# FIPS Compliance

**URL:** <https://openziti.discourse.group/t/fips-compliance/872>\
**Category:** Zitifications\
**Created:** [November 17, 2022, 5:46pm UTC](https://openziti.discourse.group/t/fips-compliance/872 "2022-11-17T17:46:39Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![ccravens](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/ccravens/32/632_2.png) [@ccravens](https://openziti.discourse.group/u/ccravens)\
**Post date:** [November 17, 2022, 7:12pm UTC](https://openziti.discourse.group/t/fips-compliance/872/3 "2022-11-17T19:12:46Z")

</div>

Hello Mike:

We discussed on our side this morning and we’re going to take some stabs at this as we’ve been working FIPS implementation for a few years now on various open source stacks. Our current FIPS environment looks like this:

- FIPS-enabled Operating System (RHEL 8 / CentOS Stream 8)
- Running a FIPS-compliant RKE2 Kubernetes Distro ([FIPS 140-2 Enablement - RKE2 - Rancher's Next Generation Kubernetes Distribution](https://docs.rke2.io/security/fips_support/))
- Running a hardened & FIPS-Enabled docker container
- Running a FIPS-Enabled Go Build of our ziti fork ([GitHub - Analytics-HQ/ziti: The parent project for OpenZiti. Here you will find the executables for a fully zero trust, application embedded, programmable network](https://github.com/Analytics-HQ/ziti))

Things we’re looking at is a FIPS-compliant Go version using Google’s BoringSSL

We’ll relay an issues we come across with this and would like to contribute updates back to OpenZiti if possible. Thanks!

---

_[View the full topic](https://openziti.discourse.group/t/fips-compliance/872)._
