HashiCorp Vault 1.10 Achieves FIPS 140-2 Compliance
HashiCorp Vault Enterprise 1.10 has been evaluated as conformant with the Federal Information Processing Standard (FIPS) 140-2 standards.
We are pleased to announce that the HashiCorp Vault Enterprise 1.10 FIPS-enabled build has been evaluated as conformant with the Federal Information Processing Standard (FIPS) 140-2 standards. A conformance review was conducted by Leidos to ensure that the HashiCorp Vault Enterprise FIPS enabled build is using validated cryptography. For more details, please see the Vault compliance letters.
The Federal Information Processing Standard (FIPS) is a cryptography-focused standard developed by the U.S. government to help computer security and interoperability. FIPS is intended for use cases in which suitable industry standards do not already exist, and is relied upon by many organizations to ensure approved cryptographic algorithms are used when processing sensitive information.
» Vault and FIPS: With and Without Hardware Security Modules
In 2017, HashiCorp Vault 0.9 went through a Leidos' evaluation focused on Vault’s Seal Wrap feature. Seal Wrap allows a Vault Enterprise system to encode cryptographic fundamentals and credentials with encryption derived from an external FIPS 140-2 certified cryptographic hardware security module (HSM). This is well-suited for customers who already have an HSM in their infrastructure, and who want the FIPS 140-2 Level 2+ protection only an HSM can provide.
Today, with HashiCorp Vault 1.10 using the FIPS enabled build, we now support a special build of Vault Enterprise (marked with a fips1402 feature name) that includes built-in support for FIPS 140-2 Level 1 compliance. Unlike using Seal Wrap for FIPS compliance, this binary has no external dependencies on an HSM, making it a good choice for organizations that do not already have an HSM in place, and that need FIPS 140-2 Level 1 cryptography.
» Next Steps
The FIPS compliance letters for both Seal Wrap and the new FIPS enabled build are available today on the HashiCorp Vault Compliance page. For more information about HashiCorp Vault Enterprise, visit https://www.hashicorp.com/products/vault/.
Sign up for the latest HashiCorp news
More blog posts like this one
Fix the developers vs. security conflict by shifting further left
Resolve the friction between dev and security teams with platform-led workflows that make cloud security seamless and scalable.
HashiCorp at AWS re:Invent: Your blueprint to cloud success
If you’re attending AWS re:Invent in Las Vegas, Dec. 2 - Dec. 6th, visit us for breakout sessions, expert talks, and product demos to learn how to take a unified approach to Infrastructure and Security Lifecycle Management.
HCP Vault Secrets adds enterprise capabilities for auto-rotation, dynamic secrets, and more
HCP Vault Secrets focuses on making a fast and easy path for secure development with key new features including auto-rotation (GA), dynamic secrets (beta), a new secret sync destination, and more.