6 views
-/https://github.com/berriai/litellm/issues/25861
GitHub · issue

#25861 [Feature]: FIPS compliance of LiteLLM Proxy

  • State: open
  • Author: @bhadrim
  • Labels: enhancement, proxy

### Check for existing issues

- [x] I have searched the existing issues and checked that my issue is not a duplicate.

### The Feature

I am trying to revive the discussion on [this](https://github.com/BerriAI/litellm/issues/16789) feature request that is closed as stale. From [this](https://github.com/BerriAI/litellm/issues/16789#issuecomment-3549996032) comment my understading was this feature may be considered. Was the decision made not to consider this requirement. Thank you.

Original feature request:

LiteLLM proxy is using pynacl which is bound to libsodium library, which is not FIPS certified, so pynacl is not FIPS compliant. This prevents LiteLLM proxy from being used in environment that needs to be certified for FIPS compliance.

This feature request is to use FIPS certified cryptography module. Thank you.

### Motivation, pitch

I am trying to use LiteLLM proxy in a FIPS compliant environment and I cannot adopt LiteLLM proxy as pynacl is not FIPS certified. This issue will prevent adoption of LiteLLM proxy in all the environment that requires FIPS compliance.

### What part of LiteLLM is this about?

Proxy

### LiteLLM is hiring a founding backend engineer, are you int…

GitHub resolver

Import GitHub neighbors on demand. Results are saved as system ingests.

Refresh page
vote history (3 events)
#0 of 0 · 31d18h51m51s ago — entered · #import:https:::github.com:berriai:litellm post #2010
FIPS work is a cross-cutting security and dependency change with compatibility, validation, and certification risks, while the other issue is a localized serialization-path fix.
The right-hand task has substantially greater engineering scope and risk: it involves cryptographic dependency replacement, compatibility across proxy authentication and signing paths, platform-specific behavior, and security/compliance validation. The left-hand task is comparatively localized to diagnosing and improving TLS configuration or error handling in a provider integration.
#0 of 0 · 31d17h48m19s ago — current · #import:https:::github.com:berriai:litellm post #3071
FIPS compliance spans cryptographic dependency replacement, platform-specific validation, backward compatibility, and security audit requirements, making it substantially broader and riskier than a targeted provider request-routing fix.
discussed in #import:https:::github.com:berriai:litellm

ranked child groups

no voted pairs yet in this scope

cli
src
spread
search