Cloud Software Group NetScaler MPX Hardware Models: 8900 FIPS, 9100 FIPS, 15000-50G FIPS Firmware Version: 13.1.FIPS FIPS 140-3 Non-Proprietary Security Policy FIPS Security Level: 2 Document Version: 0.2 Prepared for: Prepared by: Cloud Software Group Corsec Security, Inc. 851 Cypress Creek Road 12600 Fair Lakes Circle, Suite 210 Fort Lauderdale, FL 33309 Fairfax, VA 22033 United States of America United States of America Phone: +1 954 267 3000 Phone: +1 703 267 6050 www.cloud.com www.corsec.com FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 2 of 87 Abstract This is a non-proprietary Cryptographic Module Security Policy for the NetScaler MPX (version: 13.1.FIPS) from Cloud Software Group (Cloud Software Group). This Security Policy describes how the NetScaler MPX meets the security requirements of Federal Information Processing Standards (FIPS) Publication 140-3, which details the U.S. and Canadian government requirements for cryptographic modules. More information about the FIPS 140-3 standard and validation program is available on the National Institute of Standards and Technology (NIST) and the Canadian Centre for Cyber Security (CCCS) Cryptographic Module Validation Program (CMVP) website at http://csrc.nist.gov/groups/STM/cmvp. This document also describes how to run the module in an Approved mode of operation. This policy was prepared as part of the Level 2 FIPS 140-3 validation of the module. The NetScaler MPX is referred to in this document as NetScaler MPX or the module. References This document deals only with operations and capabilities of the module in the technical terms of a FIPS 140-3 cryptographic module security policy. More information is available on the module from the following sources: • The Cloud Software Group website www.cloud.com contains information on the full line of services and solutions from Cloud Software Group. • The search page on the CMVP website (https://csrc.nist.gov/Projects/cryptographic-module-validation- program/Validated-Modules/Search) can be used to locate and obtain vendor contact information for technical or sales-related questions about the module. Document Organization ISO/IEC 19790 Annex B uses the same section naming convention as ISO/IEC 19790 section 7 - Security requirements. For example, Annex B section B.2.1 is named “General” and B.2.2 is named “Cryptographic module specification,” which is the same as ISO/IEC 19790 section 7.1 and section 7.2, respectively. Therefore, the format of this Security Policy is presented in the same order as indicated in Annex B, starting with “General” and ending with “Mitigation of other attacks.” If sections are not applicable, they have been marked as such in this document. FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 3 of 87 Table of Contents 1. General..................................................................................................................................................6 1.1 Overview.................................................................................................................................................6 1.2 Security Levels.........................................................................................................................................7 2. Cryptographic Module Specification .......................................................................................................9 2.1 Description..............................................................................................................................................9 2.2 Tested and Vendor Affirmed Module Version and Identification ....................................................... 10 2.3 Excluded Components ......................................................................................................................... 11 2.4 Modes of Operation............................................................................................................................. 11 2.5 Algorithms............................................................................................................................................ 11 2.6 Security Function Implementations..................................................................................................... 18 2.7 Algorithm Specific Information............................................................................................................ 25 2.8 RNG and Entropy ................................................................................................................................. 25 2.9 Key Generation .................................................................................................................................... 26 2.10 Key Establishment................................................................................................................................ 26 2.11 Industry Protocols................................................................................................................................ 26 3. Cryptographic Module Interfaces .........................................................................................................28 3.1 Ports and Interfaces............................................................................................................................. 28 4. Roles, Services, and Authentication......................................................................................................32 4.1 Authentication Methods...................................................................................................................... 32 4.2 Roles..................................................................................................................................................... 33 4.3 Approved Services ............................................................................................................................... 33 4.4 Non-Approved Services ....................................................................................................................... 46 4.5 External Software/Firmware Loaded................................................................................................... 46 5. Software/Firmware Security ................................................................................................................47 5.1 Integrity Techniques ............................................................................................................................ 47 5.2 Initiate on Demand .............................................................................................................................. 47 6. Operational Environment.....................................................................................................................48 6.1 Operational Environment Type and Requirements............................................................................. 48 7. Physical Security ..................................................................................................................................49 7.1 Mechanisms and Actions Required ..................................................................................................... 49 8. Non-Invasive Security ..........................................................................................................................53 9. Sensitive Security Parameters Management.........................................................................................54 9.1 Storage Areas....................................................................................................................................... 54 9.2 SSP Input-Output Methods.................................................................................................................. 54 9.3 SSP Zeroization Methods..................................................................................................................... 54 9.4 SSPs...................................................................................................................................................... 55 9.5 Transitions............................................................................................................................................ 68 10. Self-Tests.............................................................................................................................................69 10.1 Pre-Operational Self-Tests................................................................................................................... 69 FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 4 of 87 10.2 Conditional Self-Tests .......................................................................................................................... 69 10.3 Periodic Self-Test Information............................................................................................................. 74 10.4 Error States .......................................................................................................................................... 76 11. Life-Cycle Assurance.............................................................................................................................78 11.1 Installation, Initialization, and Startup Procedures ............................................................................. 78 11.2 Administrator Guidance....................................................................................................................... 81 11.3 Non-Administrator Guidance............................................................................................................... 83 12. Mitigation of Other Attacks..................................................................................................................84 Appendix A. Acronyms and Abbreviations ....................................................................................................85 List of Tables Table 1: Security Levels ..............................................................................................................................................8 Table 2: Tested Module Identification – Hardware................................................................................................. 10 Table 3: Modes List and Description ....................................................................................................................... 11 Table 4: Approved Algorithms - Control Plane........................................................................................................ 13 Table 5: Approved Algorithms - Data Plane ............................................................................................................ 16 Table 6: Approved Algorithms - Hardware.............................................................................................................. 17 Table 7: Approved Algorithms - CPU Jitter Entropy Source .................................................................................... 17 Table 8: Vendor-Affirmed Algorithms ..................................................................................................................... 17 Table 9: Non-Approved, Allowed Algorithms with No Security Claimed................................................................ 18 Table 10: Security Function Implementations......................................................................................................... 25 Table 11: Entropy Certificates ................................................................................................................................. 26 Table 12: Entropy Sources....................................................................................................................................... 26 Table 13: Ports and Interfaces................................................................................................................................. 31 Table 14: Authentication Methods.......................................................................................................................... 32 Table 15: Roles ........................................................................................................................................................ 33 Table 16: Approved Services ................................................................................................................................... 45 Table 17: Mechanisms and Actions Required ......................................................................................................... 52 Table 18: Storage Areas........................................................................................................................................... 54 Table 19: SSP Input-Output Methods...................................................................................................................... 54 Table 20: SSP Zeroization Methods......................................................................................................................... 55 Table 21: SSP Table 1............................................................................................................................................... 62 Table 22: SSP Table 2............................................................................................................................................... 68 Table 23: Pre-Operational Self-Tests....................................................................................................................... 69 Table 24: Conditional Self-Tests .............................................................................................................................. 74 Table 25: Pre-Operational Periodic Information..................................................................................................... 74 Table 26: Conditional Periodic Information ............................................................................................................ 76 Table 27: Error States.............................................................................................................................................. 77 Table 28. Acronyms and Abbreviations................................................................................................................... 85 FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 5 of 87 List of Figures Figure 1. Typical NetScaler MPX “Two-Arm” Topology..............................................................................................6 Figure 2. NetScaler MPS 8900 Appliance ...................................................................................................................9 Figure 3. NetScaler MPX 9100 Appliance................................................................................................................ 10 Figure 4. NetScaler MPX 15000-50G Appliance ...................................................................................................... 10 Figure 5. NetScaler MPS 8900 Front Panel.............................................................................................................. 28 Figure 6. NetScaler MPS 8900 Rear Panel............................................................................................................... 28 Figure 7. NetScaler MPX 9100 Front Panel ............................................................................................................. 29 Figure 8. NetScaler MPX 9100 Rear Panel............................................................................................................... 29 Figure 9. NetScaler MPX 15000-50G Front Panel.................................................................................................... 30 Figure 10. NetScaler MPX 15000-50G Rear Panel................................................................................................... 30 Figure 11. Front Panel of the NetScaler MPS 8900 ................................................................................................. 49 Figure 12. Back Panel of the NetScaler MPS 8900 .................................................................................................. 49 Figure 13. Left Side of the NetScaler MPS 8900...................................................................................................... 49 Figure 14. Right Side of the NetScaler MPS 8900.................................................................................................... 50 Figure 15. Front Panel of the NetScaler MPX 9100................................................................................................. 50 Figure 16. Back Panel of the NetScaler MPX 9100 .................................................................................................. 50 Figure 17. Left Side of the NetScaler MPX 9100...................................................................................................... 50 Figure 18. Right Side of the NetScaler MPX 9100 ................................................................................................... 51 Figure 19. Front Panel of the NetScaler MPX 15000-50G ....................................................................................... 51 Figure 20. Rear Panel of the NetScaler MPX 15000-50G ........................................................................................ 51 Figure 21. Left Side of the NetScaler MPX 15000-50G............................................................................................ 52 Figure 22. Right Side of the NetScaler MPX 15000-50G.......................................................................................... 52 FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 6 of 87 1. General 1.1 Overview The NetScaler product line optimizes delivery of applications over the Internet and private networks. It is an Application Delivery Controller (ADC) that performs application-specific traffic analysis to intelligently distribute, optimize, and secure L4-L71 network traffic for web-applications. All these capabilities are combined into a single, integrated appliance for increased productivity, with lower overall total cost of ownership. The NetScaler MPX is a hardware appliance consisting of a control plane processing function (providing all configuration and management processing functions) and multiple data planes which provide data packet processing functions. All configuration and management activities are performed at the workstation via the web- based GUI2 , REST3 ful Nitro API4 , and CLI5 interfaces. The GUI includes a configuration utility for configuring the appliance and a statistical utility called Dashboard. In a typical installation (see Figure 1 for an illustration of a typical “two-arm” topology), the NetScaler MPX is installed in the data center between the clients and the internal customer network so that client requests and server responses pass through it. Administrators enable appliance features and apply configured policies to incoming and outgoing traffic. Figure 1. Typical NetScaler MPX “Two-Arm” Topology 1 L4-L7 – Layer 4 – Layer 7 2 GUI – Graphical User Interface 3 REST – Representational State Transfer 4 API – Application Programming Interface 5 CLI – Command Line Interface FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 7 of 87 The internal customer network hosts all load-balancing and authentication services, such as LDAP6 , Kerberos, and SAML7 . The feature set can be broadly categorized as consisting of switching features, security and protection features, and server-farm optimization features: • Switching features – When deployed in front of application servers, the NetScaler ensures optimal distribution of traffic by the way in which it directs client requests. Administrators can segment application traffic according to information in the body of an HTTP8 or TCP9 request, and on the basis of L4–L7 header information such as URL10 , application data type, or cookie. Numerous load balancing algorithms and extensive server health checks improve application availability by ensuring that client requests are directed to the appropriate servers. • Security and protection features – NetScaler’s security and protection features protect web applications from Application Layer attacks. NetScaler allows legitimate client requests and can block malicious requests. It provides built-in defenses against denial-of-service (DoS) attacks and supports features that protect against legitimate surges in application traffic that would otherwise overwhelm the servers. An available built-in firewall protects web applications from Application Layer attacks, including buffer overflow exploits, SQL11 injection attempts, cross-site scripting attacks, and more. In addition, the firewall provides identity theft protection by securing confidential corporate information and sensitive customer data. • Optimization features – Optimization features offload resource-intensive operations, such as SSL 12 processing, data compression, client keep-alive, TCP buffering, and the caching of static and dynamic content from servers. This improves the performance of the servers in the server farm and therefore speeds up applications. NetScaler supports several transparent TCP optimizations, which mitigate problems caused by high latency and congested network links, accelerating the delivery of applications while requiring no configuration changes to clients or servers. These appliances employ a multi-core processor design and are available in a wide range of appliance configurations, from sub gigabit throughput to 50 Gbps13 . Each leverages a fully hardened and secure operating system. 1.2 Security Levels The NetScaler MPX is validated at the FIPS 140-3 section levels shown in the table below. Section Title Security Level 1 General 2 2 Cryptographic module specification 2 6 LDAP – Lightweight Directory Access Protocol 7 SAML – Security Assurance Markup Language 8 HTTP – Hypertext Transfer Protocol 9 TCP – Transmission Control Protocol 10 URL – Uniform Resource Locator 11 SQL – Structured Query Language 12 SSL – Secure Sockets Layer 13 Gbps – Gigabits per second FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 8 of 87 Section Title Security Level 3 Cryptographic module interfaces 2 4 Roles, services, and authentication 3 5 Software/Firmware security 2 6 Operational environment N/A 7 Physical security 2 8 Non-invasive security N/A 9 Sensitive security parameter management 2 10 Self-tests 2 11 Life-cycle assurance 2 12 Mitigation of other attacks N/A Overall Level 2 Table 1: Security Levels FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 9 of 87 2. Cryptographic Module Specification 2.1 Description 2.1.1 Purpose and Use The NetScaler product line optimizes delivery of applications over the Internet and private networks. It is an Application Delivery Controller (ADC) that performs application-specific traffic analysis to intelligently distribute, optimize, and secure L4-L7 network traffic for web-applications. All these capabilities are combined into a single, integrated appliance for increased productivity, with lower overall total cost of ownership. The NetScaler MPX is a hardware appliance consisting of a control plane processing function (providing all configuration and management processing functions) and multiple data planes which provide data packet processing functions. All configuration and management activities are performed at the workstation via the web- based GUI, RESTful Nitro API, and CLI interfaces. 2.1.2 Module Type The NetScaler MPX 13.1.FIPS is a Hardware module. 2.1.3 Module Embodiment The NetScaler MPX has a Multi-Chip Standalone embodiment. 2.1.4 Module Characteristics The module does not have any additional characteristics. 2.1.5 Cryptographic Boundary The module’s cryptographic boundary is defined by its hard enclosure (shown in Figure 2, Figure 3, and Figure 4 below). This includes all ports, physical interfaces, and removable covers. Figure 2. NetScaler MPS 8900 Appliance FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 10 of 87 Figure 3. NetScaler MPX 9100 Appliance Figure 4. NetScaler MPX 15000-50G Appliance 2.2 Tested and Vendor Affirmed Module Version and Identification 2.2.1 Tested Module Identification – Hardware The module was tested and found to be compliant with FIPS 140-3 requirements using the hardware versions listed in the table below. Model and/or Part Number Hardware Version Firmware Version Processors Features NetScaler MPX 8900 8900 FIPS 13.1.FIPS Intel® Xeon® E5-2620 v4 (Broadwell) 5Gbps L4/L7 throughput NetScaler MPX 9100 9100 FIPS 13.1.FIPS Intel® Xeon® Silver 4310T (Ice Lake) 20Gbps L4/L7 throughput NetScaler MPX 15000-50G 15000-50G FIPS 13.1.FIPS Intel® Xeon® E5-2620 v4 (Broadwell) 30Gbps L4/L7 throughput Table 2: Tested Module Identification – Hardware 2.2.2 Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets) Not applicable. The module is a hardware module. 2.2.3 Tested Module Identification – Hybrid Disjoint Hardware Not applicable. The module is a hardware module. 2.2.4 Tested Module Identification – Software, Firmware, Hybrid Not applicable. The module is a hardware module. FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 11 of 87 2.2.5 Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid Not applicable. The module is a hardware module. 2.3 Excluded Components The module does not exclude any components from the requirements. 2.4 Modes of Operation 2.4.1 Modes List and Description The module supports the modes of operation listed in the table below. Mode Name Description Type Status Indicator Approved When installed, initiated, and operated according to Section 11.1 of the Security Policy, the Approved mode is the only supported mode of operation of the module. Approved Global Indicator Table 3: Modes List and Description 2.5 Algorithms 2.5.1 Approved Algorithms The module includes the following cryptographic libraries that provide basic cryptographic functionalities and support secure networking protocols. • NetScaler Control Plane Cryptographic Library v1.0 (Cert. A3942) • NetScaler Data Plane Cryptographic Library v1.0 (Cert. A3943) • NetScaler CPU Jitter Entropy Source v3.4.0 (Cert. A3513) • Intel Hardware Cryptographic Accelerator version 1.0 (Cert. A3944) Control Plane Algorithm CAVP Cert Properties Reference AES-CBC A3942 Direction - Decrypt, Encrypt Key Length - 128, 192, 256 SP 800-38A AES-CFB128 A3942 Direction - Decrypt, Encrypt Key Length - 128 SP 800-38A AES-CTR A3942 Direction - Encrypt Key Length - 128, 192, 256 Payload Length - Payload Length: 128 Supports Counter larger than maximum value - Yes Incremental Counter - Yes Counter Tests Performed - Yes SP 800-38A FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 12 of 87 Algorithm CAVP Cert Properties Reference AES-GCM A3942 Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 256 Tag Length - 104, 112, 120, 128, 32, 64, 96 IV Length - IV Length: 96, 128 Payload Length - Payload Length: 504, 512, 1016, 1024 AAD Length - AAD Length: 0, 504, 512, 1016, 1024 SP 800-38D Counter DRBG A3942 Prediction Resistance - No, Yes Supports Reseed - Yes Mode - AES-256 Derivation Function Enabled - No, Yes Additional Input - Additional Input: 0-256 Increment 8, Additional Input: 0-384 Increment 8 Entropy Input - Entropy Input: 256, Entropy Input: 384 Nonce - Nonce: 0, Nonce: 128 Personalization String Length - Personalization String Length: 0-256 Increment 8, Personalization String Length: 0-384 Increment 8 Returned Bits - 512 SP 800-90A Rev. 1 ECDSA KeyGen (FIPS186-4) A3942 Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - Extra Bits, Testing Candidates FIPS 186-4 ECDSA KeyVer (FIPS186-4) A3942 Curve - P-224, P-256, P-384, P-521 FIPS 186-4 ECDSA SigGen (FIPS186-4) A3942 Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512 FIPS 186-4 ECDSA SigVer (FIPS186-4) A3942 Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA-1, SHA2-256, SHA2-384, SHA2-512 FIPS 186-4 HMAC-SHA-1 A3942 MAC - MAC: 80, 96, 128, 160 Key Length - Key Length: 8-512 Increment 8 FIPS 198-1 HMAC-SHA2- 256 A3942 MAC - MAC: 128, 192, 256 Key Length - Key Length: 8-512 Increment 8 FIPS 198-1 HMAC-SHA2- 384 A3942 MAC - MAC: 192, 256, 320, 384 Key Length - Key Length: 8-512 Increment 8 FIPS 198-1 HMAC-SHA2- 512 A3942 MAC - MAC: 256, 320, 384, 448, 512 Key Length - Key Length: 8-512 Increment 8 FIPS 198-1 KAS-ECC-SSC Sp800-56Ar3 A3942 Domain Parameter Generation Methods - P-224, P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responder SP 800-56A Rev. 3 KAS-FFC-SSC Sp800-56Ar3 A3942 Domain Parameter Generation Methods - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, MODP-2048, MODP-3072, MODP-4096, MODP-6144 Scheme - dhEphem - KAS Role - initiator, responder SP 800-56A Rev. 3 KDF IKEv1 (CVL) A3942 Authentication Method - Pre-shared Key Initiator Nonce Length - Initiator Nonce Length: 128 Responder Nonce Length - Responder Nonce Length: 128 Preshared Key Length - Preshared Key Length: 64-504 Increment 8 Diffie-Hellman Shared Secret Length - Diffie-Hellman Shared Secret Length: 2048 Hash Algorithm - SHA-1, SHA2-256, SHA2-384, SHA2-512 SP 800-135 Rev. 1 KDF IKEv2 (CVL) A3942 Initiator Nonce Length - Initiator Nonce Length: 256 Responder Nonce Length - Responder Nonce Length: 256 Diffie-Hellman Shared Secret Length - Diffie-Hellman Shared Secret Length: 2048 Derived Keying Material Length - Derived Keying Material Length: 1056-3072 Increment 8 Hash Algorithm - SHA-1, SHA2-256, SHA2-384, SHA2-512 SP 800-135 Rev. 1 FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 13 of 87 Algorithm CAVP Cert Properties Reference KDF SNMP (CVL) A3942 Password Length - Password Length: 64-248 Increment 8 Engine ID - 800002b805123456789abcdef0123456789abcdef0123456789abcdef0123456, 80000b3f0300106b02fe55 SP 800-135 Rev. 1 KDF SSH (CVL) A3942 Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-256, SHA2-384, SHA2-512 SP 800-135 Rev. 1 KDF TLS (CVL) A3942 TLS Version - v1.0/1.1, v1.2 Hash Algorithm - SHA2-256, SHA2-384 SP 800-135 Rev. 1 KTS-IFC A3942 Function - keyPairGen, partialVal IUT ID - CAFECAFE Modulo - 2048 Key Generation Methods - rsakpg1-basic Fixed Public Exponent - 010001 Scheme - KTS-OAEP-basic - KAS Role - initiator, responder Key Transport Method - Hash Algorithms - SHA-1 Supports Null Associated Data - Yes Associated Data Pattern - Associated Data Encoding - concatenation Key Length - 384 SP 800-56B Rev. 2 PBKDF A3942 Iteration Count - Iteration Count: 10-10000 Increment 1 HMAC Algorithm - SHA-1 Password Length - Password Length: 8-128 Increment 1 Salt Length - Salt Length: 128-4096 Increment 8 Key Data Length - Key Data Length: 112-4096 Increment 8 SP 800-132 RSA KeyGen (FIPS186-4) A3942 Key Generation Mode - B.3.3 Modulo - 2048, 3072 Primality Tests - Table C.2 Info Generated By Server - No Public Exponent Mode - Fixed Fixed Public Exponent - 010001 Private Key Format - Standard FIPS 186-4 RSA SigGen (FIPS186-4) A3942 Signature Type - PKCS 1.5 Modulo - 2048, 3072 Hash Pair - Hash Algorithm - SHA2-256 FIPS 186-4 RSA SigVer (FIPS186-4) A3942 Signature Type - PKCS 1.5 Modulo - 2048, 3072 Hash Pair - Hash Algorithm - SHA2-256 Public Exponent Mode - Fixed Fixed Public Exponent - 010001 FIPS 186-4 Safe Primes Key Generation A3942 Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, MODP-2048, MODP- 3072, MODP-4096, MODP-6144 SP 800-56A Rev. 3 Safe Primes Key Verification A3942 Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, MODP-2048, MODP- 3072, MODP-4096, MODP-6144 SP 800-56A Rev. 3 SHA-1 A3942 Message Length - Message Length: 8-51200 Increment 8 FIPS 180-4 SHA2-256 A3942 Message Length - Message Length: 8-51200 Increment 8 FIPS 180-4 SHA2-384 A3942 Message Length - Message Length: 8-65536 Increment 8 FIPS 180-4 SHA2-512 A3942 Message Length - Message Length: 8-65536 Increment 8 FIPS 180-4 TLS v1.2 KDF RFC7627 (CVL) A3942 Hash Algorithm - SHA2-256, SHA2-384 SP 800-135 Rev. 1 Table 4: Approved Algorithms - Control Plane FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 14 of 87 Data Plane Algorithm CAVP Cert Properties Reference AES-CBC A3943 Direction - Decrypt, Encrypt Key Length - 128, 192, 256 SP 800-38A AES-GCM A3943 Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 256 Tag Length - 104, 112, 120, 128, 32, 64, 96 IV Length - IV Length: 96, 128 Payload Length - Payload Length: 504, 512, 1016, 1024 AAD Length - AAD Length: 0, 504, 512, 1016, 1024 SP 800-38D ECDSA KeyGen (FIPS186-4) A3943 Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - Testing Candidates FIPS 186-4 ECDSA KeyGen (FIPS186-5) A3943 Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - testing candidates FIPS 186-5 ECDSA KeyVer (FIPS186- 4) A3943 Curve - P-224, P-256, P-384, P-521 FIPS 186-4 ECDSA KeyVer (FIPS186- 5) A3943 Curve - P-224, P-256, P-384, P-521 FIPS 186-5 ECDSA SigGen (FIPS186- 4) A3943 Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512 FIPS 186-4 ECDSA SigGen (FIPS186- 5) A3943 Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512 FIPS 186-5 ECDSA SigVer (FIPS186- 4) A3943 Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512 FIPS 186-4 ECDSA SigVer (FIPS186- 5) A3943 Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512 FIPS 186-5 Hash DRBG A3943 Prediction Resistance - No, Yes Supports Reseed - Yes Mode - SHA2-256 Entropy Input - Entropy Input: 256 Nonce - Nonce: 128 Personalization String Length - Personalization String Length: 0-256 Increment 8 Additional Input - Additional Input: 0-256 Increment 8 Returned Bits - 1024 SP 800-90A Rev. 1 HMAC-SHA-1 A3943 MAC - MAC: 80, 96, 128, 160 Key Length - Key Length: 8-512 Increment 8 FIPS 198-1 HMAC-SHA2-224 A3943 MAC - MAC: 112, 128, 160, 192, 224 Key Length - Key Length: 8-512 Increment 8 FIPS 198-1 HMAC-SHA2-256 A3943 MAC - MAC: 128, 192, 256 Key Length - Key Length: 8-512 Increment 8 FIPS 198-1 HMAC-SHA2-384 A3943 MAC - MAC: 192, 256, 320, 384 Key Length - Key Length: 8-512 Increment 8 FIPS 198-1 HMAC-SHA2-512 A3943 MAC - MAC: 256, 320, 384, 448, 512 Key Length - Key Length: 8-512 Increment 8 FIPS 198-1 KAS-ECC-SSC Sp800- 56Ar3 A3943 Domain Parameter Generation Methods - P-224, P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responder SP 800-56A Rev. 3 FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 15 of 87 Algorithm CAVP Cert Properties Reference KDF SP800-108 A3943 KDF Mode - Counter MAC Mode - HMAC-SHA2-256 Supported Lengths - Supported Lengths: 8-4096 Increment 8 Fixed Data Order - Before Fixed Data Counter Length - 32 Supports Empty IV - Yes Requires Empty IV - No Custom Key In Length - 0 SP 800-108 Rev. 1 KDF TLS (CVL) A3943 TLS Version - v1.0/1.1, v1.2 Hash Algorithm - SHA2-256, SHA2-384 SP 800-135 Rev. 1 KTS-IFC A3943 Function - keyPairGen, partialVal IUT ID - CAFECAFE Modulo - 4096 Key Generation Methods - rsakpg1-basic Fixed Public Exponent - 010001 Scheme - KTS-OAEP-basic - KAS Role - initiator, responder Key Transport Method - Hash Algorithms - SHA-1 Supports Null Associated Data - Yes Associated Data Pattern - Associated Data Encoding - concatenation Key Length - 384 SP 800-56B Rev. 2 RSA SigGen (FIPS186-4) A3943 Signature Type - PKCS 1.5 Modulo - 2048, 3072, 4096 Hash Pair - Hash Algorithm - SHA2-224 FIPS 186-4 RSA SigGen (FIPS186-5) A3943 Hash Pair - Hash Algorithm - SHA2-224 Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5 FIPS 186-5 RSA SigVer (FIPS186-2) A3943 Public Exponent Mode - Random Signature Type - PKCS 1.5 Modulo - 4096 Hash Pair - Hash Algorithm - SHA2-224 FIPS 186-4 RSA SigVer (FIPS186-4) A3943 Signature Type - PKCS 1.5 Modulo - 1024, 2048, 3072, 4096 Hash Pair - Hash Algorithm - SHA2-224 Public Exponent Mode - Fixed Fixed Public Exponent - 010001 FIPS 186-4 RSA SigVer (FIPS186-5) A3943 Hash Pair - Hash Algorithm - SHA2-224 Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5 Fixed Public Exponent - 010001 Public Exponent Mode - fixed FIPS 186-5 SHA-1 A3943 Message Length - Message Length: 8-51200 Increment 8 FIPS 180-4 SHA2-224 A3943 Message Length - Message Length: 8-51200 Increment 8 FIPS 180-4 SHA2-256 A3943 Message Length - Message Length: 8-51200 Increment 8 FIPS 180-4 SHA2-384 A3943 Message Length - Message Length: 8-65536 Increment 8 FIPS 180-4 SHA2-512 A3943 Message Length - Message Length: 8-65536 Increment 8 FIPS 180-4 TLS v1.2 KDF RFC7627 (CVL) A3943 Hash Algorithm - SHA2-256, SHA2-384 SP 800-135 Rev. 1 FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 16 of 87 Algorithm CAVP Cert Properties Reference TLS v1.3 KDF (CVL) A3943 HMAC Algorithm - SHA2-256, SHA2-384 KDF Running Modes - DHE, PSK, PSK-DHE SP 800-135 Rev. 1 Table 5: Approved Algorithms - Data Plane Hardware Algorithm CAVP Cert Properties Reference AES-CBC A3944 Direction - Decrypt, Encrypt Key Length - 128, 192, 256 SP 800-38A AES-GCM A3944 Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 256 Tag Length - 104, 112, 120, 128, 32, 64, 96 IV Length - IV Length: 96 Payload Length - Payload Length: 504, 512, 1016, 1024 AAD Length - AAD Length: 504, 512, 1016, 1024 SP 800-38D ECDSA KeyGen (FIPS186- 4) A3944 Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - Testing Candidates FIPS 186-4 ECDSA KeyGen (FIPS186- 5) A3944 Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - testing candidates FIPS 186-5 ECDSA KeyVer (FIPS186-4) A3944 Curve - P-224, P-256, P-384, P-521 FIPS 186-4 ECDSA KeyVer (FIPS186-5) A3944 Curve - P-224, P-256, P-384, P-521 FIPS 186-5 ECDSA SigGen (FIPS186-4) A3944 Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512 FIPS 186-4 ECDSA SigGen (FIPS186-5) A3944 Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512 FIPS 186-5 ECDSA SigVer (FIPS186-4) A3944 Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2- 512 FIPS 186-4 ECDSA SigVer (FIPS186-5) A3944 Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512 FIPS 186-5 HMAC-SHA-1 A3944 MAC - MAC: 80, 96, 128, 160 Key Length - Key Length: 8-512 Increment 8 FIPS 198-1 HMAC-SHA2-224 A3944 MAC - MAC: 112, 128, 160, 192, 224 Key Length - Key Length: 8-512 Increment 8 FIPS 198-1 HMAC-SHA2-256 A3944 MAC - MAC: 128, 192, 256 Key Length - Key Length: 8-512 Increment 8 FIPS 198-1 HMAC-SHA2-384 A3944 MAC - MAC: 192, 256, 320, 384 Key Length - Key Length: 8-512 Increment 8 FIPS 198-1 HMAC-SHA2-512 A3944 MAC - MAC: 256, 320, 384, 448, 512 Key Length - Key Length: 8-512 Increment 8 FIPS 198-1 KAS-ECC-SSC Sp800-56Ar3 A3944 Domain Parameter Generation Methods - P-224, P-256, P-384, P- 521 Scheme - ephemeralUnified - KAS Role - initiator, responder SP 800-56A Rev. 3 KDF TLS (CVL) A3944 TLS Version - v1.0/1.1, v1.2 Hash Algorithm - SHA2-256, SHA2-384 SP 800-135 Rev. 1 RSA SigGen (FIPS186-4) A3944 Signature Type - PKCS 1.5 Modulo - 2048, 3072, 4096 Hash Pair - Hash Algorithm - SHA2-224 FIPS 186-4 RSA SigGen (FIPS186-5) A3944 Hash Pair - Hash Algorithm - SHA2-224 Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5 FIPS 186-5 FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 17 of 87 Algorithm CAVP Cert Properties Reference RSA SigVer (FIPS186-4) A3944 Signature Type - PKCS 1.5 Modulo - 1024, 2048, 3072, 4096 Hash Pair - Hash Algorithm - SHA2-224 Public Exponent Mode - Fixed Fixed Public Exponent - 010001 FIPS 186-4 RSA SigVer (FIPS186-5) A3944 Hash Pair - Hash Algorithm - SHA2-224 Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5 Fixed Public Exponent - 010001 Public Exponent Mode - fixed FIPS 186-5 SHA-1 A3944 Message Length - Message Length: 8-51200 Increment 8 FIPS 180-4 SHA2-224 A3944 Message Length - Message Length: 8-51200 Increment 8 FIPS 180-4 SHA2-256 A3944 Message Length - Message Length: 8-51200 Increment 8 FIPS 180-4 SHA2-384 A3944 Message Length - Message Length: 8-65536 Increment 8 FIPS 180-4 SHA2-512 A3944 Message Length - Message Length: 8-65536 Increment 8 FIPS 180-4 TLS v1.2 KDF RFC7627 (CVL) A3944 Hash Algorithm - SHA2-256, SHA2-384 SP 800-135 Rev. 1 Table 6: Approved Algorithms - Hardware CPU Jitter Entropy Source Algorithm CAVP Cert Properties Reference SHA3-256 A3513 Message Length - Message Length: 0-65528 Increment 8 FIPS 202 Table 7: Approved Algorithms - CPU Jitter Entropy Source 2.5.2 Vendor Affirmed Algorithms The vendor affirms the following cryptographic security methods. Name Properties Implementation Reference CKG (Control Plane - VA) CKG:Symmetric NetScaler Control Plane Cryptographic Library SP 800-133 Rev. 2, sections 4 and 6.3 CKG (Data Plane - VA) CKG:Symmetric NetScaler Data Plane Cryptographic Library SP 800-133 Rev. 2, section 4 CKG (KEK) CKG:Combining keys and other data NetScaler Control Plane Cryptographic Library NIST SP 800-133rev2, Section 6.3 Table 8: Vendor-Affirmed Algorithms 2.5.3 Non-Approved, Allowed Algorithms The module does not implement any non-approved algorithms allowed in the Approved mode of operation. N/A for this module. 2.5.4 Non-Approved, Allowed Algorithms with No Security Claimed The table below lists the non-Approved algorithms implemented by the module that are allowed for use in the Approved mode of operation with no security claimed. FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 18 of 87 Name Caveat Use and Function MD5 (NetScaler Control Plane Cryptographic Library) N/A Message digest in TLS 1.0/1.1 handshake on the control plane MD5 (NetScaler Data Plane Cryptographic Library) N/A Message digest in TLS 1.0/1.1 handshake on the data plane Table 9: Non-Approved, Allowed Algorithms with No Security Claimed 2.5.5 Non-Approved, Not Allowed Algorithms The module does not include any non-Approved algorithms not allowed in the Approved mode of operation. N/A for this module. 2.6 Security Function Implementations The table below lists the security function implementations for this module. Name Type Description Properties Algorithms AES for Disk Encryption BC-UnAuth AES for KEK, which is used for encrypting/decrypting passwords and passphrases. Publication:SP 800-38A AES-CBC: (A3942) Key Length: 256 Counter DRBG: (A3942) AES for AES Key BC-UnAuth AES for the AES Key, which is used for encryption/decryption. Publication :SP 800-38A AES-CBC: (A3943) Hash DRBG: (A3943) SHA2-256: (A3943) CKG (KEK) CKG Generation of the KEK by combining multiple keys/other data per SP 800-133rev2, Section 6.3. Publication:SP 800-133 Rev. 2 Counter DRBG: (A3942) AES for TLS Ticket BC-UnAuth AES for the TLS Ticket Encryption Key, which is used for the encryption/decryption of TLS session tickets. Publication:SP 800-38A AES-CBC: (A3943) Key Length: 128 Hash DRBG: (A3943) HMAC for TLS Ticket MAC HMAC for the TLS Ticket Authentication Key, which is used for the authentication of TLS session tickets. Publication:FIPS 198-1 HMAC-SHA2-256: (A3943, A3942) SHA2-256: (A3943, A3942) FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 19 of 87 Name Type Description Properties Algorithms Key Agreement for SSH (DH) KAS-135KDF Key agreement for SSH utilizing DH Publication:SP 800-56 Rev. 3 Key Strength:Key establishment methodology provides between 112 and 176 bits of encryption strength Caveat:No part of the SSH protocol, other than the KDF, has been tested by the CAVP and CMVP. KDF SSH: (A3942) KAS-FFC-SSC Sp800- 56Ar3: (A3942) Domain Parameter Generation Methods: MODP-2048, MODP- 4096, ffdhe2048, ffdhe4096 Counter DRBG: (A3942) Safe Primes Key Generation: (A3942) Safe Prime Groups: MODP-2048, MODP- 4096, ffdhe2048, ffdhe4096 Safe Primes Key Verification: (A3942) Safe Prime Groups: MODP-2048, MODP- 4096, ffdhe2048, ffdhe4096 SHA-1: (A3942) SHA2-256: (A3942) SHA2-384: (A3942) SHA2-512: (A3942) Key Agreement for SSH (ECDH) KAS-135KDF Key agreement for SSH utilizing ECDH Publication:SP 800-56 Rev. 3 Key Strength:Key establishment methodology provides between 112 and 256 bits of encryption strength Caveat:No part of the SSH protocol, other than the KDF, has been tested by the CAVP and CMVP. KDF SSH: (A3942) KAS-ECC-SSC Sp800- 56Ar3: (A3942, A3943) Counter DRBG: (A3942) ECDSA KeyGen (FIPS186-4): (A3942) ECDSA KeyVer (FIPS186- 4): (A3942) SHA-1: (A3942) SHA2-256: (A3942) SHA2-384: (A3942) SHA2-512: (A3942) AES for SSH BC-UnAuth AES (CTR or CBC modes) for the SSH Session Key, which is used for the encryption/decryption of SSH session packets. Publication:SP 800-38A AES-CBC: (A3942) AES-CTR: (A3942) Counter DRBG: (A3942) AES-CFB128: (A3942) HMAC for SSH MAC HMAC for the SSH Authentication Key, which is used for the authentication of SSH session packets. Publication:FIPS 198-1 Caveat:The module supports the truncation of HMAC SHA-1 to 96 bits according to NIST SP 800-107 Rev.1 HMAC-SHA-1: (A3942) HMAC-SHA2-256: (A3942) HMAC-SHA2-384: (A3942) HMAC-SHA2-512: (A3942) SHA-1: (A3942) SHA2-256: (A3942) SHA2-384: (A3942) SHA2-512: (A3942) FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 20 of 87 Name Type Description Properties Algorithms Key Agreement for IKE/IPsec (DH) KAS-135KDF Key Agreement for IKE/IPsec using DH Publication:SP 800-56 Rev. 3 Key Strength:Key establishment methodology provides between 112 and 176 bits of encryption strength. Caveat:No part of the IKE protocol, other than the KDF, has been tested by the CAVP and CMVP. KDF IKEv1: (A3942) KDF IKEv2: (A3942) KAS-FFC-SSC Sp800- 56Ar3: (A3942) Domain Parameter Generation Methods: MODP-2048, MODP- 3072, MODP-6144 Counter DRBG: (A3942) Safe Primes Key Generation: (A3942) Safe Prime Groups: MODP-2048, MODP- 3072, MODP-6144 Safe Primes Key Verification: (A3942) Safe Prime Groups: MODP-2048, MODP- 3072, MODP-6144 SHA-1: (A3942) SHA2-256: (A3942) SHA2-384: (A3942) SHA2-512: (A3942) AES for IKE/IPsec BC-UnAuth AES for the IKE/IPsecSession Key, which is used for the encryption/decryption of IKE/IPsec packets. Publication:SP 800-38A AES-CBC: (A3942) Counter DRBG: (A3942) HMAC for IKE/IPsec MAC HMAC for the IKE/IPsec Authentication Key, which is used for the authentication of IKE/Ipsec session packets. Publication :FIPS 198-1 Caveat:The module supports the truncation of HMAC SHA-1 to 96 bits according to NIST SP 800-107 Rev.1 HMAC-SHA-1: (A3943) HMAC-SHA2-224: (A3943) HMAC-SHA2-256: (A3943) HMAC-SHA2-384: (A3943) HMAC-SHA2-512: (A3943) SHA-1: (A3943) SHA2-224: (A3943) SHA2-256: (A3943) SHA2-384: (A3943) SHA2-512: (A3943) HMAC for HMAC Key MAC HMAC for HMAC key used for message authentication. Publication:FIPS PUB 198-1 Caveat:The module supports the truncation of HMAC SHA-1 to 96 bits according to NIST SP 800-107 Rev.1 HMAC-SHA-1: (A3943) HMAC-SHA2-224: (A3943) HMAC-SHA2-256: (A3943) HMAC-SHA2-384: (A3943) HMAC-SHA2-512: (A3943) SHA-1: (A3943) SHA2-224: (A3943) SHA2-256: (A3943) SHA2-384: (A3943) SHA2-512: (A3943) FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 21 of 87 Name Type Description Properties Algorithms Key Agreement for TLS (DH) KAS-135KDF Key Agreement for TLS using DH Publication:RFC 7627 Key Strength:Key establishment methodology provides between 112 and 176 bits of encryption strength. Caveat:No part of the TLS protocol, other than the KDF, has been tested by the CAVP and CMVP. KDF TLS: (A3942) TLS v1.2 KDF RFC7627: (A3942) KAS-FFC-SSC Sp800- 56Ar3: (A3942) Domain Parameter Generation Methods: ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144 Counter DRBG: (A3942) Safe Primes Key Generation: (A3942) Safe Prime Groups: ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144 Safe Primes Key Verification: (A3942) Safe Prime Groups: ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144 SHA2-256: (A3942) SHA2-384: (A3942) FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 22 of 87 Name Type Description Properties Algorithms Key Agreement for TLS (ECDH) KAS-135KDF Key agreement for TLS using ECDH Publication:RFC 7627 Key Strength:Key establishment methodology provides between 112 and 256 bits of encryption strength Caveat:No part of the TLS protocol, other than the KDF, has been tested by the CAVP and CMVP. KDF TLS: (A3942, A3943, A3944) TLS v1.2 KDF RFC7627: (A3942, A3943, A3944) TLS v1.3 KDF: (A3943) KAS-ECC-SSC Sp800- 56Ar3: (A3942, A3943, A3944) Counter DRBG: (A3942) Hash DRBG: (A3943) ECDSA KeyGen (FIPS186-4): (A3942, A3944, A3943) ECDSA KeyVer (FIPS186- 4): (A3942, A3943, A3944) SHA2-256: (A3942, A3943, A3944) SHA2-384: (A3942, A3943, A3944) ECDSA SigGen (FIPS186- 4): (A3942, A3943, A3944) ECDSA SigVer (FIPS186- 4): (A3942, A3944, A3943) RSA SigGen (FIPS186-4): (A3942, A3943, A3944) RSA SigVer (FIPS186-4): (A3942, A3943, A3944) ECDSA KeyGen (FIPS186-5): (A3943, A3944) ECDSA KeyVer (FIPS186- 5): (A3943, A3944) ECDSA SigGen (FIPS186- 5): (A3943, A3944) ECDSA SigVer (FIPS186- 5): (A3943, A3944) RSA SigGen (FIPS186-5): (A3943, A3944) RSA SigVer (FIPS186-5): (A3943, A3944) RSA SigVer (FIPS186-2): (A3943) Key Transport for TLS KTS-Encap RSA key transport for TLS. Publication:SP 800-56B Rev. 2 Key Strength:Key establishment methodology provides 112 bits of encryption strength KTS-IFC: (A3942, A3943) Counter DRBG: (A3942) Hash DRBG: (A3943) SHA-1: (A3942, A3943) RSA KeyGen (FIPS186- 4): (A3942) Modulo: 2048 RSA SigVer (FIPS186-4): (A3942, A3943) CKG (Control Plane) CKG Key Generation using the output of Counter DRBG. Publication:SP 800-133 Rev. 2 Counter DRBG: (A3942) FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 23 of 87 Name Type Description Properties Algorithms CKG (Data Plane) CKG Key Generation using the output of Hash DRBG. Publication:SP 800-133 Rev. 2 Hash DRBG: (A3943) Counter DRBG (Random bits) DRBG Get random bits from the Counter DRBG. Publication:SP 800-90A Counter DRBG: (A3942) Hash DRBG (Random bits) DRBG Get random bits from the Hash DRBG. Publication:SP 800-90A Hash DRBG: (A3943) Key Derivation for TLS Extended Master Secret KAS-135KDF Key derivation for the TLS Extended Master Secret, which are used to derive the ticket encryption key and the ticket authentication key. Publication:SP 800-135 Rev. 1 KDF TLS: (A3942, A3943) TLS v1.2 KDF RFC7627: (A3942, A3943) TLS v1.3 KDF: (A3943) SHA2-256: (A3942, A3943) SHA2-384: (A3942, A3943) Key Generation for SSH AsymKeyPair-KeyGen Asymmetric key generation (RSA or ECDSA) for the SSH private and public keys. Publication:FIPS 186-4, FIPS 186-5 ECDSA KeyGen (FIPS186-4): (A3942) RSA KeyGen (FIPS186- 4): (A3942) Counter DRBG: (A3942) Key Generation for TLS AsymKeyPair-KeyGen Key pair generation for TLS. Publication:FIPS 186-4 RSA KeyGen (FIPS186- 4): (A3942) ECDSA KeyGen (FIPS186-4): (A3942, A3943, A3944) Counter DRBG: (A3942) Hash DRBG: (A3943) AES for TLS Session BC-UnAuth AES for the TLS Session Key, which is used for the encryption/decryption of TLS session packets. Publication:FIPS 800- 38A AES-CBC: (A3942, A3943, A3944) Key Length: 128, 256 Counter DRBG: (A3942) Hash DRBG: (A3943) HMAC for TLS Session MAC HMAC for the TLS Authentication Key, which is used for the authentication of TLS session packets. Publication:FIPS 198-1 Caveat:The module supports the truncation of HMAC SHA-1 to 96 bits according to NIST SP 800-107 Rev.1 HMAC-SHA-1: (A3942, A3943, A3944) HMAC-SHA2-256: (A3942, A3943, A3944) HMAC-SHA2-384: (A3942, A3943, A3944) HMAC-SHA2-224: (A3943, A3944) SHA-1: (A3942, A3943, A3944) SHA2-256: (A3942, A3943, A3944) SHA2-384: (A3942, A3943) SHA2-224: (A3943, A3944) SHA2-512: (A3944) HMAC-SHA2-512: (A3944) AES GCM for TLS Session BC-Auth AES-GCM for the TLS Session Key, which is used for the encryption/decryption of TLS session packets. Publication:SP 800-38D AES-GCM: (A3942, A3943, A3944) Key Length: 128, 256 Counter DRBG: (A3942) Hash DRBG: (A3943) FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 24 of 87 Name Type Description Properties Algorithms RSA SigGen for DNSSec DigSig-SigGen RSA digital signature generation for DNSSec. Publication:FIPS 186-4 RSA SigGen (FIPS186-4): (A3942) Counter DRBG: (A3942) SHA-1: (A3942) RSA SigVer for DNSSec DigSig-SigVer RSA digital signature verification for DNSSec. Publication:FIPS 186-4 RSA SigVer (FIPS186-4): (A3942) Counter DRBG: (A3942) AES (PEM Key) for Encrypting TLS Private Key BC-UnAuth AES for the PEM Key, which is used to encrypt the TLS Private Key. Publication:SP 800-38A AES-CBC: (A3942) Key Length: 256 HMAC-SHA-1: (A3942) SHA-1: (A3942) PBKDF for PEM Key PBKDF Password-based key derivation for PEM Key used for the encryption and decryption of asymmetric private keys Publication:SP 800-132 PBKDF: (A3942) SHA-1: (A3942) AES for RDP Session BC-Auth AES-GCM for the RDP Session Key, which is used for the encryption /decryption of RDP user and target information. Publication:SP 800-38A AES-GCM: (A3942) Key Length: 256 Counter DRBG: (A3942) KDF SP800-108: (A3943) HMAC-SHA2-256: (A3943) SHA2-256: (A3943) KBKDF for DFA Shared Secret KBKDF Key-based key derivation for DFA Shared Secret. Publication:SP 800-108 Rev. 1 KDF SP800-108: (A3943) HMAC-SHA2-256: (A3943) SHA2-256: (A3943) AES for DFA Session Key BC-UnAuth AES for the DFA Session Key, which is used for DFA authentication to the module. Publication:SP 800-38A AES-CBC: (A3943) Key Length: 256 KDF SP800-108: (A3943) HMAC-SHA2-256: (A3943) SHA2-256: (A3943) AES for SNMPv3 BC-UnAuth AES (SNMPv3 Privacy Key) for the encryption and decryption of SNMPv3 packets Publication:SP 800-38A Counter DRBG: (A3942) KDF SNMP: (A3942) RSA SigVer (FIPS186-4): (A3943) Direction: Decrypt, Encrypt Key Length: 128 HMAC for SNMPv3 MAC HMAC (SNMPv3 Authentication Key) for the authentication of SNMPv3 packets Punlication:FIPS 198-1 Caveat:The module supports the truncation of HMAC SHA-1 to 96 bits according to NIST SP 800-107 Rev.1 HMAC-SHA-1: (A3942) KDF SNMP: (A3942) SHA-1: (A3942) RSA SigVer for Firmware Load Integrity DigSig-SigVer RSA SigVer used to verify the new firmware load Publication:FIPS 186-4 RSA SigVer (FIPS186-4): (A3943) Signature Type: pkcs1v1.5 Modulo: 2048 Hash Pair: SHA2-512 SHA2-512: (A3943) FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 25 of 87 Name Type Description Properties Algorithms RSA SigVer for Web GUI DigSig-SigVer RSA SigVer for authentication via the Web GUI. Publication:FIPS 186-4 RSA SigVer (FIPS186-4): (A3943) SHA2-256: (A3943) SHA2-384: (A3943) SHA2-512: (A3943) Entropy Source ENT-ESV CPU jitter entropy source. Publication:NIST SP 800- 90B SHA3-256: (A3513) Table 10: Security Function Implementations 2.7 Algorithm Specific Information The following is algorithm specific information for the module: • AES-GCM: AES-GCM is used in the following protocols: o AES-GCM encryption is used in the context of the TLS 1.2 protocol. The module supports acceptable AES-GCM cipher suites from section 3.3.1 of NIST SP 800-52r2 and meets the (key/IV) pair uniqueness requirements from NIST SP 800-38D. The mechanism for IV generation is compliant with RFC 5288 per scenario 1 in FIPS 140-3 IG C.H. The counter portion of the IV is strictly increasing. The nonce-explicit part of the IV does not exhaust the maximum number of possible values for a given session key. This condition is implicitly ensured by the design of the TLS protocol, in which the nonce- explicit is denied exhaustion by the control exerted by the protocol’s (and hence also the module’s) management logic (wherein the nonce-explicit is incremented per each TLS record). This management logic also implies that the probability of an exhaustion of all 264 - 1 values of the nonce-explicit for the same TLS session in a realistic time frame is not significant. o AES-GCM encryption is used in the context of the TLS 1.3 protocol. The module supports acceptable AES-GCM cipher suites from section 3.3.1.2 of NIST SP 800-52rev2 and meets the (key/IV) pair uniqueness requirements from NIST SP 800-38D. The protocol’s implementation is contained within the boundary of the module, and the generated IV is only used in the context of the AES-GCM encryption executing the provisions of the TLS 1.3 protocol. The mechanism for IV generation falls into scenario 5 in FIPS 140-3 IG C.H and is compliant with RFC 8446. Each session employs a “per-record nonce”, a 64-bit sequence number (or IV) maintained separately for reading and writing records. Each sequence number is set to 0 at the beginning of a connection and whenever the key is changed (the first record transmitted under a particular traffic key uses sequence number 0), and the appropriate sequence number is incremented by one after reading or writing each record. Because the size of sequence numbers is 64 bits, the IV should not exhaust the maximum number of possible values for a given session key. If the IV exhaustion condition is observed, this will trigger a session termination or a re-key due to session re-establishment. If the module’s power is lost and then restored, the CO shall establish a new key for AES-GCM encryption. 2.8 RNG and Entropy The table below specifies the module’s entropy certificates. FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 26 of 87 Cert Number Vendor Name E52 Cloud Software Group Table 11: Entropy Certificates The table below specifies the module’s entropy sources. Name Type Operational Environment Sample Size Entropy per Sample Conditioning Component NetScaler CPU Jitter Entropy Source Non- Physical FreeBSD 11.4 64 bits A request for 256 bits of entropy results in 256 bits of entropy per output sample, or full entropy. SHA3-256 (NetScaler CPU Jitter Entropy Source) Table 12: Entropy Sources 2.9 Key Generation When generating symmetric keys, the module uses the direct output of its approved DRBG to generate random numbers and seeding material, per the guidance in NIST SP 800-133 Rev. 2, Section 4. When generating the Key Encryption Key (KEK), the module follows the method “Symmetric Keys Produced by Combining (Multiple) Keys and Other Data” described in NIST SP 800-133 Rev. 2, Section 6.3. 2.10 Key Establishment 2.10.1 Key Agreement Information The module implements the following approved key agreement methods: KAS-ECC-SSC - NIST SP 800-56A Rev. 3 (FIPS 140-3 IG D.F, Scenario 2, Path (1) KAS-FFC-SSC - NIST SP 800-56A Rev. 3 (FIPS 140-3 IG D.F, Scenario 2, Path (1) While the module implements the protocol-specific KDFs in support of key agreement operations, the module only offers cryptographic services at the API-level to calling applications and does not implement full key agreement within the module boundary. 2.10.2 Key Transport Information The module implements the following key transport method: KTS-IFC – NIST SP 800-56B Rev. 2 (FIPS 140-3 IG D.G, Key Encapsulation/Un-encapsulation) 2.11 Industry Protocols The module uses the following industry protocols: FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 27 of 87 • IPsec with IKEv1 • IPsec with IKEv2 • SNMP • SSH • TLS 1.0/1.1 • TLS 1.2 • TLS 1.3 FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 28 of 87 3. Cryptographic Module Interfaces 3.1 Ports and Interfaces The module supports the following logical interfaces: • Data Input • Data Output • Control Input • Control Output • Status Output The module’s physical boundary includes the physical ports, manual controls, physical indicators, and physical, logical, and electrical characteristics of the device. Figure 5 and Figure 6 below depict the ports and interfaces on the front and rear panels of the NetScaler MPS 8900. USB Ports Console Port 10/100/1000 Base-T Copper Ports FIPS Tamper Seal Management Port LCD LCD Keypad LOM Port 10G SFP+ Ports Figure 5. NetScaler MPS 8900 Front Panel Power Supply 1 Power Switch Solid-State Drive NMI Button (recessed) Disable Alarm Button Power Supply 2 (optional) FIPS Tamper Seal Figure 6. NetScaler MPS 8900 Rear Panel FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 29 of 87 Figure 7 and Figure 8 below depict the ports and interfaces on the front and rear panels of the NetScaler MPX 9100. USB Ports Console Port Management Port LOM Port 25G SFP28 ports (1 thru 4) 25G SFP28 ports (5 thru 8) FIPS Tamper Seal Figure 7. NetScaler MPX 9100 Front Panel Power Supply 1 Power Switch Solid-State Drive Disable Alarm Button Power Supply 2 (customer-installed option) NMI Button (recessed) FIPS Tamper Seal Figure 8. NetScaler MPX 9100 Rear Panel Figure 9 and Figure 10 below depict the ports and interfaces on the front and rear panels of the NetScaler MPX 15000-50G. FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 30 of 87 Console Port LOM Port Management Ports 0/1 0/2 USB Ports 10/1 10/2 10/3 10/4 50/1 50/2 50/3 50/ 4 10/5 10/6 10/7 10/8 Figure 9. NetScaler MPX 15000-50G Front Panel Solid-State Drives NMI Button (recessed) FIPS Tamper Seal Power Switch Power Status LED 1 Power Supply 1 Power Supply 2 Power Status LED 2 GND Stud Disable Alarm Button Figure 10. NetScaler MPX 15000-50G Rear Panel Each of the module’s physical ports and manual controls maps to one of the logical interfaces defined in FIPS 140- 3. The table below contains a mapping of the physical and logical interfaces of the module. Physical Port Logical Interface(s) Data That Passes 10/100/1000Base-T copper RJ45 Ethernet port Data Input Network traffic (ingress) FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 31 of 87 Physical Port Logical Interface(s) Data That Passes 10/100/1000Base-T copper RJ45 Ethernet port Data Output Network traffic (egress) 10/100/1000Base-T copper RJ45 Ethernet port Control Input Management data used to remotely manage the appliance independently of the firmware via the Lights-Out Management (LOM) feature 10/100/1000Base-T copper RJ45 Ethernet port Control Output Control information sent to remote machines supporting LDAP and RADIUS in order for the module to communicate with these machines. 10/100/1000Base-T copper RJ45 Ethernet port Status Output Status information used to remotely monitor the appliance independently of the firmware via the Lights-Out Management (LOM) feature Management Port Control Input Management data used to connect directly to the appliance for CSG ADC administration functions Management Port Status Output Status information used to remotely monitor the appliance 10G SFP+ Ethernet port* Data Input Network traffic (ingress) 10G SFP+ Ethernet port* Data Output Network traffic (egress) 10G SFP+ Ethernet port* Control Input Management data used to remotely manage the appliance 10G SFP+ Ethernet port* Control Output Control information sent to remote machines supporting LDAP and RADIUS in order for the module to communicate with these machines. 10G SFP+ Ethernet port* Status Output Status information used to remotely monitor the appliance 50G Ethernet port Data Input Network traffic (ingress) 50G Ethernet port Data Output Network traffic (egress) 50G Ethernet port Control Input Management data used to remotely manage the appliance 50G Ethernet port Control Output Control information sent to remote machines supporting LDAP and RADIUS in order for the module to communicate with these machines. 50G Ethernet port Status Output Status information used to remotely monitor the appliance RS-232 serial port Control Input Initial configuration data from a connected computer RS-232 serial port Status Output Status information sent to a connected computer regarding initial configuration activities LCD Keypad Control Input Initial configuration information from a connected computer; status information (available only on the 89xx FIPS model) LCD Keypad Status Output IP information, system status updates, system information, current selection, or input information Disable Alarm button** Control Input Button used to stop the power alarm from sounding. NMI button Control Input Button used (at the request of Technical Support) to initiate a core dump. Power interface Power N/A Table 13: Ports and Interfaces FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 32 of 87 4. Roles, Services, and Authentication 4.1 Authentication Methods The module supports identity-based authentication; operators explicitly assume their role based on the authentication credentials used. Each role determines the functionality available to the operator within the module. Operators authenticate to the module using either: • Username and password. Password complexity policies can be configured by an operator with the Crypto Officer role and are enforced by the module. All operators are required to follow the password policies. • Certificates associated with the selected protocol. The module supports RSA digital certificate authentication of users during Web GUI/HTTPS (TLS) access. The strength objectives of the authentication mechanisms are as follows: • For each attempt to use an authentication mechanism, the probability shall be less than one in 1,000,000 that a random attempt will succeed or a false acceptance will occur. • For multiple attempts to use an authentication mechanism during a one-minute period, the probability shall be less than one in 100,000 that a random attempt will succeed or a false acceptance will occur. To meet these objectives, the password policies shall be configured by the Crypto Officer such that all passwords shall require: • A minimum of eight total characters • At least one lowercase letter • At least one uppercase letter • At least one digit • At least one special character (~, `, !, @, #, $, %, ^, &, *, -, _, =, +, {, }, [, ], |, \, :, <, >, /, ., ,, " ") The strength calculations for each of the authentication mechanisms are provided in the table below. Method Name Description Security Mechanism Strength Each Attempt Strength per Minute Password Password complexity policies must be configured by the Crypto Officer to include the following: a minimum of eight total characters, at least one lowercase letter, at least one uppercase letter, at least one digit, at least one special character (~, `, !, @, #, $, %, ^, &, *, -, _, =, +, {, }, [, ], |, \, :, <, >, /, ., ,, " "). Username/Password 1/11451713827320 1/4591650 Certificate The module supports RSA digital certificate authentication of users during Web GUI/HTTPS (TLS) access. RSA SigVer for Web GUI 1/2^112 1/5.19 x 10^33 1/1.77 x 10^26 Table 14: Authentication Methods FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 33 of 87 4.2 Roles The module supports a Crypto Officer (CO) that authorized operators can assume. The CO role performs administrative services on the module, such as initialization, configuration, and monitoring of the module. The CO role includes the privileges listed under the read-only, operator, network, and sysadmin command policies. The module also supports the following role(s): • User – The User role can view the current status of the module and employ the services of the module (including IPsec14 , TLS, SSH, and SNMPv3 services). The User role includes the privileges listed under the read-only command policy. The table below lists the supported roles. Name Type Operator Type Authentication Methods Crypto Officer Identity CO Password Certificate User Identity User Password Certificate Table 15: Roles 4.3 Approved Services Descriptions of the services available are provided in the table below. The keys and Sensitive Security Parameters (SSPs) listed in the table indicate the type of access required using the following notation: • G = Generate: The module generates or derives the SSP. • R = Read: The SSP is read from the module (e.g., the SSP is output). • W = Write: The SSP is updated, imported, or written to the module. • E = Execute: The module uses the SSP in performing a cryptographic operation. • Z = Zeroize: The module zeroizes the SSP. 14 IPsec – Internet Protocol Security FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 34 of 87 Name Description Indicator Inputs Outputs Security Functions SSP Access Configure system settings Configure modes and features, system settings, and cloud parameters Command Line Interface Command and parameters Command response/status output AES for Disk Encryption AES for AES Key CKG (KEK) CKG (Control Plane) CKG (Data Plane) Crypto Officer - AES Key: W - KEK: E - Hash DRBG Entropy: R,E - Hash DRBG Seed: R,W,E - Hash DRBG 'V' Value (Internal state value): R,W,E - Hash DRBG 'C' Value (Internal state value): R,W,E - KEK Fragment 1: G,E - KEK Fragment 2: G,E Configure network settings Configure network routing protocols Command Line Interface Command and parameters Command response / status output AES for Disk Encryption CKG (KEK) CKG (Control Plane) CKG (Data Plane) Crypto Officer - ZebOS Router Password: R,W - KEK: E Configure clustering Configure an appliance to either be the cluster coordinator or a node in the cluster Command Line Interface Command and parameters Command response / status output / control output None Crypto Officer - Cluster Password (Alphanumeric string): R,W Manage data policy encryption keys Add, edit, delete encryption keys Command Line Interface Command Status output AES for Disk Encryption AES for AES Key CKG (KEK) CKG (Control Plane) CKG (Data Plane) Crypto Officer - AES Key: R,W - KEK: E - Hash DRBG Entropy: R,E - Hash DRBG Seed: R,W,E - Hash DRBG 'V' Value (Internal state value): R,W,E - Hash DRBG 'C' Value (Internal state value): R,W,E Manage data policy HMAC keys Add, edit, delete HMAC keys Command Line Interface Command Status output AES for Disk Encryption CKG (KEK) HMAC for HMAC Key CKG (Control Plane) CKG (Data Plane) Crypto Officer - HMAC Key: R,W - KEK: E - Hash DRBG Entropy: R,E - Hash DRBG Seed: R,W,E - Hash DRBG 'V' Value (Internal state value): R,W,E - Hash DRBG 'C' Value (Internal state value): R,W,E FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 35 of 87 Name Description Indicator Inputs Outputs Security Functions SSP Access Exchange routing information Exchange routing update information using ZebOS, authenticate source of packets Show Command O/P and Traffic Command Status output AES for Disk Encryption Crypto Officer - ZebOS Router Password: E - KEK: E FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 36 of 87 Zeroize Reboot the module (same as power cycle) N/A Command Status output None Crypto Officer - PEM Passphrase: Z - PEM Key: Z - AES GCM Key: Z - AES GCM IV (96 and 128-bit IV): Z - DH Public Key: Z - DH Private Key: Z - ECDH Public Key : Z - ECDH Private Key : Z - RSA Public Key: Z - RSA Private Key : Z - SSH Shared Secret: Z - SSH Session Key: Z - SSH Authentication Key: Z - IKE/IPsec Shared Secret: Z - IKE/IPsec Session Key (AES key): Z - IKE/IPsec Authentication Key (HMAC key): Z - TLS Pre-Master Secret: Z - TLS Extended Master Secret: Z - TLS Session Key: Z - TLS Authentication Key (HMAC key): Z - TLS Ticket Encryption Key (AES key): Z - TLS Ticket Authentication Key (HMAC key): Z - Hash DRBG Entropy: Z - Hash DRBG Seed: Z - Hash DRBG 'V' Value (Internal state value): Z - Hash DRBG 'C' Value (Internal state value): Z - CTR DRBG Entropy: Z - CTR DRBG Seed: Z FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 37 of 87 Name Description Indicator Inputs Outputs Security Functions SSP Access - CTR DRBG 'V' Value: Z - CTR DRBG 'Key' Value (AES key): Z - SNMPv3 Privacy Key (AES key): Z - SNMPv3 Authentication Key (HMAC key): Z Zeroize KEK Zeroize KEK API return value Command Status output None Crypto Officer - KEK: W Configure Gateway Configure Gateway global settings, virtual servers, portal themes, AAA groups and users, policies, and resources Command Line Interface Command and parameters Command response / status output AES for Disk Encryption CKG (KEK) CKG (Control Plane) CKG (Data Plane) Crypto Officer - RDP PSK (Shared secret): W - KEK: E Configure IPsec Configure IPsec profile; configure CloudBridge Connector settings, network bridges, and IP tunnels; view IP tunnel details Command Line Interface Command and parameters Command response / status output AES for Disk Encryption CKG (KEK) CKG (Control Plane) CKG (Data Plane) Crypto Officer - IKE/IPsec Pre- shared key (PSK): R,W - KEK: E Establish IPsec session Establish an IPsec session using IKEv1 Traffic Command Status output AES for Disk Encryption CKG (KEK) Key Agreement for IKE/IPsec (DH) AES for IKE/IPsec HMAC for IKE/IPsec CKG (Control Plane) CKG (Data Plane) Crypto Officer - DH Private Key: W,E - DH Public Key: R,E - IKE/IPsec Shared Secret: W,E - IKE/IPsec Pre- shared key (PSK): E - KEK: E - IKE/IPsec Session Key (AES key): W,E - IKE/IPsec Authentication Key (HMAC key): W,E - CTR DRBG Entropy: R,E - CTR DRBG Seed: R,W,E - CTR DRBG 'V' Value: R,W,E - CTR DRBG 'Key' Value (AES key): R,W,E FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 38 of 87 Name Description Indicator Inputs Outputs Security Functions SSP Access Configure SSH Configure SSH authentication settings; generate SSH keys Command Line Interface Command and parameters Command response / status output Key Generation for SSH Crypto Officer - CTR DRBG Entropy: R,E - CTR DRBG Seed: R,W,E - CTR DRBG 'V' Value: R,W,E - CTR DRBG 'Key' Value (AES key): R,W,E - SSH Private Key: W,E - SSH Public Key: W Establish SSH sessions Establish an SSH session Traffic Command Status output Key Agreement for SSH (DH) Key Agreement for SSH (ECDH) AES for SSH HMAC for SSH Crypto Officer - SSH Public Key: R,E - DH Private Key: W,E - DH Public Key: R,E - CTR DRBG Entropy: R,E - CTR DRBG Seed: R,W,E - CTR DRBG 'V' Value: R,W,E - CTR DRBG 'Key' Value (AES key): R,W,E - ECDH Private Key : W,E - ECDH Public Key : R,E - SSH Session Key: W,E - SSH Authentication Key: W,E Zeroize SSH private keys Zeroize SSH private keys API return value Command Status output None Crypto Officer - SSH Private Key: W Configure SNMPv3 Configure SNMP communities, traps, managers, views, groups, users, alarms, and engine ID ; view SNMP OIDs Command Line Interface Command and parameters Command response / status output AES for Disk Encryption CKG (KEK) CKG (Control Plane) CKG (Data Plane) Crypto Officer - SNMPv3 Authentication Passphrase: R,W - SNMPv3 Privacy Passphrase : R,W - KEK: E FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 39 of 87 Name Description Indicator Inputs Outputs Security Functions SSP Access SNMPv3 traps Provides system condition information Log files None Status output / control output AES for SNMPv3 HMAC for SNMPv3 Crypto Officer - SNMPv3 Authentication Passphrase: E - SNMPv3 Privacy Passphrase : E - SNMPv3 Privacy Key (AES key): W,E - SNMPv3 Authentication Key (HMAC key): W,E Configure TLS profiles Add, edit, delete system profiles Command Line Interface Command and parameters Command response / status output AES for Disk Encryption AES for TLS Ticket HMAC for TLS Ticket Key Agreement for TLS (DH) Key Agreement for TLS (ECDH) Crypto Officer - TLS Extended Master Secret: R,W,E - TLS Ticket Encryption Key (AES key): R,W - TLS Ticket Authentication Key (HMAC key): R,W - CTR DRBG Entropy: R,W - CTR DRBG Seed: R,W,E - CTR DRBG 'V' Value: R,W,E - CTR DRBG 'Key' Value (AES key): R,W,E - KEK: E FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 40 of 87 Name Description Indicator Inputs Outputs Security Functions SSP Access Establish TLS session Establish a web session using TLS protocol Traffic Command Status output CKG (KEK) Key Agreement for TLS (DH) Key Agreement for TLS (ECDH) CKG (Control Plane) CKG (Data Plane) AES for TLS Session HMAC for TLS Session AES GCM for TLS Session AES (PEM Key) for Encrypting TLS Private Key Crypto Officer - TLS Public Key: R - DH Private Key: W - DH Public Key: R - ECDH Private Key : W - ECDH Public Key : R - RSA Private Key : W - RSA Public Key: R - TLS Pre-Master Secret: R,W - TLS Extended Master Secret: W - TLS Session Key: W - TLS Authentication Key (HMAC key): W - AES GCM IV (96 and 128-bit IV): W - AES GCM Key: W - PEM Passphrase: R - PEM Key: W - KEK: E - CTR DRBG Entropy: R - CTR DRBG Seed: R,W - CTR DRBG 'V' Value: R,W - CTR DRBG 'Key' Value (AES key): R,W - Hash DRBG Entropy: R - Hash DRBG Seed: R,W - Hash DRBG 'V' Value (Internal state value): R,W - Hash DRBG 'C' Value (Internal state value): R,W FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 41 of 87 Name Description Indicator Inputs Outputs Security Functions SSP Access Resume TLS session Resume a web session using TLS protocol Traffic Command Status output AES for Disk Encryption AES for TLS Ticket HMAC for TLS Ticket AES for TLS Session HMAC for TLS Session AES GCM for TLS Session Crypto Officer - TLS Ticket Encryption Key (AES key): R,W,E - TLS Ticket Authentication Key (HMAC key): R,W,E - TLS Session Key: R,E - TLS Authentication Key (HMAC key): R,E - AES GCM IV (96 and 128-bit IV): W,E - AES GCM Key: W,E - KEK: E - Hash DRBG Entropy: R,E - Hash DRBG Seed: R,W,E - Hash DRBG 'V' Value (Internal state value): R,W,E - Hash DRBG 'C' Value (Internal state value): R,W,E Show status Show the system status N/A Command Status output None Crypto Officer Perform self-tests on-demand Perform pre- operational self-tests Log File Command Status output None Crypto Officer Show versioning information Show module name and version Console Output Command Module name, version None Crypto Officer Firmware load Update the module's firmware to a new version Log files Command Status output Counter DRBG (Random bits) Hash DRBG (Random bits) RSA SigVer for Firmware Load Integrity Entropy Source Crypto Officer - Software Load Integrity Key (RSA public key): R Perform initial network configuration Set up initial network configuration and licenses Success from CLI Command and parameters Command response/status output None Crypto Officer View system information View system info and statistics; view/end system sessions Console Output Command Status output None Crypto Officer FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 42 of 87 Name Description Indicator Inputs Outputs Security Functions SSP Access Configure HA Configure HA nodes, route monitors, failover interface set Command Line Interface and Traffic Command and parameters Status output/control output None Crypto Officer Manage NTP servers Add, edit, delete NTP servers; configure NTP parameters and synchronization state Command Line Interface Command Status output / control output None Crypto Officer Manage users Add, edit delete users, groups, and command policies; view user/group partition bindings Command Line Interface Command Status output None Crypto Officer Configure system auditing Add, edit, delete syslog/nslog auditing policies and servers; bind classic/advanced global policies Command Line Interface Command and parameters Command response / status output / control output None Crypto Officer View audit logs View authentication, system, and event logs N/A (Audit Logs) Command Status output None Crypto Officer Backup and restore Backup/import system configuration files; download and delete backup files; restore N/A Command Status output / control output None Crypto Officer Apply data policies Apply data policies to user data in transit (according to configuration) Traffic Command Status output AES for Disk Encryption AES for AES Key HMAC for HMAC Key Crypto Officer - KEK: E - AES Key: E - HMAC Key: E Configure security Configure DNS security profiles, application firewall profiles and policies, reputation settings, protection features, and content inspection policies Command Line Interface Command and parameters Command response / status output None Crypto Officer Establish Gateway connection Establish Gateway connection based on global settings Traffic Command and parameters Command response / status output / control output AES for RDP Session AES for DFA Session Key Crypto Officer - KEK: E - RDP Session Key: R,E - RDP PSK (Shared secret): R,E Configure external servers for system, AAA, and Gateway authentication Configure LDAP , Oauth, OpenID, DFA , and SAML servers to be used in system, AAA, or Gateway authentication Command Line Interface Command and parameters Command response / status output Key Derivation for TLS Extended Master Secret KBKDF for DFA Shared Secret Crypto Officer - KEK: E - LDAP Admin Password: R,W - Oauth Client Secret (Shared secret): R,W - DFA Shared Secret: R,W FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 43 of 87 Name Description Indicator Inputs Outputs Security Functions SSP Access Authenticate operators Used for operator logins to the module Traffic Command Status output RSA SigVer for Web GUI Unauthenticated - Operator Password: R - LDAP Admin Password: R,E - SSH Public Key: E - Oauth Client Secret (Shared secret): E - DFA Shared Secret: E - DFA Session Key: E - TLS Public Key: E - AES Key: E - AES GCM Key: E - AES GCM IV (96 and 128-bit IV): E - KEK: E FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 44 of 87 Name Description Indicator Inputs Outputs Security Functions SSP Access Configure traffic management Configure TLS; Configure load balancing, priority load balancing, content switching Command Line Interface Command and parameters Command response / status output Key Transport for TLS Key Generation for TLS RSA SigGen for DNSSec RSA SigVer for DNSSec AES (PEM Key) for Encrypting TLS Private Key PBKDF for PEM Key Crypto Officer - CA Public Key: R,W,E - TLS Private Key: R,W,E - TLS Public Key: R,W - Private DNS KSK (RSA private key): R,W,E - Public DNS KSK (RSA public key): R,W - Private DNS ZSK (RSA private key): R,W,E - Public DNS ZSK (RSA public key): R,W - SSH Private Key: R,W,E - SSH Public Key: R,W,E - PEM Passphrase: R,W,E - PEM Key: W,E - KEK: E - Hash DRBG Entropy: R,E - Hash DRBG Seed: R,W,E - Hash DRBG 'V' Value (Internal state value): R,W,E - Hash DRBG 'C' Value (Internal state value): R,W,E - CTR DRBG Entropy: R,E - CTR DRBG Seed: R,W,E - CTR DRBG 'V' Value: R,W,E - CTR DRBG 'Key' Value (AES key): R,W,E FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 45 of 87 Name Description Indicator Inputs Outputs Security Functions SSP Access RADIUS Over TLS Establish a TLS session with radius server Traffic Command Status output Key Agreement for TLS (DH) Key Agreement for TLS (ECDH) AES for TLS Session HMAC for TLS Session AES GCM for TLS Session AES (PEM Key) for Encrypting TLS Private Key Crypto Officer - TLS Public Key: R,E - DH Private Key: W,E - DH Public Key: R,E - ECDH Private Key : W,E - ECDH Public Key : R,E - RSA Private Key : W,E - RSA Public Key: R,E - TLS Pre-Master Secret: R,W,E - TLS Extended Master Secret: W,E - TLS Session Key: W,E - TLS Authentication Key (HMAC key): W,E - AES GCM IV (96 and 128-bit IV): W,E - AES GCM Key: W,E - PEM Passphrase: R,E - PEM Key: W,E - KEK: E - CTR DRBG Entropy: R,E - CTR DRBG Seed: R,W,E - CTR DRBG 'V' Value: R,W,E - CTR DRBG 'Key' Value (AES key): R,W,E - Hash DRBG Entropy: R,E - Hash DRBG Seed: R,W,E - Hash DRBG 'V' Value (Internal state value): R,W,E - Hash DRBG 'C' Value (Internal state value): R,W,E Table 16: Approved Services FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 46 of 87 4.4 Non-Approved Services The module does not provide any non-Approved services. 4.5 External Software/Firmware Loaded The module does not support the loading of external software or firmware. FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 47 of 87 5. Software/Firmware Security 5.1 Integrity Techniques All software within the cryptographic boundary is verified using an approved integrity technique implemented within the cryptographic module itself. The module implements a 2048-bit RSA digital signature verification with a SHA-512 hash to ensure the integrity of its software components. The module’s pre-operational integrity check is performed automatically at module power-up. 5.2 Initiate on Demand This integrity check can also be performed on demand by the module operator by performing a reboot. FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 48 of 87 6. Operational Environment 6.1 Operational Environment Type and Requirements The NetScaler MPX comprises a hardware cryptographic module with a Limited and is complaint with level 2 physical security requirements. Therefore, per section 7.5 of the CMVP Management Manual, the requirements for this section are not applicable. FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 49 of 87 7. Physical Security 7.1 Mechanisms and Actions Required The NetScaler MPX is a multi-chip standalone hardware cryptographic module that includes an enclosure composed of hard, production-grade, metal components sufficient for compliance with FIPS 140-3 level 2 physical security requirements. The module enclosure is opaque within the visible spectrum and completely encloses all internal components. All integrated circuits are coated with commercial standard passivation. The enclosure has removable front and back panels which provide only a limited set of ventilation holes, obscuring visual access to the module’s internal components. Tamper-evident seals are applied to the module at the factory to protect against unauthorized access to the module. The NetScaler MPS 8900 will have a total of four (4) tamper-evident seals installed. • One seal is placed on the front cover, connecting the front and top of the enclosure (Figure 11). • One seal is placed on the back of the enclosure, connecting the back to the top (Figure 12). • One seal is placed on the left rear side of the enclosure, connecting the side to the top (Figure 13). • One seal is placed on the right rear side of the enclosure, connecting the side to the top (Figure 14). 1 Figure 11. Front Panel of the NetScaler MPS 8900 2 Figure 12. Back Panel of the NetScaler MPS 8900 3 Figure 13. Left Side of the NetScaler MPS 8900 FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 50 of 87 4 Figure 14. Right Side of the NetScaler MPS 8900 The NetScaler MPX 9100 will have a total of four (4) tamper-evident seals installed. • One seal is placed on the front cover, connecting the front and top of the enclosure (Figure 15). • One seal is placed on the back of the enclosure, connecting the back to the top (Figure 16). • One seal is placed on the left side rear of the enclosure, connecting the side to the top (Figure 17). • One seal is placed on the right side rear of the enclosure, connecting the side to the top (Figure 18). 1 Figure 15. Front Panel of the NetScaler MPX 9100 2 Figure 16. Back Panel of the NetScaler MPX 9100 3 Figure 17. Left Side of the NetScaler MPX 9100 FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 51 of 87 4 Figure 18. Right Side of the NetScaler MPX 9100 The NetScaler MPX 15000-50G will have a total of four (4) tamper-evident seals installed. • One seal is placed on the front cover, connecting the front and top of the enclosure (Figure 19). • One seal is placed on the back of the enclosure, connecting the back to the top. (Figure 20). • One seal is placed on the left rear side of the enclosure, connecting the side to the top (Figure 21). • One seal is placed on the right rear side of the enclosure, connecting the side to the top (Figure 22). 1 Figure 19. Front Panel of the NetScaler MPX 15000-50G 2 Figure 20. Rear Panel of the NetScaler MPX 15000-50G FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 52 of 87 3 Figure 21. Left Side of the NetScaler MPX 15000-50G 4 Figure 22. Right Side of the NetScaler MPX 15000-50G The following table describes the physical security mechanisms that are implemented in the module and the actions required by the operator(s) to ensure that the physical security is maintained. Mechanism Inspection Frequency Inspection Guidance N/A N/A N/A Table 17: Mechanisms and Actions Required All tamper-evident seals are required for the module to be considered operating in its Approved mode of operation. If any seals show signs of tampering, the module shall be considered in a non-compliant state and taken out of operation, and the CO shall immediately contact Cloud Software Group Customer Support. FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 53 of 87 8. Non-Invasive Security This section is not applicable. There are currently no approved non-invasive mitigation techniques references in Annex F of ISO/IEC 19790. FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 54 of 87 9. Sensitive Security Parameters Management 9.1 Storage Areas The table below lists sensitive security parameters (SSPs) storage areas for this module. Section 9.4 below selects from the storage areas listed and specifies the appropriate storage area in the “Storage” column if applicable to a specific SSP. Storage Area Name Description Persistence Type On Disk SSPs are stored on disk Static Volatile Memory SSPs are stored in volatile memory Dynamic Non-volatile Memory SSPs are stored in non-volatile memory Static Table 18: Storage Areas 9.2 SSP Input-Output Methods The table below lists SSP input and output methods for this module. Section 9.4 below selects from the methods listed and specifies the appropriate method in the “Inputs/Outputs” column if applicable to a specific SSP. Name From To Format Type Distribution Type Entry Type SFI or Algorithm Exported in encrypted form via part of config backup file On Disk External Encrypted Automated Electronic AES for Disk Encryption Exported in plaintext On Disk External Plaintext Automated Electronic Imported in encrypted form via TLS or SSH session External On Disk Encrypted Automated Electronic AES for Disk Encryption Imported in plaintext via local console External On Disk Plaintext Automated Electronic AES for Disk Encryption Imported in encrypted form via RSA key transport On Disk Volatile Memory Encrypted Automated Electronic Key Transport for TLS Table 19: SSP Input-Output Methods 9.3 SSP Zeroization Methods The table below lists SSP zeroization methods for this module. Section 9.4 below selects from the methods listed and specifies the appropriate method in the “Zeroization” column if applicable to a specific SSP. Zeroization Method Description Rationale Operator Initiation CLI command The zeroization method is conducted via CLI command. The CLI command overwrites the storage location keys with 0's, making them irretrievable. Crypto Officer by command FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 55 of 87 Zeroization Method Description Rationale Operator Initiation Completion of TLS Session Key and TLS Authentication Key derivation Zeroization upon the completion of a TLS Session Key and TLS Authentication Key derivation Keys are automatically zeroized upon completion of TLS key derivation and are irretrievable. Crypto Officer or User by TLS session termination NetScaler detection SSPs are not zeroized. The module detects any modification. The module detects modification of Public Security Parameters for listed entry. N/A Reboot Zeroization when module is rebooted Keys are zeroized by rebooting the module. Crypto Officer by rebooting the module Remove power Zeroization when power is removed from the module. Keys are zeroized by removing the power of the module. Crypto Officer by removing power Session termination Zeroization when the session is terminated Keys are automatically zeroized upon session termination and are irretrievable. Crypto Officer or User by session termination Zeroization of KEK The KEK is zeroized Zeroization of the KEK renders SSP permanently unrecoverable Crypto Officer reboots or removes the power Table 20: SSP Zeroization Methods 9.4 SSPs The module supports the keys and other SSPs listed in the table below. Name Description Size - Strength Type - Category Generated By Established By Used By KEK Fragment 1 Hashed in combination with KEK Fragment 2 to derive KEK N/A - N/A Keying Material - Neither CKG (Control Plane) AES for Disk Encryption KEK Fragment 2 Hashed in combination with KEK Fragment 1 to derive KEK N/A - N/A Keying Material - Neither CKG (Control Plane) AES for Disk Encryption KEK Encryption and decryption of passwords and passphrases 256 bits - 256 bits Symmetric Key - CSP CKG (KEK) AES for Disk Encryption PEM Key Encryption and decryption of asymmetric private keys 256 bits - 256 bits Symmetric Key - CSP PBKDF for PEM Key AES (PEM Key) for Encrypting TLS Private Key AES Key Encryption and decryption Between 128 and 256 bits - Between 128 and 256 bits Symmetric Key - CSP CKG (Data Plane) AES for AES Key AES GCM Key Encryption and decryption 256 bits - 256 bits Symmetric Key - CSP CKG (Data Plane) AES GCM for TLS Session HMAC Key Message authentication with SHS Between 160 and 512 bits - Between 128 and 256 bits Authentication - CSP CKG (Data Plane) HMAC for HMAC Key FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 56 of 87 Name Description Size - Strength Type - Category Generated By Established By Used By CA Public Key TLS certificate authentication [for RSA public key] Between 2048 and 3072 bits [for ECDSA public key] Between 224 and 512 bits - [for RSA public key] Between 112 and 128 bits [for ECDSA public key] Between 112 and 256 bits Public/Private - PSP DH Private Key Generation of SSH, TLS, and IKE shared secrets [for SSH sessions] Between 2048 and 6144 bits [for TLS sessions] Between 2048 and 4096 bits [for IKE sessions] 2048 bits - [for SSH sessions] Between 112 and 176 bits [for TLS sessions] Between 112 and 150 bits [for IKE sessions] 112 bits Public/Private - CSP CKG (Data Plane) Key Agreement for SSH (DH) Key Agreement for IKE/IPsec (DH) Key Agreement for TLS (DH) DH Public Key Generation of SSH, TLS, and IKE shared secrets [for SSH sessions] Between 2048 and 6144 bits [for TLS sessions] Between 2048 and 4096 bits [for IKE sessions] 2048 bits - [for SSH sessions] Between 112 and 176 bits [for TLS sessions] Between 112 and 150 bits [for IKE sessions] 112 bits Public/Private - PSP CKG (Data Plane) Key Agreement for SSH (DH) Key Agreement for IKE/IPsec (DH) Key Agreement for TLS (DH) ECDH Private Key Generation of SSH and TLS shared secrets Between 224 and 512 bits - Between 112 and 256 bits Public/Private - CSP CKG (Control Plane) CKG (Data Plane) Key Agreement for SSH (ECDH) Key Agreement for TLS (ECDH) ECDH Public Key Generation of SSH and TLS shared secrets Between 224 and 512 bits - Between 112 and 256 bits Public/Private - PSP CKG (Control Plane) CKG (Data Plane) Key Agreement for SSH (ECDH) Key Agreement for TLS (ECDH) FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 57 of 87 Name Description Size - Strength Type - Category Generated By Established By Used By RSA Private Key Generation of TLS shared secrets 2048 or 3072 bits - 112 or 128 bits Public/Private - CSP CKG (Control Plane) Key Agreement for TLS (DH) Key Agreement for TLS (ECDH) RSA Public Key Generation of TLS shared secrets 2048 or 3072 bits - 112 or 128 bits Public/Private - PSP CKG (Control Plane) Key Agreement for TLS (DH) Key Agreement for TLS (ECDH) SSH Private Key Authentication during SSH session negotiation; RBA Authentication for LDAP; GSLB configuration sync [for RSA private key] 2048 or 3072 bits [for ECDSA private key] Between 224 and 512 bits - [for RSA private key] 112 or 128 bits [for ECDSA private key] Between 112 and 256 bits Public/Private - CSP CKG (Control Plane) Key Agreement for SSH (DH) Key Agreement for SSH (ECDH) SSH Public Key Authentication during SSH session negotiation; RBA Authentication for LDAP; GSLB configuration sync [for RSA private key] 2048 or 3072 bits [for ECDSA private key] Between 224 and 512 bits - [for RSA public key] 112 or 128 bits [for ECDSA public key] Between 112 and 256 bits Public/Private - PSP CKG (Control Plane) Key Agreement for SSH (DH) Key Agreement for SSH (ECDH) SSH Session Key Encryption and decryption of SSH session packets Between 128 and 256 bits - Between 128 and 256 bits Symmetric Key - CSP Key Agreement for SSH (DH) Key Agreement for SSH (ECDH) AES for SSH SSH Authentication Key Authentication of SSH session packets Between 160 and 512 bits - Between 128 and 256 bits Authentication - PSP Key Agreement for SSH (DH) Key Agreement for SSH (ECDH) HMAC for SSH IKE/IPsec Pre- shared key (PSK) Authentication during IKE/IPsec session negotiation [IKEv1 Only] Derivation of the IKE/IPsec Session Keys and IKE/IPsec Authentication Keys - Authentication - CSP Key Agreement for IKE/IPsec (DH) FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 58 of 87 Name Description Size - Strength Type - Category Generated By Established By Used By IKE/IPsec Session Key (AES key) Encryption and decryption of IKE/IPsec session packets Between 128 and 256 bits - Between 128 and 256 bits Symmetric Key - CSP KDF IKEv1 (A3942) KDF IKEv2 (A3942) AES for IKE/IPsec IKE/IPsec Authentication Key (HMAC key) Secret value used for deriving other IKEv1 secretsAuthentication of IKE/IPsec session packets Between 160 and 512 bits - Between 128 and 256 bits Authentication - CSP KDF IKEv1 (A3942) KDF IKEv2 (A3942) HMAC for IKE/IPsec RDP Session Key Encryption and decryption of RDP user and target information 256 bits - 256 bits Symmetric Key - CSP Key Derivation for TLS Extended Master Secret AES for RDP Session DFA Session Key DFA authentication to the module 256 bits - 256 bits Symmetric Key - CSP Key Derivation for TLS Extended Master Secret AES for DFA Session Key TLS Private Key TLS authentication; SAML authentication (RSA only); OpenID authentication (RSA only) [for RSA private key] Between 2048 and 4096 bits [for ECDSA private key] Between 224 and 512 bits - [for RSA private key] Between 112 and 150 bits [for ECDSA private key] Between 112 and 256 bits Public/Private - CSP CKG (Control Plane) Key Agreement for TLS (DH) Key Agreement for TLS (ECDH) TLS Public Key TLS authentication [for RSA public key] Between 2048 and 4096 bits [for ECDSA public key] Between 224 and 512 bits - [for RSA public key] Between 112 and 150 bits [for ECDSA public key] Between 224 and 512 bits Public/Private - PSP Key Agreement for TLS (DH) Key Agreement for TLS (ECDH) FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 59 of 87 Name Description Size - Strength Type - Category Generated By Established By Used By TLS Session Key Encryption and decryption of TLS session packets [for AES key] 128 or 256 bits [for AES GCM key] 128 or 256 bits - [for AES key] 128 or 256 bits [for AES GCM key] 128 or 256 bits Symmetric Key - CSP KDF TLS (A3942) KDF TLS (A3943) KDF TLS (A3944) TLS v1.2 KDF RFC7627 (A3943) TLS v1.2 KDF RFC7627 (A3944) TLS v1.3 KDF (A3943) AES for TLS Session TLS Authentication Key (HMAC key) Authentication of TLS session packets Between 160 and 384 bits - Between 128 and 256 bits Authentication - CSP KDF TLS (A3942) KDF TLS (A3943) KDF TLS (A3944) TLS v1.2 KDF RFC7627 (A3943) TLS v1.2 KDF RFC7627 (A3944) TLS v1.3 KDF (A3943) HMAC for TLS Session TLS Ticket Encryption Key (AES key) Encryption and decryption of TLS session tickets 128 bits - 128 bits Symmetric Key - CSP CKG (Data Plane) AES for TLS Ticket TLS Ticket Authentication Key (HMAC key) Computes the digest of TLS session tickets - 256 bits Authentication - CSP CKG (Control Plane) CKG (Data Plane) HMAC for TLS Ticket SNMPv3 Privacy Key (AES key) Encryption and decryption of SNMPv3 packets 128 bits - 128 bits Symmetric Key - CSP KDF SNMP (A3942) KDF SNMP (A3942) AES for SNMPv3 SNMPv3 Authentication Key (HMAC key) Authentication of SNMPv3 packets 160 bits - 128 bits Authentication - CSP KDF SNMP (A3942) KDF SNMP (A3942) HMAC for SNMPv3 Private DNS KSK (RSA private key) Public DNS ZSK signature generation Between 2048 and 4096 bits - Between 112 and 150 bits Public/Private - CSP RSA KeyGen (FIPS186-4) (A3942) RSA SigGen for DNSSec Public DNS KSK (RSA public key) Public DNS ZSK authentication Between 2048 and 4096 bits - Between 112 and 150 bits Public/Private - PSP RSA KeyGen (FIPS186-4) (A3942) RSA SigVer for DNSSec Private DNS ZSK (RSA private key) DNS zone signature generation Between 2048 and 4096 bits - Between 112 and 150 bits Public/Private - CSP RSA KeyGen (FIPS186-4) (A3942) RSA SigGen for DNSSec FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 60 of 87 Name Description Size - Strength Type - Category Generated By Established By Used By Public DNS ZSK (RSA public key) DNS zone authentication Between 2048 and 4096 bits - Between 112 and 150 bits Public/Private - PSP RSA KeyGen (FIPS186-4) (A3942) RSA SigVer for DNSSec Software Load Integrity Key (RSA public key) Used to verify the new software load 2048 bits - 112 bits Public/Private - PSP RSA SigVer for Firmware Load Integrity PEM Passphrase Derivation of PEM Key - Alphanumeric String - CSP AES (PEM Key) for Encrypting TLS Private Key AES GCM IV (96 and 128-bit IV) IV for AES-GCM - Initialization Vector - CSP Counter DRBG (A3942) KDF SSH (A3942) TLS v1.2 KDF RFC7627 (A3942) TLS v1.2 KDF RFC7627 (A3943) TLS v1.2 KDF RFC7627 (A3944) TLS v1.3 KDF (A3943) AES-GCM (A3942) SSH Shared Secret Derivation of the SSH Session Key and SSH Authentication Key - Shared Secret - CSP Key Agreement for SSH (DH) Key Agreement for SSH (ECDH) AES for SSH HMAC for SSH TLS Pre-Master Secret Derivation of the TLS Extended Master Secret - Pre-Master Secret - CSP Counter DRBG (Random bits) Hash DRBG (Random bits) Key Agreement for TLS (DH) Key Agreement for TLS (ECDH) FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 61 of 87 Name Description Size - Strength Type - Category Generated By Established By Used By TLS Extended Master Secret Derivation of the TLS Session Key and TLS Authentication Key - Extended Master Secret - CSP Key Agreement for TLS (ECDH) Key Transport for TLS TLS v1.2 KDF RFC7627 (A3943) AES for TLS Ticket HMAC for TLS Ticket AES GCM for TLS Session Hash DRBG Entropy Entropy input for Hash DRBG - Entropy - CSP Entropy Source Hash DRBG (Random bits) Hash DRBG Seed Seed material for Hash DRBG - DRBG Seed - CSP Entropy Source Hash DRBG (Random bits) Hash DRBG 'V' Value (Internal state value) Internal state value used with Hash DRBG - Internal State Value - CSP Hash DRBG (Random bits) Hash DRBG 'C' Value (Internal state value) Internal state value used with Hash DRBG - Internal State Value - CSP Hash DRBG (Random bits) CTR DRBG Entropy Entropy input for CTR DRBG - Entropy - CSP Entropy Source Counter DRBG (Random bits) CTR DRBG Seed Seed material for CTR DRBG - DRBG Seed - CSP Entropy Source Counter DRBG (Random bits) CTR DRBG 'V' Value Internal state value used with CTR DRBG - Internal State Value - CSP Counter DRBG (Random bits) CTR DRBG 'Key' Value (AES key) Internal state value used with CTR DRBG - Internal State Value - CSP Counter DRBG (Random bits) SNMPv3 Privacy Passphrase Derivation of the SNMPv3 Privacy Key - Alphanumeric String - CSP AES for SNMPv3 SNMPv3 Authentication Passphrase Derivation of the SNMPv3 Authentication Key - Alphanumeric String - CSP HMAC for SNMPv3 LDAP Admin Password Used to bind to the LDAP server - Alphanumeric String - CSP ZebOS Router Password Router authentication - Alphanumeric String - CSP Cluster Password (Alphanumeric string) Used to connect nodes to the cluster coordinator - Alphanumeric String - CSP Operator Password Authenticate the operator to the module via an external authentication service - Alphanumeric String - CSP FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 62 of 87 Name Description Size - Strength Type - Category Generated By Established By Used By IKE/IPsec Shared Secret Derivation of the IKE/IPsec Session Keys and IKE/IPsec Authentication Keys - Shared Secret - CSP Key Agreement for IKE/IPsec (DH) AES for IKE/IPsec HMAC for IKE/IPsec DFA Shared Secret Used as input to derive DFA Session Key - Shared Secret - CSP AES for DFA Session Key RDP PSK (Shared secret) Used as input to derive RDP Session Key - Shared Secret - CSP AES for RDP Session Oauth Client Secret (Shared secret) Oauth and Oauth IDP authentication to the module - Shared Secret - CSP Table 21: SSP Table 1 Name Input - Output Storage Storage Duration Zeroization Related SSPs KEK Fragment 1 Non-volatile Memory:Plaintext Until zeroization CLI command KEK Fragment 2:Used With KEK Fragment 2 Non-volatile Memory:Plaintext Until zeroization CLI command KEK Fragment 1:Used With KEK Volatile Memory:Plaintext Until module reboot or power off Reboot Remove power KEK Fragment 1:Derived From KEK Fragment 2:Derived From PEM Key On Disk:Encrypted Until zeroization CLI command KEK:Encrypts PEM Passphrase:Derived From AES Key Exported in encrypted form via part of config backup file Imported in encrypted form via TLS or SSH session Imported in plaintext via local console On Disk:Encrypted Until reboot or power removal Reboot Remove power KEK:Encrypts AES GCM Key Volatile Memory:Plaintext Until module reboot or power off Reboot Remove power HMAC Key Exported in encrypted form via part of config backup file Imported in encrypted form via TLS or SSH session Imported in plaintext via local console On Disk:Encrypted Until zeroization of KEK Zeroization of KEK KEK:Encrypts FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 63 of 87 Name Input - Output Storage Storage Duration Zeroization Related SSPs CA Public Key Exported in plaintext Imported in encrypted form via TLS or SSH session Imported in plaintext via local console On Disk:Plaintext NetScaler detection DH Private Key Volatile Memory:Plaintext Until module reboot, power off, or session termination Reboot Remove power Session termination DH Public Key:Paired With DH Public Key Exported in plaintext Volatile Memory:Plaintext Until module reboot, power off, or session termination Reboot Remove power Session termination DH Private Key:Paired With ECDH Private Key Volatile Memory:Plaintext Until module reboot, power off, or session termination Reboot Remove power Session termination ECDH Public Key :Paired With ECDH Public Key Exported in plaintext Imported in plaintext via local console Volatile Memory:Plaintext Until module reboot, power off, or session termination Reboot Remove power Session termination ECDH Private Key :Paired With RSA Private Key On Disk:Encrypted Until zeroization of KEK Zeroization of KEK KEK:Encrypts RSA Public Key:Paired With RSA Public Key Exported in plaintext Imported in plaintext via local console Volatile Memory:Plaintext NetScaler detection RSA Private Key :Paired With SSH Private Key Exported in encrypted form via part of config backup file On Disk:Plaintext Until zeroization CLI command SSH Public Key:Paired With SSH Public Key Exported in encrypted form via part of config backup file Volatile Memory:Plaintext NetScaler detection SSH Private Key:Paired With SSH Session Key Volatile Memory:Plaintext Until module reboot, power off, or session termination Reboot Remove power Session termination SSH Shared Secret:Derived From SSH Authentication Key Volatile Memory:Plaintext Until module reboot, power off, or session termination Reboot Remove power Session termination SSH Shared Secret:Derived From FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 64 of 87 Name Input - Output Storage Storage Duration Zeroization Related SSPs IKE/IPsec Pre- shared key (PSK) Exported in encrypted form via part of config backup file Imported in plaintext via local console Volatile Memory:Plaintext Until module reboot, power off, or session termination Reboot Remove power Session termination IKE/IPsec Session Key (AES key) Volatile Memory:Plaintext Until module reboot, power off, or session termination Reboot Remove power Session termination IKE/IPsec Pre-shared key (PSK):Derived From IKE/IPsec Shared Secret:Derived From IKE/IPsec Authentication Key (HMAC key) Volatile Memory:Plaintext Until module reboot, power off, or session termination Reboot Remove power Session termination IKE/IPsec Pre-shared key (PSK):Derived From IKE/IPsec Shared Secret:Derived From RDP Session Key Volatile Memory:Plaintext Until module reboot, power off, or session termination Reboot Remove power Session termination RDP PSK (Shared secret):Derived From DFA Session Key Volatile Memory:Plaintext Until module reboot, power off, or session termination Reboot Remove power Session termination DFA Shared Secret:Derived From TLS Private Key Exported in encrypted form via part of config backup file Imported in encrypted form via TLS or SSH session Imported in plaintext via local console On Disk:Encrypted Until zeroization of KEK Zeroization of KEK PEM Key:Encrypts TLS Public Key:Paired With TLS Public Key NetScaler detection TLS Private Key:Paired With TLS Session Key Volatile Memory:Plaintext Until module reboot, power off, or session termination Reboot Remove power Session termination TLS Pre-Master Secret:Derived From TLS Authentication Key (HMAC key) Volatile Memory:Plaintext Until module reboot, power off, or session termination Reboot Remove power Session termination TLS Pre-Master Secret:Derived From TLS Ticket Encryption Key (AES key) Imported in encrypted form via TLS or SSH session Volatile Memory:Plaintext Until module reboot, power off, or session termination Reboot Remove power Session termination TLS Ticket Authentication Key (HMAC key) Imported in encrypted form via TLS or SSH session Volatile Memory:Plaintext Until module reboot, power off, or session termination Reboot Remove power Session termination FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 65 of 87 Name Input - Output Storage Storage Duration Zeroization Related SSPs SNMPv3 Privacy Key (AES key) Volatile Memory:Plaintext Until module reboot, power off, or session termination Reboot Remove power Session termination SNMPv3 Privacy Passphrase :Derived From SNMPv3 Authentication Key (HMAC key) Volatile Memory:Plaintext Until module reboot or power off Reboot Remove power SNMPv3 Authentication Passphrase:Derived From Private DNS KSK (RSA private key) Exported in encrypted form via part of config backup file Imported in encrypted form via TLS or SSH session On Disk:Encrypted Until zeroization of KEK Zeroization of KEK PEM Key:Encrypts Public DNS KSK (RSA public key):Paired With Public DNS KSK (RSA public key) Exported in encrypted form via part of config backup file Imported in encrypted form via TLS or SSH session On Disk:Plaintext NetScaler detection Private DNS KSK (RSA private key):Paired With Private DNS ZSK (RSA private key) Exported in encrypted form via part of config backup file Imported in encrypted form via TLS or SSH session On Disk:Encrypted Until zeroization of KEK Zeroization of KEK PEM Key:Encrypts Public DNS ZSK (RSA public key):Paired With Public DNS ZSK (RSA public key) Exported in encrypted form via part of config backup file Imported in encrypted form via TLS or SSH session On Disk:Plaintext NetScaler detection Private DNS ZSK (RSA private key):Paired With Software Load Integrity Key (RSA public key) Imported in plaintext via local console Volatile Memory:Plaintext Until module reboot or power off Reboot Remove power PEM Passphrase Exported in encrypted form via part of config backup file Imported in plaintext via local console Volatile Memory:Plaintext On Disk:Encrypted Until module reboot or power off Reboot Remove power KEK:Encrypts FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 66 of 87 Name Input - Output Storage Storage Duration Zeroization Related SSPs AES GCM IV (96 and 128-bit IV) Volatile Memory:Plaintext Until module reboot or power off Reboot Remove power SSH Shared Secret Volatile Memory:Plaintext Until module reboot, power off, or session termination Reboot Remove power Session termination TLS Pre-Master Secret Imported in encrypted form via RSA key transport Volatile Memory:Plaintext Until module reboot, power off, or session termination Completion of TLS Session Key and TLS Authentication Key derivation Reboot Remove power TLS Extended Master Secret Volatile Memory:Plaintext Until module reboot, power off, or session termination Reboot Remove power Session termination TLS Pre-Master Secret:Derived From Hash DRBG Entropy Volatile Memory:Plaintext Until module reboot or power off Reboot Remove power Hash DRBG Seed Volatile Memory:Plaintext Until module reboot or power off Reboot Remove power Hash DRBG 'V' Value (Internal state value) Volatile Memory:Plaintext Until module reboot or power off Reboot Remove power Hash DRBG 'C' Value (Internal state value) Volatile Memory:Plaintext Until module reboot or power off Reboot Remove power CTR DRBG Entropy Volatile Memory:Plaintext Until module reboot or power off Reboot Remove power CTR DRBG Seed Volatile Memory:Plaintext Until module reboot or power off Reboot Remove power CTR DRBG 'V' Value Volatile Memory:Plaintext Until module reboot or power off Reboot Remove power CTR DRBG 'Key' Value (AES key) Volatile Memory:Plaintext Until module reboot or power off Reboot Remove power SNMPv3 Privacy Passphrase Exported in encrypted form via part of config backup file Imported in encrypted form via TLS or SSH session Imported in plaintext via local console On Disk:Encrypted Until zeroization of KEK Zeroization of KEK KEK:Encrypts FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 67 of 87 Name Input - Output Storage Storage Duration Zeroization Related SSPs SNMPv3 Authentication Passphrase Exported in encrypted form via part of config backup file Imported in encrypted form via TLS or SSH session Imported in plaintext via local console On Disk:Encrypted Until zeroization of KEK Zeroization of KEK KEK:Encrypts LDAP Admin Password Exported in encrypted form via part of config backup file Imported in encrypted form via TLS or SSH session Imported in plaintext via local console On Disk:Encrypted Until zeroization of KEK Zeroization of KEK KEK:Encrypts ZebOS Router Password Exported in encrypted form via part of config backup file Imported in encrypted form via TLS or SSH session Imported in plaintext via local console On Disk:Encrypted Until zeroization of KEK Zeroization of KEK KEK:Encrypts Cluster Password (Alphanumeric string) Imported in encrypted form via TLS or SSH session Imported in plaintext via local console On Disk:Encrypted Until zeroization of KEK Zeroization of KEK KEK:Encrypts Operator Password Exported in encrypted form via part of config backup file Imported in encrypted form via TLS or SSH session Volatile Memory:Plaintext Until module reboot or power off Reboot Remove power IKE/IPsec Shared Secret Volatile Memory:Plaintext Until module reboot, power off, or session termination Reboot Remove power Session termination FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 68 of 87 Name Input - Output Storage Storage Duration Zeroization Related SSPs DFA Shared Secret Exported in encrypted form via part of config backup file Imported in encrypted form via TLS or SSH session Imported in plaintext via local console On Disk:Encrypted Until zeroization of KEK Zeroization of KEK KEK:Encrypts RDP PSK (Shared secret) Exported in encrypted form via part of config backup file Imported in encrypted form via TLS or SSH session Imported in plaintext via local console On Disk:Encrypted Until zeroization of KEK Zeroization of KEK KEK:Encrypts Oauth Client Secret (Shared secret) Exported in encrypted form via part of config backup file Imported in encrypted form via TLS or SSH session Imported in plaintext via local console On Disk:Encrypted Until zeroization of KEK Zeroization of KEK KEK:Encrypts Table 22: SSP Table 2 9.5 Transitions The following list specifies applicable transition periods or timeframes where an algorithm or key length transitions from Approved to non-Approved: • SHA-1: The module includes implementations of SHA-1 for MAC generation and digital signature verification. SHA-1 will be non-Approved for all uses starting January 1, 2031. FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 69 of 87 10. Self-Tests The module performs pre-operational self-tests and conditional self-tests. Pre-operational tests are performed between the time the cryptographic module is instantiated and before the module transitions to the operational state. Conditional self-tests are performed by the module during module operation when certain conditions exist. The following sections list the self-tests performed by the module, their expected error status, and the error resolutions. 10.1 Pre-Operational Self-Tests The module performs the following pre-operational self-test(s). Algorithm or Test Test Properties Test Method Test Type Indicator Details RSA SigVer (FIPS186-4) (A3943) 2048-bit; SHA2-512 Firmware Integrity SW/FW Integrity "FIPS Post Failed" message in /var/log/ns.log RSA 2048 digital signature verification with SHA2-512 Table 23: Pre-Operational Self-Tests 10.2 Conditional Self-Tests The module performs the following conditional self-tests. Algorithm or Test Test Properties Test Method Test Type Indicator Details Conditions AES-CBC (A3942) 128-bit KAT CAST "POST FAILED" message in /var/log/FIPS- post.log Encrypt / Decrypt After successful completion of firmware integrity test. AES-GCM (A3942) 128-bit KAT CAST "POST FAILED" message in /var/log/FIPS- post.log Encrypt / Decrypt After successful completion of firmware integrity test. Counter DRBG (A3942) KAT CAST "POST FAILED" message in /var/log/FIPS- post.log Instantiate/Generate/Reseed After successful completion of firmware integrity test. KAS-FFC-SSC Sp800-56Ar3 (A3942) KAT CAST "POST FAILED" message in /var/log/FIPS- post.log Primitive "Z" computation test After successful completion of firmware integrity test. KAS-ECC-SSC Sp800-56Ar3 (A3942) KAT CAST "POST FAILED" message in /var/log/FIPS- post.log Primitive "Z" computation test After successful completion of firmware integrity test. ECDSA SigGen (FIPS186-4) (A3942) P-256 KAT CAST "POST FAILED" message in /var/log/FIPS- post.log Sign After successful completion of firmware integrity test. FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 70 of 87 Algorithm or Test Test Properties Test Method Test Type Indicator Details Conditions ECDSA SigVer (FIPS186-4) (A3942) P-256 KAT CAST "POST FAILED" message in /var/log/FIPS- post.log Verify After successful completion of firmware integrity test. HMAC-SHA-1 (A3942) SHA-1 KAT CAST "POST FAILED" message in /var/log/FIPS- post.log Hashed message authentication After successful completion of firmware integrity test. HMAC-SHA2- 256 (A3942) SHA2-256 KAT CAST "POST FAILED" message in /var/log/FIPS- post.log Hashed message authentication After successful completion of firmware integrity test. HMAC-SHA2- 512 (A3942) SHA2-512 KAT CAST "POST FAILED" message in /var/log/FIPS- post.log Hashed message authentication After successful completion of firmware integrity test. PBKDF (A3942) SHA-1 KAT CAST "POST FAILED" message in /var/log/FIPS- post.log After successful completion of firmware integrity test. RSA SigGen (FIPS186-4) (A3942) 2048-bit; SHA2-256 KAT CAST "POST FAILED" message in /var/log/FIPS- post.log Sign Before firmware integrity test RSA SigVer (FIPS186-4) (A3942) 2048-bit; SHA2-256 KAT CAST "POST FAILED" message in /var/log/FIPS- post.log Verify Before firmware integrity test SHA-1 (A3942) KAT CAST "POST FAILED" message in /var/log/FIPS- post.log After successful completion of firmware integrity test. SHA2-256 (A3942) KAT CAST "POST FAILED" message in /var/log/FIPS- post.log After successful completion of firmware integrity test. SHA2-512 (A3942) KAT CAST "POST FAILED" message in /var/log/FIPS- post.log After successful completion of firmware integrity test. KDF IKEv1 (A3942) KAT CAST "POST FAILED" message in /var/log/FIPS- post.log IKEv1 KDF Test After successful completion of firmware integrity test. KDF IKEv2 (A3942) KAT CAST "POST FAILED" message in /var/log/FIPS- post.log IKEv2 KDF Test After successful completion of firmware integrity test. KDF SSH (A3942) KAT CAST "POST FAILED" message in /var/log/FIPS- post.log SSH KDF Test After successful completion of firmware integrity test. TLS v1.2 KDF RFC7627 (A3942) KAT CAST "POST FAILED" message in /var/log/FIPS- post.log TLS v1.2 Test After successful completion of firmware integrity test. FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 71 of 87 Algorithm or Test Test Properties Test Method Test Type Indicator Details Conditions AES-CBC (A3943) 128-bit KAT CAST "FIPS POST Failed" message in /var/log/ns.log Encrypt / Decrypt After successful completion of firmware integrity test. AES-GCM (A3943) 128-bit KAT CAST "FIPS POST Failed" message in /var/log/ns.log Encrypt / Decrypt After successful completion of firmware integrity test. KAS-ECC-SSC Sp800-56Ar3 (A3943) KAT CAST "FIPS POST Failed" message in /var/log/ns.log Primitive "Z" computation test After successful completion of firmware integrity test. ECDSA SigGen (FIPS186-4) (A3943) P-256 KAT CAST "FIPS POST Failed" message in /var/log/ns.log Sign After successful completion of firmware integrity test. ECDSA SigVer (FIPS186-4) (A3943) P-256 KAT CAST "FIPS POST Failed" message in /var/log/ns.log Verify After successful completion of firmware integrity test. Hash DRBG (A3943) AES, 256-bit, with derivation function KAT CAST "FIPS POST Failed" message in /var/log/ns.log Instantiate/Generate/Reseed After successful completion of firmware integrity test. HMAC-SHA-1 (A3943) 128 bits KAT CAST "FIPS POST Failed" message in /var/log/ns.log Hashed message authentication After successful completion of firmware integrity test. HMAC-SHA2- 256 (A3943) 256 bits KAT CAST "FIPS POST Failed" message in /var/log/ns.log Hashed message authentication After successful completion of firmware integrity test. HMAC-SHA2- 512 (A3943) 256 bits KAT CAST "FIPS POST Failed" message in /var/log/ns.log Hashed message authentication After successful completion of firmware integrity test. RSA SigGen (FIPS186-4) (A3943) KAT CAST "FIPS POST Failed" message in /var/log/ns.log Sign Before firmware integrity test RSA SigVer (FIPS186-4) (A3943) KAT CAST "FIPS POST Failed" message in /var/log/ns.log Verify Before firmware integrity test SHA-1 (A3943) KAT CAST "FIPS POST Failed" message in /var/log/ns.log After successful completion of firmware integrity test. SHA2-256 (A3943) KAT CAST "FIPS POST Failed" message in /var/log/ns.log After successful completion of firmware integrity test. SHA2-512 (A3943) KAT CAST "FIPS POST Failed" message in /var/log/ns.log After successful completion of firmware integrity test. FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 72 of 87 Algorithm or Test Test Properties Test Method Test Type Indicator Details Conditions KDF TLS (A3943) KAT CAST "FIPS POST Failed" message in /var/log/ns.log TLS Test After successful completion of firmware integrity test. TLS v1.2 KDF RFC7627 (A3943) KAT CAST "FIPS POST Failed" message in /var/log/ns.log TLS v1.2 Test After successful completion of firmware integrity test. TLS v1.3 KDF (A3943) KAT CAST "FIPS POST Failed" message in /var/log/ns.log TLS v1.3 Test After successful completion of firmware integrity test. SHA3-256 (A3513) KAT CAST "FIPS POST Failed" message in /var/log/ns.log After successful completion of firmware integrity test. AES-CBC (A3944) KAT CAST "FIPS POST Failed" message in /var/log/ns.log Encrypt / Decrypt After successful completion of firmware integrity test. AES-GCM (A3944) KAT CAST "FIPS POST Failed" message in /var/log/ns.log Encrypt / Decrypt After successful completion of firmware integrity test. KAS-ECC-SSC Sp800-56Ar3 (A3944) KAT CAST "POST FAILED" message in /var/log/FIPS- post.log Primitive "Z" computation test After successful completion of firmware integrity test. ECDSA SigGen (FIPS186-4) (A3944) P-256 KAT CAST "POST FAILED" message in /var/log/FIPS- post.log Sign After successful completion of firmware integrity test. ECDSA SigVer (FIPS186-4) (A3944) P-256 KAT CAST "POST FAILED" message in /var/log/FIPS- post.log Verify After successful completion of firmware integrity test. HMAC-SHA-1 (A3944) SHA-1 KAT CAST "POST FAILED" message in /var/log/FIPS- post.log Hashed message authentication After successful completion of firmware integrity test. HMAC-SHA2- 256 (A3944) SHA2-256 KAT CAST "POST FAILED" message in /var/log/FIPS- post.log Hashed message authentication After successful completion of firmware integrity test. HMAC-SHA2- 512 (A3944) SHA2-512 KAT CAST "POST FAILED" message in /var/log/FIPS- post.log Hashed message authentication After successful completion of firmware integrity test. RSA SigGen (FIPS186-4) (A3944) 2048-bit; SHA2-256 KAT CAST "POST FAILED" message in /var/log/FIPS- post.log Sign After successful completion of firmware integrity test. RSA SigVer (FIPS186-4) (A3944) 2048-bit; SHA2-256 KAT CAST "POST FAILED" message in /var/log/FIPS- post.log Verify After successful completion of firmware integrity test. FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 73 of 87 Algorithm or Test Test Properties Test Method Test Type Indicator Details Conditions SHA-1 (A3944) KAT CAST "POST FAILED" message in /var/log/FIPS- post.log After successful completion of firmware integrity test. SHA2-256 (A3944) KAT CAST "POST FAILED" message in /var/log/FIPS- post.log After successful completion of firmware integrity test. SHA2-512 (A3944) KAT CAST "POST FAILED" message in /var/log/FIPS- post.log After successful completion of firmware integrity test. KDF TLS (A3944) KAT CAST "FIPS POST Failed" message in /var/log/ns.log TLS Test After successful completion of firmware integrity test. TLS v1.2 KDF RFC7627 (A3944) KAT CAST "FIPS POST Failed" message in /var/log/ns.log TLS v1.2 Test After successful completion of firmware integrity test. Adaptive Proportion Test Entropy Adaptive Proportion Test Critical Function Message is displayed and logged if errored Adaptive Proportion Test on entropy source After successful completion of firmware integrity test. Repetition Count Test Entropy Repetition Count Test Critical Function Message is displayed and logged if errored Repetition Count Test on entropy source After successful completion of firmware integrity test. ECDSA KeyGen (FIPS186-4) (A3942) PCT PCT Message is displayed and logged if errored Sign/verify Upon generation of a keypair for ECDSA signature functions. RSA KeyGen (FIPS186-4) (A3942) PCT PCT Message is displayed and logged if errored Sign/verify/Encrypt/decrypt Upon generation of a key pair for RSA signature and RSA key transport functions. Firmware Load Test 2048-bit; SHA2-512 Firmware Load Test SW/FW Load Message is displayed and logged if errored RSA signature verification 2048-bit firmware load test Upon performing a firmware update. ECDSA KeyGen (FIPS186-4) (A3944) PCT PCT Message is displayed and logged if errored Sign/verify Upon generation of a key pair for ECDSA signature functions. KBKDF (A3943) KAT CAST "FIPS POST Failed" message in /var/log/ns.log After successful completion of firmware integrity test. KDF TLS (A3942) KAT CAST "POST FAILED" message in /var/log/FIPS- post.log TLS Test After successful completion of firmware integrity test. FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 74 of 87 Algorithm or Test Test Properties Test Method Test Type Indicator Details Conditions ECDSA KeyGen (FIPS186-4) (A3943) PCT PCT Message is displayed and logged if errored Sign/verify Upon generation of a key pair for ECDSA signature functions. Table 24: Conditional Self-Tests 10.3 Periodic Self-Test Information The module permits operators to initiate the pre-operational integrity test and conditional CASTs on demand for periodic testing of the module. The table below specifies the period and the policy for these conditions. Algorithm or Test Test Method Test Type Period Periodic Method RSA SigVer (FIPS186-4) (A3943) Firmware Integrity SW/FW Integrity On Demand Manually Table 25: Pre-Operational Periodic Information Algorithm or Test Test Method Test Type Period Periodic Method AES-CBC (A3942) KAT CAST On Demand Manually AES-GCM (A3942) KAT CAST On Demand Manually Counter DRBG (A3942) KAT CAST On Demand Manually KAS-FFC-SSC Sp800- 56Ar3 (A3942) KAT CAST On Demand Manually KAS-ECC-SSC Sp800- 56Ar3 (A3942) KAT CAST On Demand Manually ECDSA SigGen (FIPS186- 4) (A3942) KAT CAST On Demand Manually ECDSA SigVer (FIPS186- 4) (A3942) KAT CAST On Demand Manually HMAC-SHA-1 (A3942) KAT CAST On Demand Manually HMAC-SHA2-256 (A3942) KAT CAST On Demand Manually HMAC-SHA2-512 (A3942) KAT CAST On Demand Manually PBKDF (A3942) KAT CAST On Demand Manually RSA SigGen (FIPS186-4) (A3942) KAT CAST On Demand Manually RSA SigVer (FIPS186-4) (A3942) KAT CAST On Demand Manually SHA-1 (A3942) KAT CAST On Demand Manually SHA2-256 (A3942) KAT CAST On Demand Manually SHA2-512 (A3942) KAT CAST On Demand Manually KDF IKEv1 (A3942) KAT CAST On Demand Manually KDF IKEv2 (A3942) KAT CAST On Demand Manually KDF SSH (A3942) KAT CAST On Demand Manually TLS v1.2 KDF RFC7627 (A3942) KAT CAST On Demand Manually AES-CBC (A3943) KAT CAST On Demand Manually AES-GCM (A3943) KAT CAST On Demand Manually KAS-ECC-SSC Sp800- 56Ar3 (A3943) KAT CAST On Demand Manually ECDSA SigGen (FIPS186- 4) (A3943) KAT CAST On Demand Manually FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 75 of 87 Algorithm or Test Test Method Test Type Period Periodic Method ECDSA SigVer (FIPS186- 4) (A3943) KAT CAST On Demand Manually Hash DRBG (A3943) KAT CAST On Demand Manually HMAC-SHA-1 (A3943) KAT CAST On Demand Manually HMAC-SHA2-256 (A3943) KAT CAST On Demand Manually HMAC-SHA2-512 (A3943) KAT CAST On Demand Manually RSA SigGen (FIPS186-4) (A3943) KAT CAST On Demand Manually RSA SigVer (FIPS186-4) (A3943) KAT CAST On Demand Manually SHA-1 (A3943) KAT CAST On Demand Manually SHA2-256 (A3943) KAT CAST On Demand Manually SHA2-512 (A3943) KAT CAST On Demand Manually KDF TLS (A3943) KAT CAST On Demand Manually TLS v1.2 KDF RFC7627 (A3943) KAT CAST On Demand Manually TLS v1.3 KDF (A3943) KAT CAST On Demand Manually SHA3-256 (A3513) KAT CAST On Demand Manually AES-CBC (A3944) KAT CAST On Demand Manually AES-GCM (A3944) KAT CAST On Demand Manually KAS-ECC-SSC Sp800- 56Ar3 (A3944) KAT CAST On Demand Manually ECDSA SigGen (FIPS186- 4) (A3944) KAT CAST On Demand Manually ECDSA SigVer (FIPS186- 4) (A3944) KAT CAST On Demand Manually HMAC-SHA-1 (A3944) KAT CAST On Demand Manually HMAC-SHA2-256 (A3944) KAT CAST On Demand Manually HMAC-SHA2-512 (A3944) KAT CAST On Demand Manually RSA SigGen (FIPS186-4) (A3944) KAT CAST On Demand Manually RSA SigVer (FIPS186-4) (A3944) KAT CAST On Demand Manually SHA-1 (A3944) KAT CAST On Demand Manually SHA2-256 (A3944) KAT CAST On Demand Manually SHA2-512 (A3944) KAT CAST On Demand Manually KDF TLS (A3944) KAT CAST On Demand Manually TLS v1.2 KDF RFC7627 (A3944) KAT CAST On Demand Manually Adaptive Proportion Test Entropy Adaptive Proportion Test Critical Function Repetition Count Test Entropy Repetition Count Test Critical Function ECDSA KeyGen (FIPS186-4) (A3942) PCT PCT RSA KeyGen (FIPS186-4) (A3942) PCT PCT Firmware Load Test Firmware Load Test SW/FW Load ECDSA KeyGen (FIPS186-4) (A3944) PCT PCT KBKDF (A3943) KAT CAST On Demand Manually KDF TLS (A3942) KAT CAST On Demand Manually FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 76 of 87 Algorithm or Test Test Method Test Type Period Periodic Method ECDSA KeyGen (FIPS186-4) (A3943) PCT PCT Table 26: Conditional Periodic Information 10.4 Error States If the module enters the critical error state due to a failure of the pre-operational integrity test, the module enters a critical error state and logs an error message. In this state, the boot sequence and entire system is halted. The only action available from this state is to reboot the module to trigger the re-execution of the integrity test. The error condition is considered to have been cleared if the module successfully passes the pre-operational integrity test. If the module continues to return to a halted state, the module is considered to be malfunctioning or compromised, and Cloud Software Group Customer Support must be contacted. If the module enters the critical error state due to a failure of any of the conditional CASTs, cryptographic operations are halted, and the module inhibits all data output from the module. The module logs an error message and automatically reboots to clear the error state. The CO must contact Cloud Software Group if this error occurs. The successful completion or failure of the pre-operational self-tests and conditional CASTs can be verified by checking the log files. • NetScaler Control Plane Cryptographic Library – Successful completion of the self-tests is indicated by “POST Success” in /var/log/FIPS-post.log. Failure is indicated by “POST Failed” in /var/log/FIPS-post.log (both messages indicate a critical error state). • NetScaler Data Plane Cryptographic Library – Successful completion of the self-tests is indicated by “FIPS POST Successful” in /var/log/ns.log. Failure is indicated by “FIPS Post Failed” in /var/log/ns.log (both messages indicate a critical error state). If any of the remaining conditional self-tests fail, the module goes through a soft error state and the following message is displayed: “Internal failure in SSL cert/key generation tool” For these failures, the module returns to an operational state once the message is displayed (and the error is logged). The user may retry the service (which calls the conditional self-test again) or move to other operations. Successful completion of the conditional self-test is indicated by the absence of an error message. The table below describes the error states the status indicators of the module. Name Description Conditions Recovery Method Indicator Critical Error (from pre- operational tests) The booth sequence and entire system is halted. The only action available from this state is to reboot the module to trigger the re-execution of the integrity test. Module fails pre- operational integrity test. The module successfully passes the pre-operational integrity test. If the module continues to return to a halted state, the module is considered to be malfunctioning or compromised, and Cloud Software Group Customer Support must be contacted. Logs "POST Failed" error message in /var/log/FIPS- post.log for NetScaler Control Plane Cryptographic Library. Logs "FIPS Post Failed" in /var/log/ns.log for NetScaler Data Plane Cryptographic Library. FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 77 of 87 Name Description Conditions Recovery Method Indicator Critical Error (from conditional CASTs) Cryptographic operations are halted, and the module inhibits all data output from the module. Module fails any conditional CASTs. The module automatically reboots after logging an error message to clear the error state. The CO must contact Cloud Software Group Support if this error occurs. Logs "POST Failed" error message in /var/log/FIPS- post.log for NetScaler Control Plane Cryptographic Library. Logs "FIPS Post Failed" in /var/log/ns.log for NetScaler Data Plane Cryptographic Library. Soft Error Error that may occur when invoking service that calls the conditional self-test. Module fails any of the remaining conditional self-tests. The module returns to an operational state once the message is displayed, and the error is logged. The user may retry the service or move to other operations. The following message is displayed: "Internal failure in SSL cert/key generation tool". Table 27: Error States FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 78 of 87 11. Life-Cycle Assurance The sections below describe how to ensure the module is operating in its validated configuration, including the following: • Procedures for secure installation, initialization, startup, and operation of the module • Maintenance requirements • Administrator and non-Administrator guidance Operating the module without following the guidance herein (including the use of undocumented services) will result in non-compliant behavior and is outside the scope of this Security Policy. 11.1 Installation, Initialization, and Startup Procedures The module is shipped to the customer in a non-configured state. The CO is responsible for all initial setup activities, including installing and configuring the module firmware. Prior to the installation, the CO should read the document entries within the Citrix ADC 13.1 – Getting Started with Citrix ADC webpage on Citrix’s online product documentation portal. The following sections provide references to step-by-step instructions for the setup and installation of the module, as well as the steps necessary to configure the module for its Approved mode of operation. 11.1.1 Tamper-Evident Seal Inspection When the module is first received, the CO shall confirm placement of all tamper-evident seals (refer to section 7.1 of this document for details regarding label placement). If any seals show signs of tampering, the CO must contact Cloud Software Group Customer Support immediately. 11.1.2 Installation For detailed guidance regarding the installation of the module, please see the Citrix ADC 13.1 – Getting Started with Citrix ADC webpage on the online product documentation portal and refer to the following entries in that document: • Citrix ADC MPX hardware-software compatibility matrix • Prepare for Installation • Install the Hardware The above entries include the MPX support matrix and usage guidelines, prerequisites for setting up the appliance, and installation instructions. To install the required license files, the CO must follow the instructions on the Citrix ADC licensing overview webpage on Citrix’s online product documentation portal. Once the license files are installed, reboot the module so all licenses are applied. FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 79 of 87 11.1.3 Initialization After the NetScaler MPX has been setup and installed, the CO is responsible for the general configuration of the module. The Web GUI or CLI can be used for the general configuration of the module. All general configuration steps must be complete before performing any configuration steps necessary to place the module in the Approved mode of operation. The general configuration requirements and instructions are described in the “Quick Start Installation and Configuration” section of the Citrix ADC Deployment Guide found on Citrix’s online product documentation portal. 11.1.3.1 Approved Mode Configuration and Status The CO is responsible for the security-relevant configuration of the module. To initialize the module for Approved mode of operation, the CO must: • Configure the passphrase requirements • Replace the default TLS certificate • Disable HTTP access to the Web GUI • Enable external authentication • Disable local authentication To accomplish these tasks, the CO must follow the procedures detailed in the sections below (for more information, please see the “Configuration Guidelines” section of the document entry Citrix ADC Deployment Guide. 11.1.3.2 Configure the Passphrase Requirements Passphrases are used to derive keys using PBKDF. The CO must configure strong passphrase requirements. This is accomplished with the following steps from the Web GUI: 1. In the Configuration navigation pane, go to System and click the Settings node. 2. In the Settings section, click the Change Global System Settings link. 3. In the Strong Password field, select Enable All. 4. In the Min Password Length field, type “8”. 5. Click OK. 11.1.3.3 Replace the Default TLS Certificate By default, the module includes a factory-provisioned RSA certificate for TLS connections (ns-server.cert and ns-server.key). This certificate is not intended for use in production deployments and must be replaced. The CO must replace the default certificate with a newly-generated certificate after the initial installation. To replace the default TLS certificate, the CO must follow these steps: 1. Run the following CLI command to set the hostname of the module: set ns hostName [hostname] 2. From the Web GUI, complete the following procedure to create a Certificate Signing Request (CSR): • In the Configuration navigation pane, go to Traffic Management and click the SSL node. • In the SSL Certificates section, click the Create Certificate Request link. FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 80 of 87 • Make sure to provide values for all the required fields marked with an “*” and then click Create. Note that the Common Name field will contain the value of hostname created in step 1 above. 3. Submit the CSR file to a trusted CA. The CSR file is available in the /nsconfig/ssl directory. 4. After receiving the certificate from the trusted CA, copy the file to the /nsconfig/ssl directory. 5. From the Web GUI, navigate to Traffic Management > SSL and choose ns-server-certificate. 6. Click Update. 7. In the Certificate File Name field, choose the certificate file that was received from the CA. Use the Browse option to choose the file that you have received from CA after signing. Choose the Browse > Local option if the file is saved on your workstation/local drive. 8. In the Private Key File Name field, specify the default private key file name (ns-server.key). 9. Select the No Domain Check option. 10. Click OK. For more information, please refer to the Citrix Support Knowledge Center article CTX122521) on Citrix’s online product documentation portal. 11.1.3.4 Disable HTTP Access to the Web GUI The CO protects traffic to the administrative interface and Web GUI, by configuring the module to use HTTPS15 . Once the module has been configured to use new TLS and SSH certificates, disable HTTP access to the GUI management interface with the following CLI command: set ns ip -gui SECUREONLY 11.1.3.5 Enable External Authentication Once the module is configured in Approved mode and the nsroot account is disabled, then external authentication must be configured. Follow the instructions on the Citrix ADC 13.1 – Configuring external user authentication webpage found on the Cloud Software Group online product documentation portal to configure external system authentication. The CO must ensure the following before enabling external authentication: • A secure connection is established with the external authentication service. • Shell access is disabled for all profiles on the external authentication service. 11.1.3.6 Disable Local Authentication The nsroot account is a default account with root CLI access (superuser) privileges that is required for initial configuration. During initial configuration, the CO shall disable local system authentication to block access to all local accounts (including the nsroot account), and the CO must ensure that superuser privileges are not assigned to any user account. To disable local system authentication and enable external system authentication, the CO must run the following CLI command: set system parameter -localauth disabled 15 HTTPS – Hypertext Transfer Protocol Secure FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 81 of 87 11.1.4 Startup No additional startup steps are required to be performed by end-users. 11.2 Administrator Guidance Once installed and configured, the Crypto Officer is responsible for maintaining and monitoring the status of the module to ensure that it is running in its Approved mode. Please refer to this section for guidance that the Crypto Officer must follow to ensure that the module is operating in a Approved manner. 11.2.1 On-Demand Self-Tests Although pre-operational self-tests are performed automatically during module power up, they can also be manually launched on demand. Self-tests can be executed by: • power-cycling the module • using the reset button on the platform (if applicable) • the reboot CLI command • the reboot API method • via the Web GUI by navigating to Configuration > System > System Information and clicking the Reboot button 11.2.2 Zeroization There are many CSPs within the module’s cryptographic boundary including symmetric keys, private keys, public keys, and passphrases. CSPs reside in multiple storage media including the RAM and system memory. All ephemeral keys are zeroized on module reboot, power removal, or session termination. The KEK is stored as plaintext in non-volatile memory. Zeroizing the KEK renders all passphrases and passwords stored in the non-volatile memory unrecoverable, effectively zeroizing them. The KEK is zeroized via the following CLI command: rm system csps -type KEK SSH private keys are stored as plaintext in non-volatile memory. SSH private keys are zeroized via the following CLI command: rm system csps -type SSH_HOST_KEYS The output (indicator) of both zeroization commands above is successful return from the command line without any error showing on the console. If the commands fails, an error will show on the console before returning control to the user. After the module’s integrity test is complete the firmware clears out all values when the signature verification operation is complete (zeroizes temporary values used in the integrity test). FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 82 of 87 11.2.3 Status and Versioning Information The CO shall be responsible for regularly monitoring the module’s status for the Approved mode of operation. When configured according to the CO’s guidance, the module only operates in the Approved mode. Thus, the current status of the module when operational is always in the Approved mode. An operator can view the versioning information by: • using the following CLI commands: show ns info shows details about the software, including software version, enabled and disabled features, and configured network information show ns version shows version and build number of the appliance show ns hardware shows details of the appliance hardware and information such as the host ID16 and serial number • using the RESTful Nitro API with the GET method: https://module-ip-address>/nitro/v5/config/nshardware https://module-ip-address>/nitro/v5/config/nsversion • using the Web GUI by navigating to Configuration > System > System Information This will display general system and hardware information about the device, including the platform version, CPU information, and appliance serial number. Additionally, the Web GUI’s dashboard includes a system overview section with information such as system HA state, system master state, and system uptime. If any irregular activity is noticed or the module is consistently reporting errors, then Cloud Software Group Customer Support should be contacted. 11.2.4 Additional Administrator Policies and Guidance This section notes additional policies below that must be followed by COs: • All private keys (except for SSH private keys) must be stored as PEM files in encrypted format using one of the Approved encryption algorithms listed in Table 3 or Table 5. • Upon successful bootup of the module, the module is configured by default to use only NIST SP 800-52 Rev. 2 recommended cipher suites for TLS connections. If modified, the CO must ensure that only Approved cipher suites are configured while in the Approved mode. It is recommended to use the list of approved TLS cipher suites in section 3.3 of NIST SP 800-52 Rev. 2 as guidance. 16 ID – Identifier FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 83 of 87 • The module must be configured to use PSK-based authentication for IPsec connections. The CO must provide a PSK value when configuring IPsec profiles via the GUI, CLI, or API. Configuring digital certificate- based authentication for IPsec connections is prohibited while in the Approved mode of operation. • Kerberos traffic management/SSO shall not be configured or used in the Approved mode of operation. • The module supports clustering, and it may act as either the cluster coordinator or the cluster node. Once appliances are clustered together, all configuration is done on the cluster coordinator and pushed to nodes within the cluster. For details on configuring clusters, refer to Citrix ADC 13.1 – Clustering. • The CO must ensure that the “Key” and “AutoKey” authentication parameters are not set when adding NTP servers via the GUI, CLI, or API. • If the module’s power is lost and then restored, the CO shall establish a new key for AES GCM encryption. • The module has built-in CA tools used to create self-signed certificates for testing purposes. While the feature does include the generation of keys, those keys are not considered CSPs (as they are not being used for production purposes). The CO must ensure that all certificates are signed using a trusted CA and not by a self-signed certificate. • When performing a firmware update the following steps must be performed: o Load software load integrity key o Load software package o Zeroize SSH keys using rm system csps -type SSH_HOST_KEYS o Run the installation script • The operator shall not enable the LOM port via ADC configuration. • The operator shall perform the zeroization commands as specified in section 11.4.2 Zeroization prior to invoking the “Firmware Load” service. 11.3 Non-Administrator Guidance Operators with the User role do not have the ability to configure sensitive information on the module. They must be diligent to select strong passwords and must not reveal their password to anyone. Additionally, they must be careful to protect any secret or private keys in their possession. FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 84 of 87 12. Mitigation of Other Attacks The module does not claim to mitigate any attacks beyond the FIPS 140-3 Level 2 requirements for this validation. Therefore, per ISO/IEC 19790:2012 section 7.12, requirements for this section are not applicable. FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 85 of 87 Appendix A. Acronyms and Abbreviations Table 28 provides definitions for the acronyms and abbreviations used in this document. Table 28. Acronyms and Abbreviations Acronym Definition AES Advanced Encryption Standard API Application Programming Interface CBC Cipher Block Chaining CCCS Canadian Centre for Cyber Security CMVP Cryptographic Module Validation Program CO Cryptographic Officer CPU Central Processing Unit CSP Critical Security Parameter CTR Counter CVL Component Validation List DEP Default Entry Point DES Data Encryption Standard DH Diffie-Hellman DRBG Deterministic Random Bit Generator ECB Electronic Code Book ECC CDH Elliptic Curve Cryptography Cofactor Diffie-Hellman ECDH Elliptic Curve Diffie-Hellman ECDSA Elliptic Curve Digital Signature Algorithm EMI/EMC Electromagnetic Interference /Electromagnetic Compatibility FIPS Federal Information Processing Standard GCM Galois/Counter Mode GMAC Galois Message Authentication Code HMAC (keyed-) Hash Message Authentication Code KAS Key Agreement Scheme KAT Known Answer Test KTS Key Transport Scheme KW Key Wrap KWP Key Wrap with Padding NIST National Institute of Standards and Technology OS Operating System FIPS 140-3 Non-Proprietary Security Policy, Version 0.2 October 30, 2025 NetScaler MPX 13.1.FIPS ©2025 Cloud Software Group This document may be freely reproduced and distributed whole and intact including this copyright notice. Page 86 of 87 Acronym Definition PCT Pairwise Consistency Test PKCS Public Key Cryptography Standard PSS Probabilistic Signature Scheme RNG Random Number Generator RSA Rivest, Shamir, and Adleman SHA Secure Hash Algorithm SHS Secure Hash Standard SP Special Publication Prepared by: Corsec Security, Inc. 12600 Fair Lakes Circle, Suite 210 Fairfax, VA 22033 United States of America Phone: +1 703 267 6050 Email: info@corsec.com Web: www.corsec.com