3 ms·
[ Big I am a cryptographer, not your cryptographer disclaimer ] It depends, but if you are targeting Security Level 1 (which is what most folks think about whe
by FiloSottile 1y ago
[ Big I am a cryptographer, not your cryptographer disclaimer ]
It depends, but if you are targeting Security Level 1 (which is what most folks think about when they think about FIPS 140) you generally don't need your entire application to be validated, only the cryptographic module.
So (again, depending on your requirements and on the Operating Environment you deploy to and on what algorithms you use and how) setting GOFIPS140 might actually be all you need to do.
- firesteelrain 1y agoThank you. I will remember this the next time this comes up at work