3 ms·
If you were using centos for fedramp, unless you got a variance from the feds, you were not in compliance. No one actually paid to have NIST evaluate centos's b
by tiberious726 2y ago
If you were using centos for fedramp, unless you got a variance from the feds, you were not in compliance. No one actually paid to have NIST evaluate centos's binaries (evaluation/certification must be of the compiled binary, not the source code, barring an exception made for openssl, and only openssl, not the kernel)
- p_l 2y agoThis wasn't done yet for FedRAMP High, but it passed the audit for earlier customers demanding FIPS-140-2 compliance. Not that I am not saying it wasn't a clusterfuck of epic proportions in general.