Bouncy Castle Crypto Provider Package version 1.59 now available

classic Classic list List threaded Threaded
1 message Options
Reply | Threaded
Open this post in threaded view
|

Bouncy Castle Crypto Provider Package version 1.59 now available

Jon Eaves
Release 1.59 is now out.

Further work has been done on improving the BCJSSE provider and the
vulnerability described in CVE-2017-13098 has been fixed. Most PQC
algorithms can now have their keys stored in BC key stores, the
algorithms GOST3412-2015 and Blake2s have been added, support has been
added for Unified Cofactor EC Diffie-Hellman, and signature algorithm
support has been added for SHA-3. A number of other enhancements and bug
fixes have also been made.

Further details on other additions and bug fixes can be found in the
release notes at:

https://www.bouncycastle.org/releasenotes.html

Thanks also goes to other people and organisations who have
contributed/donated to the project and you can find the updated list at

https://www.bouncycastle.org/contributors.html

We would also like to thank holders of Crypto Workshop support
contracts as we were again able to fund extra work on this release
through time available from those.

For the actual release and other details go to our latest releases page:

https://www.bouncycastle.org/latest_releases.html

And for those who like living on the bleeding edge, the betas for future
releases can be downloaded from:

https://www.bouncycastle.org/betas/

and changes to the code base can be tracked via:

https://github.com/bcgit

In other news, work is ongoing for a new book to document all
these APIs as the older one "Beginning Cryptography with Java" is now
out of date. If you are interested, you can follow the progress of the
new book, "Java Cryptography: Tools and Techniques", and sign up for
notifications on it by going to:

https://leanpub.com/javacryptotoolsandtech

It is a little behind schedule but it's making progress!

On the FIPS front, the Java FIPS 1.0.1 release has now completed testing
and is under NIST review. A list of issues fixed in it can be found at:

https://www.bouncycastle.org/fips-java/BC-FJA-KnownIssues-1.0.0.csv

BC FIPS 1.0.1 is now available under our early access program.

If you are interested helping support the Bouncy Castle project through
donation, you can find the details on how to donate via PayPal or
Bitcoin, at:

https://www.bouncycastle.org/donate

If you prefer to use direct bank transfer please feel free to discuss it
with us by contacting us at [hidden email] and we'll be happy
help. The Legion of the Bouncy Castle Inc is a registered Australian
charity based in the State of Victoria, Australia.

If you wish to sponsor specific work on Bouncy Castle, get early access
to the FIPS APIs under development, or get a commercial support contract
for the APIs please contact us at Crypto Workshop
(https://www.cryptoworkshop.com )

Remember, you can also follow this project on Facebook (
https://www.facebook.com/legionofthebouncycastle ), Google+ (
https://plus.google.com/+BouncycastleOrgAPIs/posts ) and/or Twitter (
https://twitter.com/bccrypto ).

Finally, for users of the maven repositories, 1.59 should be appearing
shortly on maven central. The GitHub repository has been updated as well.