{"_type": "sec_certs.sample.fips.FIPSCertificate", "dgst": "b92f859368bbc325", "cert_id": 5435, "web_data": {"_type": "sec_certs.sample.fips.FIPSCertificate.WebData", "module_name": "SUSE Linux Enterprise NSS Cryptographic Module", "validation_history": [{"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry", "date": "2026-07-26", "validation_type": "Initial", "lab": "atsec information security corporation"}], "vendor_url": "http://www.suse.com", "vendor": "SUSE LLC", "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/July 2026_040826_0807.pdf", "module_type": "Software", "standard": "FIPS 140-3", "status": "active", "level": 1, "caveat": "When operated in approved mode. No assurance of minimum security of SSPs (e.g. keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs", "exceptions": ["Physical security: N/A", "Non-invasive security: N/A"], "embodiment": "MultiChipStand", "description": "SUSE Network Security Services (NSS) is a set of libraries designed to support cross-platform development of security-enabled client and server applications. Applications built with NSS can support TLS, PKCS #5, PKCS #7, PKCS #11, PKCS #12, S/MIME, X.509v3 certificates, and other security standards.", "tested_conf": null, "hw_versions": null, "fw_versions": null, "sw_versions": null, "mentioned_certs": {}, "historical_reason": null, "date_sunset": "2029-07-16", "revoked_reason": null, "revoked_link": null}, "pdf_data": {"_type": "sec_certs.sample.fips.FIPSCertificate.PdfData", "keywords": {"fips_cert_id": {}, "fips_security_level": {"Level": {"Level 1": 3, "level 1": 1}}, "fips_certlike": {"Certlike": {"HMAC-SHA-1": 30, "HMAC- SHA-1": 2, "SHA2-224": 37, "SHA2-256": 71, "SHA2-384": 40, "SHA2- 512": 15, "SHA-1": 15, "SHA2-512": 31, "SHA3-256": 2, "SHA2- 224": 6, "SHA2- 256": 6, "SHA2- 384": 6, "RSA 32": 1, "PKCS#5": 2, "PKCS#7": 2, "PKCS#12": 2, "- PKCS 1": 6, "PKCS#1": 38, "AES256": 1, "AES key 128, 192": 2, "DES2": 3, "PKCS 1": 6}}, "vendor": {}, "eval_facility": {"atsec": {"atsec": 101}}, "symmetric_crypto": {"AES_competition": {"AES": {"AES": 44, "AES256": 1, "AES-": 2}, "CAST": {"CAST": 231, "CAST5": 3}, "RC": {"RC2": 3, "RC4": 3, "RC5": 3}}, "DES": {"DES": {"DES": 3}, "3DES": {"Triple-DES": 3}}, "djb": {"ChaCha": {"ChaCha20": 3}, "Poly": {"Poly1305": 3}}, "miscellaneous": {"IDEA": {"IDEA": 3}, "Camellia": {"Camellia": 3}, "SEED": {"SEED": 3}}, "constructions": {"MAC": {"HMAC": 28, "CBC-MAC": 3, "CMAC": 2}}}, "asymmetric_crypto": {"ECC": {"ECDH": {"ECDH": 2}, "ECDSA": {"ECDSA": 47}, "ECC": {"ECC": 1}}, "FF": {"DH": {"Diffie-Hellman": 51, "DH": 2}, "DSA": {"DSA": 47}}}, "pq_crypto": {}, "hash_function": {"SHA": {"SHA1": {"SHA-1": 15}, "SHA3": {"SHA3-256": 2}}, "MD": {"MD5": {"MD5": 4}}, "PBKDF": {"PBKDF": 35, "PBKDF1": 3}}, "crypto_scheme": {"MAC": {"MAC": 29}, "KEX": {"Key Exchange": 3}, "KA": {"Key Agreement": 3, "Key agreement": 2}}, "crypto_protocol": {"TLS": {"TLS": {"TLS": 42, "TLS v1.2": 33, "TLSv1.0": 1, "TLS 1.3": 9, "TLS v1.0": 4, "TLS v1.3": 1, "TLSv1.2": 1, "TLSv1.3": 1}}, "IKE": {"IKEv2": 23, "IKEv1": 21, "IKE": 12}}, "randomness": {"PRNG": {"DRBG": 45}, "RNG": {"RNG": 2, "RBG": 2}}, "cipher_mode": {"ECB": {"ECB": 1}, "CBC": {"CBC": 1}, "GCM": {"GCM": 16}}, "ecc_curve": {"NIST": {"P-256": 60, "P-384": 32, "P-521": 40, "P-192": 12, "P-224": 12, "P-512": 1}, "Curve": {"Curve25519": 3}}, "crypto_engine": {}, "tls_cipher_suite": {}, "crypto_library": {"NSS": {"NSS": 106}}, "vulnerability": {}, "side_channel_analysis": {"SCA": {"Timing Attacks": 2, "timing attacks": 1}}, "device_model": {}, "tee_name": {"AMD": {"PSP": 8}, "IBM": {"SSC": 1}}, "os_name": {}, "cplc_data": {}, "ic_data_group": {}, "standard_id": {"FIPS": {"FIPS 140-3": 116, "FIPS PUB 140-3": 2, "FIPS186-4": 108, "FIPS 186-4": 25, "FIPS 198-1": 11, "FIPS 180-4": 11, "FIPS 197": 1}, "NIST": {"SP 800-132": 10, "SP 800-38A": 14, "SP 800-38B": 2, "SP 800-38D": 9, "SP 800-38F": 3, "SP 800-90A": 13, "SP 800-56A": 11, "SP 800-56C": 3, "SP 800-135": 11, "SP 800-108": 3, "SP 800-133": 3, "SP 800-52": 3, "SP 800-57": 1, "SP 800-131A": 2, "SP 800-90B": 1}, "PKCS": {"PKCS#5": 1, "PKCS#7": 1, "PKCS#12": 1, "PKCS 1": 6, "PKCS#1": 19}, "RFC": {"RFC7627": 21, "RFC5288": 1, "RFC8446": 1, "RFC7919": 3, "RFC3526": 3}, "ISO": {"ISO/IEC 9796": 6}, "X509": {"X.509": 6}}, "javacard_version": {}, "javacard_api_const": {}, "javacard_packages": {}, "certification_process": {}}, "policy_metadata": {"pdf_file_size_bytes": 1153171, "pdf_is_encrypted": false, "pdf_number_of_pages": 100, "/Producer": "Microsoft\u00ae Word for Microsoft 365", "/Creator": "Microsoft\u00ae Word for Microsoft 365", "/CreationDate": "D:20260720145637-04'00'", "/ModDate": "D:20260720145637-04'00'", "pdf_hyperlinks": {"_type": "Set", "elements": ["https://doi.org/10.6028/NIST.FIPS.180-4", "https://doi.org/10.6028/NIST.SP.800-56Ar3", "https://doi.org/10.6028/NIST.SP.800-56Cr2", "https://doi.org/10.6028/NIST.SP.800-90B", "https://doi.org/10.6028/NIST.SP.800-133r2", "https://doi.org/10.6028/NIST.SP.800-38B", "https://csrc.nist.gov/Projects/cryptographic-module-validation-program/fips-140-3-ig-announcements", "https://www.ietf.org/rfc/rfc3447.txt", "https://doi.org/10.6028/NIST.SP.800-90Ar1", "https://doi.org/10.6028/NIST.SP.800-38D", "https://doi.org/10.6028/NIST.SP.800-135r1", "https://documentation.suse.com/sle-rt/15-SP4/", "https://doi.org/10.6028/NIST.SP.800-131Ar2", "https://doi.org/10.6028/NIST.SP.800-132", "https://doi.org/10.6028/NIST.SP.800-108r1-upd1", "https://documentation.suse.com/sle-micro/5.3/single-html/SLE-Micro-security/#sec-fips-slemicro-install", "https://doi.org/10.6028/NIST.SP.800-38A", "https://documentation.suse.com/sles/15-SP4/html/SLES-all/book-security.html", "https://doi.org/10.6028/NIST.FIPS.186-4", "https://doi.org/10.6028/NIST.SP.800-52r2", "https://doi.org/10.6028/NIST.SP.800-38F", "https://documentation.suse.com/smart/linux/html/concept-bci/index.html", "https://documentation.suse.com/sled/15-SP4/html/SLED-all/book-security.html", "https://doi.org/10.6028/NIST.FIPS.198-1", "https://doi.org/10.6028/NIST.FIPS.197-upd1", "https://doi.org/10.6028/NIST.FIPS.140-3"]}}}, "heuristics": {"_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics", "algorithms": {"_type": "Set", "elements": ["AES-GCMA3587", "AES-CMACA3577", "PBKDFA3588", "HMAC-SHA2-256A3588", "KDA HKDF Sp800-56Cr1A3574", "SHA2-256A3588", "AES-KWA3576", "RSA KeyGen (FIPS186-4)A3588", "HMAC-SHA-1A3588", "SHA2-224A3588", "HMAC-SHA2-384A3575", "KDF TLSA3588", "KAS-ECC-SSC Sp800-56Ar3A3588", "ECDSA KeyVer (FIPS186-4)A3588", "ECDSA SigVer (FIPS186-4)A3588", "AES-ECBA3587", "DSA SigVer (FIPS186-4)A3588", "Safe Primes Key GenerationA3588", "KDF IKEv1A3579", "KDF IKEv2A3579", "ECDSA SigGen (FIPS186-4)A3588", "KAS-FFC-SSC Sp800-56Ar3A3588", "SHA2-512A3575", "ECDSA KeyGen (FIPS186-4)A3588", "AES-CBC-CS1A3580", "KDF SP800-108A3578", "SHA2-384A3575", "TLS v1.2 KDF RFC7627A3588", "AES-CTRA3581", "HMAC-SHA2-512A3575", "RSA SigVer (FIPS186-4)A3588", "RSA SigGen (FIPS186-4)A3588", "AES-KWPA3576", "HMAC-SHA2-224A3588", "AES-CBCA3585", "SHA-1A3588", "Hash DRBGA3588"]}, "extracted_versions": {"_type": "Set", "elements": ["-"]}, "cpe_matches": null, "verified_cpe_matches": null, "related_cves": null, "policy_prunned_references": {"_type": "Set", "elements": []}, "module_prunned_references": {"_type": "Set", "elements": []}, "policy_processed_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": null, "indirectly_referenced_by": null, "directly_referencing": null, "indirectly_referencing": null}, "module_processed_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": null, "indirectly_referenced_by": null, "directly_referencing": null, "indirectly_referencing": null}, "direct_transitive_cves": null, "indirect_transitive_cves": null}, "state": {"_type": "sec_certs.sample.fips.InternalState", "module": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": null, "txt_hash": null, "json_hash": null}, "policy": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": "1deed6fc792f96a1fb9a1b063d06079ee5e85103d772c2632ddb8bdde3091922", "txt_hash": "4de95e7bea6780137cf27b6ac7634a0c422c641d3f3199810536f575a56b0e4c", "json_hash": null}}}