This page was not yet optimized for use on mobile devices.
Rocky Linux 9 Kernel Cryptographic API
Certificate details
| Certificate ID | #5452 |
|---|---|
| Status | active |
| Validation dates | 29.07.2026 |
| Sunset date | 28-07-2031 |
| Standard | FIPS 140-3 |
| Security level | 1 |
| Type | Software |
| Embodiment | MultiChipStand |
| Caveat | When operated in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs. |
| Exceptions |
|
| Description | The Rocky Linux 9 Kernel Cryptographic API provides a C language API for use by other (kernel space and user space) processes that require cryptographic functionality. |
| Vendor | Ctrl IQ, Inc. https://ciq.com |
| Lab | atsec information security corporation |
| Algorithms |
|
| References | This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates. |
Security policy
Extracted keywords
Symmetric Algorithms
AES, AES-128, AES-192, AES-256, AES-, CAST, HMAC, CMACAsymmetric Algorithms
ECDSA, Diffie-Hellman, DHHash functions
SHA-1, SHA-512, SHA-3, SHA3-224, SHA3-256, SHA3-384, SHA3-512, PBKDF2Schemes
MAC, Key AgreementProtocols
IKEv2, IPsecRandomness
DRBG, RNG, RBGBlock cipher modes
ECB, CBC, CTR, CFB, OFB, GCM, CCM, XTSTrusted Execution Environments
PSP, SSCSecurity level
Level 1Automated analysis
Automated inference - use with caution
All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.No automatically derived data are available in this section.
Cross-references
No references are available for this certificate.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate was first processed.
{
"_type": "sec_certs.sample.fips.FIPSCertificate",
"cert_id": 5452,
"dgst": "d540bb71097dd07c",
"heuristics": {
"_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
"algorithms": {
"_type": "Set",
"elements": [
"AES-CTRA7410",
"#A7412",
"#A7413",
"SHA-1A7415",
"AES-CBC-CS3A7410",
"RSA SigVer (FIPS186-5)A7403",
"Safe Primes Key GenerationA7403",
"SHA2-224A7415",
"#A7406",
"SHA2-256A7415",
"SHA3-384A7403",
"HMAC-SHA-1A7415",
"#A7414",
"#A7403",
"AES-CCMA7410",
"#A7415",
"AES-OFBA7410",
"SHA3-512A7403",
"RSA SigVer (FIPS186-4)A7403",
"AES-CBCA7410",
"AES-GMACA7410",
"SHA3-224A7403",
"#A7408",
"#A7410",
"#A7409",
"HMAC-SHA3-256A7403",
"HMAC DRBGA7415",
"SHA2-512A7415",
"HMAC-SHA2-384A7415",
"HMAC-SHA3-224A7403",
"AES-CFB128A7410",
"#A7407",
"Counter DRBGA7412",
"HMAC-SHA3-384A7403",
"Hash DRBGA7415",
"AES-ECBA7412",
"#A7405",
"HMAC-SHA2-512A7415",
"#A7411",
"KAS-FFC-SSC Sp800-56Ar3A7403",
"AES-XTS Testing Revision 2.0A7410",
"AES-CMACA7410",
"AES-GCMA7412",
"HMAC-SHA2-224A7415",
"HMAC-SHA3-512A7403",
"SHA2-384A7415",
"HMAC-SHA2-256A7415",
"SHA3-256A7403"
]
},
"cpe_matches": null,
"direct_transitive_cves": null,
"extracted_versions": {
"_type": "Set",
"elements": [
"9"
]
},
"indirect_transitive_cves": null,
"module_processed_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": null,
"indirectly_referenced_by": null,
"indirectly_referencing": null
},
"module_prunned_references": {
"_type": "Set",
"elements": []
},
"policy_processed_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": null,
"indirectly_referenced_by": null,
"indirectly_referencing": null
},
"policy_prunned_references": {
"_type": "Set",
"elements": []
},
"related_cves": null,
"verified_cpe_matches": null
},
"pdf_data": {
"_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
"br1_deviations": 0,
"br1_tables": {
"_type": "sec_certs.heuristics.br1.table_parsing.model.br1_tables.BR1Tables",
"approved_algorithms": {
"entries": [
{
"algorithm": "AES-CBC",
"cavpCertName": "A7403, A7407, A7410",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-CBC-CS3",
"cavpCertName": "A7403, A7407, A7410",
"properties": "Direction - decrypt, encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-CCM",
"cavpCertName": "A7403, A7410",
"properties": "Key Length - 128, 192, 256",
"reference": "SP 800-38C"
},
{
"algorithm": "AES-CFB128",
"cavpCertName": "A7403, A7410",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-CMAC",
"cavpCertName": "A7403, A7410",
"properties": "Direction - Generation Key Length - 128, 192, 256",
"reference": "SP 800-38B"
},
{
"algorithm": "AES-CTR",
"cavpCertName": "A7403, A7407, A7410",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-ECB",
"cavpCertName": "A7403, A7405, A7406, A7407, A7408, A7409, A7410, A7411, A7412",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-GCM",
"cavpCertName": "A7403, A7406, A7407, A7409, A7410, A7412",
"properties": "Direction - Decrypt, Encrypt IV Generation - External Key Length - 128, 192, 256",
"reference": "SP 800-38D"
},
{
"algorithm": "AES-GCM",
"cavpCertName": "A7405, A7408, A7411",
"properties": "Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256",
"reference": "SP 800-38D"
},
{
"algorithm": "AES-GMAC",
"cavpCertName": "A7403, A7410",
"properties": "Direction - Decrypt, Encrypt IV Generation - External Key Length - 128, 192, 256",
"reference": "SP 800-38D"
},
{
"algorithm": "AES-OFB",
"cavpCertName": "A7403, A7410",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-XTS Testing Revision 2.0",
"cavpCertName": "A7403, A7407, A7410",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 256",
"reference": "SP 800-38E"
},
{
"algorithm": "Counter DRBG",
"cavpCertName": "A7403, A7405, A7406, A7407, A7408, A7409, A7410, A7411, A7412",
"properties": "Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - Yes",
"reference": "SP 800-90A Rev. 1"
},
{
"algorithm": "Hash DRBG",
"cavpCertName": "A7403, A7413, A7414, A7415",
"properties": "Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512",
"reference": "SP 800-90A Rev. 1"
},
{
"algorithm": "HMAC DRBG",
"cavpCertName": "A7403, A7413, A7414, A7415",
"properties": "Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512",
"reference": "SP 800-90A Rev. 1"
},
{
"algorithm": "HMAC-SHA-1",
"cavpCertName": "A7403, A7413, A7414, A7415",
"properties": "Key Length - Key Length: 112-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA2- 224",
"cavpCertName": "A7403, A7413, A7414, A7415",
"properties": "Key Length - Key Length: 112-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA2- 256",
"cavpCertName": "A7403, A7413, A7414, A7415",
"properties": "Key Length - Key Length: 112-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA2- 384",
"cavpCertName": "A7403, A7413, A7414, A7415",
"properties": "Key Length - Key Length: 112-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA2- 512",
"cavpCertName": "A7403, A7413, A7414, A7415",
"properties": "Key Length - Key Length: 112-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA3- 224",
"cavpCertName": "A7403",
"properties": "Key Length - Key Length: 112-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA3- 256",
"cavpCertName": "A7403",
"properties": "Key Length - Key Length: 112-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA3- 384",
"cavpCertName": "A7403",
"properties": "Key Length - Key Length: 112-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA3- 512",
"cavpCertName": "A7403",
"properties": "Key Length - Key Length: 112-524288 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "KAS-FFC-SSC Sp800-56Ar3",
"cavpCertName": "A7403",
"properties": "Domain Parameter Generation Methods ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192 Scheme - dhEphem - KAS Role - initiator, responder",
"reference": "SP 800-56A Rev. 3"
},
{
"algorithm": "RSA SigVer (FIPS186-4)",
"cavpCertName": "A7403",
"properties": "Signature Type - PKCS 1.5 Modulo - 2048, 3072, 4096",
"reference": "FIPS 186-4"
},
{
"algorithm": "RSA SigVer (FIPS186-5)",
"cavpCertName": "A7403",
"properties": "Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5",
"reference": "FIPS 186-5"
},
{
"algorithm": "Safe Primes Key Generation",
"cavpCertName": "A7403",
"properties": "Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192",
"reference": "SP 800-56A Rev. 3"
},
{
"algorithm": "SHA-1",
"cavpCertName": "A7403, A7413, A7414, A7415",
"properties": "Message Length - Message Length: 0- 65536 Increment 8 Large Message Sizes - 1, 2",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2-224",
"cavpCertName": "A7403, A7413, A7414, A7415",
"properties": "Message Length - Message Length: 0- 65536 Increment 8 Large Message Sizes - 1, 2",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2-256",
"cavpCertName": "A7403, A7413, A7414, A7415",
"properties": "Message Length - Message Length: 0- 65536 Increment 8 Large Message Sizes - 1, 2",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2-384",
"cavpCertName": "A7403, A7413, A7414, A7415",
"properties": "Message Length - Message Length: 0- 65536 Increment 8 Large Message Sizes - 1, 2",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2-512",
"cavpCertName": "A7403, A7413, A7414, A7415",
"properties": "Message Length - Message Length: 0- 65536 Increment 8 Large Message Sizes - 1, 2",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA3-224",
"cavpCertName": "A7403",
"properties": "Message Length - Message Length: 0- 65536 Increment 8 Large Message Sizes - 1, 2",
"reference": "FIPS 202"
},
{
"algorithm": "SHA3-256",
"cavpCertName": "A7403",
"properties": "Message Length - Message Length: 0- 65536 Increment 8 Large Message Sizes - 1, 2",
"reference": "FIPS 202"
},
{
"algorithm": "SHA3-384",
"cavpCertName": "A7403",
"properties": "Message Length - Message Length: 0- 65536 Increment 8 Large Message Sizes - 1, 2",
"reference": "FIPS 202"
},
{
"algorithm": "SHA3-512",
"cavpCertName": "A7403",
"properties": "Message Length - Message Length: 0- 65536 Increment 8 Large Message Sizes - 1, 2",
"reference": "FIPS 202"
}
],
"found": true,
"section": 2,
"subsection": 5
},
"approved_services": {
"entries": [
{
"description": "Encrypt a plaintext",
"indicator": "crypto_skcipher_setkey returns 0",
"inputs": "AES key, plaintext, IV (if required)",
"name": "Encryptio n",
"outputs": "Cipherte xt",
"rolesSspAccess": "Crypto Officer - AES key: W,E",
"secFunImpl": "Encryption"
},
{
"description": "Decrypt a ciphertext",
"indicator": "crypto_skcipher_setkey returns 0",
"inputs": "AES key, ciphertext , IV (if required)",
"name": "Decryptio n",
"outputs": "Plaintext",
"rolesSspAccess": "Crypto Officer - AES key: W,E",
"secFunImpl": "Decryptio n"
},
{
"description": "Encrypt and authentica te a plaintext",
"indicator": "For all except AES GCM: crypto_aead_setkey returns 0; For AES GCM: crypto_aead_get_flags(tfm) has the CRYPTO_TFM_FIPS_COM PLIANCE flag set",
"inputs": "AES key, plaintext, IV (CCM/GC M)",
"name": "Authentic ated encryption",
"outputs": "Cipherte xt, MAC tag (CCM/G CM)",
"rolesSspAccess": "Crypto Officer - AES key: W,E - GCM IV: G,R,E",
"secFunImpl": "Authentica ted encryption"
},
{
"description": "Decrypt and authentica te a ciphertext",
"indicator": "crypto_aead_setkey returns 0",
"inputs": "AES key, ciphertext , IV (CCM/GC M), MAC tag (CCM/GC M)",
"name": "Authentic ated decryption",
"outputs": "Plaintext or failure",
"rolesSspAccess": "Crypto Officer - AES key: W,E - GCM IV: W,E",
"secFunImpl": "Authentica ted decryption"
},
{
"description": "Compute a message digest",
"indicator": "crypto_shash_init returns 0",
"inputs": "Message",
"name": "Message digest",
"outputs": "Digest value",
"rolesSspAccess": "Crypto Officer",
"secFunImpl": "Message digest"
},
{
"description": "Compute a MAC tag",
"indicator": "crypto_shash_init returns 0",
"inputs": "AES key or HMAC key, message",
"name": "Message authentica tion",
"outputs": "MAC tag",
"rolesSspAccess": "Crypto Officer - AES key: W,E - HMAC key: W,E",
"secFunImpl": "Message authentica tion"
},
{
"description": "Generate random bytes",
"indicator": "crypto_rng_get_bytes returns 0",
"inputs": "Output length",
"name": "Random number generation",
"outputs": "Random bytes",
"rolesSspAccess": "Crypto Officer - Entropy input: G,E,Z - CTR_DRB G Seed (IG D.L): G,E - Hash_DRB G Seed (IG D.L): G,E - HMAC_D RBG Seed (IG D.L): G,E - CTR_DRB G Internal State (V, Key) (IG D.L): G,W,E - Hash_DRB G Internal State (V, C) (IG D.L): G,W,E - HMAC_D RBG Internal State (V, Key) (IG",
"secFunImpl": "Random Number Generation with CTR_DRB G Random Number Generation with HMAC_D RBG Random Number Generation with Hash_DRB G"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "D.L): G,W,E",
"secFunImpl": ""
},
{
"description": "Generate entropy from a dedicated instance of Jitter RNG",
"indicator": "crypto_rng_get_bytes returns 0",
"inputs": "Output length",
"name": "Random number generation using entropy source",
"outputs": "Random bytes",
"rolesSspAccess": "Crypto Officer",
"secFunImpl": ""
},
{
"description": "Compute a shared secret",
"indicator": "crypto_kpp_compute_share d_secret returns 0",
"inputs": "Owner private key, peer public key",
"name": "Shared secret computati on",
"outputs": "Shared secret",
"rolesSspAccess": "Crypto Officer - DH private key: W,E - DH public key: W,E - Shared secret: G,R",
"secFunImpl": "Shared secret computatio n"
},
{
"description": "Generate a key pair",
"indicator": "crypto_kpp_set_secret and crypto_kpp_generate_public _key return 0",
"inputs": "Group",
"name": "Key pair generation",
"outputs": "Key pair",
"rolesSspAccess": "Crypto Officer - DH private key: G,R - DH public key: G,R - Intermedia te key generation value: G,E,Z",
"secFunImpl": "Key pair generation"
},
{
"description": "Compute an EDC (crc32, crc32c, crct10dif)",
"indicator": "None",
"inputs": "Message",
"name": "Error detection code",
"outputs": "EDC",
"rolesSspAccess": "Crypto Officer",
"secFunImpl": "None"
},
{
"description": "Compress data (deflate, lz4, lz4hc, lzo, zlib- deflate, zstd)",
"indicator": "None",
"inputs": "Data",
"name": "Compressi on",
"outputs": "Compress ed data",
"rolesSspAccess": "Crypto Officer",
"secFunImpl": "None"
},
{
"description": "Use the kernel to perform various non- cryptogra phic operations",
"indicator": "None",
"inputs": "Identifier, various argument s",
"name": "Generic system call",
"outputs": "Various return values",
"rolesSspAccess": "Crypto Officer",
"secFunImpl": "None"
},
{
"description": "Return the module name and version informatio n",
"indicator": "None",
"inputs": "N/A",
"name": "Show version",
"outputs": "Module name and version",
"rolesSspAccess": "Crypto Officer",
"secFunImpl": "None"
},
{
"description": "Return the module status",
"indicator": "None",
"inputs": "N/A",
"name": "Show status",
"outputs": "Module status",
"rolesSspAccess": "Crypto Officer",
"secFunImpl": "None"
},
{
"description": "Perform the CASTs and integrity tests",
"indicator": "None",
"inputs": "N/A",
"name": "Self-test",
"outputs": "Pass/fail",
"rolesSspAccess": "Crypto Officer",
"secFunImpl": "Encryption Decryptio n Authentica ted encryption Authentica ted decryption Message digest Message authentica tion Random Number Generation with CTR_DRB G Random Number Generation with HMAC_D RBG"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "",
"secFunImpl": "Random Number Generation with Hash_DRB G Shared secret computatio n Signature verificatio n with RSA Signature verificatio n with RSA (legacy use) Key pair generation"
},
{
"description": "Zeroize SSPs",
"indicator": "None",
"inputs": "Any SSP",
"name": "Zeroizatio n",
"outputs": "N/A",
"rolesSspAccess": "Crypto Officer - AES key: Z - HMAC key: Z - Shared secret: Z - Entropy input: Z - CTR_DRB G Seed (IG D.L): Z - Hash_DRB G Seed (IG D.L): Z - HMAC_D RBG Seed (IG D.L): Z -",
"secFunImpl": "None"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "CTR_DRB G Internal State (V, Key) (IG D.L): Z - Hash_DRB G Internal State (V, C) (IG D.L): Z - HMAC_D RBG Internal State (V, Key) (IG D.L): Z - DH public key: Z - DH private key: Z - Intermedia te key generation value: Z",
"secFunImpl": ""
}
],
"found": true,
"section": 4,
"subsection": 3
},
"authentication_methods": {
"entries": [],
"found": false,
"section": 4,
"subsection": 1
},
"cond_self_tests": {
"entries": [
{
"algorithmOrTest": "AES-CBC",
"condition": "Module initialization",
"details": "Encryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128, 192, 256- bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES-CBC",
"condition": "Module initialization",
"details": "Decryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128, 192, 256- bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES-CBC (A7407)",
"condition": "Module initialization",
"details": "Encryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128, 192, 256- bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES-CBC (A7407)",
"condition": "Module initialization",
"details": "Decryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128, 192, 256- bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES-CBC (A7410)",
"condition": "Module initialization",
"details": "Encryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128, 192, 256- bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES-CBC (A7410)",
"condition": "Module initialization",
"details": "Decryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128, 192, 256- bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES-CBC- CS3",
"condition": "Module initialization",
"details": "Encryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128-bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES-CBC- CS3",
"condition": "Module initialization",
"details": "Decryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128-bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES-CBC- CS3 (A7407)",
"condition": "Module initialization",
"details": "Encryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128-bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES-CBC- CS3 (A7407)",
"condition": "Module initialization",
"details": "Decryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128-bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES-CCM",
"condition": "Module initialization",
"details": "Encryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128, 192, 256- bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES-CCM",
"condition": "Module initialization",
"details": "Decryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128, 192, 256- bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES-CCM (A7410)",
"condition": "Module initialization",
"details": "Encryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128, 192, 256- bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES-CCM (A7410)",
"condition": "Module initialization",
"details": "Decryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128, 192, 256- bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES- CFB128",
"condition": "Module initialization",
"details": "Encryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128, 192, 256- bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES- CFB128",
"condition": "Module initialization",
"details": "Decryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128, 192, 256- bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES- CFB128 (A7410)",
"condition": "Module initialization",
"details": "Encryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128, 192, 256- bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES- CFB128 (A7410)",
"condition": "Module initialization",
"details": "Decryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128, 192, 256- bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES-CTR",
"condition": "Module initialization",
"details": "Encryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128, 192, 256- bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES-CTR",
"condition": "Module initialization",
"details": "Decryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128, 192, 256- bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES-CTR (A7407)",
"condition": "Module initialization",
"details": "Encryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128, 192, 256- bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES-CTR (A7407)",
"condition": "Module initialization",
"details": "Decryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128, 192, 256- bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES-ECB",
"condition": "Module initialization",
"details": "Encryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128, 192, 256- bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES-ECB",
"condition": "Module initialization",
"details": "Decryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128, 192, 256- bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES-ECB (A7407)",
"condition": "Module initialization",
"details": "Encryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128, 192, 256- bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES-ECB (A7407)",
"condition": "Module initialization",
"details": "Decryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128, 192, 256- bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES-GCM",
"condition": "Module initialization",
"details": "Encryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128, 192, 256- bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES-GCM",
"condition": "Module initialization",
"details": "Decryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128, 192, 256- bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES-GCM (A7409)",
"condition": "Module initialization",
"details": "Encryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128, 192, 256- bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES-GCM (A7409)",
"condition": "Module initialization",
"details": "Decryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128, 192, 256- bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES-OFB",
"condition": "Module initialization",
"details": "Encryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128-bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES-OFB",
"condition": "Module initialization",
"details": "Decryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128-bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES-OFB (A7410)",
"condition": "Module initialization",
"details": "Encryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128-bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES-OFB (A7410)",
"condition": "Module initialization",
"details": "Decryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128-bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES-XTS Testing Revision 2.0",
"condition": "Module initialization",
"details": "Encryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "256, 512-bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES-XTS Testing Revision 2.0",
"condition": "Module initialization",
"details": "Decryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "256, 512-bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES-XTS Testing Revision 2.0 (A7407)",
"condition": "Module initialization",
"details": "Encryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "256, 512-bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES-XTS Testing Revision 2.0 (A7407)",
"condition": "Module initialization",
"details": "Decryption",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "256, 512-bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "SHA-1 (A7403)",
"condition": "Module initialization",
"details": "Message digest",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "0-8184-bit messages",
"type": "CAST"
},
{
"algorithmOrTest": "SHA-1 (A7413)",
"condition": "Module initialization",
"details": "Message digest",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "0-8184-bit messages",
"type": "CAST"
},
{
"algorithmOrTest": "SHA-1 (A7414)",
"condition": "Module initialization",
"details": "Message digest",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "0-8184-bit messages",
"type": "CAST"
},
{
"algorithmOrTest": "SHA-1 (A7415)",
"condition": "Module initialization",
"details": "Message digest",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "0-8184-bit messages",
"type": "CAST"
},
{
"algorithmOrTest": "SHA2-224 (A7403)",
"condition": "Module initialization",
"details": "Message digest",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "0-8184-bit messages",
"type": "CAST"
},
{
"algorithmOrTest": "SHA2-224 (A7413)",
"condition": "Module initialization",
"details": "Message digest",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "0-8184-bit messages",
"type": "CAST"
},
{
"algorithmOrTest": "SHA2-224 (A7414)",
"condition": "Module initialization",
"details": "Message digest",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "0-8184-bit messages",
"type": "CAST"
},
{
"algorithmOrTest": "SHA2-224 (A7415)",
"condition": "Module initialization",
"details": "Message digest",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "0-8184-bit messages",
"type": "CAST"
},
{
"algorithmOrTest": "SHA2-256 (A7403)",
"condition": "Module initialization",
"details": "Message digest",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "0-8184-bit messages",
"type": "CAST"
},
{
"algorithmOrTest": "SHA2-256 (A7413)",
"condition": "Module initialization",
"details": "Message digest",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "0-8184-bit messages",
"type": "CAST"
},
{
"algorithmOrTest": "SHA2-256 (A7414)",
"condition": "Module initialization",
"details": "Message digest",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "0-8184-bit messages",
"type": "CAST"
},
{
"algorithmOrTest": "SHA2-256 (A7415)",
"condition": "Module initialization",
"details": "Message digest",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "0-8184-bit messages",
"type": "CAST"
},
{
"algorithmOrTest": "SHA2-384 (A7403)",
"condition": "Module initialization",
"details": "Message digest",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "0-8184-bit messages",
"type": "CAST"
},
{
"algorithmOrTest": "SHA2-384 (A7413)",
"condition": "Module initialization",
"details": "Message digest",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "0-8184-bit messages",
"type": "CAST"
},
{
"algorithmOrTest": "SHA2-384 (A7414)",
"condition": "Module initialization",
"details": "Message digest",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "0-8184-bit messages",
"type": "CAST"
},
{
"algorithmOrTest": "SHA2-384 (A7415)",
"condition": "Module initialization",
"details": "Message digest",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "0-8184-bit messages",
"type": "CAST"
},
{
"algorithmOrTest": "SHA2-512 (A7403)",
"condition": "Module initialization",
"details": "Message digest",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "0-8184-bit messages",
"type": "CAST"
},
{
"algorithmOrTest": "SHA2-512 (A7413)",
"condition": "Module initialization",
"details": "Message digest",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "0-8184-bit messages",
"type": "CAST"
},
{
"algorithmOrTest": "SHA2-512 (A7414)",
"condition": "Module initialization",
"details": "Message digest",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "0-8184-bit messages",
"type": "CAST"
},
{
"algorithmOrTest": "SHA2-512 (A7415)",
"condition": "Module initialization",
"details": "Message digest",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "0-8184-bit messages",
"type": "CAST"
},
{
"algorithmOrTest": "SHA3-224 (A7403)",
"condition": "Module initialization",
"details": "Message digest",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "0-8184-bit messages",
"type": "CAST"
},
{
"algorithmOrTest": "SHA3-256 (A7403)",
"condition": "Module initialization",
"details": "Message digest",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "0-8184-bit messages",
"type": "CAST"
},
{
"algorithmOrTest": "SHA3-384 (A7403)",
"condition": "Module initialization",
"details": "Message digest",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "0-8184-bit messages",
"type": "CAST"
},
{
"algorithmOrTest": "SHA3-512 (A7403)",
"condition": "Module initialization",
"details": "Message digest",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "0-8184-bit messages",
"type": "CAST"
},
{
"algorithmOrTest": "AES-CMAC",
"condition": "Module initialization",
"details": "Message authentication",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128, 256-bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "AES-CMAC (A7410)",
"condition": "Module initialization",
"details": "Message authentication",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "128, 256-bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC- SHA-1",
"condition": "Module initialization",
"details": "Message authentication",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "32-64-bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC- SHA-1 (A7415)",
"condition": "Module initialization",
"details": "Message authentication",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "32-64-bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC- SHA2-224",
"condition": "Module initialization",
"details": "Message authentication",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "32-1048-bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC- SHA2-224 (A7415)",
"condition": "Module initialization",
"details": "Message authentication",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "32-1048-bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC- SHA2-256",
"condition": "Module initialization",
"details": "Message authentication",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "32-64-bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC- SHA2-256 (A7415)",
"condition": "Module initialization",
"details": "Message authentication",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "32-64-bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC- SHA2-384",
"condition": "Module initialization",
"details": "Message authentication",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "32-1048-bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC- SHA2-384 (A7415)",
"condition": "Module initialization",
"details": "Message authentication",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "32-1048-bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC- SHA2-512",
"condition": "Module initialization",
"details": "Message authentication",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "32-1048-bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC- SHA2-512 (A7415)",
"condition": "Module initialization",
"details": "Message authentication",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "32-1048-bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC- SHA3-224 (A7403)",
"condition": "Module initialization",
"details": "Message authentication",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "32-1048-bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC- SHA3-256 (A7403)",
"condition": "Module initialization",
"details": "Message authentication",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "32-1048-bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC- SHA3-384 (A7403)",
"condition": "Module initialization",
"details": "Message authentication",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "32-1048-bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC- SHA3-512 (A7403)",
"condition": "Module initialization",
"details": "Message authentication",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "32-1048-bit keys",
"type": "CAST"
},
{
"algorithmOrTest": "Counter DRBG",
"condition": "Module initialization",
"details": "SP 800-90Ar1 (instantiate, reseed, generate) health test",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "AES-128, AES- 192, AES-256 with/without prediction resistance",
"type": "CAST"
},
{
"algorithmOrTest": "Hash DRBG",
"condition": "Module initialization",
"details": "SP 800-90Ar1 (instantiate, reseed, generate) health test",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "SHA-1, SHA2- 256, SHA2-512 with/without prediction resistance",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC DRBG",
"condition": "Module initialization",
"details": "SP 800-90Ar1 (instantiate, reseed, generate) health test",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "SHA-1, SHA2- 256, SHA2-512 with/without prediction resistance",
"type": "CAST"
},
{
"algorithmOrTest": "KAS-FFC- SSC Sp800- 56Ar3 (A7403)",
"condition": "Module initialization",
"details": "Shared secret computation",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "ffdhe2048",
"type": "CAST"
},
{
"algorithmOrTest": "RSA SigVer (FIPS186-5) (A7403)",
"condition": "Module initialization",
"details": "Signature verification with RSA",
"indicator": "Module is operational",
"testMethod": "KAT",
"testProps": "PKCS#1 v1.5 with SHA-512 and 4096-bit key",
"type": "CAST"
},
{
"algorithmOrTest": "Safe Primes Key Generation (A7403)",
"condition": "Key pair generation",
"details": "SP 800-56Ar3 Section 5.6.2.1.4",
"indicator": "Key pair generation is successful",
"testMethod": "PCT",
"testProps": "N/A",
"type": "PCT"
},
{
"algorithmOrTest": "Entropy source",
"condition": "Entropy source initialization",
"details": "Entropy source start-up test on 1024 samples",
"indicator": "Entropy source is operational",
"testMethod": "APT",
"testProps": "Cutoff C = 325; Windows size = 512",
"type": "CAST"
},
{
"algorithmOrTest": "Entropy source",
"condition": "Entropy source initialization",
"details": "Entropy source start-up test on 1024 samples",
"indicator": "Entropy source is operational",
"testMethod": "RCT",
"testProps": "Cutoff C = 31",
"type": "CAST"
},
{
"algorithmOrTest": "Entropy source",
"condition": "Continuously as entropy is requested",
"details": "Entropy source continuous test",
"indicator": "jent_kcapi_random returns 0",
"testMethod": "APT",
"testProps": "Cutoff C = 355; Windows size = 512",
"type": "CAST"
},
{
"algorithmOrTest": "Entropy source",
"condition": "Continuously as entropy is requested",
"details": "Entropy source continuous test",
"indicator": "jent_kcapi_random returns 0",
"testMethod": "RCT",
"testProps": "Cutoff C = 61",
"type": "CAST"
}
],
"found": true,
"section": 10,
"subsection": 2
},
"error_states": {
"entries": [
{
"conditions": "Any self-test failure",
"description": "The Linux kernel immediately stops executing",
"indicator": "Kernel panic",
"name": "Error",
"recoveryMethod": "Restart of the module"
}
],
"found": true,
"section": 10,
"subsection": 4
},
"mechanisms_actions": {
"entries": [],
"found": false,
"section": 7,
"subsection": 1
},
"modes_of_operation": {
"entries": [
{
"description": "Automatically entered whenever an approved service is requested",
"name": "Approved mode",
"statusIndicator": "Mapped to approved service indicator in Section 4.3 for all approved algorithms except AES GCM: respective approved service function returns indicator 0; For AES GCM: crypto_aead_get_flags(tfm) has the CRYPTO_TFM_FIPS_COMPLIANCE flag set",
"type": "Approved"
},
{
"description": "Automatically entered whenever a non-approved service is requested",
"name": "Non- approved mode",
"statusIndicator": "No service indicator required for non-approved services per IG 2.4.C",
"type": "Non- Approved"
}
],
"found": true,
"section": 2,
"subsection": 4
},
"non_approved_allowed_NSC": {
"entries": [],
"found": false,
"section": 2,
"subsection": 5
},
"non_approved_allowed_algos": {
"entries": [],
"found": false,
"section": 2,
"subsection": 5
},
"non_approved_not_allowed": {
"entries": [
{
"name": "AES-GCM with external IV",
"use": "Encryption with external IV (not compliant to FIPS 140-3 IG C.H)"
},
{
"name": "KBKDF in libkcapi",
"use": "Key derivation with implementation not tested by CAVP"
},
{
"name": "HKDF in libkcapi",
"use": "Key derivation with implementation not tested by CAVP"
},
{
"name": "PBKDF2 in libkcapi",
"use": "Password-based Key derivation with implementation not tested by CAVP"
},
{
"name": "RSA PKCS#1 v1.5 with pre- hashed message",
"use": "Signature generation(pre-hashed message) primitive; Signature verification(pre-hashed message) primitive"
},
{
"name": "RSA PKCS#1 v1.5",
"use": "Key encapsulation / un-encapsulation"
},
{
"name": "RSA primitive",
"use": "Encryption primitive; Decryption primitive (not compliant to SP 800- 56Br2)"
},
{
"name": "ECDSA with pre-hashed message",
"use": "Signature generation(pre-hashed message) primitive; Signature verification(pre-hashed message) primitive"
}
],
"found": true,
"section": 2,
"subsection": 5
},
"non_approved_services": {
"entries": [
{
"alg_accessed": "AES-GCM with external",
"description": "Encrypt and authenticate a plaintext IV",
"name": "AES-GCM with external",
"role": "Crypto"
},
{
"alg_accessed": "IV",
"description": "using AES-GCM with an external",
"name": "IV encryption",
"role": "Officer"
},
{
"alg_accessed": "KBKDF in libkcapi HKDF in libkcapi PBKDF2 in libkcapi",
"description": "Derive a key from a key-derivation key, shared secret, or password",
"name": "Key derivation",
"role": "Crypto Officer"
},
{
"alg_accessed": "RSA PKCS#1 v1.5 with pre-hashed message ECDSA with pre-hashed message",
"description": "Generate a digital signature for a pre- hashed message",
"name": "Pre-hashed message signature generation",
"role": "Crypto Officer"
},
{
"alg_accessed": "RSA PKCS#1 v1.5 with pre-hashed message ECDSA with pre-hashed message",
"description": "Verify a digital signature for a pre- hashed message",
"name": "Pre-hashed message signature verification",
"role": "Crypto Officer"
},
{
"alg_accessed": "RSA PKCS#1 v1.5",
"description": "Key encapsulation using RSA PKCS#1 v1.5",
"name": "Key encapsulation",
"role": "Crypto Officer"
},
{
"alg_accessed": "RSA PKCS#1 v1.5",
"description": "Key un-encapsulation using RSA PKCS#1 v1.5",
"name": "Key un-encapsulation",
"role": "Crypto Officer"
},
{
"alg_accessed": "RSA primitive",
"description": "Compute the RSA encryption primitive",
"name": "Encryption primitive",
"role": "Crypto Officer"
},
{
"alg_accessed": "RSA primitive",
"description": "Compute the RSA decryption primitive",
"name": "Decryption primitive",
"role": "Crypto Officer"
}
],
"found": true,
"section": 4,
"subsection": 4
},
"ports_interfaces": {
"entries": [
{
"data": "API data input parameters, AF_ALG type input sockets",
"logicalInterface": "Data Input",
"physicalPort": "N/A"
},
{
"data": "API data output parameters, AF_ALG type output sockets, /proc/sys/crypto virtual files",
"logicalInterface": "Data Output",
"physicalPort": "N/A"
},
{
"data": "API function calls, API control input parameters, AF_ALG type input sockets, kernel command line arguments",
"logicalInterface": "Control Input",
"physicalPort": "N/A"
},
{
"data": "API return values, AF_ALG type output sockets, kernel logs",
"logicalInterface": "Status Output",
"physicalPort": "N/A"
}
],
"found": true,
"section": 3,
"subsection": 1
},
"roles": {
"entries": [
{
"authMethodList": "None",
"name": "Crypto Officer",
"operatorType": "Crypto Officer",
"type": "Role"
}
],
"found": true,
"section": 4,
"subsection": 2
},
"security_levels": {
"entries": [
{
"level": "1",
"section": "1",
"title": "General"
},
{
"level": "1",
"section": "2",
"title": "Cryptographic module specification"
},
{
"level": "1",
"section": "3",
"title": "Cryptographic module interfaces"
},
{
"level": "1",
"section": "4",
"title": "Roles, services, and authentication"
},
{
"level": "1",
"section": "5",
"title": "Software/Firmware security"
},
{
"level": "1",
"section": "6",
"title": "Operational environment"
},
{
"level": "N/A",
"section": "7",
"title": "Physical security"
},
{
"level": "N/A",
"section": "8",
"title": "Non-invasive security"
},
{
"level": "1",
"section": "9",
"title": "Sensitive security parameter management"
},
{
"level": "1",
"section": "10",
"title": "Self-tests"
},
{
"level": "1",
"section": "11",
"title": "Life-cycle assurance"
},
{
"level": "N/A",
"section": "12",
"title": "Mitigation of other attacks"
},
{
"level": "1",
"section": "",
"title": "Overall Level"
}
],
"found": true,
"section": 1,
"subsection": 2
},
"self_tests": {
"entries": [
{
"algorithmOrTest": "RSA SigVer (FIPS186-5) (A7403)",
"details": "Integrity test for kernel object files",
"indicator": "Module becomes operational and services are available for use",
"testMethod": "Signature verification with RSA",
"testProps": "3072-bit key with SHA2- 256",
"type": "SW/FW Integrity"
},
{
"algorithmOrTest": "HMAC- SHA2-256 (A7403)",
"details": "Integrity test for sha512hmac binary and libkcapi binary",
"indicator": "Module becomes operational and services are available for use",
"testMethod": "Message authentication",
"testProps": "128-bit key",
"type": "SW/FW Integrity"
},
{
"algorithmOrTest": "HMAC- SHA2-512 (A7403)",
"details": "Integrity test for kernel binary",
"indicator": "Module becomes operational and services are available for use",
"testMethod": "Message authentication",
"testProps": "128-bit key",
"type": "SW/FW Integrity"
}
],
"found": true,
"section": 10,
"subsection": 1
},
"ssp_io_methods": {
"entries": [
{
"dest": "Module RAM",
"distribution": "Manual",
"entry": "Electronic",
"format": "Plaintext",
"name": "API input parameters",
"sfiAlgo": "",
"source": "Operator calling application (TOEPP)"
},
{
"dest": "Module RAM",
"distribution": "Manual",
"entry": "Electronic",
"format": "Plaintext",
"name": "AF_ALG type input sockets",
"sfiAlgo": "",
"source": "Operator calling application (TOEPP)"
},
{
"dest": "Operator calling application (TOEPP)",
"distribution": "Manual",
"entry": "Electronic",
"format": "Plaintext",
"name": "API output parameters",
"sfiAlgo": "",
"source": "Module RAM"
},
{
"dest": "Operator calling application (TOEPP)",
"distribution": "Manual",
"entry": "Electronic",
"format": "Plaintext",
"name": "AF_ALG type output sockets",
"sfiAlgo": "",
"source": "Module RAM"
}
],
"found": true,
"section": 9,
"subsection": 2
},
"ssp_zeroization_methods": {
"entries": [
{
"description": "Zeroizes the SSPs contained within the cipher handle",
"method": "Free cipher handle",
"operatorId": "By calling the appropriate zeroization functions: AES key: crypto_free_skcipher and crypto_free_aead; HMAC key: crypto_free_shash and crypto_free_ahash; Entropy input: crypto_free_rng; DRBG seed: crypto_free_rng; DRBG internal state: crypto_free_rng; DH public key \u0026 DH private key: crypto_free_kpp",
"rationale": "Memory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable. The completion of the zeroization routine indicates that the zeroization procedure succeeded."
},
{
"description": "De-allocates the volatile memory used to store SSPs",
"method": "Remove power from the module",
"operatorId": "By removing power",
"rationale": "Volatile memory used by the module is overwritten within nanoseconds when power is removed. Module power off indicates that the zeroization procedure succeeded."
},
{
"description": "Automatically zeroized by the module when no longer needed",
"method": "Automatic",
"operatorId": "N/A",
"rationale": "Memory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable."
}
],
"found": true,
"section": 9,
"subsection": 3
},
"storage_areas": {
"entries": [
{
"description": "Temporary storage for SSPs used by the module as part of service execution",
"name": "Module RAM",
"persistance": "Dynamic"
}
],
"found": true,
"section": 9,
"subsection": 1
},
"tested_module_id_hw": {
"entries": [],
"found": false,
"section": 2,
"subsection": 2
},
"tested_module_id_hw_hy": {
"entries": [],
"found": false,
"section": 2,
"subsection": 2
},
"tested_module_id_sw_fw_hy": {
"entries": [],
"found": false,
"section": 2,
"subsection": 2
},
"tested_op_env_sw_fw_hy": {
"entries": [
{
"hardwarePlatform": "SuperMicro SuperServer 5039MS",
"hypervisorHostOs": "N/A",
"operatingSystem": "Rocky Linux 9",
"paa_pai": "Yes",
"processors": "Intel Kaby Lake Xeon E3-1270 v6",
"version": "kernel: rocky9.20260721; libkcapi: 1.4.0-2.el9"
},
{
"hardwarePlatform": "SuperMicro SuperServer 5039MS",
"hypervisorHostOs": "N/A",
"operatingSystem": "Rocky Linux 9",
"paa_pai": "No",
"processors": "Intel Kaby Lake Xeon E3-1270 v6",
"version": "kernel: rocky9.20260721; libkcapi: 1.4.0-2.el9"
}
],
"found": true,
"section": 2,
"subsection": 2
},
"vendor_affirmed_algos": {
"entries": [
{
"algoPropList": "Key type:Asymmetric",
"implName": "N/A",
"name": "Asymmetric Cryptographic Key Generation (CKG)",
"reference": "SP 800-133r2, Section 4, Example 1"
}
],
"found": true,
"section": 2,
"subsection": 5
},
"vendor_affirmed_op_env_sw_fw_hy": {
"entries": [],
"found": false,
"section": 2,
"subsection": 2
}
},
"is_br1_format": true,
"keywords": {
"asymmetric_crypto": {
"ECC": {
"ECDSA": {
"ECDSA": 4
}
},
"FF": {
"DH": {
"DH": 20,
"Diffie-Hellman": 4
}
}
},
"certification_process": {},
"cipher_mode": {
"CBC": {
"CBC": 2
},
"CCM": {
"CCM": 2
},
"CFB": {
"CFB": 1
},
"CTR": {
"CTR": 1
},
"ECB": {
"ECB": 1
},
"GCM": {
"GCM": 8
},
"OFB": {
"OFB": 1
},
"XTS": {
"XTS": 7
}
},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {},
"crypto_protocol": {
"IKE": {
"IKEv2": 1
},
"IPsec": {
"IPsec": 7
}
},
"crypto_scheme": {
"KA": {
"Key Agreement": 1
},
"MAC": {
"MAC": 8
}
},
"device_model": {},
"ecc_curve": {},
"eval_facility": {
"atsec": {
"atsec": 53
}
},
"fips_cert_id": {},
"fips_certlike": {
"Certlike": {
"- PKCS 1": 1,
"AES- 192": 1,
"AES-128": 2,
"AES-192": 1,
"AES-256": 2,
"AES-CBC 128, 192": 2,
"AES-CMAC 128": 1,
"AES-CTR 128": 2,
"AES-GCM 128": 2,
"HMAC- SHA-1": 2,
"HMAC-SHA-1": 6,
"PKCS 1": 1,
"PKCS#1": 14,
"RSA PKCS#1": 8,
"SHA-1": 19,
"SHA-3": 5,
"SHA-512": 1,
"SHA2- 256": 3,
"SHA2-224": 11,
"SHA2-256": 16,
"SHA2-384": 11,
"SHA2-512": 17,
"SHA3-224": 4,
"SHA3-256": 5,
"SHA3-384": 4,
"SHA3-512": 4
}
},
"fips_security_level": {
"Level": {
"Level 1": 2
}
},
"hash_function": {
"PBKDF": {
"PBKDF2": 2
},
"SHA": {
"SHA1": {
"SHA-1": 19
},
"SHA2": {
"SHA-512": 1
},
"SHA3": {
"SHA-3": 5,
"SHA3-224": 4,
"SHA3-256": 5,
"SHA3-384": 4,
"SHA3-512": 4
}
}
},
"ic_data_group": {},
"javacard_api_const": {},
"javacard_packages": {},
"javacard_version": {},
"os_name": {},
"pq_crypto": {},
"randomness": {
"PRNG": {
"DRBG": 27
},
"RNG": {
"RBG": 8,
"RNG": 2
}
},
"side_channel_analysis": {},
"standard_id": {
"FIPS": {
"FIPS 140-3": 61,
"FIPS 180-4": 6,
"FIPS 186-4": 2,
"FIPS 186-5": 2,
"FIPS 197": 1,
"FIPS 198-1": 10,
"FIPS 202": 5,
"FIPS PUB 140-3": 2,
"FIPS186-4": 2,
"FIPS186-5": 6
},
"ISO": {
"ISO/IEC 19790": 2,
"ISO/IEC 24759": 2
},
"NIST": {
"SP 800-38A": 7,
"SP 800-38B": 2,
"SP 800-38C": 2,
"SP 800-38D": 4,
"SP 800-38E": 3,
"SP 800-56A": 2,
"SP 800-90A": 3,
"SP 800-90B": 1
},
"PKCS": {
"PKCS 1": 1,
"PKCS#1": 11
},
"RFC": {
"RFC 4106": 3,
"RFC 7296": 1
}
},
"symmetric_crypto": {
"AES_competition": {
"AES": {
"AES": 25,
"AES-": 7,
"AES-128": 2,
"AES-192": 1,
"AES-256": 2
},
"CAST": {
"CAST": 175
}
},
"constructions": {
"MAC": {
"CMAC": 2,
"HMAC": 16
}
}
},
"tee_name": {
"AMD": {
"PSP": 3
},
"IBM": {
"SSC": 2
}
},
"tls_cipher_suite": {},
"vendor": {},
"vulnerability": {}
},
"module_algorithms": {
"_type": "Set",
"elements": [
"AES-CTRA7410",
"SHA-1A7415",
"AES-CBC-CS3A7410",
"RSA SigVer (FIPS186-5)A7403",
"Safe Primes Key GenerationA7403",
"SHA2-224A7415",
"SHA2-256A7415",
"SHA3-384A7403",
"HMAC-SHA-1A7415",
"AES-CCMA7410",
"AES-OFBA7410",
"SHA3-512A7403",
"RSA SigVer (FIPS186-4)A7403",
"AES-CBCA7410",
"AES-GMACA7410",
"SHA3-224A7403",
"HMAC-SHA3-256A7403",
"HMAC DRBGA7415",
"SHA2-512A7415",
"HMAC-SHA2-384A7415",
"HMAC-SHA3-224A7403",
"AES-CFB128A7410",
"Counter DRBGA7412",
"HMAC-SHA3-384A7403",
"Hash DRBGA7415",
"AES-ECBA7412",
"HMAC-SHA2-512A7415",
"KAS-FFC-SSC Sp800-56Ar3A7403",
"AES-XTS Testing Revision 2.0A7410",
"AES-CMACA7410",
"AES-GCMA7412",
"HMAC-SHA2-224A7415",
"HMAC-SHA3-512A7403",
"SHA2-384A7415",
"HMAC-SHA2-256A7415",
"SHA3-256A7403"
]
},
"policy_algorithms": {
"_type": "Set",
"elements": [
"#A7407",
"#A7412",
"#A7413",
"#A7403",
"#A7406",
"#A7408",
"#A7410",
"#A7405",
"#A7414",
"#A7409",
"#A7411",
"#A7415"
]
},
"policy_metadata": {
"/CreationDate": "D:20260727074900-04\u002700\u0027",
"/Creator": "Microsoft\u00ae Word for Microsoft 365",
"/ModDate": "D:20260727074900-04\u002700\u0027",
"/Producer": "Microsoft\u00ae Word for Microsoft 365",
"pdf_file_size_bytes": 702706,
"pdf_hyperlinks": {
"_type": "Set",
"elements": [
"https://doi.org/10.6028/NIST.SP.800-38B",
"https://doi.org/10.6028/NIST.SP.800-90B",
"https://doi.org/10.6028/NIST.SP.800-38D",
"https://doi.org/10.6028/NIST.SP.800-38A",
"https://doi.org/10.6028/NIST.FIPS.197-upd1",
"https://doi.org/10.6028/NIST.SP.800-140Br1",
"https://doi.org/10.6028/NIST.FIPS.198-1",
"https://doi.org/10.6028/NIST.FIPS.140-3",
"https://doi.org/10.6028/NIST.SP.800-133r2",
"https://doi.org/10.6028/NIST.FIPS.180-4",
"https://doi.org/10.6028/NIST.SP.800-38C",
"https://doi.org/10.6028/NIST.SP.800-56Ar3",
"https://doi.org/10.6028/NIST.SP.800-38A-Add",
"https://doi.org/10.6028/NIST.FIPS.202",
"https://doi.org/10.6028/NIST.SP.800-38E",
"https://doi.org/10.6028/NIST.FIPS.186-5",
"https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-4.pdf",
"https://doi.org/10.17487/RFC4106",
"https://doi.org/10.6028/NIST.SP.800-90Ar1",
"https://csrc.nist.gov/CSRC/media/Projects/cryptographic-module-validation-program/documents/fips%20140-3/FIPS%20140-3%20IG.pdf",
"https://doi.org/10.17487/RFC8017"
]
},
"pdf_is_encrypted": false,
"pdf_number_of_pages": 53
}
},
"state": {
"_type": "sec_certs.sample.fips.InternalState",
"module": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": null,
"source_hash": null,
"txt_hash": null
},
"policy": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": "e10dcfd8c93982a29b6c8d35b28ae20d8b30c16a7a4af8ed7e7c6228f2dff2fe",
"source_hash": "1ada63ec7d6b8a1fff86656e8dfe3163a388ba2ed7732777f36d3422376c04c7",
"txt_hash": "c81cd284cc43280a8947857f0fa8143ff24dcfff2705aa3083bb1627878d3123"
}
},
"web_data": {
"_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
"caveat": "When operated in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.",
"certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/July 2026_040826_0807.pdf",
"date_sunset": "2031-07-28",
"description": "The Rocky Linux 9 Kernel Cryptographic API provides a C language API for use by other (kernel space and user space) processes that require cryptographic functionality.",
"embodiment": "MultiChipStand",
"exceptions": [
"Physical security: N/A",
"Non-invasive security: N/A",
"Mitigation of other attacks: N/A"
],
"fw_versions": null,
"historical_reason": null,
"hw_versions": null,
"level": 1,
"mentioned_certs": {},
"module_name": "Rocky Linux 9 Kernel Cryptographic API",
"module_type": "Software",
"revoked_link": null,
"revoked_reason": null,
"standard": "FIPS 140-3",
"status": "active",
"sw_versions": null,
"tested_conf": null,
"validation_history": [
{
"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
"date": "2026-07-29",
"lab": "atsec information security corporation",
"validation_type": "Initial"
}
],
"vendor": "Ctrl IQ, Inc.",
"vendor_url": "https://ciq.com"
}
}