Ubuntu 18.04 OpenSSH Server Cryptographic Module

Certificate #3632

Webpage information

Status historical
Historical reason SP 800-56Arev3 transition
Validation dates 12.03.2020 , 14.09.2020 , 21.09.2021 , 18.10.2021
Standard FIPS 140-2
Security level 1
Type Software
Embodiment Multi-Chip Stand Alone
Caveat When operated in FIPS mode and installed, initialized and configured as specified in Section 9.1 of the Security Policy with module Ubuntu 18.04 OpenSSL Cryptographic Module validated to FIPS 140-2 under Cert. #3622 operating in FIPS mode
Exceptions
  • Physical Security: N/A
  • Mitigation of Other Attacks: N/A
Description The Ubuntu 18.04 OpenSSH Server cryptographic module provides the server-side component for an SSH protocol version 2 protected communication channel. Its cryptographic mechanisms use the OpenSSL library in FIPS 140-2 mode.
Tested configurations
  • Ubuntu 18.04 LTS 64-bit on IBM z/VM running on IBM z/14 with z14 with PAI
  • Ubuntu 18.04 LTS 64-bit on IBM z/VM running on IBM z/14 with z14 without PAI (single-user mode)
  • Ubuntu 18.04 LTS 64-bit running on Supermicro SYS-5018R-WR with Intel Xeon CPU E5-2620v3 with PAA
  • Ubuntu 18.04 LTS 64-bit running on Supermicro SYS-5018R-WR with Intel Xeon CPU E5-2620v3 without PAA
Vendor Canonical Ltd.
References

This certificate's webpage directly references 1 certificates, transitively this expands into 1 certificates.

Security policy

Symmetric Algorithms
AES, AES-128, AES-192, AES-256, DES, Triple-DES, HMAC, HMAC-SHA-256, HMAC-SHA-512
Asymmetric Algorithms
ECDSA, ECC, Diffie-Hellman, DSA
Hash functions
SHA-1, SHA-256, SHA-384, SHA-512
Schemes
MAC, Key Exchange, Key Agreement
Protocols
SSH, SSHv2
Randomness
DRBG
Libraries
OpenSSL
Elliptic Curves
P-256, P-384, P-521
Block cipher modes
CBC, CTR, GCM

Security level
Level 1, level 1

Standards
FIPS 140-2, FIPS PUB 140-2, FIPS140-2, RFC4253, RFC4344, RFC5647, RFC6668, RFC4419, RFC8268, RFC5656

File metadata

Title FIPS 140-2 Non-Proprietary Security Policy
Author Alejandro Fabio Masino
Creation date D:20210915191741+00'00'
Modification date D:20210915191741+00'00'
Pages 31
Creator Microsoft Word

References

Outgoing
  • 3622 - historical - Ubuntu 18.04 OpenSSL Cryptographic Module

Heuristics

No heuristics are available for this certificate.

References

Loading...

Updates Feed

  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 3632,
  "dgst": "37df889efd442031",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "HMAC#C688",
        "CVL#C740",
        "AES#C680",
        "CVL#C684",
        "AES#C678",
        "RSA#C685",
        "SHS#C684",
        "DRBG#C677",
        "HMAC#C685",
        "HMAC#C687",
        "AES#C670",
        "SHS#C687",
        "AES#C679",
        "CVL#C682",
        "DSA#C684",
        "DSA#C683",
        "SHS#C682",
        "DRBG#C673",
        "RSA#C688",
        "DRBG#C670",
        "RSA#C682",
        "ECDSA#C688",
        "ECDSA#C685",
        "DSA#C687",
        "CVL#C683",
        "HMAC#C683",
        "DRBG#C688",
        "DRBG#C687",
        "DSA#C688",
        "AES#C692",
        "DSA#C685",
        "RSA#C683",
        "AES#C689",
        "AES#C672",
        "AES#C675",
        "AES#C674",
        "CVL#C687",
        "AES#C676",
        "SHS#C688",
        "RSA#C684",
        "ECDSA#C683",
        "CVL#C688",
        "SHS#C683",
        "AES#C688",
        "DSA#C682",
        "Triple-DES#C686",
        "RSA#C687",
        "AES#C687",
        "Triple-DES#C669",
        "AES#C690",
        "AES#C677",
        "ECDSA#C684",
        "HMAC#C682",
        "CVL#C741",
        "AES#C671",
        "CVL#C685",
        "AES#C673",
        "HMAC#C684",
        "AES#C691",
        "SHS#C685",
        "ECDSA#C682",
        "ECDSA#C687"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "18.04"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": {
        "_type": "Set",
        "elements": [
          "3622"
        ]
      },
      "indirectly_referenced_by": null,
      "indirectly_referencing": {
        "_type": "Set",
        "elements": [
          "3622"
        ]
      }
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": [
        "3622"
      ]
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": {
        "_type": "Set",
        "elements": [
          "3622"
        ]
      },
      "indirectly_referenced_by": null,
      "indirectly_referencing": {
        "_type": "Set",
        "elements": [
          "3622"
        ]
      }
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": [
        "3622"
      ]
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 1
          },
          "ECDSA": {
            "ECDSA": 6
          }
        },
        "FF": {
          "DH": {
            "Diffie-Hellman": 26
          },
          "DSA": {
            "DSA": 8
          }
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 9
        },
        "CTR": {
          "CTR": 6
        },
        "GCM": {
          "GCM": 4
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {
        "OpenSSL": {
          "OpenSSL": 38
        }
      },
      "crypto_protocol": {
        "SSH": {
          "SSH": 42,
          "SSHv2": 10
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 2
        },
        "KEX": {
          "Key Exchange": 3
        },
        "MAC": {
          "MAC": 4
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-256": 6,
          "P-384": 6,
          "P-521": 6
        }
      },
      "eval_facility": {
        "atsec": {
          "atsec": 33
        }
      },
      "fips_cert_id": {
        "Cert": {
          "#3622": 1
        }
      },
      "fips_certlike": {
        "Certlike": {
          "AES-128": 1,
          "AES-192": 1,
          "AES-256": 1,
          "Cert. AES": 1,
          "HMAC SHA-1": 1,
          "HMAC-SHA-1": 2,
          "HMAC-SHA-256": 6,
          "HMAC-SHA-512": 2,
          "SHA- 256": 1,
          "SHA- 384": 2,
          "SHA- 512": 3,
          "SHA- 512 1024": 1,
          "SHA- 512 2048": 2,
          "SHA-1": 8,
          "SHA-1 1024": 1,
          "SHA-256": 13,
          "SHA-384": 2,
          "SHA-512": 7
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 3,
          "level 1": 3
        }
      },
      "hash_function": {
        "SHA": {
          "SHA1": {
            "SHA-1": 9
          },
          "SHA2": {
            "SHA-256": 13,
            "SHA-384": 2,
            "SHA-512": 7
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 3
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-2": 45,
          "FIPS PUB 140-2": 2,
          "FIPS140-2": 1
        },
        "RFC": {
          "RFC4253": 5,
          "RFC4344": 3,
          "RFC4419": 1,
          "RFC5647": 2,
          "RFC5656": 3,
          "RFC6668": 2,
          "RFC8268": 3
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 13,
            "AES-128": 1,
            "AES-192": 1,
            "AES-256": 1
          }
        },
        "DES": {
          "3DES": {
            "Triple-DES": 5
          },
          "DES": {
            "DES": 1
          }
        },
        "constructions": {
          "MAC": {
            "HMAC": 9,
            "HMAC-SHA-256": 3,
            "HMAC-SHA-512": 1
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "Alejandro Fabio Masino",
      "/CreationDate": "D:20210915191741+00\u002700\u0027",
      "/Creator": "Microsoft Word",
      "/ModDate": "D:20210915191741+00\u002700\u0027",
      "/Title": "FIPS 140-2 Non-Proprietary Security Policy",
      "pdf_file_size_bytes": 628669,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=11042",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=11043",
          "http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-135r1.pdf",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=11047",
          "http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90Ar1.pdf",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=11033",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=11041",
          "http://csrc.nist.gov/groups/STM/cmvp/documents/fips140-2/FIPS1402IG.pdf",
          "http://csrc.nist.gov/publications/fips/fips140-2/fips1402.pdf",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=11034",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=11036",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=11045",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=11031",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?validation=31136",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=11029",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=11048",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=11050",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=11030",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=11040",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=11037",
          "http://csrc.nist.gov/groups/STM/cmvp/documents/140-1/140sp/140sp2888.pdf",
          "https://www.ubuntu.com/contact-us",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?validation=31065",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=11035",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=11046",
          "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar2.pdf",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=11038",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=11044",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=11049",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=11028",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?validation=31137",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=11032"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 31
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
    "module_download_ok": true,
    "module_extract_ok": true,
    "policy_convert_ok": true,
    "policy_download_ok": true,
    "policy_extract_ok": true,
    "policy_json_hash": null,
    "policy_pdf_hash": "29491c5e2ab35fe7fa3c9211f645ce95bbc87f4abe84425ae03660e939714ae9",
    "policy_txt_hash": "d7b34686facaf27c521d47881f07b6e47b32dccb670440e7a42a0715c33d27b5"
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in FIPS mode and installed, initialized and configured as specified in Section 9.1 of the Security Policy with module Ubuntu 18.04 OpenSSL Cryptographic Module validated to FIPS 140-2 under Cert. #3622 operating in FIPS mode",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/March 2020_160420.pdf",
    "date_sunset": null,
    "description": "The Ubuntu 18.04 OpenSSH Server cryptographic module provides the server-side component for an SSH protocol version 2 protected communication channel. Its cryptographic mechanisms use the OpenSSL library in FIPS 140-2 mode.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Physical Security: N/A",
      "Mitigation of Other Attacks: N/A"
    ],
    "fw_versions": null,
    "historical_reason": "SP 800-56Arev3 transition",
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {
      "3622": 1
    },
    "module_name": "Ubuntu 18.04 OpenSSH Server Cryptographic Module",
    "module_type": "Software",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-2",
    "status": "historical",
    "sw_versions": "2.1",
    "tested_conf": [
      "Ubuntu 18.04 LTS 64-bit on IBM z/VM running on IBM z/14 with z14 with PAI",
      "Ubuntu 18.04 LTS 64-bit on IBM z/VM running on IBM z/14 with z14 without PAI (single-user mode)",
      "Ubuntu 18.04 LTS 64-bit running on Supermicro SYS-5018R-WR with Intel Xeon CPU E5-2620v3 with PAA",
      "Ubuntu 18.04 LTS 64-bit running on Supermicro SYS-5018R-WR with Intel Xeon CPU E5-2620v3 without PAA"
    ],
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2020-03-12",
        "lab": "atsec information security corporation",
        "validation_type": "Initial"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2020-09-14",
        "lab": "atsec information security corporation",
        "validation_type": "Update"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2021-09-21",
        "lab": "atsec information security corporation",
        "validation_type": "Update"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2021-10-18",
        "lab": "atsec information security corporation",
        "validation_type": "Update"
      }
    ],
    "vendor": "Canonical Ltd.",
    "vendor_url": "http://www.canonical.com"
  }
}