3 ms·
> Having said all this: nobody should be using crypto/fips140 unless they know specifically why they're doing that. Even in its 140-3 incarnation, FIPS 140 is m
by chrisabrams 1y ago
> Having said all this: nobody should be using crypto/fips140 unless they know specifically why they're doing that. Even in its 140-3 incarnation, FIPS 140 is mostly a genuflection to FedGov idiosyncrasies.
What should folks use then?
- tptacek 1y agocrypto/, not crypto/fips140.
- FiloSottile 1y agoTo nitpick, there is no special crypto/fips140 package. (Ok, there is, but it just has an Enabled() bool function.) FIPS 140-3 mode is enabled by building with GOFIPS140=v1.0.0 (or similar, see https://go.dev/doc/security/fips140 https://go.dev/doc/security/fips140), but it shares 99% of the code with non-FIPS mode. Still, your message is right, just GOFIPS140=off (the default!), not GOFIPS140=v1.0.0.
- tptacek 1y agoNot a nitpick! I was just wrong!
- bravesoul2 1y agoThat's a nice solution when managing a platform. You can "upgrade" all your teams, and/or easily detect they have upgraded.