SUSE Linux Enterprise OpenSSL 3 Cryptographic Module

Known vulnerabilities detected

Our automated heuristics have identified vulnerabilities that may be associated with this certificate. See the CVEs section for details.

Certificate details

Certificate ID #5096
Status active
Validation dates 26.11.2025 , 02.03.2026 , 17.08.2026
Sunset date 25-11-2030
Standard FIPS 140-3
Security level 1
Type Software
Embodiment Multi-Chip Stand Alone
Caveat When operated in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.
Exceptions
  • Physical security: N/A
  • Non-invasive security: N/A
Description SUSE Linux Enterprise Server 15 SP6 OpenSSL FIPS provider implementation providing cryptographic services to Linux user space software components. The module was tested with 64-bit word size.
Vendor SUSE LLC http://www.suse.com
Lab atsec information security corporation
Algorithms
  • AES-CBC-CS1A5658
  • AES-CBC-CS2A5658
  • AES-CBC-CS3A5658
  • AES-CBCA5658
  • AES-CCMA5658
  • AES-CFB128A5658
  • AES-CFB1A5658
  • AES-CFB8A5658
  • AES-CMACA5658
  • AES-CTRA5658
  • AES-ECBA5900
  • AES-GCMA5905
  • AES-GMACA5905
  • AES-KWA5658
  • AES-KWPA5658
  • AES-OFBA5658
  • AES-XTS Testing Revision 2.0A5658
  • Counter DRBGA5397
  • ECDSA KeyGen (FIPS186-5)A5889
  • ECDSA KeyVer (FIPS186-5)A5889
  • ECDSA SigGen (FIPS186-5)A5889
  • ECDSA SigVer (FIPS186-5)A5889
  • Hash DRBGA5397
  • HMAC DRBGA5397
  • HMAC-SHA-1A5889
  • HMAC-SHA2-224A5889
  • HMAC-SHA2-256A5889
  • HMAC-SHA2-384A5889
  • HMAC-SHA2-512/224A5889
  • HMAC-SHA2-512/256A5889
  • HMAC-SHA2-512A5889
  • HMAC-SHA3-224A5885
  • HMAC-SHA3-256A5885
  • HMAC-SHA3-384A5885
  • HMAC-SHA3-512A5885
  • KAS-ECC-SSC Sp800-56Ar3A5889
  • KAS-FFC-SSC Sp800-56Ar3A5898
  • KAS-IFC-SSCA5889
  • KDA HKDF SP800-56Cr2A5863
  • KDA OneStep SP800-56Cr2A5897
  • KDA TwoStep SP800-56Cr2A5897
  • KDF ANS 9.42A5889
  • KDF ANS 9.63A5889
  • KDF SP800-108A5899
  • KDF SSHA5900
  • KTS-IFCA5889
  • PBKDFA5889
  • RSA KeyGen (FIPS186-5)A5889
  • RSA SigGen (FIPS186-5)A5889
  • RSA SigVer (FIPS186-2)A5889
  • RSA SigVer (FIPS186-4)A5889
  • RSA SigVer (FIPS186-5)A5889
  • Safe Primes Key GenerationA5898
  • Safe Primes Key VerificationA5898
  • SHA-1A5889
  • SHA2-224A5889
  • SHA2-256A5889
  • SHA2-384A5889
  • SHA2-512/224A5889
  • SHA2-512/256A5889
  • SHA2-512A5889
  • SHA3-224A5885
  • SHA3-256A5885
  • SHA3-384A5885
  • SHA3-512A5885
  • SHAKE-128A5885
  • SHAKE-256A5885
  • TLS v1.2 KDF RFC7627A5889
  • TLS v1.3 KDFA5863
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Extracted keywords

Symmetric Algorithms
AES, AES-128, AES-192, AES-256, AES-, CAST, HMAC, CMAC
Asymmetric Algorithms
RSA-PSS, ECDH, ECDSA, EdDSA, ECC, DHE, DH, Diffie-Hellman
Hash functions
SHA-1, SHA-224, SHA-512, SHA-256, SHA-384, SHA-3, SHA3-224, SHA3-256, SHA3-512, SHA3-384, SHAKE128, SHAKE256, PBKDF2, PBKDF
Schemes
MAC, Key Exchange, Key Agreement
Protocols
SSH, TLS v1.2, TLS v1.3, TLS 1.2, TLS, TLS 1.3, IKE
Randomness
DRBG, RNG, RBG
Libraries
OpenSSL
Elliptic Curves
P-224, P-256, P-384, P-521
Block cipher modes
ECB, CBC, CTR, CFB, OFB, GCM, CCM, XTS

Trusted Execution Environments
PSP, SSC

Security level
Level 1
Side-channel analysis
side-channel, timing attacks

Automated analysis

Automated inference - use with caution

All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.

CVE matches

ID Links Severity CVSS Score Published on
Base score
CVE-2000-0218
C N
HIGH 7.2 03.02.2000
CVE-2000-0361
C N
LOW 2.1 14.12.1999
CVE-2004-1184
C N
MEDIUM 4.6 21.01.2005
CVE-2004-1191
C N
LOW 1.2 10.01.2005
CVE-2004-1491
C N
MEDIUM 5.0 31.12.2004
CVE-2005-0206
C N
HIGH 7.5 27.04.2005
CVE-2005-0638
C N
HIGH 7.5 02.03.2005
CVE-2005-0639
C N
HIGH 7.5 02.03.2005
CVE-2005-1043
C N
MEDIUM 5.0 14.04.2005
CVE-2005-3146
C N
LOW 2.1 05.10.2005
CVE-2005-3147
C N
LOW 2.1 05.10.2005
CVE-2005-3148
C N
MEDIUM 4.6 05.10.2005
CVE-2007-0460
C N
HIGH 10.0 24.01.2007
CVE-2007-4074
C N
HIGH 10.0 30.07.2007
CVE-2007-4393
C N
MEDIUM 4.6 17.08.2007
CVE-2007-6167
C N
HIGH 7.2 29.11.2007
CVE-2008-3949
C N
HIGH 7.2 22.09.2008
Showing 5 out of 17.

Cross-references

Loading...

Processing updates

Feed
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 5096,
  "dgst": "5f72fd7c6698ae5b",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "#A5872",
        "#A5904",
        "#A5894",
        "AES-ECBA5900",
        "TLS v1.3 KDFA5863",
        "HMAC-SHA3-224A5885",
        "SHA2-512A5889",
        "AES-CBC-CS3A5658",
        "#A5883",
        "#A5888",
        "RSA SigVer (FIPS186-4)A5889",
        "HMAC-SHA2-384A5889",
        "RSA SigVer (FIPS186-2)A5889",
        "KAS-IFC-SSCA5889",
        "AES-CTRA5658",
        "#A5399",
        "AES-OFBA5658",
        "SHA3-384A5885",
        "KAS-ECC-SSC Sp800-56Ar3A5889",
        "KDF ANS 9.42A5889",
        "ECDSA KeyGen (FIPS186-5)A5889",
        "#A5897",
        "KAS-FFC-SSC Sp800-56Ar3A5898",
        "RSA SigVer (FIPS186-5)A5889",
        "#A5905",
        "#A5398",
        "KDA OneStep SP800-56Cr2A5897",
        "AES-CMACA5658",
        "AES-KWPA5658",
        "#A5864",
        "#A5886",
        "KDF ANS 9.63A5889",
        "KTS-IFCA5889",
        "#A5658",
        "SHA2-224A5889",
        "KDF SSHA5900",
        "#A5884",
        "HMAC-SHA2-224A5889",
        "#A5895",
        "HMAC-SHA2-256A5889",
        "#A5893",
        "HMAC-SHA2-512/256A5889",
        "#A5898",
        "#A5881",
        "#A5869",
        "SHA2-512/256A5889",
        "Hash DRBGA5397",
        "#A5863",
        "#A5880",
        "#A5401",
        "#A5878",
        "AES-CBC-CS2A5658",
        "SHA2-384A5889",
        "AES-CFB8A5658",
        "#A5882",
        "SHA2-256A5889",
        "HMAC-SHA3-384A5885",
        "#A5887",
        "AES-GCMA5905",
        "TLS v1.2 KDF RFC7627A5889",
        "#A5870",
        "#A5397",
        "ECDSA SigGen (FIPS186-5)A5889",
        "#A5874",
        "HMAC DRBGA5397",
        "#A5402",
        "AES-CBC-CS1A5658",
        "#A5896",
        "#A5873",
        "Counter DRBGA5397",
        "AES-GMACA5905",
        "ECDSA KeyVer (FIPS186-5)A5889",
        "#A5871",
        "#A5879",
        "#A5889",
        "AES-CFB1A5658",
        "AES-KWA5658",
        "#A5400",
        "AES-CFB128A5658",
        "KDA HKDF SP800-56Cr2A5863",
        "PBKDFA5889",
        "#A5903",
        "#A5868",
        "KDA TwoStep SP800-56Cr2A5897",
        "#A5875",
        "HMAC-SHA2-512/224A5889",
        "AES-CBCA5658",
        "SHA2-512/224A5889",
        "HMAC-SHA2-512A5889",
        "HMAC-SHA3-512A5885",
        "SHA3-512A5885",
        "SHA3-224A5885",
        "SHA-1A5889",
        "#A5900",
        "AES-XTS Testing Revision 2.0A5658",
        "ECDSA SigVer (FIPS186-5)A5889",
        "#A5877",
        "RSA KeyGen (FIPS186-5)A5889",
        "SHAKE-128A5885",
        "AES-CCMA5658",
        "HMAC-SHA-1A5889",
        "KDF SP800-108A5899",
        "HMAC-SHA3-256A5885",
        "Safe Primes Key VerificationA5898",
        "#A5885",
        "#A5403",
        "SHAKE-256A5885",
        "SHA3-256A5885",
        "#A5899",
        "#A5876",
        "RSA SigGen (FIPS186-5)A5889",
        "Safe Primes Key GenerationA5898"
      ]
    },
    "cpe_matches": {
      "_type": "Set",
      "elements": [
        "cpe:2.3:o:suse:suse_linux:3.0:*:*:*:*:*:*:*"
      ]
    },
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "3"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": {
        "_type": "Set",
        "elements": [
          "5464"
        ]
      },
      "directly_referencing": null,
      "indirectly_referenced_by": {
        "_type": "Set",
        "elements": [
          "5464"
        ]
      },
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": {
      "_type": "Set",
      "elements": [
        "CVE-2007-4393",
        "CVE-2007-0460",
        "CVE-2005-0639",
        "CVE-2007-6167",
        "CVE-2008-3949",
        "CVE-2004-1491",
        "CVE-2004-1184",
        "CVE-2000-0361",
        "CVE-2004-1191",
        "CVE-2005-0638",
        "CVE-2005-1043",
        "CVE-2005-0206",
        "CVE-2005-3148",
        "CVE-2005-3147",
        "CVE-2000-0218",
        "CVE-2005-3146",
        "CVE-2007-4074"
      ]
    },
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "br1_deviations": 0,
    "br1_tables": {
      "_type": "sec_certs.heuristics.br1.table_parsing.model.br1_tables.BR1Tables",
      "approved_algorithms": {
        "entries": [
          {
            "algorithm": "AES-CBC",
            "cavpCertName": "A5398, A5399, A5400, A5401, A5402, A5403, A5658",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800- 38A"
          },
          {
            "algorithm": "AES-CBC-CS1",
            "cavpCertName": "A5398, A5399, A5400, A5401, A5402, A5403, A5658",
            "properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256",
            "reference": "SP 800- 38A"
          },
          {
            "algorithm": "AES-CBC-CS2",
            "cavpCertName": "A5398, A5399, A5400, A5401, A5402, A5403, A5658",
            "properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256",
            "reference": "SP 800- 38A"
          },
          {
            "algorithm": "AES-CBC-CS3",
            "cavpCertName": "A5398, A5399, A5400, A5401, A5402, A5403, A5658",
            "properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256",
            "reference": "SP 800- 38A"
          },
          {
            "algorithm": "AES-CCM",
            "cavpCertName": "A5398, A5399, A5400, A5401, A5402, A5403, A5658",
            "properties": "Key Length - 128, 192, 256",
            "reference": "SP 800- 38C"
          },
          {
            "algorithm": "AES-CFB1",
            "cavpCertName": "A5398, A5399, A5400, A5401, A5402, A5403, A5658",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800- 38A"
          },
          {
            "algorithm": "AES-CFB128",
            "cavpCertName": "A5398, A5399, A5400, A5401, A5402, A5403, A5658",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800- 38A"
          },
          {
            "algorithm": "AES-CFB8",
            "cavpCertName": "A5398, A5399, A5400, A5401, A5402, A5403, A5658",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800- 38A"
          },
          {
            "algorithm": "AES-CMAC",
            "cavpCertName": "A5398, A5399, A5400, A5401, A5402, A5403, A5658",
            "properties": "Direction - Generation, Verification Key Length - 128, 192, 256",
            "reference": "SP 800- 38B"
          },
          {
            "algorithm": "AES-CTR",
            "cavpCertName": "A5398, A5399, A5400, A5401, A5402, A5403, A5658",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800- 38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A5398, A5399, A5400, A5401, A5402, A5403, A5658, A5884, A5893, A5894, A5895, A5896, A5900",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800- 38A"
          },
          {
            "algorithm": "AES-GCM",
            "cavpCertName": "A5870, A5871, A5872, A5873, A5874, A5875, A5880, A5881, A5882, A5886, A5887, A5888, A5903, A5904, A5905",
            "properties": "Direction - Decrypt, Encrypt IV Generation - External, Internal Key Length - 128, 192, 256 IV Generation Mode - 8.2.2",
            "reference": "SP 800- 38D"
          },
          {
            "algorithm": "AES-GMAC",
            "cavpCertName": "A5870, A5871, A5872, A5873, A5874, A5875, A5880, A5881, A5882, A5886, A5887, A5888, A5903, A5904, A5905",
            "properties": "Direction - Decrypt, Encrypt IV Generation - External Key Length - 128, 192, 256",
            "reference": "SP 800- 38D"
          },
          {
            "algorithm": "AES-KW",
            "cavpCertName": "A5398, A5399, A5400, A5401, A5402, A5403, A5658",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38F"
          },
          {
            "algorithm": "AES-KWP",
            "cavpCertName": "A5398, A5399, A5400, A5401, A5402, A5403, A5658",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38F"
          },
          {
            "algorithm": "AES-OFB",
            "cavpCertName": "A5398, A5399, A5400, A5401, A5402, A5403, A5658",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800- 38A"
          },
          {
            "algorithm": "AES-XTS Testing Revision 2.0",
            "cavpCertName": "A5398, A5399, A5400, A5401, A5402, A5403, A5658",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 256",
            "reference": "SP 800-38E"
          },
          {
            "algorithm": "Counter DRBG",
            "cavpCertName": "A5397",
            "properties": "Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - No, Yes",
            "reference": "SP 800- 90A Rev. 1"
          },
          {
            "algorithm": "ECDSA KeyGen (FIPS186-5)",
            "cavpCertName": "A5868, A5876, A5877, A5878, A5879, A5883, A5889",
            "properties": "Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - testing candidates",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "ECDSA KeyVer (FIPS186-5)",
            "cavpCertName": "A5868, A5876, A5877, A5878, A5879, A5883, A5889",
            "properties": "Curve - P-224, P-256, P-384, P-521",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "ECDSA SigGen (FIPS186-5)",
            "cavpCertName": "A5868, A5876, A5877, A5878, A5879, A5883, A5889",
            "properties": "Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2- 384, SHA2-512, SHA2-512/224, SHA2-512/256 Component - No, Yes",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "ECDSA SigGen (FIPS186-5)",
            "cavpCertName": "A5869, A5885",
            "properties": "Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA3-224, SHA3-256, SHA3- 384, SHA3-512 Component - No, Yes",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "ECDSA SigVer (FIPS186-5)",
            "cavpCertName": "A5868, A5876, A5877, A5878, A5879, A5883, A5889",
            "properties": "Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2- 384, SHA2-512, SHA2-512/224, SHA2-512/256",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "ECDSA SigVer (FIPS186-5)",
            "cavpCertName": "A5869, A5885",
            "properties": "Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA3-224, SHA3-256, SHA3- 384, SHA3-512",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "Hash DRBG",
            "cavpCertName": "A5397",
            "properties": "Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512",
            "reference": "SP 800- 90A Rev. 1"
          },
          {
            "algorithm": "HMAC DRBG",
            "cavpCertName": "A5397",
            "properties": "Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512",
            "reference": "SP 800- 90A Rev. 1"
          },
          {
            "algorithm": "HMAC-SHA-1",
            "cavpCertName": "A5868, A5876, A5877, A5878, A5879, A5883, A5889",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2- 224",
            "cavpCertName": "A5868, A5876, A5877, A5878, A5879, A5883, A5889",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2- 256",
            "cavpCertName": "A5864, A5868, A5876, A5877, A5878, A5879, A5883, A5889",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2- 384",
            "cavpCertName": "A5868, A5876, A5877, A5878, A5879, A5883, A5889",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2- 512",
            "cavpCertName": "A5868, A5876, A5877, A5878, A5879, A5883, A5889",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2- 512/224",
            "cavpCertName": "A5868, A5876, A5877, A5878, A5879, A5883, A5889",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2- 512/256",
            "cavpCertName": "A5868, A5876, A5877, A5878, A5879, A5883, A5889",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3- 224",
            "cavpCertName": "A5869, A5885",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3- 256",
            "cavpCertName": "A5869, A5885",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3- 384",
            "cavpCertName": "A5869, A5885",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3- 512",
            "cavpCertName": "A5869, A5885",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "KAS-ECC-SSC Sp800-56Ar3",
            "cavpCertName": "A5868, A5876, A5877, A5878, A5879, A5883, A5889",
            "properties": "Domain Parameter Generation Methods - P-224, P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responder",
            "reference": "SP 800- 56A Rev. 3"
          },
          {
            "algorithm": "KAS-FFC-SSC Sp800-56Ar3",
            "cavpCertName": "A5898",
            "properties": "Domain Parameter Generation Methods - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP- 4096, MODP-6144, MODP-8192 Scheme - dhEphem - KAS Role - initiator, responder",
            "reference": "SP 800- 56A Rev. 3"
          },
          {
            "algorithm": "KAS-IFC-SSC",
            "cavpCertName": "A5868, A5876, A5877, A5878, A5879, A5883, A5889",
            "properties": "Modulo - 2048, 3072, 4096, 6144, 8192 Key Generation Methods - rsakpg1-basic, rsakpg1-crt, rsakpg1-prime-factor, rsakpg2-basic, rsakpg2-crt, rsakpg2-prime-factor Scheme - KAS1 - KAS Role - initiator, responder KAS2 - KAS Role - initiator, responder",
            "reference": "SP 800- 56A Rev. 3"
          },
          {
            "algorithm": "KDA HKDF SP800-56Cr2",
            "cavpCertName": "A5863",
            "properties": "Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8 HMAC Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512",
            "reference": "SP 800- 56C Rev. 2"
          },
          {
            "algorithm": "KDA OneStep SP800-56Cr2",
            "cavpCertName": "A5897",
            "properties": "Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-2048 Increment 8",
            "reference": "SP 800- 56C Rev. 2"
          },
          {
            "algorithm": "KDA TwoStep SP800-56Cr2",
            "cavpCertName": "A5897",
            "properties": "MAC Salting Methods - default, random KDF Mode - feedback Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-2048 Increment 8",
            "reference": "SP 800- 56C Rev. 2"
          },
          {
            "algorithm": "KDF ANS 9.42 (CVL)",
            "cavpCertName": "A5868, A5876, A5877, A5878, A5879, A5883, A5889",
            "properties": "KDF Type - DER Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2- 512/256 Key Data Length - Key Data Length: 112-4096 Increment 8",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "KDF ANS 9.42 (CVL)",
            "cavpCertName": "A5869, A5885",
            "properties": "KDF Type - DER Hash Algorithm - SHA3-224, SHA3-256, SHA3-",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "",
            "cavpCertName": "",
            "properties": "384, SHA3-512 Key Data Length - Key Data Length: 112-4096 Increment 8",
            "reference": ""
          },
          {
            "algorithm": "KDF ANS 9.63 (CVL)",
            "cavpCertName": "A5868, A5876, A5877, A5878, A5879, A5883, A5889",
            "properties": "Hash Algorithm - SHA2-224, SHA2-256, SHA2- 384, SHA2-512, SHA2-512/224, SHA2-512/256 Key Data Length - Key Data Length: 128-4096 Increment 8",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "KDF ANS 9.63 (CVL)",
            "cavpCertName": "A5869, A5885",
            "properties": "Hash Algorithm - SHA3-224, SHA3-256, SHA3- 384, SHA3-512 Key Data Length - Key Data Length: 128-4096 Increment 8",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "KDF SP800- 108",
            "cavpCertName": "A5899",
            "properties": "KDF Mode - Counter, Feedback Supported Lengths - Supported Lengths: 112-4096 Increment 8",
            "reference": "SP 800-108 Rev. 1"
          },
          {
            "algorithm": "KDF SSH (CVL)",
            "cavpCertName": "A5884, A5893, A5894, A5895, A5896, A5900",
            "properties": "Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "KTS-IFC",
            "cavpCertName": "A5868, A5876, A5877, A5878, A5879, A5883, A5889",
            "properties": "Modulo - 2048, 3072, 4096, 6144, 8192 Key Generation Methods - rsakpg1-basic, rsakpg1-crt, rsakpg1-prime-factor, rsakpg2-basic, rsakpg2-crt, rsakpg2-prime-factor Scheme - KTS-OAEP-basic - KAS Role - initiator, responder Key Transport Method - Key Length - 768",
            "reference": "SP 800- 56B Rev. 2"
          },
          {
            "algorithm": "PBKDF",
            "cavpCertName": "A5868, A5869, A5876, A5877, A5878, A5879, A5883, A5885, A5889",
            "properties": "Iteration Count - Iteration Count: 1000-10000 Increment 1 Password Length - Password Length: 8-128 Increment 1",
            "reference": "SP 800-132"
          },
          {
            "algorithm": "RSA KeyGen (FIPS186-5)",
            "cavpCertName": "A5868, A5876, A5877, A5878, A5879, A5883, A5889",
            "properties": "Key Generation Mode - probableWithProbableAux Modulo - 2048, 3072, 4096, 6144, 8192 Primality Tests - 2powSecStr Private Key Format - standard",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "RSA SigGen (FIPS186-5)",
            "cavpCertName": "A5868, A5869, A5876, A5877, A5878, A5879, A5883, A5885, A5889",
            "properties": "Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pss",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "RSA SigVer (FIPS186-2)",
            "cavpCertName": "A5868, A5876, A5877, A5878, A5879, A5883, A5889",
            "properties": "Signature Type - PKCS 1.5, PKCSPSS Modulo - 1536",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "RSA SigVer (FIPS186-4)",
            "cavpCertName": "A5868, A5876, A5877, A5878, A5879, A5883, A5889",
            "properties": "Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "RSA SigVer (FIPS186-5)",
            "cavpCertName": "A5868, A5869, A5876, A5877, A5878, A5879, A5883, A5885, A5889",
            "properties": "Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pss",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "Safe Primes Key Generation",
            "cavpCertName": "A5898",
            "properties": "Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP- 8192",
            "reference": "SP 800- 56A Rev. 3"
          },
          {
            "algorithm": "Safe Primes Key Verification",
            "cavpCertName": "A5898",
            "properties": "Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP- 8192",
            "reference": "SP 800- 56A Rev. 3"
          },
          {
            "algorithm": "SHA-1",
            "cavpCertName": "A5868, A5876, A5877, A5878, A5879, A5883, A5889",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-224",
            "cavpCertName": "A5868, A5876, A5877, A5878, A5879, A5883, A5889",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-256",
            "cavpCertName": "A5864, A5868, A5876, A5877, A5878, A5879, A5883, A5889",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-384",
            "cavpCertName": "A5868, A5876, A5877, A5878, A5879, A5883, A5889",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512",
            "cavpCertName": "A5868, A5876, A5877, A5878, A5879, A5883, A5889",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512/224",
            "cavpCertName": "A5868, A5876, A5877, A5878, A5879, A5883, A5889",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512/256",
            "cavpCertName": "A5868, A5876, A5877, A5878, A5879, A5883, A5889",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA3-224",
            "cavpCertName": "A5869, A5885",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3-256",
            "cavpCertName": "A5869, A5885",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3-384",
            "cavpCertName": "A5869, A5885",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3-512",
            "cavpCertName": "A5869, A5885",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHAKE-128",
            "cavpCertName": "A5869, A5885",
            "properties": "Output Length - Output Length: 16-65536 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHAKE-256",
            "cavpCertName": "A5869, A5885",
            "properties": "Output Length - Output Length: 16-65536 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "TLS v1.2 KDF RFC7627 (CVL)",
            "cavpCertName": "A5868, A5876, A5877, A5878, A5879, A5883, A5889",
            "properties": "Hash Algorithm - SHA2-256, SHA2-384, SHA2- 512",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "TLS v1.3 KDF (CVL)",
            "cavpCertName": "A5863",
            "properties": "HMAC Algorithm - SHA2-256, SHA2-384 KDF Running Modes - DHE, PSK, PSK-DHE",
            "reference": "SP 800-135 Rev. 1"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "approved_services": {
        "entries": [
          {
            "description": "Used to perform symmetr ic encrypti on of an entry plaintext",
            "indicator": "EVP_EncryptFinal_ex returns 1",
            "inputs": "Plaintex t, AES key, IV",
            "name": "Symmetri c Encryptio n",
            "outputs": "Ciphert ext",
            "rolesSspAccess": "Crypto Officer - AES key: W,E",
            "secFunImpl": "Symmetri c Encryptio n with AES"
          },
          {
            "description": "Used to perform symmetr ic decrypti on of an entry cipherte xt",
            "indicator": "EVP_DecryptFinal_ex returns 1",
            "inputs": "Ciphert ext, AES key, IV",
            "name": "Symmetri c Decryptio n",
            "outputs": "Plaintex t",
            "rolesSspAccess": "Crypto Officer - AES key: W,E",
            "secFunImpl": "Symmetri c Decryptio n with AES"
          },
          {
            "description": "Used to perform authenti cated symmetr",
            "indicator": "AES-GCM: EVP_CIPHER_SUSE_FIPS_INDICAT OR_APPROVED; Others: EVP_EncryptFinal_ex returns 1",
            "inputs": "Plaintex t, AES key, IV",
            "name": "Authenti cated Encryptio n",
            "outputs": "Ciphert ext, MAC tag",
            "rolesSspAccess": "Crypto Officer - AES",
            "secFunImpl": "Authenti cated Symmetri c"
          },
          {
            "description": "ic encrypti on with AES",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "key: W,E",
            "secFunImpl": "Encryptio n"
          },
          {
            "description": "Used to perform authenti cated symmetr ic decrypti on with AES",
            "indicator": "AES-GCM: EVP_CIPHER_SUSE_FIPS_INDICAT OR_APPROVED; Others: EVP_DecryptFinal_ex returns 1",
            "inputs": "Ciphert ext, AES key, IV, MAC tag",
            "name": "Authenti cated Decryptio n",
            "outputs": "Plaintex t or failure",
            "rolesSspAccess": "Crypto Officer - AES key: W,E",
            "secFunImpl": "Authenti cated Symmetri c Decryptio n"
          },
          {
            "description": "Comput e a MAC tag",
            "indicator": "HMAC: EVP_MAC_SUSE_FIPS_INDICATOR _APPROVED; Others: EVP_MAC_final returns 1",
            "inputs": "Message , AES key or HMAC key",
            "name": "Message Authenti cation Code",
            "outputs": "MAC tag",
            "rolesSspAccess": "Crypto Officer - HMAC key: W,E - AES key: W,E",
            "secFunImpl": "Message Authenti cation Code"
          },
          {
            "description": "Used to generate a SHA- 1, SHA- 2, or SHA- 3/SHAK E message digest",
            "indicator": "EVP_DigestFinal_ex returns 1",
            "inputs": "Message",
            "name": "Message Digest",
            "outputs": "Message digest",
            "rolesSspAccess": "Crypto Officer",
            "secFunImpl": "Message digest"
          },
          {
            "description": "Derive a key from a key- derivatio n key",
            "indicator": "EVP_KDF_SUSE_FIPS_INDICATOR_ APPROVED",
            "inputs": "Key- derivati on key",
            "name": "Key Derivatio n with KBKDF",
            "outputs": "KBKDF Derived Key",
            "rolesSspAccess": "Crypto Officer - Key Derivati on Key: W,E - KBKDF",
            "secFunImpl": "Key Derivatio n with KBKDF"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "Derived Key: G,R",
            "secFunImpl": ""
          },
          {
            "description": "Derive a key from a shared secret using HKDF",
            "indicator": "EVP_KDF_SUSE_FIPS_INDICATOR_ APPROVED",
            "inputs": "Shared secret",
            "name": "Key Derivatio n with HKDF",
            "outputs": "HKDF Derived Key",
            "rolesSspAccess": "Crypto Officer - Shared Secret: W,E - HKDF Derived Key: G,R",
            "secFunImpl": "Key Derivatio n with HKDF"
          },
          {
            "description": "Derive a key from a shared secret using SSH KDF",
            "indicator": "EVP_KDF_SUSE_FIPS_INDICATOR_ APPROVED",
            "inputs": "Shared secret",
            "name": "Key Derivatio n with SSH KDF",
            "outputs": "SSH Derived Key",
            "rolesSspAccess": "Crypto Officer - Shared Secret: W,E - SSH Derived Key: G,R",
            "secFunImpl": "Key Derivatio n with SSH KDF"
          },
          {
            "description": "Derive a key from a shared secret using X9.63 KDF",
            "indicator": "EVP_KDF_SUSE_FIPS_INDICATOR_ APPROVED",
            "inputs": "Shared secret",
            "name": "Key Derivatio n with X9.63 KDF",
            "outputs": "X9.63 Derived Key",
            "rolesSspAccess": "Crypto Officer - Shared Secret: W,E - X9.63 Derived Key: G,R",
            "secFunImpl": "Key Derivatio n with X9.63 KDF"
          },
          {
            "description": "Derive a key from a shared secret using X9.63 KDF",
            "indicator": "EVP_KDF_SUSE_FIPS_INDICATOR_ APPROVED",
            "inputs": "Shared secret",
            "name": "Key Derivatio n with X9.42 KDF",
            "outputs": "X9.42 Derived Key",
            "rolesSspAccess": "Crypto Officer - Shared Secret: W,E - X9.42 Derived Key: G,R",
            "secFunImpl": "Key Derivatio n with X9.42 KDF"
          },
          {
            "description": "Derive a key from a shared secret using KDA OneStep",
            "indicator": "EVP_KDF_SUSE_FIPS_INDICATOR_ APPROVED",
            "inputs": "Shared secret",
            "name": "Key Derivatio n with KDA OneStep",
            "outputs": "KDA OneStep Derived Key",
            "rolesSspAccess": "Crypto Officer - Shared Secret: W,E - KDA OneSte p Derived Key: G,R",
            "secFunImpl": "Key Derivatio n with KDA OneStep"
          },
          {
            "description": "Derive a key from a shared secret using KDA TwoStep",
            "indicator": "EVP_KDF_SUSE_FIPS_INDICATOR_ APPROVED",
            "inputs": "Shared secret",
            "name": "Key Derivatio n with KDA TwoStep",
            "outputs": "KDA TwoSte p Derived Key",
            "rolesSspAccess": "Crypto Officer - Shared Secret: W,E - KDA TwoSte p Derived Key: G,R",
            "secFunImpl": "Key Derivatio n with KDA TwoStep"
          },
          {
            "description": "Derive a key from a shared secret using TLS 1.2 KDF / TLS 1.3 KDF",
            "indicator": "EVP_KDF_SUSE_FIPS_INDICATOR_ APPROVED",
            "inputs": "Shared secret",
            "name": "TLS Key Derivatio n",
            "outputs": "TLS Derived Key",
            "rolesSspAccess": "Crypto Officer - Shared Secret: W,E - TLS Derived Key: G,R",
            "secFunImpl": "TLS Key Derivatio n"
          },
          {
            "description": "Derive a key from a passwor d",
            "indicator": "EVP_KDF_SUSE_FIPS_INDICATOR_ APPROVED",
            "inputs": "Passwor d or passphr ase",
            "name": "Password -based Key Derivatio n",
            "outputs": "PBKDF Derived Key",
            "rolesSspAccess": "Crypto Officer - Passwor d or passphr ase: W,E -",
            "secFunImpl": "Password -based Key Derivatio n"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "PBKDF Derived Key: G,R",
            "secFunImpl": ""
          },
          {
            "description": "Comput e a shared secret",
            "indicator": "EVP_PKEY_derive returns 1",
            "inputs": "DH private key, DH public key (peer)",
            "name": "Shared Secret Computat ion with DH",
            "outputs": "Shared secret",
            "rolesSspAccess": "Crypto Officer - DH Private key: W,E - DH Public key: W,E - Shared Secret: G,R",
            "secFunImpl": "Shared Secret Computat ion with DH"
          },
          {
            "description": "Comput e a shared secret",
            "indicator": "EVP_PKEY_derive returns 1",
            "inputs": "EC private key, EC public key (peer)",
            "name": "Shared Secret Computat ion with ECDH",
            "outputs": "Shared secret",
            "rolesSspAccess": "Crypto Officer - EC Private key: W,E - EC Public key: W,E - Shared Secret: G,R",
            "secFunImpl": "Shared Secret Computat ion with ECDH"
          },
          {
            "description": "Comput e a shared secret",
            "indicator": "EVP_PKEY_derive returns 1",
            "inputs": "RSA private key, RSA public key (peer)",
            "name": "Shared Secret Computat ion with RSA",
            "outputs": "Shared secret",
            "rolesSspAccess": "Crypto Officer - RSA private key: W,E - RSA public key: W,E - Shared",
            "secFunImpl": "Shared Secret Computat ion with RSA"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "Secret: G,R",
            "secFunImpl": ""
          },
          {
            "description": "Perform RSA- based encrypti on (complia nt with SP 800- 56B Rev. 2))",
            "indicator": "EVP_PKEY_encrypt returns 1",
            "inputs": "RSA public key (peer), plaintex t key",
            "name": "Asymmet ric Encryptio n",
            "outputs": "Encapsu lated key",
            "rolesSspAccess": "Crypto Officer - RSA public key: W,E",
            "secFunImpl": "Asymmet ric Encryptio n with RSA"
          },
          {
            "description": "Perform RSA- based decrypti on (complia nt with SP 800- 56B Rev. 2))",
            "indicator": "EVP_PKEY_decrypt returns 1",
            "inputs": "RSA private key (owner) , encapsu lated key",
            "name": "Asymmet ric Decryptio n",
            "outputs": "Plaintex t key",
            "rolesSspAccess": "Crypto Officer - RSA private key: W,E",
            "secFunImpl": "Asymmet ric Decryptio n with RSA"
          },
          {
            "description": "Generat e a digital signatur e",
            "indicator": "EVP_SIGNATURE_SUSE_FIPS_INDI CATOR_APPROVED",
            "inputs": "Message , private key",
            "name": "Signature Generatio n",
            "outputs": "Signatur e",
            "rolesSspAccess": "Crypto Officer - RSA private key: W,E - EC Private key: W,E",
            "secFunImpl": "Signature Generatio n"
          },
          {
            "description": "Verify a digital signatur e",
            "indicator": "EVP_SIGNATURE_SUSE_FIPS_INDI CATOR_APPROVED",
            "inputs": "Message , public key, signatur e",
            "name": "Signature Verificati on",
            "outputs": "Pass/fail",
            "rolesSspAccess": "Crypto Officer - RSA public key: W,E - EC Public",
            "secFunImpl": "Signature Verificati on"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "key: W,E",
            "secFunImpl": ""
          },
          {
            "description": "Generat e a key pair",
            "indicator": "EVP_PKEY_Generate returns 1",
            "inputs": "Group or Curve or Modulu s bits",
            "name": "Key Pair Generatio n",
            "outputs": "DH key pair; EC key pair; RSA key pair",
            "rolesSspAccess": "Crypto Officer - Module - generat ed RSA private key: G,R - Module - generat ed DH Private key: G,R - Module - generat ed RSA public key: G,R - Module - generat ed DH Public key: G,R - Module - generat ed EC Private key:",
            "secFunImpl": "Key Pair Generatio n with RSA Key Pair Generatio n with ECDSA Key Pair Generatio n with Safe Primes"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "G,R - Module - generat ed EC Public key: G,R - Interme diate key generati on value: G,E,Z",
            "secFunImpl": ""
          },
          {
            "description": "Verify a key pair generate d with Safe Primes",
            "indicator": "EVP_PKEY_public_check or EVP_PKEY_private_check or EVP_PKEY_check returns 1",
            "inputs": "Key pair",
            "name": "Key Pair Verificati on with Safe Primes",
            "outputs": "Pass/fail",
            "rolesSspAccess": "Crypto Officer - DH Public key: W,E - DH Private key: W,E",
            "secFunImpl": "Key Pair Verificati on with Safe Primes"
          },
          {
            "description": "Verify a key pair generate d with ECDSA",
            "indicator": "EVP_PKEY_public_check or EVP_PKEY_private_check or EVP_PKEY_check returns 1",
            "inputs": "Key pair",
            "name": "Key Pair Verificati on with ECDSA",
            "outputs": "Pass/fail",
            "rolesSspAccess": "Crypto Officer - EC Public key: W,E - EC Private key: W,E",
            "secFunImpl": "Key Pair Verificati on with ECDSA"
          },
          {
            "description": "Verify a key pair generate",
            "indicator": "EVP_PKEY_public_check or EVP_PKEY_private_check or EVP_PKEY_check returns 1",
            "inputs": "Key pair",
            "name": "Key Pair Verificati on with RSA",
            "outputs": "Pass/fail",
            "rolesSspAccess": "Crypto Officer - RSA public",
            "secFunImpl": ""
          },
          {
            "description": "d with RSA",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "key: W,E - RSA private key: W,E",
            "secFunImpl": ""
          },
          {
            "description": "Generat e random bytes",
            "indicator": "EVP_RAND_generate returns 1",
            "inputs": "Output length",
            "name": "Random Number Generatio n",
            "outputs": "Random bytes",
            "rolesSspAccess": "Crypto Officer - Entropy input: W,E - DRBG internal state (V value, C value): G,W,E - DRBG internal state (V value, Key): G,W,E - DRBG seed: G,W,E",
            "secFunImpl": "Random Number Generatio n"
          },
          {
            "description": "Show the current status of the module",
            "indicator": "None",
            "inputs": "N/A",
            "name": "Show status",
            "outputs": "Module status",
            "rolesSspAccess": "Crypto Officer",
            "secFunImpl": "None"
          },
          {
            "description": "Show module name and the version of the module",
            "indicator": "None",
            "inputs": "N/A",
            "name": "Show module name and version",
            "outputs": "Name and version informa tion",
            "rolesSspAccess": "Crypto Officer",
            "secFunImpl": "None"
          },
          {
            "description": "Perform CASTs and integrity test",
            "indicator": "None",
            "inputs": "N/A",
            "name": "Self-test",
            "outputs": "Pass/fail result of self- tests",
            "rolesSspAccess": "Crypto Officer",
            "secFunImpl": "Message digest Message Authenti cation Code Symmetri c Encryptio n with AES Symmetri c Decryptio n with AES Authenti cated Symmetri c Encryptio n Authenti cated Symmetri c Decryptio n Signature Generatio n Signature Verificati on Key Derivatio n with KBKDF Key Derivatio n with KDA OneStep Key"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "",
            "secFunImpl": "Derivatio n with HKDF Key Derivatio n with X9.42 KDF Key Derivatio n with X9.63 KDF Key Derivatio n with SSH KDF TLS Key Derivatio n Password -based Key Derivatio n Random Number Generatio n Shared Secret Computat ion with DH Shared Secret Computat ion with ECDH"
          },
          {
            "description": "Zeroize SSPs.",
            "indicator": "None",
            "inputs": "Any SSP",
            "name": "Zeroizati on",
            "outputs": "N/A",
            "rolesSspAccess": "Crypto Officer - AES key: Z",
            "secFunImpl": "None"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "- HMAC key: Z - RSA private key: Z - RSA public key: Z - DH Private key: Z - DH Public key: Z - EC Private key: Z - EC Public key: Z - Key Derivati on Key: Z - Passwor d or passphr ase: Z - PBKDF Derived Key: Z - KBKDF Derived Key: Z - HKDF Derived Key: Z - SSH Derived Key: Z",
            "secFunImpl": ""
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "- X9.42 Derived Key: Z - X9.63 Derived Key: Z - KDA OneSte p Derived Key: Z - KDA TwoSte p Derived Key: Z - TLS Derived Key: Z - Shared Secret: Z - Entropy input: Z - DRBG seed: Z - DRBG internal state (V value, C value): Z - DRBG internal state (V value, Key): Z - Interme diate key generati",
            "secFunImpl": ""
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "on value: Z",
            "secFunImpl": ""
          },
          {
            "description": "Service Indicator",
            "indicator": "",
            "inputs": "",
            "name": "Context",
            "outputs": "",
            "rolesSspAccess": "",
            "secFunImpl": ""
          },
          {
            "description": "OSSL_CIPHER_PARAM_SUSE_FIPS_INDICATOR",
            "indicator": "",
            "inputs": "",
            "name": "EVP_CIPHER_CTX",
            "outputs": "",
            "rolesSspAccess": "",
            "secFunImpl": ""
          },
          {
            "description": "OSSL_MAC_PARAM_SUSE_FIPS_INDICATOR",
            "indicator": "",
            "inputs": "",
            "name": "EVP_MAC_CTX",
            "outputs": "",
            "rolesSspAccess": "",
            "secFunImpl": ""
          },
          {
            "description": "OSSL_KDF_PARAM_SUSE_FIPS_INDICATOR",
            "indicator": "",
            "inputs": "",
            "name": "EVP_KDF_CTX",
            "outputs": "",
            "rolesSspAccess": "",
            "secFunImpl": ""
          },
          {
            "description": "OSSL_SIGNATURE_PARAM_SUSE_FIPS_INDICATOR",
            "indicator": "",
            "inputs": "",
            "name": "EVP_PKEY_CTX",
            "outputs": "",
            "rolesSspAccess": "",
            "secFunImpl": ""
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 3
      },
      "authentication_methods": {
        "entries": [],
        "found": false,
        "section": 4,
        "subsection": 1
      },
      "cond_self_tests": {
        "entries": [
          {
            "algorithmOrTest": "SHA-1 (A5868)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Message digest",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "24-bit message",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA-1 (A5876)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Message digest",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "24-bit message",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA-1 (A5877)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Message digest",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "24-bit message",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA-1 (A5878)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Message digest",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "24-bit message",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA-1 (A5879)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Message digest",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "24-bit message",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA-1 (A5883)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Message digest",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "24-bit message",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA-1 (A5889)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Message digest",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "24-bit message",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA2-512 (A5868)",
            "condition": "Test runs at power-on",
            "details": "Message digest",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "24-bit message",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "",
            "condition": "before the integrity test",
            "details": "",
            "indicator": "",
            "testMethod": "",
            "testProps": "",
            "type": ""
          },
          {
            "algorithmOrTest": "SHA2-512 (A5876)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Message digest",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "24-bit message",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA2-512 (A5877)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Message digest",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "24-bit message",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA2-512 (A5878)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Message digest",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "24-bit message",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA2-512 (A5879)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Message digest",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "24-bit message",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA2-512 (A5883)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Message digest",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "24-bit message",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA2-512 (A5889)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Message digest",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "24-bit message",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC- SHA2-256 (A5864)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Message digest",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC- SHA2-256 (A5868)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Message digest",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC- SHA2-256 (A5876)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Message digest",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC- SHA2-256 (A5877)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Message digest",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC- SHA2-256 (A5878)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Message digest",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC- SHA2-256 (A5879)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Message digest",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC- SHA2-256 (A5883)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Message digest",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC- SHA2-256 (A5889)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Message digest",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA3-256 (A5869)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Message digest",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "32-bit message",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA3-256 (A5885)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Message digest",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "32-bit message",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A5870)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Symmetric operation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256-bit key and 96-bit IV, encypt and decrypt",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A5871)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Symmetric operation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256-bit key and 96-bit IV, encypt and decrypt",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A5872)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Symmetric operation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256-bit key and 96-bit IV, encypt and decrypt",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A5873)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Symmetric operation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256-bit key and 96-bit IV, encypt and decrypt",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A5874)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Symmetric operation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256-bit key and 96-bit IV, encypt and decrypt",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A5875)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Symmetric operation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256-bit key and 96-bit IV, encypt and decrypt",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A5880)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Symmetric operation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256-bit key and 96-bit IV, encypt and decrypt",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A5881)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Symmetric operation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256-bit key and 96-bit IV, encypt and decrypt",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A5882)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Symmetric operation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256-bit key and 96-bit IV, encypt and decrypt",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A5886)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Symmetric operation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256-bit key and 96-bit IV, encypt and decrypt",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A5887)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Symmetric operation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256-bit key and 96-bit IV, encypt and decrypt",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A5888)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Symmetric operation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256-bit key and 96-bit IV, encypt and decrypt",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A5903)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Symmetric operation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256-bit key and 96-bit IV, encypt and decrypt",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A5904)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Symmetric operation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256-bit key and 96-bit IV, encypt and decrypt",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A5905)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Symmetric operation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256-bit key and 96-bit IV, encypt and decrypt",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-ECB (A5398)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Symmetric operation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "128-bit key, decrypt",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-ECB (A5399)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Symmetric operation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "128-bit key, decrypt",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-ECB (A5400)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Symmetric operation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "128-bit key, decrypt",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-ECB (A5401)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Symmetric operation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "128-bit key, decrypt",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-ECB (A5402)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Symmetric operation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "128-bit key, decrypt",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-ECB (A5403)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Symmetric operation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "128-bit key, decrypt",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-ECB (A5658)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Symmetric operation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "128-bit key, decrypt",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-ECB (A5884)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Symmetric operation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "128-bit key, decrypt",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-ECB (A5893)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Symmetric operation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "128-bit key, decrypt",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-ECB (A5894)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Symmetric operation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "128-bit key, decrypt",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-ECB (A5895)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Symmetric operation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "128-bit key, decrypt",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-ECB (A5896)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Symmetric operation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "128-bit key, decrypt",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-ECB (A5900)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Symmetric operation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "128-bit key, decrypt",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigGen (FIPS186-5) (A5868)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Digital signature generation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256 and 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigGen (FIPS186-5) (A5869)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Digital signature generation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256 and 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigGen (FIPS186-5) (A5876)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Digital signature generation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256 and 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigGen (FIPS186-5) (A5877)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Digital signature generation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256 and 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigGen (FIPS186-5) (A5878)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Digital signature generation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256 and 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigGen (FIPS186-5) (A5879)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Digital signature generation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256 and 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigGen (FIPS186-5) (A5883)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Digital signature generation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256 and 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigGen (FIPS186-5) (A5885)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Digital signature generation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256 and 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigGen (FIPS186-5) (A5889)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Digital signature generation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256 and 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186-5) (A5868)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Digital signature verification",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256 and 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186-5) (A5869)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Digital signature verification",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256 and 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186-5) (A5876)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Digital signature verification",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256 and 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186-5) (A5877)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Digital signature verification",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256 and 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186-5) (A5878)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Digital signature verification",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256 and 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186-5) (A5879)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Digital signature verification",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256 and 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186-5) (A5883)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Digital signature verification",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256 and 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186-5) (A5885)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Digital signature verification",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256 and 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186-5) (A5889)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Digital signature verification",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "PKCS#1 v1.5 with SHA-256 and 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigGen (FIPS186-5) (A5868)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Digital signature generation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-256 and P- 224, P-256, P- 384, and P-521",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigGen (FIPS186-5) (A5869)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Digital signature generation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-256 and P- 224, P-256, P- 384, and P-521",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigGen (FIPS186-5) (A5876)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Digital signature generation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-256 and P- 224, P-256, P- 384, and P-521",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigGen (FIPS186-5) (A5877)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Digital signature generation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-256 and P- 224, P-256, P- 384, and P-521",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigGen (FIPS186-5) (A5878)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Digital signature generation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-256 and P- 224, P-256, P- 384, and P-521",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigGen (FIPS186-5) (A5879)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Digital signature generation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-256 and P- 224, P-256, P- 384, and P-521",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigGen (FIPS186-5) (A5883)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Digital signature generation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-256 and P- 224, P-256, P- 384, and P-521",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigGen (FIPS186-5) (A5885)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Digital signature generation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-256 and P- 224, P-256, P- 384, and P-521",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigGen (FIPS186-5) (A5889)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Digital signature generation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-256 and P- 224, P-256, P- 384, and P-521",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigVer (FIPS186-5) (A5868)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Digital signature verification",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-256 and P- 224, P-256, P- 384, and P-521",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigVer (FIPS186-5) (A5869)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Digital signature verification",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-256 and P- 224, P-256, P- 384, and P-521",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigVer (FIPS186-5) (A5876)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Digital signature verification",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-256 and P- 224, P-256, P- 384, and P-521",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigVer (FIPS186-5) (A5877)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Digital signature verification",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-256 and P- 224, P-256, P- 384, and P-521",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigVer (FIPS186-5) (A5878)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Digital signature verification",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-256 and P- 224, P-256, P- 384, and P-521",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigVer (FIPS186-5) (A5879)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Digital signature verification",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-256 and P- 224, P-256, P- 384, and P-521",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigVer (FIPS186-5) (A5883)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Digital signature verification",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-256 and P- 224, P-256, P- 384, and P-521",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigVer (FIPS186-5) (A5885)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Digital signature verification",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-256 and P- 224, P-256, P- 384, and P-521",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigVer (FIPS186-5) (A5889)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Digital signature verification",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-256 and P- 224, P-256, P- 384, and P-521",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF SP800- 108 (A5899)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Key Derivation with KBKDF",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "HMAC-SHA2- 256 in counter mode and 128- bit input key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDA OneStep SP800-56Cr2 (A5897)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Shared secret key derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-224 and 448-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDA TwoStep SP800-56Cr2 (A5897)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Shared secret key derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-224 and 448-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDA HKDF SP800-56Cr2 (A5863)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Shared secret key derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256 and 48-bit secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.42 (A5868)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "ANS X9.42 key derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "AES-128 KW and SHA-1 and 160-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.42 (A5869)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "ANS X9.42 key derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "AES-128 KW and SHA-1 and 160-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.42 (A5876)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "ANS X9.42 key derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "AES-128 KW and SHA-1 and 160-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.42 (A5877)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "ANS X9.42 key derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "AES-128 KW and SHA-1 and 160-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.42 (A5878)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "ANS X9.42 key derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "AES-128 KW and SHA-1 and 160-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.42 (A5879)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "ANS X9.42 key derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "AES-128 KW and SHA-1 and 160-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.42 (A5883)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "ANS X9.42 key derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "AES-128 KW and SHA-1 and 160-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.42 (A5885)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "ANS X9.42 key derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "AES-128 KW and SHA-1 and 160-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.42 (A5889)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "ANS X9.42 key derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "AES-128 KW and SHA-1 and 160-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.63 (A5868)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "ANS X9.63 key derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256 and 192-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.63 (A5869)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "ANS X9.63 key derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256 and 192-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.63 (A5876)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "ANS X9.63 key derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256 and 192-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.63 (A5877)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "ANS X9.63 key derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256 and 192-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.63 (A5878)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "ANS X9.63 key derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256 and 192-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.63 (A5879)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "ANS X9.63 key derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256 and 192-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.63 (A5883)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "ANS X9.63 key derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256 and 192-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.63 (A5885)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "ANS X9.63 key derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256 and 192-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.63 (A5889)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "ANS X9.63 key derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256 and 192-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF SSH (A5884)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "SSH KDF key derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-1 and 1056-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF SSH (A5893)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "SSH KDF key derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-1 and 1056-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF SSH (A5894)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "SSH KDF key derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-1 and 1056-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF SSH (A5895)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "SSH KDF key derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-1 and 1056-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF SSH (A5896)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "SSH KDF key derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-1 and 1056-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF SSH (A5900)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "SSH KDF key derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-1 and 1056-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "TLS v1.2 KDF RFC7627 (A5868)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "TLS v1.2 KDF key derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256 and 384-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "TLS v1.2 KDF RFC7627 (A5876)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "TLS v1.2 KDF key derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256 and 384-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "TLS v1.2 KDF RFC7627 (A5877)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "TLS v1.2 KDF key derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256 and 384-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "TLS v1.2 KDF RFC7627 (A5878)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "TLS v1.2 KDF key derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256 and 384-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "TLS v1.2 KDF RFC7627 (A5879)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "TLS v1.2 KDF key derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256 and 384-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "TLS v1.2 KDF RFC7627 (A5883)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "TLS v1.2 KDF key derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256 and 384-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "TLS v1.2 KDF RFC7627 (A5889)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "TLS v1.2 KDF key derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256 and 384-bit input secret",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "TLS v1.3 KDF (A5863)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "TLS v1.3 KDF key derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256, extract and expand modes",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "PBKDF (A5868)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Password-based Key Derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256 with 24 characters password, 288- bit salt, 4096 iterations",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "PBKDF (A5869)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Password-based Key Derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256 with 24 characters password, 288- bit salt, 4096 iterations",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "PBKDF (A5876)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Password-based Key Derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256 with 24 characters password, 288- bit salt, 4096 iterations",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "PBKDF (A5877)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Password-based Key Derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256 with 24 characters password, 288- bit salt, 4096 iterations",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "PBKDF (A5878)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Password-based Key Derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256 with 24 characters password, 288- bit salt, 4096 iterations",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "PBKDF (A5879)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Password-based Key Derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256 with 24 characters password, 288- bit salt, 4096 iterations",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "PBKDF (A5883)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Password-based Key Derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256 with 24 characters password, 288- bit salt, 4096 iterations",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "PBKDF (A5885)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Password-based Key Derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256 with 24 characters password, 288- bit salt, 4096 iterations",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "PBKDF (A5889)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Password-based Key Derivation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256 with 24 characters password, 288- bit salt, 4096 iterations",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "Counter DRBG (A5397)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Instantiate; Generate; Reseed (compliant to SP 800-90A Rev. 1 Section 11.3)",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "AES-128 with derivation function and prediction resistance",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "Hash DRBG (A5397)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Instantiate; Generate; Reseed (compliant to SP 800-90A Rev. 1 Section 11.3)",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256 and prediction resistance",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC DRBG (A5397)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Instantiate; Generate; Reseed (compliant to SP 800-90A Rev. 1 Section 11.3)",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "HMAC-SHA-1 and prediction resistance",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS-FFC- SSC Sp800- 56Ar3 (A5898)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Shared secret computation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "ffdhe2048",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS-ECC- SSC Sp800- 56Ar3 (A5868)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Shared secret computation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "P-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS-ECC- SSC Sp800- 56Ar3 (A5876)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Shared secret computation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "P-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS-ECC- SSC Sp800- 56Ar3 (A5877)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Shared secret computation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "P-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS-ECC- SSC Sp800- 56Ar3 (A5878)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Shared secret computation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "P-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS-ECC- SSC Sp800- 56Ar3 (A5879)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Shared secret computation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "P-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS-ECC- SSC Sp800- 56Ar3 (A5883)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Shared secret computation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "P-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS-ECC- SSC Sp800- 56Ar3 (A5889)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Shared secret computation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "P-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "Safe Primes Key Generation (A5898)",
            "condition": "Key pair generation",
            "details": "SP 800-56A Rev. 3 Section 5.6.2.1.4",
            "indicator": "Key pair generation is successful",
            "testMethod": "PCT",
            "testProps": "N/A",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "RSA KeyGen (FIPS186-5) (A5868)",
            "condition": "Key pair generation",
            "details": "Signature generation and verification",
            "indicator": "Key pair generation is sucessful",
            "testMethod": "PCT",
            "testProps": "PKCS#1 v1.5 with SHA-256",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "RSA KeyGen (FIPS186-5) (A5876)",
            "condition": "Key pair generation",
            "details": "Signature generation and verification",
            "indicator": "Key pair generation is sucessful",
            "testMethod": "PCT",
            "testProps": "PKCS#1 v1.5 with SHA-256",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "RSA KeyGen (FIPS186-5) (A5877)",
            "condition": "Key pair generation",
            "details": "Signature generation and verification",
            "indicator": "Key pair generation is sucessful",
            "testMethod": "PCT",
            "testProps": "PKCS#1 v1.5 with SHA-256",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "RSA KeyGen (FIPS186-5) (A5878)",
            "condition": "Key pair generation",
            "details": "Signature generation and verification",
            "indicator": "Key pair generation is sucessful",
            "testMethod": "PCT",
            "testProps": "PKCS#1 v1.5 with SHA-256",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "RSA KeyGen (FIPS186-5) (A5879)",
            "condition": "Key pair generation",
            "details": "Signature generation and verification",
            "indicator": "Key pair generation is sucessful",
            "testMethod": "PCT",
            "testProps": "PKCS#1 v1.5 with SHA-256",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "RSA KeyGen (FIPS186-5) (A5883)",
            "condition": "Key pair generation",
            "details": "Signature generation and verification",
            "indicator": "Key pair generation is sucessful",
            "testMethod": "PCT",
            "testProps": "PKCS#1 v1.5 with SHA-256",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "RSA KeyGen (FIPS186-5) (A5889)",
            "condition": "Key pair generation",
            "details": "Signature generation and verification",
            "indicator": "Key pair generation is sucessful",
            "testMethod": "PCT",
            "testProps": "PKCS#1 v1.5 with SHA-256",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "ECDSA KeyGen (FIPS186-5) (A5868)",
            "condition": "Key pair generation",
            "details": "Signature generation and verification",
            "indicator": "Key pair generation is sucessful",
            "testMethod": "PCT",
            "testProps": "SHA-256",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "ECDSA KeyGen (FIPS186-5) (A5876)",
            "condition": "Key pair generation",
            "details": "Signature generation and verification",
            "indicator": "Key pair generation is sucessful",
            "testMethod": "PCT",
            "testProps": "SHA-256",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "ECDSA KeyGen (FIPS186-5) (A5877)",
            "condition": "Key pair generation",
            "details": "Signature generation and verification",
            "indicator": "Key pair generation is sucessful",
            "testMethod": "PCT",
            "testProps": "SHA-256",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "ECDSA KeyGen (FIPS186-5) (A5878)",
            "condition": "Key pair generation",
            "details": "Signature generation and verification",
            "indicator": "Key pair generation is sucessful",
            "testMethod": "PCT",
            "testProps": "SHA-256",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "ECDSA KeyGen (FIPS186-5) (A5879)",
            "condition": "Key pair generation",
            "details": "Signature generation and verification",
            "indicator": "Key pair generation is sucessful",
            "testMethod": "PCT",
            "testProps": "SHA-256",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "ECDSA KeyGen",
            "condition": "Key pair generation",
            "details": "Signature generation and verification",
            "indicator": "Key pair generation is sucessful",
            "testMethod": "PCT",
            "testProps": "SHA-256",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "(FIPS186-5) (A5883)",
            "condition": "",
            "details": "",
            "indicator": "",
            "testMethod": "",
            "testProps": "",
            "type": ""
          },
          {
            "algorithmOrTest": "ECDSA KeyGen (FIPS186-5) (A5889)",
            "condition": "Key pair generation",
            "details": "Signature generation and verification",
            "indicator": "Key pair generation is sucessful",
            "testMethod": "PCT",
            "testProps": "SHA-256",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "KTS-IFC (A5868)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Key encapsulation and un- encapsulation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "OAEP with 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KTS-IFC (A5876)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Key encapsulation and un- encapsulation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "OAEP with 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KTS-IFC (A5877)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Key encapsulation and un- encapsulation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "OAEP with 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KTS-IFC (A5878)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Key encapsulation and un- encapsulation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "OAEP with 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KTS-IFC (A5879)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Key encapsulation and un- encapsulation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "OAEP with 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KTS-IFC (A5883)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Key encapsulation and un- encapsulation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "OAEP with 2048-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KTS-IFC (A5889)",
            "condition": "Test runs at power-on before the integrity test",
            "details": "Key encapsulation and un- encapsulation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "OAEP with 2048-bit key",
            "type": "CAST"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 2
      },
      "error_states": {
        "entries": [
          {
            "conditions": "Software integrity test failure CAST failure",
            "description": "If the module fails any of the self-tests, the module enters the error state. In the error state, the module immediately stops functioning and ends the application process",
            "indicator": "OSSL_PROV_PARAM_STATUS is set to 0. Module will not load.",
            "name": "Error",
            "recoveryMethod": "Module reinitialization"
          },
          {
            "conditions": "PCT failure",
            "description": "Pairwise consistency test failure",
            "indicator": "Module is aborted",
            "name": "PCT Error",
            "recoveryMethod": "Module reinitialization"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 4
      },
      "mechanisms_actions": {
        "entries": [],
        "found": false,
        "section": 7,
        "subsection": 1
      },
      "modes_of_operation": {
        "entries": [
          {
            "description": "Automatically entered whenever an approved service is requested",
            "name": "Approved mode",
            "statusIndicator": "Equivalent to the indicator of the requested service",
            "type": "Approved"
          },
          {
            "description": "Automatically entered whenever a non- approved service is requested",
            "name": "Non-approved mode",
            "statusIndicator": "Equivalent to the indicator of the requested service",
            "type": "Non- Approved"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 4
      },
      "non_approved_allowed_NSC": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_allowed_algos": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_not_allowed": {
        "entries": [
          {
            "name": "AES GCM (external IV)",
            "use": "Authentication Encryption"
          },
          {
            "name": "HMAC (\u003c 112-bit keys)",
            "use": "Message Authentication Code"
          },
          {
            "name": "KBKDF, KDA OneStep, KDA TwoStep, HKDF, ANS X9.42 KDF, ANS X9.63 KDF (\u003c 112-bit keys)",
            "use": "Key Derivation"
          },
          {
            "name": "KDA OneStep, KDA TwoStep (SHAKE128, SHAKE256)",
            "use": "Key Derivation"
          },
          {
            "name": "ANS X9.42 KDF (SHAKE128, SHAKE256)",
            "use": "Key Derivation"
          },
          {
            "name": "ANS X9.63 KDF (SHA-1, SHAKE128, SHAKE256)",
            "use": "Key Derivation"
          },
          {
            "name": "SSH KDF (SHA-512/224, SHA-512/256, SHA-3, SHAKE128, SHAKE256)",
            "use": "Key Derivation"
          },
          {
            "name": "TLS 1.2 KDF (SHA-1, SHA-224, SHA-512/224, SHA-512/256, SHA-3)",
            "use": "TLS Key Derivation"
          },
          {
            "name": "TLS 1.3 KDF (SHA-1, SHA-224, SHA-512, SHA-512/224, SHA-512/256, SHA-3)",
            "use": "TLS Key Derivation"
          },
          {
            "name": "PBKDF2 (\u003c 8 characters password; \u003c 128 salt length; \u003c 1000 iterations; \u003c 112-bit keys)",
            "use": "Password-based Key Derivation"
          },
          {
            "name": "RSA and ECDSA (pre-hashed message)",
            "use": "Signature generation; Signature verification"
          },
          {
            "name": "RSA-PSS (invalid salt length: FIPS 186-5, section 5.4, item(g))",
            "use": "Signature generation; Signature verification"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "non_approved_services": {
        "entries": [
          {
            "alg_accessed": "AES GCM (external IV)",
            "description": "Authenticated Encryption",
            "name": "AES GCM (external IV)",
            "role": "CO"
          },
          {
            "alg_accessed": "HMAC (\u003c 112-bit keys)",
            "description": "Compute a MAC tag",
            "name": "HMAC (\u003c 112- bit keys)",
            "role": "CO"
          },
          {
            "alg_accessed": "KBKDF, KDA OneStep, KDA TwoStep, HKDF, ANS X9.42 KDF, ANS X9.63 KDF (\u003c 112-bit keys) KDA OneStep, KDA TwoStep (SHAKE128, SHAKE256) ANS X9.42 KDF (SHAKE128, SHAKE256) ANS X9.63 KDF (SHA-1, SHAKE128, SHAKE256) SSH KDF (SHA-512/224, SHA-512/256, SHA-3, SHAKE128, SHAKE256) TLS 1.2 KDF (SHA-1, SHA-224, SHA-512/224, SHA-512/256, SHA-3) TLS 1.3 KDF (SHA-1, SHA-224, SHA-512, SHA-512/224, SHA-512/256, SHA-3)",
            "description": "Derive a key from a key- derivation key or a shared secret",
            "name": "Key derivation",
            "role": "CO"
          },
          {
            "alg_accessed": "PBKDF2 (\u003c 8 characters password; \u003c 128 salt length; \u003c 1000 iterations; \u003c 112-bit keys)",
            "description": "Derive a key from a password",
            "name": "PBKDF2 (\u003c 112- bit keys)",
            "role": "CO"
          },
          {
            "alg_accessed": "RSA and ECDSA (pre-hashed message) RSA-PSS (invalid salt length: FIPS 186-5, section 5.4, item(g))",
            "description": "Generate a signature",
            "name": "Signature generation",
            "role": "CO"
          },
          {
            "alg_accessed": "RSA and ECDSA (pre-hashed message) RSA-PSS (invalid salt length: FIPS 186-5, section 5.4, item(g))",
            "description": "Verify a signature",
            "name": "Signature verification",
            "role": "CO"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 4
      },
      "ports_interfaces": {
        "entries": [
          {
            "data": "API input parameters",
            "logicalInterface": "Data Input",
            "physicalPort": "N/A"
          },
          {
            "data": "API output parameters",
            "logicalInterface": "Data Output",
            "physicalPort": "N/A"
          },
          {
            "data": "API function calls",
            "logicalInterface": "Control Input",
            "physicalPort": "N/A"
          },
          {
            "data": "API return codes, error queue",
            "logicalInterface": "Status Output",
            "physicalPort": "N/A"
          }
        ],
        "found": true,
        "section": 3,
        "subsection": 1
      },
      "roles": {
        "entries": [
          {
            "authMethodList": "None",
            "name": "Crypto Officer",
            "operatorType": "CO",
            "type": "Role"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 2
      },
      "security_levels": {
        "entries": [
          {
            "level": "1",
            "section": "1",
            "title": "General"
          },
          {
            "level": "1",
            "section": "2",
            "title": "Cryptographic module specification"
          },
          {
            "level": "1",
            "section": "3",
            "title": "Cryptographic module interfaces"
          },
          {
            "level": "1",
            "section": "4",
            "title": "Roles, services, and authentication"
          },
          {
            "level": "1",
            "section": "5",
            "title": "Software/Firmware security"
          },
          {
            "level": "1",
            "section": "6",
            "title": "Operational environment"
          },
          {
            "level": "N/A",
            "section": "7",
            "title": "Physical security"
          },
          {
            "level": "N/A",
            "section": "8",
            "title": "Non-invasive security"
          },
          {
            "level": "1",
            "section": "9",
            "title": "Sensitive security parameter management"
          },
          {
            "level": "1",
            "section": "10",
            "title": "Self-tests"
          },
          {
            "level": "1",
            "section": "11",
            "title": "Life-cycle assurance"
          },
          {
            "level": "1",
            "section": "12",
            "title": "Mitigation of other attacks"
          },
          {
            "level": "1",
            "section": "",
            "title": "Overall Level"
          }
        ],
        "found": true,
        "section": 1,
        "subsection": 2
      },
      "self_tests": {
        "entries": [
          {
            "algorithmOrTest": "HMAC- SHA2-256 (A5868)",
            "details": "Integrity test of the shared library component of the module. Verified by comparing an HMAC SHA-256 value calculated at run time with the HMAC SHA-256 value embedded in the fips.so file that was computed at build time.",
            "indicator": "Module becomes operational and services are available for use",
            "testMethod": "Message authentication",
            "testProps": "256-bits key",
            "type": "SW/FW Integrity"
          },
          {
            "algorithmOrTest": "HMAC- SHA2-256 (A5864)",
            "details": "Integrity test of the shared library component of the module. Verified by comparing an HMAC SHA-256 value calculated at run time with the HMAC SHA-256 value embedded in the fips.so file that was computed at build time.",
            "indicator": "Module becomes operational and services are available for use",
            "testMethod": "Message authentication",
            "testProps": "256-bits key",
            "type": "SW/FW Integrity"
          },
          {
            "algorithmOrTest": "HMAC- SHA2-256 (A5876)",
            "details": "Integrity test of the shared library component of the module. Verified by comparing an HMAC SHA-256 value calculated at run time with the HMAC SHA-256 value embedded in the fips.so file that was computed at build time.",
            "indicator": "Module becomes operational and services are available for use",
            "testMethod": "Message authentication",
            "testProps": "256-bits key",
            "type": "SW/FW Integrity"
          },
          {
            "algorithmOrTest": "HMAC- SHA2-256 (A5877)",
            "details": "Integrity test of the shared library component of the module. Verified by comparing an HMAC SHA-256 value calculated at run time with the HMAC SHA-256 value embedded in the fips.so file that was computed at build time.",
            "indicator": "Module becomes operational and services are available for use",
            "testMethod": "Message authentication",
            "testProps": "256-bits key",
            "type": "SW/FW Integrity"
          },
          {
            "algorithmOrTest": "HMAC- SHA2-256 (A5878)",
            "details": "Integrity test of the shared library component of the module. Verified by comparing an HMAC SHA-256 value calculated at run time with the HMAC SHA-256 value embedded in the fips.so file that was computed at build time.",
            "indicator": "Module becomes operational and services are available for use",
            "testMethod": "Message authentication",
            "testProps": "256-bits key",
            "type": "SW/FW Integrity"
          },
          {
            "algorithmOrTest": "HMAC- SHA2-256 (A5879)",
            "details": "Integrity test of the shared library component of the module. Verified by comparing an HMAC SHA-256 value calculated at run time with the HMAC SHA-256 value embedded in the fips.so file that was computed at build time.",
            "indicator": "Module becomes operational and services are available for use",
            "testMethod": "Message authentication",
            "testProps": "256-bits key",
            "type": "SW/FW Integrity"
          },
          {
            "algorithmOrTest": "HMAC- SHA2-256 (A5883)",
            "details": "Integrity test of the shared library component of the module. Verified by comparing an HMAC SHA-256 value calculated at run time with the HMAC SHA-256 value embedded in the fips.so file that was computed at build time.",
            "indicator": "Module becomes operational and services are available for use",
            "testMethod": "Message authentication",
            "testProps": "256-bits key",
            "type": "SW/FW Integrity"
          },
          {
            "algorithmOrTest": "HMAC- SHA2-256 (A5889)",
            "details": "Integrity test of the shared library component of the module. Verified by comparing an HMAC SHA-256 value calculated at run time with the HMAC SHA-256 value embedded in the fips.so file that was computed at build time.",
            "indicator": "Module becomes operational and services are available for use",
            "testMethod": "Message authentication",
            "testProps": "256-bits key Message",
            "type": "SW/FW Integrity"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 1
      },
      "ssp_io_methods": {
        "entries": [
          {
            "dest": "Cryptographic module",
            "distribution": "Manual",
            "entry": "Electronic",
            "format": "Plaintext",
            "name": "API input parameters",
            "sfiAlgo": "",
            "source": "Operator calling application (TOEPP)"
          },
          {
            "dest": "Operator calling application (TOEPP)",
            "distribution": "Manual",
            "entry": "Electronic",
            "format": "Plaintext",
            "name": "API output parameters",
            "sfiAlgo": "",
            "source": "Cryptographic module"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 2
      },
      "ssp_zeroization_methods": {
        "entries": [
          {
            "description": "Zeroizes the SSPs contained within the cipher handle.",
            "method": "Free cipher handle",
            "operatorId": "By calling the cipher related zeroization API",
            "rationale": "By calling the appropriate zeroization functions: AES key: EVP_CIPHER_CTX_free and EVP_MAC_CTX_free; HMAC key: EVP_MAC_CTX_free; Key-derivation key:"
          },
          {
            "description": "",
            "method": "",
            "operatorId": "",
            "rationale": "EVP_KDF_CTX_free; Shared secret: EVP_KDF_CTX_free; Password: EVP_KDF_CTX_free; KBKDF Derived Key: EVP_KDF_CTX_free; HKDF Derived Key: EVP_KDF_CTX_free; TLS Derived Key: EVP_KDF_CTX_free; SSH Derived Key: EVP_KDF_CTX_free; X9.63 Derived Key: EVP_KDF_CTX_free; X9.42 Derived Key: EVP_KDF_CTX_free; PBKDF Derived Key: EVP_KDF_CTX_free; KDA OneStep Derived Key: EVP_KDF_CTX_free; KDA TwoStep Derived Key: EVP_KDF_CTX_free; Entropy input: EVP_RAND_CTX_free; DRBG internal state (V value, Key), DRBG internal state (V value, C value): EVP_RAND_CTX_free; DH public \u0026 private key: EVP_PKEY_free; EC public \u0026 private key: EVP_PKEY_free; RSA public \u0026 private key: EVP_PKEY_free"
          },
          {
            "description": "Automatically zeroized by the module when no longer needed",
            "method": "Automatic",
            "operatorId": "N/A",
            "rationale": "Memory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable."
          },
          {
            "description": "De-allocates the volatile memory used to store SSPs",
            "method": "Module Reset",
            "operatorId": "By unloading and reloading the module",
            "rationale": "Volatile memory used by the module is overwritten within nanoseconds when power is removed."
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 3
      },
      "storage_areas": {
        "entries": [
          {
            "description": "Temporary storage for SSPs used by the module as part of service execution. SSPs are stored until they are zeroized by the operator (using a zeroization call or removing power from the module) or zeroized automatically",
            "name": "RAM",
            "persistance": "Dynamic"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 1
      },
      "tested_module_id_hw": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "tested_module_id_hw_hy": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "tested_module_id_sw_fw_hy": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "tested_op_env_sw_fw_hy": {
        "entries": [
          {
            "hardwarePlatform": "SuperMicro SuperChassis 825BTQC-R1K23LPB and Motherboard H12DSi-NT6",
            "hypervisorHostOs": "N/A",
            "operatingSystem": "SUSE Linux Enterprise Server 15 SP6",
            "paa_pai": "Yes",
            "processors": "AMD EPYC \u2122 7343",
            "version": "1.1"
          },
          {
            "hardwarePlatform": "SuperMicro SuperChassis 825BTQC-R1K23LPB and Motherboard H12DSi-NT6",
            "hypervisorHostOs": "N/A",
            "operatingSystem": "SUSE Linux Enterprise Server 15 SP6",
            "paa_pai": "No",
            "processors": "AMD EPYC \u2122 7343",
            "version": "1.1"
          },
          {
            "hardwarePlatform": "GIGABYTE R152-P30",
            "hypervisorHostOs": "N/A",
            "operatingSystem": "SUSE Linux Enterprise Server 15 SP6",
            "paa_pai": "Yes",
            "processors": "Ampere\u00ae Altra\u00ae Q80- 30",
            "version": "1.1"
          },
          {
            "hardwarePlatform": "GIGABYTE R152-P30",
            "hypervisorHostOs": "N/A",
            "operatingSystem": "SUSE Linux Enterprise Server 15 SP6",
            "paa_pai": "No",
            "processors": "Ampere\u00ae Altra\u00ae Q80- 30",
            "version": "1.1"
          },
          {
            "hardwarePlatform": "IBM z16 A01",
            "hypervisorHostOs": "N/A",
            "operatingSystem": "SUSE Linux Enterprise Server 15 SP6",
            "paa_pai": "Yes",
            "processors": "IBM\u00ae Telum \u2122",
            "version": "1.1"
          },
          {
            "hardwarePlatform": "IBM z16 A01",
            "hypervisorHostOs": "N/A",
            "operatingSystem": "SUSE Linux Enterprise Server 15 SP6",
            "paa_pai": "No",
            "processors": "IBM\u00ae Telum \u2122",
            "version": "1.1"
          },
          {
            "hardwarePlatform": "ASUS RS700-E11-RS4U",
            "hypervisorHostOs": "N/A",
            "operatingSystem": "SUSE Linux Enterprise Server 15 SP6",
            "paa_pai": "Yes",
            "processors": "Intel\u00ae Xeon\u00ae Gold 5416S",
            "version": "1.1"
          },
          {
            "hardwarePlatform": "ASUS RS700-E11-RS4U",
            "hypervisorHostOs": "N/A",
            "operatingSystem": "SUSE Linux Enterprise Server 15 SP6",
            "paa_pai": "No",
            "processors": "Intel\u00ae Xeon\u00ae Gold 5416S",
            "version": "1.1"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 2
      },
      "vendor_affirmed_algos": {
        "entries": [
          {
            "algoPropList": "",
            "implName": "N/A",
            "name": "Asymmetric Cryptographic Key Generation (CKG)",
            "reference": "SP 800-133 Rev. 2, section 4, example 1"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "vendor_affirmed_op_env_sw_fw_hy": {
        "entries": [
          {
            "hardwarePlatform": "ASUS RS700-E11-RS4U on Intel\u00ae Xeon\u00ae Gold 5416S",
            "operatingSystem": "SUSE Linux Enterprise Server for SAP 15SP6"
          },
          {
            "hardwarePlatform": "ASUS RS700-E11-RS4U on Intel\u00ae Xeon\u00ae Gold 5416S",
            "operatingSystem": "SUSE Linux Enterprise Desktop 15SP6"
          },
          {
            "hardwarePlatform": "ASUS RS700-E11-RS4U on Intel\u00ae Xeon\u00ae Gold 5416S",
            "operatingSystem": "SUSE Linux Enterprise Base Container Image 15SP6"
          },
          {
            "hardwarePlatform": "SuperMicro SuperChassis 825BTQCR1K23LPB and Motherboard H12DSi-NT6 on AMD EPYC \u2122 7343",
            "operatingSystem": "SUSE Linux Enterprise Server for SAP 15SP6"
          },
          {
            "hardwarePlatform": "SuperMicro SuperChassis 825BTQCR1K23LPB and Motherboard H12DSi-NT6 on AMD EPYC \u2122 7343",
            "operatingSystem": "SUSE Linux Enterprise Desktop 15SP6"
          },
          {
            "hardwarePlatform": "SuperMicro SuperChassis 825BTQCR1K23LPB and Motherboard H12DSi-NT6 on AMD EPYC \u2122 7343",
            "operatingSystem": "SUSE Linux Enterprise Base Container Image 15SP6"
          },
          {
            "hardwarePlatform": "IBM z16 A01 on IBM\u00ae Telum \u2122",
            "operatingSystem": "SUSE Linux Enterprise Server for SAP 15SP6"
          },
          {
            "hardwarePlatform": "IBM z16 A01 on IBM\u00ae Telum \u2122",
            "operatingSystem": "SUSE Linux Enterprise Base Container Image 15SP6"
          },
          {
            "hardwarePlatform": "IBM LinuxONE III Model LT1 QEMU VM on z15",
            "operatingSystem": "SUSE Linux Enterprise Server 15SP6"
          },
          {
            "hardwarePlatform": "IBM LinuxONE III Model LT1 QEMU VM on z15",
            "operatingSystem": "SUSE Linux Enterprise Base Container Image 15SP6"
          },
          {
            "hardwarePlatform": "QEMU VM on AMD EPYC \u2122 7773X",
            "operatingSystem": "SUSE Linux Enterprise Server Real Time 15SP6"
          },
          {
            "hardwarePlatform": "QEMU VM on AMD EPYC \u2122 7773X",
            "operatingSystem": "SUSE Linux Enterprise Server for SAP 15SP6"
          },
          {
            "hardwarePlatform": "QEMU VM on AMD EPYC \u2122 7773X",
            "operatingSystem": "SUSE Linux Enterprise Base Container Image 15SP6"
          },
          {
            "hardwarePlatform": "QEMU VM on AMD EPYC \u2122 7773X",
            "operatingSystem": "SUSE Linux Enterprise Server 15SP6"
          },
          {
            "hardwarePlatform": "QEMU VM on Intel\u00ae i7-1195G7",
            "operatingSystem": "SUSE Linux Enterprise Desktop 15SP6"
          },
          {
            "hardwarePlatform": "GIGABYTE R152-P30 on Ampere\u00ae Altra\u00ae Q80-30",
            "operatingSystem": "SUSE Linux Enterprise Base Container Image 15SP6"
          },
          {
            "hardwarePlatform": "QEMU VM on Ampere\u00ae Altra\u00ae Q80-30",
            "operatingSystem": "SUSE Linux Enterprise Server for SAP 15SP6"
          },
          {
            "hardwarePlatform": "QEMU VM on Ampere\u00ae Altra\u00ae Q80-30",
            "operatingSystem": "SUSE Linux Enterprise Base Container Image 15SP6"
          },
          {
            "hardwarePlatform": "QEMU VM on Ampere\u00ae Altra\u00ae Q80-30",
            "operatingSystem": "SUSE Linux Enterprise Server 15SP6"
          },
          {
            "hardwarePlatform": "QEMU VM on Intel\u00ae Xeon\u00ae Gold 6338",
            "operatingSystem": "SUSE Linux Enterprise Server 15SP6"
          },
          {
            "hardwarePlatform": "QEMU VM on Intel\u00ae Xeon\u00ae Gold 5218R",
            "operatingSystem": "SUSE Linux Enterprise Server for SAP 15SP6"
          },
          {
            "hardwarePlatform": "ASUS RS700-E11-RS4U on Intel\u00ae Xeon\u00ae Gold 5416S",
            "operatingSystem": "SUSE Linux Enterprise Server for SAP 15SP7"
          },
          {
            "hardwarePlatform": "SuperMicro SuperChassis 825BTQCR1K23LPB and Motherboard H12DSi-NT6 on AMD EPYC \u2122 7343",
            "operatingSystem": "SUSE Linux Enterprise Server for SAP 15SP7"
          },
          {
            "hardwarePlatform": "ASUS RS700-E11-RS4U on Intel\u00ae Xeon\u00ae Gold 5416S",
            "operatingSystem": "SUSE Linux Enterprise Desktop 15SP7"
          },
          {
            "hardwarePlatform": "SuperMicro SuperChassis 825BTQCR1K23LPB and Motherboard H12DSi-NT6 on AMD EPYC \u2122 7343",
            "operatingSystem": "SUSE Linux Enterprise Desktop 15SP7"
          },
          {
            "hardwarePlatform": "ASUS RS700-E11-RS4U on Intel\u00ae Xeon\u00ae Gold 5416S",
            "operatingSystem": "SUSE Linux Enterprise Base Container Image 15SP7"
          },
          {
            "hardwarePlatform": "SuperMicro SuperChassis 825BTQCR1K23LPB and Motherboard H12DSi-NT6 on AMD EPYC \u2122 7343",
            "operatingSystem": "SUSE Linux Enterprise Base Container Image 15SP7"
          },
          {
            "hardwarePlatform": "GIGABYTE R152-P30 on Ampere\u00ae Altra\u00ae Q80-30",
            "operatingSystem": "SUSE Linux Enterprise Base Container Image 15SP7"
          },
          {
            "hardwarePlatform": "IBM z16 A01 on IBM\u00ae Telum \u2122",
            "operatingSystem": "SUSE Linux Enterprise Base Container Image 15SP7"
          },
          {
            "hardwarePlatform": "IBM LinuxONE III Model LT1 on z15",
            "operatingSystem": "SUSE Linux Enterprise Base Container Image 15SP7"
          },
          {
            "hardwarePlatform": "IBM LinuxONE III Model LT1 on z15",
            "operatingSystem": "SUSE Linux Enterprise Server 15SP7"
          },
          {
            "hardwarePlatform": "IBM z16 A01 on IBM\u00ae Telum \u2122",
            "operatingSystem": "SUSE Linux Enterprise Server 15SP7"
          },
          {
            "hardwarePlatform": "ASUS RS700-E11-RS4U on Intel\u00ae Xeon\u00ae Gold 5416S",
            "operatingSystem": "SUSE Linux Enterprise Server 15SP7"
          },
          {
            "hardwarePlatform": "SuperMicro SuperChassis 825BTQCR1K23LPB and Motherboard H12DSi-NT6 on AMD EPYC \u2122 7343",
            "operatingSystem": "SUSE Linux Enterprise Server 15SP7"
          },
          {
            "hardwarePlatform": "GIGABYTE R152-P30 on Ampere\u00ae Altra\u00ae Q80-30",
            "operatingSystem": "SUSE Linux Enterprise Server 15SP7"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 2
      }
    },
    "is_br1_format": true,
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 1
          },
          "ECDH": {
            "ECDH": 13
          },
          "ECDSA": {
            "ECDSA": 87
          },
          "EdDSA": {
            "EdDSA": 1
          }
        },
        "FF": {
          "DH": {
            "DH": 44,
            "DHE": 2,
            "Diffie-Hellman": 11
          }
        },
        "RSA": {
          "RSA-PSS": 3
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 2
        },
        "CCM": {
          "CCM": 2
        },
        "CFB": {
          "CFB": 1
        },
        "CTR": {
          "CTR": 1
        },
        "ECB": {
          "ECB": 1
        },
        "GCM": {
          "GCM": 18
        },
        "OFB": {
          "OFB": 1
        },
        "XTS": {
          "XTS": 9
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {
        "OpenSSL": {
          "OpenSSL": 130
        }
      },
      "crypto_protocol": {
        "IKE": {
          "IKE": 6
        },
        "SSH": {
          "SSH": 42
        },
        "TLS": {
          "TLS": {
            "TLS": 32,
            "TLS 1.2": 7,
            "TLS 1.3": 6,
            "TLS v1.2": 24,
            "TLS v1.3": 6
          }
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 6
        },
        "KEX": {
          "Key Exchange": 2
        },
        "MAC": {
          "MAC": 10
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-224": 34,
          "P-256": 74,
          "P-384": 34,
          "P-521": 70
        }
      },
      "eval_facility": {
        "atsec": {
          "atsec": 2
        }
      },
      "fips_cert_id": {},
      "fips_certlike": {
        "Certlike": {
          "- PKCS 1": 2,
          "AES-128": 15,
          "AES-192": 5,
          "AES-256": 7,
          "HMAC SHA-256": 19,
          "HMAC-SHA-1": 4,
          "PKCS 1": 2,
          "PKCS#1": 56,
          "SHA- 1": 3,
          "SHA- 2": 1,
          "SHA- 256": 4,
          "SHA- 384": 5,
          "SHA- 512": 1,
          "SHA-1": 55,
          "SHA-224": 13,
          "SHA-256": 76,
          "SHA-3": 11,
          "SHA-384": 4,
          "SHA-512": 12,
          "SHA2- 256": 5,
          "SHA2- 384": 7,
          "SHA2- 512": 1,
          "SHA2-224": 15,
          "SHA2-256": 58,
          "SHA2-384": 10,
          "SHA2-512": 30,
          "SHA3- 224": 4,
          "SHA3- 256": 8,
          "SHA3- 384": 3,
          "SHA3- 512": 5,
          "SHA3-224": 12,
          "SHA3-256": 14,
          "SHA3-384": 13,
          "SHA3-512": 12
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 2
        }
      },
      "hash_function": {
        "PBKDF": {
          "PBKDF": 31,
          "PBKDF2": 8
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 55
          },
          "SHA2": {
            "SHA-224": 13,
            "SHA-256": 76,
            "SHA-384": 4,
            "SHA-512": 12
          },
          "SHA3": {
            "SHA-3": 11,
            "SHA3-224": 12,
            "SHA3-256": 14,
            "SHA3-384": 13,
            "SHA3-512": 12
          }
        },
        "SHAKE": {
          "SHAKE128": 9,
          "SHAKE256": 9
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 48
        },
        "RNG": {
          "RBG": 2,
          "RNG": 1
        }
      },
      "side_channel_analysis": {
        "SCA": {
          "side-channel": 1,
          "timing attacks": 2
        }
      },
      "standard_id": {
        "FIPS": {
          "FIPS 140": 1,
          "FIPS 140-3": 140,
          "FIPS 180-4": 8,
          "FIPS 186-2": 2,
          "FIPS 186-4": 4,
          "FIPS 186-5": 21,
          "FIPS 1862": 1,
          "FIPS 197": 1,
          "FIPS 198-1": 12,
          "FIPS 202": 7,
          "FIPS PUB 140-3": 3,
          "FIPS186-2": 2,
          "FIPS186-4": 2,
          "FIPS186-5": 116
        },
        "NIST": {
          "NIST SP 800-131A": 1,
          "SP 800-108": 2,
          "SP 800-132": 7,
          "SP 800-133": 4,
          "SP 800-135": 8,
          "SP 800-140B": 1,
          "SP 800-38A": 2,
          "SP 800-38B": 1,
          "SP 800-38C": 1,
          "SP 800-38D": 1,
          "SP 800-38E": 3,
          "SP 800-38F": 3,
          "SP 800-52": 2,
          "SP 800-56A": 9,
          "SP 800-56B": 2,
          "SP 800-56C": 1,
          "SP 800-90A": 7,
          "SP 800-90B": 1
        },
        "PKCS": {
          "PKCS 1": 2,
          "PKCS#1": 28
        },
        "RFC": {
          "RFC 3526": 3,
          "RFC 4253": 1,
          "RFC 5288": 3,
          "RFC 6668": 1,
          "RFC 7919": 3,
          "RFC 8446": 1,
          "RFC7627": 15,
          "RFC8446": 2
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 51,
            "AES-": 1,
            "AES-128": 15,
            "AES-192": 5,
            "AES-256": 7
          },
          "CAST": {
            "CAST": 305
          }
        },
        "constructions": {
          "MAC": {
            "CMAC": 4,
            "HMAC": 45
          }
        }
      },
      "tee_name": {
        "AMD": {
          "PSP": 6
        },
        "IBM": {
          "SSC": 9
        }
      },
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "module_algorithms": {
      "_type": "Set",
      "elements": [
        "KDA HKDF SP800-56Cr2A5863",
        "KAS-FFC-SSC Sp800-56Ar3A5898",
        "RSA SigVer (FIPS186-5)A5889",
        "PBKDFA5889",
        "SHA2-256A5889",
        "AES-ECBA5900",
        "HMAC-SHA3-384A5885",
        "KDA TwoStep SP800-56Cr2A5897",
        "HMAC-SHA2-512/224A5889",
        "AES-CBCA5658",
        "TLS v1.3 KDFA5863",
        "SHA2-512/224A5889",
        "HMAC-SHA2-512A5889",
        "HMAC-SHA3-512A5885",
        "SHA3-512A5885",
        "SHA3-224A5885",
        "AES-GCMA5905",
        "HMAC-SHA3-224A5885",
        "SHA-1A5889",
        "KDA OneStep SP800-56Cr2A5897",
        "TLS v1.2 KDF RFC7627A5889",
        "AES-CMACA5658",
        "AES-KWPA5658",
        "ECDSA SigVer (FIPS186-5)A5889",
        "AES-XTS Testing Revision 2.0A5658",
        "ECDSA SigGen (FIPS186-5)A5889",
        "SHA2-512A5889",
        "AES-CBC-CS3A5658",
        "KDF ANS 9.63A5889",
        "RSA KeyGen (FIPS186-5)A5889",
        "KTS-IFCA5889",
        "SHAKE-128A5885",
        "AES-CCMA5658",
        "HMAC-SHA-1A5889",
        "HMAC DRBGA5397",
        "HMAC-SHA3-256A5885",
        "KDF SP800-108A5899",
        "HMAC-SHA2-384A5889",
        "RSA SigVer (FIPS186-4)A5889",
        "Safe Primes Key VerificationA5898",
        "KDF SSHA5900",
        "AES-CBC-CS1A5658",
        "RSA SigVer (FIPS186-2)A5889",
        "SHA2-224A5889",
        "AES-CTRA5658",
        "HMAC-SHA2-224A5889",
        "KAS-IFC-SSCA5889",
        "HMAC-SHA2-256A5889",
        "AES-CBC-CS2A5658",
        "SHAKE-256A5885",
        "HMAC-SHA2-512/256A5889",
        "AES-OFBA5658",
        "Counter DRBGA5397",
        "AES-GMACA5905",
        "ECDSA KeyVer (FIPS186-5)A5889",
        "SHA2-512/256A5889",
        "SHA3-256A5885",
        "SHA3-384A5885",
        "Hash DRBGA5397",
        "KAS-ECC-SSC Sp800-56Ar3A5889",
        "AES-CFB1A5658",
        "AES-KWA5658",
        "RSA SigGen (FIPS186-5)A5889",
        "Safe Primes Key GenerationA5898",
        "AES-CFB128A5658",
        "KDF ANS 9.42A5889",
        "SHA2-384A5889",
        "ECDSA KeyGen (FIPS186-5)A5889",
        "AES-CFB8A5658"
      ]
    },
    "policy_algorithms": {
      "_type": "Set",
      "elements": [
        "#A5872",
        "#A5897",
        "#A5905",
        "#A5882",
        "#A5398",
        "#A5903",
        "#A5904",
        "#A5868",
        "#A5894",
        "#A5875",
        "#A5887",
        "#A5900",
        "#A5870",
        "#A5397",
        "#A5877",
        "#A5864",
        "#A5886",
        "#A5883",
        "#A5888",
        "#A5658",
        "#A5874",
        "#A5402",
        "#A5885",
        "#A5403",
        "#A5884",
        "#A5895",
        "#A5893",
        "#A5896",
        "#A5873",
        "#A5898",
        "#A5399",
        "#A5881",
        "#A5871",
        "#A5879",
        "#A5869",
        "#A5889",
        "#A5899",
        "#A5863",
        "#A5876",
        "#A5880",
        "#A5401",
        "#A5400",
        "#A5878"
      ]
    },
    "policy_metadata": {
      "/CreationDate": "D:20260811094840-04\u002700\u0027",
      "/Creator": "Microsoft\u00ae Word for Microsoft 365",
      "/ModDate": "D:20260811094840-04\u002700\u0027",
      "/Producer": "Microsoft\u00ae Word for Microsoft 365",
      "pdf_file_size_bytes": 1237613,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Cr2.pdf",
          "https://www.ietf.org/rfc/rfc7919.txt",
          "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-108r1-upd1.pdf",
          "https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-4.pdf",
          "https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-5.pdf",
          "https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf",
          "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90B.pdf",
          "https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-135r1.pdf",
          "https://www.ietf.org/rfc/rfc5288.txt",
          "https://webstore.ansi.org/standards/ascx9/ansix9422001",
          "https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.202.pdf",
          "https://csrc.nist.gov/projects/cmvp/sp800-140b",
          "https://csrc.nist.gov/csrc/media/Projects/cryptographic-module-validation-program/documents/fips%20140-3/FIPS%20140-3%20IG.pdf",
          "https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38a.pdf",
          "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38b.pdf",
          "https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38a-add.pdf",
          "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-133r2.pdf",
          "https://www.ietf.org/rfc/rfc3526.txt",
          "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38F.pdf",
          "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-52r2.pdf",
          "https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-3.pdf",
          "https://webstore.ansi.org/standards/ascx9/ansix9632001",
          "https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38c.pdf",
          "https://csrc.nist.gov/publications/fips/fips198-1/FIPS-198-1_final.pdf",
          "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Ar3.pdf",
          "https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38e.pdf",
          "https://csrc.nist.gov/publications/fips/fips197/fips-197.pdf",
          "https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-132.pdf",
          "https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38d.pdf",
          "https://www.ietf.org/rfc/rfc8446.txt",
          "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90Ar1.pdf"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 120
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.InternalState",
    "module": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "policy": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": "9798ab352bbd2bea4369d4517c8bb94a22c9f81e77a420a575ba7a1c4fe15881",
      "source_hash": "358c72548a2b33a92170b41246df8a4d4ea286db417e7988644dfb24f4f7f1f1",
      "txt_hash": "e9ae18d8405a8155664c4072ab290dc28f3b42e3af12c782c78ba5ad4ace671a"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/November 2025_181225_1202.pdf",
    "date_sunset": "2030-11-25",
    "description": "SUSE Linux Enterprise Server 15 SP6 OpenSSL FIPS provider implementation providing cryptographic services to Linux user space software components. The module was tested with 64-bit word size.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Physical security: N/A",
      "Non-invasive security: N/A"
    ],
    "fw_versions": null,
    "historical_reason": null,
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {},
    "module_name": "SUSE Linux Enterprise OpenSSL 3 Cryptographic Module",
    "module_type": "Software",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-3",
    "status": "active",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2025-11-26",
        "lab": "atsec information security corporation",
        "validation_type": "Initial"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2026-03-02",
        "lab": "atsec information security corporation",
        "validation_type": "Update"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2026-08-17",
        "lab": "atsec information security corporation",
        "validation_type": "Update"
      }
    ],
    "vendor": "SUSE LLC",
    "vendor_url": "http://www.suse.com"
  }
}