u/Sufficient-Owl-9737

Is FIPS-validated container security worth paying for?

w compliance requirement dropped: all containers in prod must use FIPS 140-3 validated cryptography. FedRAMP moderate boundary, deadline is Q3.

checked our base images. none of them qualify. Ubuntu has FIPS-validated packages but only through Ubuntu Pro, not available in the standard free base image we use. Alpine has no FIPS-validated OpenSSL at all. Distroless doesn't ship crypto libraries you can swap independently.

went down the path of trying to use OpenSSL's FIPS provider module on top of our existing base. problem is FIPS 140-3 validation is issued by NIST's CMVP program to a specific compiled binary from a specific vendor under lab-certified conditions, you can't just compile OpenSSL from source and call it validated. the validation doesn't transfer. only CMVP-certified binaries from approved vendors (Red Hat, AWS-LC-FIPS, BoringCrypto in FIPS mode) satisfy the requirement.

buying Ubuntu Pro for every base image changes our build strategy significantly and the validated packages still need to be activated and tested against our app stack. two services broke on the FIPS OpenSSL provider because they were using deprecated cipher suites we didn't know about.

anyone running containers in FedRAMP or DoD environments, how are you sourcing FIPS-validated base images without rebuilding your entire image pipeline?

reddit.com
u/Sufficient-Owl-9737 — 4 days ago

What do you use for SD-WAN branch performance monitoring?

we run around 200 retail locations connected to a central DC over public internet. using SD-WAN overlays.

overall branch network performance varies a lot. jitter can hit ~50 ms, packet loss around 2% during peak hours. POS transactions time out.

QoS markings aren’t consistently honored upstream. shaping on tunnels helps in some cases but doesn’t solve issues when paths degrade.

retail impact is immediate. even short degradation affects transactions and store operations.

looking at options like dual links, path steering, and better monitoring, but tradeoffs aren’t clear.

for teams running distributed retail over internet, what has actually worked to keep performance stable?

reddit.com
u/Sufficient-Owl-9737 — 6 days ago

I havent been doing MSP long but this months security update is killing me. Ton of devices not even downloading, others fail halfway. Got 150 endpoints and I'm doing it manual overnight.

Seen this before, switches to something else or just longer warranty lol.

Our Dells been DOA lately too, thinking Lenovo but patches first. Thanks.

reddit.com
u/Sufficient-Owl-9737 — 23 days ago