VMware’s Linux Kernel Cryptographic Module

Certificate details

Certificate ID #4865
Status historical
Historical reason Replaced by certificate #5286
Validation dates 05.11.2024
Standard FIPS 140-3
Security level 1
Type Software
Embodiment Multi-Chip Stand Alone
Caveat Interim validation. When operated in approved mode and installed, initialized and configured as specified in Section 11.1 of the Security Policy.
Exceptions
  • Physical security: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A
Description The VMware's Linux Kernel Cryptographic Module 5.0.0 offers symmetric encryption/decryption, digital signature generation/verification, hashing, cryptographic key generation, random number generation, message authentication, and key establishment functions to secure data.
Vendor Broadcom Inc. http://www.broadcom.com
Lab Lightship Security, Inc.
Algorithms
  • AES-CBC-CS3A4971
  • AES-CBCA4971
  • AES-CCMA4971
  • AES-CFB128A4971
  • AES-CMACA4971
  • AES-CTRA4971
  • AES-ECBA4971
  • AES-GCMA4972
  • AES-XTS Testing Revision 2.0A4971
  • Counter DRBGA4971
  • ECDSA KeyGen (FIPS186-4)A4971
  • ECDSA KeyVer (FIPS186-4)A4971
  • ECDSA SigVer (FIPS186-4)A4971
  • Hash DRBGA4971
  • HMAC DRBGA4971
  • HMAC-SHA-1A4971
  • HMAC-SHA2-224A4971
  • HMAC-SHA2-256A4971
  • HMAC-SHA2-384A4971
  • HMAC-SHA2-512A4971
  • HMAC-SHA3-224A4971
  • HMAC-SHA3-256A4971
  • HMAC-SHA3-384A4971
  • HMAC-SHA3-512A4971
  • KAS-ECC-SSC Sp800-56Ar3A4971
  • RSA SigGen (FIPS186-4)A4971
  • RSA SigVer (FIPS186-4)A4971
  • SHA-1A4971
  • SHA2-224A4971
  • SHA2-256A4971
  • SHA2-384A4971
  • SHA2-512A4971
  • SHA3-224A4971
  • SHA3-256A4971
  • SHA3-384A4971
  • SHA3-512A4971
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Extracted keywords

Symmetric Algorithms
AES-128, AES-192, AES-256, AES, AES-, CAST, HMAC, CBC-MAC, CMAC
Asymmetric Algorithms
ECDH, ECDSA
Hash functions
SHA-1, SHA1, SHA3-224, SHA3-256, SHA3-384, SHA3-512
Schemes
MAC, Key Agreement
Protocols
IPsec
Randomness
DRBG, RNG, RBG
Elliptic Curves
P-256, P-384
Block cipher modes
CTR, GCM, CCM, XTS

Trusted Execution Environments
PSP, SSC
Vendor
Broadcom Inc

Security level
Level 1

Automated analysis

Automated inference - use with caution

All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.

No automatically derived data are available in this section.

Cross-references

No references are available for this certificate.

Processing updates

Feed
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 4865,
  "dgst": "67e912e3e2b53266",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "KAS-ECC-SSC Sp800-56Ar3A4971",
        "HMAC-SHA2-256A4971",
        "Hash DRBGA4971",
        "#A4971",
        "#A4972",
        "AES-CCMA4971",
        "HMAC-SHA3-512A4971",
        "HMAC DRBGA4971",
        "AES-CFB128A4971",
        "AES-ECBA4971",
        "ECDSA KeyGen (FIPS186-4)A4971",
        "SHA3-512A4971",
        "HMAC-SHA2-512A4971",
        "RSA SigVer (FIPS186-4)A4971",
        "SHA2-256A4971",
        "RSA SigGen (FIPS186-4)A4971",
        "AES-CBCA4971",
        "ECDSA SigVer (FIPS186-4)A4971",
        "SHA2-224A4971",
        "Counter DRBGA4971",
        "HMAC-SHA2-384A4971",
        "AES-XTS Testing Revision 2.0A4971",
        "HMAC-SHA3-256A4971",
        "SHA3-384A4971",
        "AES-GCMA4972",
        "HMAC-SHA2-224A4971",
        "SHA2-384A4971",
        "AES-CMACA4971",
        "HMAC-SHA3-384A4971",
        "SHA3-224A4971",
        "SHA2-512A4971",
        "HMAC-SHA-1A4971",
        "HMAC-SHA3-224A4971",
        "SHA-1A4971",
        "SHA3-256A4971",
        "AES-CBC-CS3A4971",
        "AES-CTRA4971",
        "ECDSA KeyVer (FIPS186-4)A4971"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "-"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "br1_deviations": 0,
    "br1_tables": {
      "_type": "sec_certs.heuristics.br1.table_parsing.model.br1_tables.BR1Tables",
      "approved_algorithms": {
        "entries": [
          {
            "algorithm": "AES-CBC",
            "cavpCertName": "A4971",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CBC-CS3",
            "cavpCertName": "A4971",
            "properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CCM",
            "cavpCertName": "A4971",
            "properties": "Key Length - 128, 192, 256",
            "reference": "SP 800-38C"
          },
          {
            "algorithm": "AES-CFB128",
            "cavpCertName": "A4971",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CMAC",
            "cavpCertName": "A4971",
            "properties": "Direction - Generation, Verification Key Length - 128, 192, 256",
            "reference": "SP 800-38B"
          },
          {
            "algorithm": "AES-CTR",
            "cavpCertName": "A4971",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A4971",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-GCM",
            "cavpCertName": "A4971",
            "properties": "Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.2 Key Length - 128, 192, 256",
            "reference": "SP 800-38D"
          },
          {
            "algorithm": "AES-XTS Testing Revision 2.0",
            "cavpCertName": "A4971",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 256",
            "reference": "SP 800-38E"
          },
          {
            "algorithm": "Counter DRBG",
            "cavpCertName": "A4971",
            "properties": "Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - Yes",
            "reference": "SP 800-90A Rev. 1"
          },
          {
            "algorithm": "ECDSA KeyGen (FIPS186-4)",
            "cavpCertName": "A4971",
            "properties": "Curve - P-256, P-384 Secret Generation Mode - Extra Bits",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA KeyVer (FIPS186-4)",
            "cavpCertName": "A4971",
            "properties": "Curve - P-256, P-384",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA SigVer (FIPS186-4)",
            "cavpCertName": "A4971",
            "properties": "Curve - P-256, P-384 Hash Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "Hash DRBG",
            "cavpCertName": "A4971",
            "properties": "Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512",
            "reference": "SP 800-90A Rev. 1"
          },
          {
            "algorithm": "HMAC DRBG",
            "cavpCertName": "A4971",
            "properties": "Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512",
            "reference": "SP 800-90A Rev. 1"
          },
          {
            "algorithm": "HMAC-SHA-1",
            "cavpCertName": "A4971",
            "properties": "Key Length - Key Length: 128-2048 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-224",
            "cavpCertName": "A4971",
            "properties": "Key Length - Key Length: 128-2048 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-256",
            "cavpCertName": "A4971",
            "properties": "Key Length - Key Length: 128-2048 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-384",
            "cavpCertName": "A4971",
            "properties": "Key Length - Key Length: 128-2048 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-512",
            "cavpCertName": "A4971",
            "properties": "Key Length - Key Length: 128-2048 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3-224",
            "cavpCertName": "A4971",
            "properties": "Key Length - Key Length: 128-2048 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3-256",
            "cavpCertName": "A4971",
            "properties": "Key Length - Key Length: 128-2048 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3-384",
            "cavpCertName": "A4971",
            "properties": "Key Length - Key Length: 128-2048 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3-512",
            "cavpCertName": "A4971",
            "properties": "Key Length - Key Length: 128-2048 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "KAS-ECC-SSC Sp800-56Ar3",
            "cavpCertName": "A4971",
            "properties": "Domain Parameter Generation Methods - P- 256, P-384 Scheme - ephemeralUnified - KAS Role - initiator, responder",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "RSA SigGen (FIPS186-4)",
            "cavpCertName": "A4971",
            "properties": "Signature Type - PKCS 1.5 Modulo - 2048, 3072, 4096",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "RSA SigVer (FIPS186-4)",
            "cavpCertName": "A4971",
            "properties": "Signature Type - PKCS 1.5 Modulo - 2048, 3072, 4096",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "SHA-1",
            "cavpCertName": "A4971",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-224",
            "cavpCertName": "A4971",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-256",
            "cavpCertName": "A4971",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-384",
            "cavpCertName": "A4971",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512",
            "cavpCertName": "A4971",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA3-224",
            "cavpCertName": "A4971",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3-256",
            "cavpCertName": "A4971",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3-384",
            "cavpCertName": "A4971",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3-512",
            "cavpCertName": "A4971",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "AES-GCM",
            "cavpCertName": "A4972",
            "properties": "Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 192, 256",
            "reference": "SP 800-38D"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "approved_services": {
        "entries": [
          {
            "description": "Installation and initialization of the module",
            "indicator": "Status output",
            "inputs": "N/A",
            "name": "Installation and initialization",
            "outputs": "Status",
            "rolesSspAccess": "Crypto Officer",
            "secFunImpl": "None"
          },
          {
            "description": "Return module status",
            "indicator": "Status output",
            "inputs": "Command input",
            "name": "Show Status",
            "outputs": "Status",
            "rolesSspAccess": "Crypto Officer",
            "secFunImpl": "None"
          },
          {
            "description": "Perform pre- operational self-tests by rebooting the OS",
            "indicator": "Status output",
            "inputs": "N/A",
            "name": "On demand self-test",
            "outputs": "Status",
            "rolesSspAccess": "Crypto Officer",
            "secFunImpl": "None"
          },
          {
            "description": "Return module",
            "indicator": "Status output,",
            "inputs": "Command input",
            "name": "Show version",
            "outputs": "Status output,",
            "rolesSspAccess": "Crypto Officer",
            "secFunImpl": "None"
          },
          {
            "description": "versioning information",
            "indicator": "Module version",
            "inputs": "",
            "name": "",
            "outputs": "Module version",
            "rolesSspAccess": "",
            "secFunImpl": ""
          },
          {
            "description": "Zeroize and de-allocate memory containing sensitive data",
            "indicator": "N/A",
            "inputs": "N/A",
            "name": "Key Zeroization",
            "outputs": "Status",
            "rolesSspAccess": "Crypto Officer - AES Key: Z - Entropy: Z - RSA Public Key: Z - RSA Private Key: Z - ECDSA Public Key: Z - ECDSA Private Key: Z - HMAC Key: Z - Hash_DRBG V value: Z - Hash_DRBG C value: Z - HMAC_DRB G V value: Z - HMAC_DRB G Key value: Z - CTR_DRBG V value: Z - CTR_DRBG Key value: Z",
            "secFunImpl": "None"
          },
          {
            "description": "Encrypt plaintext data",
            "indicator": "API return value",
            "inputs": "API Parameters , plaintext data",
            "name": "Symmetric Encryption",
            "outputs": "Status, ciphertext data",
            "rolesSspAccess": "User - AES Key: W,E - AES XTS key: W,E",
            "secFunImpl": "Symmetric Ciphers"
          },
          {
            "description": "Decrypt ciphertext data",
            "indicator": "API return value",
            "inputs": "API Parameters , ciphertext data",
            "name": "Symmetric Decryption",
            "outputs": "Status, plaintext data",
            "rolesSspAccess": "User - AES Key: W,E - AES XTS key: W,E",
            "secFunImpl": "Symmetric Ciphers"
          },
          {
            "description": "Encrypt plaintext using AES GCM key",
            "indicator": "API return value",
            "inputs": "API Parameters , plaintext data",
            "name": "Authenticate d Symmetric Encryption",
            "outputs": "Status, ciphertext data",
            "rolesSspAccess": "User - GCM Key: W,E - GCM IV: W,E",
            "secFunImpl": "Symmetric Ciphers"
          },
          {
            "description": "with IV or CCM",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "- AES CCM Key: W,E",
            "secFunImpl": ""
          },
          {
            "description": "Decrypt ciphertext using AES GCM key with IV or CCM",
            "indicator": "API return value",
            "inputs": "API Parameters , ciphertext data",
            "name": "Authenticate d Symmetric Decryption",
            "outputs": "Status, plaintext data",
            "rolesSspAccess": "User - GCM Key: W,E - GCM IV: W,E - AES CCM Key: W,E",
            "secFunImpl": "Symmetric Ciphers"
          },
          {
            "description": "Return random bits to the calling application",
            "indicator": "API return value",
            "inputs": "API Parameters",
            "name": "Generate random number",
            "outputs": "Status, random number",
            "rolesSspAccess": "User - Entropy: W,E - DRBG Random Number: W,E - Hash_DRBG V value: G,E - Hash_DRBG C value: G,E - HMAC_DRB G V value: G,E - HMAC_DRB G Key value: G,E - CTR_DRBG V value: G,E - CTR_DRBG Key value: G,E",
            "secFunImpl": "Random Number Generation"
          },
          {
            "description": "Generate Symmetric Digest",
            "indicator": "API return value",
            "inputs": "API Parameters",
            "name": "Generate Symmetric Digest",
            "outputs": "Status, Symmetric Digest",
            "rolesSspAccess": "User - AES CMAC Key: W,E",
            "secFunImpl": "Symmetric Ciphers Message Authenticatio n"
          },
          {
            "description": "Verify Symmetric Digest",
            "indicator": "API return value",
            "inputs": "API Parameters",
            "name": "Verify Symmetric Digest",
            "outputs": "Status",
            "rolesSspAccess": "User - AES CMAC Key: W,E",
            "secFunImpl": "Symmetric Ciphers Message Authenticatio n"
          },
          {
            "description": "Compute a message authenticatio n code",
            "indicator": "API return value",
            "inputs": "API Parameters",
            "name": "Perform Keyed Hash Operations",
            "outputs": "Status, Message Authenticatio n Code",
            "rolesSspAccess": "User - HMAC Key: W,E",
            "secFunImpl": "Message Authenticatio n"
          },
          {
            "description": "Compute a message digest",
            "indicator": "API return value",
            "inputs": "API Parameters",
            "name": "Perform hash operation",
            "outputs": "Status, Message Digest",
            "rolesSspAccess": "User",
            "secFunImpl": "Message Digest"
          },
          {
            "description": "Generate a public/private key pair",
            "indicator": "API return value",
            "inputs": "API Parameters",
            "name": "Generate asymmetric key pair",
            "outputs": "Status",
            "rolesSspAccess": "User - ECDSA Public Key: G,R - ECDSA Private Key: G,R",
            "secFunImpl": "Asymmetric Key Generation"
          },
          {
            "description": "Verify an ECDSA public key",
            "indicator": "API return value",
            "inputs": "API Parameters",
            "name": "Verify ECDSA public key",
            "outputs": "Status",
            "rolesSspAccess": "User - ECDSA Public Key: W",
            "secFunImpl": "Asymmetric Key Verification"
          },
          {
            "description": "Generate Digital Signature",
            "indicator": "API return value",
            "inputs": "API Parameters",
            "name": "Generate Digital Signature",
            "outputs": "Status",
            "rolesSspAccess": "User - RSA Private Key: W,E",
            "secFunImpl": "Digital Signature"
          },
          {
            "description": "Verify digital signature",
            "indicator": "API return value",
            "inputs": "API Parameters",
            "name": "Verify digital signature",
            "outputs": "Status",
            "rolesSspAccess": "User - RSA Public Key: W,E - ECDSA Public Key: W,E",
            "secFunImpl": "Digital Signature"
          },
          {
            "description": "Compute ECDH shared secret",
            "indicator": "API return value",
            "inputs": "API Parameters",
            "name": "Compute Shared Secret",
            "outputs": "Status",
            "rolesSspAccess": "User - ECDH Private Component: W,E - ECDH public component: W,E",
            "secFunImpl": "Key Agreement"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 3
      },
      "authentication_methods": {
        "entries": [],
        "found": false,
        "section": 4,
        "subsection": 1
      },
      "cond_self_tests": {
        "entries": [
          {
            "algorithmOrTest": "AES-CBC (A4971)",
            "condition": "Module Initialization",
            "details": "Encrypt/Decrypt",
            "indicator": "Status Output",
            "testMethod": "KAT",
            "testProps": "128, 192, 256-bit keys",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-CBC- CS3 (A4971)",
            "condition": "Module Initialization",
            "details": "Encrypt/Decrypt",
            "indicator": "Status Output",
            "testMethod": "KAT",
            "testProps": "128, 192, 256-bit keys",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-CCM (A4971)",
            "condition": "Module Initialization",
            "details": "Encrypt/Decrypt",
            "indicator": "Status Output",
            "testMethod": "KAT",
            "testProps": "128, 192, 256-bit keys",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES- CFB128 (A4971)",
            "condition": "Module Initialization",
            "details": "Encrypt/Decrypt",
            "indicator": "Status Output",
            "testMethod": "KAT",
            "testProps": "128, 192, 256-bit keys",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-CTR (A4971)",
            "condition": "Module Initialization",
            "details": "Encrypt/Decrypt",
            "indicator": "Status Output",
            "testMethod": "KAT",
            "testProps": "128, 192, 256-bit keys",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-ECB (A4971)",
            "condition": "Module Initialization",
            "details": "Encrypt/Decrypt",
            "indicator": "Status Output",
            "testMethod": "KAT",
            "testProps": "128, 192, 256-bit keys",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A4972)",
            "condition": "Module Initialization",
            "details": "Encrypt/Decrypt",
            "indicator": "Status Output",
            "testMethod": "KAT",
            "testProps": "128, 192, 256-bit keys",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A4971)",
            "condition": "Module Initialization",
            "details": "Encrypt/Decrypt",
            "indicator": "Status Output",
            "testMethod": "KAT",
            "testProps": "128, 192, 256-bit keys",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-CMAC (A4971)",
            "condition": "Module Initialization",
            "details": "Encrypt/Decrypt",
            "indicator": "Status Output",
            "testMethod": "KAT",
            "testProps": "128, 192, 256-bit keys",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-XTS Testing Revision 2.0 (A4971)",
            "condition": "Module Initialization",
            "details": "Encrypt/Decrypt",
            "indicator": "Status Output",
            "testMethod": "KAT",
            "testProps": "128, 256-bit keys",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-CMAC (A4971)",
            "condition": "Module Initialization",
            "details": "Message Authentication",
            "indicator": "Status Output",
            "testMethod": "KAT",
            "testProps": "128, 192, 256-bit keys",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "Counter DRBG (A4971)",
            "condition": "On instantiate, generate, and reseed",
            "details": "instantiate, generate, and reseed",
            "indicator": "Status Output",
            "testMethod": "KAT",
            "testProps": "AES-128, AES- 256, AES- 192",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA KeyGen (FIPS186-4) (A4971)",
            "condition": "After key pair generation",
            "details": "Key Generation / Key Verification",
            "indicator": "Status Output",
            "testMethod": "PCT",
            "testProps": "P-256, P-384",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "ECDSA SigVer (FIPS186-4) (A4971)",
            "condition": "After Signature Verification",
            "details": "Signature Verification",
            "indicator": "Status Output",
            "testMethod": "KAT",
            "testProps": "P-256, P-384",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "Hash DRBG (A4971)",
            "condition": "On instantiate, generate, and reseed",
            "details": "instantiate, generate, and reseed",
            "indicator": "Status Output",
            "testMethod": "KAT",
            "testProps": "SHA-1, SHA2-256, SHA2-512",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC DRBG (A4971)",
            "condition": "On instantiate, generate, and reseed",
            "details": "instantiate, generate, and reseed",
            "indicator": "Status Output",
            "testMethod": "KAT",
            "testProps": "SHA-1, SHA2-256, SHA2-512",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC",
            "condition": "Module Initialization",
            "details": "Message Authentication",
            "indicator": "Status Output",
            "testMethod": "KAT",
            "testProps": "SHA-1, SHA2-224, SHA2-256, SHA2- 384, SHA2-512 SHA3-224, SHA3- 256, SHA3-384, SHA3-512",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS-ECC- SSC Sp800- 56Ar3 (A4971)",
            "condition": "Module Initialization",
            "details": "Shared Secret Computation",
            "indicator": "Status Output",
            "testMethod": "KAT",
            "testProps": "P-256, P-384",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS-ECC- SSC Sp800- 56Ar3 (A4971)",
            "condition": "After Key pair generation",
            "details": "Shared Secret Computation",
            "indicator": "Status Output",
            "testMethod": "PCT",
            "testProps": "P-256, P-384",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "RSA SigGen (FIPS186-4) (A4971)",
            "condition": "Module Initialization",
            "details": "Signature Generation",
            "indicator": "Status Output",
            "testMethod": "KAT",
            "testProps": "PKCS1v1.5 Mod (2048, 3072, 4096) Hash (SHA2-224, SHA2-256, SHA2- 384, SHA2-512)",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186-4) (A4971)",
            "condition": "Module Initialization",
            "details": "Signature Verification",
            "indicator": "Status Output",
            "testMethod": "KAT",
            "testProps": "PKCS1v1.5 Mod (2048, 3072, 4096) Hash (SHA1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512)",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHS",
            "condition": "Module Initialization",
            "details": "Message Digest",
            "indicator": "Status Output",
            "testMethod": "KAT",
            "testProps": "SHA-1, SHA2-224, SHA2-256, SHA2- 384, SHA2-512 SHA3-224, SHA3- 256, SHA3-384, SHA3-512",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SP800- 90Ar1 Continual Health Tests",
            "condition": "Continuously while the Module is loaded",
            "details": "Message Digest",
            "indicator": "Status Output",
            "testMethod": "DRBG health tests",
            "testProps": "Hash_DRBG, HMAC_DRBG and CTR_DRBG SP 800-90Ar1 Health Tests",
            "type": "CAST"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 2
      },
      "error_states": {
        "entries": [
          {
            "conditions": "Any Self-test failure",
            "description": "The module\u0027s error state.",
            "indicator": "Status Return Code",
            "name": "Critical Error",
            "recoveryMethod": "Reboot OS"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 4
      },
      "mechanisms_actions": {
        "entries": [],
        "found": false,
        "section": 7,
        "subsection": 1
      },
      "modes_of_operation": {
        "entries": [
          {
            "description": "Approved Mode of Operation",
            "name": "Approved",
            "statusIndicator": "API return value",
            "type": "Approved"
          },
          {
            "description": "Non-Approved Mode of Operation",
            "name": "Non- Approved",
            "statusIndicator": "Non-Approved service log message and API return value",
            "type": "Non- Approved"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 4
      },
      "non_approved_allowed_NSC": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_allowed_algos": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_not_allowed": {
        "entries": [
          {
            "name": "AES CBC-MAC (SP 800-38C)",
            "use": "CBC-MAC as an authentication mode outside of the CCM context."
          },
          {
            "name": "GHASH (SP 800-38D)",
            "use": "GHASH as a keyed hash function outside of GCM context"
          },
          {
            "name": "AES GCM",
            "use": "Encryption (External IV)"
          },
          {
            "name": "RSA PKCS1v1.5",
            "use": "Key Transport"
          },
          {
            "name": "AES using modes using RFC 3686 (CTR)",
            "use": "Encryption and Decryption"
          },
          {
            "name": "AES using modes using RFC 4543 (GCM) and RFC 4309 (CCM)",
            "use": "Authenticated Encryption and Decryption"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "non_approved_services": {
        "entries": [
          {
            "alg_accessed": "AES CBC-MAC (SP 800-38C)",
            "description": "Encryption/decryption",
            "name": "Perform authenticated symmetric encryption/decryption",
            "role": "User"
          },
          {
            "alg_accessed": "GHASH (SP 800-38D)",
            "description": "Hashing",
            "name": "Perform keyed hash function",
            "role": "User"
          },
          {
            "alg_accessed": "AES GCM",
            "description": "Encryption with External IV",
            "name": "Perform authenticated symmetric encryption",
            "role": "User"
          },
          {
            "alg_accessed": "RSA PKCS1v1.5",
            "description": "Key padding / Key transport",
            "name": "RSA Key Transport",
            "role": "User"
          },
          {
            "alg_accessed": "AES using modes using RFC 3686 (CTR)",
            "description": "Encryption/decryption",
            "name": "Perform symmetric encryption/decryption",
            "role": "User"
          },
          {
            "alg_accessed": "AES using modes using RFC 4543 (GCM) and RFC 4309 (CCM)",
            "description": "Authenticated encryption/decryption",
            "name": "Perform authenticated symmetric encryption/decryption",
            "role": "User"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 4
      },
      "ports_interfaces": {
        "entries": [
          {
            "data": "Data to be encrypted, decrypted, signed, verified, or hashed. Keys to be used in cryptographic services. Random seed material for the module\u0027s DRBG. Keying material to be used as input to key establishment services",
            "logicalInterface": "Data Input",
            "physicalPort": "Physical data input port(s) of the host platform"
          },
          {
            "data": "Data that has been encrypted, decrypted, or verified. Digital signatures, Hashes, Random values generated by the module\u0027s DRBG. Keys established using module\u0027s key establishment methods",
            "logicalInterface": "Data Output",
            "physicalPort": "Physical data output port(s) of the host platform"
          },
          {
            "data": "API commands invoking cryptographic services. Modes, key sizes, etc. used with cryptographic services",
            "logicalInterface": "Control Input",
            "physicalPort": "Physical control input port(s) of the host platform"
          },
          {
            "data": "Status Output API call return values",
            "logicalInterface": "Status Output",
            "physicalPort": "Physical status output port(s) of the host platform"
          }
        ],
        "found": true,
        "section": 3,
        "subsection": 1
      },
      "roles": {
        "entries": [
          {
            "authMethodList": "None",
            "name": "Crypto Officer",
            "operatorType": "Crypto Officer",
            "type": "Role"
          },
          {
            "authMethodList": "None",
            "name": "User",
            "operatorType": "User",
            "type": "Role"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 2
      },
      "security_levels": {
        "entries": [
          {
            "level": "1",
            "section": "1",
            "title": "General"
          },
          {
            "level": "1",
            "section": "2",
            "title": "Cryptographic module specification"
          },
          {
            "level": "1",
            "section": "3",
            "title": "Cryptographic module interfaces"
          },
          {
            "level": "1",
            "section": "4",
            "title": "Roles, services, and authentication"
          },
          {
            "level": "1",
            "section": "5",
            "title": "Software/Firmware security"
          },
          {
            "level": "1",
            "section": "6",
            "title": "Operational environment"
          },
          {
            "level": "N/A",
            "section": "7",
            "title": "Physical security"
          },
          {
            "level": "N/A",
            "section": "8",
            "title": "Non-invasive security"
          },
          {
            "level": "1",
            "section": "9",
            "title": "Sensitive security parameter management"
          },
          {
            "level": "1",
            "section": "10",
            "title": "Self-tests"
          },
          {
            "level": "1",
            "section": "11",
            "title": "Life-cycle assurance"
          },
          {
            "level": "N/A",
            "section": "12",
            "title": "Mitigation of other attacks"
          },
          {
            "level": "1",
            "section": "",
            "title": "Overall Level"
          }
        ],
        "found": true,
        "section": 1,
        "subsection": 2
      },
      "self_tests": {
        "entries": [
          {
            "algorithmOrTest": "HMAC-SHA2-256 (A4971)",
            "details": "",
            "indicator": "Status Output",
            "testMethod": "Software Integrity Test",
            "testProps": "HMAC-SHA2- 256",
            "type": "SW/FW Integrity"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 1
      },
      "ssp_io_methods": {
        "entries": [
          {
            "dest": "RAM",
            "distribution": "Automated",
            "entry": "Electronic",
            "format": "Plaintext",
            "name": "External to RAM",
            "sfiAlgo": "",
            "source": "External"
          },
          {
            "dest": "External",
            "distribution": "Automated",
            "entry": "Electronic",
            "format": "Plaintext",
            "name": "RAM to External",
            "sfiAlgo": "",
            "source": "RAM"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 2
      },
      "ssp_zeroization_methods": {
        "entries": [
          {
            "description": "Reboot Operating System",
            "method": "Reboot OS",
            "operatorId": "Operator Initiated",
            "rationale": "Memory is zeroized upon reboot"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 3
      },
      "storage_areas": {
        "entries": [
          {
            "description": "Memory",
            "name": "RAM",
            "persistance": "Dynamic"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 1
      },
      "tested_module_id_hw": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "tested_module_id_hw_hy": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "tested_module_id_sw_fw_hy": {
        "entries": [
          {
            "features": "software cryptographic module",
            "integrityTest": "HMAC-SHA2-256",
            "packageFileName": "fips_canister.o",
            "swFwVersion": "5.0.0"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 2
      },
      "tested_op_env_sw_fw_hy": {
        "entries": [
          {
            "hardwarePlatform": "Dell PowerEdge R650 Server",
            "hypervisorHostOs": "VMware ESXi 8.0",
            "operatingSystem": "Photon OS 4.0",
            "paa_pai": "Yes",
            "processors": "Intel\u00ae Xeon\u00ae Gold 6330",
            "version": "5.0.0"
          },
          {
            "hardwarePlatform": "Dell PowerEdge R650 Server",
            "hypervisorHostOs": "VMware ESXi 8.0",
            "operatingSystem": "Photon OS 4.0",
            "paa_pai": "No",
            "processors": "Intel\u00ae Xeon\u00ae Gold 6330",
            "version": "5.0.0"
          },
          {
            "hardwarePlatform": "Dell PowerEdge R650 Server",
            "hypervisorHostOs": "VMware ESXi 8.0",
            "operatingSystem": "Photon OS 5.0",
            "paa_pai": "Yes",
            "processors": "Intel\u00ae Xeon\u00ae Gold 6330",
            "version": "5.0.0"
          },
          {
            "hardwarePlatform": "Dell PowerEdge R650 Server",
            "hypervisorHostOs": "VMware ESXi 8.0",
            "operatingSystem": "Photon OS 5.0",
            "paa_pai": "No",
            "processors": "Intel\u00ae Xeon\u00ae Gold 6330",
            "version": "5.0.0"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 2
      },
      "vendor_affirmed_algos": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "vendor_affirmed_op_env_sw_fw_hy": {
        "entries": [
          {
            "hardwarePlatform": "Dell PowerEdge R650 with an Intel\u00ae Xeon\u00ae Gold 6330 with/without PAA",
            "operatingSystem": "Photon OS 5.0/Photon OS 4.0 on VMware ESXi 8.0/ VMware ESXi 7.0"
          },
          {
            "hardwarePlatform": "Dell PowerEdge R740 with an Intel\u00ae Xeon\u00ae Gold 6230R with/without PAA",
            "operatingSystem": "Photon OS 5.0/ Photon OS 4.0 on VMware ESXi 8.0/ VMware ESXi 7.0"
          },
          {
            "hardwarePlatform": "Dell PowerEdge R640 with an Intel(R) Xeon(R) Silver 4214 with/without PAA",
            "operatingSystem": "Photon OS 5.0/Photon OS 4.0 on VMware ESXi 8.0/ VMware ESXi 7.0"
          },
          {
            "hardwarePlatform": "Dell PowerEdge R630 with an Intel(R) Xeon(R) CPU E5-2660 v4 with/without PAA",
            "operatingSystem": "Photon OS 5.0/Photon OS 4.0 on VMware ESXi 8.0/ VMware ESXi 7.0"
          },
          {
            "hardwarePlatform": "PowerEdge R6625 with an AMD EPYC 9124 with/without PAA",
            "operatingSystem": "Photon OS 5.0/Photon OS 4.0 on VMware ESXi 8.0/ VMware ESXi 7.0"
          },
          {
            "hardwarePlatform": "ProLiant DL385 Gen10 Plus v2 with an AMD EPYC 7343 16-Core Processor with/without PAA",
            "operatingSystem": "Photon OS 5.0/Photon OS 4.0 on VMware ESXi 8.0/ VMware ESXi 7.0"
          },
          {
            "hardwarePlatform": "General-purpose computing platform with/without PAA",
            "operatingSystem": "Cloud computing environment executing VMware ESXi or other hypervisors"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 2
      }
    },
    "is_br1_format": true,
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECDH": {
            "ECDH": 11
          },
          "ECDSA": {
            "ECDSA": 27
          }
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CCM": {
          "CCM": 11
        },
        "CTR": {
          "CTR": 2
        },
        "GCM": {
          "GCM": 23
        },
        "XTS": {
          "XTS": 6
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "IPsec": {
          "IPsec": 1
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 4
        },
        "MAC": {
          "MAC": 1
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-256": 22,
          "P-384": 24
        }
      },
      "eval_facility": {},
      "fips_cert_id": {},
      "fips_certlike": {
        "Certlike": {
          "- PKCS 1": 2,
          "AES- 192": 1,
          "AES- 256": 1,
          "AES-128": 3,
          "AES-192": 2,
          "AES-256": 2,
          "DRBG 128": 2,
          "DRBG 256": 3,
          "DRBG 440": 2,
          "HMAC SHA-1": 1,
          "HMAC-SHA-1": 4,
          "PAA 64": 1,
          "PKCS 1": 2,
          "SHA-1": 11,
          "SHA1": 1,
          "SHA2- 256": 3,
          "SHA2- 384": 3,
          "SHA2-224": 7,
          "SHA2-256": 13,
          "SHA2-384": 4,
          "SHA2-512": 13,
          "SHA3- 256": 2,
          "SHA3-224": 1,
          "SHA3-256": 2,
          "SHA3-384": 3,
          "SHA3-512": 4
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 3
        }
      },
      "hash_function": {
        "SHA": {
          "SHA1": {
            "SHA-1": 11,
            "SHA1": 1
          },
          "SHA3": {
            "SHA3-224": 4,
            "SHA3-256": 1,
            "SHA3-384": 4,
            "SHA3-512": 3
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 38
        },
        "RNG": {
          "RBG": 2,
          "RNG": 1
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-3": 6,
          "FIPS 180-4": 5,
          "FIPS 186-4": 6,
          "FIPS 198-1": 9,
          "FIPS 202": 5,
          "FIPS186-4": 18
        },
        "ISO": {
          "ISO/IEC 19790:2012": 1,
          "ISO/IEC 19790:2021": 1
        },
        "NIST": {
          "SP 800-38A": 5,
          "SP 800-38B": 1,
          "SP 800-38C": 3,
          "SP 800-38D": 4,
          "SP 800-38E": 1,
          "SP 800-56A": 1,
          "SP 800-90A": 3
        },
        "PKCS": {
          "PKCS 1": 2
        },
        "RFC": {
          "RFC 3686": 2,
          "RFC 4106": 2,
          "RFC 4309": 2,
          "RFC 4543": 2
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 34,
            "AES-": 3,
            "AES-128": 3,
            "AES-192": 2,
            "AES-256": 2
          },
          "CAST": {
            "CAST": 42
          }
        },
        "constructions": {
          "MAC": {
            "CBC-MAC": 3,
            "CMAC": 6,
            "HMAC": 16
          }
        }
      },
      "tee_name": {
        "AMD": {
          "PSP": 3
        },
        "IBM": {
          "SSC": 2
        }
      },
      "tls_cipher_suite": {},
      "vendor": {
        "Broadcom": {
          "Broadcom Inc": 31
        }
      },
      "vulnerability": {}
    },
    "module_algorithms": {
      "_type": "Set",
      "elements": [
        "KAS-ECC-SSC Sp800-56Ar3A4971",
        "HMAC-SHA2-256A4971",
        "Hash DRBGA4971",
        "AES-CCMA4971",
        "HMAC-SHA3-512A4971",
        "HMAC DRBGA4971",
        "AES-CFB128A4971",
        "AES-ECBA4971",
        "ECDSA KeyGen (FIPS186-4)A4971",
        "SHA3-512A4971",
        "HMAC-SHA2-512A4971",
        "RSA SigVer (FIPS186-4)A4971",
        "SHA2-256A4971",
        "RSA SigGen (FIPS186-4)A4971",
        "AES-CBCA4971",
        "ECDSA SigVer (FIPS186-4)A4971",
        "SHA2-224A4971",
        "Counter DRBGA4971",
        "HMAC-SHA2-384A4971",
        "AES-XTS Testing Revision 2.0A4971",
        "HMAC-SHA3-256A4971",
        "SHA3-384A4971",
        "AES-GCMA4972",
        "HMAC-SHA2-224A4971",
        "SHA2-384A4971",
        "AES-CMACA4971",
        "HMAC-SHA3-384A4971",
        "SHA3-224A4971",
        "SHA2-512A4971",
        "HMAC-SHA-1A4971",
        "HMAC-SHA3-224A4971",
        "SHA-1A4971",
        "SHA3-256A4971",
        "AES-CBC-CS3A4971",
        "AES-CTRA4971",
        "ECDSA KeyVer (FIPS186-4)A4971"
      ]
    },
    "policy_algorithms": {
      "_type": "Set",
      "elements": [
        "#A4971",
        "#A4972"
      ]
    },
    "policy_metadata": {
      "/Author": "Hawes, David J. (Fed)",
      "/Comments": "",
      "/Company": "",
      "/CreationDate": "D:20241031130243-04\u002700\u0027",
      "/Creator": "Acrobat PDFMaker 24 for Word",
      "/Keywords": "",
      "/ModDate": "D:20241031130345-04\u002700\u0027",
      "/Producer": "Adobe PDF Library 24.3.144",
      "/SourceModified": "",
      "/Subject": "",
      "/Title": "",
      "pdf_file_size_bytes": 554915,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "https://csrc.nist.gov/projects/cryptographic-module-validation-program"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 29
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.InternalState",
    "module": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "policy": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": "08180a75ec0c61708aec527fddb15712caa04de764340832611d726f92b06ca4",
      "source_hash": "6a814052dd995bdb6b475f0d37af8995cc0f8ded3d183a69915d57cb2754d39c",
      "txt_hash": "15378b6e9635a8ba392184a66fdd4722e44a781c0a89d6ffee0f03433f20e910"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "Interim validation. When operated in approved mode and installed, initialized and configured as specified in Section 11.1 of the Security Policy.",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/November 2024_021224_0125.pdf",
    "date_sunset": null,
    "description": "The VMware\u0027s Linux Kernel Cryptographic Module 5.0.0 offers symmetric encryption/decryption, digital signature generation/verification, hashing, cryptographic key generation, random number generation, message authentication, and key establishment functions to secure data.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Physical security: N/A",
      "Non-invasive security: N/A",
      "Mitigation of other attacks: N/A"
    ],
    "fw_versions": null,
    "historical_reason": "Replaced by certificate #5286",
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {},
    "module_name": "VMware\u2019s Linux Kernel Cryptographic Module",
    "module_type": "Software",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-3",
    "status": "historical",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2024-11-05",
        "lab": "Lightship Security, Inc.",
        "validation_type": "Initial"
      }
    ],
    "vendor": "Broadcom Inc.",
    "vendor_url": "http://www.broadcom.com"
  }
}