{"_type": "sec_certs.sample.fips.FIPSCertificate", "dgst": "64eda62b35a3b686", "cert_id": 5404, "web_data": {"_type": "sec_certs.sample.fips.FIPSCertificate.WebData", "module_name": "Boot Manager", "validation_history": [{"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry", "date": "2026-08-31", "validation_type": "Initial", "lab": "Leidos Accredited Testing & Evaluation (AT&E) Lab"}], "vendor_url": "http://www.microsoft.com", "vendor": "Microsoft Corporation", "certificate_pdf_url": null, "module_type": "Software-Hybrid", "standard": "FIPS 140-3", "status": "active", "level": 1, "caveat": "When installed, initialized and configured as specified in Section 11 of the Security Policy. When operated in approved mode with module Kernel Mode Cryptographic Primitives Library (cng.sys) validated to FIPS 140-3 under Cert. #5408 operating in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs", "exceptions": ["Non-invasive security: N/A"], "embodiment": "MultiChipStand", "description": "The Windows Boot Manager module is a multi-chip standalone software-hybrid cryptographic module. Boot Manager is the first Windows OS component to load when the computer powers up. When Secure Boot is enabled, the integrity of Boot Manager is validated before loading by the computer\u2019s UEFI firmware. Along with other startup and initialization tasks, Boot Manager loads and cryptographically validates the integrity of Winload.efi (the Windows OS Loader), the next module in the startup sequence. The Boot Manager, which includes parts of BitLocker disk encryption, collects authorization factors, known as \u201cprotectors\u201d, by reading data or interacting with the user. BitLocker uses these protectors to encrypt entire disk volumes.", "tested_conf": null, "hw_versions": null, "fw_versions": null, "sw_versions": null, "mentioned_certs": {"5408": 1}, "historical_reason": null, "date_sunset": "2031-08-30", "revoked_reason": null, "revoked_link": null}, "pdf_data": {"_type": "sec_certs.sample.fips.FIPSCertificate.PdfData", "keywords": {"fips_cert_id": {"Cert": {"#5408": 1, "#1": 1}}, "fips_security_level": {"Level": {"level 1": 1, "Level 1": 4}}, "fips_certlike": {"Certlike": {"SHA-1": 8, "SHA2-256": 14, "SHA2-384": 7, "SHA2-512": 7, "SHA2- 256": 2, "SHA2": 3, "SHA1": 1, "- PKCS 1": 2, "RSA PKCS #1": 1, "AES-256": 2, "PKCS 1": 2, "PKCS #1": 1}}, "vendor": {"Microsoft": {"Microsoft Corporation": 56, "Microsoft": 29}}, "eval_facility": {}, "symmetric_crypto": {"AES_competition": {"AES": {"AES-256": 2, "AES": 27, "AES-": 5}, "CAST": {"CAST": 68}}}, "asymmetric_crypto": {}, "pq_crypto": {}, "hash_function": {"SHA": {"SHA1": {"SHA-1": 8, "SHA1": 1}, "SHA2": {"SHA2": 3}}, "PBKDF": {"PBKDF": 13, "PBKDF1": 7}}, "crypto_scheme": {"MAC": {"MAC": 1}}, "crypto_protocol": {"TLS": {"SSL": {"SSL": 1}, "TLS": {"TLS": 1}}}, "randomness": {"PRNG": {"DRBG": 10}, "RNG": {"RBG": 2}}, "cipher_mode": {"CBC": {"CBC": 4}, "CCM": {"CCM": 1}}, "ecc_curve": {}, "crypto_engine": {}, "tls_cipher_suite": {}, "crypto_library": {}, "vulnerability": {}, "side_channel_analysis": {}, "device_model": {}, "tee_name": {"AMD": {"PSP": 1}}, "os_name": {}, "cplc_data": {}, "ic_data_group": {}, "standard_id": {"FIPS": {"FIPS 140-3": 9, "FIPS 186-4": 11, "FIPS PUB 140-3": 1, "FIPS 198-1": 2, "FIPS186-4": 17, "FIPS 180-4": 9, "FIPS 186-5": 6, "FIPS 197": 1}, "NIST": {"SP 800-38A": 4, "SP 800-38C": 3, "SP 800-38E": 2, "SP 800-132": 2, "SP 800-90A": 2, "NIST SP 800-133": 19, "SP 800-38F": 2, "NIST SP 800-132": 11, "SP 800-133": 2}, "PKCS": {"PKCS 1": 2, "PKCS #1": 1}, "ISO": {"ISO/IEC 19790:2012": 1}}, "javacard_version": {}, "javacard_api_const": {}, "javacard_packages": {}, "certification_process": {"OutOfScope": {"out of scope": 1, "executing in a modifiable environment, non-invasive security requirements are optional and are out of scope for this validation. Section Title Security Level 1 General 1 2 Cryptographic module specification": 1}}}, "policy_metadata": {"pdf_file_size_bytes": 1512353, "pdf_is_encrypted": false, "pdf_number_of_pages": 50, "/Author": "Hawes, David J. (Fed)", "/CreationDate": "D:20260825100522-04'00'", "/Creator": "Microsoft\u00ae Word for Microsoft 365", "/MSIP_Label_4dd2c6e0-f1e3-4cf2-bd0b-256ab4cff3af_ActionId": "0cf5034e-758b-458a-a492-337d5f79acfb", "/MSIP_Label_4dd2c6e0-f1e3-4cf2-bd0b-256ab4cff3af_ContentBits": "1", "/MSIP_Label_4dd2c6e0-f1e3-4cf2-bd0b-256ab4cff3af_Enabled": "true", "/MSIP_Label_4dd2c6e0-f1e3-4cf2-bd0b-256ab4cff3af_Method": "Privileged", "/MSIP_Label_4dd2c6e0-f1e3-4cf2-bd0b-256ab4cff3af_Name": "UNCLASSIFIED", "/MSIP_Label_4dd2c6e0-f1e3-4cf2-bd0b-256ab4cff3af_SetDate": "2026-08-25T14:01:19Z", "/MSIP_Label_4dd2c6e0-f1e3-4cf2-bd0b-256ab4cff3af_SiteId": "da9cbe40-ec1e-4997-afb3-17d87574571a", "/MSIP_Label_4dd2c6e0-f1e3-4cf2-bd0b-256ab4cff3af_Tag": "10, 0, 1, 1", "/MSIP_Label_c968a81f-7ed4-4faa-9408-9652e001dd96_ActionId": "053ef52b-2470-4759-b3b9-5244ca34e381", "/MSIP_Label_c968a81f-7ed4-4faa-9408-9652e001dd96_ContentBits": "0", "/MSIP_Label_c968a81f-7ed4-4faa-9408-9652e001dd96_Enabled": "true", "/MSIP_Label_c968a81f-7ed4-4faa-9408-9652e001dd96_Method": "Privileged", "/MSIP_Label_c968a81f-7ed4-4faa-9408-9652e001dd96_Name": "Unrestricted", "/MSIP_Label_c968a81f-7ed4-4faa-9408-9652e001dd96_SetDate": "2024-05-09T18:50:49Z", "/MSIP_Label_c968a81f-7ed4-4faa-9408-9652e001dd96_SiteId": "b64da4ac-e800-4cfc-8931-e607f720a1b8", "/ModDate": "D:20260825100522-04'00'", "/Producer": "Microsoft\u00ae Word for Microsoft 365", "pdf_hyperlinks": {"_type": "Set", "elements": ["http://www.microsoft.com/en-us/howtotell/default.aspx", "https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/use/manage-servers", "https://csrc.nist.gov/publications/detail/fips/140/3/final", "https://csrc.nist.gov/pubs/fips/186-5/final", "https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-nkpu/832d73ae-7ba6-4578-9f8d-ca09adf9c685", "https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.security/get-authenticodesignature", "https://csrc.nist.gov/publications/detail/fips/197/final", "https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.management/get-itemproperty", "https://csrc.nist.gov/publications/detail/fips/186/4/final", "https://csrc.nist.gov/publications/detail/sp/800-132/final", "https://csrc.nist.gov/publications/detail/sp/800-133/rev-2/final", "https://csrc.nist.gov/publications/detail/fips/180/4/final"]}}}, "heuristics": {"_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics", "algorithms": {"_type": "Set", "elements": ["PBKDFA4009", "RSA SigVer (FIPS186-4)A3768", "SHA-1A4009", "HMAC-SHA2-256A4009", "AES-CCMA3749", "AES-XTS Testing Revision 2.0A4009", "SHA2-384A4009", "SHA2-256A4009", "SHA2-512A4009", "Counter DRBGA4009", "AES-CBCA4009"]}, "extracted_versions": {"_type": "Set", "elements": ["-"]}, "cpe_matches": null, "verified_cpe_matches": null, "related_cves": null, "policy_prunned_references": {"_type": "Set", "elements": ["5408"]}, "module_prunned_references": {"_type": "Set", "elements": ["5408"]}, "policy_processed_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": {"_type": "Set", "elements": ["5405"]}, "indirectly_referenced_by": {"_type": "Set", "elements": ["5407", "5408", "5409", "5406", "5405", "5404", "5410"]}, "directly_referencing": {"_type": "Set", "elements": ["5408"]}, "indirectly_referencing": {"_type": "Set", "elements": ["5404", "5405", "5408"]}}, "module_processed_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": {"_type": "Set", "elements": ["5405"]}, "indirectly_referenced_by": {"_type": "Set", "elements": ["5407", "5408", "5409", "5406", "5405", "5404", "5410"]}, "directly_referencing": {"_type": "Set", "elements": ["5408"]}, "indirectly_referencing": {"_type": "Set", "elements": ["5404", "5405", "5408"]}}, "direct_transitive_cves": {"_type": "Set", "elements": ["CVE-2018-0599", "CVE-2021-36958", "CVE-2010-3889", "CVE-1999-0524", "CVE-2010-3143", "CVE-2011-5049", "CVE-2008-6194", "CVE-2010-3888", "CVE-2011-0638", "CVE-2018-0598", "CVE-2011-3389", "CVE-2012-2971", "CVE-2010-2157", "CVE-2012-2972", "CVE-2010-3139"]}, "indirect_transitive_cves": {"_type": "Set", "elements": ["CVE-2018-0599", "CVE-2021-36958", "CVE-2010-3889", "CVE-1999-0524", "CVE-2010-3143", "CVE-2011-5049", "CVE-2008-6194", "CVE-2010-3888", "CVE-2011-0638", "CVE-2018-0598", "CVE-2011-3389", "CVE-2012-2971", "CVE-2010-2157", "CVE-2012-2972", "CVE-2010-3139"]}}, "state": {"_type": "sec_certs.sample.fips.InternalState", "module": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": null, "txt_hash": null, "json_hash": null}, "policy": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": "62e14e49ab1cfe87de2b314c697af1bdbcf1d3f4e78f17670d17a860c71c05e6", "txt_hash": "b1277514018c6128137dc9b545a1ca3614c3a984153596b86cfced282e129e59", "json_hash": null}}}