Comparing certificates Experimental feature

You are comparing two certificates. By default, only differing attributes are shown. Use the button below to show/hide all attributes.

Showing only differing attributes.
Amazon Linux 2 GnuTLS Cryptographic Module
Amazon Linux 2 GnuTLS Cryptographic Module
cert_id 3643 4472
dgst 6678394ac11e55af 71cadd0c63e57249
heuristics/algorithms SHS#C792, AES#C790, KTS#C792, AES#C791, AES#C789, DSA#C792, Triple-DES#C792, AES#C792, SHS#C790, CVL#C792, HMAC#C792, ECDSA#C792, DRBG#C792, RSA#C792 KTS#A4151, SHS#C792, AES#C790, AES#C789, DSA#C792, RSA#A4151, KTS#A4152, SHS#A4152, KTS#C792, AES#C791, CVL#A4151, DSA#A4151, AES#C792, AES#A4152, HMAC#C792, Triple-DES#A4151, AES#A4151, DRBG#C792, HMAC#A4152, ECDSA#A4151, CVL#C792, AES#A4150, SHS#C790, ECDSA#C792, DRBG#A4151, HMAC#A4151, Triple-DES#C792, SHS#A4151, RSA#C792
pdf_data/keywords/fips_certlike
  • Certlike:
    • AES- 256: 1
    • AES-128: 1
    • AES-256: 3
    • AES-GCM 128: 1
    • AES2: 1
    • Cert# AES: 1
    • HMAC 128: 2
    • HMAC 192: 2
    • HMAC-SHA-1: 4
    • PKCS#1: 2
    • PKCS#11: 4
    • SHA-1: 7
    • SHA2: 2
    • SHA2-224: 9
    • SHA2-256: 15
    • SHA2-384: 14
    • SHA2-512: 9
    • SHA2-512 1024: 1
    • SHA2-512 112: 1
    • SHA2-512 2048 and 3072: 1
    • SHA3: 2
  • Certlike:
    • AES- 256: 1
    • AES-128: 1
    • AES-256: 4
    • AES-GCM 128: 2
    • AES2: 1
    • AES3: 1
    • Cert# AES: 2
    • HMAC 128: 4
    • HMAC 192: 4
    • HMAC-SHA-1: 4
    • PKCS#1: 2
    • PKCS#11: 4
    • SHA-1: 11
    • SHA2: 2
    • SHA2-224: 17
    • SHA2-256: 26
    • SHA2-384: 26
    • SHA2-512: 17
    • SHA2-512 1024: 2
    • SHA2-512 112: 2
    • SHA2-512 2048 and 3072: 2
    • SHA3: 2
pdf_data/keywords/eval_facility
  • atsec:
    • atsec: 40
  • atsec:
    • atsec: 43
pdf_data/keywords/symmetric_crypto
  • AES_competition:
    • AES:
      • AES: 29
      • AES-: 2
      • AES-128: 1
      • AES-256: 3
    • CAST:
      • CAST-: 1
      • CAST128: 1
    • RC:
      • RC2: 2
      • RC4: 2
    • Serpent:
      • Serpent: 2
    • Twofish:
      • Twofish: 2
  • DES:
    • 3DES:
      • TDEA: 1
      • Triple-DES: 16
    • DES:
      • DES: 5
  • constructions:
    • MAC:
      • HMAC: 26
  • djb:
    • Salsa:
      • Salsa20: 1
  • miscellaneous:
    • Blowfish:
      • Blowfish: 2
    • Camellia:
      • Camellia: 2
    • GOST:
      • GOST 28147-89: 1
  • AES_competition:
    • AES:
      • AES: 34
      • AES-: 1
      • AES-128: 1
      • AES-256: 4
    • CAST:
      • CAST-: 1
      • CAST128: 1
    • RC:
      • RC2: 2
      • RC4: 2
    • Serpent:
      • Serpent: 2
    • Twofish:
      • Twofish: 2
  • DES:
    • 3DES:
      • TDEA: 1
      • Triple-DES: 18
    • DES:
      • DES: 4
  • constructions:
    • MAC:
      • HMAC: 30
  • djb:
    • Salsa:
      • Salsa20: 1
  • miscellaneous:
    • Blowfish:
      • Blowfish: 2
    • Camellia:
      • Camellia: 2
    • GOST:
      • GOST 28147-89: 1
pdf_data/keywords/asymmetric_crypto
  • ECC:
    • ECC:
      • ECC: 4
    • ECDH:
      • ECDH: 1
    • ECDSA:
      • ECDSA: 32
  • FF:
    • DH:
      • DH: 1
      • DHE: 1
      • Diffie-Hellman: 40
    • DSA:
      • DSA: 31
  • ECC:
    • ECDH:
      • ECDH: 1
    • ECDSA:
      • ECDSA: 35
  • FF:
    • DH:
      • DH: 1
      • DHE: 1
      • Diffie-Hellman: 15
    • DSA:
      • DSA: 34
pdf_data/keywords/hash_function
  • MD:
    • MD4:
      • MD4: 2
    • MD5:
      • MD5: 3
  • PBKDF:
    • PBKDF2: 2
  • RIPEMD:
    • RIPEMD160: 2
  • SHA:
    • SHA1:
      • SHA-1: 7
    • SHA2:
      • SHA2: 2
    • SHA3:
      • SHA3: 2
  • MD:
    • MD4:
      • MD4: 2
    • MD5:
      • MD5: 3
  • PBKDF:
    • PBKDF2: 2
  • RIPEMD:
    • RIPEMD160: 2
  • SHA:
    • SHA1:
      • SHA-1: 11
    • SHA2:
      • SHA2: 2
    • SHA3:
      • SHA3: 2
pdf_data/keywords/crypto_scheme
  • KA:
    • Key Agreement: 7
    • Key agreement: 6
  • KEX:
    • Key Exchange: 1
  • MAC:
    • MAC: 7
  • KA:
    • Key Agreement: 3
    • Key agreement: 2
  • KEX:
    • Key Exchange: 1
  • MAC:
    • MAC: 7
pdf_data/keywords/crypto_protocol
  • IKE:
    • IKE: 1
  • TLS:
    • DTLS:
      • DTLS: 3
    • TLS:
      • TLS: 49
      • TLS v1.2: 2
  • IKE:
    • IKE: 1
  • TLS:
    • DTLS:
      • DTLS: 3
    • TLS:
      • TLS: 40
      • TLS v1.2: 3
pdf_data/keywords/randomness
  • PRNG:
    • DRBG: 28
    • PRNG: 1
  • RNG:
    • RNG: 6
  • PRNG:
    • DRBG: 27
    • PRNG: 1
  • RNG:
    • RNG: 6
pdf_data/keywords/cipher_mode
  • CBC:
    • CBC: 9
  • CTR:
    • CTR: 1
  • ECB:
    • ECB: 1
  • GCM:
    • GCM: 9
  • CBC:
    • CBC: 11
  • CTR:
    • CTR: 1
  • ECB:
    • ECB: 2
  • GCM:
    • GCM: 10
pdf_data/keywords/ecc_curve
  • NIST:
    • P-256: 20
    • P-384: 16
    • P-521: 16
  • NIST:
    • P-256: 22
    • P-384: 18
    • P-521: 18
pdf_data/keywords/crypto_library
  • GnuTLS:
    • GnuTLS: 46
  • Nettle:
    • Nettle: 4
  • GnuTLS:
    • GnuTLS: 48
  • Nettle:
    • Nettle: 6
pdf_data/keywords/standard_id
  • FIPS:
    • FIPS 140: 2
    • FIPS 140-2: 54
    • FIPS 186-4: 7
    • FIPS PUB 140-2: 1
    • FIPS140-2: 1
    • FIPS180-4: 2
    • FIPS186-4: 4
    • FIPS197: 5
    • FIPS198-1: 4
  • NIST:
    • NIST SP 800-135: 1
    • NIST SP 800-90A: 1
    • SP 800-52: 1
    • SP 800-90A: 1
  • PKCS:
    • PKCS#1: 1
    • PKCS#11: 2
  • RFC:
    • RFC 5764: 1
    • RFC3711: 1
    • RFC4347: 2
    • RFC4357: 2
    • RFC5246: 3
    • RFC5288: 2
    • RFC5764: 1
  • X509:
    • X.509: 3
  • FIPS:
    • FIPS 140: 2
    • FIPS 140-2: 56
    • FIPS 186-4: 6
    • FIPS PUB 140-2: 1
    • FIPS140-2: 1
    • FIPS180-4: 3
    • FIPS186-4: 6
    • FIPS197: 9
    • FIPS198-1: 7
  • NIST:
    • NIST SP 800-90A: 1
    • SP 800-52: 1
    • SP 800-90A: 1
  • PKCS:
    • PKCS#1: 1
    • PKCS#11: 2
  • RFC:
    • RFC 5764: 1
    • RFC3711: 1
    • RFC4347: 2
    • RFC4357: 2
    • RFC5246: 3
    • RFC5288: 2
    • RFC5764: 1
  • X509:
    • X.509: 3
pdf_data/policy_metadata
state/policy_pdf_hash Different Different
state/policy_txt_hash Different Different
web_data/certificate_pdf_url https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/April 2020_010520_0717.pdf https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/April 2023_010523_0646.pdf
web_data/date_sunset 19.04.2025
web_data/historical_reason SP 800-56Arev3 transition - replaced by certificate #4472
web_data/status historical active
web_data/tested_conf Amazon Linux 2 running on Amazon EC2 i3.metal with Intel Xeon E5 with PAA, Amazon Linux 2 running on Amazon EC2 i3.metal with Intel Xeon E5 without PAA (single-user mode), , Amazon Linux 2 running on Amazon EC2 c6g.metal with Graviton 2 with PAA, Amazon Linux 2 running on Amazon EC2 c6g.metal with Graviton 2 without PAA (single-user mode), Amazon Linux 2 running on Amazon EC2 i3.metal with Intel Xeon E5 with PAA, Amazon Linux 2 running on Amazon EC2 i3.metal with Intel Xeon E5 without PAA
web_data/validation_history
  • date: 20.04.2020
  • lab: ATSEC INFORMATION SECURITY CORP
  • validation_type: Initial
  • date: 14.04.2023
  • lab: ATSEC INFORMATION SECURITY CORP
  • validation_type: Initial