FIPS 140-3 profiles
rstream now provides separate FIPS 140-3 build profiles for the Go client and Enterprise Edition standalone engine. They are intended for private and on-premises deployments that need a narrow, auditable cryptographic boundary.
The profiles cover TLS and mTLS, direct QUIC, ordinary HTTP/3, and WebTTY over WebTransport with optional authenticated application E2E. Standard builds retain the complete rstream protocol surface, while FIPS builds fail closed when their required module identity or operating mode is unavailable, or when an excluded feature is selected.
Each artifact embeds the NIST CMVP-validated Go Cryptographic Module identified by certificate 5247, Overall Security Level 1. The precise statement is FIPS 140-3 Inside — Go Cryptographic Module, Certificate #5247 (Overall Security Level 1). The certificate applies to the embedded module; rstream as a complete product has not undergone a separate CMVP module validation.
Linux x86_64 and arm64 client and server artifacts are available for contracted Enterprise deployments. The supported server profile uses a single EE engine with in-memory routing. Community Edition, distributed and Global routing, TURN, DTLS, ECH, and non-WebTransport terminal paths remain outside the profile. A FIPS client can also connect to a standard rstream cloud Engine for its allowed features, but the FIPS 140-3 Inside statement then applies only to the client artifact.
When application E2E is enabled, WebTTY uses P-256, HKDF-SHA256, and AES-256-GCM with random nonces over WebTransport. Server and workspace policies can still require E2E. The complete file-sharing feature, including WebDAV and WebRTC backends, remains outside the restricted profile. The dashboard is compatible with that protocol, but browser WebCrypto is outside the validated Go Cryptographic Module boundary.
See FIPS 140-3 Profiles for the supported boundary, build identity, deployment model, and release evidence.