Skip to main content

Understand the Bouncy Castle FIPS cryptographic provider

DigiCert​​®​​ Trust Lifecycle Manager uses the Bouncy Castle FIPS provider family for cryptographic operations. Only the core provider is a CMVP-validated cryptographic module. The companion libraries rely on the core provider for cryptographic operations.

Component

Version

Role

CMVP validation

Bouncy Castle FIPS Java API (bc-fips)

2.1.1

The validated cryptographic module. Provides all approved cryptographic primitives.

FIPS 140-3, CMVP certificate #4943

bcpkix-fips

2.1.8

Certificate, CMS, and PKCS handling. Delegates all cryptography to the validated module.

Not a separately validated module

bcutil-fips

2.1.5

ASN.1 and encoding utilities. Delegates all cryptography to the validated module.

Not a separately validated module

bctls-fips

2.1.20

TLS/JSSE provider. Delegates all cryptography to the validated module.

Not a separately validated module

Note

The running deployment reports its provider name, runtime version, CMVP certificate number, and whether the runtime version matches the validated version. Use this information to verify the provider details rather than relying on the documented values alone.

How the provider is enforced

  • BCFIPS is inserted at the highest priority position in the JCE provider list. It’s selected ahead of JDK providers for any algorithm it publishes.

  • The Bouncy Castle JSSE provider (BCJSSE) is constructed in FIPS mode and inserted at the highest priority position. It’s also installed as the default SSLContext, so TLS is negotiated through the validated module.

  • Approved-only mode is set as a JVM-wide system property before the provider initializes and is verified after initialization. If verification fails, the application does not start.

Important

Trust Lifecycle Manager doesn’t remove the JDK's built-in providers, such as SUN and SunJCE, from the provider list. Algorithms that the BC-FIPS provider does not publish can therefore still resolve to a JDK provider. Approved-only mode causes non-approved cryptographic operations to fail. This behavior makes the configuration guidance in the following section mandatory rather than advisory.