Cryptographic Module Validation Program CMVP

Certificate #3673

Details

Module Name
VMware's BC-FJA (Bouncy Castle FIPS Java API)
Standard
FIPS 140-2
Status
Active
Sunset Date
8/22/2024
Validation Dates
06/22/2020
Overall Level
1
Caveat
When installed, initialized and configured as specified in the Security Policy Section 3 and operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy.
Security Level Exceptions
  • Physical Security: N/A
Module Type
Software
Embodiment
Multi-Chip Stand Alone
Description
Vmware’s BC-FJA (Bouncy Castle FIPS Java API) is a software cryptographic module that provides cryptographic functions and services to various Vmware applications via a well-defined Java-language application programming interface (API).
Tested Configuration(s)
  • CentOS 8 with JDK 11 on VMware ESXi 7.0 running on Dell PowerEdge R740 with Intel Xeon Gold 6126
  • SUSE Linux Enterprise Server 15 with JDK 11 on VMware ESXi 7.0 running on Dell PowerEdge R740 with Intel Xeon Gold 6126
  • Ubuntu 16.04 with JDK 11 on VMware ESXi 7.0 running on Dell PowerEdge R740 with Intel Xeon Gold 6126
  • Ubuntu 16.04 with JDK 8 on VMware ESXi 7.0 running on Dell PowerEdge R740 with Intel Xeon Gold 6126
  • Ubuntu 18.04 with JDK 11 on VMware ESXi 7.0 running on Dell PowerEdge R740 with Intel Xeon Gold 6126
  • Ubuntu 18.04 with JDK 11 running on Dell Latitude E7470 with Intel Core i5
  • Ubuntu 18.04 with JDK 8 on VMware ESXi 7.0 running on Dell PowerEdge R740 with Intel Xeon Gold 6126
  • VMware Photon OS 2.0 with JDK 11 on VMware ESXi 7.0 running on Dell PowerEdge R740 with Intel Xeon Gold 6126
  • VMware Photon OS 2.0 with JDK 8 on VMware ESXi 7.0 running on Dell PowerEdge R740 with Intel Xeon Gold 6126
  • VMware Photon OS 3.0 with JDK 11 on VMware ESXi 7.0 running on Dell PowerEdge R740 with Intel Xeon Gold 6126
  • VMware Photon OS 3.0 with JDK 8 on VMware ESXi 7.0 running on Dell PowerEdge R740 with Intel Xeon Gold 6126
  • Windows 10 with JDK 11 running on Dell Latitude E7470 with Intel Core i5 (single user mode)
  • Windows Server 2016 with JDK 11 on VMware ESXi 7.0 running on Dell PowerEdge R740 with Intel Xeon Gold 6126
  • Windows Server 2016 with JDK 8 on VMware ESXi 7.0 running on Dell PowerEdge R740 with Intel Xeon Gold 6126
  • Windows Server 2019 with JDK 11 on VMware ESXi 7.0 running on Dell PowerEdge R740 with Intel Xeon Gold 6126
FIPS Algorithms
HMAC (Cert. #C1742
PBKDF (vendor affirmed
AES Cert. #C1742
CKG vendor affirmed
CVL Cert. #C1742
DRBG Cert. #C1742
DSA Cert. #C1742
ECDSA Cert. #C1742
KAS Cert. #C1742
KAS SP 800-56Arev2 with CVL Cert. #C1742, vendor affirmed
KBKDF Cert. #C1742
KTS AES Cert. #C1742; key establishment methodology provides between 128 and 256 bits of encryption strength
KTS vendor affirmed
KTS Triple-DES Cert. #C1742; key establishment methodology provides 112 bits of encryption strength
RSA Cert. #C1742
SHA-3 Cert. #C1742
SHA-3-Customized SHA-3 Cert. #C1742, vendor affirmed
SHS Cert. #C1742
Triple-DES Cert. #C1742
Allowed Algorithms
Diffie-Hellman (CVL Cert. #C1742, key agreement; key establishment methodology provides 112 bits or 128 bits of encryption strength); EC Diffie-Hellman (CVL Cert. #C1742, key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength); NDRNG; MD5; RSA (CVL Cert. #C1742, key wrapping; key establishment methodology provides between 150 and 256 bits of encryption strength)
Software Versions
1.0.2

Vendor

VMware, Inc.
3401 Hillview Ave.
Palo Alto, CA 94304
USA

Manoj Maskara
mmaskara@vmware.com
Phone: 650-427-1000
Fax: 650-475-5001

Lab

ACUMEN SECURITY, LLC
NVLAP Code: 201029-0