sonic-net / sonic-fips

SONiC FIPS module
Other
0 stars 9 forks source link

Query on recompiling sonic-fips and validity of FIPS 140-3 #59

Open rchandramouli opened 3 months ago

rchandramouli commented 3 months ago

In case of Bullseye (SONiC 202311), to include fixes for certain CVEs such as (CVE-2023-48795), we see a need to recompiling sonic-fips importing the patches of interest from debian to openssh/openssl patchset.

Does this process of recompiling sonic-fips without any changes to SymCrypt/SymCrypt-OpenSSL repos but with patches to openssh/openssl etc. and using the built debs, invalidate FIPS 140-3 certificate?

We wanted to clarify if the certification also includes specific versions of openssh/openssl and other fips associated packages as well. If that is the case, we would await for (#57) to be merged and use the binaries from the public storage.