Add supplement to FIPS compliance page for documenting known confounding patterns
Open
discussion
dotnet/svc
security-practices/subsvc
- Dominant language
- No language data
- Stars
- 4.8k
- Forks
- 6.1k
- Avg merge
- 19h 10m
- Merged PRs (30d)
- 268
Description
### Describe the issue or suggestion
[FIPS compliance - .NET Core - .NET | Microsoft Learn](https://learn.microsoft.com/en-us/dotnet/standard/security/fips-compliance) describes in general terms how an application can be in FIPS compliance. However, https://github.com/dotnet/runtime/pull/94979 introduces a scenario that could introduce confusion. It might make sense to track such patterns either as an added section to the above doc, or in a supplement.
Opening this issue to discuss and track.
cc @omajid @adegeo
Contributor guide
Assessment
This issue has not been assessed yet.