Skip to content

Conversation

@kruskall
Copy link
Member

@kruskall kruskall commented Feb 4, 2025

Proposed commit message

In version 1 of the ID, the hash algorithm is SHA1

usage of flowhash fails with the following message when the stdlib is in fips only mode:

crypto/sha1: use of SHA-1 is not allowed in FIPS 140-only mode

PR hides the communityid usage behind a method which returns an empty string in fips mode, to avoid any potential misuse and better encapsulation.

Checklist

  • My code follows the style guidelines of this project
  • I have commented my code, particularly in hard-to-understand areas
  • I have made corresponding changes to the documentation
  • I have made corresponding change to the default configuration files
  • I have added tests that prove my fix is effective or that my feature works
  • I have added an entry in CHANGELOG.next.asciidoc or CHANGELOG-developer.next.asciidoc.

Disruptive User Impact

Author's Checklist

  • [ ]

How to test this PR locally

Related issues

Use cases

Screenshots

Logs

In version 1 of the ID, the hash algorithm is SHA1

usage of flowhash fails with the following message when the stdlib
is in fips only mode:

crypto/sha1: use of SHA-1 is not allowed in FIPS 140-only mode
@kruskall kruskall requested review from a team as code owners February 4, 2025 01:11
@kruskall kruskall requested review from faec and khushijain21 February 4, 2025 01:12
@botelastic botelastic bot added the needs_team Indicates that the issue/PR needs a Team:* label label Feb 4, 2025
@mergify
Copy link
Contributor

mergify bot commented Feb 4, 2025

This pull request does not have a backport label.
If this is a bug or security fix, could you label this PR @kruskall? 🙏.
For such, you'll need to label your PR with:

  • The upcoming major version of the Elastic Stack
  • The upcoming minor version of the Elastic Stack (if you're not pushing a breaking change)

To fixup this pull request, you need to add the backport labels for the needed
branches, such as:

  • backport-8./d is the label to automatically backport to the 8./d branch. /d is the digit

@jlind23 jlind23 added the Team:Elastic-Agent-Data-Plane Label for the Agent Data Plane team label Feb 4, 2025
@botelastic botelastic bot removed the needs_team Indicates that the issue/PR needs a Team:* label label Feb 4, 2025
@elasticmachine
Copy link
Contributor

Pinging @elastic/elastic-agent-data-plane (Team:Elastic-Agent-Data-Plane)

@jlind23 jlind23 added needs_team Indicates that the issue/PR needs a Team:* label backport-8.x Automated backport to the 8.x branch with mergify backport-8.18 Automated backport to the 8.18 branch backport-9.0 Automated backport to the 9.0 branch labels Feb 4, 2025
@botelastic botelastic bot removed the needs_team Indicates that the issue/PR needs a Team:* label label Feb 4, 2025
@botelastic
Copy link

botelastic bot commented Feb 4, 2025

This pull request doesn't have a Team:<team> label.

@kruskall kruskall requested a review from simitt February 26, 2025 11:56
@pierrehilbert
Copy link
Contributor

@nfritts could we have someone to review here?

@kruskall kruskall removed the backport-8.18 Automated backport to the 8.18 branch label Mar 10, 2025
@pierrehilbert
Copy link
Contributor

@kruskall We are now good to go

@kruskall kruskall merged commit 3b00fcb into elastic:main Mar 18, 2025
143 checks passed
@kruskall kruskall deleted the fips/communityid branch March 18, 2025 21:40
mergify bot pushed a commit that referenced this pull request Mar 18, 2025
* feat(fips): disable usage of flowhash/communityid in fips mode

In version 1 of the ID, the hash algorithm is SHA1

usage of flowhash fails with the following message when the stdlib
is in fips only mode:

crypto/sha1: use of SHA-1 is not allowed in FIPS 140-only mode

* test: skip communityid tests in fips mode

* test: skip communityid tests in fips mode

* fix: resolve compile errors

* lint: fix linter issues

* refactor: add fips noop community implementation

* lint: fix linter issues

(cherry picked from commit 3b00fcb)
mergify bot pushed a commit that referenced this pull request Mar 18, 2025
* feat(fips): disable usage of flowhash/communityid in fips mode

In version 1 of the ID, the hash algorithm is SHA1

usage of flowhash fails with the following message when the stdlib
is in fips only mode:

crypto/sha1: use of SHA-1 is not allowed in FIPS 140-only mode

* test: skip communityid tests in fips mode

* test: skip communityid tests in fips mode

* fix: resolve compile errors

* lint: fix linter issues

* refactor: add fips noop community implementation

* lint: fix linter issues

(cherry picked from commit 3b00fcb)
kruskall added a commit that referenced this pull request Mar 18, 2025
… (#43354)

* feat(fips): disable usage of flowhash/communityid in fips mode

In version 1 of the ID, the hash algorithm is SHA1

usage of flowhash fails with the following message when the stdlib
is in fips only mode:

crypto/sha1: use of SHA-1 is not allowed in FIPS 140-only mode

* test: skip communityid tests in fips mode

* test: skip communityid tests in fips mode

* fix: resolve compile errors

* lint: fix linter issues

* refactor: add fips noop community implementation

* lint: fix linter issues

(cherry picked from commit 3b00fcb)

Co-authored-by: kruskall <[email protected]>
kruskall added a commit that referenced this pull request Mar 18, 2025
… (#43353)

* feat(fips): disable usage of flowhash/communityid in fips mode

In version 1 of the ID, the hash algorithm is SHA1

usage of flowhash fails with the following message when the stdlib
is in fips only mode:

crypto/sha1: use of SHA-1 is not allowed in FIPS 140-only mode

* test: skip communityid tests in fips mode

* test: skip communityid tests in fips mode

* fix: resolve compile errors

* lint: fix linter issues

* refactor: add fips noop community implementation

* lint: fix linter issues

(cherry picked from commit 3b00fcb)

Co-authored-by: kruskall <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport-8.x Automated backport to the 8.x branch with mergify backport-9.0 Automated backport to the 9.0 branch Team:Elastic-Agent-Data-Plane Label for the Agent Data Plane team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

10 participants