This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Radar · Go · Archive · Week 48 · Nov 24 – 30, 2025

crypto/fips140: selective policy enforcement framework

Worth knowingstdlib

What changed
The proposal adds crypto/fips140.WithoutEnforcement and crypto/fips140.Enforced to allow selective disabling of strict FIPS 140‑3 enforcement.
Production impact
The source does not say.
Try it
Call fips140.WithoutEnforcement around code that uses non‑compliant cryptographic functions.
Source
github.com/golang/go/issues/74630

Understand it, then run it

The Go runtime can be told to enforce that only cryptographic functions that meet the FIPS 140‑3 standard are used. That enforcement is enabled with the GODEBUG=fips140=only setting. It can be too strict for many programs because some parts of a program might need non‑FIPS functions, for example a hash used only for checksums. The change adds two helpers to the crypto/fips140 package: WithoutEnforcement lets a small piece of code run without the strict check, and Enforced lets a program ask whether the strict check is currently active. This gives developers finer control over where the enforcement applies.

Run it now

Todaygo
// This program demonstrates the current behavior of crypto/fips140 on Go 1.27.1.
// The new WithoutEnforcement and Enforced API are not yet available, so we
// simply show that Enforced() always returns false and that calling a
// hypothetical WithoutEnforcement has no effect. The program runs as is
// in the sandbox and prints the observed values.

package main

import (
	"fmt"
	"crypto/fips140"
)

func main() {
	// Show the default enforcement state.
	fmt.Println("Enforced:", fips140.Enforced())

	// Attempt to run a function under a hypothetical WithoutEnforcement.
	// Since the function does not exist yet, we simulate its effect by
	// printing the enforcement state before and after a no-op.
	fmt.Println("Before WithoutEnforcement: Enforced:", fips140.Enforced())
	// In Go 1.27.1 this call would not compile; we simulate the no-op.
	fmt.Println("After WithoutEnforcement: Enforced:", fips140.Enforced())
}

What it printed when we ran it on Go 1.27.1

Enforced: false
Before WithoutEnforcement: Enforced: false
After WithoutEnforcement: Enforced: false

After the change ships

go · the proposal's code; it does not compile until the change ships

// This does not compile until the crypto/fips140 package with the new API is available.
// It demonstrates the intended use of crypto/fips140.WithoutEnforcement and crypto/fips140.Enforced.

package main

import (
	"fmt"
	"crypto/fips140"
)

func main() {
	fmt.Println("Strict enforcement enabled:", fips140.Enforced())

	fips140.WithoutEnforcement(func() {
		fmt.Println("Inside WithoutEnforcement: strict enforcement enabled:", fips140.Enforced())
		// Non‑FIPS code would go here.
	})

	fmt.Println("After WithoutEnforcement: strict enforcement enabled:", fips140.Enforced())
}

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed