mirror of
https://github.com/gravitational/teleport.git
synced 2026-09-24 16:17:11 +08:00
* fips: Rename IsBoringBinary to IsFIPSBuild throughout Rename the function and method `IsBoringBinary` to `IsFIPSBuild` throughout the code base and change references to boringcrypto to fips140 or similar. This is part of removing boringcrypto from the build, replacing it with Go-native FIPS140. There are still some references to "boring": * The PingResponse message has a field IsBoring in authservice.proto. This cannot be changed without breaking source compatibility in api/ * The example in examples/teleport-usage has an explicit check for the boring package to set an AWS FIPS option. This will be changed when the actual change to Go-native FIPS is done. * Rust references to boringsys - this is still used in Rust and will not be changed when using Go-native FIPS. * The actual import of boring to use it. This will be changed when using Go-Native FIPS. This rename is separate from the Go-native FIPS implementation so it can be backported to keep the branches close, to avoid unnecessary conflicts. * fips: Add "crypto/tls/fipsonly" import for boring builds Import the "crypto/tls/fipsonly" package when building in fips mode. This import is also done in the Enterprise repo with some rename magic so that the file the import is in only exists for fips builds. This was necessary when boringcrypto was only available in a special branch of the Go toolchain, but has not been necessary since Go 1.19 when boringcrypto was brought into the proper toolchain. Moving this here makes the enterprise makefile and fips build simpler. There is no need to split this now. The import causes TLS negotiation to reject non-FIPS140 ciphers. --------- Co-authored-by: Cam Hutchison <camh@xdna.net>