On Tue Nov 17 23:12:52 2009, IROBERTS wrote:
Show quoted text> Also, what happens if you run:
>
> openssl genrsa 256
>
> from the command line?
Yes, in CentOS with perl 5.8.8 changing the test to 512 makes the test
succeed.
hedges@anubis:~$ openssl genrsa 256
Generating RSA private key, 256 bit long modulus
...+++++++++++++++++++++++++++
..................+++++++++++++++++++++++++++
1584:error:0408C070:rsa routines:FIPS_RSA_SIGN:digest too big for rsa
key:fips_rsa_sign.c:280:
1584:error:2D06D075:FIPS routines:fips_pkey_signature_test:test
failure:fips.c:672:
1584:error:2D06A06B:FIPS routines:FIPS_CHECK_RSA:pairwise test
failed:fips_rsa_gen.c:132:
1584:error:04081003:rsa routines:RSA_BUILTIN_KEYGEN:BN
lib:fips_rsa_gen.c:298:
hedges@anubis:~$ openssl genrsa 512
Generating RSA private key, 512 bit long modulus
...++++++++++++
.....++++++++++++
unable to write 'random state'
e is 65537 (0x10001)
Show quoted text-----BEGIN RSA PRIVATE KEY-----
MIIBOwIBAAJBANTqQfnWtnj5ZPdyzdq+MuvmGfPctQMOZ0NokaOlfsnugY1u6oSn
kY+9n5Yi1uTW7IeyfQTZpX5ElOOwmR3Bv5sCAwEAAQJAL3BKZuoqGeYnUuLnbtd1
7Q2Ftsn0IswwwdooqPeUulTbgetAVVBL04uJ1aF2bcjhDPWepFTb/Y8r2Ki/nvj1
oQIhAPt1jBvbH/+Rg/LyM6tpqtQLGdZS6klEWC+p1N2oJOlJAiEA2MKHE4R0yo23
kFvJFvJvnRm0drGX1ezMSZlKkE0IpcMCIQDAp5+v2+OZJ8DDSuNhafTSvqqN9TrA
5Zb29ZQ8Os4E2QIhALCRXUjHx/9Li7D7I4YevE6jpr5dEgr/1rVJOlTre1TTAiAJ
E9nuA4eRvnXMoRug0a5GwSX7RXrCQNTsdkK4QPKYDA==
-----END RSA PRIVATE KEY-----
Thanks for checking this out! I would love to have another item on my
checklist of why RedHate sucks. --mark--