Skip to content

BoringSSL FIPS mode - #217

Closed
Enmk wants to merge 16 commits into
releases/22.8.11-fipsfrom
22.8-fips-go1.19-boringssl
Closed

Enmk wants to merge 16 commits into
releases/22.8.11-fipsfrom
22.8-fips-go1.19-boringssl

Conversation

@Enmk

@Enmk Enmk commented Dec 30, 2022 •

Copy link
Copy Markdown
Collaborator

Building CH, BoringSSL, and Poco in FIPS mode.

There is a main option FIPS_CLICKHOUSE that turns on special build rules for BoringSSL and some other minor adjustments.

BoringSSL is built using recipes of go1.19, that is:

  • We download 3 files from golang repo (branch go1.19)
    • src/crypto/internal/boring/Dockerfile - build environment
    • src/crypto/internal/boring/build.sh - build and test script
    • src/crypto/internal/boring/goboringcrypto.h - required for producing golangs syso (whuch we do not need), but build will fail without it.

There are some minor modifications to ClickHouse code:

  • Logging "Stating in FIPS mode, KAT test result: " on startup if CH was built in FIPS mode
  • couple of const_cast<X509 *>s to match API of BoringSSL version
  • configure-time patching of /contrib/krb5/src/lib/crypto/openssl/enc_provider/aes.c since it includes missing header.

Enmk added 2 commits January 13, 2023 00:49
Build both Poco and BoringSSL in FIPS mode.
For BoringSSL that means build according to the golang 1.19 process, borrowing some code from golang sourcecode
Patching /contrib/krb5/src/lib/crypto/openssl/enc_provider/aes.c to be compatible with used version of BoringSSL
@Enmk
Enmk force-pushed the 22.8-fips-go1.19-boringssl branch from 8c22555 to b1d5419 Compare January 12, 2023 20:50
Enmk and others added 14 commits January 13, 2023 00:51
Not setting OPENSSL_FIPS - causes Poco to choose old TLSv1
Using BoringSSL's FIPS_mode() to determine if in FIPS mode.
This is required for break-hash tests
Symbols that are explicitly kept:
 * BORINGSSL_bcm_rodata_start
 * BORINGSSL_bcm_rodata_end
 * BORINGSSL_bcm_text_start
 * BORINGSSL_bcm_text_end
Disabled doing performance tests, as we don't need it and it causes troubles
Added FIPS_CLICKHOUSE to system.build_options
@Enmk Enmk mentioned this pull request Feb 27, 2023
@Enmk

Enmk commented Feb 28, 2023

Copy link
Copy Markdown
Collaborator Author

Close to reopen later

@Enmk Enmk closed this Feb 28, 2023
@Enmk Enmk reopened this Feb 28, 2023
@Enmk

Enmk commented Mar 7, 2023

Copy link
Copy Markdown
Collaborator Author

replaced by #235

@Enmk Enmk closed this Mar 7, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants