> On 24 Sep 2026, at 22:13, Tom Lane <[email protected]> wrote: > > sutyak <[email protected]> writes: >> The steps I have already taken are: > >> - Install PostgreSQL 18.6 windows-x64 >> - Install OpenSSL 3.5.8 with FIPS Provider 3.1.2 >> - Enable pgcrypto extension via pgAdmin >> - set builtin_crypto_enabled to 'fips' >> - Executing SELECT fips_mode(); always returns false. >> - Verified FIPS is not being enforced by executing SELECT >> encode(digest('test', 'md5'), 'hex'); and it always returns a value. > >> What am I missing? Thank you, > > 'builtin_crypto_enabled = fips' merely tells pgcrypto to expect > failure of relevant calls. It does not cause OpenSSL to actually > go into FIPS mode. You'd have to consult the OpenSSL docs to > find out how to do that.
+1. You need to enable the FIPS provider in openssl.conf and make sure to disable the legacy provider. The builtin_crypto_enabled setting simply makes sure to never call non-FIPS certified crypto when OpenSSL is operating in fips mode, you can also set it to 'off' and disallow non-FIPS certified crypto regardless. -- Daniel Gustafsson
