Skip to content

Decouple CertUtil to use both BC and BCFIPS - #84

Open
strehle wants to merge 1 commit into
vt-middleware:mainfrom
sap-contributions:decouple-bc
Open

strehle wants to merge 1 commit into
vt-middleware:mainfrom
sap-contributions:decouple-bc

Conversation

@strehle

@strehle strehle commented May 4, 2026 •

Copy link
Copy Markdown

This PR was created because of an issue with the chain
From spring-security we load opensaml5 and this uses this project.

Until a certain version is was possible to run spring and opensaml with BCFIPS variant of bouncy castle but with the PR #68 there was a hard dependency to BC introduced.

This PR removes the hard dependency and allows again both providers

@dfish3r

dfish3r commented May 29, 2026

Copy link
Copy Markdown
Member

Sorry it's taken me so long to get to this PR. I'd like to add a test with the BCFIPS provider available. What does your classpath look like when using the FIPS provider? Do you add bc-fips and exclude bcprov-jdk18on? Can these two jars co-exist?

@strehle

strehle commented May 29, 2026 •

Copy link
Copy Markdown
Author

Sorry it's taken me so long to get to this PR. I'd like to add a test with the BCFIPS provider available. What does your classpath look like when using the FIPS provider? Do you add bc-fips and exclude bcprov-jdk18on? Can these two jars co-exist?

No they cannot co-exist, because they offere the same APIs behind their providers, so there would be classpath collisions or runtime errors. Both offer the usage of security providers, but in your case you.used directly classes from one providers, unfortunatly for us the wrong ones. Yes we exclude the bcprov-jdk18* libraries and use these here https://github.com/cloudfoundry/uaa/blob/develop/gradle/libs.versions.toml . Your library is used in opensaml and our goal is to use opensaml with FIPS compliant libraries

FYI here is a post with more insights about co-existance: https://security.stackexchange.com/questions/274212/what-is-the-main-difference-between-bcprov-and-bc-fips-bouncycastle-jar
It may work to have both libraries in classpath but the usage must be separated means use the security providers to access the libraries

@strehle

strehle commented Sep 9, 2026

Copy link
Copy Markdown
Author

Sorry it's taken me so long to get to this PR. I'd like to add a test with the BCFIPS provider available. What does your classpath look like when using the FIPS provider? Do you add bc-fips and exclude bcprov-jdk18on? Can these two jars co-exist?

Do you need more info in order to decide about this PR ? In general BC and BCFIPS provide same functions and you could have both libraries in dependency but during runtime you need to use one of them only and in our case we have only BCFIPS available.

With this PR you simply abstract the use of BC

@dfish3r

dfish3r commented Sep 22, 2026

Copy link
Copy Markdown
Member

I do plan to get this into main and cut a new release by the end of the year. I'm completely underwater with other projects and haven't had time to review.

@strehle

strehle commented Sep 22, 2026

Copy link
Copy Markdown
Author

I do plan to get this into main and cut a new release by the end of the year. I'm completely underwater with other projects and haven't had time to review.

Thanks a lot that it good enough to plan because I will then ping the opensaml project to adopt this in order to resolve our issue

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants