HPE Juniper Networking Junos® OS Evolved OpenSSL Cryptographic Module version 3.0 FIPS 140-3 Non-Proprietary Security Policy Document Version: 1.0 Last update: 2026-07-07 Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 2 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Prepared by: Prepared for: atsec information security corporation HPE Juniper Networking 4516 Seton Center Pkwy, Suite 250 1133 Innovation Way Austin, TX 78759 Sunnyvale, CA 94089 www.atsec.com www.hpe.com/ Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 3 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Table of Contents 1 General.......................................................................................................................................................................6 1.1 Overview ............................................................................................................................................................6 1.2 Security Levels....................................................................................................................................................6 1.3 Additional Information......................................................................................................................................6 2 Cryptographic Module Specification........................................................................................................................7 2.1 Description .........................................................................................................................................................7 2.2 Tested and Vendor Affirmed Module Version and Identification ..................................................................8 2.3 Excluded Components .......................................................................................................................................9 2.4 Modes of Operation............................................................................................................................................9 2.5 Algorithms........................................................................................................................................................10 2.6 Security Function Implementations................................................................................................................15 2.7 Algorithm Specific Information ......................................................................................................................21 2.7.1 AES-GCM..................................................................................................................................................21 2.7.2 AES-XTS....................................................................................................................................................21 2.7.3 PBKDF2.....................................................................................................................................................21 2.7.4 Diffie-Hellman and EC Diffie-Hellman...................................................................................................21 2.7.5 Key Wrapping...........................................................................................................................................22 2.7.6 Key Agreement .........................................................................................................................................22 2.7.7 RSA Key Length........................................................................................................................................22 2.8 RBG and Entropy .............................................................................................................................................22 2.9 Key Generation ................................................................................................................................................22 2.10 Key Establishment..........................................................................................................................................23 2.11 Industry Protocols..........................................................................................................................................24 3 Cryptographic Module Interfaces...........................................................................................................................25 3.1 Ports and Interfaces..........................................................................................................................................25 4 Roles, Services, and Authentication .......................................................................................................................26 4.1 Authentication Methods..................................................................................................................................26 4.2 Roles..................................................................................................................................................................26 4.3 Approved Services............................................................................................................................................26 4.4 Non-Approved Services ...................................................................................................................................36 4.5 External Software/Firmware Loaded...............................................................................................................36 Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 4 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com 5 Software/Firmware Security ...................................................................................................................................37 5.1 Integrity Techniques........................................................................................................................................37 5.2 Initiate on Demand ..........................................................................................................................................37 6 Operational Environment .......................................................................................................................................38 6.1 Operational Environment Type and Requirements .......................................................................................38 6.2 Configuration Settings and Restrictions..........................................................................................................38 7 Physical Security .....................................................................................................................................................39 8 Non-Invasive Security.............................................................................................................................................40 9 Sensitive Security Parameters Management ..........................................................................................................41 9.1 Storage Areas....................................................................................................................................................41 9.2 SSP Input-Output Methods .............................................................................................................................41 9.3 SSP Zeroization Methods.................................................................................................................................41 9.4 SSPs...................................................................................................................................................................42 10 Self-Tests................................................................................................................................................................55 10.1 Pre-Operational Self-Tests.............................................................................................................................55 10.2 Conditional Self-Tests....................................................................................................................................55 10.3 Periodic Self-Test Information ......................................................................................................................65 10.4 Error States .....................................................................................................................................................71 10.5 Operator Initiation of Self-Tests....................................................................................................................72 11 Life-Cycle Assurance.............................................................................................................................................73 11.1 Installation, Initialization, and Startup Procedures......................................................................................73 11.2 Administrator Guidance ................................................................................................................................73 11.3 End of Life ......................................................................................................................................................74 12 Mitigation of Other Attacks..................................................................................................................................75 12.1 Attack List.......................................................................................................................................................75 Appendix A. Glossary and Abbreviations .................................................................................................................76 Appendix B. References .............................................................................................................................................77 Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 5 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com List of Tables Table 1: Security Levels................................................................................................................................................6 Table 2: Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets) ...............................8 Table 3: Tested Operational Environments - Software, Firmware, Hybrid ..............................................................9 Table 4: Modes List and Description ...........................................................................................................................9 Table 5: Approved Algorithms - ................................................................................................................................14 Table 6: Approved Algorithms - [EVM]....................................................................................................................14 Table 7: Vendor-Affirmed Algorithms......................................................................................................................15 Table 8: Non-Approved, Not Allowed Algorithms...................................................................................................15 Table 9: Security Function Implementations............................................................................................................20 Table 10: Ports and Interfaces....................................................................................................................................25 Table 11: Roles............................................................................................................................................................26 Table 12: Approved Services......................................................................................................................................36 Table 13: Non-Approved Services .............................................................................................................................36 Table 14: Storage Areas ..............................................................................................................................................41 Table 15: SSP Input-Output Methods .......................................................................................................................41 Table 16: SSP Zeroization Methods...........................................................................................................................42 Table 17: SSP Table 1 .................................................................................................................................................49 Table 18: SSP Table 2 .................................................................................................................................................54 Table 19: Pre-Operational Self-Tests.........................................................................................................................55 Table 20: Conditional Self-Tests ................................................................................................................................65 Table 21: Pre-Operational Periodic Information......................................................................................................65 Table 22: Conditional Periodic Information .............................................................................................................71 Table 23: Error States .................................................................................................................................................72 List of Figures Figure 1: Block Diagram...............................................................................................................................................8 Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 6 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com 1 General 1.1 Overview This document is the non-proprietary FIPS 140-3 Security Policy for version 3.0 of the Junos® OS Evolved OpenSSL Cryptographic Module. It contains the security rules under which the module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for a Security Level 1 software module. It has a one-to-one mapping to SP 800-140B starting with Section B.2.1 named “General” that maps to Section 1 in this document and ending with Section B.2.12 named “Mitigation of other attacks” that maps to Section 12 in this document. This Non-Proprietary Security Policy may be reproduced and distributed, but only whole and intact and including this notice. Other documentation is proprietary to their authors. 1.2 Security Levels Section Title Security Level 1 General 1 2 Cryptographic module specification 1 3 Cryptographic module interfaces 1 4 Roles, services, and authentication 1 5 Software/Firmware security 1 6 Operational environment 1 7 Physical security N/A 8 Non-invasive security N/A 9 Sensitive security parameter management 1 10 Self-tests 1 11 Life-cycle assurance 1 12 Mitigation of other attacks 1 Overall Level 1 Table 1: Security Levels 1.3 Additional Information In preparing the Security Policy document, the laboratory formatted the vendor-supplied documentation for consolidation without altering the technical statements therein contained. The further refining of the Security Policy document was conducted iteratively throughout the conformance testing, wherein the Security Policy was submitted to the vendor, who would then edit, modify, and add technical contents. The vendor would also supply additional documentation, which the laboratory formatted into the existing Security Policy, and resubmitted to the vendor for their final editing. Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 7 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com 2 Cryptographic Module Specification 2.1 Description Purpose and Use: The Junos® OS Evolved OpenSSL Cryptographic Module (hereafter referred to as “the module”) is defined as a software module in a multi-chip standalone embodiment. The module is a software library which provides a C language application program interface (API) for use by other applications that require cryptographic functionality. The module consists of one software component, the “FIPS provider” (i.e. fips.so), which implements the FIPS requirements and the cryptographic functionality provided to the operator. The module also uses the Junos® OS Evolved Kernel Cryptographic Module Version 2.1 as a bound module (also referred to as “the bound Kernel Crypto API module”) for performing random number generation, relying on a DRBG implemented in that bound module. Sections of this Security Policy which refer to information from the bound module, also known as the Existing Validated Module (or EVM) are marked by [EVM] as per IG 1.A Resolution 5. Module Type: Software Module Embodiment: Multi-Chip Standalone Cryptographic Boundary: Figure 1 shows a block diagram that represents the design of the module when the module is operational and providing services to other user space applications. In this diagram, the physical perimeter of the operational environment (a general-purpose computer on which the module is installed) is indicated by a purple dashed line. The cryptographic boundary is represented by a shared library implementing the FIPS provider (fips.so) along with its HMAC value which resides within a configuration file called /etc/ssl/fipsmodule.cnf. Green lines indicate the flow of data between the cryptographic module and its operator application, through the logical interfaces defined in Section 3. Components in white are only included in the diagram for informational purposes. They are not included in the cryptographic boundary (and therefore not part of the module’s validation). For example, the kernel is responsible for managing system calls issued by the module itself, as well as other applications using the module for cryptographic services. Tested Operational Environment’s Physical Perimeter (TOEPP): The tested operating environment’s physical perimeter is the general-purpose computer on which the module is running. Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 8 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Figure 1: Block Diagram 2.2 Tested and Vendor Affirmed Module Version and Identification Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets): Package or File Name Software/ Firmware Version Features Integrity Test fips.so and /etc/ssl/fipsmodule.cnf on Juniper Networks® Packet Transport Router Model PTX10001-36MR with Intel® Xeon® D- 2163IT, Juniper Networks® Packet Transport Router Model PTX10002-36QDD with Intel® Xeon® D- 1749NT, or Juniper Networks® Switch Model QFX5700 with Intel® Xeon® D-1637 3.0 N/A HMAC-SHA2-256 Table 2: Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets) Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 9 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Tested Operational Environments - Software, Firmware, Hybrid: Operating System Hardware Platform Processors PAA/PAI Hypervisor or Host OS Version(s) Junos OS Evolved version 24.4R2 Juniper Networks® Packet Transport Router Model PTX10001-36MR with Intel® Xeon® D-2163IT Intel® Xeon® D-2163IT Yes N/A 3.0 Junos OS Evolved version 24.4R2 Juniper Networks® Packet Transport Router Model PTX10001-36MR with Intel® Xeon® D-2163IT Intel® Xeon® D-2163IT No N/A 3.0 Junos OS Evolved version 24.4R2 Juniper Networks® Packet Transport Router Model PTX10002-36QDD with Intel® Xeon® D-1749NT Intel® Xeon® D-1749NT Yes N/A 3.0 Junos OS Evolved version 24.4R2 Juniper Networks® Packet Transport Router Model PTX10002-36QDD with Intel® Xeon® D-1749NT Intel® Xeon® D-1749NT No N/A 3.0 Junos OS Evolved version 24.4R2 Juniper Networks® Switch Model QFX5700 with Intel® Xeon® D- 1637 Intel® Xeon® D-1637 Yes N/A 3.0 Junos OS Evolved version 24.4R2 Juniper Networks® Switch Model QFX5700 with Intel® Xeon® D- 1637 Intel® Xeon® D-1637 No N/A 3.0 Table 3: Tested Operational Environments - Software, Firmware, Hybrid 2.3 Excluded Components The module does not have any excluded components. 2.4 Modes of Operation Modes List and Description: Mode Name Description Type Status Indicator Approved mode Automatically entered whenever an approved service is requested Approved Equivalent to the indicator of the requested service Non-approved mode Automatically entered whenever a non- approved service is requested Non- Approved Equivalent to the indicator of the requested service Table 4: Modes List and Description Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 10 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Mode Change Instructions and Status: After the module passes the pre-operational self-test and cryptographic algorithm self-tests, the module will be in the operational state in the approved mode of operation. The module can be transitioned to the non- approved mode of operation by requesting one of the non-approved services listed in Section 4.4. 2.5 Algorithms Approved Algorithms: Algorithm CAVP Cert Properties Reference AES-CBC A7226, A7227, A7228 Direction - Decrypt, Encrypt Key Length - 128, 192, 256 SP 800-38A AES-CBC-CS1 A7226, A7227, A7228 Direction - decrypt, encrypt Key Length - 128, 192, 256 SP 800-38A AES-CBC-CS2 A7226, A7227, A7228 Direction - decrypt, encrypt Key Length - 128, 192, 256 SP 800-38A AES-CBC-CS3 A7226, A7227, A7228 Direction - decrypt, encrypt Key Length - 128, 192, 256 SP 800-38A AES-CCM A7226, A7227, A7228 Key Length - 128, 192, 256 SP 800-38C AES-CFB1 A7226, A7227, A7228 Direction - Decrypt, Encrypt Key Length - 128, 192, 256 SP 800-38A AES-CFB128 A7226, A7227, A7228 Direction - Decrypt, Encrypt Key Length - 128, 192, 256 SP 800-38A AES-CFB8 A7226, A7227, A7228 Direction - Decrypt, Encrypt Key Length - 128, 192, 256 SP 800-38A AES-CMAC A7226, A7227, A7228 Direction - Generation Key Length - 128, 192, 256 SP 800-38B AES-CTR A7226, A7227, A7228 Direction - Decrypt, Encrypt Key Length - 128, 192, 256 SP 800-38A AES-ECB A7226, A7227, A7228 Direction - Decrypt, Encrypt Key Length - 128, 192, 256 SP 800-38A AES-GCM A7234, A7235, A7236, A7237, A7238, A7239, A7240, A7241, A7242 Direction - Decrypt, Encrypt IV Generation - External, Internal Key Length - 128, 192, 256 IV Generation Mode - 8.2.2 SP 800- 38D AES-GMAC A7234, A7235, A7236, A7237, A7238, A7239, Direction - Decrypt, Encrypt IV Generation - External Key Length - 128, 192, 256 SP 800- 38D Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 11 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Algorithm CAVP Cert Properties Reference A7240, A7241, A7242 AES-KW A7226, A7227, A7228 Direction - Decrypt, Encrypt Key Length - 128, 192, 256 SP 800-38F AES-KWP A7226, A7227, A7228 Direction - Decrypt, Encrypt Key Length - 128, 192, 256 SP 800-38F AES-OFB A7226, A7227, A7228 Direction - Decrypt, Encrypt Key Length - 128, 192, 256 SP 800-38A AES-XTS Testing Revision 2.0 A7226, A7227, A7228 Direction - Decrypt, Encrypt Key Length - 128, 256 SP 800-38E ECDSA KeyGen (FIPS186-5) A7243, A7244, A7245, A7246 Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - testing candidates FIPS 186-5 ECDSA KeyVer (FIPS186-5) A7243, A7244, A7245, A7246 Curve - P-224, P-256, P-384, P-521 FIPS 186-5 ECDSA SigGen (FIPS186-5) A7233 Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA3-224, SHA3-256, SHA3-384, SHA3-512 Component - No, Yes FIPS 186-5 ECDSA SigGen (FIPS186-5) A7243, A7244, A7245, A7246 Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 Component - No, Yes FIPS 186-5 ECDSA SigVer (FIPS186-5) A7233 Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA3-224, SHA3-256, SHA3-384, SHA3-512 FIPS 186-5 ECDSA SigVer (FIPS186-5) A7243, A7244, A7245, A7246 Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 FIPS 186-5 HMAC-SHA-1 A7243, A7244, A7245, A7246 Key Length - Key Length: 112-524288 Increment 8 FIPS 198-1 HMAC-SHA2- 224 A7243, A7244, A7245, A7246 Key Length - Key Length: 112-524288 Increment 8 FIPS 198-1 HMAC-SHA2- 256 A7243, A7244, A7245, A7246 Key Length - Key Length: 112-524288 Increment 8 FIPS 198-1 HMAC-SHA2- 384 A7243, A7244, A7245, A7246 Key Length - Key Length: 112-524288 Increment 8 FIPS 198-1 HMAC-SHA2- 512 A7243, A7244, A7245, A7246 Key Length - Key Length: 112-524288 Increment 8 FIPS 198-1 HMAC-SHA2- 512/224 A7243, A7244, A7245, A7246 Key Length - Key Length: 112-524288 Increment 8 FIPS 198-1 Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 12 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Algorithm CAVP Cert Properties Reference HMAC-SHA2- 512/256 A7243, A7244, A7245, A7246 Key Length - Key Length: 112-524288 Increment 8 FIPS 198-1 HMAC-SHA3- 224 A7233 Key Length - Key Length: 112-524288 Increment 8 FIPS 198-1 HMAC-SHA3- 256 A7233 Key Length - Key Length: 112-524288 Increment 8 FIPS 198-1 HMAC-SHA3- 384 A7233 Key Length - Key Length: 112-524288 Increment 8 FIPS 198-1 HMAC-SHA3- 512 A7233 Key Length - Key Length: 112-524288 Increment 8 FIPS 198-1 KAS-ECC-SSC Sp800-56Ar3 A7243, A7244, A7245, A7246 Domain Parameter Generation Methods - P-224, P- 256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responder SP 800-56A Rev. 3 KAS-FFC-SSC Sp800-56Ar3 A7248 Domain Parameter Generation Methods - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP- 2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192 Scheme - dhEphem - KAS Role - initiator, responder SP 800-56A Rev. 3 KDA HKDF SP800-56Cr2 A7225 Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224- 8192 Increment 8 HMAC Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512 SP 800-56C Rev. 2 KDA OneStep SP800-56Cr2 A7224 Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224- 8192 Increment 8 SP 800-56C Rev. 2 KDF ANS 9.42 (CVL) A7233 KDF Type - DER Hash Algorithm - SHA3-224, SHA3-256, SHA3-384, SHA3-512 Key Data Length - Key Data Length: 112-4096 Increment 8 SP 800-135 Rev. 1 KDF ANS 9.42 (CVL) A7243, A7244, A7245, A7246 KDF Type - DER Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 Key Data Length - Key Data Length: 112-4096 Increment 8 SP 800-135 Rev. 1 KDF ANS 9.63 (CVL) A7243, A7244, A7245, A7246 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512 SP 800-135 Rev. 1 Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 13 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Algorithm CAVP Cert Properties Reference Key Data Length - Key Data Length: 128-4096 Increment 8 KDF SP800- 108 A7247 KDF Mode - Counter, Feedback Supported Lengths - Supported Lengths: 112-4096 Increment 8 SP 800-108 Rev. 1 KDF SSH (CVL) A7229, A7230, A7231, A7232, A7243, A7244, A7245, A7246 Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512 SP 800-135 Rev. 1 KMAC-128 A7233 Message Length - Message Length: 0-65536 Increment 8 Key Data Length - Key Data Length: 128-1024 Increment 8 SP 800-185 KMAC-256 A7233 Message Length - Message Length: 0-65536 Increment 8 Key Data Length - Key Data Length: 256-1024 Increment 8 SP 800-185 PBKDF A7233, A7243, A7244, A7245, A7246 Iteration Count - Iteration Count: 1000-10000 Increment 1 Password Length - Password Length: 8-128 Increment 1 SP 800-132 RSA KeyGen (FIPS186-5) A7243, A7244, A7245, A7246 Key Generation Mode - probableWithProbableAux Modulo - 2048, 3072, 4096, 6144, 8192 Primality Tests - 2powSecStr Private Key Format - standard FIPS 186-5 RSA SigGen (FIPS186-5) A7233, A7243, A7244, A7245, A7246 Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pss FIPS 186-5 RSA SigVer (FIPS186-5) A7233, A7243, A7244, A7245, A7246 Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pss FIPS 186-5 Safe Primes Key Generation A7248 Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192 SP 800-56A Rev. 3 Safe Primes Key Verification A7248 Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192 SP 800-56A Rev. 3 SHA-1 A7243, A7244, A7245, A7246 Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 FIPS 180-4 SHA2-224 A7243, A7244, A7245, A7246 Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 FIPS 180-4 Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 14 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Algorithm CAVP Cert Properties Reference SHA2-256 A7243, A7244, A7245, A7246 Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 FIPS 180-4 SHA2-384 A7243, A7244, A7245, A7246 Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 FIPS 180-4 SHA2-512 A7243, A7244, A7245, A7246 Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 FIPS 180-4 SHA2-512/224 A7243, A7244, A7245, A7246 Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 FIPS 180-4 SHA2-512/256 A7243, A7244, A7245, A7246 Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 FIPS 180-4 SHA3-224 A7233 Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 FIPS 202 SHA3-256 A7233 Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 FIPS 202 SHA3-384 A7233 Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 FIPS 202 SHA3-512 A7233 Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 FIPS 202 SHAKE-128 A7233 Output Length - Output Length: 16-65536 Increment 8 FIPS 202 SHAKE-256 A7233 Output Length - Output Length: 16-65536 Increment 8 FIPS 202 TLS v1.2 KDF RFC7627 (CVL) A7243, A7244, A7245, A7246 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512 SP 800-135 Rev. 1 TLS v1.3 KDF (CVL) A7225 HMAC Algorithm - SHA2-256, SHA2-384 KDF Running Modes - DHE, PSK, PSK-DHE SP 800-135 Rev. 1 Table 5: Approved Algorithms - [EVM] Algorithm CAVP Cert Properties Reference HMAC DRBG A7308, A7310, A7311, A7313 Mode - SHA2-512 SP 800-90A Rev. 1 HMAC DRBG A7314, A7315 Mode - SHA2-256, SHA2-512 SP 800-90A Rev. 1 Table 6: Approved Algorithms - [EVM] Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 15 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Vendor-Affirmed Algorithms: Name Properties Implementation Reference CKG N/A SP 800-133 Rev. 2 Section 4 Example 1 Table 7: Vendor-Affirmed Algorithms Non-Approved, Not Allowed Algorithms: Name Use and Function AES GCM (external IV) Symmetric Encryption Table 8: Non-Approved, Not Allowed Algorithms 2.6 Security Function Implementations Name Type Description Properties Algorithms Symmetric Encryption BC-UnAuth Symmetric Encryption with AES AES-CBC: (A7226, A7227, A7228) AES-CBC-CS1: (A7226, A7227, A7228) AES-CBC-CS2: (A7226, A7227, A7228) AES-CBC-CS3: (A7226, A7227, A7228) AES-CCM: (A7226, A7227, A7228) AES-CFB1: (A7226, A7227, A7228) AES-CFB128: (A7226, A7227, A7228) AES-CFB8: (A7226, A7227, A7228) AES-CTR: (A7226, A7227, A7228) AES-ECB: (A7226, A7227, A7228) AES-OFB: (A7226, A7227, A7228) AES-XTS Testing Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 16 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Name Type Description Properties Algorithms Revision 2.0: (A7226, A7227, A7228) Symmetric Decryption BC-UnAuth Symmetric Decryption with AES AES-CBC: (A7226, A7227, A7228) AES-CBC-CS1: (A7226, A7227, A7228) AES-CBC-CS2: (A7226, A7227, A7228) AES-CBC-CS3: (A7226, A7227, A7228) AES-CCM: (A7226, A7227, A7228) AES-CFB1: (A7226, A7227, A7228) AES-CFB128: (A7226, A7227, A7228) AES-CFB8: (A7226, A7227, A7228) AES-CTR: (A7226, A7227, A7228) AES-ECB: (A7226, A7227, A7228) AES-OFB: (A7226, A7227, A7228) AES-XTS Testing Revision 2.0: (A7226, A7227, A7228) Authenticated Symmetric Encryption BC-Auth Authenticated Symmetric Encryption with AES AES-CCM: (A7226, A7227, A7228) AES-GCM: (A7234, A7235, A7236, A7237, A7238, A7239, A7240, A7241, A7242) Authenticated Symmetric Decryption BC-Auth Authenticated Symmetric Decryption with AES AES-CCM: (A7226, A7227, A7228) AES-GCM: (A7234, A7235, A7236, Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 17 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Name Type Description Properties Algorithms A7237, A7238, A7239, A7240, A7241, A7242) Key Wrapping with AES-KW BC-Auth Key Wrapping with AES-KW Compliance:IG D.G AES-KW: (A7226, A7227, A7228) Key Unwrapping with AES-KW BC-Auth Key Unwrapping with AES-KW Compliance:IG D.G AES-KW: (A7226, A7227, A7228) Key Wrapping with AES-KWP BC-Auth Key Wrapping with AES-KWP Compliance:IG D.G AES-KWP: (A7226, A7227, A7228) Key Unwrapping with AES-KWP BC-Auth Key Unwrapping with AES-KWP Compliance:IG D.G AES-KWP: (A7226, A7227, A7228) Message Digest SHA XOF Message Digest SHA-1: (A7243, A7244, A7245, A7246) SHA2-224: (A7243, A7244, A7245, A7246) SHA2-256: (A7243, A7244, A7245, A7246) SHA2-384: (A7243, A7244, A7245, A7246) SHA2-512: (A7243, A7244, A7245, A7246) SHA2-512/224: (A7243, A7244, A7245, A7246) SHA2-512/256: (A7243, A7244, A7245, A7246) SHA3-224: (A7233) SHA3-256: (A7233) SHA3-384: (A7233) SHA3-512: (A7233) SHAKE-128: (A7233) SHAKE-256: (A7233) MAC MAC Message Authentication Code AES-CMAC: (A7226, A7227, A7228) AES-GMAC: Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 18 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Name Type Description Properties Algorithms (A7234, A7235, A7236, A7237, A7238, A7239, A7240, A7241, A7242) HMAC-SHA-1: (A7243, A7244, A7245, A7246) HMAC-SHA2-224: (A7243, A7244, A7245, A7246) HMAC-SHA2-256: (A7243, A7244, A7245, A7246) HMAC-SHA2-384: (A7243, A7244, A7245, A7246) HMAC-SHA2-512: (A7243, A7244, A7245, A7246) HMAC-SHA2- 512/224: (A7243, A7244, A7245, A7246) HMAC-SHA2- 512/256: (A7243, A7244, A7245, A7246) HMAC-SHA3-224: (A7233) HMAC-SHA3-256: (A7233) HMAC-SHA3-384: (A7233) HMAC-SHA3-512: (A7233) KMAC-128: (A7233) KMAC-256: (A7233) Random Number Generation DRBG [EVM] Random Number Generation Hash:SHA2-512 Prediction resistance:No HMAC DRBG: (A7308, A7310, A7311, A7313, A7314, A7315) Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 19 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Name Type Description Properties Algorithms ECDSA Key Pair Generation AsymKeyPair- KeyGen CKG ECDSA Key Pair Generation ECDSA KeyGen (FIPS186-5): (A7243, A7244, A7245, A7246) CKG: () Safe Primes Key Pair Generation AsymKeyPair- KeyGen CKG Safe Primes Key Pair Generation Safe Primes Key Generation: (A7248) CKG: () RSA Key Pair Generation AsymKeyPair- KeyGen CKG RSA Key Pair Generation Compliance:RSA with modulus sizes other than 2048, 3072, and 4096 is not tested by CAVP but is approved as per IG C.F. Modulus sizes:2048-16384 bits RSA KeyGen (FIPS186-5): (A7243, A7244, A7245, A7246) CKG: () ECDSA Key Pair Verification AsymKeyPair- KeyVer ECDSA Key Pair Verification ECDSA KeyVer (FIPS186-5): (A7243, A7244, A7245, A7246) Safe Primes Key Pair Verification AsymKeyPair- KeyVer Safe Primes Key Pair Verification Safe Primes Key Verification: (A7248) Signature Generation DigSig-SigGen Signature Generation Compliance:RSA with modulus sizes other than 2048, 3072, and 4096 is not tested by CAVP but is approved as per IG C.F. RSA modulus sizes:2048-16384 bits ECDSA SigGen (FIPS186-5): (A7233, A7243, A7244, A7245, A7246) RSA SigGen (FIPS186-5): (A7233, A7243, A7244, A7245, A7246) Signature Verification DigSig-SigVer Signature Verification Compliance:RSA with modulus sizes other than 2048, 3072, and 4096 bits is not tested by CAVP but is ECDSA SigVer (FIPS186-5): (A7233, A7243, A7244, A7245, A7246) RSA SigVer Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 20 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Name Type Description Properties Algorithms approved as per IG C.F. RSA modulus sizes:2048-16384 bits (FIPS186-5): (A7233, A7243, A7244, A7245, A7246) DH Shared Secret Computation KAS-SSC DH Shared Secret Computation Compliance:IG D.F Scenario 2 (1) KAS-FFC-SSC Sp800-56Ar3: (A7248) ECDH Shared Secret Computation KAS-SSC ECDH Shared Secret Computation Compliance:IG D.F Scenario 2 (1) KAS-ECC-SSC Sp800-56Ar3: (A7243, A7244, A7245, A7246) KDA OneStep Key Derivation KAS-56CKDF KDA OneStep Key Derivation KDA OneStep SP800-56Cr2: (A7224) HKDF Key Derivation KAS-56CKDF HKDF Key Derivation KDA HKDF SP800- 56Cr2: (A7225) TLS 1.3 KDF Key Derivation KAS-135KDF TLS 1.3 KDF Key Derivation TLS v1.3 KDF: (A7225) SSH KDF Key Derivation KAS-135KDF SSH KDF Key Derivation KDF SSH: (A7229, A7230, A7231, A7232, A7243, A7244, A7245, A7246) ANS 9.42 KDF Key Derivation KAS-135KDF ANS 9.42 KDF Key Derivation KDF ANS 9.42: (A7233, A7243, A7244, A7245, A7246) Password-based Key Derivation PBKDF Password-based Key Derivation Password Length:10-128 characters PBKDF: (A7233, A7243, A7244, A7245, A7246) ANS 9.63 KDF Key Derivation KAS-135KDF ANS 9.63 KDF Key Derivation KDF ANS 9.63: (A7243, A7244, A7245, A7246) TLS 1.2 KDF Key Derivation KAS-135KDF TLS 1.2 KDF Key Derivation TLS v1.2 KDF RFC7627: (A7243, A7244, A7245, A7246) KBKDF Key Derivation KBKDF KBKDF Key Derivation KDF SP800-108: (A7247) Table 9: Security Function Implementations Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 21 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com 2.7 Algorithm Specific Information 2.7.1 AES-GCM [EVM] When no IV is externally provided, the AES GCM IV generation is performed in compliance with Scenario 2 of IG C.H (Random IV). The AES-GCM IV is generated randomly internal to the module using the approved DRBG provided by the bound kernel module “Junos® OS Evolved Kernel Cryptographic Module”. The DRBG seeds itself from the entropy source of the kernel. The GCM IV is 96 bits in length. 2.7.2 AES-XTS The AES algorithm in XTS mode can be only used for the cryptographic protection of data on storage devices, as specified in SP 800-38E. The length of a single data unit encrypted with the XTS-AES shall not exceed 2²⁰ AES blocks that is 16MB of data. To meet the requirement in FIPS 140-3 IG C.I, the module implements a check to ensure that the two AES keys used in XTS-AES algorithm are not identical. As the module does not generate symmetric keys, the check is performed when keys are input via the service APIs. The two AES keys shall be generated and/or established independently according to the rules for component symmetric keys from SP 800-133 Rev. 2, Section 6.3. 2.7.3 PBKDF2 The module provides password-based key derivation (PBKDF2), compliant with SP 800-132. The module supports option 1a from Section 5.4 of SP 800-132, in which the Master Key (MK) or a segment of it is used directly as the Data Protection Key (DPK). In accordance to SP 800-132 and FIPS 140-3 IG D.N, the following requirements shall be met: • Derived keys shall only be used in storage applications. The MK shall not be used for other purposes. The module accepts a minimum length of 112 bits for the MK or DPK. • Password and passphrases, used as an input for the PBKDF2, shall not be used as cryptographic keys. • The minimum length of the password or passphrase accepted by the module is 8 characters. This will result in a password strength of at least 108 . Combined with the minimum iteration count as described below, this provides an acceptable trade-off between user experience and security against brute-force attacks. • [EVM] A portion of the salt, with a length of at least 128 bits (this is verified by the module to determine the service is approved), shall be generated randomly using the SP 800-90A Rev. 1 DRBG provided by the bound kernel module. • The iteration count shall be selected as large as possible, as long as the time required to generate the key using the entered password is acceptable for the users. The module enforces a minimum iteration count of 1000. 2.7.4 Diffie-Hellman and EC Diffie-Hellman The module offers DH and ECDH shared secret computation services compliant to SP 800-56A Rev. 3 and meeting IG D.F scenario 2 path (1). In order to meet the required assurances listed in Section 5.6 of SP 800-56A Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 22 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Rev. 3, the module shall be used together with an application that implements the "TLS protocol" and the following steps shall be performed. 1. The entity using the module must use the module's "Key pair generation" service for generating DH/ECDH ephemeral keys. This meets the assurances required by key pair owner defined in the section 5.6.2.1 of SP 800-56A Rev. 3. 2. As part of the module's shared secret computation (SSC) service, the module internally performs the public key validation on the peer's public key passed in as input to the SSC function. This meets the public key validity assurance required by the sections 5.6.2.2.1/5.6.2.2.2 of SP 800-56A Rev. 3. 3. The module does not support static keys. The "assurance of peer's possession of private key" is therefore not applicable. 2.7.5 Key Wrapping The module does not establish SSPs using an approved key transport scheme (KTS). However, it does offer approved authenticated algorithms that can be used by an external operator/application as part of an approved KTS. 2.7.6 Key Agreement The module does not establish SSPs using an approved key agreement scheme (KAS). However, it does offer some or all of the underlying KAS cryptographic functionality to be used by an external operator/application as part of an approved KAS. 2.7.7 RSA Key Length The module supports RSA with any even modulus size between 2048 and 16384 bits. Moduli lengths other than 2048, 3072, and 4096 bits cannot be tested by CAVP but are approved for RSA key generation, signature generation, and signature verification as per IG C.F. 2.8 RBG and Entropy [EVM] The module does not implement any random bit generator. Instead, the module obtains random bits from the Random Number Generation (RNG) service provided by the bound kernel module “Junos® OS Evolved Kernel Cryptographic Module”. The DRBG implemented in the bound module and available to the module provides 256 bits of security strength. 2.9 Key Generation The module provides: • Safe primes key pair generation: compliant with SP 800-56A Rev. 3. The method described in Section 5.6.1.1.4 of SP 800-56A Rev. 3 (“Testing Candidates”) is used. Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 23 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com • RSA key pair generation: compliant with FIPS 186-5. The method described in Appendix A.1.6 of FIPS 186-5 (“Probable Primes with Conditions Based on Auxiliary Probable Primes”) is used. • ECC (ECDH and ECDSA) key pair generation: compliant with FIPS 186-5. The method described in Appendix A.2.2 of FIPS 186-5 (“Rejection Sampling”) is used. [EVM] When random values are required in asymmetric key pair generation, they are obtained from the SP 800-90A Rev. 1 approved DRBG implemented in the bound kernel module. The module implements Cryptographic Key Generation (CKG, vendor affirmed), compliant with SP 800-133 Rev. 2 Section 4 without the use of V (in accordance with additional comment 2 of IG D.H). Additionally, the module implements the following key derivation methods: • KBKDF: compliant with SP 800-108 Rev. 1. This implementation can be used to generate secret keys from a pre-existing key-derivation-key. • KDA OneStep, HKDF: compliant with SP 800-56C Rev. 2. These implementations shall only be used to generate secret keys in the context of an SP 800-56A Rev. 3 key agreement scheme. • ANSI X9.42 KDF, ANSI X9.63 KDF: compliant with SP 800-135 Rev. 1. These implementations shall only be used to generate secret keys in the context of an ANSI X9.42-2001 resp. ANSI X9.63-2001 key agreement scheme. • SSH KDF, TLS 1.2 KDF, TLS 1.3 KDF: compliant with SP 800-135 Rev. 1. These implementations shall only be used to generate secret keys in the context of the SSH, TLS 1.2, or TLS 1.3 protocols, respectively. • PBKDF2: compliant with option 1a of SP 800-132. This implementation shall only be used to derive keys for use in storage applications. 2.10 Key Establishment The module provides Diffie-Hellman (DH) and Elliptic Curve Diffie-Hellman (ECDH) shared secret computation compliant with SP 800-56A Rev. 3, in accordance with Scenario 2 (1) of FIPS 140-3 IG D.F. For Diffie-Hellman, the module supports the following safe prime groups: For use in the IKE protocol (RFC 3526): • MODP-2048 • MODP-3072 • MODP-4096 • MODP-6144 • MODP-8192 For use in the TLS protocol (RFC 7919): • ffdhe2048 • ffdhe3072 • ffdhe4096 • ffdhe6144 • ffdhe8192 Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 24 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com For Elliptic Curve Diffie-Hellman, the module supports the NIST-defined P-224, P-256, P-384, and P-521 curves. According to SP 800-56A Rev. 3 and FIPS 140-3 IG D.B, the key sizes of DH and ECDH shared secret computation provide 112-200 and 112-256 bits of security strength respectively in approved mode of operation. The module also offers authenticated encryption and decryption as a service using AES-KW and AES-KWP. These algorithms can be used to wrap SSPs with a security strength of 128, 192, or 256 bits, depending on the wrapping key size. 2.11 Industry Protocols The module implements the SSH key derivation function for use in the SSH protocol (RFC 4253 and RFC 6668). The module implements the TLS 1.2 and TLS 1.3 key derivation functions for use in the TLS protocol. The module implements safe primes groups as described in Section 2.10 of this security policy. No other parts of the SSH, TLS, or IKE protocols, have been tested by the CAVP and CMVP. Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 25 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com 3 Cryptographic Module Interfaces 3.1 Ports and Interfaces Physical Port Logical Interface(s) Data That Passes N/A Data Input API input parameters N/A Data Output API output parameters N/A Control Input API function calls N/A Status Output API return codes, error messages Table 10: Ports and Interfaces The module does not implement a control output interface. All data output via data output interface is inhibited when the module is performing the pre-operational self- test or zeroization or when the module enters error state. Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 26 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com 4 Roles, Services, and Authentication 4.1 Authentication Methods The module does not implement authentication. 4.2 Roles Name Type Operator Type Authentication Methods Crypto Officer Role Crypto Officer None Table 11: Roles The Crypto Officer role is implicitly and always assumed by the operator of the module. The module does not support concurrent operators. 4.3 Approved Services Name Description Indicator Inputs Outputs Security Functions SSP Access Message Digest Compute a message digest EVP_Digest*() functions will return 0 Message Message Digest Message Digest Crypto Officer XOF Compute the output of an XOF EVP_Digest*() functions will return 0 Message, output length XOF output of desired length Message Digest Crypto Officer Symmetric Encryption Encrypt a plaintext EVP_Encrypt*() functions will return 0 Plaintext, AES key, IV Ciphertext Symmetric Encryption Crypto Officer - AES key: W,E Symmetric Decryption Decrypt a ciphertext EVP_Decrypt*() functions will return 0 Ciphertext , AES key, IV Plaintext Symmetric Decryption Authenticate d Symmetric Decryption Crypto Officer - AES key: W,E Authenticate d Symmetric Encryption Encrypt & authenticat e a plaintext AES-CCM: EVP_Encrypt*() functions will return 0; AES- GCM: ERR_peek_last_ error() function returns something Plaintext, AES key, IV Ciphertext , MAC tag Authenticate d Symmetric Encryption Crypto Officer - AES key: W,E - AES-GCM IV: G,W,E Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 27 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Name Description Indicator Inputs Outputs Security Functions SSP Access different from 0x1C80012C Authenticate d Symmetric Decryption Authenticat e & decrypt a plaintext EVP_Decrypt*() functions will return 0 Ciphertext , MAC tag, AES key, IV Plaintext or Fail Authenticate d Symmetric Decryption Crypto Officer - AES key: W,E - AES-GCM IV: W,E Key Wrapping Perform AES-based key wrapping EVP_Encrypt*() functions will return 0 Key to be wrapped, AES key wrapping key Wrapped key Key Wrapping with AES- KW Key Wrapping with AES- KWP Crypto Officer - AES key: W,E Key Unwrapping Perform AES-based key unwrappin g EVP_Decrypt*() functions will return 0 Key to be unwrappe d, AES key wrapping key Unwrappe d key Key Unwrapping with AES- KW Key Unwrapping with AES- KWP Crypto Officer - AES key: W,E Message Authenticatio n Code Compute a MAC tag EVP_MAC*() functions will return 0 Message, MAC key (AES key, KMAC key, or HMAC key) MAC tag MAC Crypto Officer - AES key: W,E - HMAC key: W,E - KMAC key: W,E KBKDF Key Derivation Derive a key from a key- derivation key EVP_KDF*() functions will return 0 Key- derivation key KBKDF derived key KBKDF Key Derivation Crypto Officer - Key- derivation key: W,E - KBKDF derived key: G,R KDA OneStep Key Derivation Derive a key from a EVP_KDF*() functions will return 0 Shared secret KDA OneStep KDA OneStep Key Derivation Crypto Officer - DH shared Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 28 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Name Description Indicator Inputs Outputs Security Functions SSP Access shared secret derived key secret: W,E - ECDH shared secret: W,E - KDA OneStep derived key: G,R HKDF Key Derivation Derive a key from a shared secret EVP_KDF*() functions will return 0 Shared secret Hkdf derived key HKDF Key Derivation Crypto Officer - DH shared secret: W,E - ECDH shared secret: W,E - HKDF derived key: G,R ANS X9.42 KDF Key Derivation Derive a key from a shared secret EVP_KDF*() functions will return 0 Shared secret ANS X9.42 KDF derived key ANS 9.42 KDF Key Derivation Crypto Officer - DH shared secret: W,E - ECDH shared secret: W,E - ANS X9.42 derived key: G,R ANS X9.63 KDF Key Derivation Derive a key from a shared secret EVP_KDF*() functions will return 0 Shared secret ANS X9.63 KDF derived key ANS 9.63 KDF Key Derivation Crypto Officer - DH shared secret: W,E - ECDH shared secret: W,E - ANS X9.63 derived key: G,R SSH KDF Key Derivation Derive a key from a shared secret EVP_KDF*() functions will return 0 Shared secret SSH KDF derived key SSH KDF Key Derivation None Crypto Officer - DH shared secret: W,E - ECDH Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 29 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Name Description Indicator Inputs Outputs Security Functions SSP Access shared secret: W,E - SSH KDF derived key: G,R TLS 1.2 KDF Key Derivation Derive a key from a shared secret EVP_KDF*() functions will return 0 Shared secret TLS 1.2 KDF derived key TLS 1.2 KDF Key Derivation Crypto Officer - DH shared secret: W,E - ECDH shared secret: W,E - TLS 1.2 KDF derived key: G,R TLS 1.3 KDF Key Derivation Derive a key from a shared secret EVP_KDF*() functions will return 0 Shared secret TLS 1.3 KDF derived key TLS 1.3 KDF Key Derivation Crypto Officer - DH shared secret: W,E - ECDH shared secret: W,E - TLS 1.3 KDF derived key: G,R Password- based Key Derivation Derive a key from a password EVP_KDF*() functions will return 0 Password PBKDF derived key Password- based Key Derivation Crypto Officer - Password: W,E - PBKDF2 derived key: G,R DH Shared Secret Computation Compute a shared secret EVP_PKEY*() functions will return 0 DH private key, DH public key from peer DH shared secret DH Shared Secret Computation Crypto Officer - DH private key: W,E - DH public key: W,E - DH shared secret: G,R ECDH Shared Secret Computation Compute a shared secret EVP_PKEY*() functions will return 0 ECDH private key, ECDH shared secret ECDH Shared Crypto Officer - ECDH Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 30 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Name Description Indicator Inputs Outputs Security Functions SSP Access ECDH public key from peer Secret Computation private key: W,E - ECDH public key: W,E - ECDH shared secret: G,R Signature Generation Generate a signature EVP_DigestSign*() functions will return 0 Message, Private key (RSA private key or ECDSA private key) Signature Signature Generation Crypto Officer - RSA private key: W,E - ECDSA private key: W,E Signature Verification Verify a signature EVP_DigestVerify *() functions will return 0 Message, Public key (RSA public key or ECDSA public key), Signature Pass or Fail Signature Verification Crypto Officer - RSA public key: W,E - ECDSA public key: W,E Key Pair Generation Generate a key pair EVP_PKEY*() will return 0 Domain (group, curve, or bitlength) Key pair (DH, EC, or RSA) ECDSA Key Pair Generation Safe Primes Key Pair Generation RSA Key Pair Generation Crypto Officer - Module- generated DH private key: G,R - Module- generated DH public key: G,R - Module- generated ECDH private key: G,R - Module- generated ECDH public key: G,R Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 31 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Name Description Indicator Inputs Outputs Security Functions SSP Access - Module- generated ECDSA private key: G,R - Module- generated ECDSA public key: G,R - Module- generated RSA private key: G,R - Module- generated RSA public key: G,R - Intermediate key generation value: G,W,E Key Pair Verification Verify a key pair EVP_PKEY*() will return 0 Domain (group or curve), Key pair (DH or EC) Pass or Fail ECDSA Key Pair Verification Safe Primes Key Pair Verification Crypto Officer - DH private key: W - DH public key: W - ECDH private key: W - ECDH public key: W - ECDSA private key: W - ECDSA public key: W Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 32 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Name Description Indicator Inputs Outputs Security Functions SSP Access [EVM] Random Number Generation Generate random bytes RAND_bytes*() will return number of bytes provided Output length Random bytes Random Number Generation Crypto Officer - [EVM] DRBG entropy input string: W,E,Z - [EVM] HMAC_DRB G Seed: G,E,Z - [EVM] HMAC_DRB G internal state (V, Key): G,W,E Show Version Return the name and version information N/A N/A Module Version None Crypto Officer Show Status Return the module status N/A N/A Module Status None Crypto Officer Self-test Perform the CASTs and integrity test N/A N/A Pass or Fail Random Number Generation KDA OneStep Key Derivation ECDSA Key Pair Generation Safe Primes Key Pair Generation RSA Key Pair Generation ECDSA Key Pair Verification Safe Primes Key Pair Crypto Officer Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 33 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Name Description Indicator Inputs Outputs Security Functions SSP Access Verification Signature Generation Signature Verification ECDH Shared Secret Computation HKDF Key Derivation TLS 1.3 KDF Key Derivation Symmetric Encryption Symmetric Decryption Authenticate d Symmetric Encryption Authenticate d Symmetric Decryption MAC Key Wrapping with AES- KW Key Wrapping with AES- KWP Key Unwrapping with AES- KW Key Unwrapping with AES- KWP SSH KDF Key Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 34 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Name Description Indicator Inputs Outputs Security Functions SSP Access Derivation ANS 9.42 KDF Key Derivation Password- based Key Derivation Message Digest ANS 9.63 KDF Key Derivation TLS 1.2 KDF Key Derivation KBKDF Key Derivation DH Shared Secret Computation Zeroization Zeroize CPSs N/A Any SSP N/A None Crypto Officer - AES key: Z - HMAC key: Z - KMAC key: Z - Key- derivation key: Z - DH shared secret: Z - ECDH shared secret: Z - Password: Z - KBKDF derived key: Z - KDA OneStep derived key: Z Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 35 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Name Description Indicator Inputs Outputs Security Functions SSP Access - HKDF derived key: Z - ANS X9.42 derived key: Z - ANS X9.63 derived key: Z - SSH KDF derived key: Z - TLS 1.2 KDF derived key: Z - TLS 1.3 KDF derived key: Z - PBKDF2 derived key: Z - DH private key: Z - DH public key: Z - ECDH private key: Z - ECDH public key: Z - ECDSA private key: Z - ECDSA public key: Z - RSA private key: Z - RSA public key: Z - [EVM] DRBG entropy input string: Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 36 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Name Description Indicator Inputs Outputs Security Functions SSP Access Z - [EVM] HMAC_DRB G Seed: Z - [EVM] HMAC_DRB G internal state (V, Key): Z - AES-GCM IV: Z Table 12: Approved Services To interact with the module, a calling application must use the EVP API layer provided by OpenSSL. This layer will delegate the request to the FIPS provider, which will in turn perform the requested service. 4.4 Non-Approved Services Name Description Algorithms Role AES GCM (external IV) Symmetric Encryption AES GCM (external IV) CO Table 13: Non-Approved Services 4.5 External Software/Firmware Loaded The module does not support the loading of external software/firmware. Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 37 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com 5 Software/Firmware Security 5.1 Integrity Techniques The integrity of the module is verified by comparing a HMAC SHA2-256 value calculated at run time on the fips.so binary with the HMAC SHA2-256 value stored in the /etc/ssl/fipsmodule.cnf file that was computed during installation of the module. This verification is performed by the fips_chk_hmac utility provided by the bound Kernel module and utilizes the HMAC service provided by the module. The key used in the HMAC computations is hardcoded in the fips_chk_hmac utility. 5.2 Initiate on Demand Integrity tests are performed as part of the pre-operational self-tests, which are executed when the module is initialized. The integrity test may be invoked on-demand by unloading and subsequently re-initializing the module, or by calling the OSSL_PROVIDER_self_test function. This will perform (among others) the software integrity test. Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 38 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com 6 Operational Environment 6.1 Operational Environment Type and Requirements Type of Operational Environment: Modifiable 6.2 Configuration Settings and Restrictions The module shall be installed as stated in Section 11.1. If properly installed, the operating system provides process isolation and memory protection mechanisms that ensure appropriate separation for memory access among the processes on the system. Each process has control over its own data and uncontrolled access to the data of other processes is prevented. Instrumentation tools like the ptrace system call, gdb and strace utilities, userspace live patching, as well as other tracing mechanisms offered by the Linux environment such as ftrace or systemtap, shall not be used in the operational environment. The use of any of these tools implies that the cryptographic module is running in a non-tested operational environment. Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 39 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com 7 Physical Security The module is comprised of software only, and this section is therefore not applicable. Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 40 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com 8 Non-Invasive Security This module does not implement any non-invasive security mechanism and therefore this section is not applicable. Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 41 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com 9 Sensitive Security Parameters Management 9.1 Storage Areas Storage Area Name Description Persistence Type RAM Temporary storage for SSPs used by the module as part of service execution. Dynamic Table 14: Storage Areas SSPs are provided to the module by the calling application and are destroyed when released by the appropriate API function calls. The module does not perform persistent storage of SSPs. 9.2 SSP Input-Output Methods Name From To Format Type Distribution Type Entry Type SFI or Algorithm API input parameters Operator calling application (TOEPP) Cryptographic module Plaintext Manual Electronic API output parameters Cryptographic module Operator calling application (TOEPP) Plaintext Manual Electronic Table 15: SSP Input-Output Methods The module does not support the input or output of cryptographically protected SSPs. The module only supports SSP entry and output to and from a calling application running on the same operational environment. This corresponds to manual distribution, electronic entry/output (“CM Software to/from App via TOEPP Path”) per FIPS 140-3 IG 9.5.A Table 1. 9.3 SSP Zeroization Methods Zeroization Method Description Rationale Operator Initiation Wipe and Free memory block allocated Zeroizes the SSPs contained within the cipher handle. Memory occupied by SSPs is overwritten with zeroes and then it is released, which renders the SSP values irretrievable. The completion of the By calling the cipher related zeroization API functions: EVP_CIPHER_CTX_free/ EVP_CIPHER_reset for AES keys, HMAC_CTX_free for HMAC keys, RSA_free for RSA keys, EC_KEY_free for ECDSA and ECDH keys/shared secrets, DH_free for DH keys/shared secrets, EVP_PKEY_free for Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 42 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Zeroization Method Description Rationale Operator Initiation zeroization routine indicates that the zeroization procedure succeeded. passwords and derived keys, FIPS_drbg_free for DRBG SSPs, SSL_free/SSL_clear for TLS secrets Automatic Automatically zeroized by the module when no longer needed Memory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable. N/A Module Reset De-allocates the volatile memory used to store SSPs Volatile memory used by the module is overwritten within nanoseconds when power is removed. By unloading and reloading the module Table 16: SSP Zeroization Methods The application acting as the CO is responsible for calling the appropriate zeroization functions provided in the module’s API and listed in the table above. All data output is inhibited during zeroization. 9.4 SSPs Name Description Size - Strength Type - Category Generated By Established By Used By AES key AES key 128, 192, 256 bits - 128, 192, 256 bits Symmetric key - CSP Symmetric Encryption Symmetric Decryption Authenticated Symmetric Encryption Authenticated Symmetric Decryption MAC Key Wrapping with AES-KW Key Wrapping with AES- KWP Key Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 43 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Name Description Size - Strength Type - Category Generated By Established By Used By Unwrapping with AES-KW Key Unwrapping with AES- KWP HMAC key HMAC key 112-256 bits - 112- 256 bits Symmetric key - CSP MAC KMAC key KMAC key 128, 192, 256 bits - 128, 192, 256 bits Symmetric key - CSP MAC Key-derivation key Key- derivation key 112-256 bits - 112- 256 bits Key- derivation key - CSP KBKDF Key Derivation DH shared secret DH shared secret MODP- 2048, ffdhe2048, MODP- 3072, ffdhe3072, MODP- 4096, ffdhe4096, MODP- 6144, ffdhe6144, MODP- 8192, ffdhe8192 - 112, 128, 152, 172, 200 bits Shared Secret - CSP DH Shared Secret Computation KDA OneStep Key Derivation HKDF Key Derivation TLS 1.3 KDF Key Derivation SSH KDF Key Derivation ANS 9.42 KDF Key Derivation ANS 9.63 KDF Key Derivation TLS 1.2 KDF Key Derivation ECDH shared secret ECDH shared secret used P-224, P- 256, P-384, P-521 - 112, 128, 192, 256 bits Shared Secret - CSP ECDH Shared Secret Computation KDA OneStep Key Derivation HKDF Key Derivation TLS 1.3 KDF Key Derivation Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 44 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Name Description Size - Strength Type - Category Generated By Established By Used By SSH KDF Key Derivation ANS 9.42 KDF Key Derivation ANS 9.63 KDF Key Derivation TLS 1.2 KDF Key Derivation Password Password 8-128 bytes - N/A Password - CSP Password- based Key Derivation KBKDF derived key KBKDF derived key 112-4096 bits - 112- 256 bits Symmetric key - CSP KBKDF Key Derivation KDA OneStep derived key KDA OneStep derived key 2048 bits - 112-256 bits Symmetric key - CSP KDA OneStep Key Derivation HKDF derived key HKDF derived key 2048 bits - 112-256 bits Symmetric key - CSP HKDF Key Derivation ANS X9.42 derived key ANS X9.42 derived key 112-4096 bits - 112- 256 bits Symmetric key - CSP ANS 9.42 KDF Key Derivation ANS X9.63 derived key ANS X9.63 derived key 128-4096 bits - 112- 256 bits Symmetric key - CSP ANS 9.63 KDF Key Derivation SSH KDF derived key SSH KDF derived key 112-4096 - 112-256 bits Symmetric key - CSP SSH KDF Key Derivation TLS 1.2 KDF derived key TLS 1.2 KDF derived key 112-4096 bits - 112- 256 bits Symmetric key - CSP TLS 1.2 KDF Key Derivation TLS 1.3 KDF derived key TLS 1.3 KDF derived key 112-4096 bits - 112- 256 bits Symmetric key - CSP TLS 1.3 KDF Key Derivation PBKDF2 derived key PBKDF2 derived key 128-4096 bits - 112- 256 bits Symmetric key - CSP Password- based Key Derivation Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 45 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Name Description Size - Strength Type - Category Generated By Established By Used By DH private key DH private key input to module via API MODP- 2048, ffdhe2048, MODP- 3072, ffdhe3072, MODP- 4096, ffdhe4096, MODP- 6144, ffdhe6144, MODP- 8192, ffdhe8192 - 112, 128, 152, 172, 200 bits Private key - CSP Safe Primes Key Pair Verification DH Shared Secret Computation DH public key DH public key input to module via API MODP- 2048, ffdhe2048, MODP- 3072, ffdhe3072, MODP- 4096, ffdhe4096, MODP- 6144, ffdhe6144, MODP- 8192, ffdhe8192 - 112, 128, 152, 172, 200 bits Public key - PSP Safe Primes Key Pair Verification DH Shared Secret Computation ECDH private key ECDH private key input to module via API P-224, P- 256, P-384, P-521 bits - 112, 128, 192, 256 bits Private key - CSP ECDSA Key Pair Verification ECDH Shared Secret Computation Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 46 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Name Description Size - Strength Type - Category Generated By Established By Used By ECDH public key ECDH public key input to module via API P-224, P- 256, P-384, P-521 bits - 112, 128, 192, 256 bits Public key - PSP ECDSA Key Pair Verification ECDH Shared Secret Computation RSA private key RSA private key input to module via API 2048-16384 bits - 112- 256 bits Private key - CSP Signature Generation RSA public key RSA public key input to module via API 1024-16384 bits - 80- 256 bits Public key - PSP Signature Verification ECDSA private key ECDSA private key input to module via API P-224, P- 256, P-384, P-521 bits - 112, 128, 192, 256 bits Private key - CSP ECDSA Key Pair Verification Signature Generation ECDSA public key ECDSA public key input to module via API P-224, P- 256, P-384, P-521 bits - 112, 128, 192, 256 bits Public key - PSP ECDSA Key Pair Verification Signature Verification Module- generated DH private key DH private key generated by module MODP- 2048, ffdhe2048, MODP- 3072, ffdhe3072, MODP- 4096, ffdhe4096, MODP- 6144, ffdhe6144, MODP- 8192, ffdhe8192 - 112, 128, Private key - CSP Safe Primes Key Pair Generation Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 47 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Name Description Size - Strength Type - Category Generated By Established By Used By 152, 172, 200 bits Module- generated DH public key DH public key generated by module MODP- 2048, ffdhe2048, MODP- 3072, ffdhe3072, MODP- 4096, ffdhe4096, MODP- 6144, ffdhe6144, MODP- 8192, ffdhe8192 - 112, 128, 152, 172, 200 bits Public key - PSP Safe Primes Key Pair Generation Module- generated ECDH private key ECDH private key generated by module P-224, P- 256, P-384, P-521 bits - 112, 128, 192, 256 bits Private key - CSP ECDSA Key Pair Generation Module- generated ECDH public key ECDH public key generated by module P-224, P- 256, P-384, P-521 bits - 112, 128, 192, 256 bits Public key - PSP ECDSA Key Pair Generation Module- generated RSA private key RSA private key generated by module 2048-16384 bits - 112- 256 bits Private key - CSP RSA Key Pair Generation Module- generated RSA public key RSA public key generated by module 2048-16384 bits - 112- 256 bits Public key - PSP RSA Key Pair Generation Module- generated ECDSA private key ECDSA private key generated by module P-224, P- 256, P-384, P-521 bits - 112, 128, Private key - CSP ECDSA Key Pair Generation Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 48 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Name Description Size - Strength Type - Category Generated By Established By Used By 192, 256 bits Module- generated ECDSA public key ECDSA public key generated by module P-224, P- 256, P-384, P-521 bits - 112, 128, 192, 256 bits Public key - PSP ECDSA Key Pair Generation Intermediate key generation value Intermediate key pair generation value generated during key generation services (SP 800-133 Rev. 2 Section 4, 5.1, and 5.2 112-8192 bits - 112- 256 bits Intermediate value - CSP ECDSA Key Pair Generation Safe Primes Key Pair Generation RSA Key Pair Generation ECDSA Key Pair Generation Safe Primes Key Pair Generation RSA Key Pair Generation [EVM] DRBG entropy input string Entropy input string for DRBG in bound module(IG D.L compliant) 128-384 bits - 128- 384 bits Entropy Input - CSP Random Number Generation [EVM] HMAC_DRBG Seed DRBG seed derived from entropy input in bound module (IG D.L compliant) 160, 256, 512 bits - 128, 256 bits Seed - CSP Random Number Generation Random Number Generation [EVM] HMAC_DRBG internal state (V, Key) Internal state of DRBG (IG D.L compliant) 320, 512, 1024 bits - 128, 256 bits Internal State - CSP Random Number Generation Random Number Generation AES-GCM IV Randomly generated IV for AES- GCM (IG C.H compliant) 96-128 bits - N/A IV - PSP Random Number Generation Authenticated Symmetric Encryption Authenticated Symmetric Decryption Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 49 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Table 17: SSP Table 1 Name Input - Output Storage Storage Duration Zeroization Related SSPs AES key API input parameters RAM:Plaintext From service invocation to service completion Wipe and Free memory block allocated Module Reset HMAC key API input parameters RAM:Plaintext From service invocation to service completion Wipe and Free memory block allocated Module Reset KMAC key API input parameters RAM:Plaintext From service invocation to service completion Wipe and Free memory block allocated Module Reset Key-derivation key API input parameters RAM:Plaintext From service invocation to service completion Wipe and Free memory block allocated Module Reset KBKDF derived key:Derives DH shared secret API input parameters API output parameters RAM:Plaintext From service invocation to service completion Wipe and Free memory block allocated Module Reset KDA OneStep derived key:Derived From HKDF derived key:Derived From SSH KDF derived key:Derived From TLS 1.2 KDF derived key:Derived From TLS 1.3 KDF derived key:Derived From DH private key:Established from DH public key:Established from ECDH shared secret API input parameters API output parameters RAM:Plaintext From service invocation to service completion Wipe and Free memory block allocated Module Reset KDA OneStep derived key:Derived From HKDF derived key:Derived From Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 50 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Name Input - Output Storage Storage Duration Zeroization Related SSPs SSH KDF derived key:Derived From TLS 1.2 KDF derived key:Derived From TLS 1.3 KDF derived key:Derived From ECDH private key:Established from ECDH public key:Established from Password API input parameters RAM:Plaintext From service invocation to service completion Wipe and Free memory block allocated Module Reset PBKDF2 derived key:Derives KBKDF derived key API output parameters RAM:Plaintext From service invocation to service completion Wipe and Free memory block allocated Module Reset Key-derivation key:Derived From KDA OneStep derived key API output parameters RAM:Plaintext From service invocation to service completion Wipe and Free memory block allocated Module Reset DH shared secret:Derived From ECDH shared secret:Derived From HKDF derived key API output parameters RAM:Plaintext From service invocation to service completion Wipe and Free memory block allocated Module Reset DH shared secret:Derived From ECDH shared secret:Derived From ANS X9.42 derived key API output parameters RAM:Plaintext From service invocation to service completion Wipe and Free memory block allocated Module Reset DH shared secret:Derived From ECDH shared secret:Derived From ANS X9.63 derived key API output parameters RAM:Plaintext From service invocation to service completion Wipe and Free memory block allocated Module Reset DH shared secret:Derived From ECDH shared secret:Derived From SSH KDF derived key API output parameters RAM:Plaintext From service invocation to Wipe and Free memory block DH shared secret:Derived From Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 51 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Name Input - Output Storage Storage Duration Zeroization Related SSPs service completion allocated Module Reset ECDH shared secret:Derived From TLS 1.2 KDF derived key API output parameters RAM:Plaintext From service invocation to service completion Wipe and Free memory block allocated Module Reset DH shared secret:Derived From ECDH shared secret:Derived From TLS 1.3 KDF derived key API output parameters RAM:Plaintext From service invocation to service completion Wipe and Free memory block allocated Module Reset DH shared secret:Derived From ECDH shared secret:Derived From PBKDF2 derived key API output parameters RAM:Plaintext From service invocation to service completion Wipe and Free memory block allocated Module Reset Password:Derived From DH private key API input parameters RAM:Plaintext From service invocation to service completion Wipe and Free memory block allocated Module Reset DH shared secret:Establishes DH public key:Paired With DH public key API input parameters RAM:Plaintext From service invocation to service completion Wipe and Free memory block allocated Module Reset DH shared secret:Establishes DH private key:Paired With ECDH private key API input parameters RAM:Plaintext From service invocation to service completion Wipe and Free memory block allocated Module Reset ECDH shared secret:Establishes ECDH public key:Paired With ECDH public key API input parameters RAM:Plaintext From service invocation to service completion Wipe and Free memory block allocated Module Reset ECDH shared secret:Establishes ECDH private key:Paired With RSA private key API input parameters RAM:Plaintext From service invocation to service completion Wipe and Free memory block allocated Module Reset RSA public key:Paired With Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 52 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Name Input - Output Storage Storage Duration Zeroization Related SSPs RSA public key API input parameters RAM:Plaintext From service invocation to service completion Wipe and Free memory block allocated Module Reset RSA private key:Paired With ECDSA private key API input parameters RAM:Plaintext From service invocation to service completion Wipe and Free memory block allocated Module Reset ECDSA public key:Paired With ECDSA public key API input parameters RAM:Plaintext From service invocation to service completion Wipe and Free memory block allocated Module Reset ECDSA private key:Paired With Module- generated DH private key API output parameters RAM:Plaintext From service invocation to service completion Wipe and Free memory block allocated Module Reset Module-generated DH public key:Paired With Intermediate key generation value:Derived From Module- generated DH public key API output parameters RAM:Plaintext From service invocation to service completion Wipe and Free memory block allocated Module Reset Module-generated DH private key:Paired With Intermediate key generation value:Derived From Module- generated ECDH private key API output parameters RAM:Plaintext From service invocation to service completion Wipe and Free memory block allocated Module Reset Module-generated ECDH public key:Paired With Intermediate key generation value:Derived From Module- generated ECDH public key API output parameters RAM:Plaintext From service invocation to service completion Wipe and Free memory block allocated Module Reset Module-generated ECDH private key:Paired With Intermediate key generation value:Derived From Module- generated RSA private key API output parameters RAM:Plaintext From service invocation to service completion Wipe and Free memory block Module-generated RSA public key:Paired With Intermediate key Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 53 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Name Input - Output Storage Storage Duration Zeroization Related SSPs allocated Module Reset generation value:Derived From Module- generated RSA public key API output parameters RAM:Plaintext From service invocation to service completion Wipe and Free memory block allocated Module Reset Module-generated RSA private key:Paired With Intermediate key generation value:Derived From Module- generated ECDSA private key API output parameters RAM:Plaintext From service invocation to service completion Wipe and Free memory block allocated Module Reset Module-generated ECDSA public key:Paired With Intermediate key generation value:Derived From Module- generated ECDSA public key API output parameters RAM:Plaintext From service invocation to service completion Wipe and Free memory block allocated Module Reset Module-generated ECDSA private key:Paired With Intermediate key generation value:Derived From Intermediate key generation value RAM:Plaintext From service invocation to service completion Automatic Module-generated DH private key:Derives Module-generated DH public key:Derives Module-generated ECDH private key:Derives Module-generated ECDH public key:Derives Module-generated RSA private key:Derives Module-generated RSA public key:Derives Module-generated ECDSA private key:Derives Module-generated Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 54 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Name Input - Output Storage Storage Duration Zeroization Related SSPs ECDSA public key:Derives [EVM] DRBG entropy input string RAM:Plaintext From generation until DRBG seed is created Wipe and Free memory block allocated Automatic Module Reset [EVM] HMAC_DRBG Seed:Derives [EVM] HMAC_DRBG Seed RAM:Plaintext While DRBG is instantiated Wipe and Free memory block allocated Automatic Module Reset [EVM] DRBG entropy input string:Derived From [EVM] HMAC_DRBG internal state (V, Key):Derives [EVM] HMAC_DRBG internal state (V, Key) RAM:Plaintext From DRBG instantiation to DRBG termination Wipe and Free memory block allocated Automatic Module Reset [EVM] HMAC_DRBG Seed:Derived From AES-GCM IV API input parameters API output parameters RAM:Plaintext From service invocation to service completion Wipe and Free memory block allocated Module Reset Table 18: SSP Table 2 The SSP tables do not include SSPs related to the Random Number Generation service which is implemented in the bound module. Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 55 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com 10 Self-Tests The module performs the pre-operational self-test and CASTs automatically when the module is loaded into memory. The pre-operational integrity test is only executed after all cryptographic algorithm self-tests (CASTs) executed successfully. While the module is executing the pre-operational test and the CASTs, the module services are not available, and input and output are inhibited. The module is not available for use by the calling application until the pre- operational self-test and the CASTs are completed successfully. After the pre-operational test and the CASTs succeed, the module becomes operational. If any of the pre-operational test or any of the CASTs fail an error message is returned, and the module transitions to the error state. 10.1 Pre-Operational Self-Tests Algorithm or Test Test Properties Test Method Test Type Indicator Details HMAC-SHA2-256 (A7243) SHA2- 256 MAC tag verification SW/FW Integrity Module becomes operational N/A HMAC-SHA2-256 (A7244) SHA2- 256 MAC tag verification SW/FW Integrity Module becomes operational N/A HMAC-SHA2-256 (A7245) SHA2- 256 MAC tag verification SW/FW Integrity Module becomes operational N/A HMAC-SHA2-256 (A7246) SHA2- 256 MAC tag verification SW/FW Integrity Module becomes operational N/A Table 19: Pre-Operational Self-Tests 10.2 Conditional Self-Tests Algorithm or Test Test Properties Test Method Test Type Indicator Details Conditions SHA-1 (A7243) KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test SHA-1 (A7244) KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test SHA-1 (A7245) KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test SHA-1 (A7246) KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 56 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Algorithm or Test Test Properties Test Method Test Type Indicator Details Conditions SHA2-512 (A7243) KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test SHA2-512 (A7244) KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test SHA2-512 (A7245) KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test SHA2-512 (A7246) KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test SHA3-256 (A7233) KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test SHA3-512 (A7233) KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test SHAKE-128 (A7233) KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test AES-GCM (A7234) - Encrypt 256 bits KAT CAST Module becomes operational Encrypt Test runs at power- on before the integrity test AES-GCM (A7234) - Decrypt 256 bits KAT CAST Module becomes operational Decrypt Test runs at power- on before the integrity test AES-GCM (A7235) - Encrypt 256 bits KAT CAST Module becomes operational Encrypt Test runs at power- on before the integrity test AES-GCM (A7235) - Decrypt 256 bits KAT CAST Module becomes operational Decrypt Test runs at power- on before the integrity test AES-GCM (A7236) - Encrypt 256 bits KAT CAST Module becomes operational Encrypt Test runs at power- on before the integrity test AES-GCM (A7236) - Decrypt 256 bits KAT CAST Module becomes operational Decrypt Test runs at power- on before the integrity test AES-GCM (A7237) - Encrypt 256 bits KAT CAST Module becomes operational Encrypt Test runs at power- on before the integrity test Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 57 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Algorithm or Test Test Properties Test Method Test Type Indicator Details Conditions AES-GCM (A7237) - Decrypt 256 bits KAT CAST Module becomes operational Decrypt Test runs at power- on before the integrity test AES-GCM (A7238) - Encrypt 256 bits KAT CAST Module becomes operational Encrypt Test runs at power- on before the integrity test AES-GCM (A7238) - Decrypt 256 bits KAT CAST Module becomes operational Decrypt Test runs at power- on before the integrity test AES-GCM (A7239) - Encrypt 256 bits KAT CAST Module becomes operational Encrypt Test runs at power- on before the integrity test AES-GCM (A7239) - Decrypt 256 bits KAT CAST Module becomes operational Decrypt Test runs at power- on before the integrity test AES-GCM (A7240) - Encrypt 256 bits KAT CAST Module becomes operational Encrypt Test runs at power- on before the integrity test AES-GCM (A7240) - Decrypt 256 bits KAT CAST Module becomes operational Decrypt Test runs at power- on before the integrity test AES-GCM (A7241) - Encrypt 256 bits KAT CAST Module becomes operational Encrypt Test runs at power- on before the integrity test AES-GCM (A7241) - Decrypt 256 bits KAT CAST Module becomes operational Decrypt Test runs at power- on before the integrity test AES-GCM (A7242) - Encrypt 256 bits KAT CAST Module becomes operational Encrypt Test runs at power- on before the integrity test AES-GCM (A7242) - Decrypt 256 bits KAT CAST Module becomes operational Decrypt Test runs at power- on before the integrity test AES-ECB (A7226) 128 bits KAT CAST Module becomes operational Decrypt Test runs at power- on before the integrity test AES-ECB (A7227) 128 bits KAT CAST Module becomes operational Decrypt Test runs at power- on before the integrity test AES-ECB (A7228) 128 bits KAT CAST Module becomes operational Decrypt Test runs at power- on before the integrity test Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 58 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Algorithm or Test Test Properties Test Method Test Type Indicator Details Conditions TLS v1.3 KDF (A7225) SHA2-256 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test TLS v1.2 KDF RFC7627 (A7243) SHA2-256 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test TLS v1.2 KDF RFC7627 (A7244) SHA2-256 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test TLS v1.2 KDF RFC7627 (A7245) SHA2-256 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test TLS v1.2 KDF RFC7627 (A7246) SHA2-256 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test PBKDF (A7233) KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test PBKDF (A7243) KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test PBKDF (A7244) KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test PBKDF (A7245) KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test PBKDF (A7246) KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test KDF SSH (A7229) SHA-1 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test KDF SSH (A7230) SHA-1 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test KDF SSH (A7231) SHA-1 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test KDF SSH (A7232) SHA-1 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 59 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Algorithm or Test Test Properties Test Method Test Type Indicator Details Conditions KDF SSH (A7243) SHA-1 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test KDF SSH (A7244) SHA-1 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test KDF SSH (A7245) SHA-1 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test KDF SSH (A7246) SHA-1 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test KDF SP800- 108 (A7247) HMAC- SHA2-256 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test KDA HKDF SP800-56Cr2 (A7225) SHA2-256 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test KDA OneStep SP800-56Cr2 (A7224) SHA2-224 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test KDF ANS 9.63 (A7243) SHA2-256 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test KDF ANS 9.63 (A7244) SHA2-256 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test KDF ANS 9.63 (A7245) SHA2-256 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test KDF ANS 9.63 (A7246) SHA2-256 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test KDF ANS 9.42 (A7233) SHA-1 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test KDF ANS 9.42 (A7243) SHA-1 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 60 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Algorithm or Test Test Properties Test Method Test Type Indicator Details Conditions KDF ANS 9.42 (A7244) SHA-1 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test KDF ANS 9.42 (A7245) SHA-1 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test KDF ANS 9.42 (A7246) SHA-1 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test KAS-FFC- SSC Sp800- 56Ar3 (A7248) ffdhe2048, MODP-2048 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test KAS-ECC- SSC Sp800- 56Ar3 (A7243) P-256 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test KAS-ECC- SSC Sp800- 56Ar3 (A7244) P-256 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test KAS-ECC- SSC Sp800- 56Ar3 (A7245) P-256 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test KAS-ECC- SSC Sp800- 56Ar3 (A7246) P-256 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test RSA SigGen (FIPS186-5) (A7233) SHA2-256, 2048 bits KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test RSA SigGen (FIPS186-5) (A7243) SHA2-256, 2048 bits KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test RSA SigGen (FIPS186-5) (A7244) SHA2-256, 2048 bits KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test RSA SigGen (FIPS186-5) (A7245) SHA2-256, 2048 bits KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 61 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Algorithm or Test Test Properties Test Method Test Type Indicator Details Conditions RSA SigGen (FIPS186-5) (A7246) SHA2-256, 2048 bits KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test ECDSA SigGen (FIPS186-5) (A7233) P-224, SHA2- 256 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test ECDSA SigGen (FIPS186-5) (A7243) P-224, SHA2- 256 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test ECDSA SigGen (FIPS186-5) (A7244) P-224, SHA2- 256 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test ECDSA SigGen (FIPS186-5) (A7245) P-224, SHA2- 256 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test ECDSA SigGen (FIPS186-5) (A7246) P-224, SHA2- 256 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test RSA SigVer (FIPS186-5) (A7233) SHA2-256, 2048 bits KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test RSA SigVer (FIPS186-5) (A7243) SHA2-256, 2048 bits KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test RSA SigVer (FIPS186-5) (A7244) SHA2-256, 2048 bits KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test RSA SigVer (FIPS186-5) (A7245) SHA2-256, 2048 bits KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test RSA SigVer (FIPS186-5) (A7246) SHA2-256, 2048 bits KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test ECDSA SigVer (FIPS186-5) (A7233) P-224, SHA2- 256 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 62 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Algorithm or Test Test Properties Test Method Test Type Indicator Details Conditions ECDSA SigVer (FIPS186-5) (A7243) P-224, SHA2- 256 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test ECDSA SigVer (FIPS186-5) (A7244) P-224, SHA2- 256 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test ECDSA SigVer (FIPS186-5) (A7245) P-224, SHA2- 256 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test ECDSA SigVer (FIPS186-5) (A7246) P-224, SHA2- 256 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test HMAC-SHA- 1 (A7243) SHA-1 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test HMAC-SHA- 1 (A7244) SHA-1 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test HMAC-SHA- 1 (A7245) SHA-1 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test HMAC-SHA- 1 (A7246) SHA-1 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test HMAC- SHA2-224 (A7243) SHA2-224 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test HMAC- SHA2-224 (A7244) SHA2-224 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test HMAC- SHA2-224 (A7245) SHA2-224 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test HMAC- SHA2-224 (A7246) SHA2-224 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 63 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Algorithm or Test Test Properties Test Method Test Type Indicator Details Conditions HMAC- SHA2-256 (A7243) SHA2-256 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test HMAC- SHA2-256 (A7244) SHA2-256 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test HMAC- SHA2-256 (A7245) SHA2-256 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test HMAC- SHA2-256 (A7246) SHA2-256 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test HMAC- SHA2-384 (A7243) SHA2-384 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test HMAC- SHA2-384 (A7244) SHA2-384 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test HMAC- SHA2-384 (A7245) SHA2-384 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test HMAC- SHA2-384 (A7246) SHA2-384 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test HMAC- SHA2-512 (A7243) SHA2-512 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test HMAC- SHA2-512 (A7244) SHA2-512 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test HMAC- SHA2-512 (A7245) SHA2-512 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test HMAC- SHA2-512 (A7246) SHA2-512 KAT CAST Module becomes operational N/A Test runs at power- on before the integrity test RSA KeyGen (FIPS186-5) (A7243) PKCS#1 v1.5 with SHA2- 256 PCT PCT Successful completion of service N/A Test runs when a corresponding key pair generation service is requested Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 64 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Algorithm or Test Test Properties Test Method Test Type Indicator Details Conditions RSA KeyGen (FIPS186-5) (A7244) PKCS#1 v1.5 with SHA2- 256 PCT PCT Successful completion of service N/A Test runs when a corresponding key pair generation service is requested RSA KeyGen (FIPS186-5) (A7245) PKCS#1 v1.5 with SHA2- 256 PCT PCT Successful completion of service N/A Test runs when a corresponding key pair generation service is requested RSA KeyGen (FIPS186-5) (A7246) PKCS#1 v1.5 with SHA2- 256 PCT PCT Successful completion of service N/A Test runs when a corresponding key pair generation service is requested ECDSA KeyGen (FIPS186-5) (A7243) SHA2-256 PCT PCT Successful completion of service N/A Test runs when a corresponding key pair generation service is requested ECDSA KeyGen (FIPS186-5) (A7244) SHA2-256 PCT PCT Successful completion of service N/A Test runs when a corresponding key pair generation service is requested ECDSA KeyGen (FIPS186-5) (A7245) SHA2-256 PCT PCT Successful completion of service N/A Test runs when a corresponding key pair generation service is requested ECDSA KeyGen (FIPS186-5) (A7246) SHA2-256 PCT PCT Successful completion of service N/A Test runs when a corresponding key pair generation service is requested Safe Primes Key Generation (A7248) N/A PCT PCT Successful completion of service N/A Test runs when a corresponding key pair generation service is requested HMAC DRBG (A7308) HMAC- SHA2-512 without prediction resistance KAT CAST Module becomes operational [EVM] SP 800- 90A Rev. 1 (instantiate, reseed, generate) health test Test runs at power- on before the integrity test HMAC DRBG (A7310) HMAC- SHA2-512 without prediction resistance KAT CAST Module becomes operational [EVM] SP 800- 90A Rev. 1 (instantiate, reseed, generate) health test Test runs at power- on before the integrity test Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 65 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Algorithm or Test Test Properties Test Method Test Type Indicator Details Conditions HMAC DRBG (A7311) HMAC- SHA2-512 without prediction resistance KAT CAST Module becomes operational [EVM] SP 800- 90A Rev. 1 (instantiate, reseed, generate) health test Test runs at power- on before the integrity test HMAC DRBG (A7313) HMAC- SHA2-512 without prediction resistance KAT CAST Module becomes operational [EVM] SP 800- 90A Rev. 1 (instantiate, reseed, generate) health test Test runs at power- on before the integrity test HMAC DRBG (A7314) HMAC- SHA2-512 without prediction resistance KAT CAST Module becomes operational [EVM] SP 800- 90A Rev. 1 (instantiate, reseed, generate) health test Test runs at power- on before the integrity test HMAC DRBG (A7315) HMAC- SHA2-512 without prediction resistance KAT CAST Module becomes operational [EVM] SP 800- 90A Rev. 1 (instantiate, reseed, generate) health test Test runs at power- on before the integrity test Table 20: Conditional Self-Tests 10.3 Periodic Self-Test Information Algorithm or Test Test Method Test Type Period Periodic Method HMAC-SHA2-256 (A7243) MAC tag verification SW/FW Integrity On Demand Manually HMAC-SHA2-256 (A7244) MAC tag verification SW/FW Integrity On Demand Manually HMAC-SHA2-256 (A7245) MAC tag verification SW/FW Integrity On Demand Manually HMAC-SHA2-256 (A7246) MAC tag verification SW/FW Integrity On Demand Manually Table 21: Pre-Operational Periodic Information Algorithm or Test Test Method Test Type Period Periodic Method SHA-1 (A7243) KAT CAST On Demand Manually SHA-1 (A7244) KAT CAST On Demand Manually SHA-1 (A7245) KAT CAST On Demand Manually SHA-1 (A7246) KAT CAST On Demand Manually Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 66 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Algorithm or Test Test Method Test Type Period Periodic Method SHA2-512 (A7243) KAT CAST On Demand Manually SHA2-512 (A7244) KAT CAST On Demand Manually SHA2-512 (A7245) KAT CAST On Demand Manually SHA2-512 (A7246) KAT CAST On Demand Manually SHA3-256 (A7233) KAT CAST On Demand Manually SHA3-512 (A7233) KAT CAST On Demand Manually SHAKE-128 (A7233) KAT CAST On Demand Manually AES-GCM (A7234) - Encrypt KAT CAST On Demand Manually AES-GCM (A7234) - Decrypt KAT CAST On Demand Manually AES-GCM (A7235) - Encrypt KAT CAST On Demand Manually AES-GCM (A7235) - Decrypt KAT CAST On Demand Manually AES-GCM (A7236) - Encrypt KAT CAST On Demand Manually AES-GCM (A7236) - Decrypt KAT CAST On Demand Manually AES-GCM (A7237) - Encrypt KAT CAST On Demand Manually AES-GCM (A7237) - Decrypt KAT CAST On Demand Manually AES-GCM (A7238) - Encrypt KAT CAST On Demand Manually AES-GCM (A7238) - Decrypt KAT CAST On Demand Manually AES-GCM (A7239) - Encrypt KAT CAST On Demand Manually AES-GCM (A7239) - Decrypt KAT CAST On Demand Manually AES-GCM (A7240) - Encrypt KAT CAST On Demand Manually AES-GCM (A7240) - Decrypt KAT CAST On Demand Manually AES-GCM (A7241) - Encrypt KAT CAST On Demand Manually AES-GCM (A7241) - Decrypt KAT CAST On Demand Manually AES-GCM (A7242) - Encrypt KAT CAST On Demand Manually Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 67 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Algorithm or Test Test Method Test Type Period Periodic Method AES-GCM (A7242) - Decrypt KAT CAST On Demand Manually AES-ECB (A7226) KAT CAST On Demand Manually AES-ECB (A7227) KAT CAST On Demand Manually AES-ECB (A7228) KAT CAST On Demand Manually TLS v1.3 KDF (A7225) KAT CAST On Demand Manually TLS v1.2 KDF RFC7627 (A7243) KAT CAST On Demand Manually TLS v1.2 KDF RFC7627 (A7244) KAT CAST On Demand Manually TLS v1.2 KDF RFC7627 (A7245) KAT CAST On Demand Manually TLS v1.2 KDF RFC7627 (A7246) KAT CAST On Demand Manually PBKDF (A7233) KAT CAST On Demand Manually PBKDF (A7243) KAT CAST On Demand Manually PBKDF (A7244) KAT CAST On Demand Manually PBKDF (A7245) KAT CAST On Demand Manually PBKDF (A7246) KAT CAST On Demand Manually KDF SSH (A7229) KAT CAST On Demand Manually KDF SSH (A7230) KAT CAST On Demand Manually KDF SSH (A7231) KAT CAST On Demand Manually KDF SSH (A7232) KAT CAST On Demand Manually KDF SSH (A7243) KAT CAST On Demand Manually KDF SSH (A7244) KAT CAST On Demand Manually KDF SSH (A7245) KAT CAST On Demand Manually KDF SSH (A7246) KAT CAST On Demand Manually KDF SP800-108 (A7247) KAT CAST On Demand Manually KDA HKDF SP800- 56Cr2 (A7225) KAT CAST On Demand Manually KDA OneStep SP800-56Cr2 (A7224) KAT CAST On Demand Manually KDF ANS 9.63 (A7243) KAT CAST On Demand Manually KDF ANS 9.63 (A7244) KAT CAST On Demand Manually KDF ANS 9.63 (A7245) KAT CAST On Demand Manually KDF ANS 9.63 (A7246) KAT CAST On Demand Manually Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 68 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Algorithm or Test Test Method Test Type Period Periodic Method KDF ANS 9.42 (A7233) KAT CAST On Demand Manually KDF ANS 9.42 (A7243) KAT CAST On Demand Manually KDF ANS 9.42 (A7244) KAT CAST On Demand Manually KDF ANS 9.42 (A7245) KAT CAST On Demand Manually KDF ANS 9.42 (A7246) KAT CAST On Demand Manually KAS-FFC-SSC Sp800-56Ar3 (A7248) KAT CAST On Demand Manually KAS-ECC-SSC Sp800-56Ar3 (A7243) KAT CAST On Demand Manually KAS-ECC-SSC Sp800-56Ar3 (A7244) KAT CAST On Demand Manually KAS-ECC-SSC Sp800-56Ar3 (A7245) KAT CAST On Demand Manually KAS-ECC-SSC Sp800-56Ar3 (A7246) KAT CAST On Demand Manually RSA SigGen (FIPS186-5) (A7233) KAT CAST On Demand Manually RSA SigGen (FIPS186-5) (A7243) KAT CAST On Demand Manually RSA SigGen (FIPS186-5) (A7244) KAT CAST On Demand Manually RSA SigGen (FIPS186-5) (A7245) KAT CAST On Demand Manually RSA SigGen (FIPS186-5) (A7246) KAT CAST On Demand Manually ECDSA SigGen (FIPS186-5) (A7233) KAT CAST On Demand Manually Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 69 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Algorithm or Test Test Method Test Type Period Periodic Method ECDSA SigGen (FIPS186-5) (A7243) KAT CAST On Demand Manually ECDSA SigGen (FIPS186-5) (A7244) KAT CAST On Demand Manually ECDSA SigGen (FIPS186-5) (A7245) KAT CAST On Demand Manually ECDSA SigGen (FIPS186-5) (A7246) KAT CAST On Demand Manually RSA SigVer (FIPS186-5) (A7233) KAT CAST On Demand Manually RSA SigVer (FIPS186-5) (A7243) KAT CAST On Demand Manually RSA SigVer (FIPS186-5) (A7244) KAT CAST On Demand Manually RSA SigVer (FIPS186-5) (A7245) KAT CAST On Demand Manually RSA SigVer (FIPS186-5) (A7246) KAT CAST On Demand Manually ECDSA SigVer (FIPS186-5) (A7233) KAT CAST On Demand Manually ECDSA SigVer (FIPS186-5) (A7243) KAT CAST On Demand Manually ECDSA SigVer (FIPS186-5) (A7244) KAT CAST On Demand Manually ECDSA SigVer (FIPS186-5) (A7245) KAT CAST On Demand Manually ECDSA SigVer (FIPS186-5) (A7246) KAT CAST On Demand Manually Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 70 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Algorithm or Test Test Method Test Type Period Periodic Method HMAC-SHA-1 (A7243) KAT CAST On Demand Manually HMAC-SHA-1 (A7244) KAT CAST On Demand Manually HMAC-SHA-1 (A7245) KAT CAST On Demand Manually HMAC-SHA-1 (A7246) KAT CAST On Demand Manually HMAC-SHA2-224 (A7243) KAT CAST On Demand Manually HMAC-SHA2-224 (A7244) KAT CAST On Demand Manually HMAC-SHA2-224 (A7245) KAT CAST On Demand Manually HMAC-SHA2-224 (A7246) KAT CAST On Demand Manually HMAC-SHA2-256 (A7243) KAT CAST On Demand Manually HMAC-SHA2-256 (A7244) KAT CAST On Demand Manually HMAC-SHA2-256 (A7245) KAT CAST On Demand Manually HMAC-SHA2-256 (A7246) KAT CAST On Demand Manually HMAC-SHA2-384 (A7243) KAT CAST On Demand Manually HMAC-SHA2-384 (A7244) KAT CAST On Demand Manually HMAC-SHA2-384 (A7245) KAT CAST On Demand Manually HMAC-SHA2-384 (A7246) KAT CAST On Demand Manually HMAC-SHA2-512 (A7243) KAT CAST On Demand Manually HMAC-SHA2-512 (A7244) KAT CAST On Demand Manually HMAC-SHA2-512 (A7245) KAT CAST On Demand Manually HMAC-SHA2-512 (A7246) KAT CAST On Demand Manually RSA KeyGen (FIPS186-5) (A7243) PCT PCT On Demand Manually Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 71 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Algorithm or Test Test Method Test Type Period Periodic Method RSA KeyGen (FIPS186-5) (A7244) PCT PCT On Demand Manually RSA KeyGen (FIPS186-5) (A7245) PCT PCT On Demand Manually RSA KeyGen (FIPS186-5) (A7246) PCT PCT On Demand Manually ECDSA KeyGen (FIPS186-5) (A7243) PCT PCT On Demand Manually ECDSA KeyGen (FIPS186-5) (A7244) PCT PCT On Demand Manually ECDSA KeyGen (FIPS186-5) (A7245) PCT PCT On Demand Manually ECDSA KeyGen (FIPS186-5) (A7246) PCT PCT On Demand Manually Safe Primes Key Generation (A7248) PCT PCT On Demand Manually HMAC DRBG (A7308) KAT CAST On Demand Manually HMAC DRBG (A7310) KAT CAST On Demand Manually HMAC DRBG (A7311) KAT CAST On Demand Manually HMAC DRBG (A7313) KAT CAST On Demand Manually HMAC DRBG (A7314) KAT CAST On Demand Manually HMAC DRBG (A7315) KAT CAST On Demand Manually Table 22: Conditional Periodic Information 10.4 Error States Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 72 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com If the module fails any of the self-tests, the module enters the error state. In the error state, the module immediately stops functioning and ends the application process. Consequently, the data output interface is inhibited, and the module accepts no more inputs or requests (as the module is no longer running). Name Description Conditions Recovery Method Indicator Error General purpose error Software integrity test failure CAST failure PCT failure Restart module Module will not load/module stops functioning Table 23: Error States 10.5 Operator Initiation of Self-Tests The operator can initiate the pre-operational self-tests and the cryptographic algorithms self-tests by unloading and subsequently re-initializing the module. The operator can also initiate the pre-operational self-test by calling the OSSL_PROVIDER_self_test function. Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 73 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com 11 Life-Cycle Assurance 11.1 Installation, Initialization, and Startup Procedures The binaries of the module are contained in the base Junos Evolved installation image. The operator is responsible for verifying the correct installation of module which is already pre-installed on the image file (junos-evo-install-ptx-fixed-x86-64-24.4R2.15-EVO.iso). The following steps are required: • run the following command: openssl fipsinstall -module /usr/lib64/ossl-modules/fips.so -in /etc/ssl/openssl-fips.cnf -provider_name fips -verify Which should output the following: VERIFY PASSED • run the following command to request the “Show module name and version” service and check the name and the version of the OpenSSL: openssl list -providers Which should output the following: Providers: base name: OpenSSL Base Provider version: 3.0.16 status: active fips name: Junos OS Evolved OpenSSL Cryptographic Module version: 3.0 status: active 11.2 Administrator Guidance The Crypto Officer shall follow Section 11.1 of this Security Policy to verify that the module is installed correctly. The Crypto Officer shall follow this Security Policy to operate the module as a FIPS 140-3 validated module. Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 74 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com 11.3 End of Life As the module does not persistently store SSPs, secure sanitization of the module consists of unloading the module. This will zeroize all SSPs in volatile memory. Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 75 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com 12 Mitigation of Other Attacks 12.1 Attack List Certain cryptographic subroutines and algorithms are vulnerable to timing analysis. The module mitigates this vulnerability by using constant-time implementations. This includes, but is not limited to: • Big number operations: computing GCDs, modular inversion, multiplication, division, and modular exponentiation (using Montgomery multiplication). • Elliptic curve point arithmetic: addition and multiplication (using the Montgomery ladder). • Vector-based AES implementations. In addition, RSA, ECDSA, ECDH, and DH employ blinding techniques to further impede timing and power analysis. No configuration is needed to enable these countermeasures. Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 76 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Appendix A. Glossary and Abbreviations AES Advanced Encryption Standard API Application Programming Interface CAST Cryptographic Algorithm Self-Test CAVP Cryptographic Algorithm Validation Program CBC Cipher Block Chaining CMAC Cipher-based Message Authentication Code CMVP Cryptographic Module Validation Program CSP Critical Security Parameter CTR Counter DRBG Deterministic Random Bit Generator ECB Electronic Code Book FIPS Federal Information Processing Standards GCM Galois Counter Mode HMAC Keyed-Hash Message Authentication Code KAT Known Answer Test MAC Message Authentication Code NIST National Institute of Science and Technology PAA Processor Algorithm Acceleration PKCS Public-Key Cryptography Standards RSA Rivest, Shamir, Adleman SHA Secure Hash Algorithm SSP Sensitive Security Parameter XTS XEX-based Tweaked-codebook mode with cipher text Stealing Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 77 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com Appendix B. References FIPS 140-3 FIPS PUB 140-3 - Security Requirements For Cryptographic Modules March 2019 https://doi.org/10.6028/NIST.FIPS.140-3 FIPS 140-3 IG Implementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program September 2025 https://csrc.nist.gov/Projects/cryptographic-module-validation-program/fips-140-3-ig- announcements SP 800-133 Rev. 2 Recommendation for Cryptographic Key Generation June 2020 https://doi.org/10.6028/NIST.SP.800-133r2 SP 800-38A Recommendation for Block Cipher Modes of Operation Methods and Techniques December 2001 https://doi.org/10.6028/NIST.SP.800-38A SP 800-38B Recommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication May 2005 https://doi.org/10.6028/NIST.SP.800-38B SP 800-38C Recommendation for Block Cipher Modes of Operation: The CCM Mode for Authentication and Confidentiality May 2004 https://doi.org/10.6028/NIST.SP.800-38C SP 800-38D Recommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC November 2007 https://doi.org/10.6028/NIST.SP.800-38D SP 800-38E Recommendation for Block Cipher Modes of Operation: The XTS-AES Mode for Confidentiality of Storage Devices January 2010 https://doi.org/10.6028/NIST.SP.800-38E SP 800-38F Recommendation for Block Cipher Modes of Operation: Methods for Key Wrapping December 2012 https://doi.org/10.6028/NIST.SP.800-38F SP 800-90A Rev. 1 Recommendation for Random Number Generation Using Deterministic Random Bit Generators June 2015 https://doi.org/10.6028/NIST.SP.800-90Ar1 Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 78 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com SP 800-90B Recommendation for the Entropy Sources Used for Random Bit Generation January 2018 https://doi.org/10.6028/NIST.SP.800-90B FIPS 198-1 The Keyed-Hash Message Authentication Code (HMAC) July 2008 https://doi.org/10.6028/NIST.FIPS.198-1 FIPS 180-4 Secure Hash Standard (SHS) August 2015 https://doi.org/10.6028/NIST.FIPS.180-4 FIPS 202 SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions August 2015 https://doi.org/10.6028/NIST.FIPS.202 SP 800-185 SHA-3 Derived Functions: cSHAKE, KMAC, TupleHash and ParallelHash December 2016 https://doi.org/10.6028/NIST.SP.800-185 SP 800-132 Recommendation for Password-Based Key Derivation Part 1: Storage Applications December 2010 https://doi.org/10.6028/NIST.SP.800-132 SP 800-108 Rev. 1 Recommendation for Key Derivation Using Pseudorandom Functions August 2022 https://doi.org/10.6028/NIST.SP.800-108r1-upd1 SP 800-56A Rev. 3 Recommendation for Pair-Wise Key-Establishment Schemes Using Discrete Logarithm Cryptography April 2018 https://doi.org/10.6028/NIST.SP.800-56Ar3 SP 800-56C Rev. 2 Recommendation for Key-Derivation Methods in Key-Establishment Schemes August 2020 https://doi.org/10.6028/NIST.SP.800-56Cr2 SP 800-135 Rev. 1 Recommendation for Existing Application-Specific Key Derivation Functions December 2011 https://doi.org/10.6028/NIST.SP.800-135r1 RFC 3526 More Modular Exponential (MODP) Diffie-Hellman groups for Intenet Key Exchange (IKE) May 2003 https://www.ietf.org/rfc/rfc3526.txt RFC 4253 Lightweight Directory Access Protocol (LDAP) Schema Definitions for X.509 Certificates June 2006 https://www.ietf.org/rfc/rfc4253.txt Junos® OS Evolved OpenSSL Cryptographic Module Version 3.0 FIPS 140-3 Non-Proprietary Security Policy HPE Juniper Networking o +1 408 745 2000 79 1133 Innovation Way f +1 408 745 2100 Sunnyvale, CA 94089 www.hpe.com RFC 6668 SHA-2 Data Integrity Verification for the Secure Shell (SSH) Transport Layer Protocol July 2012 https://www.ietf.org/rfc/rfc6668.txt RFC 7919 Negotiated Finite Field Diffie-Hellman Ephemeral Parameters for Transport Layer Security (TLS) August 2016 https://www.ietf.org/rfc/rfc7919.txt