Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1krF37-0002rW-Ag for pgadmin-hackers@arkaria.postgresql.org; Mon, 21 Dec 2020 06:52:05 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.92) (envelope-from ) id 1krF35-0005Sp-BV for pgadmin-hackers@arkaria.postgresql.org; Mon, 21 Dec 2020 06:52:03 +0000 Received: from magus.postgresql.org ([2a02:c0:301:0:ffff::29]) by malur.postgresql.org with esmtps (TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1krF35-0005Si-27 for pgadmin-hackers@lists.postgresql.org; Mon, 21 Dec 2020 06:52:03 +0000 Received: from mail-lf1-x133.google.com ([2a00:1450:4864:20::133]) by magus.postgresql.org with esmtps (TLS1.3:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.92) (envelope-from ) id 1krF30-0001z7-Qc for pgadmin-hackers@lists.postgresql.org; Mon, 21 Dec 2020 06:52:02 +0000 Received: by mail-lf1-x133.google.com with SMTP id a12so21120951lfl.6 for ; Sun, 20 Dec 2020 22:51:58 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=enterprisedb-com.20150623.gappssmtp.com; s=20150623; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=GMmBsd6GA6Xc/5j1VjuDm/XHwLpggTrBX1TSZPDydhk=; b=A5QbIOxx0iP2049SizpQ+UpXkwlntdt1VzxaN/wi0Ue6I7ydZgxkfrXe4d9LCtaygg 9nuG1J6ZA43wPH6Or9kkPqpGTNnOPFGPJGOTtyIwi4DX53fuLlHhfvOtputMU8pEv0zu Gf4adRT/Y/sDsQjiL13ZvfTIblR0jjIvTZUxCla+/Hw5aquswZvLRQkCaYKdmGVFxaXA X2unMuszK1ipdC07RHEX+QlAIR4Lv7ym0p4jWtW1aFxo26yPAAXbveNq9vMQM3O048QE 0jFuBQak7muD1Y6drqDj/1OsN63aRhNx9U5IuufHuhuwpyfGygAqIazLZ8zw4qOZX8b5 +s0g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=GMmBsd6GA6Xc/5j1VjuDm/XHwLpggTrBX1TSZPDydhk=; b=TmzpaHe59uBptadj2ZSVPDhz8FqdRvrNJgCx3hxm8eIcNGM6vgKBXHGfyy0YVvav3M tTa0RaS2wTUNroAxNi5T53IaOEe/z70pCmWTRxSwk+JCXPecJxivyIEj8P6OsQvJwd4d ylyKUwPVB8bmBgFYD7sGvDF8fnbndZQ3GvZNjX0Hdq3jyto2d8vIDInTclb5u72WO9Jy 5Xjh8x3MueizVX/yuJ1iofk0+WVftja5868/9I7E/IH7X0L1Obs++qBmuZMrqc3m3ETT PFsvOBKSus3J6ksjkm85axUDkdtuZMEtWe6BhwCX6S9o1BWg4qxTbMz8I35+PCWyAhEe /mFQ== X-Gm-Message-State: AOAM531JfuZtQKIvRgzN4N/JX6evbyzioEiR7nUO6sW+bc8VfbdgmggZ h8n9ey7CrPkndzahVrmroFVxfvLdhFGXALex1e1KkxrFdjCryWJyVBjMSip9Cu/SZt69tplle9x 3F48LaCx9GzA0U5DRaAUNBzf0xoOqZkhsKHG6xiAcAUpvbxL3jC0Zah9MEP5B6lyhhmCA0BasD1 8A8Psv3135Q8pCKZ/TY60SNcqtlNASNV4vSbNj1T9bKQzd5eN+NVekTkmut9j+1MX7nfwXL0uTv A== X-Google-Smtp-Source: ABdhPJyUMk3ocIv2qXtFlKXyCJoUiNAE59bjt5ssVcmT4hAtrBCcmH4FPM0KjzOpgE3pWdSbqffwyYlOHD1tQKTkPt4= X-Received: by 2002:ac2:5689:: with SMTP id 9mr6251472lfr.175.1608533517174; Sun, 20 Dec 2020 22:51:57 -0800 (PST) MIME-Version: 1.0 References: <1428186f1afb4f84b103851054d59616@XCGVAG24.northgrum.com> In-Reply-To: <1428186f1afb4f84b103851054d59616@XCGVAG24.northgrum.com> From: Aditya Toshniwal Date: Mon, 21 Dec 2020 12:21:21 +0530 Message-ID: Subject: Re: Red Hat 7.9 FIPS 140-2 issue pgAdmin 4.27 To: "Watson, Karen L [US] (MS)" Cc: "pgadmin-hackers@lists.postgresql.org" Content-Type: multipart/alternative; boundary="000000000000e6a1e805b6f3e49e" X-CLOUD-SEC-AV-Info: enterprisedb,google_mail,monitor X-CLOUD-SEC-AV-Sent: true X-Gm-Spam: 0 X-Gm-Phishy: 0 List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Precedence: bulk --000000000000e6a1e805b6f3e49e Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Hi Karen, pgAdmin is not tested in fips 140-2. No one reported such an issue, so we were not aware of it. You can log the feature request here - https://redmine.postgresql.org/projects/pgadmin4/issues/new so that we can discuss and work on it. On Sat, Dec 19, 2020 at 12:46 AM Watson, Karen L [US] (MS) < karen.watson@ngc.com> wrote: > If this is the wrong list please direct me to where I need to post this > question. > > > > I=E2=80=99m working for a customer that requires fips 140-2 be turned on = at the > operating system level. The server is Red Hat 7.9 and is using python > 3.6.8. > > I=E2=80=99m trying to install pgAdmin 4.27 in server mode. > > > > When running setup.py after being prompted for the email address and > password for the initial pgAdmin user I get an error message > EVP_DigestInit_ex:disabled for fips. I can provide a more detailed messa= ge > when I=E2=80=99m onsite next week at the customer site if needed. > > > > I have searched the lists and the internet but have not found much > information. A few posts where individuals were having a problem but no > answers if pgAdmin will work on a fips 140-2 linux system. > > > > We had attempted to install pgAdmin a year ago on a fips 140-2 enabled Re= d > Hat OS and found out pgAdmin uses md5 and would not work when logging in > via the web login. We were hoping this had been fixed since there are > customers that require the enablement of fips 140-2 on their servers. > > > > 1) So can someone tell me if pgAdmin will work on a Red Hat 7 server > when the operating system is in fips 140-2? Yes/No > > 2) If no, is there somewhere in the python code for pgAdmin we can > update to get pgAdmin to work when the operating system is in fips 140-2? > Yes/No > > 3) If the answers to the above two questions are =E2=80=9CNo=E2=80= =9D does anyone > have any recommendations for client software that developers can use from > Window PCs to access the postgres database? > > > > Thank you in advance for any help with this. > --=20 Thanks, Aditya Toshniwal pgAdmin hacker | Sr. Software Engineer | *edbpostgres.com* "Don't Complain about Heat, Plant a TREE" --000000000000e6a1e805b6f3e49e Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable
Hi Karen,

pgAdmin is not tested in fips 140-2. No one repo= rted such an issue, so we were not aware of it.

If this is the wrong list please direct me to where = I need to post this question.

=C2=A0

I=E2=80=99m working for a customer that requires fip= s 140-2 be turned on at the operating system level.=C2=A0 The server is Red= Hat 7.9 and is using python 3.6.8.

I=E2=80=99m trying to install pgAdmin 4.27 in server= mode.

=C2=A0

When running setup.py after being prompted for the e= mail address and password for the initial pgAdmin user I get an error messa= ge EVP_DigestInit_ex:disabled for fips.=C2=A0 I can provide a more detailed= message when I=E2=80=99m onsite next week at the customer site if needed.

=C2=A0

I have searched the lists and the internet but have = not found much information.=C2=A0 A few posts where individuals were having= a problem but no answers if pgAdmin will work on a fips 140-2 linux system= .=C2=A0

=C2=A0

We had attempted to install pgAdmin a year ago on a = fips 140-2 enabled Red Hat OS and found out pgAdmin uses md5 and would not = work when logging in via the web login.=C2=A0 We were hoping this had been = fixed since there are customers that require the enablement of fips 140-2 on their servers.

=C2=A0

1)=C2=A0=C2=A0=C2=A0=C2=A0= =C2=A0 So can someone tell me if pgAdmin will work on a Red H= at 7 server when the operating system is in fips 140-2?=C2=A0 Yes/No=

2)=C2=A0=C2=A0=C2=A0=C2=A0= =C2=A0 If no, is there somewhere in the python code for pgAdm= in we can update to get pgAdmin to work when the operating system is in fip= s 140-2?=C2=A0 Yes/No

3)=C2=A0=C2=A0=C2=A0=C2=A0= =C2=A0 If the answers to the above two questions are =E2=80= =9CNo=E2=80=9D does anyone have any recommendations for client software tha= t developers can use from Window PCs to access the postgres database?

=C2=A0

Thank you in advance for any help with this.<= u>



--
Thanks,
Aditya Toshniwal
pgAdmin hacker=C2=A0| Sr. Softwa= re Engineer | edbpostgres.com<= /font>
"Don't Complain about Heat, Plant a TREE&qu= ot;
--000000000000e6a1e805b6f3e49e--