808bits

BC-FJA (Bouncy Castle FIPS Java API)

FIPS 140-3 certificate #4943 · Legion of the Bouncy Castle Inc. · data as of 2026-08-28
Active. Sunset date 2027-01-16, 140 days away.
Caveat: Interim Validation. When operated in approved mode. The module generates SSPs (e.g., keys) whose strengths are modified by available entropy

Certificate

Certificate number4943
StandardFIPS 140-3
Statusactive
Sunset date2027-01-16
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorLegion of the Bouncy Castle Inc. · website
Software versions2.1.1

Module description

The Bouncy Castle FIPS Java API is a comprehensive suite of FIPS Approved algorithms implemented in pure Java. All key sizes and modes have been implemented to allow flexibility and efficiency, and additional algorithms are available in non-approved operation as well.

Security level exceptions

  • Physical security: N/A
  • Non-invasive security: N/A

Approved algorithms

AlgorithmCAVP certificate
AES-CBCA4270
AES-CBC-CS1A4270
AES-CBC-CS2A4270
AES-CBC-CS3A4270
AES-CCMA4270
AES-CFB128A4270
AES-CFB8A4270
AES-CMACA4270
AES-CTRA4270
AES-ECBA4270
AES-FF1A4270
AES-GCMA4270
AES-GMACA4270
AES-KWA4270
AES-KWPA4270
AES-OFBA4270
Counter DRBGA4270
cSHAKE-128A4270
cSHAKE-256A4270
DSA KeyGen (FIPS186-4)A4270
DSA PQGGen (FIPS186-4)A4270
DSA PQGVer (FIPS186-4)A4270
DSA SigGen (FIPS186-4)A4270
DSA SigVer (FIPS186-4)A4270
ECDSA KeyGen (FIPS186-4)A4270
ECDSA KeyVer (FIPS186-4)A4270
ECDSA SigGen (FIPS186-4)A4270
ECDSA SigVer (FIPS186-4)A4270
EDDSA KeyGenA4270
EDDSA KeyVerA4270
EDDSA SigGenA4270
EDDSA SigVerA4270
Hash DRBGA4270
HMAC DRBGA4270
HMAC-SHA-1A4270
HMAC-SHA2-224A4270
HMAC-SHA2-256A4270
HMAC-SHA2-384A4270
HMAC-SHA2-512A4270
HMAC-SHA2-512/224A4270
HMAC-SHA2-512/256A4270
HMAC-SHA3-224A4270
HMAC-SHA3-256A4270
HMAC-SHA3-384A4270
HMAC-SHA3-512A4270
KAS-ECC Sp800-56Ar3A4270
KAS-FFC Sp800-56Ar3A4270
KAS-IFCA4270
KDA HKDF SP800-56Cr2A4270
KDA OneStep SP800-56Cr2A4270
KDA TwoStep SP800-56Cr2A4270
KDF ANS 9.63A4270
KDF IKEv2A4270
KDF SP800-108A4270
KDF SRTPA4270
KDF SSHA4270
KDF TLSA4270
KMAC-128A4270
KMAC-256A4270
KTS-IFCA4270
LMS SigVerA4270
ParallelHash-128A4270
ParallelHash-256A4270
PBKDFA4270
RSA KeyGen (FIPS186-5)A4270
RSA SigGen (FIPS186-5)A4270
RSA SigVer (FIPS186-5)A4270
Safe Primes Key GenerationA4270
Safe Primes Key VerificationA4270
SHA-1A4270
SHA2-224A4270
SHA2-256A4270
SHA2-384A4270
SHA2-512A4270
SHA2-512/224A4270
SHA2-512/256A4270
SHA3-224A4270
SHA3-256A4270
SHA3-384A4270
SHA3-512A4270
SHAKE-128A4270
SHAKE-256A4270
TLS v1.2 KDF RFC7627A4270
TupleHash-128A4270
TupleHash-256A4270

Tested configurations

  • Java SE Runtime Environment v8 (1.8) on Ubuntu 22.04 LTS running on an Intel NUC 11 Pro with an 11th Gen Intel Core i7 with PAA, Java SE Runtime Environment v8 (1.8) on Ubuntu 22.04 LTS running on an Intel NUC 11 Pro with an 11th Gen Intel Core i7 without PAA, Java SE Runtime Environment v11 (11) on Ubuntu 22.04 LTS running on an Intel NUC 11 Pro with an 11th Gen Intel Core i7 with PAA, Java SE Runtime Environment v11 (11) on Ubuntu 22.04 LTS running on an Intel NUC 11 Pro with an 11th Gen Intel Core i7 without PAA, Java SE Runtime Environment v17 (17) on Ubuntu 22.04 LTS running on an Intel NUC 11 Pro with an 11th Gen Intel Core i7 with PAA, Java SE Runtime Environment v17 (17) on Ubuntu 22.04 LTS running on an Intel NUC 11 Pro with an 11th Gen Intel Core i7 without PAA, Java SE Runtime Environment v21 (21) on Ubuntu 22.04 LTS running on an Intel NUC 11 Pro with an 11th Gen Intel Core i7 with PAA, Java SE Runtime Environment v21 (21) on Ubuntu 22.04 LTS running on an Intel NUC 11 Pro with an 11th Gen Intel Core i7 with PAA

Validation history

DateTypeLab
2025-01-17InitialLightship Security, Inc.
2025-11-14UpdateLightship Security, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2025-01-17

Source documents