Repository navigation
FIPS and shared openssl #3077
Description
Activity
- addedopensslIssues and PRs related to the OpenSSL dependency.Issues and PRs related to the OpenSSL dependency.buildIssues and PRs related to Node.js builds or CI infrastructure.Issues and PRs related to Node.js builds or CI infrastructure.
on Sep 26, 2015 +1 here — we openSUSE Tumbleweed users ran into this issue as well, see https://bugzilla.opensuse.org/show_bug.cgi?id=947747
@Nibbler999 there's hack that works this around should you need it — https://build.opensuse.org/package/view_file/home:msmeissn:branches:devel:languages:nodejs/nodejs/nodejs-no-fips.patch?rev=2
/cc @indutny :)
- added a commit that references this issue
on Oct 1, 2015 Should be fixed by #3153. Thanks!
Fixed in 9bd26e7
Fix confirmed, thanks!
- added a commit that references this issue
on Oct 2, 2015 So, is there a way to have FIPS and shared openssl?
@kasicka Does
node --enable-fipsornode --force-fipswork?Built on system without fips enabled:
[root@localhost asdf]# cat /proc/sys/crypto/fips_enabled 1 [root@localhost asdf]# node --enable-fips node: bad option: --enable-fips [root@localhost asdf]# node --force-fips node: bad option: --force-fipsBuilt on system with enabled fips has the same results, multiple tests failed.
Also:[root@localhost asdf]# node -p "process.versions.openssl" 1.0.2k-fipsI did not build it with --openssl-fips, because the fips functionality should be provided by openssl and I wasn't sure what to supply to the option.
- added a commit that references this issue
on Jul 27, 2026
If you build against the system openssl in Fedora 23 (1.0.2d-fips) node tries to enable FIPS. This causes around 100 test failures/crashes. It would be better if it only enabled FIPS if you explicitly use --openssl-fips