Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade Bouncy Castle FIPS dependencies #112989

Draft
wants to merge 7 commits into
base: main
Choose a base branch
from

Conversation

slobodanadamovic
Copy link
Contributor

This PR updates bc-fips and bctls-fips dependencies to the latest minor versions.

This PR updates `bc-fips` and `bctls-fips` dependencies
to the latest minor versions.
@slobodanadamovic slobodanadamovic added >upgrade :Security/Security Security issues without another label Team:Security Meta label for security team v8.16.0 v8.15.2 labels Sep 17, 2024
@slobodanadamovic slobodanadamovic requested a review from a team September 17, 2024 09:08
@slobodanadamovic slobodanadamovic self-assigned this Sep 17, 2024
Copy link
Contributor

Documentation preview:

@elasticsearchmachine
Copy link
Collaborator

Hi @slobodanadamovic, I've created a changelog YAML for you.

@slobodanadamovic slobodanadamovic added the :Security/FIPS Running ES in FIPS 140-2 mode label Sep 17, 2024
@slobodanadamovic
Copy link
Contributor Author

@elasticmachine update branch

@h3xcat
Copy link

h3xcat commented Nov 11, 2024

@slobodanadamovic Upgrading bc-fips to 1.0.2.5 invalidates FIPS compliance. The 1.0.2.5 version hasn't been certified for FIPS, and there are no future plans for that specific version to be certified according to library developers. Instead they recommend for applications to migrate to version 2.0.0, which was certified for FIPS.

bcgit/bc-java#1688 (comment)

https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/4743 (certificate for 2.0.0)
https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/4616 (historic certificate for 1.0.2.4)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
:Security/FIPS Running ES in FIPS 140-2 mode :Security/Security Security issues without another label Team:Security Meta label for security team >upgrade v8.15.4 v8.17.0 v9.0.0
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants