Understand the Bouncy Castle FIPS cryptographic provider
DigiCert® Trust Lifecycle Manager uses the Bouncy Castle FIPS provider family for cryptographic operations. Only the core provider is a CMVP-validated cryptographic module. The companion libraries rely on the core provider for cryptographic operations.
Component | Version | Role | CMVP validation |
|---|---|---|---|
Bouncy Castle FIPS Java API ( | 2.1.1 | The validated cryptographic module. Provides all approved cryptographic primitives. | FIPS 140-3, CMVP certificate #4943 |
| 2.1.8 | Certificate, CMS, and PKCS handling. Delegates all cryptography to the validated module. | Not a separately validated module |
| 2.1.5 | ASN.1 and encoding utilities. Delegates all cryptography to the validated module. | Not a separately validated module |
| 2.1.20 | TLS/JSSE provider. Delegates all cryptography to the validated module. | Not a separately validated module |
Note
The running deployment reports its provider name, runtime version, CMVP certificate number, and whether the runtime version matches the validated version. Use this information to verify the provider details rather than relying on the documented values alone.
How the provider is enforced
BCFIPSis inserted at the highest priority position in the JCE provider list. It’s selected ahead of JDK providers for any algorithm it publishes.The Bouncy Castle JSSE provider (
BCJSSE) is constructed in FIPS mode and inserted at the highest priority position. It’s also installed as the defaultSSLContext, so TLS is negotiated through the validated module.Approved-only mode is set as a JVM-wide system property before the provider initializes and is verified after initialization. If verification fails, the application does not start.
Important
Trust Lifecycle Manager doesn’t remove the JDK's built-in providers, such as SUN and SunJCE, from the provider list. Algorithms that the BC-FIPS provider does not publish can therefore still resolve to a JDK provider. Approved-only mode causes non-approved cryptographic operations to fail. This behavior makes the configuration guidance in the following section mandatory rather than advisory.