<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Compliance |</title>
	<atom:link href="https://newmoyergeospatial.com/tag/compliance/feed/" rel="self" type="application/rss+xml" />
	<link>https://newmoyergeospatial.com</link>
	<description>Solutions Delivered</description>
	<lastBuildDate>Fri, 08 Aug 2025 00:52:19 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://newmoyergeospatial.com/wp-content/uploads/2024/04/NGS-Logo-Icon-Trans-XSm.png</url>
	<title>Compliance |</title>
	<link>https://newmoyergeospatial.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>CoreSpatial Server Adds  FIPS 140-2 Compliance to GeoServer</title>
		<link>https://newmoyergeospatial.com/2025/08/corespatial-server-fips-compliance-geoserver/</link>
		
		<dc:creator><![CDATA[Jason Newmoyer]]></dc:creator>
		<pubDate>Fri, 08 Aug 2025 00:42:18 +0000</pubDate>
				<category><![CDATA[CoreSpatial]]></category>
		<category><![CDATA[GeoServer]]></category>
		<category><![CDATA[Product Announcements]]></category>
		<category><![CDATA[Publications]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Container Security]]></category>
		<category><![CDATA[DoD]]></category>
		<category><![CDATA[FIPS]]></category>
		<category><![CDATA[FIPS 140]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[Government IT]]></category>
		<category><![CDATA[NGS]]></category>
		<category><![CDATA[Open Source]]></category>
		<category><![CDATA[RHEL]]></category>
		<category><![CDATA[Secure GIS]]></category>
		<guid isPermaLink="false">https://newmoyergeospatial.com/?p=2735</guid>

					<description><![CDATA[<p>We’re excited to announce a major enhancement to CoreSpatial Server: support for running GeoServer in FIPS 140 compliant mode on both Red Hat Enterprise Linux (RHEL) and containerized environments. This capability represents a key milestone for CoreSpatial as we continue to expand its use in high-security environments across government and [&#8230;]</p>
<p>The post <a href="https://newmoyergeospatial.com/2025/08/corespatial-server-fips-compliance-geoserver/">CoreSpatial Server Adds  FIPS 140-2 Compliance to GeoServer</a> first appeared on <a href="https://newmoyergeospatial.com"></a>.</p>]]></description>
										<content:encoded><![CDATA[<div class="wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex">
<div class="wp-block-column is-layout-flow wp-block-column-is-layout-flow" style="flex-basis:70%">
<p class="wp-block-paragraph">We’re excited to announce a major enhancement to <strong>CoreSpatial Server</strong>: support for running <a href="https://geoserver.org/"><strong>GeoServer</strong></a><strong> in FIPS 140 compliant mode</strong> on both <strong>Red Hat Enterprise Linux (RHEL)</strong> and containerized environments. This capability represents a key milestone for CoreSpatial as we continue to expand its use in high-security environments across government and enterprise sectors.</p>
</div>



<div class="wp-block-column is-layout-flow wp-block-column-is-layout-flow" style="flex-basis:50%"><div class="wp-block-image">
<figure class="aligncenter size-full is-resized"><img fetchpriority="high" decoding="async" width="1024" height="1536" src="https://newmoyergeospatial.com/wp-content/uploads/2025/08/FIPS-140-GeoServer-Compliance.png" alt="CoreSpatial Server FIPS Mode GeoServer" class="wp-image-2734" style="width:237px;height:auto" srcset="https://newmoyergeospatial.com/wp-content/uploads/2025/08/FIPS-140-GeoServer-Compliance.png 1024w, https://newmoyergeospatial.com/wp-content/uploads/2025/08/FIPS-140-GeoServer-Compliance-200x300.png 200w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>
</div></div>
</div>



<h2 class="wp-block-heading"><strong>What Is FIPS Compliance and Why Does It Matter?</strong></h2>



<p class="wp-block-paragraph">FIPS stands for <strong>Federal Information Processing Standards</strong>, a set of publicly announced standards developed by the <a href="https://www.nist.gov/"><strong>National Institute of Standards and Technology (NIST)</strong></a> for use in computer systems by non-military government agencies and contractors. Specifically, <strong>FIPS 140-2 and 140-3</strong> relate to cryptographic module validation. They define the security requirements for cryptographic operations like encryption, hashing, and signing.</p>



<ul style="font-style:normal;font-weight:400" class="wp-block-list .line-height-fix">
<li class="has-medium-font-size">Learn more about<a href="https://csrc.nist.gov/publications/detail/fips/140/2/final"> FIPS 140-2<br></a></li>



<li class="has-medium-font-size">Explore the latest<a href="https://csrc.nist.gov/publications/detail/fips/140/3/final"> FIPS 140-3</a> standard<br></li>



<li class="has-medium-font-size">NIST’s full FIPS series can be found at<a href="https://csrc.nist.gov/publications/fips"> csrc.nist.gov<br></a></li>
</ul>



<p class="wp-block-paragraph">Many U.S. federal systems (and an increasing number of enterprise platforms handling sensitive or regulated data) are required to run only <strong>FIPS-validated cryptographic modules</strong>. Without this validation, software components like web services, authentication providers, or spatial data servers will be deemed unsuitable for use in secure environments, particularly those that handle Controlled Unclassified Information (<a href="https://www.dodcui.mil/">CUI</a>), Protected Health Information (<a href="https://www.hhs.gov/answers/hipaa/what-is-phi/index.html">PHI</a>), or mission-critical defense data.</p>



<h2 class="wp-block-heading"><strong>Why This Is a Big Deal for CoreSpatial and GeoServer Users</strong></h2>



<p class="wp-block-paragraph">GeoServer, a cornerstone of open-source geospatial services, is widely adopted across both public and private sectors. However, until now, deploying GeoServer in a FIPS-validated environment was not possible due to compatibility issues related to the use of older style JCEKS keystores for secret management, among other password handling issues.&nbsp;</p>



<p class="wp-block-paragraph">With this new release of <strong>CoreSpatial Server</strong>, we’ve resolved those limitations by:</p>



<ul class="wp-block-list">
<li><strong>Configuring the Java runtime environment</strong> to use <a href="https://www.bouncycastle.org/documentation/documentation-java/#bouncy-castle-java-fips-documentation">Bouncy Castle</a> <strong>FIPS 140-2 validated cryptographic providers </strong><strong><br></strong></li>



<li><strong>Hardening container images and RPM-based installations</strong> to ensure strict FIPS mode enforcement<br></li>



<li>Providing <strong>turnkey compatibility with RHEL FIPS-enabled operating systems</strong><strong><br></strong></li>



<li>Validating compatibility with secure ingress and <strong>TLS </strong>termination using <strong>approved ciphers and key lengths</strong><br></li>



<li>Ensuring <strong>continued compatibility with key plugins and extensions</strong>, such as WMS/WFS/WCS services, PostGIS integration, and security modules<br></li>
</ul>



<p class="wp-block-paragraph">This means CoreSpatial Server customers can now deploy GeoServer in environments where <strong>FIPS 140-2 compliance is not optional</strong> &#8211; including DoD, DHS, and state-level emergency management systems.</p>



<h2 class="wp-block-heading"><strong>Deployment Scenarios Supported</strong></h2>



<p class="wp-block-paragraph">The FIPS-compliant CoreSpatial Server supports:</p>



<ul class="wp-block-list">
<li>Bare metal or VM installations on <strong>RHEL 8 and 9 with FIPS mode enabled</strong><strong><br></strong></li>



<li>Containerized deployments using <strong>Podman, Docker, or Kubernetes</strong> where the underlying host supports FIPS 140-2 compliant cryptography<strong><br></strong></li>
</ul>



<p class="wp-block-paragraph">Whether you&#8217;re deploying in a SCIF, in a hybrid cloud with strict compliance policies, or inside an accredited container security boundary, CoreSpatial Server now enables you to take full advantage of GeoServer&#8217;s spatial publishing power without compromising on compliance.</p>



<h2 class="wp-block-heading"><strong>Get Started Today</strong></h2>



<p class="wp-block-paragraph">To explore FIPS-ready deployment options or see a demo, contact us at <a href="mailto:sales@newmoyergeospatial.com"><strong>sales@newmoyergeospatial.com</strong></a> or visit our<a href="https://newmoyergeospatial.com/corespatial"> <strong>CoreSpatial overview</strong></a>.</p>



<p class="wp-block-paragraph">For federal agencies and contractors already navigating <strong>FedRAMP, CMMC, or NIST 800-171</strong> compliance landscapes, this enhancement brings CoreSpatial one step closer to being your go-to open-source alternative for secure geospatial systems.</p><p>The post <a href="https://newmoyergeospatial.com/2025/08/corespatial-server-fips-compliance-geoserver/">CoreSpatial Server Adds  FIPS 140-2 Compliance to GeoServer</a> first appeared on <a href="https://newmoyergeospatial.com"></a>.</p>]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
