5 ms·
If our need to update fips certified packages out paces the ability to certify packages, that is absolutely a problem with the design of FIPs certifications.
by rileymat2 1mo ago
If our need to update fips certified packages out paces the ability to certify packages, that is absolutely a problem with the design of FIPs certifications.
- beardedwizard 1mo ago+1, been all the way to fed ramp high and this is a huge part of the security theater that is fedramp. The second best part is either getting really good at patching every single thing, or playing the POA&M game.
- pseudohadamard 1mo agoSo your choice inevitably boils down to running some ancient vulnerability-riddled version that's FIPS certified or running a recent less vulnerability-riddled version that's not certified. Most orgs that I've worked with keep running the vulnerable version because they have to be able to check the box that says "FIPS certified".