Sign inSign up

ninefx/erlang-fips

By ninefx

•Updated over 8 years ago

Erlang/OTP compiled with --enable-fips

Image
0

518

ninefx/erlang-fips repository overview

⁠erlang-fips

FIPS 140-2 enabled Erlang containers

⁠Erlang installation

This container contains Erlang/OTP⁠ configured with --enable-fips for a FIPS mode crypto application⁠. The container builds on an Alpine image compiled in FIPS mode⁠.

⁠rebar3

It also includes a recent version rebar3⁠ on the $PATH, installed under /root/.cache. You can update to the latest version with rebar3 local upgrade.

⁠Self-test

The Dockerfile tests that FIPS mode is successfully enabled using a simple escript. This escript is only used during the Docker image build process and is not present in the final image.

⁠Not FIPS compliant

This Docker image is not FIPS compliant. The OpenSSL FIPS Security Policy requires that "An independently acquired FIPS 140­-2 validated implementation of SHA­1 HMAC must be used for this digest verification." The SHA1 HMAC in this image is validated by a vanilla OpenSSL installation in the underlying Dockerfile. However, feel free to modify the underlying Dockerfile for use with a FIPS module you validate with your own FIPS 140-2 implementation.

The goal of this project is to provide a convenient image to build/test Erlang software in FIPS mode. It is not suitable for a production deployment when FIPS 140-2 compliance is required.

Tag summary

Content type

Image

Digest

Size

61.7 MB

Last updated

over 8 years ago

docker pull ninefx/erlang-fips