{"_type": "sec_certs.sample.fips.FIPSCertificate", "dgst": "421921b162ab5ec0", "cert_id": 5212, "web_data": {"_type": "sec_certs.sample.fips.FIPSCertificate.WebData", "module_name": "Ovation FIPS Provider based on the OpenSSL FIPS Provider", "validation_history": [{"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry", "date": "2026-03-26", "validation_type": "Initial", "lab": "Lightship Security, Inc."}], "vendor_url": "http://www.ovation.co.uk", "vendor": "Ovation Systems Ltd", "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/March 2026_020426_1121-signed.pdf", "module_type": "Software", "standard": "FIPS 140-3", "status": "active", "level": 1, "caveat": "When operated in approved mode. No assurance of the minimum strength of generated SSPs (e.g., keys).", "exceptions": ["Physical security: N/A", "Non-invasive security: N/A", "Life-cycle assurance: Level 3"], "embodiment": "MultiChipStand", "description": "The Ovation FIPS Provider based on the OpenSSL FIPS Provider is a software library providing a C-language application program interface (API) for use by applications that require cryptographic functionality.", "tested_conf": null, "hw_versions": null, "fw_versions": null, "sw_versions": null, "mentioned_certs": {}, "historical_reason": null, "date_sunset": "2030-03-10", "revoked_reason": null, "revoked_link": null}, "pdf_data": {"_type": "sec_certs.sample.fips.FIPSCertificate.PdfData", "keywords": {"fips_cert_id": {"Cert": {"#3": 4}}, "fips_security_level": {"Level": {"Level 1": 2}}, "fips_certlike": {"Certlike": {"HMAC-SHA-1": 8, "HMAC-SHA2": 2, "HMAC-SHA3": 2, "HMAC- SHA-1": 2, "HMAC- SHA1": 3, "SHA2-224": 29, "SHA2-256": 39, "SHA2- 384": 34, "SHA2-512": 37, "SHA-1": 27, "SHA2- 256": 36, "SHA2-384": 26, "SHA3-224": 14, "SHA3-256": 20, "SHA3-384": 12, "SHA3-512": 19, "SHA3- 384": 14, "SHA2- 512": 27, "SHA3": 10, "SHA3- 256": 13, "SHA3- 512": 11, "SHA2- 224": 21, "SHA2": 1, "SHA-3": 2, "SHA- 1": 2, "SHA3- 224": 10, "SHA1": 13, "PKCS 1": 8, "PKCS#1": 4, "AES-128": 3, "AES-192": 4, "AES-256": 4, "AES- 192": 1, "AES- 256": 1, "AES128": 1, "AES CTR (128": 1, "DRBG 2": 1, "DRBG 128": 1}}, "vendor": {"Microsoft": {"Microsoft": 1, "Microsoft Corporation": 1}}, "eval_facility": {}, "symmetric_crypto": {"AES_competition": {"AES": {"AES-128": 3, "AES-192": 4, "AES-256": 4, "AES": 29, "AES-": 57, "AES128": 1}, "CAST": {"CAST": 66}}, "DES": {"3DES": {"Triple-DES": 2}}, "constructions": {"MAC": {"HMAC": 31, "KMAC": 7, "CMAC": 6}}}, "asymmetric_crypto": {"RSA": {"RSA-OAEP": 2}, "ECC": {"ECDSA": {"ECDSA": 42}, "ECC": {"ECC": 5}}, "FF": {"DH": {"DHE": 1}, "DSA": {"DSA": 56}}}, "pq_crypto": {}, "hash_function": {"SHA": {"SHA1": {"SHA-1": 27, "SHA1": 13}, "SHA2": {"SHA2": 1}, "SHA3": {"SHA3-224": 14, "SHA3-256": 20, "SHA3-384": 12, "SHA3-512": 19, "SHA3": 10, "SHA-3": 2}}, "SHAKE": {"SHAKE256": 5, "SHAKE128": 4}, "PBKDF": {"PBKDF": 14, "PBKDF2": 1}}, "crypto_scheme": {"MAC": {"MAC": 9}, "KEX": {"Key exchange": 1, "Key Exchange": 2}, "KA": {"Key Agreement": 9}, "AEAD": {"AEAD": 1}}, "crypto_protocol": {"SSH": {"SSH": 10, "SSHv2": 1}, "TLS": {"TLS": {"TLS 1.2": 3, "TLS v1.2": 6, "TLS v1.3": 6, "TLS": 7, "TLS 1.3": 1}}}, "randomness": {"PRNG": {"DRBG": 40}, "RNG": {"RBG": 3}}, "cipher_mode": {"ECB": {"ECB": 4}, "CBC": {"CBC": 7}, "CTR": {"CTR": 10}, "CFB": {"CFB": 3}, "OFB": {"OFB": 3}, "GCM": {"GCM": 13}, "CCM": {"CCM": 5}, "XTS": {"XTS": 8}}, "ecc_curve": {"NIST": {"P-224": 28, "P-256": 34, "P-384": 34, "P-521": 36, "P-192": 14, "B-233": 12, "B-283": 15, "B-409": 15, "B-571": 16, "K-233": 19, "K-409": 18, "K-571": 19, "B-163": 5, "K-283": 17, "K-163": 4}, "Edwards": {"Ed448": 3, "Ed25519": 2}}, "crypto_engine": {}, "tls_cipher_suite": {}, "crypto_library": {"OpenSSL": {"OpenSSL": 121}}, "vulnerability": {}, "side_channel_analysis": {"SCA": {"timing attacks": 2}}, "device_model": {}, "tee_name": {"AMD": {"PSP": 4}, "IBM": {"SSC": 6}}, "os_name": {}, "cplc_data": {}, "ic_data_group": {}, "standard_id": {"FIPS": {"FIPS 140-3": 98, "FIPS140-3": 3, "FIPS186-4": 44, "FIPS 186-4": 18, "FIPS 198-1": 11, "FIPS 180-4": 7, "FIPS 202": 7, "FIPS 186-2": 6, "FIPS198-1": 3}, "NIST": {"SP 800-38A": 10, "SP 800-38C": 1, "SP 800-38B": 1, "SP 800-38D": 3, "SP 800-38F": 5, "SP 800-38E": 1, "SP 800-90A": 3, "SP 800-56A": 6, "SP 800-56C": 3, "SP 800-135": 5, "SP 800-108": 3, "SP 800-185": 2, "SP 800-56B": 1, "SP 800-132": 2, "NIST SP 800-132": 3, "NIST SP 800-108": 1}, "PKCS": {"PKCS 1": 4, "PKCS#1": 2}, "RFC": {"RFC7627": 5, "RFC8446": 2, "RFC4252": 1, "RFC4253": 1, "RFC5647": 1, "RFC 7627": 1}}, "javacard_version": {}, "javacard_api_const": {"curves": {"X25519": 2, "X448": 2}}, "javacard_packages": {}, "certification_process": {}}, "policy_metadata": {"pdf_file_size_bytes": 842580, "pdf_is_encrypted": false, "pdf_number_of_pages": 88, "/Author": "Hawes, David J. (Fed)", "/Comments": "", "/Company": "", "/ContentTypeId": "0x01010044788752DEE24048B316A411A5F1F9B2", "/CreationDate": "D:20260319171433-04'00'", "/Creator": "Acrobat PDFMaker 25 for Word", "/Keywords": "", "/MediaServiceImageTags": "", "/ModDate": "D:20260319171642-04'00'", "/Producer": "Adobe PDF Library 25.1.5", "/SourceModified": "", "/Subject": "", "/Title": "", "/_dlc_DocIdItemGuid": "8b2f6758-edfa-43cb-a9df-03c2ecf52a26", "/docLang": "en", "pdf_hyperlinks": {"_type": "Set", "elements": ["http://www.lightshipsec.com/"]}}, "module_algorithms": {"_type": "Set", "elements": ["KDA OneStep SP800-56Cr2A3548", "HMAC-SHA3-512A3548", "AES-CTRA3548", "AES-ECBA3548", "AES-KWA3548", "KDA TwoStep SP800-56Cr2A3548", "AES-CFB128A3548", "KAS-IFC-SSCA3548", "SHA3-224A3548", "KTS-IFCA3548", "RSA SigGen (FIPS186-4)A3548", "RSA Signature PrimitiveA3548", "SHA2-384A3548", "AES-CBC-CS1A3548", "KDF SP800-108A3548", "HMAC-SHA2-384A3548", "AES-CBCA3548", "RSA KeyGen (FIPS186-4)A3548", "KMAC-256A3548", "SHA3-256A3548", "RSA SigVer (FIPS186-4)A3548", "Counter DRBGA3548", "ECDSA KeyGen (FIPS186-4)A3548", "AES-CMACA3548", "KMAC-128A3548", "AES-GMACA3548", "HMAC-SHA2-512/256A3548", "SHA3-512A3548", "KDA HKDF SP800-56Cr2A3548", "SHA2-224A3548", "KDF KMAC Sp800-108r1A3548", "ECDSA KeyVer (FIPS186-4)A3548", "SHA2-512/224A3548", "ECDSA SigVer (FIPS186-4)A3548", "ECDSA SigGen (FIPS186-4)A3548", "DSA SigGen (FIPS186-4)A3548", "HMAC-SHA-1A3548", "HMAC-SHA2-512/224A3548", "TLS v1.2 KDF RFC7627A3548", "AES-XTS Testing Revision 2.0A3548", "AES-KWPA3548", "HMAC-SHA3-384A3548", "DSA PQGVer (FIPS186-4)A3548", "PBKDFA3548", "SHA-1A3548", "Safe Primes Key VerificationA3548", "AES-CBC-CS3A3548", "HMAC-SHA2-224A3548", "AES-CFB8A3548", "AES-OFBA3548", "Hash DRBGA3548", "AES-CCMA3548", "HMAC DRBGA3548", "HMAC-SHA3-256A3548", "KDF ANS 9.63A3548", "SHA2-512A3548", "KAS-ECC CDH-Component SP800-56Ar3A3548", "DSA PQGGen (FIPS186-4)A3548", "AES-GCMA3548", "KDF ANS 9.42A3548", "KDF SSHA3548", "TLS v1.3 KDFA3548", "SHA2-256A3548", "AES-CFB1A3548", "HMAC-SHA3-224A3548", "HMAC-SHA2-256A3548", "AES-CBC-CS2A3548", "SHAKE-256A3548", "DSA KeyGen (FIPS186-4)A3548", "SHA2-512/256A3548", "SHAKE-128A3548", "Safe Primes Key GenerationA3548", "DSA SigVer (FIPS186-4)A3548", "KAS-ECC-SSC Sp800-56Ar3A3548", "SHA3-384A3548", "KAS-FFC-SSC Sp800-56Ar3A3548", "HMAC-SHA2-512A3548"]}, "policy_algorithms": {"_type": "Set", "elements": ["#A3548"]}, "is_br1_format": true, "br1_deviations": 0, "br1_tables": {"_type": "sec_certs.heuristics.br1.table_parsing.model.br1_tables.BR1Tables", "security_levels": {"section": 1, "subsection": 2, "found": true, "entries": [{"section": "1", "title": "General", "level": "1"}, {"section": "2", "title": "Cryptographic module specification", "level": "1"}, {"section": "3", "title": "Cryptographic module interfaces", "level": "1"}, {"section": "4", "title": "Roles, services, and authentication", "level": "1"}, {"section": "5", "title": "Software/Firmware security", "level": "1"}, {"section": "6", "title": "Operational environment", "level": "1"}, {"section": "7", "title": "Physical security", "level": "N/A"}, {"section": "8", "title": "Non-invasive security", "level": "N/A"}, {"section": "9", "title": "Sensitive security parameter management", "level": "1"}, {"section": "10", "title": "Self-tests", "level": "1"}, {"section": "11", "title": "Life-cycle assurance", "level": "3"}, {"section": "12", "title": "Mitigation of other attacks", "level": "1"}, {"section": "", "title": "Overall Level", "level": "1"}]}, "tested_module_id_hw": {"section": 2, "subsection": 2, "found": false, "entries": []}, "tested_module_id_sw_fw_hy": {"section": 2, "subsection": 2, "found": true, "entries": [{"packageFileName": "fips.so", "swFwVersion": "3.1.2", "features": "fips.so for Unix/Linux platforms", "integrityTest": "HMAC-SHA2-256"}, {"packageFileName": "fips.dll", "swFwVersion": "3.1.2", "features": "fips.dll for Windows platforms", "integrityTest": "HMAC-SHA2-256"}, {"packageFileName": "fips.dylib", "swFwVersion": "3.1.2", "features": "fips.dylib for Mac platforms", "integrityTest": "HMAC-SHA2-256"}]}, "tested_module_id_hw_hy": {"section": 2, "subsection": 2, "found": false, "entries": []}, "tested_op_env_sw_fw_hy": {"section": 2, "subsection": 2, "found": true, "entries": [{"operatingSystem": "Ubuntu Linux 22.04.1 Server", "hardwarePlatform": "Dell Inspiron 7573", "processors": "Intel i7- 8550U", "paa_pai": "No", "hypervisorHostOs": "N/A", "version": "3.1.2"}, {"operatingSystem": "Ubuntu Linux 22.04.1 Server", "hardwarePlatform": "Dell Inspiron 7573", "processors": "Intel i7- 8550U", "paa_pai": "Yes", "hypervisorHostOs": "N/A", "version": "3.1.2"}, {"operatingSystem": "Debian 11.5", "hardwarePlatform": "Dell Inspiron 7573", "processors": "Intel i7- 8550U", "paa_pai": "No", "hypervisorHostOs": "N/A", "version": "3.1.2"}, {"operatingSystem": "Debian 11.5", "hardwarePlatform": "Dell Inspiron 7573", "processors": "Intel i7- 8550U", "paa_pai": "Yes", "hypervisorHostOs": "N/A", "version": "3.1.2"}, {"operatingSystem": "FreeBSD 13.1", "hardwarePlatform": "Dell Inspiron 7591 2 in 1", "processors": "Intel i7- 10510U", "paa_pai": "No", "hypervisorHostOs": "N/A", "version": "3.1.2"}, {"operatingSystem": "FreeBSD 13.1", "hardwarePlatform": "Dell Inspiron 7591 2 in 1", "processors": "Intel i7- 10510U", "paa_pai": "Yes", "hypervisorHostOs": "N/A", "version": "3.1.2"}, {"operatingSystem": "Windows 10 Pro", "hardwarePlatform": "Dell Inspiron 7591 2 in 1", "processors": "Intel i7- 10510U", "paa_pai": "No", "hypervisorHostOs": "N/A", "version": "3.1.2"}, {"operatingSystem": "Windows 10 Pro", "hardwarePlatform": "Dell Inspiron 7591 2 in 1", "processors": "Intel i7- 10510U", "paa_pai": "Yes", "hypervisorHostOs": "N/A", "version": "3.1.2"}, {"operatingSystem": "macOS 11.5.2", "hardwarePlatform": "Apple M1 Mac Mini", "processors": "M1", "paa_pai": "No", "hypervisorHostOs": "N/A", "version": "3.1.2"}, {"operatingSystem": "macOS 11.5.2", "hardwarePlatform": "Apple M1 Mac Mini", "processors": "M1", "paa_pai": "Yes", "hypervisorHostOs": "N/A", "version": "3.1.2"}, {"operatingSystem": "macOS 11.5.2", "hardwarePlatform": "Apple i7 Mac Mini", "processors": "Intel i7", "paa_pai": "No", "hypervisorHostOs": "N/A", "version": "3.1.2"}, {"operatingSystem": "macOS 11.5.2", "hardwarePlatform": "Apple i7 Mac Mini", "processors": "Intel i7", "paa_pai": "Yes", "hypervisorHostOs": "N/A", "version": "3.1.2"}]}, "vendor_affirmed_op_env_sw_fw_hy": {"section": 2, "subsection": 2, "found": true, "entries": [{"operatingSystem": "N/A", "hardwarePlatform": "N/A"}]}, "modes_of_operation": {"section": 2, "subsection": 4, "found": true, "entries": [{"name": "Approved mode", "description": "The module must be installed and configured per instructions provided in Section 11 of this document", "type": "Approved", "statusIndicator": "fips=yes"}, {"name": "", "description": "and the module is in the Approved mode by default as a result. The installation of the Module as described in Section 11 results in the settings described below this table, which are required for operation in the Approved mode", "type": "", "statusIndicator": ""}, {"name": "Non- Approved mode", "description": "The module is in the Approved mode of operation by default. Use of the non-Approved Algorithms Not Allowed in the Approved Mode will place the module in the non-approved mode of operation.", "type": "Non- Approved", "statusIndicator": "fips=no"}]}, "approved_algorithms": {"section": 2, "subsection": 5, "found": true, "entries": [{"algorithm": "AES-CBC", "cavpCertName": "A3548", "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256", "reference": "SP 800-38A"}, {"algorithm": "AES-CBC-CS1", "cavpCertName": "A3548", "properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256", "reference": "SP 800-38A"}, {"algorithm": "AES-CBC-CS2", "cavpCertName": "A3548", "properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256", "reference": "SP 800-38A"}, {"algorithm": "AES-CBC-CS3", "cavpCertName": "A3548", "properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256", "reference": "SP 800-38A"}, {"algorithm": "AES-CCM", "cavpCertName": "A3548", "properties": "Key Length - 128, 192, 256", "reference": "SP 800-38C"}, {"algorithm": "AES-CFB1", "cavpCertName": "A3548", "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256", "reference": "SP 800-38A"}, {"algorithm": "AES-CFB128", "cavpCertName": "A3548", "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256", "reference": "SP 800-38A"}, {"algorithm": "AES-CFB8", "cavpCertName": "A3548", "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256", "reference": "SP 800-38A"}, {"algorithm": "AES-CMAC", "cavpCertName": "A3548", "properties": "Direction - Generation, Verification Key Length - 128, 192, 256", "reference": "SP 800-38B"}, {"algorithm": "AES-CTR", "cavpCertName": "A3548", "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256", "reference": "SP 800-38A"}, {"algorithm": "AES-ECB", "cavpCertName": "A3548", "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256", "reference": "SP 800-38A"}, {"algorithm": "AES-GCM", "cavpCertName": "A3548", "properties": "Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256", "reference": "SP 800-38D"}, {"algorithm": "AES-GMAC", "cavpCertName": "A3548", "properties": "Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256", "reference": "SP 800-38D"}, {"algorithm": "AES-KW", "cavpCertName": "A3548", "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256", "reference": "SP 800-38F"}, {"algorithm": "AES-KWP", "cavpCertName": "A3548", "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256", "reference": "SP 800-38F"}, {"algorithm": "AES-OFB", "cavpCertName": "A3548", "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256", "reference": "SP 800-38A"}, {"algorithm": "AES-XTS Testing Revision 2.0", "cavpCertName": "A3548", "properties": "Direction - Decrypt, Encrypt Key Length - 128, 256", "reference": "SP 800-38E"}, {"algorithm": "Counter DRBG", "cavpCertName": "A3548", "properties": "Prediction Resistance - Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - No, Yes", "reference": "SP 800-90A Rev. 1"}, {"algorithm": "DSA KeyGen (FIPS186-4)", "cavpCertName": "A3548", "properties": "L - 2048, 3072 N - 224, 256", "reference": "FIPS 186-4"}, {"algorithm": "DSA PQGGen (FIPS186-4)", "cavpCertName": "A3548", "properties": "L - 2048, 3072 N - 224, 256 Hash Algorithm - SHA2-224, SHA2-256, SHA2- 384, SHA2-512, SHA2-512/224, SHA2-512/256", "reference": "FIPS 186-4"}, {"algorithm": "DSA PQGVer (FIPS186-4)", "cavpCertName": "A3548", "properties": "L - 1024, 2048, 3072 N - 160, 224, 256 Hash Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256", "reference": "FIPS 186-4"}, {"algorithm": "DSA SigGen (FIPS186-4)", "cavpCertName": "A3548", "properties": "L - 2048, 3072 N - 224, 256 Hash Algorithm - SHA2-224, SHA2-256, SHA2- 384, SHA2-512, SHA2-512/224, SHA2-512/256", "reference": "FIPS 186-4"}, {"algorithm": "DSA SigVer (FIPS186-4)", "cavpCertName": "A3548", "properties": "L - 1024, 2048, 3072 N - 160, 224, 256 Hash Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256", "reference": "FIPS 186-4"}, {"algorithm": "ECDSA KeyGen (FIPS186-4)", "cavpCertName": "A3548", "properties": "Curve - B-233, B-283, B-409, B-571, K-233, K- 283, K-409, K-571, P-224, P-256, P-384, P-521 Secret Generation Mode - Testing Candidates", "reference": "FIPS 186-4"}, {"algorithm": "ECDSA KeyVer (FIPS186-4)", "cavpCertName": "A3548", "properties": "Curve - B-163, B-233, B-283, B-409, B-571, K- 163, K-233, K-283, K-409, K-571, P-192, P- 224, P-256, P-384, P-521", "reference": "FIPS 186-4"}, {"algorithm": "ECDSA SigGen (FIPS186-4)", "cavpCertName": "A3548", "properties": "Component - No, Yes Curve - B-233, B-283, B-409, B-571, K-233, K- 283, K-409, K-571, P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2- 384, SHA2-512, SHA2-512/224, SHA2- 512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512", "reference": "FIPS 186-4"}, {"algorithm": "ECDSA SigVer (FIPS186-4)", "cavpCertName": "A3548", "properties": "Component - No, Yes Curve - B-163, B-233, B-283, B-409, B-571, K- 163, K-233, K-283, K-409, K-571, P-192, P- 224, P-256, P-384, P-521 Hash Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512", "reference": "FIPS 186-4"}, {"algorithm": "Hash DRBG", "cavpCertName": "A3548", "properties": "Prediction Resistance - Yes Mode - SHA-1, SHA2-224, SHA2-256, SHA2- 384, SHA2-512, SHA2-512/224, SHA2- 512/256, SHA3-256, SHA3-512", "reference": "SP 800-90A Rev. 1"}, {"algorithm": "HMAC DRBG", "cavpCertName": "A3548", "properties": "Prediction Resistance - Yes Mode - SHA-1, SHA2-224, SHA2-256, SHA2- 384, SHA2-512, SHA2-512/224, SHA2- 512/256, SHA3-256, SHA3-512", "reference": "SP 800-90A Rev. 1"}, {"algorithm": "HMAC-SHA-1", "cavpCertName": "A3548", "properties": "Key Length - Key Length: 8-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA2-224", "cavpCertName": "A3548", "properties": "Key Length - Key Length: 8-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA2-256", "cavpCertName": "A3548", "properties": "Key Length - Key Length: 8-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA2-384", "cavpCertName": "A3548", "properties": "Key Length - Key Length: 8-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA2-512", "cavpCertName": "A3548", "properties": "Key Length - Key Length: 8-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA2- 512/224", "cavpCertName": "A3548", "properties": "Key Length - Key Length: 8-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA2- 512/256", "cavpCertName": "A3548", "properties": "Key Length - Key Length: 8-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA3-224", "cavpCertName": "A3548", "properties": "Key Length - Key Length: 8-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA3-256", "cavpCertName": "A3548", "properties": "Key Length - Key Length: 8-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA3-384", "cavpCertName": "A3548", "properties": "Key Length - Key Length: 8-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA3-512", "cavpCertName": "A3548", "properties": "Key Length - Key Length: 8-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "KAS-ECC CDH- Component SP800-56Ar3 (CVL)", "cavpCertName": "A3548", "properties": "Curve - B-233, B-283, B-409, B-571, K-233, K- 283, K-409, K-571, P-224, P-256, P-384, P-521", "reference": "SP 800-56A Rev. 3"}, {"algorithm": "KAS-ECC-SSC Sp800-56Ar3", "cavpCertName": "A3548", "properties": "Domain Parameter Generation Methods - B- 233, B-283, B-409, B-571, K-233, K-283, K- 409, K-571, P-224, P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responder", "reference": "SP 800-56A Rev. 3"}, {"algorithm": "KAS-FFC-SSC Sp800-56Ar3", "cavpCertName": "A3548", "properties": "Domain Parameter Generation Methods - FB, FC, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP- 3072, MODP-4096, MODP-6144, MODP-8192 Scheme - dhEphem - KAS Role - initiator, responder", "reference": "SP 800-56A Rev. 3"}, {"algorithm": "KAS-IFC-SSC", "cavpCertName": "A3548", "properties": "Modulo - 2048, 3072, 4096, 6144, 8192 Key Generation Methods - rsakpg1-basic, rsakpg1-crt, rsakpg1-prime-factor, rsakpg2- basic, rsakpg2-crt, rsakpg2-prime-factor Scheme - KAS1 - KAS Role - initiator, responder KAS2 - KAS Role - initiator, responder", "reference": "SP 800-56A Rev. 3"}, {"algorithm": "KDA HKDF SP800-56Cr2", "cavpCertName": "A3548", "properties": "Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8 HMAC Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512", "reference": "SP 800-56C Rev. 2"}, {"algorithm": "KDA OneStep SP800-56Cr2", "cavpCertName": "A3548", "properties": "Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8", "reference": "SP 800-56C Rev. 2"}, {"algorithm": "KDA TwoStep SP800-56Cr2", "cavpCertName": "A3548", "properties": "MAC Salting Methods - default, random KDF Mode - feedback Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8", "reference": "SP 800-56C Rev. 2"}, {"algorithm": "KDF ANS 9.42 (CVL)", "cavpCertName": "A3548", "properties": "KDF Type - DER Hash Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512 Key Data Length - Key Data Length: 8-4096 Increment 8", "reference": "SP 800-135 Rev. 1"}, {"algorithm": "KDF ANS 9.63 (CVL)", "cavpCertName": "A3548", "properties": "Hash Algorithm - SHA2-224, SHA2-256, SHA2- 384, SHA2-512 Key Data Length - Key Data Length: 128, 4096", "reference": "SP 800-135 Rev. 1"}, {"algorithm": "KDF KMAC Sp800-108r1", "cavpCertName": "A3548", "properties": "Derived Key Length - Derived Key Length: 112- 4096 Increment 8", "reference": "SP 800-108 Rev. 1"}, {"algorithm": "KDF SP800-108", "cavpCertName": "A3548", "properties": "KDF Mode - Counter, Feedback Supported Lengths - Supported Lengths: 8, 72, 128, 776, 3456, 4096", "reference": "SP 800-108 Rev. 1"}, {"algorithm": "KDF SSH (CVL)", "cavpCertName": "A3548", "properties": "Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512", "reference": "SP 800-135 Rev. 1"}, {"algorithm": "KMAC-128", "cavpCertName": "A3548", "properties": "Message Length - Message Length: 0-65536 Increment 8 Key Data Length - Key Data Length: 128-1024 Increment 8", "reference": "SP 800-185"}, {"algorithm": "KMAC-256", "cavpCertName": "A3548", "properties": "Message Length - Message Length: 0-65536 Increment 8 Key Data Length - Key Data Length: 128-1024 Increment 8", "reference": "SP 800-185"}, {"algorithm": "KTS-IFC", "cavpCertName": "A3548", "properties": "Modulo - 2048, 3072, 4096, 6144 Key Generation Methods - rsakpg1-basic, rsakpg1-crt, rsakpg1-prime-factor, rsakpg2- basic, rsakpg2-crt, rsakpg2-prime-factor Scheme - KTS-OAEP-basic - KAS Role - initiator, responder", "reference": "SP 800-56B Rev. 2"}, {"algorithm": "", "cavpCertName": "", "properties": "Key Transport Method - Key Length - 1024", "reference": ""}, {"algorithm": "PBKDF", "cavpCertName": "A3548", "properties": "Iteration Count - Iteration Count: 1-10000 Increment 1 Password Length - Password Length: 8-128 Increment 8", "reference": "SP 800-132"}, {"algorithm": "RSA KeyGen (FIPS186-4)", "cavpCertName": "A3548", "properties": "Key Generation Mode - B.3.3, B.3.6 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2, Table C.3 Private Key Format - Standard", "reference": "FIPS 186-4"}, {"algorithm": "RSA SigGen (FIPS186-4)", "cavpCertName": "A3548", "properties": "Signature Type - ANSI X9.31, PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096", "reference": "FIPS 186-4"}, {"algorithm": "RSA Signature Primitive (CVL)", "cavpCertName": "A3548", "properties": "Private Key Format - CRT", "reference": "FIPS 186-4"}, {"algorithm": "RSA SigVer (FIPS186-4)", "cavpCertName": "A3548", "properties": "Signature Type - ANSI X9.31, PKCS 1.5, PKCSPSS Modulo - 1024, 2048, 3072, 4096", "reference": "FIPS 186-4"}, {"algorithm": "Safe Primes Key Generation", "cavpCertName": "A3548", "properties": "Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192", "reference": "SP 800-56A Rev. 3"}, {"algorithm": "Safe Primes Key Verification", "cavpCertName": "A3548", "properties": "Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192", "reference": "SP 800-56A Rev. 3"}, {"algorithm": "SHA-1", "cavpCertName": "A3548", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8", "reference": "FIPS 180-4"}, {"algorithm": "SHA2-224", "cavpCertName": "A3548", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8", "reference": "FIPS 180-4"}, {"algorithm": "SHA2-256", "cavpCertName": "A3548", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8", "reference": "FIPS 180-4"}, {"algorithm": "SHA2-384", "cavpCertName": "A3548", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8", "reference": "FIPS 180-4"}, {"algorithm": "SHA2-512", "cavpCertName": "A3548", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8", "reference": "FIPS 180-4"}, {"algorithm": "SHA2-512/224", "cavpCertName": "A3548", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8", "reference": "FIPS 180-4"}, {"algorithm": "SHA2-512/256", "cavpCertName": "A3548", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8", "reference": "FIPS 180-4"}, {"algorithm": "SHA3-224", "cavpCertName": "A3548", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8", "reference": "FIPS 202"}, {"algorithm": "SHA3-256", "cavpCertName": "A3548", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8", "reference": "FIPS 202"}, {"algorithm": "SHA3-384", "cavpCertName": "A3548", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8", "reference": "FIPS 202"}, {"algorithm": "SHA3-512", "cavpCertName": "A3548", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8", "reference": "FIPS 202"}, {"algorithm": "SHAKE-128", "cavpCertName": "A3548", "properties": "Output Length - Output Length: 16-65536 Increment 8", "reference": "FIPS 202"}, {"algorithm": "SHAKE-256", "cavpCertName": "A3548", "properties": "Output Length - Output Length: 16-65536 Increment 8", "reference": "FIPS 202"}, {"algorithm": "TLS v1.2 KDF RFC7627 (CVL)", "cavpCertName": "A3548", "properties": "Hash Algorithm - SHA2-256, SHA2-384, SHA2- 512", "reference": "SP 800-135 Rev. 1"}, {"algorithm": "TLS v1.3 KDF (CVL)", "cavpCertName": "A3548", "properties": "HMAC Algorithm - SHA2-256, SHA2-384 KDF Running Modes - DHE, PSK, PSK-DHE", "reference": "SP 800-135 Rev. 1"}]}, "vendor_affirmed_algos": {"section": 2, "subsection": 5, "found": true, "entries": [{"name": "DSA PQGGen [FIPS 186- 4]", "algoPropList": "Key Size, Key Strength:L = 2048/N = 224 (s = 112), L = 2048/N = 256 (s = 112) L = 3072/N = 256 (s = 128) Mode/Method:PQGGen using SHA3", "implName": "OpenSSL Project OpenSSL 3.x FIPS Provider", "reference": "Vendor affirmed per IG C.C and IG C.B Resolution (bullet point #3)"}, {"name": "DSA PQGVer [FIPS 186- 4]", "algoPropList": "Key Size, Key Strength:L = 1024/N = 160 (s < 112) L = 2048/N = 224 (s = 112), L = 2048/N = 256 (s = 112) L = 3072/N = 256 (s = 128) Mode/Method:PQGVer using SHA3", "implName": "OpenSSL Project OpenSSL 3.x FIPS Provider", "reference": "Vendor affirmed per IG C.C and IG C.B Resolution (bullet point #3)"}, {"name": "DSA SigGen [FIPS 186- 4]", "algoPropList": "Key Size, Key Strength:L = 2048/N = 224 (s = 112), L = 2048/N = 256 (s = 112) L = 3072/N = 256 (s = 128) Mode/Method:SigGen using SHA3", "implName": "OpenSSL Project OpenSSL 3.x FIPS Provider", "reference": "Vendor affirmed per IG C.C and IG C.B Resolution (bullet point #3)"}, {"name": "DSA SigVer [FIPS186- 4]", "algoPropList": "Key Size, Key Strength:L = 1024/N = 160 (s < 112) L = 2048/N = 224 (s = 112), L = 2048/N = 256 (s = 112) L = 3072/N = 256 (s = 128) Mode/Method:SigVer using SHA3", "implName": "OpenSSL Project OpenSSL 3.x FIPS Provider", "reference": "Vendor affirmed per IG C.C and IG C.B Resolution (bullet point #3)"}, {"name": "CKG - Section 4 and 5.1", "algoPropList": "Key Type :Asymmetric", "implName": "N/A", "reference": "NIST SP800-133r2 Section 4: Using the Output of a Random Bit Generator; Section 5.1: Key Pairs for Digital Signature Schemes"}, {"name": "CKG - Section 4 and 5.2", "algoPropList": "Key Type:Asymmetric", "implName": "N/A", "reference": "NIST SP800-133r2 Section 4: Using the Output of a Random Bit Generator; Section 5.2: Key Pairs for Key Establishment"}, {"name": "CKG - Section 4 and Section 6.1", "algoPropList": "Key Type:Symmetric", "implName": "N/A", "reference": "NIST SP800-133r2 Section 4: Using the Output of a Random Bit Generator; Section 6.1: Direct Generation of Symmetric Keys"}, {"name": "CKG - Section 6.2", "algoPropList": "Key Type:Symmetric", "implName": "N/A", "reference": "NIST SP 800-133r2 Section 6.2: Derivation of Symmetric keys"}, {"name": "CKG - Section 6.3", "algoPropList": "Key Type:Symmetric", "implName": "N/A", "reference": "NIST SP 800-133rev2, Section 6.3: Symmetric Keys Produced by Combining Multiple Keys and Other Data"}, {"name": "CKG - Section 4", "algoPropList": "Key Type:Symmetric", "implName": "N/A", "reference": "NIST SP800-133r2 Section 4: Using the Output of a Random Bit Random bits returned to the calling application"}]}, "non_approved_allowed_algos": {"section": 2, "subsection": 5, "found": true, "entries": [{"name": "AES", "algoPropList": "AES KW, KWP (Cert.#A3548):Symmetric key unwrapping", "implName": "OpenSSL Project OpenSSL 3.x FIPS Provider", "reference": "Per IG D.G Additional Comment 5"}]}, "non_approved_allowed_NSC": {"section": 2, "subsection": 5, "found": true, "entries": [{"name": "N/A", "caveat": "N/A", "use": "N/A"}]}, "non_approved_not_allowed": {"section": 2, "subsection": 5, "found": true, "entries": [{"name": "Triple-DES", "use": "Provides 3-Key ECB and CBC mode, but indicated as fips=no, Encryption, Decryption"}, {"name": "Ed448", "use": "SHAKE256, Ed448 provides 224 bits of security, Digital Signature Generation"}, {"name": "Ed25519", "use": "SHA2-512, Ed25519 provides 128 bits of security, Digital Signature Generation"}, {"name": "X448", "use": "Provides 224 bits of security, Key Agreement"}, {"name": "X25519", "use": "Provides 128 bits of security, Key Agreement"}, {"name": "ECDSA SigVer Component", "use": "Provides between 80 and 256 bits for security, Curves: B-163, B-233, B-283, B-409, B-571, K-163, K-233, K-283, K-409, K-571, P-192, P- 224, P-256, P-384, P-521, Digital Signature Verification"}, {"name": "FIPS 186-2 RSA SigGen/SigVer", "use": "Provides >= 80 bits of security, RSA signature generation/verification per FIPS 186-2"}, {"name": "FIPS 186-2 RSA KeyGen", "use": "Provides >= 112 bits of security, RSA key generation per FIPS 186-2"}, {"name": "X942KDF- CONCAT", "use": "Usage of X942KDF-CONCAT with PRF SHA-1, SHA2-512/224, SHA2- 512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512, SHAKE128, SHAKE256, KECCAK-KMAC128 and KECCAK-KMAC256"}, {"name": "X963KDF", "use": "Usage of X963KDF with PRF SHA-1, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512, SHAKE128, SHAKE256, KECCAK-KMAC128 and KECCAK-KMAC256"}, {"name": "HKDF", "use": "Provides < 112 bits of security, Usage of HKDF with key length less than 112 bits"}, {"name": "OneStep KDF", "use": "Usage of OneStep KDF with PRF SHAKE128, SHAKE256"}, {"name": "HMAC", "use": "Provides < 112 bits of security, Usage of HMAC with key length less than 112 bits for MAC generation"}, {"name": "Hash and HMAC DRBG", "use": "Usage of Hash and HMAC DRBGs with PRFs SHA2-224, SHA2-384, SHA2-512/224 and SHA2-512/256"}]}, "ports_interfaces": {"section": 3, "subsection": 1, "found": true, "entries": [{"physicalPort": "N/A", "logicalInterface": "Control Input", "data": "API entry point: stack frame including non-sensitive parameters"}, {"physicalPort": "N/A", "logicalInterface": "Data Input", "data": "API call parameters passed by reference or value for cryptographic service input"}, {"physicalPort": "N/A", "logicalInterface": "Status Output", "data": "API return value: enumerated status resulting from call execution"}, {"physicalPort": "N/A", "logicalInterface": "Data Output", "data": "API call parameters passed by reference for cryptographic service output"}]}, "authentication_methods": {"section": 4, "subsection": 1, "found": false, "entries": []}, "roles": {"section": 4, "subsection": 2, "found": true, "entries": [{"name": "Crypto Officer", "type": "Role", "operatorType": "Crypto Officer", "authMethodList": "None"}]}, "approved_services": {"section": 4, "subsection": 3, "found": true, "entries": [{"name": "Initialize", "description": "Module initialization", "indicator": "FIPS_O K", "inputs": "Core handle, dispatch in and out, provider context", "outputs": "Initializatio n status (1 = pass, 0 = fail)", "secFunImpl": "Random Number Generatio n", "rolesSspAccess": "Crypto Officer - DRBG_E I: G,W,E,Z - DRBG_S tate: G - Software Integrity key: E"}, {"name": "Core (all except Teardown) (Show Status, Show Version)", "description": "Show status; Core operations dispatched by FIPS provider: Metadata (Gettable parameters; Get parameters; Get capabilities); Query; Self- test", "indicator": "FIPS_O K", "inputs": "Provider context, paramete rs types (array), capability , callback pointer and argument s, operation ID", "outputs": "Parameter types (array) with: Name, Version, BuildInfo, Status, SecurityCh ecks; Status return, TLS group capabilities , Null or array of", "secFunImpl": "None", "rolesSspAccess": "Crypto Officer"}, {"name": "", "description": "", "indicator": "", "inputs": "", "outputs": "available operations", "secFunImpl": "", "rolesSspAccess": ""}, {"name": "Core: Perform self-tests", "description": "Run the self- test sequence", "indicator": "FIPS_O K", "inputs": "Provider context", "outputs": "Status (1 = pass, 0 = fail)", "secFunImpl": "Perform self-tests (All) Software Integrity Test", "rolesSspAccess": "Crypto Officer"}, {"name": "Core: Teardown (Perform zeroisation)", "description": "Uninstantiate the module; includes Zeroise", "indicator": "FIPS_O K", "inputs": "Provider context", "outputs": "None", "secFunImpl": "None", "rolesSspAccess": "Crypto Officer - DS_SGK : Z - DS_SVK: Z - GKP_Pri vate: Z - GKP_Pu blic: Z - KAS_Priv ate: Z - KAS_Pu blic: Z - KAS_SS: Z - KD_DKM : Z - KH_Key: Z - KTS_KD K: Z - KTS_KE K: Z - KTS_SS: Z - DRBG_E"}, {"name": "", "description": "", "indicator": "", "inputs": "", "outputs": "", "secFunImpl": "", "rolesSspAccess": "I: Z - DRBG_S eed: Z - DRBG_S tate: Z - SC_EDK: Z - Software Integrity key: Z"}, {"name": "Asymmetric cipher (Key Transport) (Perform approved security functions)", "description": "Encapsulate or decapsulate key material on behalf of the calling process (does not establish keys into the module)", "indicator": "[KTS- IFC: RSA, 4, (2048, 3072, 4096, 6144, 8192)]", "inputs": "Encapsul ate: Key struct (KTS_KD K); Decapsul ate (KTS_KE K)", "outputs": "Status return; KTS_SS", "secFunImpl": "KTS-4", "rolesSspAccess": "Crypto Officer - KTS_KD K: E - KTS_KE K: E - KTS_SS:"}, {"name": "Cipher (Encryption/Dec ryption and Key Wrapping) (Perform approved security functions)", "description": "Encrypt or decrypt data, including AEAD modes (CCM, GCM) and key wrap (KW, KWP) (CSPs are passed in by the calling process or generated within the module)", "indicator": "[AES- ECB: AES- 128- ECB, AES- 192- ECB, AES- 256- ECB]; [AES- CBC: AES- 128- CBC, AES- 192- CBC, AES- 256- CBC]; [AES-", "inputs": "SC_EDK and KH_Key (for key wrapping ); flags", "outputs": "Status return. Plaintext or ciphertext data, or wrapped key", "secFunImpl": "Symmetri c Encryptio n and Decryptio n Keyed Hash KTS-1 KTS-2 KTS-3 Cryptogra phic Key Generatio n (CKG) Cryptogra phic Key Generatio n (CKG) - AES XTS", "rolesSspAccess": "R Crypto Officer - SC_EDK: E - KH_Key: E"}, {"name": "", "description": "", "indicator": "CBC- CS: AES- 128- CBC- CTS, AES- 192- CBC- CTS, AES- 256- CBC- CTS]; [AES- OFB: AES- 128- OFB, AES- 192- OFB, AES- 256- OFB]; [AES- CFB1: AES- 128- CFB1, AES- 192- CFB1, AES- 256- CFB1]; [AES- CFB8: AES- 128- CFB8, AES- 192- CFB8, AES- 256- CFB8]; [AES-", "inputs": "", "outputs": "", "secFunImpl": "", "rolesSspAccess": ""}, {"name": "", "description": "", "indicator": "CFB128: AES- 128- CFB, AES- 192- CFB, AES- 256- CFB]; [AES- CTR: AES- 128- CTR, AES- 192- CTR, AES- 256- CTR]; [AES- CCM: AES- 128- CCM, AES- 192- CCM, AES- 256- CCM]; [AES- GCM: AES- 128- GCM, AES- 192- GCM, AES- 256- GCM]; [AES- XTS: AES- 128- XTS,", "inputs": "", "outputs": "", "secFunImpl": "", "rolesSspAccess": ""}, {"name": "", "description": "", "indicator": "AES- 256- XTS]; [AES- KW, KWP: AES- 128- WRAP, AES- 256- WRAP]", "inputs": "", "outputs": "", "secFunImpl": "", "rolesSspAccess": ""}, {"name": "Key derivation (Perform approved security functions)", "description": "Derive keying material", "indicator": "[PBKDF: PBKDF2 , (SHA- 1, SHA2- 224, SHA2- 256, SHA2- 384, SHA2- 512, SHA2- 512/224, SHA2- 512/256, SHA3- 224, SHA3- 256, SHA3- 384, SHA3- 512)]; [TLS1- PRF, (SHA2- 256, SHA2- 384, SHA2- 512)]; [TLS13- KDF, (SHA2- 256,", "inputs": "KAS_SS; flags", "outputs": "Status return; KD_DKM", "secFunImpl": "Key Derivatio n", "rolesSspAccess": "Crypto Officer - KAS_SS: W,E - KD_DKM : G,R - KTS_SS: W,E - PBKDF Passwor d: W,E,Z"}, {"name": "", "description": "", "indicator": "SHA2- 384)]; [X963- KDF, (SHA2- 224, SHA2- 256, SHA2- 384, SHA2- 512)]; [X942KD F-ASNI, (SHA1, SHA2- 224, SHA2- 256, SHA2- 384, SHA2- 512, SHA2- 512/224, SHA2- 512/256, SHA3- 224, SHA3- 256, SHA3- 384, SHA3- 512)]; [NIST SP 800- 108r1 KDF KMAC: KBKDF, (KMAC- 128, KMAC- 256)]; [NIST SP 800- 108r1", "inputs": "", "outputs": "", "secFunImpl": "", "rolesSspAccess": ""}, {"name": "", "description": "", "indicator": "KDF: KBKDF, MAC: CMAC, Cipher: AES- 128- CBC, AES- 192- CBC, AES- 256- CBC, MAC: HMAC- SHA1, HMAC- SHA2- 224, HMAC- SHA2- 256, HMAC- SHA2- 384, HMAC- SHA2- 256, HMAC- SHA2- 384, HMAC- SHA2- 512, HMAC- SHA2- 512/224, HMAC- SHA2- 512/256, HMAC- SHA3- 224, HMAC- SHA3- 256, HMAC-", "inputs": "", "outputs": "", "secFunImpl": "", "rolesSspAccess": ""}, {"name": "", "description": "", "indicator": "SHA3- 384, HMAC- SHA3- 512]; [KDF SSH: SSHKD F, (SHA1, SHA2- 224, SHA2- 256, SHA2- 384, SHA2- 512)]; [OneSte p KDF: SSKDF, (SHA1, SHA2- 224, SHA2- 256, SHA2- 384, SHA2- 512, SHA2- 512/224, SHA2- 512/256, SHA3- 224, SHA3- 256, SHA3- 384, SHA3- 512, HMAC- SHA1, HMAC- SHA2- 224, HMAC-", "inputs": "", "outputs": "", "secFunImpl": "", "rolesSspAccess": ""}, {"name": "", "description": "", "indicator": "SHA2- 256, HMAC- SHA2- 384, HMAC- SHA2- 512, HMAC- SHA2- 512/224, HMAC- SHA2- 512/256, SHA3- 224, SHA3- 256, SHA3- 384, SHA3- 512, KMAC- 128, KMAC- 256)]; [TwoSte p KDF: HKDF, MAC: HMAC, (SHA1, SHA2- 224, SHA2- 256, SHA2- 384, SHA2- 512, SHA2- 512/224, SHA2- 512/256, SHA3- 224, SHA3- 256,", "inputs": "", "outputs": "", "secFunImpl": "", "rolesSspAccess": ""}, {"name": "", "description": "", "indicator": "SHA3- 384, SHA3- 512]; [HKDF: HKDF, MAC: HMAC, (SHA1, SHA2- 224, SHA2- 256, SHA2- 384, SHA2- 512, SHA2- 512/224, SHA2- 512/256, SHA3- 224, SHA3- 256, SHA3- 384, SHA3- 512];", "inputs": "", "outputs": "", "secFunImpl": "", "rolesSspAccess": ""}, {"name": "Key exchange (Perform approved security functions)", "description": "Perform key agreement primitives on behalf of the calling process (does not establish keys into the module)", "indicator": "[KAS- FFC- SSC: DHX]; [KAS- ECC- SSC: EC]", "inputs": "Key structs (KAS_Pri vate and KAS_Pu blic); flags", "outputs": "Status return; KAS_SS", "secFunImpl": "KAS-1 KAS-2 KAS-3 KAS ECC CDH Compone nt", "rolesSspAccess": "Crypto Officer - KAS_Priv ate: E - KAS_Pu blic: E - KAS_SS: G"}, {"name": "Key management (Perform approved security functions)", "description": "Generate asymmetric key pairs", "indicator": "[SafePri mes: DHX]; [RSA KeyGen: RSA, (2048, 3072,", "inputs": "ECDSA: curve identifier. DSA/RS A: modulus size", "outputs": "Status return; Key struct (GKP_Priv ate, GKP_Publi c)", "secFunImpl": "Asymmet ric Key Pair Generatio n", "rolesSspAccess": "Crypto Officer - GKP_Pri vate: G - GKP_Pu blic: G"}, {"name": "", "description": "", "indicator": "4096)]; [ECDSA KeyGen: EC]; [DSA KeyGen: DSA, (L=2048, N=28, 32), (L=3072, N=32)]", "inputs": "", "outputs": "", "secFunImpl": "", "rolesSspAccess": ""}, {"name": "Message authentication (Perform approved security functions)", "description": "Generate or verify data integrity. (CSPs are passed in by the calling process or generated within the module)", "indicator": "[HMAC: HMAC- SHA1, HMAC- SHA2- 224, HMAC- SHA2- 256, HMAC- SHA2- 384, HMAC- SHA2- 512, HMAC- SHA2- 512/224, HMAC- SHA2- 512/256, HMAC- SHA3- 224, HMAC- SHA3- 256, HMAC- SHA3- 384, HMAC- SHA3- 512]; [CMAC]; [KMAC: KMAC-", "inputs": "KH_Key", "outputs": "Status return; Tag value", "secFunImpl": "Keyed Hash Cryptogra phic Key Generatio n (CKG)", "rolesSspAccess": "Crypto Officer - KH_Key: E"}, {"name": "", "description": "", "indicator": "128, KMAC- 256]; [GMAC: AES- 128- GCM, AES- 192- GCM, AES- 256- GCM]", "inputs": "", "outputs": "", "secFunImpl": "", "rolesSspAccess": ""}, {"name": "Message digest (Perform approved security functions)", "description": "Generate a message digest", "indicator": "[SHA-1, SHA2- 224, SHA2- 256, SHA2- 384, SHA2- 512, SHA2- 512/224, SHA2- 512/256, SHA3- 224, SHA3- 256, SHA3- 384, SHA3- 512, SHAKE- 128, SHAKE- 256]", "inputs": "Message ; flags", "outputs": "Status return; Hash value", "secFunImpl": "Message Digest", "rolesSspAccess": "Crypto Officer"}, {"name": "Random (Perform approved security functions)", "description": "Generate random bits using the DRBG", "indicator": "[Hash DRBG: HASH- DRBG, (SHA1, SHA2- 256, SHA2- 512)]; [HMAC-", "inputs": "DRBG struct (RBG State); DRBG_E I", "outputs": "Status return; Random value", "secFunImpl": "Random Number Generatio n", "rolesSspAccess": "Crypto Officer - DRBG_E I: E - DRBG_S eed: E -"}, {"name": "", "description": "", "indicator": "DRBG, (SHA1, SHA2- 256, SHA2- 512)]; [CTR- DRBG, (AES- 128- CTR, AES- 192- CTR, AES- 256- CTR)]", "inputs": "", "outputs": "", "secFunImpl": "", "rolesSspAccess": "DRBG_S tate: E"}, {"name": "Signature (Perform approved security functions)", "description": "Generate or verify digital signatures (SSPs are passed in by the calling process)", "indicator": "[RSA SigGen: RSA, (2048, 3072, 4096), (SHA2- 224, SHA2- 256, SHA2- 384, SHA2- 512, SHA2- 512/224, SHA2- 512/256) ]; [RSA SigVer: RSA, (1024, 2048, 3072, 4096), (SHA1, SHA2- 224, SHA2- 256, SHA2-", "inputs": "Sign: Key struct (DS_SG K); message ; Verify: signature value; Key struct (DS_SV K); flags; sizes", "outputs": "Status return; Signature value", "secFunImpl": "RSA Digital Signature Generatio n and Verificatio n ECDSA Signature Generatio n and Signature Verificatio n DSA Digital Signature Generatio n and Verificatio n RSA Signature Primitive", "rolesSspAccess": "Crypto Officer - DS_SGK : E - DS_SVK: E"}, {"name": "", "description": "", "indicator": "384, SHA2- 512, SHA2- 512/224, SHA2- 512/256) ]; [RSA Signatur e Primitive : RSA, 2048, hash algorith m: (null)]; [ECDSA SigGen: EC, (SHA2- 224, SHA2- 256, SHA2- 384, SHA2- 512, SHA3- 224, SHA3- 256, SHA3- 384, SHA3- 512)]; [ECDSA SigVer: EC, (SHA1, SHA2- 224, SHA2- 256, SHA2- 384, SHA2- 512,", "inputs": "", "outputs": "", "secFunImpl": "", "rolesSspAccess": ""}, {"name": "", "description": "", "indicator": "SHA2- 512/224, SHA2- 512/256) ]; [ECDSA SigGen Compon ent]: EC, hash: (null)]; [DSA, PQGGe n: DSA, (L= 2048, N=28, SHA2- 224, SHA2- 256, SHA2- 384, SHA2- 512, SHA2- 512/224, SHA2- 512/256) , (L=2048, 3072, N=32, =SHA2- 256, SHA2- 384, SHA2- 512, SHA2- 512/256) ]; [DSA PQGVer : DSA, N=20 bytes, 28", "inputs": "", "outputs": "", "secFunImpl": "", "rolesSspAccess": ""}, {"name": "", "description": "", "indicator": "32 bytes]; [DSA, SigGen: DSA, (L= 2048, 3072), (N=28, 32), (SHA2- 224, SHA2- 256, SHA2- 384, SHA2- 512, SHA2- 512/224, SHA2- 512/256) ]; [DSA, SigVer: DSA, (L=1024, N=20), (L=2048, N=28, 32), (L=3072, N=28, 32), (SHA1, SHA2- 224, SHA2- 256, SHA2- 384, SHA2- 512, SHA2- 512/224, SHA2- 512/256)", "inputs": "", "outputs": "", "secFunImpl": "", "rolesSspAccess": ""}, {"name": "Zeroise (Perform zeroisation)", "description": "\u2022The core Teardown operation zeroizes all Module scope SSPs \u2022Call stack cleanup is the duty of the application \u2022Restarting the general- purpose computer clears all SSPs in RAM \u2022OPENSSL_cl eanse provides zeroisation of SSPs managed by the caller; See the notes below this table for additional explanation", "indicator": "ZERO_ OK", "inputs": "Memory pointer", "outputs": "Void", "secFunImpl": "None", "rolesSspAccess": "Crypto Officer - DS_SGK : Z - DS_SVK: Z - GKP_Pri vate: Z - GKP_Pu blic: Z - KAS_Priv ate: Z - KAS_Pu blic: Z - KAS_SS: Z - KD_DKM : Z - KH_Key: Z - KTS_KD K: Z - KTS_KE K: Z - KTS_SS: Z - DRBG_E I: Z - DRBG_S eed: Z - DRBG_S tate: Z -"}, {"name": "", "description": "", "indicator": "", "inputs": "", "outputs": "", "secFunImpl": "", "rolesSspAccess": "SC_EDK: Z - Software Integrity key: Z"}]}, "non_approved_services": {"section": 4, "subsection": 4, "found": true, "entries": [{"name": "Signature", "description": "Generate or verify digital signatures (SSPs are passed in by the calling process)", "alg_accessed": "Ed448 Ed25519 FIPS 186-2 RSA SigGen/SigVer", "role": "Crypto Officer"}, {"name": "Key Exchange", "description": "Perform key agreement primitives on behalf of the calling process (does not establish keys into the module)", "alg_accessed": "X448 X25519", "role": "Crypto Officer"}, {"name": "Cipher (Encryption/Decryption)", "description": "Encrypt or decrypt data (CSPs are passed in by the calling process)", "alg_accessed": "Triple-DES", "role": "Crypto Officer"}, {"name": "ECDSA SigVer Component", "description": "Verify ECDSA digital signatures (SSPs are passed in by the calling process)", "alg_accessed": "ECDSA SigVer Component", "role": "Crypto Officer"}, {"name": "Key Derivation", "description": "Derive keys (key derivation key passed in by the calling process)", "alg_accessed": "X942KDF- CONCAT X963KDF HKDF OneStep KDF", "role": "Crypto Officer"}, {"name": "Key Generation", "description": "Generate RSA public/private key pair per FIPS 186-2", "alg_accessed": "FIPS 186-2 RSA KeyGen", "role": "Crypto Officer"}, {"name": "Keyed Hash", "description": "Generate HMAC using key length less than 112 bits", "alg_accessed": "HMAC", "role": "Crypto Officer"}, {"name": "Random", "description": "Generate random bits using the non-approved Hash and HMAC DRBGs with PRFs SHA2-224, SHA2-384, SHA2-512/224 and SHA2-512/256", "alg_accessed": "Hash and HMAC DRBG", "role": "Crypto Officer"}]}, "mechanisms_actions": {"section": 7, "subsection": 1, "found": false, "entries": []}, "storage_areas": {"section": 9, "subsection": 1, "found": true, "entries": [{"name": "RAM", "description": "Temporary, plaintext storage", "persistance": "Dynamic"}, {"name": "Stored in the module's configuration file", "description": "Persistent, plaintext storage", "persistance": "Static"}]}, "ssp_io_methods": {"section": 9, "subsection": 2, "found": true, "entries": [{"name": "CALL STACK (API) INPUT PARAMETER S", "source": "Calling application", "dest": "Module", "format": "Plaintex t", "distribution": "Manual", "entry": "Electroni c", "sfiAlgo": ""}, {"name": "CALL STACK (API) OUTPUT PARAMETER S", "source": "Module", "dest": "Calling application", "format": "Plaintex t", "distribution": "Manual", "entry": "Electroni c", "sfiAlgo": ""}, {"name": "Stored at manufacture", "source": "Manufacture r", "dest": "Stored in the module's configuratio n file", "format": "Plaintex t", "distribution": "N/A", "entry": "N/A", "sfiAlgo": ""}]}, "ssp_zeroization_methods": {"section": 9, "subsection": 3, "found": true, "entries": [{"method": "OPENSSL_cleanse", "description": "Zeroisation of SSPs managed by the caller", "rationale": "The OPENSSL_cleanse provides zeroisation of SSPs managed by the caller", "operatorId": "Module initiated"}, {"method": "cleared after use", "description": "Temporary copies of CSPs are zeroised within the relevant function for the scope within which they are used", "rationale": "CSPs with a lifetime associated with an OpenSSL object will be zeroized when reinitialized", "operatorId": "Module initiated"}, {"method": "Teardown", "description": "This operation triggers Module uninstantiation", "rationale": "CSPs with a lifetime associated with the Module are zeroised on Module uninstantiation", "operatorId": "Operator initiated"}, {"method": "Restarting the general-purpose computer", "description": "RAM (memory) is used for temporary storage of SSPs", "rationale": "Restarting the general- purpose computer clears all SSPs in RAM", "operatorId": "Operator initiated"}]}, "self_tests": {"section": 10, "subsection": 1, "found": true, "entries": [{"algorithmOrTest": "HMAC-SHA2- 256 (A3548)", "testProps": "Key Length: 256 bits", "testMethod": "KAT", "type": "SW/FW Integrity", "indicator": "Success: All self- tests passed (as expected)", "details": "MAC (HMAC- SHA2-256, A3548)"}]}, "cond_self_tests": {"section": 10, "subsection": 2, "found": true, "entries": [{"algorithmOrTest": "AES-ECB (A3548)", "testProps": "Key Length: 128 bits", "testMethod": "KAT", "type": "CAST", "indicator": "FIPS_OK", "details": "Decrypt", "condition": "On reloading the module"}, {"algorithmOrTest": "AES-GCM (A3548)", "testProps": "Key Length: 256 bits", "testMethod": "KAT", "type": "CAST", "indicator": "FIPS_OK", "details": "Encrypt", "condition": "On reloading the module"}, {"algorithmOrTest": "AES-GCM (A3548)", "testProps": "Key Length: 256 bits", "testMethod": "KAT", "type": "CAST", "indicator": "FIPS_OK", "details": "Decrypt", "condition": "On reloading the module"}, {"algorithmOrTest": "Counter DRBG (A3548)", "testProps": "AES CTR (128 bits) with derivation function", "testMethod": "KAT", "type": "CAST", "indicator": "FIPS_OK", "details": "Generate, Reseed, Instantiate functions", "condition": "On reloading the module"}, {"algorithmOrTest": "DSA SigGen (FIPS186- 4) (A3548)", "testProps": "Modulus: 2048 bits; Hash: SHA2-384", "testMethod": "KAT", "type": "CAST", "indicator": "FIPS_OK", "details": "Sign", "condition": "On reloading the module"}, {"algorithmOrTest": "DSA SigVer (FIPS186- 4) (A3548)", "testProps": "Modulus: 2048 bits; Hash: SHA2-384", "testMethod": "KAT", "type": "CAST", "indicator": "FIPS_OK", "details": "Verify", "condition": "On reloading the module"}, {"algorithmOrTest": "ECDSA SigGen (FIPS186- 4) (A3548)", "testProps": "Curve: P- 224; Hash: SHA2-512", "testMethod": "KAT", "type": "CAST", "indicator": "FIPS_OK", "details": "Sign", "condition": "On reloading the module"}, {"algorithmOrTest": "ECDSA SigVer (FIPS186- 4) (A3548)", "testProps": "Curve: P- 224; Hash: SHA2-512", "testMethod": "KAT", "type": "CAST", "indicator": "FIPS_OK", "details": "Verify", "condition": "On reloading the module"}, {"algorithmOrTest": "Hash DRBG (A3548)", "testProps": "PRF: SHA2-256", "testMethod": "KAT", "type": "CAST", "indicator": "FIPS_OK", "details": "Generate, Reseed, Instantiate functions", "condition": "On reloading the module"}, {"algorithmOrTest": "HMAC DRBG (A3548)", "testProps": "PRF: HMAC- SHA-1", "testMethod": "KAT", "type": "CAST", "indicator": "FIPS_OK", "details": "Generate, Reseed, Instantiate functions", "condition": "On reloading the module"}, {"algorithmOrTest": "HMAC- SHA2-256 (A3548)", "testProps": "PRF: SHA2-256", "testMethod": "KAT", "type": "CAST", "indicator": "FIPS_OK", "details": "HMAC tag Generation", "condition": "Performed prior to the software integrity test"}, {"algorithmOrTest": "KAS- ECC-SSC Sp800- 56Ar3 (A3548)", "testProps": "Scheme: Ephemeral Unified, Curve: P- 256", "testMethod": "KAT", "type": "CAST", "indicator": "FIPS_OK", "details": "Key Agreement - Shared Secret Computation", "condition": "On reloading the module"}, {"algorithmOrTest": "KAS-FFC- SSC Sp800- 56Ar3 (A3548)", "testProps": "Scheme: dhEphem; Modulus: L = 2048 bits, N = 256 bit", "testMethod": "KAT", "type": "CAST", "indicator": "FIPS_OK", "details": "Key Agreement - Shared Secret Computation", "condition": "On reloading the module"}, {"algorithmOrTest": "KAS-IFC- SSC (A3548)", "testProps": "Schemes: Basic, CRT, Modulus: L = 2048 bits", "testMethod": "KAT", "type": "CAST", "indicator": "FIPS_OK", "details": "Key Agreement - Shared Secret Computation", "condition": "On reloading the module"}, {"algorithmOrTest": "KDF SP800- 108 (A3548)", "testProps": "Mode: Counter, PRF: HMAC- SHA2-256", "testMethod": "KAT", "type": "CAST", "indicator": "FIPS_OK", "details": "Counter Mode (HMAC- SHA2-256).", "condition": "On reloading the module"}, {"algorithmOrTest": "KDA OneStep SP800- 56Cr2 (A3548)", "testProps": "Auxiliary Function, H = SHA2- 224", "testMethod": "KAT", "type": "CAST", "indicator": "FIPS_OK", "details": "Key Derivation", "condition": "On reloading the module"}, {"algorithmOrTest": "KDA TwoStep SP800- 56Cr2 (A3548)", "testProps": "Auxiliary Function, H = HMAC- SHA2-256", "testMethod": "KAT", "type": "CAST", "indicator": "FIPS_OK", "details": "Key Derivation", "condition": "On reloading the module"}, {"algorithmOrTest": "KTS-IFC (A3548)", "testProps": "Schemes: Basic Modulus: L = 2048 bits", "testMethod": "KAT", "type": "CAST", "indicator": "FIPS_OK", "details": "Encrypt", "condition": "On reloading the module"}, {"algorithmOrTest": "KTS-IFC (A3548)", "testProps": "Schemes: Basic,", "testMethod": "KAT", "type": "CAST", "indicator": "FIPS_OK", "details": "Decrypt", "condition": "On reloading the module"}, {"algorithmOrTest": "", "testProps": "CRT, Modulus: L = 2048 bits", "testMethod": "", "type": "", "indicator": "", "details": "", "condition": ""}, {"algorithmOrTest": "PBKDF (A3548)", "testProps": "Derivation of the Master Key (MK), PRF: SHA2-256", "testMethod": "KAT", "type": "CAST", "indicator": "FIPS_OK", "details": "Key Derivation", "condition": "On reloading the module"}, {"algorithmOrTest": "RSA SigGen (FIPS186- 4) (A3548)", "testProps": "Scheme: PKCS#1, Modulus: L = 2048, Hash: SHA2-256", "testMethod": "KAT", "type": "CAST", "indicator": "FIPS_OK", "details": "Sign", "condition": "On reloading the module"}, {"algorithmOrTest": "RSA SigVer (FIPS186- 4) (A3548)", "testProps": "Scheme: PKCS#1, Modulus: L = 2048, Hash: SHA2-256", "testMethod": "KAT", "type": "CAST", "indicator": "FIPS_OK", "details": "Verify", "condition": "On reloading the module"}, {"algorithmOrTest": "SHA-1 (A3548)", "testProps": "SHA-1", "testMethod": "KAT", "type": "CAST", "indicator": "FIPS_OK", "details": "Hash", "condition": "On reloading the module"}, {"algorithmOrTest": "SHA2-512 (A3548)", "testProps": "SHA2-512", "testMethod": "KAT", "type": "CAST", "indicator": "FIPS_OK", "details": "Hash", "condition": "On reloading the module"}, {"algorithmOrTest": "SHA3-256 (A3548)", "testProps": "SHA3-256", "testMethod": "KAT", "type": "CAST", "indicator": "FIPS_OK", "details": "Hash", "condition": "On reloading the module"}, {"algorithmOrTest": "KDF ANS 9.42 (A3548)", "testProps": "PRFs: AES KW (128 bits), SHA-1", "testMethod": "KAT", "type": "CAST", "indicator": "FIPS_OK", "details": "Key Derivation", "condition": "On reloading the module"}, {"algorithmOrTest": "KDF ANS 9.63 (A3548)", "testProps": "PRF: SHA2-256", "testMethod": "KAT", "type": "CAST", "indicator": "FIPS_OK", "details": "Key Derivation", "condition": "On reloading the module"}, {"algorithmOrTest": "KDF SSH (A3548)", "testProps": "PRF: SHA- 1", "testMethod": "KAT", "type": "CAST", "indicator": "FIPS_OK", "details": "Key Derivation", "condition": "On reloading the module"}, {"algorithmOrTest": "TLS v1.2 KDF RFC7627", "testProps": "PRF: SHA2-256", "testMethod": "KAT", "type": "CAST", "indicator": "FIPS_OK", "details": "Key Derivation", "condition": "On reloading the module"}, {"algorithmOrTest": "(A3548) TLS v1.3 KDF (A3548)", "testProps": "PRF: SHA2-256", "testMethod": "KAT", "type": "CAST", "indicator": "FIPS_OK", "details": "Key Derivation", "condition": "On reloading the module"}, {"algorithmOrTest": "RSA KeyGen (FIPS186- 4) (A3548)", "testProps": "Performed post key generation", "testMethod": "PCT", "type": "PCT", "indicator": "FIPS_OK", "details": "Key Generation", "condition": "On generating keys for Key Transport (KTS IFC)/Key Agreement (KAS IFC)/Signature"}, {"algorithmOrTest": "", "testProps": "", "testMethod": "", "type": "", "indicator": "", "details": "", "condition": "Generation/Signature Verification"}, {"algorithmOrTest": "ECDSA KeyGen (FIPS186- 4) (A3548)", "testProps": "Performed post key generation", "testMethod": "PCT", "type": "PCT", "indicator": "FIPS_OK", "details": "Key Generation", "condition": "On generating keys for Key Agreement (KAS ECC)/Signature Generation/Signature Verification"}, {"algorithmOrTest": "DSA KeyGen (FIPS186- 4) (A3548)", "testProps": "Performed post key generation", "testMethod": "PCT", "type": "PCT", "indicator": "FIPS_OK", "details": "Key Generation", "condition": "On generating keys for Key Agreement (KAS FFC)/Signature Generation/Signature Verification"}, {"algorithmOrTest": "ECDSA SigGen (FIPS186- 4) (A3548)", "testProps": "Curve: K- 233; Hash: SHA2-512", "testMethod": "KAT", "type": "CAST", "indicator": "FIPS_OK", "details": "Sign", "condition": "On reloading the module"}, {"algorithmOrTest": "ECDSA SigVer (FIPS186- 4) (A3548)", "testProps": "Curve: K- 233; Hash: SHA2-512", "testMethod": "KAT", "type": "CAST", "indicator": "FIPS_OK", "details": "Verify", "condition": "On reloading the module"}]}, "error_states": {"section": 10, "subsection": 4, "found": true, "entries": [{"name": "ERR OR STA TE", "description": "\u2022The error state is persistent and no services are available \u2022All attempts to use the Module's services result in the return of a non-zero error code, PROV_R_FIPS_MODULE_IN_ ERROR_STATE", "conditions": "If one of the KATs or if the Softwar e Integrit y Test fails, the Module enters the self-test failure error state", "recoveryMethod": "To recove r from an error state, reload the Modul e into memo ry", "indicator": "PROV_R_FIPS_MODULE_IN_ ERROR_STATE"}]}}}, "heuristics": {"_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics", "algorithms": {"_type": "Set", "elements": ["KDA OneStep SP800-56Cr2A3548", "HMAC-SHA3-512A3548", "AES-CTRA3548", "AES-ECBA3548", "AES-KWA3548", "KDA TwoStep SP800-56Cr2A3548", "AES-CFB128A3548", "KAS-IFC-SSCA3548", "SHA3-224A3548", "KTS-IFCA3548", "RSA SigGen (FIPS186-4)A3548", "RSA Signature PrimitiveA3548", "SHA2-384A3548", "AES-CBC-CS1A3548", "KDF SP800-108A3548", "HMAC-SHA2-384A3548", "AES-CBCA3548", "RSA KeyGen (FIPS186-4)A3548", "KMAC-256A3548", "SHA3-256A3548", "RSA SigVer (FIPS186-4)A3548", "Counter DRBGA3548", "ECDSA KeyGen (FIPS186-4)A3548", "AES-CMACA3548", "KMAC-128A3548", "AES-GMACA3548", "HMAC-SHA2-512/256A3548", "SHA3-512A3548", "KDA HKDF SP800-56Cr2A3548", "SHA2-224A3548", "KDF KMAC Sp800-108r1A3548", "ECDSA KeyVer (FIPS186-4)A3548", "SHA2-512/224A3548", "ECDSA SigVer (FIPS186-4)A3548", "ECDSA SigGen (FIPS186-4)A3548", "DSA SigGen (FIPS186-4)A3548", "HMAC-SHA-1A3548", "HMAC-SHA2-512/224A3548", "TLS v1.2 KDF RFC7627A3548", "AES-XTS Testing Revision 2.0A3548", "AES-KWPA3548", "HMAC-SHA3-384A3548", "DSA PQGVer (FIPS186-4)A3548", "PBKDFA3548", "SHA-1A3548", "Safe Primes Key VerificationA3548", "AES-CBC-CS3A3548", "HMAC-SHA2-224A3548", "AES-CFB8A3548", "AES-OFBA3548", "Hash DRBGA3548", "AES-CCMA3548", "HMAC DRBGA3548", "HMAC-SHA3-256A3548", "KDF ANS 9.63A3548", "SHA2-512A3548", "KAS-ECC CDH-Component SP800-56Ar3A3548", "DSA PQGGen (FIPS186-4)A3548", "AES-GCMA3548", "KDF ANS 9.42A3548", "KDF SSHA3548", "TLS v1.3 KDFA3548", "SHA2-256A3548", "AES-CFB1A3548", "HMAC-SHA3-224A3548", "HMAC-SHA2-256A3548", "AES-CBC-CS2A3548", "SHAKE-256A3548", "DSA KeyGen (FIPS186-4)A3548", "SHA2-512/256A3548", "SHAKE-128A3548", "Safe Primes Key GenerationA3548", "#A3548", "DSA SigVer (FIPS186-4)A3548", "KAS-ECC-SSC Sp800-56Ar3A3548", "SHA3-384A3548", "KAS-FFC-SSC Sp800-56Ar3A3548", "HMAC-SHA2-512A3548"]}, "extracted_versions": {"_type": "Set", "elements": ["-"]}, "cpe_matches": null, "verified_cpe_matches": null, "related_cves": null, "policy_prunned_references": {"_type": "Set", "elements": []}, "module_prunned_references": {"_type": "Set", "elements": []}, "policy_processed_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": null, "indirectly_referenced_by": null, "directly_referencing": null, "indirectly_referencing": null}, "module_processed_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": null, "indirectly_referenced_by": null, "directly_referencing": null, "indirectly_referencing": null}, "direct_transitive_cves": null, "indirect_transitive_cves": null}, "state": {"_type": "sec_certs.sample.fips.InternalState", "module": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": null, "txt_hash": null, "json_hash": null}, "policy": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": "c90ffca0ae477b84f20981f9bcccf46cb86731f8729b4961e195b82b55f8ea82", "txt_hash": "c3722e855e86ac4c7e64450a0dac848adf7bd981817fa8f958961a5c5ea434fc", "json_hash": "5e78a46b1e05d8a06fb21278c25a2829b4ca4670984a8abf2fdf63a4724cd95b"}}}