{"_type": "sec_certs.sample.fips.FIPSCertificate", "dgst": "b2b7178dc27bc498", "cert_id": 5261, "web_data": {"_type": "sec_certs.sample.fips.FIPSCertificate.WebData", "module_name": "Linux Kernel FIPS Object Module (KFOM) Cryptographic Module", "validation_history": [{"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry", "date": "2026-05-11", "validation_type": "Initial", "lab": "Gossamer Security Solutions"}, {"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry", "date": "2026-08-03", "validation_type": "Update", "lab": "Gossamer Security Solutions"}], "vendor_url": "http://www.cisco.com", "vendor": "Cisco Systems, Inc.", "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/May 2026_030626_0716.pdf", "module_type": "Firmware-Hybrid", "standard": "FIPS 140-3", "status": "active", "level": 1, "caveat": "No assurance of the minimum strength of generated SSPs (e.g., keys). No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs", "exceptions": ["Non-invasive security: N/A", "Mitigation of other attacks: N/A"], "embodiment": "MultiChipStand", "description": "The Cisco Linux Kernel FIPS Object Module (KFOM) is a firmware hybrid cryptographic library that serves the operating system kernel. It does not implement any security protocols, instead only allowing for Linux kernel applications access to using approved algorithms.", "tested_conf": null, "hw_versions": null, "fw_versions": null, "sw_versions": null, "mentioned_certs": {}, "historical_reason": null, "date_sunset": "2031-05-10", "revoked_reason": null, "revoked_link": null}, "pdf_data": {"_type": "sec_certs.sample.fips.FIPSCertificate.PdfData", "keywords": {"fips_cert_id": {"Cert": {"#3": 1}}, "fips_security_level": {"Level": {"Level 1": 3, "level 1": 2}}, "fips_certlike": {"Certlike": {"HMAC-SHA-1": 2, "SHA2-224": 2, "SHA2-256": 9, "SHA2-384": 4, "SHA2-512": 7, "SHA3-224": 2, "SHA3-256": 6, "SHA3-384": 2, "SHA3-512": 2, "SHA-1": 6, "SHA2": 1, "SHA-256": 3, "SHA2- 256": 1, "AES-128": 4, "AES-192": 1, "AES-256": 1}}, "vendor": {"Cisco": {"Cisco Systems, Inc": 30, "Cisco Systems": 2, "Cisco": 5}}, "eval_facility": {}, "symmetric_crypto": {"AES_competition": {"AES": {"AES-128": 4, "AES-192": 1, "AES-256": 1, "AES": 14}, "CAST": {"CAST": 36}}, "constructions": {"MAC": {"HMAC": 15}}}, "asymmetric_crypto": {"ECC": {"ECDH": {"ECDH": 11}, "ECDSA": {"ECDSA": 18}, "ECC": {"ECC": 2}}}, "pq_crypto": {"LMS": {"LMS": 19}}, "hash_function": {"SHA": {"SHA1": {"SHA-1": 6}, "SHA2": {"SHA-256": 3, "SHA2": 1}, "SHA3": {"SHA3-224": 2, "SHA3-256": 6, "SHA3-384": 2, "SHA3-512": 2}}}, "crypto_scheme": {"MAC": {"MAC": 3}}, "crypto_protocol": {}, "randomness": {"PRNG": {"DRBG": 59}, "RNG": {"RBG": 2}}, "cipher_mode": {"GCM": {"GCM": 4}, "XTS": {"XTS": 5}}, "ecc_curve": {"NIST": {"P-256": 12, "P-384": 6}}, "crypto_engine": {}, "tls_cipher_suite": {}, "crypto_library": {}, "vulnerability": {}, "side_channel_analysis": {}, "device_model": {}, "tee_name": {"AMD": {"PSP": 3}, "IBM": {"SSC": 1}}, "os_name": {}, "cplc_data": {}, "ic_data_group": {}, "standard_id": {"FIPS": {"FIPS 140-3": 6, "FIPS186-5": 4, "FIPS 186-5": 1, "FIPS 198-1": 5, "FIPS 180-4": 5, "FIPS 202": 4}, "NIST": {"SP 800-140": 1, "SP 800-38E": 1}, "ISO": {"ISO/IEC 19790": 2}}, "javacard_version": {}, "javacard_api_const": {}, "javacard_packages": {}, "certification_process": {}}, "policy_metadata": {"pdf_file_size_bytes": 604704, "pdf_is_encrypted": false, "pdf_number_of_pages": 28, "/Producer": "Microsoft\u00ae Word for Microsoft 365", "/Creator": "Microsoft\u00ae Word for Microsoft 365", "/CreationDate": "D:20260730161821-04'00'", "/ModDate": "D:20260730161821-04'00'", "pdf_hyperlinks": {"_type": "Set", "elements": []}}}, "heuristics": {"_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics", "algorithms": {"_type": "Set", "elements": ["ECDSA SigVer (FIPS186-5)A6627", "AES-CBC-CS3A6627", "SHA2-512A6627", "SHA3-384A6627", "SHA3-512A6627", "HMAC-SHA2-512A6627", "AES-CTRA6627", "SHA2-256A6627", "SHA2-224A6627", "HMAC-SHA2-224A6627", "HMAC DRBGA6627", "AES-CCMA6627", "AES-CBCA6627", "SHA-1A6627", "HMAC-SHA2-256A6627", "Hash DRBGA6627", "KAS-ECC-SSC Sp800-56Ar3A6627", "AES-CMACA6627", "Counter DRBGA6627", "AES-XTS Testing Revision 2.0A6627", "SHA3-256A6627", "HMAC-SHA-1A6627", "AES-GCMA6627", "SHA2-384A6627", "HMAC-SHA2-384A6627", "LMS SigVerA6627", "KAS-ECC CDH-Component SP800-56Ar3A6627", "AES-ECBA6627", "SHA3-224A6627"]}, "extracted_versions": {"_type": "Set", "elements": ["-"]}, "cpe_matches": null, "verified_cpe_matches": null, "related_cves": null, "policy_prunned_references": {"_type": "Set", "elements": []}, "module_prunned_references": {"_type": "Set", "elements": []}, "policy_processed_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": null, "indirectly_referenced_by": null, "directly_referencing": null, "indirectly_referencing": null}, "module_processed_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": null, "indirectly_referenced_by": null, "directly_referencing": null, "indirectly_referencing": null}, "direct_transitive_cves": null, "indirect_transitive_cves": null}, "state": {"_type": "sec_certs.sample.fips.InternalState", "module": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": null, "txt_hash": null, "json_hash": null}, "policy": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": "f758058c4f31db1764f8db0b5319129def50be8697224f30d5bca6748d28d383", "txt_hash": "a1ddd06e5b75159bb4e15bd441743d53dbcd9b15870543f9d8b6db6f706ea2c8", "json_hash": null}}}