Platform Support

Non-FIPS Builds (aws-lc-sys)

For non-FIPS builds, aws-lc-sys provides universal pre-generated bindings that work across all supported platforms. Bindgen is never required, CMake is never required, and Go is never required. The only build requirement is a C/C++ compiler.

This means that if your target platform is supported by both AWS-LC and the Rust compiler (with std support), aws-lc-rs should work out of the box without any additional tooling beyond a C/C++ compiler.

FIPS Builds (aws-lc-fips-sys)

FIPS builds always require CMake and Go in addition to a C/C++ compiler. FIPS builds also require bindgen unless pre-generated bindings are available for the target platform.

Pre-generated FIPS Bindings

Pre-generated bindings for aws-lc-fips-sys are available for the following targets. All other FIPS targets require bindgen.

PlatformPre-generated FIPS Bindings
aarch64-apple-darwin
aarch64-pc-windows-msvc✗ (bindgen required) ¹
aarch64-unknown-linux-gnu
aarch64-unknown-linux-musl
x86_64-apple-darwin
x86_64-pc-windows-msvc✗ (bindgen required) ¹
x86_64-unknown-linux-gnu
x86_64-unknown-linux-musl

¹ FIPS is supported on this platform but requires bindgen (no pre-generated FIPS bindings are available for Windows platforms)

Bindgen for FIPS Builds

For FIPS builds on targets without pre-generated bindings, one of the following options must be used for bindings generation. See requirements page for more information.

  • Enable bindgen feature in your Cargo.toml:
[dependencies]
aws-lc-rs = { version = "1", features = ["bindgen", "fips"] }

-- OR --

  • Install bindgen-cli in the build environment:
cargo install --force --locked bindgen-cli

Tested Platforms

aws-lc-rs CI builds and/or tests on many platforms beyond those listed in the FIPS bindings table above. See our CI workflow configuration for the complete list of tested platforms.

Build Requirements Summary

RequirementNon-FIPS (aws-lc-sys)FIPS (aws-lc-fips-sys)
C/C++ CompilerRequiredRequired
CMakeNever requiredAlways required
BindgenNever required (universal pre-generated bindings)Required unless target has pre-generated bindings
GoNever requiredAlways required

Linux Platforms

PlatformBuildTestsFIPS
aarch64-unknown-linux-gnu
aarch64-unknown-linux-musl
arm-unknown-linux-gnueabihf
arm-unknown-linux-musleabi
arm-unknown-linux-musleabihf
armv7-unknown-linux-gnueabihf
i686-unknown-linux-gnu
mips-unknown-linux-gnu ¹
mips-unknown-linux-musl ¹
mips64-unknown-linux-muslabi64 ¹
mips64el-unknown-linux-muslabi64 ¹
powerpc-unknown-linux-gnu
powerpc64-unknown-linux-gnu
powerpc64le-unknown-linux-gnu
riscv64gc-unknown-linux-gnu
s390x-unknown-linux-gnu
x86_64-unknown-linux-gnu
x86_64-unknown-linux-musl

¹ Requires nightly Rust toolchain

Apple Platforms

PlatformBuildTestsFIPS
aarch64-apple-darwin
aarch64-apple-ios
aarch64-apple-ios-sim
aarch64-apple-tvos-sim ¹
x86_64-apple-darwin
x86_64-apple-ios

¹ Requires nightly Rust toolchain

Windows Platforms

PlatformBuildTestsFIPS
aarch64-pc-windows-msvc
i686-pc-windows-msvc
x86_64-pc-windows-gnu
x86_64-pc-windows-msvc

Android Platforms

PlatformBuildTests
aarch64-linux-android
arm-linux-androideabi
armv7-linux-androideabi
i686-linux-android
x86_64-linux-android

BSD Platforms

PlatformBuildTestsFIPS
x86_64-unknown-freebsd
x86_64-unknown-netbsd

Other Platforms

PlatformBuildTests
x86_64-unknown-illumos
wasm32-unknown-emscripten
OpenHarmony (aarch64)
OpenWrt (aarch64-musl)
Alpine Linux