[php-src] Issue #12973: Add FIPS (140-2) mode to PHP.
| From: | TheThor | Date: | Tue, 19 Dec 2023 10:25:51 +0000 |
| Subject: | [php-src] Issue #12973: Add FIPS (140-2) mode to PHP. | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-246073@lists.php.net to get a copy of this message | ||
Issue: https://github.com/php/php-src/issues/12973
Author: TheThor
### Description
Hi,
Given the amount of applications that use PHP, it would be great to have a FIPS 140-2 compliance
mode, where all unwanted cryptography would be blocked from usage.
As an example of something that could be done, although I'm not 100% how feasible the first is,
here are two options:
- Don't include/Disable all crypto, when building PHP by adding a flag to configure script (ex
./configure --fips-mode=enable or ./configure --disable-crypto when you want to use only external
fips validate libs like openssl)
- Disable all crypto related libs from core, via php.ini, where non fips compliant functions would
throw an error when used
Then a developer could use an external library that is FIPS compliant (like OpenSSL, which has a
FIPS compliant provider), and all of the rest would be disabled. I've already built PHP with a
OpenSSL 3.0.8 in FIPs mode. But, at the same time, I have no guarantees that PHP will block md5()
for example. From a developer point of view, it would be helpful to have applications fail when
non-fips cryptos are used, instead of scraping the whole code for invalid usages.