Configuring SSL for FIPS 140-3 compatibility

Federal Information Processing Standards (FIPS) 140 is a U.S. government standard established by the National Institute of Standards and Technology (NIST) which is used to accredit cryptographic modules such as those used in TLS network encryption. Although FIPS 140 compliance is primarily required for federal agencies and their contractors, it is also used in the healthcare sector under regulations like the Health Insurance Portability and Accountability Act (HIPAA) to protect patient data.

This guide helps configure Neo4j to use TLS/SSL encryption in a FIPS-compliant way. It is supplementary to the SSL framework documentation, as many of the configuration processes and requirements are the same.

FIPS 140-2 will reach end of life (EOL) on September 21, 2026. After this date, all the FIPS 140-2 certificates will be moved to the historical list. You should audit your active systems and migrate to FIPS 140-3 validated alternatives.

All Neo4j 2025.x and 2026.x versions support SSL encryption compatible with FIPS 140-3 requirements.

Prerequisites

  • Verify that the machine running Neo4j has FIPS 140-3 compatible hardware and operating system. Only Linux operating systems are supported for Neo4j FIPS compatibility at this time.

  • Install and configure a non-native authentication provider, for example LDAP or SSO. See Authentication and authorization.

Enable FIPS SSL provider

The secure networking in Neo4j is provided through the Netty library, which supports both the native JDK SSL provider and Netty-supported OpenSSL derivatives. Specifically, Neo4j uses Netty’s Forked Tomcat Native library called netty-tcnative.

The netty-tcnative library is provided in several variants. However, to achieve FIPS compliance, you must use the dynamically linked version of netty-tcnative alongside a FIPS-compatible installation of OpenSSL.

The dynamically linked library requires the following dependencies to be installed[1]:

  • Apache Portable Runtime Library

  • A FIPS certified version of OpenSSL, with a FIPS provider installed and set as default.

Refer to Forked Tomcat Native for more information.

Netty provides a convenient pre-build, statically linked version of netty-tcnative using BoringSSL, but this is not FIPS certified[2].

By using the dynamic netty-tcnative library variant combined with a FIPS certified OpenSSL installation, Neo4j’s cryptographic operations are delegated by netty-tcnative to OpenSSL, transitively giving FIPS compatibility.

Install Apache portable runtime library

To install Apache Portable Runtime Library, use the operating system’s package manager.

In Debian/Ubuntu this package is usually called libapr1

Install Apache Portable Runtime Library in Debian or Ubuntu
apt install -y libapr1

In RedHat Enterprise Linux, the package is usually called apr:

Install Apache Portable Runtime Library in RedHat
dnf install -y apr

Install OpenSSL

Instructions on how to build and install a FIPS-compatible OpenSSL are out of scope for this document. Installation steps can differ depending on operating system, and other security requirements you might have for OpenSSL.

In general:

  • For a list of FIPS certified OpenSSL versions, see https://openssl-library.org/source/.

  • A FIPS provider must be installed into OpenSSL.

  • OpenSSL must be configured to use the FIPS provider by default.

Install the correct netty-tcnative library

Builds of netty-tcnative dynamic library are provided in the Neo4j lib directory under their own subfolder called netty-tcnative.

To install the netty-tcnative dynamic library:

  1. Locate the Neo4j lib directory.

    The location of the lib directory is different depending on the method used to install Neo4j. Check the file locations documentation for the correct location.

    This location will be referred to as <NEO4J_LIB>.

  2. Make sure there are no netty-tcnative-boringssl libraries present in the <NEO4J_LIB> folder.

    find <NEO4J_LIB> -name "netty-tcnative-boringssl*.jar" -delete
  3. Check which netty-tcnative libraries are available:

    ls -l <NEO4J_LIB>/netty-tcnative

    There are Linux and Fedora Linux variants available, compiled for both x86_64 and ARM 64 architectures. Select the one matching the local machine’s operating system and architecture.

  4. Verify the dependencies are correctly installed using ldd:

    Verify netty-tcnative dependencies are installed
    unzip -d /tmp <NEO4J_LIB>/netty-tcnative/netty-tcnative-*-linux-$(arch).jar
    ldd /tmp/META-INF/native/libnetty_tcnative_linux_*.so
    rm -rf /tmp/META-INF
    Verify Fedora variant of netty-tcnative dependencies are installed
    unzip -d /tmp <NEO4J_LIB>/netty-tcnative/netty-tcnative-*-linux-$(arch)-fedora.jar
    ldd /tmp/META-INF/native/libnetty_tcnative_linux_$(arch).so
    rm -rf /tmp/META-INF

    The ldd command shows a list of library dependencies and where they are loaded from on the local machine.

    • If any dependencies are missing, they must be installed, or Neo4j will fail to run.

    • The libssl.so and libcrypto.so libraries listed must be the ones installed with OpenSSL in the previous steps.

  5. Copy the verified JAR file to <NEO4J_LIB>.

    Only copy one of the JAR files. Otherwise Neo4j will not be able to resolve dependencies at runtime. In case of this error, you will get a message like:

    "Failed to load any of the given libraries: [netty_tcnative_linux_x86_64, netty_tcnative_linux_x86_64_fedora, netty_tcnative_x86_64, netty_tcnative]".

Generate SSL certificate and private key

Neo4j SSL encryption requires a certificate in the X.509 standard and a private key in PKCS #8 format, both encoded in PEM format.

For FIPS compatibility, the private key must be secured with a password.

Refer to the SSL certificate and key instructions for more information.

Configure Neo4j to use SSL encryption

SSL configuration is described in detail in SSL framework configuration.

This section describes configuration that must be done in addition to standard non-FIPS compliant SSL configuration.

  • The following group of FIPS-compatible cipher suites is for use with TLSv1.2:

    • TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

    • TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256

    • TLS_DHE_RSA_WITH_AES_256_GCM_SHA384

    • TLS_DHE_RSA_WITH_AES_128_GCM_SHA256

      They require additional configuration in the application or OpenSSL settings.

  • The following cipher suites are supported by default in OpenSSL when using TLSv1.3:

    • TLS_AES_256_GCM_SHA384

    • TLS_AES_128_GCM_SHA256

      These suites do not require additional configuration when OpenSSL is built with FIPS support.

Bolt

  1. Set dbms.netty.ssl.provider=OPENSSL

  2. Set server.bolt.tls_level=REQUIRED

  3. Follow instructions on how to Configure SSL over Bolt.

  4. Set additional Bolt configurations:

    dbms.ssl.policy.bolt.trust_all=false
    dbms.ssl.policy.bolt.tls_level=REQUIRED
    dbms.ssl.policy.bolt.tls_versions=TLSv1.2,TLSv1.3
    dbms.ssl.policy.bolt.ciphers=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_DHE_RSA_WITH_AES_256_GCM_SHA384,TLS_DHE_RSA_WITH_AES_128_GCM_SHA256,TLS_AES_256_GCM_SHA384,TLS_AES_128_GCM_SHA256
  5. Follow the instructions in SSL Framework → Using encrypted private key to configure dbms.ssl.policy.bolt.private_key_password to dynamically read the password from an encrypted password file. The password must not be set in plain text.

HTTPS

This section is only applicable if HTTPS is enabled.

  1. Follow instructions on how to Configure SSL over HTTPS.

  2. Set additional HTTPS configurations:

    dbms.ssl.policy.https.trust_all=false
    dbms.ssl.policy.https.tls_level=REQUIRED
    dbms.ssl.policy.https.tls_versions=TLSv1.2,TLSv1.3
    dbms.ssl.policy.https.ciphers=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_DHE_RSA_WITH_AES_256_GCM_SHA384,TLS_DHE_RSA_WITH_AES_128_GCM_SHA256,TLS_AES_256_GCM_SHA384,TLS_AES_128_GCM_SHA256
  3. Follow the instructions in SSL Framework → Using encrypted private key to configure dbms.ssl.policy.https.private_key_password to dynamically read the password from an encrypted password file. The password must NOT be set in plain text.

Intra-cluster encryption

For FIPS compatbility, intra-cluster encryption must be enabled if you are running a Neo4j cluster.

  1. Follow instructions to configure SSL for intra-cluster communication.

  2. Set additional cluster configurations:

    dbms.ssl.policy.cluster.enabled=true
    dbms.ssl.policy.cluster.tls_level=REQUIRED
    dbms.ssl.policy.cluster.client_auth=REQUIRED
    dbms.ssl.policy.cluster.tls_versions=TLSv1.2,TLSv1.3
    dbms.ssl.policy.cluster.ciphers=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_DHE_RSA_WITH_AES_256_GCM_SHA384,TLS_DHE_RSA_WITH_AES_128_GCM_SHA256,TLS_AES_256_GCM_SHA384,TLS_AES_128_GCM_SHA256
  3. Follow the instructions in SSL Framework → Using encrypted private key to configure dbms.ssl.policy.cluster.private_key_password to dynamically read the password from an encrypted password file. The password must not be set in plain text.

Backup

This section is applicable on instances or cluster members used for taking backups.

  1. Follow instructions on how to Configure SSL for backup communication.

  2. Set additional backup configurations:

    dbms.ssl.policy.backup.enabled=true
    dbms.ssl.policy.backup.client_auth=REQUIRED
    dbms.ssl.policy.backup.trust_all=false
    dbms.ssl.policy.backup.tls_versions=TLSv1.2,TLSv1.3
    dbms.ssl.policy.backup.ciphers=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_DHE_RSA_WITH_AES_256_GCM_SHA384,TLS_DHE_RSA_WITH_AES_128_GCM_SHA256,TLS_AES_256_GCM_SHA384,TLS_AES_128_GCM_SHA256
  3. Follow the instructions in SSL Framework → Using encrypted private key to configure dbms.ssl.policy.backup.private_key_password to dynamically read the password from an encrypted password file. The password must not be set in plain text.

Glossary

allocator

A component in the cluster that allocates databases to servers according to the topology constraints specified and an allocation strategy.

asynchronous replication

Asynchronous replication is used by secondary copies to poll for new transactions, which means they cannot be guaranteed to have received the most recent transactions. This enables efficient scale-out of read-performance.

Aura instance

A fully-managed DBMS represented by a single instance ID, that is running in the Neo4j Aura cloud.

auto-commit transaction

An automatically committed transaction that contains a single query.

Bolt protocol

Bolt is a protocol used for interaction between Neo4j instances and drivers.

bookmark

A marker the client can request from the cluster to ensure that it is able to read its own writes so that the application’s state is consistent and only databases that have a copy of the bookmark are permitted to respond.

category (Bloom)

A category is based on a node label and is defined in a Perspective as a way of visually distinguishing nodes with the same label(s).

causal consistency

All servers in a cluster agree on the order in which transactions take place. The position of a server on the causal chain can be guaranteed using a bookmark.

cluster

A Neo4j DBMS that spans multiple servers working together to increase fault tolerance and/or read scalability. Databases on a cluster may be configured to replicate across servers in the cluster thus achieving read scalability or high availability.

client application

Software that interacts with a Neo4j server.

commit

A commit is the successful completion of a transaction, which ensures durability of any changes made. For more details, visit Operations Manual → Transaction management.

composite database

Composite databases are the means to access partitioned graph data with a single Cypher query.

constraint

Constraints are sets of data modeling rules that ensure the data is consistent and reliable.

Cypher®

Neo4j’s graph query language.

data model

A data model defines how information is organized in a database. A good data model will make querying and understanding your data easier. In Neo4j, the data models have a graph structure.

database

A database is a container used by the DBMS to manage and store graph data. The physical structure of data is controlled by the database.

database vs graph

Databases are the physical containers of graph data. Graphs are the logical structure of data in Neo4j.

Database Management System

Database Management System, or DBMS, capable of managing multiple databases. A DBMS may run on a single server, or span several servers configured as a cluster.

database schema

The prescribed property existence and datatypes for nodes and relationships.

deallocate

An act of removing a database from a server or a server from a cluster without loss of data or reduced fault tolerance.

degree (of a node)

The number of relationships of a specific node; loops are counted twice.

disaster recovery

A manual intervention to restore availability of a cluster, or databases within a cluster.

driver

A software library that provides access to Neo4j from a particular programming language.

election

In the event that the Raft leader becomes unresponsive, followers automatically trigger an election and vote for a new leader.

entity

A node or a relationship.

expression (Cypher)

A component of a Cypher query which produces values. It may be used in projections, as a predicate, or when setting properties on graph elements.

fabric

Fabric is the architectural design of a unified system that provides a single access point to local or distributed graph data.

fault tolerance

A guarantee that a cluster can maintain a database’s persistence and availability in the event of one or more servers failing.

follower

A primary copy of a database acting as a follower, receives and acknowledges synchronous writes from the leader.

Generative AI (GenAI)

A type of artificial intelligence (AI) system that generates text, images, or other media in response to prompts.

graph

A logical representation of a set of nodes where some pairs are connected by relationships.

index

Data structure that improves read performance of a database.

knowledge graph

A specific type of graph that has an organizing principle so that a user (or a computer system) can reason about the underlying data. The organizing principle provides an additional layer of structure that adds context to support knowledge discovery.

label

Marks a node as a member of a named and indexed subset. A node may be assigned zero or more labels.

leader

A single primary copy of a database is designated as the leader. It receives all write transactions from clients and replicates writes synchronously to followers and asynchronously to secondary copies of the database.

main database

In terms of Neo4j Enterprise Studio, the database(s) containing the user’s data. Can exist in the same Neo4j deployment as the tool asset database.

motif

A description of a specific pattern within a graph.

node

A node represents an entity or discrete object in your graph data model. Nodes can be connected by relationships, hold data in properties, and are classified by labels.

operator

A symbol representing a mathematical or logical operation.

parameter

Named value provided when running a Cypher statement.

path

A sequence of nodes and the relationships connecting them, that does not contain duplicate relationships. Several paths can match a pattern.

pattern

A specific arrangement of nodes and relationships that can be matched in a graph. A pattern follows a motif.

perspective (Bloom)

A Perspective defines a certain business view or domain that can be found in the target Neo4j graph. A single Neo4j graph can be viewed through different Perspectives, each tailored for a different business purpose.

primary

A copy of the database that is able to process write transactions and is eligible to be elected as a leader. It participates in fault tolerant writes as it is part of the majority required to acknowledge and commit write transactions.

primary vs secondary

In a cluster, databases can operate in either primary or secondary mode. Primary databases are able to process write and read transactions, ensuring fault tolerance. Secondary databases are replicated asynchronously from primaries, and their main purpose is to provide read scaling within the cluster.

project (Aura)

An isolated environment in the unified Aura console that contains its own database instances, configurations, and resources. Preceded by tenant in the classic Aura console.

property

Properties are key-value pairs that are used for storing data on nodes and relationships.

query (Cypher)

A statement that retrieves or writes information to a database.

Raft group

A group of servers that are participating in hosting a particular database in primary mode.

Raft group member

A server that is participating in a Raft group. A server can be a member of one or more groups.

Raft log

A shared log between all Raft group members that is guaranteed to be consistently updated and viewed by those members. The log contains both database data and operational state of the Raft group.

Raft protocol

The networking mechanism that enables a database to replicate its data across multiple servers to give high availability for accessing the data and high durability to the data stored.

read scaling

Distributing query load by creating additional database copies hosted in secondary mode (read-only).

relationship

A relationship represents a connection between nodes in your graph data model. Relationships connect a source node to a target node, hold data in properties, and are classified by type.

secondary

An asynchronously replicated copy of the database that provides read scaling within the cluster.

seed

A seed is a database dump or a full backup used to create a database on a cluster. This is sometimes called seeding.

server

A physical machine, a virtual machine, or a container running an instance of Neo4j. Servers can be standalone or part of a cluster.

session

A causally linked sequence of transactions.

session consistency

An alternative name for Neo4j’s causal consistency.

standalone

A single server running Neo4j and not part of a cluster.

synchronous replication

Synchronous replication requires the leader primary to replicate a transaction and block the commit until a quorum of the follower primaries acknowledges that the transaction is successfully replicated. Once the transaction is replicated, the commit is allowed to proceed. This ensures data durability and consistency within the cluster.

system database

A database used by Neo4j to store system information.

tenant (Aura)

An isolated environment in the classic Aura console that contains its own database instances, configurations, and resources. Replaced by project in the unified Aura console.

tool asset database

In terms of Neo4j Enterprise Studio, the database where tools' assets are stored. This can be in the same Neo4j deployment as the main database(s) or in a separate deployment.

topology

A configuration that describes how the copies of a database should be spread across the servers in a cluster, see primary mode and secondary mode.

transaction

A transaction comprises a unit of work performed against a database. It is treated in a coherent and reliable way, independent of other transactions. Transactions comply with the ACID consistency model (atomic, consistent, isolated, and durable).