关于客户端应用能否严格符合FIPS 140-3标准的问询(含Java客户端合规性验证)
关于客户端应用能否严格符合FIPS 140-3标准的问询(含Java客户端合规性验证)
我正在研究以下客户端的FIPS 140-3合规性:
- 使用BouncyCastle FIPS Provider和BouncyCastleJSSE Provider的Java客户端
- 使用OpenSSL FIPS Provider的OpenSSL客户端
我的Java应用详情
Jar依赖
- log4j-core-2.17.1.jar、log4j-api-2.17.1.jar、jackson-annotations-2.13.4.jar、jackson-core-2.13.4.jar、jackson-databind-2.13.4.2.jar、bc-fips-2.1.0.jar、bcpkix-fips-2.1.10.jar、bctls-fips-2.1.22.jar、bcutil-fips-2.1.5.jar、log4j-jul-2.25.3.jar
设置的系统属性
System.setProperty("org.bouncycastle.fips.approved_only", Boolean.TRUE.toString()); System.setProperty("jdk.tls.trustNameService", Boolean.TRUE.toString()); System.setProperty("java.util.logging.manager", "org.apache.logging.log4j.jul.LogManager");
代码片段
if( Security.getProvider(FIPS_PROVIDER_NAME) == null) { Class<?> bcFipsClass = Class.forName("org.bouncycastle.jcajce.provider.BouncyCastleFipsProvider"); Provider bcFipsObj = (Provider)bcFipsClass.getDeclaredConstructor().newInstance(); Security.insertProviderAt(bcFipsObj, 1); } if( Security.getProvider(FIPS_JSSE_PROVIDER_NAME) == null) { Class<?> bcJsseClass = Class.forName("org.bouncycastle.jsse.provider.BouncyCastleJsseProvider"); Constructor<?> bcJsseClassConstructor = bcJsseClass.getConstructor(String.class); Provider bcJsseObj = (Provider)bcJsseClassConstructor.newInstance("fips:BCFIPS"); Security.insertProviderAt(bcJsseObj, 2); } String type = (Security.getProvider("BCJSSE") != null) ? "BCFKS" : "PKCS12"; .. // generate truststore from ca pem file KeyStore trustStore = null; if ( caPemFile != null && !caPemFile.isBlank() ) { try ( final InputStream inputStream = new FileInputStream(caPemFile) ) { CertificateFactory certificateFactory = CertificateFactory.getInstance("X.509"); Collection<? extends Certificate> certificates = certificateFactory.generateCertificates(inputStream); trustStore = KeyStore.getInstance(type); trustStore.load(null); for ( Certificate certificate : certificates ) { X500Principal principal = ( (X509Certificate)certificate ).getSubjectX500Principal(); trustStore.setCertificateEntry(principal.getName(), certificate); } } catch ( CertificateException | NoSuchAlgorithmException | IOException | KeyStoreException e) { .. } } .. TrustManager[] trustManagers = null; if ( trustStore != null ) { try { final TrustManagerFactory trustManagerFactory = TrustManagerFactory.getInstance(TrustManagerFactory.getDefaultAlgorithm()); trustManagerFactory.init(trustStore); trustManagers = trustManagerFactory.getTrustManagers(); } catch (NoSuchAlgorithmException | KeyStoreException e) { ... } } .. try { this.sslContext = SSLContext.getInstance("TLS"); sslContext.init(keyManagers, trustManagers, null); }
变量信息(均指向BCFIPS/BCJSSE提供类)
sslContext SSLContext (id=81) contextSpi ProvSSLContextSpi (id=163) contextData ContextData (id=206) cryptoProvider JcaTlsCryptoProvider (id=208) fipsMode true specifiedProtocolsClient null protocol "TLS" (id=166) provider BouncyCastleJsseProvider (id=39) keyStoreFile null keystorePassword null caPemFile "root-ca.pem" (id=32) type "BCFKS" (id=47) trustStore KeyStore (id=70) initialized true keyStoreSpi ProvBCFKS$BCFIPSKeyStoreSpi (id=82) creationDate Date (id=233) entries HashMap<K,V> (id=235) fipsProvider BouncyCastleFipsProvider (id=85) hmacAlgorithm AlgorithmIdentifier (id=238) hmacPkbdAlgorithm KeyDerivationFunc (id=243) lastModifiedDate Date (id=245) matchOnProbe true privateKeyCache HashMap<K,V> (id=246) storeEncryptionAlgorithm ASN1ObjectIdentifier (id=247) provider BouncyCastleFipsProvider (id=85) type "BCFKS" (id=47) trustManagers TrustManager[1] (id=72) [0] ExportX509TrustManager_7 (id=87) x509TrustManager ProvX509TrustManager (id=92) exportX509TrustManager ExportX509TrustManager_7 (id=87) fipsMode true helper ProviderJcaJceHelper (id=95) pkixParametersTemplate PKIXBuilderParameters (id=98) trustedCerts HashSet<E> (id=102) keyManagers null
问题:基于Wireshark的ClientHello跟踪,能否判定我的Java客户端处于严格FIPS模式?
Wireshark ClientHello跟踪内容
Transport Layer Security [Stream index: 0] TLSv1.3 Record Layer: Handshake Protocol: Client Hello Content Type: Handshake (22) Version: TLS 1.0 (0x0301) Length: 350 Handshake Protocol: Client Hello Handshake Type: Client Hello (1) Length: 346 Version: TLS 1.2 (0x0303) Random: d6e846dc5d66cb2eec837be0248d4a6c0e5784a7afa78df571b6e006f70e3845 Session ID Length: 32 Session ID: 196bc153b899cffff3e952e06dc0478567f5d5eaeb0b21b450a13bb4f86c690e Cipher Suites Length: 54 Cipher Suites (27 suites) Cipher Suite: TLS_AES_256_GCM_SHA384 (0x1302) Cipher Suite: TLS_AES_128_GCM_SHA256 (0x1301) Cipher Suite: TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 (0xc02c) Cipher Suite: TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 (0xc02b) Cipher Suite: TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (0xc030) Cipher Suite: TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xc02f) Cipher Suite: TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 (0x009f) Cipher Suite: TLS_DHE_DSS_WITH_AES_256_GCM_SHA384 (0x00a3) Cipher Suite: TLS_DHE_RSA_WITH_AES_128_GCM_SHA256 (0x009e) Cipher Suite: TLS_DHE_DSS_WITH_AES_128_GCM_SHA256 (0x00a2) Cipher Suite: TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384 (0xc024) Cipher Suite: TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 (0xc028) Cipher Suite: TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256 (0xc023) Cipher Suite: TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 (0xc027) Cipher Suite: TLS_DHE_RSA_WITH_AES_256_CBC_SHA256 (0x006b) Cipher Suite: TLS_DHE_DSS_WITH_AES_256_CBC_SHA256 (0x006a) Cipher Suite: TLS_DHE_RSA_WITH_AES_128_CBC_SHA256 (0x0067) Cipher Suite: TLS_DHE_DSS_WITH_AES_128_CBC_SHA256 (0x0040) Cipher Suite: TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA (0xc00a) Cipher Suite: TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (0xc014) Cipher Suite: TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA (0xc009) Cipher Suite: TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA (0xc013) Cipher Suite: TLS_DHE_RSA_WITH_AES_256_CBC_SHA (0x0039) Cipher Suite: TLS_DHE_DSS_WITH_AES_256_CBC_SHA (0x0038) Cipher Suite: TLS_DHE_RSA_WITH_AES_128_CBC_SHA (0x0033) Cipher Suite: TLS_DHE_DSS_WITH_AES_128_CBC_SHA (0x0032) Cipher Suite: TLS_EMPTY_RENEGOTIATION_INFO_SCSV (0x00ff) Compression Methods Length: 1 Compression Methods (1 method) Extensions Length: 219 Extension: encrypt_then_mac (len=0) Type: encrypt_then_mac (22) Length: 0 Extension: extended_master_secret (len=0) Type: extended_master_secret (23) Length: 0 Extension: supported_versions (len=5) TLS 1.3, TLS 1.2 Type: supported_versions (43) Length: 5 Supported Versions length: 4 Supported Version: TLS 1.3 (0x0304) Supported Version: TLS 1.2 (0x0303) Extension: status_request_v2 (len=16) Type: status_request_v2 (17) Length: 16 Certificate Status List Length: 14 Certificate Status Type: OCSP Multi (2) Certificate Status Length: 4 Responder ID list Length: 0 Request Extensions Length: 0 Certificate Status Type: OCSP (1) Certificate Status Length: 4 Responder ID list Length: 0 Request Extensions Length: 0 Extension: application_layer_protocol_negotiation (len=14) Type: application_layer_protocol_negotiation (16) Length: 14 ALPN Extension Length: 12 ALPN Protocol Extension: signature_algorithms (len=34) Type: signature_algorithms (13) Length: 34 Signature Hash Algorithms Length: 32 Signature Hash Algorithms (16 algorithms) Signature Algorithm: ecdsa_secp256r1_sha256 (0x0403) Signature Hash Algorithm Hash: SHA256 (4) Signature Hash Algorithm Signature: ECDSA (3)
备注:内容来源于stack exchange,提问作者forumUsr
相关产品推荐
相关产品推荐

