elastic / elastic/docs-content

[REQUEST]: Document the new FIPS-compliant EPR endpoint

Open
#7,758 1 comment 1 reaction 0 assignees View on GitHub
Team:SKI
Dominant language
No language data
Stars
47
Forks
261
Avg merge
3d 21h
Merged PRs (30d)
141

Description

### Description

We are going to add a new EPR endpoint that satisfies compliance requirements for FIPS and other security standards. See https://github.com/elastic/ingest-dev/issues/7896.

This new endpoint will be available at https://epr-fips.elastic.co, and will be functionally equivalent to https://epr.elastic.co. The main difference will be that the new endpoint will be stricter on using the most secure cryptographic protocols.

https://epr.elastic.co will remain by now the default in our products, users will need to opt-in for the new one, configuring Kibana to use this endpoint as Package Registry.

We are not changing the default by now because following the strictest recommendations can break compatibility with old clients.

We need to document:
* The existence of this new endpoint.
* The differences with the existing endpoint.
* How users can opt-in to use this endpoint.

### Resources

* Original request (not asking for FIPS, but for the similarly strict Spain’s National Cybersecurity Agency requirements) https://github.com/elastic/enhancements/issues/27763
* Change discussed in https://github.com/elastic/ingest-dev/issues/7896.
* FIPS 140-3 requirements: https://csrc.nist.gov/pubs/fips/140-3/final.

### Collaboration

The documentation team will investigate the issue and create the initial content.

### Point of contact.

**Main contact:** @jsoriano @nimarezainia

**Stakeholders:** @EdCzl

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.