This page was not yet optimized for use on mobile
devices.
SUSE Linux Enterprise Server - Kernel Crypto API Cryptographic Module
Certificate #3099
Webpage information
Security policy
Symmetric Algorithms
AES, AES-128, AES-, AES-256, Serpent, CAST5, DES, Triple-DES, TDES, TDEA, ChaCha20, Salsa20, Poly1305, SEED, HMAC, HMAC-SHA-224, HMAC-SHA-256, HMAC-SHA-512, CMACHash functions
SHA-1, SHA-224, SHA-384, SHA-512, SHA-256, MD4, MD5, RIPEMDSchemes
MAC, Key ExchangeProtocols
IKEv2, IPsecRandomness
DRBG, RNGLibraries
OpenSSLBlock cipher modes
ECB, CBC, CTR, OFB, GCM, CCM, LRW, XEX, XTSSecurity level
level 1, Level 1Standards
FIPS 140-2, FIPS197, FIPS198-1, FIPS186-4, FIPS180-4, FIPS 180-4, FIPS PUB 140-2, SP 800-90A, PKCS#1, RFC4106, RFC7296File metadata
| Title | FIPS 140-2 Non-Proprietary Security Policy |
|---|---|
| Keywords | FIPS 140-2 |
| Author | Traci Porter |
| Creation date | D:20171223220256-06'00' |
| Pages | 29 |
| Creator | Writer |
| Producer | OpenOffice 4.1.2 |
References
OutgoingHeuristics
No heuristics are available for this certificate.
References
Loading...
Updates Feed
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate was first processed.
Raw data
{
"_type": "sec_certs.sample.fips.FIPSCertificate",
"cert_id": 3099,
"dgst": "3c8b996ee07b276e",
"heuristics": {
"_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
"algorithms": {
"_type": "Set",
"elements": [
"HMAC#3058",
"AES#4672",
"SHS#3787",
"RSA#2516",
"AES#4682",
"HMAC#3056",
"SHS#3786",
"Triple-DES#2452",
"DRBG#1545",
"HMAC#3060",
"HMAC#3042",
"AES#4673",
"HMAC#3097",
"RSA#2515",
"HMAC#3054",
"KTS#4681",
"Triple-DES#2489",
"HMAC#3045",
"AES#4612",
"AES#4618",
"DRBG#1582",
"DRBG#1551",
"AES#4681",
"AES#4675",
"AES#4609",
"AES#4610",
"AES#4674",
"AES#4679",
"DRBG#1546",
"SHS#3771",
"Triple-DES#2454",
"HMAC#3043",
"Triple-DES#2453",
"AES#4611",
"AES#4613",
"DRBG#1585",
"RSA#2555",
"DRBG#1547",
"KTS#4608",
"HMAC#3044",
"SHS#3833",
"SHS#3784",
"DRBG#1544",
"SHS#3832",
"AES#4615",
"AES#4677",
"KTS#4611",
"KTS#4614",
"AES#4616",
"RSA#2517",
"HMAC#3098",
"KTS#4682",
"SHS#3789",
"AES#4608",
"DRBG#1549",
"HMAC#3059",
"SHS#3768",
"DRBG#1586",
"HMAC#3057",
"SHS#3782",
"AES#4617",
"RSA#2513",
"AES#4678",
"RSA#2554",
"SHS#3769",
"Triple-DES#2487",
"SHS#3785",
"Triple-DES#2486",
"AES#4614",
"DRBG#1584",
"SHS#3770",
"SHS#3788",
"DRBG#1550"
]
},
"cpe_matches": null,
"direct_transitive_cves": null,
"extracted_versions": {
"_type": "Set",
"elements": [
"-"
]
},
"indirect_transitive_cves": null,
"module_processed_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": {
"_type": "Set",
"elements": [
"3038"
]
},
"indirectly_referenced_by": null,
"indirectly_referencing": {
"_type": "Set",
"elements": [
"3038"
]
}
},
"module_prunned_references": {
"_type": "Set",
"elements": [
"3038"
]
},
"policy_processed_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": {
"_type": "Set",
"elements": [
"3038",
"2549"
]
},
"indirectly_referenced_by": null,
"indirectly_referencing": {
"_type": "Set",
"elements": [
"4646",
"3788",
"1628",
"4623",
"2015",
"3199",
"675",
"2645",
"3090",
"3480",
"4647",
"2648",
"2507",
"2017",
"674",
"3771",
"3789",
"2549",
"3195",
"2484",
"3194",
"3769",
"2646",
"3091",
"3045",
"3651",
"3196",
"2439",
"2016",
"3043",
"3197",
"1537",
"1127",
"3089",
"2435",
"3770",
"3042",
"586",
"3644",
"3198",
"3096",
"3114",
"3059",
"4588",
"1823",
"2014",
"3615",
"1538",
"4595",
"4645",
"3038",
"2481",
"676",
"1930",
"1536",
"3768",
"4594",
"2505",
"3044",
"4622"
]
}
},
"policy_prunned_references": {
"_type": "Set",
"elements": [
"3038",
"2549"
]
},
"related_cves": null,
"verified_cpe_matches": null
},
"pdf_data": {
"_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
"keywords": {
"asymmetric_crypto": {},
"certification_process": {},
"cipher_mode": {
"CBC": {
"CBC": 18
},
"CCM": {
"CCM": 6
},
"CTR": {
"CTR": 17
},
"ECB": {
"ECB": 14
},
"GCM": {
"GCM": 40
},
"LRW": {
"LRW": 2
},
"OFB": {
"OFB": 1
},
"XEX": {
"XEX": 1
},
"XTS": {
"XTS": 12
}
},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {
"OpenSSL": {
"OpenSSL": 7
}
},
"crypto_protocol": {
"IKE": {
"IKEv2": 2
},
"IPsec": {
"IPsec": 1
}
},
"crypto_scheme": {
"KEX": {
"Key Exchange": 1
},
"MAC": {
"MAC": 8
}
},
"device_model": {},
"ecc_curve": {},
"eval_facility": {
"atsec": {
"atsec": 32
}
},
"fips_cert_id": {
"Cert": {
"#1544": 1,
"#1545": 1,
"#1546": 1,
"#1547": 1,
"#1549": 1,
"#1550": 1,
"#1551": 1,
"#1582": 1,
"#1584": 1,
"#1585": 2,
"#1586": 1,
"#2452": 1,
"#2453": 1,
"#2454": 1,
"#2486": 1,
"#2487": 1,
"#2489": 1,
"#2513": 1,
"#2515": 1,
"#2516": 1,
"#2517": 1,
"#2549": 1,
"#2554": 1,
"#2555": 1,
"#3038": 4,
"#3042": 1,
"#3043": 1,
"#3044": 1,
"#3045": 1,
"#3054": 1,
"#3056": 1,
"#3057": 1,
"#3058": 1,
"#3059": 1,
"#3060": 1,
"#3097": 1,
"#3098": 1,
"#3768": 1,
"#3769": 1,
"#3770": 1,
"#3771": 1,
"#3782": 1,
"#3784": 1,
"#3785": 1,
"#3786": 1,
"#3787": 1,
"#3788": 1,
"#3789": 1,
"#3832": 1,
"#3833": 1,
"#4608": 1,
"#4609": 1,
"#4610": 1,
"#4611": 1,
"#4612": 1,
"#4613": 1,
"#4614": 1,
"#4615": 1,
"#4616": 1,
"#4617": 1,
"#4618": 1,
"#4672": 1,
"#4673": 1,
"#4674": 1,
"#4675": 1,
"#4677": 1,
"#4678": 1,
"#4679": 1,
"#4681": 1,
"#4682": 1
}
},
"fips_certlike": {
"Certlike": {
"AES #4608": 1,
"AES #4681": 1,
"AES- 192": 2,
"AES-128": 2,
"AES-256": 2,
"DRBG #1544": 1,
"DRBG #1582": 1,
"HMAC #3054": 2,
"HMAC #3097": 2,
"HMAC- SHA-256": 3,
"HMAC- SHA-384": 1,
"HMAC- SHA-512 112": 2,
"HMAC-SHA- 224": 4,
"HMAC-SHA- 256 #3042": 2,
"HMAC-SHA- 256 #3059": 2,
"HMAC-SHA- 384": 4,
"HMAC-SHA-1": 6,
"HMAC-SHA-224": 2,
"HMAC-SHA-256": 4,
"HMAC-SHA-512": 2,
"PKCS#1": 2,
"RSA #2513": 1,
"RSA #2554": 1,
"SHA- 224": 4,
"SHA- 256": 5,
"SHA- 512": 2,
"SHA- 512 1024": 2,
"SHA-1": 12,
"SHA-12": 2,
"SHA-224": 2,
"SHA-256": 10,
"SHA-384": 11,
"SHA-512": 6,
"SHA-512 112": 2,
"SHS #3782": 1,
"SHS #3832": 1
}
},
"fips_security_level": {
"Level": {
"Level 1": 1,
"level 1": 4
}
},
"hash_function": {
"MD": {
"MD4": {
"MD4": 2
},
"MD5": {
"MD5": 2
}
},
"RIPEMD": {
"RIPEMD": 2
},
"SHA": {
"SHA1": {
"SHA-1": 12
},
"SHA2": {
"SHA-224": 2,
"SHA-256": 10,
"SHA-384": 11,
"SHA-512": 8
}
}
},
"ic_data_group": {},
"javacard_api_const": {},
"javacard_packages": {},
"javacard_version": {},
"os_name": {},
"pq_crypto": {},
"randomness": {
"PRNG": {
"DRBG": 14
},
"RNG": {
"RNG": 3
}
},
"side_channel_analysis": {},
"standard_id": {
"FIPS": {
"FIPS 140-2": 45,
"FIPS 180-4": 2,
"FIPS PUB 140-2": 1,
"FIPS180-4": 3,
"FIPS186-4": 3,
"FIPS197": 10,
"FIPS198-1": 5
},
"NIST": {
"SP 800-90A": 2
},
"PKCS": {
"PKCS#1": 1
},
"RFC": {
"RFC4106": 26,
"RFC7296": 2
}
},
"symmetric_crypto": {
"AES_competition": {
"AES": {
"AES": 66,
"AES-": 2,
"AES-128": 2,
"AES-256": 2
},
"CAST": {
"CAST5": 2
},
"Serpent": {
"Serpent": 2
}
},
"DES": {
"3DES": {
"TDEA": 1,
"TDES": 7,
"Triple-DES": 21
},
"DES": {
"DES": 3
}
},
"constructions": {
"MAC": {
"CMAC": 10,
"HMAC": 19,
"HMAC-SHA-224": 1,
"HMAC-SHA-256": 2,
"HMAC-SHA-512": 1
}
},
"djb": {
"ChaCha": {
"ChaCha20": 2
},
"Poly": {
"Poly1305": 2
},
"Salsa": {
"Salsa20": 2
}
},
"miscellaneous": {
"SEED": {
"SEED": 2
}
}
},
"tee_name": {},
"tls_cipher_suite": {},
"vendor": {},
"vulnerability": {}
},
"policy_metadata": {
"/Author": "Traci Porter",
"/CreationDate": "D:20171223220256-06\u002700\u0027",
"/Creator": "Writer",
"/Keywords": "FIPS 140-2",
"/Producer": "OpenOffice 4.1.2",
"/Title": "FIPS 140-2 Non-Proprietary Security Policy",
"pdf_file_size_bytes": 428504,
"pdf_hyperlinks": {
"_type": "Set",
"elements": [
"https://csrc.nist.gov/projects/cryptographic-module-validation-program/Certificate/3038",
"https://csrc.nist.gov/Projects/Cryptographic-Algorithm-Validation-Program/Validation/Validation-List/SHS#3789",
"http://csrc.nist.gov/groups/STM/cavp/documents/drbg/drbgnewval.html#1584",
"http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html#4612",
"http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html#4682",
"http://csrc.nist.gov/groups/STM/cmvp/documents/fips140-2/FIPS1402IG.pdf",
"https://csrc.nist.gov/Projects/Cryptographic-Module-Validation-Program/Certificate/2549",
"https://csrc.nist.gov/Projects/Cryptographic-Algorithm-Validation-Program/Validation/Validation-List/HMAC#3059",
"http://csrc.nist.gov/publications/fips/fips140-2/fips1402.pdf",
"http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-67r1.pdf",
"http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38e.pdf",
"https://csrc.nist.gov/Projects/Cryptographic-Algorithm-Validation-Program/Validation/Validation-List/SHS#3788",
"http://www.ietf.org/rfc/rfc3447.txt",
"http://csrc.nist.gov/groups/STM/cavp/documents/shs/shaval.html#3785",
"http://csrc.nist.gov/groups/STM/cavp/documents/mac/hmacval.html#3057",
"http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html#4616",
"http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html#4672",
"http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html#4678",
"http://csrc.nist.gov/publications/fips/fips197/fips-197.pdf",
"http://csrc.nist.gov/groups/STM/cmvp/",
"http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html#4615",
"http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html#4681",
"http://csrc.nist.gov/publications/fips/fips198-1/FIPS-198-1_final.pdf",
"http://www.suse.com/",
"http://csrc.nist.gov/groups/STM/cavp/documents/drbg/drbgnewval.html#1545",
"http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html#4677",
"http://csrc.nist.gov/groups/STM/cavp/documents/des/tripledesnewval.html#2489",
"https://csrc.nist.gov/Projects/Cryptographic-Module-Validation-Program/Certificate/3038",
"http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90Ar1.pdf",
"http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html#4609",
"http://csrc.nist.gov/groups/STM/cavp/documents/des/tripledesnewval.html#2486",
"http://csrc.nist.gov/groups/STM/cavp/documents/mac/hmacval.html#3097",
"https://csrc.nist.gov/Projects/Cryptographic-Algorithm-Validation-Program/Validation/Validation-List/HMAC#3060",
"http://csrc.nist.gov/groups/STM/cavp/documents/mac/hmacval.html#3098",
"http://csrc.nist.gov/groups/STM/cavp/documents/dss/rsanewval.html#2515",
"http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html#4608",
"http://csrc.nist.gov/groups/STM/cavp/documents/dss/rsanewval.html#2555",
"http://csrc.nist.gov/groups/STM/cavp/documents/drbg/drbgnewval.html#1551",
"http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html#4673",
"http://csrc.nist.gov/groups/STM/cavp/documents/dss/rsanewval.html#2516",
"http://csrc.nist.gov/",
"http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html#4611",
"http://csrc.nist.gov/groups/STM/cavp/documents/des/tripledesnewval.html#2453",
"http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html#4613",
"http://csrc.nist.gov/groups/STM/cavp/documents/des/tripledesnewval.html#2452",
"http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38b.pdf",
"http://csrc.nist.gov/groups/STM/cavp/documents/drbg/drbgnewval.html#1586",
"https://csrc.nist.gov/Projects/Cryptographic-Algorithm-Validation-Program/Validation/Validation-List/HMAC#3042",
"http://csrc.nist.gov/groups/STM/cavp/documents/drbg/drbgnewval.html#1585",
"http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html#4618",
"http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38c.pdf",
"http://csrc.nist.gov/groups/STM/cavp/documents/dss/rsanewval.html#2513",
"http://csrc.nist.gov/groups/STM/cavp/documents/mac/hmacval.html#3056",
"http://csrc.nist.gov/groups/STM/cavp/documents/shs/shaval.html#3832",
"https://csrc.nist.gov/Projects/Cryptographic-Algorithm-Validation-Program/Validation/Validation-List/SHS#3770",
"http://csrc.nist.gov/groups/STM/cavp/documents/mac/hmacval.html#3054",
"http://csrc.nist.gov/groups/STM/cavp/documents/shs/shaval.html#3786",
"https://csrc.nist.gov/Projects/Cryptographic-Algorithm-Validation-Program/Validation/Validation-List/HMAC#3043",
"http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38a.pdf",
"https://tools.ietf.org/html/rfc7296",
"http://csrc.nist.gov/groups/STM/cavp/documents/drbg/drbgnewval.html#1547",
"http://csrc.nist.gov/groups/STM/cavp/documents/dss/rsanewval.html#2554",
"https://csrc.nist.gov/Projects/Cryptographic-Algorithm-Validation-Program/Validation/Validation-List/HMAC#3044",
"http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf",
"https://csrc.nist.gov/Projects/Cryptographic-Algorithm-Validation-Program/Validation/Validation-List/SHS#3768",
"http://csrc.nist.gov/groups/STM/cavp/documents/mac/hmacval.html#3058",
"http://csrc.nist.gov/groups/STM/cavp/documents/shs/shaval.html#3782",
"http://csrc.nist.gov/groups/STM/cavp/documents/shs/shaval.html#3787",
"http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html#4617",
"http://csrc.nist.gov/groups/STM/cavp/documents/drbg/drbgnewval.html#1546",
"http://csrc.nist.gov/groups/STM/cavp/documents/des/tripledesnewval.html#2487",
"http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html#4610",
"http://csrc.nist.gov/groups/STM/cavp/documents/shs/shaval.html#3784",
"https://tools.ietf.org/html/rfc4106",
"http://csrc.nist.gov/groups/STM/cavp/documents/shs/shaval.html#3833",
"http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html#4674",
"http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38F.pdf",
"http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-4.pdf",
"http://csrc.nist.gov/groups/STM/cavp/documents/drbg/drbgnewval.html#1549",
"http://csrc.nist.gov/groups/STM/cavp/documents/drbg/drbgnewval.html#1550",
"https://csrc.nist.gov/Projects/Cryptographic-Algorithm-Validation-Program/Validation/Validation-List/SHS#3769",
"http://csrc.nist.gov/groups/STM/cavp/documents/drbg/drbgnewval.html#1582",
"http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38d.pdf",
"http://csrc.nist.gov/groups/STM/cavp/documents/des/tripledesnewval.html#2454",
"http://csrc.nist.gov/groups/STM/cavp/documents/drbg/drbgnewval.html#1544",
"https://csrc.nist.gov/Projects/Cryptographic-Algorithm-Validation-Program/Validation/Validation-List/SHS#3771",
"http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html#4614",
"http://csrc.nist.gov/groups/STM/cavp/documents/dss/rsanewval.html#2517",
"https://csrc.nist.gov/Projects/Cryptographic-Algorithm-Validation-Program/Validation/Validation-List/HMAC#3045",
"http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html#4679",
"http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html#4675"
]
},
"pdf_is_encrypted": false,
"pdf_number_of_pages": 29
}
},
"state": {
"_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
"module_download_ok": true,
"module_extract_ok": true,
"policy_convert_ok": true,
"policy_download_ok": true,
"policy_extract_ok": true,
"policy_json_hash": null,
"policy_pdf_hash": "7e943f671f44ad43480d3ac5dc8b40f9df39051b4676b0c15a84c79f8ebdaa97",
"policy_txt_hash": "67ea93c21e99144bbafce8b7b537d04590dd275efaa7e1e3d05e463edbe3dfaf"
},
"web_data": {
"_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
"caveat": "When operated in FIPS mode with module SUSE Linux Enterprise Server 12 - OpenSSL Module v2.0 validated to FIPS 140-2 under Cert. #3038 operating in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy",
"certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/FIPS140ConsolidatedCertJan2018.pdf",
"date_sunset": null,
"description": "SUSE Linux Enterprise Server Kernel Crypto API Module provides cryptographic services to the Linux operating system kernel.",
"embodiment": "Multi-Chip Stand Alone",
"exceptions": [
"Physical Security: N/A",
"Mitigation of Other Attacks: N/A"
],
"fw_versions": null,
"historical_reason": "Moved to historical list due to dependency on certificate #3038",
"hw_versions": null,
"level": 1,
"mentioned_certs": {
"3038": 1
},
"module_name": "SUSE Linux Enterprise Server - Kernel Crypto API Cryptographic Module",
"module_type": "Software",
"revoked_link": null,
"revoked_reason": null,
"standard": "FIPS 140-2",
"status": "historical",
"sw_versions": "2.0",
"tested_conf": [
"SLES12 operating on FUJITSU Server PRIMERGY CX2570 M2 inside a CX400 M1 enclosure with PAA",
"SLES12 operating on FUJITSU Server PRIMERGY CX2570 M2 inside a CX400 M1 enclosure without PAA",
"SLES12 operating on IBM z13 with PAI",
"SLES12 operating on IBM z13 without PAI (single-user mode)"
],
"validation_history": [
{
"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
"date": "2018-01-02",
"lab": "atsec information security corporation",
"validation_type": "Initial"
}
],
"vendor": "SUSE, LLC",
"vendor_url": "http://www.suse.com"
}
}