A Spring Boot application must comply with FIPS 140-2 cryptographic standards. Which configuration change is required?
-
A
Setting spring.security.crypto.strength=256 in application.properties
-
B
Running the JVM with a FIPS-approved security provider such as Bouncy Castle FIPS and restricting algorithms accordingly
-
C
Enabling AES-256 in Spring Security's password encoder only
-
D
Configuring TLS 1.3 in the embedded Tomcat server