1 Brocade® DCX, DCX 8510-8, DCX-4S and DCX 8510-4 Backbones, 6510 and 6520 FC Switches, and 7800 Extension Switch FIPS 140-2 Non-Proprietary Security Policy Document Version 1.0 Brocade Communications Systems, Inc. January 20, 2017 Copyright Brocade Communications Systems, Inc. 2017. May be reproduced only in its original entirety [without revision]. 2 Document History Version Publication Date Summary of Changes 1.0 January 20, 2017 Initial Release 3 Table of Contents 1 Module Overview ................................................................................................................................................. 7 1.1 Brocade 6510 FC Switch .................................................................................................................................... 8 1.2 Brocade 6520 FC Switch .................................................................................................................................... 9 1.3 Brocade 7800 Extension Switch ......................................................................................................................10 1.4 Brocade DCX-4S, DCX 8510-4, DCX and DCX 8510-8 Backbones.................................................................11 1.4.1 Validated modules................................................................................................................................................................ 15 2 Security Level.....................................................................................................................................................17 3 Modes of Operation...........................................................................................................................................18 3.1 Approved mode of operation.............................................................................................................................18 3.1.1 Algorithm certificates............................................................................................................................................................ 18 3.1.1.1 Brocade 6510 and Brocade 7800.........................................................................................................18 3.1.1.2 Brocade 6520 and Brocade DCX Control Processor (CP) blade ..........................................................20 3.1.2 Invoking FIPS Approved mode ............................................................................................................................................. 22 3.2 Non-Approved mode of operation .....................................................................................................................24 4 Ports and Interfaces..........................................................................................................................................26 4.1 LED Indicators....................................................................................................................................................26 5 Identification and Authentication Policy............................................................................................................28 5.1 Assumption of Roles..........................................................................................................................................28 6 Access Control Policy .........................................................................................................................................31 6.1 Roles and Services ............................................................................................................................................31 6.2 Unauthenticated Services .................................................................................................................................31 6.3 Definition of Critical Security Parameters (CSPs).............................................................................................32 6.4 Definition of Public Keys ...................................................................................................................................33 6.5 Definition of CSPs Modes of Access .................................................................................................................33 7 OperationalEnvironment...................................................................................................................................35 8 Security Rules ....................................................................................................................................................35 9 Physical Security Policy......................................................................................................................................37 9.1 Physical Security Mechanisms..........................................................................................................................37 9.2 Operator Required Actions ................................................................................................................................37 10 Mitigation of Other Attacks Policy.....................................................................................................................38 11 Definitions and Acronyms .................................................................................................................................39 12 Brocade Abbreviations ......................................................................................................................................40 13 Appendix A: Tamper Label Application..............................................................................................................41 13.1 Brocade DCX and DCX 8510-8 Backbone........................................................................................................41 4 13.2 Brocade DCX-4S and DCX 8510-4 Backbone ..................................................................................................45 13.3 Brocade 6510 FC Switch ..................................................................................................................................48 13.4 Brocade 6520 FC Switch ..................................................................................................................................50 13.5 Brocade 7800 Extension Switch.......................................................................................................................54 14 Appendix B: Block Diagram...............................................................................................................................56 15 Appendix C: Critical Security Parameters and Public Keys .............................................................................57 5 Table of Tables Table 1 - Firmware Version ................................................................................................................................................... 7 Table 2 – Brocade 6510 FC Switches (Validated 6510 Configurations)...........................................................................8 Table 3 - Brocade 6510 FC Switch Supported Power Supplies and Fan Assemblies .......................................................8 Table 4 - Brocade 6510 FC Switch Software Licenses .......................................................................................................8 Table 5 – Brocade 6520 FC Switches (Validated Brocade 6520 Configurations) ............................................................9 Table 6- Brocade 6520 FC Switch Supported Power Supplies...........................................................................................9 Table 7 - Brocade 6520 FC Switch Supported Fan Assemblies .........................................................................................9 Table 8 - Brocade 6520 FC Switch Software Licenses .......................................................................................................9 Table 9 – Brocade 7800 Extension Switch (Validated Brocade 7800 Configurations) ..................................................10 Table 10 – Brocade 7800 Upgrade Packages (software licenses and optics)................................................................10 Table 11 - Backbone Models..............................................................................................................................................11 Table 12 - Supported Blades..............................................................................................................................................12 Table 13 - Validated DCX Configurations...........................................................................................................................15 Table 14 - Validated DCX-4S Configurations .....................................................................................................................15 Table 15 - Validated DCX 8510-4 Configurations .............................................................................................................16 Table 16 - Validated DCX 8510-8 Configurations .............................................................................................................16 Table 17 - Module Security Level Specification.................................................................................................................17 Table 18 - Approved Algorithms available in firmware on Brocade 6510 and Brocade 7800.......................................19 Table 19 - Approved Algorithms available in firmware on Brocade 6520 and DCX Control Processor (CP) blade........21 Table 20 - Services in Non-Approved Mode of Operation .................................................................................................25 Table 21 - Port/Interface Quantities ..................................................................................................................................27 Table 22 - DCX-4S, DCX, DCX 8510-4, and DCX 8510-8 blade LED counts....................................................................27 Table 23 - Roles and Required Identification and Authentication....................................................................................28 Table 24 - Strengths of Authentication Mechanisms........................................................................................................29 Table 25 - Service Descriptions..........................................................................................................................................30 Table 26 - Services Authorized for Roles ...........................................................................................................................31 Table 27 - CSP Access Rights within Roles & Services .....................................................................................................34 Table 28 - Public Key Access Rights within Roles & Services...........................................................................................34 Table 29 - Inspection/Testing of Physical Security Mechanisms .....................................................................................37 Table 30 - Mitigation of Other Attacks ...............................................................................................................................38 6 Table of Figures Figure 1 - Brocade 6510 FC Switch ..................................................................................................................................... 8 Figure 2 - Brocade 6520....................................................................................................................................................... 9 Figure 3 - Brocade 7800.....................................................................................................................................................10 Figure 4 - DCX-4S and DCX .................................................................................................................................................13 Figure 5 - DCX 8510-4 and DCX 8510-8............................................................................................................................14 Figure 6 - Brocade DCX and DCX 8510-8 Backbone chassis right side seal location.....................................................41 Figure 7 - Brocade DCX and DCX 8510-8 Backbone front side seal locations................................................................42 Figure 8 - Brocade DCX and DCX 8510-8 Backbone back side seal locations................................................................43 Figure 9 - Brocade DCX and DCX 8510-8 Backbone flat ejector handle seal application on the port side...................43 Figure 10 - Brocade DCX and DCX 8510-8 Backbone stainless steel handle seal application on the port side ..........44 Figure 11 - Brocade DCX and DCX 8510-8 Backbone filler panel seal application on the port side .............................44 Figure 12 - Brocade DCX-4S and DCX 8510-4 Backbone front side seal locations........................................................45 Figure 13 - Brocade DCX-4S and DCX 8510-4 Backbone back side seal locations........................................................46 Figure 14 - Brocade DCX-4S and DCX 8510-4 Backbone flat ejector handle seal application......................................46 Figure 15 - Brocade DCX-4S and DCX 8510-4 Backbone stainless steel ejector handle seal application....................46 Figure 16 - Brocade DCX-4S and DCX 8510-4 Backbone filler panel (PN 49-1000294-05) seal application ..............47 Figure 17 - Brocade DCX-4S Backbone filler panel (PN 49-1000064-02) seal application...........................................47 Figure 18 - Brocade 6510 left side seal application.........................................................................................................48 Figure 19 - Brocade 6510 right side seal application.......................................................................................................48 Figure 20 - Brocade 6510 bottom seal locations..............................................................................................................49 Figure 21 - Brocade 6520 left side seal locations ............................................................................................................50 Figure 22 - Brocade 6520 right side seal locations..........................................................................................................51 Figure 23 - Brocade 6520 top and non-port side seal locations......................................................................................52 Figure 24 - Brocade 6520 bottom side seal locations......................................................................................................53 Figure 25 - Brocade 7800 left side seal locations ............................................................................................................54 Figure 26 - Brocade 7800 right side seal locations..........................................................................................................54 Figure 27 - Brocade 7800 bottom seal locations..............................................................................................................55 Figure 28 - Block Diagram ..................................................................................................................................................56 7 1 Module Overview The Brocade 6510, 6520, 7800, DCX, DCX 8510-8, DCX-4S and DCX 8510-4 are multiple-chip standalone cryptographic modules, as defined by FIPS 140-2. The cryptographic boundary for DCX, DCX 8510-8, DCX-4S and DCX 8510-4 backbone is the outer perimeter of the metal chassis including the removable cover, control processor blades, core switch blades, and port blades or filler panels. The cryptographic boundary of the 6510 FC Switch, 6520 FC Switch, and 7800 is the outer perimeter of the metal chassis including the removable cover. The module is a Fiber Channel and/or Gigabit Ethernet routing switch that provides secure network services and network management. For each module to operate in a FIPS approved mode of operation, the tamper evident seals supplied in FIPS Kit P/N Brocade XBR-000195 must be installed as defined in Appendix A. The Crypto-Officer is responsible for storing and controlling the inventory of any unused seals. The unused seals shall be stored in plastic bags in a cool, dry environment between 60° and 70° F (15° to 20° C) and less than 50% relative humidity. Rolls should be stored flat on a slit edge or suspended by the core. The Crypto-Officer shall maintain a serial number inventory of all used and unused tamper evident seals. The Crypto-Officer shall periodically monitor the state of all applied seals for evidence of tampering. A seal serial number mismatch, a seal placement change, a checkerboard destruct pattern that appears in peeled film and adhesive residue on the substrate are evidence of tampering. The Crypto-Officer shall periodically view each applied seal under a UV light to verify the presence of a UV wallpaper pattern. The lack of a wallpaper pattern is evidence of tampering. The Crypto-Officer is responsible for returning a module to a FIPS approved state after any intentional or unintentional reconfiguration of the physical security measures. A validated module configuration is comprised of Fabric OS v7.4.0 (P/N: 51-1001672-01) installed on, a switch or backbone and a set of installed blades. The below platforms may be used in a validated module configuration: Firmware Fabric OS v7.4.0 Table 1 - Firmware Version REST OF THIS PAGE was intentionally left blank. Next page  8 1.1 Brocade 6510 FC Switch Figure below illustrates the Brocade 6510 FC Switch cryptographic module. Figure 1 - Brocade 6510 FC Switch Switch SKU Part Number Brief Description Brocade 6510 BR-6510-48-16G-R 80-1005272-03 Brocade 6510, 48 ports 16G configuration (minimal 24 ports + 24-port POD licenses) with port2 side air flow - Forty-eight (48) ports are enabled: Factory installed, two licenses BR-MIDR12POD-01 to enable 24 additional ports - Quantity of 48, 16GB SFPs - Quantity of 2 Power Supply and Fan Assembly (XBR-5100-0001) Table 2 – Brocade 6510 FC Switches (Validated 6510 Configurations) Table below lists power supply and fan assemblies supported on Brocade 6510 FC Switches: SKU Part Number Description XBR-5100-0001 80-1001304-02 Brocade 5100 Power Supply/Fan FRU, Port-side exhaust airflow Table 3 - Brocade 6510 FC Switch Supported Power Supplies and Fan Assemblies Table below lists software licenses supported on Brocade 6510 FC Switches: SKU Part Number Description BR-MIDR12POD-01 80-1005356-02 Software, POD license, 12 Port On-Demand internal support part Table 4 - Brocade 6510 FC Switch Software Licenses REST OF THIS PAGE was intentionally left blank. Next page  9 1.2 Brocade 6520 FC Switch Figure below illustrates the Brocade 6520 cryptographic module. Figure 2 - Brocade 6520 Switch SKU / Part Number Brief Description Brocade 6520 BR-6520-96-16G-R / 80-1007257-03 Brocade 6520, 96 ports 16G configuration (minimal 48 ports + 48-port POD license) with port side air flow - Forty-eight additional ports are enabled by software POD license SW-ENTPOD2-01. - Quantity of 96, 16GB, Short Wavelength (SWL) SFPs - Quantity of three fan FRUs (XBR-FAN-80-R) and - Quantity of two 1100W AC power supplies (XBR-1100WPSAC-R) Table 5 – Brocade 6520 FC Switches (Validated Brocade 6520 Configurations) Table below lists power supplies supported on Brocade 6520 FC Switches: SKU Part Number Brief Description XBR-1100WPSAC-R 80-1007263-01 FRU 1100W AC Power Supply, Port side exhaust airflow Table 6- Brocade 6520 FC Switch Supported Power Supplies Table below lists fan assemblies supported on Brocade 6520 FC Switches: SKU Part Number Brief Description XBR-FAN-80-R 80-1004580-02 Fan FRU, 80MM, Port side exhaust airflow Table 7 - Brocade 6520 FC Switch Supported Fan Assemblies Table below lists software licenses supported on Brocade 6520 FC Switches: SKU Part Number Brief Description SW-ENTPOD2-01 80-1007272-01 Software, Port On Demand, enable forty-eight (48) ports Table 8 - Brocade 6520 FC Switch Software Licenses REST OF THIS PAGE was intentionally left blank. Next page  10 1.3 Brocade 7800 Extension Switch Figure below illustrates the Brocade 7800 cryptographic module. Figure 3 - Brocade 7800 Switch SKU Part Number Brief Description Brocade 7800 BR-7800F-0001 80-1006977-02 Brocade 7800, 22 ports 16G configuration (baseline + 16 ports Upgrade License; with upgrade package XBR-7800UG-0001) - SW-7800UG-01 licenses - Provides 22 ports, - Quantity of 16, Fiber Channel optical ports, and - Quantity of 6, 1Gbps Ethernet ports - Quantity of 16, 8GB Short Wavelength (SWL) SFPs Table 9 – Brocade 7800 Extension Switch (Validated Brocade 7800 Configurations) Table below lists upgrade packages for Brocade 7800 Extension Switch. These upgrade packages include software licenses and optics supported on Brocade 7800 Extension Switch: SKU Part Number Brief Description XBR-7800UG-0001 80-1002820-02 Software, 7800 upgrade package: - This upgrade package includes POD software license and optics components Software POD license component: - All total 16 (4 + 12) Fiber Channel optical ports are enabled - POD license enables 12 additional ports - Base unit of this device comes with 4 minimal ports enabled - Also, all total 6 (2 + 4) 1GbE Ethernet ports are enabled - POD license enables 4 additional ports - Base unit of this device comes with 2 minimal ports enabled Optics components: - This package will also include twelve 8GB Short Wavelength SFP optics Table 10 – Brocade 7800 Upgrade Packages (software licenses and optics) REST OF THIS PAGE was intentionally left blank. 11 1.4 Brocade DCX-4S, DCX 8510-4, DCX and DCX 8510-8 Backbones Brocade DCX-4S, DCX 8510-4, DCX and DCX 8510-8 refer to four distinct 8 Gbps and 16 Gbps core Fiber Channel switch configurations. These configurations are based on selected chassis, a common Control Processor blade, four different (8 Gbps and 16 Gbps) Core blades; a selection of 8/16 Gbps FC port blades and an optional FC extender blade. Backbone models are described in the table below: Backbone SKU Part Number Brief Description Brocade DCX BR-DCX-00021 80-1006752-01 Brocade DCX configuration, 2 Power Supplies, 0 Ports, 2 Control Processor blades (CP8), 2 Core blades (CR8), 0 SFPs, Enterprise Bundle2, 2 WWN Brocade DCX-4S BR-DCX4S-00021 80-1006772-01 Brocade DCX-4S configuration, 2 Power Supplies, 0 Port, 2 Control Processor blades (CP8), 2 Core blades (CR4S-8), 0 SFPs, BR, Enterprise Bundle2 Brocade DCX 8510-4 BR-DCX8514-00021 80-1006964-01 Brocade DCX8510-4 configuration, 2 Power Supplies, 0 Ports, 2 Control Processor blades, 2 16G Core blades, 0 SFPs, Enterprise Bundle2 Brocade DCX 8510-8 BR-DCX8518-00011 80-1007025-01 Brocade DCX8510-8 configuration, 2 Power Supplies, 0 Ports, 2 Control Processor blades (CP8), 2 16GB Core blades (CR16-8), 0 SFPs, Enterprise Bundle2 Table 11 - Backbone Models Notes for table above: 1. SKU refers to a bundled / combined package which include chassis and minimal required line cards / blades. 2. Enterprise Software License Bundle: Adaptive Networking, Extended Fabrics, Advance Performance Monitoring, Trunking, Fabric Watch, Server Application Optimized. REST OF THIS PAGE was intentionally left blank. Next page  12 The blades listed below may be used in backbone-based validated module configurations: Blade Acronym Part Number Brief Description CP8 Control Processor Blade CP8 80-1006794-01 FRU, Control Processor blade for DCX product (for DCX, DCX-4S, DCX8510-4 and DCX8510-8) CR16-4 Core Switch Blade CR16-4 80-1004897-01 FRU, Core blade for DCX8510-4 CR16-8 Core Switch Blade CR16-8 80-1004898-01 FRU, Core blade for DCX8510-8 CR4S-8 Core Switch Blade CR4S-8 80-1006771-01 FRU, Core blade for DCX-4S CR8 Core Switch Blade CR8 80-1006750-01 FRU, Core blade for DCX FC16-32 Port Blade FC16-32 80-1005166-02 FRU, Port blade with 32 FC Ports for DCX8510-4 or DCX-8510-8 configurations, with 16G SFP FC16-48 Port Blade FC16-48 80-1005187-02 FRU, Port blade with 48 FC Ports for DCX8510-4 or DCX-8510-8 configurations, with 16G SFP FC8-16 Port Blade FC8-16 80-1006936-01 FRU, Port blade with 16 FC Ports for DCX or DCX-4S configurations, with 8G SFP FC8-32 Port Blade FC8-32 80-1006779-01 FRU, PORT BLADE, 32 FC Ports for DCX or DCX-4S configurations, with 8G SFP FC8-48 Port Blade FC8-48 80-1006823-01 FRU, PORT BLADE, 48 FC Ports for DCX or DCX-4S configurations, with 8G SFP FC8-64 Port Blade FC8-64 80-1007000-01 FRU, PORT BLADE, 64 Ports for DCX or DCX-4S configurations, with 8G SFP FX8-24 Port Blade FX8-24 80-1007017-01 FRU, Extender blade, 8G X 12 Ports, 10x1GBE, 2X10GBE DCX/DCX 8510-8 Filler Panel DCX/DCX 8510-8 Filler Panel 49-1000016-04 Filler Panel (for DCX and DCX8510-8) DCX-4S Backbone Filler Panel DCX-4S Filler Panel 49-1000064-02 Filler Panel (for DCX-4S) DCX-4S/DCX 8510-4 Filler Panel DCX-4S/DCX 8510-4 Filler Panel 49-1000294-05 Filler Panel (for DCX-4S and DCX8510-4) Table 12 - Supported Blades REST OF THIS PAGE was intentionally left blank. Next page  13 Figure 4, illustrates representative configurations of the DCX-4S (left image) and DCX (right image) cryptographic modules. These are not the only possible configurations. Other possible configurations can be created by utilizing other compatible blades as listed in Table 12. Figure 4 - DCX-4S and DCX REST OF THIS PAGE was intentionally left blank. Next page  14 Figure 5 illustrates representative configurations of the DCX 8510-4 (left image) and DCX 8510-8 (right image) cryptographic modules. These are not the only possible configurations. Other possible configurations can be created by utilizing other compatible blades as listed in Table 12. Figure 5 - DCX 8510-4 and DCX 8510-8 REST OF THIS PAGE was intentionally left blank. Next page  15 1.4.1 Validated modules Validated DCX configurations are listed below. Configuration Reference SKU / Part Number Quantity Description DCX (Configuration) BR-DCX-0002 / 80-1006752-01 1 Brocade DCX chassis which includes: - Quantity of 2 Power Supplies (SKU=DCX, DCX-4S + 8510 2000W POWER SUPPLY, P/N=80-1001273-03) - Quantity of 2 Control Processor blades (SKU=CP8, P/N=80-1006794-01) - Quantity of 2 Core blades (SKU=CR8, P/N=80-1006750-01) FC8-32 / 80-1006779-01 1 FC8-32 Port Blade Table 13 - Validated DCX Configurations Validated DCX-4S configurations are listed below. Configuration Reference SKU / Part Number Quantity Description DCX-4S (Configuration 1) BR-DCX4S-0002 / 80-1006772-01 1 Brocade DCX-4S chassis which includes: - Quantity of 2 Power Supplies (SKU=DCX, DCX-4S + 8510 2000W POWER SUPPLY, P/N=80-1001273-03) - Quantity of 2 Control Processor blades (SKU=CP8, P/N=80-1006794-01) - Quantity of 2 Core blades (SKU=CR4S-8, P/N=80-1006771-01) FC8-32 / 80-1006779-01 1 FC8-32 Port Blade FC8-48 / 80-1006823-01 1 FC8-48 Port Blade DCX-4S (Configuration 2) BR-DCX4S-0002 / 80-1006772-01 1 Brocade DCX-4S chassis which includes: - Quantity of 2 Power Supplies (SKU=DCX, DCX-4S + 8510 2000W POWER SUPPLY, P/N=80-1001273-03) - Quantity of 2 Control Processor blades (SKU=CP8, P/N=80-1006794-01) - Quantity of 2 Core blades (SKU=CR4S-8, P/N=80-1006771-01) FC8-16 / 80-1006936-01 1 FC8-16 Port Blade FC8-48 / 80-1006823-01 1 FC8-48 Port Blade Table 14 - Validated DCX-4S Configurations REST OF THIS PAGE was intentionally left blank. Next page  16 Validated DCX 8510-4 configurations are listed below. Configuration Reference SKU / Part Number Quantity Description DCX 8510-4 (Configuration 1) BR-DCX8514-0002 / 80-1006964-01 1 Brocade DCX chassis which includes: - Quantity of 2 Power Supplies (SKU=DCX, DCX-4S + 8510 2000W POWER SUPPLY, P/N=80-1001273-03) - Quantity of 2 Control Processor blades (SKU=CP8, P/N=80-1006794-01) - Quantity of 2 Core blades (SKU=CR16-4, P/N=80-1004897-01) FC16-48 / 80-1005187-02 1 FC16-48 Port Blade FC8-64 / 80-1007000-01 1 FC8-64 Port Blade Table 15 - Validated DCX 8510-4 Configurations Validated DCX 8510-8 configurations are listed below. Configuration Reference SKU / Part Number Quantity Description DCX 8510-8 (Configuration) BR-DCX8518-0001 / 80-1007025-01 1 Brocade DCX chassis which includes: - Quantity of 2 Power Supplies (SKU=DCX, DCX-4S + 8510 2000W POWER SUPPLY, P/N=80-1001273-03) - Quantity of 2 Control Processor blades (SKU=CP8, P/N=80-1006794-01) - Quantity of 2 Core blades (SKU=CR16-8, P/N=80-1004898-01) FC16-32 / 80-1005166-02 1 FC16-32 Port Blade FX8-24 / 80-1007017-01 1 Extender blade Table 16 - Validated DCX 8510-8 Configurations REST OF THIS PAGE was intentionally left blank. Next page  17 2 Security Level The cryptographic module meets the overall requirements applicable to Level 2 security of FIPS 140-2. Security R e qu i r em en t s Sec t i on Level CryptographicModuleSpecification 2 Module Ports and Interfaces 2 Roles, Services and Authentication 2 Finite State Model 2 PhysicalSecurity 2 Operational Environment NA Cryptographic Key Management 2 EMI/EMC 2 Self-Tests 2 DesignAssurance 2 Mitigation of Other Attacks NA Table 17 - Module Security Level Specification REST OF THIS PAGE was intentionally left blank. Next page  18 3 Modes of Operation 3.1 Approved mode of operation 3.1.1 Algorithm certificates 3.1.1.1 Brocade 6510 and Brocade 7800 Approved Algorithm Description Certificate Number AES Note: AES-ECB mode is latent functionality i.e. not used in FIPS Approved mode of operation. It is used in non- Approved FIPS mode. ECB ( e/d; 128 , 192 , 256 ); CBC ( e/d; 128 , 192 , 256 ); 2876 CVL ECC CDH Primitive (key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength) Curves tested: P-256 P-384 P-521 311 CVL TLS v1.0/1.1 and v1.2 KDF NOTE: SSL “is not” supported in FIPS mode. TLS( TLS1.0/1.1 TLS1.2 (SHA 256 , 384 ) ) 312 CVL SSHv2 KDF SSH (SHA 1 , 224 , 256 , 384 , 512) 312 DRBG SP800-90A CTR_DRBG (AES-256-CTR) CTR_DRBG: [ Prediction Resistance Tested: Enabled; BlockCipher_Use_df: ( AES-256 ) 670 ECDSA NOTE: P-384 and P-521 are latent functionality i.e. not available in any services in FIPS mode or non-FIPS mode P-256 FIPS186-4: PKG: CURVES(P-256 P-384 P-521 TestingCandidates ) PKV: CURVES( P-256 P-384 P-521 ) SigGen: CURVES( P-256: (SHA-256, 384, 512) SigVer: CURVES( P-256: (SHA-256, 384, 512) ) 942 HMAC NOTE: HMAC-SHA224 and HMAC-SHA512 are latent functionality, i.e. not available and not used in any services in FIPS mode or non-FIPS modes. HMAC-SHA-1, 224, 256, 384, 512 (160-bit key) HMAC-SHA1 (Key Sizes Ranges Tested: KS