HashiCorp Vault Enterprise 1.10 has been evaluated as conformant with the Federal Information Processing Standard (FIPS) 140-2 standards.
We are pleased to announce that the HashiCorp Vault Enterprise 1.10 FIPS-enabled build has been evaluated as conformant with the Federal Information Processing Standard (FIPS) 140-2 standards. A conformance review was conducted by Leidos to ensure that the HashiCorp Vault Enterprise FIPS enabled build is using validated cryptography. For more details, please see the Vault compliance letters.
The Federal Information Processing Standard (FIPS) is a cryptography-focused standard developed by the U.S. government to help computer security and interoperability. FIPS is intended for use cases in which suitable industry standards do not already exist, and is relied upon by many organizations to ensure approved cryptographic algorithms are used when processing sensitive information.
In 2017, HashiCorp Vault 0.9 went through a Leidos' evaluation focused on Vault’s Seal Wrap feature. Seal Wrap allows a Vault Enterprise system to encode cryptographic fundamentals and credentials with encryption derived from an external FIPS 140-2 certified cryptographic hardware security module (HSM). This is well-suited for customers who already have an HSM in their infrastructure, and who want the FIPS 140-2 Level 2+ protection only an HSM can provide.
Today, with HashiCorp Vault 1.10 using the FIPS enabled build, we now support a special build of Vault Enterprise (marked with a fips1402 feature name) that includes built-in support for FIPS 140-2 Level 1 compliance. Unlike using Seal Wrap for FIPS compliance, this binary has no external dependencies on an HSM, making it a good choice for organizations that do not already have an HSM in place, and that need FIPS 140-2 Level 1 cryptography.
The FIPS compliance letters for both Seal Wrap and the new FIPS enabled build are available today on the HashiCorp Vault Compliance page. For more information about HashiCorp Vault Enterprise, visit https://www.hashicorp.com/products/vault/.
HCP Vault Radar, HashiCorp’s new SaaS-based secret scanning and discovery product is now prepared for production workloads.
In this blog post, we’ll look at practical public key certificate management in HashiCorp Vault using dynamic secrets rotation.
Discover how HashiCorp Developer Advocate Rosemary Wang uses HashiCorp Boundary on live streams to automate access to servers and record commands to build into future automation.