镜像站点 · 本页由第三方 GitHub 只读镜像提供,非 GitHub 官方站点,不接受任何登录或凭据输入。前往 github.com
Skip to content

Node 4.2: Unable to run Node in non-FIPS mode if compiled with FIPS support #3819

Description

@lordjabez

As currently implemented, when Node is compiled with FIPS support (./configure fips), there is no way to disable engaging FIPS mode during execution. This means that several functions that rely on non-FIPS approved algorithms (e.g. md5 hashing) will fail, as will any code that depends on them (most obviously, npm).

What seems needed to me is a way to explicitly enable or disable FIPS operation each time node is invoked. The way this is done with the openssl CLI is via the OPENSSL_FIPS environment variable.

It is straightforward to add a similar capability to Node. A pull request with a suggested implementation is forthcoming.

Activity

  1. jasnell commented on Nov 13, 2015

    @jasnell
    Member
  2. added
    tlsIssues and PRs related to the tls subsystem.
    cryptoIssues and PRs related to the crypto subsystem.
    feature requestIssues requesting new Node.js features.
    on Nov 13, 2015
  3. mhdawson commented on Nov 14, 2015

    @mhdawson
    Member

    @lordjabez in what cases are you seeing npm fail with FIPS turned on ?

    I agree an option to turn on /off would likely be useful @stefanmb

  4. stefanmb commented on Nov 14, 2015

    @stefanmb
    Contributor

    @lordjabez @mhdawson

    At first look MD5 dependencies in npm are not well justified. I'm trying to fix them.

  5. lordjabez commented on Nov 14, 2015

    @lordjabez
    Author

    Certainly if npm can be made to run with FIPS mode active, that's a good thing. But in any case I agree with @mhdawson that some form of runtime switch is needed to make a FIPS validated Node practical.

    I'm pushing my company pretty hard to move our entire tech stack to Node, and running FIPS validated is a key part of that.

  6. stefanmb commented on Nov 14, 2015

    @stefanmb
    Contributor

    Another complication is that the test cases will become much more complex:

    (1) Turn on FIPS.
    (2) Test crypto, including test failures due to FIPS incompatible crypto.
    (3) Turn off FIPS.
    (4) Test crypto, include test success with FIPS incompatible crypto.
    (5) Repeat a number of times.

  7. stefanmb commented on Nov 14, 2015

    @stefanmb
    Contributor

    @lordjabez

    I had better luck with npm and FIPS after the following patches:
    npm/write-file-atomic#7
    npm/unique-slug#1
    npm/fs-write-stream-atomic#6

    I'll see if I can get them accepted. There is still the issue regarding native modules #3815 which will have to be addressed.

  8. jelmd commented on Nov 15, 2015

    @jelmd

    Not sure, whether this applies to 4.x as well, however, I had to fix v5.0.0 too because it never called FIPS_mode() (and if compiled with -DFIPS_NODE it calls fips_mode_set(1) again and again w/o need, which in turn causes annoying messages)! Anyway, see http://iws.cs.uni-magdeburg.de/~elkner/tmp/node5/ssl.patch and look for 'FIPS_mode()' (2 places) - the major problem.

    BTW: I think the major issue here is, that it is assumed, that a FIPS capable lib is always used with FIPS_mode set to 1. This is wrong! Actually one doesn't need a non-FIPS capable OpenSSL lib at all, if the application provides a mechanism, to switch it on on demand (e.g. node --fips), because basically only than the non-FIPS compliant stuff gets switched off.

  9. mhdawson commented on Nov 16, 2015

    @mhdawson
    Member

    @stefanb I could be wrong but I didn't think you could turn it on/off, more that you have to set it one way or the other before any crypto is used.

  10. stefanmb commented on Feb 10, 2016

    @stefanmb
    Contributor

    I have made PR #5181 to resolve outstanding issues here.

  11. mhdawson commented on Feb 25, 2016

    @mhdawson
    Member

    Closing since change is now in master. Since the change is semver major it won't go into 4.X or 5.X.

  12. added a commit that references this issue on Jul 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    cryptoIssues and PRs related to the crypto subsystem.feature requestIssues requesting new Node.js features.tlsIssues and PRs related to the tls subsystem.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions