SUSE Linux Enterprise Server libgcrypt Cryptographic Module

Certificate #3992

Webpage information

Status active
Validation dates 22.07.2021 , 28.11.2021
Sunset date 21-07-2026
Standard FIPS 140-2
Security level 1
Type Software
Embodiment Multi-Chip Stand Alone
Caveat When operated in FIPS mode and installed, initialized and configured as specified in section 9 of the Security Policy. The module generates cryptographic keys whose strengths are modified by available entropy.
Exceptions
  • Physical Security: N/A
Description SUSE Libgcrypt is a general purpose cryptographic library based on the code from GnuPG.
Tested configurations
  • SUSE Linux Enterprise Server 15 SP2 running on Dell EMC PowerEdge 640 with Intel Cascade Lake Xeon Gold 6234 with PAA
  • SUSE Linux Enterprise Server 15 SP2 running on Dell EMC PowerEdge 640 with Intel Cascade Lake Xeon Gold 6234 without PAA
  • SUSE Linux Enterprise Server 15 SP2 running on Gigabyte R181-T90 with Cavium ThunderX2 CN9975 ARMv8 with PAA
  • SUSE Linux Enterprise Server 15 SP2 running on Gigabyte R181-T90 with Cavium ThunderX2 CN9975 ARMv8 without PAA (single-user mode)
  • SUSE Linux Enterprise Server 15 SP2 running on IBM System Z/15 with IBM z15
Vendor SUSE, LLC
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Symmetric Algorithms
AES, AES-128, AES-192, AES-256, Serpent, CAST5, RC2, RC4, DES, Triple-DES, TDES, TDEA, ChaCha20, Salsa20, Poly1305, IDEA, Camellia, SEED, HMAC, HMAC-SHA-256, HMAC-SHA-224, HMAC-SHA-384, HMAC-SHA-512, CMAC
Asymmetric Algorithms
RSA 2048, ECDSA, EdDSA, DSA
Hash functions
SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, SHA3-224, SHA3-256, SHA3-384, SHA3-512, SHA-3, Blake2, MD4, MD5, Streebog, Whirpool, PBKDF, PBKDF2
Schemes
MAC, Key Exchange
Protocols
SSH, TLS, IKE
Randomness
DRBG, RNG
Libraries
libgcrypt
Elliptic Curves
P-256, P-384, P-521, P-224, P-192, Curve25519, Ed25519
Block cipher modes
ECB, CBC, CTR, OFB, GCM, CCM, XEX, XTS

Security level
level 1, Level 1
Side-channel analysis
Timing Attacks, timing attacks

Standards
FIPS 140-2, FIPS197, FIPS186-4, FIPS198-1, FIPS202, FIPS180-4, FIPS 186-4, FIPS PUB 140-2, SP 800-57, PKCS#1, RFC5246, RFC4253, RFC7296

File metadata

Title FIPS 140-2 Non-Proprietary Security Policy
Keywords FIPS 140-2
Author Traci Porter
Creation date D:20211123133519-06'00'
Pages 31
Creator Writer
Producer OpenOffice 4.1.10

Heuristics

No heuristics are available for this certificate.

References

No references are available for this certificate.

Updates Feed

  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 3992,
  "dgst": "94c8e9960b7d3483",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "SHS#A486",
        "DSA#A487",
        "DRBG#A1152",
        "RSA#A486",
        "RSA#A1152",
        "DRBG#A485",
        "SHA-3#A487",
        "AES#A482",
        "DSA#A486",
        "HMAC#A487",
        "SHS#A484",
        "HMAC#A484",
        "SHS#A1152",
        "AES#A1152",
        "HMAC#A488",
        "DRBG#A487",
        "SHS#A488",
        "DSA#A1152",
        "RSA#A485",
        "ECDSA#A486",
        "DRBG#A486",
        "HMAC#A486",
        "RSA#A487",
        "AES#A485",
        "DSA#A482",
        "RSA#A482",
        "HMAC#A485",
        "SHA-3#A482",
        "ECDSA#A487",
        "KTS#A1152",
        "KTS#A486",
        "HMAC#A482",
        "SHA-3#A1152",
        "Triple-DES#A482",
        "KTS#A482",
        "SHS#A482",
        "DRBG#A482",
        "ECDSA#A482",
        "DSA#A485",
        "HMAC#A1152",
        "KTS#A485",
        "AES#A486",
        "ECDSA#A1152",
        "ECDSA#A485",
        "SHS#A485"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "-"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECDSA": {
            "ECDSA": 24
          },
          "EdDSA": {
            "EdDSA": 2
          }
        },
        "FF": {
          "DSA": {
            "DSA": 29
          }
        },
        "RSA": {
          "RSA 2048": 1
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 3
        },
        "CCM": {
          "CCM": 3
        },
        "CTR": {
          "CTR": 3
        },
        "ECB": {
          "ECB": 5
        },
        "GCM": {
          "GCM": 4
        },
        "OFB": {
          "OFB": 2
        },
        "XEX": {
          "XEX": 1
        },
        "XTS": {
          "XTS": 7
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {
        "libgcrypt": {
          "libgcrypt": 39
        }
      },
      "crypto_protocol": {
        "IKE": {
          "IKE": 1
        },
        "SSH": {
          "SSH": 1
        },
        "TLS": {
          "TLS": {
            "TLS": 1
          }
        }
      },
      "crypto_scheme": {
        "KEX": {
          "Key Exchange": 1
        },
        "MAC": {
          "MAC": 7
        }
      },
      "device_model": {},
      "ecc_curve": {
        "Curve": {
          "Curve25519": 1
        },
        "Edwards": {
          "Ed25519": 1
        },
        "NIST": {
          "P-192": 4,
          "P-224": 6,
          "P-256": 8,
          "P-384": 6,
          "P-521": 6
        }
      },
      "eval_facility": {
        "atsec": {
          "atsec": 33
        }
      },
      "fips_cert_id": {},
      "fips_certlike": {
        "Certlike": {
          "AES-128": 1,
          "AES-192": 1,
          "AES-256": 1,
          "HMAC SHA-1 112": 1,
          "HMAC-SHA-1": 2,
          "HMAC-SHA-224": 2,
          "HMAC-SHA-256": 4,
          "HMAC-SHA-384": 2,
          "HMAC-SHA-512": 2,
          "PKCS#1": 3,
          "RSA 2048": 1,
          "RSA PKCS#1": 1,
          "SHA- 256": 1,
          "SHA-1": 15,
          "SHA-1 112": 1,
          "SHA-224": 18,
          "SHA-256": 28,
          "SHA-3": 2,
          "SHA-384": 18,
          "SHA-512": 13,
          "SHA-512 112": 1,
          "SHA-512 2048": 4,
          "SHA3-224": 3,
          "SHA3-256": 4,
          "SHA3-384": 4,
          "SHA3-512": 4
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 1,
          "level 1": 3
        }
      },
      "hash_function": {
        "BLAKE": {
          "Blake2": 2
        },
        "MD": {
          "MD4": {
            "MD4": 2
          },
          "MD5": {
            "MD5": 2
          }
        },
        "PBKDF": {
          "PBKDF": 8,
          "PBKDF2": 1
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 16
          },
          "SHA2": {
            "SHA-224": 18,
            "SHA-256": 28,
            "SHA-384": 18,
            "SHA-512": 18
          },
          "SHA3": {
            "SHA-3": 2,
            "SHA3-224": 3,
            "SHA3-256": 4,
            "SHA3-384": 4,
            "SHA3-512": 4
          }
        },
        "Streebog": {
          "Streebog": 1
        },
        "Whirpool": {
          "Whirpool": 2
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 24
        },
        "RNG": {
          "RNG": 2
        }
      },
      "side_channel_analysis": {
        "SCA": {
          "Timing Attacks": 2,
          "timing attacks": 1
        }
      },
      "standard_id": {
        "FIPS": {
          "FIPS 140-2": 42,
          "FIPS 186-4": 1,
          "FIPS PUB 140-2": 1,
          "FIPS180-4": 3,
          "FIPS186-4": 5,
          "FIPS197": 2,
          "FIPS198-1": 3,
          "FIPS202": 2
        },
        "NIST": {
          "SP 800-57": 1
        },
        "PKCS": {
          "PKCS#1": 2
        },
        "RFC": {
          "RFC4253": 1,
          "RFC5246": 1,
          "RFC7296": 1
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 31,
            "AES-128": 1,
            "AES-192": 1,
            "AES-256": 1
          },
          "CAST": {
            "CAST5": 2
          },
          "RC": {
            "RC2": 2,
            "RC4": 2
          },
          "Serpent": {
            "Serpent": 2
          }
        },
        "DES": {
          "3DES": {
            "TDEA": 1,
            "TDES": 1,
            "Triple-DES": 28
          },
          "DES": {
            "DES": 4
          }
        },
        "constructions": {
          "MAC": {
            "CMAC": 11,
            "HMAC": 20,
            "HMAC-SHA-224": 1,
            "HMAC-SHA-256": 2,
            "HMAC-SHA-384": 1,
            "HMAC-SHA-512": 1
          }
        },
        "djb": {
          "ChaCha": {
            "ChaCha20": 2
          },
          "Poly": {
            "Poly1305": 2
          },
          "Salsa": {
            "Salsa20": 2
          }
        },
        "miscellaneous": {
          "Camellia": {
            "Camellia": 2
          },
          "IDEA": {
            "IDEA": 1
          },
          "SEED": {
            "SEED": 2
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "Traci Porter",
      "/CreationDate": "D:20211123133519-06\u002700\u0027",
      "/Creator": "Writer",
      "/Keywords": "FIPS 140-2",
      "/Producer": "OpenOffice 4.1.10",
      "/Title": "FIPS 140-2 Non-Proprietary Security Policy",
      "pdf_file_size_bytes": 406021,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38c.pdf",
          "https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38a.pdf",
          "https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-132.pdf",
          "https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38e.pdf",
          "https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38d.pdf",
          "https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-4.pdf",
          "https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.202.pdf",
          "http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38e.pdf",
          "https://csrc.nist.gov/publications/fips/fips140-2/fips1402.pdf",
          "https://csrc.nist.gov/publications/fips/fips198-1/FIPS-198-1_final.pdf",
          "https://www.ietf.org/rfc/rfc3447.txt",
          "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-67r2.pdf",
          "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90Ar1.pdf",
          "https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf",
          "http://csrc.nist.gov/",
          "https://csrc.nist.gov/groups/STM/cmvp/documents/fips140-2/FIPS1402IG.pdf",
          "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38F.pdf",
          "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38b.pdf",
          "https://csrc.nist.gov/publications/fips/fips197/fips-197.pdf"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 31
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
    "module_download_ok": true,
    "module_extract_ok": true,
    "policy_convert_ok": true,
    "policy_download_ok": true,
    "policy_extract_ok": true,
    "policy_json_hash": null,
    "policy_pdf_hash": "972f4e42d15fde0265cb9eb91642bc7fd0b7ed108fe804cb9f3cb813064b0754",
    "policy_txt_hash": "e84f6889211138e117e2dc0b9281a524aa20b301f63207d36815c488d4e8c1ff"
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in FIPS mode and installed, initialized and configured as specified in section 9 of the Security Policy. The module generates cryptographic keys whose strengths are modified by available entropy.",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/July 2021_020821_0740_signed.pdf",
    "date_sunset": "2026-07-21",
    "description": "SUSE Libgcrypt is a general purpose cryptographic library based on the code from GnuPG.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Physical Security: N/A"
    ],
    "fw_versions": null,
    "historical_reason": null,
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {},
    "module_name": "SUSE Linux Enterprise Server libgcrypt Cryptographic Module",
    "module_type": "Software",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-2",
    "status": "active",
    "sw_versions": "3.1",
    "tested_conf": [
      "SUSE Linux Enterprise Server 15 SP2 running on Dell EMC PowerEdge 640 with Intel Cascade Lake Xeon Gold 6234 with PAA",
      "SUSE Linux Enterprise Server 15 SP2 running on Dell EMC PowerEdge 640 with Intel Cascade Lake Xeon Gold 6234 without PAA",
      "SUSE Linux Enterprise Server 15 SP2 running on Gigabyte R181-T90 with Cavium ThunderX2 CN9975 ARMv8 with PAA",
      "SUSE Linux Enterprise Server 15 SP2 running on Gigabyte R181-T90 with Cavium ThunderX2 CN9975 ARMv8 without PAA (single-user mode)",
      "SUSE Linux Enterprise Server 15 SP2 running on IBM System Z/15 with IBM z15"
    ],
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2021-07-22",
        "lab": "atsec information security corporation",
        "validation_type": "Initial"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2021-11-28",
        "lab": "atsec information security corporation",
        "validation_type": "Update"
      }
    ],
    "vendor": "SUSE, LLC",
    "vendor_url": "http://www.suse.com"
  }
}