Support native Golang "fips140" mode (#1696)

Add support for the "fips140" mode of Go:

- https://go.dev/doc/security/fips140
- https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/5247

You can build with `make fips140`, see the README changes for more info.

Some differences from the boringcrypto builds:

- We switch to using `go:linkname crypto/tls.aeadAESGCMTLS13`, which gives us the fips implementation for both `boringcrypto` and `fips140` modes. This means we also no longer need `-checklinkname=0`
- Go native `fips140` doesn't need CGO_ENABLED=1
- We decide if we should use the fips140 GCM at runtime, if `fips140.Enabled()` is true. If you use the `make release-fips140`, we build with build tag `fips140enforce` which ensures the binary is running with fips140 enabled and that only P256 / AES-GCM is being used. If you don't want this enforce mode, you can build without the build tag.
This commit is contained in:
Wade Simmons
2026-08-21 19:33:40 -04:00
committed by GitHub
parent edc3c5e018
commit 9c5d701648
23 changed files with 566 additions and 186 deletions
+10 -30
View File
@@ -25,39 +25,19 @@ jobs:
go-version: '1.26'
check-latest: true
- name: build
run: make bin-docker CGO_ENABLED=1 BUILD_ARGS=-race
- name: Smoke Docker
run: make smoke-docker
- name: setup docker image
working-directory: ./.github/workflows/smoke
run: ./build.sh
- name: Smoke Docker IPv6 overlay
run: make smoke-docker-ipv6
- name: run smoke
working-directory: ./.github/workflows/smoke
run: ./smoke.sh
- name: Smoke Relay Docker
run: make smoke-relay-docker
- name: setup docker image ipv6
working-directory: ./.github/workflows/smoke
run: SMOKE_OVERLAY_IPV6=1 ./build.sh
- name: Smoke Docker boringcrypto
run: make boringcrypto smoke-docker
- name: run smoke ipv6
working-directory: ./.github/workflows/smoke
run: SMOKE_OVERLAY_IPV6=1 ./smoke.sh
- name: setup relay docker image
working-directory: ./.github/workflows/smoke
run: ./build-relay.sh
- name: run smoke relay
working-directory: ./.github/workflows/smoke
run: ./smoke-relay.sh
- name: setup docker image for P256
working-directory: ./.github/workflows/smoke
run: NAME="smoke-p256" CURVE=P256 ./build.sh
- name: run smoke-p256
working-directory: ./.github/workflows/smoke
run: NAME="smoke-p256" ./smoke.sh
- name: Smoke Docker fips140
run: make fips140-all GOALS=smoke-docker
timeout-minutes: 10