Oracle Linux Unbreakable Enterprise Kernel (UEK) Cryptographic Module

Certificate #3348

Webpage information

Status historical
Historical reason Moved to historical list due to dependency on certificate #3111
Validation dates 02.01.2019
Standard FIPS 140-2
Security level 1
Type Software
Embodiment Multi-Chip Stand Alone
Caveat When operated in FIPS mode with module Oracle Linux NSS Cryptographic Module validated to FIPS 140-2 under Certs. #3111[1] and #3143[2] operating in FIPS mode. The module generates random strings whose strengths are modified by available entropy
Exceptions
  • Physical Security: N/A
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A
Description Oracle Linux Unbreakable Enterprise Kernel Cryptographic Module provides general-purpose cryptographic services to the remainder of the Linux kernel.
Tested configurations
  • Oracle Linux 6.9 64 bit running on Oracle Server X6-2 with Intel(R) Xeon(R) CPU E5-2699 v4 with PAA [1]
  • Oracle Linux 6.9 64 bit running on Oracle Server X6-2 with Intel(R) Xeon(R) CPU E5-2699 v4 without PAA [1]
  • Oracle Linux 6.9 64 bit running on Oracle Server X7-2 with Intel(R) Xeon(R) Silver 4114 with PAA [1]
  • Oracle Linux 6.9 64 bit running on Oracle Server X7-2 with Intel(R) Xeon(R) Silver 4114 without PAA [1]
  • Oracle Linux 7.3 64 bit running on Oracle Server X6-2 with Intel(R) Xeon(R) CPU E5-2699 v4 with PAA [2]
  • Oracle Linux 7.3 64 bit running on Oracle Server X6-2 with Intel(R) Xeon(R) CPU E5-2699 v4 without PAA [2]
  • Oracle Linux 7.3 64 bit running on Oracle Server X7-2 with Intel(R) Xeon(R) Silver 4114 with PAA [2]
  • Oracle Linux 7.3 64 bit running on Oracle Server X7-2 with Intel(R) Xeon(R) Silver 4114 without PAA [2] (single-user mode)
Vendor Oracle Corporation
References

This certificate's webpage directly references 2 certificates, transitively this expands into 2 certificates.

Security policy

Symmetric Algorithms
AES, AES-128, AES-192, AES-256, DES, Triple-DES, TDEA, HMAC, HMAC-SHA-512
Asymmetric Algorithms
ECDH, ECDSA, DH, DHE, Diffie-Hellman
Hash functions
SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, PBKDF
Schemes
Key Exchange
Protocols
IKE, IPsec
Randomness
PRNG, DRBG, RNG
Libraries
NSS
Block cipher modes
ECB, CBC, CTR, GCM, CCM, XTS

Vendor
Huawei, Cisco

Security level
Level 1, level 1

Standards
FIPS 140-2, FIPS 140, FIPS PUB 140-2, FIPS PUB 197, FIPS PUB 198-1, FIPS PUB 186-4, FIPS PUB 180-4, NIST SP 800-90A, SP 800-90A, NIST SP 800-67, NIST SP 800-131A, PKCS#1, RFC3686, RFC4106

File metadata

Title Microsoft Word - Oracle Unbreakable Kernel Security Policy20181207.docx
Creation date D:20181207214902Z00'00'
Modification date D:20181207214902Z00'00'
Pages 35
Creator Word
Producer Mac OS X 10.13.5 Quartz PDFContext

References

Outgoing
  • 3111 - historical - Oracle Linux 6 NSS Cryptographic Module
  • 3143 - historical - Oracle Linux 7 NSS Cryptographic Module

Heuristics

No heuristics are available for this certificate.

References

Loading...

Updates Feed

  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 3348,
  "dgst": "33d88765a856314f",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "DRBG#2092",
        "AES#5403",
        "DRBG#2273",
        "SHS#4512",
        "SHS#4336",
        "SHS#4337",
        "DRBG#2271",
        "DRBG#2268",
        "AES#5615",
        "AES#5621",
        "HMAC#3077",
        "Triple-DES#2830",
        "AES#5423",
        "AES#5637",
        "RSA#3028",
        "DRBG#2257",
        "RSA#3032",
        "RSA#3025",
        "Triple-DES#2831",
        "AES#5632",
        "DRBG#2267",
        "DRBG#2254",
        "AES#5624",
        "AES#5638",
        "AES#5622",
        "HMAC#3753",
        "RSA#3026",
        "HMAC#3578",
        "HMAC#3755",
        "SHS#4515",
        "HMAC#3577",
        "HMAC#3754",
        "SHS#4511",
        "RSA#3024",
        "RSA#3022",
        "DRBG#2270",
        "DRBG#2259",
        "SHS#4510",
        "DRBG#2266",
        "HMAC#3744",
        "AES#5401",
        "DRBG#2272",
        "AES#5618",
        "DRBG#2100",
        "DRBG#2260",
        "HMAC#3748",
        "RSA#3030",
        "Triple-DES#2827",
        "DRBG#2274",
        "DRBG#2097",
        "AES#5627",
        "HMAC#3767",
        "Triple-DES#2829",
        "AES#5400",
        "AES#5629",
        "DRBG#2255",
        "AES#5626",
        "DRBG#2263",
        "DRBG#2099",
        "HMAC#3746",
        "HMAC#3574",
        "DRBG#2093",
        "SHS#4518",
        "SHS#4514",
        "SHS#4521",
        "HMAC#3751",
        "HMAC#3750",
        "AES#5425",
        "AES#5633",
        "SHS#4513",
        "RSA#2889",
        "SHS#4516",
        "SHS#4331",
        "AES#5402",
        "HMAC#3628",
        "HMAC#3575",
        "RSA#3027",
        "DRBG#2262",
        "AES#5614",
        "AES#5628",
        "RSA#2887",
        "DRBG#2101",
        "DRBG#2265",
        "DRBG#2258",
        "AES#5623",
        "AES#5634",
        "AES#5617",
        "SHS#4519",
        "RSA#3021",
        "RSA#3023",
        "RSA#3029",
        "RSA#2888",
        "HMAC#3749",
        "DRBG#2261",
        "AES#5620",
        "RSA#3031",
        "DRBG#2269",
        "AES#5625",
        "SHS#4520",
        "DRBG#2098",
        "DRBG#2264",
        "AES#5398",
        "HMAC#3745",
        "HMAC#3747",
        "RSA#2886",
        "DRBG#2256",
        "Triple-DES#2826",
        "SHS#4517",
        "AES#5635",
        "HMAC#3752",
        "AES#5424",
        "AES#5631",
        "Triple-DES#2828",
        "AES#5630",
        "AES#5636",
        "SHS#4330",
        "HMAC#3184",
        "AES#5619",
        "Triple-DES#2728",
        "Triple-DES#2721"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "-"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": {
        "_type": "Set",
        "elements": [
          "3111",
          "3143"
        ]
      },
      "indirectly_referenced_by": null,
      "indirectly_referencing": {
        "_type": "Set",
        "elements": [
          "3111",
          "3143"
        ]
      }
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": [
        "3111",
        "3143"
      ]
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": {
        "_type": "Set",
        "elements": [
          "3111",
          "3143"
        ]
      },
      "indirectly_referenced_by": null,
      "indirectly_referencing": {
        "_type": "Set",
        "elements": [
          "3111",
          "3143"
        ]
      }
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": [
        "3111",
        "3143"
      ]
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECDH": {
            "ECDH": 1
          },
          "ECDSA": {
            "ECDSA": 1
          }
        },
        "FF": {
          "DH": {
            "DH": 1,
            "DHE": 1,
            "Diffie-Hellman": 1
          }
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 10
        },
        "CCM": {
          "CCM": 4
        },
        "CTR": {
          "CTR": 14
        },
        "ECB": {
          "ECB": 10
        },
        "GCM": {
          "GCM": 13
        },
        "XTS": {
          "XTS": 7
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {
        "NSS": {
          "NSS": 8
        }
      },
      "crypto_protocol": {
        "IKE": {
          "IKE": 1
        },
        "IPsec": {
          "IPsec": 3
        }
      },
      "crypto_scheme": {
        "KEX": {
          "Key Exchange": 1
        }
      },
      "device_model": {},
      "ecc_curve": {},
      "eval_facility": {
        "atsec": {
          "atsec": 1
        }
      },
      "fips_cert_id": {
        "Cert": {
          "#3111": 1,
          "#3143": 1
        }
      },
      "fips_certlike": {
        "Certlike": {
          "AES-128": 3,
          "AES-192": 3,
          "AES-256": 3,
          "HMAC-SHA-512": 8,
          "HMAC-SHA1": 8,
          "HMAC-SHA224": 8,
          "HMAC-SHA256": 8,
          "HMAC-SHA384": 8,
          "HMAC-SHA512": 10,
          "PKCS#1": 4,
          "SHA (1": 8,
          "SHA-1": 15,
          "SHA-224": 4,
          "SHA-256": 13,
          "SHA-384": 12,
          "SHA-512": 14
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 3,
          "level 1": 3
        }
      },
      "hash_function": {
        "PBKDF": {
          "PBKDF": 1
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 15
          },
          "SHA2": {
            "SHA-224": 4,
            "SHA-256": 13,
            "SHA-384": 12,
            "SHA-512": 14
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 15,
          "PRNG": 1
        },
        "RNG": {
          "RNG": 5
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140": 3,
          "FIPS 140-2": 28,
          "FIPS PUB 140-2": 10,
          "FIPS PUB 180-4": 1,
          "FIPS PUB 186-4": 1,
          "FIPS PUB 197": 1,
          "FIPS PUB 198-1": 1
        },
        "NIST": {
          "NIST SP 800-131A": 1,
          "NIST SP 800-67": 1,
          "NIST SP 800-90A": 3,
          "SP 800-90A": 3
        },
        "PKCS": {
          "PKCS#1": 2
        },
        "RFC": {
          "RFC3686": 1,
          "RFC4106": 1
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 14,
            "AES-128": 3,
            "AES-192": 3,
            "AES-256": 3
          }
        },
        "DES": {
          "3DES": {
            "TDEA": 1,
            "Triple-DES": 7
          },
          "DES": {
            "DES": 3
          }
        },
        "constructions": {
          "MAC": {
            "HMAC": 22,
            "HMAC-SHA-512": 4
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {
        "Cisco": {
          "Cisco": 23
        },
        "Huawei": {
          "Huawei": 7
        }
      },
      "vulnerability": {}
    },
    "policy_metadata": {
      "/CreationDate": "D:20181207214902Z00\u002700\u0027",
      "/Creator": "Word",
      "/ModDate": "D:20181207214902Z00\u002700\u0027",
      "/Producer": "Mac OS X 10.13.5 Quartz PDFContext",
      "/Title": "Microsoft Word - Oracle Unbreakable Kernel Security Policy20181207.docx",
      "pdf_file_size_bytes": 707004,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": []
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 35
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.InternalState",
    "module": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "policy": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": "f05c0454e35bac962a892ea103604073caa47569dfe939942553e3c3b33cfdee",
      "txt_hash": "79c3da2bd5cba63755fcd54a634ccee7f40b489dc26e4c5ad14afdb79f599b3f"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in FIPS mode with module Oracle Linux NSS Cryptographic Module validated to FIPS 140-2 under Certs. #3111[1] and #3143[2] operating in FIPS mode. The module generates random strings whose strengths are modified by available entropy",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/JanuaryConsolidatedCert.pdf",
    "date_sunset": null,
    "description": "Oracle Linux Unbreakable Enterprise Kernel Cryptographic Module provides general-purpose cryptographic services to the remainder of the Linux kernel.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Physical Security: N/A",
      "Design Assurance: Level 3",
      "Mitigation of Other Attacks: N/A"
    ],
    "fw_versions": null,
    "historical_reason": "Moved to historical list due to dependency on certificate #3111",
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {
      "3111": 1,
      "3143": 1
    },
    "module_name": "Oracle Linux Unbreakable Enterprise Kernel (UEK) Cryptographic Module",
    "module_type": "Software",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-2",
    "status": "historical",
    "sw_versions": "R6-1.0.0[1] and R7-2.0.0[2]",
    "tested_conf": [
      "Oracle Linux 6.9 64 bit running on Oracle Server X6-2 with Intel(R) Xeon(R) CPU E5-2699 v4 with PAA [1]",
      "Oracle Linux 6.9 64 bit running on Oracle Server X6-2 with Intel(R) Xeon(R) CPU E5-2699 v4 without PAA [1]",
      "Oracle Linux 6.9 64 bit running on Oracle Server X7-2 with Intel(R) Xeon(R) Silver 4114 with PAA [1]",
      "Oracle Linux 6.9 64 bit running on Oracle Server X7-2 with Intel(R) Xeon(R) Silver 4114 without PAA [1]",
      "Oracle Linux 7.3 64 bit running on Oracle Server X6-2 with Intel(R) Xeon(R) CPU E5-2699 v4 with PAA [2]",
      "Oracle Linux 7.3 64 bit running on Oracle Server X6-2 with Intel(R) Xeon(R) CPU E5-2699 v4 without PAA [2]",
      "Oracle Linux 7.3 64 bit running on Oracle Server X7-2 with Intel(R) Xeon(R) Silver 4114 with PAA [2]",
      "Oracle Linux 7.3 64 bit running on Oracle Server X7-2 with Intel(R) Xeon(R) Silver 4114 without PAA [2] (single-user mode)"
    ],
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2019-01-02",
        "lab": "atsec information security corporation",
        "validation_type": "Initial"
      }
    ],
    "vendor": "Oracle Corporation",
    "vendor_url": "http://www.oracle.com"
  }
}