RE: FIPS Java API provider and non-FIPS provider
"Rhuberg,Anthony" <[email protected]>
| Newsgroups | gmane.comp.encryption.bouncy-castle.devel |
|---|---|
| Message-ID | <DM5PR0102MB33668629E8C739B42508191E80660@DM5PR0102MB3366.prod.exchangelabs.com> |
Thanks. Makes sense. From: Matti Aarnio [mailto:[email protected]] Sent: Tuesday, June 05, 2018 2:33 PM To: Rhuberg,Anthony <[email protected]>; [email protected] Subject: Re: [dev-crypto] FIPS Java API provider and non-FIPS provider Hi Tony, The detail that affects more than "in same JVM" is "are they in same class loader?" WARs are loaded into separate class loader chains. WAR1 gets loader chain: CL1, CLroot. WAR2 gets loader chain: CL2, CLroot. If neither BCFIPS nor BCPROV are in CLroot, and instead in separate WARs, then the libraries will not see each other, and no collision happens. The "CLroot" is server/lib/ in current Tomcats. The "CLn" is webapps/warname/WEB-INF/lib/ Best Regards, Matti On 05.06.2018 21:01, Rhuberg,Anthony wrote: We have an application deployed within Tomcat and that application is uses Apache CXF which has a dependency on bcprov-jdk15on-1.51. Referring to: https://www.bouncycastle.org/fips-java/BCFipsIn100.pdf<https://na01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.bouncycastle.org%2Ffips-java%2FBCFipsIn100.pdf&data=02%7C01%7CAnthony.Rhuberg%40Cerner.com%7Ce60fa34500a84aeb1a7a08d5cb12c856%7Cfbc493a80d244454a815f4ca58e8c09d%7C0%7C1%7C636638203905695412&sdata=wmqUcMfgAVX7I2s%2F6rXx2ZCBUnzZZRRMKMBWZXLPR3o%3D&reserved=0>: “The provider jar itself has no external dependencies, but it cannot be used in the same JVM as the regular Bouncy Castle provider. The classes in the two jar files do not get along”. We are integrating FIPS Java API provider into another application WAR. We have not encountered an issues yet, but wanted to know what kinds of errors are expected if two applications use different Bouncy Castle Java implementations within the same JVM. Thanks,Tony CONFIDENTIALITY NOTICE This message and any included attachments are from Cerner Corporation and are intended only for the addressee. The information contained in this message is confidential and may constitute inside or non-public information under international, federal, or state securities laws. Unauthorized forwarding, printing, copying, distribution, or use of such information is strictly prohibited and may be unlawful. If you are not the addressee, please promptly delete this message and notify the sender of the delivery error by e-mail or you may call Cerner's corporate offices in Kansas City, Missouri, U.S.A at (+1) (816)221-1024.