All modules
CMVP Validated Module · FIPS 140-3 Security Policy

SUSE Linux Enterprise Libgcrypt Cryptographic Module

Certificate#4722StandardFIPS 140-3Level1TypeSoftwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorSUSE, LLC
Medium review priority  ·  no TCB surface named  ·  libgcrypt upstream has published 2 CVEs since this module's initial validation  ·  last validated 24 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date7/10/2029
CaveatInterim validation. When operated in approved mode. When installed, initialized and configured as specified in Section 11 of the Security Policy
VendorSUSE, LLC

Approved Algorithms (178)

AlgorithmACVP Cert
AES-CBCA3022
AES-CBCA3023
AES-CBCA3025
AES-CBCA3026
AES-CCMA3022
AES-CCMA3023
AES-CCMA3025
AES-CCMA3026
AES-CFB128A3022
AES-CFB128A3023
AES-CFB128A3025
AES-CFB128A3026
AES-CFB8A3022
AES-CFB8A3023
AES-CFB8A3025
AES-CFB8A3026
AES-CMACA3022
AES-CMACA3023
AES-CMACA3025
AES-CMACA3026
AES-CTRA3022
AES-CTRA3023
AES-CTRA3025
AES-CTRA3026
AES-ECBA3022
AES-ECBA3023
AES-ECBA3025
AES-ECBA3026
AES-KWA3022
AES-KWA3023
AES-KWA3025
AES-KWA3026
AES-OFBA3022
AES-OFBA3023
AES-OFBA3025
AES-OFBA3026
AES-XTS Testing Revision 2.0A3022
AES-XTS Testing Revision 2.0A3023
AES-XTS Testing Revision 2.0A3025
AES-XTS Testing Revision 2.0A3026
Counter DRBGA3022
Counter DRBGA3023
Counter DRBGA3025
Counter DRBGA3026
ECDSA KeyGen (FIPS186-4)A3022
ECDSA KeyGen (FIPS186-4)A3023
ECDSA KeyGen (FIPS186-4)A3024
ECDSA KeyGen (FIPS186-4)A3025
ECDSA KeyGen (FIPS186-4)A3026
ECDSA KeyVer (FIPS186-4)A3022
ECDSA KeyVer (FIPS186-4)A3023
ECDSA KeyVer (FIPS186-4)A3024
ECDSA KeyVer (FIPS186-4)A3025
ECDSA KeyVer (FIPS186-4)A3026
ECDSA SigGen (FIPS186-4)A3022
ECDSA SigGen (FIPS186-4)A3023
ECDSA SigGen (FIPS186-4)A3024
ECDSA SigGen (FIPS186-4)A3025
ECDSA SigGen (FIPS186-4)A3026
ECDSA SigVer (FIPS186-4)A3022
ECDSA SigVer (FIPS186-4)A3023
ECDSA SigVer (FIPS186-4)A3024
ECDSA SigVer (FIPS186-4)A3025
ECDSA SigVer (FIPS186-4)A3026
Hash DRBGA3022
Hash DRBGA3023
Hash DRBGA3024
Hash DRBGA3025
Hash DRBGA3026
HMAC DRBGA3022
HMAC DRBGA3023
HMAC DRBGA3024
HMAC DRBGA3025
HMAC DRBGA3026
HMAC-SHA-1A3021
HMAC-SHA-1A3022
HMAC-SHA-1A3023
HMAC-SHA-1A3024
HMAC-SHA-1A3025
HMAC-SHA-1A3026
HMAC-SHA-1A3027
HMAC-SHA2-224A3022
HMAC-SHA2-224A3023
HMAC-SHA2-224A3024
HMAC-SHA2-224A3025
HMAC-SHA2-224A3026
HMAC-SHA2-256A3022
HMAC-SHA2-256A3023
HMAC-SHA2-256A3024
HMAC-SHA2-256A3025
HMAC-SHA2-256A3026
HMAC-SHA2-384A3022
HMAC-SHA2-384A3023
HMAC-SHA2-384A3024
HMAC-SHA2-384A3025
HMAC-SHA2-384A3026
HMAC-SHA2-512A3022
HMAC-SHA2-512A3023
HMAC-SHA2-512A3024
HMAC-SHA2-512A3025
HMAC-SHA2-512A3026
HMAC-SHA3-224A3024
HMAC-SHA3-224A3025
HMAC-SHA3-224A3026
HMAC-SHA3-256A3024
HMAC-SHA3-256A3025
HMAC-SHA3-256A3026
HMAC-SHA3-384A3024
HMAC-SHA3-384A3025
HMAC-SHA3-384A3026
HMAC-SHA3-512A3024
HMAC-SHA3-512A3025
HMAC-SHA3-512A3026
PBKDFA3022
PBKDFA3023
PBKDFA3024
PBKDFA3025
PBKDFA3026
RSA KeyGen (FIPS186-4)A3022
RSA KeyGen (FIPS186-4)A3023
RSA KeyGen (FIPS186-4)A3024
RSA KeyGen (FIPS186-4)A3025
RSA KeyGen (FIPS186-4)A3026
RSA SigGen (FIPS186-4)A3022
RSA SigGen (FIPS186-4)A3023
RSA SigGen (FIPS186-4)A3024
RSA SigGen (FIPS186-4)A3025
RSA SigGen (FIPS186-4)A3026
RSA SigVer (FIPS186-4)A3022
RSA SigVer (FIPS186-4)A3023
RSA SigVer (FIPS186-4)A3024
RSA SigVer (FIPS186-4)A3025
RSA SigVer (FIPS186-4)A3026
SHA-1A3021
SHA-1A3022
SHA-1A3023
SHA-1A3024
SHA-1A3025
SHA-1A3026
SHA-1A3027
SHA2-224A3022
SHA2-224A3023
SHA2-224A3024
SHA2-224A3025
SHA2-224A3026
SHA2-256A3022
SHA2-256A3023
SHA2-256A3024
SHA2-256A3025
SHA2-256A3026
SHA2-384A3022
SHA2-384A3023
SHA2-384A3024
SHA2-384A3025
SHA2-384A3026
SHA2-512A3022
SHA2-512A3023
SHA2-512A3024
SHA2-512A3025
SHA2-512A3026
SHA3-224A3024
SHA3-224A3025
SHA3-224A3026
SHA3-256A3024
SHA3-256A3025
SHA3-256A3026
SHA3-384A3024
SHA3-384A3025
SHA3-384A3026
SHA3-512A3024
SHA3-512A3025
SHA3-512A3026
SHAKE-128A3024
SHAKE-128A3025
SHAKE-128A3026
SHAKE-256A3024
SHAKE-256A3025
SHAKE-256A3026

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for SUSE Linux Enterprise Libgcrypt Cryptographic Module
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>update</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>Status Output<br/>Show status</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>HTTPS<br/>no library/version identified</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for SUSE Linux Enterprise Libgcrypt Cryptographic Module
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>update</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>Status Output<br/>Show status</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>HTTPS<br/>no library/version identified</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

SUSE Linux Enterprise Libgcrypt Cryptographic Module version 3.2 Version 1.1 Last update: 2024-06-19 Prepared by: atsec information security corporation

4516 Seton Center Parkway, Suite 250

Austin, TX 78759 www.atsec.com © 2024 SUSE, LLC / atsec information security corporation.

Page 2
Table of Contents
#SectionPage
Page 3
ISO/IEC 24759 Section 6. [Number Below]FIPS 140-3 Section TitleSecurity Level
1General1
2Cryptographic Module Specification1
3Cryptographic Module Interfaces1
4Roles, Services, and Authentication1
5Software/Firmware Security1
6Operational Environment1
7Physical SecurityN/A
8Non-invasive SecurityN/A
9Sensitive Security Parameter Management1
10Self-tests1
11Life-cycle Assurance1
12Mitigation of Other Attacks1

This document is the non-proprietary FIPS 140-3 Security Policy for version 3.2 of the SUSE Linux Enterprise Libgcrypt Cryptographic Module. It has a one-to-one mapping to the [SP 800-140B] starting with section B.2.1 named “General” that maps to section 1 in this document and ending with section B.2.12 named “Mitigation of other attacks” that maps to section 12 in this document. Table 1 - Security Levels © 2024 SUSE, LLC / atsec information security corporation.

3 of 38

Page 4
ComponentsDescription
libgcrypt.so.20.3.4Shared library for cryptographic algorithms.
.libgcrypt.so.20.hmacIntegrity check HMAC value for the libgcrypt shared library.
2 Cryptographic Module Specification
2.1 Module Embodiment

The SUSE Linux Enterprise Libgcrypt Cryptographic Module (hereafter referred to as “the module”) is a Software multi-chip standalone cryptographic module.

2.2 Module Design, Components, Versions

The software block diagram below shows the cryptographic boundary of the module, and its interfaces with the operational environment. Figure 1

4 of 38

Page 5
#Operating SystemHardware PlatformProcessorPAA/Acceleration
1SUSE Linux Enterprise Server 15 SP4Supermicro Super Server SYS-6019P-WTRIntel® Xeon® Silver 4215RWith and without AES-NI (PAA)
2SUSE Linux Enterprise Server 15 SP4GIGABYTE R181-Z90-00AMD EPYCÔ 7371With and without AES-NI (PAA)
3SUSE Linux Enterprise Server 15 SP4GIGABYTE G242-P32-QZARM Ampere® Altra® Q80-30With and without Cryptography Extensions (PAA)
4SUSE Linux Enterprise Server 15 SP4IBM z/15z15With and without CPACF (PAI)
5SUSE Linux Enterprise Server 15 SP4 on PowerVM (VIOS 3.1.4.00)IBM Power E1080 (9080- HEX)Power10With and without ISA (PAA)
#Operating SystemHardware platformProcessorPAA/Acceleration
1SUSE Linux Enterprise Server 15SP4IBM LinuxONE III LT1z15With and without CPACF (PAI)
2SUSE Linux Enterprise Micro 5.3Supermicro Super Server SYS-6019P- WTRIntel® Xeon® Silver 4215RWith and without AES-NI (PAA)
2.3 Modes of Operation

Only if the integrity test passed successfully, the module transitions to the operational state. No operator intervention is required to reach this point. The module operates in the approved mode of operation by default and can only transition into the non-approved mode by calling one of the nonapproved services listed in Table 10. Please see section 4 for the details on service indicator provided by the module that identifies when an approved service is called.

2.4 Tested Operational Environments

The module has been tested on the following platforms with the corresponding module variants and configuration options: Table 3 - Tested Operational Environments

2.5 Vendor-Affirmed Operational Environments

In addition to the platforms listed in Table 3, SUSE has also tested the module on the platforms in Table 4, and claims vendor affirmation on them. Note: the CMVP makes no statement as to the correct operation of the module or the security strengths of the generated keys when so ported if the specific operational environment is not listed on the validation certificate. © 2024 SUSE, LLC / atsec information security corporation.

5 of 38

Page 6
#Operating SystemHardware platformProcessorPAA/Acceleration
3SUSE Linux Enterprise Micro 5.3GIGABYTE R181- Z90-00AMD EPYCÔ 7371With and without AES-NI (PAA)
4SUSE Linux Enterprise Micro 5.3GIGABYTE G242- P32-QZARM Ampere® Altra® Q80-30With and without Cryptography Extensions (PAA)
5SUSE Linux Enterprise Micro 5.3IBM z/15z15With and without CPACF (PAI)
6SUSE Linux Enterprise Micro 5.3IBM LinuxONE III LT1z15With and without CPACF (PAI)
7SUSE Linux Enterprise Server for SAP 15SP4Supermicro Super Server SYS-6019P- WTRIntel® Xeon® Silver 4215RWith and without AES-NI (PAA)
8SUSE Linux Enterprise Server for SAP 15SP4GIGABYTE R181- Z90-00AMD EPYCÔ 7371With and without AES-NI (PAA)
9SUSE Linux Enterprise Server for SAP 15SP4IBM Power E1080 (9080-HEX)Power10With and without ISA (PAA)
10SUSE Linux Enterprise Base Container Image 15SP4Supermicro Super Server SYS-6019P- WTRIntel® Xeon® Silver 4215RWith and without AES-NI (PAA)
11SUSE Linux Enterprise Base Container Image 15SP4GIGABYTE R181- Z90-00AMD EPYCÔ 7371With and without AES-NI (PAA)
12SUSE Linux Enterprise Base Container Image 15SP4GIGABYTE G242- P32-QZARM Ampere® Altra® Q80-30With and without Cryptography Extensions (PAA)
13SUSE Linux Enterprise Base Container Image 15SP4IBM z/15z15With and without CPACF (PAI)
14SUSE Linux Enterprise Base Container Image 15SP4IBM LinuxONE III LT1z15With and without CPACF (PAI)
15SUSE Linux Enterprise Base Container Image 15SP4IBM Power E1080 (9080-HEX)Power10With and without ISA (PAA)
16SUSE Linux Enterprise Desktop 15SP4Supermicro Super Server SYS-6019P- WTRIntel® Xeon® Silver 4215RWith and without AES-NI (PAA)
17SUSE Linux Enterprise Desktop 15SP4GIGABYTE R181- Z90-00AMD EPYCÔ 7371With and without AES-NI (PAA)
18SUSE Linux Enterprise Real Time 15SP4Supermicro Super Server SYS-6019P- WTRIntel® Xeon® Silver 4215RWith and without AES-NI (PAA)

© 2024 SUSE, LLC / atsec information security corporation.

6 of 38

Page 7
#Operating SystemHardware platformProcessorPAA/Acceleration
19SUSE Linux Enterprise Real Time 15SP4GIGABYTE R181- Z90-00AMD EPYCÔ 7371With and without AES-NI (PAA)
CAVP CertAlgorithm and StandardMode / MethodDescription / Key Size(s) / Key Strength(s)Use / Function
A3022 A3023AESCBC128, 192, 256-bit keysSymmetric encryption;
A3025 A3026FIPS197, SP800-with 128-256 bits keySymmetric decryption
38Astrength
AESCFB8, CFB128128, 192, 256-bit keysSymmetric encryption;
FIPS197, SP800-38Awith 128-256 bits key strengthSymmetric decryption
AESCCM128, 192, 256-bit keysKey wrapping; Key
SP800-38Cwith 128-256 bits key strengthunwrapping
AESCMAC128, 192, 256-bit keysMessage authentication
SP800-38Bwith 128-256 bits key strengthcode (MAC)
AESCTR128, 192, 256-bit keysSymmetric encryption;
FIPS197,with 128-256 bits keySymmetric decryption
SP800-38Astrength
AESECB128, 192, 256-bit keysSymmetric encryption;
FIPS197, SP800-38Awith 128-256 bits key strengthSymmetric decryption
AESKW128, 192, 256-bit keysKey wrapping; Key
FIPS197, SP800-38Fwith 128-256 bits key strengthunwrapping
AESOFB128, 192, 256-bit keysSymmetric encryption;
FIPS197, SP800-38Awith 128-256 bits key strengthSymmetric decryption
AESXTS128, 256-bit keys withSymmetric encryption
SP800-38E128 and 256 bits keyand symmetric
strengthdecryption (for data storage)

Table 4 - Vendor-Affirmed Operational Environments

2.6 Approved Algorithms

Table 5 below lists all security functions of the module, including specific key strengths employed for approved services, and implemented modes of operation. The following are allowed for legacy use only: Digital signature verification using ECDSA with a SHA-1. © 2024 SUSE, LLC / atsec information security corporation.

7 of 38

Page 8
CAVP CertAlgorithm and StandardMode / MethodDescription / Key Size(s) / Key Strength(s)Use / Function
VendorCKGRSA2048, 3072, 4096-bitKey generation
AffirmedSP 800-FIPS 186-4keys with 112-149 bits
133Rev2key strength
section 4 IG D.HECDSAP-224, P-256, P-384, P-
FIPS 186-4521 with 112-256 bits key strength
A3022 A3023CTR_DRBGAES-128, AES-128, 192, 256-bit AESRandom number
A3025 A3026SP800-90Arev1192, AES-256 withkeys with 128-256 bitsgeneration
DF, with/without PRkey strength
A3022 A3023Hash_DRBGSHA-1, SHA-256,N/A
A3024 A3025 A3026SP800-90Arev1SHA-512 with/without PR
A3022 A3023HMAC_DRBGHMAC-SHA-1,112 or more-bit HMAC
A3024 A3025 A3026SP800-90Arev1HMAC-SHA-256,keys with 112 bits key
HMAC-SHA-512 with/without PRstrength or greater
A3022 A3023ECDSAFIPS 186-4P-224, P-256, P-384,Key generation
A3024 A3025 A3026FIPS186-4Appendix B.4.2P-521 with 112-256
Testing Candidatesbits key strength
N/AP-224, P-256, P-384, P-521 with 112-256 bits key strengthPublic key verification
SHA-224, SHA-P-224, P-256, P-384,Digital signature
256, SHA-384,P-521 with 112-256generation
SHA-512bits key strength
SHA-1, SHA-224,P-224, P-256, P-384,Digital signature
SHA-256, SHA-P-521 with 112-256verification
384, SHA-512bits key strength
E31Non-PhysicalN/AEntropy input withRandom number
Entropy Source SP 800-90B256-bit strengthgeneration
A3021 A3022HMACSHA-1112 or more-bit keysMessage authentication
A3023 A3024 A3025 A3026 A3027FIPS198-1with 112 bits key strength or greatercode (MAC)
A3022 A3023SHA-224,112 or more-bit keysMessage authentication
A3024 A3025 A3026SHA-256, SHA-with 112 bits keycode (MAC)
384, SHA-512strength or greater

© 2024 SUSE, LLC / atsec information security corporation.

8 of 38

Page 9
CAVP Cert A3024 A3025 A3026Algorithm and StandardMode / Method SHA3-224, SHA3- 256, SHA3-384, SHA3-512Description / Key Size(s) / Key Strength(s) 112 or more-bit keys with 112 bits key strength or greaterUse / Function
A3022 A3023 A3025 A3026KTSAES in KW mode128, 192, 256-bit keysKey wrapping; Key
SP800-38F SP800-38Cwith 128-256 bits key strengthunwrapping
FIPS IG D.GAES in CCM mode128, 192, 256-bit keysKey wrapping; Key
with 128-256 bits key strengthunwrapping
A3022 A3023 A3024 A3025PBKDF2Option 1a withPassword: N/A; derivedKey derivation
SP800-132SHA-1, SHA-224,key with 112-256 bits
A3026SHA-256, SHA- 384, SHA-512, SHA3-224, SHA3-256, SHA3- 384, SHA3-512key strength
A3022 A3023 A3024 A3025RSAB.3.3 Random2048, 3072, 4096 withKey generation
FIPS186-4Probable Primes112-149 bits key
A3026strength
PKCS#1v1.5:2048, 3072, 4096 withDigital signature
SHA-224, SHA-112-149 bits keygeneration
256, SHA-384, SHA-512strength
PSS:2048, 3072, 4096 with
SHA-224, SHA- 256, SHA-384, SHA-512112-149 bits key strength
PKCS#1v1.5:2048, 3072, 4096 withDigital signature
SHA-224, SHA- 256, SHA-384, SHA-512112-149 bits key strengthverification
PSS: SHA-224, SHA-2048, 3072, 4096 with 112-149 bits key
256, SHA-384, SHA-512strength
A3024 A3025 A3026SHA-3SHA3-224, SHA3-N/AMessage digest
FIPS202256, SHA3-384, SHA3-512, SHAKE-128, SHAKE-256

© 2024 SUSE, LLC / atsec information security corporation.

9 of 38

Page 10
CAVP CertAlgorithm and StandardMode / MethodDescription / Key Size(s) / Key Strength(s)Use / Function
A3021 A3022 A3023 A3024 A3025 A3026 A3027SHS FIPS180-4SHA-1N/AMessage digest
A3022 A3023SHA-224, SHA-N/AMessage digest
A3024 A3025 A3026256, SHA-384, SHA-512
Algorithm/FunctionsUse/Function
AES EAXSymmetric encryption; Symmetric decryption
AES GCMSymmetric encryption; Symmetric decryption
AES GMACMessage authentication code (MAC)
AES OCBSymmetric encryption; Symmetric decryption
BLAKE2B-160, BLAKE2B-256, BLAKE2B-384, BLAKE2B-512, BLAKE2S-128, BLAKE2S-160, BLAKE2S-224, BLAKE2S-256Message digest
CRC32Error detection code
ElGamalKey generation
GOST R 34.11Message digest
MD4, MD5Message digest
PBKDF2 with non-approved message digest algorithms or using input parameters notKey derivation
2.7 Non-Approved Algorithms Allowed in the Approved Mode

of Operation The module does not implement non-approved algorithms that are allowed in the approved mode of operation.

2.8 Non-Approved Algorithms Allowed in the Approved Mode

of Operation with No Security Claimed The module does not implement non-approved algorithms that are allowed in the approved mode of operation.

2.9 Non-Approved Algorithms Not Allowed in the Approved

Mode of Operation Table 6 lists non-approved algorithms that are not allowed in the approved mode of operation. These algorithms are used by the non-approved services listed in Table 10. © 2024 SUSE, LLC / atsec information security corporation.

10 of 38

Page 11
meeting requirements stated in section 11.2.3
RIPEMD-160Message digest
RSA OAEPKey encapsulation
TigerMessage digest
SM3, STRIBOG-256, STRIBOG-512Message digest
WhirlpoolMessage digest

Table 6 - Non-Approved Not Allowed in the Approved Mode of Operation © 2024 SUSE, LLC / atsec information security corporation.

11 of 38

Page 12
Logical Interface1Data that passes over port/interface
Data InputAPI input parameters for data.
Data OutputAPI output parameters for data.
Control InputAPI function calls, API input parameters for control input, /proc/sys/crypto/fips_enabled control file.
Status OutputAPI return codes, API output parameters for status output.
3 Cryptographic Module Ports and Interfaces

As a software-only module, the module does not have physical ports. The operator can only interact with the module through the API provided by the module. Thus, the physical ports are interpreted to be the physical ports of the hardware platform on which the module runs. All data output via data output interface is inhibited when the module is performing preoperational test or zeroization or when the module enters error state. Table 7 - Ports and Interfaces

1 The control output interface is omitted on purpose because the module does not implement it.

© 2024 SUSE, LLC / atsec information security corporation.

12 of 38

Page 13
RoleServiceInputOutput
Crypto Officer (CO)Digital signature generationPrivate key, message, hash algorithmSignature
Digital signature verificationSignature, message, hash algorithm, public keySignature verification result
Error detection codeNoneCode
Key generationKey sizeKey pair
Key derivationPassword or passphraseDerived key
Key encapsulationKey encapsulating key, key to be encapsulatedEncapsulated key
Key unwrappingWrapped key, key unwrapping keyUnwrapped key
Key wrappingKey wrapping key, key to be wrappedWrapped key
Message authentication code (MAC)Message, keyMessage authentication code
Message digestMessageMessage digest
On-demand integrity testNoneReturn codes/log messages
Public key verificationKeyReturn codes/log messages
Random number generationSizeRandom number
Symmetric decryptionCiphertext, keyPlaintext
Symmetric encryptionPlaintext, keyCiphertext
Show versionN/AName and version information
Show statusN/AModule status
Self-testN/APass/fail results of self-tests
ZeroizationAny SSPN/A
4 Roles, services and authentication
4.1 Roles

The module supports the Crypto Officer role only. This sole role is implicitly assumed by the operator of the module when performing a service. The module does not support Table 8 - Roles, Service Commands, Input and Output © 2024 SUSE, LLC / atsec information security corporation.

13 of 38

Page 14
Service Cryptographic ServicesDescriptionApproved Security FunctionsKeys and/or SSPsRolesAccess rights to Keys and/or SSPsIndicator
Symmetric encryptionEncrypt a plaintextAESAES keyCOW, E_gcry_fips_indi cator_cipher function returns “0”
Symmetric decryptionDecrypt a ciphertextAESAES keyW, E_gcry_fips_indi cator_cipher function returns “0”
Key generationGenerate a key pairRSA, DRBG, CKGRSA public key, RSA private key, Intermediate key generation valueG, Rrsa_generate and _gcry_fips_indi cator_pk functions returns “0”
ECDSA, DRBG, CKGECDSA public key, ECDSA private key, Intermediate key generation valueG, R_gcry_fips_indi cator_pk function returns “0”

The module provides services to the users that assume one of the available roles. All services are shown in Table 9 and Table

  1. Table 9 lists the approved services. For each service, the table lists the associated cryptographic algorithm(s), the role to perform the service, the cryptographic keys or CSPs involved, and their access type(s). The following convention is used to specify access rights to a CSP: • G = Generate: The module generates or derives the SSP. • R = Read: The SSP is read from the module (e.g., the SSP is output). • W = Write: The SSP is updated, imported, or written to the module. • E = Execute: The module uses the SSP in performing a cryptographic operation. • Z = Zeroise: The module zeroises the SSP. • N/A: the calling application does not access any CSP or key during its operation. The details of the approved cryptographic algorithms including the CAVP certificate numbers can be found in Table
  2. The module implements dedicated functions based on the type of requested service to indicate whether it utilizes an approved security function or not. The specific functions are as listed below 4. _gcry_fips_indicator_hash - For digest functions For all approved services, the output of the function will be "0” indicating the service is approved. © 2024 SUSE, LLC / atsec information security corporation.

14 of 38

Page 15

Service Digital signature generation Digital signature verification Public key verification Random number generation Message digest XOF

Description Generate a signature Verify a signature Verify a public key Generate random bitstrings Compute a message digest Compute the output of an XOF

Approved Security Functions RSA, SHS, DRBG ECDSA, DRBG, SHS RSA, SHS ECDSA, SHS ECDSA CTR_DRBG Hash_DRBG HMAC_DRBG SHA-1, SHA-224, SHA-256, SHA- 384, SHA-512, SHA3-224, SHA3-256, SHA3-384, SHA3-512 SHAKE-128, SHAKE-256

Keys and/or SSPs RSA private key ECDSA private key RSA public key ECDSA public key ECDSA public key Entropy input DRBG seed DRBG Internal state (V, Key) Entropy input DRBG seed DRBG Internal state (V, C) Entropy input DRBG seed DRBG Internal state (V, Key) N/A N/A

Roles

Access rights to Keys and/or SSPs W, E W, E W, E W, E W, E W, E E, G W, E, G W, E E, G W, E, G W, E E, G W, E, G N/A N/A

Indicator rsa_sign and _gcry_fips_indi cator_pk functions returns “0” _gcry_fips_indi cator_pk function returns “0” rsa_verify and _gcry_fips_indi cator_pk functions returns “0” _gcry_fips_indi cator_pk function returns “0” _gcry_fips_indi cator_pk function returns “0” drbg_generate function returns “0” _gcry_fips_indi cator_hash function returns “0” _gcry_fips_indi cator_hash function returns “0”

© 2024 SUSE, LLC / atsec information security corporation.

15 of 38

Page 16
Service Message authentication code (MAC) Key wrapping Key unwrapping Key derivation On demand integrity test Other FIPS-related ServicesDescription Compute a MAC tag Perform AES- based key wrapping Perform AES- based key unwrapping Derive a key from a password Perform the integrity test on demandApproved Security Functions HMAC AES CMAC AES-KW, AES- CCM AES-KW, AES- CCM PBKDF2 HMAC-SHA-256Keys and/or SSPs HMAC key AES key AES key AES key Password or passphrase Derived key N/ARolesAccess rights to Keys and/or SSPs W, E W, E W, E W, E W, E G, R N/AIndicator _gcry_fips_indi cator_mac function returns “0” _gcry_fips_indi cator_cipher function returns “0” _gcry_fips_indi cator_cipher function returns “0” _gcry_fips_indi cator_kdf function returns “0” None
Show statusReturn the module statusN/AN/ACON/ANone
ZeroizationZeroize all SSPsN/AAny SSPZ
Self-testsPerform selft-testsAES, CMAC, DRBG, Non- Physical Entropy Source, ECDSA, HMAC, RSA, SHS, PBKDF2 See Table 13 for additional detailsAES keys HMAC keys RSA public key RSA private key ECDSA public key ECDSA private key Intermediate key generation value Password or passphrase Entropy inputE
Derived key DRBG seed DRBG Internal state (V, Key) DRBG Internal state (V, C)E, G
Show versionReturn the name and version informationN/AN/AN/A

© 2024 SUSE, LLC / atsec information security corporation.

16 of 38

Page 17
Service Cryptographic ServicesDescriptionAlgorithms AccessedRole
Symmetric encryptionAES encryption using non- approved AES modesAES (GCM, EAX and OCB)CO
Symmetric decryptionAES decryption using non- approved AES modes
Message authentication code (MAC)Message authenticationAES GMAC
Key derivationPBKDF2 Key derivationPBKDF2 with non-approved message digest algorithms or using input parameters not meeting requirements stated in section 11.2.3
Key encapsulationEncapsulate a keyRSA OAEP
Key generationGenerate a key pairElGamal
Message digestMessage digest using non- approved algorithmsMD5, MD4, GOST R 34.11, RIPEMD- 160, Tiger, Whirlpool, SM3, STRIBOG- 256, STRIBOG-512, BLAKE2B-160, BLAKE2B-256, BLAKE2B-384, BLAKE2B-512, BLAKE2S-128, BLAKE2S-160, BLAKE2S-224 and BLAKE2S-256
Error detection codeError detection codeCRC32

Table 10 lists the non-approved services. The details of the non-approved cryptographic algorithms available in non-approved mode can be found in Table 6. © 2024 SUSE, LLC / atsec information security corporation.

17 of 38

Page 18
5 Software/Firmware security
5.1 Integrity Techniques

The integrity of the module is verified by comparing an HMAC-SHA-256 value calculated at run time with the HMAC value stored in the .hmac file that was computed at build time for each software component of the module. If the HMAC values do not match, the test fails and the module enters the error state.

5.2 On-Demand Integrity Test

Integrity tests are performed as part of the Pre-Operational Self-Tests. The module provides the Self-Test service to perform self-tests on demand which includes the preoperational tests (i.e., integrity test) and cryptographic algorithm self-tests (CASTs). This service can be invoked by using the gcry_control(GCRYCTL_SELFTEST) API function call or by powering-off and reloading the module. During the execution of the on-demand self-tests, services are not available, and neither data input nor output is possible. In order to verify whether the self-tests have succeeded and the module is in the Operational state, the calling application may invoke the gcry_control(GCRYCTL_OPERATIONAL_P). The function will return TRUE if the module is in the operational state, FALSE if the module is in the Error state.

5.3 Executable Code

The module consists of executable code in the form of libgcrypt file as stated in Table 2. © 2024 SUSE, LLC / atsec information security corporation.

18 of 38

Page 19
6 Operational Environment
6.1 Applicability

This module operates in a modifiable operational environment per the FIPS 140-3 level 1 specifications. The SUSE Linux Enterprise Server operating system is used as the basis of other products. Compliance is maintained for SUSE products whenever the binary is found unchanged per the vendor affirmation from SUSE based on the allowance FIPS 140-3 management manual section 7.9.1 bullet 1 a i). Note: The CMVP makes no statement as to the correct operation of the module or the security strengths of the generated keys when supported if the specific operational environment is not listed on the validation certificate.

6.2 Policy

Instrumentation tools like the ptrace system call, gdb and strace utilities, as well as other tracing mechanisms offered by the Linux environment such as ftrace or systemtap, shall not be used in the operational environment. The use of any of these tools implies that the cryptographic module is running in a non-tested operational environment.

6.3 Requirements

The module shall be installed as stated in section 11. The operating system provides process isolation and memory protection mechanisms that ensure appropriate separation for memory access among the processes on the system. Each process has control over its own data and uncontrolled access to the data of other processes is prevented. © 2024 SUSE, LLC / atsec information security corporation.

19 of 38

Page 20
7 Physical Security

The module is comprised of software only, and therefore this section is not applicable. © 2024 SUSE, LLC / atsec information security corporation.

20 of 38

Page 21
8 Non-invasive Security

This module does not implement any non-invasive security mechanism, and therefore this section is not applicable. © 2024 SUSE, LLC / atsec information security corporation.

21 of 38

Page 22
Key/SSP Name/ TypeStrengt hSecurity Function and Cert. NumberGenerationImport/ExportEstabl ishme ntStorageZeroizationUse & related keys
AES keys (CSP)AES-XTS: 128, 256 bits Rest of the modes: 128, 192, 256 bitsAES-CBC, AES-CCM, AES-CFB128, AES-CFB8, AES-CMAC, AES-CTR, AES-KW, AES-OFB, AES-XTS A3022 A3023 A3025 A3026N/AMD/EE Import: API input parameters From: Operator calling application (TOEPP) To: Cryptographic module Export: NoneN/ARAMgcry_cipher_clos e(), gcry_free()Use: Symmetric encryption; Symmetric decryption; Message authentication code (MAC); Key wrapping; Key unwrapping Related SSPs: N/A
HMAC keys (CSP)112 or greater bitsHMAC A3021 A3022 A3023 A3024 A3025 A3026 A3027N/ARAMgcry_mac_close( ), gcry_free()Use: Message Authentication Code (MAC) Related SSPs: N/A
RSA public key (PSP)112, 128, 149 bitsRSA A3022 A3023 A3024 A3025 A3026Generated using method B.3.3 specified in FIPS 186-4; random values are obtained from the SP800- 90Arev1 DRBG.MD/EE Import: API input parameters From: Operator calling application (TOEPP) To: Cryptographic module Export: API output parameters From: Cryptographic module To: Operator calling application (TOEPP)N/ARAMgcry_sexp_releas e(), gcry_mpi_releas e(), gcry_free()Use: Digital signature verification; Key generation Related SSPs: RSA private key, Intermediate key generation value
RSA private key (CSP)112, 128, 149 bitsN/ARAMgcry_sexp_releas e(), gcry_mpi_releas e(), gcry_free()Use: Digital signature generation; Key generation Related SSPs: RSA public key, Intermediate key generation value
9 Sensitive Security Parameter Management

Table 11 summarizes the Sensitive Security Parameters (SSPs) that are used by the cryptographic © 2024 SUSE, LLC / atsec information security corporation.

22 of 38

Page 23
Key/SSP Name/ TypeStrengt hSecurity Function and Cert. NumberGenerationImport/ExportEstabl ishme ntStorageZeroizationUse & related keys
ECDSA public key (PSP)112, 128, 192, 256 bitsECDSA A3022 A3023 A3024 A3025 A3026Generated using method B.4.2 specified in FIPS 186-4; random values are obtained from the SP800- 90Arev1 DRBG.MD/EE Import: API input parameters From: Operator calling application (TOEPP) To: Cryptographic module Export: API output parameters From: Cryptographic module To: Operator calling application (TOEPP)N/ARAMgcry_sexp_releas e(), gcry_mpi_releas e(), gcry_ctx_release (), gcry_mpi_point_r elease(), gcry_free()Use: Digital signature verification; Key generation; Public key verification Related SSPs: ECDSA private key, Intermediate key generation value
ECDSA private key (CSP)112, 128, 192, 256 bitsN/ARAMgcry_sexp_releas e(), gcry_mpi_releas e(), gcry_ctx_release (), gcry_mpi_point_r elease(), gcry_free()Use: Digital signature generation; Key generation; Public key verification Related SSPs: ECDSA public key, Intermediate key generation value
Intermedia te key generation value (CSP)112-256 bitsCKG vendor affirmedSP 800- 133r2 Section 4, 5.1, and 5.2Import: None Export: NoneN/ARAMAutomaticUse: Key generation Related SSPs: ECDSA public key, ECDSA private key, RSA public key, RSA private key
Password or passphrase (CSP)N/APBKDF2 A3022 A3023 A3024 A3025 A3026N/AMD/EE Import: API input parameters From: Operator calling application (TOEPP) To: Cryptographic module Export: NoneN/ARAMgcry_free()Use: Key derivation Related SSPs: Derived key
Derived key (CSP)N/APBKDF2 A3022 A3023 A3024 A3025 A3026SP 800- 133r2, Section 6.2MD/EE Import: None Export: API output parameters From: Cryptographic moduleN/ARAMgcry_free()Use: Key derivation Related SSPs: Password or passphrase

(), e(), © 2024 SUSE, LLC / atsec information security corporation.

23 of 38

Page 24
Key/SSP Name/ TypeStrengt hSecurity Function and Cert. NumberGenerationImport/Export To: Operator calling application (TOEPP)Establ ishme ntStorageZeroizationUse & related keys
Entropy input (CSP) IG D.L Compliant256 bitsNon-Physical Entropy Source E31Obtained from Non- Physical Entropy SourceImport: None Export: NoneN/ARAMgcry_ctrl(GCRYC TL_TERM_SECME M)Use: Random number generation Related SSPs: DRBG seed
DRBG seed (CSP) IG D.L CompliantCTR_DRB G: 128, 192, 256 bits Hash_DB RG: 128, 256 bits HMAC_D RBG: 128, 256 bitsCTR_DRBG A3022 A3023 A3025 A3026 Hash_DRBG, HMAC_DRBG A3022 A3023 A3024 A3025 A3026CTR_DRBG Hash_DRBG HMAC_DRB GImport: None Export: NoneN/ARAMgcry_ctrl(GCRYC TL_TERM_SECME M)Use: Random number generation Related SSPs: Entropy input, DRBG Internal state (V, Key), DRBG Internal state (V, C)
DRBG Internal state (V, Key) (CSP) IG D.L CompliantCTR_DRBG A3022 A3023 A3025 A3026 HMAC_DRBG A3022 A3023 A3024 A3025 A3026CTR_DRBG HMAC_DRB GImport: None Export: NoneN/ARAMgcry_ctrl(GCRYC TL_TERM_SECME M)Use: Random number generation Related SSPs: DRBG seed
DRBG Internal state (V, C) (CSP) IG D.L CompliantHash_DRBG A3022 A3023 A3024 A3025 A3026Hash_DRBGImport: None Export: NoneN/ARAMgcry_ctrl(GCRYC TL_TERM_SECME M)Use: Random number generation Related SSPs: DRBG seed

Table 11 - SSPs The module employs a Deterministic Random Bit Generator (DRBG) based on [SP800-90Arev1] for the creation of RSA and ECDSA keys, RSA and ECDSA signature generation. In addition, the module provides a Random Number Generation service to calling applications. The DRBG supports the Hash_DRBG, HMAC_DRBG and CTR_DRBG mechanisms. The DRBG is initialized during module initialization; the module loads by default the DRBG using the HMAC_DRBG mechanism with SHA-256 and without prediction resistance. A different DRBG mechanism can be chosen by invoking the gcry_control(GCRYCTL_DRBG_REINIT) function. The module uses an [SP800-90B]-compliant entropy source specified in Table 12. This entropy source is located within the cryptographic boundary. The module obtains 384 bits to seed the DRBG, and 256 bits to reseed it, sufficient to provide a DRBG with 256 bits of security strength. © 2024 SUSE, LLC / atsec information security corporation.

24 of 38

Page 25
Entropy SourceMinimum number of bits of entropyDetails
SP 800-90B compliant Non-Physical Entropy Source (ESV cert. E31)256 bits of entropy in 256-bit outputThe Libgcrypt CPU Time Jitter RNG version 3.4.0 entropy source (with SHA-3 as the vetted conditioning component) is located within the module’s cryptographic boundary.

Table 12 - Non-Deterministic Random Number Generation Specification

9.2 SSP Generation

The module provides an [SP800-90Arev1]-compliant Deterministic Random Bit Generator (DRBG) for the creation of key components of asymmetric keys, and random number generation. The Cryptographic Key Generation (CKG) methods implemented in the module for Approved services in approved mode are compliant with section 5.1 of [SP800-133rev2] and with IG C.H. For generating RSA and ECDSA keys the module implements asymmetric key generation services compliant with [FIPS186-4]. A seed (i.e., the random value) used in asymmetric key generation is directly obtained from the [SP800-90Arev1] DRBG.

9.3 SSP Transport

The module provides the following key transport mechanisms:

9.4 SSP Derivation

The module supports password-based key derivation (PBKDF2). The implementation is compliant with option 1a of [SP-800-132]. Keys derived from passwords or passphrases using this method can only be used in storage applications.

9.5 SSP Entry and Output

The module does not support direct manual SSP entry or intermediate SSP generation output. The SSPs are provided to the module via API input parameters in plaintext form and output via API output parameters in plaintext form within the physical perimeter of the operational environment. This is allowed by [FIPS140-3_IG] 9.5.A, according to the “CM Software to/from App via TOEPP Path” entry on the Key Establishment Table.

9.6 SSP Storage

The module does not perform persistent storage of SSPs. The SSPs are temporarily stored in the RAM in plaintext form. SSPs are provided to the module by the calling process and are destroyed when released by the appropriate zeroization function calls. © 2024 SUSE, LLC / atsec information security corporation.

25 of 38

Page 26
9.7 SSP Zeroization

The memory occupied by SSPs is allocated by regular memory allocation operating system calls. The application that is acting as the CO is responsible for calling the appropriate zeroization functions provided in the module's API and listed in Table 11. Calling gcry_free() will zeroize the SSPs and also invoke the corresponding API functions listed in Table 11 to zeroize SSPs. The zeroization functions overwrite the memory occupied by SSPs with “zeros” and deallocate the memory with the regular memory deallocation operating system call. The completion of a zeroization routine(s) will indicate that a zeroization procedure succeeded. © 2024 SUSE, LLC / atsec information security corporation.

26 of 38

Page 27
AlgorithmConditionTest
AESPower onKAT AES ECB mode with 128, 192 and 256-bits keys, encryption, and decryption (separately tested).
CMACPower onKAT AES CMAC with 128-bit key, MAC generation.
DRBGPower onKAT CTR_DRBG with AES with 128-bit key with DF, with and without PR. KAT Hash_DRBG with SHA-256 with and without PR. KAT Hash_DRBG with SHA-1 without PR. KAT HMAC_DRBG with HMAC-SHA-256 with and without PR. Health tests according to section 11.3 of [SP800-90Arev1]
Non-Physical Entropy SourcePower onNIST SP800-90B Entropy source start-up test RCT and APT with 1024 samples
ContinuousNIST SP800-90B Entropy source continuous test: RCT with Cutoff C = 31; APT with Cutoff C = 325; W = 512
ECDSAPower onKAT ECDSA signature generation and verification with P-256 and SHA-256 (separately tested).
HMACPower onKAT HMAC-SHA-1, HMAC-SHA-224, HMAC-SHA-256, HMAC-SHA- 384, HMAC-SHA-512. KAT HMAC-SHA3-224, HMAC-SHA3-256, HMAC-SHA3-384, HMAC-SHA3-512.
10 Self-tests

The module performs pre-operational tests automatically when the module is loaded into memory; pre-operational tests ensure that the module is not corrupted, and the CASTs ensure that the cryptographic algorithms work as expected. While the module is executing the pre-operational tests and CASTs, services are not available, and input and output are inhibited. The module is not available for use by the calling application until the pre-operational tests are completed successfully. After the pre-operational test and the CASTs succeed, the module becomes operational. If any of the pre-operational test or any of the CASTs fail an error message is returned, and the module transitions to the error state.

10.1 Pre-Operational Tests

The module performs the integrity test using HMAC-SHA-256. The details of integrity test are provided in section 5.1.

10.2 Conditional Tests
10.2.1 Cryptographic algorithm tests

Table 13 specifies the CASTs performed by the module. All CASTs performed are in the form of the Known Answer Tests (KATs) and are run prior to performing the integrity test. A KAT includes the comparison of a calculated output with an expected known answer, hard coded as part of the test vectors used in the test. If the values do not match, the KAT fails. © 2024 SUSE, LLC / atsec information security corporation.

27 of 38

Page 28
AlgorithmConditionTest
RSAPower onKAT RSA PKCS#1 v1.5 signature generation and verification with 2048-bit key and SHA-256 (separately tested).
SHSPower onKAT SHA-1, SHA-224, SHA-256, SHA-384 and SHA-512.
PBKDF2Power onKAT PBKDF2 with SHA-1 and SHA-256.
AlgorithmTest
ECDSA key generationPCT using signature generation and verification with SHA-256.
RSA key generationPCT using signature generation and verification with SHA-256.
Error StateCause of ErrorStatus Indicator
Self-test error stateFailure of pre-operational tests or conditional tests.An error message related to the cause of the failure.

Table 13 – Conditional Cryptographic Algorithms Self-Tests

10.2.2 Pairwise Consistency Test

The module performs the Pair-wise Consistency Tests (PCT) shown in Table 14. If at least one of the tests fails, the module returns an error code and enters the Error state. When the module is in the Error state, no data is output, and cryptographic operations are not allowed. Table 14 - Pairwise Consistency Test

10.2.3 Periodic/On-Demand Self-Test

On-Demand self-tests can be invoked by using gcry_control(GCRYCTL_SELFTEST) API function call or by powering-off and reloading the module which cause the module to run both the pre-operational services are not available, and neither data input nor output is possible. In order to verify whether the self-tests have succeeded and the module is in the Operational state, the calling application may invoke the gcry_control(GCRYCTL_OPERATIONAL_P). The function will return TRUE if the module is in the operational state, FALSE if the module is in the Error state.

10.3 Error States

When the module fails any pre-operational self-test or conditional test, the module will return an Additionally, when random numbers are requested in the error state or cipher operations are requested on a deallocated handle, the module is aborted, enters the Error state (i.e., Abort error state) and is not available for use. Any further cryptographic operation is inhibited. When the module is in Self-test Error state, the calling application can obtain the module state by calling the gcry_control(GCRYCTL_OPERATIONAL_P) API function. The function returns FALSE to indicate that the module is in the Error state. Otherwise, the function returns TRUE to indicate that the module is in the Operational state. In the Abort Error state the module is aborted and is not available for use, therefore, the module state cannot be obtained. In both Error states, all data output is inhibited, and no cryptographic operation is allowed. The Error states can be recovered by a restart (i.e., powering off and powering on) of the module. The following table shows the error © 2024 SUSE, LLC / atsec information security corporation.

28 of 38

Page 29
Error StateCause of ErrorStatus Indicator
Abort error stateRandom numbers are requested in the error state or cipher operations are requested on a deallocated handle.The module is aborted and is not available for use.

Table 15 - Error States © 2024 SUSE, LLC / atsec information security corporation.

29 of 38

Page 30
11 Life-cycle assurance
11.1 Delivery and Operation
11.1.1 Module Installation

The Crypto Officer can install the RPM packages containing the module as listed in Table 17 using the zypper tool as follows. # zypper install libgcrypt20 # zypper install libgcrypt20-hmac The integrity of the RPM package is automatically verified during the installation, and the Crypto Officer shall not install the RPM package if there is any integrity error.

11.1.2 Operating Environment Configuration

The operating environment needs to be configured to support FIPS, so the following steps shall be performed with the root privilege:

  1. Install the dracut-fips RPM package: # zypper install dracut-fips
  2. Recreate the INITRAMFS image: # dracut -f
  3. After regenerating the initrd, the Crypto Officer has to append the following parameter in the /etc/default/grub configuration file in the GRUB_CMDLINE_LINUX_DEFAULT line: fips=1
  4. After editing the configuration file, please run the following command to change the setting in the boot loader: # grub2-mkconfig -o /boot/grub2/grub.cfg If /boot or /boot/efi resides on a separate partition, the kernel parameter boot=<partition of /boot or /boot/efi> must be supplied. The partition can be identified with the command "df /boot" or "df /boot/efi" respectively. For example: # df /boot Filesystem 1K-blocks Used Available Use% Mounted on /dev/sda1 233191 30454 190296 14% /boot The partition of /boot is located on /dev/sda1 in this example. Therefore, the following string needs to be appended in the aforementioned grub file: "boot=/dev/sda1"
  5. Reboot to apply these settings. Now, the operating environment is configured to support FIPS operation. The Crypto Officer should check the existence of the file /proc/sys/crypto/fips_enabled, and verify it contains a numeric value “1”. If the file does not exist or does not contain “1”, the operating environment is not configured to support FIPS and the module will not operate as a FIPS validated module properly.
11.1.3 Module Installation for Vendor Affirmed Platforms

Table 16 includes the information on module installation process for the vendor affirmed platforms that are listed in Table 4. © 2024 SUSE, LLC / atsec information security corporation.

30 of 38

Page 31
ProductLink
SUSE Linux Enterprise Micro 5.3https://documentation.suse.com/sle-micro/5.3/single-html/SLE- Micro-security/#sec-fips-slemicro-install
SUSE Linux Enterprise Server for SAP 15SP4https://documentation.suse.com/sles/15-SP4/html/SLES- all/book-security.html
SUSE Linux Enterprise Base Container Image 15SP4https://documentation.suse.com/smart/linux/html/concept- bci/index.html
SUSE Linux Enterprise Desktop 15SP4https://documentation.suse.com/sled/15-SP4/html/SLED- all/book-security.html
SUSE Linux Enterprise Real Time 15SP4https://documentation.suse.com/sle-rt/15-SP4/
Processor ArchitectureRPM Packages
Intel 64-bitlibgcrypt20-1.9.4-150400.6.8.1.x86_64.rpm libgcrypt20-hmac-1.9.4-150400.6.8.1.x86_64.rpm
AMD 64-bitlibgcrypt20-1.9.4-150400.6.8.1.x86_64.rpm libgcrypt20-hmac-1.9.4-150400.6.8.1.x86_64.rpm
IBM z15libgcrypt20-1.9.4-150400.6.8.1.s390x.rpm libgcrypt20-hmac-1.9.4-150400.6.8.1.s390x.rpm

Table 16 - Installation for Vendor Affirmed Platforms Note: Per section 7.9 in the FIPS 140-3 Management Manual [FIPS140-3_MM], the Cryptographic Module Validation Program (CMVP) makes no statement as to the correct operation of the module or the security strengths of the generated keys when this module is ported and executed in an operational environment not listed on the validation certificate.

11.1.4 End of Life Procedure

For secure sanitization of the cryptographic module, the module must first to be powered off, which will zeroize all keys and CSPs in volatile memory. Then, for actual deprecation, the module shall be upgraded to a newer version that is FIPS 140-3 validated. The module does not possess persistent storage of SSPs, so further sanitization steps are not required.

11.2 Crypto Officer Guidance

The binaries of the module are contained in the RPM packages for delivery. The Crypto Officer shall follow sections 11.1.1 and 11.1.2 to configure the operational environment and install the module to be operated as a FIPS 140-3 validated module. Table 17 lists the RPM packages that contain the FIPS validated module and the OE directory where the components are installed. The "Show version" service returns the value “Libgcrypt version 1.9.4-150400.6.8.1”, which matches the service output and the version information provided in the RPM packages where the module is distributed, and map to version 3.2 of the cryptographic module. © 2024 SUSE, LLC / atsec information security corporation.

31 of 38

Page 32
Processor ArchitectureRPM Packages
ARMv8 64-bitlibgcrypt20-1.9.4-150400.6.8.1.aarch64.rpm libgcrypt20-hmac-1.9.4-150400.6.8.1.aarch64.rpm
IBM Power10 64-bitlibgcrypt20-1.9.4-150400.6.8.1.ppc64le.rpm libgcrypt20-hmac-1.9.4-150400.6.8.1.ppc64le.rpm
11.2.1 Memory Management

The user shall only use the memory management functions provided by the libgcrypt API. Critical security parameters (e.g., keys) which are used as input or output parameters shall be managed using the gcry_malloc_secure(), gcry_calloc_secure() and gcry_free() functions. The function gcry_set_allocation_handler() shall not be used; the user shall not change the libgcrypt memory handlers. The use of this API function implies that the cryptographic module is being executed in an invalid configuration.

11.2.2 AES XTS

The AES algorithm in XTS mode can be only used for the cryptographic protection of data on storage devices, as specified in [SP800-38E]. The length of a single data unit encrypted with the XTS-AES shall not exceed 2²⁰ AES blocks, that is 16MB of data. To meet the requirement stated in IG C.I, the module implements a check that ensures, before performing any cryptographic operation, that the two AES keys used in AES XTS mode are not identical.

11.2.3 Key derivation using SP800-132 PBKDF2

The module provides password-based key derivation (PBKDF2), compliant with SP800-132 and IG D.N. The module supports option 1a from section 5.4 of [SP800-132], in which the Master Key (MK) or a segment of it is used directly as the Data Protection Key (DPK). In accordance with [SP800-132], the following requirements shall be met.

32 of 38

Page 33
11.2.4 RSA Signatures

In compliance with IG C.F, the module implements only the approved modulus sizes of 2048, 3072, and 4096 bits for signature generation and verification. Each algorithm was tested, and corresponding certificates can be found detailed in Section 2.6 Approved Algorithms. © 2024 SUSE, LLC / atsec information security corporation.

33 of 38

Page 34
12 Mitigation of other attacks

The module implements blinding Against RSA Timing Attacks. RSA is vulnerable to timing attacks. In a setup where attackers can measure the time of RSA decryption or signature operations, blinding must be used to protect the RSA operation from that attack. By default, the module uses the following blinding technique: instead of using the RSA decryption directly, a blinded value y = x re mod n is decrypted and the unblinded value x' = y' r−1 mod n returned. The blinding value r is a random value with the size of the modulus n. © 2024 SUSE, LLC / atsec information security corporation.

34 of 38

Page 35
Table, extracted as text (did not parse into structured rows)
Appendix A.                      Glossary and Abbreviations AES                Advanced Encryption Standard AES-NI             Advanced Encryption Standard New Instructions API                Application Programming Interface CAST               Cryptographic Algorithm Self-Test CAVP               Cryptographic Algorithm Validation Program CBC                Cipher Block Chaining CCM                Counter with Cipher Block Chaining-Message Authentication Code CFB                Cipher Feedback CKG                Cryptographic Key Generation CMAC               Cipher-based Message Authentication Code CMVP               Cryptographic Module Validation Program CPACF              Central Processor Assist for Cryptographic Function CSP                Critical Security Parameter CTR                Counter Mode DF                 Derivation Function DRBG               Deterministic Random Bit Generator ECB                Electronic Code Book ECC                Elliptic Curve Cryptography ECDSA              Elliptic Curve Digital Signature Algorithm FIPS               Federal Information Processing Standards Publication GCM                Galois Counter Mode HMAC               Hash Message Authentication Code ISA                Instruction Set Architecture KAT                Known Answer Test KW                 AES Key Wrap MAC                Message Authentication Code NIST               National Institute of Science and Technology OAEP               Optimal Asymmetric Encryption Padding OFB                Output Feedback PAA                Processor Algorithm Acceleration PAI                Processor Algorithm Implementation PBKDF2             Password-based Key Derivation Function v2 PCT                Pair-wise Consistency Test PKCS               Public-Key Cryptography Standards PR                 Prediction Resistance © 2024 SUSE, LLC / atsec information security corporation.

35 of 38

Page 36
Table, extracted as text (did not parse into structured rows)
PSS                Probabilistic Signature Scheme RNG                Random Number Generator RSA                Rivest, Shamir, Addleman SHA                Secure Hash Algorithm SHS                Secure Hash Standard SSP                Sensitive Security Parameter XOF                Extendable Output Function XTS                XEX-based Tweaked-codebook mode with cipher text Stealing © 2024 SUSE, LLC / atsec information security corporation.

36 of 38

Page 37

Appendix B. References FIPS140-3 FIPS PUB 140-3 - Security Requirements For Cryptographic Modules March 2019 https://doi.org/10.6028/NIST.FIPS.140-3 FIPS140-3_IG Implementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program March 2024 https://csrc.nist.gov/csrc/media/Projects/cryptographic-module-validationprogram/documents/fips%20140-3/FIPS%20140-3%20IG.pdf FIPS140-3_MM FIPS 140-3 Cryptographic Module Validation Program - Management Manual (Draft) December 2022 https://csrc.nist.gov/csrc/media/Projects/cryptographic-module-validationprogram/documents/fips%20140-3/Draft%20FIPS-140-3CMVP%20Management%20Manual%20v1.2%20%5BDec%2023%202022%5 D.pdf FIPS180-4 Secure Hash Standard (SHS) August 2015 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf FIPS186-4 Digital Signature Standard (DSS) July 2013 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-4.pdf FIPS197 Advanced Encryption Standard November 2001 https://csrc.nist.gov/publications/fips/fips197/fips-197.pdf FIPS198-1 The Keyed Hash Message Authentication Code (HMAC) July 2008 https://csrc.nist.gov/publications/fips/fips198-1/FIPS-198-1_final.pdf FIPS202 SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions August 2015 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.202.pdf PKCS#1 Public Key Cryptography Standards (PKCS) #1: RSA Cryptography Specifications Version 2.1 February 2003 https://www.ietf.org/rfc/rfc3447.txt SP800-38A NIST Special Publication 800-38A - Recommendation for Block Cipher Modes of Operation Methods and Techniques December 2001 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication80038a.pdf © 2024 SUSE, LLC / atsec information security corporation.

37 of 38

Page 38

SP800-38B NIST Special Publication 800-38B - Recommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication May 2005 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38b.pdf SP800-38C NIST Special Publication 800-38C - Recommendation for Block Cipher Modes of Operation: the CCM Mode for Authentication and Confidentiality May 2004 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication80038c.pdf SP800-38E NIST Special Publication 800-38E - Recommendation for Block Cipher Modes of Operation: The XTS AES Mode for Confidentiality on Storage Devices January 2010 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication80038e.pdf SP800-38F NIST Special Publication 800-38F - Recommendation for Block Cipher Modes of Operation: Methods for Key Wrapping December 2012 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38F.pdf SP800-90Arev1 NIST Special Publication 800-90A Revision 1 - Recommendation for Random Number Generation Using Deterministic Random Bit Generators June 2015 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90Ar1.pdf SP800-90B NIST Special Publication 800-90B - Recommendation for the Entropy Sources Used for Random Bit Generation January 2018 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90B.pdf SP800-132 NIST Special Publication 800-132 - Recommendation for PasswordBased Key Derivation - Part 1: Storage Applications December 2010 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800132.pdf SP800-133rev2 NIST Special Publication 800-133 - Recommendation for Cryptographic Key Generation June 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-133r2.pdf SP800-140B NIST Special Publication 800-140B - CMVP Security Policy Requirements March 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-140B.pdf © 2024 SUSE, LLC / atsec information security corporation.

38 of 38