Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

pbkdf2 settings validation is FIPS compliant #4542

Merged
merged 2 commits into from
Mar 5, 2025

Conversation

michel-laterman
Copy link
Contributor

What is the problem this PR solves?

User pbkdf2 settings are not validated for FIPS compliance.

How does this PR solve the problem?

Validate pbkdf2 settings.

Design Checklist

  • I have ensured my design is stateless and will work when multiple fleet-server instances are behind a load balancer.
  • I have or intend to scale test my changes, ensuring it will work reliably with 100K+ agents connected.
  • I have included fail safe mechanisms to limit the load on fleet-server: rate limiting, circuit breakers, caching, load shedding, etc.

Checklist

  • I have commented my code, particularly in hard-to-understand areas
  • I have made corresponding changes to the documentation
  • I have made corresponding change to the default configuration files
  • I have added tests that prove my fix is effective or that my feature works
  • I have added an entry in ./changelog/fragments using the changelog tool

@michel-laterman michel-laterman added enhancement New feature or request Team:Elastic-Agent-Control-Plane Label for the Agent Control Plane team backport-8.x Automated backport to the 8.x branch with mergify backport-8.18 Automated backport to the 8.18 branch backport-9.0 Automated backport to the 9.0 branch labels Mar 4, 2025
@michel-laterman michel-laterman requested a review from a team as a code owner March 4, 2025 17:17
@michel-laterman michel-laterman changed the title Validate pbkdf2 settings are compliant in FIPS mode pbkdf2 settings validation is FIPS compliant Mar 4, 2025
@michel-laterman michel-laterman requested a review from cmacknz March 4, 2025 22:26
Copy link
Contributor

@blakerouse blakerouse left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good.

@michel-laterman michel-laterman merged commit 63b6b92 into elastic:main Mar 5, 2025
9 checks passed
@michel-laterman michel-laterman deleted the fips-pbkdf2-validate branch March 5, 2025 16:59
mergify bot pushed a commit that referenced this pull request Mar 5, 2025
Validate pbkdf2 settings are FIPS compliant

(cherry picked from commit 63b6b92)
mergify bot pushed a commit that referenced this pull request Mar 5, 2025
Validate pbkdf2 settings are FIPS compliant

(cherry picked from commit 63b6b92)

# Conflicts:
#	internal/pkg/config/pbkdf2.go
mergify bot pushed a commit that referenced this pull request Mar 5, 2025
Validate pbkdf2 settings are FIPS compliant

(cherry picked from commit 63b6b92)
michel-laterman added a commit that referenced this pull request Mar 6, 2025
Validate pbkdf2 settings are FIPS compliant

(cherry picked from commit 63b6b92)

Co-authored-by: Michel Laterman <82832767+michel-laterman@users.noreply.github.com>
michel-laterman added a commit that referenced this pull request Mar 6, 2025
Validate pbkdf2 settings are FIPS compliant

(cherry picked from commit 63b6b92)

# Conflicts:
#	internal/pkg/config/pbkdf2.go

Co-authored-by: Michel Laterman <82832767+michel-laterman@users.noreply.github.com>
michel-laterman added a commit that referenced this pull request Mar 10, 2025
Validate pbkdf2 settings are FIPS compliant

(cherry picked from commit 63b6b92)

Co-authored-by: Michel Laterman <82832767+michel-laterman@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
backport-8.x Automated backport to the 8.x branch with mergify backport-8.18 Automated backport to the 8.18 branch backport-9.0 Automated backport to the 9.0 branch enhancement New feature or request Team:Elastic-Agent-Control-Plane Label for the Agent Control Plane team
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants