NetApp Cryptographic Security Module

Certificate #2648

Webpage information

Status historical
Historical reason SP 800-56Arev3 transition - replaced by certificate #4297
Validation dates 27.05.2016 , 10.06.2016 , 29.10.2019 , 10.02.2021 , 20.07.2021
Standard FIPS 140-2
Security level 1
Type Software
Embodiment Multi-Chip Stand Alone
Caveat When operated in FIPS mode. No assurance of the minimum strength of generated keys.
Exceptions
  • Physical Security: N/A
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A
Description The NetApp Cryptographic Security Module is a software library that provides cryptographic services to a vast array of NetApp's storage and networking products.
Tested configurations
  • Debian Linux 8 running on Fujitsu RX200S5 Server with Intel Xeon E5-2609V4 (Broadwell) with PAA
  • Debian Linux 8 running on Fujitsu RX300-S6 Server with Intel Xeon E5645 (Westmere EP) without PAA
  • FreeBSD 9.1 running on Fujitsu RX200S5 Server with Intel Xeon E5-2609V4 (Broadwell) with PAA
  • FreeBSD 9.1 running on Fujitsu RX300-S6 Server with Intel Xeon E5645 (Westmere EP) without PAA
  • ONTAP 9.7P6 running on FAS2650 with Intel Xeon D-1528 with PAA
  • ONTAP 9.7P6 running on FAS2650 with Intel Xeon D-1528 without PAA
  • ONTAP 9.7P6 running on NetApp AFF A800 with Intel Xeon Platinum 8160 with PAA
  • ONTAP 9.7P6 running on NetApp AFF A800 with Intel Xeon Platinum 8160 without PAA
  • ONTAP 9.7P6 running on NetApp FAS8300 with Intel Xeon Silver 4210 with PAA
  • ONTAP 9.7P6 running on NetApp FAS8300 with Intel Xeon Silver 4210 without PAA
  • ONTAP 9.7P6 running on NetApp FAS9000 with Intel Xeon E5-2697 with PAA
  • ONTAP 9.7P6 running on NetApp FAS9000 with Intel Xeon E5-2697 without PAA (single-user mode)
  • Scientific Linux 6.1 running on Fujitsu RX200S5 Server with Intel Xeon E5-2609V4 (Broadwell) with PAA
  • Scientific Linux 6.1 running on Fujitsu RX300-S6 Server with Intel Xeon E5645 (Westmere EP) without PAA
  • SUSE Linux 11 running on Fujitsu RX200S5 Server with Intel Xeon E5-2609V4 (Broadwell) with PAA
  • SUSE Linux 11 running on Fujitsu RX300-S6 Server with Intel Xeon E5645 (Westmere EP) without PAA
Vendor NetApp, Inc.
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Symmetric Algorithms
AES, DES, Triple-DES, HMAC, CMAC
Asymmetric Algorithms
ECDH, ECDSA, DH, Diffie-Hellman, DSA
Hash functions
SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, SHA-2
Schemes
Key agreement
Protocols
SSH, TLS, TLS 1.2
Randomness
DRBG
Elliptic Curves
P-224, P-384, P-192, P-256, P-521, K-233, K-409, B-233, B-409, K-283, K-571, B-283, B-571
Block cipher modes
ECB, CBC, CTR, OFB, GCM, CCM, XTS

Security level
Level 1, level 1, Level 3, Level 2

Standards
FIPS 140-2, FIPS PUB 140-2, FIPS 186-4, SP 800-133, SP 800-52, NIST SP 800-38D, NIST SP 800-90A, SP 800-56A, RFC 5288, RFC 5246

File metadata

Author ehackleman
Creation date D:20210606204434-07'00'
Modification date D:20210606204434-07'00'
Pages 23
Creator Microsoft® Word for Microsoft 365
Producer Microsoft® Word for Microsoft 365

References

Incoming
  • 2484 - historical - SUSE Linux Enterprise Server 12 - StrongSwan Cryptographic Module
  • 2471 - historical - SUSE Linux Enterprise Server 12 - OpenSSH Server Module
  • 2472 - historical - SUSE Linux Enterprise Server 12 - OpenSSH Client Module

Heuristics

No heuristics are available for this certificate.

References

Loading...

Updates Feed

  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 2648,
  "dgst": "3a3a99897cabe3d5",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "Triple-DES#A950",
        "DSA#998",
        "SHS#2955",
        "DSA#A950",
        "DRBG#928",
        "CVL#A950",
        "ECDSA#732",
        "AES#3593",
        "RSA#1847",
        "SHS#A950",
        "HMAC#A950",
        "AES#A950",
        "CVL#615",
        "RSA#A950",
        "HMAC#2290",
        "ECDSA#A950",
        "DRBG#A950",
        "Triple-DES#2000"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "-"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": {
        "_type": "Set",
        "elements": [
          "2484",
          "2472",
          "2471"
        ]
      },
      "directly_referencing": null,
      "indirectly_referenced_by": {
        "_type": "Set",
        "elements": [
          "2472",
          "2471",
          "3099",
          "2484",
          "2549"
        ]
      },
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECDH": {
            "ECDH": 5
          },
          "ECDSA": {
            "ECDSA": 10
          }
        },
        "FF": {
          "DH": {
            "DH": 3,
            "Diffie-Hellman": 5
          },
          "DSA": {
            "DSA": 10
          }
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 1
        },
        "CCM": {
          "CCM": 2
        },
        "CTR": {
          "CTR": 2
        },
        "ECB": {
          "ECB": 4
        },
        "GCM": {
          "GCM": 5
        },
        "OFB": {
          "OFB": 2
        },
        "XTS": {
          "XTS": 1
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "SSH": {
          "SSH": 1
        },
        "TLS": {
          "TLS": {
            "TLS": 1,
            "TLS 1.2": 1
          }
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key agreement": 1
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "B-233": 5,
          "B-283": 4,
          "B-409": 5,
          "B-571": 3,
          "K-233": 5,
          "K-283": 4,
          "K-409": 5,
          "K-571": 4,
          "P-192": 2,
          "P-224": 12,
          "P-256": 6,
          "P-384": 12,
          "P-521": 6
        }
      },
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "#615": 1
        }
      },
      "fips_certlike": {
        "Certlike": {
          "AES 128/192/256": 1,
          "HMAC-SHA-1": 2,
          "HMAC-SHA1": 6,
          "HMAC-SHA224": 4,
          "HMAC-SHA256": 4,
          "HMAC-SHA384": 4,
          "HMAC-SHA512": 4,
          "PAA 10": 1,
          "PAA 11": 1,
          "PAA 12": 1,
          "PAA 2": 1,
          "PAA 3": 1,
          "PAA 4": 1,
          "PAA 5": 1,
          "PAA 6": 1,
          "PAA 7": 1,
          "PAA 8": 1,
          "PAA 9": 1,
          "SHA 1847": 1,
          "SHA(1": 14,
          "SHA(224": 5,
          "SHA(256": 8,
          "SHA- 224": 1,
          "SHA-1": 1,
          "SHA-1, 224": 15,
          "SHA-2": 1,
          "SHA-224": 12,
          "SHA-256": 1,
          "SHA-384": 1,
          "SHA-512": 1
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 3,
          "Level 2": 1,
          "Level 3": 1,
          "level 1": 3
        }
      },
      "hash_function": {
        "SHA": {
          "SHA1": {
            "SHA-1": 16
          },
          "SHA2": {
            "SHA-2": 1,
            "SHA-224": 12,
            "SHA-256": 1,
            "SHA-384": 1,
            "SHA-512": 1
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 9
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-2": 41,
          "FIPS 186-4": 7,
          "FIPS PUB 140-2": 1
        },
        "NIST": {
          "NIST SP 800-38D": 1,
          "NIST SP 800-90A": 3,
          "SP 800-133": 2,
          "SP 800-52": 1,
          "SP 800-56A": 1
        },
        "RFC": {
          "RFC 5246": 1,
          "RFC 5288": 1
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 13
          }
        },
        "DES": {
          "3DES": {
            "Triple-DES": 10
          },
          "DES": {
            "DES": 2
          }
        },
        "constructions": {
          "MAC": {
            "CMAC": 3,
            "HMAC": 6
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "ehackleman",
      "/CreationDate": "D:20210606204434-07\u002700\u0027",
      "/Creator": "Microsoft\u00ae Word for Microsoft 365",
      "/ModDate": "D:20210606204434-07\u002700\u0027",
      "/Producer": "Microsoft\u00ae Word for Microsoft 365",
      "pdf_file_size_bytes": 572992,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "http://csrc.nist.gov/groups/STM/index.html"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 23
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
    "module_download_ok": true,
    "module_extract_ok": true,
    "policy_convert_ok": true,
    "policy_download_ok": true,
    "policy_extract_ok": true,
    "policy_json_hash": null,
    "policy_pdf_hash": "e44313afb70700a50d6fb761efe5a348adad81b501bbd4d94f53b19e35df02c7",
    "policy_txt_hash": "b02b6fad03338d79faf60c67b3872e2ecce1792c3e5831ae854930b2020acb65"
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in FIPS mode. No assurance of the minimum strength of generated keys.",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/FIPS140ConsolidatedCertMay2016.pdf",
    "date_sunset": null,
    "description": "The NetApp Cryptographic Security Module is a software library that provides cryptographic services to a vast array of NetApp\u0027s storage and networking products.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Physical Security: N/A",
      "Design Assurance: Level 3",
      "Mitigation of Other Attacks: N/A"
    ],
    "fw_versions": null,
    "historical_reason": "SP 800-56Arev3 transition - replaced by certificate #4297",
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {},
    "module_name": "NetApp Cryptographic Security Module",
    "module_type": "Software",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-2",
    "status": "historical",
    "sw_versions": "1.0",
    "tested_conf": [
      "Debian Linux 8 running on Fujitsu RX200S5 Server with Intel Xeon E5-2609V4 (Broadwell) with PAA",
      "Debian Linux 8 running on Fujitsu RX300-S6 Server with Intel Xeon E5645 (Westmere EP) without PAA",
      "FreeBSD 9.1 running on Fujitsu RX200S5 Server with Intel Xeon E5-2609V4 (Broadwell) with PAA",
      "FreeBSD 9.1 running on Fujitsu RX300-S6 Server with Intel Xeon E5645 (Westmere EP) without PAA",
      "ONTAP 9.7P6 running on FAS2650 with Intel Xeon D-1528 with PAA",
      "ONTAP 9.7P6 running on FAS2650 with Intel Xeon D-1528 without PAA",
      "ONTAP 9.7P6 running on NetApp AFF A800 with Intel Xeon Platinum 8160 with PAA",
      "ONTAP 9.7P6 running on NetApp AFF A800 with Intel Xeon Platinum 8160 without PAA",
      "ONTAP 9.7P6 running on NetApp FAS8300 with Intel Xeon Silver 4210 with PAA",
      "ONTAP 9.7P6 running on NetApp FAS8300 with Intel Xeon Silver 4210 without PAA",
      "ONTAP 9.7P6 running on NetApp FAS9000 with Intel Xeon E5-2697 with PAA",
      "ONTAP 9.7P6 running on NetApp FAS9000 with Intel Xeon E5-2697 without PAA (single-user mode)",
      "Scientific Linux 6.1 running on Fujitsu RX200S5 Server with Intel Xeon E5-2609V4 (Broadwell) with PAA",
      "Scientific Linux 6.1 running on Fujitsu RX300-S6 Server with Intel Xeon E5645 (Westmere EP) without PAA",
      "SUSE Linux 11 running on Fujitsu RX200S5 Server with Intel Xeon E5-2609V4 (Broadwell) with PAA",
      "SUSE Linux 11 running on Fujitsu RX300-S6 Server with Intel Xeon E5645 (Westmere EP) without PAA"
    ],
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2016-05-27",
        "lab": "Acumen Security",
        "validation_type": "Initial"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2016-06-10",
        "lab": "Acumen Security",
        "validation_type": "Update"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2019-10-29",
        "lab": "Acumen Security",
        "validation_type": "Update"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2021-02-10",
        "lab": "Acumen Security",
        "validation_type": "Update"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2021-07-20",
        "lab": "Acumen Security",
        "validation_type": "Update"
      }
    ],
    "vendor": "NetApp, Inc.",
    "vendor_url": "http://www.netapp.com"
  }
}