wolfSSL can bring FIPS 140-3 validated crypto to your Proxmox and LUKS deployment.
Proxmox encrypts disks with LUKS. wolfCrypt can be the validated engine underneath.
How it works
The wolfCrypt Linux kernel module registers its ciphers with the linux kernel crypto API. Proxmox dm-crypt then hands LUKS operations to wolfCrypt. Your keys and volume layout stay exactly as they are.
wolfCrypt holds multiple validations under two active CMVP certificates #4718, #5041 and has multiple others in process. Any one of the validated modules, that supports kernel space, can serve as the engine to back the Linux Kernel, LUKS, ZFS, OpenSSL3 through wolfProvider, and Proxmox itself.
Validated status applies to our commercial wolfCrypt module built for a supported operating environment, per the module security policy. The public download is FIPS-Ready, meaning it is the same crypto layer but not itself validated. To confirm your Proxmox kernel is a covered operating environment, or to have your OE added, talk to us.
Questions? Contact us at facts@wolfssl.com or call +1 425 245 8247.
Download wolfSSL Now

