Citrix FIPS Cryptographic Module

Certificate #2988

Webpage information

Status historical
Historical reason SP 800-56Arev3 transition
Validation dates 10.08.2017 , 07.02.2019 , 23.08.2019 , 30.09.2020 , 06.01.2021
Standard FIPS 140-2
Security level 1
Type Software-Hybrid
Embodiment Multi-Chip Stand Alone
Caveat When operated in FIPS Mode. No assurance of the minimum strength of generated keys
Exceptions
  • Mitigation of Other Attacks: N/A
Description The Citrix FIPS Cryptographic Module is a software toolkit which provides various cryptographic functions to support the Citrix product portfolio.
Version (Hardware) ARM v8-A, ARM v7-A, Intel Core i7 4th Generation, Intel Core i7 6th Generation, Intel Core i7 8th Generation, Intel Xeon 5600 series, Intel Xeon E5-2400 v4 series, Intel Xeon E5-2600 v2 series, Intel Xeon E5-2600 v3 series and Intel Xeon E5-2600 v4 series
Tested configurations
  • Android 4.4 running on a Google Nexus 5 (LG D820) with PAA
  • Android 5 running on a Google Nexus 6 (Motorola Nexus 6 XT11003) with PAA
  • Android 6 running on a Google Nexus 6 (Motorola Nexus 6 XT11003) with PAA
  • Android 6 running on a Samsung Galaxy S6 (SM-G920T) with PAA
  • Android 7 running on a Google Nexus 5X (LG H790) with PAA
  • Android 7 running on a Google Nexus 6 (Motorola Nexus 6 XT11003) with PAA
  • Android 8 64bit running on a Google Pixel 2 with ARM v8-A with PAA
  • Android 9 running on a Google Pixel 2 with ARM v8-A with PAA
  • FreeBSD 8.4 32bit running on a Citrix NetScaler MPX-14000-FIPS with PAA
  • FreeBSD 8.4 64bit running on a Citrix NetScaler MPX-14000-FIPS with PAA
  • iOS 10 64bit running on an Apple 12.9-inch iPad Pro (A1584) with PAA
  • iOS 11 running on an iPhone X with ARM v8-A with PAA
  • Linux 3.10 64bit running on a CyberPowerPC GLC2460 with Intel Core i7 [8th Generation] with PAA
  • Linux 3.13 64bit running on a Lenovo 20EV002JUS with PAA
  • Linux 3.16 on ESXi 5 64bit running on a HP ProLiant DL2000 with PAA
  • Linux 3.16 on Hyper-V on Windows Server 2012 R2 64bit running on a HP ProLiant DL2000 with PAA
  • Linux 3.16 on XenServer 6 64bit running on a Dell PowerEdge C6100 with PAA
  • Linux 4.15 64bit running on a CyberPowerPC GLC2460 with Intel Core i7 [8th Generation with PAA
  • Linux 4.15 64bit running on a HPE ProLiant BL460c Gen9 with Intel Xeon E5-26XX v3 with PAA
  • Linux 4.15 64bit running on a HPE Proliant BL460c Gen9 with Intel Xeon E5-26XX v4 series with PAA
  • Linux 4.x on ESXi 5 64bit running on a HPE ProLiant BL460c Gen9 with Intel Xeon E5-26XX v4 series with PAA
  • Linux 4.x on Hyper-V on Windows Server 2012 R2 64bit running on a HPE ProLiant BL460c Gen9 with Intel Xeon E5-26XX v4 series with PAA
  • Linux 4.x on XenServer 7 64bit running on a Dell PowerEdge R320 with Intel Xeon E5-24XX v2 series with PAA
  • Linux 4.x on XenServer 7 64bit running on a HPE ProLiant BL460c Gen9 with Intel Xeon E5-26XX v4 series with PAA
  • Mac OS X 10.12 64bit running on an Apple Macbook Pro (A1398) with PAA
  • Mac OS X 10.13 64bit running on an Apple Mac Mini with Intel Corei7 [4th Generation] with PAA
  • NoTouch Desktop running on an N-computing RX-HDX for Citrix with ARM v8-A with PAA
  • ViewSonic Thin OS running on a ViewSonic VS16585 with PAA
  • Windows 10 32bit running on a Lenovo 20CD00B2US with PAA
  • Windows 10 64bit running on a CyberPowerPC GLC2460 with Intel Core i7 [8th Generation] with PAA
  • Windows 10 64bit running on a Lenovo 20EV002JUS with PAA
  • Windows 8.1 64bit running on a CyberPowerPC GLC2460 with Intel Corei7 [8th Generation] with PAA
  • Windows Server 2016 on HyperV on Windows Server 2016 64bit running on a HPE ProLiant BL460c Gen9 with Intel Xeon E5-26XX v3 series with PAA
  • Windows Server 2016 on HyperV on Windows Server 2016 64bit running on HPE Proliant BL460c Gen9 with Intel Xeon E5-26XX v4 series with PAA (single-user mode)
Vendor Citrix Systems, Inc.
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Symmetric Algorithms
AES, DES, Triple-DES, TDES, HMAC, CMAC
Asymmetric Algorithms
RSA-1024, ECDH, ECDSA, ECC, DH, DSA
Hash functions
SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, SHA-2, MD5, PBKDF
Schemes
MAC, Key Agreement, Key agreement
Protocols
SSH, TLS, TLS 1.2
Randomness
DRBG, RNG
Elliptic Curves
P-384, P-256, P-521, P-224, P-512, K-233, K-283, K-571, B-233, B-283, B-409, B-571, K-409
Block cipher modes
ECB, CBC, CTR, OFB, GCM, CCM, XTS

Vendor
Samsung

Security level
level 1, Level 1

Standards
FIPS 140-2, FIPS 197, FIPS 186-4, FIPS 198-1, FIPS 186-2, FIPS 180-4, SP 800-133, SP 800-38A, SP 800-38B, SP 800-38C, SP 800-38D, SP 800-38E, SP 800-38F, SP 800-56A, SP 800-90A, SP 800-67, SP 800-20, SP 800-132, PKCS #1, PKCS1, PKCS#1

File metadata

Title Citrix FIPS Cryptographic Module, FIPS 140-2 Security Policy
Subject FIPS 140-2 Security Policy
Author Ben Tucker
Creation date D:20210104171314-08'00'
Modification date D:20210104171322-08'00'
Pages 32
Creator Acrobat PDFMaker 17 for Word
Producer Adobe PDF Library 15.0

Heuristics

No heuristics are available for this certificate.

References

No references are available for this certificate.

Updates Feed

  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 2988,
  "dgst": "0d46ebf59e025c23",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "DRBG#1417",
        "KAS#1102",
        "KAS#1103",
        "CVL#1104",
        "KTS#4397",
        "HMAC#2923",
        "CVL#1101",
        "DSA#1174",
        "Triple-DES#2371",
        "RSA#2379",
        "CVL#1103",
        "AES#4397",
        "CVL#1105",
        "SHS#3626",
        "KAS#1104",
        "KAS#1101",
        "CVL#1106",
        "CVL#1102",
        "ECDSA#1056"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "2600",
        "2400",
        "5600"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 5
          },
          "ECDH": {
            "ECDH": 12
          },
          "ECDSA": {
            "ECDSA": 13
          }
        },
        "FF": {
          "DH": {
            "DH": 14
          },
          "DSA": {
            "DSA": 14
          }
        },
        "RSA": {
          "RSA-1024": 1
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 3
        },
        "CCM": {
          "CCM": 3
        },
        "CTR": {
          "CTR": 2
        },
        "ECB": {
          "ECB": 3
        },
        "GCM": {
          "GCM": 5
        },
        "OFB": {
          "OFB": 1
        },
        "XTS": {
          "XTS": 7
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "SSH": {
          "SSH": 9
        },
        "TLS": {
          "TLS": {
            "TLS": 4,
            "TLS 1.2": 1
          }
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 6,
          "Key agreement": 1
        },
        "MAC": {
          "MAC": 6
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "B-233": 2,
          "B-283": 2,
          "B-409": 2,
          "B-571": 2,
          "K-233": 3,
          "K-283": 2,
          "K-409": 1,
          "K-571": 2,
          "P-224": 6,
          "P-256": 4,
          "P-384": 6,
          "P-512": 1,
          "P-521": 4
        }
      },
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "# 2379": 1,
          "#1": 2,
          "#10": 2,
          "#1101": 2,
          "#1102": 2,
          "#1103": 2,
          "#1104": 1,
          "#1106": 1,
          "#19": 1,
          "#3626": 1,
          "#4": 1,
          "#4397": 1
        }
      },
      "fips_certlike": {
        "Certlike": {
          "AES #4397": 1,
          "AES, 256": 1,
          "CVL #1101": 2,
          "CVL #1102": 2,
          "CVL #1103": 2,
          "Cert # AES": 1,
          "Cert # DRBG": 1,
          "Cert # RSA": 1,
          "HMAC-SHA-1": 2,
          "HMAC-SHA1": 2,
          "PKCS #1": 4,
          "PKCS#1": 2,
          "PKCS1": 6,
          "SHA-1": 7,
          "SHA-2": 1,
          "SHA-224": 6,
          "SHA-256": 12,
          "SHA-384": 8,
          "SHA-512": 7,
          "SHA-512 2923": 1,
          "SHS Cert. #3626": 1
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 4,
          "level 1": 1
        }
      },
      "hash_function": {
        "MD": {
          "MD5": {
            "MD5": 3
          }
        },
        "PBKDF": {
          "PBKDF": 3
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 7
          },
          "SHA2": {
            "SHA-2": 1,
            "SHA-224": 6,
            "SHA-256": 12,
            "SHA-384": 8,
            "SHA-512": 8
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 19
        },
        "RNG": {
          "RNG": 3
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-2": 40,
          "FIPS 180-4": 1,
          "FIPS 186-2": 1,
          "FIPS 186-4": 6,
          "FIPS 197": 6,
          "FIPS 198-1": 1
        },
        "NIST": {
          "SP 800-132": 1,
          "SP 800-133": 2,
          "SP 800-20": 1,
          "SP 800-38A": 1,
          "SP 800-38B": 2,
          "SP 800-38C": 1,
          "SP 800-38D": 1,
          "SP 800-38E": 1,
          "SP 800-38F": 1,
          "SP 800-56A": 3,
          "SP 800-67": 2,
          "SP 800-90A": 1
        },
        "PKCS": {
          "PKCS #1": 2,
          "PKCS#1": 1,
          "PKCS1": 3
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 24
          }
        },
        "DES": {
          "3DES": {
            "TDES": 3,
            "Triple-DES": 7
          },
          "DES": {
            "DES": 2
          }
        },
        "constructions": {
          "MAC": {
            "CMAC": 9,
            "HMAC": 8
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {
        "Samsung": {
          "Samsung": 1
        }
      },
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "Ben Tucker",
      "/Category": "",
      "/Comments": "",
      "/Company": "Citrix Systems, Inc.",
      "/ContentTypeId": "0x0101008681CA60AFFFF04BA463888914031D79",
      "/CreationDate": "D:20210104171314-08\u002700\u0027",
      "/Creator": "Acrobat PDFMaker 17 for Word",
      "/Keywords": "",
      "/Manager": "",
      "/ModDate": "D:20210104171322-08\u002700\u0027",
      "/Producer": "Adobe PDF Library 15.0",
      "/SourceModified": "D:20210105011238",
      "/Subject": "FIPS 140-2 Security Policy",
      "/Title": "Citrix FIPS Cryptographic Module, FIPS 140-2 Security Policy",
      "pdf_file_size_bytes": 787869,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": []
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 32
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
    "module_download_ok": true,
    "module_extract_ok": true,
    "policy_convert_ok": true,
    "policy_download_ok": true,
    "policy_extract_ok": true,
    "policy_json_hash": null,
    "policy_pdf_hash": "8943eca9d8e2779550f00dfa26cd0b3e41ff05221e05683a84bc5e86ba2ad16d",
    "policy_txt_hash": "220ede0587c8f16c116ff4eaaacb8a13131fe5bda685b8828c464de15eafe7c6"
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in FIPS Mode. No assurance of the minimum strength of generated keys",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/AugConsolidatedCert.pdf",
    "date_sunset": null,
    "description": "The Citrix FIPS Cryptographic Module is a software toolkit which provides various cryptographic functions to support the Citrix product portfolio.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Mitigation of Other Attacks: N/A"
    ],
    "fw_versions": null,
    "historical_reason": "SP 800-56Arev3 transition",
    "hw_versions": "ARM v8-A, ARM v7-A, Intel Core i7 4th Generation, Intel Core i7 6th Generation, Intel Core i7 8th Generation, Intel Xeon 5600 series, Intel Xeon E5-2400 v4 series, Intel Xeon E5-2600 v2 series, Intel Xeon E5-2600 v3 series and Intel Xeon E5-2600 v4 series",
    "level": 1,
    "mentioned_certs": {},
    "module_name": "Citrix FIPS Cryptographic Module",
    "module_type": "Software-Hybrid",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-2",
    "status": "historical",
    "sw_versions": "1.0, 1.0.1 and 1.0.2",
    "tested_conf": [
      "Android 4.4 running on a Google Nexus 5 (LG D820) with PAA",
      "Android 5 running on a Google Nexus 6 (Motorola Nexus 6 XT11003) with PAA",
      "Android 6 running on a Google Nexus 6 (Motorola Nexus 6 XT11003) with PAA",
      "Android 6 running on a Samsung Galaxy S6 (SM-G920T) with PAA",
      "Android 7 running on a Google Nexus 5X (LG H790) with PAA",
      "Android 7 running on a Google Nexus 6 (Motorola Nexus 6 XT11003) with PAA",
      "Android 8 64bit running on a Google Pixel 2 with ARM v8-A with PAA",
      "Android 9 running on a Google Pixel 2 with ARM v8-A with PAA",
      "FreeBSD 8.4 32bit running on a Citrix NetScaler MPX-14000-FIPS with PAA",
      "FreeBSD 8.4 64bit running on a Citrix NetScaler MPX-14000-FIPS with PAA",
      "iOS 10 64bit running on an Apple 12.9-inch iPad Pro (A1584) with PAA",
      "iOS 11 running on an iPhone X with ARM v8-A with PAA",
      "Linux 3.10 64bit running on a CyberPowerPC GLC2460 with Intel Core i7 [8th Generation] with PAA",
      "Linux 3.13 64bit running on a Lenovo 20EV002JUS with PAA",
      "Linux 3.16 on ESXi 5 64bit running on a HP ProLiant DL2000 with PAA",
      "Linux 3.16 on Hyper-V on Windows Server 2012 R2 64bit running on a HP ProLiant DL2000 with PAA",
      "Linux 3.16 on XenServer 6 64bit running on a Dell PowerEdge C6100 with PAA",
      "Linux 4.15 64bit running on a CyberPowerPC GLC2460 with Intel Core i7 [8th Generation with PAA",
      "Linux 4.15 64bit running on a HPE ProLiant BL460c Gen9 with Intel Xeon E5-26XX v3 with PAA",
      "Linux 4.15 64bit running on a HPE Proliant BL460c Gen9 with Intel Xeon E5-26XX v4 series with PAA",
      "Linux 4.x on ESXi 5 64bit running on a HPE ProLiant BL460c Gen9 with Intel Xeon E5-26XX v4 series with PAA",
      "Linux 4.x on Hyper-V on Windows Server 2012 R2 64bit running on a HPE ProLiant BL460c Gen9 with Intel Xeon E5-26XX v4 series with PAA",
      "Linux 4.x on XenServer 7 64bit running on a Dell PowerEdge R320 with Intel Xeon E5-24XX v2 series with PAA",
      "Linux 4.x on XenServer 7 64bit running on a HPE ProLiant BL460c Gen9 with Intel Xeon E5-26XX v4 series with PAA",
      "Mac OS X 10.12 64bit running on an Apple Macbook Pro (A1398) with PAA",
      "Mac OS X 10.13 64bit running on an Apple Mac Mini with Intel Corei7 [4th Generation] with PAA",
      "NoTouch Desktop running on an N-computing RX-HDX for Citrix with ARM v8-A with PAA",
      "ViewSonic Thin OS running on a ViewSonic VS16585 with PAA",
      "Windows 10 32bit running on a Lenovo 20CD00B2US with PAA",
      "Windows 10 64bit running on a CyberPowerPC GLC2460 with Intel Core i7 [8th Generation] with PAA",
      "Windows 10 64bit running on a Lenovo 20EV002JUS with PAA",
      "Windows 8.1 64bit running on a CyberPowerPC GLC2460 with Intel Corei7 [8th Generation] with PAA",
      "Windows Server 2016 on HyperV on Windows Server 2016 64bit running on a HPE ProLiant BL460c Gen9 with Intel Xeon E5-26XX v3 series with PAA",
      "Windows Server 2016 on HyperV on Windows Server 2016 64bit running on HPE Proliant BL460c Gen9 with Intel Xeon E5-26XX v4 series with PAA (single-user mode)"
    ],
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2017-08-10",
        "lab": "UL Verification Services, Inc.",
        "validation_type": "Initial"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2019-02-07",
        "lab": "UL Verification Services, Inc.",
        "validation_type": "Update"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2019-08-23",
        "lab": "UL Verification Services, Inc.",
        "validation_type": "Update"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2020-09-30",
        "lab": "UL Verification Services, Inc.",
        "validation_type": "Update"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2021-01-06",
        "lab": "UL Verification Services, Inc.",
        "validation_type": "Update"
      }
    ],
    "vendor": "Citrix Systems, Inc.",
    "vendor_url": "http://www.citrix.com"
  }
}