Skip to content

Document limitation of FIPS provider support relying on default configuration files#297

Merged
jbdelcuv merged 3 commits into
mainfrom
personal/jbdelcuv/fips_sgxssl_configuration_file
Jun 10, 2026
Merged

Document limitation of FIPS provider support relying on default configuration files#297
jbdelcuv merged 3 commits into
mainfrom
personal/jbdelcuv/fips_sgxssl_configuration_file

Conversation

@jbdelcuv

Copy link
Copy Markdown
Contributor

Document the limitation of FIPS provider support relying on the default OpenSSL and FIPS provider configuration files.

…lt OpenSSL and FIPS provider configuration files.

Signed-off-by: Juan del Cuvillo <juan.b.del.cuvillo@intel.com>

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the repository documentation to describe a known limitation of the experimental OpenSSL FIPS provider support when it relies on OpenSSL’s default configuration-file discovery and loading behavior.

Changes:

  • Document that FIPS provider support depends on OpenSSL/FIPS provider configuration files and may be influenced by untrusted filesystem state.
  • Describe a potential integrity risk if an attacker can modify the configuration file(s) used by the host/enclave at runtime.
  • Mark the behavior as a known limitation pending future requirements.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread README.md Outdated
Comment thread README.md Outdated
jbdelcuv added 2 commits June 9, 2026 22:15
Signed-off-by: Juan del Cuvillo <juan.b.del.cuvillo@intel.com>
Signed-off-by: Juan del Cuvillo <juan.b.del.cuvillo@intel.com>
@jbdelcuv jbdelcuv merged commit 4d66d3f into main Jun 10, 2026
3 checks passed
@jbdelcuv jbdelcuv deleted the personal/jbdelcuv/fips_sgxssl_configuration_file branch June 10, 2026 13:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants