Skip to content

feat(openssl): support package-selected FIPS providers - #18905

Merged
Christopher Co (christopherco) merged 2 commits into
microsoft:4.0from
tobiasb-ms:tobiasb-ms/openssl-configured-fips-provider
Oct 2, 2026
Merged

Christopher Co (christopherco) merged 2 commits into
microsoft:4.0from
tobiasb-ms:tobiasb-ms/openssl-configured-fips-provider

Conversation

@tobiasb-ms

Copy link
Copy Markdown
Contributor

Summary

Make OpenSSL FIPS-provider selection package-owned instead of hard-coding
SymCrypt in the OpenSSL configuration.

SymCrypt-OpenSSL remains the preferred Azure Linux provider, while the
provider-neutral contract allows another package to supply the FIPS provider
without changing OpenSSL itself.

Changes

  • make SymCrypt-OpenSSL provide openssl(fips-provider)
  • add a mutually exclusive provider registration owned by
    SymCrypt-OpenSSL
  • pin the SymCrypt provider module to its system path
  • make openssl-libs require the provider-neutral virtual capability
  • discover and activate exactly one package-owned registration in kernel
    FIPS mode
  • preserve application properties and library-context isolation
  • fail closed for missing, ambiguous, malformed, or inactive registrations
  • add source coverage for registration validation and real initialization

Testing

  • built the OpenSSL and SymCrypt-OpenSSL components
  • verified normal EVP fetches use the default provider
  • verified OPENSSL_FORCE_FIPS_MODE=1 EVP fetches use
    symcryptprovider
  • verified provider registration and activation tests pass

Copilot AI balanced review requested due to automatic review settings September 18, 2026 19:31
@tobiasb-ms

Copy link
Copy Markdown
Contributor Author

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
2 pipeline(s) were filtered out due to trigger conditions.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Unresolved FIPS paths can accept an unpinned provider or leave a usable partially configured context.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

Makes OpenSSL FIPS-provider selection package-owned while retaining SymCrypt as Azure Linux’s preferred implementation.

Changes:

  • Adds a provider-neutral RPM capability and registration contract.
  • Loads one registered provider during kernel FIPS initialization.
  • Adds validation, initialization, and isolation tests.
File summaries
File Description
specs/s/SymCrypt-OpenSSL/SymCrypt-OpenSSL.spec Renders SymCrypt registration packaging.
specs/s/SymCrypt-OpenSSL/symcrypt-fips-provider.cnf Defines the rendered registration.
specs/s/SymCrypt-OpenSSL/0001-Pin-SymCrypt-provider-module-path.patch Renders the pinned module path.
specs/o/openssl/openssl.spec Renders provider-neutral dependencies.
specs/o/openssl/0080-azl-load-registered-fips-provider.patch Renders registration loading and tests.
specs/o/openssl/0080-azl-force-symcrypt-in-kernel-fips-mode.patch Removes the rendered SymCrypt-specific implementation.
locks/SymCrypt-OpenSSL.lock Refreshes the SymCrypt input fingerprint.
locks/openssl.lock Refreshes the OpenSSL input fingerprint.
base/comps/SymCrypt-OpenSSL/SymCrypt-OpenSSL.spec Packages the capability and registration.
base/comps/SymCrypt-OpenSSL/symcrypt-fips-provider.cnf Declares SymCrypt provider metadata.
base/comps/SymCrypt-OpenSSL/0001-Pin-SymCrypt-provider-module-path.patch Pins the packaged provider module.
base/comps/openssl/overlays/0001-force-symcrypt-fips.overlay.toml Removes the provider-specific overlay.
base/comps/openssl/overlays/0001-configure-fips-provider.overlay.toml Adds provider-neutral packaging overlays.
base/comps/openssl/openssl.comp.toml Updates overlay documentation.
base/comps/openssl/0080-azl-load-registered-fips-provider.patch Implements registration discovery and activation.
base/comps/openssl/0080-azl-force-symcrypt-in-kernel-fips-mode.patch Removes the old hard-coded implementation.
Review details

Suppressed comments (1)

base/comps/SymCrypt-OpenSSL/SymCrypt-OpenSSL.spec:69

  • install defaults to mode 0755, so this creates the new registration file as executable. Install configuration data with mode 0644.
install %{SOURCE1} %{buildroot}%{_sysconfdir}/pki/tls/azl-openssl-fips-provider.d/symcrypt.cnf
  • Files reviewed: 14/16 changed files
  • Comments generated: 4
  • Review effort level: Balanced

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +273 to +275
+ if (provider_conf_load(libctx, provider, section, registration_conf) != 1)
+ goto end;
+ if (!CRYPTO_THREAD_read_lock(pcgbl->lock)) {

@tobiasb-ms Tobias Brick (tobiasb-ms) Sep 18, 2026 •

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[Perihelion🚀]

This is a valid provenance limitation, but it is inherited from Fedora's existing forced-FIPS implementation rather than introduced by this change.

Fedora's path also activates the provider by logical name through provider_conf_activate(). If a same-name provider was already initialized in the library context, it can be reused without proving that it came from the module specified by fips_local.cnf.

This change improves the same-configuration case by processing the package-owned registration before ambient provider sections. It deliberately does not attempt to harden the separate case where an application or previous configuration load initialized a same-name provider first. We evaluated a fail-closed implementation that rejects pre-existing providers, but it requires substantially more provider ownership and repeated-activation state. We therefore deferred it as a known inherited limitation: this implementation is no worse than Fedora's current behavior.

Leaving this thread unresolved for additional review.

Comment thread base/comps/openssl/0080-azl-load-registered-fips-provider.patch
Comment thread base/comps/openssl/0080-azl-load-registered-fips-provider.patch
Comment on lines +409 to +412
+# Keep alg_section before providers: default_properties replaces the property
+# query, while FIPS provider registration merges into it.
[openssl_init]
+alg_section = evp_properties

@tobiasb-ms Tobias Brick (tobiasb-ms) Sep 22, 2026 •

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[Perihelion🚀]

This ordering limitation is inherited from Fedora's existing forced-FIPS implementation. Fedora calls EVP_default_properties_enable_fips() from provider_conf_init(), which merges fips=yes into the current property query. A later alg_section containing default_properties replaces that query and can remove Fedora's FIPS constraint in the same way.

This change uses the same mechanism, but merges the selected provider's properties (?provider=... and ?fips=yes) instead. Reordering the shipped rh-openssl.cnf ensures the normal packaged configuration applies alg_section first and the provider registration last. It does not make subsequent application configuration order-independent, just as Fedora's implementation is not order-independent.

We are retaining that inherited behavior rather than introducing a broader change to OpenSSL's default-property configuration semantics in this PR. Leaving this thread unresolved for additional human review.

Copilot AI review requested due to automatic review settings September 22, 2026 13:41
@tobiasb-ms
Tobias Brick (tobiasb-ms) force-pushed the tobiasb-ms/openssl-configured-fips-provider branch from d19013f to e2506cf Compare September 22, 2026 13:41

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment thread base/comps/SymCrypt-OpenSSL/SymCrypt-OpenSSL.spec Outdated
Comment on lines +349 to +350
+ OSSL_LIB_CTX *libctx = NCONF_get0_libctx((CONF *)cnf);
+ int in_kernel_fips = ossl_get_kernel_fips_flag() != 0;

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[Perihelion🚀]

This bypass is inherited from Fedora's existing forced-FIPS implementation. Fedora performs its kernel-FIPS provider activation and fips=yes setup inside the same provider_conf_init() callback, which runs only when the selected configuration invokes the providers module. A custom configuration that omits providers therefore bypasses Fedora's enforcement path as well.

This PR replaces Fedora's hard-coded provider selection with package-owned registration while retaining that existing initialization mechanism. Moving enforcement to an unconditional library-context initialization path would be a broader behavioral and architectural change to the downstream OpenSSL integration, so it is outside the scope of this provider-selection change.

Leaving this thread unresolved for additional human review.

Comment thread base/comps/openssl/0080-azl-load-registered-fips-provider.patch
@tobiasb-ms
Tobias Brick (tobiasb-ms) force-pushed the tobiasb-ms/openssl-configured-fips-provider branch from e2506cf to 4590a7f Compare September 22, 2026 14:02
Copilot AI review requested due to automatic review settings September 22, 2026 14:02

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment thread base/comps/openssl/0080-azl-load-registered-fips-provider.patch Outdated
Copilot AI review requested due to automatic review settings September 22, 2026 14:17
@tobiasb-ms
Tobias Brick (tobiasb-ms) force-pushed the tobiasb-ms/openssl-configured-fips-provider branch from 4590a7f to cc7cf00 Compare September 22, 2026 14:17

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@tobiasb-ms
Tobias Brick (tobiasb-ms) force-pushed the tobiasb-ms/openssl-configured-fips-provider branch from cc7cf00 to 6256474 Compare September 22, 2026 16:38
Copilot AI review requested due to automatic review settings September 22, 2026 16:38

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The kernel-FIPS initialization change is security-critical, and acknowledged inherited provenance and configuration-order limitations still require final human review.

Review effort: Balanced
Findings: 3 High severity · 1 Medium severity

Open (4)
Resolved since last review (1)

@tobiasb-ms
Tobias Brick (tobiasb-ms) force-pushed the tobiasb-ms/openssl-configured-fips-provider branch from 6256474 to 82875ac Compare September 22, 2026 21:25
Copilot AI review requested due to automatic review settings September 22, 2026 21:25

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The security-sensitive OpenSSL initialization change retains known provenance and configuration-order limitations requiring final human judgment.

Review effort: Balanced
Findings: 2 High severity · 1 Medium severity

Open (3)
Resolved since last review (1)

@tobiasb-ms

Copy link
Copy Markdown
Contributor Author

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
2 pipeline(s) were filtered out due to trigger conditions.

@tobiasb-ms
Tobias Brick (tobiasb-ms) marked this pull request as ready for review September 22, 2026 21:45
@tobiasb-ms
Tobias Brick (tobiasb-ms) requested a review from a team as a code owner September 22, 2026 21:45
Copilot AI review requested due to automatic review settings September 28, 2026 21:11
Install a package-owned registration that selects SymCrypt in kernel FIPS
mode and adds optional provider and FIPS fetch preferences. Pin the provider
module path so registration cannot be redirected through the provider search
path.

Provide and conflict with openssl(fips-provider) so package transactions
install at most one conforming FIPS provider.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Replace hard-coded SymCrypt activation with a provider-neutral registration
mechanism. Require openssl(fips-provider), own the registration directory,
and let the installed provider package define its configuration and fetch
properties.

Disable fallback loading before registration discovery and fail
configuration for missing, ambiguous, malformed, or inactive providers.
Preserve existing default properties when applying provider selection.

Include source coverage for registration discovery and validation, repeated
activation, library-context isolation, property preservation, and
fail-closed configuration initialization.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@tobiasb-ms
Tobias Brick (tobiasb-ms) force-pushed the tobiasb-ms/openssl-configured-fips-provider branch from 8f61a07 to 8689034 Compare September 28, 2026 21:20
@tobiasb-ms

Copy link
Copy Markdown
Contributor Author

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
2 pipeline(s) were filtered out due to trigger conditions.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@christopherco
Christopher Co (christopherco) merged commit 437956e into microsoft:4.0 Oct 2, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants