Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.98.2) (envelope-from ) id 1x9por-00000002Fec-31xO for pgsql-general@arkaria.postgresql.org; Thu, 24 Sep 2026 20:13:25 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.98.2) (envelope-from ) id 1x9poq-0000000ESlI-3h8A for pgsql-general@arkaria.postgresql.org; Thu, 24 Sep 2026 20:13:24 +0000 Received: from magus.postgresql.org ([2a02:c0:301:0:ffff::29]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.98.2) (envelope-from ) id 1x9poq-0000000ESlA-2NWL for pgsql-general@lists.postgresql.org; Thu, 24 Sep 2026 20:13:24 +0000 Received: from sss.pgh.pa.us ([68.162.161.243]) by magus.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.98.2) (envelope-from ) id 1x9poo-000000017bO-1fEd for pgsql-general@lists.postgresql.org; Thu, 24 Sep 2026 20:13:24 +0000 Received: from sss1.sss.pgh.pa.us (localhost [127.0.0.1]) by sss.pgh.pa.us (8.18.1/8.18.1) with ESMTP id 68OKDL2e1814990; Thu, 24 Sep 2026 16:13:21 -0400 From: Tom Lane To: sutyak cc: "pgsql-general@lists.postgresql.org" Subject: Re: PostgreSQL 18 FIPS mode in Windows In-reply-to: <13DyT-dt7PRebAXIz_sNbi_b620YX_uKUa-PhyJeyx2wAEV_R-ECdopU7jCioVHbhQx_oG-Ne18GP2CJEnVYRLsvMenSM5QN23gssgsYuoU=@proton.me> References: <13DyT-dt7PRebAXIz_sNbi_b620YX_uKUa-PhyJeyx2wAEV_R-ECdopU7jCioVHbhQx_oG-Ne18GP2CJEnVYRLsvMenSM5QN23gssgsYuoU=@proton.me> Comments: In-reply-to sutyak message dated "Thu, 24 Sep 2026 20:07:48 -0000" MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-ID: <1814988.1790280801.1@sss.pgh.pa.us> Content-Transfer-Encoding: quoted-printable Date: Thu, 24 Sep 2026 16:13:21 -0400 Message-ID: <1814989.1790280801@sss.pgh.pa.us> List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk sutyak writes: > The steps I have already taken are: > - Install PostgreSQL 18.6 windows-x64 > - Install OpenSSL 3.5.8 with FIPS Provider 3.1.2 > - Enable pgcrypto extension via pgAdmin > - set builtin_crypto_enabled to 'fips' > - Executing SELECT fips_mode(); always returns false. > - Verified FIPS is not being enforced by executing SELECT encode(digest(= 'test', 'md5'), 'hex'); and it always returns a value. > What am I missing? Thank you, 'builtin_crypto_enabled =3D fips' merely tells pgcrypto to expect failure of relevant calls. It does not cause OpenSSL to actually go into FIPS mode. You'd have to consult the OpenSSL docs to find out how to do that. regards, tom lane