mongodb/node-mongodb-native · error · Error

Auth mechanism SCRAM-SHA-1 is not supported in FIPS mode

Error message

Auth mechanism SCRAM-SHA-1 is not supported in FIPS mode

What it means

Thrown as a plain Error (not a Mongo error subclass) when the MD5 digest inside passwordDigest() fails AND nodeCrypto.getFips() returns true. MD5 is not FIPS-140 approved, so OpenSSL refuses to create the hash in FIPS mode. This provides a clearer message than the raw OpenSSL error ('digital envelope routines:EVP_DigestInit_ex:disabled for FIPS').

Solutions

  1. Switch to SCRAM-SHA-256 (authMechanism=SCRAM-SHA-256), which uses SHA-256 and PBKDF2 — both FIPS-approved
  2. Use MONGODB-X509 or GSSAPI (Kerberos) authentication which avoid MD5 entirely
  3. Disable FIPS mode on the Node process only if your compliance posture permits it

Example fix

// before
const client = new MongoClient('mongodb://user:pass@host/db?authMechanism=SCRAM-SHA-1');

// after
const client = new MongoClient('mongodb://user:pass@host/db?authMechanism=SCRAM-SHA-256');
Defensive patterns

Strategy: validation

Validate before calling

import { getFips } from 'crypto';
if (getFips() && /authMechanism=SCRAM-SHA-1/.test(uri)) {
  throw new Error('SCRAM-SHA-1 (MD5) is unavailable in FIPS mode; use SCRAM-SHA-256');
}

Prevention

When it happens

Trigger: Authenticating with SCRAM-SHA-1 while the Node.js process is running with FIPS mode enabled (Node started with --enable-fips, or crypto.setFips(true), or a FIPS-validated Node build). The driver calls createHash('md5') which throws under FIPS, caught and rethrown as this message.

Common situations: Compliance-regulated environments (government, finance, healthcare) that mandate FIPS 140-2/3; containers built on RHEL with FIPS kernel mode enabled; CI pipelines that enable FIPS for security scanning.

Related errors


AI-assisted analysis of mongodb/node-mongodb-native@dce7939f86 (2026-08-11). Data as JSON: /api/errors/8328c16c62768d8b. Report an issue: GitHub.

Appendix: source

Thrown at src/cmap/auth/scram.ts:252

    nodeCrypto = require('crypto');
  } catch (e) {
    throw new MongoRuntimeError(
      'Node.js crypto module is required for SCRAM-SHA-1 authentication',
      {
        cause: e
      }
    );
  }

  try {
    const md5 = nodeCrypto.createHash('md5');
    md5.update(`${username}:mongo:${password}`, 'utf8');
    return md5.digest('hex');
  } catch (err) {
    if (nodeCrypto.getFips()) {
      // This error is (slightly) more helpful than what comes from OpenSSL directly, e.g.
      // 'Error: error:060800C8:digital envelope routines:EVP_DigestInit_ex:disabled for FIPS'
      throw new Error('Auth mechanism SCRAM-SHA-1 is not supported in FIPS mode');
    }
    throw err;
  }
}

// XOR two buffers
function xor(a: Uint8Array, b: Uint8Array) {
  const length = Math.max(a.length, b.length);
  const res = [];

  for (let i = 0; i < length; i += 1) {
    res.push(a[i] ^ b[i]);
  }

  return ByteUtils.toBase64(ByteUtils.fromNumberArray(res));
}

async function H(method: CryptoMethod, text: Uint8Array): Promise<Uint8Array> {

View on GitHub (pinned to dce7939f86)