Cloudera Cryptographic Module for Libgcrypt

Certificate #4148

Webpage information

Status historical
Historical reason Moved to historical list due to sunsetting
Validation dates 09.02.2022
Standard FIPS 140-2
Security level 1
Type Software
Embodiment Multi-Chip Stand Alone
Caveat When installed and configured per Security Policy section 3.1 and operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy. This validation entry is a non-security-relevant modification to Cert. #3604
Exceptions
  • Physical Security: N/A
  • Design Assurance: Level 3
Description The Cloudera Cryptographic Module for Libgcrypt is a general purpose FIPS 140-2 Validated Cryptographic library for use with Cloudera Data Platform (CDP) products.
Tested configurations
  • Oracle Linux 7.6 64 bit running on an Oracle Server X7-2 with an Intel(R) Xeon(R) Silver 4114
  • Oracle Linux 7.6 64 bit running on an Oracle X7-2 Server with an AMD(R) EPYC(R) 7551 (single-user mode)
Vendor Cloudera, Inc.
References

This certificate's webpage directly references 1 certificates, transitively this expands into 1 certificates.

Security policy

Symmetric Algorithms
AES, Twofish, Serpent, CAST5, RC2, DES, Triple-DES, TDES, TDEA, IDEA, Blowfish, Camellia, SEED, HMAC, HMAC-SHA-224, HMAC-SHA-384, HMAC-SHA-256, HMAC-SHA-512, CMAC
Asymmetric Algorithms
DSA
Hash functions
SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, MD4, MD5, RIPEMD
Schemes
MAC
Randomness
DRBG, RNG
Libraries
libgcrypt
Block cipher modes
ECB, CBC, CTR, CFB, OFB, GCM

Security level
Level 1
Side-channel analysis
timing attacks

Standards
FIPS 140-2, FIPS 140, FIPS 197, FIPS 186-4, FIPS 198-1, FIPS 180-4, FIPS186-4, FIPS PUB 140-2, SP 800-38A, SP 800-133, SP 800-90A, SP 800-67, SP 800-56B, SP 800-89, PKCS #1, PKCS1, PKCS#1, RFC 4880, RFC 2268

File metadata

Title Security Policy
Subject Cloudera Cryptographic Module for Libgcrypt
Author SafeLogic
Creation date D:20220131122618-08'00'
Modification date D:20220131122618-08'00'
Pages 30
Creator Microsoft® Word for Microsoft 365
Producer Microsoft® Word for Microsoft 365

Heuristics

No heuristics are available for this certificate.

References

Loading...

Updates Feed

  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 4148,
  "dgst": "2a3b858f52f76826",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "DRBG#C709",
        "DSA#C709",
        "RSA#C709",
        "AES#C709",
        "HMAC#C709",
        "SHS#C709",
        "Triple-DES#C709"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "-"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": {
        "_type": "Set",
        "elements": [
          "3604"
        ]
      },
      "indirectly_referenced_by": null,
      "indirectly_referencing": {
        "_type": "Set",
        "elements": [
          "3604"
        ]
      }
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": [
        "3604"
      ]
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "FF": {
          "DSA": {
            "DSA": 11
          }
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 4
        },
        "CFB": {
          "CFB": 1
        },
        "CTR": {
          "CTR": 5
        },
        "ECB": {
          "ECB": 3
        },
        "GCM": {
          "GCM": 1
        },
        "OFB": {
          "OFB": 3
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {
        "libgcrypt": {
          "libgcrypt": 2
        }
      },
      "crypto_protocol": {},
      "crypto_scheme": {
        "MAC": {
          "MAC": 1
        }
      },
      "device_model": {},
      "ecc_curve": {},
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "#1": 3
        }
      },
      "fips_certlike": {
        "Certlike": {
          "AES (128": 1,
          "AES 128/192/256": 1,
          "HMAC-SHA-1": 4,
          "HMAC-SHA-224": 2,
          "HMAC-SHA-256": 8,
          "HMAC-SHA-384": 2,
          "HMAC-SHA-512": 4,
          "PKCS #1": 6,
          "PKCS#1": 2,
          "PKCS1": 2,
          "SHA-1": 5,
          "SHA-224": 5,
          "SHA-256": 9,
          "SHA-384": 3,
          "SHA-512": 4
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 3
        }
      },
      "hash_function": {
        "MD": {
          "MD4": {
            "MD4": 1
          },
          "MD5": {
            "MD5": 3
          }
        },
        "RIPEMD": {
          "RIPEMD": 2
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 5
          },
          "SHA2": {
            "SHA-224": 6,
            "SHA-256": 8,
            "SHA-384": 4,
            "SHA-512": 3
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 23
        },
        "RNG": {
          "RNG": 1
        }
      },
      "side_channel_analysis": {
        "SCA": {
          "timing attacks": 1
        }
      },
      "standard_id": {
        "FIPS": {
          "FIPS 140": 6,
          "FIPS 140-2": 17,
          "FIPS 180-4": 2,
          "FIPS 186-4": 3,
          "FIPS 197": 2,
          "FIPS 198-1": 2,
          "FIPS PUB 140-2": 1,
          "FIPS186-4": 1
        },
        "NIST": {
          "SP 800-133": 2,
          "SP 800-38A": 2,
          "SP 800-56B": 1,
          "SP 800-67": 2,
          "SP 800-89": 1,
          "SP 800-90A": 10
        },
        "PKCS": {
          "PKCS #1": 3,
          "PKCS#1": 1,
          "PKCS1": 1
        },
        "RFC": {
          "RFC 2268": 1,
          "RFC 4880": 2
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 7
          },
          "CAST": {
            "CAST5": 1
          },
          "RC": {
            "RC2": 1
          },
          "Serpent": {
            "Serpent": 1
          },
          "Twofish": {
            "Twofish": 1
          }
        },
        "DES": {
          "3DES": {
            "TDEA": 5,
            "TDES": 2,
            "Triple-DES": 15
          },
          "DES": {
            "DES": 3
          }
        },
        "constructions": {
          "MAC": {
            "CMAC": 1,
            "HMAC": 14,
            "HMAC-SHA-224": 2,
            "HMAC-SHA-256": 3,
            "HMAC-SHA-384": 2,
            "HMAC-SHA-512": 1
          }
        },
        "miscellaneous": {
          "Blowfish": {
            "Blowfish": 1
          },
          "Camellia": {
            "Camellia": 1
          },
          "IDEA": {
            "IDEA": 1
          },
          "SEED": {
            "SEED": 1
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "SafeLogic",
      "/CreationDate": "D:20220131122618-08\u002700\u0027",
      "/Creator": "Microsoft\u00ae Word for Microsoft 365",
      "/ModDate": "D:20220131122618-08\u002700\u0027",
      "/Producer": "Microsoft\u00ae Word for Microsoft 365",
      "/Subject": "Cloudera Cryptographic Module for Libgcrypt",
      "/Title": "Security Policy",
      "pdf_file_size_bytes": 624221,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "www.cloudera.com/products/cloudera-data-platform",
          "http://www.safelogic.com/",
          "https://csrc.nist.gov/projects/cryptographic-module-validation-program",
          "http://www.cloudera.com/"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 30
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
    "module_download_ok": true,
    "module_extract_ok": true,
    "policy_convert_ok": true,
    "policy_download_ok": true,
    "policy_extract_ok": true,
    "policy_json_hash": null,
    "policy_pdf_hash": "bf6ac271d3193649b89133ff69a244e0ab6afb9f425ab0ee37fd2d769c11fb28",
    "policy_txt_hash": "e380b9666bd02ac4459bd92f0eb477ad03122eef04d77620c2775749128f56c7"
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When installed and configured per Security Policy section 3.1 and operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy. This validation entry is a non-security-relevant modification to Cert. #3604",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/February 2022_010322_0121_Signed.pdf",
    "date_sunset": null,
    "description": "The Cloudera Cryptographic Module for Libgcrypt is a general purpose FIPS 140-2 Validated Cryptographic library for use with Cloudera Data Platform (CDP) products.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Physical Security: N/A",
      "Design Assurance: Level 3"
    ],
    "fw_versions": null,
    "historical_reason": "Moved to historical list due to sunsetting",
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {
      "3604": 1
    },
    "module_name": "Cloudera Cryptographic Module for Libgcrypt",
    "module_type": "Software",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-2",
    "status": "historical",
    "sw_versions": "5.0",
    "tested_conf": [
      "Oracle Linux 7.6 64 bit running on an Oracle Server X7-2 with an Intel(R) Xeon(R) Silver 4114",
      "Oracle Linux 7.6 64 bit running on an Oracle X7-2 Server with an AMD(R) EPYC(R) 7551 (single-user mode)"
    ],
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2022-02-09",
        "lab": "Leidos Accredited Testing \u0026 Evaluation (AT\u0026E) Lab",
        "validation_type": "Initial"
      }
    ],
    "vendor": "Cloudera, Inc.",
    "vendor_url": "http://www.cloudera.com/"
  }
}