Skip to main content

NIST-approved algorithm list

The algorithms listed in the table above are the ones permitted by the BC-FIPS provider's approved-only mode. Each is drawn from, and used consistently with, the following NIST standards:

Algorithm family

Approved options in this deployment

Governing NIST standard

RSA key generation and signing

RSA, 3072-bit and above; RSA-PSS

FIPS 186-5 (Digital Signature Standard); key-size guidance aligned with SP 800-131A

ECDSA key generation and signing

P-256, P-384, P-521

FIPS 186-5; curve parameters per SP 800-186

EdDSA key generation and signing

Ed25519

FIPS 186-5

Secure hashing

SHA-256, SHA-384, SHA-512

FIPS 180-4 (Secure Hash Standard)

Secure hashing (SHA-3 family)

SHA3-256, SHA3-384, SHA3-512

FIPS 202 (SHA-3 Standard)

Symmetric encryption

AES

FIPS 197 (Advanced Encryption Standard)

Overall cryptographic module validation

BC-FIPS provider modules listed above

FIPS 140-3, validated under the NIST Cryptographic Module Validation Program (CMVP)

Algorithms, key sizes, and curves outside this list are not selectable anywhere in the FedRAMP deployment — the option is not offered in keypair, certificate, or signing requests.