Skip to content

openssl + fips #364

Description

@MylesBorins

So AFAICT we still have no timeline on when openSSL 1.1.0 will have a validated fips module

Based on the release documents we have until December 2019 before we have to deprecate the 1.0.2 release, the version we support in 6.x and 8.x.

The latest communication from the project seems to imply that they are still only breaking ground on a technical roadmap towards validation.

The boringSSL project is currently 1.1.0 compliant afaict and has a verified fips module
That being said, the readme clearly states.

Although BoringSSL is an open source project, it is not intended for general use, as OpenSSL is. We don't recommend that third parties depend upon it. Doing so is likely to be frustrating because there are no guarantees of API or ABI stability.

So moving to BoringSSL is obviously not an option. That being said I'm curious what other options we have.

/cc @nodejs/crypto @nodejs/security-wg

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions