Hi Matias,
Thank you for that information. Really appreciate it.
From your reply, if I sum up, wazuh is curently using 1.1.1 openssl which is not fips module compatible.
Openssl 1.0.2 is fips compatible, but need to make small changes to wazuh source code for making it work.
Two questions from this
1. Is there a version of wazuh that supported openssl 1.0.2 in the past?
2. When you say small changes, what parameter changes are required to use fips legacy module in current wazuh version?
In response to your question about our need, we are planning to use wazuh as our SIEM tool including FIM and HIDS module.
We need to make sure that the SIEM we use is FEDRAMP compliant and has FIPS enabled crypto module used for data encryption.
Yes, if wazuh could use an encryption that is fips module compatible, we can surely use that.
Thanks,
Aditya