Snowflake FIPS Provider

Certificate details

Certificate ID #4924
Status active
Validation dates 18.12.2024
Sunset date 10-07-2029
Standard FIPS 140-3
Security level 1
Type Software
Embodiment Multi-Chip Stand Alone
Caveat No assurance of the minimum strength of generated SSPs (e.g., keys).
Exceptions
  • Physical security: N/A
  • Non-invasive security: N/A
  • Life-cycle assurance: Level 3
Description The Snowflake FIPS Provider is a general-purpose cryptographic library incorporated into Snowflake platforms to provide FIPS 140-3 validated cryptography for the protection of sensitive information.
Vendor [email protected] /cdn-cgi/l/email-protection
Lab DEKRA Cybersecurity Certification Laboratory
Algorithms
  • AES-CBC-CS1A4481
  • AES-CBC-CS2A4481
  • AES-CBC-CS3A4481
  • AES-CBCA4481
  • AES-CCMA4481
  • AES-CFB128A4481
  • AES-CFB1A4481
  • AES-CFB8A4481
  • AES-CMACA4481
  • AES-CTRA4481
  • AES-ECBA4481
  • AES-GCMA4481
  • AES-GMACA4481
  • AES-KWA4481
  • AES-KWPA4481
  • AES-OFBA4481
  • AES-XTS Testing Revision 2.0A4481
  • Counter DRBGA4481
  • DSA KeyGen (FIPS186-4)A4481
  • DSA PQGGen (FIPS186-4)A4481
  • DSA PQGVer (FIPS186-4)A4481
  • DSA SigGen (FIPS186-4)A4481
  • DSA SigVer (FIPS186-4)A4481
  • ECDSA KeyGen (FIPS186-4)A4481
  • ECDSA KeyVer (FIPS186-4)A4481
  • ECDSA SigGen (FIPS186-4)A4481
  • ECDSA SigVer (FIPS186-4)A4481
  • EDDSA KeyGenA4481
  • EDDSA KeyVerA4481
  • EDDSA SigGenA4481
  • EDDSA SigVerA4481
  • Hash DRBGA4481
  • HMAC DRBGA4481
  • HMAC-SHA-1A4481
  • HMAC-SHA2-224A4481
  • HMAC-SHA2-256A4481
  • HMAC-SHA2-384A4481
  • HMAC-SHA2-512/224A4481
  • HMAC-SHA2-512/256A4481
  • HMAC-SHA2-512A4481
  • HMAC-SHA3-224A4481
  • HMAC-SHA3-256A4481
  • HMAC-SHA3-384A4481
  • HMAC-SHA3-512A4481
  • KAS-ECC CDH-Component SP800-56Ar3A4481
  • KAS-ECC-SSC Sp800-56Ar3A4481
  • KAS-FFC-SSC Sp800-56Ar3A4481
  • KAS-IFC-SSCA4481
  • KDA HKDF SP800-56Cr2A4481
  • KDA OneStep SP800-56Cr2A4481
  • KDA TwoStep SP800-56Cr2A4481
  • KDF ANS 9.42A4481
  • KDF ANS 9.63A4481
  • KDF SP800-108A4481
  • KDF SSHA4481
  • KMAC-128A4481
  • KMAC-256A4481
  • KTS-IFCA4481
  • PBKDFA4481
  • RSA KeyGen (FIPS186-4)A4481
  • RSA SigGen (FIPS186-4)A4481
  • RSA SigGen (FIPS186-5)A4481
  • RSA Signature PrimitiveA4481
  • RSA SigVer (FIPS186-4)A4481
  • RSA SigVer (FIPS186-5)A4481
  • Safe Primes Key GenerationA4481
  • Safe Primes Key VerificationA4481
  • SHA-1A4481
  • SHA2-224A4481
  • SHA2-256A4481
  • SHA2-384A4481
  • SHA2-512/224A4481
  • SHA2-512/256A4481
  • SHA2-512A4481
  • SHA3-224A4481
  • SHA3-256A4481
  • SHA3-384A4481
  • SHA3-512A4481
  • SHAKE-128A4481
  • SHAKE-256A4481
  • TLS v1.2 KDF RFC7627A4481
  • TLS v1.3 KDFA4481
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Extracted keywords

Symmetric Algorithms
AES, CAST, HMAC, KMAC, CMAC
Asymmetric Algorithms
ECDSA, EdDSA, ECC, DHE, DSA
Hash functions
SHA2, SHA3, SHAKE128, SHAKE256, PBKDF
Schemes
MAC, Key agreement, Key Agreement, AEAD
Protocols
SSH, SSHv2, TLS v1.2, TLS v1.3, TLS 1.3, TLS, TLS 1.2
Randomness
DRBG, RBG
Libraries
OpenSSL
Block cipher modes
ECB, CBC, CTR, OFB, GCM, CCM, XTS

JavaCard API constants
ED25519, ED448
Trusted Execution Environments
PSP, SSC

Security level
Level 1
Side-channel analysis
timing attacks

Automated analysis

Automated inference - use with caution

All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.

No automatically derived data are available in this section.

Cross-references

No references are available for this certificate.

Processing updates

Feed
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 4924,
  "dgst": "aab2ec504efcaee1",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "SHA2-512/224A4481",
        "AES-CFB1A4481",
        "ECDSA SigVer (FIPS186-4)A4481",
        "RSA SigVer (FIPS186-4)A4481",
        "SHA3-256A4481",
        "Hash DRBGA4481",
        "AES-CBCA4481",
        "SHA2-256A4481",
        "HMAC-SHA2-512A4481",
        "SHA3-512A4481",
        "DSA KeyGen (FIPS186-4)A4481",
        "PBKDFA4481",
        "ECDSA KeyGen (FIPS186-4)A4481",
        "KDF SP800-108A4481",
        "RSA SigGen (FIPS186-5)A4481",
        "HMAC-SHA3-256A4481",
        "KTS-IFCA4481",
        "SHA2-512/256A4481",
        "EDDSA SigGenA4481",
        "AES-CBC-CS2A4481",
        "TLS v1.3 KDFA4481",
        "Safe Primes Key GenerationA4481",
        "KDF ANS 9.63A4481",
        "AES-CBC-CS3A4481",
        "DSA PQGGen (FIPS186-4)A4481",
        "KAS-ECC CDH-Component SP800-56Ar3A4481",
        "KDF SSHA4481",
        "ECDSA KeyVer (FIPS186-4)A4481",
        "SHA2-224A4481",
        "AES-CFB8A4481",
        "AES-CFB128A4481",
        "KDA HKDF SP800-56Cr2A4481",
        "AES-CMACA4481",
        "KAS-IFC-SSCA4481",
        "DSA SigVer (FIPS186-4)A4481",
        "AES-GMACA4481",
        "HMAC-SHA2-256A4481",
        "SHA3-384A4481",
        "AES-CTRA4481",
        "AES-XTS Testing Revision 2.0A4481",
        "RSA SigGen (FIPS186-4)A4481",
        "HMAC-SHA2-512/224A4481",
        "SHA3-224A4481",
        "Counter DRBGA4481",
        "HMAC-SHA2-512/256A4481",
        "AES-ECBA4481",
        "HMAC-SHA3-224A4481",
        "SHAKE-128A4481",
        "DSA SigGen (FIPS186-4)A4481",
        "SHAKE-256A4481",
        "AES-GCMA4481",
        "KMAC-128A4481",
        "ECDSA SigGen (FIPS186-4)A4481",
        "AES-CCMA4481",
        "HMAC-SHA2-384A4481",
        "HMAC-SHA3-384A4481",
        "AES-OFBA4481",
        "AES-KWA4481",
        "EDDSA KeyVerA4481",
        "HMAC-SHA-1A4481",
        "KDA OneStep SP800-56Cr2A4481",
        "AES-KWPA4481",
        "#A4481",
        "DSA PQGVer (FIPS186-4)A4481",
        "AES-CBC-CS1A4481",
        "EDDSA KeyGenA4481",
        "RSA KeyGen (FIPS186-4)A4481",
        "KAS-ECC-SSC Sp800-56Ar3A4481",
        "SHA2-512A4481",
        "RSA Signature PrimitiveA4481",
        "SHA2-384A4481",
        "KAS-FFC-SSC Sp800-56Ar3A4481",
        "KDF ANS 9.42A4481",
        "KDA TwoStep SP800-56Cr2A4481",
        "TLS v1.2 KDF RFC7627A4481",
        "SHA-1A4481",
        "RSA SigVer (FIPS186-5)A4481",
        "Safe Primes Key VerificationA4481",
        "HMAC-SHA3-512A4481",
        "EDDSA SigVerA4481",
        "KMAC-256A4481",
        "HMAC-SHA2-224A4481",
        "HMAC DRBGA4481"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "-"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "br1_deviations": 0,
    "br1_tables": {
      "_type": "sec_certs.heuristics.br1.table_parsing.model.br1_tables.BR1Tables",
      "approved_algorithms": {
        "entries": [
          {
            "algorithm": "AES - CBC",
            "cavpCertName": "A4481",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800 - 38A"
          },
          {
            "algorithm": "AES - CBC - CS1",
            "cavpCertName": "A4481",
            "properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256",
            "reference": "SP 800 - 38A"
          },
          {
            "algorithm": "AES - CBC - CS2",
            "cavpCertName": "A4481",
            "properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256",
            "reference": "SP 800 - 38A"
          },
          {
            "algorithm": "AES - CBC - CS3",
            "cavpCertName": "A4481",
            "properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256",
            "reference": "SP 800 - 38A"
          },
          {
            "algorithm": "AES - CCM",
            "cavpCertName": "A4481",
            "properties": "Key Length - 128, 192, 256",
            "reference": "SP 800 - 38C"
          },
          {
            "algorithm": "AES - CFB1",
            "cavpCertName": "A4481",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800 - 38A"
          },
          {
            "algorithm": "AES - CFB128",
            "cavpCertName": "A4481",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800 - 38A"
          },
          {
            "algorithm": "AES - CFB8",
            "cavpCertName": "A4481",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800 - 38A"
          },
          {
            "algorithm": "AES - CTR",
            "cavpCertName": "A4481",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800 - 38A"
          },
          {
            "algorithm": "AES - ECB",
            "cavpCertName": "A4481",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800 - 38A"
          },
          {
            "algorithm": "AES - GCM",
            "cavpCertName": "A4481",
            "properties": "Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256",
            "reference": "SP 800 - 38D"
          },
          {
            "algorithm": "AES - KW",
            "cavpCertName": "A4481",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800 - 38F"
          },
          {
            "algorithm": "AES - KWP",
            "cavpCertName": "A4481",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800 - 38F"
          },
          {
            "algorithm": "AES - OFB",
            "cavpCertName": "A4481",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800 - 38A"
          },
          {
            "algorithm": "AES - XTS Testing Revision 2.0",
            "cavpCertName": "A4481",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 256",
            "reference": "SP 800 - 38E"
          },
          {
            "algorithm": "KAS - ECC CDH - Component SP800 - 56Ar3 (CVL)",
            "cavpCertName": "A4481",
            "properties": "Curve - B - 233, B - 283, B - 409, B - 571, K - 233, K - 283, K - 409, K - 571, P - 224, P - 256, P - 384, P - 521",
            "reference": "SP 800 - 56A Rev. 3"
          },
          {
            "algorithm": "KAS - ECC - SSC Sp800 - 56Ar3",
            "cavpCertName": "A4481",
            "properties": "Domain Parameter Generation Methods - B - 233, B - 283, B - 409, B - 571, K - 233, K - 283, K - 409, K - 571, P - 224, P - 256, P - 384, P - 521 Scheme - ephemeralUnified - KAS Role - initiator, responder",
            "reference": "SP 800 - 56A Rev. 3"
          },
          {
            "algorithm": "KAS - FFC - SSC Sp800 - 56Ar3",
            "cavpCertName": "A4481",
            "properties": "Domain Parameter Generation Methods - FB, FC, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, modp - 2048, modp - 3072, modp - 4096, modp - 6144, modp - 8192 Scheme - dhEphem - KAS Role - initiator, responder",
            "reference": "SP 800 - 56A Rev. 3"
          },
          {
            "algorithm": "KAS - IFC - SSC",
            "cavpCertName": "A4481",
            "properties": "Modulo - 2048, 3072, 4096, 6144, 8192 Key Generation Methods - rsakpg1 - basic, rsakpg1 - crt, rsakpg1 - prime - factor, rsakpg2 - basic, rsakpg2 - crt, rsakpg2 - prime - factor Scheme - KAS1 - KAS Role - initiator, responder KAS2 - KAS Role - initiator, responder",
            "reference": "SP 800 - 56A Rev. 3"
          },
          {
            "algorithm": "KDA HKDF SP800 - 56Cr2",
            "cavpCertName": "A4481",
            "properties": "Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224 - 8192 Increment 8 HMAC Algorithm - SHA - 1, SHA2 - 224, SHA2 - 256, SHA2 - 384, SHA2 - 512, SHA2 - 512/224, SHA2 - 512/256, SHA3 - 224, SHA3 - 256, SHA3 - 384, SHA3 - 512",
            "reference": "SP 800 - 56C Rev. 2"
          },
          {
            "algorithm": "KDA OneStep SP800 - 56Cr2",
            "cavpCertName": "A4481",
            "properties": "Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224 - 8192 Increment 8",
            "reference": "SP 800 - 56C Rev. 2"
          },
          {
            "algorithm": "KDA TwoStep SP800 - 56Cr2",
            "cavpCertName": "A4481",
            "properties": "MAC Salting Methods - default, random KDF Mode - feedback Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224 - 8192 Increment 8",
            "reference": "SP 800 - 56C Rev. 2"
          },
          {
            "algorithm": "KDF ANS 9.42 (CVL)",
            "cavpCertName": "A4481",
            "properties": "KDF Type - DER Hash Algorithm - SHA - 1, SHA2 - 224, SHA2 - 256, SHA2 - 384, SHA2 - 512, SHA2 - 512/224, SHA2 - 512/256, SHA3 - 224, SHA3 - 256, SHA3 - 384, SHA3 - 512 Key Data Length - Key Data Length: 8 - 4096 Increment 8",
            "reference": "SP 800 - 135 Rev. 1"
          },
          {
            "algorithm": "KDF ANS 9.63 (CVL)",
            "cavpCertName": "A4481",
            "properties": "Hash Algorithm - SHA2 - 224, SHA2 - 256, SHA2 - 384, SHA2 - 512 Key Data Length - Key Data Length: 128, 4096",
            "reference": "SP 800 - 135 Rev. 1"
          },
          {
            "algorithm": "KDF SP800 - 108",
            "cavpCertName": "A4481",
            "properties": "KDF Mode - Counter, Feedback Supported Lengths - Supported Lengths: 8, 72, 128, 776, 3456, 4096",
            "reference": "SP 800 - 108 Rev. 1"
          },
          {
            "algorithm": "KDF SSH (CVL)",
            "cavpCertName": "A4481",
            "properties": "Cipher - AES - 128, AES - 192, AES - 256 Hash Algorithm - SHA - 1, SHA2 - 224, SHA2 - 256, SHA2 - 384, SHA2 - 512",
            "reference": "SP 800 - 135 Rev. 1"
          },
          {
            "algorithm": "PBKDF",
            "cavpCertName": "A4481",
            "properties": "Iteration Count - Iteration Count: 1 - 10000 Increment 1 Password Length - Password Length: 8 - 128 Increment 8",
            "reference": "SP 800 - 132"
          },
          {
            "algorithm": "TLS v1.2 KDF RFC7627 (CVL)",
            "cavpCertName": "A4481",
            "properties": "Hash Algorithm - SHA2 - 256, SHA2 - 384, SHA2 - 512",
            "reference": "SP 800 - 135 Rev. 1"
          },
          {
            "algorithm": "TLS v1.3 KDF (CVL)",
            "cavpCertName": "A4481",
            "properties": "HMAC Algorithm - SHA2 - 256, SHA2 - 384 KDF Running Modes - DHE, PSK, PSK - DHE",
            "reference": "SP 800 - 135 Rev. 1"
          },
          {
            "algorithm": "DSA KeyGen (FIPS186 - 4)",
            "cavpCertName": "A4481",
            "properties": "L - 2048, 3072 N - 224, 256",
            "reference": "FIPS 186 - 4"
          },
          {
            "algorithm": "DSA PQGGen (FIPS186 - 4)",
            "cavpCertName": "A4481",
            "properties": "L - 2048, 3072 N - 224, 256 Hash Algorithm - SHA2 - 224, SHA2 - 256, SHA2 - 384, SHA2 - 512, SHA2 - 512/224, SHA2 - 512/256",
            "reference": "FIPS 186 - 4"
          },
          {
            "algorithm": "DSA PQGVer (FIPS186 - 4)",
            "cavpCertName": "A4481",
            "properties": "L - 1024, 2048, 3072 N - 160, 224, 256 Hash Algorithm - SHA - 1, SHA2 - 224, SHA2 - 256, SHA2 - 384, SHA2 - 512, SHA2 - 512/224, SHA2 - 512/256",
            "reference": "FIPS 186 - 4"
          },
          {
            "algorithm": "ECDSA KeyGen (FIPS186 - 4)",
            "cavpCertName": "A4481",
            "properties": "Curve - B - 233, B - 283, B - 409, B - 571, K - 233, K - 283, K - 409, K - 571, P - 224, P - 256, P - 384, P - 521 Secret Generation Mode - Testing Candidates",
            "reference": "FIPS 186 - 4"
          },
          {
            "algorithm": "ECDSA KeyVer (FIPS186 - 4)",
            "cavpCertName": "A4481",
            "properties": "Curve - B - 163, B - 233, B - 283, B - 409, B - 571, K - 163, K - 233, K - 283, K - 409, K - 571, P - 192, P - 224, P - 256, P - 384, P - 521",
            "reference": "FIPS 186 - 4"
          },
          {
            "algorithm": "EDDSA KeyGen",
            "cavpCertName": "A4481",
            "properties": "Curve - ED - 25519, ED - 448",
            "reference": "FIPS 186 - 5"
          },
          {
            "algorithm": "EDDSA KeyVer",
            "cavpCertName": "A4481",
            "properties": "Curve - ED - 25519, ED - 448",
            "reference": "FIPS 186 - 5"
          },
          {
            "algorithm": "Safe Primes Key Generation",
            "cavpCertName": "A4481",
            "properties": "Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, modp - 2048, modp - 3072, modp - 4096, modp - 6144, modp - 8192",
            "reference": "SP 800 - 56A Rev. 3"
          },
          {
            "algorithm": "Safe Primes Key Verification",
            "cavpCertName": "A4481",
            "properties": "Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, modp - 2048, modp - 3072, modp - 4096, modp - 6144, modp - 8192",
            "reference": "SP 800 - 56A Rev. 3"
          },
          {
            "algorithm": "RSA KeyGen (FIPS186 - 4)",
            "cavpCertName": "A4481",
            "properties": "Key Generation Mode - B.3.3 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Private Key Format - Standard",
            "reference": "FIPS 186 - 4"
          },
          {
            "algorithm": "KTS - IFC",
            "cavpCertName": "A4481",
            "properties": "Modulo - 2048, 3072, 4096, 6144 Key Generation Methods - rsakpg1 - basic, rsakpg1 - crt, rsakpg1 - prime - factor, rsakpg2 - basic, rsakpg2 - crt, rsakpg2 - prime - factor Scheme - KTS - OAEP - basic - KAS Role - initiator, responder Key Transport Method - Key Length - 1024",
            "reference": "SP 800 - 56B Rev. 2"
          },
          {
            "algorithm": "AES - CMAC",
            "cavpCertName": "A4481",
            "properties": "Direction - Generation, Verification Key Length - 128, 192, 256",
            "reference": "SP 800 - 38B"
          },
          {
            "algorithm": "AES - GMAC",
            "cavpCertName": "A4481",
            "properties": "Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256",
            "reference": "SP 800 - 38D"
          },
          {
            "algorithm": "HMAC - SHA - 1",
            "cavpCertName": "A4481",
            "properties": "Key Length - Key Length: 112 - 2048 Increment 8",
            "reference": "FIPS 198 - 1"
          },
          {
            "algorithm": "HMAC - SHA2 - 224",
            "cavpCertName": "A4481",
            "properties": "Key Length - Key Length: 112 - 2048 Increment 8",
            "reference": "FIPS 198 - 1"
          },
          {
            "algorithm": "HMAC - SHA2 - 256",
            "cavpCertName": "A4481",
            "properties": "Key Length - Key Length: 112 - 2048 Increment 8",
            "reference": "FIPS 198 - 1"
          },
          {
            "algorithm": "HMAC - SHA2 - 384",
            "cavpCertName": "A4481",
            "properties": "Key Length - Key Length: 112 - 2048 Increment 8",
            "reference": "FIPS 198 - 1"
          },
          {
            "algorithm": "HMAC - SHA2 - 512",
            "cavpCertName": "A4481",
            "properties": "Key Length - Key Length: 112 - 2048 Increment 8",
            "reference": "FIPS 198 - 1"
          },
          {
            "algorithm": "HMAC - SHA2 - 512/224",
            "cavpCertName": "A4481",
            "properties": "Key Length - Key Length: 112 - 2048 Increment 8",
            "reference": "FIPS 198 - 1"
          },
          {
            "algorithm": "HMAC - SHA2 - 512/256",
            "cavpCertName": "A4481",
            "properties": "Key Length - Key Length: 112 - 2048 Increment 8",
            "reference": "FIPS 198 - 1"
          },
          {
            "algorithm": "HMAC - SHA3 - 224",
            "cavpCertName": "A4481",
            "properties": "Key Length - Key Length: 112 - 2048 Increment 8",
            "reference": "FIPS 198 - 1"
          },
          {
            "algorithm": "HMAC - SHA3 - 256",
            "cavpCertName": "A4481",
            "properties": "Key Length - Key Length: 112 - 2048 Increment 8",
            "reference": "FIPS 198 - 1"
          },
          {
            "algorithm": "HMAC - SHA3 - 384",
            "cavpCertName": "A4481",
            "properties": "Key Length - Key Length: 112 - 2048 Increment 8",
            "reference": "FIPS 198 - 1"
          },
          {
            "algorithm": "HMAC - SHA3 - 512",
            "cavpCertName": "A4481",
            "properties": "Key Length - Key Length: 112 - 2048 Increment 8",
            "reference": "FIPS 198 - 1"
          },
          {
            "algorithm": "KMAC - 128",
            "cavpCertName": "A4481",
            "properties": "Message Length - Message Length: 0 - 65536 Increment 8 Key Data Length - Key Data Length: 128 - 1024 Increment",
            "reference": "SP 800 - 185"
          },
          {
            "algorithm": "KMAC - 256",
            "cavpCertName": "A4481",
            "properties": "Message Length - Message Length: 0 - 65536 Increment 8 Key Data Length - Key Data Length: 128 - 1024 Increment",
            "reference": "SP 800 - 185"
          },
          {
            "algorithm": "SHA - 1",
            "cavpCertName": "A4481",
            "properties": "Message Length - Message Length: 0 - 65528 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180 - 4"
          },
          {
            "algorithm": "SHA2 - 224",
            "cavpCertName": "A4481",
            "properties": "Message Length - Message Length: 0 - 65528 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180 - 4"
          },
          {
            "algorithm": "SHA2 - 256",
            "cavpCertName": "A4481",
            "properties": "Message Length - Message Length: 0 - 65528 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180 - 4"
          },
          {
            "algorithm": "SHA2 - 384",
            "cavpCertName": "A4481",
            "properties": "Message Length - Message Length: 0 - 65528 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180 - 4"
          },
          {
            "algorithm": "SHA2 - 512",
            "cavpCertName": "A4481",
            "properties": "Message Length - Message Length: 0 - 65528 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180 - 4"
          },
          {
            "algorithm": "SHA2 - 512/224",
            "cavpCertName": "A4481",
            "properties": "Message Length - Message Length: 0 - 65528 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180 - 4"
          },
          {
            "algorithm": "SHA2 - 512/256",
            "cavpCertName": "A4481",
            "properties": "Message Length - Message Length: 0 - 65528 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 180 - 4"
          },
          {
            "algorithm": "SHA3 - 224",
            "cavpCertName": "A4481",
            "properties": "Message Length - Message Length: 0 - 65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3 - 256",
            "cavpCertName": "A4481",
            "properties": "Message Length - Message Length: 0 - 65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3 - 384",
            "cavpCertName": "A4481",
            "properties": "Message Length - Message Length: 0 - 65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHA3 - 512",
            "cavpCertName": "A4481",
            "properties": "Message Length - Message Length: 0 - 65536 Increment 8 Large Message Sizes - 1, 2, 4, 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "SHAKE - 128",
            "cavpCertName": "A4481",
            "properties": "Output Length - Output Length: 16 - 65536 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "Algorithm",
            "cavpCertName": "CAVP Cert Properties",
            "properties": "CAVP Cert Properties",
            "reference": "Reference"
          },
          {
            "algorithm": "SHAKE - 256",
            "cavpCertName": "A4481",
            "properties": "Output Length - Output Length: 16 - 65536 Increment 8",
            "reference": "FIPS 202"
          },
          {
            "algorithm": "Counter DRBG",
            "cavpCertName": "A4481",
            "properties": "Prediction Resistance - Yes Mode - AES - 128, AES - 192, AES - 256 Derivation Function Enabled - No, Yes",
            "reference": "SP 800 - 90A Rev. 1"
          },
          {
            "algorithm": "Hash DRBG",
            "cavpCertName": "A4481",
            "properties": "Prediction Resistance - Yes Mode - SHA - 1, SHA2 - 224, SHA2 - 256, SHA2 - 384, SHA2 - 512, SHA2 - 512/224, SHA2 - 512/256",
            "reference": "SP 800 - 90A Rev. 1"
          },
          {
            "algorithm": "HMAC DRBG",
            "cavpCertName": "A4481",
            "properties": "Prediction Resistance - Yes Mode - SHA - 1, SHA2 - 224, SHA2 - 256, SHA2 - 384, SHA2 - 512, SHA2 - 512/224, SHA2 - 512/256",
            "reference": "SP 800 - 90A Rev. 1"
          },
          {
            "algorithm": "ECDSA SigGen (FIPS186 - 4)",
            "cavpCertName": "A4481",
            "properties": "Component - No, Yes Curve - B - 233, B - 283, B - 409, B - 571, K - 233, K - 283, K - 409, K - 571, P - 224, P - 256, P - 384, P - 521 Hash Algorithm - SHA2 - 224, SHA2 - 256, SHA2 - 384, SHA2 - 512, SHA2 - 512/224, SHA2 - 512/256",
            "reference": "FIPS 186 - 4"
          },
          {
            "algorithm": "ECDSA SigVer (FIPS186 - 4)",
            "cavpCertName": "A4481",
            "properties": "Component - No Curve - B - 163, B - 233, B - 283, B - 409, B - 571, K - 163, K - 233, K - 283, K - 409, K - 571, P - 192, P - 224, P - 256, P - 384, P - 521 Hash Algorithm - SHA - 1, SHA2 - 224, SHA2 - 256, SHA2 - 384, SHA2 - 512, SHA2 - 512/224, SHA2 - 512/256",
            "reference": "FIPS 186 - 4"
          },
          {
            "algorithm": "DSA SigGen (FIPS186 - 4)",
            "cavpCertName": "A4481",
            "properties": "L - 2048, 3072 N - 224, 256 Hash Algorithm - SHA2 - 224, SHA2 - 256, SHA2 - 384, SHA2 - 512, SHA2 - 512/224, SHA2 - 512/256",
            "reference": "FIPS 186 - 4"
          },
          {
            "algorithm": "DSA SigVer (FIPS186 - 4)",
            "cavpCertName": "A4481",
            "properties": "L - 1024, 2048, 3072 N - 160, 224, 256 Hash Algorithm - SHA - 1, SHA2 - 224, SHA2 - 256, SHA2 - 384, SHA2 - 512, SHA2 - 512/224, SHA2 - 512/256",
            "reference": "FIPS 186 - 4"
          },
          {
            "algorithm": "EDDSA SigGen",
            "cavpCertName": "A4481",
            "properties": "Curve - ED - 25519, ED - 448",
            "reference": "FIPS 186 - 5"
          },
          {
            "algorithm": "EDDSA SigVer",
            "cavpCertName": "A4481",
            "properties": "Curve - ED - 25519, ED - 448",
            "reference": "FIPS 186 - 5"
          },
          {
            "algorithm": "RSA SigGen (FIPS186 - 4)",
            "cavpCertName": "A4481",
            "properties": "Signature Type - ANSI X9.31, PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096",
            "reference": "FIPS 186 - 4"
          },
          {
            "algorithm": "RSA SigGen (FIPS186 - 5)",
            "cavpCertName": "A4481",
            "properties": "Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pss",
            "reference": "FIPS 186 - 5"
          },
          {
            "algorithm": "RSA Signature Primitive (CVL)",
            "cavpCertName": "A4481",
            "properties": "Private Key Format - crt",
            "reference": "FIPS 186 - 4"
          },
          {
            "algorithm": "RSA SigVer (FIPS186 - 4)",
            "cavpCertName": "A4481",
            "properties": "Signature Type - ANSI X9.31, PKCS 1.5, PKCSPSS Modulo - 1024, 2048, 3072, 4096",
            "reference": "FIPS 186 - 4"
          },
          {
            "algorithm": "RSA SigVer (FIPS186 - 5)",
            "cavpCertName": "A4481",
            "properties": "Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pss",
            "reference": "FIPS 186 - 5"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "approved_services": {
        "entries": [
          {
            "description": "Encrypt or decrypt data, including AEAD modes (CCM, GCM).",
            "indicator": "FIPS_OK",
            "inputs": "Encryption or decryption key; plaintext or ciphertext data; flags.",
            "name": "Cipher",
            "outputs": "Status return. Plaintext or ciphertext data.",
            "rolesSspAccess": "CO - SC_EDK_AES: W,E - SC_EDK_XTS: W,E",
            "secFunImpl": "Cipher (Unauth) Cipher (Auth)"
          },
          {
            "description": "Reports information on the requested capabilities.",
            "indicator": "FIPS_OK",
            "inputs": "Provider context, capability, callback pointer and arguments.",
            "name": "Get capabilities",
            "outputs": "Description of capabilities.",
            "rolesSspAccess": "",
            "secFunImpl": ""
          },
          {
            "description": "Module initialization, including instantiation of the opaque (managed within the",
            "indicator": "FIPS_OK",
            "inputs": "Core handle, dispatch in and out, provider context.",
            "name": "Initialize",
            "outputs": "Initialization status (1 = pass, 0 = fail).",
            "rolesSspAccess": "CO - DRBG_EI: W,E,Z - DRBG_Seed: G,E,Z",
            "secFunImpl": "Random MAC HMAC"
          },
          {
            "description": "module) Counter DRBG instance.",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "- DRBG_Key: G,W,E - DRBG_V: G,W,E",
            "secFunImpl": ""
          },
          {
            "description": "Perform key agreement primitives on behalf of the calling process (does not establish keys into the module).",
            "indicator": "FIPS_OK",
            "inputs": "Key structs (key agreement keys); flags.",
            "name": "Key agreement",
            "outputs": "Status return; key agreement shared secret.",
            "rolesSspAccess": "CO - KAS_Private_ECC: W,E - KAS_Public_ECC: W,E - KAS_Private_FFC: W,E - KAS_Public_FFC: W,E - KAS_Private_IFC: W,E - KAS_Public_IFC: W,E - KAS_SS_ECC: G,R - KAS_SS_FFC: G,R - KAS_SS_IFC: G,R",
            "secFunImpl": "CKG Section 5 Key agreement"
          },
          {
            "description": "Derive keying material from a shared secret.",
            "indicator": "FIPS_OK",
            "inputs": "Key agreement shared secret; flags.",
            "name": "Key derivation",
            "outputs": "Status return; derived keying material.",
            "rolesSspAccess": "CO - KD_DKM_KDF: G,R - KD_PW_PBKDF: W,E - KD_DKM_PBKDF: G,R - KD_SK: W,E",
            "secFunImpl": "Key derivation CKG Section 6.2"
          },
          {
            "description": "Generate asymmetric key pairs.",
            "indicator": "FIPS_OK",
            "inputs": "ECDSA, EdDSA: curve identifier. DSA, RSA: domain parameter targets.",
            "name": "Key management",
            "outputs": "Status return; general digital signature private and public keys.",
            "rolesSspAccess": "CO - DRBG_C: G,W,E - DRBG_Key: W,G,E - DRBG_V: W,G,E - GKP_Private_ECC: G,R - GKP_Public_ECC: G,R - GKP_Private_Edwards: G,R - GKP_Public_Edwards: G,R - GKP_Private_FFC: G,R - GKP_Public_FFC: G,R - GKP_Private_IFC: G,R - GKP_Public_IFC: G,R",
            "secFunImpl": "Key management ECC Key management Edwards Key management FFC Key management IFC CKG Section 4"
          },
          {
            "description": "Encapsulate or decapsulate key material on behalf of the calling process.",
            "indicator": "FIPS_OK",
            "inputs": "Key encapsulation/decapsulation key or Key wrap/unwrap key.",
            "name": "Key transport",
            "outputs": "Status return; key transport shared secret.",
            "rolesSspAccess": "CO - KTS_KDK_IFC: W,E - KTS_KEK_IFC: W,E - KTS_SS_IFC: G,R",
            "secFunImpl": "CKG Section 5 Key transport KTS (Cipher w/ CMAC, GMAC, HMAC, KMAC)"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "",
            "secFunImpl": "KTS (AES KW, KWP)"
          },
          {
            "description": "Generate or verify data integrity.",
            "indicator": "FIPS_OK",
            "inputs": "Keyed hash key.",
            "name": "Message authentication",
            "outputs": "Status return; MAC output value.",
            "rolesSspAccess": "CO - KH_Key_AES - CMAC: W,E - KH_Key_AES - GMAC: W,E - KH_Key_HMAC: W,E - KH_Key_KMAC: W,E",
            "secFunImpl": "MAC AES (CMAC, GMAC) MAC HMAC MAC KMAC (XOF)"
          },
          {
            "description": "Generate a message digest.",
            "indicator": "FIPS_OK",
            "inputs": "Message; flags.",
            "name": "Message digest",
            "outputs": "Status return; Hash output value.",
            "rolesSspAccess": "",
            "secFunImpl": "Message Digest Message Digest (XOF SHAKE)"
          },
          {
            "description": "Report available crypto operations.",
            "indicator": "FIPS_OK",
            "inputs": "Provider context, operation ID.",
            "name": "Query",
            "outputs": "Array of available operations.",
            "rolesSspAccess": "",
            "secFunImpl": ""
          },
          {
            "description": "Generate random bits using the DRBG.",
            "indicator": "FIPS_OK",
            "inputs": "DRBG struct (RBG State); DRBG_Seed.",
            "name": "Random",
            "outputs": "Status return; Random value.",
            "rolesSspAccess": "CO - DRBG_C: W,E - DRBG_EI: W,E,Z - DRBG_Seed: G,E,Z - DRBG_Key: W,E - DRBG_V: W,E",
            "secFunImpl": "Random CKG Section 4"
          },
          {
            "description": "Perform the self - test sequence.",
            "indicator": "FIPS_OK",
            "inputs": "Provider context.",
            "name": "Self - test",
            "outputs": "Status (1 = pass, 0 = fail).",
            "rolesSspAccess": "",
            "secFunImpl": ""
          },
          {
            "description": "Return module name and versioning information.",
            "indicator": "FIPS_OK",
            "inputs": "Provider context, parameter types (array).",
            "name": "Show module name and versioning information",
            "outputs": "Parameter types (array) with: Name, Version.",
            "rolesSspAccess": "",
            "secFunImpl": ""
          },
          {
            "description": "OpenSSL core metadata (Gettable parameters; Get parameters).",
            "indicator": "FIPS_OK",
            "inputs": "Provider context, parameter types (array).",
            "name": "Show status",
            "outputs": "Parameter types with: BuildInfo, Status, SecurityChecks; Status return.",
            "rolesSspAccess": "",
            "secFunImpl": ""
          },
          {
            "description": "Generate or verify digital signatures. (SSPs are passed in by the calling process.)",
            "indicator": "FIPS_OK",
            "inputs": "Sign: signing key; message. Verify: signature value; flags; sizes.",
            "name": "Signature",
            "outputs": "Status return; Signature value.",
            "rolesSspAccess": "CO - DS_SGK_ECC: W,E - DS_SVK_ECC: W,E - DS_SGK_Edwards: W,E - DS_SVK_Edwards: W,E - DS_SGK_FFC: W,E",
            "secFunImpl": "CKG Section 5 Signature DSA Signature ECDSA Signature EDDSA Signature RSA"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "- DS_SVK_FFC: W,E - DS_SGK_IFC: W,E - DS_SVK_IFC: W,E",
            "secFunImpl": ""
          },
          {
            "description": "Uninstantiate the module; zeroizes internal CTR DRBG state (DRBG_Key, DRBG_V).",
            "indicator": "FIPS_OK",
            "inputs": "Provider context.",
            "name": "Teardown",
            "outputs": "None.",
            "rolesSspAccess": "CO - DRBG_Key: Z - DRBG_V: Z",
            "secFunImpl": ""
          },
          {
            "description": "Zeroization of allocated key structures using openssl_cleanse.",
            "indicator": "FIPS_OK",
            "inputs": "Memory pointer.",
            "name": "Zeroize",
            "outputs": "Void.",
            "rolesSspAccess": "CO - DRBG_C: Z - DRBG_EI: Z - DRBG_Key: Z - DRBG_Seed: Z - DRBG_V: Z - DS_SGK_ECC: Z - DS_SGK_Edwards: Z - DS_SGK_FFC: Z - DS_SGK_IFC: Z - DS_SVK_ECC: Z - DS_SVK_Edwards: Z - DS_SVK_FFC: Z - DS_SVK_IFC: Z - GKP_Private_ECC: Z - GKP_Private_Edwards: Z - GKP_Private_FFC: Z - GKP_Private_IFC: Z - GKP_Public_ECC: Z - GKP_Public_Edwards: Z - GKP_Public_FFC: Z - GKP_Public_IFC: Z - KAS_Private_ECC: Z - KAS_Private_FFC: Z - GKP_Private_ECC: Z - KAS_Private_IFC: Z - KAS_Public_ECC: Z - KAS_Public_FFC: Z - KAS_Public_IFC: Z",
            "secFunImpl": ""
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "- KAS_SS_ECC: Z - KD_DKM_KDF: Z - KD_DKM_PBKDF: Z - KD_SK: Z - KH_Key_AES - CMAC: Z - KH_Key_AES - GMAC: Z - KH_Key_HMAC: Z - KH_Key_KMAC: Z - KTS_KDK_IFC: Z - KTS_KEK_IFC: Z - KTS_SS_IFC: Z - KAS_SS_ECC: Z - SC_EDK_AES: Z - SC_EDK_XTS: Z",
            "secFunImpl": ""
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 3
      },
      "authentication_methods": {
        "entries": [],
        "found": false,
        "section": 4,
        "subsection": 1
      },
      "cond_self_tests": {
        "entries": [
          {
            "algorithmOrTest": "AES - ECB",
            "condition": "Performed on module load.",
            "details": "Encrypt",
            "indicator": "FIPS_OK",
            "testMethod": "KAT",
            "testProps": "128 - bit",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES - ECB",
            "condition": "Performed on module load.",
            "details": "Decrypt",
            "indicator": "FIPS_OK",
            "testMethod": "KAT",
            "testProps": "128 - bit",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES - GCM",
            "condition": "Performed on module load.",
            "details": "Encrypt",
            "indicator": "FIPS_OK",
            "testMethod": "KAT",
            "testProps": "256 - bit",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES - GCM",
            "condition": "Performed on module load.",
            "details": "Decrypt",
            "indicator": "FIPS_OK",
            "testMethod": "KAT",
            "testProps": "256 - bit",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "Counter DRBG",
            "condition": "Performed on module load.",
            "details": "Instantiate, Generate, Reseed",
            "indicator": "FIPS_OK",
            "testMethod": "KAT",
            "testProps": "AES - 128 with derivation function",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "DSA SigGen (FIPS186 - 4)",
            "condition": "Performed on module load.",
            "details": "Sign",
            "indicator": "FIPS_OK",
            "testMethod": "KAT",
            "testProps": "2048 - bit with SHA2 - 384",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "DSA SigVer (FIPS186 - 4)",
            "condition": "Performed on module load.",
            "details": "Verify",
            "indicator": "FIPS_OK",
            "testMethod": "KAT",
            "testProps": "2048 - bit with SHA2 - 384",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigGen (FIPS186 - 4)",
            "condition": "Performed on module load.",
            "details": "Sign",
            "indicator": "FIPS_OK",
            "testMethod": "KAT",
            "testProps": "P - 224 with SHA2 - 512",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigVer (FIPS186 - 4)",
            "condition": "Performed on module load.",
            "details": "Verify",
            "indicator": "FIPS_OK",
            "testMethod": "KAT",
            "testProps": "P - 224 with SHA2 - 512",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "EDDSA ED448 SigGen",
            "condition": "Performed on module load.",
            "details": "Sign",
            "indicator": "FIPS_OK",
            "testMethod": "KAT",
            "testProps": "Edwards448 SigGen with SHA2 - 256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "EDDSA ED448 SigVer",
            "condition": "Performed on module load.",
            "details": "Verify",
            "indicator": "FIPS_OK",
            "testMethod": "KAT",
            "testProps": "Edwards448 SigVer with SHA2 - 256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "EDDSA ED25519 SigGen",
            "condition": "Performed on module load.",
            "details": "Sign",
            "indicator": "FIPS_OK",
            "testMethod": "KAT",
            "testProps": "Edwards25519 SigGen with SHA2 - 512",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "EDDSA ED25519 SigVer",
            "condition": "Performed on module load.",
            "details": "Verify",
            "indicator": "FIPS_OK",
            "testMethod": "KAT",
            "testProps": "Edwards25519 SigVer with SHA2 - 512",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "Hash DRBG",
            "condition": "Performed on module load.",
            "details": "Instantiate, Generate, Reseed",
            "indicator": "FIPS_OK",
            "testMethod": "KAT",
            "testProps": "SHA2 - 256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC DRBG",
            "condition": "Performed on module load.",
            "details": "Instantiate, Generate, Reseed",
            "indicator": "FIPS_OK",
            "testMethod": "KAT",
            "testProps": "SHA - 1",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC - SHA2 - 256 SHA2 - 256 with a 256 - bit key",
            "condition": "Performed on module load.",
            "details": "Generate",
            "indicator": "FIPS_OK",
            "testMethod": "KAT",
            "testProps": "HMAC - SHA2 - 256 SHA2 - 256 with a 256 - bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS - ECC - SSC Sp800 - 56Ar3",
            "condition": "Performed on module load.",
            "details": "Ephemeral Unified Shared Secret (Z) Computation",
            "indicator": "FIPS_OK",
            "testMethod": "KAT",
            "testProps": "P - 256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS - FFC - SSC Sp800 - 56Ar3",
            "condition": "Performed on module load.",
            "details": "dhEphem Shared Secret (Z) Computation",
            "indicator": "FIPS_OK",
            "testMethod": "KAT",
            "testProps": "L=2048/N=256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS - IFC - SSC",
            "condition": "Performed on module load.",
            "details": "SP 800 - 56B Rev. 2 Section 8.2.2 RSA Primitive Computation",
            "indicator": "FIPS_OK",
            "testMethod": "KAT",
            "testProps": "k=2048",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS - KDF OneStep SP800 - 56Cr2",
            "condition": "Performed on module load.",
            "details": "SP 800 - 56C Rev. 2 Section 4 OneStep KDF (AKA OpenSSL single - step or SS - KDF)",
            "indicator": "FIPS_OK",
            "testMethod": "KAT",
            "testProps": "SHA2 - 224",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS - KDF TwoStep SP800 - 56Cr2",
            "condition": "Performed on module load.",
            "details": "SP 800 - 56C Rev. 2 Section 5 TwoStep KDF (HKDF variant)",
            "indicator": "FIPS_OK",
            "testMethod": "KAT",
            "testProps": "SHA2 - 256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.42",
            "condition": "Performed on module load.",
            "details": "SP 800 - 135 Rev. 1 Section 5.1 ANSI X9.42 - 2001 KDF KAT",
            "indicator": "FIPS_OK",
            "testMethod": "KAT",
            "testProps": "Fixed input KAT",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF ANS 9.63",
            "condition": "Performed on module load.",
            "details": "SP 800 - 135 Rev. 1 Section 5.1 X9.63 - 2001 KDF KAT",
            "indicator": "FIPS_OK",
            "testMethod": "KAT",
            "testProps": "Fixed input KAT",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF SP800 - 108",
            "condition": "Performed on module load.",
            "details": "SP 800 - 108 Rev. 1 Section 4.1 KAT for a Counter Mode KDF",
            "indicator": "FIPS_OK",
            "testMethod": "KAT",
            "testProps": "HMAC - SHA2 - 256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF SSH",
            "condition": "Performed on module load.",
            "details": "SP 800 - 135 Rev. 1 Section 5.2 SSHv2 KDF KAT",
            "indicator": "FIPS_OK",
            "testMethod": "KAT",
            "testProps": "Fixed input KAT",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KTS - IFC",
            "condition": "Performed on module load.",
            "details": "SP 800 - 56B Rev. 2 Decrypt for CRT",
            "indicator": "FIPS_OK",
            "testMethod": "KAT",
            "testProps": "k=2048",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KTS - IFC",
            "condition": "Performed on module load.",
            "details": "SP 800 - 56B Rev. 2 Encrypt for Basic",
            "indicator": "FIPS_OK",
            "testMethod": "KAT",
            "testProps": "k=2048",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KTS - IFC",
            "condition": "Performed on module load.",
            "details": "SP 800 - 56B Rev. 2 Decrypt for Basic",
            "indicator": "FIPS_OK",
            "testMethod": "KAT",
            "testProps": "k=2048",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "PBKDF",
            "condition": "Performed on module load.",
            "details": "SP 800 - 132 Section 5.3 KAT of Master Key derivation",
            "indicator": "FIPS_OK",
            "testMethod": "KAT",
            "testProps": "SHA2 - 256, 24 - byte password, 36 - byte salt, iteration count of 4096",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigGen (FIPS186 - 4)",
            "condition": "Performed on module load.",
            "details": "Sign",
            "indicator": "FIPS_OK",
            "testMethod": "KAT",
            "testProps": "k=2048 with SHA2 - 256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186 - 4)",
            "condition": "Performed on module load.",
            "details": "Verify",
            "indicator": "FIPS_OK",
            "testMethod": "KAT",
            "testProps": "k=2048 with SHA2 - 256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA - 1",
            "condition": "Performed on module load.",
            "details": "Simple SHA KAT",
            "indicator": "FIPS_OK",
            "testMethod": "KAT",
            "testProps": "SHA - 1",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA2 - 512",
            "condition": "Performed on module load.",
            "details": "Simple SHA KAT",
            "indicator": "FIPS_OK",
            "testMethod": "KAT",
            "testProps": "SHA2 - 512",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA3 - 256",
            "condition": "Performed on module load.",
            "details": "Simple SHA KAT",
            "indicator": "FIPS_OK",
            "testMethod": "KAT",
            "testProps": "SHA3 - 256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "TLS v1.2 KDF RFC7627",
            "condition": "Performed on module load.",
            "details": "SP 800 - 135 Rev. 1 Section 4.2.2 TLS 1.2 KAT",
            "indicator": "FIPS_OK",
            "testMethod": "KAT",
            "testProps": "Fixed input KAT",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "TLS v1.3 KDF",
            "condition": "Performed on module load.",
            "details": "RFC8446 Section 7.1 TLS v1.3 KDF KAT",
            "indicator": "FIPS_OK",
            "testMethod": "KAT",
            "testProps": "Fixed input KAT",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "DSA KeyGen (FIPS186 - 4)",
            "condition": "Performed on FFC (DSA, KAS - FFC - SSC) key pair generation, prior to returning the key pair on conclusion of the call.",
            "details": "Sign, Verify",
            "indicator": "FIPS_OK",
            "testMethod": "PCT",
            "testProps": "PCT performed using the generated key pair",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "ECDSA KeyGen (FIPS186 - 4)",
            "condition": "Performed on ECC (ECDSA) key pair generation, prior to returning the key pair on conclusion of the call.",
            "details": "Sign, Verify",
            "indicator": "FIPS_OK",
            "testMethod": "PCT",
            "testProps": "PCT performed using the generated key pair",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "EDDSA KeyGen",
            "condition": "Performed on Edwards (EdDSA) key pair generation, prior to returning the key pair on conclusion of the call.",
            "details": "Sign, Verify",
            "indicator": "FIPS_OK",
            "testMethod": "PCT",
            "testProps": "PCT performed using the generated key pair",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "RSA KeyGen (FIPS186 - 4)",
            "condition": "Performed on IFC (RSA, KAS - IFC - SSC, KTS - IFC) key pair generation, prior to returning the key pair on conclusion of the call.",
            "details": "Sign, Verify",
            "indicator": "FIPS_OK",
            "testMethod": "PCT",
            "testProps": "PCT performed using the generated key pair",
            "type": "PCT"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 2
      },
      "error_states": {
        "entries": [
          {
            "conditions": "If one of the KATs fails or integrity test fails",
            "description": "The self - test failure error state",
            "indicator": "PROV_R_FIPS_MODULE_IN_ERROR_STATE",
            "name": "Self - test failure",
            "recoveryMethod": "Reload the Module into memory"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 4
      },
      "mechanisms_actions": {
        "entries": [],
        "found": false,
        "section": 7,
        "subsection": 1
      },
      "modes_of_operation": {
        "entries": [
          {
            "description": "Approved mode of operation",
            "name": "Nominal",
            "statusIndicator": "",
            "type": "Approved"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 4
      },
      "non_approved_allowed_NSC": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_allowed_algos": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_not_allowed": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_services": {
        "entries": [],
        "found": false,
        "section": 4,
        "subsection": 4
      },
      "ports_interfaces": {
        "entries": [
          {
            "data": "API input: stack frame including non - sensitive parameters.",
            "logicalInterface": "Control Input Data Input",
            "physicalPort": "N/A (API - input)"
          },
          {
            "data": "API output: output parameters and return value resulting from call execution.",
            "logicalInterface": "Data Output Status Output",
            "physicalPort": "N/A (API - output)"
          }
        ],
        "found": true,
        "section": 3,
        "subsection": 1
      },
      "roles": {
        "entries": [
          {
            "authMethodList": "",
            "name": "CO",
            "operatorType": "CO",
            "type": "Role"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 2
      },
      "security_levels": {
        "entries": [
          {
            "level": "1",
            "section": "1",
            "title": "General"
          },
          {
            "level": "1",
            "section": "2",
            "title": "Cryptographic module specification"
          },
          {
            "level": "1",
            "section": "3",
            "title": "Cryptographic module interfaces"
          },
          {
            "level": "1",
            "section": "4",
            "title": "Roles, services, and authentication"
          },
          {
            "level": "1",
            "section": "5",
            "title": "Software/Firmware security"
          },
          {
            "level": "1",
            "section": "6",
            "title": "Operational environment"
          },
          {
            "level": "N/A",
            "section": "7",
            "title": "Physical security"
          },
          {
            "level": "N/A",
            "section": "8",
            "title": "Non - invasive security"
          },
          {
            "level": "1",
            "section": "9",
            "title": "Sensitive security parameter management"
          },
          {
            "level": "1",
            "section": "10",
            "title": "Self - tests"
          },
          {
            "level": "3",
            "section": "11",
            "title": "Life - cycle assurance"
          },
          {
            "level": "1",
            "section": "12",
            "title": "Mitigation of other attacks"
          },
          {
            "level": "1",
            "section": "",
            "title": "Overall Level"
          }
        ],
        "found": true,
        "section": 1,
        "subsection": 2
      },
      "self_tests": {
        "entries": [],
        "found": false,
        "section": 10,
        "subsection": 1
      },
      "ssp_io_methods": {
        "entries": [
          {
            "dest": "Call stack (API) input parameters",
            "distribution": "Manual",
            "entry": "Electronic",
            "format": "Plaintext",
            "name": "I",
            "sfiAlgo": "",
            "source": "Calling process"
          },
          {
            "dest": "Calling process",
            "distribution": "Manual",
            "entry": "Electronic",
            "format": "Plaintext",
            "name": "O",
            "sfiAlgo": "",
            "source": "Call stack (API) output parameters"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 2
      },
      "ssp_zeroization_methods": {
        "entries": [
          {
            "description": "C (Cleanse): Caller invocation of openssl_cleanse.",
            "method": "C",
            "operatorId": "Caller invocation of openssl_cleanse",
            "rationale": "Overwrites with zeros"
          },
          {
            "description": "T (Teardown): Module unload - invokes cleanse internally.",
            "method": "T",
            "operatorId": "Occurs when module is unloaded",
            "rationale": "Overwrites with zeros"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 3
      },
      "storage_areas": {
        "entries": [
          {
            "description": "R: Random access memory",
            "name": "RAM",
            "persistance": "Dynamic"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 1
      },
      "tested_module_id_hw": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "tested_module_id_hw_hy": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "tested_module_id_sw_fw_hy": {
        "entries": [
          {
            "features": "N/A",
            "integrityTest": "HMAC - SHA2 - 256 #A4481 over the complete module file image",
            "packageFileName": "fips.so",
            "swFwVersion": "3.0.10 with KP_1.2"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 2
      },
      "tested_op_env_sw_fw_hy": {
        "entries": [
          {
            "hardwarePlatform": "HPE ProLiant DL60 Gen9",
            "hypervisorHostOs": "",
            "operatingSystem": "SnowflakeOS 1.2",
            "paa_pai": "Yes",
            "processors": "Intel\u00ae Xeon\u00ae E5 - 2609 (Sandy Bridge EP)",
            "version": "3.0.10 with KP_1.2"
          },
          {
            "hardwarePlatform": "HPE ProLiant DL60 Gen9",
            "hypervisorHostOs": "",
            "operatingSystem": "SnowflakeOS 1.2",
            "paa_pai": "No",
            "processors": "Intel\u00ae Xeon\u00ae E5 - 2609 (Sandy Bridge EP)",
            "version": "3.0.10 with KP_1.2"
          },
          {
            "hardwarePlatform": "Ampere\u00ae Altra\u00ae 2U Server R272 - P33",
            "hypervisorHostOs": "",
            "operatingSystem": "SnowflakeOS 1.2",
            "paa_pai": "Yes",
            "processors": "Ampere\u00ae Altra\u00ae SOC with Aarch64 ARMv8",
            "version": "3.0.10 with KP_1.2"
          },
          {
            "hardwarePlatform": "Ampere\u00ae Altra\u00ae 2U Server R272 - P33",
            "hypervisorHostOs": "",
            "operatingSystem": "SnowflakeOS 1.2",
            "paa_pai": "No",
            "processors": "Ampere\u00ae Altra\u00ae SOC with Aarch64 ARMv8",
            "version": "3.0.10 with KP_1.2"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 2
      },
      "vendor_affirmed_algos": {
        "entries": [
          {
            "algoPropList": "",
            "implName": "KeyPair FIPS Provider for OpenSSL 3",
            "name": "CKG Section 4",
            "reference": "NIST, SP 800 - 133 Rev. 2"
          },
          {
            "algoPropList": "",
            "implName": "KeyPair FIPS Provider for OpenSSL 3",
            "name": "CKG Section 5",
            "reference": "NIST, SP 800 - 133 Rev. 2"
          },
          {
            "algoPropList": "",
            "implName": "KeyPair FIPS Provider for OpenSSL 3",
            "name": "CKG Section 6.2",
            "reference": "NIST, SP 800 - 133 Rev. 2"
          },
          {
            "algoPropList": "",
            "implName": "KeyPair FIPS Provider for OpenSSL 3",
            "name": "Hash DRBG with SHA3 - 256, SHA3 - 512",
            "reference": "NIST, SP 800 - 90A Rev. 1"
          },
          {
            "algoPropList": "",
            "implName": "KeyPair FIPS Provider for OpenSSL 3",
            "name": "HMAC DRBG with SHA3 - 256, SHA3 - 512",
            "reference": "NIST, SP 800 - 90A Rev. 1"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "vendor_affirmed_op_env_sw_fw_hy": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      }
    },
    "is_br1_format": true,
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 15
          },
          "ECDSA": {
            "ECDSA": 21
          },
          "EdDSA": {
            "EdDSA": 4
          }
        },
        "FF": {
          "DH": {
            "DHE": 2
          },
          "DSA": {
            "DSA": 23
          }
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 12
        },
        "CCM": {
          "CCM": 4
        },
        "CTR": {
          "CTR": 6
        },
        "ECB": {
          "ECB": 7
        },
        "GCM": {
          "GCM": 10
        },
        "OFB": {
          "OFB": 3
        },
        "XTS": {
          "XTS": 7
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {
        "OpenSSL": {
          "OpenSSL": 10
        }
      },
      "crypto_protocol": {
        "SSH": {
          "SSH": 4,
          "SSHv2": 2
        },
        "TLS": {
          "TLS": {
            "TLS": 3,
            "TLS 1.2": 1,
            "TLS 1.3": 1,
            "TLS v1.2": 4,
            "TLS v1.3": 5
          }
        }
      },
      "crypto_scheme": {
        "AEAD": {
          "AEAD": 1
        },
        "KA": {
          "Key Agreement": 1,
          "Key agreement": 17
        },
        "MAC": {
          "MAC": 16
        }
      },
      "device_model": {},
      "ecc_curve": {},
      "eval_facility": {},
      "fips_cert_id": {},
      "fips_certlike": {
        "Certlike": {
          "AES - 128": 6,
          "AES - 192": 5,
          "AES - 256": 5,
          "AES - GCM 256": 2,
          "AES -128": 1,
          "AES -192": 1,
          "AES -256": 1,
          "HMAC - SHA - 1": 3,
          "HMAC - SHA2": 22,
          "HMAC - SHA3": 12,
          "HMAC -SHA2": 1,
          "PKCS 1": 4,
          "SHA - 1": 16,
          "SHA -1": 1,
          "SHA -3": 3,
          "SHA2": 32,
          "SHA2 - 224": 17,
          "SHA2 - 256": 32,
          "SHA2 - 384": 20,
          "SHA2 - 512": 24,
          "SHA2 -224": 1,
          "SHA2 -256": 1,
          "SHA2 -384": 1,
          "SHA2 -512": 1,
          "SHA3": 1,
          "SHA3 - 224": 7,
          "SHA3 - 256": 10,
          "SHA3 - 384": 7,
          "SHA3 - 512": 8,
          "SHA3 -224": 1,
          "SHA3 -256": 2,
          "SHA3 -384": 1,
          "SHA3 -512": 2
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 2
        }
      },
      "hash_function": {
        "PBKDF": {
          "PBKDF": 10
        },
        "SHA": {
          "SHA2": {
            "SHA2": 135
          },
          "SHA3": {
            "SHA3": 42
          }
        },
        "SHAKE": {
          "SHAKE128": 1,
          "SHAKE256": 1
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {
        "curves": {
          "ED25519": 4,
          "ED448": 4
        }
      },
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 37
        },
        "RNG": {
          "RBG": 3
        }
      },
      "side_channel_analysis": {
        "SCA": {
          "timing attacks": 2
        }
      },
      "standard_id": {
        "FIPS": {
          "FIPS 140": 61,
          "FIPS 180": 7,
          "FIPS 186": 19,
          "FIPS 198": 11,
          "FIPS 202": 6,
          "FIPS186": 45
        },
        "ISO": {
          "ISO/IEC 19790:2012": 3
        },
        "PKCS": {
          "PKCS 1": 2
        },
        "RFC": {
          "RFC 5288": 1,
          "RFC 5647": 1,
          "RFC 8446": 1,
          "RFC7627": 4,
          "RFC8446": 1
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 92
          },
          "CAST": {
            "CAST": 73
          }
        },
        "constructions": {
          "MAC": {
            "CMAC": 11,
            "HMAC": 59,
            "KMAC": 13
          }
        }
      },
      "tee_name": {
        "AMD": {
          "PSP": 12
        },
        "IBM": {
          "SSC": 18
        }
      },
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "module_algorithms": {
      "_type": "Set",
      "elements": [
        "SHA2-512/224A4481",
        "AES-CFB1A4481",
        "ECDSA SigVer (FIPS186-4)A4481",
        "RSA SigVer (FIPS186-4)A4481",
        "SHA3-256A4481",
        "Hash DRBGA4481",
        "AES-CBCA4481",
        "SHA2-256A4481",
        "HMAC-SHA2-512A4481",
        "SHA3-512A4481",
        "DSA KeyGen (FIPS186-4)A4481",
        "PBKDFA4481",
        "ECDSA KeyGen (FIPS186-4)A4481",
        "KDF SP800-108A4481",
        "RSA SigGen (FIPS186-5)A4481",
        "HMAC-SHA3-256A4481",
        "KTS-IFCA4481",
        "SHA2-512/256A4481",
        "AES-CBC-CS2A4481",
        "EDDSA SigGenA4481",
        "TLS v1.3 KDFA4481",
        "Safe Primes Key GenerationA4481",
        "KDF ANS 9.63A4481",
        "AES-CBC-CS3A4481",
        "DSA PQGGen (FIPS186-4)A4481",
        "KAS-ECC CDH-Component SP800-56Ar3A4481",
        "KDF SSHA4481",
        "ECDSA KeyVer (FIPS186-4)A4481",
        "SHA2-224A4481",
        "AES-CFB8A4481",
        "AES-CFB128A4481",
        "KDA HKDF SP800-56Cr2A4481",
        "AES-CMACA4481",
        "KAS-IFC-SSCA4481",
        "DSA SigVer (FIPS186-4)A4481",
        "AES-GMACA4481",
        "HMAC-SHA2-256A4481",
        "SHA3-384A4481",
        "AES-CTRA4481",
        "AES-XTS Testing Revision 2.0A4481",
        "RSA SigGen (FIPS186-4)A4481",
        "HMAC-SHA2-512/224A4481",
        "SHA3-224A4481",
        "Counter DRBGA4481",
        "HMAC-SHA2-512/256A4481",
        "AES-ECBA4481",
        "HMAC-SHA3-224A4481",
        "SHAKE-128A4481",
        "DSA SigGen (FIPS186-4)A4481",
        "SHAKE-256A4481",
        "AES-GCMA4481",
        "KMAC-128A4481",
        "ECDSA SigGen (FIPS186-4)A4481",
        "AES-CCMA4481",
        "HMAC-SHA2-384A4481",
        "HMAC-SHA3-384A4481",
        "AES-OFBA4481",
        "AES-KWA4481",
        "EDDSA KeyVerA4481",
        "HMAC-SHA-1A4481",
        "KDA OneStep SP800-56Cr2A4481",
        "AES-KWPA4481",
        "DSA PQGVer (FIPS186-4)A4481",
        "AES-CBC-CS1A4481",
        "EDDSA KeyGenA4481",
        "RSA KeyGen (FIPS186-4)A4481",
        "KAS-ECC-SSC Sp800-56Ar3A4481",
        "SHA2-512A4481",
        "RSA Signature PrimitiveA4481",
        "SHA2-384A4481",
        "KAS-FFC-SSC Sp800-56Ar3A4481",
        "KDF ANS 9.42A4481",
        "KDA TwoStep SP800-56Cr2A4481",
        "TLS v1.2 KDF RFC7627A4481",
        "SHA-1A4481",
        "RSA SigVer (FIPS186-5)A4481",
        "Safe Primes Key VerificationA4481",
        "HMAC-SHA3-512A4481",
        "EDDSA SigVerA4481",
        "KMAC-256A4481",
        "HMAC-SHA2-224A4481",
        "HMAC DRBGA4481"
      ]
    },
    "policy_algorithms": {
      "_type": "Set",
      "elements": [
        "#A4481"
      ]
    },
    "policy_metadata": {
      "/Author": "Rachel Shelby",
      "/CreationDate": "D:20241021152415-07\u002700\u0027",
      "/Creator": "PScript5.dll Version 5.2.2",
      "/ModDate": "D:20241021152415-07\u002700\u0027",
      "/Producer": "Acrobat Distiller 24.0 (Windows)",
      "/Title": "Microsoft Word - Snowflake FIPS 140-3 Security Policy_Output_TRD1_2024-10-21.docx",
      "pdf_file_size_bytes": 624188,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": []
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 40
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.InternalState",
    "module": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "policy": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": "ce8d066bf5cd7c0f40a8414d2456ddc7e3a4c5234ac2afc40624adf8f9393cf1",
      "source_hash": "2fd11d67715124742a10d11eeed31cfec11bff1fc49551ef1c7fd263d8edcff2",
      "txt_hash": "cdb2e721b06f4dce1b126b2b9afeaad5513de4a4bbc674aefd50d21d30a672ea"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "No assurance of the minimum strength of generated SSPs (e.g., keys).",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/December 2024_060125_0402.pdf",
    "date_sunset": "2029-07-10",
    "description": "The Snowflake FIPS Provider is a general-purpose cryptographic library incorporated into Snowflake platforms to provide FIPS 140-3 validated cryptography for the protection of sensitive information.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Physical security: N/A",
      "Non-invasive security: N/A",
      "Life-cycle assurance: Level 3"
    ],
    "fw_versions": null,
    "historical_reason": null,
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {},
    "module_name": "Snowflake FIPS Provider",
    "module_type": "Software",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-3",
    "status": "active",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2024-12-18",
        "lab": "DEKRA Cybersecurity Certification Laboratory",
        "validation_type": "Initial"
      }
    ],
    "vendor": "[email\u00a0protected]",
    "vendor_url": "/cdn-cgi/l/email-protection"
  }
}