FIPS 140-3 compliance in AI Gateway

Related Documentation
Minimum Version
AI Gateway - 2.2
Incompatible with
on-prem
Tags
Related Resources

The Federal Information Processing Standard (FIPS) 140-3 is a federal standard defined by the National Institute of Standards and Technology. It specifies the security requirements that must be satisfied by a cryptographic module.

The FIPS AI Gateway package is FIPS 140-3 compliant. Compliance means that AI Gateway only uses FIPS 140-3 approved algorithms while running in FIPS mode, but the product has not been submitted to a NIST testing lab for validation.

AI Gateway provides the FIPS 140-3 compliant package for supported distributions, including distroless packages. This package provides compliance for the core AI Gateway product and all out-of-the-box policies.

The package uses the OpenSSL FIPS Provider 3.1.2 to provide FIPS 140-3 validated cryptographic operations.

Configure FIPS

To start a data plane in FIPS mode, set the following configuration property to on in the kong.conf configuration file before starting AI Gateway:

fips = on # fips mode is enabled, causing incompatible ciphers to be disabled

You can also set this configuration using an environment variable:

export KONG_FIPS=on

Warning: Migrating from non-FIPS to FIPS mode, or the reverse, is not supported.

Password hashing

The following table describes how AI Gateway uses key derivation functions:

Component

Normal mode

FIPS mode

Notes

core/rbac bcrypt PBKDF2 1 Compliant via OpenSSL 3.1.2 FIPS provider
plugins/oauth2 2 Argon2 or bcrypt (when hash_secret=true) Disabled (hash_secret can’t be set to true) Compliant via OpenSSL 3.1.2 FIPS provider
plugins/key-auth-enc 3 SHA1 SHA256 SHA1 is read-only in FIPS mode.

Non-cryptographic usage of cryptographic algorithms

FIPS only defines the approved algorithms to use for each specific purpose, so FIPS policy doesn’t explicitly restrict the usage of cryptographic algorithms to only cases where they are necessary.

For example, using SHA-256 as the message digest algorithm is approved, while MD5 is not. However, that doesn’t mean MD5 must be completely absent from the application.

The following table explains where cryptographic algorithms are used for non-cryptographic purposes in AI Gateway:

Component

Normal mode

FIPS mode

Notes

core/balancer xxhash32 xxhash32 Used to generate a unique identifier.
core/balancer crc32 crc32 crc32 isn’t a message digest.
core/uuid Lua random number generator Lua random number generator The RNG isn’t used for cryptographic purposes.
core/declarative_config/uuid UUIDv5 (namespaced SHA1) UUIDv5 (namespaced SHA1) Used to generate a unique identifier.
core/declarative_config/config_hash and core/hybrid/hashes MD5 MD5 Used to generate a unique identifier.
core/kong_request_id rand(3) rand(3) The RNG isn’t used for cryptographic purposes.

SSL client

FIPS 140-3 defines requirements for the cryptographic module, not for SSL client roles. AI Gateway does not enforce a FIPS-specific policy on outbound clients.

Traffic that traverses AI Gateway’s own inbound and outbound TLS enforcement does honor the TLS 1.2/1.3 and applies the following constraints:

Rejected item

Details

TLS 1.0 and 1.1 Rejected at any surface Kong terminates.
TLS 1.2 without EMS The handshake fails.
Non-AES-GCM cipher suites The cipher list is fixed to approved AES-GCM profiles. Low-level SSL overrides no longer widen it.
MD5 and ChaCha20 Rejected under default OpenSSL properties.
SAML request SHA-1 signatures Rejected.
HMAC-SHA1 authentication configuration Rejected.
Ed25519 / Ed448 JWKS generation Use RSA-PSS or a NIST-curve ECDSA key (for example P-256, P-384) instead.
Application-supplied IVs for AES-GCM The FIPS provider generates the IV inside the cryptographic boundary.
Keyring RSA keys below 2048 bits Rejected at configuration validation, before startup completes.
hash_secret = true on the OAuth2 plugin The setting is disabled in FIPS mode. Use secrets management or database encryption instead.

Help us make these docs great!

Kong Developer docs are open source. If you find these useful and want to make them better, contribute today!