Jostle Supported Algorithms

Author: Shubham Kumar

Published: January 27, 2026

This document provides a complete reference for all cryptographic operations supported in the OpenSSL Jostle provider.

Note: Some algorithms might be missed from the list below. Please refer to the source code for the most accurate and up-to-date information.

1. Symmetric Block Ciphers

Padding Pattern:

  • ECB/CBC modes support NoPadding, PKCS5Padding, PKCS7Padding.

  • Stream modes (CFB, OFB, CTR) and AEAD modes (GCM, CCM, OCB) support NoPadding only.

  • Special purpose modes (XTS, WRAP, WRAP_PAD) support NoPadding only.

AES (Advanced Encryption Standard)

Property

Details

Key Sizes

128, 192, 256 bits

Supported Block Modes

ECB, CBC, CFB1, CFB8, CFB128, OFB, CTR, GCM, CCM, OCB, XTS, WRAP, WRAP_PAD

Implementation

AESBlockCipherSpi.java

Key Generator

AESKeyGenerator.java

Configuration

ProvAES.java

Unsupported Findings
(handling commented)

AES128: WRAP, WRAP_PAD, OCB, CCM (block_cipher_ctx.c)
AES192: WRAP, WRAP_PAD, OCB, CCM, XTS (block_cipher_ctx.c:221-232)
AES256: WRAP, WRAP_PAD, OCB, CCM (block_cipher_ctx.c:279-283)

ARIA

Property

Details

Key Sizes

128, 192, 256 bits

Supported Block Modes

ECB, CBC, CFB1, CFB8, CFB128, CTR, OFB, GCM, CCM

Implementation

ARIABlockCipherSpi.java

Configuration

ProvARIA.java

Unsupported Findings
(handling commented)

ARIA128: CCM, GCM (block_cipher_ctx.c)
ARIA192: CCM, GCM (block_cipher_ctx.c:375-376)
ARIA256: CCM, GCM (block_cipher_ctx.c:419-420)

CAMELLIA

Property

Details

Key Sizes

128, 192, 256 bits

Supported Block Modes

ECB, CBC, CFB1, CFB8, CFB128, OFB, CTR

Implementation

CAMELLIABlockCipherSpi.java

Configuration

ProvCAMELLIA.java

SM4

Property

Details

Key Sizes

128 bits

Supported Block Modes

ECB, CBC, CFB128, OFB, CTR

Implementation

SM4BlockCipherSpi.java

Configuration

ProvSM4.java

2. Post-Quantum Cryptography

ML-DSA (Module-Lattice-Based Digital Signature Algorithm)

Property

Details

Parameter Sets

ML-DSA-44, ML-DSA-65, ML-DSA-87

Security Levels

ML-DSA-44: NIST Level 2 (128-bit)
ML-DSA-65: NIST Level 3 (192-bit)
ML-DSA-87: NIST Level 5 (256-bit)

Signature Algorithms

MLDSA (generic, uses key to determine parameter set)
ML-DSA (alias for MLDSA)
ML-DSA-44, ML-DSA-65, ML-DSA-87
ML-DSA-EXTERNAL-MU (external message randomization)
ML-DSA-CALCULATE-MU (calculated message randomization)

Implementation

Key Pair Generator: MLDSAKeyPairGeneratorImpl.java
Signature Spi: MLDSASignatureSpi.java:28
Key Factory: MLDSAKeyFactorySpiImpl.java:28

Configuration

ProvMLDSA.java

SLH-DSA (Stateless Hash-Based Digital Signature Algorithm)

Property

Details

Parameter Sets

SLH-DSA-SHA2-128S, SLH-DSA-SHA2-128F, SLH-DSA-SHA2-192S, SLH-DSA-SHA2-192F, SLH-DSA-SHA2-256S, SLH-DSA-SHA2-256F, SLH-DSA-SHAKE-128S, SLH-DSA-SHAKE-128F, SLH-DSA-SHAKE-192S, SLH-DSA-SHAKE-192F, SLH-DSA-SHAKE-256S, SLH-DSA-SHAKE-256F

Hash Functions

SHA2-based (6 variants), SHAKE-based (6 variants)

Performance Variants

S (Small): Smaller signature size, slower signing
F (Fast): Larger signature size, faster signing

Security Levels

128-bit (SLH-DSA-SHA2-128S/F, SLH-DSA-SHAKE-128S/F)
192-bit (SLH-DSA-SHA2-192S/F, SLH-DSA-SHAKE-192S/F)
256-bit (SLH-DSA-SHA2-256S/F, SLH-DSA-SHAKE-256S/F)

Signature Algorithms

SLHDSA (generic, uses key to determine parameter set)
SLH-DSA (alias for SLHDSA)
SLH-DSA-SHA2-128S, SLH-DSA-SHA2-128F, SLH-DSA-SHA2-192S, SLH-DSA-SHA2-192F, SLH-DSA-SHA2-256S, SLH-DSA-SHA2-256F, SLH-DSA-SHAKE-128S, SLH-DSA-SHAKE-128F, SLH-DSA-SHAKE-192S, SLH-DSA-SHAKE-192F, SLH-DSA-SHAKE-256S, SLH-DSA-SHAKE-256F
SLH-DSA-PURE (pure message signing)
SLH-DSA-NONE (pre-hashed message)
DET-SLH-DSA-PURE (deterministic pure)
DET-SLH-DSA-NONE (deterministic pre-hashed)

Implementation

Key Pair Generator: SLHDSAKeyPairGenerator.java
Signature Spi: SLHDSASignatureSpi.java:26
Key Factory: SLHDSAKeyFactorySpi.java:28

Configuration

ProvSLHDSA.java

ML-KEM (Module-Lattice-Based Key Encapsulation Mechanism)

Property

Details

Parameter Sets

ML-KEM-512, ML-KEM-768, ML-KEM-1024

Security Levels

ML-KEM-512: NIST Level 1 (128-bit)
ML-KEM-768: NIST Level 3 (192-bit)
ML-KEM-1024: NIST Level 5 (256-bit)

Key Types

KeyPairGenerator: MLKEM, ML-KEM-512, ML-KEM-768, ML-KEM-1024
KeyGenerator: MLKEM, ML-KEM-512, ML-KEM-768, ML-KEM-1024
KeyFactory: MLKEM, ML-KEM-512, ML-KEM-768, ML-KEM-1024

Implementation

Key Generator: MLKEMKeyGenerator.java
Key Pair Generator: MLKEMKeyPairGenerator.java:28
Key Factory: MLKEMKeyFactorySpi.java:28

Configuration

ProvMLKEM.java

3. Key Derivation Functions (KDF)

PBKDF2 (Password-Based Key Derivation Function 2)

Property

Details

Algorithm Names

PBKDF2 (uses SHA-1 by default)
PBKDF2WithHmacSHA1, PBKDF2WithHmacSHA224, PBKDF2WithHmacSHA256, PBKDF2WithHmacSHA384, PBKDF2WithHmacSHA512, PBKDF2WithHmacSHA512-224, PBKDF2WithHmacSHA512-256
PBKDF2WithHmacSHA3-224, PBKDF2WithHmacSHA3-256, PBKDF2WithHmacSHA3-384, PBKDF2WithHmacSHA3-512
PBKDF2WithHmacBLAKE2B-512, PBKDF2WithHmacBLAKE2S-256
PBKDF2WithHmacSM3, PBKDF2WithHmacMD5, PBKDF2WithHmacMD5-SHA1, PBKDF2WithHmacRIPEMD160

HMAC Functions

SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, SHA-512/224, SHA-512/256
SHA3-224, SHA3-256, SHA3-384, SHA3-512
BLAKE2B-512, BLAKE2S-256
SM3, MD5, MD5-SHA1, RIPEMD160

Implementation

PBEKDF2SecretKeyFactory.java

Configuration

ProvPBEKDF.java

Scrypt

Property

Details

Algorithm Names

SCRYPT
1.3.6.1.4.1.11591.4.11 (OID format)

Parameters

N (CPU/memory cost), r (block size), p (parallelization)

Implementation

ScryptSecretKeyFactory.java

Configuration

ProvScryptKDF.java

4. Algorithms Present But Not Exposed

The following algorithms exist in the codebase but are NOT registered in the provider configuration.

Symmetric Ciphers (Unexposed)

You can find these algorithms defined in OSSLCipher.java but they are not registered in the provider.

Algorithm

Type

Available Modes

RC4

Stream

N/A

RC4_40

Stream

N/A

IDEA

Block

ECB, CFB64, OFB, CBC

RC2

Block

ECB, CBC, CFB64, OFB

RC2_40

Block

CBC

RC2_64

Block

CBC

BlowFish

Block

ECB, CBC, CFB64, OFB

CAST5

Block

ECB, CBC, CFB64, OFB

ChaCha20

Stream

N/A

ChaCha20-Poly1305

AEAD

N/A

SEED

Block

ECB, CBC, CFB128, OFB

Signature Algorithms (Unexposed)

You can find these algorithms defined in SigAlgs.java but they are not registered in the provider.

Algorithm

DSA_SHA1

DSA_SHA2_{256,384,512}

DSA_SHA3_{224,256,384,512}

RSA_SHA2_{224,256,384,512}

RSA_SHA3_{224,256,384,512}

ECDSA_SHA2_{224,256,384,512}

ECDSA_SHA3_{224,256,384,512}

ED25519

ED25519_CTX

ED25519_PH

ED448

ED448_PH