# Elastic search v8.18.2 fails to boot up in FIPS mode because of MD5 invocation in ESQL plugin

**URL:** https://discuss.elastic.co/t/elastic-search-v8-18-2-fails-to-boot-up-in-fips-mode-because-of-md5-invocation-in-esql-plugin/379118
**Category:** Elasticsearch
**Tags:** esql
**Created:** [June 12, 2025, 4:55am UTC](https://discuss.elastic.co/t/elastic-search-v8-18-2-fails-to-boot-up-in-fips-mode-because-of-md5-invocation-in-esql-plugin/379118 "2025-06-12T04:55:03Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![k.rajendran](https://avatars.discourse-cdn.com/v4/letter/k/e480ec/32.png) [@k.rajendran](https://discuss.elastic.co/u/k.rajendran)
#### Post date: [June 12, 2025, 4:55am UTC](https://discuss.elastic.co/t/elastic-search-v8-18-2-fails-to-boot-up-in-fips-mode-because-of-md5-invocation-in-esql-plugin/379118/1 "2025-06-12T04:55:04Z")

</div>

I am trying to upgrade our Elasticsearch FIPS enabled cluster from v8.17.4 to 8.18.2. When I tried doing this the initialization failed with this error:

```auto
[2025-06-09T20:46:40,119][ERROR][o.e.b.Elasticsearch][elasticsearch-data-2.gce-lma-01a] fatal exception while booting Elasticsearch
java.lang.ExceptionInInitializerError: null
at org.elasticsearch.xpack.esql.expression.function.scalar.ScalarFunctionWritables.getNamedWriteables(ScalarFunctionWritables.java:87) ~[?:?]
at org.elasticsearch.xpack.esql.expression.ExpressionWritables.scalars(ExpressionWritables.java:143) ~[?:?]
at org.elasticsearch.xpack.esql.expression.ExpressionWritables.getNamedWriteables(ExpressionWritables.java:99) ~[?:?]
at org.elasticsearch.xpack.esql.plugin.EsqlPlugin.getNamedWriteables(EsqlPlugin.java:203) ~[?:?]
at org.elasticsearch.plugins.PluginsService.lambda$flatMap$0(PluginsService.java:186) ~[elasticsearch-8.18.2.jar:?]
at java.util.stream.ReferencePipeline$7$1.accept(ReferencePipeline.java:273) ~[?:?]
at java.util.stream.ReferencePipeline$3$1.accept(ReferencePipeline.java:197) ~[?:?]
at java.util.AbstractList$RandomAccessSpliterator.forEachRemaining(AbstractList.java:720) ~[?:?]
at java.util.stream.AbstractPipeline.copyInto(AbstractPipeline.java:509) ~[?:?]
at java.util.stream.AbstractPipeline.wrapAndCopyInto(AbstractPipeline.java:499) ~[?:?]
at java.util.stream.ForEachOps$ForEachOp.evaluateSequential(ForEachOps.java:150) ~[?:?]
at java.util.stream.ForEachOps$ForEachOp$OfRef.evaluateSequential(ForEachOps.java:173) ~[?:?]
at java.util.stream.AbstractPipeline.evaluate(AbstractPipeline.java:234) ~[?:?]
at java.util.stream.ReferencePipeline.forEach(ReferencePipeline.java:596) ~[?:?]
at java.util.stream.ReferencePipeline$7$1.accept(ReferencePipeline.java:276) ~[?:?]
at java.util.Spliterators$ArraySpliterator.forEachRemaining(Spliterators.java:992) ~[?:?]
at java.util.stream.AbstractPipeline.copyInto(AbstractPipeline.java:509) ~[?:?]
at java.util.stream.AbstractPipeline.wrapAndCopyInto(AbstractPipeline.java:499) ~[?:?]
at java.util.stream.AbstractPipeline.evaluate(AbstractPipeline.java:575) ~[?:?]
at java.util.stream.AbstractPipeline.evaluateToArrayNode(AbstractPipeline.java:260) ~[?:?]
at java.util.stream.ReferencePipeline.toArray(ReferencePipeline.java:616) ~[?:?]
at java.util.stream.ReferencePipeline.toArray(ReferencePipeline.java:622) ~[?:?]
at java.util.stream.ReferencePipeline.toList(ReferencePipeline.java:627) ~[?:?]
at org.elasticsearch.node.NodeConstruction.createClientAndRegistries(NodeConstruction.java:592) ~[elasticsearch-8.18.2.jar:?]
at org.elasticsearch.node.NodeConstruction.prepareConstruction(NodeConstruction.java:288) ~[elasticsearch-8.18.2.jar:?]
at org.elasticsearch.node.Node.(Node.java:201) ~[elasticsearch-8.18.2.jar:?]
at org.elasticsearch.bootstrap.Elasticsearch$2.(Elasticsearch.java:385) ~[elasticsearch-8.18.2.jar:?]
at org.elasticsearch.bootstrap.Elasticsearch.initPhase3(Elasticsearch.java:385) ~[elasticsearch-8.18.2.jar:?]
at org.elasticsearch.bootstrap.Elasticsearch.main(Elasticsearch.java:97) ~[elasticsearch-8.18.2.jar:?]
Caused by: java.lang.IllegalStateException: java.security.NoSuchAlgorithmException: MD5 MessageDigest not available
at org.elasticsearch.xpack.esql.expression.function.scalar.string.Hash$HashFunction.create(Hash.java:196) ~[?:?]
at org.elasticsearch.xpack.esql.expression.function.scalar.string.Md5.(Md5.java:27) ~[?:?]
... 29 more
Caused by: java.security.NoSuchAlgorithmException: MD5 MessageDigest not available
at sun.security.jca.GetInstance.getInstance(GetInstance.java:159) ~[?:?]
at java.security.MessageDigest.getInstance(MessageDigest.java:185) ~[?:?]
at org.elasticsearch.xpack.esql.expression.function.scalar.string.Hash$HashFunction.create(Hash.java:193) ~[?:?]
at org.elasticsearch.xpack.esql.expression.function.scalar.string.Md5.(Md5.java:27) ~[?:?]
... 29 more

```

I can see that this MD5 hash was added in v8.18.0 as part of the ESQL plugin ([https://github.com/elastic/elasticsearch/blob/v8.18.0/x-pack/plugin/esql/src/main/java/org/elasticsearch/xpack/esql/expression/function/scalar/ScalarFunctionWritables.java#L87(external, opens in a new tab or window)](https://github.com/elastic/elasticsearch/blob/v8.18.0/x-pack/plugin/esql/src/main/java/org/elasticsearch/xpack/esql/expression/function/scalar/ScalarFunctionWritables.java#L87)). Since our JVM has disabled MD5 to be FIPS compliant how do we go about with this upgrade and still maintain FIPS compliance?

JVM used: OpenJDK 17, Bouncy castle jar version: 1.0.2.5

---

<div class="post-metadata">

### Author: ![RainTown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raintown/32/140206_2.png) [@RainTown](https://discuss.elastic.co/u/RainTown)
#### Post date: [June 20, 2025, 9:46pm UTC](https://discuss.elastic.co/t/elastic-search-v8-18-2-fails-to-boot-up-in-fips-mode-because-of-md5-invocation-in-esql-plugin/379118/2 "2025-06-20T21:46:40Z")

</div>

@k.rajendran

Did you find a way to resolve this ? (Just curious).

---

<div class="post-metadata">

### Author: ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)
#### Post date: [June 23, 2025, 8:52am UTC](https://discuss.elastic.co/t/elastic-search-v8-18-2-fails-to-boot-up-in-fips-mode-because-of-md5-invocation-in-esql-plugin/379118/3 "2025-06-23T08:52:22Z")

</div>

This is a known issue, it's probabkly best to remain on 8.17.4 until it's fixed:

> <https://github.com/elastic/elasticsearch/issues/129689>
>
> MD5 should not be used in a FIPS mode JVM, \_except\_ for in certain older TLS cip…hers that depend on it.
> 
> Because those TLS ciphers may need it, it technically works (at least in FIPS 140-2) but is not compliant.
> 
> Some FIPS-mode deployments may configure the JVM to disable MD5 entirely (because they do not need or enabled those older ciphers).
> 
> We have two options, either:
> 1. Check FIPS mode and disable MD5. This should be possible because the FIPS setting is in X-Pack core, and the \`esql\` module already depends on that.
> 2. Just check for an error when loading the MD5 \`MessageDigest\` and disable the function.
> 
> The former would mean ES|QL's MD5 was strictly unavailable in FIPS mode. The latter would mean that we allow anyone to turn of MD5 if they wish.
> 
> I think I would be happy with either or both.
> 
> Relates: https://github.com/elastic/elasticsearch/pull/118938

---

<div class="post-metadata">

### Author: ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)
#### Post date: [June 24, 2025, 2:42am UTC](https://discuss.elastic.co/t/elastic-search-v8-18-2-fails-to-boot-up-in-fips-mode-because-of-md5-invocation-in-esql-plugin/379118/4 "2025-06-24T02:42:22Z")

</div>

It's a bit more nuanced than that public issue describes.

The existence of an MD5 function in ES|QL should not stop a node from starting on a FIPS JVM - and it doesn't cause a problem in our testing.

The behaviour of MD5 in BC-FIPS is a little peculiar because the FIPS 140-2 standard had to make some compromises to maintain compatibility with commonly used (at the time) TLS ciphers that depend on MD5.

You shouldn't use MD5 for anything security related (whether you're on FIPS or not) because it is less secure and typically less performant than other available hashes, and we want to make it possible to exclude it from your Elasticsearch nodes if you so desire. However, so far we've been unable to reproduce the behaviour described in this thread.

Always test your upgrades (and let us know if you run into problems), but I do not expect this particular issue (whatever the specific details might be to trigger it) to prevent upgrades for typical FIPS deployments.
