maria-discuss team mailing list archive
Mailing list archive
Re: mariadb + FIPS
Reindl Harald <h.reindl@xxxxxxxxxxxxx>
Fri, 30 Aug 2019 00:33:35 +0200
the lounge interactive design
Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Thunderbird/60.8.0
Am 30.08.19 um 00:10 schrieb Captain Wiggum:
> I have searched the archives and forums and cannot find an answer to
> this question.
> Does mariadb support FIPS, and if so, how or where is a document about this.
> I use mariadb 10.3.17 with OpenSSL 1.0.2 with FIPS enabled, all built
> from source.
> In FIPS mode, SHA1 is disallowed by openssl, as required by FIPS.
> However, when I search the mariadb code, SHA1 is used in many places.
> How can I update mariadb to use sha256, without a ton of recoding?
> Any tips appreciated.
outside of encryption code nothing is wrong with SHA1 depending on the
usecase and without context "SHA1 is used in many place" is a useless
there are even usecases where MD4 is just fine
againb: not every usage of a hash function is security related or
collisions prone and in that case it would be pretty dumb use a much
slower sha256 hash