I am currently trying to make a Spring Boot 2 application to follow all FIPS 140-2 requirements and use TSL in its connections by making use of Bouncy Castle Provider. So far, I tried looking online what people been doing but it's not straightforward, for example making use of putting jars in your lib folder.
What I tried so far but I don't see how it fits together.
Application main to set Fips Provider
public static void main(String[] args) throws Exception {
Security.addProvider(new BouncyCastleFipsProvider());
...
}
Updating java.security (which is now in jdk11/conf/security)
security.provider.1=org.bouncycastle.jcajce.provider.BouncyCastleFipsProvider
And having Bouncy castle jars in classpath of the app
<dependency>
<groupId>org.bouncycastle</groupId>
<artifactId>bcpkix-jdk15on</artifactId>
<version>1.58</version>
</dependency>
<dependency>
<groupId>org.bouncycastle</groupId>
<artifactId>bc-fips</artifactId>
<version>1.0.2.1</version>
</dependency>
Configuring bean in Application (but then how to use it?)
@Bean
public Cipher cbcCipher() throws GeneralSecurityException {
Security.addProvider(new BouncyCastleFipsProvider());
return Cipher.getInstance("AES/CBC/PKCS7Padding", "BCFIPS");
}
Interesting pages Usage of Native Tomcat with OpenSSL to work with Spring Boot but not Bouncy Castle https://medium.com/@crueda/tomcat-native-openssl-in-spring-boot-2-0-a341ad07471d
Bouncy Castle userguide https://downloads.bouncycastle.org/fips-java/BC-FJA-UserGuide-1.0.2.pdf
Are there any application.properties that should be set in the app? As a note, I added the following and they work fine to read some certificate locally but not using BC FIPS
server.ssl.key-store=classpath:medium.jks
server.ssl.key-store-type=pkcs12
server.ssl.key-store-password=password
server.ssl.key-password=password
server.ssl.key-alias=medium
server.port=8080
Could you please help me see how to attach all these strings together? What am I missing? I suppose how to tell Spring Boot to use BC to its connections in the embedded web server?