Python 3.14 with wolfSSL FIPS 140-3 (Cert #4718) on Debian Trixie
1.3K
Python 3.14 on Debian Trixie with FIPS 140-3 validated cryptography — provided by wolfSSL (CMVP Certificate #4718) through the OpenSSL 3.5.6 provider interface (wolfProvider).
| Python | 3.14.3 (compiled from source, Sigstore-verified) |
| OpenSSL | 3.5.6 |
| FIPS module | wolfSSL FIPS 140-3, Certificate #4718 (via wolfProvider) |
| Base image | rootioinc/debian:trixie-slim-fips |
| Architecture | linux/amd64 |
Python 3.14 built from official source (verified with Sigstore — Python 3.14 dropped GPG
.asc signatures) on the Root.io FIPS base image. The base provides the validated crypto
stack (wolfSSL + wolfProvider as the exclusive OpenSSL provider); Python's ssl and
hashlib route through that FIPS boundary. FIPS is active out of the box.
docker pull rootioinc/python:3.14-trixie-slim-fips
# Run your app
docker run --rm -v "$PWD:/app" -w /app rootioinc/python:3.14-trixie-slim-fips python3 app.py
# Confirm the FIPS OpenSSL is in use
docker run --rm rootioinc/python:3.14-trixie-slim-fips \
python3 -c "import ssl; print(ssl.OPENSSL_VERSION)" # -> OpenSSL 3.5.6 ...
_hashlib.openssl_md5 and openssl dgst -md5
are rejected); FIPS-approved algorithms (SHA-2/3, AES-GCM, HMAC, etc.) work.OPENSSL_CONF=/etc/fips/openssl.cnf is set by the base and must not be overridden.hashlib.md5()FIPS is enforced at the OpenSSL boundary. Python's built-in hashlib.md5() /
sha1() are retained (CPython ships them independently of OpenSSL) so that
FIPS-permitted non-security use (usedforsecurity=False, e.g. cache keys) keeps working.
Applications must not use built-in MD5/SHA-1 for security purposes; see the project's
developer guide for detection/handling guidance.
appuser (uid 1001); working dir /app.fips-startup-check) and a Python FIPS
init check at startup. Set FIPS_CHECK=false to skip them (development only).scrypt is unavailable (not provided by the wolfSSL FIPS module).3.14-trixie-slim-fips — Python 3.14.3 on Debian Trixie, FIPS 140-3.Currently published for linux/amd64. The build is architecture-agnostic (Python is
compiled per-arch), but an arm64 image requires an arm64 build of the
rootioinc/debian:trixie-slim-fips base (with arm64 wolfSSL FIPS coverage) first.
Vendor: root.io Inc. — built on rootioinc/debian:trixie-slim-fips.
Content type
Image
Digest
sha256:9221b0187…
Size
88.6 MB
Last updated
about 2 months ago
docker pull rootioinc/python:3.12.13-slim-trixie-runtime-fips