FIPS mode - SSL connection fails and RAND_cleanup - Mailing list pgsql-general

From
Subject FIPS mode - SSL connection fails and RAND_cleanup
Date
Msg-id 7654067E3D35FB43BADBA290D42E66B111D8FB@MIVEXAMER1N2.corp.nai.org
Whole thread Raw
List pgsql-general

We recently upgraded to version 8.4.18 within our product but this upgrade has caused SSL connections to fail when OpenSSL is in FIPS mode. 

We receive the following error: 
2014-02-20 01:44:23 PST [9339]: [1-1] db=[unknown],user=[unknown] LOG:  could not accept SSL connection: decryption failed or bad record mac 

While looking through the recent changes, we found that commenting out the "RAND_cleanup();" call in "src/backend/postmaster/fork_process.c" allows the connection to succeed. 

Any ideas on why this "RAND_cleanup();" would cause SSL failure in FIPS mode? 
Is there a work around?  Or is this possibly a known issue? 

Thanks.

pgsql-general by date:

Previous
From: Adrian Klaver
Date:
Subject: Re: Timezone information
Next
From: Willy-Bas Loos
Date:
Subject: Re: [postgis-users] postgis in postgresql apt and upgrades