Re: [EXTERNAL] Re: Java client connection problem on FIPS enabled hosts (with password_encryption = scram-sha-256)

Поиск
Список
Период
Сортировка
От Rob Sargent
Тема Re: [EXTERNAL] Re: Java client connection problem on FIPS enabled hosts (with password_encryption = scram-sha-256)
Дата
Msg-id 2f32386c-01dd-380a-7814-e44c65525a36@gmail.com
обсуждение исходный текст
Ответ на RE: [EXTERNAL] Re: Java client connection problem on FIPS enabled hosts (with password_encryption = scram-sha-256)  ("McDermott, Becky" <bmcderm@sandia.gov>)
Список pgsql-jdbc
On 3/22/22 10:36, McDermott, Becky wrote:
@font-face {font-family:"Cambria Math"; panose-1:2 4 5 3 5 4 6 3 2 4;}@font-face {font-family:Calibri; panose-1:2 15 5 2 2 2 4 3 2 4;}p.MsoNormal, li.MsoNormal, div.MsoNormal {margin:0in; font-size:11.0pt; font-family:"Calibri",sans-serif;}span.EmailStyle18 {mso-style-type:personal-reply; font-family:"Calibri",sans-serif; color:windowtext;}.MsoChpDefault {mso-style-type:export-only; font-size:10.0pt;}div.WordSection1 {page:WordSection1;}

Probably not right away.  Getting this fixed/working will not get prioritized on the development side for a few weeks.  I was tasked with confirming that we don’t have a platform side problem which I did by confirming I can connect to postgresql using psql on a FIPS enabled host.

 

I was hoping that maybe there was something simple like the version of postgres or the jdbc driver but it sounds like it may be more than that.

 

Once our developers are tasked with actively looking into this, I will re-post.  I do know that we were using MD5 and switched to scram-sha-256 fairly recently (maybe 6 months ago).  But, up until really recently, we were not running on a FIPS enabled host.  Since FIPS is now enabled, the cryptography enforcement is actually occurring and we are seeing this problem.

 

Thank you,

Becky

Well there's still a chance someone on the list may have useful input.  If/when you return, please keep in mind that this list prefers "bottom-posting", i.e. (trimming and) adding your comments at the bottom, or where more appropriate adding comments in-line.

В списке pgsql-jdbc по дате отправления:

Предыдущее
От: "McDermott, Becky"
Дата:
Сообщение: RE: [EXTERNAL] Re: Java client connection problem on FIPS enabled hosts (with password_encryption = scram-sha-256)
Следующее
От: Michael Paquier
Дата:
Сообщение: Re: Java client connection problem on FIPS enabled hosts (with password_encryption = scram-sha-256)