FIPS compliance
It is a best practice to make your BlackBerry Dynamics apps compliant with U.S. Federal Information Processing Standards (FIPS) 140-3.The BlackBerry Dynamics SDK distribution contains FIPS canisters and tools.
- Algorithms that were restricted in FIPS 140-2 are still restricted in 140-3.
- 140-3 adds algorithms such as the SHA-3 family and post-quantum cryptography (ML-KEM, ML-DSA, SLH-DSA).
- Certain algorithms that were allowed in 140-2 are no longer supported in 140-3, including the following (for most items below, some legacy uses are allowed; see the link provided above for details):
- 3-key and 2-key TDEA encryption
- 2-key Triple-DES for encryption
- Skipjack for encryption
- SHA-1 for digital signatures
- RSA signatures less than 2048 bits
- Most DSA signatures
- ECDSA P-192 and similar that are less than 224-bit
- Review the requirements and supported standards for FIPS 140-3 to confirm that your apps are compliant.
The BlackBerry UEM administrator enables FIPS compliance using a BlackBerry Dynamics profile in the UEM management console. If enabled, BlackBerry Dynamics apps must start in FIPS-compliant mode. The SDK determines whether a service is running in FIPS mode when the app communicates with the server to receive policies.
- The use of MD4 and MD5 are prohibited. As a result, access to NTLM-protected or NTLM2-protected web pages and files is blocked.
- In secure socket key exchanges with ephemeral keys, with servers that are not configured to use Diffie-Hellman keys of sufficient length, BlackBerry Dynamics retries with static RSA cipher suites.
- When you enable FIPS compliance, user certificates must use encryption that meets FIPS standards. If a user tries to import a certificate with encryption that is not compliant, the user receives an error message indicating that the certificate is not allowed and cannot be imported.
- If FIPS is enabled in the assigned BlackBerry Dynamics profile, when a BlackBerry Dynamics app calls an S/MIME API and uses Triple-DES for message encryption, the BlackBerry Dynamics SDK will return an error. Alternative ciphers that are supported when FIPS is enabled include AES-128-CBC and AES-256-CBC.
- For iOS, when you build for testing with the x86 64-bit simulator, FIPS mode is not enforced. As a result, you might see a difference in behavior with the simulator compared to actual operation. BlackBerry recommends that you always test your app on actual iOS hardware and not rely exclusively on the simulation.