teleport
teleport copied to clipboard
User confusion around FIPS mode
What would you like Teleport to do?
Force FIPS mode whenever the FIPS binary is being used or add the --fips
flag to the systemD unit file provided by the Teleport packages (RPM, APT).
What problem does this solve?
Presently, users must add the --fips
flag when starting Teleport. This is not well documented and users do not realize they need to utilize the flag.
This is a problem for customers who are deploying on VMs without the Teleport maintained Terraform.
It's unclear why this flag is needed in addition to separate binaries.
Could we drop the --fips
flag requirement when running the fips binaries?
This means that for deployments with a mixture of FIPS-compliant environments and non-FIPS-compliant environments (e.g. running on AWS in both US and non-US regions), there need to be different binaries. This creates extra maintenance hassle; is there perhaps a better way?