Amazon Linux 2023 GnuTLS Cryptographic Module

Known vulnerabilities detected

Our automated heuristics have identified vulnerabilities that may be associated with this certificate. See the CVEs section for details.

Certificate details

Certificate ID #5015
Status active
Validation dates 05.05.2025
Sunset date 04-05-2030
Standard FIPS 140-3
Security level 1
Type Software
Embodiment Multi-Chip Stand Alone
Caveat When operated in approved mode and installed, initialized and configured as specified in Section 11 of the Security Policy.
Exceptions
  • Physical security: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A
Description GnuTLS is a secure communications library implementing the TLS protocol. It provides a simple C language application programming interface to access the secure communications protocols as well as APIs to parse and write X.509, PKCS#12, and other required structures.
Vendor Amazon Web Services, Inc. https://aws.amazon.com/linux/amazon-linux-2023/
Lab atsec information security corporation
Algorithms
  • AES-CBCA4572
  • AES-CCMA4572
  • AES-CFB8A4548
  • AES-CMACA4545
  • AES-GCMA4572
  • AES-GMACA4545
  • AES-XTS Testing Revision 2.0A4546
  • Counter DRBGA4545
  • ECDSA KeyGen (FIPS186-4)A4545
  • ECDSA KeyVer (FIPS186-4)A4545
  • ECDSA SigGen (FIPS186-4)A4545
  • ECDSA SigVer (FIPS186-4)A4545
  • HMAC-SHA-1A4572
  • HMAC-SHA2-224A4572
  • HMAC-SHA2-256A4572
  • HMAC-SHA2-384A4572
  • HMAC-SHA2-512A4572
  • KAS-ECC-SSC Sp800-56Ar3A4545
  • KAS-FFC-SSC Sp800-56Ar3A4545
  • KDA HKDF Sp800-56Cr1A4544
  • KDF TLSA4545
  • PBKDFA4545
  • RSA KeyGen (FIPS186-4)A4545
  • RSA SigGen (FIPS186-4)A4545
  • RSA SigVer (FIPS186-4)A4545
  • Safe Primes Key GenerationA4545
  • SHA-1A4572
  • SHA2-224A4572
  • SHA2-256A4572
  • SHA2-384A4572
  • SHA2-512A4572
  • SHA3-224A4547
  • SHA3-256A4547
  • SHA3-384A4547
  • SHA3-512A4547
  • TLS v1.2 KDF RFC7627A4545
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Extracted keywords

Symmetric Algorithms
AES, AES-256, Twofish, Serpent, CAST, RC2, RC4, DES, Triple-DES, Salsa20, Poly1305, Blowfish, Camellia, SEED, HMAC, CMAC
Asymmetric Algorithms
ECDH, ECDSA, ECC, Diffie-Hellman, DH, DSA
Hash functions
SHA-1, SHA3-224, SHA3-256, SHA3-384, SHA3-512, SHA-3, MD4, MD5, PBKDF, PBKDF2
Schemes
MAC, Key Agreement, Key agreement, AEAD
Protocols
TLS, TLS v1.2, TLS 1.0, TLS v1.3, TLSv1.0, TLSv1.1, TLSv1.2, TLSv1.3
Randomness
DRBG, RNG, RBG
Libraries
GnuTLS
Elliptic Curves
P-256, P-384, P-521
Block cipher modes
ECB, CBC, CTR, CFB, OFB, GCM, CCM, XTS
TLS cipher suites
TLS_DH_RSA_WITH_AES_128_CBC_SHA, TLS_DHE_RSA_WITH_AES_128_CBC_SHA, TLS_DH_RSA_WITH_AES_256_CBC_SHA, TLS_DHE_RSA_WITH_AES_256_CBC_SHA, TLS_DH_RSA_WITH_AES_128_CBC_SHA256, TLS_DHE_RSA_WITH_AES_128_CBC_SHA256, TLS_DH_RSA_WITH_AES_256_CBC_SHA256, TLS_DHE_RSA_WITH_AES_256_CBC_SHA256, TLS_PSK_WITH_AES_128_CBC_SHA, TLS_PSK_WITH_AES_256_CBC_SHA, TLS_DHE_RSA_WITH_AES_128_GCM_SHA256, TLS_DHE_RSA_WITH_AES_256_GCM_SHA384, TLS_DH_RSA_WITH_AES_128_GCM_SHA256, TLS_DH_RSA_WITH_AES_256_GCM_SHA384, TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA, TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA, TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA, TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA, TLS_ECDH_RSA_WITH_AES_128_CBC_SHA, TLS_ECDH_RSA_WITH_AES_256_CBC_SHA, TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA, TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA, TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256, TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384, TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA256, TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA384, TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, TLS_ECDH_RSA_WITH_AES_128_CBC_SHA256, TLS_ECDH_RSA_WITH_AES_256_CBC_SHA384, TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256, TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384, TLS_ECDH_ECDSA_WITH_AES_128_GCM_SHA256, TLS_ECDH_ECDSA_WITH_AES_256_GCM_SHA384, TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256, TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384, TLS_ECDH_RSA_WITH_AES_128_GCM_SHA256, TLS_ECDH_RSA_WITH_AES_256_GCM_SHA384, TLS_DHE_RSA_WITH_AES_128_CCM, TLS_DHE_RSA_WITH_AES_256_CCM, TLS_DHE_RSA_WITH_AES_128_CCM_8, TLS_DHE_RSA_WITH_AES_256_CCM_8

Trusted Execution Environments
PSP, SSC

Security level
Level 1

Automated analysis

Automated inference - use with caution

All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.

CVE matches

ID Links Severity CVSS Score Published on
Base score
CVE-2024-6387
C N
HIGH 8.1 01.07.2024

Cross-references

No references are available for this certificate.

Processing updates

Feed
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 5015,
  "dgst": "58c73a965e924d59",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "SHA2-256A4572",
        "TLS v1.2 KDF RFC7627A4545",
        "KAS-ECC-SSC Sp800-56Ar3A4545",
        "#A4547",
        "SHA-1A4572",
        "HMAC-SHA2-512A4572",
        "SHA2-512A4572",
        "HMAC-SHA2-384A4572",
        "HMAC-SHA-1A4572",
        "RSA KeyGen (FIPS186-4)A4545",
        "AES-XTS Testing Revision 2.0A4546",
        "#A4544",
        "ECDSA KeyGen (FIPS186-4)A4545",
        "Counter DRBGA4545",
        "AES-CBCA4572",
        "ECDSA SigGen (FIPS186-4)A4545",
        "HMAC-SHA2-256A4572",
        "RSA SigVer (FIPS186-4)A4545",
        "#A4538",
        "#A4540",
        "HMAC-SHA2-224A4572",
        "#A4542",
        "#A4572",
        "SHA3-224A4547",
        "Safe Primes Key GenerationA4545",
        "#A4548",
        "#A4546",
        "ECDSA SigVer (FIPS186-4)A4545",
        "AES-GMACA4545",
        "SHA2-384A4572",
        "SHA3-256A4547",
        "ECDSA KeyVer (FIPS186-4)A4545",
        "AES-CCMA4572",
        "#A4543",
        "#A4539",
        "KDF TLSA4545",
        "#A4537",
        "AES-GCMA4572",
        "KAS-FFC-SSC Sp800-56Ar3A4545",
        "SHA2-224A4572",
        "SHA3-384A4547",
        "PBKDFA4545",
        "#A4541",
        "AES-CMACA4545",
        "KDA HKDF Sp800-56Cr1A4544",
        "RSA SigGen (FIPS186-4)A4545",
        "AES-CFB8A4548",
        "#A4545",
        "SHA3-512A4547"
      ]
    },
    "cpe_matches": {
      "_type": "Set",
      "elements": [
        "cpe:2.3:o:amazon:amazon_linux:2023.0:*:*:*:*:*:*:*",
        "cpe:2.3:o:amazon:amazon_linux:2023.7:*:*:*:*:*:*:*",
        "cpe:2.3:o:amazon:amazon_linux:2023.8:*:*:*:*:*:*:*",
        "cpe:2.3:o:amazon:amazon_linux:2023.1:*:*:*:*:*:*:*",
        "cpe:2.3:o:amazon:amazon_linux:2023.2:*:*:*:*:*:*:*",
        "cpe:2.3:o:amazon:amazon_linux:2023.5:*:*:*:*:*:*:*",
        "cpe:2.3:o:amazon:amazon_linux:2023.4:*:*:*:*:*:*:*",
        "cpe:2.3:o:amazon:amazon_linux:2023.6:*:*:*:*:*:*:*",
        "cpe:2.3:o:amazon:amazon_linux:2023.3:*:*:*:*:*:*:*"
      ]
    },
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "2023"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": {
      "_type": "Set",
      "elements": [
        "CVE-2024-6387"
      ]
    },
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "br1_deviations": 0,
    "br1_tables": {
      "_type": "sec_certs.heuristics.br1.table_parsing.model.br1_tables.BR1Tables",
      "approved_algorithms": {
        "entries": [
          {
            "algorithm": "AES-CBC",
            "cavpCertName": "A4537",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CBC",
            "cavpCertName": "A4538",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CBC",
            "cavpCertName": "A4539",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CBC",
            "cavpCertName": "A4540",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CBC",
            "cavpCertName": "A4545",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CBC",
            "cavpCertName": "A4572",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CCM",
            "cavpCertName": "A4537",
            "properties": "Key Length - 128, 256",
            "reference": "SP 800-38C"
          },
          {
            "algorithm": "AES-CCM",
            "cavpCertName": "A4572",
            "properties": "Key Length - 128, 256",
            "reference": "SP 800-38C"
          },
          {
            "algorithm": "AES-CFB8",
            "cavpCertName": "A4542",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CFB8",
            "cavpCertName": "A4543",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CFB8",
            "cavpCertName": "A4548",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CMAC",
            "cavpCertName": "A4537",
            "properties": "Direction - Generation, Verification Key Length - 128, 256",
            "reference": "SP 800-38B"
          },
          {
            "algorithm": "AES-CMAC",
            "cavpCertName": "A4540",
            "properties": "Direction - Generation, Verification Key Length - 128, 256",
            "reference": "SP 800-38B"
          },
          {
            "algorithm": "AES-CMAC",
            "cavpCertName": "A4545",
            "properties": "Direction - Generation, Verification Key Length - 128, 256",
            "reference": "SP 800-38B"
          },
          {
            "algorithm": "AES-GCM",
            "cavpCertName": "A4537",
            "properties": "Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 256",
            "reference": "SP 800-38D"
          },
          {
            "algorithm": "AES-GCM",
            "cavpCertName": "A4538",
            "properties": "Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 256",
            "reference": "SP 800-38D"
          },
          {
            "algorithm": "AES-GCM",
            "cavpCertName": "A4539",
            "properties": "Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 256",
            "reference": "SP 800-38D"
          },
          {
            "algorithm": "AES-GCM",
            "cavpCertName": "A4540",
            "properties": "Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 256",
            "reference": "SP 800-38D"
          },
          {
            "algorithm": "AES-GCM",
            "cavpCertName": "A4545",
            "properties": "Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 256",
            "reference": "SP 800-38D"
          },
          {
            "algorithm": "AES-GCM",
            "cavpCertName": "A4572",
            "properties": "Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 256",
            "reference": "SP 800-38D"
          },
          {
            "algorithm": "AES-GMAC",
            "cavpCertName": "A4545",
            "properties": "Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 256",
            "reference": "SP 800-38D"
          },
          {
            "algorithm": "AES-XTS Testing Revision 2.0",
            "cavpCertName": "A4546",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 256",
            "reference": "SP 800-38E"
          },
          {
            "algorithm": "Counter DRBG",
            "cavpCertName": "A4545",
            "properties": "Prediction Resistance - No Mode - AES-256 Derivation Function Enabled - No",
            "reference": "SP 800-90A Rev. 1"
          },
          {
            "algorithm": "ECDSA KeyGen (FIPS186-4)",
            "cavpCertName": "A4545",
            "properties": "Curve - P-256, P-384, P-521 Secret Generation Mode - Testing Candidates",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA KeyVer (FIPS186-4)",
            "cavpCertName": "A4545",
            "properties": "Curve - P-256, P-384, P-521",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA SigGen (FIPS186-4)",
            "cavpCertName": "A4545",
            "properties": "Component - No Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA SigVer (FIPS186-4)",
            "cavpCertName": "A4545",
            "properties": "Component - No Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "HMAC-SHA-1",
            "cavpCertName": "A4540",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA-1",
            "cavpCertName": "A4545",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA-1",
            "cavpCertName": "A4572",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-224",
            "cavpCertName": "A4540",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-224",
            "cavpCertName": "A4545",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-224",
            "cavpCertName": "A4572",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-256",
            "cavpCertName": "A4540",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-256",
            "cavpCertName": "A4545",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-256",
            "cavpCertName": "A4572",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-384",
            "cavpCertName": "A4540",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-384",
            "cavpCertName": "A4545",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-384",
            "cavpCertName": "A4572",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-512",
            "cavpCertName": "A4540",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-512",
            "cavpCertName": "A4545",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-512",
            "cavpCertName": "A4572",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "KAS-ECC-SSC Sp800-56Ar3",
            "cavpCertName": "A4545",
            "properties": "Domain Parameter Generation Methods - P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responder",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "KAS-FFC-SSC Sp800-56Ar3",
            "cavpCertName": "A4545",
            "properties": "Domain Parameter Generation Methods - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192 Scheme - dhEphem - KAS Role - initiator, responder",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "KDA HKDF Sp800- 56Cr1",
            "cavpCertName": "A4544",
            "properties": "Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-65336 Increment 8 HMAC Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512",
            "reference": "SP 800-56C Rev. 2"
          },
          {
            "algorithm": "KDF TLS (CVL)",
            "cavpCertName": "A4545",
            "properties": "TLS Version - v1.0/1.1",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "PBKDF",
            "cavpCertName": "A4545",
            "properties": "Iteration Count - Iteration Count: 1000-10000 Increment 1 Password Length - Password Length: 8-128 Increment 1",
            "reference": "SP 800-132"
          },
          {
            "algorithm": "RSA KeyGen (FIPS186-4)",
            "cavpCertName": "A4545",
            "properties": "Key Generation Mode - B.3.2 Modulo - 2048, 3072, 4096 Hash Algorithm - SHA2-384 Primality Tests - Table C.2 Private Key Format - Standard",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "RSA SigGen (FIPS186-4)",
            "cavpCertName": "A4545",
            "properties": "Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "RSA SigVer (FIPS186-4)",
            "cavpCertName": "A4545",
            "properties": "Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "Safe Primes Key Generation",
            "cavpCertName": "A4545",
            "properties": "Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP- 2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "SHA-1",
            "cavpCertName": "A4540",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA-1",
            "cavpCertName": "A4545",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA-1",
            "cavpCertName": "A4572",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-224",
            "cavpCertName": "A4540",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-224",
            "cavpCertName": "A4545",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-224",
            "cavpCertName": "A4572",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-256",
            "cavpCertName": "A4540",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-256",
            "cavpCertName": "A4545",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-256",
            "cavpCertName": "A4572",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-384",
            "cavpCertName": "A4540",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-384",
            "cavpCertName": "A4545",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-384",
            "cavpCertName": "A4572",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512",
            "cavpCertName": "A4540",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512",
            "cavpCertName": "A4545",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512",
            "cavpCertName": "A4572",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA3-224",
            "cavpCertName": "A4541",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3-224",
            "cavpCertName": "A4547",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3-256",
            "cavpCertName": "A4541",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3-256",
            "cavpCertName": "A4547",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3-384",
            "cavpCertName": "A4541",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3-384",
            "cavpCertName": "A4547",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3-512",
            "cavpCertName": "A4541",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3-512",
            "cavpCertName": "A4547",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "TLS v1.2 KDF RFC7627 (CVL)",
            "cavpCertName": "A4545",
            "properties": "Hash Algorithm - SHA2-256, SHA2-384",
            "reference": "SP 800-135 Rev. 1"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "approved_services": {
        "entries": [
          {
            "description": "Generate AES or HMAC key",
            "indicator": "GNUTLS_FIPS140_OP_APPROVED",
            "inputs": "Key size",
            "name": "Symmetric Key Generation",
            "outputs": "Key",
            "rolesSspAccess": "Crypto Officer - Module- generated AES Key: G - Module- generated HMAC Key: G",
            "secFunImpl": "Symmetric Key Generation with Counter DRBG"
          },
          {
            "description": "Perform AES encryption",
            "indicator": "GNUTLS_FIPS140_OP_APPROVED",
            "inputs": "Key, IV (for AEAD), Plaintext",
            "name": "Symmetric Encryption",
            "outputs": "Ciphertext",
            "rolesSspAccess": "Crypto Officer - AES Key: W,E",
            "secFunImpl": "Symmetric Encryption with AES Authenticated Symmetric Encryption with AES"
          },
          {
            "description": "Perform AES decryption",
            "indicator": "GNUTLS_FIPS140_OP_APPROVED",
            "inputs": "Key, IV (for AEAD), Ciphertext",
            "name": "Symmetric Decryption",
            "outputs": "Plaintext",
            "rolesSspAccess": "Crypto Officer - AES Key: W,E",
            "secFunImpl": "Symmetric Decryption with AES Authenticated Symmetric Decryption with AES"
          },
          {
            "description": "Generate RSA or ECDSA key pairs",
            "indicator": "GNUTLS_FIPS140_OP_APPROVED",
            "inputs": "RSA key size or Elliptic Curve",
            "name": "Asymmetric Key Generation",
            "outputs": "Key pair",
            "rolesSspAccess": "Crypto Officer - Module- generated RSA Public Key: G,R - Module- generated",
            "secFunImpl": "Key Pair Generation with RSA Key Pair Generation with ECDSA"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "RSA Private Key: G,R - Module- generated ECDSA Public Key: G,R - Module- generated ECDSA Private Key: G,R - Module- generated EC Diffie- Hellman Public Key: G,R - Module- generated EC Diffie- Hellman Private Key: G,R - Intermediate Key Generation",
            "secFunImpl": ""
          },
          {
            "description": "Perform DH key agreement with safe primes",
            "indicator": "GNUTLS_FIPS140_OP_APPROVED",
            "inputs": "Key size",
            "name": "Diffie-Hellman Key Generation using Safe Primes",
            "outputs": "Key pair",
            "rolesSspAccess": "Crypto Officer - Module- generated Diffie- Hellman Public Key: G - Module- generated Diffie- Hellman Private Key: G - Intermediate Key Generation Value: G,E",
            "secFunImpl": "Key Pair Generation with Safe Primes"
          },
          {
            "description": "Generate a digital signature",
            "indicator": "GNUTLS_FIPS140_OP_APPROVED",
            "inputs": "Message, hash algorithm, private key",
            "name": "ECDSA Digital Signature Generation",
            "outputs": "Digital signature",
            "rolesSspAccess": "Crypto Officer - ECDSA Private Key: W,E",
            "secFunImpl": "Digital Signature Generation with ECDSA"
          },
          {
            "description": "Generate a digital signature",
            "indicator": "GNUTLS_FIPS140_OP_APPROVED",
            "inputs": "Message, hash algorithm, private key",
            "name": "RSA Digital Signature Generation",
            "outputs": "Digital signature",
            "rolesSspAccess": "Crypto Officer - RSA Private Key: W,E",
            "secFunImpl": "Digital Signature Generation with RSA"
          },
          {
            "description": "Verify a digital signature",
            "indicator": "GNUTLS_FIPS140_OP_APPROVED",
            "inputs": "Digital signature, hash algorithm, public key",
            "name": "ECDSA Digital Signature Verification",
            "outputs": "Verification result",
            "rolesSspAccess": "Crypto Officer - ECDSA Public Key: W,E",
            "secFunImpl": "Digital Signature Verification with ECDSA"
          },
          {
            "description": "Verify a digital signature",
            "indicator": "GNUTLS_FIPS140_OP_APPROVED",
            "inputs": "Digital signature, hash algorithm, public key",
            "name": "RSA Digital Signature Verification",
            "outputs": "Verification result",
            "rolesSspAccess": "Crypto Officer - RSA Public Key: W,E",
            "secFunImpl": "Digital Signature Verification with RSA"
          },
          {
            "description": "Verify ECDSA public key",
            "indicator": "GNUTLS_FIPS140_OP_APPROVED",
            "inputs": "Key",
            "name": "Public Key Verification",
            "outputs": "Return codes/log messages",
            "rolesSspAccess": "Crypto Officer - ECDSA Public Key: W,E",
            "secFunImpl": "Public Key Verification with ECDSA"
          },
          {
            "description": "Generate random bit strings",
            "indicator": "GNUTLS_FIPS140_OP_APPROVED",
            "inputs": "Number of bits",
            "name": "Random Number Generation",
            "outputs": "Random number",
            "rolesSspAccess": "Crypto Officer - Entropy Input: W,E - Counter DRBG Seed: G,E - Counter DRBG Internal State: V Value, Key: G,E",
            "secFunImpl": "Random Number Generation with Counter DRBG"
          },
          {
            "description": "Compute SHA hashes",
            "indicator": "GNUTLS_FIPS140_OP_APPROVED",
            "inputs": "Message",
            "name": "Message Digest",
            "outputs": "Digest of the message",
            "rolesSspAccess": "Crypto Officer",
            "secFunImpl": "Message Digest with SHA"
          },
          {
            "description": "Compute HMAC",
            "indicator": "GNUTLS_FIPS140_OP_APPROVED",
            "inputs": "Message, HMAC key",
            "name": "HMAC Message Authentication Code (MAC)",
            "outputs": "Message authentication code (MAC)",
            "rolesSspAccess": "Crypto Officer - HMAC Key: W,E",
            "secFunImpl": "Message Authentication Code with HMAC"
          },
          {
            "description": "Compute AES-based CMAC or AES-based GMAC",
            "indicator": "GNUTLS_FIPS140_OP_APPROVED",
            "inputs": "Message, AES key",
            "name": "AES Message Authentication Code (MAC)",
            "outputs": "Message authentication code (MAC)",
            "rolesSspAccess": "Crypto Officer - AES Key: W,E",
            "secFunImpl": "Message Authentication Code with AES"
          },
          {
            "description": "Perform DH shared secret computation",
            "indicator": "GNUTLS_FIPS140_OP_APPROVED",
            "inputs": "DH private key, DH public key from peer",
            "name": "Diffie-Hellman Shared Secret Computation",
            "outputs": "Shared secret",
            "rolesSspAccess": "Crypto Officer - Diffie- Hellman Public Key: W,E - Diffie- Hellman",
            "secFunImpl": "Shared Secret Computation with KAS-FFC- SSC"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "Private Key: W,E",
            "secFunImpl": ""
          },
          {
            "description": "Perform ECDH shared secret computation",
            "indicator": "GNUTLS_FIPS140_OP_APPROVED",
            "inputs": "EC private key, EC public key from peer",
            "name": "EC Diffie- Hellman Shared Secret Computation",
            "outputs": "Shared secret",
            "rolesSspAccess": "Crypto Officer - EC Diffie- Hellman Public Key: W,E - EC Diffie- Hellman Private Key: W,E",
            "secFunImpl": "Shared Secret Computation with KAS- ECC-SSC"
          },
          {
            "description": "Perform key derivation",
            "indicator": "GNUTLS_FIPS140_OP_APPROVED",
            "inputs": "TLS pre-master secret",
            "name": "TLS KDF and HKDF Key Derivation (derivation of TLS Master Secret)",
            "outputs": "TLS master secret",
            "rolesSspAccess": "Crypto Officer - TLS Pre- master Secret: W,E - TLS Master Secret: G,R",
            "secFunImpl": "Key Derivation with TLS KDF Key Derivation with KDA HKDF"
          },
          {
            "description": "Perform key derivation",
            "indicator": "GNUTLS_FIPS140_OP_APPROVED",
            "inputs": "TLS master secret",
            "name": "TLS KDF and HKDF Key Derivation (derivation of TLS Derived Secret)",
            "outputs": "TLS Derived Secret",
            "rolesSspAccess": "Crypto Officer - TLS Master Secret: W,E - TLS Derived Secret: G,R",
            "secFunImpl": "Key Derivation with TLS KDF Key Derivation with KDA HKDF"
          },
          {
            "description": "Perform password- based key derivation",
            "indicator": "GNUTLS_FIPS140_OP_APPROVED",
            "inputs": "Password/passphrase",
            "name": "PBKDF Key Derivation",
            "outputs": "PBKDF Derived key",
            "rolesSspAccess": "Crypto Officer - PBKDF Password or Passphrase: W,E,Z - PBKDF Derived Key: G,R",
            "secFunImpl": "Key Derivation with PBKDF"
          },
          {
            "description": "Provide supported cipher suites (listed in Appendix A) in approved mode",
            "indicator": "GNUTLS_FIPS140_OP_APPROVED",
            "inputs": "Cipher-suites listed in Appendix A, Digital Certificate, Public and Private Keys, Application Data",
            "name": "Transport Layer Security (TLS) Network Protocol",
            "outputs": "Return codes and/or log messages, Application data",
            "rolesSspAccess": "Crypto Officer - AES Key: W,E - HMAC Key: W,E - RSA Public Key: W,E - RSA Private Key: W,E - ECDSA Public Key: W,E - ECDSA Private Key: W,E - Module- generated Diffie-",
            "secFunImpl": "Symmetric Encryption with AES Symmetric Decryption with AES Authenticated Symmetric Encryption with AES Authenticated Symmetric Decryption with AES Message Authentication Code with HMAC Message Digest"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "Hellman Public Key: G,E - Module- generated Diffie- Hellman Private Key: G,E - Module- generated EC Diffie- Hellman Public Key: G,E - TLS Pre- master Secret: G,E - TLS Master Secret: G,E - TLS Derived Secret: G,R - Intermediate Key Generation Value: G,E",
            "secFunImpl": "with SHA Digital Signature Generation with RSA Digital Signature Generation with ECDSA Digital Signature Verification with RSA Digital Signature Verification with ECDSA Key Pair Generation with Safe Primes Public Key Verification with ECDSA TLS Handshake"
          },
          {
            "description": "Show module status",
            "indicator": "N/A",
            "inputs": "N/A",
            "name": "Show Status",
            "outputs": "Return codes and/or log messages",
            "rolesSspAccess": "Crypto Officer",
            "secFunImpl": "None"
          },
          {
            "description": "Zeroize SSPs",
            "indicator": "N/A",
            "inputs": "Context containing SSPs",
            "name": "Zeroization",
            "outputs": "N/A",
            "rolesSspAccess": "Crypto Officer - Module- generated AES Key: Z - AES Key: Z - Module- generated HMAC Key: Z - HMAC Key: Z - Module- generated RSA Public Key: Z - Module- generated RSA Private Key: Z - RSA Public Key: Z - RSA Private Key: Z - Module-",
            "secFunImpl": "None"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "generated ECDSA Public Key: Z - Module- generated ECDSA Private Key: Z - ECDSA Public Key: Z - ECDSA Private Key: Z - Module- generated Diffie- Hellman Public Key: Z - Module- generated Diffie- Hellman Private Key: Z - Diffie- Hellman Public Key: Z - Diffie- Hellman Private Key: Z - Module- generated EC Diffie- Hellman Public Key: Z - Module- generated EC Diffie- Hellman Private Key: Z - EC Diffie- Hellman Public Key: Z - EC Diffie- Hellman Private Key: Z - (Diffie- Hellman) Shared Secret: Z - (EC Diffie- Hellman) Shared Secret: Z",
            "secFunImpl": ""
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "- PBKDF Password or Passphrase: Z - PBKDF Derived Key: Z - Entropy Input: Z - Counter DRBG Seed: Z - Counter DRBG Internal State: V Value, Key: Z - TLS Pre- master Secret: Z - TLS Master Secret: Z - TLS Derived Secret: Z - Intermediate Key Generation Value: Z",
            "secFunImpl": ""
          },
          {
            "description": "Perform self- tests",
            "indicator": "N/A",
            "inputs": "Module reset",
            "name": "Self-tests",
            "outputs": "Result of self- test (pass/fail)",
            "rolesSspAccess": "Crypto Officer",
            "secFunImpl": "Symmetric Encryption with AES Symmetric Decryption with AES Authenticated Symmetric Encryption with AES Authenticated Symmetric Decryption with AES Message Authentication Code with AES Message Authentication Code with HMAC Message Digest with SHA Key Derivation with TLS KDF Key Derivation with KDA"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "",
            "secFunImpl": "HKDF Key Derivation with PBKDF Digital Signature Generation with RSA Digital Signature Generation with ECDSA Digital Signature Verification with RSA Digital Signature Verification with ECDSA Key Pair Generation with RSA Key Pair Generation with ECDSA Key Pair Generation with Safe Primes Public Key Verification with ECDSA Shared Secret Computation with KAS- ECC-SSC Shared Secret Computation with KAS-FFC- SSC Random Number Generation with Counter DRBG Key Wrapping with AES Key Unwrapping with AES Key Wrapping with AES and HMAC Key Unwrapping with AES and HMAC"
          },
          {
            "description": "Show module name and version",
            "indicator": "N/A",
            "inputs": "None",
            "name": "Show Module Name and Version",
            "outputs": "Name and version information",
            "rolesSspAccess": "Crypto Officer",
            "secFunImpl": "None"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 3
      },
      "authentication_methods": {
        "entries": [],
        "found": false,
        "section": 4,
        "subsection": 1
      },
      "cond_self_tests": {
        "entries": [
          {
            "algorithmOrTest": "AES-CBC (A4537)",
            "condition": "Module initialization",
            "details": "Encryption",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "Encrypt KAT",
            "testProps": "256-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-CBC (A4537)",
            "condition": "Module initialization",
            "details": "Decryption",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "Decrypt KAT",
            "testProps": "256-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-CFB8 (A4542)",
            "condition": "Module initialization",
            "details": "Encryption",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "Encrypt KAT",
            "testProps": "256-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-CFB8 (A4542)",
            "condition": "Module initialization",
            "details": "Decryption",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "Decrypt KAT",
            "testProps": "256-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A4537)",
            "condition": "Module initialization",
            "details": "Encryption",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "Encrypt KAT",
            "testProps": "256-bit key, 96-bit IV",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A4537)",
            "condition": "Module initialization",
            "details": "Decryption",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "Decrypt KAT",
            "testProps": "256-bit key, 96-bit IV",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-XTS Testing Revision 2.0 (A4546)",
            "condition": "Module initialization",
            "details": "Encryption",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "Encrypt KAT",
            "testProps": "256-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-XTS Testing Revision 2.0 (A4546)",
            "condition": "Module initialization",
            "details": "Decryption",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "Decrypt KAT",
            "testProps": "256-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS-FFC-SSC Sp800-56Ar3 (A4545)",
            "condition": "Module initialization",
            "details": "Shared secret computation",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "Primitive \u0027Z\u0027 Computation KAT",
            "testProps": "ffdhe3072",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS-ECC-SSC Sp800-56Ar3 (A4545)",
            "condition": "Module initialization",
            "details": "Shared secret computation",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "Primitive \u0027Z\u0027 Computation KAT",
            "testProps": "P-256 curve",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "Counter DRBG (A4545)",
            "condition": "Module initialization",
            "details": "KAT CTR_DRBG with AES with 256-bit keys without DF, without PR",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "KAT CTR_DRBG with AES without DF, without PR",
            "testProps": "256-bit keys",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "Counter DRBG (A4545)",
            "condition": "Module initialization",
            "details": "Health tests",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "Health tests according to section 11.3 of [SP800- 90Ar1]",
            "testProps": "Health tests",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigGen (FIPS186-4) (A4545)",
            "condition": "Module initialization",
            "details": "Signature generation",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "KAT with P-256 using SHA2-256",
            "testProps": "P-256 with SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigVer (FIPS186-4) (A4545)",
            "condition": "Module initialization",
            "details": "Signature verification",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "KAT with P-256 using SHA2-256",
            "testProps": "P-256 with SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigGen (FIPS186-4) (A4545)",
            "condition": "Module initialization",
            "details": "Signature generation",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "KAT with 2048-bit key using SHA2-256",
            "testProps": "2048-bit key with SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186-4) (A4545)",
            "condition": "Module initialization",
            "details": "Signature verification",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "KAT with 2048-bit key using SHA2-256",
            "testProps": "2048-bit key with SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDA HKDF Sp800-56Cr1 (A4544)",
            "condition": "Module initialization",
            "details": "Key derivation",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "KAT with HMAC- SHA2-256",
            "testProps": "HMAC-SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF TLS (A4545)",
            "condition": "Module initialization",
            "details": "Key derivation",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "KAT with HMAC- SHA2-256",
            "testProps": "HMAC-SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "PBKDF (A4545)",
            "condition": "Module initialization",
            "details": "Key derivation",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "KAT with HMAC- SHA2-256",
            "testProps": "HMAC-SHA2-256; password length: 24 bytes; salt length: 288 bits, iteration count: 4096",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA-1 (A4540)",
            "condition": "Module initialization",
            "details": "Message Authentication Code (MAC)",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "HMAC-SHA-1 KAT",
            "testProps": "HMAC-SHA-1",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA2- 224 (A4540)",
            "condition": "Module initialization",
            "details": "Message Authentication Code (MAC)",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "HMAC-SHA2-224 KAT",
            "testProps": "HMAC-SHA2-224",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA2- 256 (A4540)",
            "condition": "Module initialization",
            "details": "Message Authentication Code (MAC)",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "HMAC-SHA2-256 KAT",
            "testProps": "HMAC-SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA2- 384 (A4540)",
            "condition": "Module initialization",
            "details": "Message Authentication Code (MAC)",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "HMAC-SHA2-384 KAT",
            "testProps": "HMAC-SHA2-384",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA2- 512 (A4540)",
            "condition": "Module initialization",
            "details": "Message Authentication Code (MAC)",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "HMAC-SHA2-512 KAT",
            "testProps": "HMAC-SHA2-512",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA3-224 (A4541)",
            "condition": "Module initialization",
            "details": "Message digest",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "SHA3-224 KAT",
            "testProps": "SHA3-224",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA3-256 (A4541)",
            "condition": "Module initialization",
            "details": "Message digest",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "SHA3-256 KAT",
            "testProps": "SHA3-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA3-384 (A4541)",
            "condition": "Module initialization",
            "details": "Message digest",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "SHA3-384 KAT",
            "testProps": "SHA3-384",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA3-512 (A4541)",
            "condition": "Module initialization",
            "details": "Message digest",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "SHA3-512 KAT",
            "testProps": "SHA3-512",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA KeyGen (FIPS186-4) (A4545)",
            "condition": "Key pair generation service request",
            "details": "Signature generation and verification",
            "indicator": "Successful key generation",
            "testMethod": "Signature generation and verification",
            "testProps": "SHA2-256 with the respective curve",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "RSA KeyGen (FIPS186-4) (A4545)",
            "condition": "Key pair generation service request",
            "details": "Signature generation and verification",
            "indicator": "Successful key generation",
            "testMethod": "Signature generation and verification",
            "testProps": "SHA2-256 with the respective key",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "Safe Primes Key Generation (A4545)",
            "condition": "Key pair generation service request",
            "details": "PCT according to section 5.6.2.1.4 of [SP800-56Ar3]",
            "indicator": "Successful key generation",
            "testMethod": "PCT according to section 5.6.2.1.4 of [SP800-56Ar3]",
            "testProps": "N/A",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "ECDSA KeyGen (FIPS186-4) (A4545)",
            "condition": "Key pair generation service request",
            "details": "Signature generation and verification PCT that covers key pair generation for EC Diffie-Hellman",
            "indicator": "Successful key generation",
            "testMethod": "Signature generation and verification",
            "testProps": "SHA2-256 with the respective curve",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "AES-CBC (A4538)",
            "condition": "Module initialization",
            "details": "Encryption",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "Encrypt KAT",
            "testProps": "256-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-CBC (A4538)",
            "condition": "Module initialization",
            "details": "Decryption",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "Decrypt KAT",
            "testProps": "256-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-CBC (A4539)",
            "condition": "Module initialization",
            "details": "Encryption",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "Encrypt KAT",
            "testProps": "256-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-CBC (A4539)",
            "condition": "Module initialization",
            "details": "Decryption",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "Decrypt KAT",
            "testProps": "256-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-CBC (A4540)",
            "condition": "Module initialization",
            "details": "Encryption",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "Encrypt KAT",
            "testProps": "256-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-CBC (A4540)",
            "condition": "Module initialization",
            "details": "Decryption",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "Decrypt KAT",
            "testProps": "256-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-CBC (A4545)",
            "condition": "Module initialization",
            "details": "Encryption",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "Encrypt KAT",
            "testProps": "256-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-CBC (A4545)",
            "condition": "Module initialization",
            "details": "Decryption",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "Decrypt KAT",
            "testProps": "256-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-CBC (A4572)",
            "condition": "Module initialization",
            "details": "Encryption",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "Encrypt KAT",
            "testProps": "256-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-CBC (A4572)",
            "condition": "Module initialization",
            "details": "Decryption",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "Decrypt KAT",
            "testProps": "256-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-CFB8 (A4548)",
            "condition": "Module initialization",
            "details": "Encryption",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "Encrypt KAT",
            "testProps": "256-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-CFB8 (A4548)",
            "condition": "Module initialization",
            "details": "Decryption",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "Decrypt KAT",
            "testProps": "256-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-CFB8 (A4543)",
            "condition": "Module initialization",
            "details": "Encryption",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "Encrypt KAT",
            "testProps": "256-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-CFB8 (A4543)",
            "condition": "Module initialization",
            "details": "Decryption",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "Decrypt KAT",
            "testProps": "256-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A4538)",
            "condition": "Module initialization",
            "details": "Encryption",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "Encrypt KAT",
            "testProps": "256-bit key, 96-bit IV",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A4538)",
            "condition": "Module initialization",
            "details": "Decryption",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "Decrypt KAT",
            "testProps": "256-bit key, 96-bit IV",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A4539)",
            "condition": "Module initialization",
            "details": "Encryption",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "Encrypt KAT",
            "testProps": "256-bit key, 96-bit IV",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A4539)",
            "condition": "Module initialization",
            "details": "Decryption",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "Decrypt KAT",
            "testProps": "256-bit key, 96-bit IV",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A4540)",
            "condition": "Module initialization",
            "details": "Encryption",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "Encrypt KAT",
            "testProps": "256-bit key, 96-bit IV",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A4540)",
            "condition": "Module initialization",
            "details": "Decryption",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "Decrypt KAT",
            "testProps": "256-bit key, 96-bit IV",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A4545)",
            "condition": "Module initialization",
            "details": "Encryption",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "Encrypt KAT",
            "testProps": "256-bit key, 96-bit IV",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A4545)",
            "condition": "Module initialization",
            "details": "Decryption",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "Decrypt KAT",
            "testProps": "256-bit key, 96-bit IV",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A4572)",
            "condition": "Module initialization",
            "details": "Encryption",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "Encrypt KAT",
            "testProps": "256-bit key, 96-bit IV",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A4572)",
            "condition": "Module initialization",
            "details": "Decryption",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "Decrypt KAT",
            "testProps": "256-bit key, 96-bit IV",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA-1 (A4545)",
            "condition": "Module initialization",
            "details": "Message Authentication Code (MAC)",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "HMAC-SHA-1 KAT",
            "testProps": "HMAC-SHA-1",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA-1 (A4572)",
            "condition": "Module initialization",
            "details": "Message Authentication Code (MAC)",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "HMAC-SHA-1 KAT",
            "testProps": "HMAC-SHA-1",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA2- 224 (A4545)",
            "condition": "Module initialization",
            "details": "Message Authentication Code (MAC)",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "HMAC-SHA2-224 KAT",
            "testProps": "HMAC-SHA2-224",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA2- 224 (A4572)",
            "condition": "Module initialization",
            "details": "Message Authentication Code (MAC)",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "HMAC-SHA2-224 KAT",
            "testProps": "HMAC-SHA2-224",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA2- 256 (A4545)",
            "condition": "Module initialization",
            "details": "Message Authentication Code (MAC)",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "HMAC-SHA2-256 KAT",
            "testProps": "HMAC-SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA2- 256 (A4572)",
            "condition": "Module initialization",
            "details": "Message Authentication Code (MAC)",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "HMAC-SHA2-256 KAT",
            "testProps": "HMAC-SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA2- 512 (A4545)",
            "condition": "Module initialization",
            "details": "Message Authentication Code (MAC)",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "HMAC-SHA2-512 KAT",
            "testProps": "HMAC-SHA2-512",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA2- 512 (A4572)",
            "condition": "Module initialization",
            "details": "Message Authentication Code (MAC)",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "HMAC-SHA2-512 KAT",
            "testProps": "HMAC-SHA2-512",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA3-224 (A4547)",
            "condition": "Module initialization",
            "details": "Message digest",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "SHA3-224 KAT",
            "testProps": "SHA3-224",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA3-256 (A4547)",
            "condition": "Module initialization",
            "details": "Message digest",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "SHA3-256 KAT",
            "testProps": "SHA3-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA3-384 (A4547)",
            "condition": "Module initialization",
            "details": "Message digest",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "SHA3-384 KAT",
            "testProps": "SHA3-384",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA3-512 (A4547)",
            "condition": "Module initialization",
            "details": "Message digest",
            "indicator": "Module is operational and services are available for use",
            "testMethod": "SHA3-512 KAT",
            "testProps": "SHA3-512",
            "type": "CAST"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 2
      },
      "error_states": {
        "entries": [
          {
            "conditions": "When the integrity test or KAT fail When the KAT of DRBG fails during CASTs When the newly generated RSA, ECDSA, Diffie-Hellman or EC Diffie-Hellman key pair fails the PCT",
            "description": "The module stops functioning and ends the application process",
            "indicator": "GNUTLS_E_SELF_TEST_ERROR (-400); GNUTLS_E_RANDOM_FAILED (-206); GNUTLS_E_PK_GENERATION_ERROR (-403)",
            "name": "Error State",
            "recoveryMethod": "The module must be restarted and perform the pre-operational self-test and the CASTs to recover from these errors."
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 4
      },
      "mechanisms_actions": {
        "entries": [],
        "found": false,
        "section": 7,
        "subsection": 1
      },
      "modes_of_operation": {
        "entries": [
          {
            "description": "Entered by default, after passing the pre-operational and all conditional cryptographic algorithms self-tests (CASTs). Also, automatically entered whenever an approved service is requested",
            "name": "Approved mode of operation",
            "statusIndicator": "Equivalent to the indicator of the requested service as defined in section 4.3",
            "type": "Approved"
          },
          {
            "description": "Automatically entered whenever a non-approved service is requested",
            "name": "Non-approved mode of operation",
            "statusIndicator": "Equivalent to the indicator of the requested service as defined in section 4.4",
            "type": "Non- Approved"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 4
      },
      "non_approved_allowed_NSC": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_allowed_algos": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_not_allowed": {
        "entries": [
          {
            "name": "Blowfish",
            "use": "Symmetric Encryption; Symmetric Decryption"
          },
          {
            "name": "Camellia",
            "use": "Symmetric Encryption; Symmetric Decryption"
          },
          {
            "name": "CAST",
            "use": "Symmetric Encryption; Symmetric Decryption"
          },
          {
            "name": "Chacha20 and Poly1305",
            "use": "Authenticated Encryption; Authenticated Decryption"
          },
          {
            "name": "CMAC with Triple-DES",
            "use": "Message Authentication Code (MAC)"
          },
          {
            "name": "DES",
            "use": "Symmetric Encryption; Symmetric Decryption"
          },
          {
            "name": "Diffie-Hellman with keys generated with domain parameters other than safe primes",
            "use": "Key Agreement; Shared Secret Computation"
          },
          {
            "name": "DSA",
            "use": "Key Generation; Domain Parameter Generation; Digital Signature Generation; Digital Signature Verification"
          },
          {
            "name": "ECDSA with curves not listed in the Approved Algorithms table",
            "use": "Key Generation; Public Key Verification"
          },
          {
            "name": "ECDSA with curves/hash functions not listed in the Approved Algorithms table",
            "use": "Digital Signature Generation; Digital Signature Verification"
          },
          {
            "name": "EC Diffie-Hellman with curves not listed in the Approved Algorithms table",
            "use": "Key Agreement; Shared Secret Computation"
          },
          {
            "name": "GOST",
            "use": "Symmetric Encryption; Symmetric Decryption; Message Digest"
          },
          {
            "name": "HMAC with keys smaller than 112-bit",
            "use": "Message Authentication Code (MAC)"
          },
          {
            "name": "HMAC with GOST",
            "use": "Message Authentication Code (MAC)"
          },
          {
            "name": "MD2, MD4, MD5",
            "use": "Message Digest; Message Authentication Code (MAC)"
          },
          {
            "name": "PBKDF with HMAC not listed in the Approved Algorithms table or using input parameters not meeting requirements stated in section 2.7",
            "use": "Key Derivation"
          },
          {
            "name": "RC2, RC4",
            "use": "Symmetric Encryption; Symmetric Decryption"
          },
          {
            "name": "RMD160",
            "use": "Message Digest; Message Authentication Code (MAC)"
          },
          {
            "name": "RSA with keys smaller than 2048 bits or greater than 4096 bits.",
            "use": "Key Generation"
          },
          {
            "name": "RSA with keys smaller than 2048 bits or greater than 4096 bits and/or hash functions not listed in the Approved Algorithms table",
            "use": "Digital Signature Generation"
          },
          {
            "name": "RSA with keys smaller than 2048 bits or greater than 4096 bits and/or hash functions not listed in the Approved Algorithms table",
            "use": "Digital Signature Verification"
          },
          {
            "name": "Salsa20",
            "use": "Symmetric Encryption; Symmetric Decryption"
          },
          {
            "name": "SEED",
            "use": "Symmetric Encryption; Symmetric Decryption"
          },
          {
            "name": "Serpent",
            "use": "Symmetric Encryption; Symmetric Decryption"
          },
          {
            "name": "SRP",
            "use": "Key Agreement"
          },
          {
            "name": "STREEBOG",
            "use": "Message Digest; Message Authentication Code (MAC)"
          },
          {
            "name": "Triple-DES",
            "use": "Symmetric Encryption; Symmetric Decryption"
          },
          {
            "name": "Twofish",
            "use": "Symmetric Encryption; Symmetric Decryption"
          },
          {
            "name": "UMAC",
            "use": "Message Authentication Code (MAC)"
          },
          {
            "name": "Yarrow",
            "use": "Random Number Generation"
          },
          {
            "name": "DRBG when key length is less than 112 bits",
            "use": "Random Number Generation"
          },
          {
            "name": "RSA",
            "use": "Key Encapsulation; Key Un-encapsulation"
          },
          {
            "name": "Non-supported cipher suites (not listed in Appendix A)",
            "use": "Transport Layer Security (TLS) Network Protocol"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "non_approved_services": {
        "entries": [
          {
            "alg_accessed": "DRBG when key length is less than 112 bits",
            "description": "Generate symmetric key other than AES and HMAC keys",
            "name": "Symmetric Key Generation",
            "role": "Crypto Officer"
          },
          {
            "alg_accessed": "Blowfish Camellia CAST Chacha20 and Poly1305 DES GOST RC2, RC4 Salsa20 SEED Serpent Triple-DES Twofish",
            "description": "Compute the cipher for encryption",
            "name": "Symmetric Encryption",
            "role": "Crypto Officer"
          },
          {
            "alg_accessed": "Blowfish Camellia CAST Chacha20 and Poly1305 DES GOST RC2, RC4 Salsa20 SEED Serpent",
            "description": "Compute the plaintext for decryption",
            "name": "Symmetric Decryption",
            "role": "Crypto Officer"
          },
          {
            "alg_accessed": "Triple-DES Twofish",
            "description": "",
            "name": "",
            "role": ""
          },
          {
            "alg_accessed": "DSA ECDSA with curves not listed in the Approved Algorithms table RSA with keys smaller than 2048 bits or greater than 4096 bits.",
            "description": "Generate key pairs",
            "name": "Asymmetric Key Generation",
            "role": "Crypto Officer"
          },
          {
            "alg_accessed": "DSA ECDSA with curves/hash functions not listed in the Approved Algorithms table RSA with keys smaller than 2048 bits or greater than 4096 bits and/or hash functions not listed in the Approved Algorithms table",
            "description": "Sign RSA, DSA, and ECDSA signatures",
            "name": "Digital Signature Generation",
            "role": "Crypto Officer"
          },
          {
            "alg_accessed": "DSA ECDSA with curves/hash functions not listed in the Approved Algorithms table RSA with keys smaller than 2048 bits or greater than 4096 bits and/or hash functions not listed in the Approved Algorithms table",
            "description": "Verify RSA, DSA, and ECDSA signatures",
            "name": "Digital Signature Verification",
            "role": "Crypto Officer"
          },
          {
            "alg_accessed": "GOST MD2, MD4, MD5 RMD160 STREEBOG",
            "description": "Compute message digest",
            "name": "Message Digest",
            "role": "Crypto Officer"
          },
          {
            "alg_accessed": "CMAC with Triple-DES HMAC with keys smaller than 112-bit HMAC with GOST RMD160 UMAC",
            "description": "Compute HMAC or CMAC",
            "name": "Message Authentication Code (MAC)",
            "role": "Crypto Officer"
          },
          {
            "alg_accessed": "RSA",
            "description": "Perform RSA key encapsulation",
            "name": "Key Encapsulation",
            "role": "Crypto Officer"
          },
          {
            "alg_accessed": "RSA",
            "description": "Perform RSA key un- encapsulation",
            "name": "Key Un-encapsulation",
            "role": "Crypto Officer"
          },
          {
            "alg_accessed": "Diffie-Hellman with keys generated with domain parameters other than safe primes",
            "description": "Perform DH shared secret computation",
            "name": "Diffie-Hellman Shared Secret Computation",
            "role": "Crypto Officer"
          },
          {
            "alg_accessed": "EC Diffie-Hellman with curves not listed in the Approved Algorithms table",
            "description": "Perform ECDH shared secret computation",
            "name": "EC Diffie-Hellman Shared Secret Computation",
            "role": "Crypto Officer"
          },
          {
            "alg_accessed": "PBKDF with HMAC not listed in the Approved Algorithms table or using input parameters not meeting requirements stated in section 2.7",
            "description": "Perform key derivation",
            "name": "Key Derivation",
            "role": "Crypto Officer"
          },
          {
            "alg_accessed": "Non-supported cipher suites (not listed in Appendix A)",
            "description": "Provide non-supported cipher suites",
            "name": "Transport Layer Security (TLS) Network Protocol",
            "role": "Crypto Officer"
          },
          {
            "alg_accessed": "Yarrow",
            "description": "Generate random numbers",
            "name": "Random Number Generation",
            "role": "Crypto Officer"
          },
          {
            "alg_accessed": "Diffie-Hellman with keys generated with domain parameters other than safe primes EC Diffie-Hellman with curves not listed in the Approved Algorithms table SRP",
            "description": "Perform key agreement",
            "name": "Key Agreement",
            "role": "Crypto Officer"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 4
      },
      "ports_interfaces": {
        "entries": [
          {
            "data": "API input parameters",
            "logicalInterface": "Data Input",
            "physicalPort": "N/A"
          },
          {
            "data": "API output parameters",
            "logicalInterface": "Data Output",
            "physicalPort": "N/A"
          },
          {
            "data": "API function calls, API input parameters for control",
            "logicalInterface": "Control Input",
            "physicalPort": "N/A"
          },
          {
            "data": "API return codes",
            "logicalInterface": "Status Output",
            "physicalPort": "N/A"
          }
        ],
        "found": true,
        "section": 3,
        "subsection": 1
      },
      "roles": {
        "entries": [
          {
            "authMethodList": "None",
            "name": "Crypto Officer",
            "operatorType": "CO",
            "type": "Role"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 2
      },
      "security_levels": {
        "entries": [
          {
            "level": "1",
            "section": "1",
            "title": "General"
          },
          {
            "level": "1",
            "section": "2",
            "title": "Cryptographic module specification"
          },
          {
            "level": "1",
            "section": "3",
            "title": "Cryptographic module interfaces"
          },
          {
            "level": "1",
            "section": "4",
            "title": "Roles, services, and authentication"
          },
          {
            "level": "1",
            "section": "5",
            "title": "Software/Firmware security"
          },
          {
            "level": "1",
            "section": "6",
            "title": "Operational environment"
          },
          {
            "level": "N/A",
            "section": "7",
            "title": "Physical security"
          },
          {
            "level": "N/A",
            "section": "8",
            "title": "Non-invasive security"
          },
          {
            "level": "1",
            "section": "9",
            "title": "Sensitive security parameter management"
          },
          {
            "level": "1",
            "section": "10",
            "title": "Self-tests"
          },
          {
            "level": "1",
            "section": "11",
            "title": "Life-cycle assurance"
          },
          {
            "level": "N/A",
            "section": "12",
            "title": "Mitigation of other attacks"
          },
          {
            "level": "1",
            "section": "",
            "title": "Overall Level"
          }
        ],
        "found": true,
        "section": 1,
        "subsection": 2
      },
      "self_tests": {
        "entries": [
          {
            "algorithmOrTest": "HMAC-SHA2- 256 (A4545)",
            "details": "Integrity test for libgnutls.so.30, libnettle.so.8, libhogweed.so.6, libgmp.so.10",
            "indicator": "Module becomes operational and services are available for use",
            "testMethod": "Message Authentication",
            "testProps": "256-bit key",
            "type": "SW/FW Integrity"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 1
      },
      "ssp_io_methods": {
        "entries": [
          {
            "dest": "Cryptographic module",
            "distribution": "Manual",
            "entry": "Electronic",
            "format": "Plaintext",
            "name": "API input parameters",
            "sfiAlgo": "",
            "source": "Calling application within TOEPP"
          },
          {
            "dest": "Calling application within TOEPP",
            "distribution": "Manual",
            "entry": "Electronic",
            "format": "Plaintext",
            "name": "API output parameters",
            "sfiAlgo": "",
            "source": "Cryptographic module"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 2
      },
      "ssp_zeroization_methods": {
        "entries": [
          {
            "description": "Zeroizes the SSPs referenced in the function name",
            "method": "Free cipher handle",
            "operatorId": "By calling the appropriate zeroization functions: AES Key: gnutls_cipher_deinit() AES Key: gnutls_aead_cipher_deinit() HMAC Key: gnutls_hmac_deinit() RSA Public Key, RSA Private Key: gnutls_privkey_deinit() gnutls_x509_privkey_deinit() gnutls_rsa_params_deinit() ECDSA Public Key, ECDSA Private Key: gnutls_privkey_deinit() gnutls_x509_privkey_deinit() gnutls_rsa_params_deinit() Diffie-Hellman Public Key, Diffie-Hellman Private Key: gnutls_dh_params_deinit() TLS Pre-master Secret: gnutls_deinit() TLS Master Secret: gnutls_deinit() TLS Derived Secret: gnutls_deinit() Diffie- Hellman Public Key, Diffie-Hellman Private Key: gnutls_pk_params_clear() EC Diffie-Hellman Public Key, EC Diffie-Hellman Private Key: gnutls_pk_params_clear() Diffie-Hellman Shared Secret: zeroize key() EC Diffie-Hellman Shared Secret: zeroize key() All SSPs: gnutls_global_deinit()",
            "rationale": "Memory occupied by SSPs is overwritten with zeros, which renders the SSP values irretrievable"
          },
          {
            "description": "De-allocates the volatile memory used to store SSPs",
            "method": "Remove power from the module",
            "operatorId": "By removing power",
            "rationale": "Volatile memory used by the module is overwritten within nanoseconds when power is removed"
          },
          {
            "description": "Automatically zeroized by the module when no longer needed",
            "method": "Automatic",
            "operatorId": "N/A",
            "rationale": "Memory occupied by SSPs is overwritten with zeros, which renders the SSP values irretrievable"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 3
      },
      "storage_areas": {
        "entries": [
          {
            "description": "Temporary storage for SSPs used by the module as part of service execution. The module does not perform persistent storage of SSPs.",
            "name": "RAM",
            "persistance": "Dynamic"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 1
      },
      "tested_module_id_hw": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "tested_module_id_hw_hy": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "tested_module_id_sw_fw_hy": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "tested_op_env_sw_fw_hy": {
        "entries": [
          {
            "hardwarePlatform": "EC2 c7g.metal",
            "hypervisorHostOs": "N/A",
            "operatingSystem": "Amazon Linux 2023",
            "paa_pai": "Yes",
            "processors": "AWS Graviton3",
            "version": "3.8.0-f3d7c0863662248d"
          },
          {
            "hardwarePlatform": "EC2 c6i.metal",
            "hypervisorHostOs": "N/A",
            "operatingSystem": "Amazon Linux 2023",
            "paa_pai": "Yes",
            "processors": "Intel Xeon Platinum 8375C",
            "version": "3.8.0-f3d7c0863662248d"
          },
          {
            "hardwarePlatform": "AWS Snowball",
            "hypervisorHostOs": "N/A",
            "operatingSystem": "Amazon Linux 2023",
            "paa_pai": "Yes",
            "processors": "AMD EPYC 7702",
            "version": "3.8.0-f3d7c0863662248d"
          },
          {
            "hardwarePlatform": "AWS Snowblade",
            "hypervisorHostOs": "N/A",
            "operatingSystem": "Amazon Linux 2023",
            "paa_pai": "Yes",
            "processors": "Intel Xeon Gold 6314U",
            "version": "3.8.0-f3d7c0863662248d"
          },
          {
            "hardwarePlatform": "AWS Snowcone",
            "hypervisorHostOs": "N/A",
            "operatingSystem": "Amazon Linux 2023",
            "paa_pai": "Yes",
            "processors": "Intel Atom C3558",
            "version": "3.8.0-f3d7c0863662248d"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 2
      },
      "vendor_affirmed_algos": {
        "entries": [
          {
            "algoPropList": "RSA:2048, 3072, 4096-bit keys",
            "implName": "Amazon Linux 2023 GnuTLS (Generic C)",
            "name": "Cryptographic Key Generation (CKG)",
            "reference": "SP800-133r2, Section 5.1"
          },
          {
            "algoPropList": "ECDSA:P-256, P-384, P-521 elliptic curves",
            "implName": "Amazon Linux 2023 GnuTLS (Generic C)",
            "name": "Cryptographic Key Generation (CKG)",
            "reference": "SP800-133r2, Section 5.1, 5.2"
          },
          {
            "algoPropList": "Safe Prime:2048, 3072, 4096, 6144, 8192- bit keys",
            "implName": "Amazon Linux 2023 GnuTLS (Generic C)",
            "name": "Cryptographic Key Generation (CKG)",
            "reference": "SP800-133r2, Section 5.2"
          },
          {
            "algoPropList": "CTR_DRBG:112-256 bit keys",
            "implName": "Amazon Linux 2023 GnuTLS (Generic C)",
            "name": "Cryptographic Key Generation (CKG)",
            "reference": "SP800-133r2, Section 6.1"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "vendor_affirmed_op_env_sw_fw_hy": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      }
    },
    "is_br1_format": true,
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 1
          },
          "ECDH": {
            "ECDH": 3
          },
          "ECDSA": {
            "ECDSA": 86
          }
        },
        "FF": {
          "DH": {
            "DH": 6,
            "Diffie-Hellman": 60
          },
          "DSA": {
            "DSA": 6
          }
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 1
        },
        "CCM": {
          "CCM": 2
        },
        "CFB": {
          "CFB": 1
        },
        "CTR": {
          "CTR": 1
        },
        "ECB": {
          "ECB": 1
        },
        "GCM": {
          "GCM": 6
        },
        "OFB": {
          "OFB": 1
        },
        "XTS": {
          "XTS": 5
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {
        "GnuTLS": {
          "GnuTLS": 76
        }
      },
      "crypto_protocol": {
        "TLS": {
          "TLS": {
            "TLS": 73,
            "TLS 1.0": 1,
            "TLS v1.2": 3,
            "TLS v1.3": 1,
            "TLSv1.0": 1,
            "TLSv1.1": 1,
            "TLSv1.2": 1,
            "TLSv1.3": 1
          }
        }
      },
      "crypto_scheme": {
        "AEAD": {
          "AEAD": 2
        },
        "KA": {
          "Key Agreement": 6,
          "Key agreement": 1
        },
        "MAC": {
          "MAC": 31
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-256": 42,
          "P-384": 42,
          "P-521": 30
        }
      },
      "eval_facility": {
        "atsec": {
          "atsec": 3
        }
      },
      "fips_cert_id": {},
      "fips_certlike": {
        "Certlike": {
          "- PKCS 1": 2,
          "AES-256": 2,
          "DRBG 256": 2,
          "Diffie- Hellman 2048": 1,
          "HMAC-SHA-1": 42,
          "PKCS 1": 2,
          "PKCS#1": 2,
          "SHA-1": 6,
          "SHA-3": 1,
          "SHA2-224": 7,
          "SHA2-256": 27,
          "SHA2-384": 9,
          "SHA2-512": 8,
          "SHA3-224": 11,
          "SHA3-256": 11,
          "SHA3-384": 10,
          "SHA3-512": 10
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 2
        }
      },
      "hash_function": {
        "MD": {
          "MD4": {
            "MD4": 2
          },
          "MD5": {
            "MD5": 3
          }
        },
        "PBKDF": {
          "PBKDF": 29,
          "PBKDF2": 1
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 6
          },
          "SHA3": {
            "SHA-3": 1,
            "SHA3-224": 11,
            "SHA3-256": 12,
            "SHA3-384": 10,
            "SHA3-512": 10
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 50
        },
        "RNG": {
          "RBG": 2,
          "RNG": 2
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-3": 73,
          "FIPS 180-4": 15,
          "FIPS 186-4": 9,
          "FIPS 186-5": 1,
          "FIPS 198-1": 15,
          "FIPS 202": 8,
          "FIPS PUB 140-3": 2,
          "FIPS140-3": 1,
          "FIPS180-4": 1,
          "FIPS186-4": 21,
          "FIPS186-5": 1,
          "FIPS197": 1,
          "FIPS198-1": 1,
          "FIPS202": 1
        },
        "NIST": {
          "SP 800-132": 1,
          "SP 800-135": 2,
          "SP 800-38A": 9,
          "SP 800-38B": 3,
          "SP 800-38C": 2,
          "SP 800-38D": 7,
          "SP 800-38E": 1,
          "SP 800-56A": 3,
          "SP 800-56C": 1,
          "SP 800-90A": 1
        },
        "PKCS": {
          "PKCS 1": 2,
          "PKCS#1": 1
        },
        "RFC": {
          "RFC3268": 4,
          "RFC4279": 2,
          "RFC4492": 8,
          "RFC5246": 4,
          "RFC5288": 5,
          "RFC5289": 16,
          "RFC6655": 4,
          "RFC7627": 2,
          "RFC8446": 5
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 82,
            "AES-256": 2
          },
          "CAST": {
            "CAST": 131
          },
          "RC": {
            "RC2": 3,
            "RC4": 3
          },
          "Serpent": {
            "Serpent": 3
          },
          "Twofish": {
            "Twofish": 3
          }
        },
        "DES": {
          "3DES": {
            "Triple-DES": 5
          },
          "DES": {
            "DES": 4
          }
        },
        "constructions": {
          "MAC": {
            "CMAC": 5,
            "HMAC": 45
          }
        },
        "djb": {
          "Poly": {
            "Poly1305": 3
          },
          "Salsa": {
            "Salsa20": 3
          }
        },
        "miscellaneous": {
          "Blowfish": {
            "Blowfish": 3
          },
          "Camellia": {
            "Camellia": 3
          },
          "SEED": {
            "SEED": 3
          }
        }
      },
      "tee_name": {
        "AMD": {
          "PSP": 8
        },
        "IBM": {
          "SSC": 11
        }
      },
      "tls_cipher_suite": {
        "TLS": {
          "TLS_DHE_RSA_WITH_AES_128_CBC_SHA": 1,
          "TLS_DHE_RSA_WITH_AES_128_CBC_SHA256": 1,
          "TLS_DHE_RSA_WITH_AES_128_CCM": 1,
          "TLS_DHE_RSA_WITH_AES_128_CCM_8": 1,
          "TLS_DHE_RSA_WITH_AES_128_GCM_SHA256": 1,
          "TLS_DHE_RSA_WITH_AES_256_CBC_SHA": 1,
          "TLS_DHE_RSA_WITH_AES_256_CBC_SHA256": 1,
          "TLS_DHE_RSA_WITH_AES_256_CCM": 1,
          "TLS_DHE_RSA_WITH_AES_256_CCM_8": 1,
          "TLS_DHE_RSA_WITH_AES_256_GCM_SHA384": 1,
          "TLS_DH_RSA_WITH_AES_128_CBC_SHA": 1,
          "TLS_DH_RSA_WITH_AES_128_CBC_SHA256": 1,
          "TLS_DH_RSA_WITH_AES_128_GCM_SHA256": 1,
          "TLS_DH_RSA_WITH_AES_256_CBC_SHA": 1,
          "TLS_DH_RSA_WITH_AES_256_CBC_SHA256": 1,
          "TLS_DH_RSA_WITH_AES_256_GCM_SHA384": 1,
          "TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA": 1,
          "TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256": 1,
          "TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256": 1,
          "TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA": 1,
          "TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384": 1,
          "TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384": 1,
          "TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA": 1,
          "TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256": 1,
          "TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256": 1,
          "TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA": 1,
          "TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384": 1,
          "TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384": 1,
          "TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA": 1,
          "TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA256": 1,
          "TLS_ECDH_ECDSA_WITH_AES_128_GCM_SHA256": 1,
          "TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA": 1,
          "TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA384": 1,
          "TLS_ECDH_ECDSA_WITH_AES_256_GCM_SHA384": 1,
          "TLS_ECDH_RSA_WITH_AES_128_CBC_SHA": 1,
          "TLS_ECDH_RSA_WITH_AES_128_CBC_SHA256": 1,
          "TLS_ECDH_RSA_WITH_AES_128_GCM_SHA256": 1,
          "TLS_ECDH_RSA_WITH_AES_256_CBC_SHA": 1,
          "TLS_ECDH_RSA_WITH_AES_256_CBC_SHA384": 1,
          "TLS_ECDH_RSA_WITH_AES_256_GCM_SHA384": 1,
          "TLS_PSK_WITH_AES_128_CBC_SHA": 1,
          "TLS_PSK_WITH_AES_256_CBC_SHA": 1
        }
      },
      "vendor": {},
      "vulnerability": {}
    },
    "module_algorithms": {
      "_type": "Set",
      "elements": [
        "SHA2-256A4572",
        "TLS v1.2 KDF RFC7627A4545",
        "KAS-ECC-SSC Sp800-56Ar3A4545",
        "SHA-1A4572",
        "HMAC-SHA2-512A4572",
        "SHA2-512A4572",
        "HMAC-SHA2-384A4572",
        "HMAC-SHA-1A4572",
        "RSA KeyGen (FIPS186-4)A4545",
        "AES-XTS Testing Revision 2.0A4546",
        "ECDSA KeyGen (FIPS186-4)A4545",
        "Counter DRBGA4545",
        "AES-CBCA4572",
        "ECDSA SigGen (FIPS186-4)A4545",
        "HMAC-SHA2-256A4572",
        "RSA SigVer (FIPS186-4)A4545",
        "HMAC-SHA2-224A4572",
        "SHA3-224A4547",
        "Safe Primes Key GenerationA4545",
        "ECDSA SigVer (FIPS186-4)A4545",
        "AES-GMACA4545",
        "SHA2-384A4572",
        "SHA3-256A4547",
        "ECDSA KeyVer (FIPS186-4)A4545",
        "AES-CCMA4572",
        "KDF TLSA4545",
        "AES-GCMA4572",
        "KAS-FFC-SSC Sp800-56Ar3A4545",
        "SHA2-224A4572",
        "SHA3-384A4547",
        "PBKDFA4545",
        "AES-CMACA4545",
        "KDA HKDF Sp800-56Cr1A4544",
        "RSA SigGen (FIPS186-4)A4545",
        "AES-CFB8A4548",
        "SHA3-512A4547"
      ]
    },
    "policy_algorithms": {
      "_type": "Set",
      "elements": [
        "#A4544",
        "#A4548",
        "#A4546",
        "#A4547",
        "#A4538",
        "#A4540",
        "#A4541",
        "#A4543",
        "#A4539",
        "#A4545",
        "#A4542",
        "#A4572",
        "#A4537"
      ]
    },
    "policy_metadata": {
      "/Author": "Pittinger, Zachary E. (Ctr)",
      "/CreationDate": "D:20250501070530-04\u002700\u0027",
      "/Creator": "Microsoft\u00ae Word for Microsoft 365",
      "/ModDate": "D:20250501070530-04\u002700\u0027",
      "/Producer": "Microsoft\u00ae Word for Microsoft 365",
      "pdf_file_size_bytes": 834493,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "http://csrc.nist.gov/publications/nistpubs/800-38E/nist-sp-800-38E.pdf",
          "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r5.pdf",
          "http://csrc.nist.gov/publications/fips/fips198-1/FIPS-198-1_final.pdf",
          "https://doi.org/10.6028/NIST.SP.800-90B",
          "https://csrc.nist.gov/csrc/media/Projects/cryptographic-module-validation-program/documents/fips%20140-3/FIPS%20140-3%20IG.pdf",
          "http://csrc.nist.gov/publications/nistpubs/800-132/nist-sp800-132.pdf",
          "http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-4.pdf",
          "http://csrc.nist.gov/publications/fips/fips197/fips-197.pdf",
          "http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38c.pdf",
          "https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-5.pdf",
          "http://csrc.nist.gov/publications/nistpubs/800-38D/SP-800-38d.pdf",
          "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-52r2.pdf",
          "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar2.pdf",
          "https://doi.org/10.6028/NIST.SP.800-133r2",
          "http://csrc.nist.gov/publications/nistpubs/800-38B/SP_800-38B.pdf",
          "https://doi.org/10.6028/NIST.SP.800-56Ar3",
          "http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.202.pdf",
          "http://csrc.nist.gov/publications/nistpubs/800-38a/sp800-38a.pdf",
          "http://www.atsec.com/",
          "http://dx.doi.org/10.6028/NIST.SP.800-90Ar1",
          "http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf",
          "http://www.ietf.org/rfc/rfc3447.txt",
          "https://doi.org/10.6028/NIST.SP.800-56Cr2",
          "https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-3.pdf",
          "http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-135r1.pdf"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 69
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.InternalState",
    "module": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "policy": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": "cfeeb197bbea6e81927db5615f7ca3486ccbb2b96152d660b1ac1b125de98cc7",
      "source_hash": "8be763065ba1888b20d3f29f16bfe7a9123099650474ac91e8f7c6dd9a3ffbf7",
      "txt_hash": "a2a4d033ce29b1aa65ab9c9835813d5332e2e4c9808b6f39d756583448ab61a0"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in approved mode and installed, initialized and configured as specified in Section 11 of the Security Policy.",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/May 2025_130625_0321.pdf",
    "date_sunset": "2030-05-04",
    "description": "GnuTLS is a secure communications library implementing the TLS protocol. It provides a simple C language application programming interface to access the secure communications protocols as well as APIs to parse and write X.509, PKCS#12, and other required structures.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Physical security: N/A",
      "Non-invasive security: N/A",
      "Mitigation of other attacks: N/A"
    ],
    "fw_versions": null,
    "historical_reason": null,
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {},
    "module_name": "Amazon Linux 2023 GnuTLS Cryptographic Module",
    "module_type": "Software",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-3",
    "status": "active",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2025-05-05",
        "lab": "atsec information security corporation",
        "validation_type": "Initial"
      }
    ],
    "vendor": "Amazon Web Services, Inc.",
    "vendor_url": "https://aws.amazon.com/linux/amazon-linux-2023/"
  }
}