FIPS 140-2 Compliant Plugins

This reference lists which Kong Gateway plugins are FIPS 140-2 compliant and provides additional details about how they maintain compliance.

PluginSubcomponent Compliance (if applicable)FIPS CompliantNotes
jwe-decryptN/AYesCompliant via OpenSSL 3.0 FIPS provider
openid-connectAllYesCompliant via OpenSSL 3.0 FIPS provider
jwt-signerAllYesCompliant via OpenSSL 3.0 FIPS provider
key-auth-encN/AYesCompliant via OpenSSL 3.0 FIPS provider
hmac-authN/AYesCompliant via OpenSSL 3.0 FIPS provider
ldap-auth-advancedN/AYesCompliant via OpenSSL 3.0 FIPS provider
proxy-cacheN/AYesCompliant via OpenSSL 3.0 FIPS provider
proxy-cache-advancedN/AYesCompliant via OpenSSL 3.0 FIPS provider
graphql-proxy-cache-advancedN/AYesCompliant via OpenSSL 3.0 FIPS provider
mtls-authN/AYesCompliant via OpenSSL 3.0 FIPS provider
oauth2N/AYesCompliant via OpenSSL 3.0 FIPS provider
basic-authN/AYesCompliant via OpenSSL 3.0 FIPS provider
samlN/AYesCompliant via OpenSSL 3.0 FIPS provider
jwtN/AYesCompliant via OpenSSL 3.0 FIPS provider
All other Kong Inc. pluginsN/AN/ANo cryptographic operations involved