FIPS Compliance and BouncyCastle

I want to know if my Android application supports FIPS 140-2 if it only uses the cryptographic algorithms provided here ? I use SpongyCastle to implement these algorithms.

Edit: A generalized question: can open source libraries such as BouncyCastle / SpongyCastle be used in a module that can be FIPS certified?

+4
source share
1 answer

Bouncy Castle is not FIPS 140-2 certified, so SpongyCastle is not certified. Mocana NanoCrypto is FIPS 140-2 certified for several specific combinations of OS and Android hardware.

Generally speaking, FIPS 140-2 certification requires a lot of money, so don't expect an open source library (other than OpenSSL) to be FIPS certified

+5
source

All Articles