Repository navigation
feat(openssl): support package-selected FIPS providers - #18905
Christopher Co (christopherco) merged 2 commits into
Conversation
|
/azp run |
|
Azure Pipelines: 2 pipeline(s) were filtered out due to trigger conditions. |
There was a problem hiding this comment.
🟡 Changes recommended
Unresolved FIPS paths can accept an unpinned provider or leave a usable partially configured context.
Get a fresh assessment by requesting another Copilot review.
Pull request overview
Makes OpenSSL FIPS-provider selection package-owned while retaining SymCrypt as Azure Linux’s preferred implementation.
Changes:
- Adds a provider-neutral RPM capability and registration contract.
- Loads one registered provider during kernel FIPS initialization.
- Adds validation, initialization, and isolation tests.
File summaries
| File | Description |
|---|---|
| specs/s/SymCrypt-OpenSSL/SymCrypt-OpenSSL.spec | Renders SymCrypt registration packaging. |
| specs/s/SymCrypt-OpenSSL/symcrypt-fips-provider.cnf | Defines the rendered registration. |
| specs/s/SymCrypt-OpenSSL/0001-Pin-SymCrypt-provider-module-path.patch | Renders the pinned module path. |
| specs/o/openssl/openssl.spec | Renders provider-neutral dependencies. |
| specs/o/openssl/0080-azl-load-registered-fips-provider.patch | Renders registration loading and tests. |
| specs/o/openssl/0080-azl-force-symcrypt-in-kernel-fips-mode.patch | Removes the rendered SymCrypt-specific implementation. |
| locks/SymCrypt-OpenSSL.lock | Refreshes the SymCrypt input fingerprint. |
| locks/openssl.lock | Refreshes the OpenSSL input fingerprint. |
| base/comps/SymCrypt-OpenSSL/SymCrypt-OpenSSL.spec | Packages the capability and registration. |
| base/comps/SymCrypt-OpenSSL/symcrypt-fips-provider.cnf | Declares SymCrypt provider metadata. |
| base/comps/SymCrypt-OpenSSL/0001-Pin-SymCrypt-provider-module-path.patch | Pins the packaged provider module. |
| base/comps/openssl/overlays/0001-force-symcrypt-fips.overlay.toml | Removes the provider-specific overlay. |
| base/comps/openssl/overlays/0001-configure-fips-provider.overlay.toml | Adds provider-neutral packaging overlays. |
| base/comps/openssl/openssl.comp.toml | Updates overlay documentation. |
| base/comps/openssl/0080-azl-load-registered-fips-provider.patch | Implements registration discovery and activation. |
| base/comps/openssl/0080-azl-force-symcrypt-in-kernel-fips-mode.patch | Removes the old hard-coded implementation. |
Review details
Suppressed comments (1)
base/comps/SymCrypt-OpenSSL/SymCrypt-OpenSSL.spec:69
installdefaults to mode 0755, so this creates the new registration file as executable. Install configuration data with mode 0644.
install %{SOURCE1} %{buildroot}%{_sysconfdir}/pki/tls/azl-openssl-fips-provider.d/symcrypt.cnf
- Files reviewed: 14/16 changed files
- Comments generated: 4
- Review effort level: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| + if (provider_conf_load(libctx, provider, section, registration_conf) != 1) | ||
| + goto end; | ||
| + if (!CRYPTO_THREAD_read_lock(pcgbl->lock)) { |
There was a problem hiding this comment.
[Perihelion🚀]
This is a valid provenance limitation, but it is inherited from Fedora's existing forced-FIPS implementation rather than introduced by this change.
Fedora's path also activates the provider by logical name through provider_conf_activate(). If a same-name provider was already initialized in the library context, it can be reused without proving that it came from the module specified by fips_local.cnf.
This change improves the same-configuration case by processing the package-owned registration before ambient provider sections. It deliberately does not attempt to harden the separate case where an application or previous configuration load initialized a same-name provider first. We evaluated a fail-closed implementation that rejects pre-existing providers, but it requires substantially more provider ownership and repeated-activation state. We therefore deferred it as a known inherited limitation: this implementation is no worse than Fedora's current behavior.
Leaving this thread unresolved for additional review.
| +# Keep alg_section before providers: default_properties replaces the property | ||
| +# query, while FIPS provider registration merges into it. | ||
| [openssl_init] | ||
| +alg_section = evp_properties |
There was a problem hiding this comment.
[Perihelion🚀]
This ordering limitation is inherited from Fedora's existing forced-FIPS implementation. Fedora calls EVP_default_properties_enable_fips() from provider_conf_init(), which merges fips=yes into the current property query. A later alg_section containing default_properties replaces that query and can remove Fedora's FIPS constraint in the same way.
This change uses the same mechanism, but merges the selected provider's properties (?provider=... and ?fips=yes) instead. Reordering the shipped rh-openssl.cnf ensures the normal packaged configuration applies alg_section first and the provider registration last. It does not make subsequent application configuration order-independent, just as Fedora's implementation is not order-independent.
We are retaining that inherited behavior rather than introducing a broader change to OpenSSL's default-property configuration semantics in this PR. Leaving this thread unresolved for additional human review.
d19013f to
e2506cf
Compare
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
FIPS enforcement remains bypassable through configurations that omit or reorder provider initialization, and provider packages are not mutually exclusive.
Get a fresh assessment by requesting another Copilot review.
Review effort: Balanced
Findings: 4
Open (6)
Conflict on shared virtual capability to prevent duplicate FIPS providers · New Enforce kernel FIPS for configs without a providers directive · New Ensure module failures cannot be ignored by CONF_MFLAGS_IGNORE_ERRORS · New This activation path does not prove that the provider came from the module path in the… The FIPS property merge is only protected by reordering the shipped[openssl_init]entries.… No automated test exercises the successfulprovider_conf_init()path that discovers a…
Resolved since last review (1)
| + OSSL_LIB_CTX *libctx = NCONF_get0_libctx((CONF *)cnf); | ||
| + int in_kernel_fips = ossl_get_kernel_fips_flag() != 0; |
There was a problem hiding this comment.
[Perihelion🚀]
This bypass is inherited from Fedora's existing forced-FIPS implementation. Fedora performs its kernel-FIPS provider activation and fips=yes setup inside the same provider_conf_init() callback, which runs only when the selected configuration invokes the providers module. A custom configuration that omits providers therefore bypasses Fedora's enforcement path as well.
This PR replaces Fedora's hard-coded provider selection with package-owned registration while retaining that existing initialization mechanism. Moving enforcement to an unconditional library-context initialization path would be a broader behavioral and architectural change to the downstream OpenSSL integration, so it is outside the scope of this provider-selection change.
Leaving this thread unresolved for additional human review.
e2506cf to
4590a7f
Compare
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Provider alternatives are not mutually excluded, and malformed identity registrations can leave an unintended provider active.
Get a fresh assessment by requesting another Copilot review.
Review effort: Balanced
Findings: 5
Open (6)
Reject mismatched provider identity before activation · New Ensure module failures cannot be ignored by CONF_MFLAGS_IGNORE_ERRORS Enforce kernel FIPS for configs without a providers directive Conflict on shared virtual capability to prevent duplicate FIPS providers This activation path does not prove that the provider came from the module path in the… The FIPS property merge is only protected by reordering the shipped[openssl_init]entries.…
Resolved since last review (1)
4590a7f to
cc7cf00
Compare
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
An identity-mismatched registration can leave an active provider usable without the required FIPS properties.
Review effort: Balanced
Findings: 4
Open (5)
Reject mismatched provider identity before activation Enforce kernel FIPS for configs without a providers directive Conflict on shared virtual capability to prevent duplicate FIPS providers This activation path does not prove that the provider came from the module path in the… The FIPS property merge is only protected by reordering the shipped[openssl_init]entries.…
Resolved since last review (1)
cc7cf00 to
6256474
Compare
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The kernel-FIPS initialization change is security-critical, and acknowledged inherited provenance and configuration-order limitations still require final human review.
Review effort: Balanced
Findings: 3
Open (4)
Enforce kernel FIPS for configs without a providers directive Conflict on shared virtual capability to prevent duplicate FIPS providers This activation path does not prove that the provider came from the module path in the… The FIPS property merge is only protected by reordering the shipped[openssl_init]entries.…
Resolved since last review (1)
6256474 to
82875ac
Compare
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The security-sensitive OpenSSL initialization change retains known provenance and configuration-order limitations requiring final human judgment.
Review effort: Balanced
Findings: 2
Open (3)
Resolved since last review (1)
|
/azp run |
|
Azure Pipelines: 2 pipeline(s) were filtered out due to trigger conditions. |
82875ac to
66c5467
Compare
66c5467 to
8f61a07
Compare
Install a package-owned registration that selects SymCrypt in kernel FIPS mode and adds optional provider and FIPS fetch preferences. Pin the provider module path so registration cannot be redirected through the provider search path. Provide and conflict with openssl(fips-provider) so package transactions install at most one conforming FIPS provider. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Replace hard-coded SymCrypt activation with a provider-neutral registration mechanism. Require openssl(fips-provider), own the registration directory, and let the installed provider package define its configuration and fetch properties. Disable fallback loading before registration discovery and fail configuration for missing, ambiguous, malformed, or inactive providers. Preserve existing default properties when applying provider selection. Include source coverage for registration discovery and validation, repeated activation, library-context isolation, property preservation, and fail-closed configuration initialization. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
8f61a07 to
8689034
Compare
|
/azp run |
|
Azure Pipelines: 2 pipeline(s) were filtered out due to trigger conditions. |
Christopher Co (christopherco)
left a comment
There was a problem hiding this comment.
LGTM
437956e
into
microsoft:4.0


Summary
Make OpenSSL FIPS-provider selection package-owned instead of hard-coding
SymCrypt in the OpenSSL configuration.
SymCrypt-OpenSSL remains the preferred Azure Linux provider, while the
provider-neutral contract allows another package to supply the FIPS provider
without changing OpenSSL itself.
Changes
SymCrypt-OpenSSLprovideopenssl(fips-provider)SymCrypt-OpenSSLopenssl-libsrequire the provider-neutral virtual capabilityFIPS mode
Testing
OPENSSL_FORCE_FIPS_MODE=1EVP fetches usesymcryptprovider