On 11/11/15 20:53, jonetsu wrote: > In the NSA page referred above, the p-384 curves are specifically mentioned > for DH. These would be the ones covered by the Suite B NSA license > sub-licensed to OpenSSL, are they ? Is it possible to build OpenSSL in FIPS > in such a way that only these curves will be used ? OpenSSL 1.0.2 has Suite B support. It can be configured via the cipher list. See SUITEB128, SUITEB128ONLY, SUITEB192 here: https://www.openssl.org/docs/man1.0.2/apps/ciphers.html Matt