Ubuntu Strongswan Cryptographic Module

Certificate details

Certificate ID #2978
Status historical
Historical reason Moved to historical list due to dependency on certificate #2888
Validation dates 31.07.2017 , 27.08.2019 , 18.10.2021
Standard FIPS 140-2
Security level 1
Type Software
Embodiment Multi-Chip Stand Alone
Caveat When operated in FIPS mode with module Ubuntu OpenSSL Cryptographic Module validated to FIPS 140-2 under Cert. #2888 operating in FIPS mode and with module Ubuntu Kernel Crypto API Cryptographic Module validated to FIPS140-2 under Cert. #2962 operating in FIPS mode
Exceptions
  • Physical Security: N/A
  • Mitigation of Other Attacks: N/A
Description Ubuntu Strongswan Cryptographic Module provides cryptographic services for the Internet Key Exchange (IKE) protocol in the Ubuntu Operating System user space.
Tested configurations
  • Ubuntu 16.04 LTS 64-bit Little Endian running on IBM Power System 8001-22C with PAA
  • Ubuntu 16.04 LTS 64-bit Little Endian running on IBM Power System 8001-22C without PAA
  • Ubuntu 16.04 LTS 64-bit Little Endian running on IBM Power System 8247-22L with PAA
  • Ubuntu 16.04 LTS 64-bit Little Endian running on IBM Power System 8247-22L without PAA
  • Ubuntu 16.04 LTS 64-bit Little Endian running on IBM Power System 8335-GTB with PAA
  • Ubuntu 16.04 LTS 64-bit Little Endian running on IBM Power System 8335-GTB without PAA
  • Ubuntu 16.04 LTS 64-bit running on IBM z13 with PAI
  • Ubuntu 16.04 LTS 64-bit running on IBM z13 without PAI (single-user mode)
  • Ubuntu 16.04 LTS 64-bit running on Supermicro SYS-5018R-WR with PAA
  • Ubuntu 16.04 LTS 64-bit running on Supermicro SYS-5018R-WR without PAA
Vendor Canonical Ltd. http://www.canonical.com
Lab atsec information security corporation
References

This certificate's webpage directly references 2 certificates, transitively this expands into 2 certificates.

Security policy

Extracted keywords

Symmetric Algorithms
AES, DES, Triple-DES, HMAC, HMAC-SHA-256
Asymmetric Algorithms
ECDSA, ECC, Diffie-Hellman, DSA
Hash functions
SHA-1, SHA-256, SHA-384, SHA-512, SHA-224
Schemes
MAC, Key Exchange, Key Agreement
Protocols
SSH, IKEv2, IKE
Randomness
DRBG, RNG
Libraries
OpenSSL
Elliptic Curves
P-224, P-256, P-384, P-521
Block cipher modes
CBC, CTR, GCM

Security level
Level 1

Cross-references

Outgoing
  • 2888 - historical - Ubuntu OpenSSL Cryptographic Module
  • 2962 - historical - Ubuntu Kernel Crypto API Cryptographic Module

Automated analysis

Automated inference - use with caution

All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.

No automatically derived data are available in this section.

Cross-references

Loading...

Processing updates

Feed
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 2978,
  "dgst": "7201cd85ae026345",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "CVL#1056",
        "SHS#3597",
        "CVL#1159",
        "SHS#3693",
        "HMAC#2970",
        "SHS#3593",
        "HMAC#2897",
        "DRBG#1397",
        "SHS#3596",
        "ECDSA#1033",
        "DRBG#1396",
        "SHS#3599",
        "SHS#3694",
        "RSA#2351",
        "HMAC#2896",
        "ECDSA#1034",
        "AES#4361",
        "DRBG#1394",
        "AES#4370",
        "RSA#2352",
        "HMAC#2898",
        "HMAC#2972",
        "CVL#1065",
        "AES#4355",
        "SHS#3598",
        "HMAC#2977",
        "ECDSA#1032",
        "RSA#2356",
        "AES#4360",
        "AES#4356",
        "HMAC#2900",
        "HMAC#2971",
        "CVL#1068",
        "DRBG#1393",
        "AES#4371",
        "CVL#1054",
        "CVL#1157",
        "CVL#1067",
        "RSA#2354",
        "HMAC#2976",
        "SHS#3691",
        "RSA#2355",
        "HMAC#2895",
        "CVL#1156",
        "Triple-DES#2357",
        "CVL#1155",
        "ECDSA#1035",
        "AES#4357",
        "CVL#1069",
        "Triple-DES#2355",
        "RSA#2357",
        "HMAC#2899",
        "CVL#1053",
        "SHS#3595",
        "SHS#3594",
        "CVL#1060",
        "SHS#3689",
        "ECDSA#1037",
        "HMAC#2973",
        "CVL#1158",
        "CVL#1057",
        "DRBG#1395",
        "AES#4373",
        "CVL#1059",
        "CVL#1160",
        "ECDSA#1031",
        "SHS#3687",
        "AES#4354",
        "ECDSA#1036",
        "Triple-DES#2356",
        "DRBG#1392",
        "SHS#3690",
        "CVL#1062",
        "CVL#1063",
        "AES#4375",
        "CVL#1154",
        "AES#4374",
        "RSA#2353",
        "DRBG#1391",
        "HMAC#2901",
        "DRBG#1390",
        "AES#4359",
        "AES#4372",
        "SHS#3688",
        "AES#4358",
        "HMAC#2974"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "-"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": {
        "_type": "Set",
        "elements": [
          "2888",
          "2962"
        ]
      },
      "indirectly_referenced_by": null,
      "indirectly_referencing": {
        "_type": "Set",
        "elements": [
          "2888",
          "2962"
        ]
      }
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": [
        "2888",
        "2962"
      ]
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": {
        "_type": "Set",
        "elements": [
          "2888",
          "2962"
        ]
      },
      "indirectly_referenced_by": null,
      "indirectly_referencing": {
        "_type": "Set",
        "elements": [
          "1915",
          "1648",
          "2962",
          "2214",
          "2888"
        ]
      }
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": [
        "2888",
        "2962"
      ]
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 1
          },
          "ECDSA": {
            "ECDSA": 9
          }
        },
        "FF": {
          "DH": {
            "Diffie-Hellman": 29
          },
          "DSA": {
            "DSA": 1
          }
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 11
        },
        "CTR": {
          "CTR": 1
        },
        "GCM": {
          "GCM": 6
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {
        "OpenSSL": {
          "OpenSSL": 34
        }
      },
      "crypto_protocol": {
        "IKE": {
          "IKE": 3,
          "IKEv2": 45
        },
        "SSH": {
          "SSH": 1
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 2
        },
        "KEX": {
          "Key Exchange": 4
        },
        "MAC": {
          "MAC": 4
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-224": 4,
          "P-256": 6,
          "P-384": 6,
          "P-521": 6
        }
      },
      "eval_facility": {
        "atsec": {
          "atsec": 36
        }
      },
      "fips_cert_id": {
        "Cert": {
          "#1031": 1,
          "#1032": 1,
          "#1033": 1,
          "#1034": 1,
          "#1035": 1,
          "#1036": 1,
          "#1037": 1,
          "#1053": 6,
          "#1054": 3,
          "#1056": 6,
          "#1057": 3,
          "#1059": 6,
          "#1060": 3,
          "#1062": 3,
          "#1063": 4,
          "#1065": 7,
          "#1067": 6,
          "#1068": 3,
          "#1069": 7,
          "#1154": 3,
          "#1155": 3,
          "#1156": 3,
          "#1157": 3,
          "#1158": 3,
          "#1159": 3,
          "#1160": 3,
          "#1390": 1,
          "#1391": 1,
          "#1392": 1,
          "#1393": 1,
          "#1394": 1,
          "#1395": 1,
          "#1396": 1,
          "#1397": 1,
          "#2351": 1,
          "#2352": 1,
          "#2353": 1,
          "#2354": 1,
          "#2355": 2,
          "#2356": 2,
          "#2357": 2,
          "#2888": 1,
          "#2895": 1,
          "#2896": 1,
          "#2897": 1,
          "#2898": 1,
          "#2899": 1,
          "#2900": 1,
          "#2901": 1,
          "#2962": 1,
          "#2970": 1,
          "#2971": 1,
          "#2972": 1,
          "#2973": 1,
          "#2974": 1,
          "#2976": 1,
          "#2977": 1,
          "#3593": 1,
          "#3594": 1,
          "#3595": 1,
          "#3596": 1,
          "#3597": 1,
          "#3598": 1,
          "#3599": 1,
          "#3687": 1,
          "#3688": 1,
          "#3689": 1,
          "#3690": 1,
          "#3691": 1,
          "#3693": 1,
          "#3694": 1,
          "#4354": 1,
          "#4355": 1,
          "#4356": 1,
          "#4357": 1,
          "#4358": 1,
          "#4359": 1,
          "#4360": 1,
          "#4361": 1,
          "#4370": 1,
          "#4371": 1,
          "#4372": 1,
          "#4373": 1,
          "#4374": 1,
          "#4375": 1
        }
      },
      "fips_certlike": {
        "Certlike": {
          "#1037 HMAC": 1,
          "#1069 DRBG": 1,
          "#2357 Diffie-Hellman": 1,
          "#2357 SHS": 1,
          "#2901 RSA": 1,
          "#2977 SHS": 1,
          "AES #4354": 1,
          "CVL #1053": 4,
          "CVL #1054": 1,
          "CVL #1154": 1,
          "CVL #1155": 1,
          "CVL #1158": 1,
          "Cert. AES": 1,
          "Cert. HMAC": 1,
          "DRBG #1390": 1,
          "Diffie-Hellman CVL #1053": 2,
          "HMAC #2895": 2,
          "HMAC #2970": 2,
          "HMAC SHA-1": 3,
          "HMAC SHA-256": 3,
          "HMAC SHA-384": 2,
          "HMAC SHA-512": 2,
          "HMAC-SHA-1": 2,
          "HMAC-SHA-256": 4,
          "RSA #2351": 1,
          "SHA- 256": 6,
          "SHA- 384": 1,
          "SHA-1": 14,
          "SHA-224": 1,
          "SHA-256": 9,
          "SHA-384": 10,
          "SHA-512": 11,
          "SHS #3593": 1,
          "SHS #3687": 1
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 5
        }
      },
      "hash_function": {
        "SHA": {
          "SHA1": {
            "SHA-1": 14
          },
          "SHA2": {
            "SHA-224": 1,
            "SHA-256": 9,
            "SHA-384": 10,
            "SHA-512": 11
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 4
        },
        "RNG": {
          "RNG": 1
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-2": 46,
          "FIPS PUB 140-2": 1,
          "FIPS140-2": 1
        },
        "RFC": {
          "RFC5282": 2
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 11
          }
        },
        "DES": {
          "3DES": {
            "Triple-DES": 6
          },
          "DES": {
            "DES": 1
          }
        },
        "constructions": {
          "MAC": {
            "HMAC": 33,
            "HMAC-SHA-256": 2
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "Alejandro Fabio Masino",
      "/CreationDate": "D:20190815180128-05\u002700\u0027",
      "/Creator": "Microsoft\u00ae Office Word 2007",
      "/ModDate": "D:20190815180128-05\u002700\u0027",
      "/Producer": "Microsoft\u00ae Office Word 2007",
      "/Title": "FIPS 140-2 Non-Proprietary Security Policy",
      "pdf_file_size_bytes": 769451,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "http://csrc.nist.gov/groups/STM/cavp/documents/dss/rsanewval.html#2351",
          "http://csrc.nist.gov/groups/STM/cavp/documents/mac/hmacval.html#3693",
          "http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-135r1.pdf",
          "http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html?#4357",
          "http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html?#4370",
          "http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html?#4374",
          "http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html?#4360",
          "http://csrc.nist.gov/groups/STM/cavp/documents/components/componentnewval.html#1053",
          "http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html?#4373",
          "http://csrc.nist.gov/groups/STM/cavp/documents/dss/rsanewval.html#2355",
          "http://csrc.nist.gov/groups/STM/cmvp/documents/fips140-2/FIPS1402IG.pdf",
          "http://csrc.nist.gov/publications/fips/fips140-2/fips1402.pdf",
          "http://csrc.nist.gov/groups/STM/cavp/documents/des/tripledesnewval.html?#2356",
          "http://csrc.nist.gov/groups/STM/cavp/documents/components/componentnewval.html#1065",
          "http://csrc.nist.gov/groups/STM/cavp/documents/drbg/drbgnewval.html#1394",
          "http://csrc.nist.gov/groups/STM/cavp/documents/mac/hmacval.html#2974",
          "http://csrc.nist.gov/groups/STM/cavp/documents/shs/shaval.html#3593",
          "http://csrc.nist.gov/groups/STM/cavp/documents/drbg/drbgnewval.html#1395",
          "http://csrc.nist.gov/groups/STM/cavp/documents/mac/hmacval.html#3690",
          "http://csrc.nist.gov/groups/STM/cavp/documents/components/componentnewval.html#1160",
          "http://csrc.nist.gov/groups/STM/cmvp/documents/140-1/140sp/140sp2962.pdf",
          "http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html?#4358",
          "http://csrc.nist.gov/groups/STM/cavp/documents/drbg/drbgnewval.html#1396",
          "http://csrc.nist.gov/groups/STM/cavp/documents/components/componentnewval.html#1156",
          "http://csrc.nist.gov/groups/STM/cavp/documents/des/tripledesnewval.html?#2355",
          "http://csrc.nist.gov/groups/STM/cavp/documents/shs/shaval.html#3595",
          "http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html?#4372",
          "http://csrc.nist.gov/groups/STM/cavp/documents/mac/hmacval.html#2972",
          "http://csrc.nist.gov/groups/STM/cavp/documents/shs/shaval.html#3599",
          "http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html?#4359",
          "http://csrc.nist.gov/groups/STM/cavp/documents/dss/rsanewval.html#2353",
          "http://csrc.nist.gov/groups/STM/cavp/documents/mac/hmacval.html#3691",
          "http://csrc.nist.gov/groups/STM/cavp/documents/dss/ecdsanewval.html#1032",
          "http://csrc.nist.gov/groups/STM/cavp/documents/shs/shaval.html#3597",
          "http://csrc.nist.gov/groups/STM/cavp/documents/drbg/drbgnewval.html#1397",
          "http://csrc.nist.gov/groups/STM/cavp/documents/mac/hmacval.html#2898",
          "http://csrc.nist.gov/groups/STM/cavp/documents/mac/hmacval.html#2900",
          "http://csrc.nist.gov/groups/STM/cavp/documents/components/componentnewval.html#1157",
          "http://csrc.nist.gov/groups/STM/cmvp/documents/140-1/140sp/140sp2888.pdf",
          "http://csrc.nist.gov/groups/STM/cavp/documents/mac/hmacval.html#2896",
          "http://csrc.nist.gov/groups/STM/cavp/documents/mac/hmacval.html#3689",
          "http://csrc.nist.gov/groups/STM/cavp/documents/components/componentnewval.html#1159",
          "http://csrc.nist.gov/groups/STM/cavp/documents/mac/hmacval.html#2970",
          "http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html?#4375",
          "http://csrc.nist.gov/groups/STM/cavp/documents/components/componentnewval.html#1069",
          "http://csrc.nist.gov/groups/STM/cavp/documents/mac/hmacval.html#2971",
          "http://csrc.nist.gov/groups/STM/cavp/documents/components/componentnewval.html#1056",
          "http://csrc.nist.gov/groups/STM/cavp/documents/shs/shaval.html#3596",
          "http://csrc.nist.gov/groups/STM/cavp/documents/dss/ecdsanewval.html#1037",
          "http://csrc.nist.gov/groups/STM/cavp/documents/dss/ecdsanewval.html#1034",
          "http://csrc.nist.gov/groups/STM/cavp/documents/mac/hmacval.html#3694",
          "http://csrc.nist.gov/groups/STM/cavp/documents/dss/rsanewval.html#2354",
          "http://csrc.nist.gov/groups/STM/cavp/documents/mac/hmacval.html#2973",
          "http://csrc.nist.gov/groups/STM/cavp/documents/drbg/drbgnewval.html#1",
          "http://csrc.nist.gov/groups/STM/cavp/documents/components/componentnewval.html#1154",
          "http://csrc.nist.gov/groups/STM/cavp/documents/components/componentnewval.html#1054",
          "http://csrc.nist.gov/groups/STM/cavp/documents/components/componentnewval.html#1068",
          "http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html?#4356",
          "http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html?#4371",
          "http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html?#4354",
          "http://csrc.nist.gov/groups/STM/cavp/documents/mac/hmacval.html#3688",
          "http://csrc.nist.gov/groups/STM/cavp/documents/mac/hmacval.html#3687",
          "http://csrc.nist.gov/groups/STM/cavp/documents/shs/shaval.html#3594",
          "http://csrc.nist.gov/groups/STM/cavp/documents/dss/rsanewval.html#2357",
          "http://csrc.nist.gov/groups/STM/cavp/documents/dss/rsanewval.html#2352",
          "http://csrc.nist.gov/groups/STM/cavp/documents/des/tripledesnewval.html?#2357",
          "http://csrc.nist.gov/groups/STM/cavp/documents/dss/ecdsanewval.html#1031",
          "http://csrc.nist.gov/groups/STM/cavp/documents/mac/hmacval.html#2897",
          "http://csrc.nist.gov/groups/STM/cavp/documents/mac/hmacval.html#2899",
          "https://tools.ietf.org/html/rfc5282",
          "http://csrc.nist.gov/groups/STM/cavp/documents/dss/ecdsanewval.html#1035",
          "http://csrc.nist.gov/groups/STM/cavp/documents/components/componentnewval.html#1155",
          "http://csrc.nist.gov/groups/STM/cavp/documents/components/componentnewval.html#1057",
          "http://csrc.nist.gov/groups/STM/cavp/documents/shs/shaval.html#3598",
          "http://csrc.nist.gov/groups/STM/cavp/documents/components/componentnewval.html#1060",
          "http://csrc.nist.gov/groups/STM/cavp/documents/mac/hmacval.html#2895",
          "http://csrc.nist.gov/groups/STM/cavp/documents/components/componentnewval.html#1062",
          "http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html?#4361",
          "http://csrc.nist.gov/groups/STM/cavp/documents/components/componentnewval.html#1059",
          "http://csrc.nist.gov/groups/STM/cavp/documents/mac/hmacval.html#2901",
          "http://csrc.nist.gov/groups/STM/cavp/documents/mac/hmacval.html#2977",
          "http://csrc.nist.gov/groups/STM/cavp/documents/components/componentnewval.html#1067",
          "http://csrc.nist.gov/groups/STM/cavp/documents/drbg/drbgnewval.html#1390",
          "http://csrc.nist.gov/groups/STM/cavp/documents/dss/ecdsanewval.html#1033",
          "http://csrc.nist.gov/groups/STM/cavp/documents/components/componentnewval.html#1158",
          "http://csrc.nist.gov/groups/STM/cavp/documents/dss/rsanewval.html#2356",
          "http://csrc.nist.gov/groups/STM/cavp/documents/drbg/drbgnewval.html#1393",
          "http://csrc.nist.gov/groups/STM/cavp/documents/dss/ecdsanewval.html#1036",
          "http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html?#4355",
          "http://csrc.nist.gov/groups/STM/cavp/documents/components/componentnewval.html#1063",
          "http://csrc.nist.gov/groups/STM/cavp/documents/drbg/drbgnewval.html#1392",
          "http://csrc.nist.gov/groups/STM/cavp/documents/mac/hmacval.html#2976",
          "http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar1.pdf"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 34
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.InternalState",
    "module": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "policy": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": "e4b59c1835f5ed86d1f945204bd3464839d53b61f438b812eb60be54d29cfcd8",
      "txt_hash": "067a4f18347cfb28dd47cdcf709f79b398243f140d133c07a3db6a0974236004"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in FIPS mode with module Ubuntu OpenSSL Cryptographic Module validated to FIPS 140-2 under Cert. #2888 operating in FIPS mode and with module Ubuntu Kernel Crypto API Cryptographic Module validated to FIPS140-2 under Cert. #2962 operating in FIPS mode",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/FIPS140ConsolidatedCertJuly2017.pdf",
    "date_sunset": null,
    "description": "Ubuntu Strongswan Cryptographic Module provides cryptographic services for the Internet Key Exchange (IKE) protocol in the Ubuntu Operating System user space.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Physical Security: N/A",
      "Mitigation of Other Attacks: N/A"
    ],
    "fw_versions": null,
    "historical_reason": "Moved to historical list due to dependency on certificate #2888",
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {
      "2888": 1,
      "2962": 1
    },
    "module_name": "Ubuntu Strongswan Cryptographic Module",
    "module_type": "Software",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-2",
    "status": "historical",
    "sw_versions": "1.0 and 1.1",
    "tested_conf": [
      "Ubuntu 16.04 LTS 64-bit Little Endian running on IBM Power System 8001-22C with PAA",
      "Ubuntu 16.04 LTS 64-bit Little Endian running on IBM Power System 8001-22C without PAA",
      "Ubuntu 16.04 LTS 64-bit Little Endian running on IBM Power System 8247-22L with PAA",
      "Ubuntu 16.04 LTS 64-bit Little Endian running on IBM Power System 8247-22L without PAA",
      "Ubuntu 16.04 LTS 64-bit Little Endian running on IBM Power System 8335-GTB with PAA",
      "Ubuntu 16.04 LTS 64-bit Little Endian running on IBM Power System 8335-GTB without PAA",
      "Ubuntu 16.04 LTS 64-bit running on IBM z13 with PAI",
      "Ubuntu 16.04 LTS 64-bit running on IBM z13 without PAI (single-user mode)",
      "Ubuntu 16.04 LTS 64-bit running on Supermicro SYS-5018R-WR with PAA",
      "Ubuntu 16.04 LTS 64-bit running on Supermicro SYS-5018R-WR without PAA"
    ],
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2017-07-31",
        "lab": "atsec information security corporation",
        "validation_type": "Initial"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2019-08-27",
        "lab": "atsec information security corporation",
        "validation_type": "Update"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2021-10-18",
        "lab": "atsec information security corporation",
        "validation_type": "Update"
      }
    ],
    "vendor": "Canonical Ltd.",
    "vendor_url": "http://www.canonical.com"
  }
}