> On 24 Sep 2026, at 22:13, Tom Lane <[email protected]> wrote:
> 
> sutyak <[email protected]> writes:
>> The steps I have already taken are:
> 
>> - Install PostgreSQL 18.6 windows-x64
>> - Install OpenSSL 3.5.8 with FIPS Provider 3.1.2
>> - Enable pgcrypto extension via pgAdmin
>> - set builtin_crypto_enabled to 'fips'
>> - Executing SELECT fips_mode(); always returns false.
>> - Verified FIPS is not being enforced by executing SELECT 
>> encode(digest('test', 'md5'), 'hex'); and it always returns a value.
> 
>> What am I missing? Thank you,
> 
> 'builtin_crypto_enabled = fips' merely tells pgcrypto to expect
> failure of relevant calls.  It does not cause OpenSSL to actually
> go into FIPS mode.  You'd have to consult the OpenSSL docs to
> find out how to do that.

+1.  You need to enable the FIPS provider in openssl.conf and make sure to
disable the legacy provider.  The builtin_crypto_enabled setting simply makes
sure to never call non-FIPS certified crypto when OpenSSL is operating in fips
mode, you can also set it to 'off' and disallow non-FIPS certified crypto
regardless.

--
Daniel Gustafsson



Reply via email to