Key differences between FIPS 140-2 and FIPS 140-3
In Cloudera Runtime 7.3.2 SP1and higher versions, you must upgrade to FIPS 140-3. The transition from FIPS 140-2 to FIPS 140-3 represents a major evolution in security standards designed to address modern infrastructure vulnerabilities.
| Category | FIPS 140-2 | FIPS 140-3 |
|---|---|---|
| Status and validation lifecycle | Relies on legacy modules reaching their expiration dates. For example, standard SafeLogic and RHEL 8 modules expire through 2026. |
Enforces active FIPS 140-3 validated cryptographic modules across all federal deployments. |
| Operating system integration | Leverages legacy operating systems such as RHEL 8 or CentOS 7. | Requires modern operating system infrastructure such as RHEL 9. |
| Cryptographic modules (SafeLogic) | Uses SafeLogic CryptoComply modules (CCS, CCJ, and Libgcrypt) validated under legacy FIPS 140-2 security criteria. | Upgrades to the SafeLogic CCJ 4.x module, to maintain compliance as legacy certificates transition to the historical list. |
| Container and image standards | Relies heavily on Red Hat Universal Base Images (UBI 8) running standard open-source library wrappers. | Shifts container deployments toward Chainguard images to reduce CVE exposure while using built-in FIPS 140-3 Go or OpenSSL modules. |
