FIPS-enabled container images don't guarantee cryptographic compliance across your entire application stack. Prebuilt native dependencies can silently bypass your FIPS crypto boundary by bundling their own OpenSSL or crypto code. A Rails application using the pg gem demonstrated this when ActiveRecord triggered non-FIPS crypto
Table of contents
FIPS in practiceThe FIPS crypto error that caught us off guardWhy we cannot just fix it in the base image yetWhat to do if you are starting a FIPS journeyWhy this matters beyond government contractsThe opportunity in the complexitySort: