Re: Allow tests to pass in OpenSSL FIPS mode

From: Peter Eisentraut <peter(dot)eisentraut(at)enterprisedb(dot)com>
To: pgsql-hackers <pgsql-hackers(at)postgresql(dot)org>
Subject: Re: Allow tests to pass in OpenSSL FIPS mode
Date: 2022-10-11 11:51:50
Message-ID: 647f6cc1-473d-f788-ade0-c09201e5ab6a@enterprisedb.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

On 04.10.22 17:45, Peter Eisentraut wrote:
> While working on the column encryption patch, I wanted to check that
> what is implemented also works in OpenSSL FIPS mode.  I tried running
> the normal test suites after switching the OpenSSL installation to FIPS
> mode, but that failed all over the place.  So I embarked on fixing that.

> Of course, there are some some tests where we do want to test MD5
> functionality, such as in the authentication tests or in the tests of
> the md5() function itself.  I think we can conditionalize these somehow.

Let's make a small start on this. The attached patch moves the tests of
the md5() function to a separate test file. That would ultimately make
it easier to maintain a variant expected file for FIPS mode where that
function will fail (similar to how we have done it for the pgcrypto tests).

Attachment Content-Type Size
0001-Put-tests-of-md5-function-into-separate-test-file.patch text/plain 9.5 KB

In response to

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message jiye 2022-10-11 12:31:53 Re:Re: Is there any plan to support online schem change in postgresql?
Previous Message Bharath Rupireddy 2022-10-11 11:06:34 Re: ps command does not show walsender's connected db