On 9/24/26 16:16, Daniel Gustafsson wrote:
On 24 Sep 2026, at 22:13, Tom Lane <[email protected]> wrote:
sutyak <[email protected]> writes:
The steps I have already taken are:
- Install PostgreSQL 18.6 windows-x64
- Install OpenSSL 3.5.8 with FIPS Provider 3.1.2
- Enable pgcrypto extension via pgAdmin
- set builtin_crypto_enabled to 'fips'
- Executing SELECT fips_mode(); always returns false.
- Verified FIPS is not being enforced by executing SELECT encode(digest('test',
'md5'), 'hex'); and it always returns a value.
What am I missing? Thank you,
'builtin_crypto_enabled = fips' merely tells pgcrypto to expect
failure of relevant calls. It does not cause OpenSSL to actually
go into FIPS mode. You'd have to consult the OpenSSL docs to
find out how to do that.
+1. You need to enable the FIPS provider in openssl.conf and make sure to
disable the legacy provider. The builtin_crypto_enabled setting simply makes
sure to never call non-FIPS certified crypto when OpenSSL is operating in fips
mode, you can also set it to 'off' and disallow non-FIPS certified crypto
regardless.
Also to be clear, the distributor of the openssl library used must get
their specific bits validated in order to be actually FIPS compliant if
compliance is what you are after.
--
Joe Conway
PostgreSQL Contributors Team
Amazon Web Services: https://aws.amazon.com