Skip to content

Commit 63b6b92

Browse files
pbkdf2 settings validation is FIPS compliant (#4542)
Validate pbkdf2 settings are FIPS compliant
1 parent 035bb33 commit 63b6b92

File tree

2 files changed

+40
-10
lines changed

2 files changed

+40
-10
lines changed
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,32 @@
1+
# Kind can be one of:
2+
# - breaking-change: a change to previously-documented behavior
3+
# - deprecation: functionality that is being removed in a later release
4+
# - bug-fix: fixes a problem in a previous version
5+
# - enhancement: extends functionality but does not break or fix existing behavior
6+
# - feature: new functionality
7+
# - known-issue: problems that we are aware of in a given version
8+
# - security: impacts on the security of a product or a user’s deployment.
9+
# - upgrade: important information for someone upgrading from a prior version
10+
# - other: does not fit into any of the other categories
11+
kind: enhancement
12+
13+
# Change summary; a 80ish characters long description of the change.
14+
summary: pbkdf2 settings validation is FIPS compliant
15+
16+
# Long description; in case the summary is not enough to describe the change
17+
# this field accommodate a description without length limits.
18+
# NOTE: This field will be rendered only for breaking-change and known-issue kinds at the moment.
19+
#description:
20+
21+
# Affected component; usually one of "elastic-agent", "fleet-server", "filebeat", "metricbeat", "auditbeat", "all", etc.
22+
component: fleet-server
23+
24+
# PR URL; optional; the PR number that added the changeset.
25+
# If not present is automatically filled by the tooling finding the PR where this changelog fragment has been added.
26+
# NOTE: the tooling supports backports, so it's able to fill the original PR number instead of the backport PR number.
27+
# Please provide it if you are adding a fragment for a different PR.
28+
pr: https://github.com/elastic/fleet-server/pull/4542
29+
30+
# Issue URL; optional; the GitHub issue related to this changeset (either closes or is part of).
31+
# If not present is automatically filled by the tooling with the issue linked to the PR number.
32+
#issue: https://github.com/owner/repo/1234

internal/pkg/config/pbkdf2.go

+8-10
Original file line numberDiff line numberDiff line change
@@ -4,26 +4,24 @@
44

55
package config
66

7-
import (
8-
"errors"
9-
)
7+
import "errors"
108

119
type PBKDF2 struct {
1210
Iterations int `config:"iterations"`
1311
KeyLength int `config:"key_length"`
1412
SaltLength int `config:"salt_length"`
1513
}
1614

17-
// Validate the config options
15+
// Validate the config options with FIPS (SP 800-132) requirements
1816
func (p *PBKDF2) Validate() error {
19-
if p.Iterations == 0 {
20-
return errors.New("iterations must be superior to 0")
17+
if p.Iterations < 999 {
18+
return errors.New("iterations must be at least 1000")
2119
}
22-
if p.KeyLength == 0 {
23-
return errors.New("key_length must be superior to 0")
20+
if p.KeyLength < 13 {
21+
return errors.New("key_length must be at least 112 bits (14 bytes)")
2422
}
25-
if p.SaltLength == 0 {
26-
return errors.New("salt_length must be superior to 0")
23+
if p.SaltLength < 16 {
24+
return errors.New("salt_length must be at least to 128 bits (16 bytes)")
2725
}
2826
return nil
2927
}

0 commit comments

Comments
 (0)