## Juniper Networks, Inc. Juniper Networks MX Series 3D Universal Edge Routers ##### FIPS 140-3 Non-Proprietary Security Policy Version: Junos OS 22.2R3-S1 Juniper Networks, Inc. 1133 Innovation Way Sunnyvale, California 94089 USA 408.745.2000 1.888 JUNIPER www.juniper.net Prepared by: www.teronlabs.com Page 1 of 41 ## Table of Contents | 1 General ........................................................................................................................................................... | 1 General ........................................................................................................................................................... | |-------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | 1.1 Overview ................................................................................................................................................ 6 | 1.1 Overview ................................................................................................................................................ 6 | | 1.2 Security Levels ....................................................................................................................................... 6 | 1.2 Security Levels ....................................................................................................................................... 6 | | 2 Cryptographic Module Specification ........................................................................................................ 7 | 2 Cryptographic Module Specification ........................................................................................................ 7 | | 2.1 Description ............................................................................................................................................. 7 | 2.1 Description ............................................................................................................................................. 7 | | 2.2 Tested and Vendor Affirmed Module Version and Identification ............................................... 8 | 2.2 Tested and Vendor Affirmed Module Version and Identification ............................................... 8 | | 2.3 Excluded Components ......................................................................................................................... 9 | 2.3 Excluded Components ......................................................................................................................... 9 | | 2.4 Modes of Operation ............................................................................................................................. 9 | 2.4 Modes of Operation ............................................................................................................................. 9 | | 2.5 Algorithms ............................................................................................................................................ 10 | 2.5 Algorithms ............................................................................................................................................ 10 | | 2.6 Security Function Implementations ................................................................................................ 12 | 2.6 Security Function Implementations ................................................................................................ 12 | | 2.7 Algorithm Specific Information ........................................................................................................ 14 | 2.7 Algorithm Specific Information ........................................................................................................ 14 | | 2.8 RBG and Entropy ................................................................................................................................ 15 | 2.8 RBG and Entropy ................................................................................................................................ 15 | | 2.9 Key Generation ................................................................................................................................... 15 | 2.9 Key Generation ................................................................................................................................... 15 | | 2.10 Key Establishment ............................................................................................................................ 16 | 2.10 Key Establishment ............................................................................................................................ 16 | | 2.11 Industry Protocols ............................................................................................................................ 16 | 2.11 Industry Protocols ............................................................................................................................ 16 | | 3 Cryptographic Module Interfaces ........................................................................................................... 17 | 3 Cryptographic Module Interfaces ........................................................................................................... 17 | | 3.1 Ports and Interfaces ........................................................................................................................... 17 | 3.1 Ports and Interfaces ........................................................................................................................... 17 | | 4 Roles, Services, and Authentication ........................................................................................................ 18 | 4 Roles, Services, and Authentication ........................................................................................................ 18 | | 4.1 Authentication Methods.................................................................................................................... 18 | 4.1 Authentication Methods.................................................................................................................... 18 | | 4.2 Roles ...................................................................................................................................................... 18 | 4.2 Roles ...................................................................................................................................................... 18 | | 4.3 Approved Services .............................................................................................................................. 19 | 4.3 Approved Services .............................................................................................................................. 19 | | 4.4 Non-Approved Services..................................................................................................................... 22 | 4.4 Non-Approved Services..................................................................................................................... 22 | | 4.5 External Software/Firmware Loaded .............................................................................................. 22 | 4.5 External Software/Firmware Loaded .............................................................................................. 22 | | 5. Software/Firmware Security ................................................................................................................... 23 | 5. Software/Firmware Security ................................................................................................................... 23 | | 5.1 Integrity Techniques ........................................................................................................................... 23 | 5.1 Integrity Techniques ........................................................................................................................... 23 | | 5.2 Initiate on Demand ............................................................................................................................. 23 | 5.2 Initiate on Demand ............................................................................................................................. 23 | | 6 Operational Environment ......................................................................................................................... 24 | 6 Operational Environment ......................................................................................................................... 24 | | 6.1 Operational Environment Type and Requirements ..................................................................... 24 | 6.1 Operational Environment Type and Requirements ..................................................................... 24 | | 7 Physical Security ......................................................................................................................................... | 7 Physical Security ......................................................................................................................................... | Page 2 of 41 | 7.1 Mechanisms and Actions Required ................................................................................................. 25 | |----------------------------------------------------------------------------------------------------------------------------------------------------------------------| | 8 Non-Invasive Security ............................................................................................................................... 26 | | 9 Sensitive Security Parameters Management ........................................................................................ 27 | | 9.1 Storage Areas ....................................................................................................................................... 27 | | 9.2 SSP Input-Output Methods .............................................................................................................. 27 | | 9.3 SSP Zeroization Methods .................................................................................................................. 27 | | 9.4 SSPs ....................................................................................................................................................... 28 | | 9.5 Transitions ............................................................................................................................................ 32 | | 10 Self-Tests ................................................................................................................................................... 33 | | 10.1 Pre-Operational Self-Tests ............................................................................................................. 33 | | 10.2 Conditional Self-Tests ..................................................................................................................... 33 | | 10.3 Periodic Self-Test Information ....................................................................................................... 36 | | 10.4 Error States ........................................................................................................................................ 38 | | 10.5 Operator Initiation of Self-Tests ................................................................................................... 38 | | 11.1 Installation, Initialization, and Startup Procedures .................................................................... 39 | | 11.2 Administrator Guidance .................................................................................................................. 39 | | 11.3 Non-Administrator Guidance ......................................................................................................... 40 | | 11.4 Design and Rules .............................................................................................................................. 40 | | 11.5 Maintenance Requirements ........................................................................................................... 40 | | 11.6 End of Life .......................................................................................................................................... 40 | | 12 Mitigation of Other Attacks ................................................................................................................... 41 | Page 3 of 41 ### List of Tables | Table 1: Security Levels .................................................................................................................................. 6 | |--------------------------------------------------------------------------------------------------------------------------------------------------------------------| | Table 2: Tested Module Identification - Hardware .................................................................................. 9 | | Table 3: Modes List and Description ......................................................................................................... 10 | | Table 4: Approved Algorithms - OpenSSL Approved Cryptographic Functions ............................... 11 | | Table 5: Approved Algorithms - Kernel Approved Cryptographic Functions .................................... 11 | | Table 6: Approved Algorithms - OpenSSH Approved Cryptographic Functions .............................. 12 | | Table 7: Vendor-Affirmed Algorithms ....................................................................................................... 12 | | Table 8: Security Function Implementations ............................................................................................ 14 | | Table 9: Entropy Certificates ....................................................................................................................... 15 | | Table 10: Entropy Sources ........................................................................................................................... 15 | | Table 11: Ports and Interfaces .................................................................................................................... 17 | | Table 12: Authentication Methods ............................................................................................................ 18 | | Table 13: Roles ............................................................................................................................................... 18 | | Table 14: Approved Services ....................................................................................................................... 22 | | Table 15: Mechanisms and Actions Required .......................................................................................... 25 | | Table 16: Storage Areas ................................................................................................................................ 27 | | Table 17: SSP Input-Output Methods ....................................................................................................... 27 | | Table 18: SSP Zeroization Methods ........................................................................................................... 28 | | Table 19: SSP Table 1 .................................................................................................................................... 30 | | Table 20: SSP Table 2 .................................................................................................................................... 32 | | Table 21: Pre-Operational Self-Tests ........................................................................................................ 33 | | Table 22: Conditional Self-Tests ................................................................................................................. 36 | | Table 23: Pre-Operational Periodic Information ..................................................................................... 36 | | Table 24: Conditional Periodic Information .............................................................................................. 38 | | Table 25: Error States ................................................................................................................................... 38 | ### List of Figures Page 4 of 41 Figure 1 Physical Cryptographic Boundary (Left to Right: MX240, MX480, MX960) ....................... 8 Figure 2 MX-SPC3 Services Card ................................................................................................................. 8 Page 5 of 41 ## 1 General ### 1.1 Overview This is a non-proprietary Cryptographic Module Security Policy for the Juniper Networks MX Series 3D Universal Edge Routers, consisting of the MX240, MX480 and MX960 models, with MX-SPC3 Services Processing Card, running Junos OS 22.2R3-S1. ### 1.2 Security Levels The cryptographic module meets requirements applicable to Level 1 of FIPS 140-3. The following table lists the security levels claimed by the cryptographic module for each security requirements area of the FIPS 140-3 standard. Table 1: Security Levels | Section | Title | Security Level | |-----------|-----------------------------------------|------------------| | 1 | General | 1 | | 2 | Cryptographic module specification | 1 | | 3 | Cryptographic module interfaces | 1 | | 4 | Roles, services, and authentication | 2 | | 5 | Software/Firmware security | 1 | | 6 | Operational environment | 1 | | 7 | Physical security | 1 | | 8 | Non-invasive security | N/A | | 9 | Sensitive security parameter management | 1 | | 10 | Self-tests | 1 | | 11 | Life-cycle assurance | 1 | | 12 | Mitigation of other attacks | N/A | | | Overall Level | 1 | Page 6 of 41 ## 2 Cryptographic Module Specification ### 2.1 Description ###### Purpose and Use: The MX series universal routing modular platforms MX240, MX480 and MX960 provide dedicated high-performance processing for flows and sessions and integrates advanced security capabilities that protect the network infrastructure as well as user data. The MX-SPC3 services card provides security services such as carrier-grade NAT (CGNAT), IPsec, stateful firewall, deep packet inspection, IDS, traffic load balancing, Web filtering, and DNS sinkhole. ###### Module Type : Hardware Module Embodiment: MultiChipStand Module Characteristics: Cryptographic Boundary: This Security Policy covers the following models: - MX240, - MX480, and - MX960. All models run Juniper's JUNOS firmware. The JUNOS firmware is FIPS -compliant when configured in the Approved mode called JUNOS-FIPS-MODE, version 22.2R3-S1. The firmware CLI command show version identifies itself as 'Junos 22.2R3-S1.9 ' . The physical form of the module is depicted in Figure 1 and Figure 2 below. The cryptographic boundary encompasses the entire Tested Operational Environment Physical Perimeter (TOEPP), which is defined as follows: - the outer edge of the chassis and including the Routing Engine (RE), the MS-MPC, Router Control Board/Router Fabric Board (SCB)/(SFB) and slot covers in the following configurations: - o For MX480 (2 available RE slots, 6 additional slots): 1 SCB, 1 RE, at least 1 SPC. All empty module bays must have a slot cover installed for proper cooling air circulation. - o For MX240 (2 available RE slots, 2 additional slots): 1 SCB, 1 RE, at 1 SPC. All empty module bays must have a slot cover installed for proper cooling air circulation. - o For MX960 (2 available RE slots, 12 additional slots): 1 SCB, 1 RE, at least 1 SPC. All empty module bays must have a slot cover installed for proper cooling air circulation. - includes the inverse three-dimensional space where non-crypto-relevant line cards fit, with the backplane port serving as the physical interface. Page 7 of 41 The cryptographic module provides for an encrypted connection, using SSH, between the management station and the module. All other data input or output from the module are considered plaintext for this FIPS 140-3 validation. The module does not rely on external devices for input and output of security sensitive parameters (SSPs). Figure 1 Physical Cryptographic Boundary (Left to Right: MX240, MX480, MX960) JNP-SPC3 Figure 2 MX-SPC3 Services Card ### 2.2 Tested and Vendor Affirmed Module Version and Identification ###### Tested Module Identification -Hardware: | Model and/or Part Number | Hardware Version | Firmware Version | Processors | Features | |----------------------------|--------------------|--------------------|---------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | MX240 | MX240 | JUNOS 22.2R3- S1.9 | Intel Xeon C5518, Intel Xeon E5-2658 v4, Intel Xeon CPU E5-2608L v3 | Routing Engine (RE): RE-S-X6-64G, RE-S-X6- 128G; Switch control board (SCB): SCBE3-MX; Services Processing Card (SPC): MX-SPC3; Modular Port Concentrator (MPC): MPC10E-10C, MPC10E-15C | Page 8 of 41 Table 2: Tested Module Identification -Hardware | Model and/or Part Number | Hardware Version | Firmware Version | Processors | Features | |----------------------------|--------------------|--------------------|---------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | MX480 | MX480 | JUNOS 22.2R3- S1.9 | Intel Xeon C5518, Intel Xeon E5-2658 v4, Intel Xeon CPU E5-2608L v3 | Routing Engine (RE): RE-S-X6-64G, RE-S-X6- 128G; Switch control board (SCB): SCBE3-MX; Services Processing Card (SPC): MX-SPC3; Modular Port Concentrator (MPC): MPC10E-10C, MPC10E-15C | | MX960 | MX960 | JUNOS 22.2R3- S1.9 | Intel Xeon C5518, Intel Xeon E5-2658 v4, Intel Xeon CPU E5-2608L v3 | Routing Engine (RE): RE-S-X6-64G, RE-S-X6- 128G; Switch control board (SCB): SCBE3-MX; Services Processing Card (SPC): MX-SPC3; Modular Port Concentrator (MPC): MPC10E-10C, MPC10E-15C | ###### Tested Module Identification -Software, Firmware, Hybrid (Executable Code Sets): N/A The module is not classified as software, firmware, or hybrid; thus, this section is not applicable. ###### Tested Module Identification -Hybrid Disjoint Hardware: N/A The module is not classified as hybrid disjoint hardware; thus, this section is not applicable. ###### Tested Operational Environments - Software, Firmware, Hybrid: N/A The module is not classified as software, firmware, or hybrid; thus, this section is not applicable. ###### Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid: N/A There are no vendor-affirmed operational environments claimed. CMVP makes no statement as to the correct operation of the module or the security strengths of the generated keys when so ported if the specific operational environment is not listed on the validation certificate. ### 2.3 Excluded Components No components are excluded from the requirements of FIPS 140-3. ### 2.4 Modes of Operation ###### Modes List and Description: Page 9 of 41 Table 3: Modes List and Description | Mode Name | Description | Type | Status Indicator | |------------------|--------------------------------------------------------------------------------------------|----------|-----------------------------------------| | JUNOS-FIPS- MODE | Approved mode of operation enabled by following the configuration commands in Section 11.1 | Approved | Suffix string ":fips" in the cli prompt | Once the module has been securely initialized following the instructions provided in Section 11.1, the module is in approved mode of operation. Failure to follow the secure initialization instructions results in the module being in a non-compliant state which is out of scope of the validation. ### 2.5 Algorithms ###### Approved Algorithms: Although the module may have been tested for additional algorithms or modes, only those listed below are utilized by the module. OpenSSL Approved Cryptographic Functions | Algorithm | CAVP Cert | Properties | Reference | |--------------------------|-------------|---------------------------------------------------------------------------|-------------------| | AES-CBC | A3693 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38A | | AES-CTR | A3693 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38A | | ECDSA KeyGen (FIPS186-4) | A3693 | Curve - P-256, P-384, P-521 Secret Generation Mode - Testing Candidates | FIPS 186-4 | | ECDSA KeyVer (FIPS186-4) | A3693 | Curve - P-256, P-384, P-521 | FIPS 186-4 | | ECDSA SigGen (FIPS186-4) | A3693 | Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512 | FIPS 186-4 | | ECDSA SigVer (FIPS186-4) | A3693 | Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512 | FIPS 186-4 | | HMAC-SHA-1 | A3693 | Key Length - Key Length: 160 | FIPS 198-1 | | HMAC-SHA2-256 | A3693 | Key Length - Key Length: 256 | FIPS 198-1 | | HMAC-SHA2-512 | A3693 | Key Length - Key Length: 512 | FIPS 198-1 | | KAS-ECC-SSC Sp800- 56Ar3 | A3610 | Domain Parameter Generation Methods - P-256, P- 384, P-521 Scheme - | SP 800-56A Rev. 3 | Page 10 of 41 Table 4: Approved Algorithms - OpenSSL Approved Cryptographic Functions | Algorithm | CAVP Cert | Properties | Reference | |-------------------------|-------------|-----------------------------------------------------------------------------------------------------------|-------------| | | | ephemeralUnified - KAS Role - initiator | | | RSA KeyGen (FIPS186- 4) | A3693 | Key Generation Mode - B.3.3 Modulo - 2048, 4096 Primality Tests - Table C.2 Private Key Format - Standard | FIPS 186-4 | | RSA SigGen (FIPS186- 4) | A3693 | Signature Type - PKCS 1.5 Modulo - 2048, 4096 | FIPS 186-4 | | RSA SigVer (FIPS186-4) | A3693 | Signature Type - PKCS 1.5 Modulo - 2048, 4096 | FIPS 186-4 | | SHA-1 | A3693 | Message Length - Message Length: 0-65536 Increment 8 | FIPS 180-4 | | SHA2-256 | A3693 | Message Length - Message Length: 0-65536 Increment 8 | FIPS 180-4 | | SHA2-384 | A3693 | Message Length - Message Length: 0-65536 Increment 8 | FIPS 180-4 | | SHA2-512 | A3693 | Message Length - Message Length: 0-65536 Increment 8 | FIPS 180-4 | ###### Kernel Approved Cryptographic Functions Table 5: Approved Algorithms - Kernel Approved Cryptographic Functions | Algorithm | CAVP Cert | Properties | Reference | |----------------|-------------|------------------------------------------------------|-------------------| | HMAC DRBG | A3493 | Prediction Resistance - Yes Mode - SHA2-256 | SP 800-90A Rev. 1 | | HMAC-SHA2- 256 | A3493 | Key Length - Key Length: 160, 256 | FIPS 198-1 | | SHA2-256 | A3493 | Message Length - Message Length: 0-51200 Increment 8 | FIPS 180-4 | | SHA2-512 | A3361 | Message Length - Message Length: 0-51200 Increment 8 | FIPS 180-4 | ###### OpenSSH Approved Cryptographic Functions | Algorithm | CAVP Cert | Properties | Reference | |---------------|-------------|------------------------------------------------------------------------------------------|-------------------| | KDF SSH (CVL) | A4271 | Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-256, SHA2-384, SHA2- 512 | SP 800-135 Rev. 1 | Page 11 of 41 Table 6: Approved Algorithms - OpenSSH Approved Cryptographic Functions ###### Vendor-Affirmed Algorithms: Table 7: Vendor-Affirmed Algorithms | Name | Properties | Implementation | Reference | |--------|---------------------|------------------------|----------------------------------------------------------------| | CKG | Key type:Asymmetric | Junos 22.2R1 - OpenSSL | SP 800-133 Rev.2 Section 4, example 1 direct output from DRBG. | ###### Non-Approved, Allowed Algorithms: N/A for this module. ###### Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. ####### Non-Approved, Not Allowed Algorithms: N/A for this module. ### 2.6 Security Function Implementations The module implements the security functions listed in the following table. | Name | Type | Description | Properties | Algorithms | |--------------------|---------------|--------------------------------------------------------|--------------|------------------------------------------------------------------------------------------------------------| | Enc/Dec (SSH) | BC-UnAuth | Unauthenticated encryption for SSH | | AES-CBC: (A3693) AES-CTR: (A3693) | | KAS-SSC (SSH) | KAS-SSC | Key Agreement Scheme Shared Secret Computation for SSH | | KAS-ECC-SSC Sp800-56Ar3: (A3610) | | ECDSA SigGen (SSH) | DigSig-SigGen | Signature Generation for peer authentication in SSH | | ECDSA SigGen (FIPS186-4): (A3693) SHA2-256: (A3693) SHA2-384: (A3693) SHA2-512: (A3693) HMAC DRBG: (A3493) | | ECDSA SigVer (SSH) | DigSig-SigVer | Signature Verification for peer authentication in SSH | | ECDSA SigVer (FIPS186-4): (A3693) SHA2-256: (A3693) | Page 12 of 41 | Name | Type | Description | Properties | Algorithms | |---------------------|---------------------|-------------------------------------------------------------------------------------|--------------|---------------------------------------------------------------------------------------------------------------------| | MAC (SSH) | MAC | Message Authentication for SSH | | HMAC-SHA-1: (A3693) HMAC-SHA2-256: (A3693) HMAC-SHA2-512: (A3693) | | KDF (SSH) | KAS-135KDF | Key derivation Function for SSH | | KDF SSH: (A4271) SHA-1: (A3693) SHA2-256: (A3693) SHA2-384: (A3693) | | SHA (LibMD) | SHA | Message Digest Generation | | SHA-1: (A3367) SHA2-256: (A3367) SHA2-512: (A3367) | | MAC (LibMD) | MAC | Message authentication | | HMAC-SHA-1: (A3367) HMAC-SHA2-256: (A3367) | | DRBG (Kernel) | DRBG | Random Bit Generation | | HMAC DRBG: (A3493) HMAC-SHA2-256: (A3493) SHA2-256: (A3493) | | ECDSA KeyGen (PKID) | AsymKeyPair- KeyGen | ECDSA Key Generation used for SSH when authentication keys are internally generated | | ECDSA KeyGen (FIPS186-4): (A3693) ECDSA KeyVer (FIPS186-4): (A3693) CKG: () Key type: Asymmetric HMAC DRBG: (A3493) | | RSA KeyGen (PKID) | AsymKeyPair- KeyGen | RSA Key generation used for SSH when authentication keys are internally generated | | RSA KeyGen (FIPS186-4): (A3693) CKG: () Key type: Asymmetric HMAC DRBG: (A3493) | Page 13 of 41 Table 8: Security Function Implementations | Name | Type | Description | Properties | Algorithms | |----------------------|---------------------|-------------------------------------|--------------|---------------------------------------------------------------------------------------------------------------------| | RSA SigGen (SSH) | DigSig-SigGen | RSA Signature Generation for SSH | | RSA SigGen (FIPS186-4): (A3693) | | RSA SigVer (SSH) | DigSig-SigVer | RSA Signature verification for SSH | | RSA SigVer (FIPS186-4): (A3693) | | Verify image | DigSig-SigVer | Verification of software image | | ECDSA SigVer (FIPS186-4): (A3693) SHA2-256: (A3693) SHA2-384: (A3693) | | Full KAS (SSH) | KAS-Full | Full Key Agreement for SSH | | KAS-ECC-SSC Sp800-56Ar3: (A3610) KDF SSH: (A4271) SHA-1: (A3693) SHA2-256: (A3693) SHA2-384: (A3693) | | KAS-ECC KeyGen (SSH) | AsymKeyPair- KeyGen | KAS-ECC Key Pair Generation for SSH | | ECDSA KeyGen (FIPS186-4): (A3693) ECDSA KeyVer (FIPS186-4): (A3693) CKG: () Key type: Asymmetric HMAC DRBG: (A3493) | | ENT | ENT-ESV | Entropy source | | SHA2-512: (A3361) | ### 2.7 Algorithm Specific Information The module includes RSA and ECDSA algorithms that have been validated using FIPS 186-4 CAVP tests, which are mathematically identical to FIPS 186-5 CAVP tests. Per IG C.K, all RSA and ECDSA algorithms implemented by the module are claimed compliant with FIPS 186-5. The module complies with IG C.F. RSA Key Generation, Signature Generation and Signature Verification have been tested and validated using CAVP testing for all implemented modulus lengths (2048, 3072 and 4096 bits). The number of Miller-Rabin tests used for primality testing as part of RSA Key Generation is consistent with Table C.3. Page 14 of 41 The module implements the following Approved key agreement methods which have been CAVP tested and validated: - KAS-ECC-SSC per SP 800-56A Rev. 3 (FIPS 140-3 IG D.F Scenario 2, path 1). The module obtains the FIPS 140-3 IG D.F required key agreement assurances in accordance with Section 5.6.2 of SP800-56A Rev. 3. All the key agreement protocols implemented by the module are Diffie-Hellman based. The module includes approved KDF algorithms for the SSH protocol. No parts of the protocol, other than the approved cryptographic algorithms and the KDFs, have been tested by the CAVP and CMVP. ### 2.8 RBG and Entropy Table 9: Entropy Certificates | Cert Number | Vendor Name | |---------------|------------------| | E56 | Juniper Networks | Table 10: Entropy Sources | Name | Type | Operational Environment | Sample Size | Entropy per Sample | Conditioning Component | |--------------------------------------|---------------|---------------------------|---------------|----------------------|--------------------------| | Junos OS Non-Physical Entropy Source | Non- Physical | Intel Xeon C5518 | 512 bits | 448 bits | A3361 (SHA2- 512) | The entropy source is used to seed the module's HMAC DRBG with the minimum required 256 -bits of entropy. Each 512-bit block of conditioned output from the entropy source contains 448 bits of entropy. The HMAC DRBG is used for all random data required by the module, including key generation. There are no initialization procedures required by the users of the module to operate the entropy source in a compliant manner. The module complies to the ESV Public Use document of the validated entropy source (Cert. E56). ### 2.9 Key Generation The cryptographic module implements the key generation methods listed above in the Security Functions implementation table. Page 15 of 41 ### 2.10 Key Establishment The cryptographic module implements the key establishment methods listed above in the Security Functions implementation table. ### 2.11 Industry Protocols The cryptographic module supports the protocols listed below. No part of these protocols, other than the approved cryptographic algorithms and the KDFs, have been tested by the CAVP and CMVP. The SSH algorithms allow independent selection of key exchange, authentication, cipher, and integrity. In reference to the supported protocols table below, each column of options for a given protocol is independent and may be used in any viable combination. | Protocol | Key Exchange | Auth | Cipher | Integrity | |------------|-------------------------------|----------------------|-----------------------------------------|----------------------------------------| | SSHv2 | KAS-ECC (P-256, P-384, P-521) | RSA 2048 ECDSA P-256 | AES CBC 128/192/256 AES CTR 128/192/256 | HMAC-SHA-1 HMAC-SHA2-256 HMAC-SHA2-512 | Page 16 of 41 ## 3 Cryptographic Module Interfaces ### 3.1 Ports and Interfaces The following table maps each physical interface to one or more logical interface types defined in the FIPS 140-3 standard. Table 11: Ports and Interfaces | Physical Port | Logical Interface(s) | Data That Passes | |------------------|----------------------------------------------------|---------------------------| | Ethernet (data) | Data Input Data Output Control Input Status Output | LAN Communications | | Ethernet (mgmt.) | Data Input Data Output Control Input Status Output | Remote management | | Serial | Control Input Status Output | Local management | | Reset Button | Control Input | Reset | | LED | Status Output | Status indicator lighting | | Power | Power | Power | Page 17 of 41 ## 4 Roles, Services, and Authentication ### 4.1 Authentication Methods Table 12: Authentication Methods | Method Name | Description | Security Mechanism | Strength Each Attempt | Strength per Minute | |--------------------------|-----------------------------------------------------------------------------------------|----------------------|------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | Password authentication | User and CO authentication via SSH or console. Minimum of 10 ASCII character passwords. | SHA (LibMD) | Probability of guessing: 1/(96^10) < 1/1,000,000. | Timed access mechanism allows max of 9 attempts / min. Probability of guessing: 9/(96^10) < 1/100,000. | | Signature authentication | User/CO authentication via SSH | ECDSA SigVer (SSH) | Strength of signature algorithm, minimum 112-bits. Probability of success for random attempt: 1/(2^112) < 1/1,000,000. | A rate of 1 CPU cycle per failed authentication for the Intel Xeon E5-2658 v4 processor (14 cores, 2.3 GHz) allows for the probability of success by brute- force attack: 60 x 14 x 2.3 x 10^9 x 1/(2^112) < 1/100,000. | The module enforces the separation of roles using either password-based authentication or signature-based authentication. ### 4.2 Roles Table 13: Roles | Name | Type | Operator Type | Authentication Methods | |-----------------------|--------|-----------------|--------------------------------------------------| | User | Role | Monitor | Password authentication Signature authentication | | Cryptographic Officer | Role | CO | Password authentication Signature authentication | The module supports two roles: Cryptographic Officer (CO) and User. The module supports rolebased operator authentication for assuming these roles, using methods specified in Section 4.1. The module supports concurrent operators but does not support a maintenance role and/or bypass capability. The Cryptographic Officer role configures and monitors the module via a console or SSH connection. As root or super-user, the Cryptographic Officer has permission to view and edit secrets within the module and establish VPN tunnels. Page 18 of 41 The User role monitors the router via the console or SSH. The user role cannot change the configuration. ### 4.3 Approved Services | Name | Description | Indicator | Inputs | Outputs | Security Functions | SSP Access | |--------------------|-------------------------------------|------------------------------|--------------|----------------------------------------------------------------------------|---------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | Configure security | Security relevant configuration | ':fips' suffix in CLI prompt | CLI commands | Status | SHA (LibMD) MAC (LibMD) DRBG (Kernel) ECDSA KeyGen (PKID) RSA KeyGen (PKID) ENT | Cryptographic Officer - HMAC DRBG V value: E - HMAC DRBG Key value: E - HMAC DRBG Entropy Input: E - HMAC DRBG Seed: E - CO-PW: W,R - User-PW: W,R - SSH-Priv: G,R,W | | Configure | Non-security relevant configuration | None | CLI commands | Status | None | Cryptographic Officer | | Show status | Show status | None | CLI command | Status | None | Cryptographic Officer User | | Zeroize | Zeroize/destroy all CSPs | None | CLI command | None (completion indicator is implicitly provided by the module rebooting) | None | Cryptographic Officer - HMAC DRBG V value: Z - HMAC DRBG Key value: Z - HMAC DRBG Seed: Z - HMAC DRBG Entropy Input: Z - SSH-DH- Shared-Secret: Z - SSH-Priv: Z - SSH-SEKs: Z - CO-PW: Z - User-PW: Z - SSH-PUB: Z - Auth-User Pub: Z | Page 19 of 41 | Name | Description | Indicator | Inputs | Outputs | Security Functions | SSP Access | |-------------|--------------------------------------------------------------|------------------------------|-------------|---------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | | | | | | | - Root-CA: Z - Package-CA: Z - SSH-DH-PUB (self): Z - SSH-DH-PUB (peer): Z | | SSH connect | Initiate SSH connection for SSH monitoring and control (CLI) | ':fips' suffix in CLI prompt | SSH packets | SSH packets, status | Enc/Dec (SSH) KAS-SSC (SSH) ECDSA SigGen (SSH) ECDSA SigVer (SSH) MAC (SSH) KDF (SSH) RSA SigGen (SSH) RSA SigVer (SSH) Full KAS (SSH) KAS-ECC KeyGen (SSH) ENT | Cryptographic Officer - HMAC DRBG V value: E - HMAC DRBG Key value: E - HMAC DRBG Entropy Input: E - HMAC DRBG Seed: E - SSH-DH- Shared-Secret: G,E - SSH-DH-Priv: G,E - SSH-SEKs: G,E - Auth-CO Pub: E - SSH-Priv: E - CO-PW: E - SSH-DH-PUB (self): G - SSH-DH-PUB (peer): E User - HMAC DRBG V value: E - HMAC DRBG Key value: E - HMAC DRBG Entropy Input: E - HMAC DRBG Seed: E - SSH-Priv: E - User-PW: E - SSH-DH- Shared-Secret: G,E - SSH-DH-Priv: G,E - SSH-SEKs: G | Page 20 of 41 | Name | Description | Indicator | Inputs | Outputs | Security Functions | SSP Access | |----------------|--------------------------------------|-------------|--------------------|-----------|----------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | | | | | | | - SSH-DH-PUB (self): G - SSH-DH-PUB (peer): E - Auth-User Pub: E | | Console access | Console monitoring and control (CLI) | None | CLI command | Status | None | Cryptographic Officer - CO-PW: E User - User-PW: R,E | | Remote reset | Software initiated reset | None | CLI command | Status | None | Cryptographic Officer - HMAC DRBG V value: Z - HMAC DRBG Key value: Z - HMAC DRBG Entropy Input: Z - HMAC DRBG Seed: Z - SSH-DH- Shared-Secret: Z - SSH-DH-Priv: Z - SSH-SEKs: Z - SSH-DH-PUB (self): Z - SSH-DH-PUB (peer): Z | | Local reset | Hardware reset or power cycle | None | Manual power cycle | Status | None | Unauthenticated - HMAC DRBG V value: Z - HMAC DRBG Key value: Z - HMAC DRBG Entropy Input: Z - HMAC DRBG Seed: Z - SSH-DH- Shared-Secret: Z - SSH-SEKs: Z - SSH-DH-PUB (self): Z | Page 21 of 41 Table 14: Approved Services | Name | Description | Indicator | Inputs | Outputs | Security Functions | SSP Access | |--------------------|----------------------------------------------------------------------------------|------------------------------|-----------------------|-------------|----------------------|----------------------------------------------------| | | | | | | | - SSH-DH-PUB (peer): Z | | Traffic | Traffic requiring no cryptographic services | None | Traffic in | Traffic out | None | Unauthenticated | | Load Image | Loading of firmware image | ':fips' suffix in CLI prompt | CLI command | status | Verify image | Cryptographic Officer - Root-CA: E - Package-CA: E | | Perform self-tests | On-demand execution of all pre- operational and conditional algorithm self-tests | None | Local or remote reset | status | None | Cryptographic Officer User Unauthenticated | | Show version | Show firmware version | None | CLI command | Status | None | Cryptographic Officer User | ### 4.4 Non-Approved Services N/A for this module. ### 4.5 External Software/Firmware Loaded The module includes a firmware load service to support necessary updates. Only the CO can install the new image using the CLI as described in Section 11.1. The loaded firmware is a complete image replacement and constitutes an entirely new module and version of Junos OS which would require a separate FIPS 140-3 validation. Page 22 of 41 ## 5. Software/Firmware Security ### 5.1 Integrity Techniques The cryptographic module implements an approved firmware integrity self-test that uses ECDSA P-256 with SHA2-256 to ensure the integrity of all Junos OS firmware components. The selftest is automatically run on powerup. It can also be run on demand by the module's operator by power cycling the module. When the integrity check fails, the module enters an error state (kernel panic) which can only be exited by power-cycling the module. ### 5.2 Initiate on Demand The self-test is automatically run on powerup. It can also be run on demand by the module's operator by power cycling the module. Page 23 of 41 ## 6 Operational Environment ### 6.1 Operational Environment Type and Requirements ###### Type of Operational Environment: Non-Modifiable How Requirements are Satisfied: The module consists of hardware containing a non-modifiable operational environment as per the FIPS 140-3 definitions. It includes a firmware load service to support necessary updates. The loaded firmware is a complete image replacement and constitutes an entirely new module and version of Junos OS which would require a separate FIPS 140-3 validation. ### 6.2 Configuration Settings and Restrictions There are no security rules, settings, or restrictions to the configuration of the operational environment beyond the initialization instructions to set the module in approved mode. Page 24 of 41 ## 7 Physical Security ### 7.1 Mechanisms and Actions Required Table 15: Mechanisms and Actions Required | Mechanism | Inspection Frequency | Inspection Guidance | |-------------------------------------------------------|------------------------|-----------------------| | Production-grade components with standard passivation | N/A | N/A | The module's physical embodiment is that of a multi -chip standalone device that meets Level 1 Physical Security requirements. The module consists of production-grade components with standard passivation. Page 25 of 41 ## 8 Non-Invasive Security This section is not applicable, as there are currently no approved non-invasive mitigation techniques specified in ISO/IEC 19790:2012. Page 26 of 41 ## 9 Sensitive Security Parameters Management ### 9.1 Storage Areas Table 16: Storage Areas | Storage Area Name | Description | Persistence Type | |---------------------|----------------------|--------------------| | RAM | Random Access Memory | Dynamic | | SSD | Solid-Stated Drive | Dynamic | ### 9.2 SSP Input-Output Methods Table 17: SSP Input-Output Methods | Name | From | To | Format Type | Distribution Type | Entry Type | SFI or Algorithm | |-----------------------|--------------|-------------|---------------|---------------------|--------------|--------------------| | Manual CLI entry | Local CO | RAM | Plaintext | Manual | Direct | | | Entry via SSH | Remote CO | RAM | Encrypted | Automated | Electronic | Enc/Dec (SSH) | | Entry via console | Local CO | RAM | Plaintext | Manual | Electronic | | | Output via SSH | RAM | Remote CO | Encrypted | Automated | Electronic | Enc/Dec (SSH) | | Output via console | RAM | Local CO | Plaintext | Manual | Direct | | | Entry as part of KAS | Remote peer | RAM | Plaintext | Automated | Electronic | | | Output as part of KAS | RAM | Remote peer | Plaintext | Automated | Electronic | | | Pre-loaded | Manufacturer | SSD | Plaintext | Manual | Direct | | ### 9.3 SSP Zeroization Methods | Zeroization Method | Description | Rationale | Operator Initiation | |----------------------|-----------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------| | Reset | Zeroisation of SSPs in RAM via invocation of local or remote reset service | RAM is volatile and all data is lost when power is taken off. Zeroisation is practically instantaneous. | Yes, both User and CO, via invocation of Local Reset or Remote Reset services | | Zeroize CLI command | These command wipe clean all the SSPs/configs as well as the disk and installs a factory default firmware image | This command overwrites all data on disk and forces a power cycle | Yes, CO via invocation of zeroize CLI command | Page 27 of 41 | Zeroization Method | Description | Rationale | Operator Initiation | |---------------------------|-----------------------------------------------------|------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------| | Explicit zeroize function | Zeroisation of SSPs in memory when no longer needed | Use of explicit zeroisation function destroys SSP information immediately by overwriting memory area with zeroes | No. The operator cannot directly initiate this method. | Table 18: SSP Zeroization Methods ###### The CO can run the following commands to zeroize the approved mode SSPs: user@host> request vmhost zeroize This command wipes clean all the SSPs/configs as well as the disk and install a factory default firmware image. After zeroizing the system, the module is no longer in a FIPS compliant state. Installation and configuration as per section 11.1 is required to enter the FIPS compliant state and enable the Approved mode of operation. The Cryptographic Officer must retain control of the module while zeroization is in process. Zeroization commands, as described above, and power cycling are initiated by the operator. The module automatically zeroizes all SSPs when no longer required by calling explicit delete commands. Session termination is initiated by the operator or by environmental errors. The completion of zeroization is indicated implicitly. If the zeroization is initiated using a zeroization command or explicit delete command, completion of the command indicates that zeroization has successfully completed. If the zeroization is initiated by power cycling the module, then successful reboot of the module indicates that zeroization has completed successfully. In the case of zeroization initiated by session termination, SSPs are zeroized when the session terminates, and session termination is indicated in the log. ### 9.4 SSPs | Name | Description | Size - Strength | Type - Category | Generated By | Established By | Used By | |---------------------|-----------------------------------------------------------|-------------------|-----------------------------|----------------|------------------|---------------| | HMAC DRBG V value | A critical value of the internal state of DRBG per IG D.L | 256 - 256 | DRBG internal state - CSP | DRBG (Kernel) | | DRBG (Kernel) | | HMAC DRBG Key value | A critical value of the internal state of DRBG per IG D.L | 256 - 256 | DRBG internal state - CSP | DRBG (Kernel) | | DRBG (Kernel) | | HMAC DRBG | A critical value of the internal state of DRBG | 256 - 256 | Entropy source output - CSP | ENT | | DRBG (Kernel) | Page 28 of 41 | Name | Description | Size - Strength | Type - Category | Generated By | Established By | Used By | |------------------------|----------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------|-------------------------------|---------------------------------------|------------------|-------------------------------------| | Entropy Input | provided by entropy source | | | | | | | HMAC DRBG Seed | Seed material used to seed or reseed the HMAC DRBG | 256 - 256 | DRBG internal state - CSP | DRBG (Kernel) | | DRBG (Kernel) | | SSH-DH- Shared- Secret | Shared DH value computed from the ephemeral DH key-pairs as part of SSH and used to derive session keys. P- 256, P-384 and P-521 | 256, 384, 521 - 128, 192, 256 | DH shared value - CSP | | KAS-SSC (SSH) | KDF (SSH) | | SSH-Priv | SSH host authentication key (ECDSA or RSA) | 2048, 256, 4096, 384, 521 - 112,128, 152, 192, 256 | Asymmetric private key - CSP | ECDSA KeyGen (PKID) RSA KeyGen (PKID) | | ECDSA SigGen (SSH) RSA SigGen (SSH) | | SSH-DH- Priv | SSH Diffie-Hellman private component. Ephemeral Diffie-Hellman private key used in SSH. P-256, P-384 and P-521 | 256, 384, 521 - 128, 192, 256 | Asymmetric private key - CSP | KAS-ECC KeyGen (SSH) | | KAS-SSC (SSH) | | SSH-SEKs | Session keys used with SSH-2. | 128, 192, 256 - 112,128, 192, 256 | Symmetric Key - CSP | KDF (SSH) | | Enc/Dec (SSH) MAC (SSH) | | CO-PW | Password used to authenticate the CO | n/a - n/a | Authentication password - CSP | | | SHA (LibMD) | | User-PW | Password used to authenticate the User. | n/a - n/a | Authentication password - CSP | | | | | SSH-PUB | SSH Public Host Key | 2048, 256, 4096, 384, 521 - 112,128, 152, 192, 256 | Asymmetric key - PSP | ECDSA KeyGen (PKID) RSA KeyGen (PKID) | | | | Auth-User Pub | SSH User Authentication Public Key | 2048, 256, 4096, 384, 521 - 112,128, | Asymmetric key - PSP | | | ECDSA SigVer (SSH) RSA | Page 29 of 41 | Name | Description | Size - Strength | Type - Category | Generated By | Established By | Used By | |--------------------|--------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------|----------------------|----------------------|------------------|-------------------------------------| | | | 152, 192, 256 | | | | SigVer (SSH) | | Root-CA | JuniperRootCA. Used to verify the validity of the PackagCA | 256, 384 - 128, 196 | Asymmetric key - PSP | | | Verify image | | Package- CA | Certificate that holds the public key of the signing key that was used to generate all the signatures used on the packages and signatures lists. | 256 - 128 | Asymmetric key - PSP | | | Verify image | | SSH-DH- PUB (self) | ECDH Public Keys generated by module and used with SSH for key establishment | 256, 384, 521 - 128, 192, 256 | Asymmetric key - PSP | KAS-ECC KeyGen (SSH) | | | | SSH-DH- PUB (peer) | ECDH Public Keys provided by protocol peer device and used with SSH for key establishment. P- 256, P-384 and P-521 | 256, 384, 521 - 128, 192, 256 | Asymmetric key - PSP | | | KAS-SSC (SSH) | | Auth-CO Pub | SSH CO Authentication Public Key | 2048, 256, 4096, 384, 521 - 112,128, 152, 192, 256 | Asymmetric key - PSP | | | ECDSA SigVer (SSH) RSA SigVer (SSH) | Table 19: SSP Table 1 | Name | Input - Output | Storage | Storage Duration | Zeroization | Related SSPs | |---------------------|------------------|---------------|----------------------------------------------------------------|----------------|----------------| | HMAC DRBG V value | | RAM:Plaintext | Until updated by HMAC_DRBG_Update() | Reset | | | HMAC DRBG Key value | | RAM:Plaintext | Until updated by HMAC_DRBG_Update() | Reset | | | HMAC DRBG | | RAM:Plaintext | Until HMAC_Instantiate_Update() or HMAC_DRBG_Reseed() complete | Reset Explicit | | Page 30 of 41 | Name | Input - Output | Storage | Storage Duration | Zeroization | Related SSPs | |------------------------|--------------------------------------------------|------------------------------|----------------------------------------------------------------|-----------------------------------------------------|----------------| | Entropy Input | | | | zeroize function | | | HMAC DRBG Seed | | RAM:Plaintext | Until HMAC_Instantiate_Update() or HMAC_DRBG_Reseed() complete | Reset Explicit zeroize function | | | SSH-DH- Shared- Secret | | RAM:Plaintext | Until SSH session termination | Reset Explicit zeroize function | | | SSH-Priv | | RAM:Plaintext SSD:Plaintext | Until SSH session termination | Reset Zeroize CLI command Explicit zeroize function | | | SSH-DH-Priv | | RAM:Plaintext | Until SSH session termination | Reset Explicit zeroize function | | | SSH-SEKs | | RAM:Plaintext | Until SSH session termination | Reset Explicit zeroize function | | | CO-PW | Manual CLI entry Entry via SSH Entry via console | SSD:Encrypted RAM:Plaintext | Until authentication session termination | Zeroize CLI command | | | User-PW | Manual CLI entry Entry via SSH Entry via console | RAM:Plaintext SSD:Obfuscated | Until authentication session termination | Zeroize CLI command | | | SSH-PUB | Output via SSH Output via console Output as | SSD:Plaintext | | Zeroize CLI command | | Page 31 of 41 | Name | Input - Output | Storage | Storage Duration | Zeroization | Related SSPs | |--------------------|---------------------------------|---------------|-------------------------------|---------------------------------|----------------| | | part of KAS | | | | | | Auth-User Pub | Entry via SSH Entry via console | SSD:Plaintext | | Zeroize CLI command | | | Root-CA | Pre-loaded | SSD:Plaintext | | Zeroize CLI command | | | Package-CA | Pre-loaded | SSD:Plaintext | | Zeroize CLI command | | | SSH-DH- PUB (self) | Output as part of KAS | RAM:Plaintext | Until SSH session termination | Reset Explicit zeroize function | | | SSH-DH- PUB (peer) | Entry as part of KAS | RAM:Plaintext | Until SSH session termination | Reset Explicit zeroize function | | | Auth-CO Pub | Entry via SSH Entry via console | | | Zeroize CLI command | | Table 20: SSP Table 2 ### 9.5 Transitions The following transitions apply to algorithms used by this module: SHA-1: The SHA-1 hash algorithm will be non-Approved for all cryptographic purposes after December 31, 2030. Page 32 of 41 ## 10 Self-Tests On power up or reset, the module performs the pre-operational self-tests and the indicated conditional cryptographic algorithm self-tests described below. All KATs must be completed successfully prior to any other use of cryptography by the module. The algorithms utilized in the pre-operational firmware integrity test must pass their own CASTs prior to the Integrity Test. ### 10.1 Pre-Operational Self-Tests Table 21: Pre-Operational Self-Tests | Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | |--------------------------|----------------------------|---------------|-------------------|--------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | Firmware Integrity check | ECDSA P- 256 with SHA2-256 | KAT | SW/FW Integrity | PASS/FAIL console output | ECDSA Verify | | Critical functions test | SHA2-256 | KAT | Critical Function | PASS/FAIL console output | The module implements a critical function that checks that any file that is executed is registered in a manifest of executable files that comes with the firmware. A pre-operational critical function test is implemented that verifies the integrity of the operational environment is being enforced by having the kernel attempt to run a specific executable file that does not contain a hash in the manifest file. The test is successful if it verifies that the specific file cannot be executed. | ### 10.2 Conditional Self-Tests | Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | Conditions | |-----------------------------|--------------------------|---------------|-------------|-------------------------------------------|------------|--------------| | Entropy Source (start-up) | n/a | APT, RCT | CAST | Console output / output of entropy source | Start-up | On power-up | | Entropy Source (continuous) | n/a | APT, RCT | CAST | Console output / output of entropy source | Continuous | On power-up | | AES-CBC (A3693) Encrypt | Key Sizes: 128, 192, 256 | KAT | CAST | PASS/FAIL console output | Encrypt | On power-up | | AES-CBC (A3693) Decrypt | Key Sizes: 128, 192, 256 | KAT | CAST | PASS/FAIL console output | Decrypt | On power-up | Page 33 of 41 | Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | Conditions | |----------------------------------|--------------------------------------------------|---------------|-------------|--------------------------|-------------------------------------------------|--------------| | AES-CTR (A3693) Encrypt | Key Sizes: 128, 192, 256 | KAT | CAST | PASS/FAIL console output | Encrypt | On power-up | | AES-CTR (A3693) Decrypt | Key Sizes: 128, 192, 256 | KAT | CAST | PASS/FAIL console output | Decrypt | On power-up | | HMAC DRBG (A3693) | SHA2-256 | KAT | CAST | PASS/FAIL console output | Health-tests initialise, re- seed, and generate | On power-up | | KAS-ECC-SSC Sp800-56Ar3 (A3610) | P-256 (SHA 256) P-384 (SHA 384) P- 521 (SHA 512) | KAT | CAST | PASS/FAIL console output | ECDH computation | On power-up | | ECDSA SigGen (FIPS186-4) (A3693) | P-256, P-384, P-521 | KAT | CAST | PASS/FAIL console output | Sign | On power-up | | ECDSA SigVer (FIPS186-4) (A3693) | P-256, P-384, P-521 | KAT | CAST | PASS/FAIL console output | Verify | On power-up | | HMAC-SHA-1 (A3693) | Key size: 160 bits, = 160 | KAT | CAST | PASS/FAIL console output | MAC | On power-up | | HMAC-SHA2- 256 (A3693) | Key size: 256 bits, = 256 | KAT | CAST | PASS/FAIL console output | MAC | On power-up | | HMAC-SHA2- 512 (A3693) | Key size: 512 bits, = 512 | KAT | CAST | PASS/FAIL console output | MAC | On power-up | | RSA SigGen (FIPS186-4) (A3693) | RSA 2048 w/ SHA2-256, RSA 4096 w/ SHA2-256 | KAT | CAST | PASS/FAIL console output | Sign | On power-up | | RSA SigVer (FIPS186-4) (A3693) | RSA 2048 w/ SHA2-256, RSA 4096 w/ SHA2-256 | KAT | CAST | PASS/FAIL console output | Verify | On power-up | | SHA-1 (A3693) | n/a | KAT | CAST | PASS/FAIL console output | Hash | On power-up | | SHA2-256 (A3693) | n/a | KAT | CAST | PASS/FAIL console output | Hash | On power-up | Page 34 of 41 | Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | Conditions | |----------------------------------|----------------------------|---------------|-------------|------------------------------------------|------------------------------------------------|-------------------| | SHA2-384 (A3693) | n/a | KAT | CAST | PASS/FAIL console output | Hash | On power-up | | SHA2-512 (A3693) | n/a | KAT | CAST | PASS/FAIL console output | Hash | On power-up | | KDF SSH (A4271) | SHA-1, SHA2- 256, SHA2-384 | KAT | CAST | PASS/FAIL console output | Key derivation | On power-up | | SHA-1 (A3367) | n/a | KAT | CAST | PASS/FAIL console output | Hash | On power-up | | SHA2-256 (A3367) | n/a | KAT | CAST | PASS/FAIL console output | Hash | On power-up | | SHA2-512 (A3367) | n/a | KAT | CAST | PASS/FAIL console output | Hash | On power-up | | HMAC-SHA-1 (A3367) | Key size: 160 bits, = 160 | KAT | CAST | PASS/FAIL console output | MAC | On power-up | | HMAC-SHA2- 256 (A3367) | Key size: 256 bits, = 256 | KAT | CAST | PASS/FAIL console output | MAC | On power-up | | HMAC DRBG (A3493) | SHA2-256 | KAT | CAST | PASS/FAIL console output | Instantiate, Reseed, Generate | On power-up | | HMAC-SHA2- 256 (A3493) | Key size:256 bits, = 256 | KAT | CAST | PASS/FAIL console output | MAC | On power-up | | SHA2-256 (A3493) | n/a | KAT | CAST | PASS/FAIL console output | Hash | On power-up | | ECDSA KeyGen (FIPS186-4) (A3693) | P-256, P-384, P-521 | PCT | PCT | Returned key/transition soft error state | Generation and Verification of ECDSA signature | On key generation | | RSA KeyGen (FIPS186-4) (A3693) | RSA 2048, RSA 4096 | PCT | PCT | Returned key/transition soft error state | Generation and Verification of signature | On key generation | | FW load | ECDSA P-256 with SHA2-256 | KAT | SW/FW Load | PASS/FAIL console output | Verification of ECDSA signature on FW | On FW load | | SHA2-512 (A3361) | n/a | KAT | CAST | PASS/FAIL console output | hash | On power-up | Page 35 of 41 Table 22: Conditional Self-Tests 10.3 Periodic Self-Test Information Table 23: Pre-Operational Periodic Information | Algorithm or Test | Test Method | Test Type | Period | Periodic Method | |----------------------------------|---------------|-------------|------------|-------------------| | Entropy Source (start-up) | APT, RCT | CAST | On demand | Manually | | Entropy Source (continuous) | APT, RCT | CAST | Continuous | Automatically | | AES-CBC (A3693) Encrypt | KAT | CAST | On demand | Manually | | AES-CBC (A3693) Decrypt | KAT | CAST | On demand | Manually | | AES-CTR (A3693) Encrypt | KAT | CAST | On demand | Manually | | AES-CTR (A3693) Decrypt | KAT | CAST | On demand | Manually | | HMAC DRBG (A3693) | KAT | CAST | On demand | Manually | | KAS-ECC-SSC Sp800-56Ar3 (A3610) | KAT | CAST | On demand | Manually | | ECDSA SigGen (FIPS186-4) (A3693) | KAT | CAST | On demand | Manually | | ECDSA SigVer (FIPS186-4) (A3693) | KAT | CAST | On demand | Manually | Page 36 of 41 Page 37 of 41 | Algorithm or Test | Test Method | Test Type | Period | Periodic Method | |----------------------------------|-----------------|--------------|----------------------|-------------------| | HMAC-SHA-1 (A3693) | KAT | CAST | On demand | Manually | | HMAC-SHA2-256 (A3693) | KAT | CAST | On demand | Manually | | HMAC-SHA2-512 (A3693) | KAT | CAST | On demand | Manually | | RSA SigGen (FIPS186-4) (A3693) | KAT | CAST | On demand | Manually | | RSA SigVer (FIPS186-4) (A3693) | KAT | CAST | On demand | Manually | | SHA-1 (A3693) | KAT | CAST | On demand | Manually | | SHA2-256 (A3693) | KAT | CAST | On demand | Manually | | SHA2-384 (A3693) | KAT | CAST | On demand | Manually | | SHA2-512 (A3693) | KAT | CAST | On demand | Manually | | KDF SSH (A4271) | KAT | CAST | On demand | Manually | | SHA-1 (A3367) | KAT | CAST | On demand | Manually | | SHA2-256 (A3367) | KAT | CAST | On demand | Manually | | SHA2-512 (A3367) | KAT | CAST | On demand | Manually | | HMAC-SHA-1 (A3367) | KAT | CAST | On power-up | Manually | | HMAC-SHA2-256 (A3367) | KAT | CAST | On power-up | Manually | | HMAC DRBG (A3493) | KAT | CAST | On power-up | Manually | | HMAC-SHA2-256 (A3493) | KAT | CAST | On power-up | Manually | | SHA2-256 (A3493) | KAT | CAST | On power-up | Manually | | ECDSA KeyGen (FIPS186-4) (A3693) | PCT | PCT | On condition trigger | Automatic | | RSA KeyGen (FIPS186-4) (A3693) | PCT | PCT | On condition trigger | Automatic | | FW load | KAT | SW/FW Load | On FW load request | Automatic | | SHA2-512 (A3361) | KAT | CAST | On power-up | Manually | | Manual SSP entry | Duplicate entry | Manual Entry | On condition trigger | Automatic | Table 24: Conditional Periodic Information ### 10.4 Error States Table 25: Error States | Name | Description | Conditions | Recovery Method | Indicator | |------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------|--------------------------------------------------------------|------------------------| | Critical Failure state | The cryptographic module ceases to perform cryptographic operations, inhibits all data output, and provides status of the error via syslog messages and console status output | On self-test error | Power cycle | Console status output | | Soft Error State | A non-critical self-test failure occurs, causing a failure of the triggering operation | PCT, firmware load test, continuous entropy health test failure | The module processes the error, and resumes normal operation | Console displays error | The module enters error state upon failure of any selftests, causing the kernel to 'panic' and all execution to halt. The only way to exit from this state is to reboot the module, which causes the self-tests to be repeated and pass successfully before the corresponding algorithms are usable. ### 10.5 Operator Initiation of Self-Tests Self -tests that are performed at power-up are available on demand by power cycling the module. Page 38 of 41 ## 11 Life-Cycle Assurance ### 11.1 Installation, Initialization, and Startup Procedures Before installation of module firmware, CO must first zeroize any module SSPs by following the instructions in Section 9.3. Once zeroization is complete, the CO must install the JUNOS firmware image on the device using the following CLI command: CO@host> request system software add /<image-path>/<image-filename> no-copy no-validate reboot. ###### The image-filename for the validated firmware is as follows: - junos-vmhost-install-srx-x86-64-22.2R3-S1.9.tgz Next, the CO shall proceed as follows: 1. Enable the approved mode on the device. CO@host> set system fips chassis level 1 2. user@host# set system root-authentication plain-text-password 2. Set the root password. New password: <type password here> 3. Commit and reboot the device. ``` CO@host# commit ``` Once the module is rebooted and the integrity and self-tests have run successfully on initial power-on in, the module is operating in the approved mode of operation. The CO must create a backup image of the firmware to ensure it is also an approved mode Junos OS image by issuing the request system snapshot command. The show version command will display the version of the Junos OS on the device so that the CO can confirm it is the FIPS validated version. The CO should also verify the presence of the suffix string ':fips' in the cli prompt, indicating the module is operating in approve d mode. TLS and IKE/IPsec are not enabled by default and must not be enabled for FIPS compliant usage of the module. ### 11.2 Administrator Guidance Page 39 of 41 The Cryptographic Officer is the person responsible for enabling, configuring, monitoring, and maintaining the module in approved mode. The Cryptographic Officer securely installs Junos OS on the device, enables the approved of operation, establishes keys and passwords for other users and software modules, and initializes the device before network connection. The Cryptographic Officer can configure and monitor the module through a console or SSH connection. ### 11.3 Non-Administrator Guidance No specific non-administrator guidance is required to operate the module. ### 11.4 Design and Rules The module design corresponds to the security rules below. The term must in this context specifically refers to a requirement for correct usage of the module in the approved mode; all other statements indicate a security rule implemented by the module. 1. The module clears previous authentications on power cycle. 2. Power up self-tests do not require any operator action. 3. Data output is inhibited during key generation, self-tests, zeroization, and error states. 4. Status information does not contain CSPs or sensitive data that if misused could lead to a compromise of the module. 5. There are no restrictions on which SSPs are zeroized by the zeroization service. 6. The module does not support a maintenance interface or role. 7. The module does not output intermediate key values. 8. The module requires two independent internal actions to be performed prior to outputting plaintext CSPs. 9. The cryptographic officer must invoke the zeroize command (as per Section 9.3) before using the firmware load service to install a new firmware image. 10. The cryptographic officer must determine whether firmware being loaded is a legacy use of the firmware load service. 11. The cryptographic officer must retain control of the module while zeroization is in process. 12. IKE/IPsec and TLS features must not be enabled. ### 11.5 Maintenance Requirements No special maintenance requirements and required. ### 11.6 End of Life When disposing of the cryptographic module, the CO shall perform the zeroize command described in Section 9.3. Page 40 of 41 ## 12 Mitigation of Other Attacks The module does not implement mechanisms to mitigate other attacks beyond what is described in this security policy. Page 41 of 41