SUSE Linux Enterprise GnuTLS Cryptographic Module

Certificate #5355

Webpage information

Status active
Validation dates 25.06.2026
Sunset date 24-06-2031
Standard FIPS 140-3
Security level 1
Type Software
Embodiment MultiChipStand
Caveat When operated in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.
Exceptions
  • Physical security: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A
Description GnuTLS is a secure communications library implementing the TLS protocol. It provides a simple C language application programming interface to access the secure communications protocols as well as APIs to parse and write X.509, PKCS#12, and other required structures which is shipped with SUSE Linux Enterprise.
Vendor SUSE LLC
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Symmetric Algorithms
AES-256, AES, AES-, Twofish, Serpent, CAST, RC2, RC4, DES, Triple-DES, ChaCha20, Salsa20, Poly1305, Blowfish, Camellia, HMAC, HMAC-SHA-256, CMAC
Asymmetric Algorithms
ECDH, ECDSA, ECC, Diffie-Hellman, DH, DSA
Hash functions
SHA-1, SHA-256, SHA-3, SHA3-224, SHA3-256, SHA3-384, SHA3-512, MD4, MD5, PBKDF2, PBKDF
Schemes
MAC, Key Exchange, Key agreement, Key Agreement
Protocols
TLS, TLS v1.2, TLSv1.0, TLS 1.0, TLSv1.3, TLS v1.3, TLS 1.2, TLS 1.3, IKE
Randomness
DRBG, RNG, RBG
Libraries
GnuTLS
Elliptic Curves
P-256, P-384, P-521, P-192, P-224
Block cipher modes
ECB, CBC, CTR, CFB, GCM, CCM, XTS
TLS cipher suites
TLS_DH_RSA_WITH_AES_128_CBC_SHA, TLS_DHE_RSA_WITH_AES_128_CBC_SHA, TLS_DH_RSA_WITH_AES_256_CBC_SHA, TLS_DHE_RSA_WITH_AES_256_CBC_SHA, TLS_DH_RSA_WITH_AES_128_CBC_SHA256, TLS_DHE_RSA_WITH_AES_128_CBC_SHA256, TLS_DH_RSA_WITH_AES_256_CBC_SHA256, TLS_DHE_RSA_WITH_AES_256_CBC_SHA256, TLS_PSK_WITH_AES_128_CBC_SHA, TLS_PSK_WITH_AES_256_CBC_SHA, TLS_DHE_RSA_WITH_AES_128_GCM_SHA256, TLS_DHE_RSA_WITH_AES_256_GCM_SHA384, TLS_DH_RSA_WITH_AES_128_GCM_SHA256, TLS_DH_RSA_WITH_AES_256_GCM_SHA384, TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA, TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA, TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA, TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA, TLS_ECDH_RSA_WITH_AES_128_CBC_SHA, TLS_ECDH_RSA_WITH_AES_256_CBC_SHA, TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA, TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA, TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256, TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384, TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA256, TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA384, TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, TLS_ECDH_RSA_WITH_AES_128_CBC_SHA256, TLS_ECDH_RSA_WITH_AES_256_CBC_SHA384, TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256, TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384, TLS_ECDH_ECDSA_WITH_AES_128_GCM_SHA256, TLS_ECDH_ECDSA_WITH_AES_256_GCM_SHA384, TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256, TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384, TLS_ECDH_RSA_WITH_AES_128_GCM_SHA256, TLS_ECDH_RSA_WITH_AES_256_GCM_SHA384, TLS_DHE_RSA_WITH_AES_128_CCM, TLS_DHE_RSA_WITH_AES_256_CCM, TLS_DHE_RSA_WITH_AES_128_CCM_8, TLS_DHE_RSA_WITH_AES_256_CCM_8

Trusted Execution Environments
PSP, SSC

Security level
Level 1, level 1

File metadata

Author Natan
Creation date D:20260623141553-04'00'
Modification date D:20260623141553-04'00'
Pages 89
Creator Microsoft® Word for Microsoft 365
Producer Microsoft® Word for Microsoft 365

Heuristics

No heuristics are available for this certificate.

References

No references are available for this certificate.

Updates Feed

  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 5355,
  "dgst": "89be545c95f75dbe",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "TLS v1.2 KDF RFC7627A6368",
        "SHA2-256A6376",
        "SHA2-224A6376",
        "ECDSA KeyVer (FIPS186-4)A6368",
        "ECDSA KeyVer (FIPS186-5)A6368",
        "KDA HKDF Sp800-56Cr1A6367",
        "AES-CFB8A6371",
        "KDF TLSA6368",
        "SHA3-224A6370",
        "SHA3-256A6370",
        "Safe Primes Key GenerationA6368",
        "AES-CCMA6374",
        "AES-CMACA6374",
        "AES-CBCA6375",
        "ECDSA SigGen (FIPS186-5)A6368",
        "HMAC-SHA2-512A6376",
        "HMAC-SHA2-384A6376",
        "AES-GMACA6368",
        "RSA SigVer (FIPS186-5)A6368",
        "HMAC-SHA-1A6376",
        "SHA2-512A6376",
        "ECDSA KeyGen (FIPS186-5)A6368",
        "AES-GCMA6375",
        "Counter DRBGA6368",
        "AES-ECBA6373",
        "PBKDFA6368",
        "SHA3-512A6370",
        "SHA2-384A6376",
        "SHA3-384A6370",
        "RSA SigGen (FIPS186-5)A6368",
        "HMAC-SHA2-256A6376",
        "HMAC-SHA2-224A6376",
        "KAS-FFC-SSC Sp800-56Ar3A6368",
        "AES-XTS Testing Revision 2.0A6369",
        "ECDSA SigVer (FIPS186-5)A6368",
        "KAS-ECC-SSC Sp800-56Ar3A6368",
        "RSA KeyGen (FIPS186-5)A6368",
        "SHA-1A6376"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "-"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 2
          },
          "ECDH": {
            "ECDH": 3
          },
          "ECDSA": {
            "ECDSA": 100
          }
        },
        "FF": {
          "DH": {
            "DH": 5,
            "Diffie-Hellman": 61
          },
          "DSA": {
            "DSA": 9
          }
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 3
        },
        "CCM": {
          "CCM": 4
        },
        "CFB": {
          "CFB": 1
        },
        "CTR": {
          "CTR": 2
        },
        "ECB": {
          "ECB": 2
        },
        "GCM": {
          "GCM": 7
        },
        "XTS": {
          "XTS": 4
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {
        "GnuTLS": {
          "GnuTLS": 92
        }
      },
      "crypto_protocol": {
        "IKE": {
          "IKE": 2
        },
        "TLS": {
          "TLS": {
            "TLS": 82,
            "TLS 1.0": 5,
            "TLS 1.2": 1,
            "TLS 1.3": 1,
            "TLS v1.2": 13,
            "TLS v1.3": 1,
            "TLSv1.0": 1,
            "TLSv1.3": 5
          }
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 4,
          "Key agreement": 3
        },
        "KEX": {
          "Key Exchange": 2
        },
        "MAC": {
          "MAC": 39
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-192": 4,
          "P-224": 8,
          "P-256": 34,
          "P-384": 12,
          "P-521": 30
        }
      },
      "eval_facility": {
        "atsec": {
          "atsec": 2
        }
      },
      "fips_cert_id": {},
      "fips_certlike": {
        "Certlike": {
          "AES-256": 2,
          "Diffie- Hellman 2048": 1,
          "HMAC- SHA-1": 4,
          "HMAC-SHA-1": 10,
          "HMAC-SHA-256": 6,
          "PKCS#1": 2,
          "SHA-1": 10,
          "SHA-256": 2,
          "SHA-3": 6,
          "SHA2- 224": 2,
          "SHA2- 384": 3,
          "SHA2-224": 12,
          "SHA2-256": 23,
          "SHA2-384": 13,
          "SHA2-512": 14,
          "SHA3-224": 6,
          "SHA3-256": 6,
          "SHA3-384": 5,
          "SHA3-512": 5
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 3,
          "level 1": 1
        }
      },
      "hash_function": {
        "MD": {
          "MD4": {
            "MD4": 3
          },
          "MD5": {
            "MD5": 4
          }
        },
        "PBKDF": {
          "PBKDF": 29,
          "PBKDF2": 5
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 10
          },
          "SHA2": {
            "SHA-256": 2
          },
          "SHA3": {
            "SHA-3": 6,
            "SHA3-224": 6,
            "SHA3-256": 6,
            "SHA3-384": 5,
            "SHA3-512": 5
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 32
        },
        "RNG": {
          "RBG": 2,
          "RNG": 4
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-3": 102,
          "FIPS 180-4": 6,
          "FIPS 186-4": 2,
          "FIPS 186-5": 10,
          "FIPS 197": 1,
          "FIPS 198-1": 6,
          "FIPS 202": 5,
          "FIPS PUB 140-3": 2,
          "FIPS186-4": 2,
          "FIPS186-5": 28
        },
        "NIST": {
          "SP 800-131A": 1,
          "SP 800-132": 4,
          "SP 800-133": 1,
          "SP 800-135": 4,
          "SP 800-38A": 5,
          "SP 800-38B": 2,
          "SP 800-38C": 1,
          "SP 800-38D": 3,
          "SP 800-38E": 1,
          "SP 800-52": 1,
          "SP 800-56A": 5,
          "SP 800-56C": 3,
          "SP 800-90A": 2,
          "SP 800-90B": 1
        },
        "PKCS": {
          "PKCS#1": 1
        },
        "RFC": {
          "RFC 3526": 1,
          "RFC 5288": 1,
          "RFC 7627": 1,
          "RFC 7919": 1,
          "RFC 8446": 1,
          "RFC3268": 4,
          "RFC3526": 1,
          "RFC4279": 2,
          "RFC4492": 8,
          "RFC5246": 4,
          "RFC5288": 5,
          "RFC5289": 16,
          "RFC6655": 4,
          "RFC7627": 8,
          "RFC7919": 1,
          "RFC8446": 5
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 57,
            "AES-": 10,
            "AES-256": 2
          },
          "CAST": {
            "CAST": 172
          },
          "RC": {
            "RC2": 3,
            "RC4": 1
          },
          "Serpent": {
            "Serpent": 3
          },
          "Twofish": {
            "Twofish": 3
          }
        },
        "DES": {
          "3DES": {
            "Triple-DES": 3
          },
          "DES": {
            "DES": 4
          }
        },
        "constructions": {
          "MAC": {
            "CMAC": 4,
            "HMAC": 27,
            "HMAC-SHA-256": 3
          }
        },
        "djb": {
          "ChaCha": {
            "ChaCha20": 6
          },
          "Poly": {
            "Poly1305": 3
          },
          "Salsa": {
            "Salsa20": 3
          }
        },
        "miscellaneous": {
          "Blowfish": {
            "Blowfish": 3
          },
          "Camellia": {
            "Camellia": 3
          }
        }
      },
      "tee_name": {
        "AMD": {
          "PSP": 8
        },
        "IBM": {
          "SSC": 5
        }
      },
      "tls_cipher_suite": {
        "TLS": {
          "TLS_DHE_RSA_WITH_AES_128_CBC_SHA": 1,
          "TLS_DHE_RSA_WITH_AES_128_CBC_SHA256": 1,
          "TLS_DHE_RSA_WITH_AES_128_CCM": 1,
          "TLS_DHE_RSA_WITH_AES_128_CCM_8": 1,
          "TLS_DHE_RSA_WITH_AES_128_GCM_SHA256": 1,
          "TLS_DHE_RSA_WITH_AES_256_CBC_SHA": 1,
          "TLS_DHE_RSA_WITH_AES_256_CBC_SHA256": 1,
          "TLS_DHE_RSA_WITH_AES_256_CCM": 1,
          "TLS_DHE_RSA_WITH_AES_256_CCM_8": 1,
          "TLS_DHE_RSA_WITH_AES_256_GCM_SHA384": 1,
          "TLS_DH_RSA_WITH_AES_128_CBC_SHA": 1,
          "TLS_DH_RSA_WITH_AES_128_CBC_SHA256": 1,
          "TLS_DH_RSA_WITH_AES_128_GCM_SHA256": 1,
          "TLS_DH_RSA_WITH_AES_256_CBC_SHA": 1,
          "TLS_DH_RSA_WITH_AES_256_CBC_SHA256": 1,
          "TLS_DH_RSA_WITH_AES_256_GCM_SHA384": 1,
          "TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA": 1,
          "TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256": 1,
          "TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256": 1,
          "TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA": 1,
          "TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384": 1,
          "TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384": 1,
          "TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA": 1,
          "TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256": 1,
          "TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256": 1,
          "TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA": 1,
          "TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384": 1,
          "TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384": 1,
          "TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA": 1,
          "TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA256": 1,
          "TLS_ECDH_ECDSA_WITH_AES_128_GCM_SHA256": 1,
          "TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA": 1,
          "TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA384": 1,
          "TLS_ECDH_ECDSA_WITH_AES_256_GCM_SHA384": 1,
          "TLS_ECDH_RSA_WITH_AES_128_CBC_SHA": 1,
          "TLS_ECDH_RSA_WITH_AES_128_CBC_SHA256": 1,
          "TLS_ECDH_RSA_WITH_AES_128_GCM_SHA256": 1,
          "TLS_ECDH_RSA_WITH_AES_256_CBC_SHA": 1,
          "TLS_ECDH_RSA_WITH_AES_256_CBC_SHA384": 1,
          "TLS_ECDH_RSA_WITH_AES_256_GCM_SHA384": 1,
          "TLS_PSK_WITH_AES_128_CBC_SHA": 1,
          "TLS_PSK_WITH_AES_256_CBC_SHA": 1
        }
      },
      "vendor": {},
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "Natan",
      "/CreationDate": "D:20260623141553-04\u002700\u0027",
      "/Creator": "Microsoft\u00ae Word for Microsoft 365",
      "/MSIP_Label_4dd2c6e0-f1e3-4cf2-bd0b-256ab4cff3af_ActionId": "d17a0c56-24f1-47f5-9b1c-62f2bc02ba8f",
      "/MSIP_Label_4dd2c6e0-f1e3-4cf2-bd0b-256ab4cff3af_ContentBits": "1",
      "/MSIP_Label_4dd2c6e0-f1e3-4cf2-bd0b-256ab4cff3af_Enabled": "true",
      "/MSIP_Label_4dd2c6e0-f1e3-4cf2-bd0b-256ab4cff3af_Method": "Privileged",
      "/MSIP_Label_4dd2c6e0-f1e3-4cf2-bd0b-256ab4cff3af_Name": "UNCLASSIFIED",
      "/MSIP_Label_4dd2c6e0-f1e3-4cf2-bd0b-256ab4cff3af_SetDate": "2026-06-23T17:55:30Z",
      "/MSIP_Label_4dd2c6e0-f1e3-4cf2-bd0b-256ab4cff3af_SiteId": "da9cbe40-ec1e-4997-afb3-17d87574571a",
      "/MSIP_Label_4dd2c6e0-f1e3-4cf2-bd0b-256ab4cff3af_Tag": "10, 0, 1, 1",
      "/ModDate": "D:20260623141553-04\u002700\u0027",
      "/Producer": "Microsoft\u00ae Word for Microsoft 365",
      "pdf_file_size_bytes": 931561,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "https://doi.org/10.6028/NIST.FIPS.180-4",
          "https://www.ietf.org/rfc/rfc3526.txt",
          "https://doi.org/10.6028/NIST.SP.800-56Ar3",
          "https://www.ietf.org/rfc/rfc5288.txt",
          "https://doi.org/10.6028/NIST.SP.800-56Cr2",
          "https://doi.org/10.6028/NIST.SP.800-90B",
          "https://doi.org/10.6028/NIST.SP.800-133r2",
          "https://doi.org/10.6028/NIST.SP.800-38B",
          "https://www.ietf.org/rfc/rfc8446.txt",
          "https://csrc.nist.gov/csrc/media/Projects/cryptographic-module-validation-program/documents/fips%20140-3/FIPS%20140-3%20IG.pdf",
          "https://csrc.nist.gov/csrc/media/Projects/cryptographic-module-validation-program/documents/fips%20140-3/FIPS-140-3-CMVP%20Management%20Manual.pdf",
          "https://doi.org/10.6028/NIST.SP.800-90Ar1",
          "https://doi.org/10.6028/NIST.SP.800-38A-Add",
          "https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-3.pdf",
          "https://doi.org/10.6028/NIST.SP.800-135r1",
          "https://doi.org/10.6028/NIST.FIPS.186-5",
          "https://doi.org/10.6028/NIST.FIPS.202",
          "https://doi.org/10.6028/NIST.SP.800-132",
          "https://www.ietf.org/rfc/rfc7627.txt",
          "https://doi.org/10.6028/NIST.SP.800-38A",
          "https://doi.org/10.6028/NIST.FIPS.186-4",
          "https://www.rfc-editor.org/rfc/rfc8017.txt",
          "https://doi.org/10.6028/NIST.SP.800-52r2",
          "https://doi.org/10.6028/NIST.FIPS.198-1",
          "https://doi.org/10.6028/NIST.FIPS.197-upd1",
          "https://www.ietf.org/rfc/rfc7919.txt"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 89
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.InternalState",
    "module": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "policy": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": "38d0357aa2d1d0e61b0ed89decce57cf8d84ed975907cbacc90eddc4701bb95f",
      "txt_hash": "1591aabaa1e6a411826cc5c490548bed4872ab9a14e3a3f028c6141debb4ac75"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/June 2026_080726_0648.pdf",
    "date_sunset": "2031-06-24",
    "description": "GnuTLS is a secure communications library implementing the TLS protocol. It provides a simple C language application programming interface to access the secure communications protocols as well as APIs to parse and write X.509, PKCS#12, and other required structures which is shipped with SUSE Linux Enterprise.",
    "embodiment": "MultiChipStand",
    "exceptions": [
      "Physical security: N/A",
      "Non-invasive security: N/A",
      "Mitigation of other attacks: N/A"
    ],
    "fw_versions": null,
    "historical_reason": null,
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {},
    "module_name": "SUSE Linux Enterprise GnuTLS Cryptographic Module",
    "module_type": "Software",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-3",
    "status": "active",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2026-06-25",
        "lab": "atsec information security corporation",
        "validation_type": "Initial"
      }
    ],
    "vendor": "SUSE LLC",
    "vendor_url": "http://www.suse.com"
  }
}