Skip to content

refactor: use fips (aws-lc-rs) for aws-sigv4 via fork of smithy-rs - #1612

Draft
jkaczman wants to merge 1 commit into
mainfrom
jk-aws-sigv4-fips-repl
Draft

jkaczman wants to merge 1 commit into
mainfrom
jk-aws-sigv4-fips-repl

Conversation

@jkaczman

Copy link
Copy Markdown
Contributor

Uses our new fork of smithy-rs to change its functionality to support this. The implementation in that fork's PR for this refactor was merged from a pre-existing implementation jplock made.

Why a fork instead of trying to merge upstream? The maintainers of smithy-rs don't want to add support for fips into aws-sigv4.

Why not hand-roll our own implementation for sigv4 that uses aws-lc-rs? We may need to modify other things within smithy to support fips; seemed to make more sense for the long run to have our own fork. It's also a bit cleaner imo to have separation.

I haven't validated the correctness of their commit, since I want to make sure we're okay with going this route first. If we are, I can go through carefully before we merge this, and make sure with certainty everything looks good.

Also: I went ahead and updated the AWS SDK crates to latest while I was doing this.

Corresponding PR: pgdogdev/smithy-rs#2
Fixes #1604

@codecov

codecov Bot commented Sep 22, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Replace aws-sigv4 crate with FIPS-compliant crypto alternative

1 participant