From 701ee3f49ebfa035660839b6f3f1e0e6fadfefe1 Mon Sep 17 00:00:00 2001 From: Alexander Scheel Date: Fri, 20 May 2022 17:18:51 -0400 Subject: [PATCH] Link FIPS binary sources from the FIPS docs (#15554) Signed-off-by: Alexander Scheel --- website/content/docs/enterprise/fips/fips1402.mdx | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/website/content/docs/enterprise/fips/fips1402.mdx b/website/content/docs/enterprise/fips/fips1402.mdx index 7d2af1e9fd..f60e499cc7 100644 --- a/website/content/docs/enterprise/fips/fips1402.mdx +++ b/website/content/docs/enterprise/fips/fips1402.mdx @@ -46,6 +46,16 @@ in a FIPS-compliant manner. We are not a NIST-certified testing laboratory and thus organizations may need to consult an approved auditor for final information. +The FIPS 140-2 variant of Vault uses separate binaries; these are available +from the following sources: + + - From the [Hashicorp Releases Page](https://releases.hashicorp.com/vault), + ending with the `+ent.fips1402` and `+ent.hsm.fips1402` suffixes. + - From the [Docker Hub `hashicorp/vault-enterprise-fips`](https://hub.docker.com/r/hashicorp/vault-enterprise-fips) + container repository. + - From the [AWS ECR `hashicorp/vault-enterprise-fips`](https://gallery.ecr.aws/hashicorp/vault-enterprise-fips) + container repository. + ~> **Note**: When pulling the FIPS UBI-based images, note that they are ultimately designed for OpenShift certification; consider either adding the `--user root --cap-add IPC_LOCK` options, to allow Vault to enable