All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Red Hat Enterprise Linux 9 OpenSSL FIPS Provider

Certificate#4746StandardFIPS 140-3Level1TypeSoftwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorRed Hat®, Inc.
High review priority  ·  no TCB surface named  ·  OpenSSL upstream has published 40 CVEs since this module's initial validation  ·  last validated 24 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date7/30/2026
CaveatInterim validation. When operated in approved mode. When installed, initialized and configured as specified in Section 11 of the Security Policy. The module generates SSPs (e.g., keys) whose strengths are modified by available entropy.
VendorRed Hat®, Inc.

Approved Algorithms (321)

AlgorithmACVP Cert
AES-CBCA3527
AES-CBCA3528
AES-CBCA3529
AES-CBCA4018
AES-CBCA4461
AES-CBCA4465
AES-CBC-CS1A3527
AES-CBC-CS1A3528
AES-CBC-CS1A3529
AES-CBC-CS1A4018
AES-CBC-CS1A4461
AES-CBC-CS1A4465
AES-CBC-CS2A3527
AES-CBC-CS2A3528
AES-CBC-CS2A3529
AES-CBC-CS2A4018
AES-CBC-CS2A4461
AES-CBC-CS2A4465
AES-CBC-CS3A3527
AES-CBC-CS3A3528
AES-CBC-CS3A3529
AES-CBC-CS3A4018
AES-CBC-CS3A4461
AES-CBC-CS3A4465
AES-CCMA3527
AES-CCMA3528
AES-CCMA3529
AES-CCMA4018
AES-CCMA4461
AES-CCMA4465
AES-CFB1A3527
AES-CFB1A3528
AES-CFB1A3529
AES-CFB1A4018
AES-CFB1A4461
AES-CFB1A4465
AES-CFB128A3527
AES-CFB128A3528
AES-CFB128A3529
AES-CFB128A4018
AES-CFB128A4461
AES-CFB128A4465
AES-CFB8A3527
AES-CFB8A3528
AES-CFB8A3529
AES-CFB8A4018
AES-CFB8A4461
AES-CFB8A4465
AES-CMACA3527
AES-CMACA3528
AES-CMACA3529
AES-CMACA4018
AES-CMACA4461
AES-CMACA4465
AES-CTRA3527
AES-CTRA3528
AES-CTRA3529
AES-CTRA4018
AES-CTRA4461
AES-CTRA4465
AES-ECBA3527
AES-ECBA3528
AES-ECBA3529
AES-ECBA3530
AES-ECBA3531
AES-ECBA3532
AES-ECBA3533
AES-ECBA4018
AES-ECBA4023
AES-ECBA4460
AES-ECBA4461
AES-ECBA4465
AES-GCMA3535
AES-GCMA3536
AES-GCMA3537
AES-GCMA3538
AES-GCMA3539
AES-GCMA3540
AES-GCMA3541
AES-GCMA3542
AES-GCMA3543
AES-GCMA4019
AES-GCMA4020
AES-GCMA4021
AES-GCMA4458
AES-GCMA4462
AES-GMACA3535
AES-GMACA3536
AES-GMACA3537
AES-GMACA3538
AES-GMACA3539
AES-GMACA3540
AES-GMACA3541
AES-GMACA3542
AES-GMACA3543
AES-GMACA4019
AES-GMACA4020
AES-GMACA4021
AES-GMACA4458
AES-GMACA4462
AES-KWA3527
AES-KWA3528
AES-KWA3529
AES-KWA4018
AES-KWA4461
AES-KWA4465
AES-KWPA3527
AES-KWPA3528
AES-KWPA3529
AES-KWPA4018
AES-KWPA4461
AES-KWPA4465
AES-OFBA3527
AES-OFBA3528
AES-OFBA3529
AES-OFBA4018
AES-OFBA4461
AES-OFBA4465
AES-XTS Testing Revision 2.0A3527
AES-XTS Testing Revision 2.0A3528
AES-XTS Testing Revision 2.0A3529
AES-XTS Testing Revision 2.0A4018
AES-XTS Testing Revision 2.0A4461
AES-XTS Testing Revision 2.0A4465
Counter DRBGA3570
ECDSA KeyGen (FIPS186-4)A3544
ECDSA KeyGen (FIPS186-4)A3545
ECDSA KeyGen (FIPS186-4)A3546
ECDSA KeyGen (FIPS186-4)A3547
ECDSA KeyGen (FIPS186-4)A4022
ECDSA KeyGen (FIPS186-4)A4459
ECDSA KeyVer (FIPS186-4)A3544
ECDSA KeyVer (FIPS186-4)A3545
ECDSA KeyVer (FIPS186-4)A3546
ECDSA KeyVer (FIPS186-4)A3547
ECDSA KeyVer (FIPS186-4)A4022
ECDSA KeyVer (FIPS186-4)A4459
ECDSA SigGen (FIPS186-4)A3534
ECDSA SigGen (FIPS186-4)A3544
ECDSA SigGen (FIPS186-4)A3545
ECDSA SigGen (FIPS186-4)A3546
ECDSA SigGen (FIPS186-4)A3547
ECDSA SigGen (FIPS186-4)A4022
ECDSA SigGen (FIPS186-4)A4024
ECDSA SigGen (FIPS186-4)A4459
ECDSA SigVer (FIPS186-4)A3534
ECDSA SigVer (FIPS186-4)A3544
ECDSA SigVer (FIPS186-4)A3545
ECDSA SigVer (FIPS186-4)A3546
ECDSA SigVer (FIPS186-4)A3547
ECDSA SigVer (FIPS186-4)A4022
ECDSA SigVer (FIPS186-4)A4024
ECDSA SigVer (FIPS186-4)A4459
Hash DRBGA3570
HMAC DRBGA3570
HMAC-SHA-1A3544
HMAC-SHA-1A3545
HMAC-SHA-1A3546
HMAC-SHA-1A3547
HMAC-SHA-1A4022
HMAC-SHA-1A4459
HMAC-SHA2-224A3544
HMAC-SHA2-224A3545
HMAC-SHA2-224A3546
HMAC-SHA2-224A3547
HMAC-SHA2-224A4022
HMAC-SHA2-224A4459
HMAC-SHA2-256A3544
HMAC-SHA2-256A3545
HMAC-SHA2-256A3546
HMAC-SHA2-256A3547
HMAC-SHA2-256A4022
HMAC-SHA2-256A4459
HMAC-SHA2-384A4459
HMAC-SHA2-512A3544
HMAC-SHA2-512A3545
HMAC-SHA2-512A3546
HMAC-SHA2-512A3547
HMAC-SHA2-512A4022
HMAC-SHA2-512A4459
HMAC-SHA2-512/224A3544
HMAC-SHA2-512/224A3545
HMAC-SHA2-512/224A3546
HMAC-SHA2-512/224A3547
HMAC-SHA2-512/224A4022
HMAC-SHA2-512/224A4459
HMAC-SHA2-512/256A3544
HMAC-SHA2-512/256A3545
HMAC-SHA2-512/256A3546
HMAC-SHA2-512/256A3547
HMAC-SHA2-512/256A4022
HMAC-SHA2-512/256A4459
HMAC-SHA3-224A3534
HMAC-SHA3-224A4024
HMAC-SHA3-256A3534
HMAC-SHA3-256A4024
HMAC-SHA3-384A3534
HMAC-SHA3-384A4024
HMAC-SHA3-512A3534
HMAC-SHA3-512A4024
KAS-ECC-SSC Sp800-56Ar3A3544
KAS-ECC-SSC Sp800-56Ar3A3545
KAS-ECC-SSC Sp800-56Ar3A3546
KAS-ECC-SSC Sp800-56Ar3A3547
KAS-ECC-SSC Sp800-56Ar3A4022
KAS-ECC-SSC Sp800-56Ar3A4459
KAS-FFC-SSC Sp800-56Ar3A3554
KDA HKDF Sp800-56Cr1A3526
KDA OneStep SP800-56Cr2A3525
KDF ANS 9.42A3534
KDF ANS 9.42A3544
KDF ANS 9.42A3545
KDF ANS 9.42A3546
KDF ANS 9.42A3547
KDF ANS 9.42A4022
KDF ANS 9.42A4024
KDF ANS 9.42A4459
KDF ANS 9.63A3534
KDF ANS 9.63A3544
KDF ANS 9.63A3545
KDF ANS 9.63A3546
KDF ANS 9.63A3547
KDF ANS 9.63A4022
KDF ANS 9.63A4024
KDF ANS 9.63A4459
KDF SP800-108A3553
KDF SSHA3530
KDF SSHA3531
KDF SSHA3532
KDF SSHA3533
KDF SSHA4023
KDF SSHA4460
PBKDFA3534
PBKDFA3544
PBKDFA3545
PBKDFA3546
PBKDFA3547
PBKDFA4022
PBKDFA4024
PBKDFA4459
RSA KeyGen (FIPS186-4)A3544
RSA KeyGen (FIPS186-4)A3545
RSA KeyGen (FIPS186-4)A3546
RSA KeyGen (FIPS186-4)A3547
RSA KeyGen (FIPS186-4)A4022
RSA KeyGen (FIPS186-4)A4459
RSA SigGen (FIPS186-4)A3544
RSA SigGen (FIPS186-4)A3545
RSA SigGen (FIPS186-4)A3546
RSA SigGen (FIPS186-4)A3547
RSA SigGen (FIPS186-4)A4022
RSA SigGen (FIPS186-4)A4459
RSA SigVer (FIPS186-4)A3544
RSA SigVer (FIPS186-4)A3545
RSA SigVer (FIPS186-4)A3546
RSA SigVer (FIPS186-4)A3547
RSA SigVer (FIPS186-4)A4022
RSA SigVer (FIPS186-4)A4459
Safe Primes Key GenerationA3554
Safe Primes Key VerificationA3554
SHA-1A3544
SHA-1A3545
SHA-1A3546
SHA-1A3547
SHA-1A4022
SHA-1A4459
SHA2-224A3544
SHA2-224A3545
SHA2-224A3546
SHA2-224A3547
SHA2-224A4022
SHA2-224A4459
SHA2-256A3544
SHA2-256A3545
SHA2-256A3546
SHA2-256A3547
SHA2-256A4022
SHA2-256A4459
SHA2-384A3544
SHA2-384A3545
SHA2-384A3546
SHA2-384A3547
SHA2-384A4022
SHA2-384A4459
SHA2-512A3544
SHA2-512A3545
SHA2-512A3546
SHA2-512A3547
SHA2-512A4022
SHA2-512A4459
SHA2-512/224A3544
SHA2-512/224A3545
SHA2-512/224A3546
SHA2-512/224A3547
SHA2-512/224A4022
SHA2-512/224A4459
SHA2-512/256A3544
SHA2-512/256A3545
SHA2-512/256A3546
SHA2-512/256A3547
SHA2-512/256A4022
SHA2-512/256A4459
SHA3-224A3534
SHA3-224A4024
SHA3-256A3534
SHA3-256A4024
SHA3-384A3534
SHA3-384A4024
SHA3-512A3534
SHA3-512A4024
SHAKE-128A3534
SHAKE-128A4024
SHAKE-256A3534
SHAKE-256A4024
TLS v1.2 KDF RFC7627A3544
TLS v1.2 KDF RFC7627A3545
TLS v1.2 KDF RFC7627A3546
TLS v1.2 KDF RFC7627A3547
TLS v1.2 KDF RFC7627A4022
TLS v1.2 KDF RFC7627A4459
TLS v1.3 KDFA3526

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Red Hat Enterprise Linux 9 OpenSSL FIPS Provider
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>update</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Status Output<br/>Show status<br/>Self-test</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>SSH<br/>HTTPS</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Red Hat Enterprise Linux 9 OpenSSL FIPS Provider
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>update</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Status Output<br/>Show status<br/>Self-test</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>SSH<br/>HTTPS</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Red Hat Enterprise Linux 9 OpenSSL FIPS Provider version 3.0.1-3f45e68ee408cd9c document version 1.2 Last update: 2024-06-14 Prepared by: atsec information security corporation

4516 Seton Center Parkway, Suite 250

Austin, TX 78759 www.atsec.com © 2024 Red Hat, Inc./ atsec information security corporation.

Page 2
Table of Contents
#SectionPage
Page 3

© 2024 Red Hat, Inc. / atsec information security corporation.

3 of 46

Page 4
ISO/IEC 24759 Section 6. [Number Below]FIPS 140-3 Section TitleSecurity Level
1General1
2Cryptographic Module Specification1
3Cryptographic Module Interfaces1
4Roles, Services, and Authentication1
5Software/Firmware Security1
6Operational Environment1
7Physical SecurityNot Applicable
8Non-invasive SecurityNot Applicable
9Sensitive Security Parameter Management1
10Self-tests1
1.1 Overview

This document is the non-proprietary FIPS 140-3 Security Policy for version 3.0.13f45e68ee408cd9c of the Red Hat Enterprise Linux 9 OpenSSL FIPS Provider. It contains the security rules under which the module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for an overall Security Level 1 module. and including this notice. Other documentation is proprietary to their authors.

1.2 How this Security Policy was prepared

was further consolidated into this document by atsec information security together with other vendor-supplied documentation. In preparing the Security Policy document, the laboratory formatted the vendor-supplied documentation for consolidation without altering the technical statements therein contained. The further refining of the Security Policy document was conducted iteratively throughout the conformance testing, wherein the Security Policy was submitted to the vendor, who would then edit, modify, and add technical contents. The vendor would also supply additional documentation, which the laboratory formatted into the existing Security Policy, and resubmitted to the vendor for their final editing.

1.3 Security levels

Table 1 describes the individual security areas of FIPS 140-3, as well as the security levels of those individual areas. © 2024 Red Hat, Inc. / atsec information security corporation.

4 of 46

Page 5
11Life-cycle Assurance1
12Mitigation of Other Attacks1

Table 1 - Security Levels © 2024 Red Hat, Inc. / atsec information security corporation.

5 of 46

Page 6
#Operating SystemHardware PlatformProcessorPAA/ Acceleration
1Red Hat Enterprise Linux 9Dell PowerEdge R440Intel(R) Xeon(R) Silver 4216AES-NI, SHA extensions
2Red Hat Enterprise Linux 9IBM z16 3931-A01IBM z16CPACF
3Red Hat Enterprise Linux 9IBM 9080 HEXIBM POWER10ISA
#Operating SystemHardware Platform
1Red Hat Enterprise Linux 9Intel(R) Xeon(R) E5
2 Cryptographic module specification
2.1 Description

The Red Hat Enterprise Linux 9 OpenSSL FIPS Provider (hereafter referred to as “the module”) is defined as a software module in a multi-chip standalone embodiment. It provides a C language application program interface (API) for use by other applications that require cryptographic functionality. The module consists of one software component, the “FIPS provider”, which implements the FIPS requirements and the cryptographic functionality provided to the operator.

2.2 Operational environments

The module has been tested on the following platforms with the corresponding module variants and configuration options with and without PAA: Table 2 - Tested Operational Environments In addition to the configurations tested by the atsec CST laboratory, the vendor affirms testing was performed on the following platforms for the module. Table 3 - Vendor Affirmed Operational Environments Note: the CMVP makes no statement as to the correct operation of the module or the security strengths of the generated SSPs when so ported if the specific operational environment is not listed on the validation certificate.

2.3 Approved algorithms

Table 4 lists all approved cryptographic algorithms of the module, including specific key lengths employed for approved services (Table 9), and implemented modes or methods of operation of the algorithms. The module supports RSA modulus sizes which are not tested by CAVP in compliance with FIPS 140-3 IG C.F. © 2024 Red Hat, Inc. / atsec information security corporation.

6 of 46

Page 7
CAVP CertAlgorithm and StandardMode / MethodDescription / Key Size(s) / Key StrengthsUse / Function
A3544SHA [FIPS 180-4]SHA-1, SHA-224, SHA-256,N/AMessage digest
A3545SHA-384, SHA-512, SHA-
A3546 A3547 A4022 A4459512/224, SHA-512/256
A3534SHA-3 [FIPS 202]SHA3-224, SHA3-256, SHA3-N/AMessage digest
A4024384, SHA3-512
SHA-3 [FIPS 202]SHAKE128, SHAKE256N/AXOF
A3527AES [FIPS 197, SPECB, CBC, CBC-CTS-CS1,128, 192, 256 bits with 128,Encryption
A3528800-38A, SP 800-CBC-CTS-CS2, CBC-CTS-CS3,192, 256 bits of securityDecryption
A352938A Addendum,CFB1, CFB8, CFB128, CTR,strength
A4018SP 800-38C, SPOFB, CCM
A4023 A4460 A4461 A4465800-38F]KW, KWP (KTS)
A3535AES [FIPS 197, SPGCM (internal IV)128, 192, 256 bits with 128,Encryption
A3536800-38D]192, 256 bits of security
A3537 A3538strength
A3539AES [FIPS 197, SPGCM (external IV)128, 192, 256 bits with 128,Decryption
A3540800-38D]192, 256 bits of security
A3541 A3542 A3543 A4019 A4020 A4021 A4458 A4462strength
A3527AES [FIPS 197, SPXTS128, 256 bits with 128, 256Encryption
A3528 A3529800-38E]bits of security strengthDecryption
A4018AES [FIPS 197, SPCMAC128, 192, 256 bits with 128,Message
A4461800-38B]192, 256 bits of securityauthentication
A4465strength

© 2024 Red Hat, Inc. / atsec information security corporation.

7 of 46

Page 8
CAVP CertAlgorithm and StandardMode / MethodDescription / Key Size(s) / Key StrengthsUse / Function
A3535AES [FIPS 197, SPGMAC128, 192, 256 bits with 128,Message
A3536800-38D]192, 256 bits of securityauthentication
A3537 A3538 A3539 A3540 A3541 A3542 A3543 A4019 A4020 A4021 A4458 A4462strength
A3544HMAC [FIPS 198-SHA-1, SHA-224, SHA-256,112-524288 bits with 112-256 bits of security strengthMessage
A35451]SHA-384, SHA-512, SHA-authentication
A3546 A3547 A4022 A4459512/224, SHA-512/256
A3534SHA3-224, SHA3-256, SHA3-
A4024384, SHA3-512
A3553KBKDF [SP 800-Counter and feedback112-4096 bits with 112-256KBKDF Key
108r1]mode, using CMAC and HMAC SHA-1, SHA-224, SHA-256, SHA-384, SHA- 512, SHA-512/224, SHA- 512/256, SHA3-224, SHA3- 256, SHA3-384, SHA3-512bits of security strengthderivation
A3525KDA OneStep1 [SP(HMAC) SHA-1, SHA-224,224-8192 bits with 112-256KDA OneStep Key
800-56Cr2]SHA-256, SHA-384, SHA- 512, SHA-512/224, SHA- 512/256, SHA3-224, SHA3- 256, SHA3-384, SHA3-512bits of security strengthderivation
A3526HKDF [SP 800-SHA-1, SHA-224, SHA-256,224-8192 bits with 112-256HKDF Key derivation
56Cr2]SHA-384, SHA-512, SHA- 512/224, SHA-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512bits of security strength
A3534ANS X9.42 KDFAES KW with SHA-1, SHA-224-8192 bits with 112-256ANS X9.42 KDF Key
A3544[SP 800-135r1]224, SHA-256, SHA-384,bits of security strengthderivation
A3545CVLSHA-512, SHA-512/224,
A3546SHA-512/256, SHA3-224,
A3547SHA3-256, SHA3-384, SHA3-
A4022512

1This algorithm is referred to as “Single Step KDF” or “SSKDF” by OpenSSL. © 2024 Red Hat, Inc. / atsec information security corporation.

8 of 46

Page 9
CAVP CertAlgorithm and StandardMode / MethodDescription / Key Size(s) / Key StrengthsUse / Function
A4024 A4459ANS X9.63 KDFSHA-224, SHA-256, SHA-224-8192 bits with 112-256ANS X9.63 KDF Key
[SP 800-135r1] CVL384, SHA-512, SHA- 512/224, SHA-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512bits of security strengthderivation
A3530SSH KDF [SP 800-AES-128, AES-192, AES-256224-8192 bits with 112-256SSH KDF Key
A3531135r1]with SHA-1, SHA-224, SHA-bits of security strengthderivation
A3532 A3533 A4023 A4460CVL256, SHA-384, SHA-512
A3544TLS 1.2 KDF [SPSHA-256, SHA-384, SHA-512224-8192 bits with 112-256TLS 1.2 KDF Key
A3545 A3546 A3547 A4022 A4459800-135r1] CVLbits of security strengthderivation
A3526TLS 1.3 KDF [RFCSHA-256, SHA-384224-8192 bits with 112-256TLS 1.3 KDF Key
8446] CVLbits of security strengthderivation
A3534PBKDF2 [SP 800-Option 1a with SHA-1, SHA-8-128 characters withPassword-based key
A3544132]224, SHA-256, SHA-384,password strength betweenderivation
A3545SHA-512, SHA-512/224,108 and 10128
A3546SHA-512/256, SHA3-224,
A3547SHA3-256, SHA3-384, SHA3-
A4022 A4024 A4459512
A3570CTR_DRBG [SPAES-128, AES-192, AES-256,256, 320, 384 bits with 128,Random number
800-90Ar1]with/without derivation192, 256 bits of securitygeneration
function, with/without prediction resistancestrength
A3570Hash_DRBG [SPSHA-1, SHA-256, SHA-512880, 1776 bits with 128, 256Random number
800-90Ar1]with/without prediction resistancebits of security strengthgeneration
A3570HMAC_DRBG [SPSHA-1, SHA-256, SHA-512320, 512, 1024 bits with 128,Random number
800-90Ar1]with/without prediction resistance256 bits of security strengthgeneration
A3554KAS-FFC-SSC [SPdhEphemMODP-2048, MODP-3072,Shared secret
800-56Ar3](initiator/responder)MODP-4096, MODP-6144, MODP-8192, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192 with 112-200 bits of security strengthcomputation

© 2024 Red Hat, Inc. / atsec information security corporation.

9 of 46

Page 10
CAVP CertAlgorithm and StandardMode / MethodDescription / Key Size(s) / Key StrengthsUse / Function
A3544KAS-ECC-SSC [SPEphemeral Unified ModelP-224, P-256, P-384, P-521Shared secret computation
A3545800-56Ar3](initiator/responder)with 112, 128, 192, 256 bits of
A3546 A3547security strength
A4022RSA [FIPS 186-4]PKCS#1 v1.5 and PSS with2048-16384 bits with 112-256Signature generation
A4459SHA-224, SHA-256, SHA-bits of security strength
RSA [FIPS 186-4]384, SHA-512, SHA- 512/224, SHA-512/256,NIST SP 800-131Ar2 LegacySignature verification
SHA3-224, SHA3-256, SHA3-use: 1024-2047 bits with 80-
384, SHA3-512111 bits of security strength NIST SP 800-131Ar2 Acceptable: 2048-16384 bits with 112-256 bits of security strength
A3534ECDSA [FIPS 186-SHA-224, SHA-256, SHA-P-224, P-256, P-384, P-521Signature generation
A35444]384, SHA-512, SHA-with 112, 128, 192, 256 bits of
A3545512/224, SHA-512/256,security strength
A3546ECDSA [FIPS 186-SHA3-224, SHA3-256, SHA3-Signature verification
A3547 A4022 A4024 A44594]384, SHA3-512
A3554Safe primes [SPSP 800-56Ar3 SectionMODP-2048, MODP-3072,Key pair generation
800-56Ar3]5.6.1.1.4 TestingMODP-4096, MODP-6144,
CandidatesMODP-8192, ffdhe2048, ffdhe3072, ffdhe4096,
A3554Safe primes [SPSP 800-56Ar3 Sectionsffdhe6144, ffdhe8192 withKey pair verification
800-56Ar3]5.6.2.1.2 and 5.6.2.1.4112-200 bits of security strength
A3544RSA [FIPS 186-4]FIPS 186-4 Appendix B.3.62048-15360 bits with 112-256Key pair generation
A3545Probable Primes withbits of security strength
A3546Conditions Based on
A3547 A4022Auxiliary Probable Primes
A4459ECDSA [FIPS 186-FIPS 186-4 Appendix B.4.2P-224, P-256, P-384, P-521Key pair generation
4]Testing Candidateswith 112, 128, 192, 256 bits of security strength
ECDSA [FIPS 186- 4]N/AKey pair verification
VendorCKG [SP 800-Safe primesMODP-2048, MODP-3072,Key pair generation
affirme133r2 Section 4]MODP-4096, MODP-6144,
dMODP-8192, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192 with 112-200 bits of security strength
RSA2048-16384 bits with 112-256 bits of security strength

4] © 2024 Red Hat, Inc. / atsec information security corporation.

10 of 46

Page 11
CAVP CertAlgorithm and StandardMode / Method ECDSADescription / Key Size(s) / Key Strengths P-224, P-256, P-384, P-521 with 112, 128, 192, 256 bits of security strengthUse / Function
VendorRSA [FIPS 186-4]RSA PKCS#1 v1.5 and PSS2048-16384 bits with 112-256Signature generation
affirmeSHA-3 [FIPS 202]with SHA3-224, SHA3-256,bits of security strength
dSHA3-384, SHA3-512
[FIPS 140-3 IG C.C]NIST SP 800-131Ar2 Legacy use: 1024-2047 bits with 80- 111 bits of security strength NIST SP 800-131Ar2 Acceptable: 2048-16384 bits with 112-256 bits of security strengthSignature verification
Algorithm / FunctionsUse / Function
AES GCM (external IV)Encryption
HMAC (< 112-bit keys)Message authentication
KBKDF, KDA OneStep, HKDF, ANS X9.42 KDF, ANS X9.63 KDF (< 112-bit keys)KBKDF Key derivation KDA OneStep Key derivation HKDF Key derivation ANS X9.42 KDF Key derivation ANS X9.63 KDF Key derivation
KDA OneStep (SHAKE128, SHAKE256)KDA OneStep Key derivation
ANS X9.42 KDF (SHAKE128, SHAKE256)ANS X9.42 KDF Key derivation
ANS X9.63 KDF (SHA-1, SHAKE128, SHAKE256)ANS X9.63 KDF Key derivation
SSH KDF (SHA-512/224, SHA-512/256, SHA-3, SHAKE128, SHAKE256)SSH KDF Key derivation
TLS 1.2 KDF (SHA-1, SHA-224, SHA-512/224, SHA-512/256, SHA-3)TLS 1.2 KDF Key derivation
TLS 1.3 KDF (SHA-1, SHA-224, SHA-512, SHA-512/224, SHA-512/256, SHA-3)TLS 1.3 KDF Key derivation
2.4 Non-approved algorithms

The module does not offer any non-approved cryptographic algorithms that are allowed in approved services (with or without security claimed). Table 5 lists all non-approved cryptographic algorithms of the module employed by the nonapproved services in Table 10. © 2024 Red Hat, Inc. / atsec information security corporation.

11 of 46

Page 12
KAS1, KAS2Shared secret computation
RSA and ECDSA (pre-hashed message) RSA-PSS (invalid salt length)Signature generation Signature verification
RSA-OAEPAsymmetric encryption Asymmetric decryption

PBKDF2 (short password; short salt; insufficient iterations; < 112-bit keys) Password-based key derivation Table 5 - Non-Approved Algorithms Not Allowed in the Approved Mode of Operation

2.5 Module design and components

Figure 1 shows a block diagram that represents the design of the module when the module is operational and providing services to other user space applications. In this diagram, the physical perimeter of the operational environment (a general-purpose computer on which the module is installed) is indicated by a purple dashed line. The cryptographic boundary is represented by the component painted in orange block, which consists only of the shared library implementing the FIPS provider (fips.so). Green lines indicate the flow of data between the cryptographic module and its operator application, through the logical interfaces defined in Section 3. Components in white are only included in the diagram for informational purposes. They are not included in the cryptographic boundary (and therefore not part of the module’s validation). For example, the kernel is responsible for managing system calls issued by the module itself, as well as other applications using the module for cryptographic services. © 2024 Red Hat, Inc. / atsec information security corporation.

12 of 46

Page 13

Figure 1 – Software Block Diagram

2.6 Rules of operation

Upon initialization, the module immediately performs all cryptographic algorithm self-tests (CASTs) as specified in Table 13. When all those self-tests pass successfully, the module automatically performs the pre-operational integrity test using the integrity value embedded in the fips.so file. Only if this integrity test also passed successfully, the module transitions to the operational state. No operator intervention is required to reach this point. The module operates in the approved mode of operation by default and can only transition into the non-approved mode by calling one of the non-approved services listed in Table 10 of the Security Policy. In the operational state, the module accepts service requests from calling applications through its logical interfaces. At any point in the operational state, a calling application can end its process, thus causing the module to end its operation. The module supports two modes of operation:

13 of 46

Page 14
Physical PortLogical InterfaceData that passes over port / interface
As a software-only module, the module does not have physical ports. Physical Ports are interpreted to be the physical ports of the hardware platform on which it runs.Data InputAPI input parameters
Data OutputAPI output parameters
Control InputAPI function calls
Status OutputAPI return codes, error queue
3 Cryptographic module interfaces

The logical interfaces are the APIs through which the applications request services. These logical interfaces are logically separated from each other by the API design. Table 6 summarizes the logical interfaces: Table 6 - Ports and Interfaces © 2024 Red Hat, Inc. / atsec information security corporation.

14 of 46

Page 15
RoleServiceInputOutput
Crypto OfficerMessage digestMessageDigest value
XOFMessage, output lengthDigest value
EncryptionPlaintext, AES keyCiphertext
DecryptionCiphertext, AES keyPlaintext
Message authenticationMessage, AES key or HMAC keyMAC tag
KBKDF Key derivationKey-derivation keyKBKDF Derived key
KDA OneStep Key derivationShared secretKDA OneStep Derived key
HKDF Key derivationShared secretHKDF Derived key
ANS X9.42 KDF Key derivationShared secretANS X9.42 KDF Derived key
ANS X9.63 KDF Key derivationShared secretANS X9.63 KDF Derived key
SSH KDF Key derivationShared secretSSH KDF Derived key
TLS 1.2 KDF Key derivationShared secretTLS 1.2 KDF Derived key
TLS 1.3 KDF Key derivationShared secretTLS 1.3 KDF Derived key
Password-based key derivationPassword, salt, iteration countPBKDF2 Derived key
Random number generationOutput lengthRandom bytes
Shared secret computationOwner private key, peer public keyShared secret
Signature generationMessage, private keySignature
Signature verificationMessage, public key, signaturePass/fail
Asymmetric encryptionPlaintext, public keyCiphertext
Asymmetric decryptionCiphertext, private keyPlaintext
Key pair generationKey sizeKey pair
Key pair verificationKey pairPass/fail
4 Roles, services, and authentication
4.1 Roles

The module supports the Crypto Officer role only. This sole role is implicitly and always assumed by the operator of the module. No support is provided for multiple concurrent operators or a maintenance role. Table 7 lists the roles supported by the module with corresponding services with input and output parameters. © 2024 Red Hat, Inc. / atsec information security corporation.

15 of 46

Page 16
Show versionN/AName and version information
Show statusN/AModule status
Self-testN/APass/fail results of self-tests
ZeroizationAny SSPN/A
ContextService Indicator
EVP_CIPHER_C TXOSSL_CIPHER_PARAM_REDHAT_FIPS_INDICATOR
EVP_MAC_CTXOSSL_MAC_PARAM_REDHAT_FIPS_INDICATOR
EVP_KDF_CTXOSSL_KDF_PARAM_REDHAT_FIPS_INDICATOR
EVP_PKEY_CTXOSSL_SIGNATURE_PARAM_REDHAT_FIPS_INDICATOR
EVP_PKEY_CTXOSSL_ASYM_CIPHER_PARAM_REDHAT_FIPS_INDICATOR

Table 7 - Roles, Service Commands, Input and Output

4.2 Authentication

The module does not support authentication for roles.

4.3 Services

The module provides services to operators that assume the available role. All services are described in detail in the API documentation (manual pages). The next tables define the services that utilize approved and non-approved security functions in this module. For the respective tables, the convention below applies when specifying the access permissions (types) that the service has for each SSP.

16 of 46

Page 17
ServiceDescriptionApproved Security FunctionsKeys and/or SSPsRolesAccess rights to Keys and/or SSPsIndicator
Message digestCompute a message digestSHA-1, SHA-224, SHA-256, SHA-384, SHA-512, SHA- 512/224, SHA- 512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512N/ACON/AEVP_DigestFinal_ex returns 1
XOFCompute the output of an XOFSHAKE128, SHAKE256N/ACON/AEVP_DigestFinalXOF returns 1
EncryptionEncrypt a plaintextAES ECB, CBC, CBC- CTS-CS1, CBC-CTS- CS2, CBC-CTS-CS3, CFB1, CFB8, CFB128, CTR, OFB, CCM, KW, KWP, GCM, XTSAES keyCOW, EAES GCM: EVP_CIPHER_REDHAT_FI PS_INDICATOR_APPROVE D Others: EVP_EncryptFinal_ex returns 1
DecryptionDecrypt a ciphertextCOW, EAES GCM: EVP_CIPHER_REDHAT_FI PS_INDICATOR_APPROVE D Others: EVP_DecryptFinal_ex returns 1
Message authenticatio nCompute a MAC tagAES CMAC AES GMAC HMAC SHA-1, HMAC SHA-224, HMAC SHA-256, HMAC SHA-384, HMAC SHA-512, HMAC SHA-512/224, HMAC SHA-512/256, HMAC SHA3-224, HMAC SHA3-256, HMAC SHA3-384, HMAC SHA3-512AES key HMAC keyCOW, EHMAC: OSSL_MAC_PARAM_RED HAT_FIPS_INDICATOR_AP PROVED Others: EVP_MAC_final returns 1
KBKDF Key derivationDerive a key from a key- derivation keyKBKDFKey-derivation keyW, E
KBKDF Derived keyG, R
KDA OneStep Key derivationKDA OneStepDH Shared secret ECDH Shared secretW, E
KDA OneStep Derived keyG, R
DH Shared secret ECDH Shared secretW, E

D D n © 2024 Red Hat, Inc. / atsec information security corporation.

17 of 46

Page 18
Service ANS X9.42 KDF Key derivation ANS X9.63 KDF Key derivation SSH KDF Key derivation TLS 1.2 KDF Key derivation TLS 1.3 KDF Key derivationDescriptionApproved Security Functions ANS X9.42 KDF ANS X9.63 KDF SSH KDF TLS 1.2 KDF TLS 1.3 KDFKeys and/or SSPs HKDF Derived key DH Shared secret ECDH Shared secret ANS X9.42 KDF Derived key DH Shared secret ECDH Shared secret ANS X9.63 KDF Derived key DH Shared secret ECDH Shared secret SSH KDF Derived key DH Shared secret ECDH Shared secret TLS 1.2 KDF Derived key DH Shared secret ECDH Shared secret TLS 1.3 KDF Derived keyRolesAccess rights to Keys and/or SSPs G, R W, E G, R W, E G, R W, E G, R W, E G, R W, E G, RIndicator
Password- based key derivationDerive a key from a passwordPBKDF2PasswordCOW, EEVP_KDF_REDHAT_FIPS_I NDICATOR_APPROVED
PBKDF2 Derived keyG, R
Random number generationGenerate random bytesCTR_DRBGEntropy inputCOW, EEVP_RAND_generate returns 1
DRBG seedE, G
Internal state (V, Key)W, E, G
Hash_DRBGEntropy inputW, E
DRBG seedE, G
Internal state (V, C)W, E, G
HMAC_DRBGEntropy inputW, E
DRBG seedE, G

© 2024 Red Hat, Inc. / atsec information security corporation.

18 of 46

Page 19
ServiceDescriptionApproved Security FunctionsKeys and/or SSPs Internal state (V, Key)RolesAccess rights to Keys and/or SSPs W, E, GIndicator
Shared secret computationCompute a shared secretKAS-FFC-SSCDH private key (owner), DH public key (peer)COW, EEVP_PKEY_derive returns 1
DH Shared secretG, R
KAS-ECC-SSCEC private key (owner), EC public key (peer)W, E
ECDH Shared secretG, R
Signature generationGenerate a signatureRSA signature generation/verificati on (PKCS#1 v1.5 and PSS) ECDSA signature generation/verificati onRSA private key EC private keyCOW, ERSA: OSSL_RH_FIPSINDICATO R_APPROVED and EVP_SIGNATURE_REDHA T_FIPS_INDICATOR_APPR OVED ECDSA: OSSL_RH_FIPSINDICATO R_APPROVED
Signature verificationVerify a signatureRSA public key EC public keyCOW, E
Key pair generationGenerate a key pairCKG CTR_DRBG, Hash_DRBG, HMAC_DRBG Safe primes key pair generation RSA key pair generation ECDSA key pair generationDH private key, DH public key RSA private key, RSA public key EC private key, EC public key Intermediate key generation valueCOG, REVP_PKEY_generate returns 1
Key pair verificationVerify a key pairSafe primes key pair verification ECDSA key pair verificationDH private key, DH public key EC private key, EC public keyCOW, EEVP_PKEY_public_check or EVP_PKEY_private_check or EVP_PKEY_check returns 1
Show versionReturn the name and version informationN/AN/ACON/ANone
Show statusReturn the module statusN/AN/ACON/ANone

© 2024 Red Hat, Inc. / atsec information security corporation.

19 of 46

Page 20
ServiceDescriptionApproved Security FunctionsKeys and/or SSPsRolesAccess rights to Keys and/or SSPsIndicator
Self-testPerform the CASTs and integrity testSHA-1, SHA-224, SHA- 256, SHA-512, SHA3- 256 AES ECB, KW, GCM HMAC KBKDF, KDA OneStep, HKDF, ANS X9.42 KDF, ANS X9.63 KDF, SSH KDF, TLS 1.2 KDF, TLS 1.3 KDF PBKDF2 CTR_DRBG, Hash_DRBG, HMAC_DRBG KAS-FFC-SSC, KAS- ECC-SSC RSA (PKCS#1 v1.5) ECDSA See Table 13 for specificsAES key HMAC key Key-derivation key Password DH private key, DH public key RSA private key, RSA public key EC private key, EC public keyCOENone
DH Shared secret ECDH Shared secret KBKDF Derived key KDA OneStep Derived key HKDF Derived key ANS X9.42 KDF Derived key ANS X9.63 KDF Derived key SSH KDF Derived key TLS 1.2 KDF Derived key TLS 1.3 KDF Derived key PBKDF2 Derived key DRBG seed Internal state (V, Key) Internal state (V, C)E, G
ZeroizationZeroize all SSPsN/AAny SSPCOZNone
ServiceDescriptionAlgorithms AccessedRole
EncryptionEncrypt a plaintextAES GCM (external IV)CO

Table 10 lists the non-approved services in this module, the algorithms involved, the roles that can request the service, and the respective service indicator. In this table, CO specifies the Crypto Officer role. © 2024 Red Hat, Inc. / atsec information security corporation.

20 of 46

Page 21
ServiceDescriptionAlgorithms AccessedRole
Message authenticatio nCompute a MAC tagHMAC (< 112-bit keys)CO
KBKDF Key derivationDerive a key from a key- derivation keyKBKDF (< 112-bit keys)CO
KDA OneStep Key derivationDerive a key from a shared secretKDA OneStep (< 112-bit keys) KDA OneStep (SHAKE128, SHAKE256)
HKDF Key derivationHKDF (< 112-bit keys)
ANS X9.42 KDF Key derivationANS X9.42 KDF (< 112-bit keys) ANS X9.42 KDF (SHAKE128, SHAKE256)
ANS X9.63 KDF Key derivationANS X9.63 KDF (< 112-bit keys) ANS X9.63 KDF (SHA-1, SHAKE128, SHAKE256)
SSH KDF Key derivationSSH KDF (< 112-bit keys) SSH KDF (SHA-512/224, SHA-512/256, SHA-3, SHAKE128, SHAKE256)
TLS 1.2 KDF Key derivationTLS 1.2 KDF (< 112-bit keys) TLS 1.2 KDF (SHA-1, SHA-224, SHA-512/224, SHA-512/256, SHA- 3)
TLS 1.3 KDF Key derivationTLS 1.3 KDF (< 112-bit keys) TLS 1.3 KDF (SHA-1, SHA-224, SHA-512, SHA-512/224, SHA- 512/256, SHA-3)
Password- based key derivationDerive a key from a passwordPBKDF2 (short password; short salt; insufficient iterations; < 112-bit keys)CO
Shared secret computationCompute a shared secretKAS1, KAS2CO
Signature generationGenerate a signatureRSA and ECDSA signature generation/verification (pre-hashed message)CO
Signature verificationVerify a signatureCO
Asymmetric encryptionEncrypt a plaintextRSA-OAEP encryption/decryptionCO
Asymmetric decryptionDecrypt a plaintextCO

n Table 10 - Non-Approved Services © 2024 Red Hat, Inc. / atsec information security corporation.

21 of 46

Page 22
5 Software/Firmware security
5.1 Integrity techniques

The integrity of the module is verified by comparing a HMAC SHA-256 value calculated at run time with the HMAC SHA-256 value embedded in the fips.so file that was computed at build time.

5.2 On-demand integrity test

Integrity tests are performed as part of the pre-operational self-tests, which are executed when the module is initialized. The integrity test may be invoked on-demand by unloading and subsequently re-initializing the module. This will perform (among others) the software integrity test. © 2024 Red Hat, Inc. / atsec information security corporation.

22 of 46

Page 23
6 Operational environment
6.1 Applicability

The module operates in a modifiable operational environment per FIPS 140-3 level 1 specification: the module executes on a general purpose operating system (Red Hat Enterprise Linux 9), which allows modification, loading, and execution of software that is not part of the validated module.

6.2 Tested operational environments

See Section 2.2. The Red Hat Enterprise Linux operating system is used as the basis of other products which include but are not limited to:

6.3 Policy and requirements

The module shall be installed as stated in Section 11. If properly installed, the operating system provides process isolation and memory protection mechanisms that ensure appropriate separation for memory access among the processes on the system. Each process has control over its own data and uncontrolled access to the data of other processes is prevented. There are no concurrent operators. The module does not have the capability of loading software or firmware from an external source. Instrumentation tools like the ptrace system call, gdb and strace, userspace live patching, as well as other tracing mechanisms offered by the Linux environment such as ftrace or systemtap, shall not be used in the operational environment. The use of any of these tools implies that the cryptographic module is running in a non-validated operational environment. © 2024 Red Hat, Inc. / atsec information security corporation.

23 of 46

Page 24
7 Physical security

The module is comprised of software only and therefore this section is not applicable. © 2024 Red Hat, Inc. / atsec information security corporation.

24 of 46

Page 25
8 Non-invasive security

This module does not implement any non-invasive security mechanism and therefore this section is not applicable. © 2024 Red Hat, Inc. / atsec information security corporation.

25 of 46

Page 26
Key / SSP Name / TypeStrengthSecurity Function and Cert. NumberGenerationImport / ExportEsta blish mentStor ageZeroiza tionUse and related keys
AES key (CSP)AES-XTS: 128, 256 bits Rest of modes: 128, 192, 256 bitsAES AES CMAC AES GMAC A3527, A3528, A3529, A3535, A3536, A3537, A3538, A3539, A3540, A3541, A3542, A3543, A4018, A4019, A4020, A4021, A4023, A4458, A4460, A4461, A4462, A4465N/AMD/EE Import: API input parameters From: Operator calling application (TOEPP) To: Cryptographic module Export: NoneN/ARAMEVP_CIPHER _CTX_free EVP_MAC_C TX_freeUse: Encryption Decryption Message authentication Related SSPs: None
HMAC key (CSP)112-256 bitsHMAC A3534, A3544, A3545, A3546, A3547, A4022, A4024, A4459N/AMD/EE Import: API input parameters From: Operator calling application (TOEPP) To: Cryptographic module Export: NoneN/ARAMEVP_MAC_C TX_freeUse: Message authentication Related SSPs: None
Key- derivation key (CSP)112-256 bitsKBKDF A3553N/AMD/EE Import: API input parameters From: Operator calling application (TOEPP) To: Cryptographic moduleN/ARAMEVP_KDF_CT X_freeUse: KBKDF Key derivation Related SSPs: KBKDF Derived key
9 Sensitive security parameters management

Table 10 summarizes the Sensitive Security Parameters (SSPs) that are used by the cryptographic services implemented in the module in the approved services (Table 9). SSPs (including CSPs) are directly imported as input parameters and exported as output parameters from the module. Because these SSPs are only transiently used for a specific service, they are by definition exclusive between approved and non-approved services. © 2024 Red Hat, Inc. / atsec information security corporation.

26 of 46

Page 27
DH Shared secret (CSP)112-256 bitsKAS-FFC-SSC A3554 KDA OneStep HKDF ANS X9.42 KDF ANS X9.63 KDF SSH KDF TLS 1.2 KDF TLS 1.3 KDF A3525, A3526, A3530, A3531, A3532, A3533, A3534, A3544, A3545, A3546, A3547, A3553, A4022, A4023, A4024, A4459, A4460N/AMD/EE Import: API input parameters From: Operator calling application (TOEPP) To: Cryptographic module Export: API output parameters From: Cryptographic module To: Operator calling application (TOEPP)SP 800- 56Ar3 (DH shared secret comput ation)RAMEVP_KDF_CT X_freeUse: Shared secret computation KDA OneStep Key derivation HKDF Key derivation ANS X9.42 KDF Key derivation ANS X9.63 KDF Key derivation SSH KDF Key derivation TLS 1.2 KDF Key derivation TLS 1.3 KDF Key derivation Related SSPs: KDA OneStep Derived key HKDF Derived key ANS X9.42 KDF Derived key ANS X9.63 KDF Derived key SSH KDF Derived key TLS 1.2 KDF Derived key TLS 1.3 KDF Derived key DH private key DH public key
ECDH Shared secret (CSP)112-256 bitsKAS-ECC-SSC KDA OneStep HKDF ANS X9.42 KDF ANS X9.63 KDF SSH KDF TLS 1.2 KDF TLS 1.3 KDF A3525, A3526, A3530, A3531, A3532, A3533, A3534, A3544, A3545, A3546, A3547, A3553, A4022, A4023, A4024, A4459, A4460N/AMD/EE Import: API input parameters From: Operator calling application (TOEPP) To: Cryptographic module Export: API output parameters From: Cryptographic module To: OperatorSP 800- 56Ar3 (ECDH shared secret comput ation)RAMEVP_KDF_CT X_freeUse: Shared secret computation KDA OneStep Key derivation HKDF Key derivation ANS X9.42 KDF Key derivation ANS X9.63 KDF Key derivation SSH KDF Key derivation TLS 1.2 KDF Key derivation TLS 1.3 KDF Key derivation Related SSPs: KDA OneStep Derived key HKDF Derived

Export: None © 2024 Red Hat, Inc. / atsec information security corporation.

27 of 46

Page 28
Password (CSP)Password strength: 108 - 10128PBKDF2 A3534, A3544, A3545, A3546, A3547, A4022, A4024, A4459N/AMD/EE Import: API input parameters From: Operator calling application (TOEPP) To: Cryptographic module Export: NoneN/ARAMEVP_KDF_CT X_freeUse: Password-based key derivation Related SSPs: PBKDF2 Derived key
KBKDF Derived key (CSP)112-256 bitsKBKDF A3553SP 800-133r2, Section 6.2MD/EE Import: None Export: API output parameters From: Cryptographic module To: Operator calling application (TOEPP)N/ARAMEVP_KDF_CT X_freeUse: KBKDF Key derivation Related SSPs: Key-derivation key
KDA OneStep Derived key (CSP)KDA OneStep A3525Use: KDA OneStep Key derivation Related SSPs: DH Shared secret ECDH Shared secret
HKDF Derived key (CSP)HKDF A3526Use: HKDF Key derivation Related SSPs: DH Shared secret ECDH Shared secret
ANS X9.42 KDF Derived key (CSP)ANS X9.42 KDF A3534 A3544 A3545 A3546 A3547 A4022 A4024 A4459Use: ANS X9.42 KDF Key derivation Related SSPs: DH Shared secret

SSH KDF TLS 1.2 KDF TLS 1.3 KDF EC private key EC public key © 2024 Red Hat, Inc. / atsec information security corporation.

28 of 46

Page 29
ECDH Shared secret
ANS X9.63 KDF Derived key (CSP)ANS X9.63 KDF A3534 A3544 A3545 A3546 A3547 A4022 A4024 A4459Use: ANS X9.63 KDF Key derivation Related SSPs: DH Shared secret ECDH Shared secret
SSH KDF Derived key (CSP)SSH KDF A3530 A3531 A3532 A3533 A4023 A4460Use: SSH KDF Key derivation Related SSPs: DH Shared secret ECDH Shared secret
TLS 1.2 KDF Derived key (CSP)TLS 1.2 KDF A3544 A3545 A3546 A3547 A4022 A4459Use: TLS 1.2 KDF Key derivation Related SSPs: DH Shared secret ECDH Shared secret
TLS 1.3 KDF Derived key (CSP)TLS 1.3 KDF A3526Use: TLS 1.3 KDF Key derivation Related SSPs: DH Shared secret ECDH Shared secret
PBKDF2 Derived key (CSP)PBKDF2 A3534 A3544 A3545 A3546 A3547 A4022 A4024 A4459Use: Password-based key derivation Related SSPs: Password
Entropy input (CSP)112-336 bitsCTR_DRBG Hash_DRBG HMAC_DRBG A3570N/AImport: None Export: NoneN/ARAMEVP_RAND_ CTX_freeUse: Random number generation Related SSPs: DRBG seed
DRBG seed (CSP) IG D.L compliantCTR_DRBG: 128, 192, 256 bits Hash_DRBG: 128, 256 bits HMAC_DRBG: 128, 256 bitsCTR_DRBG Hash_DRBG HMAC_DRBGImport: None Export: NoneN/ARAMEVP_RAND_ CTX_freeUse: Random number generation Related SSPs: Entropy input Internal state (V, Key) Internal state (V, C)
Internal state (V, Key) (CSP) IG D.LCTR_DRBG HMAC_DRBG A3570CTR_DRBG HMAC_DRBGImport: None Export: NoneN/ARAMEVP_RAND_ CTX_freeUse: Random number generation

C) © 2024 Red Hat, Inc. / atsec information security corporation.

29 of 46

Page 30
Internal state (V, C) (CSP) IG D.L compliantHash_DRBG A3570Hash_DRBG
DH private key (CSP)112-200 bitsKAS-FFC-SSC A3554SP 800-56Ar3 (safe primes) Section 5.6.1.1.4 Testing CandidatesMD/EE Import: API input parameters From: Operator calling application (TOEPP) To: Cryptographic module Export: API output parameters From: Cryptographic module To: Operator calling application (TOEPP)N/ARAMEVP_PKEY_fr eeUse: Shared secret computation Key pair generation Key pair verification Related SSPs: DH public key Intermediate key generation value
DH public key (PSP)112-200 bitsUse: Shared secret computation Key pair generation Key pair verification Related SSPs: DH private key Intermediate key generation value
EC private key (CSP)112, 128, 192, 256 bitsKAS-ECC-SSC ECDSA A3534, A3544, A3545, A3546, A3547, A4022, A4024, A4459FIPS 186-4 Appendix B.4.2 Testing CandidatesMD/EE Import: API input parameters From: Operator calling application (TOEPP) To: Cryptographic module Export: API output parameters From: Cryptographic module To: Operator calling application (TOEPP)N/ARAMEVP_PKEY_fr eeUse: Shared secret computation Signature generation Key pair generation Key pair verification Related SSPs: EC public key Intermediate key generation value
EC public key (PSP)112, 128, 192, 256 bitsUse: Shared secret computation Signature verification Key pair generation Key pair verification Related SSPs: EC private key Intermediate key generation

DRBG seed © 2024 Red Hat, Inc. / atsec information security corporation.

30 of 46

Page 31
RSA private key (CSP) RSA public key (PSP)112-256 bits 80-256 bitsRSA A3544, A3545 A3546, A3547, A4022, A4459FIPS 186-4 Appendix B.3.6 Probable Primes with Conditions Based on Auxiliary Probable PrimesMD/EE Import: API input parameters From: Operator calling application (TOEPP) To: Cryptographic module Export: API output parameters From: Cryptographic module To: Operator calling application (TOEPP)N/ARAMEVP_PKEY_fr eeUse: Key pair generation Signature generation Related SSPs: RSA public key Intermediate key generation value Use: Key pair generation Signature verification Related SSPs: RSA private key Intermediate key generation value
Intermediate key generation value (CSP)112-256 bitsCKG vendor affirmedSP 800-133r2 Section 4, 5.1, and 5.2Import: None Export: NoneN/ARAMAutomaticUse: Key pair generation Related SSPs: DH private key DH public key EC private key EC public key RSA private key RSA public key

Entropy Source

Minimum number

Details

9.1 Random bit generators

The module employs two Deterministic Random Bit Generator (DRBG) implementations based on SP 800-90Ar1. These DRBGs are used internally by the module (e.g. to generate seeds for asymmetric key pairs and random numbers for security functions). They can also be accessed using the specified API functions. The following parameters are used:

  1. Private DRBG: AES-256 CTR_DRBG with derivation function. This DRBG is used to generate secret random values (e.g., during asymmetric key pair generation). It can be accessed using RAND_priv_bytes.
  2. Public DRBG: AES-256 CTR_DRBG with derivation function. This DRBG is used to generate general purpose random values that do not need to remain secret (e.g. initialization vectors). It can be accessed using RAND_bytes. These DRBGs will always employ prediction resistance. More information regarding the configuration and design of these DRBGs can be found in the module’s manual pages. © 2024 Red Hat, Inc. / atsec information security corporation.

31 of 46

Page 32
of bits of entropy
SP 800-90B compliant Non- Physical Entropy Source (ESV cert. E48)238 bits of entropy in the 256-bit outputOpenSSL CPU Jitter 2.2.0 entropy source is located within the physical perimeter of the module but partially outside the cryptographic boundary of the module.

Table 12 - Non-Deterministic Random Number Generation Specification The module generates SSPs (e.g., keys) whose strengths are modified by available entropy.

9.2 SSP generation

The module implements Cryptographic Key Generation (CKG, vendor affirmed), compliant with SP 800-133r2. When random values are required, they are obtained from the SP 800-90Ar1 approved DRBG, compliant with Section 4 of SP 800-133r2. The following methods are implemented:

2001 key agreement scheme.
9.3 SSP establishment

The module provides Diffie-Hellman (DH) and Elliptic Curve Diffie-Hellman (ECDH) shared secret computation compliant with SP800-56Ar3, in accordance with scenario 2 (1) of FIPS 140-3 IG D.F. For Diffie-Hellman, the module supports the use of the safe primes defined in RFC 3526 (IKE) and RFC 7919 (TLS). Note that the module only implements key pair generation, key pair verification, and shared secret computation. No other part of the IKE or TLS protocols is implemented (with the exception of the TLS 1.2 and 1.3 KDFs): © 2024 Red Hat, Inc. / atsec information security corporation.

32 of 46

Page 33
Table, extracted as text (did not parse into structured rows)
•   IKE (RFC 3526): ◦   MODP-2048 (ID = 14) ◦   MODP-3072 (ID = 15) ◦   MODP-4096 (ID = 16) ◦   MODP-6144 (ID = 17) ◦   MODP-8192 (ID = 18) •   TLS (RFC 7919) ◦   ffdhe2048 (ID = 256) ◦   ffdhe3072 (ID = 257) ◦   ffdhe4096 (ID = 258) ◦   ffdhe6144 (ID = 259) ◦   ffdhe8192 (ID = 260) For Elliptic Curve Diffie-Hellman, the module supports the NIST-defined P-224, P-256, P-384, and P-
521 curves.

According to FIPS 140-3 IG D.B, the key sizes of DH and ECDH shared secret computation provide 112-200 resp. 112-256 bits of security strength in an approved mode of operation. SP 800-56Ar3 assurances: To comply with the assurances found in Section 5.6.2 of SP 800-56Ar3, the operator must use the module together with an application that implements the TLS protocol. Additionally, the module’s approved “Key pair generation” service must be used to generate ephemeral Diffie- Hellman or EC Diffie-Hellman key pairs, or the key pairs must be obtained from another FIPS-validated module. As part of this service, the module will internally perform the full public key validation of the generated public key. The module’s shared secret computation service will internally perform the full public key validation of the peer public key, complying with Sections 5.6.2.2.1 and 5.6.2.2.2 of SP 800-56Ar3. The module also supports the AES KW and AES KWP key wrapping mechanisms. These algorithms can be used to wrap SSPs with a security strength of 128, 192, or 256 bits, depending on the wrapping key size.

9.4 SSP entry/output

The module only supports SSP entry and output to and from the calling application running on the same operational environment. This corresponds to manual distribution, electronic entry/output (“CM Software to/from App via TOEPP Path”) per FIPS 140-3 IG 9.5.A Table 1. There is no entry or output of cryptographically protected SSPs. SSPs can be entered into the module via API input parameters, when required by a service. SSPs can also be output from the module via API output parameters, immediately after generation of the SSP (see Section 9.2).

9.5 SSP storage

SSPs are provided to the module by the calling application and are destroyed when released by the appropriate API function calls. The module does not perform persistent storage of SSPs. © 2024 Red Hat, Inc. / atsec information security corporation.

33 of 46

Page 34
9.6 SSP zeroization

The memory occupied by SSPs is allocated by regular memory allocation operating system calls. The operator application is responsible for calling the appropriate destruction functions provided in the module's API. The destruction functions (listed in Table 11) overwrite the memory occupied by SSPs with zeroes and de-allocate the memory with the regular memory de-allocation operating system call. All data output is inhibited during zeroization. © 2024 Red Hat, Inc. / atsec information security corporation.

34 of 46

Page 35
AlgorithmParametersConditionTypeTest
HMACSHA-256Initialization (after CASTs)Pre-operational Integrity TestMAC tag verification on fips.so file
SHA-1N/AInitializationCryptographic Algorithm Self-TestKAT digest generation
SHA-512N/AInitializationCryptographic Algorithm Self-TestKAT digest generation
SHA3-256N/AInitializationCryptographic Algorithm Self-TestKAT digest generation
AES GCM256-bit keyInitializationCryptographic Algorithm Self-TestKAT encryption and decryption
AES ECB128-bit keyInitializationCryptographic Algorithm Self-TestKAT decryption
KBKDFHMAC SHA-256 in counter modeInitializationCryptographic Algorithm Self-TestKAT key derivation
KDA OneStepSHA-224InitializationCryptographic Algorithm Self-TestKAT key derivation
HKDFSHA-256InitializationCryptographic Algorithm Self-TestKAT key derivation
ANS X9.42 KDFAES-128 KW with SHA-1InitializationCryptographic Algorithm Self-TestKAT key derivation
ANS X9.63 KDFSHA-256InitializationCryptographic Algorithm Self-TestKAT key derivation
SSH KDFSHA-1InitializationCryptographic Algorithm Self-TestKAT key derivation
TLS 1.2 KDFSHA-256InitializationCryptographic Algorithm Self-TestKAT key derivation
TLS 1.3 KDFSHA-256InitializationCryptographic Algorithm Self-TestKAT key derivation
PBKDF2SHA-256 with 4096 iterationsInitializationCryptographic AlgorithmKAT password-based key derivation
10 Self-tests

The module performs pre-operational self-tests and conditional self-tests. While the module is executing the self-tests, services are not available, and data output (via the data output interface) is inhibited until the tests are successfully completed. The module does not return control to the calling application until the tests are completed. Both conditional and pre-operational self-tests can be executed on-demand by unloading and subsequently re-initializing the module. All the self-tests are listed in Table 12, with the respective condition under which those tests are performed. Note that the pre-operational integrity test is only executed after all cryptographic algorithm self-tests (CASTs) executed successfully. © 2024 Red Hat, Inc. / atsec information security corporation.

35 of 46

Page 36
AlgorithmParameters and 288-bit saltConditionType Self-TestTest
CTR_DRBGAES-128 with derivation function and prediction resistanceInitializationCryptographic Algorithm Self-TestKAT DRBG generation and reseed
Hash_DRBGSHA-256 with prediction resistanceInitializationCryptographic Algorithm Self-TestKAT DRBG generation and reseed
HMAC_DRBGSHA-1 with prediction resistanceInitializationCryptographic Algorithm Self-TestKAT DRBG generation and reseed
KAS-FFC-SSCffdhe2048InitializationCryptographic Algorithm Self-TestKAT shared secret computation
KAS-ECC-SSCP-256InitializationCryptographic Algorithm Self-TestKAT shared secret computation
RSAPKCS#1 v1.5 with SHA-256 and 2048-bit keyInitializationCryptographic Algorithm Self-TestKAT signature generation and verification
ECDSASHA-256 and P-224, P-256, P- 384, and P-521InitializationCryptographic Algorithm Self-TestKAT signature generation and verification
DHN/ADH key pair generationPair-wise Consistency TestSection 5.6.2.1.4 pair-wise consistency
RSAPKCS#1 v1.5 with SHA-256RSA key pair generationPair-wise Consistency TestSign/verify pair-wise consistency
ECDSASHA-256EC key pair generationPair-wise Consistency TestSign/verify pair-wise consistency
10.1 Pre-operational tests

The module performs pre-operational tests automatically when the module is powered on. The pre-operational self-tests ensure that the module is not corrupted. The module transitions to the operational state only after the pre-operational self-tests are passed successfully. The types of pre-operational self-tests are described in the next sub-sections.

10.1.1 Pre-operational software integrity test

The integrity of the shared library component of the module is verified by comparing an HMAC SHA-256 value calculated at run time with the HMAC SHA-256 value embedded in the fips.so file that was computed at build time. If the software integrity test fails, the module transitions to the error state (Section 10.3). As mentioned previously, the HMAC and SHA-256 algorithms go through their respective CASTs before the software integrity test is performed. © 2024 Red Hat, Inc. / atsec information security corporation.

36 of 46

Page 37
Error StateCause of ErrorStatus Indicator
ErrorSoftware integrity test failureModule will not load
CAST failureModule will not load
PCT failureModule stops functioning
10.2 Conditional self-tests
10.2.1 Conditional cryptographic algorithm tests

The module performs self-tests on all approved cryptographic algorithms as part of the approved services supported in the approved mode of operation, using the tests shown in Table 13. Data output through the data output interface is inhibited during the self-tests. If any of these tests fails, the module transitions to the error state (Section 10.3).

10.2.2 Conditional pair-wise consistency test

Upon generation of a DH, RSA or EC key pair, the module will perform a pair-wise consistency test (PCT) as shown in Table 13, which provides some assurance that the generated key pair is well formed. For DH key pairs, this tests consists of the PCT described in Section 5.6.2.1.4 of SP 80056Ar3. For RSA and EC key pairs, this test consists of a signature generation and a signature verification operation. If the test fails, the module transitions to the error state (Section 10.3).

10.3 Error states

If the module fails any of the self-tests, the module enters the error state. In the error state, the module immediately stops functioning and ends the application process. Consequently, the data output interface is inhibited, and the module accepts no more inputs or requests (as the module is no longer running). Table 8 lists the error states and the status indicator values that explain the error that has occurred. Table 14 - Error States © 2024 Red Hat, Inc. / atsec information security corporation.

37 of 46

Page 38
11 Life-cycle assurance
11.1 Delivery and operation

The module is distributed as a part of the Red Hat Enterprise Linux 9 (RHEL 9) package in the form of the openssl-3.0.1-46.el9_0.3 RPM package.

11.1.1 End of life procedures

As the module does not persistently store SSPs, secure sanitization of the module consists of unloading the module. This will zeroize all SSPs in volatile memory. Then, if desired, the openssl3.0.1-46.el9_0.3 RPM package can be uninstalled from the RHEL 9 system.

11.2 Crypto Officer guidance

Before the openssl-3.0.1-46.el9_0.3 RPM package is installed, the RHEL 9 system must operate in the approved mode. This can be achieved by:

11.2.1 AES GCM IV

The Crypto Officer shall consider the following requirements and restrictions when using the module. For TLS 1.2, the module offers the AES GCM implementation and uses the context of Scenario 1 of FIPS 140-3 IG C.H. OpenSSL 3 is compliant with SP 800-52r2 Section 3.3.1 and the mechanism for IV generation is compliant with RFC 5288 and 8446. The module does not implement the TLS protocol. The module’s implementation of AES GCM is used together with an application that runs outside the module’s cryptographic boundary. The design of the TLS protocol implicitly ensures that the counter (the nonce_explicit part of the IV) does not exhaust the maximum number of possible values for a given session key. © 2024 Red Hat, Inc. / atsec information security corporation.

38 of 46

Page 39

In the event the module’s power is lost and restored, the consuming application must ensure that a new key for use with the AES GCM key encryption or decryption under this scenario shall be established. Alternatively, the Crypto Officer can use the module’s API to perform AES GCM encryption using internal IV generation. These IVs are always 96 bits and generated using the approved DRBG internal to the module’s boundary. The module also provides a non-approved AES GCM encryption service which accepts arbitrary external IVs from the operator. This service can be requested by invoking the EVP_EncryptInit_ex2 API function with a non-NULL iv value. When this is the case, the API will set a non-approved service indicator as described in Section 4.3. Finally, for TLS 1.3, the AES GCM implementation uses the context of Scenario 5 of FIPS 140-3 IG C.H. The protocol that provides this compliance is TLS 1.3, defined in RFC8446 of August 2018, using the cipher-suites that explicitly select AES GCM as the encryption/decryption cipher (Appendix B.4 of RFC8446). The module supports acceptable AES GCM cipher suites from Section

3.3.1 of SP800-52r2. TLS 1.3 employs separate 64-bit sequence numbers, one for protocol records

that are received, and one for protocol records that are sent to a peer. These sequence numbers are set at zero at the beginning of a TLS 1.3 connection and each time when the AES-GCM key is changed. After reading or writing a record, the respective sequence number is incremented by one. The protocol specification determines that the sequence number should not wrap, and if this condition is observed, then the protocol implementation must either trigger a re-key of the session (i.e., a new key for AES-GCM), or terminate the connection.

11.2.2 AES XTS

In compliance with IG C.I, the module implements the check to ensure that the two AES keys used in AES XTS are not identical. The length of a single data unit encrypted or decrypted with AES XTS shall not exceed 2²⁰ AES blocks, that is 16MB, of data per XTS instance. An XTS instance is defined in Section 4 of SP 80038E. The XTS mode shall only be used for the cryptographic protection of data on storage devices. It shall not be used for other purposes, such as the encryption of data in transit.

11.2.3 Key derivation using SP 800-132 PBKDF2

The module provides password-based key derivation (PBKDF2), compliant with SP 800-132. The module supports option 1a from Section 5.4 of SP 800-132, in which the Master Key (MK) or a segment of it is used directly as the Data Protection Key (DPK). In accordance to SP 800-132 and FIPS 140-3 IG D.N, the following requirements shall be met:

39 of 46

Page 40

• The iteration count shall be selected as large as possible, as long as the time required to generate the key using the entered password is acceptable for the users. The module only allows minimum iteration count to be 1000. © 2024 Red Hat, Inc. / atsec information security corporation.

40 of 46

Page 41
12 Mitigation of other attacks

Certain cryptographic subroutines and algorithms are vulnerable to timing analysis. The module mitigates this vulnerability by using constant-time implementations. This includes, but is not limited to:

41 of 46

Page 42
Table, extracted as text (did not parse into structured rows)
Appendix A. Glossary and abbreviations AES          Advanced Encryption Standard AES-NI       Advanced Encryption Standard New Instructions API          Application Programming Interface CAST         Cryptographic Algorithm Self-Test CAVP         Cryptographic Algorithm Validation Program CBC          Cipher Block Chaining CCM          Counter with Cipher Block Chaining-Message Authentication Code CFB          Cipher Feedback CKG          Cryptographic Key Generation CMAC         Cipher-based Message Authentication Code CMVP         Cryptographic Module Validation Program CPACF        CP Assist for Cryptographic Functions CSP          Critical Security Parameter CTR          Counter CTS          Ciphertext Stealing DH           Diffie-Hellman DRBG         Deterministic Random Bit Generator ECB          Electronic Code Book ECC          Elliptic Curve Cryptography ECDH         Elliptic Curve Diffie-Hellman ECDSA        Elliptic Curve Digital Signature Algorithm EVP          Envelope FFC          Finite Field Cryptography FIPS         Federal Information Processing Standards GCM          Galois Counter Mode GMAC         Galois Counter Mode Message Authentication Code HKDF         HMAC-based Key Derivation Function HMAC         Keyed-Hash Message Authentication Code IKE          Internet Key Exchange KAS          Key Agreement Scheme KAT          Known Answer Test KBKDF        Key-based Key Derivation Function KW           Key Wrap KWP          Key Wrap with Padding MAC          Message Authentication Code NIST         National Institute of Science and Technology OAEP         Optimal Asymmetric Encryption Padding © 2024 Red Hat, Inc. / atsec information security corporation.

42 of 46

Page 43
Table, extracted as text (did not parse into structured rows)
OFB          Output Feedback PAA          Processor Algorithm Acceleration PCT          Pair-wise Consistency Test PBKDF2       Password-based Key Derivation Function v2 PKCS         Public-Key Cryptography Standards PSS          Probabilistic Signature Scheme RSA          Rivest, Shamir, Addleman SHA          Secure Hash Algorithm SSC          Shared Secret Computation SSH          Secure Shell SSP          Sensitive Security Parameter TLS          Transport Layer Security XOF          Extendable Output Function XTS          XEX-based Tweaked-codebook mode with cipher text Stealing © 2024 Red Hat, Inc. / atsec information security corporation.

43 of 46

Page 44
ANS X9.42-Public Key Cryptography for the Financial Services Industry: Agreement of
2001Symmetric Keys Using Discrete Logarithm Cryptography 2001 https://webstore.ansi.org/standards/ascx9/ansix9422001
ANS X9.63-Public Key Cryptography for the Financial Services Industry, Key Agreement and
2001Key Transport Using Elliptic Curve Cryptography 2001 https://webstore.ansi.org/standards/ascx9/ansix9632001
FIPS 140-3FIPS PUB 140-3 - Security Requirements For Cryptographic Modules March 2019 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-3.pdf
FIPS 140-3 IGImplementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program https://csrc.nist.gov/Projects/cryptographic-module-validation-program/fips-140-3-ig- announcements
FIPS 180-4Secure Hash Standard (SHS) March 2012 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf
FIPS 186-4Digital Signature Standard (DSS) July 2013 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-4.pdf
FIPS 197Advanced Encryption Standard November 2001 https://csrc.nist.gov/publications/fips/fips197/fips-197.pdf
FIPS 198-1The Keyed Hash Message Authentication Code (HMAC) July 2008 https://csrc.nist.gov/publications/fips/fips198-1/FIPS-198-1_final.pdf
FIPS 202SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions August 2015 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.202.pdf
PKCS#1Public Key Cryptography Standards (PKCS) #1: RSA Cryptography Specifications Version 2.1 February 2003 https://www.ietf.org/rfc/rfc3447.txt
RFC 3526More Modular Exponential (MODP) Diffie-Hellman groups for Internet Key Exchange (IKE) May 2003 https://www.ietf.org/rfc/rfc3526.txt
RFC 5288AES Galois Counter Mode (GCM) Cipher Suites for TLS August 2008 https://www.ietf.org/rfc/rfc5288.txt © 2024 Red Hat, Inc. / atsec information security corporation. 44 of 46
Page 45
RFC 7919Negotiated Finite Field Diffie-Hellman Ephemeral Parameters for Transport Layer Security (TLS) August 2016 https://www.ietf.org/rfc/rfc7919.txt
RFC 8446The Transport Layer Security (TLS) Protocol Version 1.3 August 2018 https://www.ietf.org/rfc/rfc8446.txt
SP 800-38ARecommendation for Block Cipher Modes of Operation Methods and Techniques December 2001 https://csrc.nist.gov/publications/nistpubs/800-38a/sp800-38a.pdf
SP 800-38ARecommendation for Block Cipher Modes of Operation: Three Variants of
AddendumCiphertext Stealing for CBC Mode October 2010 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38a-add.pdf
SP 800-38BRecommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication May 2005 https://csrc.nist.gov/publications/nistpubs/800-38B/SP_800-38B.pdf
SP 800-38CRecommendation for Block Cipher Modes of Operation: the CCM Mode for Authentication and Confidentiality May 2004 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38c.pdf
SP 800-38DRecommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC November 2007 https://csrc.nist.gov/publications/nistpubs/800-38D/SP-800-38D.pdf
SP 800-38ERecommendation for Block Cipher Modes of Operation: The XTS AES Mode for Confidentiality on Storage Devices January 2010 https://csrc.nist.gov/publications/nistpubs/800-38E/nist-sp-800-38E.pdf
SP 800-38FRecommendation for Block Cipher Modes of Operation: Methods for Key Wrapping December 2012 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38F.pdf
SP 800-52r2Guidelines for the Selection, Configuration, and Use of Transport Layer Security (TLS) Implementations August 2019 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-52r2.pdf
SP 800-56Ar3Recommendation for Pair-Wise Key Establishment Schemes Using Discrete Logarithm Cryptography April 2018 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Ar3.pdf
SP 800-56Cr2Recommendation for Key-Derivation Methods in Key-Establishment Schemes August 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Cr2.pdf © 2024 Red Hat, Inc. / atsec information security corporation. 45 of 46
Page 46
SP 800-90Ar1Recommendation for Random Number Generation Using Deterministic Random Bit Generators June 2015 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90Ar1.pdf
SP 800-90BRecommendation for the Entropy Sources Used for Random Bit Generation January 2018 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90B.pdf
SP 800-108r1NIST Special Publication 800-108 - Recommendation for Key Derivation Using Pseudorandom Functions August 2022 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-108r1.pdf
SP 800-131Ar2Transitioning the Use of Cryptographic Algorithms and Key Lengths March 2019 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar2.pdf
SP 800-132Recommendation for Password-Based Key Derivation - Part 1: Storage Applications December 2010 https://csrc.nist.gov/publications/nistpubs/800-132/nist-sp800-132.pdf
SP 800-133r2Recommendation for Cryptographic Key Generation June 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-133r2.pdf
SP 800-135r1Recommendation for Existing Application-Specific Key Derivation Functions December 2011 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-135r1.pdf
SP 800-140BCMVP Security Policy Requirements March 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-140B.pdf © 2024 Red Hat, Inc. / atsec information security corporation. 46 of 46