registrystack / registrystack/registry-stack

Explore optional FIPS build profile for AWS-LC backed crypto

Offen
#141 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
area:platform criticality:p3 enhancement post-1.0 triage:roadmap
Vorherrschende Sprache
Rust
Sterne
2
Forks
0
Ø Merge
2 Std. 55 Min.
Gemergte PRs (30 T.)
130

Beschreibung

## Context

As part of moving JWT and RS256 crypto away from RustCrypto `rsa`, we are adopting AWS-LC backed crypto paths. A follow-up decision is whether Registry Stack should support an optional FIPS build profile.

## Questions to answer

- Which binaries/crates would need FIPS-backed crypto in a supported deployment?
- Can `aws-lc-rs` be built with its `fips` feature across our release targets?
- What CI/release tooling would be required, including C/C++ compiler, CMake, Go, and bindgen/libclang where needed?
- Which AWS-LC-FIPS module version, NIST certificate, security policy, and supported operating environments would we rely on?
- What claims can we safely make, distinguishing "built with a FIPS module" from full application or deployment FIPS compliance?
- Should this be a separate release artifact/profile rather than the default build?

## Notes

Non-FIPS `aws-lc-rs` is the near-term target for replacing vulnerable RSA dependencies. This ticket is for a later compliance and release-engineering assessment, not a blocker for the current RSA vulnerability work.

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Es werden keine Dateien, Tests oder Einstiegspunkte genannt. Beginne mit einer Bestandsaufnahme der vom Repository abgedeckten Binaries, Crates, Release-Ziele und CI-Tooling-Komponenten und bewerte anschließend die FIPS-Build-Anforderungen von aws-lc-rs sowie die referenzierten Abhängigkeiten von Compiler, CMake, Go, bindgen und libclang. Als abgeschlossen gilt die Aufgabe, wenn eine dokumentierte Modul- und Umgebungsbewertung, belastbare Compliance-Aussagen und eine Empfehlung für ein separates Profil oder Artefakt vorliegen.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
aws, cmake, go, rust
Bereich
build-system, cryptography, release, security
Issue-Typ
Feature
Schwierigkeit
5/5
Geschätzter Aufwand
Über eine Woche
Aktivitätsstatus
Ruhig
Klarheit
Muss geklärt werden
Anfängerfreundlichkeit
35/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.