You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

关于客户端应用能否严格符合FIPS 140-3标准的问询(含Java客户端合规性验证)

关于客户端应用能否严格符合FIPS 140-3标准的问询(含Java客户端合规性验证)

我正在研究以下客户端的FIPS 140-3合规性:

  • 使用BouncyCastle FIPS Provider和BouncyCastleJSSE Provider的Java客户端
  • 使用OpenSSL FIPS Provider的OpenSSL客户端

我的Java应用详情

Jar依赖

  • log4j-core-2.17.1.jar、log4j-api-2.17.1.jar、jackson-annotations-2.13.4.jar、jackson-core-2.13.4.jar、jackson-databind-2.13.4.2.jar、bc-fips-2.1.0.jar、bcpkix-fips-2.1.10.jar、bctls-fips-2.1.22.jar、bcutil-fips-2.1.5.jar、log4j-jul-2.25.3.jar

设置的系统属性

System.setProperty("org.bouncycastle.fips.approved_only", Boolean.TRUE.toString());
System.setProperty("jdk.tls.trustNameService", Boolean.TRUE.toString());
System.setProperty("java.util.logging.manager", "org.apache.logging.log4j.jul.LogManager");

代码片段

if( Security.getProvider(FIPS_PROVIDER_NAME) == null)
{
      Class<?> bcFipsClass = Class.forName("org.bouncycastle.jcajce.provider.BouncyCastleFipsProvider");
      Provider bcFipsObj   =  (Provider)bcFipsClass.getDeclaredConstructor().newInstance();
      Security.insertProviderAt(bcFipsObj, 1);
}
if( Security.getProvider(FIPS_JSSE_PROVIDER_NAME) == null)
{
      Class<?> bcJsseClass = Class.forName("org.bouncycastle.jsse.provider.BouncyCastleJsseProvider");
      Constructor<?> bcJsseClassConstructor = bcJsseClass.getConstructor(String.class);
      Provider bcJsseObj   =  (Provider)bcJsseClassConstructor.newInstance("fips:BCFIPS");  
      Security.insertProviderAt(bcJsseObj, 2);
}

String type = (Security.getProvider("BCJSSE") != null) ? "BCFKS" : "PKCS12";
..

// generate truststore from ca pem file
KeyStore trustStore = null;
if ( caPemFile != null && !caPemFile.isBlank() )
{
    try ( final InputStream inputStream = new FileInputStream(caPemFile) )
    {
        CertificateFactory certificateFactory = CertificateFactory.getInstance("X.509");
        Collection<? extends Certificate> certificates = certificateFactory.generateCertificates(inputStream);
        
        trustStore = KeyStore.getInstance(type);
        trustStore.load(null);
        for ( Certificate certificate : certificates )
        {
            X500Principal principal = ( (X509Certificate)certificate ).getSubjectX500Principal();
            trustStore.setCertificateEntry(principal.getName(), certificate);
        }
    } 
    catch ( CertificateException | NoSuchAlgorithmException | IOException | KeyStoreException e)
    { .. }
}
..
TrustManager[] trustManagers = null;
if ( trustStore != null ) 
{
    try 
    {
        final TrustManagerFactory trustManagerFactory = TrustManagerFactory.getInstance(TrustManagerFactory.getDefaultAlgorithm());
        trustManagerFactory.init(trustStore);
        trustManagers = trustManagerFactory.getTrustManagers();
    } 
    catch (NoSuchAlgorithmException | KeyStoreException e)
    {  ... }
}
..
try 
{
    this.sslContext = SSLContext.getInstance("TLS");
    sslContext.init(keyManagers, trustManagers, null);
}

变量信息(均指向BCFIPS/BCJSSE提供类)

sslContext  SSLContext  (id=81) 
    contextSpi  ProvSSLContextSpi  (id=163) 
        contextData ContextData  (id=206)   
        cryptoProvider  JcaTlsCryptoProvider  (id=208)  
        fipsMode    true    
        specifiedProtocolsClient    null    
    protocol    "TLS" (id=166)  
    provider    BouncyCastleJsseProvider  (id=39)   

keyStoreFile    null    
keystorePassword    null    
caPemFile   "root-ca.pem" (id=32)   
type    "BCFKS" (id=47) 
trustStore  KeyStore  (id=70)   
    initialized true    
    keyStoreSpi ProvBCFKS$BCFIPSKeyStoreSpi  (id=82)    
        creationDate    Date  (id=233)  
        entries HashMap<K,V>  (id=235)  
        fipsProvider    BouncyCastleFipsProvider  (id=85)   
        hmacAlgorithm   AlgorithmIdentifier  (id=238)   
        hmacPkbdAlgorithm   KeyDerivationFunc  (id=243) 
        lastModifiedDate    Date  (id=245)  
        matchOnProbe    true    
        privateKeyCache HashMap<K,V>  (id=246)  
        storeEncryptionAlgorithm    ASN1ObjectIdentifier  (id=247)  
    provider    BouncyCastleFipsProvider  (id=85)   
    type    "BCFKS" (id=47) 
trustManagers   TrustManager[1]  (id=72)    
    [0] ExportX509TrustManager_7  (id=87)   
        x509TrustManager    ProvX509TrustManager  (id=92)   
            exportX509TrustManager  ExportX509TrustManager_7  (id=87)   
            fipsMode    true    
            helper  ProviderJcaJceHelper  (id=95)   
            pkixParametersTemplate  PKIXBuilderParameters  (id=98)  
            trustedCerts    HashSet<E>  (id=102)    
keyManagers null

问题:基于Wireshark的ClientHello跟踪,能否判定我的Java客户端处于严格FIPS模式?

Wireshark ClientHello跟踪内容

Transport Layer Security
    [Stream index: 0]
    TLSv1.3 Record Layer: Handshake Protocol: Client Hello
        Content Type: Handshake (22)
        Version: TLS 1.0 (0x0301)
        Length: 350
        Handshake Protocol: Client Hello
            Handshake Type: Client Hello (1)
            Length: 346
            Version: TLS 1.2 (0x0303)
            Random: d6e846dc5d66cb2eec837be0248d4a6c0e5784a7afa78df571b6e006f70e3845
            Session ID Length: 32
            Session ID: 196bc153b899cffff3e952e06dc0478567f5d5eaeb0b21b450a13bb4f86c690e
            Cipher Suites Length: 54
            Cipher Suites (27 suites)
                Cipher Suite: TLS_AES_256_GCM_SHA384 (0x1302)
                Cipher Suite: TLS_AES_128_GCM_SHA256 (0x1301)
                Cipher Suite: TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 (0xc02c)
                Cipher Suite: TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 (0xc02b)
                Cipher Suite: TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (0xc030)
                Cipher Suite: TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xc02f)
                Cipher Suite: TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 (0x009f)
                Cipher Suite: TLS_DHE_DSS_WITH_AES_256_GCM_SHA384 (0x00a3)
                Cipher Suite: TLS_DHE_RSA_WITH_AES_128_GCM_SHA256 (0x009e)
                Cipher Suite: TLS_DHE_DSS_WITH_AES_128_GCM_SHA256 (0x00a2)
                Cipher Suite: TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384 (0xc024)
                Cipher Suite: TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 (0xc028)
                Cipher Suite: TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256 (0xc023)
                Cipher Suite: TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 (0xc027)
                Cipher Suite: TLS_DHE_RSA_WITH_AES_256_CBC_SHA256 (0x006b)
                Cipher Suite: TLS_DHE_DSS_WITH_AES_256_CBC_SHA256 (0x006a)
                Cipher Suite: TLS_DHE_RSA_WITH_AES_128_CBC_SHA256 (0x0067)
                Cipher Suite: TLS_DHE_DSS_WITH_AES_128_CBC_SHA256 (0x0040)
                Cipher Suite: TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA (0xc00a)
                Cipher Suite: TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (0xc014)
                Cipher Suite: TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA (0xc009)
                Cipher Suite: TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (0xc013)
                Cipher Suite: TLS_DHE_RSA_WITH_AES_256_CBC_SHA (0x0039)
                Cipher Suite: TLS_DHE_DSS_WITH_AES_256_CBC_SHA (0x0038)
                Cipher Suite: TLS_DHE_RSA_WITH_AES_128_CBC_SHA (0x0033)
                Cipher Suite: TLS_DHE_DSS_WITH_AES_128_CBC_SHA (0x0032)
                Cipher Suite: TLS_EMPTY_RENEGOTIATION_INFO_SCSV (0x00ff)
            Compression Methods Length: 1
            Compression Methods (1 method)
            Extensions Length: 219
            Extension: encrypt_then_mac (len=0)
                Type: encrypt_then_mac (22)
                Length: 0
            Extension: extended_master_secret (len=0)
                Type: extended_master_secret (23)
                Length: 0
            Extension: supported_versions (len=5) TLS 1.3, TLS 1.2
                Type: supported_versions (43)
                Length: 5
                Supported Versions length: 4
                Supported Version: TLS 1.3 (0x0304)
                Supported Version: TLS 1.2 (0x0303)
            Extension: status_request_v2 (len=16)
                Type: status_request_v2 (17)
                Length: 16
                Certificate Status List Length: 14
                Certificate Status Type: OCSP Multi (2)
                Certificate Status Length: 4
                Responder ID list Length: 0
                Request Extensions Length: 0
                Certificate Status Type: OCSP (1)
                Certificate Status Length: 4
                Responder ID list Length: 0
                Request Extensions Length: 0
            Extension: application_layer_protocol_negotiation (len=14)
                Type: application_layer_protocol_negotiation (16)
                Length: 14
                ALPN Extension Length: 12
                ALPN Protocol
            Extension: signature_algorithms (len=34)
                Type: signature_algorithms (13)
                Length: 34
                Signature Hash Algorithms Length: 32
                Signature Hash Algorithms (16 algorithms)
                    Signature Algorithm: ecdsa_secp256r1_sha256 (0x0403)
                        Signature Hash Algorithm Hash: SHA256 (4)
                        Signature Hash Algorithm Signature: ECDSA (3)

备注:内容来源于stack exchange,提问作者forumUsr

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.13 18:15:27