Junos® OS Evolved OpenSSL Cryptographic Module version 3.0

Certificate details

Certificate ID #5412
Status active
Validation dates 14.07.2026
Sunset date 13-07-2031
Standard FIPS 140-3
Security level 1
Type Software
Embodiment MultiChipStand
Caveat When operated in approved mode with module Junos® OS Evolved Kernel Cryptographic Module version 2.1 validated to FIPS 140-3 under Cert. #NNNN operating in the Approved mode. No assurance of minimum security of SSPs (e.g. keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.
Exceptions
  • Physical security: N/A
  • Non-invasive security: N/A
Description The Junos® OS Evolved OpenSSL Cryptographic Module provides a C language application program interface (API) for use by other applications that require cryptographic functionality.
Vendor HPE Juniper Networking http://www.hpe.com
Lab atsec information security corporation
Algorithms
  • AES-CBC-CS1A7228
  • AES-CBC-CS2A7228
  • AES-CBC-CS3A7228
  • AES-CBCA7228
  • AES-CCMA7228
  • AES-CFB128A7228
  • AES-CFB1A7228
  • AES-CFB8A7228
  • AES-CMACA7228
  • AES-CTRA7228
  • AES-ECBA7228
  • AES-GCMA7242
  • AES-GMACA7242
  • AES-KWA7228
  • AES-KWPA7228
  • AES-OFBA7228
  • AES-XTS Testing Revision 2.0A7228
  • ECDSA KeyGen (FIPS186-5)A7246
  • ECDSA KeyVer (FIPS186-5)A7246
  • ECDSA SigGen (FIPS186-5)A7246
  • ECDSA SigVer (FIPS186-5)A7246
  • HMAC DRBGA7315
  • HMAC-SHA-1A7246
  • HMAC-SHA2-224A7246
  • HMAC-SHA2-256A7246
  • HMAC-SHA2-384A7246
  • HMAC-SHA2-512/224A7246
  • HMAC-SHA2-512/256A7246
  • HMAC-SHA2-512A7246
  • HMAC-SHA3-224A7233
  • HMAC-SHA3-256A7233
  • HMAC-SHA3-384A7233
  • HMAC-SHA3-512A7233
  • KAS-ECC-SSC Sp800-56Ar3A7246
  • KAS-FFC-SSC Sp800-56Ar3A7248
  • KDA HKDF SP800-56Cr2A7225
  • KDA OneStep SP800-56Cr2A7224
  • KDF ANS 9.42A7246
  • KDF ANS 9.63A7246
  • KDF SP800-108A7247
  • KDF SSHA7246
  • KMAC-128A7233
  • KMAC-256A7233
  • PBKDFA7246
  • RSA KeyGen (FIPS186-5)A7246
  • RSA SigGen (FIPS186-5)A7246
  • RSA SigVer (FIPS186-5)A7246
  • Safe Primes Key GenerationA7248
  • Safe Primes Key VerificationA7248
  • SHA-1A7246
  • SHA2-224A7246
  • SHA2-256A7246
  • SHA2-384A7246
  • SHA2-512/224A7246
  • SHA2-512/256A7246
  • SHA2-512A7246
  • SHA3-224A7233
  • SHA3-256A7233
  • SHA3-384A7233
  • SHA3-512A7233
  • SHAKE-128A7233
  • SHAKE-256A7233
  • TLS v1.2 KDF RFC7627A7246
  • TLS v1.3 KDFA7225
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Extracted keywords

Symmetric Algorithms
AES-128, AES-192, AES-256, AES, AES-, CAST, HMAC, KMAC, CMAC
Asymmetric Algorithms
ECDH, ECDSA, ECC, Diffie-Hellman, DHE, DH
Hash functions
SHA-1, SHA-2, SHA3-224, SHA3-256, SHA3-384, SHA3-512, SHA-3, PBKDF2, PBKDF
Schemes
MAC, Key Exchange, Key Agreement
Protocols
SSH, TLS v1.2, TLS v1.3, TLS 1.3, TLS 1.2, TLS, IKE
Randomness
DRBG, RNG, RBG
Libraries
OpenSSL
Elliptic Curves
P-224, P-256, P-384, P-521
Block cipher modes
ECB, CBC, CTR, GCM, CCM, XTS

Trusted Execution Environments
PSP, SSC

Security level
Level 1

Automated analysis

Automated inference - use with caution

All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.

No automatically derived data are available in this section.

Cross-references

Loading...

Processing updates

Feed
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 5412,
  "dgst": "8bba5b9b846fd63c",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "AES-CTRA7228",
        "#A7225",
        "#A7228",
        "SHA-1A7246",
        "KDF SP800-108A7247",
        "#A7237",
        "KDF ANS 9.63A7246",
        "ECDSA SigVer (FIPS186-5)A7246",
        "SHA3-224A7233",
        "AES-CBCA7228",
        "AES-KWPA7228",
        "SHA2-512/256A7246",
        "#A7310",
        "KDF ANS 9.42A7246",
        "SHA2-224A7246",
        "AES-CFB8A7228",
        "AES-CBC-CS3A7228",
        "AES-CFB128A7228",
        "TLS v1.3 KDFA7225",
        "AES-CCMA7228",
        "#A7235",
        "SHA2-256A7246",
        "SHA3-256A7233",
        "KDA OneStep SP800-56Cr2A7224",
        "#A7224",
        "AES-CBC-CS2A7228",
        "KMAC-256A7233",
        "HMAC-SHA3-256A7233",
        "SHA3-384A7233",
        "#A7241",
        "SHA2-512A7246",
        "#A7234",
        "HMAC-SHA2-224A7246",
        "HMAC-SHA3-384A7233",
        "HMAC-SHA2-384A7246",
        "AES-GMACA7242",
        "#A7226",
        "#A7315",
        "#A7311",
        "RSA KeyGen (FIPS186-5)A7246",
        "ECDSA KeyVer (FIPS186-5)A7246",
        "ECDSA KeyGen (FIPS186-5)A7246",
        "KDF SSHA7246",
        "TLS v1.2 KDF RFC7627A7246",
        "SHA2-384A7246",
        "SHA3-512A7233",
        "SHAKE-256A7233",
        "AES-ECBA7228",
        "RSA SigVer (FIPS186-5)A7246",
        "#A7244",
        "#A7314",
        "HMAC DRBGA7315",
        "#A7233",
        "KMAC-128A7233",
        "#A7246",
        "#A7232",
        "AES-GCMA7242",
        "HMAC-SHA2-512A7246",
        "AES-OFBA7228",
        "KAS-FFC-SSC Sp800-56Ar3A7248",
        "#A7243",
        "HMAC-SHA3-512A7233",
        "AES-CFB1A7228",
        "RSA SigGen (FIPS186-5)A7246",
        "#A7247",
        "HMAC-SHA2-256A7246",
        "#A7245",
        "#A7248",
        "#A7313",
        "AES-XTS Testing Revision 2.0A7228",
        "PBKDFA7246",
        "AES-CMACA7228",
        "ECDSA SigGen (FIPS186-5)A7246",
        "Safe Primes Key GenerationA7248",
        "AES-CBC-CS1A7228",
        "#A7239",
        "#A7231",
        "#A7240",
        "KAS-ECC-SSC Sp800-56Ar3A7246",
        "#A7236",
        "SHAKE-128A7233",
        "#A7227",
        "Safe Primes Key VerificationA7248",
        "#A7308",
        "HMAC-SHA2-512/256A7246",
        "KDA HKDF SP800-56Cr2A7225",
        "#A7230",
        "HMAC-SHA-1A7246",
        "#A7238",
        "#A7242",
        "AES-KWA7228",
        "HMAC-SHA3-224A7233",
        "SHA2-512/224A7246",
        "#A7229",
        "HMAC-SHA2-512/224A7246"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "3.0"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": {
        "_type": "Set",
        "elements": [
          "5529",
          "5470"
        ]
      },
      "directly_referencing": null,
      "indirectly_referenced_by": {
        "_type": "Set",
        "elements": [
          "5529",
          "5470"
        ]
      },
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "br1_deviations": 1,
    "br1_tables": {
      "_type": "sec_certs.heuristics.br1.table_parsing.model.br1_tables.BR1Tables",
      "approved_algorithms": {
        "entries": [
          {
            "algorithm": "AES-CBC",
            "cavpCertName": "A7226, A7227, A7228",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CBC-CS1",
            "cavpCertName": "A7226, A7227, A7228",
            "properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CBC-CS2",
            "cavpCertName": "A7226, A7227, A7228",
            "properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CBC-CS3",
            "cavpCertName": "A7226, A7227, A7228",
            "properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CCM",
            "cavpCertName": "A7226, A7227, A7228",
            "properties": "Key Length - 128, 192, 256",
            "reference": "SP 800-38C"
          },
          {
            "algorithm": "AES-CFB1",
            "cavpCertName": "A7226, A7227, A7228",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CFB128",
            "cavpCertName": "A7226, A7227, A7228",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CFB8",
            "cavpCertName": "A7226, A7227, A7228",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CMAC",
            "cavpCertName": "A7226, A7227, A7228",
            "properties": "Direction - Generation Key Length - 128, 192, 256",
            "reference": "SP 800-38B"
          },
          {
            "algorithm": "AES-CTR",
            "cavpCertName": "A7226, A7227, A7228",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-ECB",
            "cavpCertName": "A7226, A7227, A7228",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-GCM",
            "cavpCertName": "A7234, A7235, A7236, A7237, A7238, A7239, A7240, A7241, A7242",
            "properties": "Direction - Decrypt, Encrypt IV Generation - External, Internal Key Length - 128, 192, 256 IV Generation Mode - 8.2.2",
            "reference": "SP 800- 38D"
          },
          {
            "algorithm": "AES-GMAC",
            "cavpCertName": "A7234, A7235, A7236, A7237, A7238, A7239,",
            "properties": "Direction - Decrypt, Encrypt IV Generation - External Key Length - 128, 192, 256",
            "reference": "SP 800- 38D"
          },
          {
            "algorithm": "",
            "cavpCertName": "A7240, A7241, A7242",
            "properties": "",
            "reference": ""
          },
          {
            "algorithm": "AES-KW",
            "cavpCertName": "A7226, A7227, A7228",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38F"
          },
          {
            "algorithm": "AES-KWP",
            "cavpCertName": "A7226, A7227, A7228",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38F"
          },
          {
            "algorithm": "AES-OFB",
            "cavpCertName": "A7226, A7227, A7228",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-XTS Testing Revision 2.0",
            "cavpCertName": "A7226, A7227, A7228",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 256",
            "reference": "SP 800-38E"
          },
          {
            "algorithm": "ECDSA KeyGen (FIPS186-5)",
            "cavpCertName": "A7243, A7244, A7245, A7246",
            "properties": "Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - testing candidates",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "ECDSA KeyVer (FIPS186-5)",
            "cavpCertName": "A7243, A7244, A7245, A7246",
            "properties": "Curve - P-224, P-256, P-384, P-521",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "ECDSA SigGen (FIPS186-5)",
            "cavpCertName": "A7233",
            "properties": "Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA3-224, SHA3-256, SHA3-384, SHA3-512 Component - No, Yes",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "ECDSA SigGen (FIPS186-5)",
            "cavpCertName": "A7243, A7244, A7245, A7246",
            "properties": "Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 Component - No, Yes",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "ECDSA SigVer (FIPS186-5)",
            "cavpCertName": "A7233",
            "properties": "Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA3-224, SHA3-256, SHA3-384, SHA3-512",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "ECDSA SigVer (FIPS186-5)",
            "cavpCertName": "A7243, A7244, A7245, A7246",
            "properties": "Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "HMAC-SHA-1",
            "cavpCertName": "A7243, A7244, A7245, A7246",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2- 224",
            "cavpCertName": "A7243, A7244, A7245, A7246",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2- 256",
            "cavpCertName": "A7243, A7244, A7245, A7246",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2- 384",
            "cavpCertName": "A7243, A7244, A7245, A7246",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2- 512",
            "cavpCertName": "A7243, A7244, A7245, A7246",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2- 512/224",
            "cavpCertName": "A7243, A7244, A7245, A7246",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2- 512/256",
            "cavpCertName": "A7243, A7244, A7245, A7246",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3- 224",
            "cavpCertName": "A7233",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3- 256",
            "cavpCertName": "A7233",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3- 384",
            "cavpCertName": "A7233",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA3- 512",
            "cavpCertName": "A7233",
            "properties": "Key Length - Key Length: 112-524288 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "KAS-ECC-SSC Sp800-56Ar3",
            "cavpCertName": "A7243, A7244, A7245, A7246",
            "properties": "Domain Parameter Generation Methods - P-224, P- 256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responder",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "KAS-FFC-SSC Sp800-56Ar3",
            "cavpCertName": "A7248",
            "properties": "Domain Parameter Generation Methods - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP- 2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192 Scheme - dhEphem - KAS Role - initiator, responder",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "KDA HKDF SP800-56Cr2",
            "cavpCertName": "A7225",
            "properties": "Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224- 8192 Increment 8 HMAC Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512",
            "reference": "SP 800-56C Rev. 2"
          },
          {
            "algorithm": "KDA OneStep SP800-56Cr2",
            "cavpCertName": "A7224",
            "properties": "Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224- 8192 Increment 8",
            "reference": "SP 800-56C Rev. 2"
          },
          {
            "algorithm": "KDF ANS 9.42 (CVL)",
            "cavpCertName": "A7233",
            "properties": "KDF Type - DER Hash Algorithm - SHA3-224, SHA3-256, SHA3-384, SHA3-512 Key Data Length - Key Data Length: 112-4096 Increment 8",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "KDF ANS 9.42 (CVL)",
            "cavpCertName": "A7243, A7244, A7245, A7246",
            "properties": "KDF Type - DER Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 Key Data Length - Key Data Length: 112-4096 Increment 8",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "KDF ANS 9.63 (CVL)",
            "cavpCertName": "A7243, A7244, A7245, A7246",
            "properties": "Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "",
            "cavpCertName": "",
            "properties": "Key Data Length - Key Data Length: 128-4096 Increment 8",
            "reference": ""
          },
          {
            "algorithm": "KDF SP800- 108",
            "cavpCertName": "A7247",
            "properties": "KDF Mode - Counter, Feedback Supported Lengths - Supported Lengths: 112-4096 Increment 8",
            "reference": "SP 800-108 Rev. 1"
          },
          {
            "algorithm": "KDF SSH (CVL)",
            "cavpCertName": "A7229, A7230, A7231, A7232, A7243, A7244, A7245, A7246",
            "properties": "Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "KMAC-128",
            "cavpCertName": "A7233",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Key Data Length - Key Data Length: 128-1024 Increment 8",
            "reference": "SP 800-185"
          },
          {
            "algorithm": "KMAC-256",
            "cavpCertName": "A7233",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Key Data Length - Key Data Length: 256-1024 Increment 8",
            "reference": "SP 800-185"
          },
          {
            "algorithm": "PBKDF",
            "cavpCertName": "A7233, A7243, A7244, A7245, A7246",
            "properties": "Iteration Count - Iteration Count: 1000-10000 Increment 1 Password Length - Password Length: 8-128 Increment 1",
            "reference": "SP 800-132"
          },
          {
            "algorithm": "RSA KeyGen (FIPS186-5)",
            "cavpCertName": "A7243, A7244, A7245, A7246",
            "properties": "Key Generation Mode - probableWithProbableAux Modulo - 2048, 3072, 4096, 6144, 8192 Primality Tests - 2powSecStr Private Key Format - standard",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "RSA SigGen (FIPS186-5)",
            "cavpCertName": "A7233, A7243, A7244, A7245, A7246",
            "properties": "Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pss",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "RSA SigVer (FIPS186-5)",
            "cavpCertName": "A7233, A7243, A7244, A7245, A7246",
            "properties": "Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pss",
            "reference": "FIPS 186-5"
          },
          {
            "algorithm": "Safe Primes Key Generation",
            "cavpCertName": "A7248",
            "properties": "Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "Safe Primes Key Verification",
            "cavpCertName": "A7248",
            "properties": "Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "SHA-1",
            "cavpCertName": "A7243, A7244, A7245, A7246",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-224",
            "cavpCertName": "A7243, A7244, A7245, A7246",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-256",
            "cavpCertName": "A7243, A7244, A7245, A7246",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-384",
            "cavpCertName": "A7243, A7244, A7245, A7246",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512",
            "cavpCertName": "A7243, A7244, A7245, A7246",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512/224",
            "cavpCertName": "A7243, A7244, A7245, A7246",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512/256",
            "cavpCertName": "A7243, A7244, A7245, A7246",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA3-224",
            "cavpCertName": "A7233",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3-256",
            "cavpCertName": "A7233",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3-384",
            "cavpCertName": "A7233",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3-512",
            "cavpCertName": "A7233",
            "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHAKE-128",
            "cavpCertName": "A7233",
            "properties": "Output Length - Output Length: 16-65536 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHAKE-256",
            "cavpCertName": "A7233",
            "properties": "Output Length - Output Length: 16-65536 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "TLS v1.2 KDF RFC7627 (CVL)",
            "cavpCertName": "A7243, A7244, A7245, A7246",
            "properties": "Hash Algorithm - SHA2-256, SHA2-384, SHA2-512",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "TLS v1.3 KDF (CVL)",
            "cavpCertName": "A7225",
            "properties": "HMAC Algorithm - SHA2-256, SHA2-384 KDF Running Modes - DHE, PSK, PSK-DHE",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "HMAC DRBG",
            "cavpCertName": "A7308, A7310, A7311, A7313",
            "properties": "Mode - SHA2-512",
            "reference": "SP 800-90A Rev. 1"
          },
          {
            "algorithm": "HMAC DRBG",
            "cavpCertName": "A7314, A7315",
            "properties": "Mode - SHA2-256, SHA2-512",
            "reference": "SP 800-90A Rev. 1"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "approved_services": {
        "entries": [
          {
            "description": "Compute a message digest",
            "indicator": "EVP_Digest*() functions will return 0",
            "inputs": "Message",
            "name": "Message Digest",
            "outputs": "Message Digest",
            "rolesSspAccess": "Crypto Officer",
            "secFunImpl": "Message Digest"
          },
          {
            "description": "Compute the output of an XOF",
            "indicator": "EVP_Digest*() functions will return 0",
            "inputs": "Message, output length",
            "name": "XOF",
            "outputs": "XOF output of desired length",
            "rolesSspAccess": "Crypto Officer",
            "secFunImpl": "Message Digest"
          },
          {
            "description": "Encrypt a plaintext",
            "indicator": "EVP_Encrypt*() functions will return 0",
            "inputs": "Plaintext, AES key, IV",
            "name": "Symmetric Encryption",
            "outputs": "Ciphertext",
            "rolesSspAccess": "Crypto Officer - AES key: W,E",
            "secFunImpl": "Symmetric Encryption"
          },
          {
            "description": "Decrypt a ciphertext",
            "indicator": "EVP_Decrypt*() functions will return 0",
            "inputs": "Ciphertext , AES key, IV",
            "name": "Symmetric Decryption",
            "outputs": "Plaintext",
            "rolesSspAccess": "Crypto Officer - AES key: W,E",
            "secFunImpl": "Symmetric Decryption Authenticate d Symmetric Decryption"
          },
          {
            "description": "Encrypt \u0026 authenticat e a plaintext",
            "indicator": "AES-CCM: EVP_Encrypt*() functions will return 0; AES- GCM: ERR_peek_last_ error() function returns something",
            "inputs": "Plaintext, AES key, IV",
            "name": "Authenticate d Symmetric Encryption",
            "outputs": "Ciphertext , MAC tag",
            "rolesSspAccess": "Crypto Officer - AES key: W,E - AES-GCM IV: G,W,E",
            "secFunImpl": "Authenticate d Symmetric Encryption"
          },
          {
            "description": "",
            "indicator": "different from 0x1C80012C",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "",
            "secFunImpl": ""
          },
          {
            "description": "Authenticat e \u0026 decrypt a plaintext",
            "indicator": "EVP_Decrypt*() functions will return 0",
            "inputs": "Ciphertext , MAC tag, AES key, IV",
            "name": "Authenticate d Symmetric Decryption",
            "outputs": "Plaintext or Fail",
            "rolesSspAccess": "Crypto Officer - AES key: W,E - AES-GCM IV: W,E",
            "secFunImpl": "Authenticate d Symmetric Decryption"
          },
          {
            "description": "Perform AES-based key wrapping",
            "indicator": "EVP_Encrypt*() functions will return 0",
            "inputs": "Key to be wrapped, AES key wrapping key",
            "name": "Key Wrapping",
            "outputs": "Wrapped key",
            "rolesSspAccess": "Crypto Officer - AES key: W,E",
            "secFunImpl": "Key Wrapping with AES- KW Key Wrapping with AES- KWP"
          },
          {
            "description": "Perform AES-based key unwrappin g",
            "indicator": "EVP_Decrypt*() functions will return 0",
            "inputs": "Key to be unwrappe d, AES key wrapping key",
            "name": "Key Unwrapping",
            "outputs": "Unwrappe d key",
            "rolesSspAccess": "Crypto Officer - AES key: W,E",
            "secFunImpl": "Key Unwrapping with AES- KW Key Unwrapping with AES- KWP"
          },
          {
            "description": "Compute a MAC tag",
            "indicator": "EVP_MAC*() functions will return 0",
            "inputs": "Message, MAC key (AES key, KMAC key, or HMAC key)",
            "name": "Message Authenticatio n Code",
            "outputs": "MAC tag",
            "rolesSspAccess": "Crypto Officer - AES key: W,E - HMAC key: W,E - KMAC key: W,E",
            "secFunImpl": "MAC"
          },
          {
            "description": "Derive a key from a key- derivation key",
            "indicator": "EVP_KDF*() functions will return 0",
            "inputs": "Key- derivation key",
            "name": "KBKDF Key Derivation",
            "outputs": "KBKDF derived key",
            "rolesSspAccess": "Crypto Officer - Key- derivation key: W,E - KBKDF derived key: G,R",
            "secFunImpl": "KBKDF Key Derivation"
          },
          {
            "description": "Derive a key from a",
            "indicator": "EVP_KDF*() functions will return 0",
            "inputs": "Shared secret",
            "name": "KDA OneStep Key Derivation",
            "outputs": "KDA OneStep",
            "rolesSspAccess": "Crypto Officer - DH shared",
            "secFunImpl": "KDA OneStep Key Derivation"
          },
          {
            "description": "shared secret",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "derived key",
            "rolesSspAccess": "secret: W,E - ECDH shared secret: W,E - KDA OneStep derived key: G,R",
            "secFunImpl": ""
          },
          {
            "description": "Derive a key from a shared secret",
            "indicator": "EVP_KDF*() functions will return 0",
            "inputs": "Shared secret",
            "name": "HKDF Key Derivation",
            "outputs": "Hkdf derived key",
            "rolesSspAccess": "Crypto Officer - DH shared secret: W,E - ECDH shared secret: W,E - HKDF derived key: G,R",
            "secFunImpl": "HKDF Key Derivation"
          },
          {
            "description": "Derive a key from a shared secret",
            "indicator": "EVP_KDF*() functions will return 0",
            "inputs": "Shared secret",
            "name": "ANS X9.42 KDF Key Derivation",
            "outputs": "ANS X9.42 KDF derived key",
            "rolesSspAccess": "Crypto Officer - DH shared secret: W,E - ECDH shared secret: W,E - ANS X9.42 derived key: G,R",
            "secFunImpl": "ANS 9.42 KDF Key Derivation"
          },
          {
            "description": "Derive a key from a shared secret",
            "indicator": "EVP_KDF*() functions will return 0",
            "inputs": "Shared secret",
            "name": "ANS X9.63 KDF Key Derivation",
            "outputs": "ANS X9.63 KDF derived key",
            "rolesSspAccess": "Crypto Officer - DH shared secret: W,E - ECDH shared secret: W,E - ANS X9.63 derived key: G,R",
            "secFunImpl": "ANS 9.63 KDF Key Derivation"
          },
          {
            "description": "Derive a key from a shared secret",
            "indicator": "EVP_KDF*() functions will return 0",
            "inputs": "Shared secret",
            "name": "SSH KDF Key Derivation",
            "outputs": "SSH KDF derived key",
            "rolesSspAccess": "Crypto Officer - DH shared secret: W,E - ECDH",
            "secFunImpl": "SSH KDF Key Derivation None"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "shared secret: W,E - SSH KDF derived key: G,R",
            "secFunImpl": ""
          },
          {
            "description": "Derive a key from a shared secret",
            "indicator": "EVP_KDF*() functions will return 0",
            "inputs": "Shared secret",
            "name": "TLS 1.2 KDF Key Derivation",
            "outputs": "TLS 1.2 KDF derived key",
            "rolesSspAccess": "Crypto Officer - DH shared secret: W,E - ECDH shared secret: W,E - TLS 1.2 KDF derived key: G,R",
            "secFunImpl": "TLS 1.2 KDF Key Derivation"
          },
          {
            "description": "Derive a key from a shared secret",
            "indicator": "EVP_KDF*() functions will return 0",
            "inputs": "Shared secret",
            "name": "TLS 1.3 KDF Key Derivation",
            "outputs": "TLS 1.3 KDF derived key",
            "rolesSspAccess": "Crypto Officer - DH shared secret: W,E - ECDH shared secret: W,E - TLS 1.3 KDF derived key: G,R",
            "secFunImpl": "TLS 1.3 KDF Key Derivation"
          },
          {
            "description": "Derive a key from a password",
            "indicator": "EVP_KDF*() functions will return 0",
            "inputs": "Password",
            "name": "Password- based Key Derivation",
            "outputs": "PBKDF derived key",
            "rolesSspAccess": "Crypto Officer - Password: W,E - PBKDF2 derived key: G,R",
            "secFunImpl": "Password- based Key Derivation"
          },
          {
            "description": "Compute a shared secret",
            "indicator": "EVP_PKEY*() functions will return 0",
            "inputs": "DH private key, DH public key from peer",
            "name": "DH Shared Secret Computation",
            "outputs": "DH shared secret",
            "rolesSspAccess": "Crypto Officer - DH private key: W,E - DH public key: W,E - DH shared secret: G,R",
            "secFunImpl": "DH Shared Secret Computation"
          },
          {
            "description": "Compute a shared secret",
            "indicator": "EVP_PKEY*() functions will return 0",
            "inputs": "ECDH private key,",
            "name": "ECDH Shared Secret Computation",
            "outputs": "ECDH shared secret",
            "rolesSspAccess": "Crypto Officer - ECDH",
            "secFunImpl": "ECDH Shared"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "ECDH public key from peer",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "private key: W,E - ECDH public key: W,E - ECDH shared secret: G,R",
            "secFunImpl": "Secret Computation"
          },
          {
            "description": "Generate a signature",
            "indicator": "EVP_DigestSign*() functions will return 0",
            "inputs": "Message, Private key (RSA private key or ECDSA private key)",
            "name": "Signature Generation",
            "outputs": "Signature",
            "rolesSspAccess": "Crypto Officer - RSA private key: W,E - ECDSA private key: W,E",
            "secFunImpl": "Signature Generation"
          },
          {
            "description": "Verify a signature",
            "indicator": "EVP_DigestVerify *() functions will return 0",
            "inputs": "Message, Public key (RSA public key or ECDSA public key), Signature",
            "name": "Signature Verification",
            "outputs": "Pass or Fail",
            "rolesSspAccess": "Crypto Officer - RSA public key: W,E - ECDSA public key: W,E",
            "secFunImpl": "Signature Verification"
          },
          {
            "description": "Generate a key pair",
            "indicator": "EVP_PKEY*() will return 0",
            "inputs": "Domain (group, curve, or bitlength)",
            "name": "Key Pair Generation",
            "outputs": "Key pair (DH, EC, or RSA)",
            "rolesSspAccess": "Crypto Officer - Module- generated DH private key: G,R - Module- generated DH public key: G,R - Module- generated ECDH private key: G,R - Module- generated ECDH public key: G,R",
            "secFunImpl": "ECDSA Key Pair Generation Safe Primes Key Pair Generation RSA Key Pair Generation"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "- Module- generated ECDSA private key: G,R - Module- generated ECDSA public key: G,R - Module- generated RSA private key: G,R - Module- generated RSA public key: G,R - Intermediate key generation",
            "secFunImpl": ""
          },
          {
            "description": "Verify a key pair",
            "indicator": "EVP_PKEY*() will return 0",
            "inputs": "Domain (group or curve), Key pair (DH or EC)",
            "name": "Key Pair Verification",
            "outputs": "Pass or Fail",
            "rolesSspAccess": "value: G,W,E Crypto Officer - DH private key: W - DH public key: W - ECDH private key: W - ECDH public key: W - ECDSA private key: W - ECDSA public key: W",
            "secFunImpl": "ECDSA Key Pair Verification Safe Primes Key Pair Verification"
          },
          {
            "description": "Generate random bytes",
            "indicator": "RAND_bytes*() will return number of bytes provided",
            "inputs": "Output length",
            "name": "[EVM] Random Number Generation",
            "outputs": "Random bytes",
            "rolesSspAccess": "Crypto Officer - [EVM] DRBG entropy input string: W,E,Z - [EVM] HMAC_DRB G Seed: G,E,Z - [EVM] HMAC_DRB G internal state (V, Key): G,W,E",
            "secFunImpl": "Random Number Generation"
          },
          {
            "description": "Return the name and version information",
            "indicator": "N/A",
            "inputs": "N/A",
            "name": "Show Version",
            "outputs": "Module Version",
            "rolesSspAccess": "Crypto Officer",
            "secFunImpl": "None"
          },
          {
            "description": "Return the module status",
            "indicator": "N/A",
            "inputs": "N/A",
            "name": "Show Status",
            "outputs": "Module Status",
            "rolesSspAccess": "Crypto Officer",
            "secFunImpl": "None"
          },
          {
            "description": "Perform the CASTs and integrity test",
            "indicator": "N/A",
            "inputs": "N/A",
            "name": "Self-test",
            "outputs": "Pass or Fail",
            "rolesSspAccess": "Crypto Officer",
            "secFunImpl": "Random Number Generation KDA OneStep Key Derivation ECDSA Key Pair Generation Safe Primes Key Pair Generation RSA Key Pair Generation ECDSA Key Pair Verification Safe Primes Key Pair"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "",
            "secFunImpl": "Verification Signature Generation Signature Verification ECDH Shared Secret Computation HKDF Key Derivation TLS 1.3 KDF Key Derivation Symmetric Encryption Symmetric Decryption Authenticate d Symmetric Encryption Authenticate d Symmetric Decryption MAC Key Wrapping with AES- KW Key Wrapping with AES- KWP Key Unwrapping with AES- KW Key Unwrapping with AES- KWP SSH KDF Key"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "",
            "secFunImpl": "Derivation ANS 9.42 KDF Key Derivation Password- based Key Derivation Message Digest ANS 9.63 KDF Key Derivation TLS 1.2 KDF Key Derivation KBKDF Key Derivation DH Shared Secret Computation"
          },
          {
            "description": "Zeroize CPSs",
            "indicator": "N/A",
            "inputs": "Any SSP",
            "name": "Zeroization",
            "outputs": "N/A",
            "rolesSspAccess": "Crypto Officer - AES key: Z - HMAC key: Z - KMAC key: Z - Key- derivation key: Z - DH shared secret: Z - ECDH shared secret: Z - Password: Z - KBKDF derived key: Z - KDA OneStep derived key: Z",
            "secFunImpl": "None"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "- HKDF derived key: Z - ANS X9.42 derived key: Z - ANS X9.63 derived key: Z - SSH KDF derived key: Z - TLS 1.2 KDF derived key: Z - TLS 1.3 KDF derived key: Z - PBKDF2 derived key: Z - DH private key: Z - DH public key: Z - ECDH private key: Z - ECDH public key: Z - ECDSA private key: Z - ECDSA public key: Z - RSA private key: Z - RSA public key: Z - [EVM] DRBG entropy input string:",
            "secFunImpl": ""
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "Z - [EVM] HMAC_DRB G Seed: Z - [EVM] HMAC_DRB G internal state (V, Key): Z - AES-GCM IV: Z",
            "secFunImpl": ""
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 3
      },
      "authentication_methods": {
        "entries": [],
        "found": false,
        "section": 4,
        "subsection": 1
      },
      "cond_self_tests": {
        "entries": [
          {
            "algorithmOrTest": "SHA-1 (A7243)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA-1 (A7244)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA-1 (A7245)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA-1 (A7246)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA2-512 (A7243)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA2-512 (A7244)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA2-512 (A7245)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA2-512 (A7246)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA3-256 (A7233)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA3-512 (A7233)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHAKE-128 (A7233)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A7234) - Encrypt",
            "condition": "Test runs at power- on before the integrity test",
            "details": "Encrypt",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A7234) - Decrypt",
            "condition": "Test runs at power- on before the integrity test",
            "details": "Decrypt",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A7235) - Encrypt",
            "condition": "Test runs at power- on before the integrity test",
            "details": "Encrypt",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A7235) - Decrypt",
            "condition": "Test runs at power- on before the integrity test",
            "details": "Decrypt",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A7236) - Encrypt",
            "condition": "Test runs at power- on before the integrity test",
            "details": "Encrypt",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A7236) - Decrypt",
            "condition": "Test runs at power- on before the integrity test",
            "details": "Decrypt",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A7237) - Encrypt",
            "condition": "Test runs at power- on before the integrity test",
            "details": "Encrypt",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A7237) - Decrypt",
            "condition": "Test runs at power- on before the integrity test",
            "details": "Decrypt",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A7238) - Encrypt",
            "condition": "Test runs at power- on before the integrity test",
            "details": "Encrypt",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A7238) - Decrypt",
            "condition": "Test runs at power- on before the integrity test",
            "details": "Decrypt",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A7239) - Encrypt",
            "condition": "Test runs at power- on before the integrity test",
            "details": "Encrypt",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A7239) - Decrypt",
            "condition": "Test runs at power- on before the integrity test",
            "details": "Decrypt",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A7240) - Encrypt",
            "condition": "Test runs at power- on before the integrity test",
            "details": "Encrypt",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A7240) - Decrypt",
            "condition": "Test runs at power- on before the integrity test",
            "details": "Decrypt",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A7241) - Encrypt",
            "condition": "Test runs at power- on before the integrity test",
            "details": "Encrypt",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A7241) - Decrypt",
            "condition": "Test runs at power- on before the integrity test",
            "details": "Decrypt",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A7242) - Encrypt",
            "condition": "Test runs at power- on before the integrity test",
            "details": "Encrypt",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A7242) - Decrypt",
            "condition": "Test runs at power- on before the integrity test",
            "details": "Decrypt",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "256 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-ECB (A7226)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "Decrypt",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "128 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-ECB (A7227)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "Decrypt",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "128 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-ECB (A7228)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "Decrypt",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "128 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "TLS v1.3 KDF (A7225)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "TLS v1.2 KDF RFC7627 (A7243)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "TLS v1.2 KDF RFC7627 (A7244)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "TLS v1.2 KDF RFC7627 (A7245)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "TLS v1.2 KDF RFC7627 (A7246)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "PBKDF (A7233)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "PBKDF (A7243)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "PBKDF (A7244)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "PBKDF (A7245)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "PBKDF (A7246)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF SSH (A7229)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-1",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF SSH (A7230)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-1",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF SSH (A7231)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-1",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF SSH (A7232)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-1",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF SSH (A7243)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-1",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF SSH (A7244)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-1",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF SSH (A7245)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-1",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF SSH (A7246)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-1",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF SP800- 108 (A7247)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "HMAC- SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDA HKDF SP800-56Cr2 (A7225)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDA OneStep SP800-56Cr2 (A7224)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-224",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.63 (A7243)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.63 (A7244)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.63 (A7245)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.63 (A7246)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.42 (A7233)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-1",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.42 (A7243)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-1",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.42 (A7244)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-1",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.42 (A7245)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-1",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.42 (A7246)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-1",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS-FFC- SSC Sp800- 56Ar3 (A7248)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "ffdhe2048, MODP-2048",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS-ECC- SSC Sp800- 56Ar3 (A7243)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "P-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS-ECC- SSC Sp800- 56Ar3 (A7244)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "P-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS-ECC- SSC Sp800- 56Ar3 (A7245)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "P-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS-ECC- SSC Sp800- 56Ar3 (A7246)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "P-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigGen (FIPS186-5) (A7233)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256, 2048 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigGen (FIPS186-5) (A7243)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256, 2048 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigGen (FIPS186-5) (A7244)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256, 2048 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigGen (FIPS186-5) (A7245)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256, 2048 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigGen (FIPS186-5) (A7246)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256, 2048 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigGen (FIPS186-5) (A7233)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "P-224, SHA2- 256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigGen (FIPS186-5) (A7243)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "P-224, SHA2- 256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigGen (FIPS186-5) (A7244)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "P-224, SHA2- 256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigGen (FIPS186-5) (A7245)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "P-224, SHA2- 256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigGen (FIPS186-5) (A7246)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "P-224, SHA2- 256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186-5) (A7233)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256, 2048 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186-5) (A7243)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256, 2048 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186-5) (A7244)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256, 2048 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186-5) (A7245)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256, 2048 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186-5) (A7246)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256, 2048 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigVer (FIPS186-5) (A7233)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "P-224, SHA2- 256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigVer (FIPS186-5) (A7243)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "P-224, SHA2- 256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigVer (FIPS186-5) (A7244)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "P-224, SHA2- 256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigVer (FIPS186-5) (A7245)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "P-224, SHA2- 256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigVer (FIPS186-5) (A7246)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "P-224, SHA2- 256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA- 1 (A7243)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-1",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA- 1 (A7244)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-1",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA- 1 (A7245)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-1",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA- 1 (A7246)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-1",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC- SHA2-224 (A7243)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-224",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC- SHA2-224 (A7244)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-224",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC- SHA2-224 (A7245)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-224",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC- SHA2-224 (A7246)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-224",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC- SHA2-256 (A7243)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC- SHA2-256 (A7244)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC- SHA2-256 (A7245)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC- SHA2-256 (A7246)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC- SHA2-384 (A7243)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-384",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC- SHA2-384 (A7244)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-384",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC- SHA2-384 (A7245)",
            "condition": "Test runs at power- on before the integrity test power-",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-384",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC- SHA2-384 (A7246)",
            "condition": "Test runs at on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-384",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC- SHA2-512 (A7243)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-512",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC- SHA2-512 (A7244)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-512",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC- SHA2-512 (A7245)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-512",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC- SHA2-512 (A7246)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA2-512",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA KeyGen (FIPS186-5) (A7243)",
            "condition": "Test runs when a corresponding key pair generation service is requested",
            "details": "N/A",
            "indicator": "Successful completion of service",
            "testMethod": "PCT",
            "testProps": "PKCS#1 v1.5 with SHA2- 256",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "RSA KeyGen (FIPS186-5) (A7244)",
            "condition": "Test runs when a corresponding key pair generation service is requested",
            "details": "N/A",
            "indicator": "Successful completion of service",
            "testMethod": "PCT",
            "testProps": "PKCS#1 v1.5 with SHA2- 256",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "RSA KeyGen (FIPS186-5) (A7245)",
            "condition": "Test runs when a corresponding key pair generation service is requested",
            "details": "N/A",
            "indicator": "Successful completion of service",
            "testMethod": "PCT",
            "testProps": "PKCS#1 v1.5 with SHA2- 256",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "RSA KeyGen (FIPS186-5) (A7246)",
            "condition": "Test runs when a corresponding key pair generation service is requested",
            "details": "N/A",
            "indicator": "Successful completion of service",
            "testMethod": "PCT",
            "testProps": "PKCS#1 v1.5 with SHA2- 256",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "ECDSA KeyGen (FIPS186-5) (A7243)",
            "condition": "Test runs when a corresponding key pair generation service is requested",
            "details": "N/A",
            "indicator": "Successful completion of service",
            "testMethod": "PCT",
            "testProps": "SHA2-256",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "ECDSA KeyGen (FIPS186-5) (A7244)",
            "condition": "Test runs when a corresponding key pair generation service is requested",
            "details": "N/A",
            "indicator": "Successful completion of service",
            "testMethod": "PCT",
            "testProps": "SHA2-256",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "ECDSA KeyGen (FIPS186-5) (A7245)",
            "condition": "Test runs when a corresponding key pair generation service is requested",
            "details": "N/A",
            "indicator": "Successful completion of service",
            "testMethod": "PCT",
            "testProps": "SHA2-256",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "ECDSA KeyGen (FIPS186-5) (A7246)",
            "condition": "Test runs when a corresponding key pair generation service is requested",
            "details": "N/A",
            "indicator": "Successful completion of service",
            "testMethod": "PCT",
            "testProps": "SHA2-256",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "Safe Primes Key Generation (A7248)",
            "condition": "Test runs when a corresponding key pair generation service is requested",
            "details": "N/A",
            "indicator": "Successful completion of service",
            "testMethod": "PCT",
            "testProps": "N/A",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "HMAC DRBG (A7308)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "[EVM] SP 800- 90A Rev. 1 (instantiate, reseed, generate) health test",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "HMAC- SHA2-512 without prediction resistance",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC DRBG (A7310)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "[EVM] SP 800- 90A Rev. 1 (instantiate, reseed, generate) health test",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "HMAC- SHA2-512 without prediction resistance",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC DRBG (A7311)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "[EVM] SP 800- 90A Rev. 1 (instantiate, reseed, generate) health test",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "HMAC- SHA2-512 without prediction resistance",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC DRBG (A7313)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "[EVM] SP 800- 90A Rev. 1 (instantiate, reseed, generate) health test",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "HMAC- SHA2-512 without prediction resistance",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC DRBG (A7314)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "[EVM] SP 800- 90A Rev. 1 (instantiate, reseed, generate) health test",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "HMAC- SHA2-512 without prediction resistance",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC DRBG (A7315)",
            "condition": "Test runs at power- on before the integrity test",
            "details": "[EVM] SP 800- 90A Rev. 1 (instantiate, reseed, generate) health test",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "HMAC- SHA2-512 without prediction resistance",
            "type": "CAST"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 2
      },
      "error_states": {
        "entries": [],
        "found": false,
        "section": 10,
        "subsection": 4
      },
      "mechanisms_actions": {
        "entries": [],
        "found": false,
        "section": 7,
        "subsection": 1
      },
      "modes_of_operation": {
        "entries": [
          {
            "description": "Automatically entered whenever an approved service is requested",
            "name": "Approved mode",
            "statusIndicator": "Equivalent to the indicator of the requested service",
            "type": "Approved"
          },
          {
            "description": "Automatically entered whenever a non- approved service is requested",
            "name": "Non-approved mode",
            "statusIndicator": "Equivalent to the indicator of the requested service",
            "type": "Non- Approved"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 4
      },
      "non_approved_allowed_NSC": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_allowed_algos": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_not_allowed": {
        "entries": [
          {
            "name": "AES GCM (external IV)",
            "use": "Symmetric Encryption"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "non_approved_services": {
        "entries": [
          {
            "alg_accessed": "AES GCM (external IV)",
            "description": "Symmetric Encryption",
            "name": "AES GCM (external IV)",
            "role": "CO"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 4
      },
      "ports_interfaces": {
        "entries": [
          {
            "data": "API input parameters",
            "logicalInterface": "Data Input",
            "physicalPort": "N/A"
          },
          {
            "data": "API output parameters",
            "logicalInterface": "Data Output",
            "physicalPort": "N/A"
          },
          {
            "data": "API function calls",
            "logicalInterface": "Control Input",
            "physicalPort": "N/A"
          },
          {
            "data": "API return codes, error messages",
            "logicalInterface": "Status Output",
            "physicalPort": "N/A"
          }
        ],
        "found": true,
        "section": 3,
        "subsection": 1
      },
      "roles": {
        "entries": [
          {
            "authMethodList": "None",
            "name": "Crypto Officer",
            "operatorType": "Crypto Officer",
            "type": "Role"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 2
      },
      "security_levels": {
        "entries": [
          {
            "level": "1",
            "section": "1",
            "title": "General"
          },
          {
            "level": "1",
            "section": "2",
            "title": "Cryptographic module specification"
          },
          {
            "level": "1",
            "section": "3",
            "title": "Cryptographic module interfaces"
          },
          {
            "level": "1",
            "section": "4",
            "title": "Roles, services, and authentication"
          },
          {
            "level": "1",
            "section": "5",
            "title": "Software/Firmware security"
          },
          {
            "level": "1",
            "section": "6",
            "title": "Operational environment"
          },
          {
            "level": "N/A",
            "section": "7",
            "title": "Physical security"
          },
          {
            "level": "N/A",
            "section": "8",
            "title": "Non-invasive security"
          },
          {
            "level": "1",
            "section": "9",
            "title": "Sensitive security parameter management"
          },
          {
            "level": "1",
            "section": "10",
            "title": "Self-tests"
          },
          {
            "level": "1",
            "section": "11",
            "title": "Life-cycle assurance"
          },
          {
            "level": "1",
            "section": "12",
            "title": "Mitigation of other attacks"
          },
          {
            "level": "1",
            "section": "",
            "title": "Overall Level"
          }
        ],
        "found": true,
        "section": 1,
        "subsection": 2
      },
      "self_tests": {
        "entries": [
          {
            "algorithmOrTest": "HMAC-SHA2-256 (A7243)",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "MAC tag verification",
            "testProps": "SHA2- 256",
            "type": "SW/FW Integrity"
          },
          {
            "algorithmOrTest": "HMAC-SHA2-256 (A7244)",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "MAC tag verification",
            "testProps": "SHA2- 256",
            "type": "SW/FW Integrity"
          },
          {
            "algorithmOrTest": "HMAC-SHA2-256 (A7245)",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "MAC tag verification",
            "testProps": "SHA2- 256",
            "type": "SW/FW Integrity"
          },
          {
            "algorithmOrTest": "HMAC-SHA2-256 (A7246)",
            "details": "N/A",
            "indicator": "Module becomes operational",
            "testMethod": "MAC tag verification",
            "testProps": "SHA2- 256",
            "type": "SW/FW Integrity"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 1
      },
      "ssp_io_methods": {
        "entries": [
          {
            "dest": "Cryptographic module",
            "distribution": "Manual",
            "entry": "Electronic",
            "format": "Plaintext",
            "name": "API input parameters",
            "sfiAlgo": "",
            "source": "Operator calling application (TOEPP)"
          },
          {
            "dest": "Operator calling application (TOEPP)",
            "distribution": "Manual",
            "entry": "Electronic",
            "format": "Plaintext",
            "name": "API output parameters",
            "sfiAlgo": "",
            "source": "Cryptographic module"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 2
      },
      "ssp_zeroization_methods": {
        "entries": [
          {
            "description": "Zeroizes the SSPs contained within the cipher handle.",
            "method": "Wipe and Free memory block allocated",
            "operatorId": "By calling the cipher related zeroization API functions: EVP_CIPHER_CTX_free/ EVP_CIPHER_reset for AES keys, HMAC_CTX_free for HMAC keys, RSA_free for RSA keys, EC_KEY_free for ECDSA and ECDH keys/shared secrets, DH_free for DH keys/shared secrets, EVP_PKEY_free for",
            "rationale": "Memory occupied by SSPs is overwritten with zeroes and then it is released, which renders the SSP values irretrievable. The completion of the"
          },
          {
            "description": "",
            "method": "",
            "operatorId": "passwords and derived keys, FIPS_drbg_free for DRBG SSPs, SSL_free/SSL_clear for TLS secrets",
            "rationale": "zeroization routine indicates that the zeroization procedure succeeded."
          },
          {
            "description": "Automatically zeroized by the module when no longer needed",
            "method": "Automatic",
            "operatorId": "N/A",
            "rationale": "Memory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable."
          },
          {
            "description": "De-allocates the volatile memory used to store SSPs",
            "method": "Module Reset",
            "operatorId": "By unloading and reloading the module",
            "rationale": "Volatile memory used by the module is overwritten within nanoseconds when power is removed."
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 3
      },
      "storage_areas": {
        "entries": [
          {
            "description": "Temporary storage for SSPs used by the module as part of service execution.",
            "name": "RAM",
            "persistance": "Dynamic"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 1
      },
      "tested_module_id_hw": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "tested_module_id_hw_hy": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "tested_module_id_sw_fw_hy": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "tested_op_env_sw_fw_hy": {
        "entries": [
          {
            "hardwarePlatform": "Juniper Networks\u00ae Packet Transport Router Model PTX10001-36MR with Intel\u00ae Xeon\u00ae D-2163IT",
            "hypervisorHostOs": "N/A",
            "operatingSystem": "Junos OS Evolved version 24.4R2",
            "paa_pai": "Yes",
            "processors": "Intel\u00ae Xeon\u00ae D-2163IT",
            "version": "3.0"
          },
          {
            "hardwarePlatform": "Juniper Networks\u00ae Packet Transport Router Model PTX10001-36MR with Intel\u00ae Xeon\u00ae D-2163IT",
            "hypervisorHostOs": "N/A",
            "operatingSystem": "Junos OS Evolved version 24.4R2",
            "paa_pai": "No",
            "processors": "Intel\u00ae Xeon\u00ae D-2163IT",
            "version": "3.0"
          },
          {
            "hardwarePlatform": "Juniper Networks\u00ae Packet Transport Router Model PTX10002-36QDD with Intel\u00ae Xeon\u00ae D-1749NT",
            "hypervisorHostOs": "N/A",
            "operatingSystem": "Junos OS Evolved version 24.4R2",
            "paa_pai": "Yes",
            "processors": "Intel\u00ae Xeon\u00ae D-1749NT",
            "version": "3.0"
          },
          {
            "hardwarePlatform": "Juniper Networks\u00ae Packet Transport Router Model PTX10002-36QDD with Intel\u00ae Xeon\u00ae D-1749NT",
            "hypervisorHostOs": "N/A",
            "operatingSystem": "Junos OS Evolved version 24.4R2",
            "paa_pai": "No",
            "processors": "Intel\u00ae Xeon\u00ae D-1749NT",
            "version": "3.0"
          },
          {
            "hardwarePlatform": "Juniper Networks\u00ae Switch Model QFX5700 with Intel\u00ae Xeon\u00ae D- 1637",
            "hypervisorHostOs": "N/A",
            "operatingSystem": "Junos OS Evolved version 24.4R2",
            "paa_pai": "Yes",
            "processors": "Intel\u00ae Xeon\u00ae D-1637",
            "version": "3.0"
          },
          {
            "hardwarePlatform": "Juniper Networks\u00ae Switch Model QFX5700 with Intel\u00ae Xeon\u00ae D- 1637",
            "hypervisorHostOs": "N/A",
            "operatingSystem": "Junos OS Evolved version 24.4R2",
            "paa_pai": "No",
            "processors": "Intel\u00ae Xeon\u00ae D-1637",
            "version": "3.0"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 2
      },
      "vendor_affirmed_algos": {
        "entries": [
          {
            "algoPropList": "",
            "implName": "N/A",
            "name": "CKG",
            "reference": "SP 800-133 Rev. 2 Section 4 Example 1"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "vendor_affirmed_op_env_sw_fw_hy": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      }
    },
    "is_br1_format": true,
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 1
          },
          "ECDH": {
            "ECDH": 66
          },
          "ECDSA": {
            "ECDSA": 87
          }
        },
        "FF": {
          "DH": {
            "DH": 67,
            "DHE": 1,
            "Diffie-Hellman": 10
          }
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 1
        },
        "CCM": {
          "CCM": 1
        },
        "CTR": {
          "CTR": 1
        },
        "ECB": {
          "ECB": 1
        },
        "GCM": {
          "GCM": 8
        },
        "XTS": {
          "XTS": 2
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {
        "OpenSSL": {
          "OpenSSL": 84
        }
      },
      "crypto_protocol": {
        "IKE": {
          "IKE": 3
        },
        "SSH": {
          "SSH": 39
        },
        "TLS": {
          "TLS": {
            "TLS": 6,
            "TLS 1.2": 19,
            "TLS 1.3": 19,
            "TLS v1.2": 10,
            "TLS v1.3": 4
          }
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 2
        },
        "KEX": {
          "Key Exchange": 1
        },
        "MAC": {
          "MAC": 20
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-224": 54,
          "P-256": 22,
          "P-384": 34,
          "P-521": 34
        }
      },
      "eval_facility": {
        "atsec": {
          "atsec": 2
        }
      },
      "fips_cert_id": {},
      "fips_certlike": {
        "Certlike": {
          "AES key 128, 192": 1,
          "AES-128": 1,
          "AES-192": 1,
          "AES-256": 1,
          "HMAC-SHA- 1": 8,
          "HMAC-SHA-1": 10,
          "PKCS#1": 8,
          "SHA-1": 29,
          "SHA-2": 1,
          "SHA-3": 2,
          "SHA2- 256": 18,
          "SHA2-224": 16,
          "SHA2-256": 45,
          "SHA2-384": 17,
          "SHA2-512": 32,
          "SHA3-224": 5,
          "SHA3-256": 7,
          "SHA3-384": 5,
          "SHA3-512": 7
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 2
        }
      },
      "hash_function": {
        "PBKDF": {
          "PBKDF": 13,
          "PBKDF2": 10
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 29
          },
          "SHA2": {
            "SHA-2": 1
          },
          "SHA3": {
            "SHA-3": 2,
            "SHA3-224": 5,
            "SHA3-256": 7,
            "SHA3-384": 5,
            "SHA3-512": 7
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 35
        },
        "RNG": {
          "RBG": 2,
          "RNG": 1
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140": 1,
          "FIPS 140-3": 87,
          "FIPS 180-4": 8,
          "FIPS 186-5": 13,
          "FIPS 198-1": 12,
          "FIPS 202": 7,
          "FIPS PUB 140-3": 2,
          "FIPS186-5": 71
        },
        "NIST": {
          "SP 800-108": 3,
          "SP 800-132": 6,
          "SP 800-133": 5,
          "SP 800-135": 9,
          "SP 800-140B": 1,
          "SP 800-185": 3,
          "SP 800-38A": 11,
          "SP 800-38B": 2,
          "SP 800-38C": 2,
          "SP 800-38D": 1,
          "SP 800-38E": 3,
          "SP 800-38F": 3,
          "SP 800-56A": 14,
          "SP 800-56C": 4,
          "SP 800-90A": 5,
          "SP 800-90B": 1
        },
        "PKCS": {
          "PKCS#1": 4
        },
        "RFC": {
          "RFC 3526": 2,
          "RFC 4253": 2,
          "RFC 6668": 2,
          "RFC 7919": 2,
          "RFC7627": 9
        },
        "X509": {
          "X.509": 1
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 33,
            "AES-": 12,
            "AES-128": 1,
            "AES-192": 1,
            "AES-256": 1
          },
          "CAST": {
            "CAST": 228
          }
        },
        "constructions": {
          "MAC": {
            "CMAC": 2,
            "HMAC": 31,
            "KMAC": 7
          }
        }
      },
      "tee_name": {
        "AMD": {
          "PSP": 9
        },
        "IBM": {
          "SSC": 7
        }
      },
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "module_algorithms": {
      "_type": "Set",
      "elements": [
        "AES-CTRA7228",
        "SHA2-256A7246",
        "HMAC DRBGA7315",
        "KAS-ECC-SSC Sp800-56Ar3A7246",
        "SHA-1A7246",
        "KDF SP800-108A7247",
        "SHA3-256A7233",
        "KMAC-128A7233",
        "KDA OneStep SP800-56Cr2A7224",
        "SHAKE-128A7233",
        "AES-GCMA7242",
        "AES-CBC-CS2A7228",
        "HMAC-SHA2-512A7246",
        "KMAC-256A7233",
        "HMAC-SHA3-256A7233",
        "AES-OFBA7228",
        "KAS-FFC-SSC Sp800-56Ar3A7248",
        "Safe Primes Key VerificationA7248",
        "KDF ANS 9.63A7246",
        "SHA3-384A7233",
        "AES-ECBA7228",
        "ECDSA SigVer (FIPS186-5)A7246",
        "HMAC-SHA3-512A7233",
        "HMAC-SHA2-512/256A7246",
        "KDA HKDF SP800-56Cr2A7225",
        "SHA3-224A7233",
        "SHA2-512A7246",
        "AES-CBCA7228",
        "HMAC-SHA-1A7246",
        "AES-CFB1A7228",
        "HMAC-SHA2-224A7246",
        "RSA SigGen (FIPS186-5)A7246",
        "HMAC-SHA2-256A7246",
        "HMAC-SHA3-384A7233",
        "AES-KWPA7228",
        "AES-GMACA7242",
        "HMAC-SHA2-384A7246",
        "SHA2-512/256A7246",
        "HMAC-SHA2-512/224A7246",
        "AES-XTS Testing Revision 2.0A7228",
        "RSA KeyGen (FIPS186-5)A7246",
        "PBKDFA7246",
        "AES-CMACA7228",
        "ECDSA KeyVer (FIPS186-5)A7246",
        "AES-KWA7228",
        "ECDSA KeyGen (FIPS186-5)A7246",
        "HMAC-SHA3-224A7233",
        "KDF SSHA7246",
        "ECDSA SigGen (FIPS186-5)A7246",
        "TLS v1.2 KDF RFC7627A7246",
        "Safe Primes Key GenerationA7248",
        "SHA2-224A7246",
        "AES-CBC-CS1A7228",
        "AES-CFB8A7228",
        "AES-CBC-CS3A7228",
        "AES-CFB128A7228",
        "SHA2-384A7246",
        "AES-CCMA7228",
        "SHA3-512A7233",
        "SHA2-512/224A7246",
        "SHAKE-256A7233",
        "TLS v1.3 KDFA7225",
        "KDF ANS 9.42A7246",
        "RSA SigVer (FIPS186-5)A7246"
      ]
    },
    "policy_algorithms": {
      "_type": "Set",
      "elements": [
        "#A7244",
        "#A7225",
        "#A7240",
        "#A7314",
        "#A7231",
        "#A7228",
        "#A7236",
        "#A7233",
        "#A7224",
        "#A7246",
        "#A7232",
        "#A7237",
        "#A7227",
        "#A7243",
        "#A7308",
        "#A7230",
        "#A7241",
        "#A7234",
        "#A7247",
        "#A7226",
        "#A7245",
        "#A7238",
        "#A7315",
        "#A7311",
        "#A7248",
        "#A7242",
        "#A7313",
        "#A7310",
        "#A7229",
        "#A7235",
        "#A7239"
      ]
    },
    "policy_metadata": {
      "/Author": "Hawes, David J. (Fed)",
      "/CreationDate": "D:20260713083521-04\u002700\u0027",
      "/Creator": "Microsoft\u00ae Word for Microsoft 365",
      "/ModDate": "D:20260713083521-04\u002700\u0027",
      "/Producer": "Microsoft\u00ae Word for Microsoft 365",
      "pdf_file_size_bytes": 1205692,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "https://doi.org/10.6028/NIST.SP.800-38B",
          "https://doi.org/10.6028/NIST.SP.800-135r1",
          "https://doi.org/10.6028/NIST.SP.800-90B",
          "https://www.ietf.org/rfc/rfc6668.txt",
          "https://doi.org/10.6028/NIST.SP.800-38D",
          "https://doi.org/10.6028/NIST.SP.800-38F",
          "http://www.hpe.com/",
          "https://doi.org/10.6028/NIST.SP.800-108r1-upd1",
          "https://doi.org/10.6028/NIST.SP.800-38A",
          "https://www.ietf.org/rfc/rfc4253.txt",
          "https://doi.org/10.6028/NIST.FIPS.198-1",
          "https://csrc.nist.gov/Projects/cryptographic-module-validation-program/fips-140-3-ig-announcements",
          "https://doi.org/10.6028/NIST.FIPS.140-3",
          "https://doi.org/10.6028/NIST.SP.800-133r2",
          "https://doi.org/10.6028/NIST.FIPS.180-4",
          "https://doi.org/10.6028/NIST.SP.800-38C",
          "https://doi.org/10.6028/NIST.SP.800-56Ar3",
          "https://www.ietf.org/rfc/rfc7919.txt",
          "https://doi.org/10.6028/NIST.FIPS.202",
          "https://doi.org/10.6028/NIST.SP.800-38E",
          "http://www.atsec.com/",
          "https://doi.org/10.6028/NIST.SP.800-132",
          "https://www.ietf.org/rfc/rfc3526.txt",
          "https://doi.org/10.6028/NIST.SP.800-185",
          "https://doi.org/10.6028/NIST.SP.800-56Cr2",
          "https://doi.org/10.6028/NIST.SP.800-90Ar1"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 79
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.InternalState",
    "module": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "policy": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": "0f12e5e855c5219c0b30e974e4f10405f047479278f7befca84e8ddee41dfc0f",
      "source_hash": "e3096401a5510c3a9ff6000564821beec04f6d2f0f63c9cd2f5cc5aff361861f",
      "txt_hash": "e4896ef518c92211a441f7084e597bc68d7e9416fb014c56066dddd4b33ad995"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in approved mode with module Junos\u00ae OS Evolved Kernel Cryptographic Module version 2.1 validated to FIPS 140-3 under Cert. #NNNN operating in the Approved mode. No assurance of minimum security of SSPs (e.g. keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/July 2026_040826_0807.pdf",
    "date_sunset": "2031-07-13",
    "description": "The Junos\u00ae OS Evolved OpenSSL Cryptographic Module provides a C language application program interface (API) for use by other applications that require cryptographic functionality.",
    "embodiment": "MultiChipStand",
    "exceptions": [
      "Physical security: N/A",
      "Non-invasive security: N/A"
    ],
    "fw_versions": null,
    "historical_reason": null,
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {},
    "module_name": "Junos\u00ae OS Evolved OpenSSL Cryptographic Module version 3.0",
    "module_type": "Software",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-3",
    "status": "active",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2026-07-14",
        "lab": "atsec information security corporation",
        "validation_type": "Initial"
      }
    ],
    "vendor": "HPE Juniper Networking",
    "vendor_url": "http://www.hpe.com"
  }
}