CiscoSSL FIPS Provider

Certificate details

Certificate ID #4891
Status historical
Historical reason Replaced by certificate #5430
Validation dates 18.11.2024
Standard FIPS 140-3
Security level 1
Type Firmware
Embodiment Multi-Chip Stand Alone
Caveat Interim validation. When operated in approved mode. No assurance of the minimum strength of generated SSPs (e.g., keys)
Exceptions
  • Non-invasive security: N/A
Description The CiscoSSL FIPS Provider is a firmware library that provides cryptographic services to a vast array of Cisco's networking and collaboration products. The module is comprised of a single object module file called fips.so.
Vendor Cisco Systems, Inc https://www.cisco.com/
Lab Acumen Security
Algorithms
  • AES-CBC-CS1A3252
  • AES-CBC-CS2A3252
  • AES-CBC-CS3A3252
  • AES-CBCA3252
  • AES-CCMA3252
  • AES-CFB128A3252
  • AES-CFB1A3252
  • AES-CFB8A3252
  • AES-CMACA3252
  • AES-CTRA3252
  • AES-ECBA3252
  • AES-GCMA3252
  • AES-GMACA3252
  • AES-KWA3252
  • AES-KWPA3252
  • AES-OFBA3252
  • AES-XTS Testing Revision 2.0A3252
  • Counter DRBGA3252
  • DSA KeyGen (FIPS186-4)A3252
  • DSA PQGGen (FIPS186-4)A3252
  • DSA PQGVer (FIPS186-4)A3252
  • DSA SigGen (FIPS186-4)A3252
  • DSA SigVer (FIPS186-4)A3252
  • ECDSA KeyGen (FIPS186-4)A3252
  • ECDSA KeyVer (FIPS186-4)A3252
  • ECDSA SigGen (FIPS186-4)A3252
  • ECDSA SigVer (FIPS186-4)A3252
  • Hash DRBGA3252
  • HMAC DRBGA3252
  • HMAC-SHA-1A3252
  • HMAC-SHA2-224A3252
  • HMAC-SHA2-256A3252
  • HMAC-SHA2-384A3252
  • HMAC-SHA2-512/224A3252
  • HMAC-SHA2-512/256A3252
  • HMAC-SHA2-512A3252
  • HMAC-SHA3-224A3252
  • HMAC-SHA3-256A3252
  • HMAC-SHA3-384A3252
  • HMAC-SHA3-512A3252
  • KAS-ECC CDH-Component SP800-56Ar3A3252
  • KAS-ECC-SSC Sp800-56Ar3A3252
  • KAS-FFC-SSC Sp800-56Ar3A3252
  • KAS-IFC-SSCA3252
  • KDA HKDF SP800-56Cr2A3252
  • KDA OneStep SP800-56Cr2A3252
  • KDA TwoStep SP800-56Cr2A3252
  • KDF ANS 9.42A3252
  • KDF ANS 9.63A3252
  • KDF IKEv2A3252
  • KDF SNMPA3252
  • KDF SP800-108A3252
  • KDF SRTPA3252
  • KDF SSHA3252
  • KMAC-128A3252
  • KMAC-256A3252
  • KTS-IFCA3252
  • PBKDFA3252
  • RSA KeyGen (FIPS186-4)A3252
  • RSA SigGen (FIPS186-4)A3252
  • RSA Signature PrimitiveA3252
  • RSA SigVer (FIPS186-4)A3252
  • Safe Primes Key GenerationA3252
  • Safe Primes Key VerificationA3252
  • SHA-1A3252
  • SHA2-224A3252
  • SHA2-256A3252
  • SHA2-384A3252
  • SHA2-512/224A3252
  • SHA2-512/256A3252
  • SHA2-512A3252
  • SHA3-224A3252
  • SHA3-256A3252
  • SHA3-384A3252
  • SHA3-512A3252
  • SHAKE-128A3252
  • SHAKE-256A3252
  • TDES-CBCA3252
  • TDES-CMACA3252
  • TDES-ECBA3252
  • TLS v1.2 KDF RFC7627A3252
  • TLS v1.3 KDFA3252
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Extracted keywords

Symmetric Algorithms
AES-128, AES-192, AES-256, AES, AES-, CAST, TDES, HMAC, KMAC, CMAC
Asymmetric Algorithms
ECDH, ECDSA, EdDSA, ECC, Diffie-Hellman, DHE, DH, DSA
Hash functions
SHA-1, SHA1, SHA512, SHA-2, SHA3-224, SHA3-256, SHA3-512, SHA3-384, SHA-3, SHA3, PBKDF, PBKDF2
Schemes
MAC, Key Agreement
Protocols
SSH, SSHv2, TLS, TLS v1.2, TLS v1.3, TLS 1.2, TLS 1.3, IKEv2, IKE
Randomness
DRBG, RBG
Libraries
OpenSSL
Elliptic Curves
P-256, P-384, P-521, Ed25519, Ed448
Block cipher modes
CBC, CTR, GCM, XTS

JavaCard API constants
ED25519, ED448, X25519, X448
Trusted Execution Environments
PSP, SSC
Vendor
Cisco Systems, Cisco Systems, Inc, Cisco

Security level
Level 1, level 1
Side-channel analysis
side-channel, timing attacks

Automated analysis

Automated inference - use with caution

All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.

No automatically derived data are available in this section.

Cross-references

No references are available for this certificate.

Processing updates

Feed
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 4891,
  "dgst": "42a8d10424653fc2",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "KDA OneStep SP800-56Cr2A3252",
        "KMAC-128A3252",
        "HMAC-SHA3-224A3252",
        "KTS-IFCA3252",
        "KDA HKDF SP800-56Cr2A3252",
        "KDA TwoStep SP800-56Cr2A3252",
        "AES-GMACA3252",
        "AES-CTRA3252",
        "KDF IKEv2A3252",
        "DSA PQGGen (FIPS186-4)A3252",
        "SHA3-512A3252",
        "KAS-IFC-SSCA3252",
        "SHA3-224A3252",
        "KDF SNMPA3252",
        "SHA2-512/256A3252",
        "AES-XTS Testing Revision 2.0A3252",
        "SHA2-384A3252",
        "AES-KWPA3252",
        "ECDSA KeyVer (FIPS186-4)A3252",
        "Hash DRBGA3252",
        "KAS-FFC-SSC Sp800-56Ar3A3252",
        "ECDSA KeyGen (FIPS186-4)A3252",
        "DSA SigVer (FIPS186-4)A3252",
        "AES-CFB1A3252",
        "SHA2-224A3252",
        "ECDSA SigVer (FIPS186-4)A3252",
        "KAS-ECC CDH-Component SP800-56Ar3A3252",
        "TLS v1.3 KDFA3252",
        "KDF ANS 9.63A3252",
        "KDF SP800-108A3252",
        "DSA PQGVer (FIPS186-4)A3252",
        "HMAC-SHA2-512/256A3252",
        "HMAC-SHA3-256A3252",
        "AES-CBC-CS1A3252",
        "AES-CFB128A3252",
        "Safe Primes Key GenerationA3252",
        "HMAC-SHA-1A3252",
        "KDF SSHA3252",
        "Safe Primes Key VerificationA3252",
        "HMAC-SHA2-512A3252",
        "TDES-CMACA3252",
        "KDF ANS 9.42A3252",
        "#A3032",
        "TDES-ECBA3252",
        "RSA KeyGen (FIPS186-4)A3252",
        "HMAC DRBGA3252",
        "DSA KeyGen (FIPS186-4)A3252",
        "SHA3-256A3252",
        "AES-CBCA3252",
        "TDES-CBCA3252",
        "KDF SRTPA3252",
        "AES-ECBA3252",
        "AES-CCMA3252",
        "AES-KWA3252",
        "AES-GCMA3252",
        "ECDSA SigGen (FIPS186-4)A3252",
        "SHA2-512A3252",
        "SHA2-512/224A3252",
        "RSA Signature PrimitiveA3252",
        "SHAKE-256A3252",
        "HMAC-SHA2-384A3252",
        "SHA3-384A3252",
        "HMAC-SHA3-384A3252",
        "AES-CFB8A3252",
        "PBKDFA3252",
        "AES-CBC-CS3A3252",
        "RSA SigVer (FIPS186-4)A3252",
        "HMAC-SHA2-224A3252",
        "#A3252",
        "SHAKE-128A3252",
        "Counter DRBGA3252",
        "KMAC-256A3252",
        "AES-OFBA3252",
        "AES-CMACA3252",
        "KAS-ECC-SSC Sp800-56Ar3A3252",
        "RSA SigGen (FIPS186-4)A3252",
        "DSA SigGen (FIPS186-4)A3252",
        "HMAC-SHA2-512/224A3252",
        "HMAC-SHA3-512A3252",
        "AES-CBC-CS2A3252",
        "SHA2-256A3252",
        "HMAC-SHA2-256A3252",
        "TLS v1.2 KDF RFC7627A3252",
        "SHA-1A3252"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "-"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "br1_deviations": 0,
    "br1_tables": {
      "_type": "sec_certs.heuristics.br1.table_parsing.model.br1_tables.BR1Tables",
      "approved_algorithms": {
        "entries": [
          {
            "algorithm": "AES-CBC",
            "cavpCertName": "A3032",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CBC-CS1",
            "cavpCertName": "A3032",
            "properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CBC-CS2",
            "cavpCertName": "A3032",
            "properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CBC-CS3",
            "cavpCertName": "A3032",
            "properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CCM",
            "cavpCertName": "A3032",
            "properties": "Key Length - 128, 192, 256",
            "reference": "SP 800-38C"
          },
          {
            "algorithm": "AES-CFB1",
            "cavpCertName": "A3032",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CFB128",
            "cavpCertName": "A3032",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CFB8",
            "cavpCertName": "A3032",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CMAC",
            "cavpCertName": "A3032",
            "properties": "Direction - Generation, Verification Key Length - 128, 192, 256",
            "reference": "SP 800-38B"
          },
          {
            "algorithm": "AES-CTR",
            "cavpCertName": "A3032",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A3032",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-GCM",
            "cavpCertName": "A3032",
            "properties": "Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256",
            "reference": "SP 800-38D"
          },
          {
            "algorithm": "AES-GMAC",
            "cavpCertName": "A3032",
            "properties": "Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256",
            "reference": "SP 800-38D"
          },
          {
            "algorithm": "AES-KW",
            "cavpCertName": "A3032",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38F"
          },
          {
            "algorithm": "AES-KWP",
            "cavpCertName": "A3032",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38F"
          },
          {
            "algorithm": "AES-OFB",
            "cavpCertName": "A3032",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-XTS Testing Revision 2.0",
            "cavpCertName": "A3032",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 256",
            "reference": "SP 800-38E"
          },
          {
            "algorithm": "Counter DRBG",
            "cavpCertName": "A3032",
            "properties": "Prediction Resistance - Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - No, Yes",
            "reference": "SP 800-90A Rev. 1"
          },
          {
            "algorithm": "DSA KeyGen (FIPS186-4)",
            "cavpCertName": "A3032",
            "properties": "L - 2048, 3072 N - 224, 256",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "DSA PQGGen (FIPS186-4)",
            "cavpCertName": "A3032",
            "properties": "L - 2048, 3072 N - 224, 256 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2- 512/256",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "DSA PQGVer (FIPS186-4)",
            "cavpCertName": "A3032",
            "properties": "L - 1024, 2048, 3072 N - 160, 224, 256 Hash Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "DSA SigGen (FIPS186-4)",
            "cavpCertName": "A3032",
            "properties": "L - 2048, 3072 N - 224, 256 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2- 512/256",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "DSA SigVer (FIPS186-4)",
            "cavpCertName": "A3032",
            "properties": "L - 1024, 2048, 3072 N - 160, 224, 256 Hash Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA KeyGen (FIPS186-4)",
            "cavpCertName": "A3032",
            "properties": "Curve - P-256, P-384, P-521 Secret Generation Mode - Testing Candidates",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA KeyVer (FIPS186-4)",
            "cavpCertName": "A3032",
            "properties": "Curve - P-256, P-384, P-521",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA SigGen (FIPS186-4)",
            "cavpCertName": "A3032",
            "properties": "Component - No, Yes Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2- 512/256",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA SigVer (FIPS186-4)",
            "cavpCertName": "A3032",
            "properties": "Component - No Curve - P-256, P-384, P-521 Hash Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "Hash DRBG",
            "cavpCertName": "A3032",
            "properties": "Prediction Resistance - Yes Mode - SHA-1, SHA2-224, SHA2-256, SHA2- 384, SHA2-512, SHA2-512/224, SHA2- 512/256",
            "reference": "SP 800-90A Rev. 1"
          },
          {
            "algorithm": "HMAC DRBG",
            "cavpCertName": "A3032",
            "properties": "Prediction Resistance - Yes Mode - SHA-1, SHA2-224, SHA2-256, SHA2- 384, SHA2-512, SHA2-512/224, SHA2- 512/256",
            "reference": "SP 800-90A Rev. 1"
          },
          {
            "algorithm": "HMAC-SHA-1",
            "cavpCertName": "A3032",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-224",
            "cavpCertName": "A3032",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-256",
            "cavpCertName": "A3032",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-384",
            "cavpCertName": "A3032",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-512",
            "cavpCertName": "A3032",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2- 512/224",
            "cavpCertName": "A3032",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2- 512/256",
            "cavpCertName": "A3032",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3-224",
            "cavpCertName": "A3032",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3-256",
            "cavpCertName": "A3032",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3-384",
            "cavpCertName": "A3032",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3-512",
            "cavpCertName": "A3032",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "KAS-ECC CDH- Component SP800-56Ar3 (CVL)",
            "cavpCertName": "A3032",
            "properties": "Curve - P-256, P-384, P-521",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "KAS-ECC-SSC Sp800-56Ar3",
            "cavpCertName": "A3032",
            "properties": "Domain Parameter Generation Methods - P- 256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responder",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "KAS-FFC-SSC Sp800-56Ar3",
            "cavpCertName": "A3032",
            "properties": "Domain Parameter Generation Methods - FB, FC, ffdhe2048, ffdhe3072, ffdhe4096, modp- 2048, modp-3072, modp-4096 Scheme - dhEphem - KAS Role - initiator, responder",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "KAS-IFC-SSC",
            "cavpCertName": "A3032",
            "properties": "Modulo - 2048, 3072, 4096, 6144, 8192 Key Generation Methods - rsakpg1-basic, rsakpg1-crt, rsakpg1-prime-factor, rsakpg2- basic, rsakpg2-crt, rsakpg2-prime-factor Scheme - KAS1 - KAS Role - initiator, responder KAS2 - KAS Role - initiator, responder",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "KDA HKDF SP800- 56Cr2",
            "cavpCertName": "A3032",
            "properties": "Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8 HMAC Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512",
            "reference": "SP 800-56C Rev. 2"
          },
          {
            "algorithm": "KDA OneStep SP800-56Cr2",
            "cavpCertName": "A3032",
            "properties": "Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8",
            "reference": "SP 800-56C Rev. 2"
          },
          {
            "algorithm": "KDA TwoStep SP800-56Cr2",
            "cavpCertName": "A3032",
            "properties": "MAC Salting Methods - default, random KDF Mode - feedback Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8",
            "reference": "SP 800-56C Rev. 2"
          },
          {
            "algorithm": "KDF ANS 9.42 (CVL)",
            "cavpCertName": "A3032",
            "properties": "KDF Type - DER Hash Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2-512/224,",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "",
            "cavpCertName": "",
            "properties": "SHA2-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512 Key Data Length - Key Data Length: 8-4096 Increment 8",
            "reference": ""
          },
          {
            "algorithm": "KDF ANS 9.63 (CVL)",
            "cavpCertName": "A3032",
            "properties": "Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512 Key Data Length - Key Data Length: 128, 4096",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "KDF IKEv2 (CVL)",
            "cavpCertName": "A3032",
            "properties": "Diffie-Hellman Shared Secret Length - Diffie- Hellman Shared Secret Length: 2048 Derived Keying Material Length - Derived Keying Material Length: 3072 Hash Algorithm - SHA-1",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "KDF SNMP (CVL)",
            "cavpCertName": "A3032",
            "properties": "Password Length - Password Length: 256, 64",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "KDF SP800-108",
            "cavpCertName": "A3032",
            "properties": "KDF Mode - Counter, Feedback Supported Lengths - Supported Lengths: 8, 72, 128, 776, 3456, 4096",
            "reference": "SP 800-108 Rev. 1"
          },
          {
            "algorithm": "KDF SRTP (CVL)",
            "cavpCertName": "A3032",
            "properties": "AES Key Length - 128, 192, 256",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "KDF SSH (CVL)",
            "cavpCertName": "A3032",
            "properties": "Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "KMAC-128",
            "cavpCertName": "A3032",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Key Data Length - Key Data Length: 128-1024 Increment 8",
            "reference": "SP 800-185"
          },
          {
            "algorithm": "KMAC-256",
            "cavpCertName": "A3032",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Key Data Length - Key Data Length: 128-1024 Increment 8",
            "reference": "SP 800-185"
          },
          {
            "algorithm": "KTS-IFC",
            "cavpCertName": "A3032",
            "properties": "Modulo - 2048, 3072, 4096, 6144 Key Generation Methods - rsakpg1-basic, rsakpg1-crt, rsakpg1-prime-factor, rsakpg2- basic, rsakpg2-crt, rsakpg2-prime-factor Scheme - KTS-OAEP-basic - KAS Role - initiator, responder Key Transport Method - Key Length - 1024",
            "reference": "SP 800-56B Rev. 2"
          },
          {
            "algorithm": "PBKDF",
            "cavpCertName": "A3032",
            "properties": "Iteration Count - Iteration Count: 1-10000 Increment 1 Password Length - Password Length: 8-128 Increment 8",
            "reference": "SP 800-132"
          },
          {
            "algorithm": "RSA KeyGen (FIPS186-4)",
            "cavpCertName": "A3032",
            "properties": "Key Generation Mode - B.3.6 Modulo - 2048, 3072, 4096",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "",
            "cavpCertName": "",
            "properties": "Primality Tests - Table C.2 Private Key Format - Standard",
            "reference": ""
          },
          {
            "algorithm": "RSA SigGen (FIPS186-4)",
            "cavpCertName": "A3032",
            "properties": "Signature Type - ANSI X9.31, PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "RSA Signature Primitive (CVL)",
            "cavpCertName": "A3032",
            "properties": "Private Key Format - crt",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "RSA SigVer (FIPS186-4)",
            "cavpCertName": "A3032",
            "properties": "Signature Type - ANSI X9.31, PKCS 1.5, PKCSPSS Modulo - 1024, 2048, 3072, 4096",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "Safe Primes Key Generation",
            "cavpCertName": "A3032",
            "properties": "Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, modp-2048, modp-3072, modp- 4096",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "Safe Primes Key Verification",
            "cavpCertName": "A3032",
            "properties": "Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, modp-2048, modp-3072, modp- 4096",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "SHA-1",
            "cavpCertName": "A3032",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-224",
            "cavpCertName": "A3032",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-256",
            "cavpCertName": "A3032",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-384",
            "cavpCertName": "A3032",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512",
            "cavpCertName": "A3032",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512/224",
            "cavpCertName": "A3032",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512/256",
            "cavpCertName": "A3032",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA3-224",
            "cavpCertName": "A3032",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3-256",
            "cavpCertName": "A3032",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3-384",
            "cavpCertName": "A3032",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3-512",
            "cavpCertName": "A3032",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHAKE-128",
            "cavpCertName": "A3032",
            "properties": "Output Length - Output Length: 16-65536 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHAKE-256",
            "cavpCertName": "A3032",
            "properties": "Output Length - Output Length: 16-65536 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "TLS v1.2 KDF RFC7627 (CVL)",
            "cavpCertName": "A3032",
            "properties": "Hash Algorithm - SHA2-256, SHA2-384, SHA2-512",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "TLS v1.3 KDF (CVL)",
            "cavpCertName": "A3032",
            "properties": "HMAC Algorithm - SHA2-256, SHA2-384 KDF Running Modes - DHE, PSK, PSK-DHE",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "TDES-CBC",
            "cavpCertName": "A3032",
            "properties": "Direction - Decrypt",
            "reference": "SP 800-67 Rev. 2"
          },
          {
            "algorithm": "TDES-CMAC",
            "cavpCertName": "A3032",
            "properties": "Direction - Verification",
            "reference": "SP 800-67 Rev. 2"
          },
          {
            "algorithm": "TDES-ECB",
            "cavpCertName": "A3032",
            "properties": "Direction - Decrypt",
            "reference": "SP 800-67 Rev. 2"
          },
          {
            "algorithm": "AES-CBC",
            "cavpCertName": "A3252",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CBC-CS1",
            "cavpCertName": "A3252",
            "properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CBC-CS2",
            "cavpCertName": "A3252",
            "properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CBC-CS3",
            "cavpCertName": "A3252",
            "properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CCM",
            "cavpCertName": "A3252",
            "properties": "Key Length - 128, 192, 256",
            "reference": "SP 800-38C"
          },
          {
            "algorithm": "AES-CFB1",
            "cavpCertName": "A3252",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CFB128",
            "cavpCertName": "A3252",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CFB8",
            "cavpCertName": "A3252",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CMAC",
            "cavpCertName": "A3252",
            "properties": "Direction - Generation, Verification Key Length - 128, 192, 256",
            "reference": "SP 800-38B"
          },
          {
            "algorithm": "AES-CTR",
            "cavpCertName": "A3252",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A3252",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-GCM",
            "cavpCertName": "A3252",
            "properties": "Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256",
            "reference": "SP 800-38D"
          },
          {
            "algorithm": "AES-GMAC",
            "cavpCertName": "A3252",
            "properties": "Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256",
            "reference": "SP 800-38D"
          },
          {
            "algorithm": "AES-KW",
            "cavpCertName": "A3252",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38F"
          },
          {
            "algorithm": "AES-KWP",
            "cavpCertName": "A3252",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38F"
          },
          {
            "algorithm": "AES-OFB",
            "cavpCertName": "A3252",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-XTS Testing Revision 2.0",
            "cavpCertName": "A3252",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 256",
            "reference": "SP 800-38E"
          },
          {
            "algorithm": "Counter DRBG",
            "cavpCertName": "A3252",
            "properties": "Prediction Resistance - Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - No, Yes",
            "reference": "SP 800-90A Rev. 1"
          },
          {
            "algorithm": "DSA KeyGen (FIPS186-4)",
            "cavpCertName": "A3252",
            "properties": "L - 2048, 3072 N - 224, 256",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "DSA PQGGen (FIPS186-4)",
            "cavpCertName": "A3252",
            "properties": "L - 2048, 3072 N - 224, 256 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2- 512/256",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "DSA PQGVer (FIPS186-4)",
            "cavpCertName": "A3252",
            "properties": "L - 1024, 2048, 3072 N - 160, 224, 256 Hash Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "DSA SigGen (FIPS186-4)",
            "cavpCertName": "A3252",
            "properties": "L - 2048, 3072 N - 224, 256 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2- 512/256",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "DSA SigVer (FIPS186-4)",
            "cavpCertName": "A3252",
            "properties": "L - 1024, 2048, 3072 N - 160, 224, 256 Hash Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA KeyGen (FIPS186-4)",
            "cavpCertName": "A3252",
            "properties": "Curve - P-256, P-384, P-521 Secret Generation Mode - Testing Candidates",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA KeyVer (FIPS186-4)",
            "cavpCertName": "A3252",
            "properties": "Curve - P-256, P-384, P-521",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA SigGen (FIPS186-4)",
            "cavpCertName": "A3252",
            "properties": "Component - No, Yes Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2- 512/256",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA SigVer (FIPS186-4)",
            "cavpCertName": "A3252",
            "properties": "Component - No Curve - P-256, P-384, P-521 Hash Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "Hash DRBG",
            "cavpCertName": "A3252",
            "properties": "Prediction Resistance - Yes Mode - SHA-1, SHA2-224, SHA2-256, SHA2-",
            "reference": "SP 800-90A Rev. 1"
          },
          {
            "algorithm": "",
            "cavpCertName": "",
            "properties": "384, SHA2-512, SHA2-512/224, SHA2- 512/256",
            "reference": ""
          },
          {
            "algorithm": "HMAC DRBG",
            "cavpCertName": "A3252",
            "properties": "Prediction Resistance - Yes Mode - SHA-1, SHA2-224, SHA2-256, SHA2- 384, SHA2-512, SHA2-512/224, SHA2- 512/256",
            "reference": "SP 800-90A Rev. 1"
          },
          {
            "algorithm": "HMAC-SHA-1",
            "cavpCertName": "A3252",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-224",
            "cavpCertName": "A3252",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-256",
            "cavpCertName": "A3252",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-384",
            "cavpCertName": "A3252",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-512",
            "cavpCertName": "A3252",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2- 512/224",
            "cavpCertName": "A3252",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2- 512/256",
            "cavpCertName": "A3252",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3-224",
            "cavpCertName": "A3252",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3-256",
            "cavpCertName": "A3252",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3-384",
            "cavpCertName": "A3252",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3-512",
            "cavpCertName": "A3252",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "KAS-ECC CDH- Component SP800-56Ar3 (CVL)",
            "cavpCertName": "A3252",
            "properties": "Curve - P-256, P-384, P-521",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "KAS-ECC-SSC Sp800-56Ar3",
            "cavpCertName": "A3252",
            "properties": "Domain Parameter Generation Methods - P- 256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responder",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "KAS-FFC-SSC Sp800-56Ar3",
            "cavpCertName": "A3252",
            "properties": "Domain Parameter Generation Methods - FB, FC, ffdhe2048, ffdhe3072, ffdhe4096, modp- 2048, modp-3072, modp-4096 Scheme - dhEphem - KAS Role - initiator, responder",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "KAS-IFC-SSC",
            "cavpCertName": "A3252",
            "properties": "Modulo - 2048, 3072, 4096, 6144, 8192 Key Generation Methods - rsakpg1-basic,",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "",
            "cavpCertName": "",
            "properties": "rsakpg1-crt, rsakpg1-prime-factor, rsakpg2- basic, rsakpg2-crt, rsakpg2-prime-factor Scheme - KAS1 - KAS Role - initiator, responder KAS2 - KAS Role - initiator, responder",
            "reference": ""
          },
          {
            "algorithm": "KDA HKDF SP800- 56Cr2",
            "cavpCertName": "A3252",
            "properties": "Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8 HMAC Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512",
            "reference": "SP 800-56C Rev. 2"
          },
          {
            "algorithm": "KDA OneStep SP800-56Cr2",
            "cavpCertName": "A3252",
            "properties": "Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8",
            "reference": "SP 800-56C Rev. 2"
          },
          {
            "algorithm": "KDA TwoStep SP800-56Cr2",
            "cavpCertName": "A3252",
            "properties": "MAC Salting Methods - default, random KDF Mode - feedback Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8",
            "reference": "SP 800-56C Rev. 2"
          },
          {
            "algorithm": "KDF ANS 9.42 (CVL)",
            "cavpCertName": "A3252",
            "properties": "KDF Type - DER Hash Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512 Key Data Length - Key Data Length: 8-4096 Increment 8",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "KDF ANS 9.63 (CVL)",
            "cavpCertName": "A3252",
            "properties": "Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512 Key Data Length - Key Data Length: 128, 4096",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "KDF IKEv2 (CVL)",
            "cavpCertName": "A3252",
            "properties": "Diffie-Hellman Shared Secret Length - Diffie- Hellman Shared Secret Length: 2048 Derived Keying Material Length - Derived Keying Material Length: 3072 Hash Algorithm - SHA-1",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "KDF SNMP (CVL)",
            "cavpCertName": "A3252",
            "properties": "Password Length - Password Length: 256, 64",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "KDF SP800-108",
            "cavpCertName": "A3252",
            "properties": "KDF Mode - Counter, Feedback Supported Lengths - Supported Lengths: 8, 72, 128, 776, 3456, 4096",
            "reference": "SP 800-108 Rev. 1"
          },
          {
            "algorithm": "KDF SRTP (CVL)",
            "cavpCertName": "A3252",
            "properties": "AES Key Length - 128, 192, 256",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "KDF SSH (CVL)",
            "cavpCertName": "A3252",
            "properties": "Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "KMAC-128",
            "cavpCertName": "A3252",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Key Data Length - Key Data Length: 128-1024 Increment 8",
            "reference": "SP 800-185"
          },
          {
            "algorithm": "KMAC-256",
            "cavpCertName": "A3252",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Key Data Length - Key Data Length: 128-1024 Increment 8",
            "reference": "SP 800-185"
          },
          {
            "algorithm": "KTS-IFC",
            "cavpCertName": "A3252",
            "properties": "Modulo - 2048, 3072, 4096, 6144 Key Generation Methods - rsakpg1-basic, rsakpg1-crt, rsakpg1-prime-factor, rsakpg2- basic, rsakpg2-crt, rsakpg2-prime-factor Scheme - KTS-OAEP-basic - KAS Role - initiator, responder Key Transport Method - Key Length - 1024",
            "reference": "SP 800-56B Rev. 2"
          },
          {
            "algorithm": "PBKDF",
            "cavpCertName": "A3252",
            "properties": "Iteration Count - Iteration Count: 1-10000 Increment 1 Password Length - Password Length: 8-128 Increment 8",
            "reference": "SP 800-132"
          },
          {
            "algorithm": "RSA KeyGen (FIPS186-4)",
            "cavpCertName": "A3252",
            "properties": "Key Generation Mode - B.3.6 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Private Key Format - Standard",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "RSA SigGen (FIPS186-4)",
            "cavpCertName": "A3252",
            "properties": "Signature Type - ANSI X9.31, PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "RSA Signature Primitive (CVL)",
            "cavpCertName": "A3252",
            "properties": "Private Key Format - crt",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "RSA SigVer (FIPS186-4)",
            "cavpCertName": "A3252",
            "properties": "Signature Type - ANSI X9.31, PKCS 1.5, PKCSPSS Modulo - 1024, 2048, 3072, 4096",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "Safe Primes Key Generation",
            "cavpCertName": "A3252",
            "properties": "Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, modp-2048, modp-3072, modp- 4096",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "Safe Primes Key Verification",
            "cavpCertName": "A3252",
            "properties": "Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, modp-2048, modp-3072, modp- 4096",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "SHA-1",
            "cavpCertName": "A3252",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-224",
            "cavpCertName": "A3252",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-256",
            "cavpCertName": "A3252",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-384",
            "cavpCertName": "A3252",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512",
            "cavpCertName": "A3252",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512/224",
            "cavpCertName": "A3252",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512/256",
            "cavpCertName": "A3252",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA3-224",
            "cavpCertName": "A3252",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3-256",
            "cavpCertName": "A3252",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3-384",
            "cavpCertName": "A3252",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3-512",
            "cavpCertName": "A3252",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHAKE-128",
            "cavpCertName": "A3252",
            "properties": "Output Length - Output Length: 16-65536 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHAKE-256",
            "cavpCertName": "A3252",
            "properties": "Output Length - Output Length: 16-65536 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "TLS v1.2 KDF RFC7627 (CVL)",
            "cavpCertName": "A3252",
            "properties": "Hash Algorithm - SHA2-256, SHA2-384, SHA2-512",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "TLS v1.3 KDF (CVL)",
            "cavpCertName": "A3252",
            "properties": "HMAC Algorithm - SHA2-256, SHA2-384 KDF Running Modes - DHE, PSK, PSK-DHE",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "TDES-CBC",
            "cavpCertName": "A3252",
            "properties": "Direction - Decrypt",
            "reference": "SP 800-67 Rev. 2"
          },
          {
            "algorithm": "TDES-CMAC",
            "cavpCertName": "A3252",
            "properties": "Direction - Verification",
            "reference": "SP 800-67 Rev. 2"
          },
          {
            "algorithm": "TDES-ECB",
            "cavpCertName": "A3252",
            "properties": "Direction - Decrypt",
            "reference": "SP 800-67 Rev. 2"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "approved_services": {
        "entries": [
          {
            "description": "Used for random number and symmetri c key generatio n",
            "indicator": "1",
            "inputs": "DRBG struct (RBG State); DRBG_S eed",
            "name": "Random Number Generation",
            "outputs": "Status return; Random value",
            "rolesSspAccess": "Crypto- Officer - DRBG_C: W,E - Entropy Input: W,E,Z",
            "secFunImpl": "Random Number Generation"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "- DRBG_Ke y: W,E - DRBG_Se ed: G,E,Z - DRBG_V: W,E",
            "secFunImpl": ""
          },
          {
            "description": "Generate asymmet ric key pairs",
            "indicator": "1",
            "inputs": "ECDSA: curve identifier. DSA, RSA: domain paramete r targets",
            "name": "Asymmetric Key Generation",
            "outputs": "Status return; general digital signature private and public keys",
            "rolesSspAccess": "Crypto- Officer - RSA SGK: G,R - ECDSA SGK: G,R - DSA SGK: G,R - RSA SVK: G,R - ECDSA SVK: G,R - DSA SVK: G,R - RSA KDK: G,R - RSA KEK: G,R",
            "secFunImpl": "Asymmetric Key Generation"
          },
          {
            "description": "Used to derive keys using KBKDF, PBKDF2, HKDF, SP 800- 56C rev2 One-Step KDF (KDA), SP 800- 56C rev2 Two-Step KDF (KDA), SP 800- 135 rev1",
            "indicator": "1",
            "inputs": "Key agreemen t shared secret; flags",
            "name": "Key Derivation Function (KDF)",
            "outputs": "Status return; derived keying material",
            "rolesSspAccess": "Crypto- Officer - KDF Derived Key: G,R",
            "secFunImpl": "Key Derivation Function (KDF)"
          },
          {
            "description": "TLS 1.2, SSHv2, SNMPv3, SRTP, IKEv2, ANSI X9.6- 2001, ANSI X9.42- 2001 KDFs and TLS 1.3 KDF",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "",
            "secFunImpl": ""
          },
          {
            "description": "Used to encrypt or decrypt data. Executes using AES EDK (passed in by the calling applicatio n)",
            "indicator": "1",
            "inputs": "Encryptio n or decryptio n key; plaintext or ciphertext data; flags",
            "name": "Symmetric Encrypt/Dec rypt",
            "outputs": "Status return. Plaintext or ciphertext data",
            "rolesSspAccess": "Crypto- Officer - AES EDK: W,E - AES GCM: W,E - AES XTS: W,E - AES Key Wrapping: W,E - TDES DK: W,E",
            "secFunImpl": "Symmetric Encrypt/Decrypt"
          },
          {
            "description": "Used to generate a SHA-1, SHA-2, or SHA-3 message digest",
            "indicator": "1",
            "inputs": "Data to be hashed",
            "name": "Message Digest (SHS)",
            "outputs": "Status return. Hashed data",
            "rolesSspAccess": "Crypto- Officer",
            "secFunImpl": "Message Digest (SHS)"
          },
          {
            "description": "Used to generate or verify data integrity with HMAC, KMAC or CMAC. Executes using",
            "indicator": "1",
            "inputs": "Data to be hashed and keying material",
            "name": "Keyed Hash",
            "outputs": "Status return; MAC output value.",
            "rolesSspAccess": "Crypto- Officer - HMAC Key: W,E - KMAC Key: W,E - AES CMAC: W,E - TDES",
            "secFunImpl": "Keyed Hash (HMAC/KMAC/C MAC)"
          },
          {
            "description": "HMAC, KMAC or AES Key (passed in by the calling applicatio n)",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "CMAC: W,E",
            "secFunImpl": ""
          },
          {
            "description": "Used to encrypt a key value on behalf of the calling applicatio n. Executes using AES Key Wrapping Key (passed in by the calling applicatio n). AES- KW, AES- KWP is CAVP tested per FIPS 140-3 IG D.G.",
            "indicator": "1",
            "inputs": "Keying material",
            "name": "Key Wrapping (KW)",
            "outputs": "Encrypted key",
            "rolesSspAccess": "Crypto- Officer - AES Key Wrapping: W,E",
            "secFunImpl": "Key Wrapping (KW)"
          },
          {
            "description": "Used to perform key agreeme nt primitives on behalf of the calling applicatio n (does not",
            "indicator": "1",
            "inputs": "Key structs (key agreemen t keys); flags",
            "name": "Key Agreement/ Agreement Component (SP 800- 56A rev3)",
            "outputs": "Status return; key agreement shared secret",
            "rolesSspAccess": "Crypto- Officer - DH Private: W,E - EC DH Private: W,E - RSA SGK: W,E - DH Public:",
            "secFunImpl": "Key Agreement/Agree ment Component (SP 800-56A rev3, SP 800- 56B rev2)"
          },
          {
            "description": "establish keys into the module). Executes using DH Private, DH Public, EC DH Private, EC DH Public, RSA SGK, RSA SVK (passed in by the calling applicatio n)",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "W,E - EC DH Public: W,E - RSA SVK: W,E",
            "secFunImpl": ""
          },
          {
            "description": "Used to generate or verify RSA, DSA, ECDSA, digital signature s. Executes using RSA SGK, RSA SVK; DSA SGK, DSA SVK; ECDSA SGK, ECDSA SVK, (passed",
            "indicator": "1",
            "inputs": "Sign: signing key; message. Verify: signature value; flags; sizes",
            "name": "Digital Signature",
            "outputs": "Status return; Signature value",
            "rolesSspAccess": "Crypto- Officer - RSA SGK: W,E - RSA SVK: W,E - DSA SGK: W,E - DSA SVK: W,E - ECDSA SGK: W,E - ECDSA SVK: W,E",
            "secFunImpl": "Digital Signature"
          },
          {
            "description": "in by the calling applicatio n)",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "",
            "secFunImpl": ""
          },
          {
            "description": "Used to verify ECDSA keys",
            "indicator": "1",
            "inputs": "Public Key",
            "name": "Asymmetric Key Verification",
            "outputs": "Status return",
            "rolesSspAccess": "Crypto- Officer - ECDSA SVK: W,E",
            "secFunImpl": "Asymmetric Key Verification"
          },
          {
            "description": "The module is initialized when the provider is loaded",
            "indicator": "1",
            "inputs": "N/A",
            "name": "Module initialization",
            "outputs": "N/A",
            "rolesSspAccess": "Crypto- Officer",
            "secFunImpl": "None"
          },
          {
            "description": "Perform self-tests on demand",
            "indicator": "1",
            "inputs": "N/A",
            "name": "Perform Self-Test",
            "outputs": "Success/fai lure message",
            "rolesSspAccess": "Crypto- Officer",
            "secFunImpl": "None"
          },
          {
            "description": "Used for Key Transport",
            "indicator": "1",
            "inputs": "Key to be transporte d",
            "name": "Key Transport",
            "outputs": "Encrypted key",
            "rolesSspAccess": "Crypto- Officer - RSA KDK: W,E - RSA KEK: W,E",
            "secFunImpl": "Key Transport"
          },
          {
            "description": "Used to output module name and version",
            "indicator": "N/A",
            "inputs": "N/A",
            "name": "Show Module Name and Version",
            "outputs": "name: CiscoSSL FIPS Provider version: 8.0",
            "rolesSspAccess": "Crypto- Officer",
            "secFunImpl": "None"
          },
          {
            "description": "Used to output module status",
            "indicator": "N/A",
            "inputs": "N/A",
            "name": "Show Status",
            "outputs": "status: active",
            "rolesSspAccess": "Crypto- Officer",
            "secFunImpl": "None"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 3
      },
      "authentication_methods": {
        "entries": [],
        "found": false,
        "section": 4,
        "subsection": 1
      },
      "cond_self_tests": {
        "entries": [
          {
            "algorithmOrTest": "AES-ECB (A3032)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Encrypt KAT",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "128 bits",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "AES-ECB (A3252)",
            "condition": "Upon power-up and call of",
            "details": "Encrypt KAT",
            "indicator": "Returns 1 on",
            "testMethod": "KAT",
            "testProps": "128 bits",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "",
            "condition": "SELF_TEST_post( ) function",
            "details": "",
            "indicator": "successful completio n",
            "testMethod": "",
            "testProps": "",
            "type": ""
          },
          {
            "algorithmOrTest": "AES- GCM (A3032)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Encrypt KAT",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "256 bits",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "AES- GCM (A3252)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Encrypt KAT",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "256 bits",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "AES- CMAC (A3032)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Generate KAT",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "128, 192, 256 bits",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "AES- CMAC (A3252)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Generate KAT",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "128, 192, 256 bits",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "Counter DRBG (A3032)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Instantiate, Generate, Reseed",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "AES-128 with derivation function",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "Counter DRBG (A3252)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Instantiate, Generate, Reseed",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "AES-128 with derivation function",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "Hash DRBG (A3032)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Instantiate, Generate, Reseed",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "SHA2-256",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "Hash DRBG (A3252)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Instantiate, Generate, Reseed",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "SHA2-256",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "HMAC DRBG (A3032)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Instantiate, Generate, Reseed",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "SHA-1",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "HMAC DRBG (A3252)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Instantiate, Generate, Reseed",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "SHA-1",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "DSA SigGen (FIPS186- 4) (A3032)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Sign",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "2048-bit with SHA2-256",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "DSA SigGen (FIPS186- 4) (A3252)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Sign",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "2048-bit with SHA2-256",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "DSA SigVer (FIPS186- 4) (A3032)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Verify",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "2048-bit with SHA2-256",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "DSA SigVer (FIPS186- 4) (A3252)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Verify",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "2048-bit with SHA2-256",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "ECDSA SigGen (FIPS186- 4) (A3032)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Sign",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "P-256 with SHA2-256",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "ECDSA SigGen (FIPS186- 4) (A3252)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Sign",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "P-256 with SHA2-256",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "ECDSA SigVer (FIPS186- 4) (A3032)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Verify",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "P-256 with SHA2-256",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "ECDSA SigVer (FIPS186- 4) (A3252)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Verify",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "P-256 with SHA2-256",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "RSA SigGen (FIPS186- 4) (A3032)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Sign",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "k=2048 with SHA2-256",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "RSA SigGen (FIPS186- 4) (A3252)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Sign",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "k=2048 with SHA2-256",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186- 4) (A3032)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Verify",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "k=2048 with SHA2-256",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186- 4) (A3252)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Verify",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "k=2048 with SHA2-256",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "KAS- FFC-SSC Sp800- 56Ar3 (A3032)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "dhEphem Shared Secret (Z) Computatio n",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "L=2048/N=25 6",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "KAS- FFC-SSC Sp800- 56Ar3 (A3252)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "dhEphem Shared Secret (Z) Computatio n",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "L=2048/N=25 6",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "KAS- ECC-SSC Sp800- 56Ar3 (A3032)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Ephemeral Unified Shared Secret (Z) Computatio n",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "P-256",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "KAS- ECC-SSC Sp800-",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Ephemeral Unified Shared Secret (Z)",
            "indicator": "Returns 1 on successful",
            "testMethod": "KAT",
            "testProps": "P-256",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "56Ar3 (A3252)",
            "condition": "",
            "details": "Computatio n",
            "indicator": "completio n",
            "testMethod": "",
            "testProps": "",
            "type": ""
          },
          {
            "algorithmOrTest": "KAS-IFC- SSC (A3032)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "[SP 800- 56B rev2] Section 8.2.2 RSA Primitive Computatio n",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "k=2048",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "KAS-IFC- SSC (A3252)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "[SP 800- 56B rev2] Section 8.2.2 RSA Primitive Computatio n",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "k=2048",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "SHA-1 (A3032)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Simple SHA KAT",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "SHA-1",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "SHA-1 (A3252)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Simple SHA KAT",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "SHA-1",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "SHA2- 512 (A3032)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Simple SHA KAT",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "SHA2-512",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "SHA2- 512 (A3252)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Simple SHA KAT",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "SHA2-512",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "SHA3- 256 (A3032)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Simple SHA KAT",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "SHA3-256",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "SHA3- 256 (A3252)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Simple SHA KAT",
            "indicator": "Returns 1 on successful",
            "testMethod": "KAT",
            "testProps": "SHA3-256",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "",
            "condition": "",
            "details": "",
            "indicator": "completio n",
            "testMethod": "",
            "testProps": "",
            "type": ""
          },
          {
            "algorithmOrTest": "HMAC- SHA2- 256 (A3032)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Generate",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "SHA2-256 with a 256-bit key",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "HMAC- SHA2- 256 (A3252)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Generate",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "SHA2-256 with a 256-bit key",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "KDF SP800- 108 (A3032)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "[S P800- 108 rev1] Section 4.1 KAT for a Counter Mode KDF",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "HMAC-SHA2- 256",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "KDF SP800- 108 (A3252)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "[SP 800- 108 rev1] Section 4.1 KAT for a Counter Mode KDF",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "HMAC-SHA2- 256",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "KDA OneStep SP800- 56Cr2 (A3032)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "[SP 800- 56C rev2] Section 4 OneStep KDF (AKA OpenSSL single-step or SS-KDF)",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "SHA2-224",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "KDA OneStep SP800- 56Cr2 (A3252)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "[SP 800- 56C rev2] Section 4 OneStep KDF (AKA OpenSSL single-step or SS-KDF)",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "SHA2-224",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "KDA TwoStep SP800- 56Cr2 (A3032)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "[SP 800- 56C rev2] Section 5 TwoStep",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "SHA2-256",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "",
            "condition": "",
            "details": "KDF (HKDF variant)",
            "indicator": "",
            "testMethod": "",
            "testProps": "",
            "type": ""
          },
          {
            "algorithmOrTest": "KDA TwoStep SP800- 56Cr2 (A3252)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "[SP 800- 56C rev2] Section 5 TwoStep KDF (HKDF variant)",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "SHA2-256",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "PBKDF (A3032)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "[SP 800- 132] Section 5.3 KAT of Master Key derivation",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "SHA2-256, 24-byte password, 36- byte salt, iteration count of 4096",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "PBKDF (A3252)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "[SP 800- 132] Section 5.3 KAT of Master Key derivation",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "SHA2-256, 24-byte password, 36- byte salt, iteration count of 4096",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "TLS v1.3 KDF (A3032)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "[RFC8446] Section 7.1 TLS v1.3 KDF KAT",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "Fixed input KAT",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "TLS v1.3 KDF (A3252)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "[RFC8446] Section 7.1 TLS v1.3 KDF KAT",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "Fixed input KAT",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "TLS v1.2 KDF RFC7627 (A3032)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "[SP 800- 135 rev1] Section 4.2.2 TLS 1.2 KAT",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "Fixed input KAT",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "TLS v1.2 KDF RFC7627 (A3252)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "[SP 800- 135 rev1] Section 4.2.2 TLS 1.2 KAT",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "Fixed input KAT",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "DSA KeyGen (FIPS186- 4) (A3032)",
            "condition": "Performed on FFC (DSA, KAS-FFC- SSC) key pair generation, prior to returning the key",
            "details": "Sign, Verify",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "PCT",
            "testProps": "PCT performed using the generated key pair",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "",
            "condition": "pair on conclusion of the call",
            "details": "",
            "indicator": "",
            "testMethod": "",
            "testProps": "",
            "type": ""
          },
          {
            "algorithmOrTest": "DSA KeyGen (FIPS186- 4) (A3252)",
            "condition": "Performed on FFC (DSA, KAS-FFC- SSC) key pair generation, prior to returning the key pair on conclusion of the call",
            "details": "Sign, Verify",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "PCT",
            "testProps": "PCT performed using the generated key pair",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "ECDSA KeyGen (FIPS186- 4) (A3032)",
            "condition": "Performed on ECC (ECDSA, KAS- ECC CDH- Component, KAS- ECC-SSC) key pair generation, prior to returning the key pair on conclusion of the call",
            "details": "Sign, Verify",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "PCT",
            "testProps": "PCT performed using the generated key pair",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "ECDSA KeyGen (FIPS186- 4) (A3252)",
            "condition": "Performed on ECC (ECDSA, KAS- ECC CDH- Component, KAS- ECC-SSC) key pair generation, prior to returning the key pair on conclusion of the call",
            "details": "Sign, Verify",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "PCT",
            "testProps": "PCT performed using the generated key pair",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "RSA KeyGen (FIPS186- 4) (A3032)",
            "condition": "Performed on IFC (RSA, KAS-IFC- SSC, KTS-IFC) key pair generation, prior to returning the key pair on conclusion of the call",
            "details": "Sign, Verify",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "PCT",
            "testProps": "PCT performed using the generated key pair",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "RSA KeyGen (FIPS186- 4) (A3252)",
            "condition": "Performed on IFC (RSA, KAS-IFC- SSC, KTS-IFC) key pair generation, prior to returning the key pair on conclusion of the call",
            "details": "Sign, Verify",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "PCT",
            "testProps": "PCT performed using the generated key pair",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "KDF ANS 9.42 (A3032)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "[SP 800- 135 rev1] Section 5.1 ANSI X9.42-2001 KDF KAT",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "Fixed input KAT",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "KDF ANS 9.63 (A3032)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "[SP 800- 135 rev1] Section 5.1 X9.63-2001 KDF KAT",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "Fixed input KAT",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "KDF IKEv2 (A3032)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "[SP 800- 135 rev1] Section 4.1.2 IKEv2 KDF KAT",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "Fixed input KAT",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "KDF SNMP (A3032)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "[SP 800- 135 rev1] Section 5.4 SNMPv3 KDF KAT",
            "indicator": "Returns 1 on successful completio",
            "testMethod": "KAT",
            "testProps": "Fixed input KAT",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "KDF SRTP (A3032)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "[SP 800- 135 rev1] Section 5.3 SRTP KDF KAT",
            "indicator": "n Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "Fixed input KAT",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "KDF SSH (A3032)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "[SP 800- 135 rev1] Section 5.2 SSHv2 KDF KAT",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "SHA1",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "KDF ANS 9.42 (A3252)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "[SP 800- 135 rev1] Section 5.1 ANSI X9.42-2001 KDF KAT",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "Fixed input KAT",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "KDF ANS 9.63 (A3252)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "[SP 800- 135 rev1] Section 5.1 X9.63-2001 KDF KAT",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "Fixed input KAT",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "KDF IKEv2 (A3252)",
            "condition": "Upon power-up and call of",
            "details": "[SP 800- 135 rev1] Section",
            "indicator": "Returns 1 on successful",
            "testMethod": "KAT",
            "testProps": "Fixed input KAT",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "",
            "condition": "SELF_TEST_post( ) function",
            "details": "4.1.2 IKEv2 KDF KAT",
            "indicator": "completio n",
            "testMethod": "",
            "testProps": "",
            "type": ""
          },
          {
            "algorithmOrTest": "KDF SNMP (A3252)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "[SP 800- 135 rev1] Section 5.4 SNMPv3 KDF KAT",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "Fixed input KAT",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "KDF SRTP (A3252)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "[SP 800- 135 rev1] Section 5.3 SRTP KDF KAT",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "Fixed input KAT",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "KDF SSH (A3252)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "[SP 800- 135 rev1] Section 5.2 SSHv2 KDF KAT",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "SHA1",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "TDES- CBC (A3032)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Decrypt KAT",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "Keying Option: 1",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "TDES- CMAC (A3032)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Verify KAT",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "Keying Option: 1",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "TDES- CBC (A3252)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Decrypt KAT",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "Keying Option: 1",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "TDES- CMAC (A3252)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Verify KAT",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "Keying Option: 1",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "AES-ECB (A3032)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Decrypt KAT",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "128 bits",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "AES-ECB (A3252)",
            "condition": "Upon power-up and call of",
            "details": "Decrypt KAT",
            "indicator": "Returns 1 on successful",
            "testMethod": "KAT",
            "testProps": "128 bits",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "",
            "condition": "SELF_TEST_post( ) function",
            "details": "",
            "indicator": "completio n",
            "testMethod": "",
            "testProps": "",
            "type": ""
          },
          {
            "algorithmOrTest": "AES- GCM (A3032)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Decrypt KAT",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "256 bits",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "AES- GCM (A3252)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Decrypt KAT",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "256 bits",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "AES- CMAC (A3032)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Verify KAT",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "128, 192, 256 bits",
            "type": "CAS T"
          },
          {
            "algorithmOrTest": "AES- CMAC (A3252)",
            "condition": "Upon power-up and call of SELF_TEST_post( ) function",
            "details": "Verify KAT",
            "indicator": "Returns 1 on successful completio n",
            "testMethod": "KAT",
            "testProps": "128, 192, 256 bits",
            "type": "CAS T"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 2
      },
      "error_states": {
        "entries": [
          {
            "conditions": "Failure of self tests",
            "description": "Error State is entered when self tests fail",
            "indicator": "0",
            "name": "Error State",
            "recoveryMethod": "Restarting the module"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 4
      },
      "mechanisms_actions": {
        "entries": [],
        "found": false,
        "section": 7,
        "subsection": 1
      },
      "modes_of_operation": {
        "entries": [
          {
            "description": "Provides services approved by FIPS 140-3",
            "name": "Approved Mode",
            "statusIndicator": "Returns 1 when approved services are run successfully",
            "type": "Approved"
          },
          {
            "description": "Provides services not approved for use in FIPS 140-3",
            "name": "Non- Approved Mode",
            "statusIndicator": "Returns 3, ED25519, ED448, X25519, X448 when non-approved services are run successfully",
            "type": "Non- Approved"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 4
      },
      "non_approved_allowed_NSC": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_allowed_algos": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_not_allowed": {
        "entries": [
          {
            "name": "EdDSA KeyGen",
            "use": "Asymmetric Key Generation (Ed25519, Ed448, X25519, and X448)"
          },
          {
            "name": "EdDSA SigGen",
            "use": "Signature generation using Edwards curves (ED25519, ED448)"
          },
          {
            "name": "EdDSA SigVer",
            "use": "Signature verification using Edwards curves (ED25519, ED448)"
          },
          {
            "name": "RSA Primitives",
            "use": "RSA Signature generation, verification, encrypt and decrypt primitives"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "non_approved_services": {
        "entries": [
          {
            "alg_accessed": "EdDSA KeyGen",
            "description": "Key pair generation using Edwards curves (ED25519, ED448, X25519, X448)",
            "name": "Edwards curves Key Generation",
            "role": "CO, User"
          },
          {
            "alg_accessed": "EdDSA SigGen",
            "description": "Signature generation using Edwards curves (ED25519, ED448)",
            "name": "Edwards curves Digital Signature Generation",
            "role": "CO, User"
          },
          {
            "alg_accessed": "EdDSA SigVer",
            "description": "Signature verification using Edwards curves (ED25519, ED448)",
            "name": "Edwards curves Digital Signature Verification",
            "role": "CO, User"
          },
          {
            "alg_accessed": "RSA Primitives",
            "description": "RSA Sign, verify, encrypt, decrypt without hashing/padding",
            "name": "RSA Primitives",
            "role": "CO, User"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 4
      },
      "ports_interfaces": {
        "entries": [
          {
            "data": "API entry point data input stack parameters",
            "logicalInterface": "Data Input",
            "physicalPort": "N/A"
          },
          {
            "data": "API output parameters resulting from call execution",
            "logicalInterface": "Data Output",
            "physicalPort": "N/A"
          },
          {
            "data": "API entry point and corresponding stack parameters",
            "logicalInterface": "Control Input",
            "physicalPort": "N/A"
          },
          {
            "data": "API return value resulting from call execution",
            "logicalInterface": "Status Output",
            "physicalPort": "N/A"
          }
        ],
        "found": true,
        "section": 3,
        "subsection": 1
      },
      "roles": {
        "entries": [
          {
            "authMethodList": "None",
            "name": "Crypto-Officer",
            "operatorType": "Crypto-Officer",
            "type": "Role"
          },
          {
            "authMethodList": "None",
            "name": "User",
            "operatorType": "User",
            "type": "Role"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 2
      },
      "security_levels": {
        "entries": [
          {
            "level": "1",
            "section": "1",
            "title": "General"
          },
          {
            "level": "1",
            "section": "2",
            "title": "Cryptographic module specification"
          },
          {
            "level": "1",
            "section": "3",
            "title": "Cryptographic module interfaces"
          },
          {
            "level": "1",
            "section": "4",
            "title": "Roles, services, and authentication"
          },
          {
            "level": "1",
            "section": "5",
            "title": "Software/Firmware security"
          },
          {
            "level": "1",
            "section": "6",
            "title": "Operational environment"
          },
          {
            "level": "1",
            "section": "7",
            "title": "Physical security"
          },
          {
            "level": "N/A",
            "section": "8",
            "title": "Non-invasive security"
          },
          {
            "level": "1",
            "section": "9",
            "title": "Sensitive security parameter management"
          },
          {
            "level": "1",
            "section": "10",
            "title": "Self-tests"
          },
          {
            "level": "1",
            "section": "11",
            "title": "Life-cycle assurance"
          },
          {
            "level": "1",
            "section": "12",
            "title": "Mitigation of other attacks"
          },
          {
            "level": "1",
            "section": "",
            "title": "Overall Level"
          }
        ],
        "found": true,
        "section": 1,
        "subsection": 2
      },
      "self_tests": {
        "entries": [
          {
            "algorithmOrTest": "HMAC- SHA2-256 (A3032)",
            "details": "The SELF_TEST_post() function performs all power-up self-tests listed above with no",
            "indicator": "Returns 1 when power up",
            "testMethod": "Firmware Integrity Test",
            "testProps": "256 bits",
            "type": "SW/FW Integrity"
          },
          {
            "algorithmOrTest": "",
            "details": "operator intervention required when the module loads, returning a \u00271\u0027 if all power-up self-tests succeed, and a \u00270\u0027 otherwise. The power-up self- tests may also be performed on-demand by calling this function and interpretation of the return code is the responsibility of the calling application",
            "indicator": "self tests succeed",
            "testMethod": "",
            "testProps": "",
            "type": ""
          },
          {
            "algorithmOrTest": "HMAC- SHA2-256 (A3252)",
            "details": "The SELF_TEST_post() function performs all power-up self-tests listed above with no operator intervention required when the module loads, returning a \u00271\u0027 if all power-up self-tests succeed, and a \u00270\u0027 otherwise. The power-up self- tests may also be performed on-demand by calling this function and interpretation of the return code is the responsibility of the calling application",
            "indicator": "Returns 1 when power up self tests succeed",
            "testMethod": "Firmware Integrity Test",
            "testProps": "256 bits",
            "type": "SW/FW Integrity"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 1
      },
      "ssp_io_methods": {
        "entries": [
          {
            "dest": "API input parameters",
            "distribution": "Manual",
            "entry": "Electronic",
            "format": "Plaintext",
            "name": "API Input",
            "sfiAlgo": "",
            "source": "Calling process"
          },
          {
            "dest": "Calling process",
            "distribution": "Manual",
            "entry": "Electronic",
            "format": "Plaintext",
            "name": "API Output",
            "sfiAlgo": "",
            "source": "API output parameters"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 2
      },
      "ssp_zeroization_methods": {
        "entries": [
          {
            "description": "API call clears the temporarily stored CSPs",
            "method": "OPENSSL_cleanse()",
            "operatorId": "Allowed",
            "rationale": "Zeroized SSPs will no longer be accessible through API calls"
          },
          {
            "description": "Power Cycle zeroizes all stored SSPs",
            "method": "Power Cycle",
            "operatorId": "Allowed",
            "rationale": "Operating System zeroizes all the stored SSPs"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 3
      },
      "storage_areas": {
        "entries": [
          {
            "description": "Volatile Memory",
            "name": "RAM",
            "persistance": "Dynamic"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 1
      },
      "tested_module_id_hw": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "tested_module_id_hw_hy": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "tested_module_id_sw_fw_hy": {
        "entries": [
          {
            "features": "",
            "integrityTest": "HMAC SHA2-256",
            "packageFileName": "fips.so",
            "swFwVersion": "8.0"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 2
      },
      "tested_op_env_sw_fw_hy": {
        "entries": [
          {
            "hardwarePlatform": "Cisco Unified Computing System (UCS)",
            "hypervisorHostOs": "ESXi 7.0",
            "operatingSystem": "Cisco IOS-XE 17.14",
            "paa_pai": "Yes",
            "processors": "Intel Xeon Gold 6244",
            "version": "8.0"
          },
          {
            "hardwarePlatform": "Cisco Unified Computing System (UCS)",
            "hypervisorHostOs": "ESXi 7.0",
            "operatingSystem": "Cisco IOS-XE 17.14",
            "paa_pai": "No",
            "processors": "Intel Xeon Gold 6244",
            "version": "8.0"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 2
      },
      "vendor_affirmed_algos": {
        "entries": [
          {
            "algoPropList": "",
            "implName": "CiscoSSL FIPS Provider Cryptographic Implementation",
            "name": "CKG Section 4",
            "reference": "Section 4 of NIST SP 800-133 rev2"
          },
          {
            "algoPropList": "",
            "implName": "CiscoSSL FIPS Provider Cryptographic Implementation Non-PAA",
            "name": "CKG Section 4",
            "reference": "Section 4 of NIST SP 800-133 rev2"
          },
          {
            "algoPropList": "",
            "implName": "CiscoSSL FIPS Provider Cryptographic Implementation",
            "name": "CKG Section 5",
            "reference": "Section 5 of NIST SP 800-133 rev2"
          },
          {
            "algoPropList": "",
            "implName": "CiscoSSL FIPS Provider Cryptographic Implementation Non-PAA",
            "name": "CKG Section 5",
            "reference": "Section 5 of NIST SP 800-133 rev2"
          },
          {
            "algoPropList": "",
            "implName": "CiscoSSL FIPS Provider Cryptographic Implementation",
            "name": "CKG Section 6.2",
            "reference": "Section 6 of NIST SP 800-133 rev2"
          },
          {
            "algoPropList": "",
            "implName": "CiscoSSL FIPS Provider Cryptographic Implementation Non-PAA",
            "name": "CKG Section 6.2",
            "reference": "Section 6 of NIST SP 800-133 rev2"
          },
          {
            "algoPropList": "",
            "implName": "CiscoSSL FIPS Provider Cryptographic Implementation",
            "name": "CKG Section 6.1",
            "reference": "Section 6 of NIST SP 800-133 rev2"
          },
          {
            "algoPropList": "",
            "implName": "CiscoSSL FIPS Provider Cryptographic Implementation Non-PAA",
            "name": "CKG Section 6.1",
            "reference": "Section 6 of NIST SP 800-133 rev2"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "vendor_affirmed_op_env_sw_fw_hy": {
        "entries": [
          {
            "hardwarePlatform": "N/A",
            "operatingSystem": "N/A"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 2
      }
    },
    "is_br1_format": true,
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 4
          },
          "ECDH": {
            "ECDH": 1
          },
          "ECDSA": {
            "ECDSA": 53
          },
          "EdDSA": {
            "EdDSA": 6
          }
        },
        "FF": {
          "DH": {
            "DH": 27,
            "DHE": 2,
            "Diffie-Hellman": 4
          },
          "DSA": {
            "DSA": 56
          }
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 2
        },
        "CTR": {
          "CTR": 2
        },
        "GCM": {
          "GCM": 13
        },
        "XTS": {
          "XTS": 2
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {
        "OpenSSL": {
          "OpenSSL": 2
        }
      },
      "crypto_protocol": {
        "IKE": {
          "IKE": 1,
          "IKEv2": 12
        },
        "SSH": {
          "SSH": 9,
          "SSHv2": 4
        },
        "TLS": {
          "TLS": {
            "TLS": 4,
            "TLS 1.2": 6,
            "TLS 1.3": 2,
            "TLS v1.2": 7,
            "TLS v1.3": 10
          }
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 5
        },
        "MAC": {
          "MAC": 13
        }
      },
      "device_model": {},
      "ecc_curve": {
        "Edwards": {
          "Ed25519": 1,
          "Ed448": 1
        },
        "NIST": {
          "P-256": 34,
          "P-384": 26,
          "P-521": 24
        }
      },
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "#1": 2,
          "#3": 1
        }
      },
      "fips_certlike": {
        "Certlike": {
          "AES-128": 6,
          "AES-192": 4,
          "AES-256": 4,
          "HMAC SHA2256": 1,
          "HMAC-SHA-1": 8,
          "HMAC-SHA3": 2,
          "PKCS 1": 8,
          "SHA-1": 33,
          "SHA-2": 2,
          "SHA-3": 2,
          "SHA1": 2,
          "SHA2- 256": 14,
          "SHA2- 384": 3,
          "SHA2- 512": 2,
          "SHA2-224": 28,
          "SHA2-256": 44,
          "SHA2-384": 26,
          "SHA2-512": 34,
          "SHA2256": 1,
          "SHA3": 3,
          "SHA3- 256": 2,
          "SHA3- 384": 4,
          "SHA3-224": 8,
          "SHA3-256": 10,
          "SHA3-384": 4,
          "SHA3-512": 6,
          "SHA512": 1
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 4,
          "level 1": 2
        }
      },
      "hash_function": {
        "PBKDF": {
          "PBKDF": 13,
          "PBKDF2": 2
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 33,
            "SHA1": 2
          },
          "SHA2": {
            "SHA-2": 2,
            "SHA512": 1
          },
          "SHA3": {
            "SHA-3": 2,
            "SHA3": 3,
            "SHA3-224": 8,
            "SHA3-256": 10,
            "SHA3-384": 4,
            "SHA3-512": 6
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {
        "curves": {
          "ED25519": 7,
          "ED448": 7,
          "X25519": 4,
          "X448": 4
        }
      },
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 39
        },
        "RNG": {
          "RBG": 3
        }
      },
      "side_channel_analysis": {
        "SCA": {
          "side-channel": 1,
          "timing attacks": 2
        }
      },
      "standard_id": {
        "FIPS": {
          "FIPS 140-3": 30,
          "FIPS 180-4": 14,
          "FIPS 186-4": 26,
          "FIPS 198-1": 22,
          "FIPS 202": 12,
          "FIPS PUB 140-3": 1,
          "FIPS186-4": 66
        },
        "ISO": {
          "ISO/IEC 19790": 4
        },
        "NIST": {
          "NIST SP 800-133": 8,
          "SP 800-108": 2,
          "SP 800-131A": 1,
          "SP 800-132": 4,
          "SP 800-133": 4,
          "SP 800-135": 17,
          "SP 800-140B": 1,
          "SP 800-185": 4,
          "SP 800-38A": 20,
          "SP 800-38B": 2,
          "SP 800-38C": 2,
          "SP 800-38D": 5,
          "SP 800-38E": 3,
          "SP 800-38F": 5,
          "SP 800-52": 1,
          "SP 800-56A": 21,
          "SP 800-56B": 11,
          "SP 800-56C": 7,
          "SP 800-67": 6,
          "SP 800-90A": 9
        },
        "PKCS": {
          "PKCS 1": 4
        },
        "RFC": {
          "RFC 5246": 1,
          "RFC 5288": 1,
          "RFC 7296": 1,
          "RFC 8446": 1,
          "RFC5282": 1,
          "RFC7627": 7,
          "RFC8446": 2
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 30,
            "AES-": 11,
            "AES-128": 6,
            "AES-192": 4,
            "AES-256": 4
          },
          "CAST": {
            "CAST": 73
          }
        },
        "DES": {
          "3DES": {
            "TDES": 8
          }
        },
        "constructions": {
          "MAC": {
            "CMAC": 12,
            "HMAC": 28,
            "KMAC": 7
          }
        }
      },
      "tee_name": {
        "AMD": {
          "PSP": 7
        },
        "IBM": {
          "SSC": 6
        }
      },
      "tls_cipher_suite": {},
      "vendor": {
        "Cisco": {
          "Cisco": 11,
          "Cisco Systems": 1,
          "Cisco Systems, Inc": 21
        }
      },
      "vulnerability": {}
    },
    "module_algorithms": {
      "_type": "Set",
      "elements": [
        "KDA OneStep SP800-56Cr2A3252",
        "KMAC-128A3252",
        "HMAC-SHA3-224A3252",
        "KTS-IFCA3252",
        "KDA HKDF SP800-56Cr2A3252",
        "KDA TwoStep SP800-56Cr2A3252",
        "AES-GMACA3252",
        "AES-CTRA3252",
        "KDF IKEv2A3252",
        "DSA PQGGen (FIPS186-4)A3252",
        "SHA3-512A3252",
        "KAS-IFC-SSCA3252",
        "KDF SNMPA3252",
        "SHA3-224A3252",
        "SHA2-512/256A3252",
        "AES-XTS Testing Revision 2.0A3252",
        "SHA2-384A3252",
        "AES-KWPA3252",
        "ECDSA KeyVer (FIPS186-4)A3252",
        "Hash DRBGA3252",
        "KAS-FFC-SSC Sp800-56Ar3A3252",
        "ECDSA KeyGen (FIPS186-4)A3252",
        "DSA SigVer (FIPS186-4)A3252",
        "AES-CFB1A3252",
        "SHA2-224A3252",
        "ECDSA SigVer (FIPS186-4)A3252",
        "KAS-ECC CDH-Component SP800-56Ar3A3252",
        "TLS v1.3 KDFA3252",
        "KDF ANS 9.63A3252",
        "KDF SP800-108A3252",
        "DSA PQGVer (FIPS186-4)A3252",
        "HMAC-SHA2-512/256A3252",
        "HMAC-SHA3-256A3252",
        "AES-CBC-CS1A3252",
        "AES-CFB128A3252",
        "Safe Primes Key GenerationA3252",
        "HMAC-SHA-1A3252",
        "KDF SSHA3252",
        "Safe Primes Key VerificationA3252",
        "HMAC-SHA2-512A3252",
        "TDES-CMACA3252",
        "KDF ANS 9.42A3252",
        "TDES-ECBA3252",
        "RSA KeyGen (FIPS186-4)A3252",
        "HMAC DRBGA3252",
        "DSA KeyGen (FIPS186-4)A3252",
        "SHA3-256A3252",
        "AES-CBCA3252",
        "TDES-CBCA3252",
        "KDF SRTPA3252",
        "AES-ECBA3252",
        "AES-CCMA3252",
        "AES-KWA3252",
        "AES-GCMA3252",
        "ECDSA SigGen (FIPS186-4)A3252",
        "SHA2-512A3252",
        "SHA2-512/224A3252",
        "RSA Signature PrimitiveA3252",
        "SHAKE-256A3252",
        "HMAC-SHA2-384A3252",
        "SHA3-384A3252",
        "HMAC-SHA3-384A3252",
        "AES-CFB8A3252",
        "PBKDFA3252",
        "AES-CBC-CS3A3252",
        "RSA SigVer (FIPS186-4)A3252",
        "HMAC-SHA2-224A3252",
        "SHAKE-128A3252",
        "Counter DRBGA3252",
        "KMAC-256A3252",
        "AES-OFBA3252",
        "AES-CMACA3252",
        "KAS-ECC-SSC Sp800-56Ar3A3252",
        "RSA SigGen (FIPS186-4)A3252",
        "DSA SigGen (FIPS186-4)A3252",
        "HMAC-SHA2-512/224A3252",
        "HMAC-SHA3-512A3252",
        "AES-CBC-CS2A3252",
        "SHA2-256A3252",
        "HMAC-SHA2-256A3252",
        "TLS v1.2 KDF RFC7627A3252",
        "SHA-1A3252"
      ]
    },
    "policy_algorithms": {
      "_type": "Set",
      "elements": [
        "#A3032",
        "#A3252"
      ]
    },
    "policy_metadata": {
      "/Author": "Hawes, David J. (Fed)",
      "/Comments": "",
      "/Company": "",
      "/CreationDate": "D:20241206124717-05\u002700\u0027",
      "/Creator": "Acrobat PDFMaker 24 for Word",
      "/Keywords": "",
      "/ModDate": "D:20241206124910-05\u002700\u0027",
      "/Producer": "Adobe PDF Library 24.3.144",
      "/SourceModified": "",
      "/Subject": "",
      "/Title": "",
      "pdf_file_size_bytes": 636974,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": []
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 66
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.InternalState",
    "module": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "policy": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": "6ec720fa6440373decc1f046d97ee869de5561c76ef8150eec4766fd777997e3",
      "source_hash": "389e6c4a28bc57162f37f22ebec0dbc81c450b32049448aa852fdd0c89358357",
      "txt_hash": "78b3348b9c18c055936b40750895efb9c35aaa9da63f6320bfcd1b6ad917edaf"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "Interim validation. When operated in approved mode. No assurance of the minimum strength of generated SSPs (e.g., keys)",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/November 2024_021224_0125.pdf",
    "date_sunset": null,
    "description": "The CiscoSSL FIPS Provider is a firmware library that provides cryptographic services to a vast array of Cisco\u0027s networking and collaboration products. The module is comprised of a single object module file called fips.so.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Non-invasive security: N/A"
    ],
    "fw_versions": null,
    "historical_reason": "Replaced by certificate #5430",
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {},
    "module_name": "CiscoSSL FIPS Provider",
    "module_type": "Firmware",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-3",
    "status": "historical",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2024-11-18",
        "lab": "Acumen Security",
        "validation_type": "Initial"
      }
    ],
    "vendor": "Cisco Systems, Inc",
    "vendor_url": "https://www.cisco.com/"
  }
}