{"_type": "sec_certs.sample.fips.FIPSCertificate", "dgst": "193dfde4a2d3ab02", "cert_id": 5405, "web_data": {"_type": "sec_certs.sample.fips.FIPSCertificate.WebData", "module_name": "Windows OS Loader", "validation_history": [{"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry", "date": "2026-08-31", "validation_type": "Initial", "lab": "Leidos Accredited Testing & Evaluation (AT&E) Lab"}], "vendor_url": "http://www.microsoft.com", "vendor": "Microsoft Corporation", "certificate_pdf_url": null, "module_type": "Software-Hybrid", "standard": "FIPS 140-3", "status": "active", "level": 1, "caveat": "When installed, initialized and configured as specified in Section 11.1 of the Security Policy. When operated in approved mode with module Boot Manager validated to FIPS 140-3 under Cert. #5404 operating in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs. No assurance of FIPS 140-3 requirements met for the components of the RBG construct that are external to the module boundary (e.g., DRBG, ESV) except for SP 800-90C compliance and security strength of the provided random bits", "exceptions": ["Non-invasive security: N/A"], "embodiment": "MultiChipStand", "description": "The Windows OS Loader (the \"module\") is the component that loads the operating system kernel (ntoskrnl.exe) and other boot stage binary image files. The module is a part of BitLocker Drive Encryption, which is a data protection feature of the Windows operating system that encrypts data on a storage volume.", "tested_conf": null, "hw_versions": null, "fw_versions": null, "sw_versions": null, "mentioned_certs": {"5404": 1}, "historical_reason": null, "date_sunset": "2031-08-30", "revoked_reason": null, "revoked_link": null}, "pdf_data": {"_type": "sec_certs.sample.fips.FIPSCertificate.PdfData", "keywords": {"fips_cert_id": {"Cert": {"#5404": 2, "#1": 1}}, "fips_security_level": {"Level": {"level 1": 1, "Level 1": 4}}, "fips_certlike": {"Certlike": {"SHA-1": 9, "SHA2-256": 15, "SHA2-384": 6, "SHA2-512": 10, "SHS1": 6, "SHA2": 3, "- PKCS 1": 4, "RSA PKCS #1": 1, "AES-256": 6, "AES- 128": 2, "DRBG1": 9, "PKCS 1": 4, "PKCS #1": 1}}, "vendor": {"Microsoft": {"Microsoft Corporation": 55, "Microsoft": 35}}, "eval_facility": {}, "symmetric_crypto": {"AES_competition": {"AES": {"AES-256": 6, "AES": 31, "AES-": 8}, "CAST": {"CAST": 66}}, "constructions": {"MAC": {"CBC-MAC": 2}}}, "asymmetric_crypto": {}, "pq_crypto": {}, "hash_function": {"SHA": {"SHA1": {"SHA-1": 9}, "SHA2": {"SHA2": 3}}}, "crypto_scheme": {}, "crypto_protocol": {"TLS": {"TLS": {"TLS": 4}}}, "randomness": {"PRNG": {"DRBG": 36}, "RNG": {"RBG": 5}}, "cipher_mode": {"CTR": {"CTR": 4}, "GCM": {"GCM": 1}, "CCM": {"CCM": 1}, "XTS": {"XTS": 2}}, "ecc_curve": {}, "crypto_engine": {}, "tls_cipher_suite": {}, "crypto_library": {}, "vulnerability": {}, "side_channel_analysis": {}, "device_model": {}, "tee_name": {"AMD": {"PSP": 1}}, "os_name": {}, "cplc_data": {}, "ic_data_group": {}, "standard_id": {"FIPS": {"FIPS 140-3": 8, "FIPS 186-4": 13, "FIPS PUB 140-3": 1, "FIPS186-4": 20, "FIPS 180-4": 11, "FIPS 186-5": 6, "FIPS 197": 1}, "NIST": {"SP 800-38A": 2, "SP 800-38C": 2, "SP 800-38D": 2, "SP 800-38E": 2, "SP 800-90A": 2, "SP 800-90B": 1, "NIST SP 800-38A": 1, "NIST SP 800-38C": 1, "NIST SP 800-38D": 1, "NIST SP 800-38E": 1, "NIST SP 800-90A": 1, "NIST SP 800-90B": 1}, "PKCS": {"PKCS 1": 4, "PKCS #1": 1}, "ISO": {"ISO/IEC 19790:2012": 1}}, "javacard_version": {}, "javacard_api_const": {}, "javacard_packages": {}, "certification_process": {}}, "policy_metadata": {"pdf_file_size_bytes": 1244985, "pdf_is_encrypted": false, "pdf_number_of_pages": 46, "/Author": "Robert Durff", "/CreationDate": "D:20260825072747-04'00'", "/Creator": "Microsoft\u00ae Word for Microsoft 365", "/MSIP_Label_09028634-1b4d-412c-bf5f-1be49c7e2c2f_ActionId": "ecb8c4a0-a6b5-43c7-984e-0529691b71b3", "/MSIP_Label_09028634-1b4d-412c-bf5f-1be49c7e2c2f_ContentBits": "0", "/MSIP_Label_09028634-1b4d-412c-bf5f-1be49c7e2c2f_Enabled": "true", "/MSIP_Label_09028634-1b4d-412c-bf5f-1be49c7e2c2f_Method": "Privileged", "/MSIP_Label_09028634-1b4d-412c-bf5f-1be49c7e2c2f_Name": "Third Party Protected Information", "/MSIP_Label_09028634-1b4d-412c-bf5f-1be49c7e2c2f_SetDate": "2026-08-19T13:12:40Z", "/MSIP_Label_09028634-1b4d-412c-bf5f-1be49c7e2c2f_SiteId": "b64da4ac-e800-4cfc-8931-e607f720a1b8", "/MSIP_Label_09028634-1b4d-412c-bf5f-1be49c7e2c2f_Tag": "10, 0, 1, 1", "/MSIP_Label_4dd2c6e0-f1e3-4cf2-bd0b-256ab4cff3af_ActionId": "180250b5-f515-447c-b295-4c272bff8ae1", "/MSIP_Label_4dd2c6e0-f1e3-4cf2-bd0b-256ab4cff3af_ContentBits": "1", "/MSIP_Label_4dd2c6e0-f1e3-4cf2-bd0b-256ab4cff3af_Enabled": "true", "/MSIP_Label_4dd2c6e0-f1e3-4cf2-bd0b-256ab4cff3af_Method": "Privileged", "/MSIP_Label_4dd2c6e0-f1e3-4cf2-bd0b-256ab4cff3af_Name": "UNCLASSIFIED", "/MSIP_Label_4dd2c6e0-f1e3-4cf2-bd0b-256ab4cff3af_SetDate": "2026-08-25T11:22:17Z", "/MSIP_Label_4dd2c6e0-f1e3-4cf2-bd0b-256ab4cff3af_SiteId": "da9cbe40-ec1e-4997-afb3-17d87574571a", "/MSIP_Label_4dd2c6e0-f1e3-4cf2-bd0b-256ab4cff3af_Tag": "10, 0, 1, 1", "/ModDate": "D:20260825072747-04'00'", "/Producer": "Microsoft\u00ae Word for Microsoft 365", "pdf_hyperlinks": {"_type": "Set", "elements": ["https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/use/manage-servers", "https://csrc.nist.gov/publications/detail/fips/140/3/final", "https://csrc.nist.gov/publications/detail/sp/800-38c/final", "https://csrc.nist.gov/pubs/fips/186-5/final", "https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.security/get-authenticodesignature", "https://csrc.nist.gov/publications/detail/fips/197/final", "https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.management/get-itemproperty", "https://csrc.nist.gov/publications/detail/fips/186/4/final", "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/entropy/E216_PublicUse.pdf", "https://csrc.nist.gov/publications/detail/sp/800-90b/final", "https://csrc.nist.gov/publications/detail/sp/800-38a/final", "https://csrc.nist.gov/publications/detail/sp/800-38d/final", "https://csrc.nist.gov/publications/detail/sp/800-90a/rev-1/final", "https://csrc.nist.gov/publications/detail/fips/180/4/final", "https://csrc.nist.gov/publications/detail/sp/800-38e/final", "https://www.microsoft.com/en-us/howtotell/default.aspx", "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/entropy/E189_PublicUse.pdf"]}}}, "heuristics": {"_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics", "algorithms": {"_type": "Set", "elements": ["AES-CCMA4009", "RSA SigVer (FIPS186-4)A3768", "SHA-1A4009", "AES-GCMA4009", "SHA2-384A4009", "AES-XTS Testing Revision 2.0A4009", "SHA2-256A4009", "SHA2-512A4009", "Counter DRBGA4009", "AES-CBCA4009"]}, "extracted_versions": {"_type": "Set", "elements": ["-"]}, "cpe_matches": {"_type": "Set", "elements": ["cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:arm64:*"]}, "verified_cpe_matches": null, "related_cves": {"_type": "Set", "elements": ["CVE-2018-0599", "CVE-2021-36958", "CVE-2010-3889", "CVE-1999-0524", "CVE-2010-3143", "CVE-2011-5049", "CVE-2008-6194", "CVE-2010-3888", "CVE-2011-0638", "CVE-2018-0598", "CVE-2011-3389", "CVE-2012-2971", "CVE-2010-2157", "CVE-2012-2972", "CVE-2010-3139"]}, "policy_prunned_references": {"_type": "Set", "elements": ["5404"]}, "module_prunned_references": {"_type": "Set", "elements": ["5404"]}, "policy_processed_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": {"_type": "Set", "elements": ["5406", "5407", "5408"]}, "indirectly_referenced_by": {"_type": "Set", "elements": ["5407", "5408", "5409", "5406", "5405", "5404", "5410"]}, "directly_referencing": {"_type": "Set", "elements": ["5404"]}, "indirectly_referencing": {"_type": "Set", "elements": ["5404", "5405", "5408"]}}, "module_processed_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": {"_type": "Set", "elements": ["5406", "5407", "5408"]}, "indirectly_referenced_by": {"_type": "Set", "elements": ["5407", "5408", "5409", "5406", "5405", "5404", "5410"]}, "directly_referencing": {"_type": "Set", "elements": ["5404"]}, "indirectly_referencing": {"_type": "Set", "elements": ["5404", "5405", "5408"]}}, "direct_transitive_cves": null, "indirect_transitive_cves": {"_type": "Set", "elements": ["CVE-2018-0599", "CVE-2021-36958", "CVE-2010-3889", "CVE-1999-0524", "CVE-2010-3143", "CVE-2011-5049", "CVE-2008-6194", "CVE-2010-3888", "CVE-2011-0638", "CVE-2018-0598", "CVE-2011-3389", "CVE-2012-2971", "CVE-2010-2157", "CVE-2012-2972", "CVE-2010-3139"]}}, "state": {"_type": "sec_certs.sample.fips.InternalState", "module": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": null, "txt_hash": null, "json_hash": null}, "policy": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": "328d4acf26046633a257c74c22b401c1d4b22f40126049c2a3d15bd5d4d4907c", "txt_hash": "33392bd50b670075e54ae9178e9e78b2ebb17967132944c2658a1d7a995dd905", "json_hash": null}}}