Ensure builtin hashlib implementations honor usedforsecurity=True when _hashlib is in FIPS mode
Nessuno ha ancora preso questa issue.
- Lingua principale
- Python
- Stelle
- 77.2k
- Fork
- 35.9k
- Metriche di merge delle PR
- Metriche PR in attesa
Descrizione
Feature or enhancement
Proposal:
When OpenSSL is not available, or is not in FIPS mode:
- no change of behaviour
When OpenSSL is available and is in FIPS mode:
- ensure that only OpenSSL implementations are used when usedforsecurity=True
- ensure that all built-in (fallback) implementations require usedforsecurity=False
This addresses all needs of FIPS users that expect approved only cryptography from hashlib by default.
It satisfies Python guarantees of always available algorithms, as built-in fallbacks remain accessible with an explicit consent from the user that unapproved (an FIPS/ISO term) implementation is acceptable to the user.
In FIPS mode it means that all users can gain access to blake2/shake/md5, even when these algorithms are either blocked or unavailable from the runtime OpenSSL in FIPS mode. As long as usedforsecurity=False is used.
This also removes need to recompile or configure python somehow different for a non-fips & fips build, specifically one can safely compile python with all with-builtin-hashlib-hashes enabled.
Diagrams and full details of the current state of hashlib; and FIPS user desires are documented in this issue is opened as a reference for potential implementations to resolve all needs and desires listed there.
This issue will be used as a reference for potential implementations.
Has this already been discussed elsewhere?
I have already discussed this feature proposal on Discourse
Links to previous discussion of this feature:
Discuss:
(note there are some off-topic messages there)
Linked PRs
- gh-127301
- gh-127492
Guida per i contributori
Apri la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Direzione di ricerca
Inizia esaminando le PR collegate gh-127301 e gh-127492, quindi leggi la discussione Discourse collegata nell’issue per il contesto. Confronta il comportamento richiesto di hashlib dentro e fuori dalla modalità FIPS di OpenSSL; il lavoro è completato quando vengono utilizzate implementazioni OpenSSL per usedforsecurity=True e le implementazioni di fallback richiedono usedforsecurity=False in modalità FIPS.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Valutazione
- Stack tecnologico
- python
- Ambito
- cryptography, security
- Tipo di issue
- Funzionalità
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Stato di attività
- Ferma
- Chiarezza
- Abbastanza chiara
- Idoneità per principianti
- 20/100