All modules
CMVP Validated Module · FIPS 140-3 Security Policy

NetApp CryptoMod

Certificate#4731StandardFIPS 140-3Level1TypeSoftwareEmbodimentMulti-Chip Stand AloneStatusHistoricalVendorNetApp, Inc.
Low review priority  ·  no TCB surface named  ·  last validated 4 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
StatusHistorical
CaveatInterim validation. When installed, initialized and configured as specified in section 11 of the Security Policy
VendorNetApp, Inc.

Approved Algorithms (18)

AlgorithmACVP Cert
AES-CBCA2640
AES-CCMA2640
AES-CMACA2640
AES-ECBA2640
AES-GCMA2640
AES-GMACA2640
AES-KWPA2640
AES-XTS Testing Revision 2.0A2640
Counter DRBGA2640
HMAC-SHA-1A2640
HMAC-SHA2-256A2640
HMAC-SHA2-512A2640
KDF SP800-108A2640
PBKDFA2640
SHA-1A2640
SHA2-256A2640
SHA2-512A2640
SHA3-256A2640

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for NetApp CryptoMod
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Recovery</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Status Output</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>IPSEC<br/>HTTPS</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>kernel<br/>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for NetApp CryptoMod
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Recovery</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Status Output</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>IPSEC<br/>HTTPS</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>kernel<br/>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

NetApp, Inc. NetApp CryptoMod 3.0

Page 2
Table of Contents
#SectionPage
Page 4
List of Tables
ItemPage
Table 1: Security Levels5
Table 2: Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets)8
Table 3: Tested Operational Environments - Software, Firmware, Hybrid8
Table 4: Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid15
Table 5: Modes List and Description15
Table 6: Approved Algorithms16
Table 7: Vendor-Affirmed Algorithms16
Table 8: Security Function Implementations19
Table 9: Entropy Certificates21
Table 10: Entropy Sources21
Table 11: Ports and Interfaces23
Table 12: Roles23
Table 13: Approved Services27
Table 14: Storage Areas28
Table 15: SSP Input-Output Methods29
Table 16: SSP Zeroization Methods29
Table 17: SSP Table 131
Table 18: SSP Table 233
Table 19: Pre-Operational Self-Tests33
Table 20: Conditional Self-Tests34
Table 21: Pre-Operational Periodic Information35
Table 22: Conditional Periodic Information36
Table 23: Error States36
Figure 1: Block Diagram7
Page 5
SectionTitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication1
5Software/Firmware security1
6Operational environment1
7Physical securityN/A
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacksN/A
Overall Level1
1.1 Overview

The NetApp CryptoMod module, hereby referred to as either CryptoMod, or “the Module”, is a multi-chip standalone module validated at FIPS 140-3 Security Level 1. Specifically, the module meets the following security levels for each of the individual sections in the FIPS 140-3 standard:

1.2 Security Levels
1.3 Additional Information

In accordance with AS02.05, [ISO 19790] §7.7 Physical Security is optional and does not apply to the Module. In accordance with current CMVP policy, [ISO 19790] §7.8 Non-Invasive Security is not applicable.

2.1 Description

Purpose and Use: The Module is a kernel mode cryptographic software library providing a C-language application program interface (API) for use by ONTAP kernel modules that require cryptographic functionality. The Module is designated as a software module with multi-chip standalone embodiment based on the descriptions of [ISO 19790] AS02.03. The Module is intended for use by US and Canadian Federal agencies and other markets that require FIPS 140-3 validated cryptographic functionality. The Module’s formal name and version are “CryptoMod” and “3.0”, respectively. The Module’s design corresponds to the Module security roles. Security roles enforced by the Module are described in the appropriate context of the document.

Page 6

Module Type: Software Module Embodiment: MultiChipStand Cryptographic Boundary: The cryptographic boundary of the CryptoMod module is the cryptomod_fips kernel module of the ONTAP OS kernel. The cryptographic boundary is depicted in red in the figure below. The Module’s approved DRBG is used to supply the Module’s cryptographic keys. Tested Operational Environment’s Physical Perimeter (TOEPP): The Tested OE’s Physical Perimeter (TOEPP) for the module is the enclosure of the NetApp controller.

Page 7
Package or File NameSoftware/ Firmware VersionFeaturesIntegrity Test
cryptomod_fips.ko3.0N/AHMAC-SHA2-256
2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification

Page 8
Operating SystemHardware PlatformProcessorsPAA/PAIHypervisor or Host OSVersion(s)
ONTAP 9.11.1AFF A250Intel Xeon D-2164ITNoN/A3.0
ONTAP 9.11.1AFF A250Intel Xeon D-2164ITYesN/A3.0
ONTAP 9.11.1AFF A400Intel Xeon Silver 4210NoN/A3.0
ONTAP 9.11.1AFF A400Intel Xeon Silver 4210YesN/A3.0
ONTAP 9.11.1AFF A900Intel Xeon Platinum 8352YNoN/A3.0
ONTAP 9.11.1AFF A900Intel Xeon Platinum 8352YYesN/A3.0
Operating SystemHardware Platform
ONTAP 9.11AFF A150
ONTAP 9.12AFF A150
ONTAP 9.13AFF A150
ONTAP 9.14AFF A150
ONTAP 9.15AFF A150
ONTAP 9.16AFF A150
ONTAP 9.17AFF A150
ONTAP 9.15AFF A1K
ONTAP 9.16AFF A1K
ONTAP 9.17AFF A1K
ONTAP 9.11AFF A220
ONTAP 9.12AFF A220
ONTAP 9.13AFF A220
ONTAP 9.14AFF A220
ONTAP 9.15AFF A220
ONTAP 9.16AFF A220
ONTAP 9.17AFF A220
ONTAP 9.12AFF A250
ONTAP 9.13AFF A250
ONTAP 9.14AFF A250
ONTAP 9.15AFF A250

Table 2: Tested Module Identification

Page 9
Operating SystemHardware Platform
ONTAP 9.16AFF A250
ONTAP 9.17AFF A250
ONTAP 9.11AFF A300
ONTAP 9.12AFF A300
ONTAP 9.13AFF A300
ONTAP 9.14AFF A300
ONTAP 9.15AFF A300
ONTAP 9.16AFF A300
ONTAP 9.11AFF A320
ONTAP 9.12AFF A320
ONTAP 9.13AFF A320
ONTAP 9.14AFF A320
ONTAP 9.12AFF A400
ONTAP 9.13AFF A400
ONTAP 9.14AFF A400
ONTAP 9.15AFF A400
ONTAP 9.16AFF A400
ONTAP 9.17AFF A400
ONTAP 9.16AFF A20
ONTAP 9.17AFF A20
ONTAP 9.16AFF A30
ONTAP 9.17AFF A30
ONTAP 9.16AFF A50
ONTAP 9.17AFF A50
ONTAP 9.15AFF A70
ONTAP 9.16AFF A70
ONTAP 9.17AFF A70
ONTAP 9.15AFF A90
ONTAP 9.16AFF A90
ONTAP 9.17AFF A90
ONTAP 9.11AFF A700
ONTAP 9.12AFF A700
ONTAP 9.13AFF A700
ONTAP 9.14AFF A700
ONTAP 9.15AFF A700
ONTAP 9.16AFF A700
ONTAP 9.17AFF A700
ONTAP 9.11AFF A800
ONTAP 9.12AFF A800
ONTAP 9.13AFF A800
ONTAP 9.14AFF A800
ONTAP 9.15AFF A800
ONTAP 9.16AFF A800
ONTAP 9.17AFF A800
ONTAP 9.12AFF A900
ONTAP 9.13AFF A900
ONTAP 9.14AFF A900
ONTAP 9.15AFF A900
Page 10
Operating SystemHardware Platform
ONTAP 9.16AFF A900
ONTAP 9.17AFF A900
ONTAP 9.16AFF C30
ONTAP 9.17AFF C30
ONTAP 9.16AFF C60
ONTAP 9.17AFF C60
ONTAP 9.16AFF C80
ONTAP 9.17AFF C80
ONTAP 9.11AFF C190
ONTAP 9.12AFF C190
ONTAP 9.13AFF C190
ONTAP 9.14AFF C190
ONTAP 9.15AFF C190
ONTAP 9.16AFF C190
ONTAP 9.17AFF C190
ONTAP 9.11AFF C250
ONTAP 9.12AFF C250
ONTAP 9.13AFF C250
ONTAP 9.14AFF C250
ONTAP 9.15AFF C250
ONTAP 9.16AFF C250
ONTAP 9.17AFF C250
ONTAP 9.11AFF C400
ONTAP 9.12AFF C400
ONTAP 9.13AFF C400
ONTAP 9.14AFF C400
ONTAP 9.15AFF C400
ONTAP 9.16AFF C400
ONTAP 9.17AFF C400
ONTAP 9.11AFF C800
ONTAP 9.12AFF C800
ONTAP 9.13AFF C800
ONTAP 9.14AFF C800
ONTAP 9.15AFF C800
ONTAP 9.16AFF C800
ONTAP 9.17AFF C800
ONTAP 9.16ASA A1K
ONTAP 9.17ASA A1K
ONTAP 9.16ASA A20
ONTAP 9.17ASA A20
ONTAP 9.16ASA A30
ONTAP 9.17ASA A30
ONTAP 9.16ASA A50
ONTAP 9.17ASA A50
ONTAP 9.16ASA A70
ONTAP 9.17ASA A70
ONTAP 9.16ASA A90
ONTAP 9.17ASA A90
Page 11
Operating SystemHardware Platform
ONTAP 9.13ASA A150
ONTAP 9.14ASA A150
ONTAP 9.15ASA A150
ONTAP 9.16ASA A150
ONTAP 9.17ASA A150
ONTAP 9.13ASA A250
ONTAP 9.14ASA A250
ONTAP 9.15ASA A250
ONTAP 9.16ASA A250
ONTAP 9.17ASA A250
ONTAP 9.13ASA A400
ONTAP 9.14ASA A400
ONTAP 9.15ASA A400
ONTAP 9.16ASA A400
ONTAP 9.17ASA A400
ONTAP 9.13ASA A800
ONTAP 9.14ASA A800
ONTAP 9.15ASA A800
ONTAP 9.16ASA A800
ONTAP 9.17ASA A800
ONTAP 9.13ASA A900
ONTAP 9.14ASA A900
ONTAP 9.15ASA A900
ONTAP 9.16ASA A900
ONTAP 9.17ASA A900
ONTAP 9.11ASA AFF A220
ONTAP 9.12ASA AFF A220
ONTAP 9.13ASA AFF A220
ONTAP 9.14ASA AFF A220
ONTAP 9.15ASA AFF A220
ONTAP 9.16ASA AFF A220
ONTAP 9.17ASA AFF A220
ONTAP 9.11ASA AFF A250
ONTAP 9.12ASA AFF A250
ONTAP 9.13ASA AFF A250
ONTAP 9.11ASA AFF A400
ONTAP 9.12ASA AFF A400
ONTAP 9.13ASA AFF A400
ONTAP 9.11ASA AFF A700
ONTAP 9.12ASA AFF A700
ONTAP 9.13ASA AFF A700
ONTAP 9.14ASA AFF A700
ONTAP 9.15ASA AFF A700
ONTAP 9.16ASA AFF A700
ONTAP 9.17ASA AFF A700
ONTAP 9.11ASA AFF A800
ONTAP 9.12ASA AFF A800
ONTAP 9.13ASA AFF A800
Page 12
Operating SystemHardware Platform
ONTAP 9.16ASA C30
ONTAP 9.17ASA C30
ONTAP 9.13ASA C250
ONTAP 9.14ASA C250
ONTAP 9.15ASA C250
ONTAP 9.16ASA C250
ONTAP 9.17ASA C250
ONTAP 9.13ASA C400
ONTAP 9.14ASA C400
ONTAP 9.15ASA C400
ONTAP 9.16ASA C400
ONTAP 9.17ASA C400
ONTAP 9.13ASA C800
ONTAP 9.14ASA C800
ONTAP 9.15ASA C800
ONTAP 9.16ASA C800
ONTAP 9.17ASA C800
ONTAP 9.16FAS50
ONTAP 9.17FAS50
ONTAP 9.15FAS70
ONTAP 9.16FAS70
ONTAP 9.17FAS70
ONTAP 9.15FAS90
ONTAP 9.16FAS90
ONTAP 9.17FAS90
ONTAP 9.11FAS2720
ONTAP 9.12FAS2720
ONTAP 9.13FAS2720
ONTAP 9.14FAS2720
ONTAP 9.15FAS2720
ONTAP 9.16FAS2720
ONTAP 9.17FAS2720
ONTAP 9.11FAS2750
ONTAP 9.12FAS2750
ONTAP 9.13FAS2750
ONTAP 9.14FAS2750
ONTAP 9.15FAS2750
ONTAP 9.16FAS2750
ONTAP 9.17FAS2750
ONTAP 9.13FAS2820
ONTAP 9.14FAS2820
ONTAP 9.15FAS2820
ONTAP 9.16FAS2820
ONTAP 9.17FAS2820
ONTAP 9.11FAS500f
ONTAP 9.12FAS500f
ONTAP 9.13FAS500f
ONTAP 9.14FAS500f
Page 13
Operating SystemHardware Platform
ONTAP 9.15FAS500f
ONTAP 9.16FAS500f
ONTAP 9.17FAS500f
ONTAP 9.11FAS8200
ONTAP 9.12FAS8200
ONTAP 9.13FAS8200
ONTAP 9.14FAS8200
ONTAP 9.15FAS8200
ONTAP 9.16FAS8200
ONTAP 9.11FAS8300
ONTAP 9.12FAS8300
ONTAP 9.13FAS8300
ONTAP 9.14FAS8300
ONTAP 9.15FAS8300
ONTAP 9.16FAS8300
ONTAP 9.17FAS8300
ONTAP 9.11FAS8700
ONTAP 9.12FAS8700
ONTAP 9.13FAS8700
ONTAP 9.14FAS8700
ONTAP 9.15FAS8700
ONTAP 9.16FAS8700
ONTAP 9.17FAS8700
ONTAP 9.11FAS9000
ONTAP 9.12FAS9000
ONTAP 9.13FAS9000
ONTAP 9.14FAS9000
ONTAP 9.15FAS9000
ONTAP 9.16FAS9000
ONTAP 9.17FAS9000
ONTAP 9.11FAS9500
ONTAP 9.12FAS9500
ONTAP 9.13FAS9500
ONTAP 9.14FAS9500
ONTAP 9.15FAS9500
ONTAP 9.16FAS9500
ONTAP 9.17FAS9500
ONTAP 9.11AFF A700s
ONTAP 9.12AFF A700s
ONTAP 9.13AFF A700s
ONTAP 9.14AFF A700s
ONTAP 9.15AFF A700s
ONTAP 9.16AFF A700s
ONTAP 9.17AFF A700s
Data ONTAP Select 9.11 with VMware ESXi 7, 8FDvM300-16GB
Data ONTAP Select 9.12 with VMware ESXi 7, 8FDvM300-16GB
Data ONTAP Select 9.13 with VMware ESXi 7, 8FDvM300-16GB
Data ONTAP Select 9.14 with VMware ESXi 7, 8FDvM300-16GB
Page 14
Operating SystemHardware Platform
Data ONTAP Select 9.15 with VMware ESXi 7, 8FDvM300-16GB
Data ONTAP Select 9.16 with VMware ESXi 7, 8FDvM300-16GB
Data ONTAP Select 9.17 with VMware ESXi 7, 8FDvM300-16GB
Data ONTAP Select 9.17 with VMware ESXi 9FDvM300-16GB
Data ONTAP Select 9.16 with RHEL Server KVM 9.5, 9.6FDvM300-16GB
Data ONTAP Select 9.17 with RHEL Server KVM 9.5, 9.6FDvM300-16GB
Data ONTAP Select 9.14 with RHEL Server KVM 8.6, 8.7, 8.8, 8.9, 9.0, 9.1, 9.2, 9.3, 9.4FDvM300-16GB
Data ONTAP Select 9.15 with RHEL Server KVM 8.6, 8.7, 8.8, 8.9, 9.0, 9.1, 9.2, 9.3, 9.4FDvM300-16GB
Data ONTAP Select 9.16 with RHEL Server KVM 8.6, 8.7, 8.8, 8.9, 9.0, 9.1, 9.2, 9.3, 9.4FDvM300-16GB
Data ONTAP Select 9.11 with VMware ESXi 7, 8FDvM300-64GB
Data ONTAP Select 9.12 with VMware ESXi 7, 8FDvM300-64GB
Data ONTAP Select 9.13 with VMware ESXi 7, 8FDvM300-64GB
Data ONTAP Select 9.14 with VMware ESXi 7, 8FDvM300-64GB
Data ONTAP Select 9.15 with VMware ESXi 7, 8FDvM300-64GB
Data ONTAP Select 9.16 with VMware ESXi 7, 8FDvM300-64GB
Data ONTAP Select 9.17 with VMware ESXi 7, 8FDvM300-64GB
Data ONTAP Select 9.17 with VMware ESXi 9FDvM300-64GB
Data ONTAP Select 9.16 with RHEL Server KVM 9.5, 9.6FDvM300-64GB
Data ONTAP Select 9.17 with RHEL Server KVM 9.5, 9.6FDvM300-64GB
Data ONTAP Select 9.14 with RHEL Server KVM 8.6, 8.7, 8.8, 8.9, 9.0, 9.1, 9.2, 9.3, 9.4FDvM300-64GB
Data ONTAP Select 9.15 with RHEL Server KVM 8.6, 8.7, 8.8, 8.9, 9.0, 9.1, 9.2, 9.3, 9.4FDvM300-64GB
Data ONTAP Select 9.16 with RHEL Server KVM 8.6, 8.7, 8.8, 8.9, 9.0, 9.1, 9.2, 9.3, 9.4FDvM300-64GB
Data ONTAP Select 9.11 with VMware ESXi 7, 8FDvM300-128GB
Data ONTAP Select 9.12 with VMware ESXi 7, 8FDvM300-128GB
Data ONTAP Select 9.13 with VMware ESXi 7, 8FDvM300-128GB
Data ONTAP Select 9.14 with VMware ESXi 7, 8FDvM300-128GB
Data ONTAP Select 9.15 with VMware ESXi 7, 8FDvM300-128GB
Data ONTAP Select 9.16 with VMware ESXi 7, 8FDvM300-128GB
Data ONTAP Select 9.17 with VMware ESXi 7, 8FDvM300-128GB
Data ONTAP Select 9.17 with VMware ESXi 9FDvM300-128GB
Amazon FSx for NetApp ONTAP 9.11AWS EC2 Nitro
Amazon FSx for NetApp ONTAP 9.12AWS EC2 Nitro
Amazon FSx for NetApp ONTAP 9.13AWS EC2 Nitro
Amazon FSx for NetApp ONTAP 9.14AWS EC2 Nitro
Amazon FSx for NetApp ONTAP 9.15AWS EC2 Nitro
Amazon FSx for NetApp ONTAP 9.16AWS EC2 Nitro
Amazon FSx for NetApp ONTAP 9.17AWS EC2 Nitro
Cloud Volumes ONTAP 9.11Microsoft Azure Compute
Cloud Volumes ONTAP 9.12Microsoft Azure Compute
Page 15
Operating SystemHardware Platform
Cloud Volumes ONTAP 9.13Microsoft Azure Compute
Cloud Volumes ONTAP 9.14Microsoft Azure Compute
Cloud Volumes ONTAP 9.15Microsoft Azure Compute
Cloud Volumes ONTAP 9.16Microsoft Azure Compute
Cloud Volumes ONTAP 9.17Microsoft Azure Compute
Cloud Volumes ONTAP 9.11Google Compute Engine
Cloud Volumes ONTAP 9.12Google Compute Engine
Cloud Volumes ONTAP 9.13Google Compute Engine
Cloud Volumes ONTAP 9.14Google Compute Engine
Cloud Volumes ONTAP 9.15Google Compute Engine
Cloud Volumes ONTAP 9.16Google Compute Engine
Cloud Volumes ONTAP 9.17Google Compute Engine
Mode NameDescriptionTypeStatus Indicator
Approved modeThe module must be installed per instructions provided in Section 11 of this document.ApprovedFIPS mode = true

Table 4: Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid CMVP makes no statement as to the correct operation of the module or the security strengths of the generated keys when so ported if the specific operational environment is not listed on the validation certificate.

2.3 Excluded Components

No components are excluded from the [FIPS 140-3] requirements.

2.4 Modes of Operation

Modes List and Description: Table 5: Modes List and Description mode when all the power up self-tests have completed successfully, and only Approved

Page 16
AlgorithmCAVP CertPropertiesReference
AES-CBCA6624-SP 800-38A
AES-CCMA6624-SP 800-38C
AES-CMACA6624-SP 800-38B
AES-ECBA6624-SP 800-38A
AES-GCMA6624-SP 800-38D
AES-GMACA6624-SP 800-38D
AES-KWPA6624-SP 800-38F
AES-XTS Testing Revision 2.0A6624-SP 800-38E
Counter DRBGA6624-SP 800-90A Rev. 1
HMAC-SHA-1A6624-FIPS 198-1
HMAC-SHA2-256A6624-FIPS 198-1
HMAC-SHA2-512A6624-FIPS 198-1
KDF SP800-108A6624-SP 800-108 Rev. 1
PBKDFA6624-SP 800-132
SHA-1A6624-FIPS 180-4
SHA2-256A6624-FIPS 180-4
SHA2-512A6624-FIPS 180-4
SHA3-256A6624-FIPS 202
NamePropertiesImplementationReference
CKG - Section 6.3Key Type:SymmetricNetApp CryptoModSP 800-133 Rev. 2 Section 6.3: Symmetric Keys Produced by Combining Multiple Keys and Other Data. (Method 2)

algorithms are invoked. If the power-up self-tests fail, then the module reboots the hardware platform. Mode Change Instructions and Status: The Module only supports an Approved mode of operation. Degraded Mode Description: The Module does not support a degraded mode of operation.

2.5 Algorithms

Approved Algorithms: Table 6: Approved Algorithms Vendor-Affirmed Algorithms: 2) Table 7: Vendor-Affirmed Algorithms

Page 17
NameTypeDescriptionPropertiesAlgorithms
Symmetric Encryption and DecryptionBC-UnAuthSymmetric encryption and decryptionKey Length:128, 256 bitsAES-CBC: (A6624) AES-ECB: (A6624) AES-XTS Testing Revision 2.0: (A6624)
Authenticated Symmetric Encryption and DecryptionBC-AuthAuthenticated symmetric encryption and decryptionKey Length:128, 256 bits Key Length (CCM):128 bitsAES-CCM: (A6624) AES-CMAC: (A6624) AES-GCM: (A6624) AES-GMAC: (A6624)
Message DigestSHAMessage DigestPublication:FIPS 180-4SHA-1: (A6624) SHA2-256: (A6624) SHA2-512: (A6624) SHA3-256: (A6624)
Keyed HashMACKeyed HashPublication:FIPS 198-1HMAC-SHA-1: (A6624) HMAC-SHA2- 256: (A6624) HMAC-SHA2- 512: (A6624)

Non-Approved, Allowed Algorithms: N/A for this module. The Module does not support any Non-Approved, Allowed Algorithms. Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. The Module does not support any Non-Approved, Allowed Algorithms with No Security Claimed. Non-Approved, Not Allowed Algorithms: N/A for this module. The Module does not support any Non-Approved, Not Allowed Algorithms.

2.6 Security Function Implementations
Page 18
NameTypeDescriptionPropertiesAlgorithms
AES Keyed HashBC-Auth MACKeyed HashKey Length:128, 256 bits Key Length (CCM):128 bitsAES-CMAC: (A6624) AES-GMAC: (A6624)
Random Number GenerationDRBGRandom Number GenerationPublication:SP 800-90A Rev. 1Counter DRBG: (A6624)
Entropy Noise SourceENT-Cond ENT-ESV ENT-NPEntropy noise sourcePublication:SP 800-90BSHA3-256: (A6624)
Cryptographic Key Generation (CKG)CKGAES keys generated to comply with the approved key generation guidelines of SP800-133 Rev. 2, Section 6.3, Symmetric Keys Produced by Combining Multiple Keys and Other DataKey Length:128, 256 bitsSHA3-256: (A6624)
Key DerivationKBKDF PBKDFDerive keying materialPublications:SP 800-108 Rev. 1 UPD 1, SP 800- 132 Key size:8 to 4096 bit derived keysKDF SP800- 108: (A6624) PBKDF: (A6624)
KTS-AESKTS-WrapAES keys generated to comply with the approved key generation guidelines of SP800-133 Rev. 2, Section 6.3, Symmetric Keys Produced by Combining Multiple Keys and Other DataPublication:SP 800-38F Key Strength:Key establishment methodology provides between 128 and 256 bits of encryption strengthAES-KWP: (A6624)
Software Integrity TestMACHMAC-SHA2- 256 used to perform the software integrity testKey size:256 bitsHMAC-SHA2- 256: (A6624)
Page 19
NameTypeDescriptionPropertiesAlgorithms
Perform self- tests (All)BC-Auth BC-UnAuth DRBG KBKDF MAC PBKDF SHAAll self-tests executed by the module at bootAES-CBC: (A6624) AES-CCM: (A6624) AES-CMAC: (A6624) AES-ECB: (A6624) AES-GCM: (A6624) AES-XTS Testing Revision 2.0: (A6624) Counter DRBG: (A6624) HMAC-SHA-1: (A6624) HMAC-SHA2- 256: (A6624) HMAC-SHA2- 512: (A6624) KDF SP800- 108: (A6624) PBKDF: (A6624) SHA-1: (A6624) SHA2-256: (A6624) SHA2-512: (A6624) SHA3-256: (A6624)

Table 8: Security Function Implementations

2.7 Algorithm Specific Information

The AES-GCM IV is partially generated by an industry protocol and is always passed to the module via an API call. The counter portion of the IV is set by the module within the module’s cryptographic boundary. When used with TLS 1.2/1.3, the AES-GCM IV is constructed in compliance with IG C.H scenario 1. The GCM IV generation follows RFC 5288. The counter portion of the IV is set by the module within the module’s cryptographic boundary. The module does not implement the TLS protocol. The module’s implementation of AES-GCM, when used for TLS, is used with another ONTAP application running outside of the module’s boundary. The design of the TLS

Page 20

protocol implicitly ensures that the counter portion of the IV will not exhaust all its possible values. When used with the IPsec-v3 protocol, GCM IV generation follows RFC 4106 and is constructed in compliance with IG C.H scenario

  1. The counter portion of the IV is set by the module within the module’s cryptographic boundary. The module does not implement the IPsec protocol. The module’s implementation of AES-GCM, when used for IPsec, is used with another ONTAP application running outside of the module’s boundary. The design of the IPsec protocol implicitly ensures that the counter portion of the IV will not exhaust all its possible values. When used with SMB 3.x, the AES-GCM IV is constructed in compliance with IG C.H scenario 5 with 8 bytes of random data followed by 8 bytes from the network context. The counter portion of the IV is set by the module within the module’s cryptographic boundary. The module does not implement the SMB protocol. The module’s implementation of AES-GCM, when used for SMB, is used with another ONTAP application running outside of the module’s boundary. The design of the SMB protocol implicitly ensures that the counter portion of the IV will not exhaust all its possible values. In all instances, the AES-GCM IV is not persistently stored; therefore, whenever the module’s power is lost and then restored, the user of the module (i.e., TLS, IPsec, or SMB) along with the ONTAP application that implements the protocol, must re-establish keying material using new random values and a KDF operation to establish the pertinent network communication channel. b) PBKDF Usage The module provides password-based key derivation (PBKD), compliant with NIST SP 800-132 Rev.
  2. The CryptoMod module supports option 1a from section 5.4 of [SP800-132]. In option 1a, the Master Key (MK), or a segment of the MK, is used directly as the Data Protection Key (DPK). In line with the requirements for NIST SP800-132, keys generated using the approved PBKDF algorithm must only be used for storage applications. The length of the MK or DPK shall be 112 bits or more. A salt, with a length of at least 128 bits, shall be generated using the NIST SP 800-90Arev1 DRBG. The iteration count shall be selected as large as possible, with a minimum value of 1000. Passwords or passphrases, used as input for the PBKDF, shall not be used as cryptographic keys. The length of the password of passphrase shall be at least 32 characters and shall consist of ASCII printable characters. The probability of guessing the value is estimated to be: 1/9532 <10-64, which is less than 2-112. As the module is a general-purpose software module, it is not possible to predict the use of the PBKDF, however a user of the module should also note that a password should contain at least enough entropy to be unguessable and contain enough entropy to reflect
Page 21
Cert NumberVendor Name
Entropy Certificate #E1NetApp, Inc.
NameTypeOperational EnvironmentSample SizeEntropy per SampleConditioning Component
CPU Jitter RNG v3.4.0Non- PhysicalONTAP 9.16.1 on Intel® Xeon® Bronze 3508U (Sapphire Rapids), ONTAP 9.16.1 on Intel® Xeon® Gold 6438N (Sapphire Rapids), ONTAP 9.16.1 on Intel® Xeon® Platinum 8352Y (Ice Lake), ONTAP 9.16.1 on Intel® Xeon® D-1735TR (Ice Lake), ONTAP 9.16.1 on Silver 4210 (Cascade Lake), ONTAP 9.16.1 on Intel® Xeon® Silver 4114 (Skylake), ONTAP 9.16.1 on Intel® Xeon® D-2164IT (Skylake), ONTAP 9.16.1 on Intel® Xeon® D- 1557 (Broadwell)641SHA3-256 (A2640)

the security strength required for the key being generated. Users are referred to Appendix A, “Security Considerations” of NIST SP 800-132 Rev. 2 for further information on password selection. c) AES-XTS Usage Per the requirements of NIST SP 800-38E, AES-XTS mode shall be used for storage purposes only. The length of the AES-XTS data unit does not exceed 220 blocks. In accordance with IG C.I when generating an AES-XTS key, the module checks to ensure that key1 is not equal to key2. If key1 is equal to key2, then the module fails the key generation request. d) SHA-1 Usage The module implements SHA-1 for usage in the following:

2.8 RBG and Entropy

Table 9: Entropy Certificates Table 10: Entropy Sources

Page 22

The ESV (#E1) entropy source used by the Counter DRBG in the module is described above. The module’s embedded entropy source provides 256 bits of min-entropy per 256-bit output sample of full entropy.

2.9 Key Generation

CryptoMod implements a NIST SP800-90A Rev. 1 Counter DRBG for the generation of random bits and keys. The implementation of the Counter DRBG uses AES-256 (maximum of 256 bits of security strength) as the block cipher along with the appropriate derivation function. On the tested system, entropy is provided from the module’s embedded jitter-entropy CPU ESV (#E1) implementation. The module uses its embedded entropy source in accordance with the ESV (#E1) Public Use Document. The module requests a minimum number of 512 bits of entropy from its Operational Environment per each call. In addition, the vendor affirmed CKG implementation uses an Approved Counter DRBG as specified in NIST SP 800-90 A Rev.

  1. The key generation method adheres to NIST SP800-133 Rev. 2, and the module utilizes post processing. The output of the CryptoMod DRBG is XOR’d with a random mask obtained from ESV (#E1) to compute the secret value "K" as per Section 6.3, method #2 in NIST SP800-133 Rev. 2 with m = 1 and n =
  2. The post-processing is performed on the DRBG output with the post-processing operation resulting in the new "U".
2.10 Key Establishment

Key Agreement Schemes The Module does not support any key establishment algorithms. Key Transport Schemes The module implements the following Approved/allowed key transport methods as specified in [FIPS140-3_IG] IG D.G which have been CAVP tested and validated: • AES-KWP wrap/unwrap

2.11 Industry Protocols

The Module conforms to Resolution 3 per [FIPS140-3_IG] D.C References to the Support of Industry Protocols: while it provides cryptographic APIs that may be used by IPSec and TLS components, the Module does not contain an implementation for IPSec or TLS. The following caveat is required: No parts of the IPSec and TLS protocols, other than the approved cryptographic algorithms and the KDFs, have been tested by the CAVP and CMVP.

3 Cryptographic Module Interfaces
3.1 Ports and Interfaces
Page 23
Physical PortLogical Interface(s)Data That Passes
N/AControl InputAPI call parameters passed by reference or value for cryptographic service input
N/AControl OutputNot implemented
N/AData InputAPI call parameters passed by reference or value for cryptographic service input
N/AData OutputAPI call parameters passed by reference or value for cryptographic service output
N/AStatus OutputAPI return value: enumerated status resulting from call execution
NameTypeOperator TypeAuthentication Methods
UserRoleUser
Crypto OfficerRoleCrypto Officer
NameDescripti onIndicat orInputsOutputsSecurity FunctionsSSP Access
Show versioning informationReturns the name of the moduleN/AAPI call paramete rsModule name and versionCrypto Officer

Table 11: Ports and Interfaces As a software-only module, CryptoMod does not have any physical ports. The logical interfaces for the module are defined by the API for CryptoMod. If the module enters an error state, then data output interfaces are disabled (note: the module does not utilize control input or output interfaces).

4 Roles, Services, and Authentication

The Module does not provide an authentication or identification method of its own; operators implicitly assume an authorized role based on the service selected.

4.2 Roles

Table 12: Roles The module supports the User and mandatory Cryptographic Officer operational role, which is implicitly defined. The module does not support a maintenance role, nor does it support a bypass capability. The module does not support multiple concurrent operators.

4.3 Approved Services
Page 24
NameDescripti onIndicat orInputsOutputsSecurity FunctionsSSP Access
and the version associate d with the module
Show statusReturn FIPS mode statusFIPS statusAPI call paramete rsFIPS statusCrypto Officer
Perform on demand self-testsInitiates and runs the pre- operationa l self-testsAPI output of 0 indicate s successAPI call paramete rsAPI output of 0 indicates success, non-zero indicates failurePerform self-tests (All) Software Integrity TestCrypto Officer
Encryption/decrypt ionPerform encryption or decryption using AESAPI output of 0 indicate s successAPI call paramete rsStatus return, plaintext or ciphertex tSymmetric Encryption and DecryptionUser - AES key: E,W - AES XTS key: E,W
Authenticated encryption/decrypt ionPerform encryption or decryption using AES CCM or AES GCMAPI output of 0 indicate s successAPI call paramete rsStatus return, plaintext or ciphertex tAuthenticat ed Symmetric Encryption and DecryptionUser - AES CCM key: E,W - AES GCM key: E,W
Key wrapping/unwrapp ingPerform key wrapping or unwrappin g using AESAPI output of 0 indicate s successAPI call paramete rsStatus return, wrapped or unwrapp ed keyKTS-AESUser - AES key: E,R,W - CPKEK key: E,R,W
Random bit generationProvide random bits from the module's DRBGAPI output of 0 indicate s successAPI call paramete rsStatus, random bytesEntropy Noise Source Random Number GenerationUser - DRBG V value: E,G - DRBG entropy input: E,G - DRBG internal state key: E,G
Page 25
NameDescripti onIndicat orInputsOutputsSecurity FunctionsSSP Access
- ESV state: E,G
Key generationPerform key generation using the module's DRBGAPI output of 0 indicate s successAPI call paramete rsStatus return, keyEntropy Noise Source Random Number Generation Cryptograp hic Key Generation (CKG)User - AES key: R - AES CCM key: R - AES CMAC key: R - AES GCM key: R - AES GMAC key: R - AES KEK key: R - AES XTS key: R
HMAC message authenticationGenerate or verify data integrityAPI output of 0 indicate s successAPI call paramete rsStatus return, tag valueKeyed HashUser - HMAC key: E,R,W
AES message authenticationGenerate or verify data integrityAPI output of 0 indicate s successAPI call paramete rsStatus return, tag valueAES Keyed HashUser - AES CCM key: E,R,W - AES GCM key: E,R,W
HashingPerform SHA hashing functionAPI output of 0 indicate s successAPI call paramete rsStatus return, digestMessage DigestUser
Key derivationPerform key derivation using PBKDF or NIST SPAPI output of 0 indicate s successAPI call paramete rsStatus return, keyKey DerivationUser - Passphras e: E,W,Z - CPKEK key: G,R
Page 26
NameDescripti onIndicat orInputsOutputsSecurity FunctionsSSP Access
800-108 in CTR mode- KDK key: E,W - KDK output key: G,R
ZeroizeZeroize and dellocate memory containing sensitive dataNoneReboot or power cycle NetApp platformNoneCrypto Officer - AES key: Z - AES CCM key: Z - AES CMAC key: Z - AES GCM key: Z - AES GMAC key: Z - AES KEK key: Z - AES XTS key: Z - CPKEK key: Z - HMAC key: Z - DRBG V value: Z - DRBG entropy input: Z - DRBG internal state key: Z - DRBG seed: Z - ESV state: Z - KDK key: Z - KDK output key: Z
Page 27
NameDescripti onIndicat orInputsOutputsSecurity FunctionsSSP Access
- Passphras e: Z

e: Z Table 13: Approved Services Legend: G = Generate: The module generates or derives the SSP. R = Read: The SSP is read from the module (e.g., the SSP is output). W = Write: The SSP is updated, imported, or written to the module. E = Execute: The module uses the SSP in performing a cryptographic operation. Z = Zeroize: The module zeroizes the SSP.

4.4 Non-Approved Services

N/A for this module. The Module does not support any non-approved services.

4.5 External Software/Firmware Loaded

The Module does not have the capability of loading software or firmware from an external source.

5 Software/Firmware Security
5.1 Integrity Techniques

The module compares the HMAC-SHA2-256 digest created over the .text and .data sections of the module versus the digest pre-calculated at compile time. The module’s self-integrity check is automatically performed when the module is loaded into kernel memory. Since the module, once loaded, cannot be unloaded, the self-integrity check can only be initiated by rebooting the platform.

5.2 Initiate on Demand

The Module does not support initiate on demand functionality. The self-integrity check can only be initiated by rebooting the platform.

6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Modifiable

Page 28
Storage Area NameDescriptionPersistence Type
RAMTemporary, plaintext storageDynamic
NameFromToFormat TypeDistribution TypeEntry TypeSFI or Algorithm
[Input] Call stack parametersCalling applicationModulePlaintextManualElectronic

How Requirements are Satisfied: The module operates in a modifiable operational environment on the validated platforms and the vendor-affirmed platforms listed in Section 2.2 Tested and Vendor Affirmed Module Version and Identification. The Module conforms to [FIPS 140-3_IG] 2.3.C Processor Algorithm Accelerators (PAA) and Processor Algorithm Implementation (PAI). The AES-NI functions are identified by [FIPS 140-3_IG] 2.3.C as a known PAA.

6.2 Configuration Settings and Restrictions

No operational environment restrictions are required for operation in the approved mode. As indicated in Section 2, the Module always operates in the approved mode.

7 Physical Security

Physical Security requirements are not applicable for this software Module.

8 Non-Invasive Security

In accordance with current CMVP policy, Non-Invasive Security is not applicable.

9 Sensitive Security Parameters Management
9.1 Storage Areas

Table 14: Storage Areas The cryptographic module does not persistently store keys. Keys and CSPs are passed to the module by the calling kernel process. The keys and CSPs are stored in nondumpable memory in plaintext. Keys and CSPs residing in internally allocated data structures (during the lifetime of an API call) can only be accessed using the module defined API. The ONTAP operating system protects memory and process space from unauthorized access.

9.2 SSP Input-Output Methods
Page 29
NameFromToFormat TypeDistribution TypeEntry TypeSFI or Algorithm
[Output] Call stack parametersModuleCalling applicationPlaintextManualElectronic
Zeroization MethodDescriptionRationaleOperator Initiation
CleansedZeroisation of SSPs managed by the callerOverwrites with random data followed by an overwrite with zeroesModule initiated
Cleared after useZeroisation of temporary copies of CSPs within the relevant functionOverwrites with zeroesModule initiated
RebootRAM is used for temporary storage of SSPsRestarting the NetApp controller clears the SSPs in RAMOperator initiated
NameDescriptio nSize - Strengt hType - CategoryGenerated ByEstablish ed ByUsed By
AES keyAES key used for symmetric decryption, encryption128, 256 bits - 128, 256 bitsSymmetric Key - CSPCryptograp hic Key Generation (CKG)Symmetric Encryption and Decryption
AES CCM keyAES CCM key used for authenticat ed symmetric decryption, encryption128 bits - 128 bitsSymmetric Key - CSPAuthenticat ed Symmetric Encryption and Decryption
AES CMAC keyAES CMAC key used for CMAC128, 256 bits - 128, 256 bitsMAC - CSPAES Keyed Hash

Table 15: SSP Input-Output Methods

9.3 SSP Zeroization Methods

Table 16: SSP Zeroization Methods h

Page 30
NameDescriptio n generation, verificationSize - Strengt hType - CategoryGenerated ByEstablish ed ByUsed By
AES GCM keyAES GCM key used for authenticat ed symmetric decryption, encryption128, 256 bits - 128, 256 bitsSymmetric Key - CSPAuthenticat ed Symmetric Encryption and Decryption
AES GMAC keyAES GMAC key used for GMAC generation, verification128, 256 bits - 128, 256 bitsMAC - CSPAES Keyed Hash
AES KEK keyKey wrapping and unwrappin g128, 256 bits - 128, 256 bitsSymmetric Key - CSPCryptograp hic Key Generation (CKG)KTS-AES
AES XTS keyAES XTS key used for symmetric decryption, encryption128, 256 bits - 128, 256 bitsSymmetric Key - CSPCryptograp hic Key Generation (CKG)Symmetric Encryption and Decryption
CPKEK keyKey wrapping and unwrappin g128, 256 bits - 128, 256 bitsSymmetric Key - CSPKey DerivationKTS-AES
HMAC keyKeyed Hash112 bits (minimu m) - 112 bits (minimu m)MAC - CSPKeyed Hash
DRBG V valueState value for DRBG256 bits - 256 bits256 bits - CSPRandom Number GenerationRandom Number Generation
DRBG entropy inputEntropy material for DRBG4096 bits - N/AEntropy input - CSPEntropy Noise SourceRandom Number Generation
DRBG internal state keyDRBG internal state key256 bits - 256 bitsCTR_DRBG_ Key - CSPRandom Number Generation
Page 31
NameDescriptio nSize - Strengt hType - CategoryGenerated ByEstablish ed ByUsed By
DRBG seedSeeding material for DRBG384 bits - 384 bitsEntropy input - CSPEntropy Noise SourceRandom Number Generation
ESV stateESV internal stateN/A - 256 bitsEntropy state - CSPEntropy Noise SourceEntropy Noise Source
KDK keyKey derivation source key256 bits - 256 bitsKDF - CSPKey Derivation
KDK output keyKey derivation output key256 bits - 256 bitsKDF - CSPKey Derivation
Passphra seInput to PBKDF for key derivation32 to 256 bytes - 112 bits or greaterSymmetric Key - CSPKey Derivation
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
AES key[Input] Call stack parameters [Output] Call stack parametersRAM:PlaintextCall lifetimeCleansed Cleared after use Reboot
AES CCM key[Input] Call stack parametersRAM:PlaintextCall lifetimeCleansed Cleared after use Reboot
AES CMAC key[Input] Call stack parametersRAM:PlaintextCall lifetimeCleansed Cleared after use Reboot
AES GCM key[Input] Call stack parametersRAM:PlaintextCall lifetimeCleansed Cleared after use Reboot
AES GMAC key[Input] Call stack parametersRAM:PlaintextCall lifetimeCleansed Cleared after use Reboot
AES KEK key[Input] Call stackRAM:PlaintextCall lifetimeCleansed Cleared
Page 32
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
parameters [Output] Call stack parametersafter use Reboot
AES XTS key[Input] Call stack parameters [Output] Call stack parametersRAM:PlaintextCall lifetimeCleansed Cleared after use Reboot
CPKEK key[Input] Call stack parameters [Output] Call stack parametersRAM:PlaintextCall lifetimeCleansed Cleared after use Reboot
HMAC key[Input] Call stack parametersRAM:PlaintextCall lifetimeCleansed Cleared after use Reboot
DRBG V value[Input] Call stack parameters [Output] Call stack parametersRAM:PlaintextModule lifetimeReboot
DRBG entropy input[Input] Call stack parametersRAM:PlaintextCall lifetimeCleared after use RebootDRBG seed:Used to derive
DRBG internal state key[Input] Call stack parameters [Output] Call stack parametersRAM:PlaintextModule lifetimeCleansed Cleared after use RebootDRBG seed:Derived from
DRBG seed[Input] Call stack parameters [Output] Call stack parametersRAM:PlaintextCall lifetimeCleansed Cleared after use RebootDRBG entropy input:Derived from
ESV state[Input] Call stack parametersRAM:PlaintextCall lifetimeCleared after use Reboot
KDK key[Input] Call stack parametersRAM:PlaintextCall lifetimeCleansed Cleared after use Reboot
Page 33
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
KDK output key[Output] Call stack parametersRAM:PlaintextCall lifetimeCleansed Cleared after use Reboot
Passphrase[Input] Call stack parametersRAM:PlaintextCall lifetimeCleansed Cleared after use Reboot
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
HMAC-SHA2- 256 (A2640)Key length: 256 bitsKATSW/FW IntegritySuccess: all self- tests passed (as expected)MAC (HMAC- SHA2-256, A2640)
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-CBCKey Length: 128 and 256 bitsKATCASTFIPS_OKEncrypt/DecryptOn reloading the module
AES-CCMKey Length: 128 bitsKATCASTFIPS_OKEncrypt/DecryptOn reloading the module
AES- CMACKey Length: 128 and 256 bitsKATCASTFIPS_OKHashOn reloading the module
AES-ECBKey Length: 128 and 256 bitsKATCASTFIPS_OKEncrypt/DecryptOn reloading the module
AES-GCMKey Length: 128 and 256 bitsKATCASTFIPS_OKEncrypt/DecryptOn reloading the module
10.1 Pre-Operational Self-Tests

Table 19: Pre-Operational Self-Tests The module is compliant with FIPS 140-3 IG 10.2.A in that it performs a self-test, a Known

10.2 Conditional Self-Tests
Page 34
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-KWPKey Length: 128 and 256 bitsKATCASTFIPS_OKEncrypt/DecryptOn reloading the module
AES- GMACKey Length: 128 and 256 bitsKATCASTFIPS_OKEncrypt/DecryptOn reloading the module
AES-XTS Testing Revision 2.0Key Length: 128 and 256 bitsKATCASTFIPS_OKEncrypt/DecryptOn reloading the module
Counter DRBGAES CTR (256 bits) with derivation functionKATCASTFIPS_OKGenerate, Reseed, Instantiate functionsOn reloading the module
HMAC- SHA-1PRF: SHA-1KATCASTFIPS_OKHMAC tag generationOn reloading the module
HMAC- SHA2-256PRF: SHA2- 256KATCASTFIPS_OKHMAC tag generationOn reloading the module
HMAC- SHA2-512PRF: SHA2- 512KATCASTFIPS_OKHMAC tag generationOn reloading the module
KDF SP800-108PRF: HMAC- SHA2-512KATCASTFIPS_OKCounter Mode (HMAC-SHA2- 512)On reloading the module
PBKDFDerivation of the Master Key (MK) PRF: HMAC-SHA-1, HMAC-SHA2- 256, HMAC- SHA2-512KATCASTFIPS_OKKey DerivationOn reloading the module
SHA-1SHA-1KATCASTFIPS_OKHashOn reloading the module
SHA2-256SHA2-256KATCASTFIPS_OKHashOn reloading the module
SHA2-512SHA2-512KATCASTFIPS_OKHashOn reloading the module
SHA3-256SHA3-256KATCASTFIPS_OKHashOn reloading the module
2.0 Table 20: Conditional Self-Tests
Page 35
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2- 256 (A2640)KATSW/FW IntegrityOn DemandManually by reloading the module
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-CBCKATCASTOn DemandManually by reloading the module
AES-CCMKATCASTOn DemandManually by reloading the module
AES-CMACKATCASTOn DemandManually by reloading the module
AES-ECBKATCASTOn DemandManually by reloading the module
AES-GCMKATCASTOn DemandManually by reloading the module
AES-KWPKATCASTOn DemandManually by reloading the module
AES-GMACKATCASTOn DemandManually by reloading the module
AES-XTS Testing Revision 2.0KATCASTOn DemandManually by reloading the module
Counter DRBGKATCASTOn DemandManually by reloading the module
HMAC-SHA-1KATCASTOn DemandManually by reloading the module
HMAC-SHA2- 256KATCASTOn DemandManually by reloading the module

Each time the platform is powered up it tests that the cryptographic algorithms still operate correctly and that sensitive data has not been damaged. On Module instantiation, the Module performs the pre-operational self-tests and CASTs listed above. All KATs must complete successfully prior to any other use of cryptography by the Module.

10.3 Periodic Self-Test Information

Table 21: Pre-Operational Periodic Information

Page 36
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2- 512KATCASTOn DemandManually by reloading the module
KDF SP800-108KATCASTOn DemandManually by reloading the module
PBKDFKATCASTOn DemandManually by reloading the module
SHA-1KATCASTOn DemandManually by reloading the module
SHA2-256KATCASTOn DemandManually by reloading the module
SHA2-512KATCASTOn DemandManually by reloading the module
SHA3-256KATCASTOn DemandManually by reloading the module
NameDescriptionConditionsRecovery MethodIndicator
ERROR_STATEThe error state is persistent and no services are available. Any attempt to use the Module's services result in the return of a non-zero error code.Entered whenever one or more KAT self-tests fail or if the software integrity test fails.The NetApp platform automatically reboots.ERROR_STATE

Table 22: Conditional Periodic Information

10.4 Error States

Table 23: Error States Errors encountered during the power-on self-test operations will result in an automatic reboot of the operating system. If the module encounters a fatal error state, other than one encountered during self-tests, then the Crypto-Officer must manually reboot the system to return the module to normal operation.

Page 37
10.5 Operator Initiation of Self-Tests

The operator can reload the module by rebooting the NetApp platform, fulfilling AS05.11.

11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

The module consists of a single kernel object module that provides cryptographic services as part of the NetApp ONTAP operating system. The CryptoMod module is automatically installed with ONTAP and is automatically initialized and started up whenever the appliance and/or ONTAP instance is restarted. See the NetApp documentation center (https://docs.netapp.com) for ONTAP product documentation. ONTAP 9.15 and greater will use the NetApp CryptoMod version 3.0 module without any required user intervention. When used with ONTAP versions less than ONTAP 9.15, the FIPS 140-3 variant of the module is initialized by executing the following ONTAP CLI diagnostic level command: *> security cryptomod_fips modify -node local -is_iut_enabled true followed by a reboot of the controller. Once the controller has rebooted, the FIPS 140-3 variant of the module will be automatically used.

11.2 Administrator Guidance

ONTAP 9.15 and greater will use the NetApp CryptoMod version 3.0 module without any required administrator intervention. When used with ONTAP versions less than ONTAP 9.15, the FIPS 140-3 variant of the module is initialized by executing the following ONTAP CLI diagnostic level command: *> security cryptomod_fips modify -node local -is_iut_enabled true followed by a reboot of the controller. Once the controller has rebooted, the FIPS 140-3 variant of the module will be automatically used.

11.3 Non-Administrator Guidance

Users can determine if they are using the FIPS 140-3 variant of the module by running the following ONTAP CLI command: *> security cryptomod-fips show

12 Mitigation of Other Attacks

This section is not applicable. The module does not claim to mitigate against any attacks beyond the FIPS 140-3 requirements for a Level 1 module.