FIPS compliance

It is a best practice to make your BlackBerry Dynamics apps compliant with U.S. Federal Information Processing Standards (FIPS) 140-3.The BlackBerry Dynamics SDK distribution contains FIPS canisters and tools.

The BlackBerry Dynamics SDK upgraded to FIPS 140-3 in SDK version 15.0, replacing FIPS 140-2, to provide stronger, more modern security requirements. For more information and full details about FIPS 140-3 and 140-2, see NIST: Cryptographic Module Validation Program. Take note of the following regarding the upgrade to FIPS 140-3:
  • Algorithms that were restricted in FIPS 140-2 are still restricted in 140-3.
  • 140-3 adds algorithms such as the SHA-3 family and post-quantum cryptography (ML-KEM, ML-DSA, SLH-DSA).
  • Certain algorithms that were allowed in 140-2 are no longer supported in 140-3, including the following (for most items below, some legacy uses are allowed; see the link provided above for details):
    • 3-key and 2-key TDEA encryption
    • 2-key Triple-DES for encryption
    • Skipjack for encryption
    • SHA-1 for digital signatures
    • RSA signatures less than 2048 bits
    • Most DSA signatures
    • ECDSA P-192 and similar that are less than 224-bit
  • Review the requirements and supported standards for FIPS 140-3 to confirm that your apps are compliant.

The BlackBerry UEM administrator enables FIPS compliance using a BlackBerry Dynamics profile in the UEM management console. If enabled, BlackBerry Dynamics apps must start in FIPS-compliant mode. The SDK determines whether a service is running in FIPS mode when the app communicates with the server to receive policies.

FIPS compliance enforces the following constraints:
  • The use of MD4 and MD5 are prohibited. As a result, access to NTLM-protected or NTLM2-protected web pages and files is blocked.
  • In secure socket key exchanges with ephemeral keys, with servers that are not configured to use Diffie-Hellman keys of sufficient length, BlackBerry Dynamics retries with static RSA cipher suites.
Note:
  • When you enable FIPS compliance, user certificates must use encryption that meets FIPS standards. If a user tries to import a certificate with encryption that is not compliant, the user receives an error message indicating that the certificate is not allowed and cannot be imported.
  • If FIPS is enabled in the assigned BlackBerry Dynamics profile, when a BlackBerry Dynamics app calls an S/MIME API and uses Triple-DES for message encryption, the BlackBerry Dynamics SDK will return an error. Alternative ciphers that are supported when FIPS is enabled include AES-128-CBC and AES-256-CBC.
  • For iOS, when you build for testing with the x86 64-bit simulator, FIPS mode is not enforced. As a result, you might see a difference in behavior with the simulator compared to actual operation. BlackBerry recommends that you always test your app on actual iOS hardware and not rely exclusively on the simulation.