{"_type": "sec_certs.sample.fips.FIPSCertificate", "dgst": "c9dc6a27c2a566b4", "cert_id": 5097, "web_data": {"_type": "sec_certs.sample.fips.FIPSCertificate.WebData", "module_name": "NetApp StorageGRID Kernel Crypto API", "validation_history": [{"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry", "date": "2025-11-30", "validation_type": "Initial", "lab": "atsec information security corporation"}], "vendor_url": "https://www.netapp.com", "vendor": "NetApp, Inc.", "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/November 2025_181225_1202.pdf", "module_type": "Software", "standard": "FIPS 140-3", "status": "active", "level": 1, "caveat": "When operated in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.", "exceptions": ["Physical security: N/A", "Non-invasive security: N/A", "Mitigation of other attacks: N/A"], "embodiment": "Multi-Chip Stand Alone", "description": "The NetApp StorageGRID Kernel Crypto API provides a C language API for use by other (kernel space and user space) processes that require cryptographic functionality.", "tested_conf": null, "hw_versions": null, "fw_versions": null, "sw_versions": null, "mentioned_certs": {}, "historical_reason": null, "date_sunset": "2030-11-29", "revoked_reason": null, "revoked_link": null}, "pdf_data": {"_type": "sec_certs.sample.fips.FIPSCertificate.PdfData", "keywords": {"fips_cert_id": {}, "fips_security_level": {"Level": {"Level 1": 2}}, "fips_certlike": {"Certlike": {"HMAC-SHA-1": 10, "HMAC-SHA-512": 4, "SHA2-512": 12, "SHA-1": 18, "SHA2-256": 15, "SHA2-224": 11, "SHA2-384": 9, "SHA3-224": 3, "SHA3-256": 4, "SHA3-384": 3, "SHA3-512": 3, "SHA-256": 3, "SHA- 512": 2, "SHA-224": 1, "SHA-384": 1, "SHA-512 and 2048": 1, "SHA-3": 1, "- PKCS 1": 1, "RSA PKCS#1": 8, "PKCS#1": 12, "AES-128": 2, "AES-192": 2, "AES-256": 1, "AES-CMAC 128": 1, "AES- 256": 1, "PKCS 1": 1}}, "vendor": {}, "eval_facility": {"atsec": {"atsec": 62}}, "symmetric_crypto": {"AES_competition": {"AES": {"AES-128": 2, "AES-192": 2, "AES-256": 1, "AES": 28, "AES-": 3}, "CAST": {"CAST": 112}}, "constructions": {"MAC": {"HMAC": 14, "HMAC-SHA-512": 2, "CMAC": 2}}}, "asymmetric_crypto": {"ECC": {"ECDH": {"ECDH": 1}, "ECDSA": {"ECDSA": 5}, "ECC": {"ECC": 3}}, "FF": {"DH": {"Diffie-Hellman": 7, "DH": 16}}}, "pq_crypto": {}, "hash_function": {"SHA": {"SHA1": {"SHA-1": 18}, "SHA2": {"SHA-256": 3, "SHA-224": 1, "SHA-384": 1, "SHA-512": 1}, "SHA3": {"SHA3-224": 3, "SHA3-256": 4, "SHA3-384": 3, "SHA3-512": 3, "SHA-3": 1}}, "PBKDF": {"PBKDF2": 2, "PBKDF": 1}}, "crypto_scheme": {"MAC": {"MAC": 13}, "KA": {"Key Agreement": 1}}, "crypto_protocol": {"TLS": {"TLS": {"TLS 1.2": 4, "TLS 1.3": 4, "TLS": 13}}, "IKE": {"IKEv2": 1}, "IPsec": {"IPsec": 7}}, "randomness": {"PRNG": {"DRBG": 30}, "RNG": {"RNG": 1, "RBG": 10}}, "cipher_mode": {"ECB": {"ECB": 1}, "CBC": {"CBC": 2}, "CTR": {"CTR": 1}, "CFB": {"CFB": 1}, "OFB": {"OFB": 1}, "GCM": {"GCM": 3}, "CCM": {"CCM": 2}, "XTS": {"XTS": 8}}, "ecc_curve": {"NIST": {"P-256": 14, "P-384": 4}}, "crypto_engine": {}, "tls_cipher_suite": {}, "crypto_library": {}, "vulnerability": {}, "side_channel_analysis": {}, "device_model": {}, "tee_name": {"AMD": {"PSP": 3}, "IBM": {"SSC": 1}}, "os_name": {}, "cplc_data": {}, "ic_data_group": {}, "standard_id": {"FIPS": {"FIPS 140-3": 68, "FIPS PUB 140-3": 2, "FIPS186-5": 8, "FIPS 186-5": 5, "FIPS 198-1": 10, "FIPS186-4": 2, "FIPS 186-4": 2, "FIPS 180-4": 6, "FIPS 202": 5, "FIPS 197": 1}, "NIST": {"SP 800-38A": 7, "SP 800-38C": 2, "SP 800-38B": 2, "SP 800-38D": 4, "SP 800-38F": 2, "SP 800-38E": 3, "SP 800-90A": 3, "SP 800-56A": 3, "SP 800-56C": 1, "SP 800-108": 1, "SP 800-90B": 1}, "PKCS": {"PKCS 1": 1, "PKCS#1": 10}, "RFC": {"RFC 4106": 3, "RFC 5288": 4, "RFC 8446": 4, "RFC 7296": 1}, "ISO": {"ISO/IEC 24759": 2, "ISO/IEC 19790": 2}}, "javacard_version": {}, "javacard_api_const": {}, "javacard_packages": {}, "certification_process": {}}, "policy_metadata": {"pdf_file_size_bytes": 636583, "pdf_is_encrypted": false, "pdf_number_of_pages": 62, "/Author": "Christopher Dickerman", "/Comments": "", "/Company": "", "/CreationDate": "D:20251125161016-05'00'", "/Creator": "Acrobat PDFMaker 25 for Word", "/Keywords": "", "/ModDate": "D:20251125161330-05'00'", "/Producer": "Adobe PDF Library 25.1.51", "/SourceModified": "", "/Subject": "", "/Title": "", "pdf_hyperlinks": {"_type": "Set", "elements": ["https://doi.org/10.6028/NIST.SP.800-38B", "https://doi.org/10.6028/NIST.SP.800-90B", "https://doi.org/10.6028/NIST.SP.800-38D", "https://doi.org/10.6028/NIST.SP.800-38F", "https://doi.org/10.6028/NIST.FIPS.186-4", "https://doi.org/10.17487/RFC8446", "https://doi.org/10.6028/NIST.SP.800-108r1-upd1", "https://doi.org/10.6028/NIST.SP.800-38A", "https://doi.org/10.6028/NIST.FIPS.197-upd1", "https://doi.org/10.6028/NIST.SP.800-140Br1", "https://doi.org/10.6028/NIST.FIPS.198-1", "https://doi.org/10.6028/NIST.SP.800-52r2", "https://doi.org/10.6028/NIST.SP.800-131Ar2", "https://doi.org/10.6028/NIST.FIPS.140-3", "https://doi.org/10.6028/NIST.SP.800-133r2", "https://doi.org/10.6028/NIST.FIPS.180-4", "https://doi.org/10.6028/NIST.SP.800-38C", "https://doi.org/10.6028/NIST.SP.800-56Ar3", "https://doi.org/10.6028/NIST.SP.800-38A-Add", "https://doi.org/10.6028/NIST.FIPS.202", "https://doi.org/10.6028/NIST.SP.800-38E", "https://doi.org/10.6028/NIST.FIPS.186-5", "https://doi.org/10.17487/RFC4106", "https://doi.org/10.17487/RFC5246", "https://doi.org/10.6028/NIST.SP.800-56Cr2", "https://doi.org/10.6028/NIST.SP.800-90Ar1", "https://csrc.nist.gov/CSRC/media/Projects/cryptographic-module-validation-program/documents/fips%20140-3/FIPS%20140-3%20IG.pdf", "https://doi.org/10.17487/RFC8017"]}}, "module_algorithms": {"_type": "Set", "elements": ["HMAC-SHA-1A6267", "SHA2-512A6266", "ECDSA KeyGen (FIPS186-5)A6242", "SHA3-512A6242", "SHA3-224A6242", "Counter DRBGA6263", "HMAC-SHA2-384A6266", "KAS-ECC-SSC Sp800-56Ar3A6242", "HMAC-SHA3-224A6242", "AES-OFBA6251", "HMAC-SHA2-512A6266", "SHA3-384A6242", "SHA2-384A6266", "HMAC-SHA2-256A6267", "SHA2-224A6267", "HMAC DRBGA6267", "KAS-FFC-SSC Sp800-56Ar3A6242", "AES-KWA6251", "AES-CFB128A6251", "AES-CTRA6251", "RSA SigVer (FIPS186-5)A6242", "AES-CBC-CS3A6251", "SHA-1A6267", "Hash DRBGA6267", "AES-ECBA6263", "KDA OneStep SP800-56Cr2A6242", "HMAC-SHA3-512A6242", "AES-CBCA6251", "RSA SigVer (FIPS186-4)A6242", "SHA3-256A6242", "HMAC-SHA3-256A6242", "AES-CMACA6251", "Safe Primes Key GenerationA6242", "AES-XTS Testing Revision 2.0A6261", "AES-GMACA6261", "HMAC-SHA2-224A6267", "HMAC-SHA3-384A6242", "AES-GCMA6263", "SHA2-256A6267", "KDF SP800-108A6242", "AES-CCMA6251"]}, "policy_algorithms": {"_type": "Set", "elements": ["#A6260", "#A6246", "#A6248", "#A6258", "#A6259", "#A6255", "#A6266", "#A6252", "#A6249", "#A6243", "#A6245", "#A6247", "#A6257", "#A6263", "#A6250", "#A6265", "#A6262", "#A6256", "#A6254", "#A6264", "#A6267", "#A6251", "#A6242", "#A6244", "#A6261", "#A6253"]}, "is_br1_format": true, "br1_deviations": 0, "br1_tables": {"_type": "sec_certs.heuristics.br1.table_parsing.model.br1_tables.BR1Tables", "security_levels": {"section": 1, "subsection": 2, "found": true, "entries": [{"section": "1", "title": "General", "level": "1"}, {"section": "2", "title": "Cryptographic module specification", "level": "1"}, {"section": "3", "title": "Cryptographic module interfaces", "level": "1"}, {"section": "4", "title": "Roles, services, and authentication", "level": "1"}, {"section": "5", "title": "Software/Firmware security", "level": "1"}, {"section": "6", "title": "Operational environment", "level": "1"}, {"section": "7", "title": "Physical security", "level": "N/A"}, {"section": "8", "title": "Non-invasive security", "level": "N/A"}, {"section": "9", "title": "Sensitive security parameter management", "level": "1"}, {"section": "10", "title": "Self-tests", "level": "1"}, {"section": "11", "title": "Life-cycle assurance", "level": "1"}, {"section": "12", "title": "Mitigation of other attacks", "level": "N/A"}, {"section": "", "title": "Overall Level", "level": "1"}]}, "tested_module_id_hw": {"section": 2, "subsection": 2, "found": false, "entries": []}, "tested_module_id_sw_fw_hy": {"section": 2, "subsection": 2, "found": true, "entries": [{"packageFileName": "/boot/vmlinuz- 6.1.129-1-ntap1- amd64; /usr/bin/kcapi- hasher; /lib/x86_64- linux- gnu/libkcapi.so.1.4.0", "swFwVersion": "kernel 6.1.129-1- ntap1-amd64; libkcapi 1.4.0- 1+ntap0", "features": "N/A", "integrityTest": "HMAC-SHA2-256 (libkcapi.so); HMAC- SHA2-512 (vmlinuz, kcapi-hasher)"}]}, "tested_module_id_hw_hy": {"section": 2, "subsection": 2, "found": false, "entries": []}, "tested_op_env_sw_fw_hy": {"section": 2, "subsection": 2, "found": true, "entries": [{"operatingSystem": "StorageGRID 12", "hardwarePlatform": "SG5812", "processors": "Intel Xeon D- 1735TR", "paa_pai": "Yes", "hypervisorHostOs": "", "version": "kernel 6.1.129-1- ntap1-amd64; libkcapi 1.4.0- 1+ntap0"}, {"operatingSystem": "StorageGRID 12", "hardwarePlatform": "SG5812", "processors": "Intel Xeon D- 1735TR", "paa_pai": "No", "hypervisorHostOs": "", "version": "kernel 6.1.129-1- ntap1-amd64; libkcapi 1.4.0- 1+ntap0"}, {"operatingSystem": "StorageGRID 12", "hardwarePlatform": "SG6160", "processors": "Intel Xeon Gold 5318Y", "paa_pai": "Yes", "hypervisorHostOs": "", "version": "kernel 6.1.129-1- ntap1-amd64; libkcapi 1.4.0- 1+ntap0"}, {"operatingSystem": "StorageGRID 12", "hardwarePlatform": "SG6160", "processors": "Intel Xeon Gold 5318Y", "paa_pai": "No", "hypervisorHostOs": "", "version": "kernel 6.1.129-1- ntap1-amd64; libkcapi 1.4.0- 1+ntap0"}, {"operatingSystem": "StorageGRID 12", "hardwarePlatform": "SG110", "processors": "Intel Xeon Silver 4310", "paa_pai": "Yes", "hypervisorHostOs": "", "version": "kernel 6.1.129-1- ntap1-amd64; libkcapi 1.4.0- 1+ntap0"}, {"operatingSystem": "StorageGRID 12", "hardwarePlatform": "SG110", "processors": "Intel Xeon Silver 4310", "paa_pai": "No", "hypervisorHostOs": "", "version": "kernel 6.1.129-1- ntap1-amd64; libkcapi 1.4.0- 1+ntap0"}]}, "vendor_affirmed_op_env_sw_fw_hy": {"section": 2, "subsection": 2, "found": true, "entries": [{"operatingSystem": "StorageGRID 12", "hardwarePlatform": "SGF6112"}, {"operatingSystem": "StorageGRID 12", "hardwarePlatform": "SG1100"}, {"operatingSystem": "StorageGRID 12", "hardwarePlatform": "SG5860"}]}, "modes_of_operation": {"section": 2, "subsection": 4, "found": true, "entries": [{"name": "Approved mode", "description": "Automatically entered whenever an approved service is requested", "type": "Approved", "statusIndicator": "Mapped to approved service indicator in Section 4.3 for all approved algorithms except GCM: respective approved service function returns indicator 0. For GCM: crypto_aead_get_flags(tfm) has the CRYPTO_TFM_FIPS_COMPLIANCE flag set"}, {"name": "Non- approved mode", "description": "Automatically entered whenever a non- approved service is requested", "type": "Non- Approved", "statusIndicator": "No service indicator required for non-approved services per IG 2.4.C"}]}, "approved_algorithms": {"section": 2, "subsection": 5, "found": true, "entries": [{"algorithm": "AES-CBC", "cavpCertName": "A6242, A6245, A6248, A6251", "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256", "reference": "SP 800-38A"}, {"algorithm": "AES-CBC-CS3", "cavpCertName": "A6242, A6245, A6248, A6251", "properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256", "reference": "SP 800-38A"}, {"algorithm": "AES-CCM", "cavpCertName": "A6242, A6245, A6251", "properties": "Key Length - 128, 192, 256", "reference": "SP 800-38C"}, {"algorithm": "AES-CFB128", "cavpCertName": "A6242, A6245, A6251", "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256", "reference": "SP 800-38A"}, {"algorithm": "AES-CMAC", "cavpCertName": "A6242, A6245, A6251", "properties": "Direction - Generation Key Length - 128, 192, 256", "reference": "SP 800-38B"}, {"algorithm": "AES-CTR", "cavpCertName": "A6242, A6245, A6248, A6251", "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256", "reference": "SP 800-38A"}, {"algorithm": "AES-ECB", "cavpCertName": "A6242, A6243, A6244, A6245, A6246, A6247, A6248, A6249, A6250, A6251, A6252, A6253, A6254, A6255, A6256, A6258, A6259, A6260, A6261, A6262, A6263", "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256", "reference": "SP 800-38A"}, {"algorithm": "AES-GCM", "cavpCertName": "A6242, A6244, A6245, A6247, A6248, A6250, A6251, A6253, A6254, A6256, A6258, A6260, A6261, A6263", "properties": "Direction - Decrypt, Encrypt IV Generation - External Key Length - 128, 192, 256", "reference": "SP 800-38D"}, {"algorithm": "AES-GCM", "cavpCertName": "A6243, A6246, A6249, A6252, A6255, A6259, A6262", "properties": "Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256", "reference": "SP 800-38D"}, {"algorithm": "AES-GMAC", "cavpCertName": "A6242, A6245, A6248, A6251, A6254, A6258, A6261", "properties": "Direction - Decrypt, Encrypt IV Generation - External Key Length - 128, 192, 256", "reference": "SP 800-38D"}, {"algorithm": "AES-KW", "cavpCertName": "A6242, A6245, A6251", "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256", "reference": "SP 800-38F"}, {"algorithm": "AES-OFB", "cavpCertName": "A6242, A6245, A6251", "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256", "reference": "SP 800-38A"}, {"algorithm": "AES-XTS Testing Revision 2.0", "cavpCertName": "A6242, A6245, A6248, A6251, A6254, A6257, A6258, A6261", "properties": "Direction - Decrypt, Encrypt Key Length - 128, 256", "reference": "SP 800-38E"}, {"algorithm": "Counter DRBG", "cavpCertName": "A6242, A6243, A6244, A6245, A6246, A6247, A6248, A6249, A6250, A6251, A6252, A6253, A6254, A6255, A6256, A6258, A6259, A6260, A6261, A6262, A6263", "properties": "Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - Yes", "reference": "SP 800-90A Rev. 1"}, {"algorithm": "ECDSA KeyGen (FIPS186-5)", "cavpCertName": "A6242", "properties": "Curve - P-256, P-384 Secret Generation Mode - testing candidates", "reference": "FIPS 186-5"}, {"algorithm": "Hash DRBG", "cavpCertName": "A6242, A6264, A6265, A6266, A6267", "properties": "Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256,", "reference": "SP 800-90A Rev. 1"}, {"algorithm": "HMAC DRBG", "cavpCertName": "A6242, A6264, A6265, A6266, A6267", "properties": "SHA2-512 Prediction Resistance - No, Yes", "reference": "SP 800-90A Rev. 1"}, {"algorithm": "Algorithm", "cavpCertName": "CAVP Cert", "properties": "Mode - SHA-1, SHA2-256, SHA2-512", "reference": ""}, {"algorithm": "HMAC-SHA-1", "cavpCertName": "A6242, A6264, A6265, A6266, A6267", "properties": "Key Length - Key Length: 112-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA2- 224", "cavpCertName": "A6242, A6264, A6265, A6266, A6267", "properties": "Key Length - Key Length: 112-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA2- 256", "cavpCertName": "A6242, A6264, A6265, A6266, A6267", "properties": "Key Length - Key Length: 112-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA2- 384", "cavpCertName": "A6242, A6264, A6265, A6266", "properties": "Key Length - Key Length: 112-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA2- 512", "cavpCertName": "A6242, A6264, A6265, A6266", "properties": "Key Length - Key Length: 112-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA3- 224", "cavpCertName": "A6242", "properties": "Key Length - Key Length: 112-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA3- 256", "cavpCertName": "A6242", "properties": "Key Length - Key Length: 112-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA3- 384", "cavpCertName": "A6242", "properties": "Key Length - Key Length: 112-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "HMAC-SHA3- 512", "cavpCertName": "A6242", "properties": "Key Length - Key Length: 112-524288 Increment 8", "reference": "FIPS 198-1"}, {"algorithm": "KAS-ECC-SSC Sp800-56Ar3", "cavpCertName": "A6242", "properties": "Domain Parameter Generation Methods - P-256, P-384 Scheme - ephemeralUnified - KAS Role - initiator, responder", "reference": "SP 800-56A Rev. 3"}, {"algorithm": "KAS-FFC-SSC Sp800-56Ar3", "cavpCertName": "A6242", "properties": "Domain Parameter Generation Methods - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192 Scheme - dhEphem - KAS Role - initiator, responder", "reference": "SP 800-56A Rev. 3"}, {"algorithm": "KDA OneStep SP800-56Cr2", "cavpCertName": "A6242", "properties": "Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224- 2048 Increment 8", "reference": "SP 800-56C Rev. 2"}, {"algorithm": "KDF SP800- 108", "cavpCertName": "A6242", "properties": "KDF Mode - Counter Supported Lengths - Supported Lengths: 112- 4096 Increment 8", "reference": "SP 800-108 Rev. 1"}, {"algorithm": "RSA SigVer (FIPS186-4)", "cavpCertName": "A6242", "properties": "Signature Type - PKCS 1.5 Modulo - 2048, 3072, 4096", "reference": "FIPS 186-4"}, {"algorithm": "RSA SigVer (FIPS186-5)", "cavpCertName": "A6242", "properties": "Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5", "reference": "FIPS 186-5"}, {"algorithm": "Safe Primes Key Generation", "cavpCertName": "A6242", "properties": "Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192", "reference": "SP 800-56A Rev. 3"}, {"algorithm": "SHA-1", "cavpCertName": "A6242, A6264, A6265, A6266, A6267", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2", "reference": "FIPS 180-4"}, {"algorithm": "SHA2-224", "cavpCertName": "A6242, A6264, A6265, A6266, A6267", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2", "reference": "FIPS 180-4"}, {"algorithm": "SHA2-256", "cavpCertName": "A6242, A6264, A6265, A6266, A6267", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2", "reference": "FIPS 180-4"}, {"algorithm": "SHA2-384", "cavpCertName": "A6242, A6264, A6265, A6266", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2", "reference": "FIPS 180-4"}, {"algorithm": "SHA2-512", "cavpCertName": "A6242, A6264, A6265, A6266", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2", "reference": "FIPS 180-4"}, {"algorithm": "SHA3-224", "cavpCertName": "A6242", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2", "reference": "FIPS 202"}, {"algorithm": "SHA3-256", "cavpCertName": "A6242", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2", "reference": "FIPS 202"}, {"algorithm": "SHA3-384", "cavpCertName": "A6242", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2", "reference": "FIPS 202"}, {"algorithm": "SHA3-512", "cavpCertName": "A6242", "properties": "Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2", "reference": "FIPS 202"}]}, "vendor_affirmed_algos": {"section": 2, "subsection": 5, "found": true, "entries": [{"name": "Asymmetric CKG", "algoPropList": "Key Type:Asymmetric", "implName": "N/A", "reference": "SP 800-133r2, section 4, example 1"}]}, "non_approved_allowed_algos": {"section": 2, "subsection": 5, "found": false, "entries": []}, "non_approved_allowed_NSC": {"section": 2, "subsection": 5, "found": false, "entries": []}, "non_approved_not_allowed": {"section": 2, "subsection": 5, "found": true, "entries": [{"name": "AES-GCM with external IV", "use": "Encryption with external IV (not compliant to FIPS 140- 3 IG C.H)"}, {"name": "KBKDF in libkcapi", "use": "Key Derivation with implementation not tested by CAVP"}, {"name": "HKDF in libkcapi", "use": "Key Derivation with implementation not tested by CAVP"}, {"name": "PBKDF2 in libkcapi", "use": "Password-Based Key Derivation with implementation not tested by CAVP"}, {"name": "RSA PKCS#1 v1.5 with pre- hashed message", "use": "Signature generation / verification"}, {"name": "RSA PKCS#1 v1.5", "use": "Key encapsulation / un-encapsulation (not compliant to SP 800-56Br2)"}, {"name": "RSA primitive", "use": "Encryption / decryption (not compliant to SP 800-56Br2)"}]}, "ports_interfaces": {"section": 3, "subsection": 1, "found": true, "entries": [{"physicalPort": "N/A", "logicalInterface": "Data Input", "data": "API data input parameters, AF_ALG type input sockets, SOL_TLS type input sockets"}, {"physicalPort": "N/A", "logicalInterface": "Data Output", "data": "API data output parameters, AF_ALG type output sockets, SOL_TLS type output sockets, /proc/sys/crypto virtual files"}, {"physicalPort": "N/A", "logicalInterface": "Control Input", "data": "API function calls, API control input parameters, AF_ALG type input sockets, SOL_TLS type input sockets"}, {"physicalPort": "N/A", "logicalInterface": "Status Output", "data": "API return values, AF_ALG type output sockets, SOL_TLS type output sockets, kernel logs"}]}, "authentication_methods": {"section": 4, "subsection": 1, "found": false, "entries": []}, "roles": {"section": 4, "subsection": 2, "found": true, "entries": [{"name": "Crypto Officer", "type": "Role", "operatorType": "Crypto Officer", "authMethodList": "None"}]}, "approved_services": {"section": 4, "subsection": 3, "found": true, "entries": [{"name": "Encryptio n", "description": "Encrypt a plaintext", "indicator": "crypto_skcipher_setkey returns 0", "inputs": "AES key, plaintex t, IV (if require d)", "outputs": "Ciphert ext", "secFunImpl": "Encryptio n", "rolesSspAccess": "Crypto Officer - AES key: W,E"}, {"name": "Decryptio n", "description": "Decrypt a cipherte xt", "indicator": "crypto_skcipher_setkey returns 0", "inputs": "AES key, ciphert ext, IV (if require d)", "outputs": "Plaintex t", "secFunImpl": "Decryptio n", "rolesSspAccess": "Crypto Officer - AES key: W,E"}, {"name": "Authentic ated encryptio n", "description": "Encrypt a plaintext in an authenti cated mode", "indicator": "AES-GCM: crypto_aead_get_flags(t fm) has CRYPTO_ALG_FIPS140_ COMPLIANT set; Others: crypto_aead_setkey returns 0", "inputs": "AES key, plaintex t, IV (CCM/G CM)", "outputs": "Ciphert ext, MAC tag (CCM/G CM)", "secFunImpl": "Authentic ated encryptio n", "rolesSspAccess": "Crypto Officer - AES key: W,E"}, {"name": "Authentic ated decryptio n", "description": "Decrypt a cipherte xt in an authenti cated mode", "indicator": "crypto_aead_setkey returns 0", "inputs": "AES key, ciphert ext, IV (CCM/G CM), MAC tag (CCM/G CM)", "outputs": "Plaintex t or failure", "secFunImpl": "Authentic ated decryptio n", "rolesSspAccess": "Crypto Officer - AES key: W,E"}, {"name": "Message digest", "description": "Compute a message digest", "indicator": "crypto_shash_init returns 0", "inputs": "Messag e", "outputs": "Digest value", "secFunImpl": "Message digest", "rolesSspAccess": "Crypto Officer"}, {"name": "Message authentic ation code generatio n", "description": "Compute a MAC tag", "indicator": "crypto_shash_init returns 0", "inputs": "AES key or HMAC key, messag e", "outputs": "MAC tag", "secFunImpl": "Message authentic ation code generatio n", "rolesSspAccess": "Crypto Officer - AES key: W,E - HMAC key: W,E"}, {"name": "Message authentic ation code verificati on", "description": "Verify a MAC tag", "indicator": "crypto_shash_init returns 0", "inputs": "AES key, messag e, MAC tag", "outputs": "Pass/fail", "secFunImpl": "Message authentic ation code verificati on", "rolesSspAccess": "Crypto Officer - AES key: W,E"}, {"name": "Key- based key derivatio n", "description": "Derive keying material from a key- derivatio n key", "indicator": "crypto_kdf108_ctr_gene rate returns 0", "inputs": "Key- derivati on key, output length", "outputs": "Derived key", "secFunImpl": "Key- based key derivatio n", "rolesSspAccess": "Crypto Officer - Key- derivati on key: W,E - Derived key: G,R"}, {"name": "Key- establish ment key derivatio n", "description": "Derive keying material from a shared secret", "indicator": "crypto_kdf108_ctr_gene rate returns 0", "inputs": "Shared secret, output length", "outputs": "Derived key", "secFunImpl": "Key- establish ment key derivatio n", "rolesSspAccess": "Crypto Officer - Shared secret: W,E - Derived key: G,R"}, {"name": "Random number generatio n", "description": "Generate random bytes", "indicator": "crypto_rng_get_bytes returns 0", "inputs": "Output length", "outputs": "Random bytes", "secFunImpl": "Random number generatio n", "rolesSspAccess": "Crypto Officer - Entropy input: G,E,Z - HMAC_D RBG Seed: G,E,Z - HMAC_D RBG internal state (V, Key): G,W,E"}, {"name": "", "description": "", "indicator": "", "inputs": "", "outputs": "", "secFunImpl": "", "rolesSspAccess": "- Hash_D RBG Seed: G,E,Z - Hash_D RBG internal state (V, C): G,W,E - CTR_DR BG Seed: G,E,Z - CTR_DR BG internal state (V, Key): G,W,E"}, {"name": "Shared secret computat ion", "description": "Compute a shared secret", "indicator": "crypto_kpp_compute_s hared_secret returns 0", "inputs": "Owner private key, peer public key", "outputs": "Shared secret", "secFunImpl": "Shared secret computat ion", "rolesSspAccess": "Crypto Officer - DH private key: W,E - DH public key: W,E - EC private key: W,E - EC public key: W,E - Shared secret:"}, {"name": "Key pair generatio n", "description": "Generate a key pair", "indicator": "crypto_kpp_set_secret and crypto_kpp_generate_p ublic_key return 0", "inputs": "Group or curve", "outputs": "Key pair", "secFunImpl": "Key pair generatio n", "rolesSspAccess": "G,R Crypto Officer - DH private key: G,R - DH public key: G,R - EC private"}, {"name": "", "description": "", "indicator": "", "inputs": "", "outputs": "", "secFunImpl": "", "rolesSspAccess": "key: G,R - EC public key: G,R - Interme diate key generati on value: G,E,Z"}, {"name": "Kernel TLS encryptio n", "description": "Perform TLS bulk data encrypti on", "indicator": "AES-GCM: crypto_aead_get_flags( aead) has CRYPTO_ALG_FIPS140_ COMPLIANT set; Others: setsockopt for SOL_TLS returns 0", "inputs": "AES key, plaintex t", "outputs": "Encrypt ed TLS record", "secFunImpl": "Authentic ated encryptio n", "rolesSspAccess": "Crypto Officer - AES key: W,E"}, {"name": "Kernel TLS decryptio n", "description": "Perform TLS bulk data decrypti on", "indicator": "setsockopt for SOL_TLS returns 0", "inputs": "AES key, encrypt ed TLS record", "outputs": "Plaintex t or failure", "secFunImpl": "Authentic ated decryptio n", "rolesSspAccess": "Crypto Officer - AES key: W,E"}, {"name": "Error detection code", "description": "Compute an EDC (crc32, crc32c, crct10dif )", "indicator": "None", "inputs": "Messag e", "outputs": "EDC", "secFunImpl": "None", "rolesSspAccess": "Crypto Officer"}, {"name": "Compres sion", "description": "Compres s data (deflate, lz4, lz4hc, lzo, zlib- deflate, zstd)", "indicator": "None", "inputs": "Data", "outputs": "Compre ssed data", "secFunImpl": "None", "rolesSspAccess": "Crypto Officer"}, {"name": "Generic system call", "description": "Use the kernel to perform various non- cryptogr aphic operatio ns", "indicator": "None", "inputs": "Identifi er, various argume nts", "outputs": "Various return values", "secFunImpl": "None", "rolesSspAccess": "Crypto Officer"}, {"name": "Show version", "description": "Return the module", "indicator": "None", "inputs": "N/A", "outputs": "Module name", "secFunImpl": "None", "rolesSspAccess": "Crypto Officer"}, {"name": "", "description": "name and version informati on", "indicator": "", "inputs": "", "outputs": "and version", "secFunImpl": "", "rolesSspAccess": ""}, {"name": "Show status", "description": "Return the module status", "indicator": "None", "inputs": "N/A", "outputs": "Module status", "secFunImpl": "None", "rolesSspAccess": "Crypto Officer"}, {"name": "Self-test", "description": "Perform the CASTs and integrity tests", "indicator": "None", "inputs": "N/A", "outputs": "Pass/Fai l", "secFunImpl": "Encryptio n Decryptio n Authentic ated encryptio n Authentic ated decryptio n Message digest Message authentic ation code verificati on Message authentic ation code generatio n Key- based key derivatio n Key- establish ment key derivatio n Random number generatio n Shared secret", "rolesSspAccess": "Crypto Officer"}, {"name": "", "description": "", "indicator": "", "inputs": "", "outputs": "", "secFunImpl": "computat ion Digital signature verificati on Key pair generatio n", "rolesSspAccess": ""}, {"name": "Zeroizati on", "description": "Zeroize all SSPs", "indicator": "None", "inputs": "Any SSP", "outputs": "N/A", "secFunImpl": "None", "rolesSspAccess": "Crypto Officer - AES key: Z - HMAC key: Z - Key- derivati on key: Z - Shared secret: Z - Derived key: Z - Entropy input: Z - HMAC_D RBG Seed: Z - HMAC_D RBG internal state (V, Key): Z - Hash_D RBG Seed: Z - Hash_D RBG internal state (V, C): Z - CTR_DR BG"}, {"name": "", "description": "", "indicator": "", "inputs": "", "outputs": "", "secFunImpl": "", "rolesSspAccess": "Seed: Z - CTR_DR BG internal state (V, Key): Z - DH public key: Z - DH private key: Z - EC public key: Z - EC private key: Z - Interme diate key generati on value: Z"}]}, "non_approved_services": {"section": 4, "subsection": 4, "found": true, "entries": [{"name": "AES-GCM with external IV encryption", "description": "Encrypt and authenticate a plaintext using AES-GCM with an external IV", "alg_accessed": "AES-GCM with external IV", "role": "Crypto Officer"}, {"name": "Key derivation (libkcapi)", "description": "Derive a key from a key- derivation key, shared secret, or password", "alg_accessed": "KBKDF in libkcapi HKDF in libkcapi PBKDF2 in libkcapi", "role": "Crypto Officer"}, {"name": "Pre-hashed message signature generation", "description": "Generate a digital signature for a pre-hashed message", "alg_accessed": "RSA PKCS#1 v1.5 with pre-hashed message", "role": "Crypto Officer"}, {"name": "Pre-hashed message signature verification", "description": "Verify a digital signature for a pre-hashed message", "alg_accessed": "RSA PKCS#1 v1.5 with pre-hashed message", "role": "Crypto Officer"}, {"name": "Key encapsulation", "description": "Key encapsulation using RSA PKCS#1 v1.5", "alg_accessed": "RSA PKCS#1 v1.5", "role": "Crypto Officer"}, {"name": "Key un-encapsulation", "description": "Key un-encapsulation using RSA PKCS#1 v1.5", "alg_accessed": "RSA PKCS#1 v1.5", "role": "Crypto Officer"}, {"name": "Encryption primitive", "description": "Compute the RSA encryption primitive", "alg_accessed": "RSA primitive", "role": "Crypto Officer"}, {"name": "Decryption primitive", "description": "Compute the RSA decryption primitive", "alg_accessed": "RSA primitive", "role": "Crypto Officer"}]}, "mechanisms_actions": {"section": 7, "subsection": 1, "found": false, "entries": []}, "storage_areas": {"section": 9, "subsection": 1, "found": true, "entries": [{"name": "RAM", "description": "Temporary storage for SSPs used by the module as part of service execution", "persistance": "Dynamic"}]}, "ssp_io_methods": {"section": 9, "subsection": 2, "found": true, "entries": [{"name": "API input parameters", "source": "Operator calling application TOEPP", "dest": "RAM", "format": "Plaintext", "distribution": "Manual", "entry": "Electronic", "sfiAlgo": ""}, {"name": "AF_ALG type input sockets", "source": "Operator calling application TOEPP", "dest": "RAM", "format": "Plaintext", "distribution": "Manual", "entry": "Electronic", "sfiAlgo": ""}, {"name": "SOL_TLS type input sockets", "source": "Operator calling application TOEPP", "dest": "RAM", "format": "Plaintext", "distribution": "Manual", "entry": "Electronic", "sfiAlgo": ""}, {"name": "API output parameters", "source": "RAM", "dest": "Operator calling application TOEPP", "format": "Plaintext", "distribution": "Manual", "entry": "Electronic", "sfiAlgo": ""}, {"name": "AF_ALG type output sockets", "source": "RAM", "dest": "Operator calling application TOEPP", "format": "Plaintext", "distribution": "Manual", "entry": "Electronic", "sfiAlgo": ""}]}, "ssp_zeroization_methods": {"section": 9, "subsection": 3, "found": true, "entries": [{"method": "Free cipher handle", "description": "Zeroizes the SSPs contained within the cipher handle", "rationale": "Memory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable.", "operatorId": "By calling the appropriate zeroization functions: AES key: crypto_free_skcipher and crypto_free_aead; HMAC key: crypto_free_shash and"}, {"method": "", "description": "", "rationale": "The completion of the zeroization routine indicates that the zeroization procedure succeeded.", "operatorId": "crypto_free_ahash; Key- derivation key: crypto_free_shash; Shared secret: crypto_free_shash; Entropy input: crypto_free_rng; DRBG seed: crypto_free_rng; DRBG internal state: crypto_free_rng; DH public key & DH private key: crypto_free_kpp; EC public key & EC private key: crypto_free_kpp; RSA public key: public_key_free"}, {"method": "Remove power from the module", "description": "De-allocates the volatile memory used to store SSPs", "rationale": "Volatile memory used by the module is overwritten within nanoseconds when power is removed. Module power off indicates that the zeroization procedure succeeded.", "operatorId": "By removing power"}, {"method": "Automatic", "description": "Automatically zeroized by the module when no longer needed", "rationale": "Memory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable.", "operatorId": "N/A"}]}, "self_tests": {"section": 10, "subsection": 1, "found": true, "entries": [{"algorithmOrTest": "HMAC-SHA2- 512 - kcapi- hasher", "testProps": "128-bit key", "testMethod": "Message Authentication", "type": "SW/FW Integrity", "indicator": "Module becomes operational", "details": "Integrity test for kcapi- hasher binary"}, {"algorithmOrTest": "HMAC-SHA2- 256 - libkcapi", "testProps": "256-bit key", "testMethod": "Message Authentication", "type": "SW/FW Integrity", "indicator": "Module becomes operational", "details": "Integrity test for libkcapi shared library"}, {"algorithmOrTest": "HMAC-SHA2- 512 - vmlinuz", "testProps": "128-bit key", "testMethod": "Message Authentication", "type": "SW/FW Integrity", "indicator": "Module becomes operational", "details": "Integrity test for vmlinuz binary"}]}, "cond_self_tests": {"section": 10, "subsection": 2, "found": true, "entries": [{"algorithmOrTest": "AES-CBC Encryption", "testProps": "128, 192, 256-bit keys", "testMethod": "KAT", "type": "CAS T", "indicator": "Module is operational", "details": "Encryption", "condition": "Module initializatio n"}, {"algorithmOrTest": "AES-CBC Decryption", "testProps": "128, 192, 256-bit keys", "testMethod": "KAT", "type": "CAS T", "indicator": "Module is operational", "details": "Decryption", "condition": "Module initializatio n"}, {"algorithmOrTest": "AES-CBC (AESNI_ASM) Encryption", "testProps": "128, 192, 256-bit keys", "testMethod": "KAT", "type": "CAS T", "indicator": "Module is operational", "details": "Encryption", "condition": "Module initializatio n"}, {"algorithmOrTest": "AES-CBC (AESNI_ASM) Decryption", "testProps": "128, 192, 256-bit keys", "testMethod": "KAT", "type": "CAS T", "indicator": "Module is operational", "details": "Decryption", "condition": "Module initializatio n"}, {"algorithmOrTest": "AES-CBC (AESNI_C) Encryption", "testProps": "128, 192, 256-bit keys", "testMethod": "KAT", "type": "CAS T", "indicator": "Module is operational", "details": "Encryption", "condition": "Module initializatio n"}, {"algorithmOrTest": "AES-CBC (AESNI_C) Decryption", "testProps": "128, 192, 256-bit keys", "testMethod": "KAT", "type": "CAS T", "indicator": "Module is operational", "details": "Decryption", "condition": "Module initializatio n"}, {"algorithmOrTest": "Algorithm Test", "testProps": "or", "testMethod": "Test Properti es", "type": "Test Metho d", "indicator": "Tes t Typ e", "details": "Indicator", "condition": "Details"}, {"algorithmOrTest": "AES-CBC-CS3 Encryption", "testProps": "", "testMethod": "128, 192, 256-bit keys", "type": "KAT", "indicator": "CAS T", "details": "Module is operational", "condition": "Encryption"}, {"algorithmOrTest": "AES-CBC-CS3 Decryption", "testProps": "", "testMethod": "128, 192, 256-bit keys", "type": "KAT", "indicator": "CAS T", "details": "Module is operational", "condition": "Decryption"}, {"algorithmOrTest": "AES-CBC-CS3 (AESNI_C) Encryption", "testProps": "", "testMethod": "128, 192, 256-bit keys", "type": "KAT", "indicator": "CAS T", "details": "Module is operational", "condition": "Encryption"}, {"algorithmOrTest": "AES-CBC-CS3 (AESNI_C) Decryption", "testProps": "", "testMethod": "128, 192, 256-bit keys", "type": "KAT", "indicator": "CAS T", "details": "Module is operational", "condition": "Decryption"}, {"algorithmOrTest": "AES-CCM Authenticated encryption", "testProps": "", "testMethod": "128, 192, 256-bit keys; 56, 64, 72, 80, 88, 96, 112, 128- bit IVs", "type": "KAT", "indicator": "CAS T", "details": "Module is operational", "condition": "Authenticat ed encryption"}, {"algorithmOrTest": "AES-CCM Authenticated decryption", "testProps": "", "testMethod": "128, 192, 256-bit keys; 56, 64, 72, 80, 88, 96, 112, 128-", "type": "KAT", "indicator": "CAS T", "details": "Module is operational", "condition": "Authenticat ed decryption"}, {"algorithmOrTest": "AES-CCM (AESNI_C) Authenticated encryption", "testProps": "", "testMethod": "bit IVs 128, 192, 256-bit keys; 56, 64, 72, 80, 88, 96, 112, 128-", "type": "KAT", "indicator": "CAS T", "details": "Module is operational", "condition": "Authenticat ed encryption"}, {"algorithmOrTest": "AES-CCM (AESNI_C) Authenticated decryption", "testProps": "", "testMethod": "bit IVs 128, 192, 256-bit keys; 56, 64, 72, 80, 88, 96, 112, 128-", "type": "KAT", "indicator": "CAS T", "details": "Module is operational", "condition": "Authenticat ed decryption"}, {"algorithmOrTest": "AES-CFB128 Encryption", "testProps": "", "testMethod": "bit IVs 128, 192, 256-bit keys", "type": "KAT", "indicator": "CAS T", "details": "Module is operational", "condition": "Encryption"}, {"algorithmOrTest": "AES-CFB128 Decryption", "testProps": "", "testMethod": "128, 192, 256-bit keys", "type": "KAT", "indicator": "CAS T", "details": "Module is operational", "condition": "Decryption"}, {"algorithmOrTest": "AES-CFB128 (AESNI_C) Encryption", "testProps": "", "testMethod": "128, 192, 256-bit keys", "type": "KAT", "indicator": "CAS T", "details": "Module is operational", "condition": "Encryption"}, {"algorithmOrTest": "Algorithm Test", "testProps": "or", "testMethod": "Test Properti es", "type": "Test Metho d", "indicator": "Tes t Typ e", "details": "Indicator", "condition": ""}, {"algorithmOrTest": "AES-CFB128 (AESNI_C) Decryption", "testProps": "", "testMethod": "128, 192, 256-bit keys", "type": "KAT", "indicator": "CAS T", "details": "Module operational", "condition": "is"}, {"algorithmOrTest": "AES-CTR Encryption", "testProps": "", "testMethod": "128, 192, 256-bit keys", "type": "KAT", "indicator": "CAS T", "details": "Module operational", "condition": "is"}, {"algorithmOrTest": "AES-CTR Decryption", "testProps": "", "testMethod": "128, 192, 256-bit keys", "type": "KAT", "indicator": "CAS T", "details": "Module operational", "condition": "is"}, {"algorithmOrTest": "AES-CTR (AESNI_ASM) Encryption", "testProps": "", "testMethod": "128, 192, 256-bit keys", "type": "KAT", "indicator": "CAS T", "details": "Module operational", "condition": "is"}, {"algorithmOrTest": "AES-CTR (AESNI_ASM) Decryption", "testProps": "", "testMethod": "128, 192, 256-bit keys", "type": "KAT", "indicator": "CAS T", "details": "Module operational", "condition": "is"}, {"algorithmOrTest": "AES-ECB Encryption", "testProps": "", "testMethod": "128, 192, 256-bit keys", "type": "KAT", "indicator": "CAS T", "details": "Module operational", "condition": "is"}, {"algorithmOrTest": "AES-ECB Decryption", "testProps": "", "testMethod": "128, 192, 256-bit keys", "type": "KAT", "indicator": "CAS T", "details": "Module operational", "condition": "is"}, {"algorithmOrTest": "AES-ECB (CTI_C) Encryption", "testProps": "", "testMethod": "128, 192, 256-bit keys", "type": "KAT", "indicator": "CAS T", "details": "Module operational", "condition": "is"}, {"algorithmOrTest": "AES-ECB (CTI_C) Decryption", "testProps": "", "testMethod": "128, 192, 256-bit keys", "type": "KAT", "indicator": "CAS T", "details": "Module operational", "condition": "is"}, {"algorithmOrTest": "AES-ECB (AESNI_ASM) Encryption", "testProps": "", "testMethod": "128, 192, 256-bit keys", "type": "KAT", "indicator": "CAS T", "details": "Module operational", "condition": "is"}, {"algorithmOrTest": "AES-ECB (AESNI_ASM) Decryption", "testProps": "", "testMethod": "128, 192, 256-bit keys", "type": "KAT", "indicator": "CAS T", "details": "Module operational", "condition": "is"}, {"algorithmOrTest": "AES-ECB (AESNI_C) Encryption", "testProps": "", "testMethod": "128, 192, 256-bit keys", "type": "KAT", "indicator": "CAS T", "details": "Module operational", "condition": "is"}, {"algorithmOrTest": "AES-ECB (AESNI_C) Decryption", "testProps": "", "testMethod": "128, 192, 256-bit keys", "type": "KAT", "indicator": "CAS T", "details": "Module operational", "condition": "is"}, {"algorithmOrTest": "AES-GCM Authenticated encryption", "testProps": "", "testMethod": "128, 192, 256-bit keys; 96- bit IVs", "type": "KAT", "indicator": "CAS T", "details": "Module operational", "condition": "is"}, {"algorithmOrTest": "AES-GCM Authenticated decryption", "testProps": "", "testMethod": "128, 192, 256-bit keys; 96- bit IVs", "type": "KAT", "indicator": "CAS T", "details": "Module operational", "condition": "is"}, {"algorithmOrTest": "Algorithm or Test", "testProps": "Test Properti es", "testMethod": "Test Metho d", "type": "Tes t Typ e", "indicator": "Indicator", "details": "", "condition": "Details"}, {"algorithmOrTest": "AES-GCM (AESNI_ASM) Authenticated encryption", "testProps": "128, 192, 256-bit keys; 96- bit IVs", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Authenticat ed encryption"}, {"algorithmOrTest": "AES-GCM (AESNI_ASM) Authenticated decryption", "testProps": "128, 192, 256-bit keys; 96- bit IVs", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Authenticat ed decryption"}, {"algorithmOrTest": "AES-GCM (AESNI_AVX) Authenticated encryption", "testProps": "128, 192, 256-bit keys; 96- bit IVs", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Authenticat ed encryption"}, {"algorithmOrTest": "AES-GCM (AESNI_AVX) Authenticated decryption", "testProps": "128, 192, 256-bit keys; 96- bit IVs", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Authenticat ed decryption"}, {"algorithmOrTest": "AES-GCM (VAES_AVX10_2 56) Authenticated encryption", "testProps": "128, 192, 256-bit keys; 96- bit IVs", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Authenticat ed encryption"}, {"algorithmOrTest": "AES-GCM (VAES_AVX10_2 56) Authenticated decryption", "testProps": "128, 192, 256-bit keys; 96- bit IVs", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Authenticat ed decryption"}, {"algorithmOrTest": "AES-GCM (VAES_AVX10_5 12) Authenticated encryption", "testProps": "128, 192, 256-bit keys; 96- bit IVs", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Authenticat ed encryption"}, {"algorithmOrTest": "AES-GCM (VAES_AVX10_5 12) Authenticated decryption", "testProps": "128, 192, 256-bit keys; 96- bit IVs", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Authenticat ed decryption"}, {"algorithmOrTest": "AES-OFB Encryption", "testProps": "128, 192, 256-bit keys", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Encryption"}, {"algorithmOrTest": "AES-OFB Decryption", "testProps": "128, 192, 256-bit keys", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Decryption"}, {"algorithmOrTest": "AES-OFB (AESNI_C) Encryption", "testProps": "128, 192, 256-bit keys", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Encryption"}, {"algorithmOrTest": "AES-OFB (AESNI_C) Decryption", "testProps": "128, 192, 256-bit keys", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Decryption"}, {"algorithmOrTest": "Algorithm or Test", "testProps": "Test Properti es", "testMethod": "Test Metho d", "type": "Tes t Typ e", "indicator": "Indicator", "details": "", "condition": "Details"}, {"algorithmOrTest": "AES-XTS Testing Revision 2.0 Encryption", "testProps": "128, 256- bit keys", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Encryption"}, {"algorithmOrTest": "AES-XTS Testing Revision 2.0 Decryption", "testProps": "128, 256- bit keys", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Decryption"}, {"algorithmOrTest": "AES-XTS Testing Revision 2.0 (AESNI_ASM) Encryption", "testProps": "128, 256- bit keys", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Encryption"}, {"algorithmOrTest": "AES-XTS Testing Revision 2.0 (AESNI_ASM) Decryption", "testProps": "128, 256- bit keys", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Decryption"}, {"algorithmOrTest": "AES-XTS Testing Revision 2.0 (AESNI_AVX) Encryption", "testProps": "128, 256- bit keys", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Encryption"}, {"algorithmOrTest": "AES-XTS Testing Revision 2.0 (AESNI_AVX) Decryption", "testProps": "128, 256- bit keys", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Decryption"}, {"algorithmOrTest": "AES-XTS Testing Revision 2.0 (VAES_AVX2) Encryption", "testProps": "128, 256- bit keys", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Encryption"}, {"algorithmOrTest": "AES-XTS Testing Revision 2.0 (VAES_AVX2) Decryption", "testProps": "128, 256- bit keys", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Decryption"}, {"algorithmOrTest": "AES-XTS Testing Revision 2.0 (VAES_AVX10_2 56) Encryption", "testProps": "128, 256- bit keys", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Encryption"}, {"algorithmOrTest": "AES-XTS Testing Revision 2.0 (VAES_AVX10_2 56) Decryption", "testProps": "128, 256- bit keys", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Decryption"}, {"algorithmOrTest": "AES-XTS Testing Revision 2.0 (VAES_AVX10_5 12) Encryption", "testProps": "128, 256- bit keys", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Encryption"}, {"algorithmOrTest": "AES-XTS Testing Revision 2.0 (VAES_AVX10_5 12) Decryption", "testProps": "128, 256- bit keys", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Decryption"}, {"algorithmOrTest": "SHA-1", "testProps": "0-65536- bit messages", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Message Digest"}, {"algorithmOrTest": "Algorithm or Test", "testProps": "Test Properti es", "testMethod": "Test Metho d", "type": "Tes t Typ e", "indicator": "Indicator", "details": "", "condition": "Details"}, {"algorithmOrTest": "SHA-1 (SSSE3)", "testProps": "0-65536- bit messages", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Message Digest"}, {"algorithmOrTest": "SHA-1 (AVX)", "testProps": "0-65536- bit messages", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Message Digest"}, {"algorithmOrTest": "SHA-1 (AVX2)", "testProps": "0-65536- bit messages", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Message Digest"}, {"algorithmOrTest": "SHA-1 (SHA_NI)", "testProps": "0-65536- bit messages", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Message Digest"}, {"algorithmOrTest": "SHA2-224", "testProps": "0-65536- bit messages", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Message Digest"}, {"algorithmOrTest": "SHA2-224 (SSSE3)", "testProps": "0-65536- bit messages", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Message Digest"}, {"algorithmOrTest": "SHA2-224 (AVX)", "testProps": "0-65536- bit messages", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Message Digest"}, {"algorithmOrTest": "SHA2-224 (AVX2)", "testProps": "0-65536- bit messages", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Message Digest"}, {"algorithmOrTest": "SHA2-224 (SHA_NI)", "testProps": "0-65536- bit messages", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Message Digest"}, {"algorithmOrTest": "SHA2-256", "testProps": "0-65536- bit messages", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Message Digest"}, {"algorithmOrTest": "SHA2-256 (SSSE3)", "testProps": "0-65536- bit messages", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Message Digest"}, {"algorithmOrTest": "SHA2-256 (AVX)", "testProps": "0-65536- bit messages", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Message Digest"}, {"algorithmOrTest": "SHA2-256 (AVX2)", "testProps": "0-65536- bit messages", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Message Digest"}, {"algorithmOrTest": "SHA2-256 (SHA_NI)", "testProps": "0-65536- bit messages", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Message Digest"}, {"algorithmOrTest": "SHA2-384", "testProps": "0-65536- bit messages", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Message Digest"}, {"algorithmOrTest": "SHA2-384 (SSSE3)", "testProps": "0-65536- bit messages", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Message Digest"}, {"algorithmOrTest": "Algorithm or Test", "testProps": "Test Properti es", "testMethod": "Test Metho d", "type": "Tes t Typ e", "indicator": "Indicator", "details": "", "condition": "Details"}, {"algorithmOrTest": "SHA2-384 (AVX)", "testProps": "0-65536- bit messages", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Message Digest"}, {"algorithmOrTest": "SHA2-384 (AVX2)", "testProps": "0-65536- bit messages", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Message Digest"}, {"algorithmOrTest": "SHA2-512", "testProps": "0-65536- bit messages", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Message Digest"}, {"algorithmOrTest": "SHA2-512 (SSSE3)", "testProps": "0-65536- bit messages", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Message Digest"}, {"algorithmOrTest": "SHA2-512 (AVX)", "testProps": "0-65536- bit messages", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Message Digest"}, {"algorithmOrTest": "SHA2-512 (AVX2)", "testProps": "0-65536- bit messages", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Message Digest"}, {"algorithmOrTest": "SHA3-224", "testProps": "0-65536- bit messages", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Message Digest"}, {"algorithmOrTest": "SHA3-256", "testProps": "0-65536- bit messages", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Message Digest"}, {"algorithmOrTest": "SHA3-384", "testProps": "0-65536- bit messages", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Message Digest"}, {"algorithmOrTest": "SHA3-512", "testProps": "0-65536- bit messages", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Message Digest"}, {"algorithmOrTest": "AES-CMAC", "testProps": "128, 192, 256-bit keys", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Message Authenticati on"}, {"algorithmOrTest": "AES-CMAC (AESNI_C)", "testProps": "128, 192, 256-bit keys", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Message Authenticati on"}, {"algorithmOrTest": "HMAC-SHA-1", "testProps": "112- 524288- bit keys", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Message Authenticati on"}, {"algorithmOrTest": "HMAC-SHA-1 (SHA_NI)", "testProps": "112- 524288- bit keys", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Message Authenticati on"}, {"algorithmOrTest": "HMAC-SHA2- 224", "testProps": "112- 524288- bit keys", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Message Authenticati on"}, {"algorithmOrTest": "HMAC-SHA2- 224 (SHA_NI)", "testProps": "112- 524288- bit keys", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Message Authenticati on"}, {"algorithmOrTest": "Algorithm Test", "testProps": "or", "testMethod": "Test Properti es", "type": "Test Metho d", "indicator": "Tes t Typ e", "details": "Indicator", "condition": "Details"}, {"algorithmOrTest": "HMAC-SHA2- 256", "testProps": "", "testMethod": "112- 524288- bit keys", "type": "KAT", "indicator": "CAS T", "details": "Module is operational", "condition": "Message Authenticati on"}, {"algorithmOrTest": "HMAC-SHA2- 256 (SHA_NI)", "testProps": "", "testMethod": "112- 524288- bit keys", "type": "KAT", "indicator": "CAS T", "details": "Module is operational", "condition": "Message Authenticati on"}, {"algorithmOrTest": "HMAC-SHA2- 384", "testProps": "", "testMethod": "112- 524288- bit keys", "type": "KAT", "indicator": "CAS T", "details": "Module is operational", "condition": "Message Authenticati on"}, {"algorithmOrTest": "HMAC-SHA2- 384 (AVX2)", "testProps": "", "testMethod": "112- 524288- bit keys", "type": "KAT", "indicator": "CAS T", "details": "Module is operational", "condition": "Message Authenticati on"}, {"algorithmOrTest": "HMAC-SHA2- 512", "testProps": "", "testMethod": "112- 524288- bit keys", "type": "KAT", "indicator": "CAS T", "details": "Module is operational", "condition": "Message Authenticati on"}, {"algorithmOrTest": "HMAC-SHA2- 512 (AVX2)", "testProps": "", "testMethod": "112- 524288- bit keys", "type": "KAT", "indicator": "CAS T", "details": "Module is operational", "condition": "Message Authenticati on"}, {"algorithmOrTest": "HMAC-SHA3- 224", "testProps": "", "testMethod": "112- 524288- bit keys", "type": "KAT", "indicator": "CAS T", "details": "Module is operational", "condition": "Message Authenticati on"}, {"algorithmOrTest": "HMAC-SHA3- 256", "testProps": "", "testMethod": "112- 524288- bit keys", "type": "KAT", "indicator": "CAS T", "details": "Module is operational", "condition": "Message Authenticati on"}, {"algorithmOrTest": "HMAC-SHA3- 384", "testProps": "", "testMethod": "112- 524288- bit keys", "type": "KAT", "indicator": "CAS T", "details": "Module is operational", "condition": "Message Authenticati on"}, {"algorithmOrTest": "HMAC-SHA3- 512", "testProps": "", "testMethod": "112- 524288- bit keys", "type": "KAT", "indicator": "CAS T", "details": "Module is operational", "condition": "Message Authenticati on"}, {"algorithmOrTest": "KDF SP800-108", "testProps": "", "testMethod": "SHA2-256", "type": "KAT", "indicator": "CAS T", "details": "Module is operational", "condition": "Key derivation"}, {"algorithmOrTest": "KDA OneStep SP800-56Cr2", "testProps": "", "testMethod": "SHA2-256", "type": "KAT", "indicator": "CAS T", "details": "Module is operational", "condition": "Key derivation"}, {"algorithmOrTest": "Counter DRBG", "testProps": "", "testMethod": "AES-128, AES-192, and AES- 256 with/witho ut prediction resistance", "type": "KAT", "indicator": "CAS T", "details": "Module is operational", "condition": "Instantiate, seed, reseed, generate (compliant to SP 800- 90Ar1 Section 11.3)"}, {"algorithmOrTest": "Hash DRBG", "testProps": "", "testMethod": "SHA-1, SHA-256, and SHA- 512", "type": "KAT", "indicator": "CAS T", "details": "Module is operational", "condition": "Instantiate, seed, reseed, generate"}, {"algorithmOrTest": "Algorithm or Test", "testProps": "Test Properti es", "testMethod": "Test Metho d", "type": "Tes t Typ e", "indicator": "Indicator", "details": "", "condition": "Details"}, {"algorithmOrTest": "", "testProps": "with/witho ut prediction resistance", "testMethod": "", "type": "", "indicator": "", "details": "", "condition": "(compliant to SP 800- 90Ar1 Section 11.3)"}, {"algorithmOrTest": "HMAC DRBG", "testProps": "SHA-1, SHA-256, and SHA- 512 with/witho ut prediction resistance", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Instantiate, seed, reseed, generate (compliant to SP 800- 90Ar1 Section 11.3)"}, {"algorithmOrTest": "KAS-FFC-SSC Sp800-56Ar3", "testProps": "ffdhe2048 , ffdhe3072 , ffdhe4096 , ffdhe6144 , ffdhe8192", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Shared secret computatio n"}, {"algorithmOrTest": "KAS-ECC-SSC Sp800-56Ar3", "testProps": "P-256, P- 384", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Shared secret computatio n"}, {"algorithmOrTest": "RSA SigVer (FIPS186-5)", "testProps": "PKCS#1 v1.5 with SHA-224, SHA-256, SHA-384, SHA-512 and 2048, 3072, 4096-bit keys", "testMethod": "KAT", "type": "CAS T", "indicator": "Module operational", "details": "is", "condition": "Signature verification"}, {"algorithmOrTest": "Entropy Source Start Up APT", "testProps": "Cutoff C = 325; Window size = 512", "testMethod": "APT", "type": "CAS T", "indicator": "Entropy source is operational", "details": "Entropy source is operational", "condition": "Entropy source start-up test on 1024 samples"}, {"algorithmOrTest": "Entropy Source Start Up RCT", "testProps": "Cutoff C = 31", "testMethod": "RCT", "type": "CAS T", "indicator": "Entropy source is operational", "details": "Entropy source is operational", "condition": "Entropy source start-up test on 1024 samples"}, {"algorithmOrTest": "Entropy Source Continuous APT", "testProps": "Permanen t cutoff C", "testMethod": "APT", "type": "CAS T", "indicator": "jent_kcapi_rand om returns 0", "details": "jent_kcapi_rand om returns 0", "condition": "Entropy source"}, {"algorithmOrTest": "", "testProps": "= 355; Window size = 512", "testMethod": "", "type": "", "indicator": "", "details": "continuous test", "condition": "entropy is requested"}, {"algorithmOrTest": "Entropy Source Continuous RCT", "testProps": "Permanen t cutoff C = 61", "testMethod": "RCT", "type": "CAS T", "indicator": "jent_kcapi_rand om returns 0", "details": "Entropy source continuous test", "condition": "Continuou sly as entropy is requested"}, {"algorithmOrTest": "Safe Primes Key Generation", "testProps": "ffdhe2048 , ffdhe3072 , ffdhe4096 , ffdhe6144 , ffdhe8192", "testMethod": "PCT", "type": "PCT", "indicator": "Key pair generation is successful", "details": "SP 800- 56Ar3 Section 5.6.2.1.4", "condition": "Key pair generation"}, {"algorithmOrTest": "ECDSA KeyGen (FIPS186-5)", "testProps": "P-256, P- 384", "testMethod": "PCT", "type": "PCT", "indicator": "Key pair generation is successful", "details": "SP 800- 56Ar3 Section 5.6.2.1.4", "condition": "Key pair generation"}]}, "error_states": {"section": 10, "subsection": 4, "found": true, "entries": [{"name": "Error", "description": "The Linux kernel immediately stops executing", "conditions": "Any self-test failure", "recoveryMethod": "Restart of the module", "indicator": "Kernel panic"}]}}}, "heuristics": {"_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics", "algorithms": {"_type": "Set", "elements": ["HMAC-SHA-1A6267", "SHA2-512A6266", "ECDSA KeyGen (FIPS186-5)A6242", "SHA3-512A6242", "SHA3-224A6242", "#A6260", "Counter DRBGA6263", "#A6246", "#A6248", "HMAC-SHA2-384A6266", "KAS-ECC-SSC Sp800-56Ar3A6242", "HMAC-SHA3-224A6242", "AES-OFBA6251", "HMAC-SHA2-512A6266", "SHA3-384A6242", "#A6258", "SHA2-384A6266", "HMAC-SHA2-256A6267", "SHA2-224A6267", "#A6259", "HMAC DRBGA6267", "#A6255", "KAS-FFC-SSC Sp800-56Ar3A6242", "AES-KWA6251", "#A6266", "AES-CFB128A6251", "AES-CTRA6251", "RSA SigVer (FIPS186-5)A6242", "AES-CBC-CS3A6251", "#A6252", "SHA-1A6267", "Hash DRBGA6267", "#A6249", "AES-ECBA6263", "#A6243", "#A6245", "#A6247", "#A6257", "#A6263", "#A6250", "#A6265", "KDA OneStep SP800-56Cr2A6242", "HMAC-SHA3-512A6242", "#A6262", "#A6256", "AES-CBCA6251", "RSA SigVer (FIPS186-4)A6242", "SHA3-256A6242", "#A6254", "HMAC-SHA3-256A6242", "#A6264", "AES-CMACA6251", "#A6267", "Safe Primes Key GenerationA6242", "AES-XTS Testing Revision 2.0A6261", "#A6251", "AES-GMACA6261", "HMAC-SHA2-224A6267", "HMAC-SHA3-384A6242", "AES-GCMA6263", "#A6242", "SHA2-256A6267", "KDF SP800-108A6242", "#A6244", "#A6261", "AES-CCMA6251", "#A6253"]}, "extracted_versions": {"_type": "Set", "elements": ["-"]}, "cpe_matches": null, "verified_cpe_matches": null, "related_cves": null, "policy_prunned_references": {"_type": "Set", "elements": []}, "module_prunned_references": {"_type": "Set", "elements": []}, "policy_processed_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": null, "indirectly_referenced_by": null, "directly_referencing": null, "indirectly_referencing": null}, "module_processed_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": null, "indirectly_referenced_by": null, "directly_referencing": null, "indirectly_referencing": null}, "direct_transitive_cves": null, "indirect_transitive_cves": null}, "state": {"_type": "sec_certs.sample.fips.InternalState", "module": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": null, "txt_hash": null, "json_hash": null}, "policy": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": "b561c282ed547d8e1b42174b61b81c99a0c0891fc9f5ad93c96ed179d9bcd831", "txt_hash": "f74e2294e4a73b6fd8f2908caa4a1d5e3e82b0658b4444c9f3740fde2d5f6d1b", "json_hash": "a48799ca2011ffb4a3ab4db7abdc899f00c1bf50ea2813b28a869ad80a53b381"}}}