808bits

BC-FJA (Bouncy Castle FIPS Java API)

FIPS 140-2 certificate #3152 · Legion of the Bouncy Castle Inc. · data as of 2026-08-28
Historical. SP 800-56Arev3 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy. No assurance of the minimum strength of generated keys

Certificate

Certificate number3152
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorLegion of the Bouncy Castle Inc. · website
Software versions1.0.1

Module description

The Bouncy Castle FIPS Java API is a comprehensive suite of FIPS Approved algorithms implemented in pure Java. All key sizes and modes have been implemented to allow flexibility and efficiency, and additional algorithms are available in non-approved operation as well. The module is designed to integrate with the associated Bouncy Castle APIs including those for TLS, X.509, CMS, S/MIME, TSP, PKIX, and OpenPGP.

Security level exceptions

  • Physical Security: N/A

Approved algorithms

AlgorithmCAVP certificate
AES4759
CKGvendor affirmed
CVL1398, 1399, 1400, 1401, 1402
DRBG1636
DSA1279
ECDSA1191
HMAC3170
KAS135
KASvendor affirmed
KBKDF153
KTS
KTSvendor affirmed
KTS
PBKDFvendor affirmed
RSA2602
SHA-338
SHS3901
Triple DES

Allowed algorithms

Diffie-Hellman (key agreement; key establishment methodology provides 112 bits of encryption strength); MD5; RSA (key wrapping; key establishment methodology provides 112 or 128 bits of encryption strength)

Tested configurations

  • Linux 3.10 on Java SE Runtime Environment v8 (1.8.0) running on NetScout PowerEdge R730 with an Intel Xeon Processor E5-2697 v3
  • Linux 3.10 on Java SE Runtime Environment v8 (1.8.0) running on NetScout PowerEdge R740 with an Intel Xeon Processor Silver 4110
  • Lollipop Android 5.1 on Android 5 Java ART running on Zebra TC75 Touch Computer with a Qualcomm MS8960 Pro
  • Marshmallow Android 6.0 on Android 6 Java ART running on Zebra TC51-HC Touch Computer with a Qualcomm MSM8956
  • Microsoft Windows Server 2016 ESXi 6.7 on Java SE Runtime Environment v8 (1.8.0) running on Dell PowerEdge R740 with an Intel Xeon 6126
  • Oreo Android 8.1 on Android 8 Java ART running on Zebra TC52 Touch Computer with a Qualcomm SD660
  • Photon OS 2.0 on VMware ESXi 6.7 on Java SE Runtime Environment v8 (1.8.0) running on Dell PowerEdge R740 with an Intel Xeon 6126
  • Red Hat Enterprise Linux (RHEL) 7.3 on VMware ESXi 5.5 and Java SE Runtime Environment v7 (1.7.0) running on HP ProLiant DL360 G7 Server with an Intel Xeon X5670
  • Red Hat Enterprise Linux (RHEL) 7.3 on VMware ESXi 5.5 and Java SE Runtime Environment v8 (1.8.0) running on HP ProLiant DL360 G7 Server with an Intel Xeon X5670
  • Ubuntu 16.04 on VMware ESXi 6.7 on Java SE Runtime Environment v8 (1.8.0) running on Dell PowerEdge R740 with an Intel Xeon Processor 6126
  • Ubuntu 16.04 on VMware ESXi 7.0 on Java SE Runtime Environment v8 (1.8.0) running on Dell PowerEdge R740 with an Intel Xeon Gold 6126
  • Ubuntu 18.04 on VMware ESXi 7.0 on Java SE Runtime Environment v11 (1.11.0) running on Dell PowerEdge R740 with an Intel Xeon Gold 6126 (single-user mode)

Validation history

DateTypeLab
2018-03-15InitialUL Verification Services, Inc.
2019-04-02UpdateUL Verification Services, Inc.
2019-04-09UpdateUL Verification Services, Inc.
2020-07-23UpdateUL Verification Services, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2018-03-15, 2019-04-02, 2019-04-09, 2020-07-23

Source documents