Supported cryptographic modules by operation
Software Trust Manager uses NIST Cryptographic Module Validation Program (CMVP)-validated modules for the cryptographic operations that protect federal customer data, broken out by the flow that uses each module.
Module | Version | CMVP certificate | Software Trust Manager operation |
|---|---|---|---|
BC-FIPS (Bouncy Castle FIPS JCA/JCE provider) | bc-fips 2.1.0 | [Certificate number and link] | Keypair generation |
BC-FIPS PKIX (Bouncy Castle FIPS PKIX provider) | bcpkix-fips 2.1.9 | [Certificate number and link] | Certificate generation and certificate signing |
BC-FIPS (Bouncy Castle FIPS JCA/JCE provider) | bc-fips 2.1.0 | [Certificate number and link] | Signing activity (hash/data signing requests forwarded for signature) |
BC-FIPS Util (Bouncy Castle FIPS utility/ASN.1 module) | bcutil-fips 2.1.4 | [Certificate number and link] | Supporting ASN.1 and certificate-encoding operations for certificate generation and signing |
BC-FIPS JSSE (Bouncy Castle FIPS JSSE provider) | Bundled with bc-fips 2.1.0 | [Certificate number and link] | TLS connections to Software Trust Manager endpoints |