<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>FIPS on</title><link>https://deploy-preview-3422--ornate-narwhal-088216.netlify.app/tags/fips/</link><description>Recent content in FIPS on</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>Copyright (c) 2023 Chainguard</copyright><lastBuildDate>Thu, 04 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://deploy-preview-3422--ornate-narwhal-088216.netlify.app/tags/fips/index.xml" rel="self" type="application/rss+xml"/><item><title>FedRAMP Technical Considerations &amp; Risk Factors</title><link>https://deploy-preview-3422--ornate-narwhal-088216.netlify.app/chainguard/chainguard-images/staying-secure/fedramp-considerations/</link><pubDate>Wed, 29 Jan 2025 15:56:52 -0700</pubDate><guid>https://deploy-preview-3422--ornate-narwhal-088216.netlify.app/chainguard/chainguard-images/staying-secure/fedramp-considerations/</guid><description>&lt;p&gt;Many frequently asked questions revolve around how organizations are meant to stay on top of the changing landscape for FedRAMP, PMOS, Revisions, and Certificates. This article outlines various considerations and risk factors that organizations should keep in mind when working to become and stay FedRAMP authorized.&lt;/p&gt;
&lt;h2 id="important-considerations-for-pmo-revision-trends" class="heading-2" data-heading-level="2"&gt;
&lt;span class="heading-text"&gt;Important Considerations for PMO Revision Trends&lt;/span&gt;
&lt;a href="#important-considerations-for-pmo-revision-trends" class="anchor" aria-label="Link to Important Considerations for PMO Revision Trends" title="Link to this section"&gt;
&lt;svg width="16" height="9" viewBox="0 0 16 9" fill="none" xmlns="http://www.w3.org/2000/svg" aria-hidden="true"&gt;
&lt;path d="M6.833 8.125H4C3 8.125 2.146 7.77067 1.438 7.062C0.729333 6.354 0.375 5.5 0.375 4.5C0.375 3.5 0.729333 2.646 1.438 1.938C2.146 1.22933 3 0.875 4 0.875H6.833V1.958H4C3.30533 1.958 2.708 2.208 2.208 2.708C1.708 3.208 1.458 3.80533 1.458 4.5C1.458 5.19467 1.708 5.792 2.208 6.292C2.708 6.792 3.30533 7.042 4 7.042H6.833V8.125ZM5.208 5.042V3.958H10.792V5.042H5.208ZM9.167 8.125V7.042H12C12.6947 7.042 13.292 6.792 13.792 6.292C14.292 5.792 14.542 5.19467 14.542 4.5C14.542 3.80533 14.292 3.208 13.792 2.708C13.292 2.208 12.6947 1.958 12 1.958H9.167V0.875H12C13 0.875 13.854 1.22933 14.562 1.938C15.2707 2.646 15.625 3.5 15.625 4.5C15.625 5.5 15.2707 6.354 14.562 7.062C13.854 7.77067 13 8.125 12 8.125H9.167Z" fill="currentColor"/&gt;
&lt;/svg&gt;
&lt;/a&gt;
&lt;/h2&gt;&lt;p&gt;There are a number of things one should keep in mind when analyzing revision trends from the FedRAMP Program Management Office (PMO) — which oversees the development of the FedRAMP program — and the changes in &lt;a href="https://csrc.nist.gov/projects/fips-140-3-transition-effort"&gt;FIPS 140-3&lt;/a&gt;. The following are of particular importance:&lt;/p&gt;</description></item><item><title>Understanding FIPS</title><link>https://deploy-preview-3422--ornate-narwhal-088216.netlify.app/chainguard/fips/understanding-fips/</link><pubDate>Thu, 16 Oct 2025 08:00:00 +0000</pubDate><guid>https://deploy-preview-3422--ornate-narwhal-088216.netlify.app/chainguard/fips/understanding-fips/</guid><description>&lt;h2 id="what-is-fips" class="heading-2" data-heading-level="2"&gt;
&lt;span class="heading-text"&gt;What is FIPS?&lt;/span&gt;
&lt;a href="#what-is-fips" class="anchor" aria-label="Link to What is FIPS?" title="Link to this section"&gt;
&lt;svg width="16" height="9" viewBox="0 0 16 9" fill="none" xmlns="http://www.w3.org/2000/svg" aria-hidden="true"&gt;
&lt;path d="M6.833 8.125H4C3 8.125 2.146 7.77067 1.438 7.062C0.729333 6.354 0.375 5.5 0.375 4.5C0.375 3.5 0.729333 2.646 1.438 1.938C2.146 1.22933 3 0.875 4 0.875H6.833V1.958H4C3.30533 1.958 2.708 2.208 2.208 2.708C1.708 3.208 1.458 3.80533 1.458 4.5C1.458 5.19467 1.708 5.792 2.208 6.292C2.708 6.792 3.30533 7.042 4 7.042H6.833V8.125ZM5.208 5.042V3.958H10.792V5.042H5.208ZM9.167 8.125V7.042H12C12.6947 7.042 13.292 6.792 13.792 6.292C14.292 5.792 14.542 5.19467 14.542 4.5C14.542 3.80533 14.292 3.208 13.792 2.708C13.292 2.208 12.6947 1.958 12 1.958H9.167V0.875H12C13 0.875 13.854 1.22933 14.562 1.938C15.2707 2.646 15.625 3.5 15.625 4.5C15.625 5.5 15.2707 6.354 14.562 7.062C13.854 7.77067 13 8.125 12 8.125H9.167Z" fill="currentColor"/&gt;
&lt;/svg&gt;
&lt;/a&gt;
&lt;/h2&gt;&lt;p&gt;Federal Information Processing Standards (FIPS) are publicly announced standards developed by the &lt;a href="https://www.nist.gov/itl/publications-0/federal-information-processing-standards-fips"&gt;National Institute of Standards and Technology&lt;/a&gt; (NIST) in accordance with the Federal Information Security Management Act (FISMA) and approved by the U.S. Secretary of Commerce.&lt;/p&gt;</description></item><item><title>Chainguard FIPS Containers</title><link>https://deploy-preview-3422--ornate-narwhal-088216.netlify.app/chainguard/fips/fips-images/</link><pubDate>Thu, 08 Feb 2024 15:56:52 -0700</pubDate><guid>https://deploy-preview-3422--ornate-narwhal-088216.netlify.app/chainguard/fips/fips-images/</guid><description>&lt;h2 id="what-is-fips" class="heading-2" data-heading-level="2"&gt;
&lt;span class="heading-text"&gt;What is FIPS?&lt;/span&gt;
&lt;a href="#what-is-fips" class="anchor" aria-label="Link to What is FIPS?" title="Link to this section"&gt;
&lt;svg width="16" height="9" viewBox="0 0 16 9" fill="none" xmlns="http://www.w3.org/2000/svg" aria-hidden="true"&gt;
&lt;path d="M6.833 8.125H4C3 8.125 2.146 7.77067 1.438 7.062C0.729333 6.354 0.375 5.5 0.375 4.5C0.375 3.5 0.729333 2.646 1.438 1.938C2.146 1.22933 3 0.875 4 0.875H6.833V1.958H4C3.30533 1.958 2.708 2.208 2.208 2.708C1.708 3.208 1.458 3.80533 1.458 4.5C1.458 5.19467 1.708 5.792 2.208 6.292C2.708 6.792 3.30533 7.042 4 7.042H6.833V8.125ZM5.208 5.042V3.958H10.792V5.042H5.208ZM9.167 8.125V7.042H12C12.6947 7.042 13.292 6.792 13.792 6.292C14.292 5.792 14.542 5.19467 14.542 4.5C14.542 3.80533 14.292 3.208 13.792 2.708C13.292 2.208 12.6947 1.958 12 1.958H9.167V0.875H12C13 0.875 13.854 1.22933 14.562 1.938C15.2707 2.646 15.625 3.5 15.625 4.5C15.625 5.5 15.2707 6.354 14.562 7.062C13.854 7.77067 13 8.125 12 8.125H9.167Z" fill="currentColor"/&gt;
&lt;/svg&gt;
&lt;/a&gt;
&lt;/h2&gt;&lt;p&gt;&lt;a href="https://www.nist.gov/itl/publications-0/federal-information-processing-standards-fips"&gt;Federal Information Processing Standards&lt;/a&gt; (FIPS) are standards developed by the National Institute of Standards and Technology (NIST) in accordance with the Federal Information Security Management Act (FISMA). FIPS compliance ensures that cryptographic security services within applications meet strict security and integrity standards, and are implemented and configured correctly.&lt;/p&gt;</description></item><item><title>Getting Started with FIPS Containers</title><link>https://deploy-preview-3422--ornate-narwhal-088216.netlify.app/chainguard/fips/getting-started/</link><pubDate>Thu, 16 Oct 2025 08:00:00 +0000</pubDate><guid>https://deploy-preview-3422--ornate-narwhal-088216.netlify.app/chainguard/fips/getting-started/</guid><description>&lt;h2 id="prerequisites" class="heading-2" data-heading-level="2"&gt;
&lt;span class="heading-text"&gt;Prerequisites&lt;/span&gt;
&lt;a href="#prerequisites" class="anchor" aria-label="Link to Prerequisites" title="Link to this section"&gt;
&lt;svg width="16" height="9" viewBox="0 0 16 9" fill="none" xmlns="http://www.w3.org/2000/svg" aria-hidden="true"&gt;
&lt;path d="M6.833 8.125H4C3 8.125 2.146 7.77067 1.438 7.062C0.729333 6.354 0.375 5.5 0.375 4.5C0.375 3.5 0.729333 2.646 1.438 1.938C2.146 1.22933 3 0.875 4 0.875H6.833V1.958H4C3.30533 1.958 2.708 2.208 2.208 2.708C1.708 3.208 1.458 3.80533 1.458 4.5C1.458 5.19467 1.708 5.792 2.208 6.292C2.708 6.792 3.30533 7.042 4 7.042H6.833V8.125ZM5.208 5.042V3.958H10.792V5.042H5.208ZM9.167 8.125V7.042H12C12.6947 7.042 13.292 6.792 13.792 6.292C14.292 5.792 14.542 5.19467 14.542 4.5C14.542 3.80533 14.292 3.208 13.792 2.708C13.292 2.208 12.6947 1.958 12 1.958H9.167V0.875H12C13 0.875 13.854 1.22933 14.562 1.938C15.2707 2.646 15.625 3.5 15.625 4.5C15.625 5.5 15.2707 6.354 14.562 7.062C13.854 7.77067 13 8.125 12 8.125H9.167Z" fill="currentColor"/&gt;
&lt;/svg&gt;
&lt;/a&gt;
&lt;/h2&gt;&lt;p&gt;Before starting, you&amp;rsquo;ll need:&lt;/p&gt;</description></item><item><title>Chainguard FIPS TLS Connectivity Requirements</title><link>https://deploy-preview-3422--ornate-narwhal-088216.netlify.app/chainguard/fips/tls-requirements/</link><pubDate>Sat, 15 Nov 2025 08:49:31 +0000</pubDate><guid>https://deploy-preview-3422--ornate-narwhal-088216.netlify.app/chainguard/fips/tls-requirements/</guid><description>&lt;p&gt;This document provides an overview of FIPS TLS connectivity requirements for using Chainguard FIPS products. These FIPS products have &lt;strong&gt;higher&lt;/strong&gt; minimum TLS requirements, which complicates connecting them to insecure EOL non-FIPS systems, as well as FIPS systems with lapsed (historical) certification.&lt;/p&gt;
&lt;p&gt;Chainguard strives to ensure the broadest connectivity possible for its FIPS products. However, many obsolete systems are still widely used and may not be able to connect with Chainguard FIPS products.&lt;/p&gt;</description></item><item><title>Overview of Chainguard EKS Add-ons</title><link>https://deploy-preview-3422--ornate-narwhal-088216.netlify.app/chainguard/fips/eks-add-ons/</link><pubDate>Fri, 10 Apr 2026 00:00:00 +0000</pubDate><guid>https://deploy-preview-3422--ornate-narwhal-088216.netlify.app/chainguard/fips/eks-add-ons/</guid><description>&lt;p&gt;Chainguard EKS add-ons are hardened, minimal container images for the foundational software components that power Amazon Elastic Kubernetes Service (EKS) clusters. Available through &lt;a href="https://aws.amazon.com/marketplace"&gt;AWS Marketplace&lt;/a&gt;, they serve as FIPS-validated drop-in replacements for AWS default add-ons, providing zero known CVEs and FIPS 140-3 validated cryptography without requiring custom image builds or manifest overrides.&lt;/p&gt;
&lt;h2 id="what-are-eks-add-ons" class="heading-2" data-heading-level="2"&gt;
&lt;span class="heading-text"&gt;What are EKS add-ons?&lt;/span&gt;
&lt;a href="#what-are-eks-add-ons" class="anchor" aria-label="Link to What are EKS add-ons?" title="Link to this section"&gt;
&lt;svg width="16" height="9" viewBox="0 0 16 9" fill="none" xmlns="http://www.w3.org/2000/svg" aria-hidden="true"&gt;
&lt;path d="M6.833 8.125H4C3 8.125 2.146 7.77067 1.438 7.062C0.729333 6.354 0.375 5.5 0.375 4.5C0.375 3.5 0.729333 2.646 1.438 1.938C2.146 1.22933 3 0.875 4 0.875H6.833V1.958H4C3.30533 1.958 2.708 2.208 2.208 2.708C1.708 3.208 1.458 3.80533 1.458 4.5C1.458 5.19467 1.708 5.792 2.208 6.292C2.708 6.792 3.30533 7.042 4 7.042H6.833V8.125ZM5.208 5.042V3.958H10.792V5.042H5.208ZM9.167 8.125V7.042H12C12.6947 7.042 13.292 6.792 13.792 6.292C14.292 5.792 14.542 5.19467 14.542 4.5C14.542 3.80533 14.292 3.208 13.792 2.708C13.292 2.208 12.6947 1.958 12 1.958H9.167V0.875H12C13 0.875 13.854 1.22933 14.562 1.938C15.2707 2.646 15.625 3.5 15.625 4.5C15.625 5.5 15.2707 6.354 14.562 7.062C13.854 7.77067 13 8.125 12 8.125H9.167Z" fill="currentColor"/&gt;
&lt;/svg&gt;
&lt;/a&gt;
&lt;/h2&gt;&lt;p&gt;Amazon EKS add-ons are software components that provide supporting operational capabilities to Kubernetes applications — things like networking drivers, storage integrations, and observability agents that allow the cluster to interact with underlying AWS resources, but aren&amp;rsquo;t specific to any application running on it.&lt;/p&gt;</description></item><item><title>FIPS and Non-Approved Algorithms</title><link>https://deploy-preview-3422--ornate-narwhal-088216.netlify.app/chainguard/fips/non-approved-algorithms/</link><pubDate>Tue, 28 Oct 2025 08:00:00 +0000</pubDate><guid>https://deploy-preview-3422--ornate-narwhal-088216.netlify.app/chainguard/fips/non-approved-algorithms/</guid><description>&lt;h2 id="overview" class="heading-2" data-heading-level="2"&gt;
&lt;span class="heading-text"&gt;Overview&lt;/span&gt;
&lt;a href="#overview" class="anchor" aria-label="Link to Overview" title="Link to this section"&gt;
&lt;svg width="16" height="9" viewBox="0 0 16 9" fill="none" xmlns="http://www.w3.org/2000/svg" aria-hidden="true"&gt;
&lt;path d="M6.833 8.125H4C3 8.125 2.146 7.77067 1.438 7.062C0.729333 6.354 0.375 5.5 0.375 4.5C0.375 3.5 0.729333 2.646 1.438 1.938C2.146 1.22933 3 0.875 4 0.875H6.833V1.958H4C3.30533 1.958 2.708 2.208 2.208 2.708C1.708 3.208 1.458 3.80533 1.458 4.5C1.458 5.19467 1.708 5.792 2.208 6.292C2.708 6.792 3.30533 7.042 4 7.042H6.833V8.125ZM5.208 5.042V3.958H10.792V5.042H5.208ZM9.167 8.125V7.042H12C12.6947 7.042 13.292 6.792 13.792 6.292C14.292 5.792 14.542 5.19467 14.542 4.5C14.542 3.80533 14.292 3.208 13.792 2.708C13.292 2.208 12.6947 1.958 12 1.958H9.167V0.875H12C13 0.875 13.854 1.22933 14.562 1.938C15.2707 2.646 15.625 3.5 15.625 4.5C15.625 5.5 15.2707 6.354 14.562 7.062C13.854 7.77067 13 8.125 12 8.125H9.167Z" fill="currentColor"/&gt;
&lt;/svg&gt;
&lt;/a&gt;
&lt;/h2&gt;&lt;p&gt;FIPS cryptographic modules implement cryptographically strong protection of data at rest and in transit. NIST&amp;rsquo;s position on this is very clear (&lt;a href="https://csrc.nist.gov/projects/cryptographic-module-validation-program"&gt;source&lt;/a&gt;):&lt;/p&gt;</description></item><item><title>Verify that Chainguard FIPS Containers are Configured to Use FIPS Modules</title><link>https://deploy-preview-3422--ornate-narwhal-088216.netlify.app/chainguard/fips/verify-fips/</link><pubDate>Sun, 23 Nov 2025 08:04:00 +0000</pubDate><guid>https://deploy-preview-3422--ornate-narwhal-088216.netlify.app/chainguard/fips/verify-fips/</guid><description>&lt;p&gt;Chainguard offers hundreds of FIPS container image variants covering language runtimes (Go, Java, Python, Node.js, .NET, PHP, C/C++), databases, web servers, and Kubernetes components. These images use NIST-validated cryptographic modules including the OpenSSL FIPS provider, Bouncy Castle FIPS, and BoringCrypto. Refer to Chainguard&amp;rsquo;s &lt;a href="https://www.chainguard.dev/legal/fips-commitment"&gt;FIPS Commitment&lt;/a&gt; for a full list of the modules used in Chainguard FIPS Images, as well as their respective CMVP certificates and SBOM indicators.&lt;/p&gt;
&lt;p&gt;This guide outlines how to verify that Chainguard&amp;rsquo;s FIPS images are properly configured to use these FIPS modules.&lt;/p&gt;</description></item><item><title>Kernel-Independent FIPS Architecture</title><link>https://deploy-preview-3422--ornate-narwhal-088216.netlify.app/chainguard/fips/kernel-independent-architecture/</link><pubDate>Thu, 16 Oct 2025 08:00:00 +0000</pubDate><guid>https://deploy-preview-3422--ornate-narwhal-088216.netlify.app/chainguard/fips/kernel-independent-architecture/</guid><description>&lt;h2 id="overview" class="heading-2" data-heading-level="2"&gt;
&lt;span class="heading-text"&gt;Overview&lt;/span&gt;
&lt;a href="#overview" class="anchor" aria-label="Link to Overview" title="Link to this section"&gt;
&lt;svg width="16" height="9" viewBox="0 0 16 9" fill="none" xmlns="http://www.w3.org/2000/svg" aria-hidden="true"&gt;
&lt;path d="M6.833 8.125H4C3 8.125 2.146 7.77067 1.438 7.062C0.729333 6.354 0.375 5.5 0.375 4.5C0.375 3.5 0.729333 2.646 1.438 1.938C2.146 1.22933 3 0.875 4 0.875H6.833V1.958H4C3.30533 1.958 2.708 2.208 2.208 2.708C1.708 3.208 1.458 3.80533 1.458 4.5C1.458 5.19467 1.708 5.792 2.208 6.292C2.708 6.792 3.30533 7.042 4 7.042H6.833V8.125ZM5.208 5.042V3.958H10.792V5.042H5.208ZM9.167 8.125V7.042H12C12.6947 7.042 13.292 6.792 13.792 6.292C14.292 5.792 14.542 5.19467 14.542 4.5C14.542 3.80533 14.292 3.208 13.792 2.708C13.292 2.208 12.6947 1.958 12 1.958H9.167V0.875H12C13 0.875 13.854 1.22933 14.562 1.938C15.2707 2.646 15.625 3.5 15.625 4.5C15.625 5.5 15.2707 6.354 14.562 7.062C13.854 7.77067 13 8.125 12 8.125H9.167Z" fill="currentColor"/&gt;
&lt;/svg&gt;
&lt;/a&gt;
&lt;/h2&gt;&lt;p&gt;Chainguard FIPS Containers use a userspace entropy source instead of relying on the host kernel to provide validated randomness. This kernel-independent design allows FIPS containers to run on any recent Linux kernel, eliminating the traditional requirement for kernels configured in FIPS mode.&lt;/p&gt;</description></item><item><title>Chainguard FIPS Container FAQs</title><link>https://deploy-preview-3422--ornate-narwhal-088216.netlify.app/chainguard/fips/faqs/</link><pubDate>Fri, 10 Jan 2025 15:56:52 -0700</pubDate><guid>https://deploy-preview-3422--ornate-narwhal-088216.netlify.app/chainguard/fips/faqs/</guid><description>&lt;p&gt;Answers to your questions about Chainguard FIPS container images.&lt;/p&gt;
&lt;h2 id="is-there-a-way-to-enable-or-disable-the-fips-mode-in-a-fips-image" class="heading-2" data-heading-level="2"&gt;
&lt;span class="heading-text"&gt;Is there a way to enable or disable the FIPS mode in a FIPS image?&lt;/span&gt;
&lt;a href="#is-there-a-way-to-enable-or-disable-the-fips-mode-in-a-fips-image" class="anchor" aria-label="Link to Is there a way to enable or disable the FIPS mode in a FIPS image?" title="Link to this section"&gt;
&lt;svg width="16" height="9" viewBox="0 0 16 9" fill="none" xmlns="http://www.w3.org/2000/svg" aria-hidden="true"&gt;
&lt;path d="M6.833 8.125H4C3 8.125 2.146 7.77067 1.438 7.062C0.729333 6.354 0.375 5.5 0.375 4.5C0.375 3.5 0.729333 2.646 1.438 1.938C2.146 1.22933 3 0.875 4 0.875H6.833V1.958H4C3.30533 1.958 2.708 2.208 2.208 2.708C1.708 3.208 1.458 3.80533 1.458 4.5C1.458 5.19467 1.708 5.792 2.208 6.292C2.708 6.792 3.30533 7.042 4 7.042H6.833V8.125ZM5.208 5.042V3.958H10.792V5.042H5.208ZM9.167 8.125V7.042H12C12.6947 7.042 13.292 6.792 13.792 6.292C14.292 5.792 14.542 5.19467 14.542 4.5C14.542 3.80533 14.292 3.208 13.792 2.708C13.292 2.208 12.6947 1.958 12 1.958H9.167V0.875H12C13 0.875 13.854 1.22933 14.562 1.938C15.2707 2.646 15.625 3.5 15.625 4.5C15.625 5.5 15.2707 6.354 14.562 7.062C13.854 7.77067 13 8.125 12 8.125H9.167Z" fill="currentColor"/&gt;
&lt;/svg&gt;
&lt;/a&gt;
&lt;/h2&gt;&lt;p&gt;All Chainguard FIPS Containers are configured in approved-only mode as noted in our &lt;a href="https://www.chainguard.dev/legal/fips-commitment"&gt;FIPS commitment&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Getting started with the Chainguard Spark FIPS container</title><link>https://deploy-preview-3422--ornate-narwhal-088216.netlify.app/chainguard/chainguard-images/getting-started/spark-fips/</link><pubDate>Thu, 04 Jun 2026 00:00:00 +0000</pubDate><guid>https://deploy-preview-3422--ornate-narwhal-088216.netlify.app/chainguard/chainguard-images/getting-started/spark-fips/</guid><description>&lt;p&gt;Apache Spark is a distributed computing engine for batch processing, stream processing, and machine learning at scale. Organizations subject to federal compliance requirements—including FedRAMP, FISMA, and Department of Defense frameworks—must use FIPS 140-3 validated cryptography for all cryptographic operations in Spark.&lt;/p&gt;
&lt;p&gt;Chainguard&amp;rsquo;s Spark FIPS container packages Apache Spark with the Bouncy Castle FIPS cryptographic provider, replacing the standard JVM cryptographic modules with NIST-validated equivalents. In FIPS mode, TLS connections require BCFKS-format keystores rather than the standard PKCS12 or JKS formats, and only FIPS-approved cipher suites are permitted.&lt;/p&gt;</description></item></channel></rss>