Skip to content
@ciq-rocky-fips

Ctrl IQ, Inc.

CIQ FIPS for Rocky Linux

Welcome to the official GitHub repository for CIQ's FIPS (Federal Information Processing Standards) offering for Rocky Linux. Our mission is to meet the stringent security requirements of federal customers and beyond, ensuring the highest level of data protection and compliance.

CIQ's FIPS Offering

CIQ has developed a robust FIPS solution on the x86_64 architecture for Rocky Linux, focusing on hardening critical security modules including:

  • Libgcrypt
  • OpenSSL
  • NSS (Network Security Services)
  • GnuTLS
  • Kernel

These modules have been built from the ground up to meet the latest FIPS 140-3 standard and are released as updates to subscribed customers via Mountain.

Independent Validation

Our FIPS modules undergo independent validation by the National Institute of Standards and Technology's Cryptographic Module Validation Program (NIST's CMVP), ensuring they adhere to the most rigorous security standards.

Supported Versions and Lifecycle

Following the release timelines of Rocky Linux, CIQ offers extended support and updates for FIPS modules, aligning with our Long Term Support (LTS) offering. This ensures that even after a Rocky Linux version is declared EOL, your systems remain secure and compliant.

FIPS / LTS Product Access

Access to repositories for FIPS and LTS updates is provided via Mountain, offering:

  • LTS Updates: Containing Rocky 8.x & Rocky 9.x updates following our Security Vulnerability Policy.
  • FIPS Validated: Modules validated by CMVP.
  • FIPS Compliant: Security updates to FIPS modules post-validation.

Security Vulnerability Policy

CIQ commits to the highest standards of security:

  • Backports for Critical or Important Issues: Focusing on packages with a CVSS score of 8.0 or higher.
  • Discretionary Backports: For packages with lower CVSS scores, based on CIQ's discretion.
  • Re-validation: Updates impacting the FIPS modules' entropy functionality or algorithm integrity may be evaluated for CMVP re-validation.

FIPS Modules & Versions

CIQ maintains a comprehensive list of FIPS modules and versions for both Rocky Linux 8 and Rocky Linux 9, ensuring your systems are equipped with the most secure and up-to-date components.

Popular repositories Loading

  1. openssl openssl Public

    1

  2. libgcrypt libgcrypt Public

  3. nss nss Public

  4. gnutls gnutls Public

  5. kernel kernel Public

  6. .github .github Public

    1

Repositories

Showing 7 of 7 repositories
  • nss Public
    ciq-rocky-fips/nss’s past year of commit activity
    0 0 0 1 Updated Sep 17, 2024
  • kernel Public
    ciq-rocky-fips/kernel’s past year of commit activity
    0 0 0 2 Updated Sep 17, 2024
  • gnutls Public
    ciq-rocky-fips/gnutls’s past year of commit activity
    0 0 0 0 Updated Sep 17, 2024
  • ciq-rocky-fips/libgcrypt’s past year of commit activity
    0 0 0 0 Updated Sep 17, 2024
  • openssl Public
    ciq-rocky-fips/openssl’s past year of commit activity
    0 1 0 1 Updated Sep 17, 2024
  • .github Public
    ciq-rocky-fips/.github’s past year of commit activity
    0 1 0 0 Updated Apr 30, 2024
  • dracut Public
    ciq-rocky-fips/dracut’s past year of commit activity
    0 0 0 0 Updated Mar 28, 2024

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Top languages

Loading…

Most used topics

Loading…