{"record":{"id":"8328c16c62768d8b","repo":"mongodb/node-mongodb-native","slug":"auth-mechanism-scram-sha-1-is-not-supported-in-fip","errorCode":null,"errorMessage":"Auth mechanism SCRAM-SHA-1 is not supported in FIPS mode","messagePattern":"Auth mechanism SCRAM-SHA-1 is not supported in FIPS mode","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"src/cmap/auth/scram.ts","lineNumber":252,"sourceCode":"    nodeCrypto = require('crypto');\n  } catch (e) {\n    throw new MongoRuntimeError(\n      'Node.js crypto module is required for SCRAM-SHA-1 authentication',\n      {\n        cause: e\n      }\n    );\n  }\n\n  try {\n    const md5 = nodeCrypto.createHash('md5');\n    md5.update(`${username}:mongo:${password}`, 'utf8');\n    return md5.digest('hex');\n  } catch (err) {\n    if (nodeCrypto.getFips()) {\n      // This error is (slightly) more helpful than what comes from OpenSSL directly, e.g.\n      // 'Error: error:060800C8:digital envelope routines:EVP_DigestInit_ex:disabled for FIPS'\n      throw new Error('Auth mechanism SCRAM-SHA-1 is not supported in FIPS mode');\n    }\n    throw err;\n  }\n}\n\n// XOR two buffers\nfunction xor(a: Uint8Array, b: Uint8Array) {\n  const length = Math.max(a.length, b.length);\n  const res = [];\n\n  for (let i = 0; i < length; i += 1) {\n    res.push(a[i] ^ b[i]);\n  }\n\n  return ByteUtils.toBase64(ByteUtils.fromNumberArray(res));\n}\n\nasync function H(method: CryptoMethod, text: Uint8Array): Promise<Uint8Array> {","sourceCodeStart":234,"sourceCodeEnd":270,"githubUrl":"https://github.com/mongodb/node-mongodb-native/blob/dce7939f86fb283e167ad709955abedb7bf23124/src/cmap/auth/scram.ts#L234-L270","documentation":"Thrown as a plain Error (not a Mongo error subclass) when the MD5 digest inside passwordDigest() fails AND nodeCrypto.getFips() returns true. MD5 is not FIPS-140 approved, so OpenSSL refuses to create the hash in FIPS mode. This provides a clearer message than the raw OpenSSL error ('digital envelope routines:EVP_DigestInit_ex:disabled for FIPS').","triggerScenarios":"Authenticating with SCRAM-SHA-1 while the Node.js process is running with FIPS mode enabled (Node started with --enable-fips, or crypto.setFips(true), or a FIPS-validated Node build). The driver calls createHash('md5') which throws under FIPS, caught and rethrown as this message.","commonSituations":"Compliance-regulated environments (government, finance, healthcare) that mandate FIPS 140-2/3; containers built on RHEL with FIPS kernel mode enabled; CI pipelines that enable FIPS for security scanning.","solutions":["Switch to SCRAM-SHA-256 (authMechanism=SCRAM-SHA-256), which uses SHA-256 and PBKDF2 — both FIPS-approved","Use MONGODB-X509 or GSSAPI (Kerberos) authentication which avoid MD5 entirely","Disable FIPS mode on the Node process only if your compliance posture permits it"],"exampleFix":"// before\nconst client = new MongoClient('mongodb://user:pass@host/db?authMechanism=SCRAM-SHA-1');\n\n// after\nconst client = new MongoClient('mongodb://user:pass@host/db?authMechanism=SCRAM-SHA-256');","handlingStrategy":"validation","validationCode":"import { getFips } from 'crypto';\nif (getFips() && /authMechanism=SCRAM-SHA-1/.test(uri)) {\n  throw new Error('SCRAM-SHA-1 (MD5) is unavailable in FIPS mode; use SCRAM-SHA-256');\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["In FIPS-regulated environments, always use SCRAM-SHA-256 or X.509/Kerberos","Do not set authMechanism=SCRAM-SHA-1 in shared config that may run under FIPS","Document the FIPS incompatibility of MD5-based SCRAM-SHA-1 in your runbook"],"tags":["authentication","scram","fips","compliance","crypto"],"backgroundTag":null,"analyzedSha":"dce7939f86fb283e167ad709955abedb7bf23124","analyzedAt":"2026-08-11T04:54:53.215Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}