I forgot to mention I did ensure FIPS is the only option enabled in OpenSSL. Verified by running openssl.exe
list-providers.
Mark
Sent from Proton Mail for Android.
-------- Original Message --------
On Thursday, 09/24/26 at 16:17 Daniel Gustafsson <daniel@yesql.se> wrote:
> On 24 Sep 2026, at 22:13, Tom Lane <tgl@sss.pgh.pa.us> wrote:
>
> sutyak <sutyak@proton.me> writes:
>> The steps I have already taken are:
>
>> - Install PostgreSQL 18.6 windows-x64
>> - Install OpenSSL 3.5.8 with FIPS Provider 3.1.2
>> - Enable pgcrypto extension via pgAdmin
>> - set builtin_crypto_enabled to 'fips'
>> - Executing SELECT fips_mode(); always returns false.
>> - Verified FIPS is not being enforced by executing SELECT encode(digest('test', 'md5'), 'hex'); and it always
returnsa value.
>
>> What am I missing? Thank you,
>
> 'builtin_crypto_enabled = fips' merely tells pgcrypto to expect
> failure of relevant calls. It does not cause OpenSSL to actually
> go into FIPS mode. You'd have to consult the OpenSSL docs to
> find out how to do that.
+1. You need to enable the FIPS provider in openssl.conf and make sure to
disable the legacy provider. The builtin_crypto_enabled setting simply makes
sure to never call non-FIPS certified crypto when OpenSSL is operating in fips
mode, you can also set it to 'off' and disallow non-FIPS certified crypto
regardless.
--
Daniel Gustafsson