Uploaded image for project: 'JBoss Enterprise Application Platform'
  1. JBoss Enterprise Application Platform
  2. JBEAP-20274

Emphasize that BouncyCastle third party jar works with multiple platforms

XMLWordPrintable

    • Icon: Documentation Documentation
    • Resolution: Obsolete
    • Icon: Major Major
    • None
    • 7.3.1.GA
    • Documentation, JCA
    • None
    • False
    • False
    • Undefined

      Documentation [1] states that "The scope of this configuration example is limited to Red Hat Enterprise Linux 7 and later". We should also add that BouncyCastle is certified on multiple operating systems including Windows. One of the use cases for recommending a pure Java FIPS-certified JCA provider is that it simplifies running apps on multiple operating systems by limiting platform unique configurations. For example, EAP customers on Windows are FIPS 140-2 compliant when using the BouncyCastle certified jars.

      The NIST website lists the certificates for bouncy castle. The certificate for their latest version is here [2]. The caveat field states the conditions where the certificate is considered valid.

      [1]https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/7.3/html-single/how_to_configure_server_security/index#configure_ssl_fips_bouncycastle

      [2]https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/3514

       

            msvehla@redhat.com Martin Svehla
            rlucente-se-jboss Richard Lucente
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: