Signing email - FIPS 140-2 compliant
My application needs to digitally sign email using the server's certificate from within WebLogic Server 8.1. The encryption algorithm implementations need to be FIPS 140-2 approved. We have no incoming mail, so signing is the only S/MIME functionality that I need. The weblogic.jar contains many of the certicom and rsa classes that could probably be used to sign, but I don't see anything there that could easily be leveraged to create the signed message.

I found bouncycastle.org, but they appear to have written their own JCE provider that is not FIPS 140-2 approved. The Sun JCE that comes with the JDK 1.4 would probably work for the provider, but it looks like bouncycastle is tied to its own provider.

I also found nsoftware's IP*Works! S/MIME V6 Java Server. Have any of you had any experience with this product?

Please let me know if you have written code you can share that will fit my requirements. Alternatively if you know of or have had any experience with other open source or commercial libraries I would be interest in hearing your experiences.

Mar 22, 2019