From 14c92881278f4d4e1b8a5cef7c5ede00bb94f548 Mon Sep 17 00:00:00 2001 From: Wade Simmons Date: Wed, 8 Jul 2026 10:33:55 -0400 Subject: [PATCH] Ensure Curve25519 and ChaChaPoly are not used in fips140 enforced mode Since these some from golang/x/crypto, there is a change that stdlib fips140.Enforced gate won't catch their usage. --- pki.go | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/pki.go b/pki.go index 1bef5106..b63c5b89 100644 --- a/pki.go +++ b/pki.go @@ -1,6 +1,7 @@ package nebula import ( + "crypto/fips140" "encoding/binary" "encoding/json" "errors" @@ -241,6 +242,9 @@ func newCipherSuite(curve cert.Curve, pkcs11backed bool, cipher string) (noise.C var dhFunc noise.DHFunc switch curve { case cert.Curve_CURVE25519: + if fips140.Enforced() { + panic("pki: use of Curve25519 is not allowed in FIPS 140-only mode") + } dhFunc = noise.DH25519 case cert.Curve_P256: if pkcs11backed { @@ -253,6 +257,9 @@ func newCipherSuite(curve cert.Curve, pkcs11backed bool, cipher string) (noise.C } if cipher == "chachapoly" { + if fips140.Enforced() { + panic("pki: use of ChaChaPoly is not allowed in FIPS 140-only mode") + } return noise.NewCipherSuite(dhFunc, noise.CipherChaChaPoly, noise.HashSHA256), nil } return noise.NewCipherSuite(dhFunc, noiseutil.CipherAESGCM, noise.HashSHA256), nil