Re: PostgreSQL 18 FIPS mode in Windows - Mailing list pgsql-general

From sutyak
Subject Re: PostgreSQL 18 FIPS mode in Windows
Date
Msg-id TDoTBKJfmBs_hTCgoC6VK5r7HvrmHhokkyPz04MCkveOa7MD0LmpJ0bXTKaBRpTyoGlRZZuPsHyBx__hrtgkpZQ2wu5PSWLCDiyXG-HQxt4=@proton.me
Whole thread
In response to Re: PostgreSQL 18 FIPS mode in Windows  (Daniel Gustafsson <daniel@yesql.se>)
Responses Re: PostgreSQL 18 FIPS mode in Windows
List pgsql-general
I forgot to mention I did ensure FIPS is the only option enabled in OpenSSL.  Verified by running openssl.exe
list-providers.

Mark


Sent from Proton Mail for Android.

-------- Original Message --------
On Thursday, 09/24/26 at 16:17 Daniel Gustafsson <daniel@yesql.se> wrote:
> On 24 Sep 2026, at 22:13, Tom Lane <tgl@sss.pgh.pa.us> wrote:
>
> sutyak <sutyak@proton.me> writes:
>> The steps I have already taken are:
>
>> - Install PostgreSQL 18.6 windows-x64
>> - Install OpenSSL 3.5.8 with FIPS Provider 3.1.2
>> - Enable pgcrypto extension via pgAdmin
>> - set builtin_crypto_enabled to 'fips'
>> - Executing SELECT fips_mode(); always returns false.
>> - Verified FIPS is not being enforced by executing SELECT encode(digest('test', 'md5'), 'hex'); and it always
returnsa value. 
>
>> What am I missing? Thank you,
>
> 'builtin_crypto_enabled = fips' merely tells pgcrypto to expect
> failure of relevant calls.  It does not cause OpenSSL to actually
> go into FIPS mode.  You'd have to consult the OpenSSL docs to
> find out how to do that.

+1.  You need to enable the FIPS provider in openssl.conf and make sure to
disable the legacy provider.  The builtin_crypto_enabled setting simply makes
sure to never call non-FIPS certified crypto when OpenSSL is operating in fips
mode, you can also set it to 'off' and disallow non-FIPS certified crypto
regardless.

--
Daniel Gustafsson







pgsql-general by date:

Previous
From: Joe Conway
Date:
Subject: Re: PostgreSQL 18 FIPS mode in Windows
Next
From: Daniel Gustafsson
Date:
Subject: Re: PostgreSQL 18 FIPS mode in Windows