Uploaded image for project: 'Hybrid Cloud Console'
  1. Hybrid Cloud Console
  2. RHCLOUD-37203

Ensure Kessel Inventory Images are built using FIPS compliant libraries

XMLWordPrintable

    • Icon: Task Task
    • Resolution: Done
    • Icon: Normal Normal
    • None
    • None
    • None
    • False
    • Hide

      None

      Show
      None
    • False
    • Unset
    • CRCPLAN-306 - Management Fabric | Onboard FedRAMP to Kessel
    • None

      All services running in a FedRAMP environment must leverage FIPS approved cryptographic ciphers and libraries. In order to run the Kessel services in FedRAMP, they must be built using this approved libraries

      Done Critieria

      • Image/Binary build process is updated to ensurue FIPS approved ciphers are leveraged and the image/binary is FIPS compliant

      Useful Resources

      • Any SREP operators running in FedRAMP are FIPS compliant and have solved this issue – see their various dockerfiles and build flags for guidance: LINK
      • Red Hat ships a special fork of Go that supports using the correct libraries for FIPS, using UBI images – this doc is useful for testing and validating FIPS compliance: LINK

              anatale.openshift Antony Natale
              anatale.openshift Antony Natale
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: