Amazon Linux 2023 OpenSSL FIPS Provider

Known vulnerabilities detected

Our automated heuristics have identified vulnerabilities that may be associated with this certificate. See the CVEs section for details.

Certificate details

Certificate ID #5021
Status active
Validation dates 26.05.2025
Sunset date 25-05-2030
Standard FIPS 140-3
Security level 1
Type Software
Embodiment Multi-Chip Stand Alone
Caveat When operated in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.
Exceptions
  • Physical security: N/A
  • Non-invasive security: N/A
Description The Amazon Linux 2023 OpenSSL FIPS Provider is a software library implementing general purpose cryptographic algorithms.
Vendor Amazon Web Services, Inc. http://www.amazon.com
Lab atsec information security corporation
Algorithms
  • AES-CBC-CS1A4611
  • AES-CBC-CS2A4611
  • AES-CBC-CS3A4611
  • AES-CBCA4611
  • AES-CCMA4611
  • AES-CFB128A4611
  • AES-CFB1A4611
  • AES-CFB8A4611
  • AES-CMACA4611
  • AES-CTRA4611
  • AES-ECBA4639
  • AES-GCMA4628
  • AES-GMACA4628
  • AES-KWA4611
  • AES-KWPA4611
  • AES-OFBA4611
  • AES-XTS Testing Revision 2.0A4611
  • Counter DRBGA4604
  • ECDSA KeyGen (FIPS186-5)A4632
  • ECDSA KeyVer (FIPS186-5)A4632
  • ECDSA SigGen (FIPS186-5)A4632
  • ECDSA SigVer (FIPS186-5)A4632
  • Hash DRBGA4604
  • HMAC DRBGA4604
  • HMAC-SHA-1A4632
  • HMAC-SHA2-224A4632
  • HMAC-SHA2-256A4632
  • HMAC-SHA2-384A4632
  • HMAC-SHA2-512/224A4632
  • HMAC-SHA2-512/256A4632
  • HMAC-SHA2-512A4632
  • HMAC-SHA3-224A4619
  • HMAC-SHA3-256A4619
  • HMAC-SHA3-384A4619
  • HMAC-SHA3-512A4619
  • KAS-ECC-SSC Sp800-56Ar3A4632
  • KAS-FFC-SSC Sp800-56Ar3A4642
  • KDA HKDF Sp800-56Cr1A4603
  • KDA OneStep SP800-56Cr2A4641
  • KDA TwoStep SP800-56Cr2A4641
  • KDF ANS 9.42A4632
  • KDF ANS 9.63A4632
  • KDF SP800-108A4640
  • KDF SSHA4639
  • PBKDFA4632
  • RSA KeyGen (FIPS186-5)A4632
  • RSA SigGen (FIPS186-5)A4632
  • RSA SigVer (FIPS186-4)A4632
  • RSA SigVer (FIPS186-5)A4632
  • Safe Primes Key GenerationA4642
  • Safe Primes Key VerificationA4642
  • SHA-1A4632
  • SHA2-224A4632
  • SHA2-256A4632
  • SHA2-384A4632
  • SHA2-512/224A4632
  • SHA2-512/256A4632
  • SHA2-512A4632
  • SHA3-224A4619
  • SHA3-256A4619
  • SHA3-384A4619
  • SHA3-512A4619
  • SHAKE-128A4619
  • SHAKE-256A4619
  • TLS v1.2 KDF RFC7627A4632
  • TLS v1.3 KDFA4603
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Extracted keywords

Symmetric Algorithms
AES, AES-128, AES-192, AES-256, AES-, CAST, HMAC, HMAC-SHA-256, CMAC
Asymmetric Algorithms
RSA-PSS, RSA-OAEP, ECDH, ECDSA, ECC, DHE, Diffie-Hellman, DH
Hash functions
SHA-1, SHA-224, SHA-512, SHA-256, SHA-384, SHA-3, SHA3-224, SHA3-256, SHA3-384, SHA3-512, SHAKE128, SHAKE256, PBKDF2, PBKDF
Schemes
MAC, Key Exchange, Key Agreement
Protocols
SSH, TLS v1.2, TLS v1.3, TLS 1.2, TLS 1.3, TLS, IKE
Randomness
DRBG, RNG, RBG
Libraries
OpenSSL
Elliptic Curves
P-224, P-256, P-384, P-521
Block cipher modes
ECB, CBC, CTR, CFB, OFB, GCM, CCM, XTS

Trusted Execution Environments
PSP, SSC

Security level
Level 1

Automated analysis

Automated inference - use with caution

All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.

CVE matches

ID Links Severity CVSS Score Published on
Base score
CVE-2024-6387
C N
HIGH 8.1 01.07.2024

Cross-references

No references are available for this certificate.

Processing updates

Feed
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 5021,
  "dgst": "1210e6c2e909ec7c",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "#A4632",
        "HMAC-SHA2-512A4632",
        "SHA3-256A4619",
        "HMAC-SHA3-256A4619",
        "KDA TwoStep SP800-56Cr2A4641",
        "AES-OFBA4611",
        "#A4605",
        "#A4630",
        "ECDSA KeyVer (FIPS186-5)A4632",
        "Safe Primes Key GenerationA4642",
        "#A4620",
        "HMAC DRBGA4604",
        "HMAC-SHA2-512/224A4632",
        "#A4611",
        "#A4619",
        "#A4608",
        "SHA3-512A4619",
        "RSA SigVer (FIPS186-4)A4632",
        "KDA HKDF Sp800-56Cr1A4603",
        "#A4642",
        "AES-CBC-CS1A4611",
        "AES-CTRA4611",
        "HMAC-SHA2-512/256A4632",
        "AES-KWA4611",
        "#A4609",
        "Hash DRBGA4604",
        "AES-CCMA4611",
        "#A4625",
        "AES-CMACA4611",
        "AES-GMACA4628",
        "#A4606",
        "AES-CFB8A4611",
        "KDF SSHA4639",
        "KAS-FFC-SSC Sp800-56Ar3A4642",
        "#A4627",
        "RSA SigVer (FIPS186-5)A4632",
        "AES-ECBA4639",
        "#A4612",
        "SHA2-384A4632",
        "#A4604",
        "#A4613",
        "TLS v1.3 KDFA4603",
        "AES-GCMA4628",
        "ECDSA SigGen (FIPS186-5)A4632",
        "#A4624",
        "#A4639",
        "#A4631",
        "HMAC-SHA2-224A4632",
        "#A4623",
        "#A4614",
        "HMAC-SHA-1A4632",
        "KDA OneStep SP800-56Cr2A4641",
        "#A4607",
        "AES-CFB1A4611",
        "RSA KeyGen (FIPS186-5)A4632",
        "#A4603",
        "KDF ANS 9.42A4632",
        "KDF ANS 9.63A4632",
        "#A4615",
        "SHAKE-128A4619",
        "Counter DRBGA4604",
        "RSA SigGen (FIPS186-5)A4632",
        "#A4640",
        "#A4628",
        "#A4641",
        "PBKDFA4632",
        "#A4618",
        "#A4617",
        "AES-CBC-CS3A4611",
        "HMAC-SHA3-224A4619",
        "HMAC-SHA2-256A4632",
        "SHA3-384A4619",
        "SHA2-512/224A4632",
        "ECDSA SigVer (FIPS186-5)A4632",
        "SHA2-224A4632",
        "KAS-ECC-SSC Sp800-56Ar3A4632",
        "#A4637",
        "AES-XTS Testing Revision 2.0A4611",
        "AES-CBC-CS2A4611",
        "AES-CFB128A4611",
        "#A4635",
        "#A4621",
        "SHA-1A4632",
        "HMAC-SHA3-384A4619",
        "HMAC-SHA3-512A4619",
        "SHA2-512/256A4632",
        "#A4626",
        "#A4629",
        "SHA3-224A4619",
        "ECDSA KeyGen (FIPS186-5)A4632",
        "AES-CBCA4611",
        "#A4610",
        "#A4638",
        "Safe Primes Key VerificationA4642",
        "#A4622",
        "AES-KWPA4611",
        "#A4636",
        "SHAKE-256A4619",
        "KDF SP800-108A4640",
        "SHA2-512A4632",
        "TLS v1.2 KDF RFC7627A4632",
        "#A4616",
        "SHA2-256A4632",
        "HMAC-SHA2-384A4632"
      ]
    },
    "cpe_matches": {
      "_type": "Set",
      "elements": [
        "cpe:2.3:o:amazon:amazon_linux:2023.0:*:*:*:*:*:*:*",
        "cpe:2.3:o:amazon:amazon_linux:2023.7:*:*:*:*:*:*:*",
        "cpe:2.3:o:amazon:amazon_linux:2023.8:*:*:*:*:*:*:*",
        "cpe:2.3:o:amazon:amazon_linux:2023.1:*:*:*:*:*:*:*",
        "cpe:2.3:o:amazon:amazon_linux:2023.2:*:*:*:*:*:*:*",
        "cpe:2.3:o:amazon:amazon_linux:2023.5:*:*:*:*:*:*:*",
        "cpe:2.3:o:amazon:amazon_linux:2023.4:*:*:*:*:*:*:*",
        "cpe:2.3:o:amazon:amazon_linux:2023.6:*:*:*:*:*:*:*",
        "cpe:2.3:o:amazon:amazon_linux:2023.3:*:*:*:*:*:*:*"
      ]
    },
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "2023"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": {
      "_type": "Set",
      "elements": [
        "CVE-2024-6387"
      ]
    },
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "br1_deviations": 1,
    "br1_tables": {
      "_type": "sec_certs.heuristics.br1.table_parsing.model.br1_tables.BR1Tables",
      "approved_algorithms": {
        "entries": [
          {
            "algorithm": "AES-CBC",
            "cavpCertName": "A4605, A4606, A4607, A4609, A4610, A4611",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CBC-CS1",
            "cavpCertName": "A4605, A4606, A4607, A4609, A4610, A4611",
            "properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CBC-CS2",
            "cavpCertName": "A4605, A4606, A4607, A4609, A4610, A4611",
            "properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CBC-CS3",
            "cavpCertName": "A4605, A4606, A4607, A4609, A4610, A4611",
            "properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CCM",
            "cavpCertName": "A4605, A4606, A4607, A4609, A4610, A4611",
            "properties": "Key Length - 128, 192, 256",
            "reference": "SP 800-38C"
          },
          {
            "algorithm": "AES-CFB1",
            "cavpCertName": "A4605, A4606, A4607, A4609, A4610, A4611",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CFB128",
            "cavpCertName": "A4605, A4606, A4607, A4609, A4610, A4611",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CFB8",
            "cavpCertName": "A4605, A4606, A4607, A4609, A4610, A4611",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CMAC",
            "cavpCertName": "A4605, A4606, A4607, A4609, A4610, A4611",
            "properties": "Direction - Generation, Verification Key Length - 128, 192, 256",
            "reference": "SP 800-38B"
          },
          {
            "algorithm": "AES-CTR",
            "cavpCertName": "A4605, A4606, A4607, A4609, A4610, A4611",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A4605, A4606, A4607, A4609, A4610, A4611, A4635, A4636, A4637, A4638, A4639",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-GCM",
            "cavpCertName": "A4614, A4615, A4616, A4617, A4620, A4621, A4622, A4623, A4624, A4625, A4626, A4627,",
            "properties": "Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 192, 256",
            "reference": "SP 800-38D"
          },
          {
            "algorithm": "AES-GMAC",
            "cavpCertName": "A4628 A4614, A4615, A4616, A4617, A4620, A4621, A4622, A4623, A4624, A4625, A4626, A4627, A4628",
            "properties": "Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 192, 256",
            "reference": "SP 800-38D"
          },
          {
            "algorithm": "AES-KW",
            "cavpCertName": "A4605, A4606, A4607, A4609, A4610, A4611",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38F"
          },
          {
            "algorithm": "AES-KWP",
            "cavpCertName": "A4605, A4606, A4607, A4609, A4610, A4611",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38F"
          },
          {
            "algorithm": "AES-OFB",
            "cavpCertName": "A4605, A4606, A4607, A4609, A4610, A4611",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-XTS Testing Revision 2.0",
            "cavpCertName": "A4605, A4606, A4607, A4609, A4610, A4611",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 256",
            "reference": "SP 800-38E"
          },
          {
            "algorithm": "Counter DRBG",
            "cavpCertName": "A4604",
            "properties": "Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - No, Yes",
            "reference": "SP 800-90A Rev. 1"
          },
          {
            "algorithm": "ECDSA KeyGen (FIPS186-5)",
            "cavpCertName": "A4612, A4618, A4629, A4630, A4631, A4632",
            "properties": "Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - testing candidates",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "ECDSA KeyVer (FIPS186-5)",
            "cavpCertName": "A4612, A4618, A4629, A4630, A4631, A4632",
            "properties": "Curve - P-224, P-256, P-384, P-521",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "ECDSA SigGen (FIPS186-5)",
            "cavpCertName": "A4612, A4618, A4629, A4630, A4631, A4632",
            "properties": "Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 Component - No",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "ECDSA SigGen (FIPS186-5)",
            "cavpCertName": "A4613, A4619",
            "properties": "Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA3-224, SHA3-256, SHA3-384, SHA3-512 Component - No",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "ECDSA SigVer (FIPS186-5)",
            "cavpCertName": "A4612, A4618, A4629, A4630, A4631, A4632",
            "properties": "Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "ECDSA SigVer (FIPS186-5)",
            "cavpCertName": "A4613, A4619",
            "properties": "Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA3-224, SHA3-256, SHA3-384, SHA3-512",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "Hash DRBG",
            "cavpCertName": "A4604",
            "properties": "Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512",
            "reference": "SP 800-90A Rev. 1"
          },
          {
            "algorithm": "HMAC DRBG",
            "cavpCertName": "A4604",
            "properties": "Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512",
            "reference": "SP 800-90A Rev. 1"
          },
          {
            "algorithm": "HMAC-SHA-1",
            "cavpCertName": "A4612, A4618, A4629, A4630, A4631, A4632",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2- 224",
            "cavpCertName": "A4612, A4618, A4629, A4630, A4631, A4632",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2- 256",
            "cavpCertName": "A4608, A4612, A4618, A4629, A4630, A4631, A4632",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2- 384",
            "cavpCertName": "A4612, A4618, A4629, A4630, A4631, A4632",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2- 512",
            "cavpCertName": "A4612, A4618, A4629, A4630, A4631, A4632",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2- 512/224",
            "cavpCertName": "A4612, A4618, A4629, A4630, A4631, A4632",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2- 512/256",
            "cavpCertName": "A4612, A4618, A4629, A4630, A4631, A4632",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3- 224",
            "cavpCertName": "A4613, A4619",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3- 256",
            "cavpCertName": "A4613, A4619",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3- 384",
            "cavpCertName": "A4613, A4619",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3- 512",
            "cavpCertName": "A4613, A4619",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "KAS-ECC-SSC Sp800-56Ar3",
            "cavpCertName": "A4612, A4618, A4629, A4630, A4631, A4632",
            "properties": "Domain Parameter Generation Methods - P-224, P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responder",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "KAS-FFC-SSC Sp800-56Ar3",
            "cavpCertName": "A4642",
            "properties": "Domain Parameter Generation Methods - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192 Scheme - dhEphem - KAS Role - initiator, responder",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "KDA HKDF Sp800-56Cr1",
            "cavpCertName": "A4603",
            "properties": "Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-2048 Increment 8 HMAC Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2- 512/256, SHA3-224, SHA3-256, SHA3-384",
            "reference": "SP 800-56C Rev. 2"
          },
          {
            "algorithm": "KDA OneStep SP800-56Cr2",
            "cavpCertName": "A4641",
            "properties": "Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-2048 Increment 8",
            "reference": "SP 800-56C Rev. 2"
          },
          {
            "algorithm": "KDA TwoStep SP800-56Cr2",
            "cavpCertName": "A4641",
            "properties": "MAC Salting Methods - default, random KDF Mode - feedback Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-2048 Increment 8",
            "reference": "SP 800-56C Rev. 2"
          },
          {
            "algorithm": "KDF ANS 9.42 (CVL)",
            "cavpCertName": "A4612, A4618, A4629, A4630, A4631, A4632",
            "properties": "KDF Type - DER Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2- 512/256 Key Data Length - Key Data Length: 8-4096 Increment 8",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "KDF ANS 9.42 (CVL)",
            "cavpCertName": "A4613, A4619",
            "properties": "KDF Type - DER Hash Algorithm - SHA3-224, SHA3-256, SHA3-384, SHA3-512 Key Data Length - Key Data Length: 8-4096 Increment 8",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "KDF ANS 9.63 (CVL)",
            "cavpCertName": "A4612, A4618, A4629, A4630, A4631, A4632",
            "properties": "Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 Key Data Length - Key Data Length: 128-4096 Increment 8",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "KDF ANS 9.63 (CVL)",
            "cavpCertName": "A4613, A4619",
            "properties": "Hash Algorithm - SHA3-224, SHA3-256, SHA3-384, SHA3-512 Key Data Length - Key Data Length: 128-4096 Increment 8",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "KDF SP800- 108",
            "cavpCertName": "A4608, A4640",
            "properties": "KDF Mode - Counter, Feedback Supported Lengths - Supported Lengths: 8, 72, 128, 776, 3456, 4096",
            "reference": "SP 800-108 Rev. 1"
          },
          {
            "algorithm": "KDF SSH (CVL)",
            "cavpCertName": "A4635, A4636, A4637, A4638, A4639",
            "properties": "Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-256, SHA2-384, SHA2-512",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "PBKDF",
            "cavpCertName": "A4612, A4613, A4618, A4619, A4629, A4630, A4631, A4632",
            "properties": "Iteration Count - Iteration Count: 1000-10000 Increment 1 Password Length - Password Length: 8-128 Increment 1",
            "reference": "SP 800-132"
          },
          {
            "algorithm": "RSA KeyGen (FIPS186-5)",
            "cavpCertName": "A4612, A4618, A4629, A4630, A4631, A4632",
            "properties": "Key Generation Mode - probableWithProbableAux Modulo - 2048, 3072, 4096 Primality Tests - 2powSecStr Private Key Format - standard",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "RSA SigGen (FIPS186-5)",
            "cavpCertName": "A4612, A4613, A4618, A4619, A4629, A4630, A4631, A4632",
            "properties": "Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pss",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "RSA SigVer (FIPS186-4)",
            "cavpCertName": "A4612, A4618, A4629, A4630, A4631, A4632",
            "properties": "Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "RSA SigVer (FIPS186-5)",
            "cavpCertName": "A4612, A4613, A4618, A4619, A4629, A4630, A4631, A4632",
            "properties": "Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pss",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "Safe Primes Key Generation",
            "cavpCertName": "A4642",
            "properties": "Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP- 8192",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "Safe Primes Key Verification",
            "cavpCertName": "A4642",
            "properties": "Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP- 8192",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "SHA-1",
            "cavpCertName": "A4612, A4618, A4629, A4630, A4631, A4632",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-224",
            "cavpCertName": "A4612, A4618, A4629, A4630, A4631, A4632",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-256",
            "cavpCertName": "A4608, A4612, A4618, A4629, A4630, A4631, A4632",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-384",
            "cavpCertName": "A4612, A4618, A4629, A4630, A4631, A4632",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512",
            "cavpCertName": "A4612, A4618, A4629, A4630, A4631, A4632",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512/224",
            "cavpCertName": "A4612, A4618, A4629, A4630, A4631, A4632",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512/256",
            "cavpCertName": "A4612, A4618, A4629, A4630, A4631, A4632",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA3-224",
            "cavpCertName": "A4613, A4619",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3-256",
            "cavpCertName": "A4613, A4619",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3-384",
            "cavpCertName": "A4613, A4619",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3-512",
            "cavpCertName": "A4613, A4619",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHAKE-128",
            "cavpCertName": "A4613, A4619",
            "properties": "Output Length - Output Length: 16-65536 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHAKE-256",
            "cavpCertName": "A4613, A4619",
            "properties": "Output Length - Output Length: 16-65536 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "TLS v1.2 KDF RFC7627 (CVL)",
            "cavpCertName": "A4612, A4618, A4629, A4630, A4631, A4632",
            "properties": "Hash Algorithm - SHA2-256, SHA2-384, SHA2-512",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "TLS v1.3 KDF (CVL)",
            "cavpCertName": "A4603",
            "properties": "HMAC Algorithm - SHA2-256, SHA2-384 KDF Running Modes - DHE, PSK, PSK-DHE",
            "reference": "SP 800-135 Rev. 1"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "approved_services": {
        "entries": [
          {
            "description": "Compute a message digest",
            "indicator": "EVP_DigestFinal_ex returns 1",
            "inputs": "Messag e",
            "name": "Message digest",
            "outputs": "Digest value",
            "rolesSspAccess": "Crypto Officer",
            "secFunImpl": "Hashing"
          },
          {
            "description": "Compute output of XOF",
            "indicator": "EVP_DigestFinalXOF_ex returns 1",
            "inputs": "Messag e, output length",
            "name": "XOF",
            "outputs": "Digest value",
            "rolesSspAccess": "Crypto Officer",
            "secFunImpl": "Extendabl e Output Function"
          },
          {
            "description": "Encrypt a plaintext",
            "indicator": "EVP_EncryptFinal_ex returns 1",
            "inputs": "Plaintex t, AES key",
            "name": "Encryptio n",
            "outputs": "Ciphert ext",
            "rolesSspAccess": "Crypto Officer - AES key: W,E",
            "secFunImpl": "Encryptio n with AES"
          },
          {
            "description": "Decrypt a plaintext",
            "indicator": "EVP_DecryptFinal_ex returns 1",
            "inputs": "Ciphert ext, AES key",
            "name": "Decryptio n",
            "outputs": "Plaintex t",
            "rolesSspAccess": "Crypto Officer - AES key: W,E",
            "secFunImpl": "Decryptio n with AES"
          },
          {
            "description": "Encrypt and authenti cate a plaintext",
            "indicator": "AES GCM: EVP_CIPHER_REDHAT_FIPS_INDICATOR_ APPROVED; Others: EVP_EncryptFinal_ex returns 1",
            "inputs": "AES key, IV (only CCM and GCM), plaintex t",
            "name": "Authentic ated Encryptio n",
            "outputs": "Ciphert ext, MAC tag (only CCM and GCM)",
            "rolesSspAccess": "Crypto Officer - AES key: W,E",
            "secFunImpl": "Authentic ated Encryptio n with AES Key wrapping using AES KW Key wrapping using AES KWP Key wrapping using AES CCM Key wrapping using AES GCM"
          },
          {
            "description": "Descrip tion",
            "indicator": "Indicator",
            "inputs": "Inputs",
            "name": "Name",
            "outputs": "Output s",
            "rolesSspAccess": "SSP Access",
            "secFunImpl": "Security Function"
          },
          {
            "description": "Decrypt and authenti cate a cipherte xt",
            "indicator": "AES GCM: EVP_CIPHER_REDHAT_FIPS_INDICATOR_ APPROVED; Others: EVP_DecryptFinal_ex returns 1",
            "inputs": "AES key, ciphert ext, MAC tag (only CCM and GCM), IV (only CCM and GCM)",
            "name": "Authentic ated Decryptio n",
            "outputs": "Plaintex t or failure",
            "rolesSspAccess": "Crypto Officer - AES key: W,E",
            "secFunImpl": "s Authentic ated Decryptio n with AES Key unwrappi ng using AES KW Key unwrappi ng using AES KWP Key unwrappi ng using AES CCM Key unwrappi ng using AES GCM"
          },
          {
            "description": "Compute s a MAC tag",
            "indicator": "HMAC: EVP_MAC_REDHAT_FIPS_INDICATOR_AP PROVED; Others: EVP_MAC_final returns 1",
            "inputs": "Messag e, AES or HMAC key",
            "name": "Message Authentic ation",
            "outputs": "MAC tag",
            "rolesSspAccess": "Crypto Officer - AES key: W,E - HMAC key: W,E",
            "secFunImpl": "Message authentic ation"
          },
          {
            "description": "Derive a key from a key- derivatio n key using KBKDF",
            "indicator": "EVP_KDF_REDHAT_FIPS_INDICATOR_APP ROVED",
            "inputs": "Key- derivati on key",
            "name": "Key derivation with KBKDF",
            "outputs": "KBKDF Derived key",
            "rolesSspAccess": "Crypto Officer - Key- derivation key: W,E - KBKDF Derived key: G,R",
            "secFunImpl": "Key derivation with KBKDF"
          },
          {
            "description": "Derive a key from a shared secret using HKDF",
            "indicator": "EVP_KDF_REDHAT_FIPS_INDICATOR_APP ROVED",
            "inputs": "Shared secret",
            "name": "Key derivation with HKDF",
            "outputs": "HKDF Derived key",
            "rolesSspAccess": "Crypto Officer - HKDF Derived key: G,R - Shared secret: W,E",
            "secFunImpl": "Key derivation with HKDF"
          },
          {
            "description": "Derive a key from a shared secret using TLS KDF",
            "indicator": "EVP_KDF_REDHAT_FIPS_INDICATOR_APP ROVED",
            "inputs": "Shared secret",
            "name": "Key derivation with TLS KDF",
            "outputs": "TLS Derived key",
            "rolesSspAccess": "Crypto Officer - Shared secret: W,E - TLS Derived key: G,R",
            "secFunImpl": "Key derivation with TLS 1.2 KDF Key derivation with TLS 1.3 KDF"
          },
          {
            "description": "Derive a key from a shared secret using SSH KDF",
            "indicator": "EVP_KDF_REDHAT_FIPS_INDICATOR_APP ROVED",
            "inputs": "Shared secret",
            "name": "Key derivation with SSH KDF",
            "outputs": "SSH Derived key",
            "rolesSspAccess": "Crypto Officer - Shared secret: W,E - SSH Derived key: G,R",
            "secFunImpl": "Key derivation with SSH KDF"
          },
          {
            "description": "Derive a key from a shared secret using X9.63 KDF",
            "indicator": "EVP_KDF_REDHAT_FIPS_INDICATOR_APP ROVED",
            "inputs": "Shared secret",
            "name": "Key derivation with X9.63 KDF",
            "outputs": "X9.63 Derived key",
            "rolesSspAccess": "Crypto Officer - Shared secret: W,E - X9.63 Derived key: G,R",
            "secFunImpl": "Key derivation with X9.63 KDF"
          },
          {
            "description": "Derive a key from a shared secret using X9.42",
            "indicator": "EVP_KDF_REDHAT_FIPS_INDICATOR_APP ROVED",
            "inputs": "Shared secret",
            "name": "Key derivation using X9.42 KDF",
            "outputs": "X9.42 Derived key",
            "rolesSspAccess": "Crypto Officer - Shared secret: W,E - X9.42 Derived key: G,R",
            "secFunImpl": "Key derivation with X9.42 KDF"
          },
          {
            "description": "KDF Derive a key from a shared secret using KDA OneStep",
            "indicator": "EVP_KDF_REDHAT_FIPS_INDICATOR_APP ROVED",
            "inputs": "Shared secret",
            "name": "Key derivation with KDA OneStep",
            "outputs": "KDA OneSte p Derived key",
            "rolesSspAccess": "Crypto Officer - KDA OneStep Derived key: G,R - Shared secret: W,E",
            "secFunImpl": "Key derivation using KDA OneStep"
          },
          {
            "description": "Derive a key from a shared secret using KDA OneStep",
            "indicator": "EVP_KDF_REDHAT_FIPS_INDICATOR_APP ROVED",
            "inputs": "Shared secret",
            "name": "Key derivation with KDA TwoStep",
            "outputs": "KDA TwoSte p Derived key",
            "rolesSspAccess": "Crypto Officer - KDA TwoStep Derived key: G,R - Shared secret: W,E",
            "secFunImpl": "Key derivation using KDA TwoStep"
          },
          {
            "description": "Derive a key from a passwor d",
            "indicator": "EVP_KDF_REDHAT_FIPS_INDICATOR_APP ROVED",
            "inputs": "Passwo rd, salt, iteratio n count",
            "name": "Password- based key derivation",
            "outputs": "PBKDF Derived key",
            "rolesSspAccess": "Crypto Officer - Password: W,E - PBKDF Derived key: G,R",
            "secFunImpl": "Key derivation with PBKDF"
          },
          {
            "description": "Generate random bytes",
            "indicator": "EVP_RAND_generate returns 1",
            "inputs": "Seed, Output length",
            "name": "Random number generatio n",
            "outputs": "Random bytes",
            "rolesSspAccess": "Crypto Officer - Entropy input: W,E - DRBG seed: G,E - Internal state (V, Key): G,W,E - Internal state (V, C): G,W,E",
            "secFunImpl": "Random Number Generatio n with DRBG"
          },
          {
            "description": "Compute a shared secret",
            "indicator": "EVP_PKEY_derive returns 1",
            "inputs": "DH private key, DH public key; EC private key, EC public key",
            "name": "Shared secret computati on",
            "outputs": "Shared secret",
            "rolesSspAccess": "Crypto Officer - Shared secret: G,R - DH private key: W,E - DH public key: W,E",
            "secFunImpl": "Shared secret computati on using Diffie- Hellman Shared secret computati"
          },
          {
            "description": "Generate a signatur e",
            "indicator": "RSA: OSSL_RH_FIPSINDICATOR_APPROVED and EVP_SIGNATURE_REDHAT_FIPS_INDICAT OR_APPROVED; ECDSA: OSSL_RH_FIPSINDICATOR_APPROVED",
            "inputs": "Messag e, RSA or EC private key",
            "name": "Signature generatio n",
            "outputs": "Signatu re",
            "rolesSspAccess": "key: W,E Crypto Officer - RSA private key: W,E - EC private key: W,E",
            "secFunImpl": "Signature Generatio n with RSA Signature Generatio n with ECDSA"
          },
          {
            "description": "Verify a sigantur e",
            "indicator": "RSA: OSSL_RH_FIPSINDICATOR_APPROVED and EVP_SIGNATURE_REDHAT_FIPS_INDICAT OR_APPROVED; ECDSA: OSSL_RH_FIPSINDICATOR_APPROVED",
            "inputs": "Messag e, signatu re, RSA or EC public key",
            "name": "Signature verificatio n",
            "outputs": "Pass/fail",
            "rolesSspAccess": "Crypto Officer - RSA public key: W,E - EC public key: W,E",
            "secFunImpl": "Signature Verificatio n with RSA Signature Verificatio n with ECDSA"
          },
          {
            "description": "Generate a key pair",
            "indicator": "EVP_PKEY_generate returns 1",
            "inputs": "Group; Curve; Modulu s bits",
            "name": "Key pair generatio n",
            "outputs": "DH key pair; EC key pair; RSA key pair",
            "rolesSspAccess": "Crypto Officer - DH private key: G,R - DH public key: G,R - RSA private key: G,R - RSA public key: G,R - EC private key: G,R - EC public key: G,R - Intermediat e key generation value: G,E,Z",
            "secFunImpl": "Key Pair Generatio n with RSA Key Pair Generatio n with ECDSA Key Pair Generatio n with Safe Primes"
          },
          {
            "description": "Verify an EC public key",
            "indicator": "EVP_PKEY_public_check or EVP_PKEY_private_check or EVP_PKEY_check returns 1",
            "inputs": "EC public key",
            "name": "Public key verificatio n",
            "outputs": "Pass/fail",
            "rolesSspAccess": "Crypto Officer - EC public key: W,E",
            "secFunImpl": "Public Key Verificatio n with ECDSA"
          },
          {
            "description": "Verify a DH key pair",
            "indicator": "EVP_PKEY_public_check or EVP_PKEY_private_check or EVP_PKEY_check returns 1",
            "inputs": "DH public key; DH private key",
            "name": "Key pair verificatio n",
            "outputs": "Pass/fail",
            "rolesSspAccess": "Crypto Officer - DH private key: W,E - DH public key: W,E",
            "secFunImpl": "Key Pair Verificatio n with Safe Primes"
          },
          {
            "description": "Return the name and version",
            "indicator": "None",
            "inputs": "N/A",
            "name": "Show version",
            "outputs": "Name and version informa tion",
            "rolesSspAccess": "Unauthenti cated",
            "secFunImpl": "None"
          },
          {
            "description": "informati on",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "",
            "secFunImpl": ""
          },
          {
            "description": "Return the module status",
            "indicator": "None",
            "inputs": "N/A",
            "name": "Show status",
            "outputs": "Module status",
            "rolesSspAccess": "Unauthenti cated",
            "secFunImpl": "None"
          },
          {
            "description": "Perform CASTs and integrity test",
            "indicator": "None",
            "inputs": "N/A",
            "name": "Self-tests",
            "outputs": "Pass/fail results of self- tests",
            "rolesSspAccess": "Unauthenti cated",
            "secFunImpl": "Encryptio n with AES Decryptio n with AES Authentic ated Encryptio n with AES Authentic ated Decryptio n with AES Shared secret computati on using Diffie- Hellman Shared secret computati on using EC Diffie- Hellman Hashing Message authentic ation Key Pair Generatio n with RSA Key Pair Generatio n with ECDSA Public Key Verificatio n with ECDSA Signature Generatio n with RSA Signature Verificatio n with RSA"
          },
          {
            "description": "Descrip tion",
            "indicator": "Indicator",
            "inputs": "Inputs",
            "name": "Name",
            "outputs": "Output s",
            "rolesSspAccess": "SSP Access",
            "secFunImpl": "Security Function"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "",
            "secFunImpl": "s Signature Generatio n with ECDSA Signature Verificatio n with ECDSA Random Number Generatio n with DRBG Key derivation with KBKDF Key derivation with HKDF Key derivation with TLS 1.2 KDF Key derivation with TLS 1.3 KDF Key derivation with SSH KDF Key derivation with X9.63 KDF Key derivation with X9.42 KDF Key derivation with PBKDF Key Pair Generatio n with Safe Primes Key derivation using KDA OneStep Key derivation using KDA TwoStep"
          },
          {
            "description": "Zeroize any SSP",
            "indicator": "None",
            "inputs": "Any SSP",
            "name": "Zeroizatio n",
            "outputs": "None",
            "rolesSspAccess": "Unauthenti cated - AES key: Z - HMAC key: Z - Key- derivation key: Z - Shared secret: Z - Password: Z - KBKDF Derived key: Z - HKDF Derived key: Z - X9.63 Derived key: Z - X9.42 Derived key: Z - SSH Derived key: Z - KDA OneStep Derived key: Z - KDA TwoStep Derived key: Z - TLS Derived key: Z - PBKDF Derived key: Z - Entropy input: Z - DRBG seed: Z - Internal state (V, Key): Z - Internal state (V, C): Z - DH private key: Z - DH public key: Z - EC private",
            "secFunImpl": "None"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "key: Z - EC public key: Z - RSA private key: Z - RSA public key: Z - Intermediat e key generation value: Z",
            "secFunImpl": ""
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 3
      },
      "authentication_methods": {
        "entries": [],
        "found": false,
        "section": 4,
        "subsection": 1
      },
      "cond_self_tests": {
        "entries": [
          {
            "algorithmOrTest": "SHA-1 (A4612)",
            "condition": "Module initialization (before integrity test)",
            "details": "Message digest",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "24-bit message",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA-1 (A4618)",
            "condition": "Module initialization (before integrity test)",
            "details": "Message digest",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "24-bit message",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA-1 (A4629)",
            "condition": "Module initialization (before integrity test)",
            "details": "Message digest",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "24-bit message",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA-1 (A4630)",
            "condition": "Module initialization (before integrity test)",
            "details": "Message digest",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "24-bit message",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA-1 (A4631)",
            "condition": "Module initialization (before integrity test)",
            "details": "Message digest",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "24-bit message",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA-1 (A4632)",
            "condition": "Module initialization (before integrity test)",
            "details": "Message digest",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "24-bit message",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA2-512 (A4612)",
            "condition": "Module initialization",
            "details": "Message digest",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "24-bit message",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "",
            "condition": "(before integrity test)",
            "details": "",
            "indicator": "",
            "testMethod": "",
            "testProps": "",
            "type": ""
          },
          {
            "algorithmOrTest": "SHA2-512 (A4618)",
            "condition": "Module initialization (before integrity test)",
            "details": "Message digest",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "24-bit message",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA2-512 (A4629)",
            "condition": "Module initialization (before integrity test)",
            "details": "Message digest",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "24-bit message",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA2-512 (A4630)",
            "condition": "Module initialization (before integrity test)",
            "details": "Message digest",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "24-bit message",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA2-512 (A4631)",
            "condition": "Module initialization (before integrity test)",
            "details": "Message digest",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "24-bit message",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA2-512 (A4632)",
            "condition": "Module initialization (before integrity test)",
            "details": "Message digest",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "24-bit message",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA3-256 (A4613)",
            "condition": "Module initialization (before integrity test)",
            "details": "Message digest",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "32-bit message",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA3-256 (A4619)",
            "condition": "Module initialization (before integrity test)",
            "details": "Message digest",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "32-bit message",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A4614)",
            "condition": "Module initialization (before integrity test)",
            "details": "Encryption, Decryption (Separately)",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "256-bit key, 96-bit IV, 128-bit plaintext, 128-bit additional data",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A4615)",
            "condition": "Module initialization (before integrity test)",
            "details": "Encryption, Decryption (Separately)",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "256-bit key, 96-bit IV, 128-bit plaintext, 128-bit additional data",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A4616)",
            "condition": "Module initialization (before integrity test)",
            "details": "Encryption, Decryption (Separately)",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "256-bit key, 96-bit IV, 128-bit plaintext, 128-bit additional data",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A4617)",
            "condition": "Module initialization (before integrity test)",
            "details": "Encryption, Decryption (Separately)",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "256-bit key, 96-bit IV, 128-bit plaintext, 128-bit additional data",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A4620)",
            "condition": "Module initialization (before integrity test)",
            "details": "Encryption, Decryption (Separately)",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "256-bit key, 96-bit IV, 128-bit plaintext, 128-bit additional data",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A4621)",
            "condition": "Module initialization (before integrity test)",
            "details": "Encryption, Decryption (Separately)",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "256-bit key, 96-bit IV, 128-bit plaintext, 128-bit additional data",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A4622)",
            "condition": "Module initialization (before integrity test)",
            "details": "Encryption, Decryption (Separately)",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "256-bit key, 96-bit IV, 128-bit plaintext, 128-bit additional data",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A4623)",
            "condition": "Module initialization (before integrity test)",
            "details": "Encryption, Decryption (Separately)",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "256-bit key, 96-bit IV, 128-bit plaintext, 128-bit additional data",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A4624)",
            "condition": "Module initialization (before integrity test)",
            "details": "Encryption, Decryption (Separately)",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "256-bit key, 96-bit IV, 128-bit plaintext, 128-bit additional data",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A4625)",
            "condition": "Module initialization (before integrity test)",
            "details": "Encryption, Decryption (Separately)",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "256-bit key, 96-bit IV, 128-bit plaintext, 128-bit additional data",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A4626)",
            "condition": "Module initialization (before integrity test)",
            "details": "Encryption, Decryption (Separately)",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "256-bit key, 96-bit IV, 128-bit plaintext, 128-bit additional data",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A4627)",
            "condition": "Module initialization (before integrity test)",
            "details": "Encryption, Decryption (Separately)",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "256-bit key, 96-bit IV, 128-bit plaintext, 128-bit additional data",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A4614)",
            "condition": "Module initialization (before integrity test)",
            "details": "Encryption, Decryption (Separately)",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "256-bit key, 96-bit IV, 128-bit plaintext, 128-bit additional data",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-ECB (A4605)",
            "condition": "Module initialization (before integrity test)",
            "details": "Decryption",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "128-bit key; 128- bit ciphertext",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-ECB (A4606)",
            "condition": "Module initialization (before integrity test)",
            "details": "Decryption",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "128-bit key; 128- bit ciphertext",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-ECB (A4607)",
            "condition": "Module initialization (before integrity test)",
            "details": "Decryption",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "128-bit key; 128- bit ciphertext",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-ECB (A4609)",
            "condition": "Module initialization (before integrity test)",
            "details": "Decryption",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "128-bit key; 128- bit ciphertext",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-ECB (A4610)",
            "condition": "Module initialization (before integrity test)",
            "details": "Decryption",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "128-bit key; 128- bit ciphertext",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-ECB (A4611)",
            "condition": "Module initialization (before integrity test)",
            "details": "Decryption",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "128-bit key; 128- bit ciphertext",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-ECB (A4635)",
            "condition": "Module initialization (before integrity test)",
            "details": "Decryption",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "128-bit key; 128- bit ciphertext",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-ECB (A4636)",
            "condition": "Module initialization (before integrity test)",
            "details": "Decryption",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "128-bit key; 128- bit ciphertext",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-ECB (A4637)",
            "condition": "Module initialization",
            "details": "Decryption",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "128-bit key; 128- bit ciphertext",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "",
            "condition": "(before integrity test)",
            "details": "",
            "indicator": "",
            "testMethod": "",
            "testProps": "",
            "type": ""
          },
          {
            "algorithmOrTest": "AES-ECB (A4638)",
            "condition": "Module initialization (before integrity test)",
            "details": "Decryption",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "128-bit key; 128- bit ciphertext",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-ECB (A4639)",
            "condition": "Module initialization (before integrity test)",
            "details": "Decryption",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "128-bit key; 128- bit ciphertext",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF SP800- 108 (A4640)",
            "condition": "Module initialization (before integrity test)",
            "details": "Key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "Counter mode; HMAC-SHA-256; 128-bit input key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDA OneStep SP800-56Cr2 (A4641)",
            "condition": "Module initialization (before integrity test)",
            "details": "Key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-224; 392-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDA HKDF Sp800-56Cr1 (A4603)",
            "condition": "Module initialization (before integrity test)",
            "details": "Key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256, 48-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.42 (A4613)",
            "condition": "Module initialization (before integrity test)",
            "details": "Key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-1 with AES- 128 KW; 160-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.42 (A4612)",
            "condition": "Module initialization (before integrity test)",
            "details": "Key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-1 with AES- 128 KW; 160-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.42 (A4618)",
            "condition": "Module initialization (before integrity test)",
            "details": "Key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-1 with AES- 128 KW; 160-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.42 (A4619)",
            "condition": "Module initialization (before integrity test)",
            "details": "Key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-1 with AES- 128 KW; 160-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.42 (A4629)",
            "condition": "Module initialization (before integrity test)",
            "details": "Key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-1 with AES- 128 KW; 160-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.42 (A4630)",
            "condition": "Module initialization (before integrity test)",
            "details": "Key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-1 with AES- 128 KW; 160-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.42 (A4631)",
            "condition": "Module initialization (before integrity test)",
            "details": "Key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-1 with AES- 128 KW; 160-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.42 (A4632)",
            "condition": "Module initialization (before integrity test)",
            "details": "Key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-1 with AES- 128 KW; 160-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.63 (A4618)",
            "condition": "Module initialization (before integrity test)",
            "details": "Key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256; 192-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF SSH (A4635)",
            "condition": "Module initialization (before integrity test)",
            "details": "Key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-1; 1056-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF SSH (A4636)",
            "condition": "Module initialization (before integrity test)",
            "details": "Key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-1; 1056-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF SSH (A4637)",
            "condition": "Module initialization (before integrity test)",
            "details": "Key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-1; 1056-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF SSH (A4638)",
            "condition": "Module initialization (before integrity test)",
            "details": "Key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-1; 1056-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF SSH (A4639)",
            "condition": "Module initialization (before integrity test)",
            "details": "Key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-1; 1056-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "TLS v1.2 KDF RFC7627 (A4612)",
            "condition": "Module initialization (before integrity test)",
            "details": "Key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256; 384-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "TLS v1.2 KDF RFC7627 (A4618)",
            "condition": "Module initialization (before integrity test)",
            "details": "Key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256; 384-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "TLS v1.2 KDF RFC7627 (A4629)",
            "condition": "Module initialization (before integrity test)",
            "details": "Key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256; 384-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "TLS v1.2 KDF RFC7627 (A4630)",
            "condition": "Module initialization (before integrity test)",
            "details": "Key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256; 384-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "TLS v1.2 KDF RFC7627 (A4631)",
            "condition": "Module initialization (before integrity test)",
            "details": "Key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256; 384-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "TLS v1.2 KDF RFC7627 (A4632)",
            "condition": "Module initialization (before integrity test)",
            "details": "Key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256; 384-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "TLS v1.3 KDF (A4603)",
            "condition": "Module initialization (before integrity test)",
            "details": "Key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "Extract and expand modes; SHA-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "PBKDF (A4612)",
            "condition": "Module initialization (before integrity test)",
            "details": "Password-based key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256; 24 character password; 288-bit salt; Iteration count: 4096",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "PBKDF (A4613)",
            "condition": "Module initialization (before integrity test)",
            "details": "Password-based key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256; 24 character password; 288-bit salt; Iteration count: 4096",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "PBKDF (A4618)",
            "condition": "Module initialization (before integrity test)",
            "details": "Password-based key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256; 24 character password; 288-bit salt; Iteration count: 4096",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "PBKDF (A4619)",
            "condition": "Module initialization (before integrity test)",
            "details": "Password-based key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256; 24 character password; 288-bit salt; Iteration count: 4096",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "PBKDF (A4629)",
            "condition": "Module initialization (before integrity test)",
            "details": "Password-based key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256; 24 character password; 288-bit salt; Iteration count: 4096",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "PBKDF (A4630)",
            "condition": "Module initialization (before integrity test)",
            "details": "Password-based key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256; 24 character password; 288-bit salt; Iteration count: 4096",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "PBKDF (A4631)",
            "condition": "Module initialization (before integrity test)",
            "details": "Password-based key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256; 24 character password; 288-bit salt; Iteration count: 4096",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "PBKDF (A4632)",
            "condition": "Module initialization (before integrity test)",
            "details": "Password-based key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256; 24 character password; 288-bit salt; Iteration count: 4096",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "Counter DRBG (A4604)",
            "condition": "Module initialization (before integrity test)",
            "details": "Instantiate; Generate; Reseed (compliant to SP 800-90Arev1 Section 11.3)",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "AES-128 with prediction resistance",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "Hash DRBG (A4604)",
            "condition": "Module initialization (before integrity test)",
            "details": "Instantiate; Generate; Reseed (compliant to SP 800-90Arev1 Section 11.3)",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256 with prediction resistance",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC DRBG (A4604)",
            "condition": "Module initialization (before integrity test)",
            "details": "Instantiate; Generate; Reseed (compliant to SP 800-90Arev1 Section 11.3)",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-1 with prediction resistance",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS-FFC-SSC Sp800-56Ar3 (A4642)",
            "condition": "Module initialization (before integrity test)",
            "details": "Shared Secret Computation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "ffdhe2048",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS-ECC-SSC Sp800-56Ar3 (A4612)",
            "condition": "Module initialization (before integrity test)",
            "details": "Shared Secret Computation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "P-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS-ECC-SSC Sp800-56Ar3 (A4618)",
            "condition": "Module initialization (before integrity test)",
            "details": "Shared Secret Computation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "P-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS-ECC-SSC Sp800-56Ar3 (A4629)",
            "condition": "Module initialization (before integrity test)",
            "details": "Shared Secret Computation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "P-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS-ECC-SSC Sp800-56Ar3 (A4630)",
            "condition": "Module initialization (before integrity test)",
            "details": "Shared Secret Computation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "P-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS-ECC-SSC Sp800-56Ar3 (A4631)",
            "condition": "Module initialization (before integrity test)",
            "details": "Shared Secret Computation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "P-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS-ECC-SSC Sp800-56Ar3 (A4632)",
            "condition": "Module initialization (before integrity test)",
            "details": "Shared Secret Computation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "P-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigGen (FIPS186-5) (A4612)",
            "condition": "Module initialization (before integrity test)",
            "details": "Signature generation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256; 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigGen (FIPS186-5) (A4613)",
            "condition": "Module initialization (before integrity test)",
            "details": "Signature generation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256; 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigGen (FIPS186-5) (A4618)",
            "condition": "Module initialization (before integrity test)",
            "details": "Signature generation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256; 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigGen (FIPS186-5) (A4619)",
            "condition": "Module initialization (before integrity test)",
            "details": "Signature generation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256; 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigGen (FIPS186-5) (A4629)",
            "condition": "Module initialization (before integrity test)",
            "details": "Signature generation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256; 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigGen (FIPS186-5) (A4630)",
            "condition": "Module initialization (before integrity test)",
            "details": "Signature generation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256; 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigGen (FIPS186-5) (A4631)",
            "condition": "Module initialization (before integrity test)",
            "details": "Signature generation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256; 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigGen (FIPS186-5) (A4632)",
            "condition": "Module initialization (before integrity test)",
            "details": "Signature generation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256; 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186-5) (A4612)",
            "condition": "Module initialization (before integrity test)",
            "details": "Signature verification",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256; 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186-5) (A4613)",
            "condition": "Module initialization (before integrity test)",
            "details": "Signature verification",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256; 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186-5) (A4618)",
            "condition": "Module initialization",
            "details": "Signature verification",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256; 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "",
            "condition": "(before integrity test)",
            "details": "",
            "indicator": "",
            "testMethod": "",
            "testProps": "",
            "type": ""
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186-5) (A4619)",
            "condition": "Module initialization (before integrity test)",
            "details": "Signature verification",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256; 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186-5) (A4629)",
            "condition": "Module initialization (before integrity test)",
            "details": "Signature verification",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256; 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186-5) (A4630)",
            "condition": "Module initialization (before integrity test)",
            "details": "Signature verification",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256; 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186-5) (A4631)",
            "condition": "Module initialization (before integrity test)",
            "details": "Signature verification",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256; 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186-5) (A4632)",
            "condition": "Module initialization (before integrity test)",
            "details": "Signature verification",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256; 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186-4) (A4612)",
            "condition": "Module initialization (before integrity test)",
            "details": "Signature verification",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256; 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186-4) (A4618)",
            "condition": "Module initialization (before integrity test)",
            "details": "Signature verification",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256; 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186-4) (A4629)",
            "condition": "Module initialization (before integrity test)",
            "details": "Signature verification",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256; 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186-4) (A4630)",
            "condition": "Module initialization (before integrity test)",
            "details": "Signature verification",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256; 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186-4) (A4631)",
            "condition": "Module initialization (before integrity test)",
            "details": "Signature verification",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256; 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186-4) (A4632)",
            "condition": "Module initialization (before integrity test)",
            "details": "Signature verification",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256; 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigGen (FIPS186-5) (A4612)",
            "condition": "Module initialization (before integrity test)",
            "details": "Signature generation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256; P-224, P- 256, P-384, P-521",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigGen (FIPS186-5) (A4613)",
            "condition": "Module initialization (before integrity test)",
            "details": "Signature generation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256; P-224, P- 256, P-384, P-521",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigGen (FIPS186-5) (A4618)",
            "condition": "Module initialization (before integrity test)",
            "details": "Signature generation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256; P-224, P- 256, P-384, P-521",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigGen (FIPS186-5) (A4619)",
            "condition": "Module initialization (before integrity test)",
            "details": "Signature generation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256; P-224, P- 256, P-384, P-521",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigGen (FIPS186-5) (A4629)",
            "condition": "Module initialization (before integrity test)",
            "details": "Signature generation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256; P-224, P- 256, P-384, P-521",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigGen (FIPS186-5) (A4630)",
            "condition": "Module initialization (before integrity test)",
            "details": "Signature generation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256; P-224, P- 256, P-384, P-521",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigGen (FIPS186-5) (A4631)",
            "condition": "Module initialization (before integrity test)",
            "details": "Signature generation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256; P-224, P- 256, P-384, P-521",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigGen (FIPS186-5) (A4632)",
            "condition": "Module initialization (before integrity test)",
            "details": "Signature generation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256; P-224, P- 256, P-384, P-521",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigVer (FIPS186-5) (A4618)",
            "condition": "Module initialization (before integrity test)",
            "details": "Signature verification",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256; P-224, P- 256, P-384, P-521",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigVer (FIPS186-5) (A4619)",
            "condition": "Module initialization (before integrity test)",
            "details": "Signature verification",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256; P-224, P- 256, P-384, P-521",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigVer (FIPS186-5) (A4629)",
            "condition": "Module initialization (before integrity test)",
            "details": "Signature verification",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256; P-224, P- 256, P-384, P-521",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigVer (FIPS186-5) (A4630)",
            "condition": "Module initialization (before integrity test)",
            "details": "Signature verification",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256; P-224, P- 256, P-384, P-521",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigVer (FIPS186-5) (A4631)",
            "condition": "Module initialization (before integrity test)",
            "details": "Signature verification",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256; P-224, P- 256, P-384, P-521",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigVer (FIPS186-5) (A4632)",
            "condition": "Module initialization (before integrity test)",
            "details": "Signature verification",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256; P-224, P- 256, P-384, P-521",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "Safe Primes Key Generation",
            "condition": "Key pair generation",
            "details": "SP 800-56Arev3 Section 5.6.2.1.4",
            "indicator": "Key pair generation is successful",
            "testMethod": "PCT",
            "testProps": "N/A",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "(A4642) RSA KeyGen (FIPS186-5) (A4612)",
            "condition": "Key pair generation",
            "details": "Signature generation \u0026 verification",
            "indicator": "Key pair generation is sucessful",
            "testMethod": "PCT",
            "testProps": "N/A",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "RSA KeyGen (FIPS186-5) (A4618)",
            "condition": "Key pair generation",
            "details": "Signature generation \u0026 verification",
            "indicator": "Key pair generation is sucessful",
            "testMethod": "PCT",
            "testProps": "N/A",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "RSA KeyGen (FIPS186-5) (A4629)",
            "condition": "Key pair generation",
            "details": "Signature generation \u0026 verification",
            "indicator": "Key pair generation is sucessful",
            "testMethod": "PCT",
            "testProps": "N/A",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "RSA KeyGen (FIPS186-5) (A4630)",
            "condition": "Key pair generation",
            "details": "Signature generation \u0026 verification",
            "indicator": "Key pair generation is sucessful",
            "testMethod": "PCT",
            "testProps": "N/A",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "RSA KeyGen (FIPS186-5) (A4631)",
            "condition": "Key pair generation",
            "details": "Signature generation \u0026 verification",
            "indicator": "Key pair generation is sucessful",
            "testMethod": "PCT",
            "testProps": "N/A",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "RSA KeyGen (FIPS186-5) (A4632)",
            "condition": "Key pair generation",
            "details": "Signature generation \u0026 verification",
            "indicator": "Key pair generation is sucessful",
            "testMethod": "PCT",
            "testProps": "N/A",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "ECDSA KeyGen (FIPS186-5) (A4612)",
            "condition": "Key pair generation",
            "details": "Signature generation \u0026 verification",
            "indicator": "Key pair generation successful",
            "testMethod": "PCT",
            "testProps": "SHA-256",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "ECDSA KeyGen (FIPS186-5) (A4618)",
            "condition": "Key pair generation",
            "details": "Signature generation \u0026 verification",
            "indicator": "Key pair generation successful",
            "testMethod": "PCT",
            "testProps": "SHA-256",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "ECDSA KeyGen (FIPS186-5) (A4629)",
            "condition": "Key pair generation",
            "details": "Signature generation \u0026 verification",
            "indicator": "Key pair generation successful",
            "testMethod": "PCT",
            "testProps": "SHA-256",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "ECDSA KeyGen (FIPS186-5) (A4630)",
            "condition": "Key pair generation",
            "details": "Signature generation \u0026 verification",
            "indicator": "Key pair generation successful",
            "testMethod": "PCT",
            "testProps": "SHA-256",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "ECDSA KeyGen (FIPS186-5) (A4631)",
            "condition": "Key pair generation",
            "details": "Signature generation \u0026 verification",
            "indicator": "Key pair generation successful",
            "testMethod": "PCT",
            "testProps": "SHA-256",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "ECDSA KeyGen (FIPS186-5) (A4632)",
            "condition": "Key pair generation",
            "details": "Signature generation \u0026 verification",
            "indicator": "Key pair generation successful",
            "testMethod": "PCT",
            "testProps": "SHA-256",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "ECDSA SigVer (FIPS186-5) (A4613)",
            "condition": "Module initialization (before integrity test)",
            "details": "Signature verification",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256; P-224, P- 256, P-384, P-521",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.63 (A4613)",
            "condition": "Module initialization (before integrity test)",
            "details": "Key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256; 192-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigVer (FIPS186-5) (A4612)",
            "condition": "Module initialization (before integrity test)",
            "details": "Signature verification",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256; P-224, P- 256, P-384, P-521",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.63 (A4612)",
            "condition": "Module initialization (before integrity test)",
            "details": "Key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256; 192-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.63 (A4619)",
            "condition": "Module initialization (before integrity test)",
            "details": "Key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256; 192-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.63 (A4629)",
            "condition": "Module initialization (before integrity test)",
            "details": "Key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256; 192-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.63 (A4630)",
            "condition": "Module initialization (before integrity test)",
            "details": "Key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256; 192-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.63 (A4631)",
            "condition": "Module initialization (before integrity test)",
            "details": "Key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256; 192-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.63 (A4632)",
            "condition": "Module initialization (before integrity test)",
            "details": "Key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256; 192-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDA TwoStep SP800-56Cr2 (A4641)",
            "condition": "Module initialization (before integrity test)",
            "details": "Key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "SHA-256, 48-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF SP800- 108 (A4608)",
            "condition": "Module initialization (before integrity test)",
            "details": "Key derivation",
            "indicator": "Module is operational",
            "testMethod": "KAT",
            "testProps": "Counter mode; HMAC-SHA-256; 128-bit input key",
            "type": "CAST"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 2
      },
      "error_states": {
        "entries": [
          {
            "conditions": "Software integrity test failure CAST failure PCT failure",
            "description": "The module immediately stops functioning",
            "indicator": "Module will not load; Module is aborted for PCT failure",
            "name": "Error",
            "recoveryMethod": "Re-initialization of the module"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 4
      },
      "mechanisms_actions": {
        "entries": [],
        "found": false,
        "section": 7,
        "subsection": 1
      },
      "modes_of_operation": {
        "entries": [
          {
            "description": "Automatically entered whenever an approved service is requested",
            "name": "Approved mode",
            "statusIndicator": "Equivalent to the indicator (specified in Section 4.3) of the requested service",
            "type": "Approved"
          },
          {
            "description": "Automatically entered whenever a non-approved service is requested",
            "name": "Non- approved mode",
            "statusIndicator": "Equivalent to the indicator (specified in Section 4.3) of the requested service",
            "type": "Non- Approved"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 4
      },
      "non_approved_allowed_NSC": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_allowed_algos": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_not_allowed": {
        "entries": [
          {
            "name": "AES GCM (external IV)",
            "use": "Authenticated encryption"
          },
          {
            "name": "HMAC (\u003c 112-bit keys)",
            "use": "Message authentication"
          },
          {
            "name": "KBKDF, KDA OneStep, KDA TwoStep, HKDF, ANS X9.42 KDF, ANS X9.63 KDF (\u003c 112-bit keys)",
            "use": "Key derivation"
          },
          {
            "name": "KDA OneStep, KDA TwoStep (SHAKE128, SHAKE256)",
            "use": "Key derivation"
          },
          {
            "name": "ANS X9.42 KDF (SHAKE128, SHAKE256)",
            "use": "Key derivation"
          },
          {
            "name": "ANS X9.63 KDF (SHA-1, SHAKE128, SHAKE256)",
            "use": "Key derivation"
          },
          {
            "name": "SSH KDF (SHA-512/224, SHA-512/256, SHA-3, SHAKE128, SHAKE256)",
            "use": "Key derivation"
          },
          {
            "name": "TLS 1.2 KDF (SHA-1, SHA-224, SHA-512/224, SHA-512/256, SHA- 3)",
            "use": "Key derivation"
          },
          {
            "name": "TLS 1.3 KDF (SHA-1, SHA-224, SHA-512, SHA-512/224, SHA- 512/256, SHA-3)",
            "use": "Key derivation"
          },
          {
            "name": "PBKDF2 (\u003c 8 characters password; \u003c 128 salt length; \u003c 1000 iterations; \u003c 112-bit keys)",
            "use": "Password-based key derivation"
          },
          {
            "name": "RSA (KAS1, KAS2 schemes)",
            "use": "Shared secret computation"
          },
          {
            "name": "RSA and ECDSA (pre-hashed message)",
            "use": "Signature generation; Signature verification"
          },
          {
            "name": "RSA-PSS (invalid salt length)",
            "use": "Signature generation; Signature verification"
          },
          {
            "name": "RSA-OAEP",
            "use": "Asymmetric encryption; Asymmetric decryption"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "non_approved_services": {
        "entries": [
          {
            "alg_accessed": "AES GCM (external IV)",
            "description": "Encrypt a plaintext",
            "name": "Encryption",
            "role": "CO"
          },
          {
            "alg_accessed": "HMAC (\u003c 112-bit keys)",
            "description": "Compute a MAC tag",
            "name": "Message authentication",
            "role": "CO"
          },
          {
            "alg_accessed": "KBKDF, KDA OneStep, KDA TwoStep, HKDF, ANS X9.42 KDF, ANS X9.63 KDF (\u003c 112-bit keys) KDA OneStep, KDA TwoStep (SHAKE128, SHAKE256) ANS X9.42 KDF (SHAKE128, SHAKE256) ANS X9.63 KDF (SHA-1, SHAKE128, SHAKE256) SSH KDF (SHA-512/224, SHA-512/256, SHA-",
            "description": "Derive a key from a key- derivation key or a shared secret",
            "name": "Key derivation",
            "role": "CO"
          },
          {
            "alg_accessed": "3, SHAKE128, SHAKE256) TLS 1.2 KDF (SHA-1, SHA-224, SHA- 512/224, SHA-512/256, SHA-3) TLS 1.3 KDF (SHA-1, SHA-224, SHA-512, SHA-512/224, SHA-512/256, SHA-3)",
            "description": "",
            "name": "",
            "role": ""
          },
          {
            "alg_accessed": "PBKDF2 (\u003c 8 characters password; \u003c 128 salt length; \u003c 1000 iterations; \u003c 112-bit keys)",
            "description": "Derive a key from a password",
            "name": "Password-based key derivation",
            "role": "CO"
          },
          {
            "alg_accessed": "RSA (KAS1, KAS2 schemes)",
            "description": "Compute a shared secret",
            "name": "Shared secret computation",
            "role": "CO"
          },
          {
            "alg_accessed": "RSA and ECDSA (pre-hashed message) RSA-PSS (invalid salt length)",
            "description": "Generate a signature",
            "name": "Signature generation",
            "role": "CO"
          },
          {
            "alg_accessed": "RSA and ECDSA (pre-hashed message) RSA-PSS (invalid salt length)",
            "description": "Verify a signature",
            "name": "Signature verification",
            "role": "CO"
          },
          {
            "alg_accessed": "RSA-OAEP",
            "description": "Encrypt a plaintext",
            "name": "Asymmetric encryption",
            "role": "CO"
          },
          {
            "alg_accessed": "RSA-OAEP",
            "description": "Decrypt a ciphertext",
            "name": "Asymmetric decryption",
            "role": "CO"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 4
      },
      "ports_interfaces": {
        "entries": [
          {
            "data": "API input parameters",
            "logicalInterface": "Data Input",
            "physicalPort": "N/A"
          },
          {
            "data": "API output parameters",
            "logicalInterface": "Data Output",
            "physicalPort": "N/A"
          },
          {
            "data": "API function calls",
            "logicalInterface": "Control Input",
            "physicalPort": "N/A"
          },
          {
            "data": "queue",
            "logicalInterface": "Status Output API return codes, error",
            "physicalPort": "N/A"
          }
        ],
        "found": true,
        "section": 3,
        "subsection": 1
      },
      "roles": {
        "entries": [
          {
            "authMethodList": "None",
            "name": "Crypto Officer",
            "operatorType": "CO",
            "type": "Role"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 2
      },
      "security_levels": {
        "entries": [
          {
            "level": "1",
            "section": "1",
            "title": "General"
          },
          {
            "level": "1",
            "section": "2",
            "title": "Cryptographic module specification"
          },
          {
            "level": "1",
            "section": "3",
            "title": "Cryptographic module interfaces"
          },
          {
            "level": "1",
            "section": "4",
            "title": "Roles, services, and authentication"
          },
          {
            "level": "1",
            "section": "5",
            "title": "Software/Firmware security"
          },
          {
            "level": "1",
            "section": "6",
            "title": "Operational environment"
          },
          {
            "level": "N/A",
            "section": "7",
            "title": "Physical security"
          },
          {
            "level": "N/A",
            "section": "8",
            "title": "Non-invasive security"
          },
          {
            "level": "1",
            "section": "9",
            "title": "Sensitive security parameter management"
          },
          {
            "level": "1",
            "section": "10",
            "title": "Self-tests"
          },
          {
            "level": "1",
            "section": "11",
            "title": "Life-cycle assurance"
          },
          {
            "level": "1",
            "section": "12",
            "title": "Mitigation of other attacks"
          },
          {
            "level": "1",
            "section": "",
            "title": "Overall Level"
          }
        ],
        "found": true,
        "section": 1,
        "subsection": 2
      },
      "self_tests": {
        "entries": [
          {
            "algorithmOrTest": "HMAC-SHA2-256 (A4608)",
            "details": "Integrity test for fips.so",
            "indicator": "Module becomes operational",
            "testMethod": "Message authentication",
            "testProps": "256-bit key",
            "type": "SW/FW Integrity"
          },
          {
            "algorithmOrTest": "HMAC-SHA2-256 (A4612)",
            "details": "Integrity test for fips.so",
            "indicator": "Module becomes operational",
            "testMethod": "Message authentication",
            "testProps": "256-bit key",
            "type": "SW/FW Integrity"
          },
          {
            "algorithmOrTest": "HMAC-SHA2-256 (A4618)",
            "details": "Integrity test for fips.so",
            "indicator": "Module becomes operational",
            "testMethod": "Message authentication",
            "testProps": "256-bit key",
            "type": "SW/FW Integrity"
          },
          {
            "algorithmOrTest": "HMAC-SHA2-256 (A4629)",
            "details": "Integrity test for fips.so",
            "indicator": "Module becomes operational",
            "testMethod": "Message authentication",
            "testProps": "256-bit key",
            "type": "SW/FW Integrity"
          },
          {
            "algorithmOrTest": "HMAC-SHA2-256 (A4630)",
            "details": "Integrity test for fips.so",
            "indicator": "Module becomes operational",
            "testMethod": "Message authentication",
            "testProps": "256-bit key",
            "type": "SW/FW Integrity"
          },
          {
            "algorithmOrTest": "HMAC-SHA2-256 (A4631)",
            "details": "Integrity test for fips.so",
            "indicator": "Module becomes operational",
            "testMethod": "Message authentication",
            "testProps": "256-bit key",
            "type": "SW/FW Integrity"
          },
          {
            "algorithmOrTest": "HMAC-SHA2-256 (A4632)",
            "details": "Integrity test for fips.so",
            "indicator": "Module becomes operational",
            "testMethod": "Message authentication",
            "testProps": "256-bit key",
            "type": "SW/FW Integrity"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 1
      },
      "ssp_io_methods": {
        "entries": [
          {
            "dest": "Cryptographic module",
            "distribution": "Manual",
            "entry": "Electronic",
            "format": "Plaintext",
            "name": "API input parameters",
            "sfiAlgo": "",
            "source": "Operator calling application (TOEPP)"
          },
          {
            "dest": "Operator calling application (TOEPP)",
            "distribution": "Manual",
            "entry": "Electronic",
            "format": "Plaintext",
            "name": "API output parameters",
            "sfiAlgo": "",
            "source": "Cryptographic module"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 2
      },
      "ssp_zeroization_methods": {
        "entries": [
          {
            "description": "Zeroizes the SSPs contained within the cipher handle",
            "method": "Free cipher handle",
            "operatorId": "By calling the appropriate zeroization functions: AES key: EVP_CIPHER_CTX_free and EVP_MAC_CTX_free; HMAC key: EVP_MAC_CTX_free; Key-derivation key: EVP_KDF_CTX_free; Shared secret: EVP_KDF_CTX_free; Password: EVP_KDF_CTX_free; KBKDF Derived key: EVP_KDF_CTX_free; HKDF Derived key: EVP_KDF_CTX_free; TLS Derived key: EVP_KDF_CTX_free; SSH Derived key: EVP_KDF_CTX_free; X9.63 Derived key: EVP_KDF_CTX_free; X9.42 Derived key: EVP_KDF_CTX_free; PBKDF Derived key: EVP_KDF_CTX_free; KDA OneStep Derived key: EVP_KDF_CTX_free; KDA TwoStep Derived key: EVP_KDF_CTX_free; Entropy input: EVP_RAND_CTX_free; DRBG seed: EVP_RAND_CTX_free; Internal state: EVP_RAND_CTX_free; DH public \u0026 private key: EVP_PKEY_free; EC public \u0026 private key: EVP_PKEY_free; RSA public \u0026 private key: EVP_PKEY_free",
            "rationale": "Memory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable. The completion of the zeroization routine indicates that the zeroization procedure succeeded."
          },
          {
            "description": "Automatically zeroized by the module when no longer needed",
            "method": "Automatic",
            "operatorId": "N/A",
            "rationale": "Memory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable"
          },
          {
            "description": "De-allocates the volatile memory",
            "method": "Remove power from the module",
            "operatorId": "By unloading the module",
            "rationale": "Volatile memory used by the module is overwritten within nanoseconds when"
          },
          {
            "description": "used to store SSPs",
            "method": "",
            "operatorId": "",
            "rationale": "the module is unloaded. The successful completion of the removal of power from the module indicates that zeroization has completed."
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 3
      },
      "storage_areas": {
        "entries": [
          {
            "description": "Temporary storage for SSPs used by the module as part of service execution. SSPs are stored until they are zeroized by the operator (using a zeroization call or removing power from the module) or zeroized automatically.",
            "name": "RAM",
            "persistance": "Dynamic"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 1
      },
      "tested_module_id_hw": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "tested_module_id_hw_hy": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "tested_module_id_sw_fw_hy": {
        "entries": [
          {
            "features": "N/A",
            "integrityTest": "HMAC-SHA-256",
            "packageFileName": "fips.so on Amazon Linux 2023 with AWS Graviton3",
            "swFwVersion": "3.0.8- d694bfa693b76001"
          },
          {
            "features": "N/A",
            "integrityTest": "HMAC-SHA-256",
            "packageFileName": "fips.so on Amazon Linux 2023 with Intel Xeon Platinum 8375C",
            "swFwVersion": "3.0.8- d694bfa693b76001"
          },
          {
            "features": "N/A",
            "integrityTest": "HMAC-SHA-256",
            "packageFileName": "fips.so on Amazon Linux 2023 with AMD EPYC 7702",
            "swFwVersion": "3.0.8- d694bfa693b76001"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 2
      },
      "tested_op_env_sw_fw_hy": {
        "entries": [
          {
            "hardwarePlatform": "EC2 c7g.metal",
            "hypervisorHostOs": "N/A",
            "operatingSystem": "Amazon Linux 2023",
            "paa_pai": "Yes",
            "processors": "AWS Graviton3",
            "version": "3.0.8- d694bfa693b76001"
          },
          {
            "hardwarePlatform": "EC2 c6i.metal",
            "hypervisorHostOs": "N/A",
            "operatingSystem": "Amazon Linux 2023",
            "paa_pai": "Yes",
            "processors": "Intel Xeon Platinum 8375C",
            "version": "3.0.8- d694bfa693b76001"
          },
          {
            "hardwarePlatform": "AWS Snowball",
            "hypervisorHostOs": "N/A",
            "operatingSystem": "Amazon Linux 2023",
            "paa_pai": "Yes",
            "processors": "AMD EPYC 7702",
            "version": "3.0.8- d694bfa693b76001"
          },
          {
            "hardwarePlatform": "EC2 c7g.metal",
            "hypervisorHostOs": "N/A",
            "operatingSystem": "Amazon Linux 2023",
            "paa_pai": "No",
            "processors": "AWS Graviton3",
            "version": "3.0.8- d694bfa693b76001"
          },
          {
            "hardwarePlatform": "EC2 c6i.metal",
            "hypervisorHostOs": "N/A",
            "operatingSystem": "Amazon Linux 2023",
            "paa_pai": "No",
            "processors": "Intel Xeon Platinum 8375C",
            "version": "3.0.8- d694bfa693b76001"
          },
          {
            "hardwarePlatform": "AWS Snowball",
            "hypervisorHostOs": "N/A",
            "operatingSystem": "Amazon Linux 2023",
            "paa_pai": "No",
            "processors": "AMD EPYC 7702",
            "version": "3.0.8- d694bfa693b76001"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 2
      },
      "vendor_affirmed_algos": {
        "entries": [
          {
            "algoPropList": "Key Type:Asymmetric",
            "implName": "N/A",
            "name": "Asymmetric Cryptographic Key Generation (CKG)",
            "reference": "SP 800-133Rev2 section 4, example 1"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "vendor_affirmed_op_env_sw_fw_hy": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      }
    },
    "is_br1_format": true,
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 1
          },
          "ECDH": {
            "ECDH": 5
          },
          "ECDSA": {
            "ECDSA": 88
          }
        },
        "FF": {
          "DH": {
            "DH": 30,
            "DHE": 2,
            "Diffie-Hellman": 12
          }
        },
        "RSA": {
          "RSA-OAEP": 3,
          "RSA-PSS": 3
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 2
        },
        "CCM": {
          "CCM": 15
        },
        "CFB": {
          "CFB": 1
        },
        "CTR": {
          "CTR": 2
        },
        "ECB": {
          "ECB": 1
        },
        "GCM": {
          "GCM": 29
        },
        "OFB": {
          "OFB": 1
        },
        "XTS": {
          "XTS": 8
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {
        "OpenSSL": {
          "OpenSSL": 78
        }
      },
      "crypto_protocol": {
        "IKE": {
          "IKE": 4
        },
        "SSH": {
          "SSH": 34
        },
        "TLS": {
          "TLS": {
            "TLS": 22,
            "TLS 1.2": 12,
            "TLS 1.3": 15,
            "TLS v1.2": 14,
            "TLS v1.3": 4
          }
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 2
        },
        "KEX": {
          "Key Exchange": 2
        },
        "MAC": {
          "MAC": 11
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-224": 50,
          "P-256": 40,
          "P-384": 56,
          "P-521": 60
        }
      },
      "eval_facility": {
        "atsec": {
          "atsec": 3
        }
      },
      "fips_cert_id": {},
      "fips_certlike": {
        "Certlike": {
          "- PKCS 1": 1,
          "AES- 128": 8,
          "AES- 192": 1,
          "AES-128": 3,
          "AES-192": 3,
          "AES-256": 7,
          "HMAC SHA-1": 1,
          "HMAC SHA-256": 2,
          "HMAC- SHA-512": 1,
          "HMAC-SHA-1": 2,
          "HMAC-SHA-256": 10,
          "PKCS 1": 1,
          "PKCS#1": 44,
          "SHA- 224": 4,
          "SHA- 256": 5,
          "SHA- 3": 1,
          "SHA- 384": 5,
          "SHA- 512": 2,
          "SHA-1": 43,
          "SHA-224": 9,
          "SHA-256": 82,
          "SHA-3": 10,
          "SHA-384": 10,
          "SHA-512": 17,
          "SHA2-224": 6,
          "SHA2-256": 11,
          "SHA2-384": 9,
          "SHA2-512": 22,
          "SHA3- 256": 7,
          "SHA3-224": 18,
          "SHA3-256": 15,
          "SHA3-384": 19,
          "SHA3-512": 17,
          "SHA3-512 2": 1
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 2
        }
      },
      "hash_function": {
        "PBKDF": {
          "PBKDF": 32,
          "PBKDF2": 7
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 43
          },
          "SHA2": {
            "SHA-224": 9,
            "SHA-256": 82,
            "SHA-384": 10,
            "SHA-512": 17
          },
          "SHA3": {
            "SHA-3": 10,
            "SHA3-224": 18,
            "SHA3-256": 15,
            "SHA3-384": 19,
            "SHA3-512": 18
          }
        },
        "SHAKE": {
          "SHAKE128": 9,
          "SHAKE256": 9
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 43
        },
        "RNG": {
          "RBG": 2,
          "RNG": 1
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-3": 81,
          "FIPS 180-4": 8,
          "FIPS 186-4": 2,
          "FIPS 186-5": 10,
          "FIPS 197": 1,
          "FIPS 198-1": 12,
          "FIPS 202": 7,
          "FIPS PUB 140-3": 3,
          "FIPS186-4": 14,
          "FIPS186-5": 104
        },
        "NIST": {
          "SP 800-108": 1,
          "SP 800-132": 8,
          "SP 800-135": 7,
          "SP 800-38A": 12,
          "SP 800-38B": 2,
          "SP 800-38C": 2,
          "SP 800-38D": 3,
          "SP 800-38E": 3,
          "SP 800-38F": 4,
          "SP 800-56A": 4,
          "SP 800-56C": 3,
          "SP 800-90A": 3,
          "SP 800-90B": 1
        },
        "PKCS": {
          "PKCS 1": 1,
          "PKCS#1": 22
        },
        "RFC": {
          "RFC 3526": 2,
          "RFC 4253": 1,
          "RFC 5288": 3,
          "RFC 6668": 1,
          "RFC 7919": 2,
          "RFC 8446": 1,
          "RFC7627": 13,
          "RFC8446": 2
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 93,
            "AES-": 9,
            "AES-128": 3,
            "AES-192": 3,
            "AES-256": 7
          },
          "CAST": {
            "CAST": 255
          }
        },
        "constructions": {
          "MAC": {
            "CMAC": 3,
            "HMAC": 24,
            "HMAC-SHA-256": 5
          }
        }
      },
      "tee_name": {
        "AMD": {
          "PSP": 3
        },
        "IBM": {
          "SSC": 1
        }
      },
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "module_algorithms": {
      "_type": "Set",
      "elements": [
        "HMAC-SHA-1A4632",
        "ECDSA SigVer (FIPS186-5)A4632",
        "Hash DRBGA4604",
        "AES-CCMA4611",
        "KDA OneStep SP800-56Cr2A4641",
        "HMAC-SHA2-512A4632",
        "SHA3-256A4619",
        "SHA2-224A4632",
        "KAS-ECC-SSC Sp800-56Ar3A4632",
        "AES-CFB1A4611",
        "AES-CMACA4611",
        "AES-XTS Testing Revision 2.0A4611",
        "AES-GMACA4628",
        "HMAC-SHA3-256A4619",
        "KDA TwoStep SP800-56Cr2A4641",
        "RSA KeyGen (FIPS186-5)A4632",
        "AES-CBC-CS2A4611",
        "AES-CFB8A4611",
        "AES-CFB128A4611",
        "KDF ANS 9.42A4632",
        "KDF ANS 9.63A4632",
        "KDF SSHA4639",
        "AES-OFBA4611",
        "SHA-1A4632",
        "HMAC-SHA3-384A4619",
        "KAS-FFC-SSC Sp800-56Ar3A4642",
        "AES-KWA4611",
        "HMAC-SHA3-512A4619",
        "SHA2-512/256A4632",
        "SHAKE-128A4619",
        "ECDSA KeyVer (FIPS186-5)A4632",
        "Counter DRBGA4604",
        "Safe Primes Key GenerationA4642",
        "RSA SigVer (FIPS186-5)A4632",
        "AES-ECBA4639",
        "SHA3-224A4619",
        "ECDSA KeyGen (FIPS186-5)A4632",
        "RSA SigGen (FIPS186-5)A4632",
        "HMAC DRBGA4604",
        "AES-CBCA4611",
        "HMAC-SHA2-512/224A4632",
        "SHA2-384A4632",
        "Safe Primes Key VerificationA4642",
        "PBKDFA4632",
        "SHA3-512A4619",
        "AES-KWPA4611",
        "RSA SigVer (FIPS186-4)A4632",
        "KDA HKDF Sp800-56Cr1A4603",
        "KDF SP800-108A4640",
        "SHA2-512A4632",
        "AES-GCMA4628",
        "ECDSA SigGen (FIPS186-5)A4632",
        "SHAKE-256A4619",
        "TLS v1.2 KDF RFC7627A4632",
        "TLS v1.3 KDFA4603",
        "AES-CBC-CS1A4611",
        "AES-CBC-CS3A4611",
        "HMAC-SHA3-224A4619",
        "HMAC-SHA2-224A4632",
        "HMAC-SHA2-512/256A4632",
        "AES-CTRA4611",
        "HMAC-SHA2-256A4632",
        "SHA3-384A4619",
        "SHA2-512/224A4632",
        "SHA2-256A4632",
        "HMAC-SHA2-384A4632"
      ]
    },
    "policy_algorithms": {
      "_type": "Set",
      "elements": [
        "#A4614",
        "#A4632",
        "#A4609",
        "#A4607",
        "#A4625",
        "#A4637",
        "#A4606",
        "#A4603",
        "#A4635",
        "#A4621",
        "#A4615",
        "#A4605",
        "#A4627",
        "#A4630",
        "#A4626",
        "#A4629",
        "#A4620",
        "#A4612",
        "#A4604",
        "#A4640",
        "#A4611",
        "#A4613",
        "#A4628",
        "#A4610",
        "#A4641",
        "#A4619",
        "#A4638",
        "#A4608",
        "#A4622",
        "#A4636",
        "#A4618",
        "#A4624",
        "#A4639",
        "#A4617",
        "#A4616",
        "#A4631",
        "#A4642",
        "#A4623"
      ]
    },
    "policy_metadata": {
      "/Author": "",
      "/Comments": "",
      "/Company": "",
      "/CreationDate": "D:20250520101806-04\u002700\u0027",
      "/Creator": "Acrobat PDFMaker 25 for Word",
      "/Keywords": "",
      "/ModDate": "D:20250520102228-04\u002700\u0027",
      "/Producer": "Adobe PDF Library 25.1.208",
      "/SourceModified": "",
      "/Subject": "",
      "/Title": "",
      "pdf_file_size_bytes": 843059,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.202.pdf",
          "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90B.pdf",
          "https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-5.pdf",
          "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-52r2.pdf",
          "https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf",
          "https://csrc.nist.gov/Projects/cryptographic-module-validation-program/fips-140-3-ig-announcements",
          "https://csrc.nist.gov/publications/fips/fips198-1/FIPS-198-1_final.pdf",
          "https://csrc.nist.gov/publications/nistpubs/800-132/nist-sp800-132.pdf",
          "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Ar3.pdf",
          "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90Ar1.pdf",
          "https://docs.aws.amazon.com/linux/al2023/ug/fips-mode.html",
          "https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-135r1.pdf",
          "https://csrc.nist.gov/publications/nistpubs/800-38B/SP_800-38B.pdf",
          "https://csrc.nist.gov/publications/fips/fips197/fips-197.pdf",
          "https://www.ietf.org/rfc/rfc7919.txt",
          "https://www.ietf.org/rfc/rfc8446.txt",
          "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Cr1.pdf",
          "https://www.ietf.org/rfc/rfc5288.txt",
          "https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38d.pdf",
          "http://www.atsec.com/",
          "https://csrc.nist.gov/publications/nistpubs/800-38a/sp800-38a.pdf",
          "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-133r2.pdf",
          "https://webstore.ansi.org/standards/ascx9/ansix9422001",
          "https://webstore.ansi.org/standards/ascx9/ansix9632001",
          "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38F.pdf",
          "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Cr2.pdf",
          "https://www.ietf.org/rfc/rfc3526.txt",
          "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-108r1.pdf",
          "https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38a-add.pdf",
          "https://csrc.nist.gov/publications/nistpubs/800-38E/nist-sp-800-38E.pdf",
          "https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-4.pdf",
          "https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-3.pdf",
          "https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38c.pdf"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 71
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.InternalState",
    "module": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "policy": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": "7d0e15a8ff411affd680906a013791878fcad74a05b8c158d495415181981639",
      "source_hash": "08b753738dd1beb426485dee82c0352c023e4c46660e485117dd307de1526f63",
      "txt_hash": "a33ba48de806fa59de4b1c103bd3f7bfe16b31881f4393f316efa3ac97bf379f"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/May 2025_130625_0321.pdf",
    "date_sunset": "2030-05-25",
    "description": "The Amazon Linux 2023 OpenSSL FIPS Provider is a software library implementing general purpose cryptographic algorithms.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Physical security: N/A",
      "Non-invasive security: N/A"
    ],
    "fw_versions": null,
    "historical_reason": null,
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {},
    "module_name": "Amazon Linux 2023 OpenSSL FIPS Provider",
    "module_type": "Software",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-3",
    "status": "active",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2025-05-26",
        "lab": "atsec information security corporation",
        "validation_type": "Initial"
      }
    ],
    "vendor": "Amazon Web Services, Inc.",
    "vendor_url": "http://www.amazon.com"
  }
}