This page was not yet optimized for use on mobile
devices.
VMware Kernel Cryptographic Module
Certificate #2180
Webpage information
Security policy
Symmetric Algorithms
AES, DES, Triple-DES, HMAC, CBC-MACAsymmetric Algorithms
DSAHash functions
SHA-1, SHA-512, SHA-384, SHA-224, SHA-256Schemes
MACProtocols
IPsec, VPNRandomness
PRNG, RNGLibraries
NSSBlock cipher modes
ECB, CBC, CTR, GCM, CCM, XTSSecurity level
Level 1, Level 9Standards
FIPS 140-2, SP 800-131AFile metadata
| Title | 1B - VMware Kernel Crypto Module FIPS 140-2 Security Policy |
|---|---|
| Author | jschultz |
| Creation date | D:20140521123408-04'00' |
| Modification date | D:20140521123408-04'00' |
| Pages | 21 |
| Creator | PDFCreator Version 1.7.2 |
| Producer | GPL Ghostscript 9.10 |
References
OutgoingHeuristics
No heuristics are available for this certificate.
References
Loading...
Updates Feed
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate was first processed.
Raw data
{
"_type": "sec_certs.sample.fips.FIPSCertificate",
"cert_id": 2180,
"dgst": "25dbd7ca6d959934",
"heuristics": {
"_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
"algorithms": {
"_type": "Set",
"elements": [
"RNG#1259",
"HMAC#1697",
"AES#2718",
"Triple-DES#1635",
"SHS#2283"
]
},
"cpe_matches": null,
"direct_transitive_cves": null,
"extracted_versions": {
"_type": "Set",
"elements": [
"-"
]
},
"indirect_transitive_cves": null,
"module_processed_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": {
"_type": "Set",
"elements": [
"2155"
]
},
"indirectly_referenced_by": null,
"indirectly_referencing": {
"_type": "Set",
"elements": [
"2155"
]
}
},
"module_prunned_references": {
"_type": "Set",
"elements": [
"2155"
]
},
"policy_processed_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": {
"_type": "Set",
"elements": [
"821",
"2155"
]
},
"indirectly_referenced_by": null,
"indirectly_referencing": {
"_type": "Set",
"elements": [
"821",
"2155"
]
}
},
"policy_prunned_references": {
"_type": "Set",
"elements": [
"821",
"2155"
]
},
"related_cves": null,
"verified_cpe_matches": null
},
"pdf_data": {
"_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
"keywords": {
"asymmetric_crypto": {
"FF": {
"DSA": {
"DSA": 2
}
}
},
"certification_process": {},
"cipher_mode": {
"CBC": {
"CBC": 4
},
"CCM": {
"CCM": 3
},
"CTR": {
"CTR": 4
},
"ECB": {
"ECB": 4
},
"GCM": {
"GCM": 3
},
"XTS": {
"XTS": 9
}
},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {
"NSS": {
"NSS": 15
}
},
"crypto_protocol": {
"IPsec": {
"IPsec": 7
},
"VPN": {
"VPN": 4
}
},
"crypto_scheme": {
"MAC": {
"MAC": 1
}
},
"device_model": {},
"ecc_curve": {},
"eval_facility": {},
"fips_cert_id": {
"Cert": {
"# 2155": 2,
"#1681": 1,
"#821": 1
}
},
"fips_certlike": {
"Certlike": {
"AES 128": 2,
"AES GCM15": 1,
"AES key 128, 192": 1,
"AES3": 1,
"DSA 1024": 1,
"HMAC SHA-1": 1,
"HMAC SHA-384": 1,
"HMAC SHA-512": 13,
"HMAC6": 2,
"SHA-1": 5,
"SHA-224": 4,
"SHA-256": 4,
"SHA-384": 2,
"SHA-512": 14,
"SHA-512 (Cert #1681": 1,
"SHA5": 1,
"SHS22": 1
}
},
"fips_security_level": {
"Level": {
"Level 1": 4,
"Level 9": 1
}
},
"hash_function": {
"SHA": {
"SHA1": {
"SHA-1": 5
},
"SHA2": {
"SHA-224": 4,
"SHA-256": 4,
"SHA-384": 2,
"SHA-512": 15
}
}
},
"ic_data_group": {},
"javacard_api_const": {},
"javacard_packages": {},
"javacard_version": {},
"os_name": {},
"pq_crypto": {},
"randomness": {
"PRNG": {
"PRNG": 8
},
"RNG": {
"RNG": 3
}
},
"side_channel_analysis": {},
"standard_id": {
"FIPS": {
"FIPS 140-2": 19
},
"NIST": {
"SP 800-131A": 1
}
},
"symmetric_crypto": {
"AES_competition": {
"AES": {
"AES": 27
}
},
"DES": {
"3DES": {
"Triple-DES": 11
},
"DES": {
"DES": 4
}
},
"constructions": {
"MAC": {
"CBC-MAC": 2,
"HMAC": 23
}
}
},
"tee_name": {},
"tls_cipher_suite": {},
"vendor": {},
"vulnerability": {}
},
"policy_metadata": {
"/Author": "jschultz",
"/CreationDate": "D:20140521123408-04\u002700\u0027",
"/Creator": "PDFCreator Version 1.7.2",
"/Keywords": "",
"/ModDate": "D:20140521123408-04\u002700\u0027",
"/Producer": "GPL Ghostscript 9.10",
"/Subject": "",
"/Title": "1B - VMware Kernel Crypto Module FIPS 140-2 Security Policy",
"pdf_file_size_bytes": 1069533,
"pdf_hyperlinks": {
"_type": "Set",
"elements": []
},
"pdf_is_encrypted": false,
"pdf_number_of_pages": 21
}
},
"state": {
"_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
"module_download_ok": true,
"module_extract_ok": true,
"policy_convert_garbage": false,
"policy_convert_ok": true,
"policy_download_ok": true,
"policy_extract_ok": true,
"policy_pdf_hash": "5230d52e65448d7d83fa6632dc64a55592672f18b4a1e988c9ec5df77fcc9dd2",
"policy_txt_hash": "fbc7b3ce64545f2428c216a2bebe5f679fdcbb94f96fbc3a4ebe5332a0e36e55"
},
"web_data": {
"_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
"caveat": "When installed, initialized and configured as specified in the Security Policy Section 3 and operated in FIPS mode with VMware NSS Cryptographic Module validated to FIPS 140-2 under Cert. #2155 operating in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy. No assurance of the minimum strength of generated keys",
"certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/FIPS140ConsolidatedCertList0042.pdf",
"date_sunset": null,
"description": "The VMware Kernel Cryptographic Module is a flexible software library providing FIPS-140-2 approved cryptographic operations for VMware products and platforms.",
"embodiment": "Multi-Chip Stand Alone",
"exceptions": [
"Physical Security: N/A",
"Mitigation of Other Attacks: N/A"
],
"fw_versions": null,
"historical_reason": "RNG SP800-131A Revision 1 Transition",
"hw_versions": null,
"level": 1,
"mentioned_certs": {
"2155": 1
},
"module_name": "VMware Kernel Cryptographic Module",
"module_type": "Software",
"revoked_link": null,
"revoked_reason": null,
"standard": "FIPS 140-2",
"status": "historical",
"sw_versions": "1.0",
"tested_conf": [
"VMware vCloud Networking and Security 5.5.0a Edge OS on VMware vSphere Hypervisor (ESXi) 5.5 running on HP ProLiant DL380e Gen8 Server with PAA",
"VMware vCloud Networking and Security 5.5.0a Edge OS on VMware vSphere Hypervisor (ESXi) 5.5 running on HP ProLiant DL380e Gen8 Server without PAA (single-user mode)"
],
"validation_history": [
{
"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
"date": "2014-06-20",
"lab": "CGI Information Systems \u0026 Management Consultants Inc",
"validation_type": "Initial"
}
],
"vendor": "VMware, Inc.",
"vendor_url": "http://www.vmware.com"
}
}