zitadel / zitadel

ZITADEL - Identity infrastructure, simplified for you.
https://zitadel.com
Apache License 2.0
9.06k stars 577 forks source link

FIPS 140-2 compliance mode / binary / container #4335

Open mffap opened 2 years ago

mffap commented 2 years ago

Background

Some customers, especially with business in the US, require FIPS 140-2 Security Policy Compliance. Golang's crypto implementation is, by default, not suitable and cannot achieve compliance set out by FIPS.

Proposal

Acceptance Criteria

muhlemmer commented 1 year ago

Just browsing I came accross some additional info that might be helpfull:

badrobit commented 3 months ago

may want to update this from FIPS 140-2 to the current standard FIPS 140-3 https://csrc.nist.gov/pubs/fips/140-3/final

BillyBolton commented 1 month ago

Any update on this?

muhlemmer commented 1 month ago

It's in the backlog without priority at the moment. This may change if we get demand from enterprise users.