (PDT)
X-Received: by 2002:a9d:7e8d:0:b0:6b9:c180:ffac with SMTP id
m13-20020a9d7e8d000000b006b9c180ffacmr1992319otp.1.1689750357068; Wed, 19 Jul
2023 00:05:57 -0700 (PDT)
Path: i2pn2.org!i2pn.org!usenet.blueworldhosting.com!diablo1.usenet.blueworldhosting.com!peer02.iad!feed-me.highwinds-media.com!news.highwinds-media.com!news-out.google.com!nntp.google.com!postnews.google.com!google-groups.googlegroups.com!not-for-mail
Newsgroups: comp.os.vms
Date: Wed, 19 Jul 2023 00:05:56 -0700 (PDT)
In-Reply-To: <u85cd2$fuh$1@reader2.panix.com>
Injection-Info: google-groups.googlegroups.com; posting-host=24.112.128.217; posting-account=lrsA6goAAAD4xKaYqFQ04PLmg_wnS0uk
NNTP-Posting-Host: 24.112.128.217
References: <memo.20230615232651.16808C@jgd.cix.co.uk> <u84l3q$kcjd$1@dont-email.me>
<u8567o$e1g$1@reader2.panix.com> <u859bs$q1h7$1@dont-email.me> <u85cd2$fuh$1@reader2.panix.com>
User-Agent: G2/1.0
MIME-Version: 1.0
Message-ID: <4de5b86b-357a-496c-8d01-32f91aecaac0n@googlegroups.com>
Subject: Re: VSI has released 9.2-1
From: mok...@gmail.com (Gary Sparkes)
Injection-Date: Wed, 19 Jul 2023 07:05:57 +0000
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
X-Received-Bytes: 4668
 by: Gary Sparkes - Wed, 19 Jul 2023 07:05 UTC

On Wednesday, July 5, 2023 at 11:28:37 PM UTC-4, Dan Cross wrote:
> In article <u859bs$q1h7$1...@dont-email.me>,
> Arne Vajhøj <ar...@vajhoej.dk> wrote:
> >On 7/5/2023 9:43 PM, Dan Cross wrote:
> >> In article <u84l3q$kcjd$1...@dont-email.me>,
> >> Arne Vajhøj <ar...@vajhoej.dk> wrote:
> >>>> Debian 11.5 running on Dell Inspiron 7591 with Intel i7(x86) with PAA
> >>>> Debian 11.5 running on Dell Inspiron 7591 with Intel i7(x86)
> >>>> without PAA
> >>>> FreeBSD 13.1 running on Dell Inspiron 7591 with Intel i7(x64) with PAA
> >>>> FreeBSD 13.1 running on Dell Inspiron 7591 with Intel i7(x64)
> >>>> without PAA
> >>>> macOS 11.5.2 running on Apple i7 Mac Mini with Intel i7(x64) with PAA
> >>>> macOS 11.5.2 running on Apple i7 Mac Mini with Intel i7(x64)
> >>>> without PAA
> >>>> macOS 11.5.2 running on Apple M1 Mac Mini with M1 with PAA
> >>>> macOS 11.5.2 running on Apple M1 Mac Mini with M1 without PAA
> >>>> (single-user mode)
> >>>> Ubuntu Linux 22.04.1 LTS running on Dell Inspiron 7591 with Intel
> >>>> i7(x64) with PAA
> >>>> Ubuntu Linux 22.04.1 LTS running on Dell Inspiron 7591 with Intel
> >>>> i7(x64) without PAA
> >>>> Windows 10 running on Dell Inspiron 7591 with Intel i7(x64) with PAA
> >>>> Windows 10 running on Dell Inspiron 7591 with Intel i7(x64) without
> >>>> PAA

> Hypervisors are software. The guest OS running on them is also
> software. Certifying an OS running on a specific hypervisor on
> a specific hardware platform is certainly doable.
> >VMS 9.2-1 on a VirtualBox VM setup as ... running on
> >RockyLinux 9 running on Dell Inspiron 7591 with Intel i7(x64)????
> Sounds pretty bog standard as these things go, but I imagine it
> would be more like VMS on ESXi on a Dell Xeon thing. Probably
> much of that combination is already at least partially tested
> for the US military (ESXi on Dell hardware was very common when
> I was a communications officer in the US Marine Corps, which
> wasn't _that_ long ago).
>
> - Dan C.

In this specific case, it's just the test/lab configurations that were used..
Note that it's each OS on two different configurations.

Linux x86 (where applicable) and x64 in both modes.
FreeBSD in x64 with both modes.
macOS on x64 and ARM in both modes.

The organization that submitted it for validation wanted it tested in all
those.

Sounds like the lab just used the first 3 machines available that
could run all the tests under the submission's request.

But as this is a software module validation, as long as the source is
unmodified for this module, and it passes its own internal unmodified
self-tests, it would be considered validated and approved on VSI VMS
without any additional need to do anything.

Since it's only the OpenSSL module itself that's validated. Nothing else.

However, for sake of ease and procurement procedures, OS vendors
do tend to time to time submit for validation their implementation.
Especially ones delivered in binary form. But it would be trivial for me
to get approval and/or defend procurement if I can demonstrate that
the correct module and version is loaded and in use in the correct
configuration.

Re: VSI has released 9.2-1

<ubj7pu$3dpse$1@dont-email.me>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=29268&group=comp.os.vms#29268

  copy link   Newsgroups: comp.os.vms
Path: i2pn2.org!i2pn.org!eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: mai...@SendSpamHere.ORG (Brian Schenkenberger)
Newsgroups: comp.os.vms
Subject: Re: VSI has released 9.2-1
Date: Wed, 16 Aug 2023 15:24:46 -0400
Organization: Tmesis Software
Lines: 26
Message-ID: <ubj7pu$3dpse$1@dont-email.me>
References: <memo.20230615232651.16808C@jgd.cix.co.uk>
MIME-Version: 1.0
Content-Type: text/plain; charset=iso-8859-1; format=flowed
Content-Transfer-Encoding: 8bit
Injection-Info: dont-email.me; posting-host="fcfce7a8bcd0271f10e3eeffd4e35e59";
logging-data="3598222"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/JepV3u1r4yMXrby3TdTxV"
User-Agent: Unison/2.2
Cancel-Lock: sha1:B8/Kuj2A78mgyfiz7HlQxmXivXU=
 by: Brian Schenkenberger - Wed, 16 Aug 2023 19:24 UTC

On 2023-06-15 22:26:00 +0000, John Dallman said:

> * AMD CPUs compatibility
> * Initial support for KVM SCSI VirtIO
> * Built-in SSL3
> * Numerous fixes and improvements to the debugger and dump analyzer
> * Many native compilers, such as C, C++, Fortran, and Macro, are now
> available for field test. A new set that includes Bliss, COBOL, and
> BASIC is expected to become available soon
> * Support for newer VMWare hypervisors versions
> * Additional entropy collection mechanism
>
> https://vmssoftware.com/about/news/2023-06-15-openvms-v9-2-1-release/
>
> "SSL3" seems to mean OpenSSL v3, not the SSL v3 protocol, which has been
> deprecated for years.
>
> John

It would be nice to get my hands on this. The registration page form
is hopelessly horked with the stupid reCAPTCHA.

Doesn't anyone read the messaged via the site's contact form or is that
too fucked up?

Re: VSI has released 9.2-1

<ubl2i9$3p195$1@dont-email.me>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=29281&group=comp.os.vms#29281

  copy link   Newsgroups: comp.os.vms
Path: i2pn2.org!i2pn.org!eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: club...@remove_me.eisner.decus.org-Earth.UFP (Simon Clubley)
Newsgroups: comp.os.vms
Subject: Re: VSI has released 9.2-1
Date: Thu, 17 Aug 2023 12:07:38 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 21
Message-ID: <ubl2i9$3p195$1@dont-email.me>
References: <memo.20230615232651.16808C@jgd.cix.co.uk> <ubj7pu$3dpse$1@dont-email.me>
Injection-Date: Thu, 17 Aug 2023 12:07:38 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="47e15f2e5a49303f19705f2acd96a8b4";
logging-data="3966245"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/mFZ/NBxyCvjQW9LEIP4Y+4FuP4GP1Rvc="
User-Agent: slrn/0.9.8.1 (VMS/Multinet)
Cancel-Lock: sha1:0Qf7NwXtNjfAf/RSmQGhE0lK4E4=
 by: Simon Clubley - Thu, 17 Aug 2023 12:07 UTC

On 2023-08-16, Brian Schenkenberger <mail@SendSpamHere.ORG> wrote:
>
> It would be nice to get my hands on this. The registration page form
> is hopelessly horked with the stupid reCAPTCHA.
>

That must be new. Don't ever recall having to do that before or is it
only x86-64 specific ?

> Doesn't anyone read the messaged via the site's contact form or is that
> too fucked up?
>

I do get replies from queries sent via the contact form (at least when
VSI decide not to ignore me. :-))

Simon.

--
Simon Clubley, clubley@remove_me.eisner.decus.org-Earth.UFP
Walking destinations on a map are further away than they appear.

Pages:1234
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor