Re: Allow tests to pass in OpenSSL FIPS mode - Mailing list pgsql-hackers

From Peter Eisentraut
Subject Re: Allow tests to pass in OpenSSL FIPS mode
Date
Msg-id 647f6cc1-473d-f788-ade0-c09201e5ab6a@enterprisedb.com
Whole thread Raw
In response to Allow tests to pass in OpenSSL FIPS mode  (Peter Eisentraut <peter.eisentraut@enterprisedb.com>)
Responses Re: Allow tests to pass in OpenSSL FIPS mode  (Michael Paquier <michael@paquier.xyz>)
List pgsql-hackers
On 04.10.22 17:45, Peter Eisentraut wrote:
> While working on the column encryption patch, I wanted to check that 
> what is implemented also works in OpenSSL FIPS mode.  I tried running 
> the normal test suites after switching the OpenSSL installation to FIPS 
> mode, but that failed all over the place.  So I embarked on fixing that. 

> Of course, there are some some tests where we do want to test MD5 
> functionality, such as in the authentication tests or in the tests of 
> the md5() function itself.  I think we can conditionalize these somehow. 

Let's make a small start on this.  The attached patch moves the tests of 
the md5() function to a separate test file.  That would ultimately make 
it easier to maintain a variant expected file for FIPS mode where that 
function will fail (similar to how we have done it for the pgcrypto tests).

Attachment

pgsql-hackers by date:

Previous
From: Bharath Rupireddy
Date:
Subject: Re: ps command does not show walsender's connected db
Next
From: jiye
Date:
Subject: Re:Re: Is there any plan to support online schem change in postgresql?