RE: BC FIPS provider got handshake errors for some FIPS mode cipher suites

"Eckenfels. Bernd" <[email protected]> Tue, 29 Oct 2019 23:55:20 +0000
Newsgroups gmane.comp.encryption.bouncy-castle.devel
Message-ID <ED12D06EC205E3458FC3E23CD84D4ED502552AEF01@dedcexch02.seeburger.de>
DSS ciphers require a (uncommon and insecure) DH certificate and for ECDSA =
ciphers you need a EC cert. If you have a RSA certificate only, it is norma=
l what you have described. RSA DHE ciphers should also exist, but I don=92t=
 see any in your list. If you care about security (within the anschient FIP=
S parameters) ECDHE with ECDSA or RSA are the only once to consider (imho)
--
http://www.seeburger.com
________________________________________
From: Jeff Huang [jeff.huang-/Il8SMrEplgS/6/[email protected]]
Sent: Tuesday, October 29, 2019 23:45
To: [email protected]
Subject: [dev-crypto] BC FIPS provider got handshake errors for some FIPS m=
ode cipher suites

Hello,

The following cipher suites are FIPS mode based on "Appendix B =96 Supporte=
d
Cipher Suites" in BC-FJA-(D)TLSUserGuide-1.0.9.pdf.

I got handshake errors for all cipher suites with DHE key exchange algorith=
m
and all cipher suites with ECDHE key exchange algorithm and ECDSA
authentication algorithm.

*The following cipher suite are not working*
 TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA,
 TLS_DHE_DSS_WITH_AES_128_CBC_SHA,
 TLS_DHE_DSS_WITH_AES_128_CBC_SHA256,
 TLS_DHE_DSS_WITH_AES_256_CBC_SHA,
 TLS_DHE_DSS_WITH_AES_256_CBC_SHA256,

TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA,
TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA,
TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256,
TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA,
TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384,

*The following cipher suites are working. *
TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA,
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA,
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256,
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA,
TLS_RSA_WITH_3DES_EDE_CBC_SHA,
TLS_RSA_WITH_AES_128_CBC_SHA,
TLS_RSA_WITH_AES_128_CBC_SHA256,
TLS_RSA_WITH_AES_128_CCM,
TLS_RSA_WITH_AES_256_CBC_SHA,
TLS_RSA_WITH_AES_256_CBC_SHA256,
TLS_RSA_WITH_AES_256_CCM

Is that right behavior? Or I missed something. I did both key manager
algorithm and trust manager algorithm to PKIS, key store type is pkcs12.

Thanks!

Jeff.



--
Sent from: http://bouncy-castle.1462172.n4.nabble.com/Bouncy-Castle-Dev-f14=
62173.html









SEEBURGER AG            Vorstand/SEEBURGER Executive Board:
Sitz der Gesellschaft/Registered Office:                Axel Haas, Michael =
Kleeberg, Axel Otto, Dr. Martin Kuntz, Matthias Fe=DFenbecker
Edisonstr. 1
D-75015 Bretten         Vorsitzende des Aufsichtsrats/Chairperson of the SE=
EBURGER Supervisory Board:
Tel.: 07252 / 96 - 0            Prof. Dr. Simone Zeuchner
Fax: 07252 / 96 - 2222
Internet: http://www.seeburger.de               Registergericht/Commercial =
Register:
e-mail: [email protected]               HRB 240708 Mannheim


Dieses E-Mail ist nur f=FCr den Empf=E4nger bestimmt, an den es gerichtet i=
st und kann vertrauliches bzw. unter das Berufsgeheimnis fallendes Material=
 enthalten. Jegliche darin enthaltene Ansicht oder Meinungs=E4u=DFerung ist=
 die des Autors und stellt nicht notwendigerweise die Ansicht oder Meinung =
der SEEBURGER AG dar. Sind Sie nicht der Empf=E4nger, so haben Sie diese E-=
Mail irrt=FCmlich erhalten und jegliche Verwendung, Ver=F6ffentlichung, Wei=
terleitung, Abschrift oder jeglicher Druck dieser E-Mail ist strengstens un=
tersagt. Weder die SEEBURGER AG noch der Absender (Eckenfels. Bernd) =FCber=
nehmen die Haftung f=FCr Viren; es obliegt Ihrer Verantwortung, die E-Mail =
und deren Anh=E4nge auf Viren zu pr=FCfen.


This email is intended only for the recipient(s) to whom it is addressed. T=
his email may contain confidential material that may be protected by profes=
sional secrecy. Any fact or opinion contained, or expression of the materia=
l herein, does not necessarily reflect that of SEEBURGER AG. If you are not=
 the addressee or if you have received this email in error, any use, public=
ation or distribution including forwarding, copying or printing is strictly=
 prohibited. Neither SEEBURGER AG, nor the sender (Eckenfels. Bernd) accept=
 liability for viruses; it is your responsibility to check this email and i=
ts attachments for viruses.