This page was not yet optimized for use on mobile
devices.
Juniper Kernel Crypto Cryptographic Module
Certificate #4214
Webpage information
Security policy
Symmetric Algorithms
AES, AES-128, AES-192, AES-256, AES-, DES, Triple-DES, TDEA, HMAC, HMAC-SHA-512, HMAC-SHA-224, HMAC-SHA-256, HMAC-SHA-384, CMACAsymmetric Algorithms
ECC, Diffie-Hellman, DSAHash functions
SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, SHA3, SHA-3Schemes
MAC, Key Exchange, Key AgreementProtocols
SSH, TLS, DTLS, IKE, IPsecRandomness
PRNG, DRBG, RNGLibraries
OpenSSLBlock cipher modes
ECB, CBC, CTR, CFB, OFB, GCM, CCM, XTSSecurity level
Level 1, level 1Standards
FIPS 140-2, FIPS PUB 140-2, FIPS197, FIPS198-1, FIPS186-4, FIPS180-4, FIPS140-2, PKCS#1, RFC4106, RFC5246, RFC4253, RFC7296, X.509File metadata
| Title | Microsoft Word - JuniperKCAPI-SecurityPolicy.docx |
|---|---|
| Creation date | D:20220422181428Z00'00' |
| Modification date | D:20220422181428Z00'00' |
| Pages | 30 |
| Creator | Word |
| Producer | macOS Version 11.6.5 (Build 20G527) Quartz PDFContext |
References
Outgoing- 4131 - historical - Juniper OpenSSL Cryptographic Module
Heuristics
No heuristics are available for this certificate.
References
Loading...
Updates Feed
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate was first processed.
Raw data
{
"_type": "sec_certs.sample.fips.FIPSCertificate",
"cert_id": 4214,
"dgst": "3c74149664dcf740",
"heuristics": {
"_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
"algorithms": {
"_type": "Set",
"elements": [
"Triple-DES#C1883",
"RSA#C1883",
"Triple-DES#A2409",
"KTS#C1883",
"SHS#C1883",
"SHS#A2409",
"HMAC#C1883",
"AES#C1891",
"HMAC#A650",
"DRBG#C1883",
"AES#A2409",
"AES#C1883",
"AES#A2411",
"AES#A2410",
"KTS#A2409",
"HMAC#A2409",
"AES#C1890"
]
},
"cpe_matches": null,
"direct_transitive_cves": null,
"extracted_versions": {
"_type": "Set",
"elements": [
"-"
]
},
"indirect_transitive_cves": null,
"module_processed_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": {
"_type": "Set",
"elements": [
"4131"
]
},
"indirectly_referenced_by": null,
"indirectly_referencing": {
"_type": "Set",
"elements": [
"4131"
]
}
},
"module_prunned_references": {
"_type": "Set",
"elements": [
"4131"
]
},
"policy_processed_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": {
"_type": "Set",
"elements": [
"4131"
]
},
"indirectly_referenced_by": null,
"indirectly_referencing": {
"_type": "Set",
"elements": [
"4131"
]
}
},
"policy_prunned_references": {
"_type": "Set",
"elements": [
"4131"
]
},
"related_cves": null,
"verified_cpe_matches": null
},
"pdf_data": {
"_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
"keywords": {
"asymmetric_crypto": {
"ECC": {
"ECC": {
"ECC": 1
}
},
"FF": {
"DH": {
"Diffie-Hellman": 6
},
"DSA": {
"DSA": 1
}
}
},
"certification_process": {},
"cipher_mode": {
"CBC": {
"CBC": 9
},
"CCM": {
"CCM": 6
},
"CFB": {
"CFB": 1
},
"CTR": {
"CTR": 6
},
"ECB": {
"ECB": 5
},
"GCM": {
"GCM": 13
},
"OFB": {
"OFB": 1
},
"XTS": {
"XTS": 5
}
},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {
"OpenSSL": {
"OpenSSL": 4
}
},
"crypto_protocol": {
"IKE": {
"IKE": 1
},
"IPsec": {
"IPsec": 1
},
"SSH": {
"SSH": 1
},
"TLS": {
"DTLS": {
"DTLS": 1
},
"TLS": {
"TLS": 2
}
}
},
"crypto_scheme": {
"KA": {
"Key Agreement": 2
},
"KEX": {
"Key Exchange": 1
},
"MAC": {
"MAC": 10
}
},
"device_model": {},
"ecc_curve": {},
"eval_facility": {
"atsec": {
"atsec": 2
}
},
"fips_cert_id": {
"Cert": {
"#4131": 1
}
},
"fips_certlike": {
"Certlike": {
"AES GCM 128": 1,
"AES key 1": 1,
"AES key 10": 1,
"AES-128": 3,
"AES-192": 2,
"AES-256": 2,
"HMAC 128": 2,
"HMAC 192": 2,
"HMAC SHA-1": 1,
"HMAC-SHA-1": 2,
"HMAC-SHA-224": 2,
"HMAC-SHA-256": 6,
"HMAC-SHA-384": 2,
"HMAC-SHA-512": 8,
"HMAC-SHA1": 2,
"HMAC-SHA3": 4,
"PKCS#1": 2,
"SHA-1": 8,
"SHA-224": 5,
"SHA-256": 10,
"SHA-3": 1,
"SHA-384": 7,
"SHA-512": 6,
"SHA-512 1024": 1,
"SHA-512 112": 1,
"SHA3": 1
}
},
"fips_security_level": {
"Level": {
"Level 1": 3,
"level 1": 4
}
},
"hash_function": {
"SHA": {
"SHA1": {
"SHA-1": 8
},
"SHA2": {
"SHA-224": 5,
"SHA-256": 10,
"SHA-384": 7,
"SHA-512": 8
},
"SHA3": {
"SHA-3": 1,
"SHA3": 1
}
}
},
"ic_data_group": {},
"javacard_api_const": {},
"javacard_packages": {},
"javacard_version": {},
"os_name": {},
"pq_crypto": {},
"randomness": {
"PRNG": {
"DRBG": 16,
"PRNG": 1
},
"RNG": {
"RNG": 1
}
},
"side_channel_analysis": {},
"standard_id": {
"FIPS": {
"FIPS 140-2": 10,
"FIPS PUB 140-2": 2,
"FIPS140-2": 1,
"FIPS180-4": 2,
"FIPS186-4": 2,
"FIPS197": 3,
"FIPS198-1": 2
},
"PKCS": {
"PKCS#1": 1
},
"RFC": {
"RFC4106": 2,
"RFC4253": 1,
"RFC5246": 1,
"RFC7296": 1
},
"X509": {
"X.509": 1
}
},
"symmetric_crypto": {
"AES_competition": {
"AES": {
"AES": 33,
"AES-": 1,
"AES-128": 3,
"AES-192": 2,
"AES-256": 2
}
},
"DES": {
"3DES": {
"TDEA": 1,
"Triple-DES": 26
},
"DES": {
"DES": 2
}
},
"constructions": {
"MAC": {
"CMAC": 10,
"HMAC": 29,
"HMAC-SHA-224": 1,
"HMAC-SHA-256": 3,
"HMAC-SHA-384": 1,
"HMAC-SHA-512": 4
}
}
},
"tee_name": {},
"tls_cipher_suite": {},
"vendor": {},
"vulnerability": {}
},
"policy_metadata": {
"/CreationDate": "D:20220422181428Z00\u002700\u0027",
"/Creator": "Word",
"/ModDate": "D:20220422181428Z00\u002700\u0027",
"/Producer": "macOS Version 11.6.5 (Build 20G527) Quartz PDFContext",
"/Title": "Microsoft Word - JuniperKCAPI-SecurityPolicy.docx",
"pdf_file_size_bytes": 622998,
"pdf_hyperlinks": {
"_type": "Set",
"elements": []
},
"pdf_is_encrypted": false,
"pdf_number_of_pages": 30
}
},
"state": {
"_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
"module_download_ok": true,
"module_extract_ok": true,
"policy_convert_ok": true,
"policy_download_ok": true,
"policy_extract_ok": true,
"policy_json_hash": null,
"policy_pdf_hash": "163e5b4b45acf9d0feeb23f1d3c81a66f0448e83ecd1ad965668ccb6589198d1",
"policy_txt_hash": "7115fedbb14310e1f5c3c7f798a504b13fbc6210f6d496c64d63c531a6eca6b0"
},
"web_data": {
"_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
"caveat": "When operated in FIPS mode with bound module Juniper OpenSSL Cryptographic Module validated to FIPS 140-2 under Cert. #4131 operating in FIPS mode. The module generates random strings whose strengths are modified by available entropy",
"certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/May 2022_010622_0641_signed.pdf",
"date_sunset": "2026-09-21",
"description": "The Juniper Kernel Cryptographic Module is a software module running as part of the operating system kernel that provides general purpose cryptographic services.",
"embodiment": "Multi-Chip Stand Alone",
"exceptions": [
"Physical Security: N/A",
"Mitigation of Other Attacks: N/A"
],
"fw_versions": null,
"historical_reason": null,
"hw_versions": null,
"level": 1,
"mentioned_certs": {
"4131": 1
},
"module_name": "Juniper Kernel Crypto Cryptographic Module",
"module_type": "Software",
"revoked_link": null,
"revoked_reason": null,
"standard": "FIPS 140-2",
"status": "active",
"sw_versions": "1.0",
"tested_conf": [
"Junos OS Evolved version 19.4R2 running on Juniper Networks Packet Transport Router Model PTX10003-80C with Intel Xeon E5-2628Lv4 with PAA",
"Junos OS Evolved version 19.4R2 running on Juniper Networks Packet Transport Router Model PTX10003-80C with Intel Xeon E5-2628Lv4 without PAA(single-user mode)"
],
"validation_history": [
{
"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
"date": "2022-05-09",
"lab": "atsec information security corporation",
"validation_type": "Initial"
}
],
"vendor": "Juniper Networks, Inc.",
"vendor_url": "http://www.juniper.net/us/en/"
}
}