From a05f69f350506a72afb456da7fa0d40bb669aaca Mon Sep 17 00:00:00 2001 From: nmburgan <13688219+nmburgan@users.noreply.github.com> Date: Mon, 5 Oct 2026 17:46:09 -0700 Subject: [PATCH] Build the OpenSSL FIPS provider on FIPS platforms The FIPS agent packages have taken fips.so from the separate openssl-fips repository, where its version is pinned apart from the library and can fall behind it. This was done intentionally, because only certain OpenSSL FIPS module versions are officially "certified". However, these versions become out of date very quickly and can accumulate CVEs. For example, the only non-EOL "certified" FIPS module version is 3.1.2, but this contains several CVEs. A 3.5 version is currently undergoing certification, but it will run into the same issue in time. Instead, because we care more about remediating CVEs than the official certification, this builds the FIPS provider together with the library on FIPS platforms, removing the need for the openssl-fips component in the openvox packaging repo. Signed-off-by: nmburgan <13688219+nmburgan@users.noreply.github.com> --- configs/components/openssl-3.0.rb | 7 ++++++- configs/components/openssl-3.5.rb | 7 ++++++- 2 files changed, 12 insertions(+), 2 deletions(-) diff --git a/configs/components/openssl-3.0.rb b/configs/components/openssl-3.0.rb index dc3e485b..f381cf27 100644 --- a/configs/components/openssl-3.0.rb +++ b/configs/components/openssl-3.0.rb @@ -94,6 +94,7 @@ else configure_flags << 'no-legacy' << 'no-md4' end + configure_flags << 'enable-fips' if platform.is_fips? # Individual projects may provide their own openssl configure flags: project_flags = settings[:openssl_extra_configure_flags] || [] @@ -126,8 +127,12 @@ install_commands = [] # Skip man and html docs - install_commands << "#{platform[:make]} #{install_prefix} install_sw install_ssldirs" + install_targets = 'install_sw install_ssldirs' + install_targets += ' install_fips' if platform.is_fips? + install_commands << "#{platform[:make]} #{install_prefix} #{install_targets}" install_commands << "rm -f #{settings[:prefix]}/bin/c_rehash" + # The agent package generates fipsmodule.cnf on the host it is installed on + install_commands << "rm -f #{settings[:prefix]}/ssl/fipsmodule.cnf" if platform.is_fips? pkg.install do install_commands diff --git a/configs/components/openssl-3.5.rb b/configs/components/openssl-3.5.rb index 25d79bc0..bcee184c 100644 --- a/configs/components/openssl-3.5.rb +++ b/configs/components/openssl-3.5.rb @@ -84,6 +84,7 @@ ] configure_flags << 'no-legacy' << 'no-md4' + configure_flags << 'enable-fips' if platform.is_fips? # Individual projects may provide their own openssl configure flags: project_flags = settings[:openssl_extra_configure_flags] || [] @@ -114,8 +115,12 @@ install_commands = [] # Skip man and html docs - install_commands << "#{platform[:make]} #{install_prefix} install_sw install_ssldirs" + install_targets = 'install_sw install_ssldirs' + install_targets += ' install_fips' if platform.is_fips? + install_commands << "#{platform[:make]} #{install_prefix} #{install_targets}" install_commands << "rm -f #{settings[:prefix]}/bin/c_rehash" + # The agent package generates fipsmodule.cnf on the host it is installed on + install_commands << "rm -f #{settings[:prefix]}/ssl/fipsmodule.cnf" if platform.is_fips? pkg.install do install_commands