Sign inSign up

rootioinc/python

By rootioinc

•Updated about 2 months ago

Python 3.14 with wolfSSL FIPS 140-3 (Cert #4718) on Debian Trixie

Image
0

1.3K

rootioinc/python repository overview

⁠rootioinc/python:3.14-trixie-slim-fips

Python 3.14 on Debian Trixie with FIPS 140-3 validated cryptography — provided by wolfSSL (CMVP Certificate #4718) through the OpenSSL 3.5.6 provider interface (wolfProvider).

Python3.14.3 (compiled from source, Sigstore-verified)
OpenSSL3.5.6
FIPS modulewolfSSL FIPS 140-3, Certificate #4718 (via wolfProvider)
Base imagerootioinc/debian:trixie-slim-fips
Architecturelinux/amd64

⁠What this image is

Python 3.14 built from official source (verified with Sigstore — Python 3.14 dropped GPG .asc signatures) on the Root.io FIPS base image. The base provides the validated crypto stack (wolfSSL + wolfProvider as the exclusive OpenSSL provider); Python's ssl and hashlib route through that FIPS boundary. FIPS is active out of the box.

⁠Quick start

docker pull rootioinc/python:3.14-trixie-slim-fips

# Run your app
docker run --rm -v "$PWD:/app" -w /app rootioinc/python:3.14-trixie-slim-fips python3 app.py

# Confirm the FIPS OpenSSL is in use
docker run --rm rootioinc/python:3.14-trixie-slim-fips \
  python3 -c "import ssl; print(ssl.OPENSSL_VERSION)"   # -> OpenSSL 3.5.6 ...

⁠FIPS behaviour

  • Crypto routes through wolfSSL FIPS (Cert #4718) via wolfProvider; the OpenSSL default provider is not loaded.
  • MD5 is blocked at the OpenSSL level (_hashlib.openssl_md5 and openssl dgst -md5 are rejected); FIPS-approved algorithms (SHA-2/3, AES-GCM, HMAC, etc.) work.
  • TLS 1.2 / 1.3 supported with FIPS-approved cipher suites.
  • OPENSSL_CONF=/etc/fips/openssl.cnf is set by the base and must not be overridden.
⁠Note on hashlib.md5()

FIPS is enforced at the OpenSSL boundary. Python's built-in hashlib.md5() / sha1() are retained (CPython ships them independently of OpenSSL) so that FIPS-permitted non-security use (usedforsecurity=False, e.g. cache keys) keeps working. Applications must not use built-in MD5/SHA-1 for security purposes; see the project's developer guide for detection/handling guidance.

⁠Runtime notes

  • Runs as non-root user appuser (uid 1001); working dir /app.
  • The entrypoint runs a FIPS power-on self-test (fips-startup-check) and a Python FIPS init check at startup. Set FIPS_CHECK=false to skip them (development only).
  • scrypt is unavailable (not provided by the wolfSSL FIPS module).

⁠Tags

  • 3.14-trixie-slim-fips — Python 3.14.3 on Debian Trixie, FIPS 140-3.

⁠Architecture / multi-arch

Currently published for linux/amd64. The build is architecture-agnostic (Python is compiled per-arch), but an arm64 image requires an arm64 build of the rootioinc/debian:trixie-slim-fips base (with arm64 wolfSSL FIPS coverage) first.


Vendor: root.io Inc. — built on rootioinc/debian:trixie-slim-fips.

Tag summary

Content type

Image

Digest

sha256:9221b0187…

Size

88.6 MB

Last updated

about 2 months ago

docker pull rootioinc/python:3.12.13-slim-trixie-runtime-fips