ROSA GovCloud and FIPS-validated Cryptography
ROSA GovCloud Update: OCP Versions > 4.18 Available + FIPS Status
Overview
As of the time of this article’s publishing, ROSA in AWS GovCloud only supports OpenShift Container Platform version 4.18.x. This version is derived from a RHEL 9.4 base image, for which all cryptographic modules have been granted Approved or Implementation Under Test validation status by the Cryptographic Module Validation Program (CMVP) in accordance with FedRAMP High security controls.
On October 31, 2026, ROSA in AWS GovCloud will additionally support OCP versions 4.19, 4.20, 4.21, and 4.22. These OCP versions leverage cryptographic modules that are currently in the process of obtaining FIPS 140-3 validation from CMVP. All ROSA GovCloud clusters are deployed in FIPS mode.
Customer Experience
Starting October 31, 2026, ROSA GovCloud customers will be able to begin using OCP Versions 4.19 and beyond in FIPS mode with no disruption.
Customer Choice: This requires that customers accept the small risk of using these OCP versions with cryptographic modules that are currently not formally approved by CMVP.
Long Term Resolution: Once CMVPNIST approval is received, the corresponding clusters will automatically inherit the compliance status.
Benefits of upgrading to OCP version 4.19 and higher:
- Access to newer product features and functionality
- Unblocked upgrade paths from version 4.18 in preparation for OCP 5
- Accelerated delivery of patches and CVE vulnerability fixes
- Compatibility with the latest versions of layered products, such as ACS and ACM
- Continued deployment of all clusters in FIPS mode utilizing FIPS-compliant ciphers
Considerations / Limitations:
- The underlying RHEL base image relies on cryptographic modules currently pending NIST validation
References
FIPS: https://access.redhat.com//compliance/fips
OCP Versions and RHEL: https://access.redhat.com/articles/6907891
Comments