fips

package
v0.0.0-...-c361317 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 28, 2026 License: AGPL-3.0 Imports: 2 Imported by: 0

Documentation

Overview

Package fips centralizes Arc's FIPS 140-3 posture: detecting whether the process is running against the Go Cryptographic Module in FIPS mode, and producing TLS configurations restricted to FIPS-approved primitives.

Arc ships two build variants. The default build is unchanged. The "fips" build (built with -tags=fips and GOFIPS140=v1.0.0) bakes in GODEBUG=fips140=only via a //go:debug directive (see cmd/arc/fips.go, which is in package main where //go:debug takes effect), runs against the CMVP-certified Go Cryptographic Module, and fails closed on non-approved code paths (legacy token hashes, InsecureSkipVerify, etc.).

IMPORTANT: the Go FIPS module only covers the standard library crypto/* tree. golang.org/x/crypto packages (bcrypt, hkdf, …) are OUTSIDE the boundary and are NOT rejected by fips140=only — they must be removed by code change. This package exists so the policy lives in one place rather than being re-derived at each call site.

Index

Constants

View Source
const BuildTagged = false

BuildTagged reports whether this binary was compiled with the "fips" build tag. False in the default (non-FIPS) build variant. See build_fips.go for the full contract.

Variables

This section is empty.

Functions

func Enabled

func Enabled() bool

Enabled reports whether the process is running with the Go Cryptographic Module in FIPS mode (GODEBUG=fips140=on or =only). It returns true only in the fips build variant run with the proper GODEBUG; it is a runtime check, not a build-tag check. Use BuildTagged for the compile-time variant.

func HardenTLSConfig

func HardenTLSConfig(cfg *tls.Config) *tls.Config

HardenTLSConfig applies Arc's TLS hardening to a config. It mutates and returns the passed config (or allocates one if nil) so it composes with builders that have already populated Certificates / RootCAs / ClientAuth (e.g. ClusterTLSConfig).

The TLS 1.2 minimum-version floor is applied in BOTH build variants — that is the pre-existing behavior (every call site previously set MinVersion: tls.VersionTLS12 explicitly) and is plain hardening, not a FIPS-specific restriction. Setting it explicitly (rather than relying on Go's MinVersion==0 default) keeps the floor pinned across Go-version default changes and ignores the GODEBUG=tls10server escape hatch.

The FIPS-approved cipher-suite and curve restrictions are applied ONLY in the fips build (BuildTagged). The default build keeps Go's default cipher suites and curves — notably X25519, which the FIPS-approved set excludes — so standard-build TLS behavior (beyond the long-standing 1.2 floor) is unchanged. The two build variants do not mix TLS posture.

Types

This section is empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL