Skip to main content

Understand the BC-FIPS cryptographic provider

Software Trust Manager registers the Bouncy Castle FIPS Java API (BC-FIPS) as the sole cryptographic provider in the FedRAMP deployment. Standard (non-FIPS) Bouncy Castle and any other JCA/JCE/JSSE provider are removed from the Java security provider list at startup, so only the validated provider chain below can perform key generation, certificate issuance, signing, and TLS operations.

Provider

Role

Component / version

Notes

BCFIPS (Bouncy Castle FIPS JCA/JCE provider)

Key generation, certificate signing, data signing

bc-fips 2.1.0

Registered at the highest JCA provider priority (position 1) so it is selected before any other provider for cryptographic operations.

BCFIPS companion modules

X.509/PKIX certificate handling, ASN.1/utility support

bcpkix-fips 2.1.9, bcutil-fips 2.1.4

Loaded alongside bc-fips as part of the same FIPS-validated module family; not mixed with the non-FIPS bcprov/bcpkix/bcutil artifacts.

BCJSSE (Bouncy Castle FIPS JSSE provider)

TLS 1.2/1.3 transport security

Bundled with the bc-fips module family

Registered at JCA provider priority position 2, immediately after BCFIPS, so all TLS handshakes use the validated module rather than the platform default JSSE

SUN / SunJSSE / SunRsaSign

JVM bookkeeping only (not used for cryptographic operations)

JDK-bundled

Left registered only where the JVM itself requires a provider entry; no signing, key generation, or certificate operation is permitted to fall back to these providers.

Key enforcement behaviors:

  • Approved-only mode is enabled (org.bouncycastle.fips.approved_only=true), so the provider itself will not perform an algorithm, key size, or curve operation outside the FIPS-approved set — this is a second, provider-level enforcement layer underneath the application-level checks described above.

  • Build-time selection. The FIPS provider chain is compiled in via a dedicated FIPS build variant; the standard (non-FIPS) Bouncy Castle build variant is not present in the FedRAMP deployment image, so there is no runtime toggle that could silently fall back to non-FIPS crypto.

  • Startup verification. Software Trust Manager fails to start if the FIPS provider modules are not present on the classpath when the FedRAMP/FIPS deployment profile is active, rather than silently continuing with a non-validated provider.