This page was not yet optimized for use on mobile devices.
Oracle OpenSSL FIPS Object Module
Certificate details
| Certificate ID | #3335 |
|---|---|
| Status | historical |
| Historical reason | Moved to historical list due to sunsetting |
| Validation dates | 03.12.2018 , 18.07.2019 , 29.04.2020 , 23.10.2020 , 02.03.2021 , 17.05.2021 , 03.08.2021 , 29.07.2022 |
| Standard | FIPS 140-2 |
| Security level | 1 |
| Type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Caveat | When operated in FIPS mode. No assurance of the minimum strength of generated keys. |
| Exceptions |
|
| Description | Oracle OpenSSL FIPS Object Module is a software library providing a C language application program interface (API) for use by processes that require cryptographic services. It is implemented in products such as Oracle Solaris 11, Oracle Integrated Lights Out Manager (ILOM), and Oracle ZFS Storage Appliance. |
| Tested configurations |
|
| Vendor | Oracle Corporation http://www.oracle.com |
| Lab | Acumen Security |
| Algorithms |
|
| References | This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates. |
Security policy
Extracted keywords
Symmetric Algorithms
AES-128, AES-192, AES-256, AES, TDES, Triple-DES, TDEA, HMAC, CMACAsymmetric Algorithms
ECDH, ECDSA, ECC, Diffie-Hellman, DH, DSAHash functions
SHA-1, SHA1, SHA-224, SHA-384, SHA-512, SHA-256, SHA256, SHA-2, SHA2Schemes
Key AgreementProtocols
TLSRandomness
DRBGLibraries
OpenSSLElliptic Curves
P-224, P-384, P-192, P-256, P-521, K-233, K-409, B-233, B-409, B-163, K-283, K-571Block cipher modes
ECB, CBC, CTR, CFB, OFB, GCM, CCM, XTSSecurity level
Level 1, level 1Cross-references
IncomingAutomated analysis
Automated inference - use with caution
All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.No automatically derived data are available in this section.
Cross-references
Loading...
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate was first processed.
{
"_type": "sec_certs.sample.fips.FIPSCertificate",
"cert_id": 3335,
"dgst": "0457c48d8fc39719",
"heuristics": {
"_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
"algorithms": {
"_type": "Set",
"elements": [
"RSA#A2511",
"#C1651",
"DSA#A2514",
"Triple-DES#2735",
"SHS#A2514",
"DSA#C1651",
"RSA#2921",
"SHS#A861",
"#2129",
"RSA#A2514",
"DRBG#C1651",
"#5445",
"AES#C1651",
"AES#A2511",
"#1449",
"HMAC#C1651",
"Triple-DES#A2511",
"AES#A2514",
"HMAC#A2511",
"AES#A861",
"#3603",
"#A861",
"#2921",
"SHS#A2511",
"AES#5445",
"DSA#A2511",
"SHS#C1651",
"ECDSA#C1651",
"Triple-DES#A2514",
"ECDSA#A2511",
"#2735",
"SHS#4364",
"Triple-DES#A861",
"ECDSA#A861",
"DRBG#A2511",
"RSA#C1651",
"ECDSA#A2514",
"DSA#1400",
"HMAC#A2514",
"#A2514",
"RSA#A861",
"DRBG#2129",
"DRBG#A861",
"DRBG#A2514",
"HMAC#A861",
"ECDSA#1449",
"Triple-DES#C1651",
"#4364",
"DSA#A861",
"HMAC#3603",
"#1400",
"#A2511"
]
},
"cpe_matches": null,
"direct_transitive_cves": {
"_type": "Set",
"elements": [
"CVE-2016-2334",
"CVE-2017-3623",
"CVE-1999-0046"
]
},
"extracted_versions": {
"_type": "Set",
"elements": [
"-"
]
},
"indirect_transitive_cves": {
"_type": "Set",
"elements": [
"CVE-2016-2334",
"CVE-2017-3623",
"CVE-1999-0046"
]
},
"module_processed_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": {
"_type": "Set",
"elements": [
"3503"
]
},
"directly_referencing": null,
"indirectly_referenced_by": {
"_type": "Set",
"elements": [
"3503",
"3569",
"4015",
"3638",
"4024"
]
},
"indirectly_referencing": null
},
"module_prunned_references": {
"_type": "Set",
"elements": []
},
"policy_processed_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": {
"_type": "Set",
"elements": [
"4178",
"4142"
]
},
"directly_referencing": null,
"indirectly_referenced_by": {
"_type": "Set",
"elements": [
"4178",
"4142"
]
},
"indirectly_referencing": null
},
"policy_prunned_references": {
"_type": "Set",
"elements": []
},
"related_cves": null,
"verified_cpe_matches": null
},
"pdf_data": {
"_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
"br1_deviations": 43,
"br1_tables": null,
"is_br1_format": false,
"keywords": {
"asymmetric_crypto": {
"ECC": {
"ECC": {
"ECC": 2
},
"ECDH": {
"ECDH": 1
},
"ECDSA": {
"ECDSA": 15
}
},
"FF": {
"DH": {
"DH": 6,
"Diffie-Hellman": 4
},
"DSA": {
"DSA": 16
}
}
},
"certification_process": {},
"cipher_mode": {
"CBC": {
"CBC": 3
},
"CCM": {
"CCM": 4
},
"CFB": {
"CFB": 3
},
"CTR": {
"CTR": 1
},
"ECB": {
"ECB": 3
},
"GCM": {
"GCM": 8
},
"OFB": {
"OFB": 1
},
"XTS": {
"XTS": 5
}
},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {
"OpenSSL": {
"OpenSSL": 41
}
},
"crypto_protocol": {
"TLS": {
"TLS": {
"TLS": 2
}
}
},
"crypto_scheme": {
"KA": {
"Key Agreement": 1
}
},
"device_model": {},
"ecc_curve": {
"NIST": {
"B-163": 2,
"B-233": 2,
"B-409": 2,
"K-233": 2,
"K-283": 1,
"K-409": 1,
"K-571": 1,
"P-192": 6,
"P-224": 4,
"P-256": 2,
"P-384": 2,
"P-521": 2
}
},
"eval_facility": {
"Acumen": {
"Acumen Security": 1
}
},
"fips_cert_id": {},
"fips_certlike": {
"Certlike": {
"# A2514": 1,
"AES 128/192/256": 1,
"AES GCM 3": 1,
"AES, 256": 1,
"AES-128": 3,
"AES-128 128": 1,
"AES-192": 2,
"AES-192 192": 1,
"AES-256": 2,
"AES-256 256": 1,
"DRBG 1": 1,
"HMAC SHA-1": 1,
"HMAC-SHA-1": 28,
"HMAC-SHA1": 2,
"PKCS#1": 2,
"SHA- 256": 2,
"SHA-1": 19,
"SHA-1 128": 1,
"SHA-1, 224": 18,
"SHA-2": 3,
"SHA-2 (224": 2,
"SHA-224": 16,
"SHA-256": 3,
"SHA-384": 5,
"SHA-512": 4,
"SHA-512 256": 1,
"SHA1": 2,
"SHA2": 1,
"SHA256": 2
}
},
"fips_security_level": {
"Level": {
"Level 1": 1,
"level 1": 1
}
},
"hash_function": {
"SHA": {
"SHA1": {
"SHA-1": 38,
"SHA1": 2
},
"SHA2": {
"SHA-2": 5,
"SHA-224": 16,
"SHA-256": 3,
"SHA-384": 5,
"SHA-512": 5,
"SHA2": 1,
"SHA256": 2
}
}
},
"ic_data_group": {},
"javacard_api_const": {},
"javacard_packages": {},
"javacard_version": {},
"os_name": {},
"pq_crypto": {},
"randomness": {
"PRNG": {
"DRBG": 20
}
},
"side_channel_analysis": {},
"standard_id": {
"FIPS": {
"FIPS 140-2": 17,
"FIPS 180-4": 2,
"FIPS 186-2": 4,
"FIPS 186-4": 8,
"FIPS 197": 2,
"FIPS 198": 1,
"FIPS 198-1": 1
},
"NIST": {
"NIST SP 800-38D": 1,
"SP 800-131A": 1,
"SP 800-133": 1,
"SP 800-135": 1,
"SP 800-38A": 2,
"SP 800-38B": 2,
"SP 800-38C": 2,
"SP 800-38D": 2,
"SP 800-38E": 1,
"SP 800-56A": 2,
"SP 800-56C": 1,
"SP 800-67": 1,
"SP 800-89": 1,
"SP 800-90A": 4
},
"PKCS": {
"PKCS#1": 1
},
"RFC": {
"RFC 5246": 1,
"RFC 5288": 1
}
},
"symmetric_crypto": {
"AES_competition": {
"AES": {
"AES": 19,
"AES-128": 4,
"AES-192": 3,
"AES-256": 3
}
},
"DES": {
"3DES": {
"TDEA": 1,
"TDES": 1,
"Triple-DES": 7
}
},
"constructions": {
"MAC": {
"CMAC": 16,
"HMAC": 7
}
}
},
"tee_name": {},
"tls_cipher_suite": {},
"vendor": {},
"vulnerability": {}
},
"module_algorithms": {
"_type": "Set",
"elements": [
"RSA#A2511",
"DSA#A2514",
"Triple-DES#2735",
"SHS#A2514",
"DSA#C1651",
"RSA#2921",
"SHS#A861",
"RSA#A2514",
"DRBG#C1651",
"AES#C1651",
"AES#A2511",
"HMAC#C1651",
"Triple-DES#A2511",
"AES#A2514",
"HMAC#A2511",
"AES#A861",
"SHS#A2511",
"AES#5445",
"DSA#A2511",
"SHS#C1651",
"ECDSA#C1651",
"Triple-DES#A2514",
"ECDSA#A2511",
"SHS#4364",
"Triple-DES#A861",
"ECDSA#A861",
"DRBG#A2511",
"RSA#C1651",
"ECDSA#A2514",
"DSA#1400",
"HMAC#A2514",
"RSA#A861",
"DRBG#2129",
"DRBG#A861",
"DRBG#A2514",
"HMAC#A861",
"ECDSA#1449",
"Triple-DES#C1651",
"DSA#A861",
"HMAC#3603"
]
},
"policy_algorithms": {
"_type": "Set",
"elements": [
"#C1651",
"#1449",
"#2735",
"#4364",
"#1400",
"#3603",
"#A861",
"#A2511",
"#2129",
"#2921",
"#5445",
"#A2514"
]
},
"policy_metadata": {
"/CreationDate": "D:20220728174322-07\u002700\u0027",
"/Creator": "Microsoft\u00ae Word for Microsoft 365",
"/ModDate": "D:20220728174322-07\u002700\u0027",
"/Producer": "Microsoft\u00ae Word for Microsoft 365",
"pdf_file_size_bytes": 682093,
"pdf_hyperlinks": {
"_type": "Set",
"elements": [
"https://csrc.nist.gov/Projects/Cryptographic-Algorithm-Validation-Program/Validation/Validation-List/SHS#4364",
"https://csrc.nist.gov/Projects/Cryptographic-Algorithm-Validation-Program/Validation/Validation-List/DSA#1400",
"http://csrc.nist.gov/publications/nistpubs/800-67/SP800-67.pdf",
"http://csrc.nist.gov/publications/fips/fips198-1/FIPS-198-1_final.pdf",
"https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=13352",
"http://csrc.nist.gov/publications/nistpubs/800-131A/sp800-131A.pdf",
"https://github.com/oracle/solaris-openssl-fips/",
"https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?validation=35122",
"http://www.oracle.com/",
"http://csrc.nist.gov/publications/nistpubs/800-90/SP800-90revised_March2007.pdf",
"https://csrc.nist.gov/Projects/Cryptographic-Algorithm-Validation-Program/Validation/Validation-List/TDES#2735",
"http://csrc.nist.gov/publications/fips/fips180-3/fips180-3_final.pdf",
"http://csrc.nist.gov/publications/fips/fips197/fips-197.pdf",
"http://csrc.nist.gov/publications/fips/fips186-3/fips_186-3.pdf",
"http://csrc.nist.gov/publications/fips/fips140-2/fips1402.pdf",
"https://csrc.nist.gov/Projects/Cryptographic-Algorithm-Validation-Program/Validation/Validation-List/RSA#2921",
"http://csrc.nist.gov/publications/nistpubs/800-38D/SP-800-38D.pdf",
"http://www.arm.com/products/processors/technologies/neon.php",
"https://csrc.nist.gov/Projects/Cryptographic-Algorithm-Validation-Program/Validation/Validation-List/ECDSA#1449",
"https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?validation=32292",
"https://csrc.nist.gov/Projects/Cryptographic-Algorithm-Validation-Program/Validation/Validation-List/HMAC#3603",
"https://csrc.nist.gov/Projects/Cryptographic-Algorithm-Validation-Program/Validation/Validation-List/DRBG#2129",
"https://csrc.nist.gov/projects/cryptographic-module-validation-program",
"http://csrc.nist.gov/publications/nistpubs/800-89/SP-800-89_November2006.pdf",
"https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?validation=35125",
"https://linux-git.us.oracle.com/oraclelinux/oracle-openssl-fips/tree/OpenSSL_2.0.13_OracleFIPS_1.1",
"https://tools.ietf.org/html/rfc5288",
"http://www.intel.com/support/processors/sb/CS-030123.htm?wapkw=sse2",
"https://tools.ietf.org/html/rfc5246",
"https://github.com/oracle/solaris-openssl-fips/releases/download/v1.0/OpenSSL_2.0.13_OracleFIPS_1.0.tar.gz",
"http://csrc.nist.gov/publications/nistpubs/800-56A/SP800-56A_Revision1_Mar08-2007.pdf",
"https://csrc.nist.gov/Projects/Cryptographic-Algorithm-Validation-Program/Validation/Validation-List/AES#5445"
]
},
"pdf_is_encrypted": false,
"pdf_number_of_pages": 29
}
},
"state": {
"_type": "sec_certs.sample.fips.InternalState",
"module": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": null,
"source_hash": null,
"txt_hash": null
},
"policy": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": "eb1977d0be2a051de3c797d5e0a9af219e027f4ea32f23a28628963f90c54edc",
"source_hash": "2b005153baa0d4995c55d796cea80dfef422400357723b3b8f637e2f3edb972c",
"txt_hash": "41a339d07c022dffdba2ef97af8ccb2e1b425335c853c8570e49d53ef630ad70"
}
},
"web_data": {
"_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
"caveat": "When operated in FIPS mode. No assurance of the minimum strength of generated keys.",
"certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/Dec2018Cert.pdf",
"date_sunset": null,
"description": "Oracle OpenSSL FIPS Object Module is a software library providing a C language application program interface (API) for use by processes that require cryptographic services. It is implemented in products such as Oracle Solaris 11, Oracle Integrated Lights Out Manager (ILOM), and Oracle ZFS Storage Appliance.",
"embodiment": "Multi-Chip Stand Alone",
"exceptions": [
"Roles, Services, and Authentication: Level 2",
"Physical Security: N/A",
"Design Assurance: Level 3",
"Mitigation of Other Attacks: N/A"
],
"fw_versions": null,
"historical_reason": "Moved to historical list due to sunsetting",
"hw_versions": null,
"level": 1,
"mentioned_certs": {},
"module_name": "Oracle OpenSSL FIPS Object Module",
"module_type": "Software",
"revoked_link": null,
"revoked_reason": null,
"standard": "FIPS 140-2",
"status": "historical",
"sw_versions": "OpenSSL_2.0.13_OracleFIPS_1.0; OpenSSL_2.0.13_OracleFIPS_1.1; OpenSSL_2.0.13_OracleFIPS_1.2",
"tested_conf": [
"Oracle ILOM OS v5.1 running on AST2600 Server Management Processor with Oracle ILOM SP v6 (ARM v7) without PAA",
"Oracle\u00ae ILOM OS v3.0 running on Emulex Pilot-4 Orion mainboard with Oracle\u00ae ILOM SP v2 (ARM v5) without PAA",
"Oracle\u00ae ILOM OS v3.0 running on Oracle X5-2 server with Oracle\u00ae ILOM SP v3 (ARM v7) with PAA",
"Oracle\u00ae ILOM OS v3.0 running on Oracle X5-2 server with Oracle\u00ae ILOM SP v3 (ARM v7) without PAA",
"Oracle\u00ae ILOM OS v4.0 running on AST2400 Server Management Processor with Oracle\u00ae ILOM SP v4 (ARM v9) without PAA",
"Oracle\u00ae ILOM OS v5.0 running on AST2520 Server Management Processor with Oracle\u00ae ILOM SP v5 (ARM v11) without PAA",
"Oracle\u00ae Linux 7.6 64 bit running on Oracle\u00ae X7-2 Server with AMD\u00ae EPYC\u00ae 7551 with PAA",
"Oracle\u00ae Linux 7.6 64 bit running on Oracle\u00ae X7-2 Server with AMD\u00ae EPYC\u00ae 7551 without PAA",
"Oracle\u00ae Linux 7.6 64 bit running on Oracle\u00ae X7-2 Server with Intel\u00ae Xeon\u00ae Silver 4114 with PAA",
"Oracle\u00ae Linux 7.6 64 bit running on Oracle\u00ae X7-2 Server with Intel\u00ae Xeon\u00ae Silver 4114 without PAA",
"Oracle\u00ae Linux 7.8 64 bit running on Marvell MIPS III 64-bit (T73) without PAA",
"Oracle\u00ae Linux 7.8 64 bit running on Marvell ThunderX2 (ARM 8.1) without PAA",
"Oracle\u00ae Solaris 11.4 running on Oracle S7-2L with an Oracle\u00ae SPARC S7 without PAA",
"Oracle\u00ae Solaris 11.4 running on Oracle S7-2L with Oracle\u00ae SPARC S7 with PAA",
"Oracle\u00ae Solaris 11.4 running on Oracle X5-2 server with Intel Xeon E5-2600 with PAA",
"Oracle\u00ae Solaris 11.4 running on Oracle X5-2 server with Intel Xeon E5-2600 without PAA",
"Oracle\u00ae Solaris 11.4 running on Oracle\u00ae SPARC T8 server with SPARC M8 with PAA",
"Oracle\u00ae Solaris 11.4 running on Oracle\u00ae SPARC T8 server with SPARC M8 without PAA",
"Oracle\u00ae Solaris 11.4 running on Oracle\u00ae X8-2 server with Intel Xeon Gold 5200 series with PAA",
"Oracle\u00ae Solaris 11.4 running on Oracle\u00ae X8-2 server with Intel Xeon Gold 5200 series without PAA",
"Oracle\u00ae ZFS Storage OS 8.8 running on Oracle\u00ae ZFS Storage ZS5-2 with Intel Xeon E5 with PAA",
"Oracle\u00ae ZFS Storage OS 8.8 running on Oracle\u00ae ZFS Storage ZS5-2 with Intel Xeon E5 without PAA",
"Oracle\u00ae ZFS Storage OS 8.8 running on Oracle\u00ae ZFS Storage ZS5-4 with Intel Xeon E7",
"Oracle\u00ae ZFS Storage OS 8.8 running on Oracle\u00ae ZFS Storage ZS5-4 with Intel Xeon E7 without PAA",
"Windows Server 2019 on VMWare ESXi 6.0 running on Oracle Server E2-2C with AMD\u00ae EPYC\u00ae 7742 with PAA",
"Windows Server 2019 on VMWare ESXi 6.0 running on Oracle Server E2-2C with AMD\u00ae EPYC\u00ae 7742 without PAA",
"Windows Server 2019 on VMWare ESXi 6.0 running on Oracle Server E2-2C with Intel\u00ae Xeon\u00ae CPU ES-2695 v4 with PAA",
"Windows Server 2019 on VMWare ESXi 6.0 running on Oracle Server E2-2C with Intel\u00ae Xeon\u00ae CPU ES-2695 v4 without PAA (single-user mode)"
],
"validation_history": [
{
"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
"date": "2018-12-03",
"lab": "Acumen Security",
"validation_type": "Initial"
},
{
"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
"date": "2019-07-18",
"lab": "Acumen Security",
"validation_type": "Update"
},
{
"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
"date": "2020-04-29",
"lab": "Acumen Security",
"validation_type": "Update"
},
{
"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
"date": "2020-10-23",
"lab": "Acumen Security",
"validation_type": "Update"
},
{
"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
"date": "2021-03-02",
"lab": "Acumen Security",
"validation_type": "Update"
},
{
"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
"date": "2021-05-17",
"lab": "Acumen Security",
"validation_type": "Update"
},
{
"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
"date": "2021-08-03",
"lab": "Acumen Security",
"validation_type": "Update"
},
{
"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
"date": "2022-07-29",
"lab": "Acumen Security",
"validation_type": "Update"
}
],
"vendor": "Oracle Corporation",
"vendor_url": "http://www.oracle.com"
}
}