Understand the BC-FIPS cryptographic provider
Software Trust Manager registers the Bouncy Castle FIPS Java API (BC-FIPS) as the sole cryptographic provider in the FedRAMP deployment. Standard (non-FIPS) Bouncy Castle and any other JCA/JCE/JSSE provider are removed from the Java security provider list at startup, so only the validated provider chain below can perform key generation, certificate issuance, signing, and TLS operations.
Provider | Role | Component / version | Notes |
|---|---|---|---|
BCFIPS (Bouncy Castle FIPS JCA/JCE provider) | Key generation, certificate signing, data signing | bc-fips 2.1.0 | Registered at the highest JCA provider priority (position 1) so it is selected before any other provider for cryptographic operations. |
BCFIPS companion modules | X.509/PKIX certificate handling, ASN.1/utility support | bcpkix-fips 2.1.9, bcutil-fips 2.1.4 | Loaded alongside bc-fips as part of the same FIPS-validated module family; not mixed with the non-FIPS bcprov/bcpkix/bcutil artifacts. |
BCJSSE (Bouncy Castle FIPS JSSE provider) | TLS 1.2/1.3 transport security | Bundled with the bc-fips module family | Registered at JCA provider priority position 2, immediately after BCFIPS, so all TLS handshakes use the validated module rather than the platform default JSSE |
SUN / SunJSSE / SunRsaSign | JVM bookkeeping only (not used for cryptographic operations) | JDK-bundled | Left registered only where the JVM itself requires a provider entry; no signing, key generation, or certificate operation is permitted to fall back to these providers. |
Key enforcement behaviors:
Approved-only mode is enabled (org.bouncycastle.fips.approved_only=true), so the provider itself will not perform an algorithm, key size, or curve operation outside the FIPS-approved set — this is a second, provider-level enforcement layer underneath the application-level checks described above.
Build-time selection. The FIPS provider chain is compiled in via a dedicated FIPS build variant; the standard (non-FIPS) Bouncy Castle build variant is not present in the FedRAMP deployment image, so there is no runtime toggle that could silently fall back to non-FIPS crypto.
Startup verification. Software Trust Manager fails to start if the FIPS provider modules are not present on the classpath when the FedRAMP/FIPS deployment profile is active, rather than silently continuing with a non-validated provider.