All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Oracle Linux 9 OpenSSL FIPS Provider

Certificate#4779StandardFIPS 140-3Level1TypeSoftwareEmbodimentMulti-Chip Stand AloneStatusHistoricalVendorOracle Corporation
Medium review priority  ·  no TCB surface named  ·  OpenSSL upstream has published 40 CVEs since this module's initial validation  ·  last validated 10 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
StatusHistorical
CaveatInterim validation; When operated in approved mode; When installed, initialized and configured as specified in Section 11.1 of the Security Policy
VendorOracle Corporation

Approved Algorithms (337)

AlgorithmACVP Cert
AES-CBCA4313
AES-CBCA4314
AES-CBCA4315
AES-CBCA4327
AES-CBCA4328
AES-CBCA4329
AES-CBC-CS1A4313
AES-CBC-CS1A4314
AES-CBC-CS1A4315
AES-CBC-CS1A4327
AES-CBC-CS1A4328
AES-CBC-CS1A4329
AES-CBC-CS2A4313
AES-CBC-CS2A4314
AES-CBC-CS2A4315
AES-CBC-CS2A4327
AES-CBC-CS2A4328
AES-CBC-CS2A4329
AES-CBC-CS3A4313
AES-CBC-CS3A4314
AES-CBC-CS3A4315
AES-CBC-CS3A4327
AES-CBC-CS3A4328
AES-CBC-CS3A4329
AES-CCMA4313
AES-CCMA4314
AES-CCMA4315
AES-CCMA4327
AES-CCMA4328
AES-CCMA4329
AES-CFB1A4313
AES-CFB1A4314
AES-CFB1A4315
AES-CFB1A4327
AES-CFB1A4328
AES-CFB1A4329
AES-CFB128A4313
AES-CFB128A4314
AES-CFB128A4315
AES-CFB128A4327
AES-CFB128A4328
AES-CFB128A4329
AES-CFB8A4313
AES-CFB8A4314
AES-CFB8A4315
AES-CFB8A4327
AES-CFB8A4328
AES-CFB8A4329
AES-CMACA4313
AES-CMACA4314
AES-CMACA4315
AES-CMACA4327
AES-CMACA4328
AES-CMACA4329
AES-CTRA4313
AES-CTRA4314
AES-CTRA4315
AES-CTRA4327
AES-CTRA4328
AES-CTRA4329
AES-ECBA4313
AES-ECBA4314
AES-ECBA4315
AES-ECBA4320
AES-ECBA4327
AES-ECBA4328
AES-ECBA4329
AES-ECBA4331
AES-ECBA4332
AES-ECBA4333
AES-ECBA4334
AES-GCMA4316
AES-GCMA4316
AES-GCMA4321
AES-GCMA4321
AES-GCMA4322
AES-GCMA4322
AES-GCMA4323
AES-GCMA4323
AES-GCMA4335
AES-GCMA4335
AES-GCMA4336
AES-GCMA4336
AES-GCMA4337
AES-GCMA4337
AES-GCMA4338
AES-GCMA4338
AES-GCMA4339
AES-GCMA4339
AES-GCMA4340
AES-GCMA4340
AES-GCMA4341
AES-GCMA4341
AES-GCMA4342
AES-GCMA4342
AES-GCMA4343
AES-GCMA4343
AES-GMACA4316
AES-GMACA4321
AES-GMACA4322
AES-GMACA4323
AES-GMACA4335
AES-GMACA4336
AES-GMACA4337
AES-GMACA4338
AES-GMACA4339
AES-GMACA4340
AES-GMACA4341
AES-GMACA4342
AES-GMACA4343
AES-KWA4313
AES-KWA4314
AES-KWA4315
AES-KWA4327
AES-KWA4328
AES-KWA4329
AES-KWPA4313
AES-KWPA4314
AES-KWPA4315
AES-KWPA4327
AES-KWPA4328
AES-KWPA4329
AES-OFBA4313
AES-OFBA4314
AES-OFBA4315
AES-OFBA4327
AES-OFBA4328
AES-OFBA4329
AES-XTS Testing Revision 2.0A4313
AES-XTS Testing Revision 2.0A4314
AES-XTS Testing Revision 2.0A4315
AES-XTS Testing Revision 2.0A4327
AES-XTS Testing Revision 2.0A4328
AES-XTS Testing Revision 2.0A4329
Counter DRBGA4311
ECDSA KeyGen (FIPS186-4)A4317
ECDSA KeyGen (FIPS186-4)A4326
ECDSA KeyGen (FIPS186-4)A4330
ECDSA KeyGen (FIPS186-4)A4344
ECDSA KeyGen (FIPS186-4)A4345
ECDSA KeyGen (FIPS186-4)A4346
ECDSA KeyVer (FIPS186-4)A4317
ECDSA KeyVer (FIPS186-4)A4326
ECDSA KeyVer (FIPS186-4)A4330
ECDSA KeyVer (FIPS186-4)A4344
ECDSA KeyVer (FIPS186-4)A4345
ECDSA KeyVer (FIPS186-4)A4346
ECDSA SigGen (FIPS186-4)A4312
ECDSA SigGen (FIPS186-4)A4317
ECDSA SigGen (FIPS186-4)A4319
ECDSA SigGen (FIPS186-4)A4326
ECDSA SigGen (FIPS186-4)A4330
ECDSA SigGen (FIPS186-4)A4344
ECDSA SigGen (FIPS186-4)A4345
ECDSA SigGen (FIPS186-4)A4346
ECDSA SigVer (FIPS186-4)A4312
ECDSA SigVer (FIPS186-4)A4317
ECDSA SigVer (FIPS186-4)A4319
ECDSA SigVer (FIPS186-4)A4326
ECDSA SigVer (FIPS186-4)A4330
ECDSA SigVer (FIPS186-4)A4344
ECDSA SigVer (FIPS186-4)A4345
ECDSA SigVer (FIPS186-4)A4346
Hash DRBGA4311
HMAC DRBGA4311
HMAC-SHA-1A4317
HMAC-SHA-1A4326
HMAC-SHA-1A4330
HMAC-SHA-1A4344
HMAC-SHA-1A4345
HMAC-SHA-1A4346
HMAC-SHA2-224A4317
HMAC-SHA2-224A4326
HMAC-SHA2-224A4330
HMAC-SHA2-224A4344
HMAC-SHA2-224A4345
HMAC-SHA2-224A4346
HMAC-SHA2-256A4317
HMAC-SHA2-256A4318
HMAC-SHA2-256A4326
HMAC-SHA2-256A4330
HMAC-SHA2-256A4344
HMAC-SHA2-256A4345
HMAC-SHA2-256A4346
HMAC-SHA2-384A4317
HMAC-SHA2-384A4326
HMAC-SHA2-384A4330
HMAC-SHA2-384A4344
HMAC-SHA2-384A4345
HMAC-SHA2-384A4346
HMAC-SHA2-512A4317
HMAC-SHA2-512A4326
HMAC-SHA2-512A4330
HMAC-SHA2-512A4344
HMAC-SHA2-512A4345
HMAC-SHA2-512A4346
HMAC-SHA2-512/224A4317
HMAC-SHA2-512/224A4326
HMAC-SHA2-512/224A4330
HMAC-SHA2-512/224A4344
HMAC-SHA2-512/224A4345
HMAC-SHA2-512/224A4346
HMAC-SHA2-512/256A4317
HMAC-SHA2-512/256A4326
HMAC-SHA2-512/256A4330
HMAC-SHA2-512/256A4344
HMAC-SHA2-512/256A4345
HMAC-SHA2-512/256A4346
HMAC-SHA3-224A4312
HMAC-SHA3-224A4319
HMAC-SHA3-256A4312
HMAC-SHA3-256A4319
HMAC-SHA3-384A4312
HMAC-SHA3-384A4319
HMAC-SHA3-512A4312
HMAC-SHA3-512A4319
KAS-ECC-SSC Sp800-56Ar3A4317
KAS-ECC-SSC Sp800-56Ar3A4326
KAS-ECC-SSC Sp800-56Ar3A4330
KAS-ECC-SSC Sp800-56Ar3A4344
KAS-ECC-SSC Sp800-56Ar3A4345
KAS-ECC-SSC Sp800-56Ar3A4346
KAS-FFC-SSC Sp800-56Ar3A4325
KDA HKDF Sp800-56Cr1A4310
KDA OneStep SP800-56Cr2A4309
KDF ANS 9.42A4312
KDF ANS 9.42A4317
KDF ANS 9.42A4319
KDF ANS 9.42A4326
KDF ANS 9.42A4330
KDF ANS 9.42A4344
KDF ANS 9.42A4345
KDF ANS 9.42A4346
KDF ANS 9.63A4312
KDF ANS 9.63A4317
KDF ANS 9.63A4319
KDF ANS 9.63A4326
KDF ANS 9.63A4330
KDF ANS 9.63A4344
KDF ANS 9.63A4345
KDF ANS 9.63A4346
KDF SP800-108A4324
KDF SSHA4320
KDF SSHA4331
KDF SSHA4332
KDF SSHA4333
KDF SSHA4334
PBKDFA4312
PBKDFA4317
PBKDFA4319
PBKDFA4326
PBKDFA4330
PBKDFA4344
PBKDFA4345
PBKDFA4346
RSA KeyGen (FIPS186-4)A4317
RSA KeyGen (FIPS186-4)A4326
RSA KeyGen (FIPS186-4)A4330
RSA KeyGen (FIPS186-4)A4344
RSA KeyGen (FIPS186-4)A4345
RSA KeyGen (FIPS186-4)A4346
RSA SigGen (FIPS186-4)A4317
RSA SigGen (FIPS186-4)A4326
RSA SigGen (FIPS186-4)A4330
RSA SigGen (FIPS186-4)A4344
RSA SigGen (FIPS186-4)A4345
RSA SigGen (FIPS186-4)A4346
RSA SigVer (FIPS186-4)A4317
RSA SigVer (FIPS186-4)A4326
RSA SigVer (FIPS186-4)A4330
RSA SigVer (FIPS186-4)A4344
RSA SigVer (FIPS186-4)A4345
RSA SigVer (FIPS186-4)A4346
Safe Primes Key GenerationA4325
Safe Primes Key VerificationA4325
SHA-1A4317
SHA-1A4326
SHA-1A4330
SHA-1A4344
SHA-1A4345
SHA-1A4346
SHA2-224A4317
SHA2-224A4326
SHA2-224A4330
SHA2-224A4344
SHA2-224A4345
SHA2-224A4346
SHA2-256A4317
SHA2-256A4318
SHA2-256A4326
SHA2-256A4330
SHA2-256A4344
SHA2-256A4345
SHA2-256A4346
SHA2-384A4317
SHA2-384A4326
SHA2-384A4330
SHA2-384A4344
SHA2-384A4345
SHA2-384A4346
SHA2-512A4317
SHA2-512A4326
SHA2-512A4330
SHA2-512A4344
SHA2-512A4345
SHA2-512A4346
SHA2-512/224A4317
SHA2-512/224A4326
SHA2-512/224A4330
SHA2-512/224A4344
SHA2-512/224A4345
SHA2-512/224A4346
SHA2-512/256A4317
SHA2-512/256A4326
SHA2-512/256A4330
SHA2-512/256A4344
SHA2-512/256A4345
SHA2-512/256A4346
SHA3-224A4312
SHA3-224A4319
SHA3-256A4312
SHA3-256A4319
SHA3-384A4312
SHA3-384A4319
SHA3-512A4312
SHA3-512A4319
SHAKE-128A4312
SHAKE-128A4319
SHAKE-256A4312
SHAKE-256A4319
TLS v1.2 KDF RFC7627A4317
TLS v1.2 KDF RFC7627A4326
TLS v1.2 KDF RFC7627A4330
TLS v1.2 KDF RFC7627A4344
TLS v1.2 KDF RFC7627A4345
TLS v1.2 KDF RFC7627A4346
TLS v1.3 KDFA4310

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Oracle Linux 9 OpenSSL FIPS Provider
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Recovery<br/>Update</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Status Output<br/>Show Status<br/>Self-Test</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>SSH<br/>HTTPS</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Oracle Linux 9 OpenSSL FIPS Provider
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Recovery<br/>Update</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Status Output<br/>Show Status<br/>Self-Test</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>SSH<br/>HTTPS</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Oracle Linux 9 OpenSSL FIPS Provider FIPS 140-3 Level 1 Validation Software Version: 3.0.7-b27cdeb3ba51be46 Last Updated: 2025-05-16 Prepared by: atsec information security corporation

4516 Seton Center Pkwy, Suite 250

Austin, TX 78759 www.atsec.com Document Version 1.3 ©Oracle Corporation

Page 2

Title: Oracle Linux 9 OpenSSL FIPS Provider Security Policy Date: May 14th, 2025 Contributing Authors: Oracle Linux Engineering Security Evaluations – Global Product Security atsec information security Oracle Corporation World Headquarters

2300 Oracle Way

Austin, TX 78741 U.S.A. Worldwide Inquiries: Phone: +1.650.506.7000 Fax: +1.650.506.7200 www.oracle.com change without notice. This document is not warranted to be error-free, nor subject to any other warranties or conditions, whether expressed orally or implied in law, including implied warranties and conditions of merchantability or fitness for a particular purpose. Oracle specifically disclaim any liability with respect to this document and no contractual obligations are formed either directly or indirectly by this document. This document may be reproduced or distributed whole and Oracle and Java are registered trademarks of Oracle and/or its affiliates. Other names may be trademarks of their respective owners. Oracle Linux 9 OpenSSL FIPS Provider Security Policy i

Page 3
Table of Contents
#SectionPage
Page 4

Oracle Linux 9 OpenSSL FIPS Provider Security Policy iii

Page 5
List of Tables
ItemPage
Table 1 - Security Levels1
Table 2 - Software, Firmware, Hybrid Tested Operating Environments3
Table 3 - Executable Code Sets3
Table 4 - Vendor Affirmed Operational Environments3
Table 5 - Modes List and Description3
Table 6 - Approved Algorithms12
Table 7 - Vendor Affirmed Algorithms12
Table 8 - Non-Approved, Not Allowed Algorithms13
Table 9 - Security Function Implementation13
Table 10 - Entropy15
Table 11 - Key Generation16
Table 12 - Key Establishment17
Table 13 - Ports and Interfaces18
Table 14 - Roles19
Table 15 - Approved Services22
Table 16 - Non-Approved Services23
Table 17 - Storage Areas29
Table 18 - SSP Input-Output29
Table 19 - SSP Zeroization Methods29
Table 20 - SSP Information First32
Table 21 - SSP Information Second34
Table 22 - Pre-Operational Self-Tests36
Table 23 - Conditional Self-Tests38
Table 24 - Error States38
Figure 1 – Block Diagram2
Page 6
ISO/IEC 24759 Section 6 SubsectionsFIPS 140-3 Section TitleSecurity Level
1General1
2Cryptographic Module Specification1
3Cryptographic Module Interfaces1
4Roles, Services, and Authentication1
5Software/Firmware Security1
6Operational Environment1
7Physical SecurityNot Applicable
8Non-invasive SecurityNot Applicable
9Sensitive Security Parameter Management1
10Self-tests1
11Life-cycle Assurance1
12Mitigation of Other Attacks1
Overall Level1
1.1 Overview

This document is the non-proprietary FIPS 140-3 Security Policy for software version 3.0.7-b27cdeb3ba51be46 of the Oracle Linux 9 OpenSSL FIPS Provider. It contains the security rules under which the module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for Other documentation is proprietary to their authors.

1.1.1 How this Security Policy Was Prepared

In preparing the Security Policy document, the laboratory formatted the vendor-supplied documentation for consolidation without altering the technical statements therein contained. The further refining of the Security Policy document was conducted iteratively throughout the conformance testing, wherein the Security Policy was submitted to the vendor, who would then edit, modify, and add technical contents. The vendor would also supply additional documentation, which the laboratory formatted into the existing Security Policy, and resubmitted to the vendor for their final editing.

1.2 Security Levels

Table 1 describes the individual security areas of FIPS 140-3, as well as the security levels of those individual areas. Table 1 - Security Levels Oracle Linux 9 OpenSSL FIPS Provider Security Policy

Page 7
2 Cryptographic Module Specification
2.1 Description

Purpose and Use: The Oracle Linux 9 OpenSSL FIPS Provider (hereafter referred to as “the module”) is defined as a software module in a multi-chip standalone embodiment. It provides a C language application program interface (API) for use by other applications that require cryptographic functionality. The module consists of one software component, the “FIPS provider”, which implements the FIPS requirements, and the cryptographic functionality provided to the operator. Module Type: Software Module Embodiment: Multi-chip standalone Module Characteristics: N/A Cryptographic Boundary: Figure 1 shows the cryptographic boundary of the module, its interfaces with the operational environment and the flow of information between the module and operator (depicted through the arrows). Tested Operational Environment’s Physical Perimeter (TOEPP): The TOEPP of the module is defined as the general-purpose computer on which the module is installed. Figure 1 – Block Diagram Oracle Linux 9 OpenSSL FIPS Provider Security Policy

Page 8
Operating SystemHardware PlatformProcessor(s)PAA/PAIHypervisor and Host OS
Oracle Linux 9ORACLE SERVER X9-2cIntel(R) Xeon(R) Platinum 8358AES-NI and SHA ExtensionsKVM on Oracle Linux 8
ORACLE SERVER E4-2cAMD EPYC 7J13AES-NI and SHA Extensions
ORACLE SERVER A1-2cAmpere(R) Altra(R) Q80- 30NEON and Cryptography Extensions (CE)
Oracle Linux 9Marvell Liquid IO II (MIPS64) SmartNICOCTEON IIINoN/A
Package or File NamesSoftware/ Firmware VersionsFeaturesHybrid Hardware VersionIntegrity Test
fips.so3.0.7-b27cdeb3ba51be46N/AN/AHMAC-SHA-256
Operating SystemsHardware PlatformsVirtual Platforms
Oracle Linux 9Oracle X Series Servers Oracle E Series Servers Oracle A Series Servers Marvell T93 LiquidIO III (ARM v8.x) SmartNICPensando DSC-200-R (ARM v8.x) SmartNICOracle Linux KVM VmWare ESXi
NameDescriptionTypeStatus Indicator
Approved modeAutomatically entered whenever an approved service is requestedApprovedEquivalent to the indicator of the requested service
Non-approved modeAutomatically entered whenever a non- approved service is requestedNon-approvedEquivalent to the indicator of the requested service
2.2 Operating Environments

Table 2 - Software, Firmware, Hybrid Tested Operating Environments Executable Code Sets: Table 3 - Executable Code Sets Vendor Affirmed Operating Environments: Table 4 - Vendor Affirmed Operational Environments Note: the CMVP makes no statement as to the correct operation of the module or the security strengths of the generated SSPs when so ported if the specific operational environment is not listed on the validation certificate.

2.3 Excluded Components

There are no components within the cryptographic boundary excluded from the FIPS 140-3 requirements.

2.4 Modes of Operation

Modes List and Description: Table 5 - Modes List and Description Oracle Linux 9 OpenSSL FIPS Provider Security Policy

Page 9
Algorithm NameCAVP NumbersAlgorithms CapabilitiesOE (Implementation)Reference
AES-CBC AES-CBC-CTS-CS1 AES-CBC-CTS-CS2 AES-CBC-CTS-CS3#A4313, #A4314, #A4315, #A4327, #A4328, #A4329Encryption, Decryption using 128, 192, 256-bit keysOracle Linux 9 on KVM on Oracle Linux 8 on AMD EPYCTM 7001 Series AMD EPYC 7J13: AESNI, BAES_CTASM, AESASM Oracle Linux 9 on KVM on Oracle Linux 8 on Ampere® Altra® Q80-30: CE, VPAES, AES_C Oracle Linux 9 on KVM on Oracle Linux 8 on Intel® Xeon® Platinum 8358: AESNI, BAES_CTASM, AESASM Oracle Linux 9 on Marvell OCTEON III: AESASMFIPS 197, SP 800-38A, SP 800-38A Addendum
AES-CCMAuthenticated Encryption, Authenticated Decryption, Key Wrapping, Key Unwrapping (compliant to IG D.G) using 128, 192, 256-bit keys
AES-CFB1 AES-CFB8 AES-CFB128Encryption, Decryption using 128, 192, 256-bit keys
AES-CMACMessage Authentication Code Generation, Message Authentication Code Verification using 128, 192, 256-bit keysFIPS 197, SP 800-38B
AES-CTREncryption, Decryption using 128, 192, 256-bit keysFIPS 197, SP 800-38A, SP 800-38A Addendum
AES-ECB#A4320, #A4327, #A4328, #A4329, #A4331, #A4332, #A4333, #A4334Encryption, Decryption using 128, 192, 256-bit keysOracle Linux 9 on KVM on Oracle Linux 8 on AMD EPYCTM 7001 Series AMD EPYC 7J13: SSH_ASM, AESNI, BAES_CTASM, AESASM, SSH_SHANI, SSH_AVX2, SSH_AVX, SSH_SSSE3

After passing all pre-operational self-tests and cryptographic algorithm self-tests executed on start-up, the module automatically transitions to the approved mode. Mode change instructions and status indicators: The module automatically switches between the approved and non-approved modes depending on the services requested by the operator. The status indicator of the mode of operation is equivalent to the indicator of the service that was requested. Degraded Mode Description: The module does not implement a degraded mode of operation. Approved Algorithms: Oracle Linux 9 OpenSSL FIPS Provider Security Policy

Page 10
Algorithm NameCAVP NumbersAlgorithms CapabilitiesOE (Implementation) Oracle Linux 9 on KVM on Oracle Linux 8 on Ampere® Altra® Q80-30: SSH_ASM, CE, VPAES, AES_C Oracle Linux 9 on KVM on Oracle Linux 8 on Intel® Xeon® Platinum 8358: SSH_ASM, AESNI, BAES_CTASM, AESASM, SSH_SHANI, SSH_AVX2, SSH_AVX, SSH_SSSE3 Oracle Linux 9 on Marvell OCTEON III: AESASMReference
AES-GCM (internal IV)#A4316, #A4321, #A4322, #A4323, #A4335, #A4336, #A4337, #A4338, #A4339, #A4340, #A4341, #A4342, #A4343Authenticated Encryption, Key Wrapping using 128, 192, 256-bit keysOracle Linux 9 on KVM on Oracle Linux 8 on AMD EPYCTM 7001 Series AMD EPYC 7J13: AESNI_AVX, AESNI_CLMULNI, AESNI_ASM, BAES_CTASM_AVX, BAES_CTASM_CLMULNI, BAES_CTASM_ASM, AESASM_AVX, AESASM_CLMULNI, AESASM_ASM Oracle Linux 9 on KVM on Oracle Linux 8 on Ampere® Altra® Q80-30: CE_GCM_UNROLL8_EOR3, CE_GCM, VPAES_GCM, AES_C_GCM Oracle Linux 9 on KVM on Oracle Linux 8 on Intel® Xeon® Platinum 8358: AESNI_AVX, AESNI_CLMULNI, AESNI_ASM, BAES_CTASM_AVX, BAES_CTASM_CLMULNI, BAES_CTASM_ASM, AESASM_AVX, AESASM_CLMULNI, AESASM_ASM Oracle Linux 9 on Marvell OCTEON III: AESASM_ASMFIPS 197 SP 800-38D FIPS 140-3 IG D.G Additional comment 8
AES-GCM (external IV)Authenticated Decryption, Key Unwrapping using 128, 192, 256-bit keys
AES-GMACMessage Authentication Code Generation, Message Authentication Code Verification using 128, 192, 256-bit keys
AES-OFB#A4313, #A4314, #A4315, #A4327, #A4328, #A4329Encryption, Decryption using 128, 192, 256-bit keysOracle Linux 9 on KVM on Oracle Linux 8 on AMD EPYCTM 7001 Series AMD EPYC 7J13: AESNI, BAES_CTASM, AESASM Oracle Linux 9 on KVM on Oracle Linux 8 on Ampere® Altra® Q80-30: CE, VPAES, AES_C Oracle Linux 9 on KVM on Oracle Linux 8 on Intel® Xeon® Platinum 8358: AESNI, BAES_CTASM, AESASM Oracle Linux 9 on Marvell OCTEON III: AESASMFIPS 197, SP 800-38A, SP 800-38A Addendum
AES-KW AES-KWPKey Wrapping, Key Unwrapping (compliant to IG D.G) using 128, 192, 256-bit keysFIPS 197, SP 800-38F
AES-XTSEncryption, Decryption using 128 and 256-bit keysFIPS 197, SP 800-38E
ANS X9.42 KDF (CVL) with AES KW-128, AES KW-192, AES KW-256 and SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2- 512/256,#A4326, #A4330, #A4344, #A4345, #A4346Key DerivationOracle Linux 9 on KVM on Oracle Linux 8 on AMD EPYCTM 7001 Series AMD EPYC 7J13: SHA_ASM, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3 Oracle Linux 9 on KVM on Oracle Linux 8 on Ampere® Altra® Q80-30: SHA_ASM, SHA_CE Oracle Linux 9 on KVM on Oracle Linux 8 on Intel® Xeon® Platinum 8358: SHA_ASM, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3SP 800-135r1

Oracle Linux 9 OpenSSL FIPS Provider Security Policy

Page 11
Algorithm Name ANS X9.42 KDF (CVL) with AES KW-128, AES KW-192, AES KW-256 with SHA3-224, SHA3- 256, SHA3-384, SHA3- 512 ANS X9.63 KDF (CVL) with SHA2-224, SHA2- 256, SHA2-384, SHA2- 512, SHA2-512/224, SHA2-512/256, ANS X9.63 KDF (CVL) with SHA3-224, SHA3- 256, SHA3-384, SHA3- 512CAVP Numbers #A4312, #A4319, #A4317, #A4326, #A4330, #A4344, #A4345, #A4346 #A4312, #A4319Algorithms CapabilitiesOE (Implementation) Oracle Linux 9 on Marvell OCTEON III: SHA_ASM Oracle Linux 9 on KVM on Oracle Linux 8 on AMD EPYCTM 7001 Series AMD EPYC 7J13: SHA3_ASM Oracle Linux 9 on KVM on Oracle Linux 8 on Ampere® Altra® Q80-30: SHA3_CE Oracle Linux 9 on KVM on Oracle Linux 8 on Intel® Xeon® Platinum 8358: SHA3_ASM Oracle Linux 9 on Marvell OCTEON III: SHA3_ASM Oracle Linux 9 on KVM on Oracle Linux 8 on AMD EPYCTM 7001 Series AMD EPYC 7J13: SHA_ASM, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3 Oracle Linux 9 on KVM on Oracle Linux 8 on Ampere® Altra® Q80-30: SHA_ASM, SHA_CE Oracle Linux 9 on KVM on Oracle Linux 8 on Intel® Xeon® Platinum 8358: SHA_ASM, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3 Oracle Linux 9 on Marvell OCTEON III: SHA_ASM Oracle Linux 9 on KVM on Oracle Linux 8 on AMD EPYCTM 7001 Series AMD EPYC 7J13: SHA3_ASM Oracle Linux 9 on KVM on Oracle Linux 8 on Ampere® Altra® Q80-30: SHA3_CE Oracle Linux 9 on KVM on Oracle Linux 8 on Intel® Xeon® Platinum 8358: SHA3_ASM Oracle Linux 9 on Marvell OCTEON III: SHA3_ASMReference
CTR_DRBG#A4311Random Number Generation using 128, 192, 256-bit keys, with/without PR, with/without DFOracle Linux 9 on KVM on Oracle Linux 8 on AMD EPYCTM 7001 Series AMD EPYC 7J13: DRBG_3 Oracle Linux 9 on KVM on Oracle Linux 8 on Ampere® Altra® Q80-30: DRBG_3 Oracle Linux 9 on KVM on Oracle Linux 8 on Intel® Xeon® Platinum 8358: DRBG_3 Oracle Linux 9 on Marvell OCTEON III: DRBG_3SP 800-90Ar1
ECDSA with SHA2- 224, SHA2-256, SHA2- 384, SHA2-512, SHA2- 512/224, SHA2- 512/256#A4317, #A4326, #A4330, #A4344, #A4345, #A4346Signature Generation, Signature Verification using P- 224, P-256, P-384, P-521 elliptic curvesOracle Linux 9 on KVM on Oracle Linux 8 on AMD EPYCTM 7001 Series AMD EPYC 7J13: SHA_ASM, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3, Oracle Linux 9 on KVM on Oracle Linux 8 on Ampere® Altra® Q80-30: SHA_ASM, SHA_CE Oracle Linux 9 on KVM on Oracle Linux 8 on Intel® Xeon® Platinum 8358: SHA_ASM,FIPS 186-4

Oracle Linux 9 OpenSSL FIPS Provider Security Policy

Page 12
Algorithm Name ECDSA with SHA3- 224, SHA3-256, SHA3- 384, SHA3-512CAVP Numbers #A4312, #A4319Algorithms Capabilities Signature Generation, Signature Verification P-224, P-256, P-384, P-521 elliptic curvesOE (Implementation) SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3, Oracle Linux 9 on Marvell OCTEON III: SHA_ASM Oracle Linux 9 on KVM on Oracle Linux 8 on AMD EPYCTM 7001 Series AMD EPYC 7J13: SHA3_ASM Oracle Linux 9 on KVM on Oracle Linux 8 on Ampere® Altra® Q80-30: SHA3_CE Oracle Linux 9 on KVM on Oracle Linux 8 on Intel® Xeon® Platinum 8358: SHA3_ASM Oracle Linux 9 on Marvell OCTEON III: SHA3_ASMReference
ECDSA#A4317, #A4326, #A4330, #A4344, #A4345, #A4346Key Pair Generation using P-224, P-256, P-384, P-521 elliptic curvesOracle Linux 9 on KVM on Oracle Linux 8 on AMD EPYCTM 7001 Series AMD EPYC 7J13: SHA_ASM, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3, Oracle Linux 9 on KVM on Oracle Linux 8 on Ampere® Altra® Q80-30: SHA_ASM, SHA_CE Oracle Linux 9 on KVM on Oracle Linux 8 on Intel® Xeon® Platinum 8358: SHA_ASM, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3, Oracle Linux 9 on Marvell OCTEON III: SHA_ASMFIPS 186-4 Appendix B.4.2 Testing Candidates
Key Pair Verification using P- 224, P-256, P-384, P-521 elliptic curvesFIPS 186-4
HKDF with SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2- 512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512#A4310Key DerivationOracle Linux 9 on KVM on Oracle Linux 8 on AMD EPYCTM 7001 Series AMD EPYC 7J13: TLS v1.3 Oracle Linux 9 on KVM on Oracle Linux 8 on Ampere® Altra® Q80-30: TLS v1.3 Oracle Linux 9 on KVM on Oracle Linux 8 on Intel® Xeon® Platinum 8358: TLS v1.3 Oracle Linux 9 on Marvell OCTEON III: TLS v1.3SP800-56Cr1
HMAC-SHA-1, HMAC- SHA2-224, HMAC- SHA2-384, HMAC- SHA2-512, HMAC- SHA2-512/224, HMAC-SHA2-512/256#A4317, #A4326, #A4330, #A4344, #A4345, #A4346Message Authentication Code Generation, Message Authentication Code Verification using 112-524288- bit keysOracle Linux 9 on KVM on Oracle Linux 8 on AMD EPYCTM 7001 Series AMD EPYC 7J13: SHA_ASM, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3, Oracle Linux 9 on KVM on Oracle Linux 8 on Ampere® Altra® Q80-30: SHA_ASM, SHA_CE Oracle Linux 9 on KVM on Oracle Linux 8 on Intel® Xeon® Platinum 8358: SHA_ASM, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3 Oracle Linux 9 on Marvell OCTEON III: SHA_ASMFIPS 198-1

Oracle Linux 9 OpenSSL FIPS Provider Security Policy

Page 13
Algorithm Name HMAC-SHA2-256 HMAC-SHA3-224, HMAC-SHA3-256, HMAC-SHA3-384, HMAC-SHA3-512CAVP Numbers #A4317, #A4318, #A4326, #A4330, #A4344, #A4345, #A4346 #A4312, #A4319Algorithms CapabilitiesOE (Implementation) Oracle Linux 9 on KVM on Oracle Linux 8 on AMD EPYCTM 7001 Series AMD EPYC 7J13: SHA_ASM, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3, Oracle Linux 9 on KVM on Oracle Linux 8 on Ampere® Altra® Q80-30: SHA_ASM, SHA_CE, NEON Oracle Linux 9 on KVM on Oracle Linux 8 on Intel® Xeon® Platinum 8358: SHA_ASM, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3 Oracle Linux 9 on Marvell OCTEON III: SHA_ASM Oracle Linux 9 on KVM on Oracle Linux 8 on AMD EPYCTM 7001 Series AMD EPYC 7J13: SHA3_ASM Oracle Linux 9 on KVM on Oracle Linux 8 on Ampere® Altra® Q80-30: SHA3_CE Oracle Linux 9 on KVM on Oracle Linux 8 on Intel® Xeon® Platinum 8358: SHA3_ASM Oracle Linux 9 on Marvell OCTEON III: SHA3_ASMReference FIPS 202
HMAC_DRBG#A4311Random Number Generation using 112-524288-bit keys, with/without PROracle Linux 9 on KVM on Oracle Linux 8 on AMD EPYCTM 7001 Series AMD EPYC 7J13: DRBG_3 Oracle Linux 9 on KVM on Oracle Linux 8 on Ampere® Altra® Q80-30: DRBG_3 Oracle Linux 9 on KVM on Oracle Linux 8 on Intel® Xeon® Platinum 8358: DRBG_3 Oracle Linux 9 on Marvell OCTEON III: DRBG_3SP 800-90Ar1
Hash_DRBGRandom Number Generation, with/without PR
KAS-ECC-SSC#A4317, #A4326, #A4330, #A4344, #A4345, #A4346Shared Secret Computation with P-256, P-384, P-521 elliptic curvesOracle Linux 9 on KVM on Oracle Linux 8 on AMD EPYCTM 7001 Series AMD EPYC 7J13: SHA_ASM, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3, Oracle Linux 9 on KVM on Oracle Linux 8 on Ampere® Altra® Q80-30: SHA_ASM, SHA_CE Oracle Linux 9 on KVM on Oracle Linux 8 on Intel® Xeon® Platinum 8358: SHA_ASM, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3, Oracle Linux 9 on Marvell OCTEON III: SHA_ASMSP 800-56Ar3 FIPS 140-3 IG D.F scenario 2 path (1)
KAS-FFC-SSC#A4325Shared Secret Computation with MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192, ffdhe2048,Oracle Linux 9 on KVM on Oracle Linux 8 on AMD EPYCTM 7001 Series AMD EPYC 7J13: FFC_DH Oracle Linux 9 on KVM on Oracle Linux 8 on Ampere® Altra® Q80-30: FFC_DH Oracle Linux 9 on KVM on Oracle Linux 8 on Intel® Xeon® Platinum 8358: FFC_DH

Oracle Linux 9 OpenSSL FIPS Provider Security Policy

Page 14
Algorithm NameCAVP NumbersAlgorithms Capabilities ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192OE (Implementation) Oracle Linux 9 on Marvell OCTEON III: FFC_DHReference
KBKDF with CMAC- AES128, CMAC- AES192, CMAC- AES256 and HMAC SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2- 512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512#A4324Key DerivationOracle Linux 9 on KVM on Oracle Linux 8 on AMD EPYCTM 7001 Series AMD EPYC 7J13: KBKDF Oracle Linux 9 on KVM on Oracle Linux 8 on Ampere® Altra® Q80-30: KBKDF Oracle Linux 9 on KVM on Oracle Linux 8 on Intel® Xeon® Platinum 8358: KBKDF Oracle Linux 9 on Marvell OCTEON III: KBKDFSP 800-108r1
KDA OneStep1 with HMAC-SHA-1, HMAC- SHA2-224, HMAC- SHA2-256, HMAC- SHA2-384, HMAC- SHA2-512, HMAC- SHA2-512/224, HMAC-SHA2-512/256, HMAC-SHA3-224, HMAC-SHA3-256, HMAC-SHA3-384, HMAC-SHA3-512#A4309Oracle Linux 9 on KVM on Oracle Linux 8 on AMD EPYCTM 7001 Series AMD EPYC 7J13: KDA Oracle Linux 9 on KVM on Oracle Linux 8 on Ampere® Altra® Q80-30: KDA Oracle Linux 9 on KVM on Oracle Linux 8 on Intel® Xeon® Platinum 8358: KDA Oracle Linux 9 on Marvell OCTEON III: KDASP 800-56Cr2
PBKDF2 with SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2- 512/256,#A4317, #A4326, #A4330, #A4344, #A4345, #A4346Oracle Linux 9 on KVM on Oracle Linux 8 on AMD EPYCTM 7001 Series AMD EPYC 7J13: SHA_ASM, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3 Oracle Linux 9 on KVM on Oracle Linux 8 on Ampere® Altra® Q80-30: SHA_ASM, SHA_CE Oracle Linux 9 on KVM on Oracle Linux 8 on Intel® Xeon® Platinum 8358: SHA_ASM, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3 Oracle Linux 9 on Marvell OCTEON III: SHA_ASMOption 1a SP 800-132
PBKDF2 with SHA3- 224, SHA3-256, SHA3- 384, SHA3-512#A4312, #A4319Oracle Linux 9 on KVM on Oracle Linux 8 on AMD EPYCTM 7001 Series AMD EPYC 7J13: SHA3_ASM Oracle Linux 9 on KVM on Oracle Linux 8 on Ampere® Altra® Q80-30: SHA3_CE Oracle Linux 9 on KVM on Oracle Linux 8 on Intel® Xeon® Platinum 8358: SHA3_ASM Oracle Linux 9 on Marvell OCTEON III: SHA3_ASM

1 This algorithm is referred to as “Single Step KDF” or “SSKDF” by OpenSSL.

Oracle Linux 9 OpenSSL FIPS Provider Security Policy

Page 15
Algorithm NameCAVP NumbersAlgorithms CapabilitiesOE (Implementation)Reference
RSA PKCS#1 v1.5 and PSS with SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2- 512/224, SHA2- 512/256#A4317, #A4326, #A4330, #A4344, #A4345, #A4346Signature Generation using 2048, 3072, 4096- bit keysOracle Linux 9 on KVM on Oracle Linux 8 on AMD EPYCTM 7001 Series AMD EPYC 7J13: SHA_ASM, SHA_SHANI, SHA_AVX2, SHA_SSSE3 Oracle Linux 9 on KVM on Oracle Linux 8 on Ampere® Altra® Q80-30: SHA_ASM, SHA_CE Oracle Linux 9 on KVM on Oracle Linux 8 on Intel® Xeon® Platinum 8358: SHA_ASM, SHA_SHANI, SHA_AVX2, SHA_SSSE3 Oracle Linux 9 on Marvell OCTEON III: SHA_ASMFIPS 186-4
Signature Verification using 1024, 2048, 3072, 4096-bit keysOracle Linux 9 on KVM on Oracle Linux 8 on AMD EPYCTM 7001 Series AMD EPYC 7J13: SHA_ASM, SHA_SHANI Oracle Linux 9 on KVM on Oracle Linux 8 on Ampere® Altra® Q80-30: SHA_ASM Oracle Linux 9 on KVM on Oracle Linux 8 on Intel® Xeon® Platinum 8358: SHA_ASM, SHA_SHANI Oracle Linux 9 on Marvell OCTEON III: SHA_ASM
RSA#A4317, #A4326, #A4330, #A4344, #A4345, #A4346Key Pair Generation using 2048-15360- bit keysOracle Linux 9 on KVM on Oracle Linux 8 on AMD EPYCTM 7001 Series AMD EPYC 7J13: SHA_ASM, SHA_SHANI, SHA_AVX2, SHA_SSSE3 Oracle Linux 9 on KVM on Oracle Linux 8 on Ampere® Altra® Q80-30: SHA_ASM, SHA_CE Oracle Linux 9 on KVM on Oracle Linux 8 on Intel® Xeon® Platinum 8358: SHA_ASM, SHA_SHANI, SHA_AVX2, SHA_SSSE3 Oracle Linux 9 on Marvell OCTEON III: SHA_ASMFIPS 186-4 Appendix B.3.6 Probable Primes with Conditions Based on Auxiliary Probable Primes
Safe Primes#A4325Key Generation using MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192Oracle Linux 9 on KVM on Oracle Linux 8 on AMD EPYCTM 7001 Series AMD EPYC 7J13: FFC_DH Oracle Linux 9 on KVM on Oracle Linux 8 on Ampere® Altra® Q80-30: FFC_DH Oracle Linux 9 on KVM on Oracle Linux 8 on Intel® Xeon® Platinum 8358: FFC_DH Oracle Linux 9 on Marvell OCTEON III: FFC_DHSP 800-56Ar3 Section 5.6.1.1.4 Testing Candidates
Safe PrimesKey Verification using MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192, ffdhe2048, ffdhe3072, ffdhe4096,SP 800-56Ar3 Sections 5.6.2.1.2 and 5.6.2.1.4

Oracle Linux 9 OpenSSL FIPS Provider Security Policy

Page 16
Algorithm NameCAVP NumbersAlgorithms Capabilities ffdhe6144, ffdhe8192OE (Implementation)Reference
SHA-1, SHA2-224, SHA2-384, SHA2-512, SHA2-512/224, SHA2- 512/256#A4317, #A4326, #A4330, #A4344, #A4345, #A4346HashingOracle Linux 9 on KVM on Oracle Linux 8 on AMD EPYCTM 7001 Series AMD EPYC 7J13: SHA_ASM, SHA_SHANI, SHA_AVX2, SHA_SSSE3 Oracle Linux 9 on KVM on Oracle Linux 8 on Ampere® Altra® Q80-30: SHA_ASM, SHA_CE Oracle Linux 9 on KVM on Oracle Linux 8 on Intel® Xeon® Platinum 8358: SHA_ASM, SHA_SHANI, SHA_AVX2, SHA_SSSE3 Oracle Linux 9 on Marvell OCTEON III: SHA_ASMFIPS 180-4
SHA2-256#A4317, #A4318, #A4326, #A4330, #A4344, #A4345, #A4346Oracle Linux 9 on KVM on Oracle Linux 8 on AMD EPYCTM 7001 Series AMD EPYC 7J13: SHA_ASM, SHA_SHANI, SHA_AVX2, SHA_SSSE3 Oracle Linux 9 on KVM on Oracle Linux 8 on Ampere® Altra® Q80-30: SHA_ASM, SHA_CE, NEON Oracle Linux 9 on KVM on Oracle Linux 8 on Intel® Xeon® Platinum 8358: SHA_ASM, SHA_SHANI, SHA_AVX2, SHA_SSSE3 Oracle Linux 9 on Marvell OCTEON III: SHA_ASM
SHA3-224, SHA3-256, SHA3-384, SHA3-512#A4312, #A4319Oracle Linux 9 on KVM on Oracle Linux 8 on AMD EPYCTM 7001 Series AMD EPYC 7J13: SHA3_ASM Oracle Linux 9 on KVM on Oracle Linux 8 on Ampere® Altra® Q80-30: SHA3_CE Oracle Linux 9 on KVM on Oracle Linux 8 on Intel® Xeon® Platinum 8358: SHA3_ASM Oracle Linux 9 on Marvell OCTEON III: SHA3_ASMFIPS 202
SHAKE128, SHAKE256XOFs
SSH KDF (CVL) with AES-128, AES-192, AES-256 and SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512#A4320, #A4331, #A4332, #A4333, #A4334Key DerivationOracle Linux 9 on KVM on Oracle Linux 8 on AMD EPYCTM 7001 Series AMD EPYC 7J13: SSH_ASM, SSH_SHANI, SSH_AVX2, SSH_AVX, SSH_SSSE3 Oracle Linux 9 on KVM on Oracle Linux 8 on Ampere® Altra® Q80-30: SSH_ASM Oracle Linux 9 on KVM on Oracle Linux 8 on Intel® Xeon® Platinum 8358: SSH_ASM, SSH_SHANI, SSH_AVX2, SSH_AVX, SSH_SSSE3 Oracle Linux 9 on Marvell OCTEON III: SSH_ASMSP 800-135r1
TLS 1.2 KDF (RFC 7627) (CVL) with SHA2-256, SHA2-384, SHA2-512 using RFC#A4317, #A4326, #A4330, #A4344, #A4345, #A4346Oracle Linux 9 on KVM on Oracle Linux 8 on AMD EPYCTM 7001 Series AMD EPYC 7J13: SHA_ASM, SHA_SHANI, SHA_AVX2, SHA_SSSE3

Oracle Linux 9 OpenSSL FIPS Provider Security Policy

Page 17

Algorithm Name 7627 Extended Master Secret TLS 1.3 KDF (CVL) with SHA2-256, SHA2-384

CAVP Numbers #A4310

Algorithms Capabilities

OE (Implementation) Oracle Linux 9 on KVM on Oracle Linux 8 on Ampere® Altra® Q80-30: SHA_ASM, SHA_CE Oracle Linux 9 on KVM on Oracle Linux 8 on Intel® Xeon® Platinum 8358: SHA_ASM, SHA_SHANI, SHA_AVX2, SHA_SSSE3 Oracle Linux 9 on Marvell OCTEON III: SHA_ASM Oracle Linux 9 on KVM on Oracle Linux 8 on AMD EPYCTM 7001 Series AMD EPYC 7J13: TLS v1.3 Oracle Linux 9 on KVM on Oracle Linux 8 on Ampere® Altra® Q80-30: TLS v1.3 Oracle Linux 9 on KVM on Oracle Linux 8 on Intel® Xeon® Platinum 8358: TLS v1.3 Oracle Linux 9 on Marvell OCTEON III: TLS v1.3

Reference RFC 8446

Algorithm NameAlgorithm CapabilitiesOE (Implementation)References
Cryptographic Key Generation (CKG)FIPS 186-4 Key generation RSA KeyGen: 2048, 3072, 4096 bits with 112, 128, 149 bits of key strength. ECDSA KeyGen: P-224, P-256, P 384, P- 521 elliptic curves with 112-256 bits of key strength Safe Primes Key Generation: MODP-2048, MODP-3072, MODP-4096, MODP-6144, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192 with 112-200 bits of key strengthSame as in Table 6SP 800-133Rev2 Section 4, 5.1, 5.2 FIPS 140-3 IG D.H
NameUse and Function
AES GCM with external IVEncryption
ANS X9.42 KDF (SHAKE128, SHAKE256) ANS X9.63 KDF (SHA-1, SHAKE128, SHAKE256)Key Derivation
Hash_DRBG (SHA-224, SHA-384) HMAC_DRBG (SHA-224, SHA-384)Random Number Generation
ECDSA with curve P-192Key Pair Generation, Key Pair Verification
HMAC (< 112-bit keys)Message Authentication Code Generation, Message Authentication Code Verification
KAS1, KAS2Shared Secret Computation

Vendor Affirmed Algorithms: Table 7 - Vendor Affirmed Algorithms Non-Approved, Allowed Algorithms: The module does not implement non-approved algorithms allowed in the approved mode of operation. Non-Approved, Allowed Algorithms with No Security Claimed: The module does not implement non-approved algorithms allowed in the approved mode of operation with no security claimed. Non-Approved, Not Allowed Algorithms: Oracle Linux 9 OpenSSL FIPS Provider Security Policy

Page 18
NameUse and Function
KBKDF, KDA OneStep, HKDF, ANS X9.42 KDF, ANS X9.63 KDF (< 112-bit keys) KDA OneStep, HKDF (SHAKE128, SHAKE256)Key Derivation
PBKDF2 (short password; short salt; insufficient iterations; < 112-bit keys)Password-Based Key Derivation
RSA and ECDSA (pre-hashed message), ECDSA with curve P-192 RSA-PSS (invalid salt length)Signature Generation, Signature Verification
RSA-OAEPAsymmetric Encryption, Asymmetric Decryption
SSH KDF (SHA-512/224, SHA-512/256, SHA-3, SHAKE128, SHAKE256) TLS 1.2 KDF (SHA-1, SHA-224, SHA-512/224, SHA-512/256, SHA-3) TLS 1.2 KDF using master secret non-compliant with RFC 7627 TLS 1.3 KDF (SHA-1, SHA-224, SHA-512, SHA-512/224, SHA-512/256, SHA-3)Key Derivation
NameTypeDescriptionSF CapabilitiesAlgorithms
KAS-ECC-SSCKASSP 800-56Arev3. KAS-ECC- SSC per IG D.F scenario 2(1)Ephemeral Unified scheme Curves: P-224, P-256, P-384, P-521 elliptic curves with 112-256 bits of key strengthKAS-ECC-SSC: #A4317, #A4326, #A4330, #A4344, #A4345, #A4346
KAS-FFC-SSCSP 800-56Arev3. KAS-FFC- SSC per IG D.F scenario 2(1)Ephemeral Unified scheme Keys: 2048, 3072, 4096, 6144, 8192-bit keys with 112-200 bits of key strengthKAS-FFC-SSC: #A4325
AES-CCMKTSSP 800-38C and SP 800- 38F. KTS (Key wrapping and unwrapping) per IG D.G128, 192, 256 bits with 128-256 bits of key strengthAES: #A4313, #A4314, #A4315, #A4327, #A4328, #A4329
AES-GCMSP 800-38D and SP 800- 38F. KTS (Key wrapping and unwrapping) per IG D.G, Additional Comment 8128, 192, 256 bits with 128-256 bits of key strengthAES: #A4316, #A4321, #A4322, #A4323, #A4335, #A4336, #A4337, #A4338, #A4339, #A4340, #A4341, #A4342, #A4343
AES-KW AES-KWPSP 800-38F. KTS (Key wrapping and unwrapping) per IG D.G128, 192, 256 bits with 128-256 bits of key strengthAES: #A4313, #A4314, #A4315, #A4327, #A4328, #A4329

Table 8 - Non-Approved, Not Allowed Algorithms

2.6 Security Function Implementations

D.G Table 9 - Security Function Implementation

2.7 Algorithm Specific Information

The Crypto Officer shall consider the following requirements and restrictions when using the module. For TLS 1.2, the module offers the AES GCM implementation and uses the context of Scenario 1 of FIPS 140-3 IG C.H. The module is compliant with SP 800-52r2 Section 3.3.1 and the mechanism for IV generation is compliant with RFC 5288 and 8446. The module does not implement the TLS protocol. The module’s implementation of AES GCM is used together with an application that runs outside the module’s cryptographic boundary. The design of the TLS protocol implicitly ensures that the counter (the nonce_explicit part of the IV) does not exhaust the maximum number of possible values for a given session key. In the event the module’s power is lost and restored, the consuming application must ensure that a new key for use with the AES GCM key encryption or decryption under this scenario shall be established. Oracle Linux 9 OpenSSL FIPS Provider Security Policy

Page 19

Alternatively, the Crypto Officer can use the module’s API to perform AES GCM encryption using internal IV generation. These IVs are always 96 bits and generated using the approved DRBG internal to the module’s boundary, compliant with Scenario 2 of FIPS 140-3 IG C.H. The module also provides a non-approved AES GCM encryption service which accepts arbitrary external IVs from the operator. This service can be requested by invoking the EVP_EncryptInit_ex2 API function with a non-NULL iv value. When this is the case, the API will set a non-approved service indicator. Finally, for TLS 1.3, the AES GCM implementation uses the context of Scenario 5 of FIPS 140-3 IG C.H. The protocol that provides this compliance is TLS 1.3, defined in RFC8446 of August 2018, using the cipher-suites that explicitly select AES GCM as the encryption/decryption cipher (Appendix B.4 of RFC8446). The module supports acceptable AES GCM cipher suites from Section

3.3.1 of SP800-52r2. The module’s implementation of AES GCM is used together with an application that runs outside the

module’s cryptographic boundary. The design of the TLS protocol implicitly ensures that the counter (the nonce_explicit part of the IV) does not exhaust the maximum number of possible values for a given session key.

2.7.2 Key Derivation using SP 800-132 PBKDF2

The module provides password-based key derivation (PBKDF2), compliant with SP 800-132. The module supports option 1a from Section 5.4 of SP 800-132, in which the Master Key (MK) or a segment of it is used directly as the Data Protection Key (DPK). In accordance with SP 800-132 and FIPS 140-3 IG D.N, the following requirements shall be met:

2.7.3 AES XTS

The length of a single data unit encrypted or decrypted with AES XTS shall not exceed 220 AES blocks, that is 16MB, of data per XTS instance. An XTS instance is defined in Section 4 of SP 800-38E. The XTS mode shall only be used for the cryptographic protection of data on storage devices. It shall not be used for other purposes, such as the encryption of data in transit. To meet the requirement stated in IG C.I, the module implements a check to ensure that the two AES keys used in AES XTS mode are not identical.

2.7.4 SP 800-56Ar3 Assurances

The module offers DH and ECDH shared secret computation services compliant to the SP 800-56Ar3 and meeting IG D.F scenario

2 path (1). To meet the required assurances listed in section 5.6 of SP 800-56Ar3, the module shall be used together with an

application that implements the “TLS protocol” and the following steps shall be performed.

Page 20
NameTypeOperational EnvironmentSample SizeEntropy Per SampleConditioning Component
Oracle OpenSSL CPU Time Jitter RNG Entropy Source (Cert. #E90)Non-physicalSee Table 264 bitsFull entropyLinear-Feedback Shift Register (LFSR); HMAC-SHA-512 DRBG (AVP cert A3862, A4162); AES-256 CTR DRBG (CAVP cert A4311)
NameTypeProperties
Safe primes key pair generationCKGKey type: DH key pair Groups: MODP-2048, MODP-3072, MODP-4096, MODP-6144, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192 Security strength: 112-200 bits Method: SP 800-56Ar3 (safe primes) Section 5.6.1.1.4 Testing Candidates Compliant to FIPS 140-3 IG D.H, SP 800-133r2, Section 4, 5.2
ECDSA key pair generationKey type: EC key pair Curves: P-224, P-256, P-384, P-521 Security strength: 112-256 bits Method: FIPS 186-4 Appendix B.4.2 Testing Candidates Compliant to FIPS 140-3 IG D.H, SP 800-133r2, Section 4, 5.1
RSA key pair generationKey type: RSA key pair Modulus: 2048-15360 bits Security strength: 112-256 bits Method: FIPS 186-4 Appendix B.3.6 Probable Primes with Conditions Based on Auxiliary Probable Primes Compliant to FIPS 140-3 IG D.H, SP 800-133r2, Section 4, 5.1
KBKDF key derivationKey DerivationKey type: Symmetric key
2.7.5 Legacy Algorithms

The module provides the following legacy uses as defined in SP 800-131rev2: • RSA Signature Verification, under FIPS 186-4, allows verifying signatures with a bit size of 1024, along with the approved Entropy Information: RNG Information: The module employs two Deterministic Random Bit Generator (DRBG) implementations based on SP 800-90Ar1. These DRBGs are used internally by the module (e.g. to generate seeds for asymmetric key pairs and random numbers for security functions). They can also be accessed using the specified API functions. The following parameters are used:

  1. Private DRBG: AES-256 CTR_DRBG with derivation function. This DRBG is used to generate secret random values (e.g. during asymmetric key pair generation). It can be accessed using RAND_priv_bytes.
  2. Public DRBG: AES-256 CTR_DRBG with derivation function. This DRBG is used to generate general purpose random values that do not need to remain secret (e.g. initialization vectors). It can be accessed using RAND_bytes. For seeding, the DRBG that is seeded with 384 bits of seed material, corresponding to 384 bits of entropy, obtained from the SP800-90B compliant entropy source above in Table
  3. During reseeding, the DRBG obtains 256 bits of seed material, corresponding to 256 bits of entropy. These DRBGs will always employ prediction resistance. More information regarding the configuration and design of these DRBGs can be found in the module’s manual pages. Oracle Linux 9 OpenSSL FIPS Provider Security Policy
Page 21
Security strength: 112-256 bits Method: Counter and feedback mode, using CMAC and HMAC SHA-1, SHA-224, SHA- 256, SHA-384, SHA-512, SHA-512/224, SHA-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512 Compliant to SP 800-108r1
KDA OneStepKey type: Symmetric key Security strength: 112-256 bits Method: (HMAC) SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, SHA-512/224, SHA- 512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512 Compliant to SP 800-56Cr2
HKDFKey type: Symmetric key Security strength: 112-256 bits Method: (HMAC) SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, SHA-512/224, SHA- 512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512 Compliant to SP 800-56Cr1
ANS X9.42 KDF (CVL)Key type: Symmetric key Security strength: 112-256 bits Method: AES KW with SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, SHA-512/224, SHA-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512 Compliant to SP 800-135r1
ANS X9.63 KDF (CVL)Key type: Symmetric key Security strength: 112-256 bits Method: SHA-224, SHA-256, SHA-384, SHA-512, SHA-512/224, SHA-512/256, SHA3- 224, SHA3-256, SHA3-384, SHA3-512 Compliant to SP 800-135r1
SSH KDF (CVL)Key type: Symmetric key Security strength: 112-256 bits Method: AES-128, AES-192, AES-256 with SHA-1, SHA-224, SHA-256, SHA-384, SHA- 512 Compliant to SP 800-135r1
TLS 1.2 KDF (RFC 7627) (CVL)Key type: Symmetric key Security strength: 112-256 bits Method: SHA-256, SHA-384, SHA-512 Compliant to SP 800-135r1
TLS 1.3 KDF (CVL)Key type: Symmetric key Security strength: 112-256 bits Method: SHA-256, SHA-384 Compliant to SP 800-135r1
PBKDF2Key type: Symmetric key Security strength: 112-256 bits Method: Option 1a with SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, SHA-512/224, SHA-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512 Compliant to option 1a of SP 800-132

Table 11 - Key Generation Oracle Linux 9 OpenSSL FIPS Provider Security Policy

Page 22
NameTypeProperties
KAS-FFC-SSC [SP800-56Arev3]KAS (Shared Secret Computation)Groups: ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192 Security strength: 112-200 bits Compliant with: Scenario 2 (1) of FIPS 140-3 IG D.F: Shared secret computation
KAS-ECC-SSC [SP800-56Arev3]Curves: P-224, P-256, P-384, P-521 Security strength: 112-256 bits Compliant with: Scenario 2 (1) of FIPS 140-3 IG D.F: Shared secret computation
AES CCM [SP 800-38C]KTS-Wrap (Key Wrapping, Key Unwrapping)Keys: 128, 192, or 256 bits Security strength: 128, 192, or 256 bits Compliant with IG D.G
AES GCM [SP 800-38D]KTS-Wrap (Key Wrapping)Keys: 128, 192, or 256 bits Security strength: 128, 192, or 256 bits IV generated internally Compliant with IG D.G Additional comment 8
KTS-Wrap (Key Unwrapping)Keys: 128, 192, or 256 bits Security strength: 128, 192, or 256 bits IV provided externally Compliant with IG D.G Additional comment 8
AES KW [SP 800-38F] AES KWP [SP 800-38F]KTS-Wrap (Key Wrapping, Key Unwrapping)Keys: 128, 192, or 256 bits Security strength: 128, 192, or 256 bits Compliant with IG D.G
2.10 Key Establishment
2.11 Industry Protocols

For DH, the module supports the use of the safe primes defined in RFC 3526 (IKE) and RFC 7919 (TLS) as listed in Table 12. Note that the module only implements key pair generation, key pair verification, and shared secret computation. SSH KDF, TLS 1.2 KDF (RFC 7627), TLS 1.3 KDF implementations shall only be used to generate secret keys in the context of the SSH, TLS 1.2, or TLS 1.3 protocols, respectively. Note that TLS 1.2 KDF must be compliant with RFC 7627 to be considered approved. ANS X9.42 KDF and ANS X9.63 KDF implementations shall only be used to generate secret keys in the context of an ANS X9.42-

2001 resp. ANS X9.63-2001 key agreement scheme.

No other part of the IKE, SSH or TLS protocols, other than the approved cryptographic algorithms and the KDFs listed above, have been tested by the CAVP and CMVP. Oracle Linux 9 OpenSSL FIPS Provider Security Policy

Page 23
Physical PortLogical InterfaceData That Passes Over the Port/Interface
As a software-only module, the module does not have physical ports. Physical Ports are interpreted to be the physical ports of the hardware platform on which it runs.Data InputAPI data input parameters
Data OutputAPI output parameters
Control InputAPI function calls, API control input parameters
Status OutputAPI return code, error queue
3 Cryptographic Module Interfaces
3.1 Description

Table 13 - Ports and Interfaces The logical interfaces are the APIs through which the applications request services. These logical interfaces are logically separated from each other by the API design.

3.2 Trusted Channel Specification

The module does not implement a trusted channel. Oracle Linux 9 OpenSSL FIPS Provider Security Policy

Page 24
NameTypeOperator TypeAuthentication Methods
Crypto OfficerRoleCON/A (Implicitly assumed)
NameDescriptionIndicatorInputsOutputsSecurity FunctionsRolesSSP Access
Message DigestCompute a message digestEVP_DigestFinal_ex returns 1MessageDigest valueSHA-1, SHA2-224, SHA2-256, SHA2- 384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3- 256, SHA3-384, SHA3-512CON/A
XOFCompute the output of an XOFEVP_DigestFinalXOF returns 1MessageDigest valueSHAKE128, SHAKE256N/A
EncryptionEncrypt a plaintextEVP_EncryptFinal_ex returns 1AES Key, plaintextCiphertextAES ECB, CBC, CBC-CTS-CS1, CBC-CTS-CS2, CBC-CTS-CS3, CFB1, CFB8, CFB128, CTR, OFB, XTSAES Key: W, E
DecryptionDecrypt a ciphertextEVP_DecryptFinal_ex returns 1AES Key, ciphertextPlaintext
Authenticated EncryptionEncrypt a plaintextAES GCM: EVP_CIPHER_*_FIPS_INDICA TOR_APPROVED Others: EVP_EncryptFinal_ex returns 1AES Key, plaintext, IV (for CCM and GCM only)Ciphertext, MAC tagAES CCM, GCM (internal IV)AES Key: W, E
Authenticated DecryptionDecrypt a ciphertextAES GCM: EVP_CIPHER_*_FIPS_INDICA TOR_APPROVED Others: EVP_DecryptFinal_ex returns 1AES Key, ciphertext, MAC tagPlaintext or failureAES CCM, GCM (external IV)
Message Authentication Code GenerationCompute a MAC tagHMAC: EVP_MAC_*_FIPS_INDICAT OR_APPROVED Others: EVP_MAC_final returns 1AES Key, messageMAC tagAES CMAC, AES GMACAES Key: W, E
HMAC Key, messageHMAC-SHA-1, HMAC-SHA2-224, HMAC-SHA2-256,HMAC Key: W, E

The module does not implement authentication. Table 14 - Roles The module supports the Crypto Officer role only. This sole role is implicitly and always assumed by the operator of the module. No support is provided for multiple concurrent operators.

4.3 Approved Services

Oracle Linux 9 OpenSSL FIPS Provider Security Policy

Page 25

Name Message Authentication Code Verification Shared Secret Computation Key Derivation Key-Based Key Derivation Password- Based Key Derivation Key Pair Generation

Description Verify a MAC tag Compute a Shared Secret Derive a key Derive a key from a key Derive a key from a password Generate a key pair

Indicator EVP_PKEY_derive returns 1 EVP_KDF_*_FIPS_INDICATO R_APPROVED EVP_PKEY_generate returns 1

Inputs AES Key, message, MAC tag HMAC Key, message, MAC tag DH Private Key, DH Public Key EC Private Key, EC Public Key TLS Pre- Master Secret TLS Master Secret Shared Secret Key- Derivation Key Password DH Group

Outputs Pass/fail Shared Secret TLS Master Secret TLS Derived Key Derived Key Module Generated DH Private Key, Module Generated

Security Functions HMAC-SHA2-384, HMAC-SHA2-512, HMAC-SHA2- 512/224, HMAC- SHA2-512/256, HMAC-SHA3-224, HMAC-SHA3-256, HMAC-SHA3-384, HMAC-SHA3-512 AES CMAC, AES GMAC HMAC-SHA-1, HMAC-SHA2-224, HMAC-SHA2-256, HMAC-SHA2-384, HMAC-SHA2-512, HMAC-SHA2- 512/224, HMAC- SHA2-512/256, HMAC-SHA3-224, HMAC-SHA3-256, HMAC-SHA3-384, HMAC-SHA3-512 KAS-FFC-SSC KAS-ECC-SSC TLS 1.2 KDF (RFC 7627) (CVL), TLS 1.3 KDF (CVL) TLS 1.2 KDF (RFC 7627) (CVL), TLS 1.3 KDF (CVL) KDA OneStep, KDA HKDF, KDF, ANS X9.42 KDF (CVL), ANS X9.63 KDF (CVL), SSH KDF (CVL) KBKDF PBKDF2 Safe Primes Key Generation CKG

Roles

SSP Access AES Key: W, E HMAC Key: W, E DH Private Key: W, E; DH Public Key: W, E; Shared Secret: G, R EC Private Key: W, E; EC Public Key: W, E; Shared Secret: G, R TLS Pre-Master Secret: G; TLS Master Secret: G TLS Master Secret: E; TLS Derived Key: G, R Shared Secret: W, E; KDA HKDF Derived key: G, R; KDA OneStep Derived key: G, R; SSH KDF Derived Key: G, R ANS X9.42 KDF Derived key: G, R; ANS X9.63 KDF Derived key: G, R; Key-Derivation Key: W, E; KBKDF Derived Key: G, R Password: W, E; PBKDF2 Derived Key: G, R Module Generated DH Private Key: G, R; Module Generated DH Public Key: G, R; Intermediate Key Generation Value: G, E, Z

R; Oracle Linux 9 OpenSSL FIPS Provider Security Policy

Page 26

Name Key Pair Verification Key Wrapping Key Unwrapping Random Number Generation Signature Verification Signature Generation

Description Verify a key pair. Safe primes key pair verification, ECDSA key pair verification Wrap a key Unwrap a key Generate random bytes Verify a digital signature Generate a digital signature

Indicator EVP_PKEY_public_check or EVP_PKEY_private_check or EVP_PKEY_check returns 1 EVP_EncryptFinal_ex returns 1 EVP_DecryptFinal_ex returns 1 EVP_RAND_generate returns 1 RSA: OSSL_*_FIPSINDICATOR_AP PROVED and EVP_SIGNATURE_*_FIPS_IN DICATOR_APPROVED ECDSA: OSSL_*_FIPSINDICATOR_AP PROVED

Inputs Curve Modulus DH Private Key, DH Public Key EC Private Key, EC Public Key AES Key, key to be wrapped AES Key, key to be unwrapped Output length Message, EC public key or RSA Public Key, signature, hash algorithm Message, EC Private Key or RSA Private Key, hash algorithm

Outputs DH Public Key Module Generated EC Private Key, Module Generated EC Public Key Module Generated RSA Private Key, Module Generated RSA Public Key Pass/fail Wrapped key Unwrappe d key Random bytes Pass/fail Signature

Security Functions ECDSA KeyGen CKG RSA KeyGen CKG Safe Prime KeyVer, ECDSA KeyVer AES CCM, GCM (internal IV), AES KW, AES KWP AES CCM, GCM (external IV), AES KW, AES KWP CTR_DRBG HMAC_DRBG Hash_DRBG RSA PKCS#1 v1.5 and PSS with SHA-224, SHA- 256, SHA-384, SHA-512, SHA- 512/224, SHA- 512/256 ECDSA (P-224, P- 256, P-384, P- 521) with SHA- 224, SHA-256, SHA-384, SHA- 512, SHA- 512/224, SHA- 512/256, SHA3- 224, SHA3-256, SHA3-384, SHA3-

Roles

SSP Access Module Generated EC Private Key: G, R; Module Generated EC Public Key: G, R; Intermediate Key Generation Value: G, E, Z Module Generated RSA Private Key: G, R; Module Generated RSA Public Key: G, R Intermediate Key Generation Value: G, E, Z DH Public Key: W, E; DH Private Key: W, E; EC Private Key: W, E; EC Public Key: W, E AES Key: W, E AES Key: W, E Entropy Input: W, E; DRBG Seed: E, G; Internal State (V, Key): E, G Entropy Input: W, E; DRBG Seed: E, G; Internal State (V, C): E, G RSA Public Key: W, E; ECDSA Public Key: W, E RSA Private Key: W, E; ECDSA Private Key: W, E

Oracle Linux 9 OpenSSL FIPS Provider Security Policy

Page 27

Name Show Version Show Status Self-Test Zeroization

Description Return the module name and version information Return the module status Perform the CASTs and integrity tests Zeroize all SSPs

Indicator None None None None

Inputs N/A N/A N/A Any SSP

Outputs Module name and version Module status Pass/fail N/A

Security Functions 512 N/A N/A SHA-1, SHA-512, SHA3-256, AES ECB, AES GCM, KBKDF, KDA OneStep, HKDF, ANS X9.42 KDF (CVL), ANS X9.63 KDF (CVL), SSH KDF (CVL), TLS 1.2 KDF (RFC 7627) (CVL), TLS 1.3 KDF (CVL), PBKDF2, CTR_DRBG, Hash_DRBG, HMAC_DRBG, KAS-FFC-SSC, KAS-ECC-SSC, RSA PKCS#1 v1.5, ECDSA See Table 23 for specifics N/A

Roles

SSP Access N/A N/A N/A All SSPs: Z

Table 15 - Approved Services Table 15 above lists the approved services. The following convention is used to specify access rights to SSPs:

Page 28
NameDescriptionSecurity FunctionsRole
EncryptionEncrypt a plaintextAES GCM with external IVCO
Message Authentication Code GenerationCompute a MAC tagHMAC with < 112-bit keys
Message Authentication Code VerificationVerify a MAC tag
Key DerivationDerive a keyKDA OneStep with < 112-bit keys HKDF with < 112-bit keys ANS X9.42 KDF with < 112-bit keys ANS X9.63 KDF with < 112-bit keys SSH KDF with < 112-bit keys TLS 1.2 KDF < 112-bit keys TLS 1.3 KDF < 112-bit keys KDA OneStep with SHAKE128, SHAKE256 ANS X9.42 KDF with SHAKE128, SHAKE256 ANS X9.63 KDF with SHA-1, SHAKE128, SHAKE256 SSH KDF with SHA-512/224, SHA-512/256, SHA-3, SHAKE128, SHAKE256 TLS 1.2 KDF using master secret non-compliant with RFC 7627 TLS 1.2 KDF with SHA-1, SHA-224, SHA-512/224, SHA- 512/256, SHA-3 TLS 1.3 KDF with SHA-1, SHA-224, SHA-512, SHA-512/224, SHA-512/256, SHA-3
Key-Based Key DerivationDerive a key from a derivation keyKBKDF with < 112-bit keys
Password-Based Key DerivationDerive a key from a passwordPBKDF2 with a short password; short salt; insufficient iterations; < 112-bit keys
Key Pair GenerationGenerate a key pairECDSA with curve P-192
Key Pair VerificationVerify a key
Shared Secret ComputationCompute a shared secretKAS1, KAS2
Signature GenerationGenerate a signatureECDSA signature generation with a pre-hashed message, ECDSA with curve P-192 RSA signature generation with a pre-hashed message
Signature VerificationVerify a signatureECDSA signature verification with a pre-hashed message, ECDSA with curve P-192 RSA signature verification with a pre-hashed message
Asymmetric EncryptionEncrypt a plaintextRSA-OAEP encryption
Asymmetric DecryptionDecrypt a plaintextRSA-OAEP decryption
4.4 Non-Approved Services

Table 16 - Non-Approved Services

4.5 External Software/Firmware Loaded

The module does not load external software or firmware.

4.6 Bypass Actions and Status

The module does not implement a bypass capability. Oracle Linux 9 OpenSSL FIPS Provider Security Policy

Page 29
4.7 Cryptographic Output Actions and Status

The module does not implement a self-initiated cryptographic output capability. Oracle Linux 9 OpenSSL FIPS Provider Security Policy

Page 30
5 Software/Firmware Security
5.1 Integrity Techniques

The integrity of the module is verified by comparing a HMAC SHA-256 value calculated at run time with the HMAC SHA-256 value embedded in the fips.so file that was computed at build time. If the integrity test fails, the module enters the error state.

5.2 Initiate on Demand

Integrity tests are performed as part of the pre-operational self-tests, which are executed when the module is initialized. The integrity test may be invoked on-demand by unloading and subsequently re-initializing the module, or by calling the OSSL_PROVIDER_self_test function. This will perform (among others) the software integrity test. Oracle Linux 9 OpenSSL FIPS Provider Security Policy

Page 31
6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operating Environment: modifiable: the module executes on a general purpose operating system (Oracle Linux 9), which allows modification, loading, and execution of software that is not part of the validated module. How Requirements are Satisfied: The operating system provides process isolation and memory protection mechanisms that ensure appropriate separation for memory access among the processes on the system. Each process has control over its own data and uncontrolled access to the data of other processes is prevented.

6.2 Configurable Settings and Restrictions

The module shall be installed as stated in Section 11.1. There are no concurrent operators. The module does not have the capability of loading software or firmware from an external source. Instrumentation tools like the ptrace system call, gdb and strace, userspace live patching, as well as other tracing mechanisms offered by the Linux environment such as ftrace or systemtap, shall not be used in the operational environment. The use of any of these tools implies that the cryptographic module is running in a non-validated operational environment. Oracle Linux 9 OpenSSL FIPS Provider Security Policy

Page 32
7 Physical Security

The module is comprised of software only and therefore this section is not applicable. Oracle Linux 9 OpenSSL FIPS Provider Security Policy

Page 33
8 Non-Invasive Security

This module does not implement any non-invasive security mechanism and therefore this section is not applicable. Oracle Linux 9 OpenSSL FIPS Provider Security Policy

Page 34
Storage Area NameDescriptionPersistence Type
RAMTemporary storage for SSPs used by the module as part of service execution. The module does not perform persistent storage of SSPs.Dynamic
NameFromToFormat TypeDistribution TypeEntry TypeRelated SFI
API input parametersOperator calling application (TOEPP)Cryptographic modulePlaintext (P)Manual (MD)Electronic (EE)N/A
API output parametersCryptographic moduleOperator calling application (TOEPP)
Zeroization MethodDescriptionRationaleOperator Initiation
Calling the zeroization APIZeroizes the SSPsMemory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable. All data output is inhibited during zeroization.By calling the appropriate zeroization functions: AES key: EVP_CIPHER_CTX_free, EVP_MAC_CTX_free HMAC key: EVP_MAC_CTX_free Key-derivation key: EVP_KDF_CTX_free Shared secret: EVP_KDF_CTX_free PBKDF Password: EVP_KDF_CTX_free Derived key: EVP_KDF_CTX_free Entropy input: EVP_RAND_CTX_free DRBG seed: EVP_RAND_CTX_free DRBG Internal state: EVP_RAND_CTX_free DH private key: EVP_PKEY_free DH public key: EVP_PKEY_free EC private key: EVP_PKEY_free EC public key: EVP_PKEY_free RSA private key: EVP_PKEY_free RSA public key: EVP_PKEY_free TLS pre-master secret: EVP_KDF_CTX_free TLS master secret: EVP_KDF_CTX_free TLS derived secret: EVP_KDF_CTX_free
AutomaticIntermediate key generation value: zeroized automatically by the module (after the requested service completed)
Remove power from the moduleDe-allocates the volatile memory used to store SSPsVolatile memory used by the module is overwritten within nanoseconds when power is removedBy removing power
9 Sensitive Security Parameters Management
9.1 Storage Areas

Table 17 - Storage Areas The module does not support entry and output of SSPs beyond the physical perimeter of the operational environment. The SSPs are provided to the module via API input parameters in the plaintext form and output via API output parameters in the plaintext form to and from the calling application running on the same operational environment. Table 19 - SSP Zeroization Methods Oracle Linux 9 OpenSSL FIPS Provider Security Policy

Page 35
NameDescriptionSizeStrengthTypeGenerated ByEstablished By
AES KeyAES key used for encryption, decryption, authenticated encryption, authenticated decryption, key wrapping, key unwrapping, and computing MAC tags128, 192, 256 bits128-256 bitsSymmetric keyN/AN/A
HMAC KeyHMAC key112-524288 bits112-256 bitsAuthentication keyN/AN/A
Shared SecretShared secret established by DH/ECDHECDH: 128-256 bits128-256 bitsShared secretN/AKAS-ECC-SSC
DH: 112-200 bits112-200 bitsKAS-FFC-SSC
Key-Derivation KeyKey-derivation key for KBKDF112-256 bits112-256 bitsKey-derivation keyN/AN/A
PasswordPBKDF2 passwordAt least 14 charactersN/APasswordN/AN/A
KBKDF Derived KeyKBKDF derived key112-4096 bits112-256 bitsDerived keyKBKDFN/A
PBKDF2 Derived keyPBKDF2 derived key112-4096 bitsPBKDF2
KDA OneStep Derived keyKDA OneStep derived key112-2048 bitsOneStep KDA
KDA HKDF Derived keyKDA HKDF derived key2048 bitsKDA HKDF
ANS X9.42 KDF Derived keyANS X9.42 KDF derived key112-4096 bitsANS X9.42 KDF (CVL)
ANS X9.63 KDF Derived keyANS X9.63 KDF derived key128-4096 bitsANS X9.63 KDF (CVL)
SSH KDF Derived keySSH KDF derived key112-1024 bitsSSH KDF (CVL)
Entropy InputEntropy input used to seed the DRBGs128-448 bits128-256 bitsEntropyEntropy Source (ESV cert. E90) See Table 10N/A
DRBG SeedDRBG seed derived from entropy input as defined in SP 800- 90Ar1CTR_DRBG: 128, 192, 256 bits Hash_DRBG: 128, 256 bits HMAC_DRBG: 128, 256 bits128-256 bitsSeedCTR_DRBG, Hash_DRBG, HMAC_DRBGN/A
DRBG Internal State (V, Key)Internal state of CTR_DRBG and HMAC_DRBGCTR_DRBG: 128, 192, 256 bits HMAC_DRBG: 128, 256 bits128-256 bitsDRBG Internal stateCTR_DRBG, HMAC_DRBG (derived from DRBG seed as defined in SP800-90Ar1)N/A
DRBG Internal State (V, C)Internal state ofHash_DRBG: 128, 256 bits128-256 bitsHash_DRBG (derived from DRBG seed asN/A
9.4 SSPs

Oracle Linux 9 OpenSSL FIPS Provider Security Policy

Page 36
NameDescription Hash_DRBGSizeStrengthTypeGenerated By defined in SP800- 90Ar1)Established By
DH Public KeyPublic key used for Shared Secret Computationffdhe2048, ffdhe3072, ffdhe4096,112-200 bitsPublic keyN/AKAS-FFC-SSC
DH Private KeyPrivate key used for Shared Secret Computationffdhe6144, 2048, MODP-3072,Private key
Module Generated DH Public KeyDH public key generated by the moduleMODP-4096, MODP-6144, MODP-8192Public keySafe primes (SP 800- 56Ar3 section 5.6.1.1.4 Testing Candidates) CTR_DRBG (for generation of random values per SP 800- 90Ar1)N/A
Module Generated DH Private KeyDH private key generated by the modulePrivate key
EC Private KeyPrivate key used for ECDSA signature generation and Shared Secret ComputationP-224, P-256, P- 384, P-521112, 128, 192, 256 bitsPrivate keyN/AKAS-ECC-SSC
EC Public KeyPublic key used for ECDSA signature verification and Shared Secret ComputationPublic key
Module Generated EC Private KeyEC private key generated by the modulePrivate keyECDSA (FIPS 186-4 Appendix B.4.2 Testing Candidates) CTR_DRBG (for generation of random values per SP 800- 90Ar1)N/A
Module Generated EC Public KeyEC public key generated by the modulePublic key
RSA Private KeyPrivate key used for RSA signature generation2048, 3072, 4096 bits112, 128, 150 bitsPrivate keyN/AN/A
RSA Public KeyPublic key used for RSA signature verification1024, 2048, 3072, 4096 bits80, 112, 128, 150 bitsPublic keyN/AN/A
Module Generated RSA Private KeyRSA private key generated by the module2048, 3072, 4096 bits112, 128, 150 bitsPrivate keyRSA (FIPS 186-4 Appendix B.3.6 Probable Primes with Conditions Based on Auxiliary Probable Primes) CTR_DRBG (random values generation per 800-90Ar1)N/A
Module Generated RSA Public KeyRSA public key generated by the modulePublic keyN/A
Intermediate Key Generation ValueIntermediate key generation value224-4096 bits112-256 bitsIntermediate key generation valueCKGN/A

Oracle Linux 9 OpenSSL FIPS Provider Security Policy

Page 37
NameDescriptionSizeStrengthTypeGenerated ByEstablished By
TLS Pre-Master SecretTLS pre-master secret used for deriving the TLS master secret112-256 bits112-256 bitsTLS pre-master secretN/AKAS-FFC-SSC, KAS-ECC-SSC
TLS Master SecretTLS master secret used for deriving the TLS derived secret112-256 bits112-256 bitsTLS master secretTLS 1.2 KDF (RFC 7627) (CVL), TLS 1.3 KDF (CVL)N/A
TLS Derived KeyTLS derived key, derived from TLS master secret112-256 bits112-256 bitsShared secretN/A
NameUsed ByInputs/OutputsStorageStorage DurationZeroizationTypeRelated SSPs
AES KeyEncryption, Decryption, Authenticated Encryption, Authenticated Decryption, Key Wrapping, Key Unwrapping Message Authentication Code Generation, Message Authentication Code VerificationAPI input parameters (input)RAMFor the duration of the serviceFree Cipher Handle, Module ResetCSPNone
HMAC KeyMessage Authentication Code Generation, Message Authentication Code Verification
Shared SecretKey DerivationAPI output parameters (output)DH Public Key, DH Private Key, EC Public Key, EC Private Key, KDA OneStep Derived key, KDA HKDF Derived key, ANS X9.63 KDF Derived key, SSH KDF Derived key
Key-Derivation KeyKey-Based Key DerivationAPI input parameters (input)For the duration of the serviceKBKDF Derived Key
PasswordPassword-Based Key DerivationAPI input parameters (input)PBKDF2 Derived Key
KBKDF Derived KeyKey-based Key DerivationAPI output parameters (output)Key-derivation Key
PBKDF2 DerivedPassword-basedPassword

Table 20 - SSP Information First Oracle Linux 9 OpenSSL FIPS Provider Security Policy

Page 38

Name key KDA OneStep Derived key KDA HKDF Derived key ANS X9.42 KDF Derived key ANS X9.63 KDF Derived key SSH KDF Derived key Entropy Input DRBG Seed DRBG Internal State (V, Key) DRBG Internal State (V, C) DH Public Key DH Private Key Module Generated DH Public Key Module Generated DH Private Key EC Public Key EC Private Key Module Generated EC Public Key

Used By Key Derivation Key Derivation Random Number Generation Shared Secret Computation, Key Pair Verification Shared Secret Computation Shared Secret Computation, Signature Verification, Key Pair Verification Shared Secret Computation, Signature Generation, Key Pair Verification Shared Secret Computation

Inputs/Outputs N/A N/A N/A N/A API input parameters (input) API output parameters (output) API input parameters (input) API output parameters (output)

Storage

Storage Duration From generation until DRBG seed is created While the DRBG is being instantiated From DRBG instantiation until DRBG termination For the duration of the service

Zeroization

Type CSP (Compliant with IG D.L) PSP CSP PSP CSP PSP CSP PSP

Related SSPs Shared secret Shared secret Shared secret Shared secret Shared secret DRBG Seed Entropy Input DRBG Internal State (V, C) DRBG Internal State (V, Key) DRBG Seed DRBG Seed DH Private Key Shared Secret DH Public Key Shared Secret Module Generated DH Private Key Intermediate key generation value Module Generated DH Public Key Intermediate key generation value EC Private Key Shared Secret EC Public Key Shared Secret Module Generated EC Private Key Intermediate key generation value

Oracle Linux 9 OpenSSL FIPS Provider Security Policy

Page 39

Name Module Generated EC Private Key RSA Private Key RSA Public Key Module Generated RSA Private Key Module Generated RSA Public Key Intermediate Key Generation Value TLS Pre-Master Secret TLS Master Secret TLS Derived Key

Used By Digital Signature Generation Digital Signature Verification N/A Key Pair Generation Key Derivation

Inputs/Outputs API input parameters (input) API output parameters (output) N/A N/A N/A API output parameters (output)

Storage

Storage Duration

Zeroization Automatically Free Cipher Handle, Module Reset

Type CSP CSP PSP CSP PSP CSP CSP CSP CSP

Related SSPs Module Generated EC Public Key Intermediate key generation value RSA Public Key RSA Private Key Module Generated RSA Public Key Intermediate key generation value Module Generated RSA Private Key Intermediate key generation value Module Generated RSA Public Key, Module Generated RSA Private Key, Module Generated DH Public Key, Module Generated DH Private Key, Module Generated EC Public Key, Module Generated EC Private Key TLS Master Secret DH Public Key DH Private Key EC Public Key EC Private Key TLS Pre-Master Secret TLS Derived Secret TLS Master Secret

Table 21 - SSP Information Second

9.5 Transitions

The SHA-1 algorithm as implemented by the module will be non-approved for all purposes, starting January 1, 2030. Oracle Linux 9 OpenSSL FIPS Provider Security Policy

Page 40

The RSA, ECDSA algorithm as implemented by the module conforms to FIPS 186-4, which has been superseded by FIPS 186-5. FIPS 186-4 will be withdrawn on February 3, 2024. Oracle Linux 9 OpenSSL FIPS Provider Security Policy

Page 41
AlgorithmImplementationTest PropertiesTest MethodTest TypeIndicatorDetails
HMAC-SHA2-256SHA_CE, SHA_ASM, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3, NEON256-bit keyMessage AuthenticationSoftware integrityModule becomes operationalIntegrity test for fips.so
AlgorithmImplementationTest PropertiesTest MethodTypeIndicatorDetailsConditions
ECDSASHA_ASM, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3, SHA_ASM, SHA_CESHA2-256PCTPair-Wise Consistency TestSuccessful key generationSignature generation and verificationEC key pair generation
RSASHA_ASM, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3, SHA_ASM, SHA_CEPKCS#1 v1.5 with SHA2-256RSA key pair generation
Safe PrimesCN/APublic key re- computation and comparison with the existing public key (per SP 800-56Ar3 Section 5.6.2.1.4)Safe Primes key pair generation
SHA-1, SHA2-512SHA_CE, SHA_ASM, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE324-bit messageKATCASTModule is operationalMessage DigestModule initialization
SHA3-256SHA3_ASM, SHA3_CE32-bit message
AES-ECBSSH_ASM, AESNI, BAES_CTASM, AESASM, SSH_SHANI, SSH_AVX2, SSH_AVX, SSH_SSSE3, CE, VPAES, AES_C128-bit keys, 128-bit ciphertextDecryption
10 Self-Tests
10.1 Pre-Operational Self-Tests

Table 22 - Pre-Operational Self-Tests The pre-operational software integrity test is performed automatically (after the CASTs) when the module is powered on before before the software integrity test is performed. While the module is executing the self-tests, services are not available, and data output (via the data output interface) is inhibited until the tests are successfully completed. The module transitions to the operational state only after the pre-operational self-test has passed successfully. If the pre-operational self-test fails, the module transitions to the error state.

10.2 Conditional Self-Tests

5.6.2.1.4) Oracle Linux 9 OpenSSL FIPS Provider Security Policy

Page 42

Algorithm AES-GCM KBKDF KDA OneStep HKDF ANS X9.42 KDF (CVL) ANS X9.63 KDF (CVL) SSH KDF (CVL) TLS 1.2 KDF (CVL) TLS 1.3 KDF (CVL) PBKDF2 CTR_DRBG

Implementation AESNI_AVX, AESNI_CLMULNI, AESNI_ASM, BAES_CTASM_AVX, BAES_CTASM_CLMULNI, BAES_CTASM_ASM, AESASM_AVX, AESASM_CLMULNI, AESASM_ASM, CE_GCM_UNROLL8_EOR3, CE_GCM, VPAES_GCM, AES_C_GCM KBKDF KDA TLS v1.3 SHA_ASM, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3, SHA_CE SHA3_ASM, SHA_CE, SHA3_CE, SHA_ASM, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3, SHA_CE SSH_ASM, SSH_SHANI, SSH_AVX2, SSH_AVX, SSH_SSSE3 SHA_CE, SHA_ASM, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3, SHA_CE TLS v1.3 SHA_CE, SHA_ASM, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3, SHA_CE DRBG_3

Test Properties 256-bit keys, 96- bit IVs, 128-bit plaintext, 128- bit additional data Counter mode, HMAC-SHA2- 256, 128-bit input key SHA-224, 392-bit input secret SHA-256, 48-bit input secret SHA-1 with AES- 128, KW, 160-bit input secret SHA-256, 192-bit input secret SHA-1, 1056-bit input secret SHA-256, 84-bit input secret Extract and expand modes, SHA-256 SHA-256, 24- character password, 288- bit salt, Iteration count: 4096 AES-128 with prediction resistance and derivation function

Test Method

Type

Indicator

Details Encryption Decryption Key Derivation Instantiate, Generate, Reseed, Generate (compliant

Conditions

Oracle Linux 9 OpenSSL FIPS Provider Security Policy

Page 43

Algorithm Hash_DRBG HMAC_DRBG KAS-FFC-SSC KAS-ECC-SSC RSA ECDSA

Implementation DRBG_3 DRBG_3 C C SHA_ASM, SHA_SHANI, SHA_AVX2, SHA_SSSE3, SHA_CE, NEON SHA_ASM, SHA_SHANI, SHA_AVX2, SHA_AVX, SHA_SSSE3, SHA_CE

Test Properties SHA-256 with prediction resistance SHA-1 with prediction resistance ffdhe2048 P-256 PKCS#1 v1.5 with SHA-256 and 2048-bit key SHA-256 and P- 224, P-256, P- 384, and P-521

Test Method

Type

Indicator

Details with SP 800- 90Ar1 Section 11.3) Shared Secret Computation Signature Generation Signature Verification Signature Generation Signature Verification

Conditions

NameDescriptionConditionsRecovery MethodIndicator
Error StateThe module immediately stops functioning due to a self-test failureSoftware integrity test failure CAST failure PCT failureRestart of the moduleModule will not load Module stops functioning

Table 23 - Conditional Self-Tests

10.2.1 Conditional Cryptographic Algorithm Tests

The module performs self-tests on all approved cryptographic algorithms as part of the approved services supported in the approved mode of operation, using the tests shown in Table 23. Services are not available, and data output (via the data output interface) is inhibited during the self-tests. If any of these tests fails, the module transitions to the error state.

10.2.2 Conditional Cryptographic Algorithm Tests

Upon generation of a DH, EC or RSA key pair, the module will perform a pair-wise consistency test (PCT) as shown in Table 23, which provides some assurance that the generated key pair is well formed. The test for DH consists of the PCT described in Section 5.6.2.1.4 of SP 800-56Ar3. For EC or RSA key pairs, the tests consist of performing signature generation and verification using the generated key pairs. Services are not available, and data output (via the data output interface) is inhibited during

10.3 Periodic Self-Tests

The module does not implement any periodic self-tests.

10.4 Error States

Table 24 - Error States In the error state, the output interface is inhibited, and the module accepts no more inputs or requests (as the module is no longer running). Oracle Linux 9 OpenSSL FIPS Provider Security Policy

Page 44
10.5 Operator Initiation

The software integrity tests and CASTs can be invoked on demand by unloading and subsequently re-initializing the module. Additionally, the integrity test may be invoked on-demand by calling the OSSL_PROVIDER_self_test function. The PCTs can be invoked on demand by requesting the Key Pair Generation service. Oracle Linux 9 OpenSSL FIPS Provider Security Policy

Page 45
11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

The module is distributed as a part of the Oracle Linux 9 (OL9) RPM package in the form of openssl-libs-3.0.7-24.0.3.el9_fips RPM package that is located in the “Oracle Linux 9 Security Validation (Update 3)” yum repository (ol9_u3_security_validation). Also, the module can be distributed using the openssl-fips-provider-3.0.7-6.0.1.el9_5 RPM package. The module can achieve the approved mode by:

11.2 Administrator Guidance

The Approved and Non-Approved modes of operation are specified in Section 2.4. The administrative functions are specified in the Approved Services table. All the logical interfaces are specified in Section 3.1.

11.3 Non-Administrator Guidance

The approved and non-approved security functions available to users are listed in Section 2. The physical ports and logical interfaces available to users are specified in Section 3.1. The approved and non-approved modes of operation are specified in Section 2.4. All the algorithm-specific information is listed in Section 2.7.

11.4 Maintenance Requirements

There are no maintenance requirements.

11.5 End of Life

As the module does not persistently store SSPs, secure sanitization of the module consists of unloading the module. This will zeroize all SSPs in volatile memory. Then, if desired, the openssl-libs-3.0.7-24.0.3.el9_fips RPM package can be uninstalled from the Oracle Linux 9 system. Oracle Linux 9 OpenSSL FIPS Provider Security Policy

Page 46
12 Mitigation of Other Attacks

Certain cryptographic subroutines and algorithms are vulnerable to timing analysis. The module mitigates this vulnerability by using constant-time implementations. This includes, but is not limited to:

Page 47
AESAdvanced Encryption Standard
AES-NIAdvanced Encryption Standard New Instructions
APIApplication Programming Interface
CASTCryptographic Algorithm Self-Test
CAVPCryptographic Algorithm Validation Program
CBCCipher Block Chaining
CCMCounter with Cipher Block Chaining-Message Authentication Code
CFBCipher Feedback
CMACCipher-based Message Authentication Code
CMVPCryptographic Module Validation Program
CSPCritical Security Parameter
CTRCounter
CTSCiphertext Stealing
DHDiffie-Hellman
DRBGDeterministic Random Bit Generator
ECBElectronic Code Book
ECCElliptic Curve Cryptography
ECDHElliptic Curve Diffie-Hellman
ECDSAElliptic Curve Digital Signature Algorithm
ENT (NP)Non-physical Entropy Source
FFCFinite Field Cryptography
FIPSFederal Information Processing Standards
GCMGalois Counter Mode
GMACGalois Counter Mode Message Authentication Code
HKDFHMAC-based Key Derivation Function
HMACKeyed-Hash Message Authentication Code
KATKnown Answer Test
KBKDFKey-based Key Derivation Function
MACMessage Authentication Code
NISTNational Institute of Science and Technology
PAAProcessor Algorithm Acceleration
PBKDF2Password-based Key Derivation Function v2
PKCSPublic-Key Cryptography Standards
RSARivest, Shamir, Adleman
SHASecure Hash Algorithm
SSCShared Secret Computation
SSPSensitive Security Parameter
TOEPPTested Operational Environment’s Physical Perimeter
XTSXEX-based Tweaked-codebook mode with cipher text Stealing

Glossary and Abbreviations Oracle Linux 9 OpenSSL FIPS Provider Security Policy

Page 48
ANS X9.42-2001Public Key Cryptography for the Financial Services Industry: Agreement of Symmetric Keys Using Discrete Logarithm Cryptography 2001 https://webstore.ansi.org/standards/ascx9/ansix9422001
ANS X9.63-2001Public Key Cryptography for the Financial Services Industry, Key Agreement and Key Transport Using Elliptic Curve Cryptography 2001 https://webstore.ansi.org/standards/ascx9/ansix9632001
FIPS 140-3FIPS PUB 140-3 - Security Requirements For Cryptographic Modules March 2019 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-3.pdf
FIPS 140-3 IGImplementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program https://csrc.nist.gov/Projects/cryptographic-module-validation-program/fips-140-3-ig-announcements
FIPS 180-4Secure Hash Standard (SHS) March 2012 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf
FIPS 186-4Digital Signature Standard (DSS) July 2013 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-4.pdf
FIPS 186-5Digital Signature Standard (DSS) February 2023 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-5.pdf
FIPS 197Advanced Encryption Standard November 2001 https://csrc.nist.gov/publications/fips/fips197/fips-197.pdf
FIPS 198-1The Keyed Hash Message Authentication Code (HMAC) July 2008 https://csrc.nist.gov/publications/fips/fips198-1/FIPS-198-1_final.pdf
FIPS 202SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions August 2015 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.202.pdf
PKCS#1Public Key Cryptography Standards (PKCS) #1: RSA Cryptography Specifications Version 2.1 February 2003 https://www.ietf.org/rfc/rfc3447.txt
RFC 3526More Modular Exponential (MODP) Diffie-Hellman groups for Internet Key Exchange (IKE) May 2003 https://www.ietf.org/rfc/rfc3526.txt
RFC 5288AES Galois Counter Mode (GCM) Cipher Suites for TLS August 2008 https://www.ietf.org/rfc/rfc5288.txt
RFC 7919Negotiated Finite Field Diffie-Hellman Ephemeral Parameters for Transport Layer Security (TLS) August 2016 https://www.ietf.org/rfc/rfc7919.txt
RFC 8446The Transport Layer Security (TLS) Protocol Version 1.3 August 2018 https://www.ietf.org/rfc/rfc8446.txt
SP 800-38ARecommendation for Block Cipher Modes of Operation Methods and Techniques December 2001 https://csrc.nist.gov/publications/nistpubs/800-38a/sp800-38a.pdf
SP 800-38A AddendumRecommendation for Block Cipher Modes of Operation: Three Variants of Ciphertext Stealing for CBC Mode October 2010 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38a-add.pdf
SP 800-38BRecommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication May 2005 https://csrc.nist.gov/publications/nistpubs/800-38B/SP_800-38B.pdf
SP 800-38CRecommendation for Block Cipher Modes of Operation: the CCM Mode for Authentication and Confidentiality

References Oracle Linux 9 OpenSSL FIPS Provider Security Policy

Page 49
May 2004 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38c.pdf
SP 800-38DRecommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC November 2007 https://csrc.nist.gov/publications/nistpubs/800-38D/SP-800-38D.pdf
SP 800-38ERecommendation for Block Cipher Modes of Operation: The XTS AES Mode for Confidentiality on Storage Devices January 2010 https://csrc.nist.gov/publications/nistpubs/800-38E/nist-sp-800-38E.pdf
SP 800-38FRecommendation for Block Cipher Modes of Operation: Methods for Key Wrapping December 2012 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38F.pdf
SP 800-52r2Guidelines for the Selection, Configuration, and Use of Transport Layer Security (TLS) Implementations August 2019 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-52r2.pdf
SP 800-56Ar3Recommendation for Pair-Wise Key Establishment Schemes Using Discrete Logarithm Cryptography April 2018 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Ar3.pdf
SP 800-56Cr1Recommendation for Key-Derivation Methods in Key-Establishment Schemes August 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Cr1.pdf
SP 800-56Cr2Recommendation for Key-Derivation Methods in Key-Establishment Schemes August 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Cr2.pdf
SP 800-90Ar1Recommendation for Random Number Generation Using Deterministic Random Bit Generators June 2015 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90Ar1.pdf
SP 800-90BRecommendation for the Entropy Sources Used for Random Bit Generation January 2018 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90B.pdf
SP 800-108r1NIST Special Publication 800-108 - Recommendation for Key Derivation Using Pseudorandom Functions August 2022 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-108r1.pdf
SP 800-131Ar2Transitioning the Use of Cryptographic Algorithms and Key Lengths March 2019 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar2.pdf
SP 800-132Recommendation for Password-Based Key Derivation - Part 1: Storage Applications December 2010 https://csrc.nist.gov/publications/nistpubs/800-132/nist-sp800-132.pdf
SP 800-133r2Recommendation for Cryptographic Key Generation June 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-133r2.pdf
SP 800-135r1Recommendation for Existing Application-Specific Key Derivation Functions December 2011 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-135r1.pdf
SP 800-140BCMVP Security Policy Requirements March 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-140B.pdf

Oracle Linux 9 OpenSSL FIPS Provider Security Policy