Vormetric Data Security Manager Module

Certificate #3442

Webpage information

Status historical
Historical reason SP 800-56Arev3 transition
Validation dates 26.04.2019 , 06.06.2019
Standard FIPS 140-2
Security level 2
Type Hardware
Embodiment Multi-Chip Stand Alone
Caveat When Operated in FIPS mode. The protocol SSH shall not be used when operated in FIPS mode.
Exceptions
  • Roles, Services, and Authentication: Level 3
  • Cryptographic Key Management: Level 3
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A
Description The Vormetric Data Security Server is a multi-chip standalone cryptographic module. The Vormetric Data Security Server is the central point of management for the Vormetric Data Security product. It manages keys and policies, and controls Vormetric Transparent Encryption Agents. These agents contain the Vormetric Encryption Expert Cryptographic Module, which has been validated separately from this module.
Version (Hardware) 3.0
Version (Firmware) 6.0.2
Vendor Thales eSecurity
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Symmetric Algorithms
AES, AES-256, AES-128, Triple-DES, ARIA, HMAC, HMAC-SHA-256, HMAC-SHA-384
Asymmetric Algorithms
RSA 2048, RSA 1024, RSA 4096, ECDH, ECDSA, DH, Diffie-Hellman
Hash functions
SHA-256, SHA-384, SHA-512
Schemes
Key Exchange, Key agreement
Protocols
SSH, TLS, TLS 1.2, TLS v1.2
Randomness
DRBG, RNG
Libraries
OpenSSL
Elliptic Curves
P-384, P-256
Block cipher modes
CBC, GCM
TLS cipher suites
TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384, TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384, TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256, TLS_RSA_WITH_AES_256_CBC_SHA256

Vendor
Thales

Security level
Level 2, Level 3

Standards
FIPS 140-2, FIPS 186-4, FIPS 197, FIPS 180-4, FIPS 198-1, NIST SP 800-90A, SP 800-38A, SP 800-133, SP 800-52, PKCS1, RFC 5246

File metadata

Title security policy
Author Peter Tsai
Creation date D:20190523204037+02'00'
Modification date D:20190523204037+02'00'
Pages 25
Creator Microsoft® Word 2016
Producer Microsoft® Word 2016

Heuristics

No heuristics are available for this certificate.

References

No references are available for this certificate.

Updates Feed

  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 3442,
  "dgst": "82bd3b63e2f8767c",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "HMAC#3687",
        "CVL#1481",
        "AES#5535",
        "DRBG#1702",
        "SHS#3986",
        "HMAC#3245",
        "RSA#2663",
        "KTS#5535",
        "AES#4845",
        "CVL#1978",
        "SHS#4442",
        "RSA#2969",
        "ECDSA#1239"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "3.0",
        "6.0.2"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECDH": {
            "ECDH": 1
          },
          "ECDSA": {
            "ECDSA": 15
          }
        },
        "FF": {
          "DH": {
            "DH": 6,
            "Diffie-Hellman": 1
          }
        },
        "RSA": {
          "RSA 1024": 1,
          "RSA 2048": 4,
          "RSA 4096": 1
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 2
        },
        "GCM": {
          "GCM": 8
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {
        "OpenSSL": {
          "OpenSSL": 10
        }
      },
      "crypto_protocol": {
        "SSH": {
          "SSH": 2
        },
        "TLS": {
          "TLS": {
            "TLS": 56,
            "TLS 1.2": 3,
            "TLS v1.2": 2
          }
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key agreement": 1
        },
        "KEX": {
          "Key Exchange": 1
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-256": 4,
          "P-384": 22
        }
      },
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "#1702": 1
        }
      },
      "fips_certlike": {
        "Certlike": {
          "AES 128": 1,
          "AES 128 and 256": 1,
          "AES 256": 5,
          "AES-128": 1,
          "AES-256": 2,
          "DRBG cert #1702": 1,
          "HMAC SHA-384": 1,
          "HMAC-SHA-256": 10,
          "HMAC-SHA-384": 4,
          "HMAC-SHA-384 256": 2,
          "HMAC-SHA-3842": 2,
          "PKCS1": 6,
          "RSA 1024": 1,
          "RSA 2048": 4,
          "RSA 4096": 1,
          "SHA-256": 9,
          "SHA-384": 9,
          "SHA-512": 3
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 2": 4,
          "Level 3": 1
        }
      },
      "hash_function": {
        "SHA": {
          "SHA2": {
            "SHA-256": 9,
            "SHA-384": 9,
            "SHA-512": 3
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 33
        },
        "RNG": {
          "RNG": 3
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-2": 9,
          "FIPS 180-4": 2,
          "FIPS 186-4": 9,
          "FIPS 197": 2,
          "FIPS 198-1": 2
        },
        "NIST": {
          "NIST SP 800-90A": 22,
          "SP 800-133": 1,
          "SP 800-38A": 2,
          "SP 800-52": 1
        },
        "PKCS": {
          "PKCS1": 3
        },
        "RFC": {
          "RFC 5246": 1
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 18,
            "AES-128": 1,
            "AES-256": 2
          }
        },
        "DES": {
          "3DES": {
            "Triple-DES": 4
          }
        },
        "constructions": {
          "MAC": {
            "HMAC": 6,
            "HMAC-SHA-256": 5,
            "HMAC-SHA-384": 3
          }
        },
        "miscellaneous": {
          "ARIA": {
            "ARIA": 4
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {
        "TLS": {
          "TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384": 1,
          "TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384": 1,
          "TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256": 1,
          "TLS_RSA_WITH_AES_256_CBC_SHA256": 1
        }
      },
      "vendor": {
        "Thales": {
          "Thales": 29
        }
      },
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "Peter Tsai",
      "/CreationDate": "D:20190523204037+02\u002700\u0027",
      "/Creator": "Microsoft\u00ae Word 2016",
      "/ModDate": "D:20190523204037+02\u002700\u0027",
      "/Producer": "Microsoft\u00ae Word 2016",
      "/Title": "security policy",
      "pdf_file_size_bytes": 1443947,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "https://csrc.nist.gov/Projects/Cryptographic-Algorithm-Validation-Program/Validation/Validation-List/RSAhttp:/csrc.nist.gov/groups/STM/cavp/documents/dss/rsanewval.html",
          "https://csrc.nist.gov/Projects/Cryptographic-Algorithm-Validation-Program/Validation/Validation-List/AES",
          "https://csrc.nist.gov/Projects/Cryptographic-Algorithm-Validation-Program/Validation/Validation-List/ECDSA",
          "https://csrc.nist.gov/Projects/Cryptographic-Algorithm-Validation-Program/Validation/Validation-List/HMAC",
          "https://csrc.nist.gov/Projects/Cryptographic-Algorithm-Validation-Program/Validation/Validation-List/DRBG",
          "http://csrc.nist.gov/groups/STM/cmvp/index.html",
          "https://csrc.nist.gov/Projects/Cryptographic-Algorithm-Validation-Program/Validation/Validation-List/SHS",
          "https://csrc.nist.gov/Projects/Cryptographic-Algorithm-Validation-Program/Validation/Validation-List/Component"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 25
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
    "module_download_ok": true,
    "module_extract_ok": true,
    "policy_convert_ok": true,
    "policy_download_ok": true,
    "policy_extract_ok": true,
    "policy_json_hash": null,
    "policy_pdf_hash": "311564c9bb3c30be5484cd2b1a004f9ff87c04ad1e25614cb361340d65f3a8d4",
    "policy_txt_hash": "0e084621cd1a6ad3d13a5dacad670491e931be43026919355b148be6afb7230a"
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When Operated in FIPS mode. The protocol SSH shall not be used when operated in FIPS mode.",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/AprilConsolidated.pdf",
    "date_sunset": null,
    "description": "The Vormetric Data Security Server is a multi-chip standalone cryptographic module. The Vormetric Data Security Server is the central point of management for the Vormetric Data Security product. It manages keys and policies, and controls Vormetric Transparent Encryption Agents. These agents contain the Vormetric Encryption Expert Cryptographic Module, which has been validated separately from this module.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Roles, Services, and Authentication: Level 3",
      "Cryptographic Key Management: Level 3",
      "Design Assurance: Level 3",
      "Mitigation of Other Attacks: N/A"
    ],
    "fw_versions": "6.0.2",
    "historical_reason": "SP 800-56Arev3 transition",
    "hw_versions": "3.0",
    "level": 2,
    "mentioned_certs": {},
    "module_name": "Vormetric Data Security Manager Module",
    "module_type": "Hardware",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-2",
    "status": "historical",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2019-04-26",
        "lab": "CYGNACOM SOLUTIONS INC",
        "validation_type": "Initial"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2019-06-06",
        "lab": "CYGNACOM SOLUTIONS INC",
        "validation_type": "Update"
      }
    ],
    "vendor": "Thales eSecurity",
    "vendor_url": "http://www.thalesesecurity.com"
  }
}