Skip to content

Always report FIPS mode true on developer platforms#1166

Merged
jasonkatonica merged 1 commit intoIBM:mainfrom
Mohit-Rajbhar100698:fix/disallow-weak-rsa-keys-for-fips-on-macos-in-developer-mode
Feb 12, 2026
Merged

Always report FIPS mode true on developer platforms#1166
jasonkatonica merged 1 commit intoIBM:mainfrom
Mohit-Rajbhar100698:fix/disallow-weak-rsa-keys-for-fips-on-macos-in-developer-mode

Conversation

@Mohit-Rajbhar100698
Copy link
Collaborator

@Mohit-Rajbhar100698 Mohit-Rajbhar100698 commented Feb 6, 2026

The OpenJCEPlusFIPS provider may run on platforms that support developer mode. On these systems, the provider should always report that it is operating in FIPS mode to ensure behavior is consistent with fully FIPS-certified platforms. This change simulates FIPS operation as closely as possible in development environments.

Signed-off-by: Mohit Rajbhar mohit.rajbhar@ibm.com

@Mohit-Rajbhar100698
Copy link
Collaborator Author

I was trying to rename the branch to match the PR title, but unfortunately the PR got closed by mistake. This is the newly updated PR.

@Mohit-Rajbhar100698 Mohit-Rajbhar100698 force-pushed the fix/disallow-weak-rsa-keys-for-fips-on-macos-in-developer-mode branch from f3ef91e to 6b75d60 Compare February 6, 2026 22:33
@jasonkatonica
Copy link
Member

Hi Mohit, I think the PR description and title ( and associated commit title and description ) are a bit misleading as the update is much more broad then just impacts to RSA. Perhaps something like this would make sense?

Always report FIPS mode true on developer platforms

The OpenJCEPlusFIPS provider may run on platforms that support developer
mode. On these systems, the provider should always report that it is
operating in FIPS mode to ensure behavior is consistent with fully
FIPS-certified platforms. This change simulates FIPS operation as closely
as possible in development environments.

@Mohit-Rajbhar100698 Mohit-Rajbhar100698 force-pushed the fix/disallow-weak-rsa-keys-for-fips-on-macos-in-developer-mode branch from 6b75d60 to 557e489 Compare February 9, 2026 17:23
@Mohit-Rajbhar100698 Mohit-Rajbhar100698 changed the title Disallow weak RSA keys on macOS and Linux (aarch64) in FIPS developer mode Always report FIPS mode true on developer platforms Feb 9, 2026
@Mohit-Rajbhar100698 Mohit-Rajbhar100698 force-pushed the fix/disallow-weak-rsa-keys-for-fips-on-macos-in-developer-mode branch from 557e489 to 58368d9 Compare February 9, 2026 17:27
@Mohit-Rajbhar100698 Mohit-Rajbhar100698 force-pushed the fix/disallow-weak-rsa-keys-for-fips-on-macos-in-developer-mode branch from 58368d9 to 28f7fd9 Compare February 12, 2026 11:30
The OpenJCEPlusFIPS provider may run on platforms that support developer
mode. On these systems, the provider should always report that it is operating in FIPS mode
to ensure behavior is consistent with fully FIPS-certified platforms.
This change simulates FIPS operation as closely as possible in development environments.

Fixes: https://github.ibm.com/runtimes/jit-crypto/issues/1076

Signed-off-by: Mohit Rajbhar <mohit.rajbhar@ibm.com>
@Mohit-Rajbhar100698 Mohit-Rajbhar100698 force-pushed the fix/disallow-weak-rsa-keys-for-fips-on-macos-in-developer-mode branch from 3a3e062 to b1e4fa6 Compare February 12, 2026 11:58
Copy link
Member

@jasonkatonica jasonkatonica left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Copy link
Member

@KostasTsiounis KostasTsiounis left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants