All modules
CMVP Validated Module · FIPS 140-3 Security Policy

SUSE Linux Enterprise OpenSSL Cryptographic Module

Certificate#4725StandardFIPS 140-3Level1TypeSoftwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorSUSE, LLC
Medium review priority  ·  no TCB surface named  ·  OpenSSL upstream has published 40 CVEs since this module's initial validation  ·  last validated 7 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date7/11/2029
CaveatInterim validation. When operated in the approved mode. When installed, initialized and configured as specified in Section 11 of the Security Policy
VendorSUSE, LLC

Approved Algorithms (539)

AlgorithmACVP Cert
AES-CBCA3136
AES-CBCA3137
AES-CBCA3138
AES-CBCA3150
AES-CBCA3154
AES-CBCA3158
AES-CBCA3160
AES-CBCA3162
AES-CBCA3163
AES-CBCA3165
AES-CBCA3166
AES-CBCA3167
AES-CCMA3136
AES-CCMA3137
AES-CCMA3138
AES-CCMA3150
AES-CCMA3154
AES-CCMA3158
AES-CCMA3160
AES-CCMA3162
AES-CCMA3163
AES-CCMA3165
AES-CCMA3166
AES-CCMA3167
AES-CFB1A3136
AES-CFB1A3137
AES-CFB1A3138
AES-CFB1A3150
AES-CFB1A3154
AES-CFB1A3158
AES-CFB1A3160
AES-CFB1A3162
AES-CFB1A3163
AES-CFB1A3165
AES-CFB1A3166
AES-CFB1A3167
AES-CFB128A3136
AES-CFB128A3137
AES-CFB128A3138
AES-CFB128A3150
AES-CFB128A3154
AES-CFB128A3158
AES-CFB128A3160
AES-CFB128A3162
AES-CFB128A3163
AES-CFB128A3165
AES-CFB128A3166
AES-CFB128A3167
AES-CFB8A3136
AES-CFB8A3137
AES-CFB8A3138
AES-CFB8A3150
AES-CFB8A3154
AES-CFB8A3158
AES-CFB8A3160
AES-CFB8A3162
AES-CFB8A3163
AES-CFB8A3165
AES-CFB8A3166
AES-CFB8A3167
AES-CMACA3136
AES-CMACA3137
AES-CMACA3138
AES-CMACA3150
AES-CMACA3154
AES-CMACA3158
AES-CMACA3160
AES-CMACA3162
AES-CMACA3163
AES-CMACA3165
AES-CMACA3166
AES-CMACA3167
AES-CTRA3136
AES-CTRA3137
AES-CTRA3138
AES-CTRA3150
AES-CTRA3154
AES-CTRA3158
AES-CTRA3160
AES-CTRA3162
AES-CTRA3163
AES-CTRA3165
AES-CTRA3166
AES-CTRA3167
AES-ECBA3136
AES-ECBA3137
AES-ECBA3138
AES-ECBA3140
AES-ECBA3141
AES-ECBA3142
AES-ECBA3143
AES-ECBA3149
AES-ECBA3150
AES-ECBA3154
AES-ECBA3157
AES-ECBA3158
AES-ECBA3160
AES-ECBA3162
AES-ECBA3163
AES-ECBA3165
AES-ECBA3166
AES-ECBA3167
AES-ECBA3169
AES-ECBA3170
AES-ECBA3171
AES-ECBA3172
AES-GCMA3151
AES-GCMA3151
AES-GCMA3152
AES-GCMA3152
AES-GCMA3153
AES-GCMA3153
AES-GCMA3155
AES-GCMA3155
AES-GCMA3159
AES-GCMA3159
AES-GCMA3176
AES-GCMA3176
AES-GCMA3177
AES-GCMA3177
AES-GCMA3178
AES-GCMA3178
AES-GCMA3179
AES-GCMA3179
AES-GCMA3180
AES-GCMA3180
AES-GCMA3181
AES-GCMA3181
AES-GCMA3182
AES-GCMA3182
AES-GCMA3183
AES-GCMA3183
AES-GCMA3184
AES-GCMA3184
AES-GCMA3190
AES-GCMA3190
AES-GCMA3194
AES-GCMA3194
AES-GCMA3195
AES-GCMA3195
AES-GCMA3196
AES-GCMA3196
AES-GCMA3197
AES-GCMA3197
AES-GCMA3198
AES-GCMA3198
AES-GCMA3199
AES-GCMA3199
AES-GCMA3200
AES-GCMA3200
AES-GCMA3201
AES-GCMA3201
AES-GCMA3204
AES-GCMA3204
AES-GCMA3205
AES-GCMA3205
AES-GCMA3206
AES-GCMA3206
AES-KWA3136
AES-KWA3137
AES-KWA3138
AES-KWA3150
AES-KWA3154
AES-KWA3158
AES-KWA3160
AES-KWA3162
AES-KWA3163
AES-KWA3165
AES-KWA3166
AES-KWA3167
AES-KWPA3136
AES-KWPA3137
AES-KWPA3138
AES-KWPA3150
AES-KWPA3154
AES-KWPA3158
AES-KWPA3160
AES-KWPA3162
AES-KWPA3163
AES-KWPA3165
AES-KWPA3166
AES-KWPA3167
AES-OFBA3136
AES-OFBA3137
AES-OFBA3138
AES-OFBA3150
AES-OFBA3154
AES-OFBA3158
AES-OFBA3160
AES-OFBA3162
AES-OFBA3163
AES-OFBA3165
AES-OFBA3166
AES-OFBA3167
AES-XTS Testing Revision 2.0A3136
AES-XTS Testing Revision 2.0A3137
AES-XTS Testing Revision 2.0A3138
AES-XTS Testing Revision 2.0A3150
AES-XTS Testing Revision 2.0A3154
AES-XTS Testing Revision 2.0A3158
AES-XTS Testing Revision 2.0A3160
AES-XTS Testing Revision 2.0A3162
AES-XTS Testing Revision 2.0A3163
AES-XTS Testing Revision 2.0A3165
AES-XTS Testing Revision 2.0A3166
AES-XTS Testing Revision 2.0A3167
Counter DRBGA3136
Counter DRBGA3137
Counter DRBGA3138
Counter DRBGA3150
Counter DRBGA3154
Counter DRBGA3158
Counter DRBGA3160
Counter DRBGA3162
Counter DRBGA3163
Counter DRBGA3165
Counter DRBGA3166
Counter DRBGA3167
ECDSA KeyGen (FIPS186-4)A3147
ECDSA KeyGen (FIPS186-4)A3156
ECDSA KeyGen (FIPS186-4)A3185
ECDSA KeyGen (FIPS186-4)A3186
ECDSA KeyGen (FIPS186-4)A3187
ECDSA KeyGen (FIPS186-4)A3188
ECDSA KeyGen (FIPS186-4)A3193
ECDSA KeyGen (FIPS186-4)A3202
ECDSA KeyGen (FIPS186-4)A3203
ECDSA KeyGen (FIPS186-4)A3210
ECDSA KeyVer (FIPS186-4)A3147
ECDSA KeyVer (FIPS186-4)A3156
ECDSA KeyVer (FIPS186-4)A3185
ECDSA KeyVer (FIPS186-4)A3186
ECDSA KeyVer (FIPS186-4)A3187
ECDSA KeyVer (FIPS186-4)A3188
ECDSA KeyVer (FIPS186-4)A3193
ECDSA KeyVer (FIPS186-4)A3202
ECDSA KeyVer (FIPS186-4)A3203
ECDSA KeyVer (FIPS186-4)A3210
ECDSA SigGen (FIPS186-4)A3144
ECDSA SigGen (FIPS186-4)A3145
ECDSA SigGen (FIPS186-4)A3146
ECDSA SigGen (FIPS186-4)A3147
ECDSA SigGen (FIPS186-4)A3148
ECDSA SigGen (FIPS186-4)A3156
ECDSA SigGen (FIPS186-4)A3173
ECDSA SigGen (FIPS186-4)A3174
ECDSA SigGen (FIPS186-4)A3175
ECDSA SigGen (FIPS186-4)A3185
ECDSA SigGen (FIPS186-4)A3186
ECDSA SigGen (FIPS186-4)A3187
ECDSA SigGen (FIPS186-4)A3188
ECDSA SigGen (FIPS186-4)A3193
ECDSA SigGen (FIPS186-4)A3202
ECDSA SigGen (FIPS186-4)A3203
ECDSA SigGen (FIPS186-4)A3210
ECDSA SigVer (FIPS186-4)A3144
ECDSA SigVer (FIPS186-4)A3145
ECDSA SigVer (FIPS186-4)A3146
ECDSA SigVer (FIPS186-4)A3147
ECDSA SigVer (FIPS186-4)A3148
ECDSA SigVer (FIPS186-4)A3156
ECDSA SigVer (FIPS186-4)A3173
ECDSA SigVer (FIPS186-4)A3174
ECDSA SigVer (FIPS186-4)A3175
ECDSA SigVer (FIPS186-4)A3185
ECDSA SigVer (FIPS186-4)A3186
ECDSA SigVer (FIPS186-4)A3187
ECDSA SigVer (FIPS186-4)A3188
ECDSA SigVer (FIPS186-4)A3193
ECDSA SigVer (FIPS186-4)A3202
ECDSA SigVer (FIPS186-4)A3203
ECDSA SigVer (FIPS186-4)A3210
HMAC-SHA-1A3147
HMAC-SHA-1A3156
HMAC-SHA-1A3185
HMAC-SHA-1A3186
HMAC-SHA-1A3187
HMAC-SHA-1A3188
HMAC-SHA-1A3193
HMAC-SHA-1A3202
HMAC-SHA-1A3203
HMAC-SHA-1A3210
HMAC-SHA2-224A3147
HMAC-SHA2-224A3156
HMAC-SHA2-224A3185
HMAC-SHA2-224A3186
HMAC-SHA2-224A3187
HMAC-SHA2-224A3188
HMAC-SHA2-224A3193
HMAC-SHA2-224A3202
HMAC-SHA2-224A3203
HMAC-SHA2-224A3210
HMAC-SHA2-256A3147
HMAC-SHA2-256A3156
HMAC-SHA2-256A3161
HMAC-SHA2-256A3185
HMAC-SHA2-256A3186
HMAC-SHA2-256A3187
HMAC-SHA2-256A3188
HMAC-SHA2-256A3193
HMAC-SHA2-256A3202
HMAC-SHA2-256A3203
HMAC-SHA2-256A3210
HMAC-SHA2-384A3147
HMAC-SHA2-384A3156
HMAC-SHA2-384A3185
HMAC-SHA2-384A3186
HMAC-SHA2-384A3187
HMAC-SHA2-384A3188
HMAC-SHA2-384A3193
HMAC-SHA2-384A3202
HMAC-SHA2-384A3203
HMAC-SHA2-384A3210
HMAC-SHA2-512A3147
HMAC-SHA2-512A3156
HMAC-SHA2-512A3185
HMAC-SHA2-512A3186
HMAC-SHA2-512A3187
HMAC-SHA2-512A3188
HMAC-SHA2-512A3193
HMAC-SHA2-512A3202
HMAC-SHA2-512A3203
HMAC-SHA2-512A3210
HMAC-SHA3-224A3144
HMAC-SHA3-224A3145
HMAC-SHA3-224A3146
HMAC-SHA3-224A3148
HMAC-SHA3-224A3173
HMAC-SHA3-224A3174
HMAC-SHA3-224A3175
HMAC-SHA3-256A3144
HMAC-SHA3-256A3145
HMAC-SHA3-256A3146
HMAC-SHA3-256A3148
HMAC-SHA3-256A3173
HMAC-SHA3-256A3174
HMAC-SHA3-256A3175
HMAC-SHA3-384A3144
HMAC-SHA3-384A3145
HMAC-SHA3-384A3146
HMAC-SHA3-384A3148
HMAC-SHA3-384A3173
HMAC-SHA3-384A3174
HMAC-SHA3-384A3175
HMAC-SHA3-512A3144
HMAC-SHA3-512A3145
HMAC-SHA3-512A3146
HMAC-SHA3-512A3148
HMAC-SHA3-512A3173
HMAC-SHA3-512A3174
HMAC-SHA3-512A3175
KAS-ECC-SSC Sp800-56Ar3A3147
KAS-ECC-SSC Sp800-56Ar3A3156
KAS-ECC-SSC Sp800-56Ar3A3185
KAS-ECC-SSC Sp800-56Ar3A3186
KAS-ECC-SSC Sp800-56Ar3A3187
KAS-ECC-SSC Sp800-56Ar3A3188
KAS-ECC-SSC Sp800-56Ar3A3193
KAS-ECC-SSC Sp800-56Ar3A3202
KAS-ECC-SSC Sp800-56Ar3A3203
KAS-ECC-SSC Sp800-56Ar3A3210
KAS-FFC-SSC Sp800-56Ar3A3207
KAS-FFC-SSC Sp800-56Ar3A3211
KDA HKDF Sp800-56Cr1A3139
KDA HKDF Sp800-56Cr1A3168
KDF SSHA3140
KDF SSHA3141
KDF SSHA3142
KDF SSHA3143
KDF SSHA3149
KDF SSHA3157
KDF SSHA3169
KDF SSHA3170
KDF SSHA3171
KDF SSHA3172
KDF TLSA3147
KDF TLSA3156
KDF TLSA3185
KDF TLSA3186
KDF TLSA3187
KDF TLSA3188
KDF TLSA3193
KDF TLSA3202
KDF TLSA3203
KDF TLSA3210
PBKDFA3144
PBKDFA3145
PBKDFA3146
PBKDFA3147
PBKDFA3148
PBKDFA3156
PBKDFA3173
PBKDFA3174
PBKDFA3175
PBKDFA3185
PBKDFA3186
PBKDFA3187
PBKDFA3188
PBKDFA3193
PBKDFA3202
PBKDFA3203
PBKDFA3210
RSA KeyGen (FIPS186-4)A3147
RSA KeyGen (FIPS186-4)A3156
RSA KeyGen (FIPS186-4)A3185
RSA KeyGen (FIPS186-4)A3186
RSA KeyGen (FIPS186-4)A3187
RSA KeyGen (FIPS186-4)A3188
RSA KeyGen (FIPS186-4)A3193
RSA KeyGen (FIPS186-4)A3202
RSA KeyGen (FIPS186-4)A3203
RSA KeyGen (FIPS186-4)A3210
RSA SigGen (FIPS186-4)A3147
RSA SigGen (FIPS186-4)A3156
RSA SigGen (FIPS186-4)A3185
RSA SigGen (FIPS186-4)A3186
RSA SigGen (FIPS186-4)A3187
RSA SigGen (FIPS186-4)A3188
RSA SigGen (FIPS186-4)A3193
RSA SigGen (FIPS186-4)A3202
RSA SigGen (FIPS186-4)A3203
RSA SigGen (FIPS186-4)A3210
RSA SigVer (FIPS186-4)A3147
RSA SigVer (FIPS186-4)A3156
RSA SigVer (FIPS186-4)A3185
RSA SigVer (FIPS186-4)A3186
RSA SigVer (FIPS186-4)A3187
RSA SigVer (FIPS186-4)A3188
RSA SigVer (FIPS186-4)A3193
RSA SigVer (FIPS186-4)A3202
RSA SigVer (FIPS186-4)A3203
RSA SigVer (FIPS186-4)A3210
Safe Primes Key GenerationA3207
Safe Primes Key GenerationA3211
Safe Primes Key VerificationA3207
Safe Primes Key VerificationA3211
SHA-1A3147
SHA-1A3156
SHA-1A3185
SHA-1A3186
SHA-1A3187
SHA-1A3188
SHA-1A3193
SHA-1A3202
SHA-1A3203
SHA-1A3210
SHA2-224A3147
SHA2-224A3156
SHA2-224A3185
SHA2-224A3186
SHA2-224A3187
SHA2-224A3188
SHA2-224A3193
SHA2-224A3202
SHA2-224A3203
SHA2-224A3210
SHA2-256A3147
SHA2-256A3156
SHA2-256A3161
SHA2-256A3185
SHA2-256A3186
SHA2-256A3187
SHA2-256A3188
SHA2-256A3193
SHA2-256A3202
SHA2-256A3203
SHA2-256A3210
SHA2-384A3147
SHA2-384A3156
SHA2-384A3185
SHA2-384A3186
SHA2-384A3187
SHA2-384A3188
SHA2-384A3193
SHA2-384A3202
SHA2-384A3203
SHA2-384A3210
SHA2-512A3147
SHA2-512A3156
SHA2-512A3185
SHA2-512A3186
SHA2-512A3187
SHA2-512A3188
SHA2-512A3193
SHA2-512A3202
SHA2-512A3203
SHA2-512A3210
SHA3-224A3144
SHA3-224A3145
SHA3-224A3146
SHA3-224A3148
SHA3-224A3173
SHA3-224A3174
SHA3-224A3175
SHA3-256A3144
SHA3-256A3145
SHA3-256A3146
SHA3-256A3148
SHA3-256A3173
SHA3-256A3174
SHA3-256A3175
SHA3-384A3144
SHA3-384A3145
SHA3-384A3146
SHA3-384A3148
SHA3-384A3173
SHA3-384A3174
SHA3-384A3175
SHA3-512A3144
SHA3-512A3145
SHA3-512A3146
SHA3-512A3148
SHA3-512A3173
SHA3-512A3174
SHA3-512A3175
SHAKE-128A3144
SHAKE-128A3145
SHAKE-128A3146
SHAKE-128A3148
SHAKE-128A3173
SHAKE-128A3174
SHAKE-128A3175
SHAKE-256A3144
SHAKE-256A3145
SHAKE-256A3146
SHAKE-256A3148
SHAKE-256A3173
SHAKE-256A3174
SHAKE-256A3175
TLS v1.2 KDF RFC7627A3147
TLS v1.2 KDF RFC7627A3156
TLS v1.2 KDF RFC7627A3185
TLS v1.2 KDF RFC7627A3186
TLS v1.2 KDF RFC7627A3187
TLS v1.2 KDF RFC7627A3188
TLS v1.2 KDF RFC7627A3193
TLS v1.2 KDF RFC7627A3202
TLS v1.2 KDF RFC7627A3203
TLS v1.2 KDF RFC7627A3210

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for SUSE Linux Enterprise OpenSSL Cryptographic Module
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>update</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>Status Output<br/>Show status</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>SSH<br/>IKEV</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for SUSE Linux Enterprise OpenSSL Cryptographic Module
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>update</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>Status Output<br/>Show status</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>SSH<br/>IKEV</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

SUSE Linux Enterprise OpenSSL Cryptographic Module version 4.4 Version 1.3 Last update: 2025-07-29 Prepared by: atsec information security corporation

4516 Seton Center Parkway, Suite 250

Austin, TX 78759 www.atsec.com © 2025 SUSE, LLC / atsec information security.

Page 2
1 Table of Contents

2.8 Non-Approved Algorithms Allowed in the Approved Mode of Operation with No Security

© 2025 SUSE, LLC / atsec information security.

2 of 56

Page 3

© 2025 SUSE, LLC / atsec information security.

3 of 56

Page 4
ISO/IEC 24759 Section 6. [Number Below]FIPS 140-3 Section TitleSecurity Level
1General1
2Cryptographic Module Specification1
3Cryptographic Module Interfaces1
4Roles, Services, and Authentication1
5Software/Firmware Security1
6Operational Environment1
7Physical SecurityN/A
8Non-invasive SecurityN/A
9Sensitive Security Parameter Management1
10Self-tests1
11Life-cycle Assurance1
12Mitigation of Other Attacks1

This document is the non-proprietary FIPS 140-3 Security Policy for version 4.4 of the SUSE Linux Enterprise OpenSSL Cryptographic Module. It has a one-to-one mapping to the [SP800-140B] starting with section B.2.1 named “General” that maps to section 1 in this document and ending with section B.2.12 named “Mitigation of other attacks” that maps to section 12 in this document. Table 1 - Security Levels © 2025 SUSE, LLC / atsec information security.

4 of 56

Page 5
2 Cryptographic Module Specification
2.1 Module Embodiment

The SUSE Linux Enterprise OpenSSL Cryptographic Module (hereafter referred to as “the module”) is a Software multi-chip standalone cryptographic module.

2.2 Module Design, Components, Versions

The software block diagram below shows the cryptographic boundary of the module, and its interfaces with the operational environment. Figure 1 - Cryptographic boundary Table 2 lists the software components of the cryptographic module, which defines its cryptographic boundary. © 2025 SUSE, LLC / atsec information security.

5 of 56

Page 6
ComponentsDescription
libcrypto.so.1.1Shared library for cryptographic algorithms.
.libcrypto.so.1.1.hmacIntegrity check HMAC value for the libcrypto shared library.
libssl.so.1.1Shared library for TLS/DTLS network protocols.
.libssl.so.1.1.hmacIntegrity check HMAC value for the libssl shared library.
#Operating SystemHardware PlatformProcessorPAA/AccelerationModule version
1SUSE Linux Enterprise Server 15 SP4Supermicro Super Server SYS-6019P-WTRIntel® Xeon® Silver 4215RWith and without AES-NI (PAA)32-bit 64-bit
2SUSE Linux Enterprise Server 15 SP4GIGABYTE R181- Z90-00AMD EPYCÔ 7371With and without AES-NI (PAA)64-bit
3SUSE Linux Enterprise Server 15 SP4GIGABYTE G242- P32-QZARM Ampere® Altra® Q80-30With and without Cryptography Extensions (PAA)64-bit
4SUSE Linux Enterprise Server 15 SP4IBM z/15z15With and without CPACF (PAI)64-bit
5SUSE Linux Enterprise Server 15 SP4 on PowerVM (VIOS 3.1.4.00)IBM Power E1080 (9080- HEX)Power10With and without ISA (PAA)64-bit
2.3 Modes of operation

When the module starts up successfully, after passing all the pre-operational and conditional cryptographic algorithms self-tests (CASTs), the module is operating in the approved mode of operation by default and can only be transitioned into the non-Approved mode by calling one of the non-Approved services listed in Table 12. Please see section 4 for the details on service indicator provided by the module that identifies when an approved service is called.

2.4 Tested Operational Environments

The module has been tested on the following platforms with the corresponding module variants and configuration options: Table 3 - Tested Operational Environments

2.5 Vendor-Affirmed Operational Environments

In addition to the platforms listed in Table 3, SUSE has also tested the module on the platforms in Table 4 and Table 5, and claims vendor affirmation on them. Note: the CMVP makes no statement as to the correct operation of the module or the security strengths of the generated keys when so ported if the specific operational environment is not listed on the validation certificate. © 2025 SUSE, LLC / atsec information security.

6 of 56

Page 7
#Operating SystemHardware PlatformProcessorPAA/Acceleration
1SUSE Linux Enterprise Server 15SP4IBM LinuxONE III LT1z15With and without CPACF (PAI)
2SUSE Linux Enterprise Micro 5.3Supermicro Super Server SYS-6019P- WTRIntel® Xeon® Silver 4215RWith and without AES-NI (PAA)
3SUSE Linux Enterprise Micro 5.3GIGABYTE R181- Z90-00AMD EPYCÔ 7371With and without AES-NI (PAA)
4SUSE Linux Enterprise Micro 5.3GIGABYTE G242- P32-QZARM Ampere® Altra® Q80- 30With and without Cryptography Extensions (PAA)
5SUSE Linux Enterprise Micro 5.3IBM z/15z15With and without CPACF (PAI)
6SUSE Linux Enterprise Micro 5.3IBM LinuxONE III LT1z15With and without CPACF (PAI)
7SUSE Linux Enterprise Server for SAP 15SP4Supermicro Super Server SYS-6019P- WTRIntel® Xeon® Silver 4215RWith and without AES-NI (PAA)
8SUSE Linux Enterprise Server for SAP 15SP4GIGABYTE R181- Z90-00AMD EPYCÔ 7371With and without AES-NI (PAA)
9SUSE Linux Enterprise Server for SAP 15SP4 on PowerVM (VIOS 3.1.4.00)IBM Power E1080 (9080-HEX)Power10With and without ISA (PAA)
10SUSE Linux Enterprise Base Container Image 15SP4Supermicro Super Server SYS-6019P- WTRIntel® Xeon® Silver 4215RWith and without AES-NI (PAA)
11SUSE Linux Enterprise Base Container Image 15SP4GIGABYTE R181- Z90-00AMD EPYCÔ 7371With and without AES-NI (PAA)
12SUSE Linux Enterprise Base Container Image 15SP4GIGABYTE G242- P32-QZARM Ampere® Altra® Q80- 30With and without Cryptography Extensions (PAA)
13SUSE Linux Enterprise Base Container Image 15SP4IBM z/15z15With and without CPACF (PAI)
14SUSE Linux Enterprise Base Container Image 15SP4IBM LinuxONE III LT1z15With and without CPACF (PAI)
15SUSE Linux Enterprise Base Container Image 15SP4 on PowerVM (VIOS 3.1.4.00)IBM Power E1080 (9080-HEX)Power10With and without ISA (PAA)
2.5.1 OpenSSL 64-bit Vendor Affirmed Operational Environments

© 2025 SUSE, LLC / atsec information security.

7 of 56

Page 8
#Operating SystemHardware PlatformProcessorPAA/Acceleration
16SUSE Linux Enterprise Desktop 15SP4Supermicro Super Server SYS-6019P- WTRIntel® Xeon® Silver 4215RWith and without AES-NI (PAA)
17SUSE Linux Enterprise Desktop 15SP4GIGABYTE R181- Z90-00AMD EPYCÔ 7371With and without AES-NI (PAA)
18SUSE Linux Enterprise Real Time 15SP4Supermicro Super Server SYS-6019P- WTRIntel® Xeon® Silver 4215RWith and without AES-NI (PAA)
19SUSE Linux Enterprise Real Time 15SP4GIGABYTE R181- Z90-00AMD EPYCÔ 7371With and without AES-NI (PAA)
#Operating SystemHardware PlatformProcessorPAA/Acceleration
1SUSE Linux Enterprise Server 15SP4GIGABYTE R181- Z90-00AMD EPYCÔ 7371With and without AES-NI (PAA)
2SUSE Linux Enterprise Server for SAP 15SP4Supermicro Super Server SYS- 6019P-WTRIntel® Xeon® Silver 4215RWith and without AES-NI (PAA)
3SUSE Linux Enterprise Server for SAP 15SP4GIGABYTE R181- Z90-00AMD EPYCÔ 7371With and without AES-NI (PAA)
4SUSE Linux Enterprise Desktop 15SP4Supermicro Super Server SYS- 6019P-WTRIntel® Xeon® Silver 4215RWith and without AES-NI (PAA)
5SUSE Linux Enterprise Desktop 15SP4GIGABYTE R181- Z90-00AMD EPYCÔ 7371With and without AES-NI (PAA)
6SUSE Linux Enterprise Real Time 15SP4Supermicro Super Server SYS- 6019P-WTRIntel® Xeon® Silver 4215RWith and without AES-NI (PAA)
7SUSE Linux Enterprise Real Time 15SP4GIGABYTE R181- Z90-00AMD EPYCÔ 7371With and without AES-NI (PAA)

Table 4 - Vendor-Affirmed Operational Environments for OpenSSL (64-bit)

2.5.2 OpenSSL 32-bit Vendor Affirmed Operational Environments

Table 5 - Vendor-Affirmed Operational Environments for OpenSSL (32-bit)

2.6 Approved Algorithms

Table 6 lists all the approved security functions of the module, including specific key strengths employed for approved services. © 2025 SUSE, LLC / atsec information security.

8 of 56

Page 9
CAVP CertAlgorithm and StandardMode/MethodDescription / Key Size(s) / Key Strength(s)Use / Function
A3136, A3137,AESCBC, CCM, CFB1,128, 192, 256-bit keys withSymmetric
A3138, A3150,FIPS197,CFB8, CFB128,128-256 bits of securityencryption;
A3154, A3158,SP800-38A,CTR, OFBstrengthSymmetric
A3160, A3162, A3163, A3165, A3166, A3167SP800-38Cdecryption
A3136, A3137,AESCMAC128, 192, 256-bit keys withMessage
A3138, A3150,SP800-38B128-256 bits of securityauthentication
A3154, A3158, A3160, A3162, A3163, A3165, A3166, A3167strengthcode (MAC)
A3136, A3137,AESECB128, 192, 256-bit keys withSymmetric
A3138, A3140,FIPS197,128-256 bits of securityencryption;
A3141, A3142,SP800-38AstrengthSymmetric
A3143, A3149, A3150, A3154, A3157, A3158, A3160, A3162, A3163, A3165, A3166, A3167, A3169, A3170, A3171, A3172decryption
A3151, A3152,AESGCM with internal128, 192, 256-bit keys withSymmetric
A3153, A3155,SP800-38DIV128-256 bits of securityencryption;
A3159, A3176,(IV Gen ModestrengthSymmetric
A3177, A3178, A3179, A3180, A3181, A3182, A3183, A3184, A3190, A3194, A3195, A3196, A3197, A3198, A3199, A3200, A3201, A3204, A3205, A32068.2.1)decryption

© 2025 SUSE, LLC / atsec information security.

9 of 56

Page 10
CAVP CertAlgorithm and StandardMode/MethodDescription / Key Size(s) / Key Strength(s)Use / Function
A3151, A3152,AESGCM with128, 192, 256-bit keys withSymmetric decryption
A3153, A3155,SP800-38Dexternal IV128-256 bits of security
A3159, A3176, A3177, A3178, A3179, A3180, A3181, A3182, A3183, A3184, A3190, A3194, A3195, A3196, A3197, A3198, A3199, A3200, A3201, A3204, A3205, A3206(IV Gen Mode 8.2.1)strength
A3136, A3137,AESKW, KWP128, 192, 256-bit keys withKey wrapping and unwrapping
A3138, A3150,SP800-38F128-256 bits of security
A3154, A3158, A3160, A3162, A3163, A3165, A3166, A3167strength
A3136, A3137,AESXTS128, 256-bit keys with 128-Symmetric encryption; Symmetric decryption (for data storage)
A3138, A3150, A3154, A3158, A3160, A3162, A3163, A3165, A3166, A3167SP800-38E256 bits of security strength
VendorCKGFIPS186-4, SP800-RSA: 2048 to 16384-bit keysKey pair generation
AffirmedSP800-133rev256Arev3, SP800-with 112-256 bits of security
90Arev1strength ECDSA: P-224, P-256, P-384, P- 521-bit keys with 112-256 bits of security strength Safe Primes: 2048, 3072, 4096, 6144, 8192-bit keys with 112-200 bits of security strength
A3136, A3137,DRBGCTR_DRBG:128, 192, 256-bit keys withRandom number generation
A3138, A3150,SP800-90Arev1AES-128, AES-128, 192 and 256 bits of
A3154, A3158,192, AES-256security strength
A3160, A3162, A3163, A3165, A3166, A3167with/without DF, with/without PR
A3147, A3156,ECDSAB.4.2 TestingP-224, P-256, P-384, P-521Key pair generation
A3185, A3186,FIPS186-4Candidateswith 112-256 bits of security
A3187, A3188,strength

© 2025 SUSE, LLC / atsec information security.

10 of 56

Page 11
CAVP Cert A3193, A3202, A3203, A3210 A3144, A3145, A3146, A3147, A3148, A3156, A3173, A3174, A3175, A3185, A3186, A3187, A3188, A3193, A3202, A3203, A3210Algorithm and StandardMode/Method N/A SHA2-224, SHA2- 256, SHA2-384, SHA2-512 SHA3-224, SHA3- 256, SHA3-384, SHA3-512 SHA-1, SHA2-224, SHA2-256, SHA2- 384, SHA2-512 SHA3-224, SHA3- 256, SHA3-384, SHA3-512Description / Key Size(s) / Key Strength(s) P-224, P-256, P-384, P-521 with 112-256 bits of security strength P-224, P-256, P-384, P-521 with 112-256 bits of security strength P-192, P-224, P-256, P-384, P- 521 with 80-256 bits of security strengthUse / Function Key pair validation, ECDSA Public key validation Digital signature generation Digital signature verification (usage of P-192 curve or SHA-1 are considered Legacy Use)
E22, E28, E29, E30ESV SP800-90BN/AN/AEntropy source
A3147, A3156,HMACSHA-1, SHA2-224,³ 112-bit keys with 112-256Message
A3185, A3186,FIPS198-1SHA2-256, SHA2-bits of security strengthauthentication
A3187, A3188, A3193, A3202, A3203, A3210384, SHA2-512code (MAC)
A3161SHA2-256
A3144, A3145,SHA3-224, SHA3-³ 112-bit keys with 112 -256Message
A3146, A3148,256, SHA3-384,bits of security strengthauthentication
A3173, A3174, A3175SHA3-512code (MAC)
A3147, A3156,KAS-ECC-SSCECCP-224, P-256, P-384, P-521(EC Diffie-
A3185, A3186,with 112-256 bits of securityHellman) Key
SP800-56Arev3Ephemeral
A3187, A3188, A3193, A3202, A3203, A3210Unified Schemestrengthagreement
A3207, A3211KAS-FFC-SSCdhEphem SchemeMODP-2048, MODP-3072,(Diffie-Hellman)
SP800-56Arev3with safe primeMODP-4096, MODP-6144,key agreement
groupsMODP-8192, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192 with keys with 112-200 bits of security strength

© 2025 SUSE, LLC / atsec information security.

11 of 56

Page 12
CAVP CertAlgorithm and StandardMode/MethodDescription / Key Size(s) / Key Strength(s)Use / Function
CVL. A3139,KDA HKDFSHA2-224, SHA2-N/AKey derivation
A3168SP800-56Crev1256, SHA2-384,for TLS v1.3
SHA2-512used in the TLS protocol service
CVL. A3140,KDF SSHAES with SHA-1,128, 192, 256-bit keys withKey derivation
A3141, A3142,SP800-135rev1SHA2-256, SHA2-128-256 bits of security
A3143, A3149, A3157, A3169, A3170, A3171, A3172384, SHA2-512strength
CVL. A3147,KDF TLSTLS v1.0, v1.1,N/AKey derivation
A3156, A3185, A3186, A3187, A3188, A3193, A3202, A3203, A3210SP800-135rev1 RFC7627v1.2
A3136, A3137,KTSAES KW, KWP128, 192, 256-bit keys withKey wrapping;
A3138, A3150,SP800-38F128-256 bits of securityKey unwrapping
A3154, A3158, A3160, A3162, A3163, A3165, A3166, A3167strength
A3136, A3137,KTSAES CCM128, 256-bit keys with 128,Key wrapping
A3138, A3150,SP800-38C256 bits of security strengthand key
A3154, A3158,unwrapping (as
A3160, A3162,part of the
A3163, A3165,cipher suites in
A3166, A3167the TLS
A3151, A3152,KTSAES GCM128, 256-bit keys with 128,protocol)
A3153, A3155, A3159, A3176, A3177, A3178, A3179, A3180, A3181, A3182, A3183, A3184, A3190, A3194, A3195, A3196, A3197, A3198, A3199, A3200, A3201, A3204, A3205, A3206SP800-38D256 bits of security strength

© 2025 SUSE, LLC / atsec information security.

12 of 56

Page 13
CAVP Cert (AES) A3136, A3137, A3138, A3150, A3154, A3158, A3160, A3162, A3163, A3165, A3166, A3167 (HMAC) A3144, A3145, A3146, A3147, A3148, A3156, A3161, A3173, A3174, A3175, A3185, A3186, A3187, A3188, A3193, A3202, A3203, A3210Algorithm and Standard KTS SP800-38A, FIPS198-1Mode/Method AES CBC and HMACDescription / Key Size(s) / Key Strength(s) 128, 256-bit keys with 128, 256 bits of security strengthUse / Function
A3144, A3145,PBKDFHMAC-SHA-1,N/AKey derivation
A3146, A3147,SP800-132HMAC-SHA2-224,
A3148, A3156,HMAC-SHA2-256,
A3173, A3174,HMAC-SHA2-384,
A3175, A3185,HMAC-SHA2-512
A3186, A3187, A3188, A3193,HMAC-SHA3-224, HMAC-SHA3-256,
A3202, A3203, A3210HMAC-SHA3-384, HMAC-SHA3-512
A3147, A3156,RSAB.3.3 Random2048, 3072 and 4096-bit keysKey pair generation
A3185, A3186,FIPS186-4Probable Primeswith 112-149 bits of security
A3187, A3188,strength
A3193, A3202, A3203, A3210Key sizes greater than 4096 bits provide 150-256 bits of security strength.
Key sizes other thanPKCS#1v1.5:2048, 3072 and 4096-bit keysDigital signature generation
mentionedSHA2-224, SHA2-with 112-149 bits of security
here and up256, SHA2-384,strength
to 16384 bits are not CAVPSHA2-512
tested butPSS:2048, 3072 and 4096-bit keys
approved perSHA2-224, SHA2-with 112-149 bits of security
IG C.F256, SHA2-384, SHA2-512strength
X9.31: SHA2-256, SHA2-2048, 3072 and 4096-bit keys with 112-149 bits of security
384, SHA2-512strength

© 2025 SUSE, LLC / atsec information security.

13 of 56

Page 14
CAVP CertAlgorithm and StandardMode/Method PKCS#1v1.5: SHA-1, SHA2-224, SHA2-256, SHA2- 384, SHA2-512 PSS: SHA-1, SHA2-224, SHA2-256, SHA2- 384, SHA2-512 X9.31: SHA-1, SHA2-224, SHA2-256, SHA2- 384, SHA2-512Description / Key Size(s) / Key Strength(s) 1024, 2048, 3072 and 4096-bit keys with 80-149 bits of security strength 1024, 2048, 3072 and 4096-bit keys with 80-149 bits of security strength 1024, 2048, 3072 and 4096 keys with 80-149 bits of security strengthUse / Function Digital signature verification (usage of 1024- bit keys or SHA- 1 is considered Legacy Use)
A3207, A3211Safe PrimesSection 5.6.1.1.4MODP-2048, MODP-3072,Key pair
SP800-56Arev3TestingMODP-4096, MODP-6144,generation,
CandidatesMODP-8192, ffdhe2048,Diffie-Hellman
ffdhe3072, ffdhe4096,public key
ffdhe6144, ffdhe8192 keys with 112-200 bits of security strengthvalidation
A3144, A3145,SHA-3SHA3-224, SHA3-N/AMessage digest
A3146, A3148,FIPS202256, SHA3-384,
A3173, A3174,SHA3-512,
A3175SHAKE-128, SHAKE-256
A3147, A3156,SHSSHA-1, SHA2-224,N/AMessage digest
A3185, A3186,FIPS180-4SHA2-256, SHA2-
A3187, A3188, A3193, A3202, A3203, A3210384, SHA2-512
A3161SHA2-256
2.7 Non-Approved Algorithms Allowed in the Approved Mode

of Operation The module does not implement non-approved algorithms that are allowed in the approved mode of operation. © 2025 SUSE, LLC / atsec information security.

14 of 56

Page 15
Algorithm1CaveatUse/Function
MD5Only allowed as the PRF in TLSv1.0 and v1.1 per IG 2.4.AMessage digest used in TLSv1.0 / v1.1 KDF only
Algorithm/FunctionsUse/Function
AES(GCM) with external IVSymmetric encryption
ARIASymmetric encryption; Symmetric decryption
Blake2Message digest
BlowfishSymmetric encryption; Symmetric decryption
CamelliaSymmetric encryption; Symmetric decryption
CASTSymmetric encryption; Symmetric decryption
CAST5Symmetric encryption; Symmetric decryption
ChaCha20Symmetric encryption; Symmetric decryption
DESSymmetric encryption; Symmetric decryption
Chacha20 and Poly1305Authenticated encryption; Authenticated decryption
CMAC with Triple-DESMessage authentication code (MAC)
Diffie-Hellman with keys generated with domain parameters other than safe primesKey pair generation; Diffie-Hellman public key validation; Key agreement; Shared secret computation
DSA with any key sizesKey pair generation; Domain parameter generation, Digital signature generation; Digital signature verification
2.8 Non-Approved Algorithms Allowed in the Approved Mode

of Operation with No Security Claimed Table 7 lists the non-approved algorithms that are allowed in the approved mode of operation with no security claimed. These algorithms are used by the approved services listed in Table 10. Table 7 - Non-Approved Algorithms Allowed in the Approved Mode of Operation with No Security Claimed

2.9 Non-Approved Algorithms Not Allowed in the Approved

Mode of Operation Table 8 lists non-approved algorithms that are not allowed in the approved mode of operation. These algorithms are used by the non-approved services listed in Table 12.

1 These algorithms do not claim any security and are not used to meet FIPS 140-3 requirements. Therefore, SSPs do not

map to these algorithms. © 2025 SUSE, LLC / atsec information security.

15 of 56

Page 16
Algorithm/FunctionsUse/Function
EC Diffie-Hellman with P-192 curve, K curves, B curves and non-NIST curvesKey agreement; Shared secret computation
ECDSA with P-192 curve, K curves, B curves and non-NIST curvesKey pair generation; Key pair validation; ECDSA public key validation
ECDSA with P-192 curve, K curves, B curves and non-NIST curvesDigital signature generation; Digital signature verification
GHASHMessage digest
GostMessage digest
HKDFKey derivation as a standalone service
HMAC with less than 112-bit keysMessage authentication Code (MAC)
KDF SSH using Triple-DESKey derivation
MD4Message digest
MD5Message digest
MDC2Message digest
Multiblock ciphers using AES in CBC mode with 128- and 256-bit keys and HMAC SHA-1 and SHA2-256 (available only in Intel processors with AES-NI capability)Authenticated encryption; Authenticated decryption
PBKDF with non-approved message digest algorithms or using input parameters not meeting requirements stated in section 11.2.4Key derivation
RC2Symmetric encryption; Symmetric decryption
RC4Symmetric encryption; Symmetric decryption
RMD160Message digest
RSA with keys smaller than 2048 bitsKey pair generation; Domain parameter verification; Digital signature generation
RSA with keys smaller than 1024 bitsDigital signature verification
RSA encryption and decryption with any key sizesKey encapsulation
SEEDSymmetric encryption; Symmetric decryption
SHA-1Digital signature generation
SipHashMessage authentication code (MAC)
SM3Message digest
SM4Symmetric encryption; Symmetric decryption
Triple-DESSymmetric encryption; Symmetric decryption

Table 8 - Non-Approved Algorithms Not Allowed in the Approved Mode of Operation © 2025 SUSE, LLC / atsec information security.

16 of 56

Page 17
Logical InterfaceData that passes over port/interface
Data InputAPI input parameters, kernel I/O network or files on filesystem, TLS protocol input messages.
Data OutputAPI output parameters, kernel I/O network or files on filesystem, TLS protocol output messages.
Control InputAPI function calls, API input parameters for control.
Status OutputAPI return codes, API output parameters for status output.
3 Cryptographic Module Ports and Interfaces

As a software-only module, the module does not have physical ports. The operator can only interact with the module through the API provided by the module. Thus, the physical ports are interpreted to be the physical ports of the hardware platform on which the module runs. The following table shows the logical interfaces implemented in the module. All data output via data output interface is inhibited when the module is performing preoperational test or zeroization or when the module enters error state. Table 9 - Ports and Interfaces Note: The module does not implement a control output interface. © 2025 SUSE, LLC / atsec information security.

17 of 56

Page 18
RoleServiceInputOutput
Crypto Officer (CO)Symmetric encryptionPlaintext, keyCiphertext
Symmetric decryptionCiphertext, keyPlaintext
Authenticated encryptionPlaintext, keyCiphertext, authentication tag
Authenticated decryptionCiphertext, authentication tag, keyPlaintext
Key pair generationKey sizeKey pair
Domain parameter generationKey sizeDomain parameters
Domain parameter verificationDomain parametersReturn codes/log messages
Key pair validationKey pairReturn codes/log messages
Key agreementKey pairShared secret
Digital signature generationMessage, hash algorithm, private keySignature
Digital signature verificationSignature, hash algorithm, public keySignature verification result
Random number generationSizeRandom number
Message digestMessageMessage digest
Message authentication code (MAC)Message, keyMessage authentication code
Key wrappingKey to be wrapped, key wrapping keyWrapped key
Key unwrappingWrapped key, key unwrapping keyUnwrapped key
4 Roles, services, and authentication
4.1 Services

The module supports the Crypto Officer role only. This sole role is implicitly assumed by the operator of the module when performing a service. The module does not support © 2025 SUSE, LLC / atsec information security.

18 of 56

Page 19

Role

Service Key encapsulation Shared secret computation Diffie-Hellman key generation using safe primes Public key validation TLS Key derivation SSH Key Derivation PBKDF Key Derivation HKDF Key Derivation Show status Zeroization Self-test On-demand integrity test Module installation and configuration Module initialization Show module name and version Transport Layer Security (TLS) network protocol

Input Key to be encapsulated, key encapsulating key Private key, public key from peer Safe prime Public key TLS pre-master secret Shared secret Password/passphrase Shared secret None Context containing SSPs Module reset None None None None Application data

Output Encapsulated key Shared secret Key pair Return codes/log messages Derived key Derived key Derived key Derived key Return codes/log messages None Self-test results Self-test results Log messages Log messages Name and version of the module Application data

Table 10 - Roles, Service Commands, Input and Output The module provides services to the users that assume one of the available roles. All services are shown in Table 11 and Table 12.

4.2 Approved Services

Table 11 lists the approved services. For each service, the table lists the associated cryptographic algorithm(s), the role to perform the service, the cryptographic keys or SSPs involved, and their access type(s). No support of intermediate key generation is provided. The following convention is used to specify access rights to an SSP: © 2025 SUSE, LLC / atsec information security.

19 of 56

Page 20
Service Cryptographic ServicesDescriptionApproved Security FunctionsKeys and/or SSPsRolesAccess rights to Keys and/or SSPsIndicator
Symmetric encryptionPerform AES encryptionAESAES keyCOW, Efips_sli_is_approved_EVP _CIPHER_CTX returns 1
Symmetric decryptionPerform AES decryptionAESAES keyW, Efips_sli_is_approved_EVP _CIPHER_CTX returns 1
Key pair generationGenerate RSA key pairsRSA, DRBGRSA public key, RSA private keyE, G, Rfips_sli_is_approved_EVP _PKEY_CTX returns 1
Generate ECDSA key pairsECDSA, DRBGECDSA public key, ECDSA private keyE, G, Rfips_sli_is_approved_EVP _PKEY_CTX returns 1
Digital signature generationSign using RSARSA, SHSRSA private keyW, Efips_sli_is_approved_EVP _PKEY_CTX returns 1
Sign using ECDSAECDSA, DRBG, SHSECDSA private keyW, Efips_sli_is_approved_EVP _PKEY_CTX returns 1
Digital signature verificationVerify RSA signaturesRSA, SHSRSA public keyW, Efips_sli_is_approved_EVP _PKEY_CTX returns 1
Verify ECDSA signaturesECDSA, SHSECDSA public keyW, Efips_sli_is_approved_EVP _PKEY_CTX returns 1

20 of 56

Page 21

Service Key pair validation ECDSA public key validation Random number generation Message digest Message authentication code (MAC) Key wrapping Key unwrapping Shared secret computation

Description Validate ECDSA public key Validate ECDSA public key Generate random bitstrings Compute SHA hashes Compute HMAC Compute and AES-based CMAC Perform AES- based key wrapping Perform AES- based key unwrapping Diffie-Hellman shared secret computation EC Diffie- Hellman shared secret computation

Approved Security Functions ECDSA ECDSA DRBG SHA-1, SHA2- 224, SHA2-256, SHA2-384, SHA2-512 SHA3-224, SHA3-256, SHA3-384, SHA3-512 HMAC CMAC with AES AES-KW, AES- KWP AES-KW, AES- KWP KAS-FFC-SSC KAS-ECC-SSC

Keys and/or SSPs ECDSA public key ECDSA private key ECDSA public key Entropy input DRBG seed , DRBG internal state (V, Key) None HMAC key AES key AES key AES key Diffie-Hellman public key, Diffie-Hellman private key Diffie-Hellman shared secret EC Diffie- Hellman public key, EC Diffie- Hellman private key EC Diffie- Hellman shared secret

Roles

Access rights to Keys and/or SSPs W, E W, E W, E W, E E, G N/A W, E W, E W, E W, E G, R W, E G, R

Indicator fips_sli_is_approved_EVP _PKEY_CTX returns 1 fips_sli_is_approved_EVP _PKEY_CTX returns 1 fips_sli_RAND_bytes_is_a pproved returns 1 fips_sli_RAND_priv_bytes _is_approved returns 1 fips_sli_SHA*_is_approve d returns 1 fips_sli_HMAC_is_approve d returns 1 fips_sli_is_approved_CMA C_CTX returns 1 fips_sli_is_approved_EVP _CIPHER_CTX returns 1 fips_sli_is_approved_EVP _CIPHER_CTX returns 1 fips_sli_is_approved_EVP _PKEY_CTX returns 1 fips_sli_is_approved_EVP _PKEY_CTX returns 1

© 2025 SUSE, LLC / atsec information security.

21 of 56

Page 22
Service Diffie-Hellman key generation Diffie-Hellman public key validation Key derivation Transport Layer Security (TLS) network protocol Other FIPS-related ServicesDescription Perform Diffie- Hellman key generation with safe primes Perform Diffie- Hellman public key validation Perform key derivation Provide supported cipher suites in the approved modeApproved Security Functions Safe Primes Key Generation Safe Primes Public key validation TLS KDF SSH KDF PBKDF KDF Supported cipher suites in the approved mode (see Appendix A for the complete list of valid cipher suites)Keys and/or SSPs Diffie-Hellman public key, Diffie-Hellman private key Diffie-Hellman public key TLS pre-master secret TLS master secret TLS derived key Diffie-Hellman or EC Diffie- Hellman shared secret SSH derived key Password/passp hrase PBKDF Derived key RSA public key, RSA private key, ECDSA public key, ECDSA private key TLS pre-master secret, TLS master secret, , Diffie-Hellman private key, EC Diffie-Hellman private key, TLS derived key Diffie-Hellman public key, EC Diffie-Hellman public key,RolesAccess rights to Keys and/or SSPs E, G, R W, E W, E W, E, G G, R W, E G, R W, E G, R W, E E, G W, E, G, RIndicator fips_sli_is_approved_EVP _PKEY_CTX returns 1 fips_sli_is_approved_EVP _PKEY_CTX returns 1 fips_sli_is_approved_EVP _KDF_CTX returns 1 fips_sli_is_approved_EVP _KDF_CTX returns 1 fips_sli_PKCS5_PBKDF2_HM AC_is_approved returns 1 SSL_CIPHER_get_protocol_ id or SSL_get_current_cipher return a two-byte ID matching an approved cipher suite (listed in Appendix C).
Show statusShow module statusN/ANoneCON/AImplicit (always approved)
ZeroizationZeroize SSPsN/AAll SSPsZImplicit (always approved)

© 2025 SUSE, LLC / atsec information security.

22 of 56

Page 23

Service Self-tests Show module name and version

Description Perform self- tests Show module name and version

Approved Security Functions AES, Diffie- Hellman, EC Diffie-Hellman, ECDSA, DRBG, HMAC, RSA, SHS N/A

Keys and/or SSPs None None

Roles

Access rights to Keys and/or SSPs N/A N/A

Indicator Implicit (always approved) Implicit (always approved)

Service Cryptographic ServicesDescriptionAlgorithms AccessedRoles
Symmetric encryptionCompute the cipher for encryptionARIA, Blowfish, Camellia, ChaCha20, CAST, CAST5, DES, RC2, RC4, SEED, Triple-DESCO
Symmetric decryptionCompute the plaintext for decryption
Authenticated encryptionCompute authenticated encryption cipherAES-GCM with external IV
Authenticated encryptionCompute authenticated encryption cipherAES and SHA from multi-buffer or stitch implementations listed in Table 8, ChaCha20 and Poly1305
Authenticated decryptionCompute plaintext from authenticated encryption
Key pair generationGenerate RSA, DSA, and ECDSA key pairsRSA, DSA and ECDSA with restrictions listed in Table 8
Digital signature generationSign using RSA, DSA or ECDSARSA, DSA and ECDSA and message digest restrictions listed in Table 8
Digital signature verificationVerify RSA, DSA, ECDSA signatures
Message digestCompute message digestBlake2, Gost, MD4, MD5, MDC2, RMD160
Message authentication code (MAC)Compute HMAC and CMACHMAC and CMAC with restrictions listed in Table 8
Key encapsulationPerform RSA key encapsulationRSA encryption and decryption with any key sizes
Shared secret computationPerform Diffie-Hellman or EC Diffie-Hellman key agreementDiffie-Hellman and EC Diffie-Hellman restrictions listed in Table 8

Table 12 lists the non-approved services. The details of the non-approved cryptographic algorithms available in non-approved mode can be found in Table 8. © 2025 SUSE, LLC / atsec information security.

23 of 56

Page 24
Service Key derivation Network Protocol ServicesDescription Perform key derivationAlgorithms Accessed KDF SSH using Triple-DES HKDF (as a standalone service) PBKDF using non-approved message digest or input parameters not meeting requirements stated in section 11.2.4Roles
Transport Layer Security (TLS) network protocolProvide non-supported cipher suitesNon-supported cipher suites (see Appendix A for the complete list of valid cipher suites)CO

© 2025 SUSE, LLC / atsec information security.

24 of 56

Page 25
5 Software/Firmware security
5.1 Integrity Techniques

The integrity of the module is verified by comparing an HMAC-SHA2-256 value calculated at run time with the HMAC value stored in the .hmac file that was computed at build time for each software component of the module listed in section 2. If the HMAC values do not match, the test fails, and the module enters the error state.

5.2 On-Demand Integrity Test

On-Demand integrity tests can be invoked by powering-off and reloading the module.

5.3 Executable Code

The module consists of executable code in the form of libcrypto and libssl shared libraries as stated in section 2. © 2025 SUSE, LLC / atsec information security.

25 of 56

Page 26
6 Operational Environment
6.1 Applicability

This module operates in a modifiable operational environment per the FIPS 140-3 level 1 specifications. The SUSE Linux Enterprise Server operating system is used as the basis of other products. Compliance is maintained for SUSE products whenever the binary is found unchanged per the vendor affirmation from SUSE based on the allowance FIPS 140-3 management manual [FIPS140-3_MM] section 7.9.1 bullet 1 a i). Note: The CMVP makes no statement as to the correct operation of the module or the security strengths of the generated keys when supported if the specific operational environment is not listed on the validation certificate.

6.2 Policy

Instrumentation tools like the ptrace system call, gdb and strace utilities, userspace live patching, as well as other tracing mechanisms offered by the Linux environment such as ftrace or systemtap, shall not be used in the operational environment. The use of any of these tools implies that the cryptographic module is running in a non-tested operational environment.

6.3 Requirements

The module shall be installed as stated in section 11. The operating system provides process isolation and memory protection mechanisms that ensure appropriate separation for memory access among the processes on the system. Each process has control over its own data and uncontrolled access to the data of other processes is prevented. © 2025 SUSE, LLC / atsec information security.

26 of 56

Page 27
7 Physical Security

The module is comprised of software only, and therefore this section is not applicable. © 2025 SUSE, LLC / atsec information security.

27 of 56

Page 28
8 Non-invasive Security

This module does not implement any non-invasive security mechanism and therefore this section is not applicable. © 2025 SUSE, LLC / atsec information security.

28 of 56

Page 29
Key/SSP Name/Typ eStren gthSecurity Function and Cert. NumberGenerationImport/ExportEstablish mentStor ageZeroizationUse & related SSPs
AES key128, 192, 256AES-CBC, AES- CCM, AES-CFB1, AES-CFB128, AES-CFB8, AES- CMAC, AES- CTR, AES-GCM, AES-KW, AES- KWP, AES- OFB, AES-XTS, CTR- DRBG A3136, A3137, A3138, A3140, A3141, A3142, A3143, A3149, A3150, A3151, A3152, A3153, A3154, A3155, A3157, A3158, A3159, A3160, A3162, A3163, A3165, A3166, A3167, A3169, A3170, A3171, A3172, A3176, A3177, A3178, A3179, A3180, A3181, A3182, A3183, A3184, A3190, A3194, A3195, A3196, A3197, A3198, A3199, A3200, A3201, A3204, A3205, A3206N/AImport: CM from TOEPP Path. Passed to the module via API parameters in plaintext (P) format. Export: N/AN/ARAMEVP_CIPHER_ CTX_free, EVP_CIPHER_ CTX_resetUse: Symmetric encryption and decryption; Key wrapping and unwrapping; Message authentication code (MAC) generation and verification Related keys: N/A
HMAC key112 to 256HMAC A3144, A3145, A3146, A3147, A3148, A3156, A3161, A3173, A3174, A3175, A3185, A3186, A3187, A3188, A3193, A3202, A3203, A3210N/AImport: CM from TOEPP Path. Passed to the module via API parameters in plaintext (P) format. Export: N/AN/ARAMHMAC_CTX_fr eeUse: Message authentication code (MAC) generation and verification Related keys: N/A
9 Sensitive Security Parameter Management

Table 13 summarizes the Sensitive Security Parameters (SSPs) that are used by the cryptographic © 2025 SUSE, LLC / atsec information security.

29 of 56

Page 30
Key/SSP Name/Typ eStren gthSecurity Function and Cert. NumberGenerationImport/ExportEstablish mentStor ageZeroizationUse & related SSPs
Module- generated RSA public key112, to 2562RSA A3147, A3156, A3185, A3186, A3187, A3188, A3193, A3202, A3203, A3210Generated using the random probable primes method (B.3.3) specified in FIPS 186-4; random values are obtained from the SP800- 90Arev1 DRBG.Import: N/A Export: CM to TOEPP Path. Passed from the module via API parameters in plaintext (P) format.N/ARAMRSA_freeUse: Key generation Related keys: DRBG internal state; Module- generated RSA private key
Module- generated RSA private key112 to 256RSA A3147, A3156, A3185, A3186, A3187, A3188, A3193, A3202, A3203, A3210Generated using the random probable primes method (B.3.3) specified in FIPS 186-4; random values are obtained from the SP800- 90Arev1 DRBG.Import: N/A Export: CM to TOEPP Path. Passed from the module via API parameters in plaintext (P) format.N/ARAMRSA_freeUse: Key generation Related keys: DRBG internal state; Module- generated RSA public key
RSA public key803 to 256RSA A3147, A3156, A3185, A3186, A3187, A3188, A3193, A3202, A3203, A3210N/AImport: CM from TOEPP Path. Passed to the module via API parameters in plaintext (P) format. Export: N/AN/ARAMRSA_freeUse: Digital signature verification Related keys: RSA private key
RSA private key112 to 256RSA A3147, A3156, A3185, A3186, A3187, A3188, A3193, A3202, A3203, A3210N/AImport: CM from TOEPP Path. Passed to the module via API parameters in plaintext (P) format. Export: N/AN/ARAMRSA_freeUse: Digital signature generation Related keys: RSA public key

2 The security strength of RSA is based on key sizes between 2048 and up to 16384 bits allowed by IG C.F.

3 RSA public key with less than 2048 bits and security strength of 80-111 bits is allowed for legacy use.

© 2025 SUSE, LLC / atsec information security.

30 of 56

Page 31
Key/SSP Name/Typ eStren gthSecurity Function and Cert. NumberGenerationImport/ExportEstablish mentStor ageZeroizationUse & related SSPs
Module- generated ECDSA public key112, 128, 192, 256ECDSA A3144, A3145, A3146, A3147, A3148, A3156, A3173, A3174, A3175, A3185, A3186, A3187, A3188, A3193, A3202, A3203, A3210B.4.2 Testing Candidates Generated using the testing candidates method specified in FIPS 186-4; random values are obtained from the SP800- 90Arev1 DRBGImport: N/A Export: CM to TOEPP Path. Passed from the module via API parameters in plaintext (P) format.N/ARAMEC_KEY_freeUse: Key generation Related keys: DRBG internal state, Module- generated ECDSA private key
Module- generated ECDSA private key112, 128, 192, 256ECDSA A3144, A3145, A3146, A3147, A3148, A3156, A3173, A3174, A3175, A3185, A3186, A3187, A3188, A3193, A3202, A3203, A3210B.4.2 Testing Candidates Generated using the testing candidates method specified in FIPS 186-4; random values are obtained from the SP800- 90Arev1 DRBGImport: N/A Export: CM to TOEPP Path. Passed from the module via API parameters in plaintext (P) format.N/ARAMEC_KEY_freeUse: Key generation Related keys: DRBG internal state, Module- generated ECDSA public key
ECDSA public key112, 128, 192, 256ECDSA A3144, A3145, A3146, A3147, A3148, A3156, A3173, A3174, A3175, A3185, A3186, A3187, A3188, A3193, A3202, A3203, A3210N/AImport: CM from TOEPP Path. Passed to the module via API parameters in plaintext (P) format. Export: N/AN/ARAMEC_KEY_freeUse: Key pair validation; ECDSA public key validation; Digital signature verification Related keys: ECDSA private key

© 2025 SUSE, LLC / atsec information security.

31 of 56

Page 32
Key/SSP Name/Typ eStren gthSecurity Function and Cert. NumberGenerationImport/ExportEstablish mentStor ageZeroizationUse & related SSPs
ECDSA private key112, 128, 192, 256ECDSA A3144, A3145, A3146, A3147, A3148, A3156, A3173, A3174, A3175, A3185, A3186, A3187, A3188, A3193, A3202, A3203, A3210N/AImport: CM from TOEPP Path. Passed to the module via API parameters in plaintext (P) format. Export: N/AN/ARAMEC_KEY_freeUse: Key pair validation; Digital signature generation Related keys: ECDSA public key
Module- generated EC Diffie- Hellman public key112 to 256KAS-ECC-SSC A3147, A3156, A3185, A3186, A3187, A3188, A3193, A3202, A3203, A3210Generated using the testing candidates method specified in SP800-56Arev3; random values are obtained from the SP800 90Arev1 DRBG.Import: N/A Export: CM to TOEPP Path. Passed from the module via API parameters in plaintext (P) format.N/ARAMEC_KEY_freeUse: Key generation; Shared secret computation; Transport Layer Security (TLS) network protocol Related SSPs: DRBG internal state; EC Diffie- Hellman private key; EC Diffie- Hellman shared secret
Module- generated EC Diffie- Hellman private key112 to 256KAS-ECC-SSC A3147, A3156, A3185, A3186, A3187, A3188, A3193, A3202, A3203, A3210Generated using the testing candidates method specified in SP800-56Arev3; random values are obtained from the SP800 90Arev1 DRBG.Import: N/A Export: CM to TOEPP Path. Passed from the module via API parameters in plaintext (P) format.N/ARAMEC_KEY_freeUse: Key generation; Shared secret computation; Transport Layer Security (TLS) network protocol Related SSPs: DRBG internal state; EC Diffie- Hellman public key; EC Diffie-Hellman shared secret

© 2025 SUSE, LLC / atsec information security.

32 of 56

Page 33
Key/SSP Name/Typ eStren gthSecurity Function and Cert. NumberGenerationImport/ExportEstablish mentStor ageZeroizationUse & related SSPs
EC Diffie- Hellman public key112 to 256KAS-ECC-SSC A3147, A3156, A3185, A3186, A3187, A3188, A3193, A3202, A3203, A3210N/AImport: CM from TOEPP Path. Passed to the module via API parameters in plaintext (P) format. Export: N/AN/ARAMEC_KEY_freeUse: Key pair validation; Shared secret computation; Transport Layer Security (TLS) network protocol Related SSPs: EC Diffie-Hellman shared secret
EC Diffie- Hellman private key112 to 256KAS-ECC-SSC A3147, A3156, A3185, A3186, A3187, A3188, A3193, A3202, A3203, A3210N/AImport: CM from TOEPP Path. Passed to the module via API parameters in plaintext (P) format. Export: N/AN/ARAMEC_KEY_freeUse: Key pair validation; Shared secret computation Related SSPs: EC Diffie-Hellman shared secret
Module- generated Diffie- Hellman public key112 to 200KAS-FFC-SSC A3207, A3211Generated using safe prime key generation method specified in SP800-56Arev3; random values are obtained from the SP800- 90Arev1 DRBG.Import: N/A Export: CM to TOEPP Path. Passed from the module via API parameters in plaintext (P) format.N/ARAMDH_freeUse: Key generation; Shared secret computation; Transport Layer Security (TLS) network protocol Related SSPs: DRBG internal state; Module- generated Diffie-Hellman private key; Diffie-Hellman shared secret
Module- generated Diffie- Hellman private key112 to 200KAS-FFC-SSC A3207, A3211Generated using safe prime key generation method specified in SP800-56Arev3;Import: N/A Export: CM to TOEPP Path. Passed rom the module via APIN/ARAMDH_freeUse: Key generation; Shared secret computation; Transport Layer Security

© 2025 SUSE, LLC / atsec information security.

33 of 56

Page 34
Key/SSP Name/Typ eStren gthSecurity Function and Cert. NumberGeneration random values are obtained from the SP800- 90Arev1 DRBG.Import/Export parameters in plaintext (P) format.Establish mentStor ageZeroizationUse & related SSPs (TLS) network protocol Related SSPs: DRBG internal state; Module- generated Diffie-Hellman public key; Diffie-Hellman shared secret
Diffie- Hellman public key112 to 200KAS-FFC-SSC A3207, A3211N/A.Import: CM from TOEPP Path. Passed to the module via API parameters in plaintext (P) format. Export: N/AN/ARAMDH_freeUse: Diffie- Hellman public key validation; Shared secret computation; Transport Layer Security (TLS) network protocol Related SSPs: Diffie- Hellman shared secret
Diffie- Hellman private key112 to 200KAS-FFC-SSC A3207, A3211N/AImport: CM from TOEPP Path. Passed to the module via API parameters in plaintext (P) format. Export: N/AN/ARAMDH_freeUse: Shared secret computation Related SSPs: Diffie- Hellman shared secret
EC Diffie- Hellman shared secret112 to 256KAS-ECC-SSC A3147, A3156, A3185, A3186, A3187, A3188, A3193, A3202, A3203, A3210N/AImport/Export: CM to/from TOEPP Path. Passed to/from the module via API parameters in plaintext (P) format.Computed during the EC Diffie- Hellman key agreement and shared secret computatio n per SP800- 56Arev3.RAMEC_KEY_freeUse: Key derivation; EC Diffie-Hellman shared secret computation Related SSPs: EC Diffie-Hellman public key; EC Diffie-Hellman private key; TLS derived key; SSH derived key
Diffie- Hellman shared secret112 to 200KAS-FFC-SSC A3207, A3211N/AImport/Export: CM to/from TOEPP Path. Passed to/from the module via API parameters in plaintext (P) format.Computed during the Diffie- Hellman key agreement and shared secret computatioRAMDH_freeUse: Key derivation; DH shared secret computation Related SSPs: Diffie- Hellman public key; Diffie-Hellman

© 2025 SUSE, LLC / atsec information security.

34 of 56

Page 35
Key/SSP Name/Typ eStren gthSecurity Function and Cert. NumberGenerationImport/ExportEstablish ment n per SP800- 56Arev3.Stor ageZeroizationUse & related SSPs private key; TLS derived key; SSH derived key
Password/p assphraseN/APBKDF A3144, A3145, A3146, A3147, A3148, A3156, A3173, A3174, A3175, A3185, A3186, A3187, A3188, A3193, A3202, A3203, A3210N/AImport: CM to TOEPP Path. Passed to the module via API parameters in plaintext (P) format. Export: N/AN/ARAMEVP_PKEY_fr eeUse: Key derivation. Related SSPs: PBKDF derived key
TLS Derived keyAES 128, 192, 256; HMAC 112 to 256TLS KDF A3147, A3156, A3185, A3186, A3187, A3188, A3193, A3202, A3203, A3210 KDA HKDF A3139, A3168Generated during the TLS KDFImport: N/A Export: CM to TOEPP Path. Passed from the module via API parameters in plaintext (P) format.N/ARAMEVP_PKEY_fr eeUse: Transport Layer Security (TLS) network protocol Related SSPs: TLS pre-master secret, TLS master secret
SSH Derived keyAES 128, 192, 256; HMAC 112 to 256SSH KDF A3140, A3141, A3142, A3143, A3149, A3157, A3169, A3170, A3171, A3172Generated during the SSH KDFImport: N/A Export: CM to TOEPP Path. Passed from the module via API parameters in plaintext (P) format.N/ARAMEVP_PKEY_fr eeUse: Key derivation Related SSPs: Shared secret
PBKDF Derived key112 to 256PBKDF A3144, A3145, A3146, A3147, A3148, A3156, A3173, A3174, A3175, A3185, A3186, A3187, A3188, A3193, A3202, A3203, A3210Generated during the PBKDF compliant with SP800-132.Import: N/A Export: CM to TOEPP Path. Passed from the module via API parameters in plaintext (P) format.N/ARAMEVP_PKEY_fr eeUse: Key derivation Related SSPs: Password/pass phrase
Entropy input IG D.L compliant192 to 384CTR_DRBG A3136, A3137, A3138, A3150, A3154, A3158, A3160, A3162, A3163, A3165, A3166, A3167Obtained from the SP800-90B entropy sourceImport/Export: N/A; it remains within the cryptographic boundary.N/ARAMFIPS_drbg_f reeUse: Random number generation Related SSPs: DRBG seed
DRBG seed IG D.L compliant192 to 384CTR_DRBG A3136, A3137, A3138, A3150, A3154, A3158, A3160, A3162,Derived from the entropy input as defined in SP800- 90Arev1Import/Export: N/A; it remains within the cryptographic boundary.N/ARAMFIPS_drbg_f reeUse: Random number generation Related SSPs: Entropy

© 2025 SUSE, LLC / atsec information security.

35 of 56

Page 36
Key/SSP Name/Typ eStren gthSecurity Function and Cert. Number A3163, A3165, A3166, A3167GenerationImport/ExportEstablish mentStor ageZeroizationUse & related SSPs input, DRBG Internal state
DRBG internal state (V, key) IG D.L compliant128 to 256CTR_DRBG A3136, A3137, A3138, A3150, A3154, A3158, A3160, A3162, A3163, A3165, A3166, A3167Derived from seed as defined in SP800- 90Arev1Import/Export: N/A; it remains within the cryptographic boundary.N/ARAMFIPS_drbg_f reeUse: Random number generation Related SSPs: Entropy input, DRBG seed
TLS pre- master secretDH 112 to 200 ECDH 128 to 256TLS KDF A3147, A3156, A3185, A3186, A3187, A3188, A3193, A3202, A3203, A3210N/AImport: CM to TOEPP Path. Passed to the module via API parameters in plaintext (P) format. Export: N/AComputed during key agreement for Diffie- Hellman or EC Diffie- Hellman cipher suites.RAMSSL_free, SSL_clearUse: Transport Layer Security (TLS) network protocol Related SSPs: TLS master secret
TLS master secret384TLS KDF A3147, A3156, A3185, A3186, A3187, A3188, A3193, A3202, A3203, A3210Derived from TLS pre-master secret using TLS KDF per SP800-135rev1.Import/Export: N/A; it remains within the cryptographic boundary.N/ARAMSSL_free, SSL_clearUse: Transport Layer Security (TLS) network protocol Related SSPs: TLS pre-master secret; TLS derived key

Table 13 - SSPs The module employs a Deterministic Random Bit Generator (DRBG) based on [SP800-90Arev1] for the creation of seeds for asymmetric keys, random numbers for security functions (e.g. ECDSA module provides a Random Number Generation service to calling applications. The DRBG supports the CTR_DRBG mechanisms. The DRBG is initialized during module initialization; the module loads by default the DRBG using the CTR_DRBG mechanism with AES256, with derivation function, and without prediction resistance. A different DRBG mechanism can be chosen through an API function call. The module uses an SP800-90B-compliant entropy source specified in Table 14. This entropy source is located within the physical perimeter, but outside of the cryptographic boundary of the provide a DRBG with 256 bits of security strength. © 2025 SUSE, LLC / atsec information security.

36 of 56

Page 37
Entropy SourcesMinimum number of bits of entropyDetails
ESV certs. E22, E28, E29, E30256 bits of entropy in the 256-bit outputStandalone Userspace CPU Time Jitter RNG version 3.4.0 entropy source with SHA-3 as the vetted conditioning component is located within the physical perimeter of the operational environment but outside the module cryptographic boundary.

Table 14 - Non-Deterministic Random Number Generation Specification

9.2 SSP Generation

The SSP generation methods implemented in the module are compliant with [SP800-133rev2]. For generating RSA, ECDSA keys, the module implements asymmetric key generation services compliant with [FIPS186-4]. A seed (i.e., the random value) used in asymmetric key generation is directly obtained from the [SP800-90Arev1] DRBG. The public and private keys used in the EC Diffie-Hellman key agreement schemes are generated internally by the module using the ECDSA key generation method compliant with [FIPS186-4] and [SP800-56Arev3]. The Diffie-Hellman key agreement scheme is also compliant with [SP80056Arev3] and generates keys using safe primes defined in RFC7919 and RFC3526, as described in the next section. In accordance with FIPS 140-3 IG D.H, the cryptographic module performs Cryptographic Key Generation (CKG) for asymmetric keys as per section 5.1 of SP800-133rev2 (vendor affirmed) by obtaining a random bit string directly from an approved DRBG and that can support the required security strength requested by the caller (without any V, as described in Additional Comments 2 of IG D.H). The module supports the following key derivation methods according to [SP800-135rev1]:

9.3 SSP establishment

The module provides Diffie-Hellman and EC Diffie-Hellman shared secret computation compliant with SP800-56Arev3, in accordance with scenario 2 (1) of IG D.F. The module also provides Diffie-Hellman and EC Diffie-Hellman key agreement schemes compliant with SP800-56rev3 and used as part of the TLS protocol key exchange in accordance with scenario

2 (2) of IG D.F; that is, the shared secret computation (KAS-FFC-SSC and KAS-ECC-SSC) followed by

the derivation of the keying material using SP800-135rev1 KDF. For Diffie-Hellman, the module supports the use of safe primes from RFC7919 for domain parameters and key generation, which are used in the TLS key agreement implemented by the

37 of 56

Page 38
9.4 SSP Entry and Output

The module does not support manual SSP entry or intermediate SSP generation output. The SSPs are provided to the module via API input parameters in plaintext form and output via API output parameters in plaintext form within the physical perimeter of the operational environment. This is allowed by [FIPS140-3_IG] IG 9.5.A, according to the “CM Software to/from App via TOEPP Path” entry in the Key Establishment Table.

9.5 SSP Storage

The module does not perform persistent storage of SSPs. The SSPs are temporarily stored in the RAM in plaintext form. SSPs are provided to the module by the calling process and are destroyed when released by the appropriate zeroization function calls.

9.6 SSP Zeroization

The memory occupied by SSPs is allocated by regular memory allocation operating system calls. The application that is acting as the CO is responsible for calling the appropriate zeroization © 2025 SUSE, LLC / atsec information security.

38 of 56

Page 39

functions provided in the module's API and listed in Table 13. Calling the SSL_free() and SSL_clear() will zeroize the SSPs stored in the TLS protocol internal state and also invoke the corresponding API functions listed in Table 13 to zeroize SSPs. The zeroization functions overwrite the memory occupied by SSPs with “zeros” and deallocate the memory with the regular memory deallocation operating system call. The completion of a zeroization routine(s) will indicate that a zeroization procedure succeeded. © 2025 SUSE, LLC / atsec information security.

39 of 56

Page 40
AlgorithmTest
AESKAT AES ECB mode with 128-bit key, encryption and decryption (separately tested) KAT AES CCM mode with 192-bit key, encryption and decryption (separately tested) KAT AES GCM mode with 256-bit key, encryption and decryption (separately tested) KAT AES XTS mode with 128 and 256-bit keys, encryption, and decryption (separately tested)
CMACKAT AES CMAC with 128-,192-, and 256-bit keys, MAC generation
Diffie-HellmanPrimitive “Z” computation KAT with 2048-bit key
DRBGKAT CTR_DRBG with AES with 256-bit keys with and without DF, with and without PR Health tests according to section 11.3 of [SP800-90Arev1]
EC Diffie-HellmanPrimitive “Z” computation KAT with P-256 curve
ECDSAKAT ECDSA with P-256 and SHA2-256, signature generation and verification (separately tested)
HMACKAT HMAC-SHA-1, HMAC-SHA2-224, HMAC-SHA2-256, HMAC-SHA2-384, HMAC-SHA2-512 KAT HMAC-SHA3-224, HMAC-SHA3-256, HMAC-SHA3-384, HMAC-SHA3-512
PBKDFKAT with SHA2-256
RSAKAT RSA with 2048-bit key, PKCS#1 v1.5 scheme and SHA2-256, signature generation and verification (separately tested) KAT RSA with 2048-bit key, PSS scheme and SHA2-256, signature generation and verification (separately tested)
SHA-3KAT SHA3-256, SHA3-512, SHAKE-128 and SHAKE-256
SHAKAT SHA-1, SHA2-224, SHA2-256, SHA2-384 and SHA2-512.
10 Self-Tests

The module performs the pre-operational self-test and CASTs automatically when the module is loaded into memory. Pre-operational self-test ensure that the module is not corrupted, and the CASTs ensure that the cryptographic algorithms work as expected. While the module is executing the pre-operational test and the CASTs, the module services are not available, and input and output are inhibited. The module is not available for use by the calling application until the preoperational self-test and the CASTs are completed successfully. After the pre-operational test and the CASTs succeed, the module becomes operational. If any of the pre-operational test or any of the CASTs fail an error message is returned, and the module transitions to the error state. © 2025 SUSE, LLC / atsec information security.

40 of 56

Page 41
AlgorithmTest
SSH KDFKAT with SHA2-256
TLSv1.2 KDFKAT with SHA2-256
HKDFKAT with SHA2-256
AlgorithmTest
ECDSA key generationPCT using SHA2-256, signature generation and verification
RSA key generationPCT using SHA2-256, signature generation and verification
Diffie-Hellman key generationPCT according to section 5.6.2.1.4 of [SP800-56Arev3]
ECDH key generationCovered by ECDSA PCT as allowed by IG 10.3, additional comment 1.

Table 15 – Cryptographic Algorithms Self-Tests

10.1 Pre-Operational Tests

The module performs the integrity test of the shared libraries that comprise the module. The details of integrity test are provided in section 5.1.

10.2 Conditional Tests
10.2.1 Cryptographic Algorithm Self-Tests

Table 15 specifies all the CASTs. All the CASTs are performed in the form of the Known Answer Tests (KATs) and are run prior to performing the integrity test. A KAT includes the comparison of a calculated output with an expected known answer, hard coded as part of the test vectors used in the test. If the values do not match, the KAT fails.

10.2.2 Pairwise Consistency Test

The module performs the Pair-wise Consistency Tests (PCT) shown in the following table. If at least one of the tests fails, the module returns an error code and enters the Error state. When the module is in the Error state, no data is output, and cryptographic operations are not allowed. Table 16 - Pairwise Consistency Test

10.3 Periodic/On-Demand Self-Test

On-Demand self-tests can be invoked by powering-off and reloading the module which cause the module to run the power-up tests again.

10.4 Error States

When the module fails the pre-operational self-test or any conditional test, the module returns an error code to indicate the error and enter the “Abort” error state, showing the following message to © 2025 SUSE, LLC / atsec information security.

41 of 56

Page 42
StateCause of ErrorStatus Indicator
AbortThe integrity test fails at power-up.FIPS_R_FINGERPRINT_DOES_NOT_MATC H (110). Module stops functioning.
AbortAny of the AES, CMAC, DRBG, HMAC, or SHA KATs fails during CAST.FIPS_R_SELFTEST_FAILED (101). Module stops functioning.
AbortAny of the KATs for RSA or ECDSA fails during CAST.FIPS_R_TEST_FAILURE (117). Module stops functioning.
AbortThe KAT of a DRBG fails during CAST.FIPS_R_NOPR_TEST1_FAILURE (145) FIPS_R_NOPR_TEST2_FAILURE(146) FIPS_R_PR_TEST1_FAILURE (147) FIPS_R_PR_TEST2_FAILURE (148) Module stops functioning.
ErrorThe PCT of a newly generated RSA, ECDSA, Diffie-Hellman or EC Diffie-Hellman key pair fails during conditional tests.FIPS_R_PAIRWISE_TEST_FAILED (127)
ErrorThe module is in the Error state and a cryptographic service other than the following is invoked: Message Digest, Encryption/Decryption, Diffie-Hellman.FIPS_R_FIPS_SELFTEST_FAILED (106)
AbortThe module is in the Error state and one of the following cryptographic services is invoked: Message Digest, Encryption/Decryption, Diffie-Hellman.Error message “OpenSSL internal error, assertion failed: FATAL FIPS SELFTEST FAILURE” shown in stderr. Module stops functioning.

functioning. The only way to recover from this error is to restart the application. If the failure persists, the module must be reinstalled. When a PCT fails during conditional tests, the module returns an error code to indicate the error and enter the “Error” error state. Any further cryptographic operation is inhibited. The calling application can obtain the module state by requesting the “Show status” service by calling the Some cryptographic services cannot handle the return value of the “Error” state, and when the module is in that state and receives a service request, shows an error message and transitions to failed: FATAL FIPS SELFTEST FAILURE” and stopping functioning. The only way to recover from this error is to restart the application. Table 17 shows the error codes and the corresponding condition: Table 17 - Error States © 2025 SUSE, LLC / atsec information security.

42 of 56

Page 43

In the “Error” state, errors are reported through the regular ERR interface of the modules and can be queried by functions such as ERR_get_error(). See the OpenSSL man pages for the function description. © 2025 SUSE, LLC / atsec information security.

43 of 56

Page 44
11 Life-cycle assurance
11.1 Delivery and Operation
11.1.1 Module Installation

The Crypto Officer can install the RPM packages containing the module as listed in Table 19 using the zypper tool as follows: # zypper install libopenssl1_1 # zypper install libopenssl1_1-hmac If the use of certified 32-bit Openssl libraries on Intel x86 is required, then use the following to install the 32bit libraries and hmac packages: # zypper install libopenssl1_1-32bit # zypper install libopenssl1_1-hmac-32bit The integrity of the RPM package is automatically verified during the installation, and the Crypto Officer shall not install the RPM package if there is any integrity error.

11.1.2 Operating Environment Configuration

The operating environment needs to be configured to support the approved mode of operation, so the following steps shall be performed with the root privilege:

  1. Install the dracut-fips RPM package: # zypper install dracut-fips
  2. Recreate the INITRAMFS image: # dracut -f
  3. After regenerating the initrd, the Crypto Officer has to append the following parameter in the /etc/default/grub configuration file in the GRUB_CMDLINE_LINUX_DEFAULT line: fips=1
  4. After editing the configuration file, please run the following command to change the setting in the boot loader: # grub2-mkconfig -o /boot/grub2/grub.cfg If /boot or /boot/efi resides on a separate partition, the kernel parameter boot=<partition of /boot or /boot/efi> must be supplied. The partition can be identified with the command "df /boot" or "df /boot/efi" respectively. For example: # df /boot Filesystem 1K-blocks Used Available Use% Mounted on /dev/sda1 233191 30454 190296 14% /boot The partition of /boot is located on /dev/sda1 in this example. Therefore, the following string needs to be appended in the aforementioned grub file: "boot=/dev/sda1"
  5. Reboot to apply these settings. Now, the operating environment is configured to support the approved mode of operation. The Crypto Officer should check the existence of the file /proc/sys/crypto/fips_enabled, and verify it © 2025 SUSE, LLC / atsec information security.

44 of 56

Page 45
ProductLink
SUSE Linux Enterprise Micro 5.3https://documentation.suse.com/sle-micro/5.3/single-html/SLE-Micro- security/#sec-fips-slemicro-install
SUSE Linux Enterprise Server for SAP 15SP4https://documentation.suse.com/sles/15-SP4/html/SLES-all/book- security.html
SUSE Linux Enterprise Base Container Image 15SP4https://documentation.suse.com/smart/linux/html/concept-bci/index.html
SUSE Linux Enterprise Desktop 15SP4https://documentation.suse.com/sled/15-SP4/html/SLED-all/book- security.html
SUSE Linux Enterprise Real Time 15SP4https://documentation.suse.com/sle-rt/15-SP4

contains a numeric value “1”. If the file does not exist or does not contain “1”, the operating environment is not configured to support the approved mode of operation and the module will not operate as a FIPS validated module properly.

11.1.3 Module Installation for Vendor Affirmed Platforms

Table 18 includes the information on module installation process for the vendor affirmed platforms that are listed in Table 4 and Table 5. Table 18 - Installation for Vendor Affirmed Platforms Note: Per section 7.9 in the FIPS 140-3 Management Manual [FIPS140-3_MM], the Cryptographic Module Validation Program (CMVP) makes no statement as to the correct operation of the module or the security strengths of the generated keys when this module is ported and executed in an operational environment not listed on the validation certificate.

11.1.4 End of Life Procedure

For secure sanitization of the cryptographic module, the module needs first to be powered off, which will zeroize all keys and CSPs in volatile memory. Then, for actual deprecation, the module shall be upgraded to a newer version that is FIPS 140-3 validated. The module does not possess persistent storage of SSPs, so further sanitization steps are not needed.

11.2 Crypto Officer Guidance

The binaries of the module are contained in the RPM packages for delivery. The Crypto Officer shall follow section 11.1.1 and 11.1.2 to configure the operational environment and install the module to be operated as a FIPS 140-3 validated module. Table 19 lists the RPM packages that contain the FIPS validated module and the OE directory where the components are installed. The "Show module name and version" service returns the value "OpenSSL 1.1.1l-fips 24 Aug 2021 SUSE release 150400.7.81.1”, which matches the version included in the RPM package filenames. © 2025 SUSE, LLC / atsec information security.

45 of 56

Page 46
Processor ArchitectureRPM PackagesLocation in the OE
Intel 64-bitlibopenssl1_1-1.1.1l-150400.7.81.1.x86_64.rpm libopenssl1_1-hmac-1.1.1l-150400.7.81.1.x86_64.rpm/usr/lib64
Intel 32-bitlibopenssl1_1-32bit-1.1.1l-150400.7.81.1.x86_64.rpm libopenssl1_1-hmac-32bit-1.1.1l-150400.7.81.1.x86_64.rpm/usr/lib
AMD 64-bitlibopenssl1_1-1.1.1l-150400.7.81.1.x86_64.rpm libopenssl1_1-hmac-1.1.1l-150400.7.81.1.x86_64.rpm/usr/lib64
IBM z15libopenssl1_1-1.1.1l-150400.7.81.1.s390x.rpm libopenssl1_1-hmac-1.1.1l-150400.7.81.1.s390x.rpm/usr/lib64
ARMv8 64-bitlibopenssl1_1-1.1.1l-150400.7.81.1.aarch64.rpm libopenssl1_1-hmac-1.1.1l-150400.7.81.1.aarch64.rpm/usr/lib64
IBM Power10 64-bitlibopenssl1_1-1.1.1l-150400.7.81.1.ppc64le.rpm libopenssl1_1-hmac-1.1.1l-150400.7.81.1.ppc64le.rpm/usr/lib64
11.2.1 AES XTS

The AES algorithm in XTS mode can be only used for the cryptographic protection of data on storage devices, as specified in [SP800-38E]. The length of a single data unit encrypted with the XTS-AES shall not exceed 2²⁰ AES blocks, that is 16MB of data. To meet the requirement stated in IG C.I, the module implements a check that ensures, before performing any cryptographic operation, that the two AES keys used in AES XTS mode are not identical. Note: AES-XTS shall be used with 128 and 256-bit keys only. AES-XTS with 192-bit keys is not an Approved service.

11.2.2 AES GCM IV

The AES GCM IV generation is in compliance with the [RFC5288] and shall only be used for the TLS protocol version 1.2 to be compliant with [FIPS140-3_IG] IG C.H, provision 1 (“TLS protocol IV generation”); in addition, the module is compliant with section 3.3.1 of [SP800-52rev2]. The nonce_explicit part of the IV does not exhaust the maximum number of possible values for a given session key. The design of the TLS protocol in this module implicitly ensures that the nonce_explicit, or counter portion of the IV will not exhaust all of its possible values. In case the module's power is lost and then restored, the key used for the AES GCM encryption or decryption shall be redistributed. When a GCM IV is used for decryption, the responsibility for the IV generation lies with the party that performs the AES GCM encryption.

11.2.3 Environment Variables

OPENSSL_ENFORCE_MODULUS_BITS © 2025 SUSE, LLC / atsec information security.

46 of 56

Page 47

Setting the environment variable OPENSSL_ENFORCE_MODULUS_BITS can restrict the module to only generate the acceptable key sizes of RSA. If the environment variable is set, the module enforces the generation of keys of 2048 bits or more. Notice that even if this environment variable is not set, the module will provide the corresponding value of the service indicator depending on the size of the key generated.

11.2.4 Key derivation using SP800-132 PBKDF

The module provides password-based key derivation (PBKDF), compliant with SP800-132 and IG D.N. The module supports option 1a from section 5.4 of [SP800-132], in which the Master Key (MK) or a segment of it is used directly as the Data Protection Key (DPK). In accordance with [SP800-132], the following requirements shall be met.

47 of 56

Page 48
12 Mitigation of other attacks

The module implements blinding against RSA timing attacks. RSA is vulnerable to timing attacks. In a setup where attackers can measure the time of RSA decryption or signature operations, blinding must be used to protect the RSA operation from that attack. The module provides the API functions RSA_blinding_on() and RSA_blinding_off() to turn the blinding on and off for RSA. When the blinding is on, the module generates a random value to form a blinding factor in the RSA key before the RSA key is used in the RSA cryptographic operations. © 2025 SUSE, LLC / atsec information security.

48 of 56

Page 49
Cipher SuiteIDReference
TLS_DH_RSA_WITH_AES_128_CBC_SHA{ 0x00, 0x31 }RFC3268
TLS_DHE_RSA_WITH_AES_128_CBC_SHA{ 0x00, 0x33 }RFC3268
TLS_DH_RSA_WITH_AES_256_CBC_SHA{ 0x00, 0x37 }RFC3268
TLS_DHE_RSA_WITH_AES_256_CBC_SHA{ 0x00, 0x39 }RFC3268
TLS_DH_RSA_WITH_AES_128_CBC_SHA256{ 0x00,0x3F }RFC5246
TLS_DHE_RSA_WITH_AES_128_CBC_SHA256{ 0x00,0x67 }RFC5246
TLS_DH_RSA_WITH_AES_256_CBC_SHA256{ 0x00,0x69 }RFC5246
TLS_DHE_RSA_WITH_AES_256_CBC_SHA256{ 0x00,0x6B }RFC5246
TLS_PSK_WITH_AES_128_CBC_SHA{ 0x00, 0x8C }RFC4279
TLS_PSK_WITH_AES_256_CBC_SHA{ 0x00, 0x8D }RFC4279
TLS_DHE_RSA_WITH_AES_128_GCM_SHA256{ 0x00, 0x9E }RFC5288
TLS_DHE_RSA_WITH_AES_256_GCM_SHA384{ 0x00, 0x9F }RFC5288
TLS_DH_RSA_WITH_AES_128_GCM_SHA256{ 0x00, 0xA0 }RFC5288
TLS_DH_RSA_WITH_AES_256_GCM_SHA384{ 0x00, 0xA1 }RFC5288
TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA{ 0xC0, 0x04 }RFC4492
TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA{ 0xC0, 0x05 }RFC4492
TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA{ 0xC0, 0x09 }RFC4492
TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA{ 0xC0, 0x0A }RFC4492
TLS_ECDH_RSA_WITH_AES_128_CBC_SHA{ 0xC0, 0x0E }RFC4492
TLS_ECDH_RSA_WITH_AES_256_CBC_SHA{ 0xC0, 0x0F }RFC4492
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA{ 0xC0, 0x13 }RFC4492
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA{ 0xC0, 0x14 }RFC4492
TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256{ 0xC0, 0x23 }RFC5289
TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384{ 0xC0, 0x24 }RFC5289
TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA256{ 0xC0, 0x25 }RFC5289

Appendix A. TLS Cipher Suites The module supports the following cipher suites for the TLS protocol versions 1.0, 1.1, 1.2 and 1.3 compliant with section 3.3.1 of [SP800-52rev2]. Each cipher suite defines the key exchange algorithm, the bulk encryption algorithm (including the symmetric key size) and the MAC algorithm. © 2025 SUSE, LLC / atsec information security.

49 of 56

Page 50
Cipher SuiteIDReference
TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA384{ 0xC0, 0x26 }RFC5289
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256{ 0xC0, 0x27 }RFC5289
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384{ 0xC0, 0x28 }RFC5289
TLS_ECDH_RSA_WITH_AES_128_CBC_SHA256{ 0xC0, 0x29 }RFC5289
TLS_ECDH_RSA_WITH_AES_256_CBC_SHA384{ 0xC0, 0x2A }RFC5289
TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256{ 0xC0, 0x2B }RFC5289
TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384{ 0xC0, 0x2C }RFC5289
TLS_ECDH_ECDSA_WITH_AES_128_GCM_SHA256{ 0xC0, 0x2D }RFC5289
TLS_ECDH_ECDSA_WITH_AES_256_GCM_SHA384{ 0xC0, 0x2E }RFC5289
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256{ 0xC0, 0x2F }RFC5289
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384{ 0xC0, 0x30 }RFC5289
TLS_ECDH_RSA_WITH_AES_128_GCM_SHA256{ 0xC0, 0x31 }RFC5289
TLS_ECDH_RSA_WITH_AES_256_GCM_SHA384{ 0xC0, 0x32 }RFC5289
TLS_DHE_RSA_WITH_AES_128_CCM{ 0xC0, 0x9E }RFC6655
TLS_DHE_RSA_WITH_AES_256_CCM{ 0xC0, 0x9F }RFC6655
TLS_DHE_RSA_WITH_AES_128_CCM_8{ 0xC0, 0xA2 }RFC6655
TLS_DHE_RSA_WITH_AES_256_CCM_8{ 0xC0, 0xA3 }RFC6655
TLS_AES_128_GCM_SHA256{ 0x13, 0x01 }RFC8446
TLS_AES_256_GCM_SHA384{ 0x13, 0x02 }RFC8446
TLS_AES_128_CCM_SHA256{ 0x13, 0x04 }RFC8446
TLS_AES_128_CCM_8_SHA256{ 0x13, 0x05 }RFC8446

Table 20 - TLS Cipher Suites © 2025 SUSE, LLC / atsec information security.

50 of 56

Page 51
Table, extracted as text (did not parse into structured rows)
Appendix B.                      Glossary and Abbreviations AES                 Advanced Encryption Standard AES-NI              Advanced Encryption Standard New Instructions CAST                Cryptographic Algorithm Self-Tests CAVP                Cryptographic Algorithm Validation Program CBC                 Cipher Block Chaining CCM                 Counter with Cipher Block Chaining-Message Authentication Code CFB                 Cipher Feedback CMAC                Cipher-based Message Authentication Code CMVP                Cryptographic Module Validation Program CPACF               Central Processor Assist for Cryptographic Function CSP                 Critical Security Parameter CTR                 Counter Mode DES                 Data Encryption Standard DF                  Derivation Function DSA                 Digital Signature Algorithm DRBG                Deterministic Random Bit Generator ECB                 Electronic Code Book ECC                 Elliptic Curve Cryptography FFC                 Finite Field Cryptography FIPS                Federal Information Processing Standards Publication FSM                 Finite State Model GCM                 Galois Counter Mode HMAC                Hash Message Authentication Code ISA                 Instruction Set Architecture KAS                 Key Agreement Schema KAT                 Known Answer Test KW                  AES Key Wrap KWP                 AES Key Wrap with Padding MAC                 Message Authentication Code NDF                 No Derivation Function NIST                National Institute of Science and Technology OFB                 Output Feedback PAA                 Processor Algorithm Acceleration PAI                 Processor Algorithm Implementation PR                  Prediction Resistance © 2025 SUSE, LLC / atsec information security.

51 of 56

Page 52
Table, extracted as text (did not parse into structured rows)
PSS                 Probabilistic Signature Scheme RNG                 Random Number Generator RSA                 Rivest, Shamir, Addleman SDK                 Software Development Kit SHA                 Secure Hash Algorithm SHS                 Secure Hash Standard SSH                 Secure Shell SSP                 Sensitive Security Parameter TDES                Triple-DES XTS                 XEX-based Tweaked-codebook mode with cipher text Stealing © 2025 SUSE, LLC / atsec information security.

52 of 56

Page 53

Appendix C. References FIPS140-3 FIPS PUB 140-3 - Security Requirements For Cryptographic Modules March 2019 https://csrc.nist.gov/csrc/media/Projects/cryptographic-module-validationprogram/documents/fips%20140-3/FIPS%20140-3%20IG.pdf FIPS140-3_IG Implementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program October 2022 https://csrc.nist.gov/csrc/media/Projects/cryptographic-module-validationprogram/documents/fips%20140-3/FIPS%20140-3%20IG.pdf FIPS140-3_MM FIPS 140-3 Cryptographic Module Validation Program Management Manual April 2024 https://csrc.nist.gov/csrc/media/Projects/cryptographic-module-validationprogram/documents/fips%20140-3/FIPS-140-3CMVP%20Management%20Manual.pdf FIPS180-4 Secure Hash Standard (SHS) March 2012 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf FIPS186-4 Digital Signature Standard (DSS) July 2013 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-4.pdf FIPS197 Advanced Encryption Standard November 2001 https://csrc.nist.gov/publications/fips/fips197/fips-197.pdf FIPS198-1 The Keyed Hash Message Authentication Code (HMAC) July 2008 https://csrc.nist.gov/publications/fips/fips198-1/FIPS-198-1_final.pdf FIPS202 SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions August 2015 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.202.pdf PKCS#1 Public Key Cryptography Standards (PKCS) #1: RSA Cryptography Specifications Version 2.1 February 2003 https://www.ietf.org/rfc/rfc3447.txt RFC3394 Advanced Encryption Standard (AES) Key Wrap Algorithm September 2002 https://www.ietf.org/rfc/rfc3394.txt © 2025 SUSE, LLC / atsec information security.

53 of 56

Page 54

RFC5649 Advanced Encryption Standard (AES) Key Wrap with Padding Algorithm September 2009 https://www.ietf.org/rfc/rfc5649.txt SP800-38A NIST Special Publication 800-38A - Recommendation for Block Cipher Modes of Operation Methods and Techniques December 2001 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication80038a.pdf SP800-38B NIST Special Publication 800-38B - Recommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication May 2005 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38B.pdf SP800-38C NIST Special Publication 800-38C - Recommendation for Block Cipher Modes of Operation: the CCM Mode for Authentication and Confidentiality May 2004 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication80038c.pdf SP800-38D NIST Special Publication 800-38D - Recommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC November 2007 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication80038d.pdf SP800-38E NIST Special Publication 800-38E - Recommendation for Block Cipher Modes of Operation: The XTS AES Mode for Confidentiality on Storage Devices January 2010 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication80038e.pdf SP800-38F NIST Special Publication 800-38F - Recommendation for Block Cipher Modes of Operation: Methods for Key Wrapping December 2012 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38F.pdf SP800-38G NIST Special Publication 800-38G - Recommendation for Block Cipher Modes of Operation: Methods for Format - Preserving Encryption March 2016 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38G.pdf SP800-52rev2 NIST Special Publication 800-52 Revision 2 - Guidelines for the Selection, Configuration, and Use of Transport Layer Security (TLS) Implementations August 2019 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-52r2.pdf © 2025 SUSE, LLC / atsec information security.

54 of 56

Page 55

SP800-56Arev3 NIST Special Publication 800-56A Revision 3 - Recommendation for Pair Wise Key Establishment Schemes Using Discrete Logarithm Cryptography April 2018 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Ar3.pdf SP800-56Crev2 Recommendation for Key Derivation through Extraction-thenExpansion August 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Cr2.pdf SP800-57rev5 NIST Special Publication 800-57 Part 1 Revision 5 Recommendation for Key Management Part 1: General May 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.80057pt1r5.pdf SP800-90Arev1 NIST Special Publication 800-90A - Revision 1 - Recommendation for Random Number Generation Using Deterministic Random Bit Generators June 2015 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90Ar1.pdf SP800-90B NIST Special Publication 800-90B - Recommendation for the Entropy Sources Used for Random Bit Generation January 2018 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90B.pdf SP800-131Arev2 NIST Special Publication 800-131A Revision 2 - Transitions: Recommendation for Transitioning the Use of Cryptographic Algorithms and Key Lengths March 2019 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800131Ar2.pdf SP800-132 NIST Special Publication 800-132 - Recommendation for PasswordBased Key Derivation - Part 1: Storage Applications December 2010 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800132.pdf SP800-133rev2 NIST Special Publication 800-133 Revision 2 - Recommendation for Cryptographic Key Generation June 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-133r2.pdf SP800-135rev1 NIST Special Publication 800-135 Revision 1 - Recommendation for Existing Application-Specific Key Derivation Functions December 2011 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800135r1.pdf © 2025 SUSE, LLC / atsec information security.

55 of 56

Page 56

SP800-140B NIST Special Publication 800-140B - CMVP Security Policy Requirements March 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-140B.pdf © 2025 SUSE, LLC / atsec information security.

56 of 56