Expand description
§ic-fips — the FIPS 140-3 module boundary
§What this is, and what it is not
This crate implements the discipline FIPS 140-3 asks for: a defined module boundary, pre-operational self-tests, per-algorithm known-answer tests (CASTs), a latching error state, an approved mode of operation that refuses unapproved algorithms, and a service indicator that reports whether each call was approved.
It is not a validated module. IronCrypto holds no CMVP certificate,
and running initialize does not create one. Validation is a laboratory
process against a specific binary on specific platforms. What this crate
gives you is a codebase that is shaped for that process, and a runtime
that tells the truth about its own status — see
ic_ontology::runtime::has with "fips-validated", which returns false
and will keep returning false until a certificate exists.
Claiming otherwise to an auditor, a customer, or an agent would be a misrepresentation, so every surface here is written to make the distinction impossible to miss.
§Using it
use ic_fips::{initialize, Mode, ServiceIndicator};
// Runs every known-answer test. Refuses service if any of them fail.
initialize()?;
ic_fips::set_mode(Mode::Approved)?;
// Approved: AES-256-GCM is an approved security function.
assert_eq!(ic_fips::check("aes-256-gcm")?, ServiceIndicator::Approved);
// Refused: ChaCha20-Poly1305 is not approved, so approved mode blocks it
// rather than letting it through with a warning.
assert!(ic_fips::check("chacha20-poly1305").is_err());Re-exports§
pub use selftest::run_all_self_tests;pub use selftest::SelfTestReport;pub use selftest::TestOutcome;
Modules§
- selftest
- Known-answer tests for every implemented algorithm.
Enums§
- Mode
- The module’s operating mode.
- Service
Indicator - FIPS 140-3 requires a module to tell the caller whether the service it just used was an approved one. This is that indicator.
- State
- The module’s lifecycle state.
Constants§
- VALIDATION_
STATEMENT - A statement of this module’s validation status, for display to humans and agents that ask.
Functions§
- check
- Check whether
algorithm_idmay be used right now, and report its status. - enter_
error_ state - Force the module into its error state.
- guarded
- Run
oponly ifalgorithm_idis permitted, returning the result along with the service indicator. - initialize
- Run the pre-operational self-tests and bring the module up.
- mode
- The current mode, or
Nonewhen the module is not operational. - set_
mode - Switch the operating mode.
- state
- The module’s current state.