Re: PostgreSQL 18 FIPS mode in Windows - Mailing list pgsql-general

From Tom Lane
Subject Re: PostgreSQL 18 FIPS mode in Windows
Date
Msg-id 1814989.1790280801@sss.pgh.pa.us
Whole thread
In response to PostgreSQL 18 FIPS mode in Windows  (sutyak <sutyak@proton.me>)
Responses Re: PostgreSQL 18 FIPS mode in Windows
List pgsql-general
sutyak <sutyak@proton.me> writes:
> The steps I have already taken are:

> - Install PostgreSQL 18.6 windows-x64
> - Install OpenSSL 3.5.8 with FIPS Provider 3.1.2
> - Enable pgcrypto extension via pgAdmin
> - set builtin_crypto_enabled to 'fips'
> - Executing SELECT fips_mode(); always returns false.
> - Verified FIPS is not being enforced by executing SELECT encode(digest('test', 'md5'), 'hex'); and it always returns
avalue. 

> What am I missing? Thank you,

'builtin_crypto_enabled = fips' merely tells pgcrypto to expect
failure of relevant calls.  It does not cause OpenSSL to actually
go into FIPS mode.  You'd have to consult the OpenSSL docs to
find out how to do that.

            regards, tom lane



pgsql-general by date:

Previous
From: sutyak
Date:
Subject: PostgreSQL 18 FIPS mode in Windows
Next
From: Daniel Gustafsson
Date:
Subject: Re: PostgreSQL 18 FIPS mode in Windows