448 questions
0
votes
0
answers
30
views
Verify Tomcat 9 Running in FIPS Mode [closed]
I need to verify that my Tomcat 9 server for my Java application is running in FIPS mode, according to this STIG:
Tomcat must use FIPS-validated ciphers on secured connectors. Connectors are how ...
0
votes
0
answers
287
views
OpenSSL 3.1.2 - FIPS Module Enabled, but still able to use MD5
I'm building a docker container based on Ubuntu, and manually downloading / building / installing OpenSSL 3.1.2. I'm using the enable-fips congfig option, installing, then running openssl fipsinstall, ...
0
votes
0
answers
173
views
Spring Boot application intended to be FIPS-compliant by using bouncycastle fails to start without SUN security provider
I'm trying to make my Spring Boot microservices FIPS 10-3 compliant, which led me to Bouncycastle as the security providers.
I have a basic Spring Boot application created with Spring initializr which ...
1
vote
1
answer
245
views
Why is ExtendedMasterSecret not being offered, using JSSE with openjdk17 (in container under k8s, CRI-o)
I have a simple java test program, that opens an SSL connection to a server. This is on a redhat linux system, actually a UBI 9.5 container. The container is running on a RHEL 9.5 system, with ...
0
votes
0
answers
55
views
BCFIPS provider be positioned at the bottom of the security provider list in non-FIPS environment
We are currently using the Snowflake JDBC FIPS driver in a non-FIPS environment. The reason for this choice is to simplify maintenance, as managing different drivers for various environments can be ...
1
vote
0
answers
103
views
Snowflake JDBC FIPS driver in non fips mode
We have a requirement to use the JDBC FIPS driver in both FIPS and non-FIPS modes. When using the JDBC FIPS driver, it mandates that the BouncyCastleFipsProvider must always be at the top of Java's ...
0
votes
1
answer
402
views
OpenSSL 1.0.2 with FIPS 2.0.16
I want to understand the behavior when OpenSSL 1.0.2 is integrated with FIPS module 2.0.16. OpenSSL 1.0.2 has inbuild FIPS module, however we are building OpenSSL 1.0.2 with FIPS 2.0.16. could you ...
1
vote
1
answer
652
views
Disable FIPS for NodeJS build
I am running into the following problem when building NodeJS app on a FIPS-enabled RHEL8 server. The command is CI=false npm run build
Error: error:060800C8:digital envelope routines:EVP_DigestInit_ex:...
1
vote
2
answers
2k
views
How to use ML-KEM/Kyber for encrypting data using PublicKey and decrypting data using PrivateKey
I am learning how to use Post quantum cryptography with Java. The vendor implementation is provided by BouncyCastle version 1.78.1. In short, I'm using a BouncyCastlePQCProvider to obtain a Key Pair ...
4
votes
1
answer
368
views
OpenSSL 3.0.8 FIPS compliant integration in iOS
I am building OpenSSL 3.0.8 with FIPS for an iOS device. This is my first time undertaking such a task.
Here are the steps I have followed so far:
Downloaded the OpenSSL 3.0.8 source code and ...
1
vote
1
answer
134
views
Configure .Net AES to produce results of FIPS 197
For testing I want to configure any .Net AES algorithm to produce the results given in the FIPS 197 publication (Appendix B).
I tried different parameters (block size = key size = feedback size = 128, ...
2
votes
1
answer
570
views
How to check FIPS compliance for JavaScript libraries?
I've identified the crypto libraries(direct/indirect dependencies) being used in the application developed using the React Framework(JavaScript). I need to know if there's a way to identify if each of ...
1
vote
0
answers
2k
views
RHEL9, OpenJDK 11, FIPS - issues with PBES2 ciphers
I've read through several topics related to this issue but none so far have helped.
We're running RHEL9 with OpenJDK 11.0.22 and OpenSSL 3.0.7, with FIPS mode enabled (disabling FIPS is not an option)....
0
votes
0
answers
211
views
How to build OpenSSL iOS libs with flips compliance and validate the libraries
I'm attempting to build an iOS OpenSSL library with FIPS (Federal Information Processing Standards) compliance enabled. I've modified the build script from the krzyzanowskim/OpenSSL repository (https:/...
0
votes
1
answer
95
views
rsaJsonWebKey.toJson throws ClassCastException on FIPS enabled host
Jose4j up to and including version 0.9.4 throws a ClassCastException on the toJson method when running the following code on a FIPS enabled host.
If you disable FIPS on the host, this same code does ...
1
vote
1
answer
504
views
Is there a known workaround to make Spring Security 6 SAML usage FIPS-compliant?
Spring Security 6 uses OpenSAML 4.1.1 which has a dependency on the standard (non-FIPS) distribution of BouncyCastle.
Has anyone devised a workaround to make Spring Security 6 FIPS-compliant? I haven'...
1
vote
0
answers
296
views
Python 3.10 on openshift with fips mode got error on pandarallel
run on docker with rhel 8 on openshift without root user
this is the information about the OS that the docker is running
NAME="Red Hat Enterprise Linux"
VERSION="8.8 (Ootpa)"
ID=&...
1
vote
1
answer
914
views
Issues with building Python 3.9.2 from source with OpenSSL 3.0.8
I have been trying to build FIPS version of Python 3.9.2. on debian. I have gathered that FIPS certified version of OpenSSL is required and chose 3.0.8 as OpenSSL 1 has reached EOL. I have updated ...
0
votes
1
answer
665
views
Error upgrading to Keycloak 22.0.0 but 21.1.2 works fine
I am trying to upgrade to Keycloak 22.0.0 from version 20.0.0 using the Quay.io image and I get the following error:
Exception in thread "main" java.lang.reflect.InvocationTargetException......
0
votes
1
answer
571
views
Openjdk 1.8.0 failing when FIPs enabled in container
Good afternoon,
I have a java application that is failing to deploy on FIPS enabled Kubernetes node. I get the following error on startup:
org.springframework.beans.factory.BeanCreationException: ...
0
votes
0
answers
358
views
SunJGSS in FIPS mode
I need to use "SunJGSS" as one of the security providers in a FIPS environment. Is there a FIPS version of the "SunJGSS" Provider or if the underlying JCE/JCA is a FIPS provider ...
1
vote
0
answers
2k
views
OpenSSL internal error, assertion failed: FATAL FIPS SELFTEST FAILURE
I had an application written in Python3.9 packaged as executable file using PyInstaller in a CentOs7 docker image. Able to install the app successfully in linux machines where FIPS is disabled.
If I ...
0
votes
1
answer
5k
views
Implement FIPS 140-2 with openssl
I want to use openssl with fips 140-2 to encrypt and decrypt files.
Source OS: ubuntu 18.04.
I have followed below steps:
I have uninstalled the existing openssl version.
Downloaded openssl-3.1.0.tar....
7
votes
1
answer
827
views
How will new rules of CA/B Forum's Code Signing Certificates affect UWP Signing process?
We have a UWP that we use to sign with a certificate installed in a CI/CD Pipeline Machine. We use this PowerShell command to get it signed
.\signtool.exe sign /fd sha256 /t http://timestamp.digicert....
0
votes
1
answer
420
views
Access OpenSSL FIPS APIs from python ctypes not working
Python: 3.9.16
OpenSSL: 3.0.8
fips_ccode.c
#include <stdio.h>
#include <stdlib.h>
#include <openssl/provider.h>
#include "openssl/md5.h"
int main(void)
{
...