FIPS 140-3 support for Elasticsearch and Kibana
- Dominant language
- No language data
- Stars
- 6
- Forks
- 1
- PR merge metrics
- No merged PRs in 30d
Description
**Value proposition**
Organizations in **regulated and public-sector** environments must run workloads that use **FIPS-validated cryptography**. As the ecosystem moves from **FIPS 140-2** toward **FIPS 140-3**, customers need a **clear, supported path** on the Elastic Stack so they can **stay compliant** and **reduce reliance on exceptions**.
**Expected outcome**
- **Broader eligibility** for Elastic in **government, defense, finance, healthcare**, and other sectors with strict cryptographic baselines.
- **Reduced friction** for security, platform, and compliance stakeholders: alignment with **industry timelines** for 140-2 sunset and 140-3 adoption.
- Customers who **must** run in **FIPS 140-3** mode can do so on **supported stack versions**, including a path for teams not yet on the latest major (**8.19.x** as well as **9.x**).
- **FIPS 140-2** remains available where needed for **backward compatibility** during migration; we do not force an immediate breaking change for existing 140-2 deployments.
**Key user stories / use cases**
1. **As a security or compliance lead**, I need our Elasticsearch and Kibana deployment to operate with **FIPS 140-3-validated cryptography** so our **assessors and authorizing officials** accept the stack under current and upcoming requirements.
1. **As a platform architect**, I need **first-class FIPS 140-3 support** in Elasticsearch and Kibana so I can **standardize on Elastic** in a **FIPS-enforced** environment without unsupported workarounds.
1. **As a federal or regulated program**, I need the stack to align with **FIPS 140-3** expectations so we can **renew authorizations**, pass **crypto reviews**, and **de-risk** dependency on **sunsetting 140-2** modules and programs.
1. **As a customer still on FIPS 140-2**, I need **140-2 to remain available** until we complete testing and cutover, so we can **migrate on our schedule** without losing backward compatibility.
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.