HP Inc. HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider FIPS 140-3 Non-Proprietary Security Policy July 2026 Document Version 1.0 Prepared by: www.lightshipsec.com HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider FIPS 140-3 Non-Proprietary Security Policy HP Inc. 2026 Page 1 of 92 This document may be reproduced and distributed only in its original entirety without revision. Table of Contents 1 General........................................................................................................................................4 1.1 Overview ...............................................................................................................................4 1.2 Security Levels........................................................................................................................4 1.3 Additional Information............................................................................................................5 2 Cryptographic Module Specification..............................................................................................6 2.1 Description ............................................................................................................................6 2.2 Tested and Vendor Affirmed Module Version and Identification.................................................7 2.3 Excluded Components ............................................................................................................8 2.4 Modes of Operation................................................................................................................8 2.5 Algorithms ...........................................................................................................................10 2.6 Security Function Implementations........................................................................................21 2.7 Algorithm Specific Information ..............................................................................................36 2.8 RBG and Entropy ..................................................................................................................39 2.9 Key Generation ....................................................................................................................39 2.10 Key Establishment ..............................................................................................................39 2.11 Industry Protocols...............................................................................................................40 3 Cryptographic Module Interfaces ................................................................................................41 3.1 Ports and Interfaces..............................................................................................................41 4 Roles, Services, and Authentication.............................................................................................42 4.1 Authentication Methods .......................................................................................................42 4.2 Roles ...................................................................................................................................42 4.3 Approved Services ................................................................................................................42 4.4 Non-Approved Services.........................................................................................................62 4.5 External Software/Firmware Loaded ......................................................................................62 4.6 Bypass Actions and Status .....................................................................................................62 4.7 Cryptographic Output Actions and Status ...............................................................................62 5 Software/Firmware Security .......................................................................................................63 5.1 Integrity Techniques .............................................................................................................63 5.2 Initiate on Demand...............................................................................................................63 5.3 Open-Source Parameters ......................................................................................................63 6 Operational Environment ...........................................................................................................64 6.1 Operational Environment Type and Requirements ..................................................................64 6.2 Configuration Settings and Restrictions ..................................................................................64 7 Physical Security ........................................................................................................................65 HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider FIPS 140-3 Non-Proprietary Security Policy HP Inc. 2026 Page 2 of 92 This document may be reproduced and distributed only in its original entirety without revision. 8 Non-Invasive Security.................................................................................................................66 9 Sensitive Security Parameters Management ................................................................................67 9.1 Storage Areas.......................................................................................................................67 9.2 SSP Input-Output Methods....................................................................................................67 9.3 SSP Zeroization Methods.......................................................................................................67 9.4 SSPs ....................................................................................................................................68 10 Self-Tests .................................................................................................................................79 10.1 Pre-Operational Self-Tests...................................................................................................79 10.2 Conditional Self-Tests..........................................................................................................79 10.3 Periodic Self-Test Information..............................................................................................82 10.4 Error States........................................................................................................................87 10.5 Operator Initiation of Self-Tests ...........................................................................................87 11 Life-Cycle Assurance .................................................................................................................88 11.1 Installation, Initialization, and Startup Procedures .................................................................88 11.2 Administrator Guidance ......................................................................................................89 11.3 Non-Administrator Guidance ...............................................................................................89 11.4 Design and Rules ................................................................................................................90 11.5 Maintenance Requirements.................................................................................................90 11.6 End of Life..........................................................................................................................90 12 Mitigation of Other Attacks.......................................................................................................91 12.1 Attack List ..........................................................................................................................91 HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider FIPS 140-3 Non-Proprietary Security Policy HP Inc. 2026 Page 3 of 92 This document may be reproduced and distributed only in its original entirety without revision. List of Tables Table 1: Security Levels................................................................................................................5 Table 2: Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets).....7 Table 3: Tested Operational Environments - Software, Firmware, Hybrid....................................8 Table 4: Modes List and Description.............................................................................................9 Table 5: Approved Algorithms.....................................................................................................18 Table 6: Vendor-Affirmed Algorithms..........................................................................................20 Table 7: Non-Approved, Allowed Algorithms ..............................................................................20 Table 8: Non-Approved, Not Allowed Algorithms........................................................................21 Table 9: Security Function Implementations...............................................................................35 Table 10: Ports and Interfaces....................................................................................................41 Table 11: Roles...........................................................................................................................42 Table 12: Approved Services......................................................................................................60 Table 13: Non-Approved Services..............................................................................................62 Table 14: Storage Areas.............................................................................................................67 Table 15: SSP Input-Output Methods.........................................................................................67 Table 16: SSP Zeroization Methods ...........................................................................................68 Table 17: SSP Table 1................................................................................................................74 Table 18: SSP Table 2................................................................................................................77 Table 19: Pre-Operational Self-Tests .........................................................................................79 Table 20: Conditional Self-Tests.................................................................................................82 Table 21: Pre-Operational Periodic Information..........................................................................82 Table 22: Conditional Periodic Information.................................................................................87 Table 23: Error States.................................................................................................................87 List of Figures Figure 1: HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider Block Diagram .................7 HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider FIPS 140-3 Non-Proprietary Security Policy HP Inc. 2026 Page 4 of 92 This document may be reproduced and distributed only in its original entirety without revision. 1 General 1.1 Overview Introduction Federal Information Processing Standards Publication 140-3 — Security Requirements for Cryptographic Modules specifies requirements for cryptographic modules to be deployed in a Sensitive but Unclassified environment. The National Institute of Standards and Technology (NIST) and Canadian Centre for Cyber Security (CCCS) Cryptographic Module Validation Program (CMVP) run the FIPS 140-3 program. The NVLAP accredits independent testing labs to perform FIPS 140-3 testing; the CMVP validates modules meeting FIPS 140-3 validation. Validated is the term given to a module that is documented and tested against the FIPS 140-3 criteria. More information is available on the CMVP website at: https://csrc.nist.gov/projects/cryptographic-module-validation-program. About this Document This document describes the non-proprietary Security Policy for the HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider cryptographic module (hereafter referred to as “the Module”) from HP Inc. It contains specification of the security rules under which the Module operates, including the security rules derived from the requirements of the FIPS 140-3 standard. The OpenSSL Project may also be referred to as “OpenSSL” in this document. The following trademarks are referenced within this Security Policy: • Linux®: Linux is the registered trademark of Linus Torvalds in the U.S. and other countries. • Unix®: UNIX is a registered trademark of The Open Group. • Microsoft Windows®: Windows is a registered trademark of Microsoft Corporation in the United States and other countries. Copyright Notice Copyright © 2025 The OpenSSL Project Authors. This document may be freely reproduced and distributed whole and intact including this copyright notice. OpenSSL 3.1.2 FIPS 140-3 Validation Contributors: KeyPair Consulting Inc 1.2 Security Levels The Module meets FIPS 140-3 overall Level 1 requirements, with security levels as follows: Section Title Security Level 1 General 1 HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider FIPS 140-3 Non-Proprietary Security Policy HP Inc. 2026 Page 5 of 92 This document may be reproduced and distributed only in its original entirety without revision. Section Title Security Level 2 Cryptographic module specification 1 3 Cryptographic module interfaces 1 4 Roles, services, and authentication 1 5 Software/Firmware security 1 6 Operational environment 1 7 Physical security N/A 8 Non-invasive security N/A 9 Sensitive security parameter management 1 10 Self-tests 1 11 Life-cycle assurance 3 12 Mitigation of other attacks 1 Overall Level 1 Table 1: Security Levels 1.3 Additional Information In accordance with AS02.05, [ISO19790] §7.7 Physical Security is optional and does not apply to the Module. In accordance with current CMVP policy, [ISO19790] §7.8 Non-Invasive Security is not applicable. HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider FIPS 140-3 Non-Proprietary Security Policy HP Inc. 2026 Page 6 of 92 This document may be reproduced and distributed only in its original entirety without revision. 2 Cryptographic Module Specification 2.1 Description Purpose and Use: The Module is a cryptographic software library providing a C-language application program interface (API) for use by applications that require cryptographic functionality and is designated as a software module with a multi-chip standalone embodiment based on the descriptions of [ISO19790] AS02.03. The Module is intended for use by US and Canadian Federal agencies and other markets that require FIPS 140-3 validated cryptographic functionality. The Module’s formal name and version are “HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider” and “3.1.2”, respectively. The Module design corresponds to the Module security rules. Security rules enforced by the Module are described in the appropriate context of this document. Module Type: Software Module Embodiment: Multi-Chip Standalone Cryptographic Boundary: Figure 1 depicts the Module operational environment, with the cryptographic boundary highlighted in red inclusive of all Module entry points (API calls). The Module is defined as a Software module per [ISO19790] AS02.03. The cryptographic boundary of the Module is the FIPS Provider, a dynamically loadable library. The Module performs no communication other than with the calling application via APIs that invoke the Module. The pre-operational approved integrity test is performed over all components within the cryptographic boundary. Tested Operational Environment’s Physical Perimeter (TOEPP): The Tested Operational Environment’s Physical Perimeter (TOEPP) is the General Purpose Computer. HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider FIPS 140-3 Non-Proprietary Security Policy HP Inc. 2026 Page 7 of 92 This document may be reproduced and distributed only in its original entirety without revision. Figure 1: HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider Block Diagram 2.2 Tested and Vendor Affirmed Module Version and Identification Tested Module Identification – Hardware: N/A for this module. Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets): Package or File Name Software/ Firmware Version Features Integrity Test fips.so 3.1.2 fips.so for Unix/Linux platforms HMAC-SHA2-256 fips.dll 3.1.2 fips.dll for Windows platforms HMAC-SHA2-256 fips.dylib 3.1.2 fips.dylib for Mac platforms HMAC-SHA2-256 Table 2: Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets) Tested Module Identification – Hybrid Disjoint Hardware: N/A for this module. Tested Operational Environments - Software, Firmware, Hybrid: HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider FIPS 140-3 Non-Proprietary Security Policy HP Inc. 2026 Page 8 of 92 This document may be reproduced and distributed only in its original entirety without revision. Operating System Hardware Platform Processors PAA/PAI Hypervisor or Host OS Version(s) Ubuntu Linux 22.04.1 Server Dell Inspiron 7573 Intel i7- 8550U No N/A 3.1.2 Ubuntu Linux 22.04.1 Server Dell Inspiron 7573 Intel i7- 8550U Yes N/A 3.1.2 Debian 11.5 Dell Inspiron 7573 Intel i7- 8550U No N/A 3.1.2 Debian 11.5 Dell Inspiron 7573 Intel i7- 8550U Yes N/A 3.1.2 FreeBSD 13.1 Dell Inspiron 7591 2 in 1 Intel i7- 10510U No N/A 3.1.2 FreeBSD 13.1 Dell Inspiron 7591 2 in 1 Intel i7- 10510U Yes N/A 3.1.2 Windows 10 Pro Dell Inspiron 7591 2 in 1 Intel i7- 10510U No N/A 3.1.2 Windows 10 Pro Dell Inspiron 7591 2 in 1 Intel i7- 10510U Yes N/A 3.1.2 macOS 11.5.2 Apple M1 Mac Mini M1 No N/A 3.1.2 macOS 11.5.2 Apple M1 Mac Mini M1 Yes N/A 3.1.2 macOS 11.5.2 Apple i7 Mac Mini Intel i7 No N/A 3.1.2 macOS 11.5.2 Apple i7 Mac Mini Intel i7 Yes N/A 3.1.2 Table 3: Tested Operational Environments - Software, Firmware, Hybrid Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid: N/A for this module. No operational environments are vendor affirmed. 2.3 Excluded Components No components are excluded from [FIPS140-3] requirements. 2.4 Modes of Operation Modes List and Description: Mode Name Description Type Status Indicator Approved mode The module must be installed and configured per instructions provided in Section 11 of this document and the module is in the Approved mode by default as a result. The installation of the Module as described in Section 11 results in the settings described below this Approved fips=yes HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider FIPS 140-3 Non-Proprietary Security Policy HP Inc. 2026 Page 9 of 92 This document may be reproduced and distributed only in its original entirety without revision. Mode Name Description Type Status Indicator table, which are required for operation in the Approved mode Non- Approved mode The module is in the Approved mode of operation by default. Use of the non-Approved Algorithms Not Allowed in the Approved Mode will place the module in the non-approved mode of operation. Non- Approved fips=no Table 4: Modes List and Description The Module supports an Approved mode and a non-Approved mode of operation. The inherent properties of the Module are: 1. Manual key entry is not supported. 2. Data output is inhibited during self-tests, zeroisation, SSP generation and error states. 3. The Module does not perform any cryptographic function if any self-test has failed. The conditions for using the Module in the [FIPS140-3] Approved mode of operation are: 1. Installation of the Module as described in Section 11 results in the settings described below, which are required for operation in the Approved mode: a. security-checks = 1 Enforce minimum key strengths and approved curve names. b.conditional-errors = 1 Enforce the Module entering the error state on conditional test errors such as PCT failure. c. drbg-no-trunc-md=1 Disallow use of truncated digests with HASH and HMAC DRBGs (IG D.R) d.tls1-prf-ems-check=1 Enforce Extended Master Secret (EMS) use with TLS 1.2 (IG D.Q) 2. The Module is a cryptographic library used by a calling application. The calling application is responsible for: a. Use of the primitives in the correct sequence. b.Use of keys in accordance with [SP800-140Dr2] (as the keys used by the Module for cryptographic purposes are provided over the call stack by the calling application). c. Use of a [SP800-90B] compliant entropy source. Entropy is supplied to the Module via callback functions. The callback functions return an error if the minimum entropy strength cannot be met. Mode Change Instructions and Status: Use of the Approved algorithms and Non-Approved Algorithms Allowed in the Approved Mode will ensure operation of the module in the Approved mode of operation. Use of the non-Approved Algorithms Not Allowed in the Approved Mode will place the module in the non-approved mode of operation. Degraded Mode Description: The module does not support a degraded mode of operation. HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider FIPS 140-3 Non-Proprietary Security Policy HP Inc. 2026 Page 10 of 92 This document may be reproduced and distributed only in its original entirety without revision. 2.5 Algorithms Approved Algorithms: Algorithm CAVP Cert Properties Reference AES-CBC A3548 Direction - Decrypt, Encrypt Key Length - 128, 192, 256 SP 800- 38A AES-CBC- CS1 A3548 Direction - decrypt, encrypt Key Length - 128, 192, 256 Payload Length - Payload Length: 128-65536 Increment 8 SP 800- 38A AES-CBC- CS2 A3548 Direction - decrypt, encrypt Key Length - 128, 192, 256 Payload Length - Payload Length: 128-65536 Increment 8 SP 800- 38A AES-CBC- CS3 A3548 Direction - decrypt, encrypt Key Length - 128, 192, 256 Payload Length - Payload Length: 128-65536 Increment 8 SP 800- 38A AES-CCM A3548 Key Length - 128, 192, 256 Tag Length - 112, 128, 32, 48, 64, 80, 96 IV Length - IV Length: 56-104 Increment 8 Payload Length - Payload Length: 0-256 Increment 8 AAD Length - AAD Length: 0-524288 Increment 8 SP 800- 38C AES-CFB1 A3548 Direction - Decrypt, Encrypt Key Length - 128, 192, 256 SP 800- 38A AES-CFB128 A3548 Direction - Decrypt, Encrypt Key Length - 128, 192, 256 SP 800- 38A AES-CFB8 A3548 Direction - Decrypt, Encrypt Key Length - 128, 192, 256 SP 800- 38A AES-CMAC A3548 Direction - Generation, Verification Key Length - 128, 192, 256 MAC Length - MAC Length: 128 Message Length - Message Length: 0-524288 Increment 8 SP 800- 38B AES-CTR A3548 Direction - Decrypt, Encrypt Key Length - 128, 192, 256 Payload Length - Payload Length: 8-128 Increment 8 Supports Counter larger than maximum value - No Incremental Counter - Yes Counter Tests Performed - Yes SP 800- 38A AES-ECB A3548 Direction - Decrypt, Encrypt Key Length - 128, 192, 256 SP 800- 38A AES-GCM A3548 Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256 Tag Length - 104, 112, 120, 128, 32, 64, 96 IV Length - IV Length: 96-1024 Increment 8 Payload Length - Payload Length: 0-65536 Increment SP 800- 38D HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider FIPS 140-3 Non-Proprietary Security Policy HP Inc. 2026 Page 11 of 92 This document may be reproduced and distributed only in its original entirety without revision. Algorithm CAVP Cert Properties Reference 8, Payload Length: 8-65536 Increment 8 AAD Length - AAD Length: 0-65536 Increment 8 AES-GMAC A3548 Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256 Tag Length - 104, 112, 120, 128, 32, 64, 96 IV Length - IV Length: 96-1024 Increment 8 AAD Length - AAD Length: 0-65536 Increment 8 SP 800- 38D AES-KW A3548 Direction - Decrypt, Encrypt Cipher - Cipher, Inverse Key Length - 128, 192, 256 Payload Length - Payload Length: 128-4096 Increment 128 SP 800- 38F AES-KWP A3548 Direction - Decrypt, Encrypt Cipher - Cipher, Inverse Key Length - 128, 192, 256 Payload Length - Payload Length: 8-4096 Increment 8 SP 800- 38F AES-OFB A3548 Direction - Decrypt, Encrypt Key Length - 128, 192, 256 SP 800- 38A AES-XTS Testing Revision 2.0 A3548 Direction - Decrypt, Encrypt Key Length - 128, 256 Payload Length - Payload Length: 128-65536 Increment 128 Tweak Mode - Hex Data Unit Length Matches Payload Length - Yes SP 800- 38E Counter DRBG A3548 Prediction Resistance - Yes Supports Reseed - Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - No, Yes Additional Input - Additional Input: 0-256 Increment 256, Additional Input: 256, Additional Input: 320, Additional Input: 384 Entropy Input - Entropy Input: 128-256 Increment 128, Entropy Input: 256, Entropy Input: 256-512 Increment 128, Entropy Input: 320, Entropy Input: 384 Nonce - Nonce: 0, Nonce: 128 Personalization String Length - Personalization String Length: 0-256 Increment 256, Personalization String Length: 256, Personalization String Length: 320, Personalization String Length: 384 Returned Bits - 256 SP 800- 90A Rev. 1 DSA KeyGen (FIPS186-4) A3548 L - 2048, 3072 N - 224, 256 FIPS 186-4 DSA PQGGen (FIPS186-4) A3548 P/Q Generation Methods - Probable G Generation Methods - Canonical, Unverifiable L - 2048, 3072 FIPS 186-4 HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider FIPS 140-3 Non-Proprietary Security Policy HP Inc. 2026 Page 12 of 92 This document may be reproduced and distributed only in its original entirety without revision. Algorithm CAVP Cert Properties Reference N - 224, 256 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 DSA PQGVer (FIPS186-4) A3548 P/Q Generation Methods - Probable G Generation Methods - Canonical, Unverifiable L - 1024, 2048, 3072 N - 160, 224, 256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2- 512/256 FIPS 186-4 DSA SigGen (FIPS186-4) A3548 L - 2048, 3072 N - 224, 256 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 FIPS 186-4 DSA SigVer (FIPS186-4) A3548 L - 1024, 2048, 3072 N - 160, 224, 256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2- 512/256 FIPS 186-4 ECDSA KeyGen (FIPS186-4) A3548 Curve - B-233, B-283, B-409, B-571, K-233, K-283, K- 409, K-571, P-224, P-256, P-384, P-521 Secret Generation Mode - Testing Candidates FIPS 186-4 ECDSA KeyVer (FIPS186-4) A3548 Curve - B-163, B-233, B-283, B-409, B-571, K-163, K- 233, K-283, K-409, K-571, P-192, P-224, P-256, P- 384, P-521 FIPS 186-4 ECDSA SigGen (FIPS186-4) A3548 Component - No, Yes Curve - B-233, B-283, B-409, B-571, K-233, K-283, K- 409, K-571, P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3- 224, SHA3-256, SHA3-384, SHA3-512 FIPS 186-4 ECDSA SigVer (FIPS186-4) A3548 Component - No, Yes Curve - B-163, B-233, B-283, B-409, B-571, K-163, K- 233, K-283, K-409, K-571, P-192, P-224, P-256, P- 384, P-521 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2- 512/256, SHA3-224, SHA3-256, SHA3-384, SHA3- 512 FIPS 186-4 Hash DRBG A3548 Prediction Resistance - Yes Supports Reseed - Yes Mode - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3- 256, SHA3-512 Entropy Input - Entropy Input: 128-256 Increment 64, Entropy Input: 192-256 Increment 64, Entropy Input: 256-320 Increment 64, Entropy Input: 256-65536 Increment 64 SP 800- 90A Rev. 1 HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider FIPS 140-3 Non-Proprietary Security Policy HP Inc. 2026 Page 13 of 92 This document may be reproduced and distributed only in its original entirety without revision. Algorithm CAVP Cert Properties Reference Nonce - Nonce: 128-160 Increment 32, Nonce: 96- 128 Increment 32 Personalization String Length - Personalization String Length: 0-256 Increment 128, Personalization String Length: 0-65536 Increment 128 Additional Input - Additional Input: 0-256 Increment 128 Returned Bits - 160, 224, 256, 384, 512 HMAC DRBG A3548 Prediction Resistance - Yes Supports Reseed - Yes Mode - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3- 256, SHA3-512 Entropy Input - Entropy Input: 160-256 Increment 32, Entropy Input: 192-256 Increment 64, Entropy Input: 256-512 Increment 64, Entropy Input: 256-65536 Increment 64, Entropy Input: 384-512 Increment 64, Entropy Input: 512-1024 Increment 64 Nonce - Nonce: 128, Nonce: 128-160 Increment 32, Nonce: 64, Nonce: 96 Personalization String Length - Personalization String Length: 0-192 Increment 64, Personalization String Length: 0-256 Increment 128, Personalization String Length: 0-65536 Increment 128 Additional Input - Additional Input: 0-256 Increment 128, Additional Input: 192 Returned Bits - 160, 224, 256, 384, 512 SP 800- 90A Rev. 1 HMAC-SHA-1 A3548 MAC - MAC: 32-160 Increment 8 Key Length - Key Length: 8-524288 Increment 8 FIPS 198-1 HMAC-SHA2- 224 A3548 MAC - MAC: 32-224 Increment 8 Key Length - Key Length: 8-524288 Increment 8 FIPS 198-1 HMAC-SHA2- 256 A3548 MAC - MAC: 32-256 Increment 8 Key Length - Key Length: 8-524288 Increment 8 FIPS 198-1 HMAC-SHA2- 384 A3548 MAC - MAC: 32-384 Increment 8 Key Length - Key Length: 8-524288 Increment 8 FIPS 198-1 HMAC-SHA2- 512 A3548 MAC - MAC: 32-512 Increment 8 Key Length - Key Length: 8-524288 Increment 8 FIPS 198-1 HMAC-SHA2- 512/224 A3548 MAC - MAC: 32-224 Increment 8 Key Length - Key Length: 8-524288 Increment 8 FIPS 198-1 HMAC-SHA2- 512/256 A3548 MAC - MAC: 32-256 Increment 8 Key Length - Key Length: 8-524288 Increment 8 FIPS 198-1 HMAC-SHA3- 224 A3548 MAC - MAC: 32-224 Increment 8 Key Length - Key Length: 8-524288 Increment 8 FIPS 198-1 HMAC-SHA3- 256 A3548 MAC - MAC: 32-256 Increment 8 Key Length - Key Length: 8-524288 Increment 8 FIPS 198-1 HMAC-SHA3- 384 A3548 MAC - MAC: 32-384 Increment 8 Key Length - Key Length: 8-524288 Increment 8 FIPS 198-1 HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider FIPS 140-3 Non-Proprietary Security Policy HP Inc. 2026 Page 14 of 92 This document may be reproduced and distributed only in its original entirety without revision. Algorithm CAVP Cert Properties Reference HMAC-SHA3- 512 A3548 MAC - MAC: 32-512 Increment 8 Key Length - Key Length: 8-524288 Increment 8 FIPS 198-1 KAS-ECC CDH- Component SP800-56Ar3 (CVL) A3548 Curve - B-233, B-283, B-409, B-571, K-233, K-283, K- 409, K-571, P-224, P-256, P-384, P-521 SP 800- 56A Rev. 3 KAS-ECC- SSC Sp800- 56Ar3 A3548 Domain Parameter Generation Methods - B-233, B- 283, B-409, B-571, K-233, K-283, K-409, K-571, P- 224, P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responder SP 800- 56A Rev. 3 KAS-FFC- SSC Sp800- 56Ar3 A3548 Domain Parameter Generation Methods - FB, FC, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192 Scheme - dhEphem - KAS Role - initiator, responder SP 800- 56A Rev. 3 KAS-IFC-SSC A3548 Modulo - 2048, 3072, 4096, 6144, 8192 Key Generation Methods - rsakpg1-basic, rsakpg1- crt, rsakpg1-prime-factor, rsakpg2-basic, rsakpg2-crt, rsakpg2-prime-factor Scheme - KAS1 - KAS Role - initiator, responder KAS2 - KAS Role - initiator, responder Fixed Public Exponent - 010001 SP 800- 56A Rev. 3 KDA HKDF SP800-56Cr2 A3548 Fixed Info Pattern - algorithmId||l||uPartyInfo||vPartyInfo Fixed Info Encoding - concatenation Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224- 8192 Increment 8 HMAC Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2- 512/256, SHA3-224, SHA3-256, SHA3-384, SHA3- 512 Perform Multiple Expansion Tests - No Uses Hybrid Shared Secret - No SP 800- 56C Rev. 2 KDA OneStep SP800-56Cr2 A3548 Auxiliary Function Methods - Auxiliary Function Name - SHA-1 MAC Salting Methods - default, random Fixed Info Pattern - algorithmId||l||uPartyInfo||vPartyInfo Fixed Info Encoding - concatenation SP 800- 56C Rev. 2 HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider FIPS 140-3 Non-Proprietary Security Policy HP Inc. 2026 Page 15 of 92 This document may be reproduced and distributed only in its original entirety without revision. Algorithm CAVP Cert Properties Reference Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224- 8192 Increment 8 KDA TwoStep SP800-56Cr2 A3548 MAC Salting Methods - default, random Fixed Info Pattern - algorithmId||l||uPartyInfo||vPartyInfo Fixed Info Encoding - concatenation KDF Mode - feedback MAC Modes - HMAC-SHA-1, HMAC-SHA2-224, HMAC-SHA2-256, HMAC-SHA2-384, HMAC-SHA2- 512, HMAC-SHA2-512/224, HMAC-SHA2-512/256, HMAC-SHA3-224, HMAC-SHA3-256, HMAC-SHA3- 384, HMAC-SHA3-512 Fixed Data Order - after fixed data Counter Lengths - 8 The KDF supports an empty IV - Yes The KDF requires an empty IV - Yes Supported Lengths - Supported Lengths: 2048 Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224- 8192 Increment 8 Perform Multiple Expansion Tests - No Uses Hybrid Shared Secret - No SP 800- 56C Rev. 2 KDF ANS 9.42 (CVL) A3548 KDF Type - DER Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2- 512/256, SHA3-224, SHA3-256, SHA3-384, SHA3- 512 Other Info Length - Other Info Length: 0-4096 Increment 8 zz Length - zz Length: 8-4096 Increment 8 Key Data Length - Key Data Length: 8-4096 Increment 8 Supplemental Information Length - Supplemental Information Length: 0-120 Increment 8 OID - AES-128-KW, AES-192-KW, AES-256-KW SP 800- 135 Rev. 1 KDF ANS 9.63 (CVL) A3548 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512 Field Size - 224, 571 Shared Info Length - Shared Info Length: 0, 1024 Key Data Length - Key Data Length: 128, 4096 SP 800- 135 Rev. 1 KDF KMAC Sp800-108r1 A3548 Key Derivation Key Length - Key Derivation Key Length: 112-4096 Increment 8 Context Length - Context Length: 8-4096 Increment 8 Label Length - Label Length: 8-4096 Increment 8 Derived Key Length - Derived Key Length: 112-4096 Increment 8 MAC Modes - KMAC-128, KMAC-256 SP 800- 108 Rev. 1 HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider FIPS 140-3 Non-Proprietary Security Policy HP Inc. 2026 Page 16 of 92 This document may be reproduced and distributed only in its original entirety without revision. Algorithm CAVP Cert Properties Reference KDF SP800- 108 A3548 KDF Mode - Counter, Feedback MAC Mode - CMAC-AES128, CMAC-AES192, CMAC-AES256, HMAC-SHA-1, HMAC-SHA2-224, HMAC-SHA2-256, HMAC-SHA2-384, HMAC-SHA2- 512, HMAC-SHA2-512/224, HMAC-SHA2-512/256, HMAC-SHA3-224, HMAC-SHA3-256, HMAC-SHA3- 384, HMAC-SHA3-512 Supported Lengths - Supported Lengths: 8, 72, 128, 776, 3456, 4096 Fixed Data Order - Before Fixed Data Counter Length - 32 Supports Empty IV - No Custom Key In Length - 0 SP 800- 108 Rev. 1 KDF SSH (CVL) A3548 Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512 SP 800- 135 Rev. 1 KMAC-128 A3548 Message Length - Message Length: 0-65536 Increment 8 MAC Length - MAC Length: 32-65536 Increment 8 Key Data Length - Key Data Length: 128-1024 Increment 8 Hex Customization - No Supports eXtendable-Output Functions - No, Yes SP 800- 185 KMAC-256 A3548 Message Length - Message Length: 0-65536 Increment 8 MAC Length - MAC Length: 32-65536 Increment 8 Key Data Length - Key Data Length: 128-1024 Increment 8 Hex Customization - No Supports eXtendable-Output Functions - No, Yes SP 800- 185 KTS-IFC A3548 IUT ID - ABCD Modulo - 2048, 3072, 4096, 6144 Key Generation Methods - rsakpg1-basic, rsakpg1- crt, rsakpg1-prime-factor, rsakpg2-basic, rsakpg2-crt, rsakpg2-prime-factor Fixed Public Exponent - 010001 Scheme - KTS-OAEP-basic - KAS Role - initiator, responder Key Transport Method - Hash Algorithms - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3- 224, SHA3-256, SHA3-384, SHA3-512 Supports Null Associated Data - Yes Associated Data Encoding - concatenation Key Length - 1024 SP 800- 56B Rev. 2 PBKDF A3548 Iteration Count - Iteration Count: 1-10000 Increment 1 HMAC Algorithm - SHA-1, SHA2-224, SHA2-256, SP 800- 132 HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider FIPS 140-3 Non-Proprietary Security Policy HP Inc. 2026 Page 17 of 92 This document may be reproduced and distributed only in its original entirety without revision. Algorithm CAVP Cert Properties Reference SHA2-384, SHA2-512, SHA2-512/224, SHA2- 512/256, SHA3-224, SHA3-256, SHA3-384, SHA3- 512 Password Length - Password Length: 8-128 Increment 8 Salt Length - Salt Length: 128-4096 Increment 8 Key Data Length - Key Data Length: 112-4096 Increment 8 RSA KeyGen (FIPS186-4) A3548 Key Generation Mode - B.3.3, B.3.6 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2, Table C.3 Info Generated By Server - Yes Public Exponent Mode - Fixed, Random Private Key Format - Standard Fixed Public Exponent - 010001 FIPS 186-4 RSA SigGen (FIPS186-4) A3548 Signature Type - ANSI X9.31, PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096 Hash Pair - Hash Algorithm - SHA2-224 FIPS 186-4 RSA Signature Primitive (CVL) A3548 Private Key Format - CRT Public Exponent Mode - fixed Fixed Public Exponent - 010001 FIPS 186-4 RSA SigVer (FIPS186-4) A3548 Signature Type - ANSI X9.31, PKCS 1.5, PKCSPSS Modulo - 1024, 2048, 3072, 4096 Hash Pair - Hash Algorithm - SHA-1 Public Exponent Mode - Random FIPS 186-4 Safe Primes Key Generation A3548 Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192 SP 800- 56A Rev. 3 Safe Primes Key Verification A3548 Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192 SP 800- 56A Rev. 3 SHA-1 A3548 Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 FIPS 180-4 SHA2-224 A3548 Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 FIPS 180-4 SHA2-256 A3548 Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 FIPS 180-4 SHA2-384 A3548 Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 FIPS 180-4 HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider FIPS 140-3 Non-Proprietary Security Policy HP Inc. 2026 Page 18 of 92 This document may be reproduced and distributed only in its original entirety without revision. Algorithm CAVP Cert Properties Reference SHA2-512 A3548 Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 FIPS 180-4 SHA2- 512/224 A3548 Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 FIPS 180-4 SHA2- 512/256 A3548 Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 FIPS 180-4 SHA3-224 A3548 Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 FIPS 202 SHA3-256 A3548 Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 FIPS 202 SHA3-384 A3548 Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 FIPS 202 SHA3-512 A3548 Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 FIPS 202 SHAKE-128 A3548 Supports Bit-Oriented Messages - No Supports Empty Message - Yes Supports Bit-Oriented Output - No Output Length - Output Length: 16-65536 Increment 8 FIPS 202 SHAKE-256 A3548 Supports Bit-Oriented Messages - No Supports Empty Message - Yes Supports Bit-Oriented Output - No Output Length - Output Length: 16-65536 Increment 8 FIPS 202 TLS v1.2 KDF RFC7627 (CVL) A3548 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512 Key Block Length - Key Block Length: 1024 SP 800- 135 Rev. 1 TLS v1.3 KDF (CVL) A3548 HMAC Algorithm - SHA2-256, SHA2-384 KDF Running Modes - DHE, PSK, PSK-DHE SP 800- 135 Rev. 1 Table 5: Approved Algorithms The Module implements the Approved cryptographic functions listed in Table 5. Vendor-Affirmed Algorithms: Name Properties Implementation Reference DSA PQGGen [FIPS 186- 4] Key Size, Key Strength:L = 2048/N = 224 (s = 112), L = 2048/N = 256 (s = 112) L = 3072/N = 256 (s = 128) Mode/Method:PQGGen using SHA3 OpenSSL Project OpenSSL 3.x FIPS Provider Vendor affirmed per IG C.C and IG C.B Resolution (bullet point #3) HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider FIPS 140-3 Non-Proprietary Security Policy HP Inc. 2026 Page 19 of 92 This document may be reproduced and distributed only in its original entirety without revision. Name Properties Implementation Reference DSA PQGVer [FIPS 186- 4] Key Size, Key Strength:L = 1024/N = 160 (s < 112) L = 2048/N = 224 (s = 112), L = 2048/N = 256 (s = 112) L = 3072/N = 256 (s = 128) Mode/Method:PQGVer using SHA3 OpenSSL Project OpenSSL 3.x FIPS Provider Vendor affirmed per IG C.C and IG C.B Resolution (bullet point #3) DSA SigGen [FIPS 186- 4] Key Size, Key Strength:L = 2048/N = 224 (s = 112), L = 2048/N = 256 (s = 112) L = 3072/N = 256 (s = 128) Mode/Method:SigGen using SHA3 OpenSSL Project OpenSSL 3.x FIPS Provider Vendor affirmed per IG C.C and IG C.B Resolution (bullet point #3) DSA SigVer [FIPS186- 4] Key Size, Key Strength:L = 1024/N = 160 (s < 112) L = 2048/N = 224 (s = 112), L = 2048/N = 256 (s = 112) L = 3072/N = 256 (s = 128) Mode/Method:SigVer using SHA3 OpenSSL Project OpenSSL 3.x FIPS Provider Vendor affirmed per IG C.C and IG C.B Resolution (bullet point #3) CKG - Section 4 and 5.1 Key Type :Asymmetric N/A NIST SP800-133r2 Section 4: Using the Output of a Random Bit Generator; Section 5.1: Key Pairs for Digital Signature Schemes CKG - Section 4 and 5.2 Key Type:Asymmetric N/A NIST SP800-133r2 Section 4: Using the Output of a Random Bit Generator; Section 5.2: Key Pairs for Key Establishment CKG - Section 4 and Section 6.1 Key Type:Symmetric N/A NIST SP800-133r2 Section 4: Using the Output of a Random Bit Generator; Section 6.1: Direct Generation of Symmetric Keys CKG - Section 6.2 Key Type:Symmetric N/A NIST SP 800-133r2 Section 6.2: Derivation of Symmetric keys CKG - Section 6.3 Key Type:Symmetric N/A NIST SP 800-133rev2, Section 6.3: Symmetric Keys Produced by Combining Multiple Keys and Other Data CKG – Section 4 Key Type:Symmetric N/A NIST SP800-133r2 Section 4: Using the HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider FIPS 140-3 Non-Proprietary Security Policy HP Inc. 2026 Page 20 of 92 This document may be reproduced and distributed only in its original entirety without revision. Name Properties Implementation Reference Output of a Random Bit Random bits returned to the calling application Table 6: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: Name Properties Implementation Reference AES AES (Any non-authenticated mode), (Cert.#A3548):Symmetric key unwrapping OpenSSL Project OpenSSL 3.x FIPS Provider Per IG D.G Additional Comment 5 Table 7: Non-Approved, Allowed Algorithms Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. The module does not support any Non-Approved Algorithms Allowed in the Approved Mode of Operation with No Security Claimed. Non-Approved, Not Allowed Algorithms: Name Use and Function Triple-DES Provides 3-Key ECB and CBC mode, but indicated as fips=no, Encryption, Decryption Ed448 SHAKE256, Ed448 provides 224 bits of security, Digital Signature Generation Ed25519 SHA2-512, Ed25519 provides 128 bits of security, Digital Signature Generation X448 Provides 224 bits of security, Key Agreement X25519 Provides 128 bits of security, Key Agreement ECDSA SigVer Component Provides between 80 and 256 bits for security, Curves: B-163, B-233, B-283, B-409, B-571, K-163, K-233, K-283, K-409, K-571, P-192, P- 224, P-256, P-384, P-521, Digital Signature Verification FIPS 186-2 RSA SigGen/SigVer Provides >= 80 bits of security, RSA signature generation/verification per FIPS 186-2 FIPS 186-2 RSA KeyGen Provides >= 112 bits of security, RSA key generation per FIPS 186-2 X942KDF- CONCAT Usage of X942KDF-CONCAT with PRF SHA-1, SHA2-512/224, SHA2- 512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512, SHAKE128, SHAKE256, KECCAK-KMAC128 and KECCAK-KMAC256 X963KDF Usage of X963KDF with PRF SHA-1, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512, SHAKE128, SHAKE256, KECCAK-KMAC128 and KECCAK-KMAC256 HKDF Provides < 112 bits of security, Usage of HKDF with key length less than 112 bits OneStep KDF Usage of OneStep KDF with PRF SHAKE128, SHAKE256 HMAC Provides < 112 bits of security, Usage of HMAC with key length less than 112 bits for MAC generation HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider FIPS 140-3 Non-Proprietary Security Policy HP Inc. 2026 Page 21 of 92 This document may be reproduced and distributed only in its original entirety without revision. Name Use and Function Hash and HMAC DRBG Usage of Hash and HMAC DRBGs with PRFs SHA2-224, SHA2-384, SHA2-512/224 and SHA2-512/256 Table 8: Non-Approved, Not Allowed Algorithms 2.6 Security Function Implementations Name Type Description Properties Algorithms Symmetric Encryption and Decryption BC-Auth BC-UnAuth Symmetric Encryption and Decryption Key Length:128, 192 and 256 bits Key Length (XTS):128 and 256 bits AES-CBC: (A3548) AES-CBC- CS1: (A3548) AES-CBC- CS2: (A3548) AES-CBC- CS3: (A3548) AES-CCM: (A3548) AES-CFB1: (A3548) AES-CFB128: (A3548) AES-CFB8: (A3548) AES-CMAC: (A3548) AES-CTR: (A3548) AES-ECB: (A3548) AES-GCM: (A3548) AES-GMAC: (A3548) AES-OFB: (A3548) AES-XTS Testing Revision 2.0: (A3548) Message Digest SHA Message Digest SHA-1 :(s = 160) Large Message Sizes: 1, 2, 4, 8gigabytes SHA2:SHA2-224 (s = 224), SHA2-256 (s = 256), SHA2-384 (s = 384), SHA2-512 (s = 512), SHA2-512/224 (s = 224), SHA2- SHA-1: (A3548) SHA2-224: (A3548) SHA2-256: (A3548) SHA2-384: (A3548) SHA2-512: (A3548) HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider FIPS 140-3 Non-Proprietary Security Policy HP Inc. 2026 Page 22 of 92 This document may be reproduced and distributed only in its original entirety without revision. Name Type Description Properties Algorithms 512/256 (s = 256). Large Message Sizes: 1, 2, 4, 8gigabytes SHA3:SHA3-224 (s = 224), SHA3-256 (s = 256), SHA3-384 (s = 384), SHA3-512 (s = 512). See Note 1. Large Message Sizes: 1, 2, 4, 8gigabytes SHAKE:SHAKE-128 (s = 128), SHAKE- 256 (s = 256). See Note 1. SHA2- 512/224: (A3548) SHA3-224: (A3548) SHA3-256: (A3548) SHA3-384: (A3548) SHA3-512: (A3548) SHAKE-128: (A3548) SHAKE-256: (A3548) SHA2- 512/256: (A3548) Keyed Hash BC-Auth MAC Keyed Hash HMAC-SHA-1 [FIPS198-1]:SHA-1 (s = 160) HMAC-SHA2 [FIPS198-1]:SHA2- 224 (s = 224), SHA2- 256 (s = 256), SHA2- 384 (s = 384), SHA2- 512 (s = 512), SHA2- 512/224 (s = 224), SHA2-512/256 (s = 256) HMAC-SHA3 [FIPS198-1]:SHA3- 224 (s = 224), SHA3- 256 (s = 256), SHA3- 384 (s = 384), SHA3- 512 (s = 512) KMAC:KMAC-128 (112 ≤ s ≤ 128), KMAC-256 (112 ≤ s ≤ 256). See Note 8. HMAC-SHA-1: (A3548) HMAC-SHA2- 224: (A3548) HMAC-SHA2- 256: (A3548) HMAC-SHA2- 384: (A3548) HMAC-SHA2- 512: (A3548) HMAC-SHA2- 512/224: (A3548) HMAC-SHA2- 512/256: (A3548) HMAC-SHA3- 224: (A3548) HMAC-SHA3- 256: (A3548) HMAC-SHA3- 384: (A3548) HMAC-SHA3- 512: (A3548) AES-CMAC: (A3548) KMAC-128: (A3548) KMAC-256: (A3548) AES-GMAC: (A3548) HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider FIPS 140-3 Non-Proprietary Security Policy HP Inc. 2026 Page 23 of 92 This document may be reproduced and distributed only in its original entirety without revision. Name Type Description Properties Algorithms RSA Digital Signature Generation and Verification DigSig- SigGen DigSig-SigVer RSA Digital Signature Generation and Verification Signature type: ANSI X9.31 tested with the listed moduli and the following hash algorithms: SHA2- 256, SHA2-384, SHA2-512:k=2048 (s ~= 112), k=3072 (s ~= 128), k=4096 (s ~= 152) Signature type: PKCS 1.5 tested with the listed moduli and the following hash algorithms: SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2- 512/256:k=2048 (s ~= 112), k=3072 (s ~= 128), k=4096 (s ~= 152) Signature type: PKCSPSS tested with the listed moduli and the following hash algorithms: SHA2- 224, SHA2- 256, SHA2-384, SHA2- 512, SHA2- 512/224, SHA2- 512/256:k=2048 (s ~= 112), k=3072 (s ~= 128), k=4096 (s ~= 152) Signature type: ANSI X9.31 tested with the listed moduli and the following hash algorithms: SHA-1*, SHA2-256, SHA2- 384, SHA2- 512:k=1024 (s ≤ 112), k=2048 (s ~= 112), k=3072 (s ~= 128), k=4096 (s ~= 152) Signature type: PKCS 1.5 tested RSA SigGen (FIPS186-4): (A3548) RSA SigVer (FIPS186-4): (A3548) HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider FIPS 140-3 Non-Proprietary Security Policy HP Inc. 2026 Page 24 of 92 This document may be reproduced and distributed only in its original entirety without revision. Name Type Description Properties Algorithms with the listed moduli and the following hash algorithms: SHA-1*, SHA2-224, SHA2-256, SHA2- 384, SHA2-512, SHA2-512/224, SHA2- 512/256:k=1024 (s ≤ 112), k=2048 (s ~= 112), k=3072 (s ~= 128), k=4096 (s ~= 152) Signature type: PKCSPSS tested with the listed moduli and the following hash algorithms: SHA-1*, SHA2-224, SHA2-256, SHA2- 384, SHA2-512, SHA2-512/224, SHA2- 512/256:k=1024 (s ≤ 112), k=2048 (s ~= 112), k=3072 (s ~= 128), k=4096 (s ~= 152) ECDSA Signature Generation and Signature Verification DigSig- SigGen DigSig-SigVer ECDSA Signature Generation and Signature Verification SigGen (includes SigGen Component) (tested with SHA2- 224, SHA2-256, SHA2-384, SHA2- 512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3- 256, SHA3-384, SHA3-512):B-233, K- 233, P-224 (s ~= 112); B-283, K-283, P-256 (s ~= 128); B- 409, K-409, P-384 (s ~= 192); B-571, K- 571, P-521 (s ~= 256) SigVer (tested with SHA-1*, SHA2-224, SHA2-256, SHA2- 384, SHA2-512, SHA2-512/224, ECDSA SigGen (FIPS186-4): (A3548) ECDSA SigVer (FIPS186-4): (A3548) HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider FIPS 140-3 Non-Proprietary Security Policy HP Inc. 2026 Page 25 of 92 This document may be reproduced and distributed only in its original entirety without revision. Name Type Description Properties Algorithms SHA2-512/256, SHA3-224, SHA3- 256, SHA3-384, SHA3-512):B-163, K- 163, P-192 (s < 112); B-233, K-233, P-224 (s ~= 112); B-283, K- 283, P-256 (s ~= 128); B-409, K-409, P-384 (s ~= 192); B- 571, K-571, P-521 (s ~= 256) DSA Digital Signature Generation and Verification DigSig- SigGen DigSig-SigVer DSA Digital Signature Generation and Verification SigGen (tested with SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2- 512/256); SigGen using SHA3; no ACVP testing is available:L = 2048/N = 224 (s = 112), L = 2048/N = 256 (s = 112) L = 3072/N = 256 (s = 128) SigVer (tested with SHA-1, SHA2-224, SHA2-256, SHA2- 384, SHA2-512, SHA2-512/224, SHA2-512/256); SigVer using SHA3; no ACVP testing is available:L = 1024/N = 160 (s < 112) L = 2048/N = 224 (s = 112), L = 2048/N = 256 (s = 112) L = 3072/N = 256 (s = 128) DSA SigGen (FIPS186-4): (A3548) DSA SigVer (FIPS186-4): (A3548) DSA SigGen [FIPS 186-4]: () Key Size, Key Strength: L = 2048/N = 224 (s = 112), L = 2048/N = 256 (s = 112) L = 3072/N = 256 (s = 128) Mode/Method: SigGen using SHA3 DSA SigVer [FIPS186-4]: () Key Size, Key Strength: L = 1024/N = 160 (s < 112) L = 2048/N = 224 (s = 112), L = 2048/N = 256 (s = 112) L = 3072/N = 256 (s = 128) Mode/Method: SigVer using SHA3 RSA Signature Primitive DigSig- SigGen Signature primitive Private Key format:CRT Public Exponent RSA Signature HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider FIPS 140-3 Non-Proprietary Security Policy HP Inc. 2026 Page 26 of 92 This document may be reproduced and distributed only in its original entirety without revision. Name Type Description Properties Algorithms Mode:Fixed : k = 2048 Primitive: (A3548) Asymmetric Key Pair Generation AsymKeyPair- KeyGen AsymKeyPair- KeyVer Generation of asymmetric key pairs RSA KeyGen:k=2048 (s ~= 112), k=3072 (s ~= 128), k=4096 (s ~= 152) DSA KeyGen:L = 2048/N = 224 (s = 112), L = 2048/N = 256 (s = 112) L = 3072/N = 256 (s = 128) ECDSA KeyGen: Secret Generation Mode: Testing Candidates:B-233, K- 233, P-224 (s ~= 112); B-283, K-283, P-256 (s ~= 128); B- 409, K-409, P-384 (s ~= 192); B-571, K- 571, P-521 (s ~= 256) Safe Primes Key Generation, Safe Primes Key Verification:ffdhe2048 (s = 112), ffdhe3072 (112 ≤ s ≤ 128), ffdhe4096 (112 ≤ s ≤ 152), ffdhe6144 (112 ≤ s ≤ 176), ffdhe8192 (112 ≤ s ≤ 200), MODP-2048 (s = 112), MODP-3072 (112 ≤ s ≤ 128), MODP-4096 (112 ≤ s ≤ 152), MODP-6144 (112 ≤ s ≤ 176), MODP-8192 (112 ≤ s ≤ 200) ECDSA KeyVer:B- 163, K-163, P-192 (s < 112); B-233, K-233, P-224 (s ~= 112); B- 283, K-283, P-256 (s ~= 128); B-409, K- 409, P-384 (s ~= 192); B-571, K-571, P-521 (s ~= 256) RSA KeyGen (FIPS186-4): (A3548) DSA KeyGen (FIPS186-4): (A3548) ECDSA KeyGen (FIPS186-4): (A3548) Safe Primes Key Generation: (A3548) ECDSA KeyVer (FIPS186-4): (A3548) Safe Primes Key Verification: (A3548) CKG - Section 4 and 5.1: () Key Type : Asymmetric CKG - Section 4 and 5.2: () Key Type: Asymmetric DSA PQGGen (FIPS186-4): (A3548) DSA PQGVer (FIPS186-4): (A3548) DSA PQGGen [FIPS 186-4]: () Key Size, Key Strength: L = 2048/N = 224 (s = 112), L = 2048/N = 256 (s = 112) L = 3072/N = 256 (s = 128) Mode/Method: HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider FIPS 140-3 Non-Proprietary Security Policy HP Inc. 2026 Page 27 of 92 This document may be reproduced and distributed only in its original entirety without revision. Name Type Description Properties Algorithms DSA PQGGen (FIPS186-4), DSA PQGGen [FIPS 186- 4] (VA):L = 2048/N = 224 (s = 112), L = 2048/N = 256 (s = 112) L = 3072/N = 256 (s = 128) DSA PQGVer (FIPS186-4), DSA PQGVer [FIPS 186-4] (VA):L = 1024/N = 160 (s < 112) L = 2048/N = 224 (s = 112), L = 2048/N = 256 (s = 112) L = 3072/N = 256 (s = 128) PQGGen using SHA3 DSA PQGVer [FIPS 186-4]: () Key Size, Key Strength: L = 1024/N = 160 (s < 112) L = 2048/N = 224 (s = 112), L = 2048/N = 256 (s = 112) L = 3072/N = 256 (s = 128) Mode/Method: PQGVer using SHA3 Random Number Generation DRBG Random Number Generation - Hash_DRBG, CTR_DRBG and HMAC_DRBG Counter DRBG [SP800-90Ar1]:AES- 128 (s = 128), AES- 192 (s = 192), AES- 256 (s = 256) Hash DRBG [SP800- 90Ar1]:SHA-1 (s = 160), SHA2-256 (s = 256), SHA2-512 (s = 512) SHA3-256 (s = 256), SHA3-512 (s = 512) HMAC DRBG [SP800-90Ar1]:SHA- 1 (s = 160), SHA2- 256 (s = 256), SHA2- 512 (s = 512) SHA3- 256 (s = 256), SHA3- 512 (s = 512) Counter DRBG: (A3548) Hash DRBG: (A3548) HMAC DRBG: (A3548) CKG – Section 4: () Key Type: Symmetric Key Derivation KBKDF PBKDF Derive Keying Material KDA HKDF:SHA-1 (s = 160), SHA2-224 (s = 224), SHA2-256 (s = 256), SHA2-384 (s = 384), SHA2-512 (s = 512), SHA2- 512/224 (s = 224), SHA2-512/256 (s = 256), SHA3-224 (s = 224), SHA3-256 (s = 256), SHA3-384 (s = 384), SHA3-512 (s = 512) KDA HKDF SP800-56Cr2: (A3548) KDA OneStep SP800-56Cr2: (A3548) KDA TwoStep SP800-56Cr2: (A3548) KDF ANS 9.42: (A3548) KDF ANS 9.63: (A3548) HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider FIPS 140-3 Non-Proprietary Security Policy HP Inc. 2026 Page 28 of 92 This document may be reproduced and distributed only in its original entirety without revision. Name Type Description Properties Algorithms KDA OneStep:SHA-1 (s = 160), SHA2-224 (s = 224), SHA2-256 (s = 256), SHA2-384 (s = 384), SHA2-512 (s = 512), SHA2- 512/224 (s = 224), SHA2-512/256 (s = 256), SHA3-224 (s = 224), SHA3-256 (s = 256), SHA3-384 (s = 384), SHA3-512 (s = 512); HMAC-SHA-1 (s = 160), HMAC- SHA2-224 (s = 224), HMAC-SHA2-256 (s = 256), HMAC-SHA2- 384 (s = 384), HMAC-SHA2-512 (s = 512), HMAC-SHA2- 512/224 (s = 224), HMAC-SHA2- 512/256 (s = 256), HMAC-SHA3-224 (s = 224), HMAC-SHA3- 256 (s = 256), HMAC-SHA3-384 (s = 384), HMAC-SHA3- 512 (s = 512); KMAC-128 (112 ≤ s ≤ 128), KMAC-256 (112 ≤ s ≤ 256) KDA TwoStep [SP800- 56Cr2]:HMAC-SHA-1 (s = 160), HMAC- SHA2-224 (s = 224), HMAC-SHA2-256 (s = 256), HMAC-SHA2- 384 (s = 384), HMAC-SHA2-512 (s = 512), HMAC-SHA2- 512/224 (s = 224), HMAC-SHA2- 512/256 (s = 256), HMAC-SHA3-224 (s = 224), HMAC-SHA3- 256 (s = 256), HMAC-SHA3-384 (s = 384), HMAC-SHA3- KDF KMAC Sp800-108r1: (A3548) KDF SP800- 108: (A3548) KDF SSH: (A3548) PBKDF: (A3548) TLS v1.2 KDF RFC7627: (A3548) TLS v1.3 KDF: (A3548) CKG - Section 6.2: () Key Type: Symmetric HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider FIPS 140-3 Non-Proprietary Security Policy HP Inc. 2026 Page 29 of 92 This document may be reproduced and distributed only in its original entirety without revision. Name Type Description Properties Algorithms 512 (s = 512) KDF ANS 9.42 [SP800-135r1]:SHA-1 (s = 160), SHA2-224 (s = 224), SHA2-256 (s = 256), SHA2-384 (s = 384), SHA2-512 (s = 512), SHA2- 512/224 (s = 224), SHA2-512/256 (s = 256), SHA3-224 (s = 224), SHA3-256 (s = 256), SHA3-384 (s = 384), SHA3-512 (s = 512) KDF ANS 9.63 [SP800-135r1]:SHA2- 224 (s = 224), SHA2- 256 (s = 256), SHA2- 384 (s = 384), SHA2- 512 (s = 512) KDF KMAC [SP800- 108r1]:KMAC-128 (112 ≤ s ≤ 128), KMAC-256 (112 ≤ s ≤ 256) KDF [SP800- 108r1]:CMAC- AES128 (s = 128), CMAC-AES192 (s = 192), CMAC-AES256 (s = 256), HMAC- SHA-1 (s = 160), HMAC-SHA2-224 (s = 224), HMAC-SHA2- 256 (s = 256), HMAC-SHA2-384 (s = 384), HMAC-SHA2- 512 (s = 512), HMAC-SHA2- 512/224 (s = 224), HMAC-SHA2- 512/256 (s = 256), HMAC-SHA3-224 (s = 224), HMAC-SHA3- 256 (s = 256), HMAC-SHA3-384 (s = 384), HMAC-SHA3- 512 (s = 512) KDF SSH [SP800- HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider FIPS 140-3 Non-Proprietary Security Policy HP Inc. 2026 Page 30 of 92 This document may be reproduced and distributed only in its original entirety without revision. Name Type Description Properties Algorithms 135r1]:AES-128 (s = 128), AES-192 (s = 192), AES-256 (s = 256); SHA-1 (s = 160), SHA2-224 (s = 224), SHA2-256 (s = 256), SHA2-384 (s = 384), SHA2-512 (s = 512) PBKDF [SP800- 132]:SHA-1 (s = 160), SHA2-224 (s = 224), SHA2-256 (s = 256), SHA2-384 (s = 384), SHA2-512 (s = 512), SHA2-512/224 (s = 224), SHA2- 512/256 (s = 256), SHA3-224 (s = 224), SHA3-256 (s = 256), SHA3-384 (s = 384), SHA3-512 (s = 512) TLS v1.2 KDF RFC7627: TLS [RFC7627] key derivation with Extended Master Secret (EMS) support, using the listed hash algorithms:SHA2-256 (s = 256), SHA2-384 (s = 384), SHA2-512 (s = 512) TLS v1.3 KDF [RFC8446]:HMAC- SHA2-256 (s = 256), HMAC-SHA2-384 (s = 384) KAS-1 KAS-SSC Scheme: EphemeralUnified, KAS Role: Initiator, Responder SP800-56Ar3 KAS- ECC-SSC per IG D.F Scenario 2 path (1):B-233, K-233, P- 224, B-283, K-283, P- 256, B-409, K-409, P- 384, B-571, K-571, and P-521 curves providing 112, 128, 192, or 256 bits of encryption strength KAS-ECC- SSC Sp800- 56Ar3: (A3548) HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider FIPS 140-3 Non-Proprietary Security Policy HP Inc. 2026 Page 31 of 92 This document may be reproduced and distributed only in its original entirety without revision. Name Type Description Properties Algorithms KAS-2 KAS-SSC Scheme: dhEphem. KAS Role: Initiator, Responder SP800-56Ar3 KAS- FFC-SSC IG D.F Scenario 2 path (1):2048, 3072, 4096, 6144, and 8192-bit key providing 112, 128, 152, 176, or 200 bits of encryption strength KAS-FFC- SSC Sp800- 56Ar3: (A3548) KAS-3 KAS-SSC Scheme: KAS1, KAS2. KAS Role: Initiator, Responder SP800-56Br2 KAS- IFC-SSC IG D.F Scenario 1 path (1):2048, 3072, 4096, 6144, and 8192-bit key providing 112, 128, 152, 176, or 200 bits of encryption strength KAS-IFC- SSC: (A3548) KTS-1 KTS-Wrap Key Transport in compliance with [SP800- 38F] when approved using AES KW or KWP SP 800-38F KTS (key wrapping) per IG D.G :128, 192, and 256-bit keys providing 128, 192, or 256 bits of encryption strength AES-KW: (A3548) AES-KWP: (A3548) KTS-2 KTS-Wrap Key Transport in compliance with [SP800- 38F] when approved AES (any mode) and approved HMAC, KMAC, GMAC or CMAC are used in combination SP 800-38F KTS (key wrapping) per IG D.G : 128, 192, and 256-bit keys providing 128, 192, or 256 bits of encryption strength AES-CBC: (A3548) AES-CFB1: (A3548) AES-CFB128: (A3548) AES-CFB8: (A3548) AES-CTR: (A3548) AES-ECB: (A3548) AES-OFB: (A3548) AES-XTS Testing Revision 2.0: (A3548) AES-CBC- CS2: (A3548) AES-CBC- CS3: (A3548) AES-CCM: (A3548) HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider FIPS 140-3 Non-Proprietary Security Policy HP Inc. 2026 Page 32 of 92 This document may be reproduced and distributed only in its original entirety without revision. Name Type Description Properties Algorithms AES-CMAC: (A3548) AES-GCM: (A3548) AES-GMAC: (A3548) AES-KW: (A3548) AES-KWP: (A3548) HMAC-SHA-1: (A3548) HMAC-SHA2- 224: (A3548) HMAC-SHA2- 256: (A3548) HMAC-SHA2- 384: (A3548) HMAC-SHA2- 512: (A3548) HMAC-SHA2- 512/224: (A3548) HMAC-SHA2- 512/256: (A3548) HMAC-SHA3- 224: (A3548) HMAC-SHA3- 256: (A3548) HMAC-SHA3- 384: (A3548) HMAC-SHA3- 512: (A3548) KMAC-128: (A3548) KMAC-256: (A3548) AES-CBC- CS1: (A3548) KTS-3 KTS-Wrap Key Transport in compliance with [SP800- 38F] when approved using an Authenticated AES mode (AES CCM; AES GCM; AES GMAC; AES CMAC) SP 800-38F KTS (key wrapping) per IG D.G : 128, 192, and 256-bit keys providing 128, 192, or 256 bits of encryption strength AES-CCM: (A3548) AES-CMAC: (A3548) AES-GCM: (A3548) AES-GMAC: (A3548) HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider FIPS 140-3 Non-Proprietary Security Policy HP Inc. 2026 Page 33 of 92 This document may be reproduced and distributed only in its original entirety without revision. Name Type Description Properties Algorithms KTS-4 KTS-Encap Key Transport; Scheme: KTS- OAEP-basic (no key confirmation): RSA-OAEP, Key Encapsulation, Key Unencapsulation Key Generation Methods: rsakpg1-basic, rsakpg1-crt, rsakpg1-prime- factor, rsakpg2- basic, rsakpg2-crt, rsakpg2- prime- factor SP 800-56Brev2 KTS-IFC (key encapsulation and un-encapsulation) per IG D.G:2048, 3072, 4096, and 6144-bit key providing 112, 128, 152, or 176 bits of encryption strength KTS-IFC: (A3548) KAS ECC CDH Component KAS-SSC KAS-ECC-SSC primitive Curves:B-233, K-233, P-224 (s ~= 112); B- 283, K-283, P-256 (s ~= 128); B-409, K- 409, P-384 (s ~= 192); B-571, K-571, P-521 (s ~= 256). KAS-ECC CDH- Component SP800-56Ar3: (A3548) Perform self- tests (All) BC-Auth BC-UnAuth DigSig- SigGen DigSig-SigVer DRBG KAS-SSC KBKDF MAC PBKDF SHA XOF All self-tests executed by the module at boot AES-ECB: (A3548) AES-GCM: (A3548) Hash DRBG: (A3548) Counter DRBG: (A3548) HMAC DRBG: (A3548) DSA SigGen (FIPS186-4): (A3548) DSA SigVer (FIPS186-4): (A3548) ECDSA SigGen (FIPS186-4): (A3548) ECDSA SigVer (FIPS186-4): (A3548) RSA SigGen HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider FIPS 140-3 Non-Proprietary Security Policy HP Inc. 2026 Page 34 of 92 This document may be reproduced and distributed only in its original entirety without revision. Name Type Description Properties Algorithms (FIPS186-4): (A3548) RSA SigVer (FIPS186-4): (A3548) HMAC-SHA2- 256: (A3548) SHA-1: (A3548) SHA3-256: (A3548) SHA2-512: (A3548) KDF ANS 9.42: (A3548) KDF ANS 9.63: (A3548) KAS-ECC- SSC Sp800- 56Ar3: (A3548) KAS-FFC- SSC Sp800- 56Ar3: (A3548) KAS-IFC- SSC: (A3548) KDA OneStep SP800-56Cr2: (A3548) KDA TwoStep SP800-56Cr2: (A3548) KDF SSH: (A3548) KDF SP800- 108: (A3548) PBKDF: (A3548) TLS v1.2 KDF RFC7627: (A3548) TLS v1.3 KDF: (A3548) Cryptographic Key Generation (CKG) CKG Direct generation of symmetric keys per NIST SP 800- 133r2 CKG - Section 4 and Section 6.1: () Software Integrity Test MAC HMAC-SHA2-256 used to perform Key size: 256 bits HMAC-SHA2- 256: (A3548) HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider FIPS 140-3 Non-Proprietary Security Policy HP Inc. 2026 Page 35 of 92 This document may be reproduced and distributed only in its original entirety without revision. Name Type Description Properties Algorithms the software integrity test Cryptographic Key Generation (CKG) - AES XTS CKG AES XTS Key generated to comply with the approved key generation guidelines of NIST SP 800-133rev2, Section 6.3, Symmetric Keys Produced by Combining Multiple Keys and Other Data Key size:128, 256 bits CKG - Section 6.3: () KTS-5 KTS-Unwrap Key Unwrapping using any non- authenticated AES mode KTS (key unwrapping) per IG D.G:128, 192, and 256-bit keys providing 128, 192, or 256 bits of decryption strength AES-CBC: (A3548) AES-CFB1: (A3548) AES-CFB128: (A3548) AES-CFB8: (A3548) AES-CTR: (A3548) AES-ECB: (A3548) AES-OFB: (A3548) AES-CBC- CS1: (A3548) AES-CBC- CS2: (A3548) AES-CBC- CS3: (A3548) Table 9: Security Function Implementations Equivalent strength in bits is given for each key or algorithm type (as some algorithms do not use or produce keys). The term s is used throughout to indicate security strength, following the notation used in the majority of the sources. Note 1: Preimage resistance strength applies to hash algorithms used in DRBG, KDFs. Described also in [SP800- 57P1r5] Table 3. Note 2: Elliptic curve strengths are annotated as approximate (i.e., s ~=) since [SP800-186] Table 1 provides approximate security strengths. Note 3: [SP800-186] (cited in [SP800-140Cr2]) and [FIPS140-3_IG] C.K indicate that the Binary (B-) and Koblitz (K-) curves are deprecated. Note 4: Approved elliptic curves for ECC key agreement are given in [SP800-56Ar3] Table 24. HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider FIPS 140-3 Non-Proprietary Security Policy HP Inc. 2026 Page 36 of 92 This document may be reproduced and distributed only in its original entirety without revision. Note 5: In Digital Signature applications, security strength is primarily associated with the asymmetric key pair specification. The hash function used must have equivalent strength equal to or greater than the security strength of the associated key pair. Note 6: Approved key types for FFC key agreement are given in [SP800-56Ar3] Tables 25, 26. The group notation of Table 26 is used for consistency with CAVP algorithm listings and ACVP capability registration. Note 7: Approved key types for IFC key agreement are given in [SP800-56Br2] Table 4. IFC key types approved for Digital Signature Generation and Verification are given also in [SP800-57P1r5] Table 2. Equivalent strengths are annotated as approximate (i.e., s ~=) since [SP800-56Br2] Table 4 provides approximate security strengths. Note 8: Security strengths for KDA One Step are given in [SP800-56Cr2] Table 1 (hash), Table 2 (HMAC) and Table 3 (KMAC). Note 9: Security strength for L=2048/N=256 is determined in accordance with [FIPS140-3_IG] D.B Strength of SSP Establishment Methods as y = min(x, N/2), where x is 112 and therefore y = min(112, 128) = 112. Other reference sources for the strengths are as follows: • AES (AES-128, AES-192, AES-256): [SP800-57P1r5] Table 2. • ECC (B-163, B-233, B-283, B-409, B-571, K-163, K-233, K-283, K-409, K-571, P-192, P-224, P-256, P-384, P-521): [SP800-186] Table 1. • FFC (L=1024/N=160, L=2048/N=224, L=2048/N=256, L=3072/N=256): [SP800-57P1r5] Table 2. • FFC (ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP- 6144, MODP-8192): [SP800-56Ar3] Tables 25 and 26. • IFC (k=1024, k=2048, k=3072, k=4096, k=6144, k=8192): [SP800-56Br2] Table 4. • KMAC (KMAC128, KMAC256): [SP800-56Cr2] Table 3. • SHA-1, SHA2 (SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256): [SP800-107] Table 1. • SHA3 (SHA3-224, SHA3-256, SHA3-384, SHA3-512): [SP800-57P1r5] Table 3. • SHAKE (SHAKE128, SHAKE256): [SP800-185] Section 8.1. 2.7 Algorithm Specific Information a. AES-GCM Usage AES GCM IV generation must be compliant to [FIPS140-3_IG] C.H Key/IV Pair Uniqueness Requirements from SP 800-38D Scenario 1(a), tested per option (ii) under C.H TLS/DTLS 1.2 protocol IV generation per RFC7627, Scenario 1(d) SSHv2 per RFC4252, RFC4253 and RFC5647 and Scenario 5 TLS 1.3 per RFC8446. IV constructed in compliance with a protocol shall only be used in the context of the AES-GCM mode encryptions within the protocol. The Module does not implement the TLS and SSH protocols itself, however, it provides the cryptographic functions required for implementing the protocols. AES GCM encryption is used in the context of the SSH and TLS protocol versions 1.2 and 1.3. The module provides the primitives to support the AES GCM ciphersuites from [SP800-52r1] Section 3.3.1. The module’s implementation of AES-GCM is used together with an application that runs outside the module’s cryptographic boundary. The application negotiates the protocol session’s keys and the 32-bit nonce value of the IV. When the IV exhausts the maximum number of possible values for a given session key (2^64 - 1), this results in a failure in encryption and a handshake to establish a new encryption key will be required. It is the responsibility of the user of the module, i.e., the first party, client or server, to encounter this condition, to trigger this handshake in accordance with the TLS/SSH protocol. The Module also supports internal IV generation using the module’s approved DRBG. The IV is at least 96 bits in length per [SP800-38D] Section 8.2.2. Per [FIPS140-3_IG] C.H Scenario 2 and [SP800-38D], the approved DRBG generates outputs such that the (key, IV) pair collision probability is less than 2^-32. In each case, in the event that the Module power is lost and restored the user must ensure that the AES GCM encryption/decryption keys are re-distributed in accordance with IG C.H Scenario 3. The module does not support persistent storage of SSPs. HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider FIPS 140-3 Non-Proprietary Security Policy HP Inc. 2026 Page 37 of 92 This document may be reproduced and distributed only in its original entirety without revision. The Module also supports importing of GCM IVs when an IV is not generated within the Module. In the approved mode, an IV must not be imported for encryption from outside the cryptographic boundary of the Module as this will result in a non-conformance. This is in accordance with IG 2.4.A: If the module operator (e.g., calling application) can do things outside of the module’s control/visibility that can take an otherwise approved algorithm and use it in a non-approved way (e.g., use PBKDF and/or AES XTS outside of storage applications), the corresponding module service may still be considered approved (and if so, shall have an approved indicator per AS02.24) and the Security Policy shall clarify how to use the service in an approved manner (per ISO 19790 B.2.2 on Overall security design and the rules of operation). b. PBKDF Usage The lower limit on the supported length of a password/passphrase used in key derivation is 1-character. The ASCII system comprises of 94 printable characters (letters, digits, punctuation, and symbols). For a 1- character password/passphrase chosen from 94 printable ASCII characters, the total combinations are: 94^1. Thus, the probability of guessing the correct password/passphrase on a random attempt is: 1/94^1 ~0.010. The module being a software module, does not restrict the usage of a password/string used as the password and input to the PBKDF. The onus is on the calling application to provide a password of an appropriate length based on the intended security strength (and size) of the key to be derived. In accordance with NIST SP 800-132, passwords shorter than 10 characters are usually considered to be weak. There are many other properties that may render a password weak. For example, it is not advisable to use sequences of numbers or sequences of letters as passwords. Easily accessed personal information, such as the user’s name, phone number, and date of birth, should not be used directly as a password. Passphrases frequently consist solely of letters, but they make up for their lack of entropy by being much longer than passwords, typically 20 to 30 characters. Passphrases shorter than 20 characters are usually considered weak. The module complies with NIST SP 800-132 Section 5.4 Option 1 a and IG D.N. The iteration count values used range from 1 to 10000 per NIST SP 800-132 Section 5.2 whereby the iteration count shall be selected as large as possible, as long as the time required to generate the key using the entered password is acceptable for the users. Keys derived from passwords, as shown in SP 800-132, may only be used in storage applications. The security strength of the derived key is at least 112 bits. The module implements CKG per NIST SP 800-133r2 Section 6.2.2. c. AES-XTS Usage Usage In accordance with [SP800-38E], the XTS-AES algorithm shall only be used for confidentiality on storage devices. The Module complies with [FIPS140-3_IG] C.I by explicitly checking that Key_1 ≠ Key_2 before using the keys in the XTS-AES algorithm to process data with them. The module implements CKG per NIST SP 800-133r2 Section 6.3. d. Legacy Usage The module supports the following implementations for legacy use/support per NIST SP 800-131Ar2:  RSA (modulus 1024 bits), DSA (modulus 1024 bits), ECDSA (B-163, K-163 and P-192, curves) digital signature verification providing less than 112 bits of security strength.  RSA, ECDSA and DSA digital signature verification with SHA-1 used as the underlying hash algorithm. HP Inc. OpenSSL FIPS Provider based on the OpenSSL FIPS Provider FIPS 140-3 Non-Proprietary Security Policy HP Inc. 2026 Page 38 of 92 This document may be reproduced and distributed only in its original entirety without revision. e. Component Validation List (CVL) In accordance with IG 2.4.B, all tested components that may be called during the operation of the module and shown in the module’s CVL certificates have been listed individually in Table 5. All vendor affirmed components that may be called during the operation of the module have also been listed individually in Table 6 per IG 2.4.B. f. FIPS 202 Usage In accordance with IG C.C Resolution 2. a., each SHA-3 and SHAKE function has been tested and validated on all of the module’s operating environments. Per Resolution 2. c., SHA-3 hash functions used as part of the higher-level DRBG algorithms for which the CAVP testing is not yet available have been vendor affirmed as documented in Table 6. g. RSA Usage  Per IG C.E, the module generates RSA signature keys using an approved key generation procedure per RSA KeyGen validated for conformance to FIPS 186-4 Cert. #A3548.  Per IG C.F, the RSA SigGen and SigVer implementations have been tested for all implemented RSA modulus lengths where CAVP testing is available. The module supports generation of RSA keys with the following untested approved moduli/sizes: 4096