Ubuntu 18.04 Strongswan Cryptographic Module

Certificate #3648

Webpage information

Status historical
Historical reason SP 800-56Arev3 transition
Validation dates 29.04.2020 , 30.11.2020 , 21.09.2021 , 18.10.2021
Standard FIPS 140-2
Security level 1
Type Software
Embodiment Multi-Chip Stand Alone
Caveat When operated in FIPS mode and installed, initialized and configured as specified in Section 9.1 of the Security Policy with module Ubuntu OpenSSL Cryptographic Module validated to FIPS 140-2 under Cert. #3622 operating in FIPS mode and with module Ubuntu Kernel Crypto API Cryptographic Module validated to FIPS140-2 under Cert. #3647 operating in FIPS mode
Exceptions
  • Physical Security: N/A
  • Mitigation of Other Attacks: N/A
Description Ubuntu 18.04 Strongswan Cryptographic Module provides cryptographic services for the Internet Key Exchange (IKE) protocol in the Ubuntu Operating System user space.
Tested configurations
  • Ubuntu 18.04 LTS 64-bit on IBM z/VM running on IBM z/14 with z14 with PAI [1]
  • Ubuntu 18.04 LTS 64-bit on IBM z/VM running on IBM z/14 with z14 without PAI [1] (single-user mode)
  • Ubuntu 18.04 LTS 64-bit running on Supermicro SYS-5018R-WR with Intel Xeon CPU E5-2620v3 with PAA [1][2]
  • Ubuntu 18.04 LTS 64-bit running on Supermicro SYS-5018R-WR with Intel Xeon CPU E5-2620v3 without PAA [1][2]
Vendor Canonical Ltd.
References

This certificate's webpage directly references 2 certificates, transitively this expands into 2 certificates.

Security policy

Symmetric Algorithms
AES, DES, Triple-DES, HMAC, HMAC-SHA-256, HMAC-SHA-384, HMAC-SHA-512
Asymmetric Algorithms
ECDSA, ECC, Diffie-Hellman, DSA
Hash functions
SHA-1, SHA-256, SHA-384, SHA-512, SHA-224
Schemes
MAC, Key Exchange, Key Agreement
Protocols
SSH, IKEv2, IKE
Randomness
DRBG, RNG
Libraries
OpenSSL
Elliptic Curves
P-224, P-256, P-384, P-521, P-512
Block cipher modes
CBC, CTR, GCM

Security level
Level 1, level 1

Standards
FIPS 140-2, FIPS140-2, FIPS PUB 140-2, RFC5282, RFC7296

File metadata

Title FIPS 140-2 Non-Proprietary Security Policy
Author Alejandro Fabio Masino
Creation date D:20210915192036+00'00'
Modification date D:20210915192036+00'00'
Pages 33
Creator Microsoft Word

References

Outgoing
  • 3647 - historical - Ubuntu 18.04 Kernel Crypto API Cryptographic Module
  • 3622 - historical - Ubuntu 18.04 OpenSSL Cryptographic Module

Heuristics

No heuristics are available for this certificate.

References

Loading...

Updates Feed

  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 3648,
  "dgst": "8d3e3fa0a4294fb5",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "HMAC#C688",
        "CVL#C753",
        "SHS#C766",
        "HMAC#C772",
        "SHS#C767",
        "CVL#C684",
        "AES#C678",
        "AES#C680",
        "HMAC#C768",
        "ECDSA#C687",
        "SHS#C684",
        "RSA#C685",
        "DRBG#C677",
        "HMAC#C685",
        "HMAC#C687",
        "SHS#C687",
        "AES#C670",
        "AES#C679",
        "CVL#C682",
        "SHS#C682",
        "HMAC#C766",
        "DRBG#C673",
        "SHS#C771",
        "RSA#C688",
        "DRBG#C670",
        "ECDSA#C688",
        "ECDSA#C685",
        "RSA#C683",
        "CVL#C683",
        "HMAC#C683",
        "RSA#C682",
        "DRBG#C688",
        "DRBG#C687",
        "AES#C692",
        "HMAC#C771",
        "HMAC#C755",
        "AES#C689",
        "SHS#C768",
        "AES#C672",
        "AES#C675",
        "AES#C674",
        "SHS#C688",
        "AES#C676",
        "CVL#C687",
        "RSA#C684",
        "ECDSA#C683",
        "CVL#C688",
        "SHS#C683",
        "AES#C688",
        "Triple-DES#C686",
        "RSA#C687",
        "HMAC#C767",
        "AES#C687",
        "Triple-DES#C669",
        "AES#C690",
        "AES#C677",
        "ECDSA#C684",
        "HMAC#C682",
        "CVL#C752",
        "SHS#C755",
        "AES#C671",
        "CVL#C685",
        "AES#C673",
        "HMAC#C684",
        "AES#C691",
        "SHS#C685",
        "ECDSA#C682",
        "SHS#C772"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "18.04"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": {
        "_type": "Set",
        "elements": [
          "3647",
          "3622"
        ]
      },
      "indirectly_referenced_by": null,
      "indirectly_referencing": {
        "_type": "Set",
        "elements": [
          "3647",
          "3622"
        ]
      }
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": [
        "3647",
        "3622"
      ]
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": {
        "_type": "Set",
        "elements": [
          "3647",
          "3622"
        ]
      },
      "indirectly_referenced_by": null,
      "indirectly_referencing": {
        "_type": "Set",
        "elements": [
          "3647",
          "3622"
        ]
      }
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": [
        "3647",
        "3622"
      ]
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 1
          },
          "ECDSA": {
            "ECDSA": 9
          }
        },
        "FF": {
          "DH": {
            "Diffie-Hellman": 25
          },
          "DSA": {
            "DSA": 1
          }
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 13
        },
        "CTR": {
          "CTR": 1
        },
        "GCM": {
          "GCM": 5
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {
        "OpenSSL": {
          "OpenSSL": 37
        }
      },
      "crypto_protocol": {
        "IKE": {
          "IKE": 3,
          "IKEv2": 44
        },
        "SSH": {
          "SSH": 1
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 2
        },
        "KEX": {
          "Key Exchange": 5
        },
        "MAC": {
          "MAC": 4
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-224": 10,
          "P-256": 12,
          "P-384": 12,
          "P-512": 1,
          "P-521": 10
        }
      },
      "eval_facility": {
        "atsec": {
          "atsec": 35
        }
      },
      "fips_cert_id": {
        "Cert": {
          "#3622": 2,
          "#3647": 2
        }
      },
      "fips_certlike": {
        "Certlike": {
          "Cert. AES": 1,
          "Cert. HMAC": 1,
          "HMAC SHA-1": 3,
          "HMAC SHA-256": 3,
          "HMAC SHA-384": 2,
          "HMAC SHA-512": 2,
          "HMAC-SHA-1": 4,
          "HMAC-SHA-256": 8,
          "HMAC-SHA-384": 2,
          "HMAC-SHA-512": 2,
          "SHA- 256": 6,
          "SHA- 384": 1,
          "SHA-1": 14,
          "SHA-224": 2,
          "SHA-256": 11,
          "SHA-384": 12,
          "SHA-512": 13
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 5,
          "level 1": 1
        }
      },
      "hash_function": {
        "SHA": {
          "SHA1": {
            "SHA-1": 14
          },
          "SHA2": {
            "SHA-224": 2,
            "SHA-256": 11,
            "SHA-384": 12,
            "SHA-512": 13
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 4
        },
        "RNG": {
          "RNG": 1
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-2": 47,
          "FIPS PUB 140-2": 1,
          "FIPS140-2": 1
        },
        "RFC": {
          "RFC5282": 2,
          "RFC7296": 2
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 9
          }
        },
        "DES": {
          "3DES": {
            "Triple-DES": 6
          },
          "DES": {
            "DES": 1
          }
        },
        "constructions": {
          "MAC": {
            "HMAC": 31,
            "HMAC-SHA-256": 4,
            "HMAC-SHA-384": 1,
            "HMAC-SHA-512": 1
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "Alejandro Fabio Masino",
      "/CreationDate": "D:20210915192036+00\u002700\u0027",
      "/Creator": "Microsoft Word",
      "/ModDate": "D:20210915192036+00\u002700\u0027",
      "/Title": "FIPS 140-2 Non-Proprietary Security Policy",
      "pdf_file_size_bytes": 607650,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "http://csrc.nist.gov/publications/fips/fips140-2/fips1402.pdf",
          "https://csrc.nist.gov/Projects/Cryptographic-Module-Validation-Program/Certificate/3622",
          "https://tools.ietf.org/html/rfc5282",
          "http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-135r1.pdf",
          "https://www.ubuntu.com/contact-us",
          "https://tools.ietf.org/html/rfc7296",
          "https://csrc.nist.gov/Projects/Cryptographic-Module-Validation-Program/Certificate/3647",
          "http://csrc.nist.gov/groups/STM/cmvp/documents/fips140-2/FIPS1402IG.pdf"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 33
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
    "module_download_ok": true,
    "module_extract_ok": true,
    "policy_convert_ok": true,
    "policy_download_ok": true,
    "policy_extract_ok": true,
    "policy_json_hash": null,
    "policy_pdf_hash": "a3798b5e4297debf2e3ccb205e44a40699a4aa66d548a0c112c8d49b726adc1a",
    "policy_txt_hash": "081319da46c4526bf54fdac464193ea962fd8ff7d4b7f3fcf8a8bb4bdbe2bbb5"
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in FIPS mode and installed, initialized and configured as specified in Section 9.1 of the Security Policy with module Ubuntu OpenSSL Cryptographic Module validated to FIPS 140-2 under Cert. #3622 operating in FIPS mode and with module Ubuntu Kernel Crypto API Cryptographic Module validated to FIPS140-2 under Cert. #3647 operating in FIPS mode",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/April 2020_010520_0717.pdf",
    "date_sunset": null,
    "description": "Ubuntu 18.04 Strongswan Cryptographic Module provides cryptographic services for the Internet Key Exchange (IKE) protocol in the Ubuntu Operating System user space.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Physical Security: N/A",
      "Mitigation of Other Attacks: N/A"
    ],
    "fw_versions": null,
    "historical_reason": "SP 800-56Arev3 transition",
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {
      "3622": 1,
      "3647": 1
    },
    "module_name": "Ubuntu 18.04 Strongswan Cryptographic Module",
    "module_type": "Software",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-2",
    "status": "historical",
    "sw_versions": "2.0 [1] and 2.1 [2]",
    "tested_conf": [
      "Ubuntu 18.04 LTS 64-bit on IBM z/VM running on IBM z/14 with z14 with PAI [1]",
      "Ubuntu 18.04 LTS 64-bit on IBM z/VM running on IBM z/14 with z14 without PAI [1] (single-user mode)",
      "Ubuntu 18.04 LTS 64-bit running on Supermicro SYS-5018R-WR with Intel Xeon CPU E5-2620v3 with PAA [1][2]",
      "Ubuntu 18.04 LTS 64-bit running on Supermicro SYS-5018R-WR with Intel Xeon CPU E5-2620v3 without PAA [1][2]"
    ],
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2020-04-29",
        "lab": "atsec information security corporation",
        "validation_type": "Initial"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2020-11-30",
        "lab": "atsec information security corporation",
        "validation_type": "Update"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2021-09-21",
        "lab": "atsec information security corporation",
        "validation_type": "Update"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2021-10-18",
        "lab": "atsec information security corporation",
        "validation_type": "Update"
      }
    ],
    "vendor": "Canonical Ltd.",
    "vendor_url": "http://www.canonical.com"
  }
}