NIST-approved algorithm list
The algorithms listed in the table above are the ones permitted by the BC-FIPS provider's approved-only mode. Each is drawn from, and used consistently with, the following NIST standards:
Algorithm family | Approved options in this deployment | Governing NIST standard |
|---|---|---|
RSA key generation and signing | RSA, 3072-bit and above; RSA-PSS | FIPS 186-5 (Digital Signature Standard); key-size guidance aligned with SP 800-131A |
ECDSA key generation and signing | P-256, P-384, P-521 | FIPS 186-5; curve parameters per SP 800-186 |
EdDSA key generation and signing | Ed25519 | FIPS 186-5 |
Secure hashing | SHA-256, SHA-384, SHA-512 | FIPS 180-4 (Secure Hash Standard) |
Secure hashing (SHA-3 family) | SHA3-256, SHA3-384, SHA3-512 | FIPS 202 (SHA-3 Standard) |
Symmetric encryption | AES | FIPS 197 (Advanced Encryption Standard) |
Overall cryptographic module validation | BC-FIPS provider modules listed above | FIPS 140-3, validated under the NIST Cryptographic Module Validation Program (CMVP) |
Algorithms, key sizes, and curves outside this list are not selectable anywhere in the FedRAMP deployment — the option is not offered in keypair, certificate, or signing requests.