[php-src] Issue #12973: Add FIPS (140-2) mode to PHP.

From: Date: Tue, 19 Dec 2023 10:25:51 +0000
Subject: [php-src] Issue #12973: Add FIPS (140-2) mode to PHP.
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-246073@lists.php.net to get a copy of this message
Issue: https://github.com/php/php-src/issues/12973 Author: TheThor ### Description Hi, Given the amount of applications that use PHP, it would be great to have a FIPS 140-2 compliance mode, where all unwanted cryptography would be blocked from usage. As an example of something that could be done, although I'm not 100% how feasible the first is, here are two options: - Don't include/Disable all crypto, when building PHP by adding a flag to configure script (ex ./configure --fips-mode=enable or ./configure --disable-crypto when you want to use only external fips validate libs like openssl) - Disable all crypto related libs from core, via php.ini, where non fips compliant functions would throw an error when used Then a developer could use an external library that is FIPS compliant (like OpenSSL, which has a FIPS compliant provider), and all of the rest would be disabled. I've already built PHP with a OpenSSL 3.0.8 in FIPs mode. But, at the same time, I have no guarantees that PHP will block md5() for example. From a developer point of view, it would be helpful to have applications fail when non-fips cryptos are used, instead of scraping the whole code for invalid usages.

« previous php.bugs (#246073) next »