Comparing certificates Experimental feature

You are comparing two certificates. By default, only differing attributes are shown. Use the button below to show/hide all attributes.

Showing only differing attributes.
SUSE Linux Enterprise OpenSSL Cryptographic Module
SUSE Linux Enterprise OpenSSL Cryptographic Module
cert_id 4070 4725
dgst 634bce1b71598aee 6879547fb139e734
heuristics/algorithms AES#A787, KTS#A780, ECDSA#A782, AES#A788, AES#A789, DSA#A781, SHS#A780, KTS#A793, AES#A795, KTS#A779, KTS#A782, AES#A784, ECDSA#A781, CVL#A779, KAS#A807, CVL#A780, DRBG#A792, KAS-SSC#A781, SHS#A781, AES#A791, DRBG#A795, KAS#A781, KAS-SSC#A807, AES#A792, CVL#A781, DSA#A780, HMAC#A780, RSA#A782, SHS#A779, ECDSA#A779, HMAC#A782, RSA#A779, AES#A794, HMAC#A781, AES#A790, DSA#A779, AES#A785, AES#A783, ECDSA#A780, DRBG#A797, RSA#A780, KAS#A779, SHS#A782, KAS#A780, HMAC#A779, KTS#A781, KAS-SSC#A779, KAS-SSC#A780, CVL#A782, KAS-SSC#A782, KAS#A782, DSA#A782, DRBG#A786, RSA#A781, Triple-DES#A793, AES#A786 AES-CTRA3167, HMAC-SHA3-512A3175, HMAC-SHA2-256A3210, AES-KWPA3167, SHA3-224A3175, AES-GCMA3206, AES-XTS Testing Revision 2.0A3167, PBKDFA3210, HMAC-SHA2-384A3210, Counter DRBGA3167, SHA2-384A3210, SHAKE-128A3175, HMAC-SHA2-512A3210, ECDSA KeyGen (FIPS186-4)A3210, KDF SSHA3172, SHA3-384A3175, SHA2-256A3210, ECDSA KeyVer (FIPS186-4)A3210, HMAC-SHA3-384A3175, KAS-FFC-SSC Sp800-56Ar3A3211, AES-CFB128A3167, HMAC-SHA2-224A3210, AES-CFB8A3167, KDF TLSA3210, ECDSA SigVer (FIPS186-4)A3210, SHA3-512A3175, AES-CFB1A3167, RSA SigGen (FIPS186-4)A3210, AES-CMACA3167, Safe Primes Key VerificationA3211, AES-KWA3167, AES-CCMA3167, SHA-1A3210, SHA2-224A3210, AES-OFBA3167, RSA SigVer (FIPS186-4)A3210, SHA2-512A3210, SHAKE-256A3175, HMAC-SHA3-224A3175, KAS-ECC-SSC Sp800-56Ar3A3210, TLS v1.2 KDF RFC7627A3210, HMAC-SHA3-256A3175, KDA HKDF Sp800-56Cr1A3168, RSA KeyGen (FIPS186-4)A3210, HMAC-SHA-1A3210, Safe Primes Key GenerationA3211, AES-ECBA3172, SHA3-256A3175, ECDSA SigGen (FIPS186-4)A3210, AES-CBCA3167
heuristics/module_processed_references/directly_referenced_by {} 4822
heuristics/module_processed_references/indirectly_referenced_by {} 4822
heuristics/policy_processed_references/directly_referenced_by {} 4822
heuristics/policy_processed_references/indirectly_referenced_by {} 4822
pdf_data/keywords/fips_security_level
  • Level:
    • Level 1: 1
    • level 1: 3
  • Level:
    • Level 1: 1
    • level 1: 1
pdf_data/keywords/fips_certlike
  • Certlike:
    • AES GCM 128: 1
    • AES-128: 1
    • AES-192: 1
    • AES-256: 2
    • HMAC 128: 2
    • HMAC 192: 2
    • HMAC SHA-1: 2
    • HMAC-SHA-1: 4
    • HMAC-SHA-224: 4
    • HMAC-SHA-256: 6
    • HMAC-SHA-384: 4
    • HMAC-SHA-512: 4
    • PKCS#1: 4
    • RSA PKCS#1: 2
    • SHA- 256: 2
    • SHA- 384: 1
    • SHA-1: 14
    • SHA-224: 19
    • SHA-256: 30
    • SHA-3: 1
    • SHA-384: 21
    • SHA-512: 14
    • SHA-512 1024: 3
    • SHA-512 112: 1
    • SHA-512 2048: 3
    • SHA1: 2
    • SHA224: 2
    • SHS4: 1
  • Certlike:
    • AES 128, 192: 2
    • AES GCM 128: 1
    • AES key 128, 192: 1
    • AES- 192: 1
    • AES- 256: 1
    • AES-128: 1
    • AES-256: 1
    • HMAC 112: 4
    • HMAC 128: 2
    • HMAC SHA-1: 1
    • HMAC-SHA-1: 4
    • PKCS#1: 4
    • SHA- 1: 1
    • SHA-1: 12
    • SHA-3: 4
    • SHA2- 224: 1
    • SHA2- 256: 4
    • SHA2- 384: 8
    • SHA2-224: 11
    • SHA2-256: 22
    • SHA2-384: 6
    • SHA2-512: 7
    • SHA2-512 1024: 3
    • SHA2-512 128: 1
    • SHA2-512 2048: 3
    • SHA3- 256: 4
    • SHA3-224: 3
    • SHA3-256: 2
    • SHA3-384: 5
    • SHA3-512: 6
pdf_data/keywords/eval_facility
  • atsec:
    • atsec: 40
  • atsec:
    • atsec: 58
pdf_data/keywords/symmetric_crypto
  • AES_competition:
    • AES:
      • AES: 57
      • AES-: 1
      • AES-128: 1
      • AES-192: 1
      • AES-256: 2
    • CAST:
      • CAST: 2
      • CAST5: 2
    • RC:
      • RC2: 2
      • RC4: 2
      • RC5: 2
  • DES:
    • 3DES:
      • TDEA: 1
      • TDES: 1
      • Triple-DES: 37
    • DES:
      • DES: 5
  • constructions:
    • MAC:
      • CMAC: 11
      • HMAC: 28
      • HMAC-SHA-224: 2
      • HMAC-SHA-256: 3
      • HMAC-SHA-384: 2
      • HMAC-SHA-512: 2
  • miscellaneous:
    • Camellia:
      • Camellia: 2
    • IDEA:
      • IDEA: 2
    • SEED:
      • SEED: 2
  • AES_competition:
    • AES:
      • AES: 57
      • AES-: 11
      • AES-128: 1
      • AES-256: 1
    • CAST:
      • CAST: 6
      • CAST5: 2
    • RC:
      • RC2: 2
      • RC4: 2
  • DES:
    • 3DES:
      • TDES: 1
      • Triple-DES: 5
    • DES:
      • DES: 3
  • constructions:
    • MAC:
      • CMAC: 11
      • HMAC: 24
  • djb:
    • ChaCha:
      • ChaCha20: 3
    • Poly:
      • Poly1305: 2
  • miscellaneous:
    • ARIA:
      • ARIA: 2
    • Blowfish:
      • Blowfish: 2
    • Camellia:
      • Camellia: 2
    • SEED:
      • SEED: 2
    • SM4:
      • SM4: 1
pdf_data/keywords/asymmetric_crypto
  • ECC:
    • ECC:
      • ECC: 3
    • ECDSA:
      • ECDSA: 30
  • FF:
    • DH:
      • DH: 2
    • DSA:
      • DSA: 33
  • ECC:
    • ECC:
      • ECC: 2
    • ECDH:
      • ECDH: 2
    • ECDSA:
      • ECDSA: 50
  • FF:
    • DH:
      • DH: 2
      • Diffie-Hellman: 54
    • DSA:
      • DSA: 7
pdf_data/keywords/hash_function
  • MD:
    • MD4:
      • MD4: 2
    • MD5:
      • MD5: 5
  • PBKDF:
    • PBKDF: 11
  • SHA:
    • SHA1:
      • SHA-1: 14
      • SHA1: 2
    • SHA2:
      • SHA-224: 19
      • SHA-256: 30
      • SHA-384: 21
      • SHA-512: 21
      • SHA224: 2
    • SHA3:
      • SHA-3: 1
  • BLAKE:
    • Blake2: 2
  • MD:
    • MD4:
      • MD4: 2
    • MD5:
      • MD5: 3
  • PBKDF:
    • PBKDF: 17
  • SHA:
    • SHA1:
      • SHA-1: 12
    • SHA3:
      • SHA-3: 4
      • SHA3-224: 5
      • SHA3-256: 2
      • SHA3-384: 5
      • SHA3-512: 6
pdf_data/keywords/crypto_scheme
  • KA:
    • Key Agreement: 8
  • KEX:
    • Key Exchange: 3
  • MAC:
    • MAC: 8
  • KA:
    • Key Agreement: 1
    • Key agreement: 4
  • KEX:
    • Key Exchange: 1
  • MAC:
    • MAC: 14
pdf_data/keywords/crypto_protocol
  • IKE:
    • IKE: 5
    • IKEv2: 2
  • SSH:
    • SSH: 1
  • TLS:
    • DTLS:
      • DTLS: 1
    • TLS:
      • TLS: 67
      • TLS v1.0: 2
      • TLS v1.3: 1
      • TLSv1.2: 1
  • IKE:
    • IKE: 2
    • IKEv2: 1
  • SSH:
    • SSH: 13
  • TLS:
    • TLS:
      • TLS: 57
      • TLS v1.0: 1
      • TLS v1.3: 1
      • TLSv1.0: 2
      • TLSv1.2: 2
      • TLSv1.3: 1
pdf_data/keywords/randomness
  • PRNG:
    • DRBG: 30
  • RNG:
    • RNG: 4
  • PRNG:
    • DRBG: 44
  • RNG:
    • RNG: 2
pdf_data/keywords/cipher_mode
  • CBC:
    • CBC: 9
  • CCM:
    • CCM: 6
  • CTR:
    • CTR: 2
  • ECB:
    • ECB: 5
  • GCM:
    • GCM: 14
  • OFB:
    • OFB: 2
  • XEX:
    • XEX: 1
  • XTS:
    • XTS: 8
  • CBC:
    • CBC: 5
  • CCM:
    • CCM: 6
  • CFB:
    • CFB: 1
  • CTR:
    • CTR: 3
  • ECB:
    • ECB: 3
  • GCM:
    • GCM: 13
  • OFB:
    • OFB: 3
  • XTS:
    • XTS: 8
pdf_data/keywords/ecc_curve
  • NIST:
    • P-192: 6
    • P-224: 8
    • P-256: 12
    • P-384: 8
    • P-521: 8
  • NIST:
    • P-192: 10
    • P-224: 12
    • P-256: 16
    • P-384: 12
    • P-521: 8
pdf_data/keywords/tls_cipher_suite
  • TLS:
    • TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA: 1
    • TLS_DHE_DSS_WITH_AES_128_CBC_SHA: 1
    • TLS_DHE_DSS_WITH_AES_128_CBC_SHA256: 1
    • TLS_DHE_DSS_WITH_AES_128_GCM_SHA256: 1
    • TLS_DHE_DSS_WITH_AES_256_CBC_SHA: 1
    • TLS_DHE_DSS_WITH_AES_256_CBC_SHA256: 1
    • TLS_DHE_DSS_WITH_AES_256_GCM_SHA384: 1
    • TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA: 1
    • TLS_DHE_RSA_WITH_AES_128_CBC_SHA: 1
    • TLS_DHE_RSA_WITH_AES_128_CBC_SHA256: 1
    • TLS_DHE_RSA_WITH_AES_128_CCM: 1
    • TLS_DHE_RSA_WITH_AES_128_CCM_8: 1
    • TLS_DHE_RSA_WITH_AES_128_GCM_SHA256: 1
    • TLS_DHE_RSA_WITH_AES_256_CBC_SHA: 1
    • TLS_DHE_RSA_WITH_AES_256_CBC_SHA256: 1
    • TLS_DHE_RSA_WITH_AES_256_CCM: 1
    • TLS_DHE_RSA_WITH_AES_256_CCM_8: 1
    • TLS_DHE_RSA_WITH_AES_256_GCM_SHA384: 1
    • TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA: 1
    • TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA: 1
    • TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256: 1
    • TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256: 1
    • TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA: 1
    • TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384: 1
    • TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384: 1
    • TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA: 1
    • TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA: 1
    • TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256: 1
    • TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256: 1
    • TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA: 1
    • TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384: 1
    • TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384: 1
    • TLS_PSK_WITH_3DES_EDE_CBC_SHA: 1
    • TLS_PSK_WITH_AES_128_CBC_SHA: 1
    • TLS_PSK_WITH_AES_256_CBC_SHA: 1
    • TLS_RSA_WITH_3DES_EDE_CBC_SHA: 1
    • TLS_RSA_WITH_AES_128_CBC_SHA: 1
    • TLS_RSA_WITH_AES_128_CBC_SHA256: 1
    • TLS_RSA_WITH_AES_128_CCM: 1
    • TLS_RSA_WITH_AES_128_CCM_8: 1
    • TLS_RSA_WITH_AES_128_GCM_SHA256: 1
    • TLS_RSA_WITH_AES_256_CBC_SHA: 1
    • TLS_RSA_WITH_AES_256_CBC_SHA256: 1
    • TLS_RSA_WITH_AES_256_CCM: 1
    • TLS_RSA_WITH_AES_256_CCM_8: 1
    • TLS_RSA_WITH_AES_256_GCM_SHA384: 1
  • TLS:
    • TLS_DHE_RSA_WITH_AES_128_CBC_SHA: 1
    • TLS_DHE_RSA_WITH_AES_128_CBC_SHA256: 1
    • TLS_DHE_RSA_WITH_AES_128_CCM: 1
    • TLS_DHE_RSA_WITH_AES_128_CCM_8: 1
    • TLS_DHE_RSA_WITH_AES_128_GCM_SHA256: 1
    • TLS_DHE_RSA_WITH_AES_256_CBC_SHA: 1
    • TLS_DHE_RSA_WITH_AES_256_CBC_SHA256: 1
    • TLS_DHE_RSA_WITH_AES_256_CCM: 1
    • TLS_DHE_RSA_WITH_AES_256_CCM_8: 1
    • TLS_DHE_RSA_WITH_AES_256_GCM_SHA384: 1
    • TLS_DH_RSA_WITH_AES_128_CBC_SHA: 1
    • TLS_DH_RSA_WITH_AES_128_CBC_SHA256: 1
    • TLS_DH_RSA_WITH_AES_128_GCM_SHA256: 1
    • TLS_DH_RSA_WITH_AES_256_CBC_SHA: 1
    • TLS_DH_RSA_WITH_AES_256_CBC_SHA256: 1
    • TLS_DH_RSA_WITH_AES_256_GCM_SHA384: 1
    • TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA: 1
    • TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256: 1
    • TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256: 1
    • TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA: 1
    • TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384: 1
    • TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384: 1
    • TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA: 1
    • TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256: 1
    • TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256: 1
    • TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA: 1
    • TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384: 1
    • TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384: 1
    • TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA: 1
    • TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA256: 1
    • TLS_ECDH_ECDSA_WITH_AES_128_GCM_SHA256: 1
    • TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA: 1
    • TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA384: 1
    • TLS_ECDH_ECDSA_WITH_AES_256_GCM_SHA384: 1
    • TLS_ECDH_RSA_WITH_AES_128_CBC_SHA: 1
    • TLS_ECDH_RSA_WITH_AES_128_CBC_SHA256: 1
    • TLS_ECDH_RSA_WITH_AES_128_GCM_SHA256: 1
    • TLS_ECDH_RSA_WITH_AES_256_CBC_SHA: 1
    • TLS_ECDH_RSA_WITH_AES_256_CBC_SHA384: 1
    • TLS_ECDH_RSA_WITH_AES_256_GCM_SHA384: 1
    • TLS_PSK_WITH_AES_128_CBC_SHA: 1
    • TLS_PSK_WITH_AES_256_CBC_SHA: 1
pdf_data/keywords/crypto_library
  • OpenSSL:
    • OpenSSL: 44
  • OpenSSL:
    • OpenSSL: 66
pdf_data/keywords/side_channel_analysis
  • SCA:
    • Timing Attacks: 2
    • timing attacks: 1
  • SCA:
    • timing attacks: 2
pdf_data/keywords/tee_name
  • IBM:
    • SSC: 2
pdf_data/keywords/standard_id
  • FIPS:
    • FIPS 140-2: 50
    • FIPS 186-4: 2
    • FIPS PUB 140-2: 1
    • FIPS180-4: 2
    • FIPS186-4: 6
    • FIPS197: 2
    • FIPS198-1: 2
    • FIPS202: 1
  • NIST:
    • SP 800-57: 1
  • PKCS:
    • PKCS#1: 3
  • RFC:
    • RFC2246: 4
    • RFC3268: 7
    • RFC3526: 5
    • RFC4253: 1
    • RFC4279: 4
    • RFC4346: 1
    • RFC4492: 7
    • RFC5116: 1
    • RFC5246: 8
    • RFC5288: 8
    • RFC5289: 8
    • RFC5487: 1
    • RFC5489: 1
    • RFC6655: 9
    • RFC7251: 1
    • RFC7296: 2
    • RFC7919: 4
  • FIPS:
    • FIPS 140-3: 66
    • FIPS 186-4: 4
    • FIPS PUB 140-3: 1
    • FIPS140-3: 1
    • FIPS180-4: 2
    • FIPS186-4: 6
    • FIPS197: 3
    • FIPS198-1: 3
    • FIPS202: 2
  • ISO:
    • ISO/IEC 24759: 2
  • PKCS:
    • PKCS#1: 2
  • RFC:
    • RFC3268: 4
    • RFC3394: 1
    • RFC3526: 3
    • RFC4279: 2
    • RFC4492: 8
    • RFC5246: 4
    • RFC5288: 5
    • RFC5289: 16
    • RFC5649: 1
    • RFC6655: 4
    • RFC7627: 1
    • RFC7919: 3
    • RFC8446: 4
pdf_data/policy_metadata
state/policy_pdf_hash Different Different
state/policy_txt_hash Different Different
web_data/caveat When operated in FIPS mode and installed, initialized and configured as specified in Section 9.1 of the Security Policy. The module generates cryptographic keys whose strengths are modified by available entropy. Interim validation. When operated in the approved mode. When installed, initialized and configured as specified in Section 11 of the Security Policy
web_data/certificate_pdf_url https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/November 2021_011221_0923_signed.pdf https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/July 2024_010824_1146.pdf
web_data/date_sunset 21.09.2026 11.07.2026
web_data/exceptions Physical Security: N/A, , , Physical security: N/A, Non-invasive security: N/A, Documentation requirements: N/A, Cryptographic module security policy: N/A
web_data/standard FIPS 140-2 FIPS 140-3
web_data/sw_versions 3.1 4.2
web_data/tested_conf SUSE Linux Enterprise Server 12 SP5 running on FUJITSU Server PRIMERGY RX4770 M5 with Intel Cascade Lake Xeon Platinum 8268 with PAA, SUSE Linux Enterprise Server 12 SP5 running on FUJITSU Server PRIMERGY RX4770 M5 with Intel Cascade Lake Xeon Platinum 8268 without PAA, SUSE Linux Enterprise Server 12 SP5 running on IBM z13 with z13 with PAI, SUSE Linux Enterprise Server 12 SP5 running on IBM z13 with z13 without PAI (single-user mode), , , , , , SUSE Linux Enterprise Server 15 SP4 on PowerVM (VIOS 3.1.4.00) running on IBM Power E1080 (9080-HEX) with Power10 with PAA, SUSE Linux Enterprise Server 15 SP4 on PowerVM (VIOS 3.1.4.00) running on IBM Power E1080 (9080-HEX) with Power10 without PAA, SUSE Linux Enterprise Server 15 SP4 running on GIGABYTE G242-P32-QZ with ARM Ampere(R) Altra(R) Q80-30 with PAA, SUSE Linux Enterprise Server 15 SP4 running on GIGABYTE G242-P32-QZ with ARM Ampere(R) Altra(R) Q80-30 without PAA, SUSE Linux Enterprise Server 15 SP4 running on GIGABYTE R181-Z90-00 with AMD EPYC(TM) 7371 with PAA, SUSE Linux Enterprise Server 15 SP4 running on GIGABYTE R181-Z90-00 with AMD EPYC(TM) 7371 without PAA, SUSE Linux Enterprise Server 15 SP4 running on IBM z/15 with z15 with PAI, SUSE Linux Enterprise Server 15 SP4 running on IBM z/15 with z15 without PAI, SUSE Linux Enterprise Server 15 SP4 running on Supermicro Super Server SYS-6019P-WTR with Intel(R) Xeon(R) Silver 4215R with PAA, SUSE Linux Enterprise Server 15 SP4 running on Supermicro Super Server SYS-6019P-WTR with Intel(R) Xeon(R) Silver 4215R without PAA
web_data/validation_history
  • date: 15.11.2021
  • lab: ATSEC INFORMATION SECURITY CORP
  • validation_type: Initial
  • date: 12.07.2024
  • lab: ATSEC INFORMATION SECURITY CORP
  • validation_type: Initial