OpenSSL version 1.1.1 is not listed under OpenSSL Library's FIPS compliant library list
Nobody has claimed this yet.
- Dominant language
- Go
- Stars
- 431
- Forks
- 44
- Avg merge
- 21h 18m
- Merged PRs (30d)
- 30
Description
I am trying to utilize Microsoft Go Bullseye container (mcr.microsoft.com/oss/go/microsoft/golang:1.22-bullseye) to use OpenSSL FIPS compliant shared libs to replace stdlib Go crypto as documented here.
However, I am having a hard time reconciling my understanding of OpenSSL's certification windows, which basically states we have to use OpenSSL versions 3.0.0, 3.0.8, or 3.0.9 if we want to be using a FIPS validated OpenSSL.
However, the OpenSSL version in the latest Microsoft Go containers are using version 1.1.1w. Looking at the main README for go-crypto-openssl, it states:
The openssl package has support for multiple OpenSSL versions, namely 1.0.2, 1.1.0, 1.1.1 and 3.0.2.
None of these versions are listed as FIPS validated on OpenSSL's side.
My questions are 2 fold:
- What is the difference in what the microsoft/go says is "FIPS" mode vs what OpenSSL says is "FIPS" validated in terms of OpenSSL versions
- If we need to be using OpenSSL 3.0.9 as listed in OpenSSL FIPS validated versions list, how could we accomplish that in
mcr.microsoft.com/oss/go/microsoft/golang:1.22-bullseye? (i.e. could we just source installhttps://www.openssl.org/source/openssl-3.0.9.tar.gzand expect the Microsoft go compiler to work?)
Thank you
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Read eng/doc/fips/README.md and the go-crypto-openssl README, then compare their OpenSSL version statements with the OpenSSL source and FIPS validated versions list linked in the issue. Check the mcr.microsoft.com/oss/go/microsoft/golang:1.22-bullseye image context. Done means the documentation clearly explains the two uses of “FIPS” and how the container’s OpenSSL version relates to the documented requirements.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- docker, go
- Domain
- cryptography, security
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100