cryptofips

package
v0.0.0-...-19d0b87 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Jun 3, 2026 License: Apache-2.0 Imports: 5 Imported by: 0

Documentation

Overview

Package cryptofips provides a startup self-test that verifies the process is running with the Go FIPS 140-3 cryptographic module active when FIPS mode is required (CRY-WU-02).

FIPS mode is selected at build time with GOFIPS140 and at runtime with GODEBUG=fips140=on (or "only"); crypto/fips140.Enabled() reports the effective state. Whether the deployment *requires* FIPS is an operational decision driven by the REQUIRE_FIPS environment variable: non-production builds may run without the validated module, while production Helm values set REQUIRE_FIPS=true so a misbuilt or misconfigured image fails fast instead of silently serving traffic on non-validated crypto.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func Check

func Check(required, enabled bool) error

Check is the pure, testable core of the self-test: it returns a non-nil error when FIPS mode is required but the module is not active.

func Enabled

func Enabled() bool

Enabled reports whether the Go FIPS 140-3 module is active for this process.

func MustEnforce

func MustEnforce(logger *zap.Logger)

MustEnforce runs the startup self-test and aborts the process via logger.Fatal when FIPS mode is required but not active. It always logs the effective FIPS status so operators can confirm the mode at boot. Call it from each main() before any network listener is opened.

func Required

func Required() bool

Required reports whether FIPS mode is mandatory for this process. It is driven by REQUIRE_FIPS (default false). Any value parseable as a true boolean by strconv.ParseBool ("1", "true", "TRUE", ...) enables the requirement; anything else (including unset or unparseable) leaves it off.

Types

This section is empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL