http://www.va.gov/TRM/ToolPage.asp?tid=5692&tab=2
contrast that with Oracle:
http://www.va.gov/TRM/ToolPage.asp?tid=9&tab=2
(Don't miss the difference in tone on the "Analysis" tabs.)
I'm sure some of that is due to lobbyists, but nonetheless it seems to me that there are legitimate challenges in making Postgres meet FIPS 140-2 requirements. I've been able to recompile Postgres to use the FIPS OpenSSL wrapper, but storing passwords with MD5 is a harder issue to fix, and of course there is no definitive list. Does anyone have some experience with this?