Support FIPS-capable TLS by `aws-lc-rs`
Author: ChihweiLHBirdCreated Aug 11, 2026Updated Aug 11, 2026
Motivation
libsql’s HTTP/TLS stack is built on rustls + hyper-rustls. Today that path is effectively ring-backed, which blocks deployments that need FIPS-validated cryptography.
The Rust TLS ecosystem has been moving toward aws-lc-rs for this reason:
- rustls made aws-lc-rs the default crypto backend and added FIPS support
- rustls documents a FIPS path via aws-lc-rs (
fipsfeature + FIPSCryptoProvider) — see rustls FIPS guide - aws-lc-rs exists in large part as a ring-compatible provider with FIPS
Supporting aws-lc-rs (and ideally a documented FIPS configuration) would align libsql with that direction and unblock regulated / government workloads.
Proposal
- Expose a crate feature (e.g.
aws-lc-rs) that backs the built-in TLS connector with aws-lc-rs
I am happy to contribute a PR for this proposal if needed.
Alternatives
- Hard switch from ring to aws-lc-rs, but this may introduce more breaking changes
Source: tursodatabase/libsql