-
Epic
-
Resolution: Unresolved
-
Undefined
-
None
-
None
-
None
-
[OCMUI] ROSA HCP with FIPS target crypto
-
Product / Portfolio Work
-
False
-
-
False
-
To Do
-
ROSA-123 - ROSA HCP with FIPS target crypto
-
100% To Do, 0% In Progress, 0% Done
Description
As a cluster administrator, I want to create ROSA HCP clusters with FIPS cryptography enabled so that the cluster satisfies my security requirements
Acceptance criteria
When creating a ROSA HCP cluster it is possible to enable FIPS cryptography.
When enabling FIPS encryption, auto-enable etcd encryption and prevent disabling it. By auto-enabling etcd encryption. a custom KMS key will become required (this is existing behavior and we are not changing it)
The FIPS setting cannot be changed after a cluster is created.
There are no specific tracking requirement as FIPS usage can be tracked with cluster creation.