Riverbed Cryptographic Module

Certificate details

Certificate ID #5017
Status active
Validation dates 14.05.2025
Sunset date 13-05-2030
Standard FIPS 140-3
Security level 1
Type Software
Embodiment Multi-Chip Stand Alone
Caveat When operated in approved mode. No assurance of the minimum strength of generated keys
Exceptions
  • Physical security: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A
Description The Riverbed Cryptographic Module v2.0.1 is a software library providing a C language API for use by other applications requiring cryptographic functionality. Riverbed Cryptographic Module v2.0.1 offers symmetric encryption/decryption, digital signature generation/verification, hashing, cryptographic key generation, random number generation, message authentication, and key establishment functions to secure data-at-rest/data-in-flight and to support secure communications protocols (including TLS 1.2/1.3).
Vendor Riverbed Technology, LLC http://www.riverbed.com
Lab Lightship Security, Inc.
Algorithms
  • AES-CBCA5835
  • AES-CCMA5835
  • AES-CFB128A5835
  • AES-CFB1A5835
  • AES-CFB8A5835
  • AES-CMACA5835
  • AES-CTRA5835
  • AES-ECBA5835
  • AES-GCMA5835
  • AES-GMACA5835
  • AES-KWA5835
  • AES-KWPA5835
  • AES-OFBA5835
  • AES-XTS Testing Revision 2.0A5835
  • Counter DRBGA5835
  • DSA KeyGen (FIPS186-4)A5835
  • DSA PQGGen (FIPS186-4)A5835
  • DSA PQGVer (FIPS186-4)A5835
  • DSA SigGen (FIPS186-4)A5835
  • DSA SigVer (FIPS186-4)A5835
  • ECDSA KeyGen (FIPS186-4)A5835
  • ECDSA KeyVer (FIPS186-4)A5835
  • ECDSA SigGen (FIPS186-4)A5835
  • ECDSA SigVer (FIPS186-4)A5835
  • HMAC-SHA-1A5835
  • HMAC-SHA2-224A5835
  • HMAC-SHA2-256A5835
  • HMAC-SHA2-384A5835
  • HMAC-SHA2-512A5835
  • HMAC-SHA3-224A5835
  • HMAC-SHA3-256A5835
  • HMAC-SHA3-384A5835
  • HMAC-SHA3-512A5835
  • KAS-ECC-SSC Sp800-56Ar3A5835
  • KAS-FFC-SSC Sp800-56Ar3A5835
  • PBKDFA5835
  • RSA KeyGen (FIPS186-4)A5835
  • RSA SigGen (FIPS186-4)A5835
  • RSA SigVer (FIPS186-4)A5835
  • SHA-1A5835
  • SHA2-224A5835
  • SHA2-256A5835
  • SHA2-384A5835
  • SHA2-512A5835
  • SHA3-224A5835
  • SHA3-256A5835
  • SHA3-384A5835
  • SHA3-512A5835
  • SHAKE-128A5835
  • SHAKE-256A5835
  • TDES-CBCA5835
  • TDES-CFB1A5835
  • TDES-CFB64A5835
  • TDES-CFB8A5835
  • TDES-CMACA5835
  • TDES-ECBA5835
  • TDES-OFBA5835
  • TLS v1.2 KDF RFC7627A5835
  • TLS v1.3 KDFA5836
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Extracted keywords

Symmetric Algorithms
AES, AES-128, AES-192, AES-256, AES-, CAST, CAST5, RC2, RC4, RC5, DES, Triple-DES, TDES, ChaCha20, Poly1305, IDEA, Blowfish, Camellia, ARIA, SM4, SEED, HMAC, CMAC
Asymmetric Algorithms
ECDH, ECDSA, EdDSA, ECC, DHE, DH, Diffie-Hellman, DSA
Hash functions
SHA-1, SHA-256, SHA3-224, SHA3-256, SHA3-384, SHA3-512, Blake2, MD4, MD5, RIPEMD, PBKDF, PBKDF2
Schemes
MAC, Key agreement, Key Agreement
Protocols
SSL, TLS, TLS v1.2, TLS v1.3, TLS 1.2, TLS 1.3
Randomness
DRBG, RNG
Elliptic Curves
P-224, P-256, P-384, P-521, P-192, B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571, B-163, K-163
Block cipher modes
ECB, CBC, CTR, CFB, OFB, GCM, CCM, XEX, XTS

JavaCard API constants
SM2
Trusted Execution Environments
PSP

Security level
Level 1

Automated analysis

Automated inference - use with caution

All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.

No automatically derived data are available in this section.

Cross-references

No references are available for this certificate.

Processing updates

Feed
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 5017,
  "dgst": "815d19a0553b4947",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "TDES-CBCA5835",
        "DSA SigVer (FIPS186-4)A5835",
        "HMAC-SHA2-512A5835",
        "RSA KeyGen (FIPS186-4)A5835",
        "DSA SigGen (FIPS186-4)A5835",
        "AES-XTS Testing Revision 2.0A5835",
        "PBKDFA5835",
        "TDES-OFBA5835",
        "ECDSA KeyGen (FIPS186-4)A5835",
        "AES-KWPA5835",
        "HMAC-SHA3-384A5835",
        "AES-OFBA5835",
        "HMAC-SHA2-224A5835",
        "ECDSA KeyVer (FIPS186-4)A5835",
        "AES-GCMA5835",
        "DSA KeyGen (FIPS186-4)A5835",
        "AES-ECBA5835",
        "AES-KWA5835",
        "DSA PQGVer (FIPS186-4)A5835",
        "SHA3-256A5835",
        "TDES-CMACA5835",
        "TDES-CFB64A5835",
        "KAS-ECC-SSC Sp800-56Ar3A5835",
        "AES-CFB128A5835",
        "AES-CCMA5835",
        "HMAC-SHA-1A5835",
        "HMAC-SHA3-512A5835",
        "ECDSA SigGen (FIPS186-4)A5835",
        "HMAC-SHA3-256A5835",
        "SHAKE-256A5835",
        "SHA3-384A5835",
        "DSA PQGGen (FIPS186-4)A5835",
        "SHA3-224A5835",
        "#A5836",
        "HMAC-SHA2-384A5835",
        "AES-CFB1A5835",
        "TDES-ECBA5835",
        "AES-CTRA5835",
        "AES-CMACA5835",
        "Counter DRBGA5835",
        "HMAC-SHA2-256A5835",
        "SHA2-224A5835",
        "SHA3-512A5835",
        "AES-CBCA5835",
        "#A5835",
        "SHA2-512A5835",
        "KAS-FFC-SSC Sp800-56Ar3A5835",
        "ECDSA SigVer (FIPS186-4)A5835",
        "TDES-CFB1A5835",
        "TLS v1.3 KDFA5836",
        "RSA SigGen (FIPS186-4)A5835",
        "TDES-CFB8A5835",
        "SHA-1A5835",
        "AES-GMACA5835",
        "HMAC-SHA3-224A5835",
        "RSA SigVer (FIPS186-4)A5835",
        "TLS v1.2 KDF RFC7627A5835",
        "AES-CFB8A5835",
        "SHA2-384A5835",
        "SHA2-256A5835",
        "SHAKE-128A5835"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "-"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "br1_deviations": 0,
    "br1_tables": {
      "_type": "sec_certs.heuristics.br1.table_parsing.model.br1_tables.BR1Tables",
      "approved_algorithms": {
        "entries": [
          {
            "algorithm": "AES-CBC",
            "cavpCertName": "A5835",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CCM",
            "cavpCertName": "A5835",
            "properties": "Key Length - 128, 192, 256",
            "reference": "SP 800-38C"
          },
          {
            "algorithm": "AES-CFB1",
            "cavpCertName": "A5835",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CFB128",
            "cavpCertName": "A5835",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CFB8",
            "cavpCertName": "A5835",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CMAC",
            "cavpCertName": "A5835",
            "properties": "Direction - Generation, Verification Key Length - 128, 192, 256",
            "reference": "SP 800-38B"
          },
          {
            "algorithm": "AES-CTR",
            "cavpCertName": "A5835",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A5835",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-GCM",
            "cavpCertName": "A5835",
            "properties": "Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.2 Key Length - 128, 192, 256",
            "reference": "SP 800-38D"
          },
          {
            "algorithm": "AES-GMAC",
            "cavpCertName": "A5835",
            "properties": "Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256",
            "reference": "SP 800-38D"
          },
          {
            "algorithm": "AES-KW",
            "cavpCertName": "A5835",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38F"
          },
          {
            "algorithm": "AES-KWP",
            "cavpCertName": "A5835",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38F"
          },
          {
            "algorithm": "AES-OFB",
            "cavpCertName": "A5835",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-XTS Testing Revision 2.0",
            "cavpCertName": "A5835",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 256",
            "reference": "SP 800-38E"
          },
          {
            "algorithm": "Counter DRBG",
            "cavpCertName": "A5835",
            "properties": "Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - Yes",
            "reference": "SP 800-90A Rev. 1"
          },
          {
            "algorithm": "DSA KeyGen (FIPS186-4)",
            "cavpCertName": "A5835",
            "properties": "L - 2048, 3072 N - 224, 256",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "DSA PQGGen (FIPS186-4)",
            "cavpCertName": "A5835",
            "properties": "L - 2048, 3072 N - 224, 256 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "DSA PQGVer (FIPS186-4)",
            "cavpCertName": "A5835",
            "properties": "L - 1024, 2048, 3072 N - 160, 224, 256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "DSA SigGen (FIPS186-4)",
            "cavpCertName": "A5835",
            "properties": "L - 2048, 3072 N - 224, 256 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "DSA SigVer (FIPS186-4)",
            "cavpCertName": "A5835",
            "properties": "L - 2048, 3072 N - 224, 256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA KeyGen (FIPS186-4)",
            "cavpCertName": "A5835",
            "properties": "Curve - B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571, P-224, P-256, P-384, P-521 Secret Generation Mode - Testing Candidates",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA KeyVer (FIPS186-4)",
            "cavpCertName": "A5835",
            "properties": "Curve - B-163, B-233, B-283, B-409, B-571, K-163, K-233, K-283, K-409, K-571, P-192, P-224, P-256, P-384, P-521",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA SigGen (FIPS186-4)",
            "cavpCertName": "A5835",
            "properties": "Curve - B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571, P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA SigVer (FIPS186-4)",
            "cavpCertName": "A5835",
            "properties": "Curve - B-163, B-233, B-283, B-409, B-571, K-163, K-233, K-283, K-409, K-571, P-192, P-224, P-256, P-384, P-521 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "HMAC-SHA-1",
            "cavpCertName": "A5835",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-224",
            "cavpCertName": "A5835",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-256",
            "cavpCertName": "A5835",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-384",
            "cavpCertName": "A5835",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-512",
            "cavpCertName": "A5835",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3-224",
            "cavpCertName": "A5835",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3-256",
            "cavpCertName": "A5835",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3-384",
            "cavpCertName": "A5835",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3-512",
            "cavpCertName": "A5835",
            "properties": "Key Length - Key Length: 8-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "KAS-ECC-SSC Sp800- 56Ar3",
            "cavpCertName": "A5835",
            "properties": "Domain Parameter Generation Methods - B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571, P-224, P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responder",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "KAS-FFC-SSC Sp800- 56Ar3",
            "cavpCertName": "A5835",
            "properties": "Domain Parameter Generation Methods - FB, FC Scheme - dhEphem - KAS Role - initiator, responder",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "PBKDF",
            "cavpCertName": "A5835",
            "properties": "Iteration Count - Iteration Count: 10-10000 Increment 1 Password Length - Password Length: 8-128 Increment 1",
            "reference": "SP 800-132"
          },
          {
            "algorithm": "RSA KeyGen (FIPS186-4)",
            "cavpCertName": "A5835",
            "properties": "Key Generation Mode - B.3.3 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Private Key Format - Standard",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "RSA SigGen (FIPS186-4)",
            "cavpCertName": "A5835",
            "properties": "Signature Type - ANSI X9.31, PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "RSA SigVer (FIPS186-4)",
            "cavpCertName": "A5835",
            "properties": "Signature Type - ANSI X9.31, PKCS 1.5, PKCSPSS Modulo - 1024, 2048, 3072, 4096",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "SHA-1",
            "cavpCertName": "A5835",
            "properties": "Message Length - Message Length: 0-65528 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-224",
            "cavpCertName": "A5835",
            "properties": "Message Length - Message Length: 0-65528 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-256",
            "cavpCertName": "A5835",
            "properties": "Message Length - Message Length: 0-65528 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-384",
            "cavpCertName": "A5835",
            "properties": "Message Length - Message Length: 0-65528 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512",
            "cavpCertName": "A5835",
            "properties": "Message Length - Message Length: 0-65528 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA3-224",
            "cavpCertName": "A5835",
            "properties": "Message Length - Message Length: 0-65528 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3-256",
            "cavpCertName": "A5835",
            "properties": "Message Length - Message Length: 0-65528 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3-384",
            "cavpCertName": "A5835",
            "properties": "Message Length - Message Length: 0-65528 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3-512",
            "cavpCertName": "A5835",
            "properties": "Message Length - Message Length: 0-65528 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHAKE-128",
            "cavpCertName": "A5835",
            "properties": "Output Length - Output Length: 16-1024 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHAKE-256",
            "cavpCertName": "A5835",
            "properties": "Output Length - Output Length: 16-1024 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "TDES-CBC",
            "cavpCertName": "A5835",
            "properties": "Direction - Decrypt",
            "reference": "SP 800-67 Rev. 2"
          },
          {
            "algorithm": "TDES-CFB1",
            "cavpCertName": "A5835",
            "properties": "Direction - Decrypt",
            "reference": "SP 800-67 Rev. 2"
          },
          {
            "algorithm": "TDES-CFB64",
            "cavpCertName": "A5835",
            "properties": "Direction - Decrypt",
            "reference": "SP 800-67 Rev. 2"
          },
          {
            "algorithm": "TDES-CFB8",
            "cavpCertName": "A5835",
            "properties": "Direction - Decrypt",
            "reference": "SP 800-67 Rev. 2"
          },
          {
            "algorithm": "TDES-CMAC",
            "cavpCertName": "A5835",
            "properties": "Direction - Verification",
            "reference": "SP 800-67 Rev. 2"
          },
          {
            "algorithm": "TDES-ECB",
            "cavpCertName": "A5835",
            "properties": "Direction - Decrypt",
            "reference": "SP 800-67 Rev. 2"
          },
          {
            "algorithm": "TDES-OFB",
            "cavpCertName": "A5835",
            "properties": "Direction - Decrypt",
            "reference": "SP 800-67 Rev. 2"
          },
          {
            "algorithm": "TLS v1.2 KDF RFC7627 (CVL)",
            "cavpCertName": "A5835",
            "properties": "Hash Algorithm - SHA2-256, SHA2-384, SHA2-512",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "TLS v1.3 KDF (CVL)",
            "cavpCertName": "A5836",
            "properties": "HMAC Algorithm - SHA2-256, SHA2-384 KDF Running Modes - DHE, PSK, PSK-DHE",
            "reference": "SP 800-135 Rev. 1"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "approved_services": {
        "entries": [
          {
            "description": "Return FIPS mode status",
            "indicator": "API call parameters",
            "inputs": "Current operational status",
            "name": "Show Status",
            "outputs": "N/A",
            "rolesSspAccess": "Crypto Officer",
            "secFunImpl": "None"
          },
          {
            "description": "Perform pre- operational self- tests",
            "indicator": "Indicator API return value = 1",
            "inputs": "Indicator API return value = 1",
            "name": "Perform self- tests on- demand",
            "outputs": "Status",
            "rolesSspAccess": "Crypto Officer",
            "secFunImpl": "None"
          },
          {
            "description": "Zeroize and de- allocate memory containing sensitive data",
            "indicator": "N/A",
            "inputs": "Restart calling application; reboot or power-cycle host platform",
            "name": "Zeroize",
            "outputs": "None",
            "rolesSspAccess": "Crypto Officer - AES key: Z - AES CCM key : Z - AES GCM key : Z - AES XTS key : Z - AES CMAC key : Z - AES GMAC key : Z - Triple-DES key : Z - Triple-DES CMAC key : Z - HMAC key : Z - DSA public key : Z - ECDSA private key : Z - ECDSA public key : Z - RSA private key : Z - RSA public key : Z - DH private component : Z - DH public component : Z - ECDH private component : Z - ECDH public component : Z - Passphrase: Z - AES GCM IV: Z - TLS pre-",
            "secFunImpl": "None"
          },
          {
            "description": "Description",
            "indicator": "Indicator",
            "inputs": "Inputs",
            "name": "Name",
            "outputs": "Outputs",
            "rolesSspAccess": "SSP Access - DRBG seed: Z - DRBG \u0027Key\u0027 value: Z - DSA private key : Z",
            "secFunImpl": "Security Functions"
          },
          {
            "description": "Encrypt plaintext data",
            "indicator": "Indicator API return value = 1",
            "inputs": "API call parameters, key, plaintext",
            "name": "Perform symmetric encryption",
            "outputs": "Status, ciphertext",
            "rolesSspAccess": "User - AES key: W,E - AES XTS key : W,E",
            "secFunImpl": "AES for Symmetric Encryption/Decryption AES-XTS for Symmetric Encryption/Decryption"
          },
          {
            "description": "Decrypt ciphertext data",
            "indicator": "Indicator API return value = 1",
            "inputs": "API call parameters, key, ciphertext",
            "name": "Perform symmetric decryption",
            "outputs": "Status, plaintext",
            "rolesSspAccess": "User - AES key: W,E - AES XTS key : W,E - Triple-DES key : W,E",
            "secFunImpl": "AES for Symmetric Encryption/Decryption AES-XTS for Symmetric Encryption/Decryption TDES for Symmetric Decryption (legacy)"
          },
          {
            "description": "Generate symmetric digest",
            "indicator": "Indicator API return value = 1",
            "inputs": "API call parameters, key, plaintext",
            "name": "Generate symmetric digest",
            "outputs": "Status, digest",
            "rolesSspAccess": "User - AES CMAC key : W,E - AES GMAC key : W,E",
            "secFunImpl": "AES-CMAC for MAC Generation/Verification TDES for MAC Verification (legacy)"
          },
          {
            "description": "Verify symmetric digest",
            "indicator": "Indicator API return value = 1",
            "inputs": "API call parameters, digest",
            "name": "Verify symmetric digest",
            "outputs": "API call parameters, digest",
            "rolesSspAccess": "User - AES GCM key : W,E - AES GCM IV: W,E - Triple-DES CMAC key : W,E",
            "secFunImpl": "AES-CMAC for MAC Generation/Verification AES-GMAC for MAC Generation/Verification"
          },
          {
            "description": "Encrypt plaintext using supplied AES GCM key and IV",
            "indicator": "Encrypt plaintext using supplied AES GCM key and IV",
            "inputs": "API call parameters, key, plaintext",
            "name": "Perform authenticated encryption",
            "outputs": "Status, ciphertext, tab",
            "rolesSspAccess": "User - AES GCM key : W,E - AES GCM IV: W,E - AES CCM key : W,E",
            "secFunImpl": "AES-CCM for Authenticated Symmetric Encryption/Decryption AES-GCM for Authenticated Symmetric Encryption/Decryption"
          },
          {
            "description": "Decrypt ciphertext using supplied AES GCM key and IV",
            "indicator": "Indicator API return value = 1",
            "inputs": "Indicator API return value = 1",
            "name": "Perform authenticated decryption",
            "outputs": "Status, plaintext",
            "rolesSspAccess": "User - AES CCM key : W,E - AES GCM key : W,E - AES GCM IV: W,E",
            "secFunImpl": "AES-CCM for Authenticated Symmetric Encryption/Decryption AES-GCM for Authenticated Symmetric Encryption/Decryption"
          },
          {
            "description": "Return random bits to the calling application",
            "indicator": "Indicator API return value = 1",
            "inputs": "API call parameters, entropy DRBG state values",
            "name": "Generate random number",
            "outputs": "Status, random number",
            "rolesSspAccess": "User - DRBG entropy input: G,E - DRBG seed: G,E - DRBG \u0027V\u0027 value: G,E - DRBG \u0027Key\u0027 value: G,E",
            "secFunImpl": "DRBG"
          },
          {
            "description": "Compute a message authentication code",
            "indicator": "Indicator API return value = 1",
            "inputs": "API call parameters, key, message",
            "name": "Perform keyed hash operations",
            "outputs": "Status, MAC",
            "rolesSspAccess": "User - HMAC key : W,E",
            "secFunImpl": "HMAC for Message Authentication"
          },
          {
            "description": "Generate a message digest",
            "indicator": "Indicator API return value = 1",
            "inputs": "Indicator API return value = 1",
            "name": "Generate message digest",
            "outputs": "Status, digest",
            "rolesSspAccess": "User",
            "secFunImpl": "SHA/SHAKE for Message Digest"
          },
          {
            "description": "Generate a public/private key pair",
            "indicator": "Indicator API return value = 1",
            "inputs": "Indicator API return value = 1",
            "name": "Generate asymmetric key pair",
            "outputs": "Status, key pair",
            "rolesSspAccess": "User - ECDSA private key : G - ECDSA public key : G - RSA private key : G - RSA public key : G",
            "secFunImpl": "ECDSA for Key Generation RSA for Key Generation DSA for Domain Parameter Generation DSA for Key Generation"
          },
          {
            "description": "Verify an ECDSA public key",
            "indicator": "Indicator API return value = 1",
            "inputs": "API call parameters, key",
            "name": "Verify ECDSA public key",
            "outputs": "Status",
            "rolesSspAccess": "User - ECDSA public key : W",
            "secFunImpl": "ECDSA for Key Verification ECDSA for Key Verification (legacy)"
          },
          {
            "description": "Generate a digital signature",
            "indicator": "Indicator API return value = 1",
            "inputs": "API call parameters, key, message",
            "name": "Generate digital signature",
            "outputs": "Status, signature",
            "rolesSspAccess": "User - ECDSA private key : W,E - RSA private key : W,E",
            "secFunImpl": "ECDSA for Digital Signature Generation RSA for Signature Generation DSA for Digital Signature Generation"
          },
          {
            "description": "Verify a digital signature",
            "indicator": "Indicator API return value = 1",
            "inputs": "API call parameters, key, signature, message",
            "name": "Verify digital signature",
            "outputs": "Status",
            "rolesSspAccess": "User - DSA public key : W,E - ECDSA public key : W,E - RSA public key : W,E",
            "secFunImpl": "DSA for Digital Signature Verification (legacy) ECDSA for Digital Signature Verification RSA for Signature Verification ECDSA for Digital Signature Verification (legacy) RSA for Signature"
          },
          {
            "description": "Perform key wrap",
            "indicator": "Indicator API return value = 1",
            "inputs": "API call parameters, encryption key, key",
            "name": "Perform key wrap",
            "outputs": "Status, encrypted key",
            "rolesSspAccess": "User - AES key: W,E - AES CCM key : W,E - AES CMAC key : W,E - AES GMAC key : W,E - AES GCM key : W,E - AES GCM IV: W,E - HMAC key :",
            "secFunImpl": "Verification (legacy) KTS-AES+MAC KTS-AES-CCM KTS-AES-GCM KTS-AES-KW AES+MAC for Key Wrap/Unwrap"
          },
          {
            "description": "Perform key unwrap",
            "indicator": "Indicator API return value = 1",
            "inputs": "API call parameters, decryption key, key",
            "name": "Perform key unwrap",
            "outputs": "Status, decrypted key",
            "rolesSspAccess": "User - AES key: W,E - AES CCM key : W,E - AES CMAC key : W,E - AES GMAC key : W,E - AES GCM key : W,E - AES GCM IV: W,E - HMAC key : W,E - Triple-DES key : W,E",
            "secFunImpl": "KTS-AES+MAC KTS-AES-CCM KTS-AES-GCM KTS-AES-KW AES for Unauthenticated Key Unwrap (allowed) (legacy) TDES+MAC for Key Unwrap (legacy) TDES for Unauthenticated Key Unwrap (allowed) (legacy) AES+MAC for Key Wrap/Unwrap"
          },
          {
            "description": "Perform key unwrap Compute DH/ECDH shared secret suitable for use as input to a TLS KDF",
            "indicator": "Perform key unwrap Compute DH/ECDH shared secret suitable for use as input to a TLS KDF",
            "inputs": "API call parameters",
            "name": "Compute shared secret",
            "outputs": "API call parameters",
            "rolesSspAccess": "User - DH public component : W,E - DH private component : W,E - ECDH private component : W,E - ECDH public component : W,E - TLS pre- master secret: G,E",
            "secFunImpl": "DSA KeyGen for DH ECDSA KeyGen for ECDH ECDH Shared Secret Computation DH Shared Secret Computation"
          },
          {
            "description": "Derive TLS session and integrity keys",
            "indicator": "Indicator API return value = 1",
            "inputs": "API call parameters, TLS pre- master secret",
            "name": "Derive TLS keys",
            "outputs": "Status, TLS keys",
            "rolesSspAccess": "User - AES key: G,R - AES GCM key : G,R - AES GCM IV: G,R - HMAC key : G,R - TLS pre- master secret: W,E - TLS master secret: G,E",
            "secFunImpl": "TLS1.2-KDF (CVL) TLS1.3-KDF (CVL)"
          },
          {
            "description": "Derive key via PBKDF2",
            "indicator": "Indicator API return value = 1",
            "inputs": "API call parameters, password",
            "name": "Derive key via PBKDF2",
            "outputs": "Status, key",
            "rolesSspAccess": "User - Passphrase: W,E - AES key: G,R - Triple-DES key : G,R",
            "secFunImpl": "PBKDF"
          },
          {
            "description": "Return module versioning information",
            "indicator": "N/A",
            "inputs": "API call parameters",
            "name": "Show versioning information",
            "outputs": "Module name, version",
            "rolesSspAccess": "Crypto Officer",
            "secFunImpl": "None"
          },
          {
            "description": "Generate DSA domain parameters",
            "indicator": "Indicator API return value = 1",
            "inputs": "API call parameters",
            "name": "Generate DSA domain parameters",
            "outputs": "Status, domain parameters",
            "rolesSspAccess": "User",
            "secFunImpl": "DSA for Domain Parameter Generation"
          },
          {
            "description": "Verify DSA domain parameters",
            "indicator": "Indicator API return value = 1",
            "inputs": "API call parameters",
            "name": "Verify DSA domain parameters",
            "outputs": "Status",
            "rolesSspAccess": "User",
            "secFunImpl": "DSA for Domain Parameter Verification (legacy)"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 3
      },
      "authentication_methods": {
        "entries": [],
        "found": false,
        "section": 4,
        "subsection": 1
      },
      "cond_self_tests": {
        "entries": [
          {
            "algorithmOrTest": "AES-CBC (A5835)",
            "condition": "After successful software integrity test",
            "details": "encrypt",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "128 bit",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-ECB (A5835)",
            "condition": "After successful software integrity test",
            "details": "decrypt",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "128 bit",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-CCM (A5835)",
            "condition": "After successful software integrity test",
            "details": "encrypt",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "192 bit",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-CCM (A5835)",
            "condition": "After successful software integrity test",
            "details": "decrypt",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "192 bit",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A5835)",
            "condition": "After successful software integrity test",
            "details": "encrypt",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "128 bit",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A5835)",
            "condition": "After successful software integrity test",
            "details": "decrypt",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "128 bit",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-XTS Testing Revision 2.0 (A5835)",
            "condition": "After successful software integrity test",
            "details": "encrypt",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "128 bit",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-XTS Testing Revision 2.0 (A5835)",
            "condition": "After successful software integrity test",
            "details": "decrypt",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "128 bit",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-CMAC (A5835)",
            "condition": "After successful software integrity test",
            "details": "Generate",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "CBC mode, 128- bit; 192-bit; 256- bit",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-CMAC (A5835)",
            "condition": "After successful software integrity test",
            "details": "Verify",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "CBC mode, 128- bit; 192-bit; 256- bit",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "TDES-ECB (A5835)",
            "condition": "After successful software integrity test",
            "details": "Encrypt",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "3Key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "TDES-ECB (A5835)",
            "condition": "After successful software integrity test",
            "details": "Decrypt",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "3Key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "TDES-CMAC (A5835)",
            "condition": "After successful software integrity test",
            "details": "Generate",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "CBC mode, 3Key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "TDES-CMAC (A5835)",
            "condition": "After successful software integrity test",
            "details": "Verify",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "CBC mode, 3Key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "Counter DRBG (A5835)",
            "condition": "After successful software integrity test",
            "details": "Generate/Instantiate/Reseed",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "AES, 256-bit",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "DSA SigGen (FIPS186-4) (A5835)",
            "condition": "After successful software integrity test",
            "details": "Sign",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "2048-bit; SHA2- 256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "DSA SigVer (FIPS186-4) (A5835)",
            "condition": "After successful software integrity test",
            "details": "Verify",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "2048-bit; SHA2- 256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigVer (FIPS186-4) (A5835)",
            "condition": "After successful software integrity test",
            "details": "Verify",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "P-224; K-233; SHA-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigGen (FIPS186-4) (A5835)",
            "condition": "After successful software integrity test",
            "details": "Sign",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "2048-bit; SHA2- 256; PKCS#1.5 scheme",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186-4) (A5835)",
            "condition": "After successful software integrity test",
            "details": "Verify",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "2048-bit; SHA2- 256; PKCS#1.5 scheme",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA-1 (A5835)",
            "condition": "After successful software integrity test",
            "details": "Hashed Message",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "SHA-1",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA2- 224 (A5835)",
            "condition": "After successful software integrity test",
            "details": "Hashed Message",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "SHA2-224",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA2- 256 (A5835)",
            "condition": "Prior to the software integrity test",
            "details": "Hashed Message",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA2- 384 (A5835)",
            "condition": "After successful software integrity test",
            "details": "Hashed Message",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "SHA2-384",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA2- 512 (A5835)",
            "condition": "After successful software integrity test",
            "details": "Hashed Message",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "SHA2-512",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA3- 224 (A5835)",
            "condition": "After successful software integrity test",
            "details": "Hashed Message",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "SHA3-224",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA3- 256 (A5835)",
            "condition": "Prior to the software integrity test",
            "details": "Hashed Message",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "SHA3-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA3- 384 (A5835)",
            "condition": "After successful software integrity test",
            "details": "Hashed Message",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "SHA3-384",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA3- 512 (A5835)",
            "condition": "After successful software integrity test",
            "details": "Hashed Message",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "SHA3-512",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA-1 (A5835)",
            "condition": "After successful software integrity test",
            "details": "Hash",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "-",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA2-224 (A5835)",
            "condition": "After successful software integrity test",
            "details": "Hash",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "-",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA2-256 (A5835)",
            "condition": "After successful software integrity test",
            "details": "Hash",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "-",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA2-384 (A5835)",
            "condition": "After successful software integrity test",
            "details": "Hash",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "-",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA2-512 (A5835)",
            "condition": "After successful software integrity test",
            "details": "Hash",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "-",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA3-224 (A5835)",
            "condition": "After successful software integrity test",
            "details": "Hash",
            "indicator": "returned success or",
            "testMethod": "KAT",
            "testProps": "-",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA3-256 (A5835)",
            "condition": "After successful software integrity test",
            "details": "Hash",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "-",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA3-384 (A5835)",
            "condition": "After successful software integrity test",
            "details": "Hash",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "-",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA3-512 (A5835)",
            "condition": "After successful software integrity test",
            "details": "Hash",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "-",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS-FFC-SSC Sp800-56Ar3 (A5835)",
            "condition": "After successful software integrity test",
            "details": "Shared Secret \u0027Z\u0027 Computation",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "2048-bit",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS-ECC-SSC Sp800-56Ar3 (A5835)",
            "condition": "After successful software integrity test",
            "details": "Shared Secret \u0027Z\u0027 Computation",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "P-224",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "PBKDF (A5835)",
            "condition": "After successful software integrity test",
            "details": "KDF",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "SHA2-224",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "TLS v1.2 KDF RFC7627 (A5835)",
            "condition": "After successful software integrity test",
            "details": "KDF",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "-",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "TLS v1.3 KDF (A5836)",
            "condition": "After successful software integrity test",
            "details": "KDF",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "-",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "DSA KeyGen (FIPS186-4) (A5835)",
            "condition": "When an ECDSA key pair is generated for use with sign/verify functions",
            "details": "Sign/Verify",
            "indicator": "returned success or error code",
            "testMethod": "PCT",
            "testProps": "-",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "ECDSA KeyGen (FIPS186-4) (A5835)",
            "condition": "When an ECDSA key pair is generated for use with sign/verify functions",
            "details": "Sign/Verify",
            "indicator": "returned success or error code",
            "testMethod": "PCT",
            "testProps": "-",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "RSA KeyGen (FIPS186-4) (A5835)",
            "condition": "When an RSA key pair is generated for use with sign/verify functions",
            "details": "Sign/Verify",
            "indicator": "returned success or error code",
            "testMethod": "PCT",
            "testProps": "-",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "DH",
            "condition": "When a DSA key pair is generated for use with DH key transport functions",
            "details": "Key Agreement",
            "indicator": "returned success or error code",
            "testMethod": "PCT",
            "testProps": "-",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "ECDH",
            "condition": "When an ECDSA key pair is generated for use with ECDH key transport functions",
            "details": "Key Agreement",
            "indicator": "returned success or error code",
            "testMethod": "PCT",
            "testProps": "-",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "ECDSA SigGen (FIPS186-4) (A5835)",
            "condition": "After successful software integrity test",
            "details": "Sign",
            "indicator": "returned success or error code",
            "testMethod": "KAT",
            "testProps": "P-224; K-233; SHA-256",
            "type": "CAST"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 2
      },
      "error_states": {
        "entries": [
          {
            "conditions": "Upon failure of any pre- operational or conditional self- test,",
            "description": "Module immediately terminates the calling application and sets an internal flag signaling the error condition. The module disables access to all cryptographic functions, SSPs, and data output services while the error condition persists.",
            "indicator": "Returns error code upon self-test failure; returns failure indicator for subsequent requests for cryptographic services.",
            "name": "Critical Error",
            "recoveryMethod": "The module must be re- instantiated by the calling application. The CO should contact Riverbed Technology LLC if errors persist after re- instantiation."
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 4
      },
      "mechanisms_actions": {
        "entries": [],
        "found": false,
        "section": 7,
        "subsection": 1
      },
      "modes_of_operation": {
        "entries": [
          {
            "description": "The module switches between the Approved mode and Non-Approved mode depending on the service executed. The module is in this mode once all pre- operational self-tests have completed successfully, and only Approved services are invoked.",
            "name": "Approved",
            "statusIndicator": "Indicator API return value = 1",
            "type": "Approved"
          },
          {
            "description": "The module will switch to the non-Approved mode upon execution of a non- Approved service.",
            "name": "Non- Approved",
            "statusIndicator": "Indicator API return value other than 1",
            "type": "Non- Approved"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 4
      },
      "non_approved_allowed_NSC": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_allowed_algos": {
        "entries": [
          {
            "algoPropList": "Key unwrapping:128, 192, 256",
            "implName": "Riverbed Cryptographic Module (libcrypto)",
            "name": "AES-CBC",
            "reference": "FIPS 197, SP 800-38A, FIPS 140-3 IG D.G"
          },
          {
            "algoPropList": "Key unwrapping:128, 192, 256",
            "implName": "Riverbed Cryptographic Module (libcrypto)",
            "name": "AES-CFB1",
            "reference": "FIPS 197, SP 800-38A, FIPS 140-3 IG D.G"
          },
          {
            "algoPropList": "Key unwrapping:128, 192, 256",
            "implName": "Riverbed Cryptographic Module (libcrypto)",
            "name": "AES-CFB128",
            "reference": "FIPS 197, SP 800-38A, FIPS 140-3 IG D.G"
          },
          {
            "algoPropList": "Key unwrapping:128, 192, 256",
            "implName": "Riverbed Cryptographic Module (libcrypto)",
            "name": "AES-CFB8",
            "reference": "FIPS 197, SP 800-38A, FIPS 140-3 IG D.G"
          },
          {
            "algoPropList": "Key unwrapping:128, 192, 256",
            "implName": "Riverbed Cryptographic Module (libcrypto)",
            "name": "AES-CTR",
            "reference": "FIPS 197, SP 800-38A, FIPS 140-3 IG D.G"
          },
          {
            "algoPropList": "Key unwrapping:128, 192, 256",
            "implName": "Riverbed Cryptographic Module (libcrypto)",
            "name": "AES-ECB",
            "reference": "FIPS 197, SP 800-38A, FIPS 140-3 IG D.G"
          },
          {
            "algoPropList": "Key unwrapping:128, 192, 256",
            "implName": "Riverbed Cryptographic Module (libcrypto)",
            "name": "AES-OFB",
            "reference": "FIPS 197, SP 800-38A, FIPS 140-3 IG D.G"
          },
          {
            "algoPropList": "Key unwrapping:",
            "implName": "Riverbed Cryptographic Module (libcrypto)",
            "name": "TDES-CBC (2-key or 3- key)",
            "reference": "SP 800-67 Rev. 2, SP 800-38A, FIPS 140-3 IG D.G"
          },
          {
            "algoPropList": "Key unwrapping:",
            "implName": "Riverbed Cryptographic Module (libcrypto)",
            "name": "TDES-CFB1 (2-key or 3- key)",
            "reference": "SP 800-67 Rev. 2, SP 800-38A, FIPS 140-3 IG D.G"
          },
          {
            "algoPropList": "Key unwrapping:",
            "implName": "Riverbed Cryptographic Module (libcrypto)",
            "name": "TDES-CFB64 (2-key or 3-key)",
            "reference": "SP 800-67 Rev. 2, SP 800-38A, FIPS 140-3 IG D.G"
          },
          {
            "algoPropList": "Key unwrapping:",
            "implName": "Riverbed Cryptographic Module (libcrypto)",
            "name": "TDES-CFB8 (2-key or 3- key)",
            "reference": "SP 800-67 Rev. 2, SP 800-38A, FIPS 140-3 IG D.G"
          },
          {
            "algoPropList": "Key unwrapping:",
            "implName": "Riverbed Cryptographic Module (libcrypto)",
            "name": "TDES-ECB (2-key or 3- key)",
            "reference": "SP 800-67 Rev. 2, SP 800-38A, FIPS 140-3 IG D.G"
          },
          {
            "algoPropList": "Key unwrapping:",
            "implName": "Riverbed Cryptographic Module (libcrypto)",
            "name": "TDES-OFB (2-key or 3- key)",
            "reference": "SP 800-67 Rev. 2, SP 800-38A, FIPS 140-3 IG D.G"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "non_approved_not_allowed": {
        "entries": [
          {
            "name": "AES-GCM (non-compliant)",
            "use": "Authenticated encryption/decryption using external IV"
          },
          {
            "name": "AES-OCB",
            "use": "Authenticated encryption/decryption"
          },
          {
            "name": "ANSI X9.31 RNG (non- compliant)",
            "use": "Random number generation using with 128-bit AES core"
          },
          {
            "name": "ARIA",
            "use": "Encryption/decryption"
          },
          {
            "name": "Blake2",
            "use": "Encryption/decryption"
          },
          {
            "name": "Blowfish",
            "use": "Encryption/decryption"
          },
          {
            "name": "Camellia",
            "use": "Encryption/decryption"
          },
          {
            "name": "CAST, CAST5",
            "use": "Encryption/decryption"
          },
          {
            "name": "ChaCha20",
            "use": "Encryption/decryption"
          },
          {
            "name": "DES",
            "use": "Encryption/decryption"
          },
          {
            "name": "DH (non-compliant)",
            "use": "Key agreement (non-compliant with key sizes below 2048)"
          },
          {
            "name": "DRBG (non-compliant)",
            "use": "Random bit generation (non-compliant when using Hash_DRBG and HMAC_DRBG)"
          },
          {
            "name": "DSA (non-compliant)",
            "use": "Key pair generation; digital signature generation; digital signature verification (non-compliant with key sizes below the minimums for Approved mode)"
          },
          {
            "name": "DSA, ECDSA, and RSA (non- compliant)",
            "use": "Digital signature generation (non-compliant when used with SHA-1 outside the TLS protocol)"
          },
          {
            "name": "ECDH (non-compliant)",
            "use": "Key agreement (non-compliant with curves P-192, K-163, B-163, and non-NIST curves)"
          },
          {
            "name": "ECDSA (non-compliant)",
            "use": "Key pair generation; digital signature generation; digital signature verification (non-compliant with curves P-192, K-163, B-163, and non-NIST curves)"
          },
          {
            "name": "EdDSA",
            "use": "Key pair generation; digital signature generation; digital signature verification"
          },
          {
            "name": "HKDF",
            "use": "HMAC-based key derivation"
          },
          {
            "name": "IDEA",
            "use": "Encryption/decryption"
          },
          {
            "name": "MD2, MD4, MD5",
            "use": "Message digest"
          },
          {
            "name": "Poly1305",
            "use": "Message authentication code"
          },
          {
            "name": "RC2, RC4, RC5",
            "use": "Encryption/decryption"
          },
          {
            "name": "RIPEMD",
            "use": "Message digest"
          },
          {
            "name": "RMD160",
            "use": "Message digest"
          },
          {
            "name": "RSA (non-compliant)",
            "use": "Key pair generation; digital signature generation; signature verification; key transport (non-compliant with non-approved/untested key sizes, and functions)"
          },
          {
            "name": "SEED",
            "use": "Encryption/decryption"
          },
          {
            "name": "SHA-1 (non-compliant)",
            "use": "Signature generation in TLS 1.0/1.1"
          },
          {
            "name": "SM2, SM3",
            "use": "Message digest"
          },
          {
            "name": "SM4",
            "use": "Encryption/decryption"
          },
          {
            "name": "TLS 1.2 KDF (non- compliant)",
            "use": "Key derivation function per (RFC 5246)"
          },
          {
            "name": "Triple-DES (non-compliant)",
            "use": "Encryption; MAC generation; key wrapping"
          },
          {
            "name": "Whirlpool",
            "use": "Message digest"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "non_approved_services": {
        "entries": [
          {
            "alg_accessed": "ARIA Blake2 Blowfish Camellia CAST, CAST5 ChaCha20 DES IDEA RC2, RC4, RC5 SEED SM4 Triple-DES (non-compliant)",
            "description": "Perform symmetric data encryption",
            "name": "Perform data encryption (non-compliant)",
            "role": "User"
          },
          {
            "alg_accessed": "ARIA Blake2 Blowfish Camellia CAST, CAST5 ChaCha20 DES IDEA RC2, RC4, RC5 SEED",
            "description": "Perform symmetric data decryption",
            "name": "Perform data decryption (non-compliant)",
            "role": "User"
          },
          {
            "alg_accessed": "Poly1305 Triple-DES (non-compliant)",
            "description": "Perform message authentication operations",
            "name": "Perform MAC operations (non-compliant)",
            "role": "User"
          },
          {
            "alg_accessed": "MD2, MD4, MD5 RIPEMD RMD160 SHA-1 (non-compliant) SM2, SM3 Whirlpool",
            "description": "Perform hash operation",
            "name": "Perform hash operation (non-compliant)",
            "role": "User"
          },
          {
            "alg_accessed": "DSA (non-compliant) ECDSA (non-compliant) EdDSA RSA (non-compliant)",
            "description": "Perform digital signature functions",
            "name": "Perform digital signature functions (non- compliant)",
            "role": "User"
          },
          {
            "alg_accessed": "DH (non-compliant) ECDH (non-compliant)",
            "description": "Perform key agreement functions",
            "name": "Perform key agreement functions (non- compliant)",
            "role": "User"
          },
          {
            "alg_accessed": "Triple-DES (non-compliant)",
            "description": "Perform key wrap functions",
            "name": "Perform key wrap (non-compliant)",
            "role": "User"
          },
          {
            "alg_accessed": "RSA (non-compliant)",
            "description": "Perform key encapsulation function",
            "name": "Perform key encapsulation function (non- compliant)",
            "role": "User"
          },
          {
            "alg_accessed": "RSA (non-compliant)",
            "description": "Perform key un-encapsulation function",
            "name": "Perform key un-encapsulation function (non- compliant)",
            "role": "User"
          },
          {
            "alg_accessed": "HKDF TLS 1.2 KDF (non-compliant)",
            "description": "Perform key derivation functions",
            "name": "Perform key derivation functions (non- compliant)",
            "role": "User"
          },
          {
            "alg_accessed": "AES-GCM (non-compliant) AES-OCB",
            "description": "Perform authenticated encryption/decryption",
            "name": "Perform authenticated encryption/decryption",
            "role": "User"
          },
          {
            "alg_accessed": "ANSI X9.31 RNG (non- compliant) DRBG (non-compliant)",
            "description": "Perform random number generation",
            "name": "Perform random number generation",
            "role": "User"
          },
          {
            "alg_accessed": "DSA (non-compliant) DSA, ECDSA, and RSA (non- compliant) ECDSA (non-compliant) EdDSA RSA (non-compliant)",
            "description": "Perform key pair generation",
            "name": "Perform key pair generation",
            "role": "User"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 4
      },
      "ports_interfaces": {
        "entries": [
          {
            "data": "API input parameters - Includes data to be encrypted/decrypted/signed/verified/hashed, keys to be used in cryptographic services, random seed material for the module\u0027s DRBG, and keying material to be used as input to key establishment services",
            "logicalInterface": "Data Input",
            "physicalPort": "N/A"
          },
          {
            "data": "API output parameters and return values - Includes data that has been encrypted/decrypted/verified, digital signatures, hashes, random values generated by the module\u0027s DRBG, and keys established using module\u0027s key establishment methods",
            "logicalInterface": "Data Output",
            "physicalPort": "N/A"
          },
          {
            "data": "API method calls - Includes API commands invoking cryptographic services, modes/key sizes/etc. used with cryptographic services",
            "logicalInterface": "Control Input",
            "physicalPort": "N/A"
          },
          {
            "data": "API output parameters and return/error codes - Includes status information regarding the module and status information regarding the invoked service/operation",
            "logicalInterface": "Status Output",
            "physicalPort": "N/A"
          }
        ],
        "found": true,
        "section": 3,
        "subsection": 1
      },
      "roles": {
        "entries": [
          {
            "authMethodList": "None",
            "name": "Crypto Officer",
            "operatorType": "CO",
            "type": "Role"
          },
          {
            "authMethodList": "None",
            "name": "User",
            "operatorType": "User",
            "type": "Role"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 2
      },
      "security_levels": {
        "entries": [
          {
            "level": "1",
            "section": "1",
            "title": "General"
          },
          {
            "level": "1",
            "section": "2",
            "title": "Cryptographic module specification"
          },
          {
            "level": "1",
            "section": "3",
            "title": "Cryptographic module interfaces"
          },
          {
            "level": "1",
            "section": "4",
            "title": "Roles, services, and authentication"
          },
          {
            "level": "1",
            "section": "5",
            "title": "Software/Firmware security"
          },
          {
            "level": "1",
            "section": "6",
            "title": "Operational environment"
          },
          {
            "level": "N/A",
            "section": "7",
            "title": "Physical security"
          },
          {
            "level": "N/A",
            "section": "8",
            "title": "Non-invasive security"
          },
          {
            "level": "1",
            "section": "9",
            "title": "Sensitive security parameter management"
          },
          {
            "level": "1",
            "section": "10",
            "title": "Self-tests"
          },
          {
            "level": "1",
            "section": "11",
            "title": "Life-cycle assurance"
          },
          {
            "level": "N/A",
            "section": "12",
            "title": "Mitigation of other attacks"
          },
          {
            "level": "1",
            "section": "",
            "title": "Overall Level"
          }
        ],
        "found": true,
        "section": 1,
        "subsection": 2
      },
      "self_tests": {
        "entries": [
          {
            "algorithmOrTest": "HMAC-SHA2-256 (A5835)",
            "details": "Test for libcrypto. Performed automatically without operator action",
            "indicator": "Returned success or error code",
            "testMethod": "Software Integrity Test",
            "testProps": "SHA2-256",
            "type": "SW/FW Integrity"
          },
          {
            "algorithmOrTest": "HMAC-SHA2-256 (A5835)",
            "details": "Test for libssl. Performed automatically without operator action",
            "indicator": "Returned success or error code",
            "testMethod": "Software Integrity Test",
            "testProps": "SHA2-256",
            "type": "SW/FW Integrity"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 1
      },
      "ssp_io_methods": {
        "entries": [
          {
            "dest": "RAM",
            "distribution": "Automated",
            "entry": "Electronic",
            "format": "Plaintext",
            "name": "[Input] External to RAM via Plaintext",
            "sfiAlgo": "",
            "source": "External"
          },
          {
            "dest": "External",
            "distribution": "Automated",
            "entry": "Electronic",
            "format": "Plaintext",
            "name": "[Output] RAM to External via Plaintext",
            "sfiAlgo": "",
            "source": "RAM"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 2
      },
      "ssp_zeroization_methods": {
        "entries": [
          {
            "description": "Upon removing power from the host device, the SSPs in memory are zeroized.",
            "method": "Remove Power",
            "operatorId": "Operator removes power from the host device.",
            "rationale": "Removing power from the host device yields SSPs in memory irretrievable and unusable, effectively zeroizing them."
          },
          {
            "description": "Upon rebooting the host device, the SSPs in memory are zeroized.",
            "method": "Reboot",
            "operatorId": "Operator reboots the host device",
            "rationale": "Rebooting the host device yields SSPs in memory irretrievable and unusable, effectively zeroizing them."
          },
          {
            "description": "Upon power-cycling the host device, the SSPs in memory are zeroized.",
            "method": "Power-cycle",
            "operatorId": "Operator power-cycles the host device",
            "rationale": "Power-cycling the host device yields SSPs in memory irretrievable and unusable, effectively zeroizing them."
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 3
      },
      "storage_areas": {
        "entries": [],
        "found": false,
        "section": 9,
        "subsection": 1
      },
      "tested_module_id_hw": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "tested_module_id_hw_hy": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "tested_module_id_sw_fw_hy": {
        "entries": [
          {
            "features": "N/A",
            "integrityTest": "Yes",
            "packageFileName": "libcrypto.so",
            "swFwVersion": "2.0.1"
          },
          {
            "features": "N/A",
            "integrityTest": "Yes",
            "packageFileName": "libssl.so",
            "swFwVersion": "2.0.1"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 2
      },
      "tested_op_env_sw_fw_hy": {
        "entries": [
          {
            "hardwarePlatform": "Riverbed AppResponse 2180",
            "hypervisorHostOs": "N/A",
            "operatingSystem": "AlmaLinux 8",
            "paa_pai": "Yes",
            "processors": "Intel Xeon Silver 4110",
            "version": "2.0.1"
          },
          {
            "hardwarePlatform": "Riverbed AppResponse 2180",
            "hypervisorHostOs": "N/A",
            "operatingSystem": "AlmaLinux 8",
            "paa_pai": "No",
            "processors": "Intel Xeon Silver 4110",
            "version": "2.0.1"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 2
      },
      "vendor_affirmed_algos": {
        "entries": [
          {
            "algoPropList": "Key Type:Asymmetric",
            "implName": "Riverbed Cryptographic Module (libcrypto)",
            "name": "CKG1",
            "reference": "SP 800-133 Rev. 2 Section 4."
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "vendor_affirmed_op_env_sw_fw_hy": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      }
    },
    "is_br1_format": true,
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 2
          },
          "ECDH": {
            "ECDH": 27
          },
          "ECDSA": {
            "ECDSA": 75
          },
          "EdDSA": {
            "EdDSA": 3
          }
        },
        "FF": {
          "DH": {
            "DH": 27,
            "DHE": 1,
            "Diffie-Hellman": 2
          },
          "DSA": {
            "DSA": 66
          }
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 5
        },
        "CCM": {
          "CCM": 10
        },
        "CFB": {
          "CFB": 1
        },
        "CTR": {
          "CTR": 1
        },
        "ECB": {
          "ECB": 1
        },
        "GCM": {
          "GCM": 33
        },
        "OFB": {
          "OFB": 1
        },
        "XEX": {
          "XEX": 1
        },
        "XTS": {
          "XTS": 8
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "TLS": {
          "SSL": {
            "SSL": 3
          },
          "TLS": {
            "TLS": 33,
            "TLS 1.2": 4,
            "TLS 1.3": 5,
            "TLS v1.2": 6,
            "TLS v1.3": 6
          }
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 4,
          "Key agreement": 2
        },
        "MAC": {
          "MAC": 29
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "B-163": 6,
          "B-233": 5,
          "B-283": 5,
          "B-409": 5,
          "B-571": 5,
          "K-163": 6,
          "K-233": 7,
          "K-283": 5,
          "K-409": 5,
          "K-571": 5,
          "P-192": 12,
          "P-224": 16,
          "P-256": 10,
          "P-384": 10,
          "P-521": 10
        }
      },
      "eval_facility": {},
      "fips_cert_id": {},
      "fips_certlike": {
        "Certlike": {
          "AES-128": 1,
          "AES-192": 1,
          "AES-256": 1,
          "DRBG 128": 1,
          "HMAC-SHA-1": 14,
          "PKCS 1": 4,
          "PKCS#1": 4,
          "SHA-1": 17,
          "SHA-256": 2,
          "SHA2- 256": 4,
          "SHA2-224": 18,
          "SHA2-256": 22,
          "SHA2-384": 19,
          "SHA2-512": 16,
          "SHA2-512 2": 1,
          "SHA3-224": 4,
          "SHA3-256": 7,
          "SHA3-384": 4,
          "SHA3-512": 6
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 3
        }
      },
      "hash_function": {
        "BLAKE": {
          "Blake2": 3
        },
        "MD": {
          "MD4": {
            "MD4": 2
          },
          "MD5": {
            "MD5": 2
          }
        },
        "PBKDF": {
          "PBKDF": 13,
          "PBKDF2": 4
        },
        "RIPEMD": {
          "RIPEMD": 2
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 17
          },
          "SHA2": {
            "SHA-256": 2
          },
          "SHA3": {
            "SHA3-224": 7,
            "SHA3-256": 4,
            "SHA3-384": 7,
            "SHA3-512": 5
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {
        "curves": {
          "SM2": 2
        }
      },
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 63
        },
        "RNG": {
          "RNG": 5
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-3": 85,
          "FIPS 180-4": 5,
          "FIPS 186-4": 14,
          "FIPS 197": 7,
          "FIPS 198-1": 9,
          "FIPS 202": 6,
          "FIPS PUB 186-5": 1,
          "FIPS186-4": 42
        },
        "ISO": {
          "ISO/IEC 19790": 8,
          "ISO/IEC 19790:2012": 1
        },
        "NIST": {
          "NIST SP 800-132": 3,
          "NIST SP 800-38D": 3,
          "NIST SP 800-38E": 1,
          "SP 800-132": 2,
          "SP 800-133": 1,
          "SP 800-135": 2,
          "SP 800-38A": 20,
          "SP 800-38B": 1,
          "SP 800-38C": 1,
          "SP 800-38D": 2,
          "SP 800-38E": 1,
          "SP 800-38F": 2,
          "SP 800-56A": 2,
          "SP 800-67": 13,
          "SP 800-90A": 1
        },
        "PKCS": {
          "PKCS 1": 2,
          "PKCS#1": 2
        },
        "RFC": {
          "RFC 5246": 1,
          "RFC 5288": 1,
          "RFC 7627": 1,
          "RFC 8446": 1,
          "RFC7627": 4
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 97,
            "AES-": 2,
            "AES-128": 1,
            "AES-192": 1,
            "AES-256": 1
          },
          "CAST": {
            "CAST": 92,
            "CAST5": 3
          },
          "RC": {
            "RC2": 3,
            "RC4": 3,
            "RC5": 3
          }
        },
        "DES": {
          "3DES": {
            "TDES": 17,
            "Triple-DES": 15
          },
          "DES": {
            "DES": 6
          }
        },
        "constructions": {
          "MAC": {
            "CMAC": 16,
            "HMAC": 19
          }
        },
        "djb": {
          "ChaCha": {
            "ChaCha20": 3
          },
          "Poly": {
            "Poly1305": 2
          }
        },
        "miscellaneous": {
          "ARIA": {
            "ARIA": 3
          },
          "Blowfish": {
            "Blowfish": 3
          },
          "Camellia": {
            "Camellia": 3
          },
          "IDEA": {
            "IDEA": 3
          },
          "SEED": {
            "SEED": 3
          },
          "SM4": {
            "SM4": 2
          }
        }
      },
      "tee_name": {
        "AMD": {
          "PSP": 5
        }
      },
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "module_algorithms": {
      "_type": "Set",
      "elements": [
        "TDES-CBCA5835",
        "DSA SigVer (FIPS186-4)A5835",
        "HMAC-SHA2-512A5835",
        "RSA KeyGen (FIPS186-4)A5835",
        "DSA SigGen (FIPS186-4)A5835",
        "AES-XTS Testing Revision 2.0A5835",
        "PBKDFA5835",
        "TDES-OFBA5835",
        "ECDSA KeyGen (FIPS186-4)A5835",
        "AES-KWPA5835",
        "HMAC-SHA3-384A5835",
        "AES-OFBA5835",
        "HMAC-SHA2-224A5835",
        "ECDSA KeyVer (FIPS186-4)A5835",
        "AES-GCMA5835",
        "DSA KeyGen (FIPS186-4)A5835",
        "AES-ECBA5835",
        "AES-KWA5835",
        "DSA PQGVer (FIPS186-4)A5835",
        "SHA3-256A5835",
        "TDES-CMACA5835",
        "TDES-CFB64A5835",
        "KAS-ECC-SSC Sp800-56Ar3A5835",
        "AES-CFB128A5835",
        "AES-CCMA5835",
        "HMAC-SHA-1A5835",
        "HMAC-SHA3-512A5835",
        "ECDSA SigGen (FIPS186-4)A5835",
        "HMAC-SHA3-256A5835",
        "SHAKE-256A5835",
        "SHA3-384A5835",
        "DSA PQGGen (FIPS186-4)A5835",
        "SHA3-224A5835",
        "HMAC-SHA2-384A5835",
        "AES-CFB1A5835",
        "TDES-ECBA5835",
        "AES-CTRA5835",
        "AES-CMACA5835",
        "Counter DRBGA5835",
        "HMAC-SHA2-256A5835",
        "SHA2-224A5835",
        "SHA3-512A5835",
        "AES-CBCA5835",
        "SHA2-512A5835",
        "KAS-FFC-SSC Sp800-56Ar3A5835",
        "ECDSA SigVer (FIPS186-4)A5835",
        "TDES-CFB1A5835",
        "TLS v1.3 KDFA5836",
        "RSA SigGen (FIPS186-4)A5835",
        "TDES-CFB8A5835",
        "SHA-1A5835",
        "AES-GMACA5835",
        "HMAC-SHA3-224A5835",
        "RSA SigVer (FIPS186-4)A5835",
        "TLS v1.2 KDF RFC7627A5835",
        "AES-CFB8A5835",
        "SHA2-384A5835",
        "SHA2-256A5835",
        "SHAKE-128A5835"
      ]
    },
    "policy_algorithms": {
      "_type": "Set",
      "elements": [
        "#A5836",
        "#A5835"
      ]
    },
    "policy_metadata": {
      "/Author": "Corsec Security, Inc.",
      "/Comments": "",
      "/Company": "Corsec Security, Inc.",
      "/ContentTypeId": "0x010100F0033FC9EC5FDD48A2BABA694750568F",
      "/CreationDate": "D:20250519081634-04\u002700\u0027",
      "/Creator": "Acrobat PDFMaker 25 for Word",
      "/Keywords": "",
      "/MediaServiceImageTags": "",
      "/ModDate": "D:20250519081923-04\u002700\u0027",
      "/Producer": "Adobe PDF Library 25.1.208",
      "/SourceModified": "",
      "/Subject": "",
      "/Title": "FIPS 140-3 Non-Proprietary Security Policy",
      "/_Copyright": "2025",
      "/_Document Date": "January 29, 2025",
      "/_Document Version": "0.5",
      "/_FIPS Security Level": "1",
      "/_Hardware/Software/Firmware": "software",
      "/_Module Name (long)": "Riverbed Cryptographic Module",
      "/_Module Name (short)": "Riverbed Crypto Module",
      "/_Module Version Number": "2.0.1",
      "/_Vendor Name (long)": "Riverbed Technology, LLC",
      "/_Vendor Name (short)": "Riverbed",
      "pdf_file_size_bytes": 880183,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?validation=38445",
          "http://www.riverbed.com/",
          "https://csrc.nist.gov/Projects/cryptographic-module-validation-program/Validated-Modules/Search",
          "http://csrc.nist.gov/groups/STM/cmvp",
          "http://www.corsec.com/",
          "mailto:[email protected]",
          "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?validation=38446"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 58
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.InternalState",
    "module": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "policy": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": "85c665c2a9c0cd193b6a94136cbaf3a0d26da1590db518202914c72939d542c0",
      "source_hash": "59f2b2d2e7a05f18313ff5261681557229dbbdf8f061a46d69708aad0249f700",
      "txt_hash": "3a8ba5718a31441263f51b3607d2c990bc90c00d71e26c62925e2981a7336fbc"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in approved mode. No assurance of the minimum strength of generated keys",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/May 2025_130625_0321.pdf",
    "date_sunset": "2030-05-13",
    "description": "The Riverbed Cryptographic Module v2.0.1 is a software library providing a C language API for use by other applications requiring cryptographic functionality. Riverbed Cryptographic Module v2.0.1 offers symmetric encryption/decryption, digital signature generation/verification, hashing, cryptographic key generation, random number generation, message authentication, and key establishment functions to secure data-at-rest/data-in-flight and to support secure communications protocols (including TLS 1.2/1.3).",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Physical security: N/A",
      "Non-invasive security: N/A",
      "Mitigation of other attacks: N/A"
    ],
    "fw_versions": null,
    "historical_reason": null,
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {},
    "module_name": "Riverbed Cryptographic Module",
    "module_type": "Software",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-3",
    "status": "active",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2025-05-14",
        "lab": "Lightship Security, Inc.",
        "validation_type": "Initial"
      }
    ],
    "vendor": "Riverbed Technology, LLC",
    "vendor_url": "http://www.riverbed.com"
  }
}