Windows Server 2008 Code Integrity (ci.dll)

Certificate #1006

Webpage information

Status historical
Historical reason Moved to historical list due to sunsetting
Validation dates 15.08.2008 , 24.07.2009
Standard FIPS 140-2
Security level 1
Type Software
Embodiment Multi-Chip Stand Alone
Caveat When operated in FIPS mode with Winload OS Loader (winload.exe) validated to FIPS 140-2 under Cert. #1005 operating in FIPS mode
Description This is a dynamically linked library that runs as ntoskrnl.exe. It verifies the integrity of executable files, including kernel mode drivers, critical system components and user mode crypto modules, before these files are loaded from disk into memory by the memory manager.
Tested configurations
  • Microsoft Windows Server 2008 (IA64 version) (single-user mode)
  • Microsoft Windows Server 2008 (x64 version)
  • Microsoft Windows Server 2008 (x86 Version)
Vendor Microsoft Corporation
References

This certificate's webpage directly references 1 certificates, transitively this expands into 2 certificates.

Security policy

Hash functions
SHA-1, bcrypt

Vendor
Microsoft

Standards
FIPS 140-2, PKCS#1

File metadata

Title Microsoft Word - Windows 2008 Code Integrity FIPS Security Policy
Author marescaj
Creation date D:20090722105715-04'00'
Modification date D:20090722105715-04'00'
Pages 6
Creator PScript5.dll Version 5.2
Producer Acrobat Distiller 8.0.0 (Windows)

References

Outgoing
  • 1005 - historical - Windows Server 2008 Winload OS Loader (winload.exe)
Incoming
  • 1009 - historical - Windows Server 2008 Enhanced DSS and Diffie-Hellman Cryptographic Provider (DSSENH)
  • 1010 - historical - Windows Server 2008 Enhanced Cryptographic Provider (RSAENH)
  • 1008 - historical - Microsoft Windows Server 2008 Cryptographic Primitives Library (bcrypt.dll)
  • 1054 - historical - BitLockerâ„¢ Drive Encryption

Heuristics

No heuristics are available for this certificate.

References

Loading...

Updates Feed

  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 1006,
  "dgst": "478c4ffb1cbcea37",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "SHS#753",
        "RSA#355"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "2008"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": {
        "_type": "Set",
        "elements": [
          "1010",
          "1008",
          "1009"
        ]
      },
      "directly_referencing": {
        "_type": "Set",
        "elements": [
          "1005"
        ]
      },
      "indirectly_referenced_by": {
        "_type": "Set",
        "elements": [
          "1500",
          "1008",
          "1054",
          "1009",
          "1010",
          "2005"
        ]
      },
      "indirectly_referencing": {
        "_type": "Set",
        "elements": [
          "1004",
          "1005"
        ]
      }
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": [
        "1005"
      ]
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": {
        "_type": "Set",
        "elements": [
          "1010",
          "1008",
          "1054",
          "1009"
        ]
      },
      "directly_referencing": {
        "_type": "Set",
        "elements": [
          "1005"
        ]
      },
      "indirectly_referenced_by": {
        "_type": "Set",
        "elements": [
          "1008",
          "1054",
          "1009",
          "1010",
          "2005"
        ]
      },
      "indirectly_referencing": {
        "_type": "Set",
        "elements": [
          "1004",
          "1005"
        ]
      }
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": [
        "1005"
      ]
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {},
      "certification_process": {},
      "cipher_mode": {},
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {},
      "crypto_scheme": {},
      "device_model": {},
      "ecc_curve": {},
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "#1005": 1,
          "#355": 1,
          "#753": 1
        }
      },
      "fips_certlike": {
        "Certlike": {
          "PKCS#1": 9,
          "RSA PKCS#1": 3,
          "SHA-1": 8
        }
      },
      "fips_security_level": {},
      "hash_function": {
        "SHA": {
          "SHA1": {
            "SHA-1": 8
          }
        },
        "bcrypt": {
          "bcrypt": 2
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {},
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-2": 4
        },
        "PKCS": {
          "PKCS#1": 6
        }
      },
      "symmetric_crypto": {},
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {
        "Microsoft": {
          "Microsoft": 8
        }
      },
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "marescaj",
      "/CreationDate": "D:20090722105715-04\u002700\u0027",
      "/Creator": "PScript5.dll Version 5.2",
      "/ModDate": "D:20090722105715-04\u002700\u0027",
      "/Producer": "Acrobat Distiller 8.0.0 (Windows)",
      "/Title": "Microsoft Word - Windows 2008 Code Integrity FIPS Security Policy",
      "pdf_file_size_bytes": 56575,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": []
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 6
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
    "module_download_ok": true,
    "module_extract_ok": true,
    "policy_convert_ok": true,
    "policy_download_ok": true,
    "policy_extract_ok": true,
    "policy_json_hash": null,
    "policy_pdf_hash": "f3ed119d0d49c524d744a54bbb9cb811eb04a592a8cafc12a8bc4ee584f126c7",
    "policy_txt_hash": "8ddf9cb9724531646b2cbd22367e32c74295b4b2045e971b0cf99067ce4daf8e"
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in FIPS mode with Winload OS Loader (winload.exe) validated to FIPS 140-2 under Cert. #1005 operating in FIPS mode",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/140crt1006.pdf",
    "date_sunset": null,
    "description": "This is a dynamically linked library that runs as ntoskrnl.exe. It verifies the integrity of executable files, including kernel mode drivers, critical system components and user mode crypto modules, before these files are loaded from disk into memory by the memory manager.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": null,
    "fw_versions": null,
    "historical_reason": "Moved to historical list due to sunsetting",
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {
      "1005": 1
    },
    "module_name": "Windows Server 2008 Code Integrity (ci.dll)",
    "module_type": "Software",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-2",
    "status": "historical",
    "sw_versions": "6.0.6001.18000 and 6.0.6002.18005",
    "tested_conf": [
      "Microsoft Windows Server 2008 (IA64 version) (single-user mode)",
      "Microsoft Windows Server 2008 (x64 version)",
      "Microsoft Windows Server 2008 (x86 Version)"
    ],
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2008-08-15",
        "lab": "SAIC-VA",
        "validation_type": "Initial"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2009-07-24",
        "lab": "",
        "validation_type": "Update"
      }
    ],
    "vendor": "Microsoft Corporation",
    "vendor_url": "http://www.microsoft.com"
  }
}