elastic / elastic/docs-content
[REQUEST]: Document the new FIPS-compliant EPR endpoint
- Dominant language
- No language data
- Stars
- 47
- Forks
- 261
- Avg merge
- 3d 21h
- Merged PRs (30d)
- 141
Description
### Description
We are going to add a new EPR endpoint that satisfies compliance requirements for FIPS and other security standards. See https://github.com/elastic/ingest-dev/issues/7896.
This new endpoint will be available at https://epr-fips.elastic.co, and will be functionally equivalent to https://epr.elastic.co. The main difference will be that the new endpoint will be stricter on using the most secure cryptographic protocols.
https://epr.elastic.co will remain by now the default in our products, users will need to opt-in for the new one, configuring Kibana to use this endpoint as Package Registry.
We are not changing the default by now because following the strictest recommendations can break compatibility with old clients.
We need to document:
* The existence of this new endpoint.
* The differences with the existing endpoint.
* How users can opt-in to use this endpoint.
### Resources
* Original request (not asking for FIPS, but for the similarly strict Spain’s National Cybersecurity Agency requirements) https://github.com/elastic/enhancements/issues/27763
* Change discussed in https://github.com/elastic/ingest-dev/issues/7896.
* FIPS 140-3 requirements: https://csrc.nist.gov/pubs/fips/140-3/final.
### Collaboration
The documentation team will investigate the issue and create the initial content.
### Point of contact.
**Main contact:** @jsoriano @nimarezainia
**Stakeholders:** @EdCzl
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.