{"_type": "sec_certs.sample.fips.FIPSCertificate", "dgst": "525cfd02ce6f836c", "cert_id": 5400, "web_data": {"_type": "sec_certs.sample.fips.FIPSCertificate.WebData", "module_name": "Junos\u00ae OS Evolved OpenSSL Cryptographic Module", "validation_history": [{"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry", "date": "2026-07-20", "validation_type": "Initial", "lab": "atsec information security corporation"}], "vendor_url": "http://www.juniper.net", "vendor": "Juniper Networks, Inc.", "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/July 2026_040826_0807.pdf", "module_type": "Software", "standard": "FIPS 140-3", "status": "active", "level": 1, "caveat": "When operated in approved mode with module Junos\u00ae OS Evolved Kernel Cryptographic Module version 2.0 validated to FIPS 140-3 under Cert. #5399 operating in the Approved mode. The module generates cryptographic keys whose strengths are modified by available entropy. No assurance of minimum security of SSPs (e.g. keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.", "exceptions": ["Physical security: N/A", "Non-invasive security: N/A"], "embodiment": "MultiChipStand", "description": "The Junos\u00ae OS Evolved OpenSSL Cryptographic Module provides a C language application program interface (API) for use by other applications that require cryptographic functionality.", "tested_conf": null, "hw_versions": null, "fw_versions": null, "sw_versions": null, "mentioned_certs": {"5399": 1}, "historical_reason": null, "date_sunset": "2029-09-02", "revoked_reason": null, "revoked_link": null}, "pdf_data": {"_type": "sec_certs.sample.fips.FIPSCertificate.PdfData", "keywords": {"fips_cert_id": {"Cert": {"#5399": 1}}, "fips_security_level": {"Level": {"Level 1": 3}}, "fips_certlike": {"Certlike": {"HMAC-SHA- 1": 2, "HMAC-SHA-1": 18, "SHA2-224": 16, "SHA2-256": 44, "SHA2-384": 12, "SHA2- 512": 3, "SHA3-224": 9, "SHA3-256": 15, "SHA3-384": 13, "SHA3- 512": 7, "SHA-1": 31, "SHA2- 384": 5, "SHA2-512": 28, "SHA3-512": 8, "SHA-3": 4, "SHA2- 256": 8, "SHA-224": 14, "SHA-256": 5, "SHA-2": 1, "- PKCS 1": 2, "PKCS#1": 26, "AES256": 1, "AES-128": 1, "AES-192": 1, "AES-256": 1, "AES key 128, 192": 1, "PKCS 1": 2}}, "vendor": {}, "eval_facility": {"atsec": {"atsec": 2}}, "symmetric_crypto": {"AES_competition": {"AES": {"AES256": 1, "AES-128": 1, "AES-192": 1, "AES-256": 1, "AES": 30, "AES-": 6}, "CAST": {"CAST": 234}}, "constructions": {"MAC": {"HMAC": 30, "KMAC": 8, "CMAC": 3}}}, "asymmetric_crypto": {"ECC": {"ECDH": {"ECDH": 57}, "ECDSA": {"ECDSA": 76}, "ECC": {"ECC": 2}}, "FF": {"DH": {"Diffie-Hellman": 10, "DHE": 1, "DH": 58}}}, "pq_crypto": {}, "hash_function": {"SHA": {"SHA1": {"SHA-1": 31}, "SHA2": {"SHA-224": 14, "SHA-256": 5, "SHA-2": 1}, "SHA3": {"SHA3-224": 9, "SHA3-256": 15, "SHA3-384": 13, "SHA3-512": 8, "SHA-3": 4}}, "PBKDF": {"PBKDF2": 10, "PBKDF": 14}}, "crypto_scheme": {"MAC": {"MAC": 38}, "KEX": {"Key Exchange": 1}, "KA": {"Key Agreement": 3}}, "crypto_protocol": {"SSH": {"SSH": 36}, "TLS": {"TLS": {"TLS v1.2": 14, "TLS v1.3": 5, "TLS 1.3": 19, "TLS 1.2": 19, "TLS": 7}}, "IKE": {"IKE": 3}}, "randomness": {"PRNG": {"DRBG": 29}, "RNG": {"RNG": 2, "RBG": 2}}, "cipher_mode": {"ECB": {"ECB": 1}, "CBC": {"CBC": 1}, "CTR": {"CTR": 1}, "GCM": {"GCM": 7}, "CCM": {"CCM": 1}, "XTS": {"XTS": 2}}, "ecc_curve": {"NIST": {"P-224": 56, "P-256": 28, "P-384": 26, "P-521": 26, "B-233": 22, "B-283": 9, "B-409": 8, "B-571": 9, "K-233": 9, "K-283": 9, "K-409": 9, "K-571": 9}}, "crypto_engine": {}, "tls_cipher_suite": {}, "crypto_library": {"OpenSSL": {"OpenSSL": 85}}, "vulnerability": {}, "side_channel_analysis": {}, "device_model": {}, "tee_name": {"AMD": {"PSP": 4}, "IBM": {"SSC": 2}}, "os_name": {}, "cplc_data": {}, "ic_data_group": {}, "standard_id": {"FIPS": {"FIPS 140-3": 91, "FIPS PUB 140-3": 2, "FIPS186-4": 84, "FIPS 186-4": 22, "FIPS 198-1": 12, "FIPS 180-4": 8, "FIPS 202": 7}, "NIST": {"SP 800-140B": 1, "SP 800-135": 9, "SP 800-108": 3, "SP 800-185": 3, "SP 800-132": 7, "SP 800-90A": 9, "SP 800-133": 5, "SP 800-38E": 2, "SP 800-56A": 9, "SP 800-90B": 2, "SP 800-56C": 2, "SP 800-38A": 1, "SP 800-38B": 1, "SP 800-38C": 1, "SP 800-38D": 1, "SP 800-38F": 1}, "PKCS": {"PKCS 1": 2, "PKCS#1": 13}, "RFC": {"RFC7627": 9, "RFC 3526": 2, "RFC 7919": 2, "RFC 4253": 2, "RFC 6668": 2}}, "javacard_version": {}, "javacard_api_const": {}, "javacard_packages": {}, "certification_process": {}}, "policy_metadata": {"pdf_file_size_bytes": 1065614, "pdf_is_encrypted": false, "pdf_number_of_pages": 80, "/Producer": "Microsoft\u00ae Word for Microsoft 365", "/Creator": "Microsoft\u00ae Word for Microsoft 365", "/CreationDate": "D:20260720152907-04'00'", "/ModDate": "D:20260720152907-04'00'", "pdf_hyperlinks": {"_type": "Set", "elements": ["https://doi.org/10.6028/NIST.FIPS.180-4", "https://www.ietf.org/rfc/rfc3526.txt", "https://doi.org/10.6028/NIST.SP.800-56Ar3", "https://doi.org/10.6028/NIST.SP.800-56Cr2", "https://doi.org/10.6028/NIST.SP.800-38E", "https://doi.org/10.6028/NIST.SP.800-90B", "https://doi.org/10.6028/NIST.SP.800-133r2", "https://doi.org/10.6028/NIST.SP.800-38B", "https://csrc.nist.gov/Projects/cryptographic-module-validation-program/fips-140-3-ig-announcements", "http://www.atsec.com/", "https://www.ietf.org/rfc/rfc6668.txt", "https://doi.org/10.6028/NIST.SP.800-185", "https://www.ietf.org/rfc/rfc4253.txt", "https://www.ietf.org/rfc/rfc3447.txt", "https://webstore.ansi.org/Standards/ASCX9/ANSIX9422003R2013", "https://doi.org/10.6028/NIST.SP.800-90Ar1", "https://doi.org/10.6028/NIST.SP.800-38D", "https://webstore.ansi.org/Standards/ASCX9/ANSIX9632011R2017", "https://doi.org/10.6028/NIST.SP.800-135r1", "http://www.juniper.net/", "https://doi.org/10.6028/NIST.FIPS.202", "https://doi.org/10.6028/NIST.SP.800-132", "https://doi.org/10.6028/NIST.SP.800-108r1-upd1", "https://doi.org/10.6028/NIST.SP.800-38A", "https://doi.org/10.6028/NIST.FIPS.186-4", "https://doi.org/10.6028/NIST.SP.800-38F", "https://doi.org/10.6028/NIST.FIPS.198-1", "https://doi.org/10.6028/NIST.SP.800-38C", "https://www.ietf.org/rfc/rfc7919.txt", "https://doi.org/10.6028/NIST.FIPS.140-3"]}}}, "heuristics": {"_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics", "algorithms": {"_type": "Set", "elements": ["AES-CMACA4231", "KAS-FFC-SSC Sp800-56Ar3A4251", "AES-CFB1A4231", "HMAC-SHA2-512/224A4249", "KDF SP800-108A4250", "SHA3-384A4236", "KDA OneStep SP800-56Cr2A4224", "Safe Primes Key VerificationA4251", "SHA2-224A4249", "ECDSA KeyGen (FIPS186-4)A4249", "KDF SSHA4235", "HMAC-SHA2-256A4249", "ECDSA SigGen (FIPS186-4)A4249", "AES-CFB128A4231", "SHA2-512A4249", "SHA2-256A4249", "RSA SigGen (FIPS186-4)A4249", "KAS-ECC-SSC Sp800-56Ar3A4249", "HMAC-SHA2-512A4249", "TLS v1.3 KDFA4228", "AES-KWPA4231", "AES-XTS Testing Revision 2.0A4231", "HMAC-SHA2-384A4249", "KDA HKDF Sp800-56Cr1A4228", "KMAC-256A4236", "SHAKE-128A4236", "AES-CCMA4231", "RSA SigVer (FIPS186-4)A4249", "HMAC-SHA2-224A4249", "SHA3-224A4236", "Safe Primes Key GenerationA4251", "HMAC-SHA2-512/256A4249", "HMAC-SHA3-512A4236", "SHA3-256A4236", "SHA3-512A4236", "KMAC-128A4236", "SHA2-512/224A4249", "AES-CFB8A4231", "AES-CTRA4231", "PBKDFA4249", "HMAC-SHA3-256A4236", "HMAC DRBGA3605", "SHAKE-256A4236", "SHA2-512/256A4249", "SHA2-384A4249", "AES-CBC-CS3A4231", "ECDSA KeyVer (FIPS186-4)A4249", "AES-CBCA4231", "AES-GCMA4245", "RSA KeyGen (FIPS186-4)A4249", "AES-OFBA4231", "KDF ANS 9.63A4249", "TLS v1.2 KDF RFC7627A4249", "HMAC-SHA-1A4249", "SHA-1A4249", "AES-KWA4231", "AES-CBC-CS1A4231", "KDF ANS 9.42A4249", "HMAC-SHA3-384A4236", "AES-GMACA4245", "ECDSA SigVer (FIPS186-4)A4249", "AES-ECBA4235", "AES-CBC-CS2A4231", "HMAC-SHA3-224A4236"]}, "extracted_versions": {"_type": "Set", "elements": ["-"]}, "cpe_matches": null, "verified_cpe_matches": null, "related_cves": null, "policy_prunned_references": {"_type": "Set", "elements": ["5399"]}, "module_prunned_references": {"_type": "Set", "elements": ["5399"]}, "policy_processed_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": {"_type": "Set", "elements": ["5399", "5489", "5490"]}, "indirectly_referenced_by": {"_type": "Set", "elements": ["5399", "5400", "5489", "5490"]}, "directly_referencing": {"_type": "Set", "elements": ["5399"]}, "indirectly_referencing": {"_type": "Set", "elements": ["5399", "5400"]}}, "module_processed_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": {"_type": "Set", "elements": ["5399", "5489", "5490"]}, "indirectly_referenced_by": {"_type": "Set", "elements": ["5399", "5400", "5489", "5490"]}, "directly_referencing": {"_type": "Set", "elements": ["5399"]}, "indirectly_referencing": {"_type": "Set", "elements": ["5399", "5400"]}}, "direct_transitive_cves": null, "indirect_transitive_cves": null}, "state": {"_type": "sec_certs.sample.fips.InternalState", "module": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": null, "txt_hash": null, "json_hash": null}, "policy": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": "31e68cdddd9be1c5ea720aa14a92a9df2a05d5459c1adadd9bddf209ce23ac94", "txt_hash": "f484bee41cfb2e38417141c2d40489055f7f7072894bb85fde36be0c0cd77f28", "json_hash": null}}}