Tycho Softworks · @tychosoft
351 followers · 5078 posts · Server fosstodon.org

@fasterthanlime sometimes things like compliance matters more than just speed...

#fips

Last updated 2 years ago

Skepickle · @skepickle
11 followers · 49 posts · Server tty0.social

Ever learned a new language _just_ to debug a issue?... and then find out the compiler/interpreter needs to be compiled with enabled? 🤦 Looking at you, !

#programming #security #fips #erlang

Last updated 2 years ago

Friendoftibet · @Gozoklaus
49 followers · 388 posts · Server muenster.im

#fips #merz #amthor

Last updated 2 years ago

AI6YR · @ai6yr
3263 followers · 14179 posts · Server m.ai6yr.org

mystery of the day: why does the code for states skip 03, 07, 14, and 43?!?!

#gis #fips

Last updated 2 years ago

Eingfoan :donor: · @eingfoan
117 followers · 1005 posts · Server infosec.exchange

Is there a well known list of keys and comparison of their ( ) capabilities?

Such as





….

#fido #security #level2 #fips #nfc #usbc #usba

Last updated 2 years ago

· @trippedup
37 followers · 132 posts · Server mstdn.starnix.network

Watching the Murdaugh trial live feed and saw the South Carolina court needs to activate (and apparently update) .

Can't wait until and get their validations so I can say there is a "free as in beer" replacement available, but in the meantime plenty of paid enterprise distros are validated. Would love to see more in public use.

#windows #RockyLinux #AlmaLinux #fips #foss

Last updated 2 years ago

Sergi Blanch-Torné · @sergi
19 followers · 154 posts · Server fosstodon.org

Now it's time to review the talks on . One to highlight is the talk about and fosdem.org/2023/schedule/event a lot of interesting information for developers that use libraries and crypto tools.

#fosdem #fips #openssl

Last updated 2 years ago

Sam Bowne :donor: · @sambowne
689 followers · 3141 posts · Server infosec.exchange

Edwards-curve Digital Signature Algorithm (EdDSA) is a digital signature scheme using a variant of Schnorr signature based on twisted Edwards curves Wikipedia

en.wikipedia.org/wiki/EdDSA

#cryptography #security #fips

Last updated 2 years ago

Soatok Dreamseeker · @soatok
3104 followers · 3667 posts · Server furry.engineer

FIPS 186-5 is out. It includes EdDSA (Ed25519, Ed448).

public-inspection.federalregis

#crypto #nist #fips

Last updated 2 years ago

Kinetischer Impaktor · @fbausch
231 followers · 1975 posts · Server heidel.berg.social

#heidelberg #fips #rnv #opnv

Last updated 2 years ago

Anil John 🇺🇸 · @aniltj
-1 followers · 303 posts · Server infosec.exchange

Hey @mprorock , are you aware of anyone who has written a step-by-step HOWTO on creating a fully w3.org/TR/did-core/ conformant (did.json) using:


compliant cryptographic primitives
❖ Stored in .well-known for per the :web Method Spec @ w3c-ccg.github.io/did-method-w

... of which, You Sir, are an editor! 🙂

#diddocument #openssl #fips #didresolution #did

Last updated 2 years ago

Thomas Powell.🧻🐴💩 · @stringsn88keys
29 followers · 38 posts · Server sdf.land

Anyone else had the joy of troubleshooting , , and at the same time? thomaspowell.com/2022/11/16/fi

#fips #windows #ruby

Last updated 2 years ago

Jason "JK" Keirstead · @BlueTeamJK
15 followers · 39 posts · Server infosec.exchange

It would be a great accelerator for adoption if there was a way to leverage them to accelerate / /

If one was able to digitally attest to known approved versions of software libraries in their SBOM, you would think it could reduce their certification burden.

The current NIAP/CC/FedRAMP process is endlessly broken and this could be a great way to start to modernize it.

#SBOM #niap #fips #fedramp

Last updated 2 years ago

Andy Tinkham · @andytinkham
130 followers · 350 posts · Server infosec.exchange

Are there any tools or vendors to help with determining FIPS compliance (I assume 140-3, but still figuring that out) for a large set of third-party libraries? So far, all I've gotten for internal guidance is "Figure out if our 3rd party dependencies are FIPS compliant", so starting from scratch here.

#fips #appsec #dependencies

Last updated 2 years ago

Thomas Powell.🧻🐴💩 · @stringsn88keys
22 followers · 28 posts · Server sdf.land

I would create a reasonable introductory post, especially since I just moved servers, but I'm trying to get with support running on and, tbh, I'm flinging more spaghetti plates at the wall than the billionaire who owns that other site. But I hope I at least have a sense of humility about it.

#openssl #fips #windows #ruby

Last updated 2 years ago

David Sugar · @tychosoft
244 followers · 3145 posts · Server fosstodon.org

Though I hate having to use this link, it is clear is a large social and developer culture promoter of toxic and this offers an example of what I mean. I am a bit glad redhat was bounced from many federal contracts, though they were replaced by . The key is certification is required for federal linux uses. Github - all your code belong to copilot ;).

developers.redhat.com/devnatio

#redhat #github #canonical #fips

Last updated 3 years ago

David Sugar · @tychosoft
244 followers · 3147 posts · Server fosstodon.org

I hear @IBM has setup 9 streams. Given many federal agencies had already rejected rhel 8 and decided to upgrade from rhel 7 to @Canonical, even canceling ongoing contracts that proposed upgrading products to rhel 8, while requiring compliant ubuntu for future things instead, I have no need to touch it, and have strong doubts ibm/ @redhat will remain a major distro player in the future.

#centos #fips

Last updated 3 years ago

Nicola Tuveri · @romen
32 followers · 142 posts · Server floss.social

RT @iamamoose@twitter.com

Our FIPS 140-2 validation report for the OpenSSL FIPS Provider was submitted to the CMVP on September 17.

keypair.us/2021/09/tested-conf

🐦🔗: twitter.com/iamamoose/status/1

#OpenSSL #fips #openssl30

Last updated 3 years ago

David Sugar · @tychosoft
244 followers · 3147 posts · Server fosstodon.org

Since the fed seems to now reject rhel, and I don't expect to ever have need for it again, I have purged my and dev and redhat testing images, saving a lot of disk space in the process.

#redhat #fips #centos

Last updated 4 years ago

David Sugar · @tychosoft
244 followers · 3147 posts · Server fosstodon.org

It is possible to produce certified binaries and native crypto with , which I only recently learned, and part of why I looked at it again and chose using it once I got sane project environments working in it. While @google only offers a docker image with the boring ssl patches built on it, an easy way to get a full go dev environment with fips compliance is to eviscerate the docker image, and copy it's /usr/local/go to your amd64 linux distro directly.

#fips #golang

Last updated 4 years ago