Comment 3 for bug 1943530

Revision history for this message
Dimitri John Ledkov (xnox) wrote :

> Do we even know for sure this krb5-k5tls is enough for fips compliance, and that it replaces *all* crypto code in kerberos with openssl calls?

No it does not. But intention is to make the over the network communications with TLS to be FIPS-TLS compliant which is cheaper to certify when reusing a certified TLS component library.