Re: PostgreSQL 18 FIPS mode in Windows - Mailing list pgsql-general

From Joe Conway
Subject Re: PostgreSQL 18 FIPS mode in Windows
Date
Msg-id 29961e58-b60e-4bbb-97f6-d558a07371cc@joeconway.com
Whole thread
In response to Re: PostgreSQL 18 FIPS mode in Windows  (Daniel Gustafsson <daniel@yesql.se>)
List pgsql-general
On 9/24/26 16:16, Daniel Gustafsson wrote:
>> On 24 Sep 2026, at 22:13, Tom Lane <tgl@sss.pgh.pa.us> wrote:
>> 
>> sutyak <sutyak@proton.me> writes:
>>> The steps I have already taken are:
>> 
>>> - Install PostgreSQL 18.6 windows-x64
>>> - Install OpenSSL 3.5.8 with FIPS Provider 3.1.2
>>> - Enable pgcrypto extension via pgAdmin
>>> - set builtin_crypto_enabled to 'fips'
>>> - Executing SELECT fips_mode(); always returns false.
>>> - Verified FIPS is not being enforced by executing SELECT encode(digest('test', 'md5'), 'hex'); and it always
returnsa value.
 
>> 
>>> What am I missing? Thank you,
>> 
>> 'builtin_crypto_enabled = fips' merely tells pgcrypto to expect
>> failure of relevant calls.  It does not cause OpenSSL to actually
>> go into FIPS mode.  You'd have to consult the OpenSSL docs to
>> find out how to do that.
> 
> +1.  You need to enable the FIPS provider in openssl.conf and make sure to
> disable the legacy provider.  The builtin_crypto_enabled setting simply makes
> sure to never call non-FIPS certified crypto when OpenSSL is operating in fips
> mode, you can also set it to 'off' and disallow non-FIPS certified crypto
> regardless.


Also to be clear, the distributor of the openssl library used must get 
their specific bits validated in order to be actually FIPS compliant if 
compliance is what you are after.


-- 
Joe Conway
PostgreSQL Contributors Team
Amazon Web Services: https://aws.amazon.com



pgsql-general by date:

Previous
From: Daniel Gustafsson
Date:
Subject: Re: PostgreSQL 18 FIPS mode in Windows
Next
From: sutyak
Date:
Subject: Re: PostgreSQL 18 FIPS mode in Windows