What “FIPS support” meansWhen CockroachDB documentation refers to “FIPS support” or “FIPS-ready” deployments, this means CockroachDB can be configured to use FIPS 140-3-approved cryptographic algorithms and operate in accordance with a FIPS 140-3 cryptographic module’s Security Policy. It does not mean that CockroachDB itself is FIPS 140-3 validated.CockroachDB uses the frozen Go Cryptographic Module v1.0.0, which is FIPS 140-3 validated under CMVP Certificate #5247.
Overview of FIPS-ready CockroachDB
Federal Information Processing Standards (FIPS) 140-3 is a U.S. government standard that specifies security requirements for cryptographic modules. FIPS 140-3 provides measurable security guidelines for protecting sensitive but unclassified information. The standard is applicable to all federal agencies that use cryptographic-based security systems to protect sensitive information in computer and telecommunication systems. U.S. and Canadian governments, as well as organizations working with them, may be subject to FIPS 140-3 requirements. The Cryptographic Module Validation Program (CMVP) validates cryptographic modules to FIPS 140-3 and other cryptography-based standards. When a cryptographic module or library has a FIPS 140-3 certificate, it has been tested and formally validated under the CMVP as meeting the requirements for FIPS 140-3. FIPS-ready CockroachDB binaries and Docker images are available for CockroachDB v23.1.0 and later. FIPS-ready CockroachDB runtimes run on Intel 64-bit Linux systems. Starting with v26.1, FIPS-ready CockroachDB binaries are built using Go’s native FIPS 140-3 support. The cryptographic operations are performed by Go’s built-in cryptographic modules, which are independent of the host operating system’s libraries. This represents a significant architectural change from previous versions (v25.4 and earlier), which used Red Hat’s golang-fips toolchain with OpenSSL.Migration from FIPS 140-2 to FIPS 140-3Previous versions of CockroachDB (v25.4 and earlier) supported FIPS 140-2. Starting with v26.1, CockroachDB uses a cryptographic module designed for FIPS 140-3 support. Starting with v26.2, CockroachDB uses
GOFIPS140=v1.0.0, the frozen module version that is FIPS 140-3 validated under CMVP Certificate #5247.FIPS 140-2 will transition to historical status on September 22, 2026, per NIST’s FIPS 140-3 Transition Effort.FIPS-ready features
When you use a FIPS-ready CockroachDB runtime, Cockroach Labs has verified that cryptographic operations in the following contexts meet the requirements of FIPS 140-3:When running a FIPS-ready runtime, Cockroach Labs recommends that you avoid using cryptographic operations that are not supported by FIPS 140-3. For example, generating an MD5 hash is not compatible with FIPS 140-3, because MD5 is not a FIPS-validated algorithm. Use algorithms and functions that do not comply with the standard at your own risk.
Performance considerations
When comparing performance of the same workload in a FIPS-ready CockroachDB runtime to a standard CockroachDB runtime, some performance difference may be observed. The amount of performance impact depends upon the workload, cluster configuration, query load, and other factors.Upgrading to a FIPS-ready CockroachDB runtime
Upgrading an existing CockroachDB cluster’s binaries in-place to be FIPS-ready is not supported.Operating system requirements
FIPS-ready CockroachDB uses Go’s native cryptographic module, which is independent of the host operating system’s libraries. The FIPS-ready binary can run on any Intel 64-bit Linux system. The FIPS-ready CockroachDB Docker images are based on Red Hat’s Universal Base Image 10. To use the FIPS-ready CockroachDB Docker image, skip directly to that section of this page.Extend Red Hat’s Universal Base Image 10 Docker image
If you do not want to use the FIPS-ready CockroachDB Docker image directly, you can create a custom Docker image based on Red Hat’s Universal Base Image 10:- The FIPS-ready binary includes the FIPS 140-3 Go Cryptographic Module and does not require additional system libraries to be installed.
Download FIPS-ready runtimes
To download FIPS-ready CockroachDB runtimes, use the following links.Production releases
Install the FIPS-ready CockroachDB runtime
After you download a FIPS-ready CockroachDB binary, install it in the same way as the standard binary. Refer to .Upgrade from v25.4 or v26.1 FIPS to v26.2 or laterCockroachDB v26.1 and later use Go’s native FIPS cryptographic module, a significant architectural change from the OpenSSL-based approach used in v25.4 and earlier. FIPS support was Preview in v26.1, so deployments using FIPS on v25.4 or v26.1 should upgrade to v26.2 or a later version.Upgrading an existing CockroachDB cluster’s binary in-place from non-FIPS to FIPS is not supported. Instead, you can to a new FIPS-ready cluster.
Verify that CockroachDB is FIPS-ready
To verify that the CockroachDB binary is FIPS-ready, use thecockroach version command and check for the FIPS enabled field:
Change from previous versions: In v25.4 and earlier, FIPS-ready binaries showed
fips appended to the Go version (e.g., go1.19.5fips). Starting with v26.1, FIPS status is indicated by the FIPS enabled: true field.Use the FIPS-ready CockroachDB Docker image
The FIPS-ready CockroachDB Docker image is based on Red Hat Universal Base Image 10 and includes the FIPS-ready CockroachDB binary.-
Go to Download FIPS-ready Runtimes and copy the name of a FIPS-ready Docker image tag. The image tag format is
cockroachdb/cockroach:v26.2.0-fips(replace with the specific version). -
Pull the Docker image locally, create a new container that uses it, run the container, and attach to it. The following example gives the running container the name
cockroachdb-fips-container. Replace with the name of the Docker image tag you copied. - In the running container, verify that CockroachDB is FIPS-ready.
-
To stop the container, use
CTRL-C. To detach from the container but keep it running in the background, use the sequenceCTRL+P+CTRL+Q.
Details about cryptographic algorithms
This section provides more information about the cryptographic algorithms and key lengths used by FIPS-ready CockroachDB.Authentication
Inter-node and node identity
Algorithm: TLS 1.3 (RFC 8446). Refer to .Client identity
Password authentication
Algorithm:bcrypt or scram-sha-256.
Refer to .
Client certificates
Algorithm: TLS 1.3 (RFC 8446). Refer to .GSSAPI / Kerberos
Not supported for FIPS-ready deployments.SASL / SCRAM password authentication
Algorithm:scram-sha-256.
Refer to .
JSON Web Tokens (JWTs)
Algorithms: Specified by the . Refer to .DB Console authentication via OIDC
Algorithm: Specified by the identity provider (IdP) as part of the OIDC handshake process. Refer to .HTTP API access via login tokens
Algorithm:sha256 (RFC 6234).
Encryption
In flight
Algorithm: TLS 1.3 (RFC 8446). Key sizes: Depends upon the cipher suite in use:-
TLS 1.2:
-
tls.TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 -
tls.TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 -
tls.TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 -
tls.TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 -
If the
COCKROACH_TLS_ENABLE_OLD_CIPHER_SUITESenvironment variable is set:tls.TLS_RSA_WITH_AES_128_GCM_SHA256tls.TLS_RSA_WITH_AES_256_GCM_SHA384
-
-
TLS 1.3:
TLS_AES_128_GCM_SHA256TLS_AES_256_GCM_SHA384

