This page was not yet optimized for use on mobile devices.
Kasten BoringCrypto
Certificate #4353
Webpage information ?
Security policy ?
Symmetric Algorithms
AES, AES-256, DES, Triple-DES, TDEA, HMAC, HMAC-SHA-256, HMAC-SHA-384, HMAC-SHA-512, CMACAsymmetric Algorithms
ECDSA, ECC, DH, Diffie-HellmanHash functions
SHA-1, SHA-224, SHA-384, SHA-512, SHA-256, MD4, MD5Schemes
MAC, Key AgreementProtocols
TLS, TLS 1.0Randomness
DRBGLibraries
BoringSSLElliptic Curves
P-224, P-256, P-384, P-521Block cipher modes
ECB, CBC, CTR, CFB, OFB, GCMSecurity level
Level 1Standards
FIPS 140-2, FIPS 140, FIPS 197, FIPS 186-4, FIPS 198-1, FIPS 180-4, FIPS PUB 140-2, SP 800-38A, SP 800-38F, SP 800-38D, SP 800-133, SP 800-67, SP 800-135, NIST SP 800-133, NIST SP 800-90A, SP 800-90A, NIST SP 800-52, NIST SP 800-38D, NIST SP 800-131A, SP 800-56A, SP 800-52, RFC 5288, RFC 5246File metadata
Author | Matt Bator |
---|---|
Creation date | D:20221003134239+00'00' |
Modification date | D:20221003134239+00'00' |
Pages | 24 |
Creator | Microsoft Word |
Heuristics ?
No heuristics are available for this certificate.
References ?
No references are available for this certificate.
Updates ?
-
09.02.2023 The certificate data changed.
Certificate changed
The cert_id was updated.
- The new value is
4353
.
The web extraction data was updated.
- The following values were inserted:
{'validation_history': [{'_type': 'sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry', 'date': '2022-11-03', 'validation_type': 'Initial', 'lab': 'LEIDOS CSTL'}], 'vendor_url': 'http://www.kasten.io', 'certificate_pdf_url': 'https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/November 2022_051222_0640_signed.pdf', 'hw_versions': None, 'fw_versions': None}
. - The standard property was set to
FIPS 140-2
. - The status property was set to
active
. - The level property was set to
1
. - The embodiment property was set to
Multi-Chip Stand Alone
. - The following properties were deleted:
['date_validation', 'algorithms', 'vendor_www', 'lab', 'lab_nvlap', 'security_policy_www', 'certificate_www', 'hw_version', 'fw_version', 'product_url']
.
The PDF extraction data was updated.
- The following values were inserted:
{'policy_metadata': {'pdf_file_size_bytes': 412214, 'pdf_is_encrypted': False, 'pdf_number_of_pages': 24, '/Author': 'Matt Bator', '/Creator': 'Microsoft Word', '/CreationDate': "D:20221003134239+00'00'", '/ModDate': "D:20221003134239+00'00'", 'pdf_hyperlinks': {'_type': 'Set', 'elements': ['https://commondatastorage.googleapis.com/chromium-boringssl-fips/boringssl-ae223d6138807a13006342edfeef32e813246b39.tar.xz', 'http://csrc.nist.gov/groups/STM/cmvp/index.html']}}}
. - The following properties were deleted:
['cert_id', 'algorithms', 'clean_cert_ids', 'st_metadata']
.
The computed heuristics were updated.
- The following values were inserted:
{'policy_prunned_references': {'_type': 'Set', 'elements': []}, 'module_prunned_references': {'_type': 'Set', 'elements': []}, 'policy_processed_references': {'_type': 'sec_certs.sample.certificate.References', 'directly_referenced_by': None, 'indirectly_referenced_by': None, 'directly_referencing': None, 'indirectly_referencing': None}, 'module_processed_references': {'_type': 'sec_certs.sample.certificate.References', 'directly_referenced_by': None, 'indirectly_referenced_by': None, 'directly_referencing': None, 'indirectly_referencing': None}, 'direct_transitive_cves': None, 'indirect_transitive_cves': None}
. - The algorithms property was set to
{'_type': 'Set', 'elements': ['CVL#C1063', 'Triple-DES#C1063', 'SHS#C1063', 'DRBG#C1063', 'RSA#C1063', 'ECDSA#C1063', 'KTS#C1063', 'HMAC#C1063', 'AES#C1063']}
. - The following properties were deleted:
['keywords', 'unmatched_algs', 'clean_cert_ids', 'st_references', 'web_references']
.
The state was updated.
- The following values were inserted:
{'module_download_ok': True, 'policy_download_ok': True, 'policy_convert_garbage': False, 'policy_convert_ok': True, 'module_extract_ok': True, 'policy_extract_ok': True, 'policy_pdf_hash': '84cea49f6af0aed4adbe270ba96021a1539351f9f59cb02d7377416c08ec6ecf', 'policy_txt_hash': '82d7b842555e26926f44d69b0aa986be4d090e47f9fa808146dca025e0ac1636'}
. - The following properties were deleted:
['sp_path', 'html_path', 'tables_done', 'file_status', 'txt_state']
.
- The new value is
-
07.12.2022 The certificate data changed.
Certificate changed
The web extraction data was updated.
- The certificate_www property was set to
https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/November 2022_051222_0640_signed.pdf
.
- The certificate_www property was set to
-
05.11.2022 The certificate was first processed.
New certificate
A new FIPS 140 certificate with the product name was processed.
Raw data
{
"_type": "sec_certs.sample.fips.FIPSCertificate",
"cert_id": 4353,
"dgst": "f8feb05f30d18136",
"heuristics": {
"_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
"algorithms": {
"_type": "Set",
"elements": [
"RSA#C1063",
"SHS#C1063",
"AES#C1063",
"KTS#C1063",
"HMAC#C1063",
"ECDSA#C1063",
"DRBG#C1063",
"CVL#C1063",
"Triple-DES#C1063"
]
},
"cpe_matches": null,
"direct_transitive_cves": null,
"extracted_versions": {
"_type": "Set",
"elements": [
"-"
]
},
"indirect_transitive_cves": null,
"module_processed_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": null,
"indirectly_referenced_by": null,
"indirectly_referencing": null
},
"module_prunned_references": {
"_type": "Set",
"elements": []
},
"policy_processed_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": null,
"indirectly_referenced_by": null,
"indirectly_referencing": null
},
"policy_prunned_references": {
"_type": "Set",
"elements": []
},
"related_cves": null,
"verified_cpe_matches": null
},
"pdf_data": {
"_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
"keywords": {
"asymmetric_crypto": {
"ECC": {
"ECC": {
"ECC": 1
},
"ECDSA": {
"ECDSA": 18
}
},
"FF": {
"DH": {
"DH": 6,
"Diffie-Hellman": 3
}
}
},
"certification_process": {},
"cipher_mode": {
"CBC": {
"CBC": 3
},
"CFB": {
"CFB": 3
},
"CTR": {
"CTR": 2
},
"ECB": {
"ECB": 2
},
"GCM": {
"GCM": 4
},
"OFB": {
"OFB": 3
}
},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {
"BoringSSL": {
"BoringSSL": 3
}
},
"crypto_protocol": {
"TLS": {
"TLS": {
"TLS": 10,
"TLS 1.0": 1
}
}
},
"crypto_scheme": {
"KA": {
"Key Agreement": 3
},
"MAC": {
"MAC": 1
}
},
"device_model": {},
"ecc_curve": {
"NIST": {
"P-224": 4,
"P-256": 6,
"P-384": 4,
"P-521": 2
}
},
"eval_facility": {},
"fips_cert_id": {},
"fips_certlike": {
"Certlike": {
"AES-256": 1,
"HMAC-SHA-1": 4,
"HMAC-SHA-256": 2,
"HMAC-SHA-384": 2,
"HMAC-SHA-512": 4,
"HMACSHA- 224": 1,
"HMACSHA-512": 1,
"SHA- 256": 1,
"SHA-1": 2,
"SHA-224": 1,
"SHA-256": 2,
"SHA-384": 1,
"SHA-512": 2,
"SHA2-224": 1,
"SHA2-256": 1,
"SHA2-384": 1,
"SHA2-512": 1
}
},
"fips_security_level": {
"Level": {
"Level 1": 2
}
},
"hash_function": {
"MD": {
"MD4": {
"MD4": 2
},
"MD5": {
"MD5": 5
}
},
"SHA": {
"SHA1": {
"SHA-1": 2
},
"SHA2": {
"SHA-224": 1,
"SHA-256": 2,
"SHA-384": 1,
"SHA-512": 2
}
}
},
"ic_data_group": {},
"javacard_api_const": {},
"javacard_packages": {},
"javacard_version": {},
"os_name": {},
"pq_crypto": {},
"randomness": {
"PRNG": {
"DRBG": 8
}
},
"side_channel_analysis": {},
"standard_id": {
"FIPS": {
"FIPS 140": 4,
"FIPS 140-2": 20,
"FIPS 180-4": 2,
"FIPS 186-4": 3,
"FIPS 197": 2,
"FIPS 198-1": 2,
"FIPS PUB 140-2": 1
},
"NIST": {
"NIST SP 800-131A": 1,
"NIST SP 800-133": 1,
"NIST SP 800-38D": 1,
"NIST SP 800-52": 1,
"NIST SP 800-90A": 1,
"SP 800-133": 2,
"SP 800-135": 2,
"SP 800-38A": 2,
"SP 800-38D": 2,
"SP 800-38F": 3,
"SP 800-52": 1,
"SP 800-56A": 1,
"SP 800-67": 2,
"SP 800-90A": 2
},
"RFC": {
"RFC 5246": 2,
"RFC 5288": 1
}
},
"symmetric_crypto": {
"AES_competition": {
"AES": {
"AES": 17,
"AES-256": 1
}
},
"DES": {
"3DES": {
"TDEA": 1,
"Triple-DES": 15
},
"DES": {
"DES": 3
}
},
"constructions": {
"MAC": {
"CMAC": 1,
"HMAC": 6,
"HMAC-SHA-256": 1,
"HMAC-SHA-384": 1,
"HMAC-SHA-512": 2
}
}
},
"tee_name": {},
"tls_cipher_suite": {},
"vendor": {},
"vulnerability": {}
},
"policy_metadata": {
"/Author": "Matt Bator",
"/CreationDate": "D:20221003134239+00\u002700\u0027",
"/Creator": "Microsoft Word",
"/ModDate": "D:20221003134239+00\u002700\u0027",
"pdf_file_size_bytes": 412214,
"pdf_hyperlinks": {
"_type": "Set",
"elements": [
"http://csrc.nist.gov/groups/STM/cmvp/index.html",
"https://commondatastorage.googleapis.com/chromium-boringssl-fips/boringssl-ae223d6138807a13006342edfeef32e813246b39.tar.xz"
]
},
"pdf_is_encrypted": false,
"pdf_number_of_pages": 24
}
},
"state": {
"_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
"module_download_ok": true,
"module_extract_ok": true,
"policy_convert_garbage": false,
"policy_convert_ok": true,
"policy_download_ok": true,
"policy_extract_ok": true,
"policy_pdf_hash": "84cea49f6af0aed4adbe270ba96021a1539351f9f59cb02d7377416c08ec6ecf",
"policy_txt_hash": "82d7b842555e26926f44d69b0aa986be4d090e47f9fa808146dca025e0ac1636"
},
"web_data": {
"_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
"caveat": "When installed, initialized and configured as specified in Section 12.1 of the Security Policy and operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy",
"certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/November 2022_051222_0640_signed.pdf",
"date_sunset": "2025-07-12",
"description": "A software library that contains cryptographic functionality to serve BoringSSL and other user-space applications.",
"embodiment": "Multi-Chip Stand Alone",
"exceptions": [
"Physical Security: N/A",
"Mitigation of Other Attacks: N/A"
],
"fw_versions": null,
"historical_reason": null,
"hw_versions": null,
"level": 1,
"mentioned_certs": {},
"module_name": "Kasten BoringCrypto",
"module_type": "Software",
"revoked_link": null,
"revoked_reason": null,
"standard": "FIPS 140-2",
"status": "active",
"sw_versions": "ae223d6138807a13006342edfeef32e813246b39",
"tested_conf": [
"Debian Linux 4.19.37 (Rodete) running on an HPE Z620 with Intel Xeon E5-2680 without PAA",
"Debian Linux 4.19.37 (Rodete) running on HPE Z620 with Intel Xeon E5-2680 with PAA",
"Ubuntu Linux 18.04 running on a Google Arcadia-Rome with AMD Rome with PAA",
"Ubuntu Linux 18.04 running on a Google Arcadia-Rome with AMD Rome without PAA",
"Ubuntu Linux 18.04 running on a Zaius P9 with POWER9 with PAA",
"Ubuntu Linux 18.04 running on a Zaius P9 with POWER9 without PAA (single-user mode)"
],
"validation_history": [
{
"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
"date": "2022-11-03",
"lab": "LEIDOS CSTL",
"validation_type": "Initial"
}
],
"vendor": "Kasten, Inc.",
"vendor_url": "http://www.kasten.io"
}
}