RE: BC FIPS provider got handshake errors for some FIPS mode cipher suites
"Eckenfels. Bernd" <[email protected]> Tue, 29 Oct 2019 23:55:20 +0000
| Newsgroups | gmane.comp.encryption.bouncy-castle.devel |
|---|---|
| Message-ID | <ED12D06EC205E3458FC3E23CD84D4ED502552AEF01@dedcexch02.seeburger.de> |
DSS ciphers require a (uncommon and insecure) DH certificate and for ECDSA = ciphers you need a EC cert. If you have a RSA certificate only, it is norma= l what you have described. RSA DHE ciphers should also exist, but I don=92t= see any in your list. If you care about security (within the anschient FIP= S parameters) ECDHE with ECDSA or RSA are the only once to consider (imho) -- http://www.seeburger.com ________________________________________ From: Jeff Huang [jeff.huang-/Il8SMrEplgS/6/[email protected]] Sent: Tuesday, October 29, 2019 23:45 To: [email protected] Subject: [dev-crypto] BC FIPS provider got handshake errors for some FIPS m= ode cipher suites Hello, The following cipher suites are FIPS mode based on "Appendix B =96 Supporte= d Cipher Suites" in BC-FJA-(D)TLSUserGuide-1.0.9.pdf. I got handshake errors for all cipher suites with DHE key exchange algorith= m and all cipher suites with ECDHE key exchange algorithm and ECDSA authentication algorithm. *The following cipher suite are not working* TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA, TLS_DHE_DSS_WITH_AES_128_CBC_SHA, TLS_DHE_DSS_WITH_AES_128_CBC_SHA256, TLS_DHE_DSS_WITH_AES_256_CBC_SHA, TLS_DHE_DSS_WITH_AES_256_CBC_SHA256, TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA, TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA, TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256, TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA, TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384, *The following cipher suites are working. * TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA, TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA, TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA, TLS_RSA_WITH_3DES_EDE_CBC_SHA, TLS_RSA_WITH_AES_128_CBC_SHA, TLS_RSA_WITH_AES_128_CBC_SHA256, TLS_RSA_WITH_AES_128_CCM, TLS_RSA_WITH_AES_256_CBC_SHA, TLS_RSA_WITH_AES_256_CBC_SHA256, TLS_RSA_WITH_AES_256_CCM Is that right behavior? Or I missed something. I did both key manager algorithm and trust manager algorithm to PKIS, key store type is pkcs12. Thanks! Jeff. -- Sent from: http://bouncy-castle.1462172.n4.nabble.com/Bouncy-Castle-Dev-f14= 62173.html SEEBURGER AG Vorstand/SEEBURGER Executive Board: Sitz der Gesellschaft/Registered Office: Axel Haas, Michael = Kleeberg, Axel Otto, Dr. Martin Kuntz, Matthias Fe=DFenbecker Edisonstr. 1 D-75015 Bretten Vorsitzende des Aufsichtsrats/Chairperson of the SE= EBURGER Supervisory Board: Tel.: 07252 / 96 - 0 Prof. Dr. Simone Zeuchner Fax: 07252 / 96 - 2222 Internet: http://www.seeburger.de Registergericht/Commercial = Register: e-mail: [email protected] HRB 240708 Mannheim Dieses E-Mail ist nur f=FCr den Empf=E4nger bestimmt, an den es gerichtet i= st und kann vertrauliches bzw. unter das Berufsgeheimnis fallendes Material= enthalten. Jegliche darin enthaltene Ansicht oder Meinungs=E4u=DFerung ist= die des Autors und stellt nicht notwendigerweise die Ansicht oder Meinung = der SEEBURGER AG dar. Sind Sie nicht der Empf=E4nger, so haben Sie diese E-= Mail irrt=FCmlich erhalten und jegliche Verwendung, Ver=F6ffentlichung, Wei= terleitung, Abschrift oder jeglicher Druck dieser E-Mail ist strengstens un= tersagt. Weder die SEEBURGER AG noch der Absender (Eckenfels. Bernd) =FCber= nehmen die Haftung f=FCr Viren; es obliegt Ihrer Verantwortung, die E-Mail = und deren Anh=E4nge auf Viren zu pr=FCfen. This email is intended only for the recipient(s) to whom it is addressed. T= his email may contain confidential material that may be protected by profes= sional secrecy. Any fact or opinion contained, or expression of the materia= l herein, does not necessarily reflect that of SEEBURGER AG. If you are not= the addressee or if you have received this email in error, any use, public= ation or distribution including forwarding, copying or printing is strictly= prohibited. Neither SEEBURGER AG, nor the sender (Eckenfels. Bernd) accept= liability for viruses; it is your responsibility to check this email and i= ts attachments for viruses.