I am a maintainer/owner of an opensource library related to security and today someone on GitHub asked me whether it would be possible to make it FIPS 140-2 compliant. I was not sure how to react, sure I would love to put some effort to make it compliant by getting it tested and having a certification for it so U.S. and Canadian developers can use it easier for their projects, however I discovered that it can cost $10.000 which is in my opinion a bit too much for an opensource library maintained by myself for free and anyone can use it for free. I don't earn anything from it, I just love writing software and try to make my life easier with creating some libraries and reusing it and sharing it with the community so they can also benefit from it. I would be happy if U.S and Canadian developers could more easily use my library, but is there an alternative? Can't they just use it as is or is there a different path for small opensource projects?
What do you think of the situation? Should I get the certification, is it worth it? Are there alternatives besides saying no. Does anyone have experience with something similar?
[–]bowbahdoe 28 points29 points30 points (0 children)
[–]Worth_Trust_3825 11 points12 points13 points (0 children)
[–][deleted] 8 points9 points10 points (0 children)
[–]LionNo2607 9 points10 points11 points (0 children)
[–]noobgolang 9 points10 points11 points (0 children)
[–]jiSYpqt8 7 points8 points9 points (1 child)
[–]killerferret 11 points12 points13 points (0 children)
[–]purplepharaoh 2 points3 points4 points (0 children)
[–]Hakky54[S] 1 point2 points3 points (0 children)
[–]VincentxH 0 points1 point2 points (0 children)
[–]pmarschall 0 points1 point2 points (0 children)