808bits

BC-FNA (Bouncy Castle FIPS .NET API)

FIPS 140-2 certificate #2792 · Legion of the Bouncy Castle Inc. · data as of 2026-08-28
Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When installed, initialized and configured as specified in the Security Policy Section 8 and operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy. No assurance of the minimum strength of generated keys.

Certificate

Certificate number2792
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorLegion of the Bouncy Castle Inc. · website
Software versions1.0.1.1

Module description

The Bouncy Castle FIPS .NET API is a comprehensive suite of FIPS Approved algorithms implemented in pure C#. All key sizes and modes have been implemented to allow flexibility and efficiency, and additional algorithms, including some post-quantum ones, are available in non-approved operation as well.

Security level exceptions

  • Physical Security: N/A

Approved algorithms

AlgorithmCAVP certificate
AESC2202
CVLC2202
DRBGC2202
DSAC2202
ECDSAC2202
HMACC2202
KAS-SSCvendor affirmed
KTS
KTS
KTSvendor affirmed
PBKDFvendor affirmed
RSAC2202
SHA-3C2202
SHSC2202
Triple-DESC2202

Other algorithms

MD5; RSA (key wrapping; key establishment methodology provides 112 or 128 bits of encryption strength; non-compliant less than 112 bits of encryption strength); AES (non-compliant); ARC4; Camellia; ChaCha; ElGamal; NewHope; OpenSSL PBKDF; PKCS#12 PBKDF; Poly1305; SEED; Serpent; SPHINCS-256

Tested configurations

  • Microsoft Windows 10 Professional (64-bit) on .NET 4.5.2 framework running on Dell XPS 15 7590 with Intel Core i7-9750H (single-user mode)

Validation history

DateTypeLab
2016-11-14InitialCGI Information Systems & Management Consultants Inc
2021-04-19UpdateAcumen Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2016-11-14, 2021-04-19

Source documents