PostgreSQL fails to start after upgrade when SSL is enabled
This issue may occur only when upgrading MetaDefender Core from a version prior to 5.22.0 to version 5.22.0 or later, on deployments where SSL is enabled for the bundled PostgreSQL database.
It can be resolved with a configuration change, and no re-installation is required.
Overview
After upgrading MetaDefender Core from a version earlier than 5.22.0 to 5.22.0 or later, the bundled PostgreSQL service may fail to start if SSL was previously enabled for it without an ssl_groups setting. MetaDefender Core then cannot reach its database.
This applies only to standalone deployments that use the bundled PostgreSQL.
Symptoms
The upgrade completes and the package reports as installed, but the Web Console is not usable after the upgrade
Sign-in requests fail with HTTP
500, whileGET /versionstill answers with the new versionThe MetaDefender Core log contains the following errors:
[ERROR ] (core.postgres) Postgres issue, error='Starting postgres service failed', param='pg_ctl: could not start serverExamine the log output.'[ERROR ] (core.postgres) Postgres issue, error='Failed to restart PostgreSQL under FIPS after cluster upgrade'[ERROR ] (common.base) Unhandled internal exception occurred in a slot, message='Failed to re-engage FIPS for the bundled PostgreSQL after cluster upgradeStarting PostgreSQL manually reports the following error:
FATAL: could not set group names specified in ssl_groups: No valid groups foundHINT: Ensure that each group name is spelled correctly and supported by the installed version of OpenSSL.
Root Cause
From MetaDefender Core 5.22.0, the bundled PostgreSQL ships with a FIPS 140-3 validated OpenSSL module, and non-approved algorithms such as X25519 are not available to the database server. The PostgreSQL default for ssl_groups is X25519:prime256v1, so a PostgreSQL SSL configuration that does not set ssl_groups makes the service fail to start.
SSL configurations created for earlier versions do not contain ssl_groups. The upgrade keeps that configuration file, and PostgreSQL fails to start with it when the upgrade restarts the database.
Solution
Open the PostgreSQL SSL configuration file (the file that contains
ssl = on) in the PostgreSQL folder:Windows:
<installation folder>/postgres/Linux:
/usr/lib/ometascan/postgres/
Correct the setting named in the error:
ssl_groups: set a FIPS-approved group
For example:ssl = onssl_groups = 'prime256v1'ssl_ciphers = 'HIGH:MEDIUM:+3DES:!aNULL'ssl_prefer_server_ciphers = onssl_cert_file = '<absolute_path_to_cert_file>'ssl_key_file = '<absolute_path_to_key_file>'ssl_ca_file = '<absolute_path_to_root_ca_cert_file>'
Restart the MetaDefender Core service:
# Use systemctlsystemctl restart ometascan# Or use serviceservice ometascan restart