Page tree

Versions Compared


  • This line was added.
  • This line was removed.
  • Formatting was changed.

Current FIPS Overview

The BC FIPS Java Description contains a broad overview of the motivations and design of the BC FIPS Java module.

As of BC Java 1.54 from a JCA/JCE point of view the module is largely a drop in replacement and can be used with the other BC APIs for certificate generation, CMS, TSP, S/MIME, OpenPGP and other protocols. Owing to the requirements of FIPS, particularly in respect to boundary issues the lightweight API is quite different, however the ASN.1 modules packages and the EC math module is package are the same.



Name: bc-fips-1.0.0.jar

BC FIPS 1.0.0 User Guide

BC FIPS 1.0.0 Security Policy

Status: The BC FIPS 1.0.0 module is currently in the NIST queue awaiting review. Progress of the module can be followed at:

Status: Released 11 November, 2016.

The module is currently tested against the JRE 1.7 and the JRE 1.8. The module is source and byte code compatible back to JDK 1.5.

Planned Releases

  1. bc-fips-1.0.1.jar
          patch release of bc-fips-1.0.0 (bug fixes, some improvements)
               - CAVP Lab Testing completed 8th June 2017
               - Lab Code Review completed 7th June 2017

  2. bc-fips-1.1.0.jar

Planned Retests

We expect to do a retest of BC FIPS Java 1.0.1 against JDK 1.9 when it is finalised.

Scheduled Additions for BC FIPS 1.1.0:

Support for PKIXRevocationChecker in the CertPath implementation.

Option for SOFT_FAIL style revocation checking flagfor the extended PKIXParameters class.

Approved Mode Algorithms


SHA-3 Signature Algorithms: PKCS#1.5, RSA PSS, ECDSA, DSA

SP 800-38G: Methods for format preserving encryption

Additional KAS modes for ephemeral keys.

Non-approved Mode Algorithms





GOST R 34.11-2012

Possible Additions for BC FIPS 1.1.0: