All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Canonical Ltd. Ubuntu 22.04 OpenSSL Cryptographic Module

Certificate#4794StandardFIPS 140-3Level1TypeSoftwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorCanonical Ltd.
High review priority  ·  no TCB surface named  ·  OpenSSL upstream has published 40 CVEs since this module's initial validation  ·  last validated 22 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date9/10/2029
CaveatInterim validation; When operated in approved mode; When installed, initialized and configured as specified in Section 11 of the Security Policy
VendorCanonical Ltd.

Approved Algorithms (518)

AlgorithmACVP Cert
AES-CBCA3958
AES-CBCA3958
AES-CBCA3959
AES-CBCA3959
AES-CBCA3960
AES-CBCA3960
AES-CBCA3973
AES-CBCA3973
AES-CBCA3980
AES-CBCA3980
AES-CBCA3981
AES-CBCA3981
AES-CBCA3982
AES-CBCA3982
AES-CBC-CS1A3958
AES-CBC-CS1A3958
AES-CBC-CS1A3959
AES-CBC-CS1A3959
AES-CBC-CS1A3960
AES-CBC-CS1A3960
AES-CBC-CS1A3973
AES-CBC-CS1A3973
AES-CBC-CS1A3980
AES-CBC-CS1A3980
AES-CBC-CS1A3981
AES-CBC-CS1A3981
AES-CBC-CS1A3982
AES-CBC-CS1A3982
AES-CBC-CS2A3958
AES-CBC-CS2A3958
AES-CBC-CS2A3959
AES-CBC-CS2A3959
AES-CBC-CS2A3960
AES-CBC-CS2A3960
AES-CBC-CS2A3973
AES-CBC-CS2A3973
AES-CBC-CS2A3980
AES-CBC-CS2A3980
AES-CBC-CS2A3981
AES-CBC-CS2A3981
AES-CBC-CS2A3982
AES-CBC-CS2A3982
AES-CBC-CS3A3958
AES-CBC-CS3A3958
AES-CBC-CS3A3959
AES-CBC-CS3A3959
AES-CBC-CS3A3960
AES-CBC-CS3A3960
AES-CBC-CS3A3973
AES-CBC-CS3A3973
AES-CBC-CS3A3980
AES-CBC-CS3A3980
AES-CBC-CS3A3981
AES-CBC-CS3A3981
AES-CBC-CS3A3982
AES-CBC-CS3A3982
AES-CCMA3958
AES-CCMA3958
AES-CCMA3959
AES-CCMA3959
AES-CCMA3960
AES-CCMA3960
AES-CCMA3973
AES-CCMA3973
AES-CCMA3980
AES-CCMA3980
AES-CCMA3981
AES-CCMA3981
AES-CCMA3982
AES-CCMA3982
AES-CFB1A3958
AES-CFB1A3958
AES-CFB1A3959
AES-CFB1A3959
AES-CFB1A3960
AES-CFB1A3960
AES-CFB1A3973
AES-CFB1A3973
AES-CFB1A3980
AES-CFB1A3980
AES-CFB1A3981
AES-CFB1A3981
AES-CFB1A3982
AES-CFB1A3982
AES-CFB128A3958
AES-CFB128A3958
AES-CFB128A3959
AES-CFB128A3959
AES-CFB128A3960
AES-CFB128A3960
AES-CFB128A3973
AES-CFB128A3973
AES-CFB128A3980
AES-CFB128A3980
AES-CFB128A3981
AES-CFB128A3981
AES-CFB128A3982
AES-CFB128A3982
AES-CFB8A3958
AES-CFB8A3958
AES-CFB8A3959
AES-CFB8A3959
AES-CFB8A3960
AES-CFB8A3960
AES-CFB8A3973
AES-CFB8A3973
AES-CFB8A3980
AES-CFB8A3980
AES-CFB8A3981
AES-CFB8A3981
AES-CFB8A3982
AES-CFB8A3982
AES-CMACA3958
AES-CMACA3959
AES-CMACA3960
AES-CMACA3973
AES-CMACA3980
AES-CMACA3981
AES-CMACA3982
AES-CTRA3958
AES-CTRA3958
AES-CTRA3959
AES-CTRA3959
AES-CTRA3960
AES-CTRA3960
AES-CTRA3973
AES-CTRA3973
AES-CTRA3980
AES-CTRA3980
AES-CTRA3981
AES-CTRA3981
AES-CTRA3982
AES-CTRA3982
AES-ECBA3958
AES-ECBA3958
AES-ECBA3959
AES-ECBA3959
AES-ECBA3960
AES-ECBA3960
AES-ECBA3971
AES-ECBA3971
AES-ECBA3973
AES-ECBA3973
AES-ECBA3978
AES-ECBA3978
AES-ECBA3980
AES-ECBA3980
AES-ECBA3981
AES-ECBA3981
AES-ECBA3982
AES-ECBA3982
AES-ECBA3984
AES-ECBA3984
AES-ECBA3985
AES-ECBA3985
AES-ECBA3986
AES-ECBA3986
AES-ECBA3987
AES-ECBA3987
AES-GCMA3961
AES-GCMA3961
AES-GCMA3974
AES-GCMA3974
AES-GCMA3975
AES-GCMA3975
AES-GCMA3976
AES-GCMA3976
AES-GCMA3988
AES-GCMA3988
AES-GCMA3989
AES-GCMA3989
AES-GCMA3990
AES-GCMA3990
AES-GCMA3994
AES-GCMA3994
AES-GCMA3995
AES-GCMA3995
AES-GCMA3996
AES-GCMA3996
AES-GCMA3997
AES-GCMA3997
AES-GCMA3998
AES-GCMA3998
AES-GCMA3999
AES-GCMA3999
AES-GCMA4000
AES-GCMA4000
AES-GCMA4001
AES-GCMA4001
AES-GCMA4002
AES-GCMA4002
AES-GMACA3961
AES-GMACA3974
AES-GMACA3975
AES-GMACA3976
AES-GMACA3988
AES-GMACA3989
AES-GMACA3990
AES-GMACA3994
AES-GMACA3995
AES-GMACA3996
AES-GMACA3997
AES-GMACA3998
AES-GMACA3999
AES-GMACA4000
AES-GMACA4001
AES-GMACA4002
AES-KWA3958
AES-KWA3958
AES-KWA3959
AES-KWA3959
AES-KWA3960
AES-KWA3960
AES-KWA3973
AES-KWA3973
AES-KWA3980
AES-KWA3980
AES-KWA3981
AES-KWA3981
AES-KWA3982
AES-KWA3982
AES-KWPA3958
AES-KWPA3958
AES-KWPA3959
AES-KWPA3959
AES-KWPA3960
AES-KWPA3960
AES-KWPA3973
AES-KWPA3973
AES-KWPA3980
AES-KWPA3980
AES-KWPA3981
AES-KWPA3981
AES-KWPA3982
AES-KWPA3982
AES-OFBA3958
AES-OFBA3958
AES-OFBA3959
AES-OFBA3959
AES-OFBA3960
AES-OFBA3960
AES-OFBA3973
AES-OFBA3973
AES-OFBA3980
AES-OFBA3980
AES-OFBA3981
AES-OFBA3981
AES-OFBA3982
AES-OFBA3982
AES-XTS Testing Revision 2.0A3958
AES-XTS Testing Revision 2.0A3958
AES-XTS Testing Revision 2.0A3959
AES-XTS Testing Revision 2.0A3959
AES-XTS Testing Revision 2.0A3960
AES-XTS Testing Revision 2.0A3960
AES-XTS Testing Revision 2.0A3973
AES-XTS Testing Revision 2.0A3973
AES-XTS Testing Revision 2.0A3980
AES-XTS Testing Revision 2.0A3980
AES-XTS Testing Revision 2.0A3981
AES-XTS Testing Revision 2.0A3981
AES-XTS Testing Revision 2.0A3982
AES-XTS Testing Revision 2.0A3982
Counter DRBGA3970
ECDSA KeyGen (FIPS186-4)A3962
ECDSA KeyGen (FIPS186-4)A3966
ECDSA KeyGen (FIPS186-4)A3977
ECDSA KeyGen (FIPS186-4)A3983
ECDSA KeyGen (FIPS186-4)A3993
ECDSA KeyGen (FIPS186-4)A4003
ECDSA KeyGen (FIPS186-4)A4004
ECDSA KeyGen (FIPS186-4)A4005
ECDSA KeyVer (FIPS186-4)A3962
ECDSA KeyVer (FIPS186-4)A3966
ECDSA KeyVer (FIPS186-4)A3977
ECDSA KeyVer (FIPS186-4)A3983
ECDSA KeyVer (FIPS186-4)A3993
ECDSA KeyVer (FIPS186-4)A4003
ECDSA KeyVer (FIPS186-4)A4004
ECDSA KeyVer (FIPS186-4)A4005
ECDSA SigGen (FIPS186-4)A3962
ECDSA SigGen (FIPS186-4)A3964
ECDSA SigGen (FIPS186-4)A3966
ECDSA SigGen (FIPS186-4)A3967
ECDSA SigGen (FIPS186-4)A3972
ECDSA SigGen (FIPS186-4)A3977
ECDSA SigGen (FIPS186-4)A3979
ECDSA SigGen (FIPS186-4)A3983
ECDSA SigGen (FIPS186-4)A3993
ECDSA SigGen (FIPS186-4)A4003
ECDSA SigGen (FIPS186-4)A4004
ECDSA SigGen (FIPS186-4)A4005
ECDSA SigVer (FIPS186-4)A3962
ECDSA SigVer (FIPS186-4)A3964
ECDSA SigVer (FIPS186-4)A3966
ECDSA SigVer (FIPS186-4)A3967
ECDSA SigVer (FIPS186-4)A3972
ECDSA SigVer (FIPS186-4)A3977
ECDSA SigVer (FIPS186-4)A3979
ECDSA SigVer (FIPS186-4)A3983
ECDSA SigVer (FIPS186-4)A3993
ECDSA SigVer (FIPS186-4)A4003
ECDSA SigVer (FIPS186-4)A4004
ECDSA SigVer (FIPS186-4)A4005
Hash DRBGA3970
HMAC DRBGA3970
HMAC-SHA-1A3962
HMAC-SHA-1A3977
HMAC-SHA-1A3983
HMAC-SHA-1A3993
HMAC-SHA-1A4003
HMAC-SHA-1A4004
HMAC-SHA-1A4005
HMAC-SHA2-224A3962
HMAC-SHA2-224A3977
HMAC-SHA2-224A3983
HMAC-SHA2-224A3993
HMAC-SHA2-224A4003
HMAC-SHA2-224A4004
HMAC-SHA2-224A4005
HMAC-SHA2-256A3962
HMAC-SHA2-256A3963
HMAC-SHA2-256A3977
HMAC-SHA2-256A3983
HMAC-SHA2-256A3993
HMAC-SHA2-256A4003
HMAC-SHA2-256A4004
HMAC-SHA2-256A4005
HMAC-SHA2-384A3962
HMAC-SHA2-384A3977
HMAC-SHA2-384A3983
HMAC-SHA2-384A3993
HMAC-SHA2-384A4003
HMAC-SHA2-384A4004
HMAC-SHA2-384A4005
HMAC-SHA2-512A3962
HMAC-SHA2-512A3977
HMAC-SHA2-512A3983
HMAC-SHA2-512A3993
HMAC-SHA2-512A4003
HMAC-SHA2-512A4004
HMAC-SHA2-512A4005
HMAC-SHA2-512/224A3962
HMAC-SHA2-512/224A3977
HMAC-SHA2-512/224A3983
HMAC-SHA2-512/224A3993
HMAC-SHA2-512/224A4003
HMAC-SHA2-512/224A4004
HMAC-SHA2-512/224A4005
HMAC-SHA2-512/256A3962
HMAC-SHA2-512/256A3977
HMAC-SHA2-512/256A3983
HMAC-SHA2-512/256A3993
HMAC-SHA2-512/256A4003
HMAC-SHA2-512/256A4004
HMAC-SHA2-512/256A4005
HMAC-SHA3-224A3964
HMAC-SHA3-224A3972
HMAC-SHA3-224A3979
HMAC-SHA3-256A3964
HMAC-SHA3-256A3972
HMAC-SHA3-256A3979
HMAC-SHA3-384A3964
HMAC-SHA3-384A3972
HMAC-SHA3-384A3979
HMAC-SHA3-512A3964
HMAC-SHA3-512A3972
HMAC-SHA3-512A3979
KAS-ECC-SSC Sp800-56Ar3A3962
KAS-ECC-SSC Sp800-56Ar3A3968
KAS-ECC-SSC Sp800-56Ar3A3977
KAS-ECC-SSC Sp800-56Ar3A3983
KAS-ECC-SSC Sp800-56Ar3A3993
KAS-ECC-SSC Sp800-56Ar3A4003
KAS-ECC-SSC Sp800-56Ar3A4004
KAS-ECC-SSC Sp800-56Ar3A4005
KAS-FFC-SSC Sp800-56Ar3A3992
KDA HKDF Sp800-56Cr1A3969
KDA OneStep SP800-56Cr2A3965
KDF ANS 9.42A3962
KDF ANS 9.42A3964
KDF ANS 9.42A3972
KDF ANS 9.42A3977
KDF ANS 9.42A3979
KDF ANS 9.42A3983
KDF ANS 9.42A3993
KDF ANS 9.42A4003
KDF ANS 9.42A4004
KDF ANS 9.42A4005
KDF ANS 9.63A3962
KDF ANS 9.63A3977
KDF ANS 9.63A3983
KDF ANS 9.63A3993
KDF ANS 9.63A4003
KDF ANS 9.63A4004
KDF ANS 9.63A4005
KDF SP800-108A3991
KDF SSHA3971
KDF SSHA3978
KDF SSHA3984
KDF SSHA3985
KDF SSHA3986
KDF SSHA3987
KMAC-128A3964
KMAC-128A3972
KMAC-128A3979
KMAC-256A3964
KMAC-256A3972
KMAC-256A3979
PBKDFA3962
PBKDFA3964
PBKDFA3972
PBKDFA3977
PBKDFA3979
PBKDFA3983
PBKDFA3993
PBKDFA4003
PBKDFA4004
PBKDFA4005
RSA KeyGen (FIPS186-4)A3962
RSA KeyGen (FIPS186-4)A3977
RSA KeyGen (FIPS186-4)A3983
RSA KeyGen (FIPS186-4)A3993
RSA KeyGen (FIPS186-4)A4003
RSA KeyGen (FIPS186-4)A4004
RSA KeyGen (FIPS186-4)A4005
RSA SigGen (FIPS186-4)A3962
RSA SigGen (FIPS186-4)A3977
RSA SigGen (FIPS186-4)A3983
RSA SigGen (FIPS186-4)A3993
RSA SigGen (FIPS186-4)A4003
RSA SigGen (FIPS186-4)A4004
RSA SigGen (FIPS186-4)A4005
RSA SigVer (FIPS186-4)A3962
RSA SigVer (FIPS186-4)A3977
RSA SigVer (FIPS186-4)A3983
RSA SigVer (FIPS186-4)A3993
RSA SigVer (FIPS186-4)A4003
RSA SigVer (FIPS186-4)A4004
RSA SigVer (FIPS186-4)A4005
Safe Primes Key GenerationA3992
Safe Primes Key VerificationA3992
SHA-1A3962
SHA-1A3977
SHA-1A3983
SHA-1A3993
SHA-1A4003
SHA-1A4004
SHA-1A4005
SHA2-224A3962
SHA2-224A3977
SHA2-224A3983
SHA2-224A3993
SHA2-224A4003
SHA2-224A4004
SHA2-224A4005
SHA2-256A3962
SHA2-256A3963
SHA2-256A3977
SHA2-256A3983
SHA2-256A3993
SHA2-256A4003
SHA2-256A4004
SHA2-256A4005
SHA2-384A3962
SHA2-384A3977
SHA2-384A3983
SHA2-384A3993
SHA2-384A4003
SHA2-384A4004
SHA2-384A4005
SHA2-512A3962
SHA2-512A3977
SHA2-512A3983
SHA2-512A3993
SHA2-512A4003
SHA2-512A4004
SHA2-512A4005
SHA2-512/224A3962
SHA2-512/224A3977
SHA2-512/224A3983
SHA2-512/224A3993
SHA2-512/224A4003
SHA2-512/224A4004
SHA2-512/224A4005
SHA2-512/256A3962
SHA2-512/256A3977
SHA2-512/256A3983
SHA2-512/256A3993
SHA2-512/256A4003
SHA2-512/256A4004
SHA2-512/256A4005
SHA3-224A3964
SHA3-224A3972
SHA3-224A3979
SHA3-256A3964
SHA3-256A3972
SHA3-256A3979
SHA3-384A3964
SHA3-384A3972
SHA3-384A3979
SHA3-512A3964
SHA3-512A3972
SHA3-512A3979
SHAKE-128A3964
SHAKE-128A3972
SHAKE-128A3979
SHAKE-256A3964
SHAKE-256A3972
SHAKE-256A3979
TLS v1.2 KDF RFC7627A3962
TLS v1.2 KDF RFC7627A3977
TLS v1.2 KDF RFC7627A3983
TLS v1.2 KDF RFC7627A3993
TLS v1.2 KDF RFC7627A4003
TLS v1.2 KDF RFC7627A4004
TLS v1.2 KDF RFC7627A4005
TLS v1.3 KDFA3969

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Canonical Ltd. Ubuntu 22.04 OpenSSL Cryptographic Module
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Recovery<br/>update</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>SSH<br/>HTTPS</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Canonical Ltd. Ubuntu 22.04 OpenSSL Cryptographic Module
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Recovery<br/>update</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>SSH<br/>HTTPS</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Canonical Ltd. Canonical Ltd. Ubuntu 22.04 OpenSSL Cryptographic Module Document Version: 1.1 Last Updated: 2024-08-28 Prepared by: Prepared for: atsec information security corporation Canonical Ltd.

4516 Seton Center Parkway, Suite 250 110 Southwark Street, Blue Fin Building,

5th Floor Austin, TX 78759 London, SE1 0SU www.atsec.com www.canonical.com

Page 2
Table of Contents
#SectionPage
Page 3

© 2024 Canonical Ltd. / atsec information security.

Page 4

© 2024 Canonical Ltd. / atsec information security.

Page 5
List of Tables
ItemPage
Table 1: Security Levels6
Table 2: Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets)8
Table 3: Tested Operational Environments - Software, Firmware, Hybrid9
Table 4: Modes List and Description9
Table 5: Approved Algorithms31
Table 6: Vendor-Affirmed Algorithms31
Table 7: Non-Approved, Not Allowed Algorithms32
Table 8: Security Function Implementations44
Table 9: Entropy Certificates46
Table 10: Entropy Sources46
Table 11: Ports and Interfaces50
Table 12: Roles51
Table 13: Approved Services58
Table 14: Non-Approved Services59
Table 15: EFP/EFT Information63
Table 16: Hardness Testing Temperatures63
Table 17: Storage Areas66
Table 18: SSP Input-Output Methods66
Table 19: SSP Zeroization Methods67
Table 20: SSP Table 169
Table 21: SSP Table 272
Table 22: Pre-Operational Self-Tests74
Table 23: Conditional Self-Tests89
Table 24: Pre-Operational Periodic Information90
Table 25: Conditional Periodic Information96
Table 26: Error States96
Figure 1: Block Diagram8
Page 6
SectionSecurity Level
11
21
31
41
51
61
7N/A
8N/A
91
101
111
121 1
1 General
1.1 Overview

This document is the non-proprietary FIPS 140-3 Security Policy for version 3.0.50ubuntu0.1+Fips2.1 of the Canonical Ltd. Ubuntu 22.04 OpenSSL Cryptographic Module. It contains the security rules under which the module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for an overall Security Level 1 module. whole and intact and including this notice. Other documentation is proprietary to their authors.

1.2 Security Levels

1 1

2 1

3 1

4 1

5 1

6 1

7 N/A

8 N/A

9 1

1.3 Additional Information

module, which was further consolidated into this document by atsec information security together with other vendor-supplied documentation. In preparing the Security Policy document, the laboratory formatted the vendor-supplied documentation for consolidation without altering the technical statements therein contained. The further refining of the Security Policy document was conducted iteratively throughout the conformance testing, wherein the Security Policy was submitted to the vendor, who would then edit, modify, and add technical contents. The vendor would also supply additional documentation, which the laboratory formatted into the existing Security Policy, and resubmitted to the vendor for their final editing. © 2024 Canonical Ltd. / atsec information security.

Page 7
2 Cryptographic Module Specification
2.1 Description

Purpose and Use: The Canonical Ltd. Ubuntu 22.04 OpenSSL Cryptographic Module (hereafter referred to as “the module”) is defined as a software module in a multi-chip standalone embodiment. It provides a C language application program interface (API) for use by other applications that require cryptographic functionality. The module consists of one software component, the “FIPS provider” i.e., fips.so, which implements the FIPS requirements and the cryptographic functionality provided to the operator. Module Type: Software Module Embodiment: MultiChipStand Module Characteristics: Cryptographic Boundary: Components in white are only included in the diagram for informational purposes. They are not included in the cryptographic boundary (and therefore not part of the module’s validation). For example, the kernel is responsible for managing system calls issued by the module itself, as well as other applications using the module for cryptographic services. Tested Operational Environment’s Physical Perimeter (TOEPP): Figure 1 shows a block diagram that represents the design of the module when the module is operational and providing services to other user space applications. In this diagram, the physical perimeter of the operational environment (a general-purpose computer on which the module is installed) is indicated by a purple dashed line. The cryptographic boundary is represented by the components painted in orange blocks, which consists only of the shared library implementing the FIPS provider (fips.so). Green lines indicate the flow of data between the cryptographic module and its operator application, through the logical interfaces defined in Section 3. © 2024 Canonical Ltd. / atsec information security.

Page 8
Package or File NameSoftware/ Firmware VersionFeaturesIntegrity Test
fips.so on Ubuntu 22.04 with Intel Xeon Gold 62263.0.5- 0ubuntu0.1+Fips2.1N/AHMAC-SHA2-256
fips.so on Ubuntu 22.04 with AWS Graviton23.0.5- 0ubuntu0.1+Fips2.1N/AHMAC-SHA2-256
fips.so on Ubuntu 22.04 with IBM z153.0.5- 0ubuntu0.1+Fips2.1N/AHMAC-SHA2-256
2.2 Tested and Vendor Affirmed Module Version and

Identification Tested Module Identification

Page 9
Operating SystemHardware PlatformProcessorsPAA/PAIHypervisor or Host OSVersion(s)
Ubuntu 22.04Supermicro SYS-1019P- WTRIntel Xeon Gold 6226YesN/A3.0.5- 0ubuntu0.1+Fips2.1
Ubuntu 22.04Amazon Web Services (AWS) c6g.metalAWS Graviton2YesN/A3.0.5- 0ubuntu0.1+Fips2.1
Ubuntu 22.04IBM z15IBM z15YesN/A3.0.5- 0ubuntu0.1+Fips2.1
Ubuntu 22.04Supermicro SYS-1019P- WTRIntel Xeon Gold 6226NoN/A3.0.5- 0ubuntu0.1+Fips2.1
Ubuntu 22.04Amazon Web Services (AWS) c6g.metalAWS Graviton2NoN/A3.0.5- 0ubuntu0.1+Fips2.1
Ubuntu 22.04IBM z15IBM z15NoN/A3.0.5- 0ubuntu0.1+Fips2.1
Mode NameDescriptionTypeStatus Indicator
Approved modeAutomatically entered whenever an approved service is requestedApprovedEquivalent to the indicator of the requested service
Non-approved modeAutomatically entered whenever a non- approved service is requestedNon- ApprovedEquivalent to the indicator of the requested service

Table 3: Tested Operational Environments - Software, Firmware, Hybrid Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid: N/A for this module. CMVP makes no statement as to the correct operation of the module or the security strengths of the generated keys when so ported if the specific operational environment is not listed on the validation certificate.

2.3 Excluded Components

There are no components excluded from the module.

2.4 Modes of Operation

Modes List and Description: Table 4: Modes List and Description The module supports two modes of operation: (1) the approved mode of operation, in which the approved or vendor affirmed services are available as specified in the Approved Services table and (2) the non-approved mode of operation, in which the non-approved services are available as specified in the Non-Approved Services table. Mode Change Instructions and Status: The module automatically switches between the approved and non-approved modes © 2024 Canonical Ltd. / atsec information security.

Page 10
AlgorithmCAVP CertPropertiesReference
AES-CBCA3958Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS1A3958Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS2A3958Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS3A3958Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CCMA3958Key Length - 128, 192, 256SP 800-38C
AES-CFB1A3958Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB128A3958Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB8A3958Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CMACA3958Direction - Generation, Verification Key Length - 128, 192, 256SP 800-38B
AES-CTRA3958Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA3958Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-KWA3958Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-KWPA3958Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-OFBA3958Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-XTS Testing Revision 2.0A3958Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38E
AES-CBCA3959Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS1A3959Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS2A3959Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS3A3959Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CCMA3959Key Length - 128, 192, 256SP 800-38C
AES-CFB1A3959Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A

The module does not implement a degraded mode of operation.

2.5 Algorithms

Approved Algorithms: © 2024 Canonical Ltd. / atsec information security.

Page 11
AlgorithmCAVP CertPropertiesReference
AES-CFB128A3959Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB8A3959Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CMACA3959Direction - Generation, Verification Key Length - 128, 192, 256SP 800-38B
AES-CTRA3959Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA3959Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-KWA3959Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-KWPA3959Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-OFBA3959Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-XTS Testing Revision 2.0A3959Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38E
AES-CBCA3960Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS1A3960Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS2A3960Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS3A3960Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CCMA3960Key Length - 128, 192, 256SP 800-38C
AES-CFB1A3960Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB128A3960Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB8A3960Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CMACA3960Direction - Generation, Verification Key Length - 128, 192, 256SP 800-38B
AES-CTRA3960Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA3960Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-KWA3960Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-KWPA3960Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-OFBA3960Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A

© 2024 Canonical Ltd. / atsec information security.

Page 12
AlgorithmCAVP CertPropertiesReference
AES-XTS Testing Revision 2.0A3960Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38E
AES-GCMA3961Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GMACA3961Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
ECDSA KeyGen (FIPS186-4)A3962Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - Testing CandidatesFIPS 186-4
ECDSA KeyVer (FIPS186-4)A3962Curve - P-224, P-256, P-384, P-521FIPS 186-4
ECDSA SigGen (FIPS186-4)A3962Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256FIPS 186-4
ECDSA SigVer (FIPS186-4)A3962Component - No Curve - P-192, P-224, P-256, P-384, P-521 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256FIPS 186-4
HMAC-SHA-1A3962Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 224A3962Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 256A3962Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 384A3962Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512A3962Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/224A3962Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/256A3962Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
KAS-ECC-SSC Sp800-56Ar3A3962Domain Parameter Generation Methods - P-224, P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KDF ANS 9.42 (CVL)A3962KDF Type - DER Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 Key Data Length - Key Data Length: 112-4096 Increment 8SP 800-135 Rev. 1
KDF ANS 9.63 (CVL)A3962Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 Key Data Length - Key Data Length: 128-4096 Increment 8SP 800-135 Rev. 1

© 2024 Canonical Ltd. / atsec information security.

Page 13
AlgorithmCAVP CertPropertiesReference
PBKDFA3962Iteration Count - Iteration Count: 1000-10000 Increment 1 Password Length - Password Length: 8-128 Increment 1SP 800-132
RSA KeyGen (FIPS186-4)A3962Key Generation Mode - B.3.6 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Private Key Format - StandardFIPS 186-4
RSA SigGen (FIPS186-4)A3962Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186-4)A3962Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024, 2048, 3072, 4096FIPS 186-4
SHA-1A3962Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-224A3962Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-256A3962Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-384A3962Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512A3962Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/224A3962Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/256A3962Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
TLS v1.2 KDF RFC7627 (CVL)A3962Hash Algorithm - SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
HMAC-SHA2- 256A3963Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
SHA2-256A3963Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
ECDSA SigGen (FIPS186-4)A3964Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA3-224, SHA3-256, SHA3-384, SHA3-512FIPS 186-4
ECDSA SigVer (FIPS186-4)A3964Component - No Curve - P-192, P-224, P-256, P-384, P-521 Hash Algorithm - SHA3-224, SHA3-256, SHA3-384, SHA3-512FIPS 186-4
HMAC-SHA3- 224A3964Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3- 256A3964Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3- 384A3964Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3- 512A3964Key Length - Key Length: 112-524288 Increment 8FIPS 198-1

© 2024 Canonical Ltd. / atsec information security.

Page 14
AlgorithmCAVP CertPropertiesReference
KDF ANS 9.42 (CVL)A3964KDF Type - DER Hash Algorithm - SHA3-224, SHA3-256, SHA3-384, SHA3-512 Key Data Length - Key Data Length: 112-4096 Increment 8SP 800-135 Rev. 1
KMAC-128A3964Message Length - Message Length: 0-65536 Increment 8 Key Data Length - Key Data Length: 128-1024 Increment 8SP 800-185
KMAC-256A3964Message Length - Message Length: 0-65536 Increment 8 Key Data Length - Key Data Length: 128-1024 Increment 8SP 800-185
PBKDFA3964Iteration Count - Iteration Count: 1000-10000 Increment 1 Password Length - Password Length: 8-128 Increment 1SP 800-132
SHA3-224A3964Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHA3-256A3964Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHA3-384A3964Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHA3-512A3964Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHAKE-128A3964Output Length - Output Length: 16-65536 Increment 8FIPS 202
SHAKE-256A3964Output Length - Output Length: 16-65536 Increment 8FIPS 202
KDA OneStep SP800-56Cr2A3965Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-2048 Increment 8SP 800-56C Rev. 2
ECDSA KeyGen (FIPS186-4)A3966Curve - B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571 Secret Generation Mode - Testing CandidatesFIPS 186-4
ECDSA KeyVer (FIPS186-4)A3966Curve - B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571FIPS 186-4
ECDSA SigGen (FIPS186-4)A3966Component - No Curve - B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256FIPS 186-4
ECDSA SigVer (FIPS186-4)A3966Component - No Curve - B-163, B-233, B-283, B-409, B-571, K-163, K-233, K- 283, K-409, K-571 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256FIPS 186-4
ECDSA SigGen (FIPS186-4)A3967Component - No Curve - B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571 Hash Algorithm - SHA3-224, SHA3-256, SHA3-384, SHA3-512FIPS 186-4
ECDSA SigVer (FIPS186-4)A3967Component - No Curve - B-163, B-233, B-283, B-409, B-571, K-163, K-233, K- 283, K-409, K-571 Hash Algorithm - SHA3-224, SHA3-256, SHA3-384, SHA3-512FIPS 186-4
KAS-ECC-SSC Sp800-56Ar3A3968Domain Parameter Generation Methods - B-233, B-283, B- 409, B-571, K-233, K-283, K-409, K-571 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3

© 2024 Canonical Ltd. / atsec information security.

Page 15
AlgorithmCAVP CertPropertiesReference
KDA HKDF Sp800-56Cr1A3969Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-2048 Increment 8 HMAC Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3- 256, SHA3-384SP 800-56C Rev. 2
TLS v1.3 KDF (CVL)A3969HMAC Algorithm - SHA2-256, SHA2-384 KDF Running Modes - DHE, PSK, PSK-DHESP 800-135 Rev. 1
Counter DRBGA3970Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - No, YesSP 800-90A Rev. 1
Hash DRBGA3970Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
HMAC DRBGA3970Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
AES-ECBA3971Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
KDF SSH (CVL)A3971Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
ECDSA SigGen (FIPS186-4)A3972Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA3-224, SHA3-256, SHA3-384, SHA3-512FIPS 186-4
ECDSA SigVer (FIPS186-4)A3972Component - No Curve - P-192, P-224, P-256, P-384, P-521 Hash Algorithm - SHA3-224, SHA3-256, SHA3-384, SHA3-512FIPS 186-4
HMAC-SHA3- 224A3972Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3- 256A3972Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3- 384A3972Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3- 512A3972Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
KDF ANS 9.42 (CVL)A3972KDF Type - DER Hash Algorithm - SHA3-224, SHA3-256, SHA3-384, SHA3-512 Key Data Length - Key Data Length: 112-4096 Increment 8SP 800-135 Rev. 1
KMAC-128A3972Message Length - Message Length: 0-65536 Increment 8 Key Data Length - Key Data Length: 128-1024 Increment 8SP 800-185
KMAC-256A3972Message Length - Message Length: 0-65536 Increment 8 Key Data Length - Key Data Length: 128-1024 Increment 8SP 800-185
PBKDFA3972Iteration Count - Iteration Count: 1000-10000 Increment 1 Password Length - Password Length: 8-128 Increment 1SP 800-132
SHA3-224A3972Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHA3-256A3972Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202

© 2024 Canonical Ltd. / atsec information security.

Page 16
AlgorithmCAVP CertPropertiesReference
SHA3-384A3972Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHA3-512A3972Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHAKE-128A3972Output Length - Output Length: 16-65536 Increment 8FIPS 202
SHAKE-256A3972Output Length - Output Length: 16-65536 Increment 8FIPS 202
AES-CBCA3973Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS1A3973Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS2A3973Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS3A3973Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CCMA3973Key Length - 128, 192, 256SP 800-38C
AES-CFB1A3973Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB128A3973Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB8A3973Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CMACA3973Direction - Generation, Verification Key Length - 128, 192, 256SP 800-38B
AES-CTRA3973Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA3973Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-KWA3973Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-KWPA3973Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-OFBA3973Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-XTS Testing Revision 2.0A3973Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38E
AES-GCMA3974Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GMACA3974Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GCMA3975Direction - Decrypt, Encrypt IV Generation - External, InternalSP 800-38D

© 2024 Canonical Ltd. / atsec information security.

Page 17
AlgorithmCAVP CertProperties IV Generation Mode - 8.2.1 Key Length - 128, 192, 256Reference
AES-GMACA3975Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GCMA3976Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GMACA3976Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
ECDSA KeyGen (FIPS186-4)A3977Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - Testing CandidatesFIPS 186-4
ECDSA KeyVer (FIPS186-4)A3977Curve - P-224, P-256, P-384, P-521FIPS 186-4
ECDSA SigGen (FIPS186-4)A3977Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256FIPS 186-4
ECDSA SigVer (FIPS186-4)A3977Component - No Curve - P-192, P-224, P-256, P-384, P-521 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256FIPS 186-4
HMAC-SHA-1A3977Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 224A3977Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 256A3977Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 384A3977Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512A3977Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/224A3977Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/256A3977Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
KAS-ECC-SSC Sp800-56Ar3A3977Domain Parameter Generation Methods - P-224, P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KDF ANS 9.42 (CVL)A3977KDF Type - DER Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384,SP 800-135 Rev. 1

© 2024 Canonical Ltd. / atsec information security.

Page 18
AlgorithmCAVP CertProperties SHA2-512, SHA2-512/224, SHA2-512/256 Key Data Length - Key Data Length: 112-4096 Increment 8Reference
KDF ANS 9.63 (CVL)A3977Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 Key Data Length - Key Data Length: 128-4096 Increment 8SP 800-135 Rev. 1
PBKDFA3977Iteration Count - Iteration Count: 1000-10000 Increment 1 Password Length - Password Length: 8-128 Increment 1SP 800-132
RSA KeyGen (FIPS186-4)A3977Key Generation Mode - B.3.6 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Private Key Format - StandardFIPS 186-4
RSA SigGen (FIPS186-4)A3977Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186-4)A3977Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024, 2048, 3072, 4096FIPS 186-4
SHA-1A3977Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-224A3977Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-256A3977Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-384A3977Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512A3977Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/224A3977Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/256A3977Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
TLS v1.2 KDF RFC7627 (CVL)A3977Hash Algorithm - SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
AES-ECBA3978Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
KDF SSH (CVL)A3978Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
ECDSA SigGen (FIPS186-4)A3979Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA3-224, SHA3-256, SHA3-384, SHA3-512FIPS 186-4
ECDSA SigVer (FIPS186-4)A3979Component - No Curve - P-192, P-224, P-256, P-384, P-521 Hash Algorithm - SHA3-224, SHA3-256, SHA3-384, SHA3-512FIPS 186-4
HMAC-SHA3- 224A3979Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3- 256A3979Key Length - Key Length: 112-524288 Increment 8FIPS 198-1

© 2024 Canonical Ltd. / atsec information security.

Page 19
AlgorithmCAVP CertPropertiesReference
HMAC-SHA3- 384A3979Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3- 512A3979Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
KDF ANS 9.42 (CVL)A3979KDF Type - DER Hash Algorithm - SHA3-224, SHA3-256, SHA3-384, SHA3-512 Key Data Length - Key Data Length: 112-4096 Increment 8SP 800-135 Rev. 1
KMAC-128A3979Message Length - Message Length: 0-65536 Increment 8 Key Data Length - Key Data Length: 128-1024 Increment 8SP 800-185
KMAC-256A3979Message Length - Message Length: 0-65536 Increment 8 Key Data Length - Key Data Length: 128-1024 Increment 8SP 800-185
PBKDFA3979Iteration Count - Iteration Count: 1000-10000 Increment 1 Password Length - Password Length: 8-128 Increment 1SP 800-132
SHA3-224A3979Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHA3-256A3979Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHA3-384A3979Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHA3-512A3979Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHAKE-128A3979Output Length - Output Length: 16-65536 Increment 8FIPS 202
SHAKE-256A3979Output Length - Output Length: 16-65536 Increment 8FIPS 202
AES-CBCA3980Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS1A3980Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS2A3980Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS3A3980Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CCMA3980Key Length - 128, 192, 256SP 800-38C
AES-CFB1A3980Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB128A3980Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB8A3980Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CMACA3980Direction - Generation, Verification Key Length - 128, 192, 256SP 800-38B
AES-CTRA3980Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA3980Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A

© 2024 Canonical Ltd. / atsec information security.

Page 20
AlgorithmCAVP CertPropertiesReference
AES-KWA3980Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-KWPA3980Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-OFBA3980Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-XTS Testing Revision 2.0A3980Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38E
AES-CBCA3981Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS1A3981Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS2A3981Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS3A3981Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CCMA3981Key Length - 128, 192, 256SP 800-38C
AES-CFB1A3981Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB128A3981Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB8A3981Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CMACA3981Direction - Generation, Verification Key Length - 128, 192, 256SP 800-38B
AES-CTRA3981Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA3981Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-KWA3981Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-KWPA3981Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-OFBA3981Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-XTS Testing Revision 2.0A3981Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38E
AES-CBCA3982Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS1A3982Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS2A3982Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS3A3982Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A

© 2024 Canonical Ltd. / atsec information security.

Page 21
AlgorithmCAVP CertPropertiesReference
AES-CCMA3982Key Length - 128, 192, 256SP 800-38C
AES-CFB1A3982Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB128A3982Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB8A3982Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CMACA3982Direction - Generation, Verification Key Length - 128, 192, 256SP 800-38B
AES-CTRA3982Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA3982Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-KWA3982Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-KWPA3982Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-OFBA3982Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-XTS Testing Revision 2.0A3982Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38E
ECDSA KeyGen (FIPS186-4)A3983Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - Testing CandidatesFIPS 186-4
ECDSA KeyVer (FIPS186-4)A3983Curve - P-224, P-256, P-384, P-521FIPS 186-4
ECDSA SigGen (FIPS186-4)A3983Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256FIPS 186-4
ECDSA SigVer (FIPS186-4)A3983Component - No Curve - P-192, P-224, P-256, P-384, P-521 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256FIPS 186-4
HMAC-SHA-1A3983Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 224A3983Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 256A3983Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 384A3983Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512A3983Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/224A3983Key Length - Key Length: 112-524288 Increment 8FIPS 198-1

© 2024 Canonical Ltd. / atsec information security.

Page 22
AlgorithmCAVP CertPropertiesReference
HMAC-SHA2- 512/256A3983Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
KAS-ECC-SSC Sp800-56Ar3A3983Domain Parameter Generation Methods - P-224, P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KDF ANS 9.42 (CVL)A3983KDF Type - DER Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 Key Data Length - Key Data Length: 112-4096 Increment 8SP 800-135 Rev. 1
KDF ANS 9.63 (CVL)A3983Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 Key Data Length - Key Data Length: 128-4096 Increment 8SP 800-135 Rev. 1
PBKDFA3983Iteration Count - Iteration Count: 1000-10000 Increment 1 Password Length - Password Length: 8-128 Increment 1SP 800-132
RSA KeyGen (FIPS186-4)A3983Key Generation Mode - B.3.6 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Private Key Format - StandardFIPS 186-4
RSA SigGen (FIPS186-4)A3983Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186-4)A3983Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024, 2048, 3072, 4096FIPS 186-4
SHA-1A3983Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-224A3983Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-256A3983Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-384A3983Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512A3983Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/224A3983Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/256A3983Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
TLS v1.2 KDF RFC7627 (CVL)A3983Hash Algorithm - SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
AES-ECBA3984Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
KDF SSH (CVL)A3984Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
AES-ECBA3985Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A

© 2024 Canonical Ltd. / atsec information security.

Page 23
AlgorithmCAVP CertPropertiesReference
KDF SSH (CVL)A3985Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
AES-ECBA3986Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
KDF SSH (CVL)A3986Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
AES-ECBA3987Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
KDF SSH (CVL)A3987Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
AES-GCMA3988Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GMACA3988Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GCMA3989Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GMACA3989Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GCMA3990Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GMACA3990Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
KDF SP800-108A3991KDF Mode - Counter, Feedback Supported Lengths - Supported Lengths: 112-4096 Increment 8SP 800-108 Rev. 1
KAS-FFC-SSC Sp800-56Ar3A3992Domain Parameter Generation Methods - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192 Scheme - dhEphem - KAS Role - initiator, responderSP 800-56A Rev. 3
Safe Primes Key GenerationA3992Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP- 4096, MODP-6144, MODP-8192SP 800-56A Rev. 3

© 2024 Canonical Ltd. / atsec information security.

Page 24
AlgorithmCAVP CertPropertiesReference
Safe Primes Key VerificationA3992Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP- 4096, MODP-6144, MODP-8192SP 800-56A Rev. 3
ECDSA KeyGen (FIPS186-4)A3993Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - Testing CandidatesFIPS 186-4
ECDSA KeyVer (FIPS186-4)A3993Curve - P-224, P-256, P-384, P-521FIPS 186-4
ECDSA SigGen (FIPS186-4)A3993Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256FIPS 186-4
ECDSA SigVer (FIPS186-4)A3993Component - No Curve - P-192, P-224, P-256, P-384, P-521 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256FIPS 186-4
HMAC-SHA-1A3993Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 224A3993Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 256A3993Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 384A3993Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512A3993Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/224A3993Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/256A3993Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
KAS-ECC-SSC Sp800-56Ar3A3993Domain Parameter Generation Methods - P-224, P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KDF ANS 9.42 (CVL)A3993KDF Type - DER Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 Key Data Length - Key Data Length: 112-4096 Increment 8SP 800-135 Rev. 1
KDF ANS 9.63 (CVL)A3993Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 Key Data Length - Key Data Length: 128-4096 Increment 8SP 800-135 Rev. 1
PBKDFA3993Iteration Count - Iteration Count: 1000-10000 Increment 1 Password Length - Password Length: 8-128 Increment 1SP 800-132
RSA KeyGen (FIPS186-4)A3993Key Generation Mode - B.3.6 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Private Key Format - StandardFIPS 186-4

© 2024 Canonical Ltd. / atsec information security.

Page 25
AlgorithmCAVP CertPropertiesReference
RSA SigGen (FIPS186-4)A3993Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186-4)A3993Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024, 2048, 3072, 4096FIPS 186-4
SHA-1A3993Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-224A3993Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-256A3993Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-384A3993Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512A3993Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/224A3993Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/256A3993Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
TLS v1.2 KDF RFC7627 (CVL)A3993Hash Algorithm - SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
AES-GCMA3994Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GMACA3994Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GCMA3995Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GMACA3995Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GCMA3996Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GMACA3996Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GCMA3997Direction - Decrypt, Encrypt IV Generation - External, InternalSP 800-38D

© 2024 Canonical Ltd. / atsec information security.

Page 26
AlgorithmCAVP CertProperties IV Generation Mode - 8.2.1 Key Length - 128, 192, 256Reference
AES-GMACA3997Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GCMA3998Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GMACA3998Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GCMA3999Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GMACA3999Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GCMA4000Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GMACA4000Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GCMA4001Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GMACA4001Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GCMA4002Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GMACA4002Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
ECDSA KeyGen (FIPS186-4)A4003Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - Testing CandidatesFIPS 186-4

© 2024 Canonical Ltd. / atsec information security.

Page 27
AlgorithmCAVP CertPropertiesReference
ECDSA KeyVer (FIPS186-4)A4003Curve - P-224, P-256, P-384, P-521FIPS 186-4
ECDSA SigGen (FIPS186-4)A4003Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256FIPS 186-4
ECDSA SigVer (FIPS186-4)A4003Component - No Curve - P-192, P-224, P-256, P-384, P-521 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256FIPS 186-4
HMAC-SHA-1A4003Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 224A4003Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 256A4003Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 384A4003Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512A4003Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/224A4003Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/256A4003Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
KAS-ECC-SSC Sp800-56Ar3A4003Domain Parameter Generation Methods - P-224, P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KDF ANS 9.42 (CVL)A4003KDF Type - DER Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 Key Data Length - Key Data Length: 112-4096 Increment 8SP 800-135 Rev. 1
KDF ANS 9.63 (CVL)A4003Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 Key Data Length - Key Data Length: 128-4096 Increment 8SP 800-135 Rev. 1
PBKDFA4003Iteration Count - Iteration Count: 1000-10000 Increment 1 Password Length - Password Length: 8-128 Increment 1SP 800-132
RSA KeyGen (FIPS186-4)A4003Key Generation Mode - B.3.6 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Private Key Format - StandardFIPS 186-4
RSA SigGen (FIPS186-4)A4003Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186-4)A4003Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024, 2048, 3072, 4096FIPS 186-4
SHA-1A4003Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4

© 2024 Canonical Ltd. / atsec information security.

Page 28
AlgorithmCAVP CertPropertiesReference
SHA2-224A4003Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-256A4003Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-384A4003Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512A4003Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/224A4003Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/256A4003Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
TLS v1.2 KDF RFC7627 (CVL)A4003Hash Algorithm - SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
ECDSA KeyGen (FIPS186-4)A4004Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - Testing CandidatesFIPS 186-4
ECDSA KeyVer (FIPS186-4)A4004Curve - P-224, P-256, P-384, P-521FIPS 186-4
ECDSA SigGen (FIPS186-4)A4004Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256FIPS 186-4
ECDSA SigVer (FIPS186-4)A4004Component - No Curve - P-192, P-224, P-256, P-384, P-521 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256FIPS 186-4
HMAC-SHA-1A4004Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 224A4004Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 256A4004Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 384A4004Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512A4004Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/224A4004Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/256A4004Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
KAS-ECC-SSC Sp800-56Ar3A4004Domain Parameter Generation Methods - P-224, P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KDF ANS 9.42 (CVL)A4004KDF Type - DER Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384,SP 800-135 Rev. 1

© 2024 Canonical Ltd. / atsec information security.

Page 29
AlgorithmCAVP CertProperties SHA2-512, SHA2-512/224, SHA2-512/256 Key Data Length - Key Data Length: 112-4096 Increment 8Reference
KDF ANS 9.63 (CVL)A4004Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 Key Data Length - Key Data Length: 128-4096 Increment 8SP 800-135 Rev. 1
PBKDFA4004Iteration Count - Iteration Count: 1000-10000 Increment 1 Password Length - Password Length: 8-128 Increment 1SP 800-132
RSA KeyGen (FIPS186-4)A4004Key Generation Mode - B.3.6 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Private Key Format - StandardFIPS 186-4
RSA SigGen (FIPS186-4)A4004Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186-4)A4004Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024, 2048, 3072, 4096FIPS 186-4
SHA-1A4004Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-224A4004Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-256A4004Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-384A4004Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512A4004Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/224A4004Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/256A4004Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
TLS v1.2 KDF RFC7627 (CVL)A4004Hash Algorithm - SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
ECDSA KeyGen (FIPS186-4)A4005Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - Testing CandidatesFIPS 186-4
ECDSA KeyVer (FIPS186-4)A4005Curve - P-224, P-256, P-384, P-521FIPS 186-4
ECDSA SigGen (FIPS186-4)A4005Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256FIPS 186-4
ECDSA SigVer (FIPS186-4)A4005Component - No Curve - P-192, P-224, P-256, P-384, P-521 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256FIPS 186-4
HMAC-SHA-1A4005Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 224A4005Key Length - Key Length: 112-524288 Increment 8FIPS 198-1

© 2024 Canonical Ltd. / atsec information security.

Page 30
AlgorithmCAVP CertPropertiesReference
HMAC-SHA2- 256A4005Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 384A4005Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512A4005Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/224A4005Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/256A4005Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
KAS-ECC-SSC Sp800-56Ar3A4005Domain Parameter Generation Methods - P-224, P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KDF ANS 9.42 (CVL)A4005KDF Type - DER Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 Key Data Length - Key Data Length: 112-4096 Increment 8SP 800-135 Rev. 1
KDF ANS 9.63 (CVL)A4005Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256 Key Data Length - Key Data Length: 128-4096 Increment 8SP 800-135 Rev. 1
PBKDFA4005Iteration Count - Iteration Count: 1000-10000 Increment 1 Password Length - Password Length: 8-128 Increment 1SP 800-132
RSA KeyGen (FIPS186-4)A4005Key Generation Mode - B.3.6 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Private Key Format - StandardFIPS 186-4
RSA SigGen (FIPS186-4)A4005Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186-4)A4005Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024, 2048, 3072, 4096FIPS 186-4
SHA-1A4005Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-224A4005Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-256A4005Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-384A4005Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512A4005Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/224A4005Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/256A4005Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4

© 2024 Canonical Ltd. / atsec information security.

Page 31
AlgorithmCAVP CertPropertiesReference
TLS v1.2 KDF RFC7627 (CVL)A4005Hash Algorithm - SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
NamePropertiesImplementationReference
Cryptographic Key Generation (CKG)Key Type:Asymmetric RSA:2048, 3072, 4096-bit keys ECDSA:P-224, P-256, P-384, P-521, B-233, B- 283, B-409, B-571, K-233, K-283, K-409, K-571 elliptic curves Safe Prime Groups:ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP- 8192N/ASP800-133rev2, Section 4, example 1
NameUse and Function
AES GCM (external IV)Encryption
DSASignature generation
DSASignature verification
DSAKey pair generation
DSAKey pair verification
ECDSA with curve P-192Key pair generation
RSA and ECDSA (pre-hashed message)Signature generation (pre-hashed message)
RSA and ECDSA (pre-hashed message)Signature verification (pre-hashed message)
RSA X9.31Signature generation
RSA X9.31Signature verification
RSA primitiveAsymmetric encryption
RSA primitiveAsymmetric decryption
RSA-OAEPAsymmetric encryption
RSA-OAEPAsymmetric decryption
RSASVESecret value encapsulation

Table 5: Approved Algorithms The table above lists all implemented modes or methods of operation for the approved cryptographic algorithms of the module that are employed for approved services (Approved Services table). Vendor-Affirmed Algorithms: Table 6: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: N/A for this module. Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. Non-Approved, Not Allowed Algorithms: © 2024 Canonical Ltd. / atsec information security.

Page 32
NameUse and Function
RSASVESecret value decapsulation
NameTypeDescriptionPropertiesAlgorithms
Symmetric encryptionBC-UnAuth BC-AuthSymmetric encryptionAES-CBC:128, 192, 256 bits AES-CBC-CS1:128, 192, 256 bits AES-CBC-CS2:128, 192, 256 bits AES-CBC-CS3:128, 192, 256 bits AES-CCM:128, 192, 256 bits AES-CFB1:128, 192, 256 bits AES-CFB128:128, 192, 256 bits AES-CFB8:128, 192, 256 bits AES-CTR:128, 192, 256 bits AES-ECB:128, 192, 256 bits AES-OFB:128, 192, 256 bits AES-XTS Testing Revision 2.0:128, 256 bits AES-GCM:128, 192, 256 bitsAES-CBC AES-CBC AES-CBC AES-CBC AES-CBC AES-CBC AES-CBC AES-CBC-CS1 AES-CBC-CS1 AES-CBC-CS1 AES-CBC-CS1 AES-CBC-CS1 AES-CBC-CS1 AES-CBC-CS1 AES-CBC-CS2 AES-CBC-CS2 AES-CBC-CS2 AES-CBC-CS2 AES-CBC-CS2 AES-CBC-CS2 AES-CBC-CS2 AES-CBC-CS3 AES-CBC-CS3 AES-CBC-CS3 AES-CBC-CS3 AES-CBC-CS3 AES-CBC-CS3 AES-CBC-CS3 AES-CCM AES-CCM AES-CCM AES-CCM AES-CCM AES-CCM AES-CCM AES-CFB1 AES-CFB1 AES-CFB1 AES-CFB1 AES-CFB1 AES-CFB1 AES-CFB1 AES-CFB128

Table 7: Non-Approved, Not Allowed Algorithms The table above lists all the non-approved cryptographic algorithms of the module employed by the non-approved services in the Non-Approved Services table.

2.6 Security Function Implementations

© 2024 Canonical Ltd. / atsec information security.

Page 33

Name

Type

Description

Properties

Algorithms AES-CFB128 AES-CFB128 AES-CFB128 AES-CFB128 AES-CFB128 AES-CFB128 AES-CFB8 AES-CFB8 AES-CFB8 AES-CFB8 AES-CFB8 AES-CFB8 AES-CFB8 AES-CTR AES-CTR AES-CTR AES-CTR AES-CTR AES-CTR AES-CTR AES-ECB AES-ECB AES-ECB AES-ECB AES-ECB AES-ECB AES-ECB AES-ECB AES-ECB AES-ECB AES-ECB AES-ECB AES-ECB AES-OFB AES-OFB AES-OFB AES-OFB AES-OFB AES-OFB AES-OFB AES-XTS Testing Revision 2.0 AES-XTS Testing Revision 2.0 AES-XTS Testing Revision 2.0 AES-XTS Testing Revision 2.0 AES-XTS Testing Revision 2.0 AES-XTS Testing Revision 2.0 AES-XTS Testing

© 2024 Canonical Ltd. / atsec information security.

Page 34
NameTypeDescriptionPropertiesAlgorithms Revision 2.0 AES-GCM AES-GCM AES-GCM AES-GCM AES-GCM AES-GCM AES-GCM AES-GCM AES-GCM AES-GCM AES-GCM AES-GCM AES-GCM AES-GCM AES-GCM AES-GCM
Symmetric decryptionBC-UnAuth BC-AuthSymmetric decryptionAES-CBC:128, 192, 256 bits AES-CBC-CS1:128, 192, 256 bits AES-CBC-CS2:128, 192, 256 bits AES-CBC-CS3:128, 192, 256 bits AES-CCM:128, 192, 256 bits AES-CFB1:128, 192, 256 bits AES-CFB128:128, 192, 256 bits AES-CFB8:128, 192, 256 bits AES-CTR:128, 192, 256 bits AES-ECB:128, 192, 256 bits AES-OFB:128, 192, 256 bits AES-XTS Testing Revision 2.0:128, 256 bits AES-GCM:128, 192, 256 bitsAES-CBC AES-CBC AES-CBC AES-CBC AES-CBC AES-CBC AES-CBC AES-CBC-CS1 AES-CBC-CS1 AES-CBC-CS1 AES-CBC-CS1 AES-CBC-CS1 AES-CBC-CS1 AES-CBC-CS1 AES-CBC-CS2 AES-CBC-CS2 AES-CBC-CS2 AES-CBC-CS2 AES-CBC-CS2 AES-CBC-CS2 AES-CBC-CS2 AES-CBC-CS3 AES-CBC-CS3 AES-CBC-CS3 AES-CBC-CS3 AES-CBC-CS3 AES-CBC-CS3 AES-CBC-CS3 AES-CCM AES-CCM AES-CCM AES-CCM AES-CCM AES-CCM AES-CCM

© 2024 Canonical Ltd. / atsec information security.

Page 35

Name

Type

Description

Properties

Algorithms AES-CFB1 AES-CFB1 AES-CFB1 AES-CFB1 AES-CFB1 AES-CFB1 AES-CFB1 AES-CFB128 AES-CFB128 AES-CFB128 AES-CFB128 AES-CFB128 AES-CFB128 AES-CFB128 AES-CFB8 AES-CFB8 AES-CFB8 AES-CFB8 AES-CFB8 AES-CFB8 AES-CFB8 AES-CTR AES-CTR AES-CTR AES-CTR AES-CTR AES-CTR AES-CTR AES-ECB AES-ECB AES-ECB AES-ECB AES-ECB AES-ECB AES-ECB AES-ECB AES-ECB AES-ECB AES-ECB AES-ECB AES-ECB AES-OFB AES-OFB AES-OFB AES-OFB AES-OFB AES-OFB AES-OFB AES-XTS Testing Revision 2.0 AES-XTS Testing Revision 2.0 AES-XTS Testing

© 2024 Canonical Ltd. / atsec information security.

Page 36
NameTypeDescriptionPropertiesAlgorithms Revision 2.0 AES-XTS Testing Revision 2.0 AES-XTS Testing Revision 2.0 AES-XTS Testing Revision 2.0 AES-XTS Testing Revision 2.0 AES-GCM AES-GCM AES-GCM AES-GCM AES-GCM AES-GCM AES-GCM AES-GCM AES-GCM AES-GCM AES-GCM AES-GCM AES-GCM AES-GCM AES-GCM AES-GCM
Key wrappingKTS-WrapKey wrapping (compliant with IG D.G)AES-KW:128, 192, 256 bits AES-KWP:128, 192, 256 bitsAES-KW AES-KW AES-KW AES-KW AES-KW AES-KW AES-KW AES-KWP AES-KWP AES-KWP AES-KWP AES-KWP AES-KWP AES-KWP
Key unwrappingKTS-WrapKey unwrapping (compliant with IG D.G)AES-KW:128, 192, 256 bits AES-KWP:128, 192, 256 bitsAES-KW AES-KW AES-KW AES-KW AES-KW AES-KW AES-KW AES-KWP AES-KWP AES-KWP AES-KWP AES-KWP

© 2024 Canonical Ltd. / atsec information security.

Page 37
NameTypeDescriptionPropertiesAlgorithms AES-KWP AES-KWP
Key pair generationAsymKeyPair- KeyGenKey pair generationECDSA KeyGen (FIPS186-4):P-224, P-256, P-384, P-521, K-233, K-283, K-409, K-571, B-233, B- 283, B-409, B-571 (112, 128, 192, 256 bits) RSA KeyGen (FIPS186-4):2048- 15360 bits (112-256 bits) Safe Primes Key Generation:MODP- 2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192 (112-200 bits)ECDSA KeyGen (FIPS186-4) ECDSA KeyGen (FIPS186-4) ECDSA KeyGen (FIPS186-4) ECDSA KeyGen (FIPS186-4) ECDSA KeyGen (FIPS186-4) ECDSA KeyGen (FIPS186-4) ECDSA KeyGen (FIPS186-4) ECDSA KeyGen (FIPS186-4) RSA KeyGen (FIPS186-4) RSA KeyGen (FIPS186-4) RSA KeyGen (FIPS186-4) RSA KeyGen (FIPS186-4) RSA KeyGen (FIPS186-4) RSA KeyGen (FIPS186-4) RSA KeyGen (FIPS186-4) Safe Primes Key Generation
Key pair verificationAsymKeyPair- KeyVerKey pair verificationECDSA KeyVer (FIPS186-4):P-192, P-224, P-256, P-384, P-521, K-163, K-233, K-283, K-409, K-571, B-163, B-233, B- 283, B-409, B-571 (80-256 bits) Safe Primes Key Verification:MODP- 2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144,ECDSA KeyVer (FIPS186-4) ECDSA KeyVer (FIPS186-4) ECDSA KeyVer (FIPS186-4) ECDSA KeyVer (FIPS186-4) ECDSA KeyVer (FIPS186-4) ECDSA KeyVer (FIPS186-4) ECDSA KeyVer (FIPS186-4) ECDSA KeyVer (FIPS186-4) Safe Primes Key Verification

© 2024 Canonical Ltd. / atsec information security.

Page 38
NameTypeDescriptionProperties ffdhe8192 (112-200 bits)Algorithms
Digital signature generationDigSig-SigGenDigital signature generationECDSA SigGen (FIPS186-4):P-224, P-256, P-384, P-521, K-233, K-283, K-409, K-571, B-233, B- 283, B-409, B-571 (112, 128, 192, 256 bits) RSA SigGen (FIPS186-4):2048- 16384 bits (112-256 bits)ECDSA SigGen (FIPS186-4) ECDSA SigGen (FIPS186-4) ECDSA SigGen (FIPS186-4) ECDSA SigGen (FIPS186-4) ECDSA SigGen (FIPS186-4) ECDSA SigGen (FIPS186-4) ECDSA SigGen (FIPS186-4) ECDSA SigGen (FIPS186-4) ECDSA SigGen (FIPS186-4) ECDSA SigGen (FIPS186-4) ECDSA SigGen (FIPS186-4) ECDSA SigGen (FIPS186-4) RSA SigGen (FIPS186-4) RSA SigGen (FIPS186-4) RSA SigGen (FIPS186-4) RSA SigGen (FIPS186-4) RSA SigGen (FIPS186-4) RSA SigGen (FIPS186-4) RSA SigGen (FIPS186-4)
Digital signature verificationDigSig-SigVerDigital signature verificationRSA SigVer (FIPS186-4):1024- 16384 bits (80-256 bits) ECDSA SigVer (FIPS186-4):1024- 16384 bits (80-256 bits)RSA SigVer (FIPS186-4) RSA SigVer (FIPS186-4) RSA SigVer (FIPS186-4) RSA SigVer (FIPS186-4) RSA SigVer (FIPS186-4) RSA SigVer (FIPS186-4)

© 2024 Canonical Ltd. / atsec information security.

Page 39
NameTypeDescriptionPropertiesAlgorithms RSA SigVer (FIPS186-4) ECDSA SigVer (FIPS186-4) ECDSA SigVer (FIPS186-4) ECDSA SigVer (FIPS186-4) ECDSA SigVer (FIPS186-4) ECDSA SigVer (FIPS186-4) ECDSA SigVer (FIPS186-4) ECDSA SigVer (FIPS186-4) ECDSA SigVer (FIPS186-4) ECDSA SigVer (FIPS186-4) ECDSA SigVer (FIPS186-4) ECDSA SigVer (FIPS186-4) ECDSA SigVer (FIPS186-4)
Message authenticationMACMessage authenticationAES-CMAC:128, 192, 256 bits AES-GMAC:128, 192, 256 bits HMAC-SHA-1:112- 524288 bits (112- 256 bits) HMAC-SHA2- 224:112-524288 bits (112-256 bits) HMAC-SHA2- 256:112-524288 bits (112-256 bits) HMAC-SHA2- 384:112-524288 bits (112-256 bits) HMAC-SHA2- 512:112-524288 bits (112-256 bits) HMAC-SHA2- 512/224:112- 524288 bits (112- 256 bits) HMAC-SHA2- 512/256:112- 524288 bits (112-AES-CMAC AES-CMAC AES-CMAC AES-CMAC AES-CMAC AES-CMAC AES-CMAC AES-GMAC AES-GMAC AES-GMAC AES-GMAC AES-GMAC AES-GMAC AES-GMAC AES-GMAC AES-GMAC AES-GMAC AES-GMAC AES-GMAC AES-GMAC AES-GMAC AES-GMAC AES-GMAC HMAC-SHA-1 HMAC-SHA-1 HMAC-SHA-1

© 2024 Canonical Ltd. / atsec information security.

Page 40

Name

Type

Description

Properties 256 bits) HMAC-SHA3- 224:112-524288 bits (112-256 bits) HMAC-SHA3- 256:112-524288 bits (112-256 bits) HMAC-SHA3- 384:112-524288 bits (112-256 bits) HMAC-SHA3- 512:112-524288 bits (112-256 bits) KMAC-128:128- 1024 bits (128-256 bits) KMAC-256:128- 1024 bits (128-256 bits)

Algorithms HMAC-SHA-1 HMAC-SHA-1 HMAC-SHA-1 HMAC-SHA-1 HMAC-SHA2-224 HMAC-SHA2-224 HMAC-SHA2-224 HMAC-SHA2-224 HMAC-SHA2-224 HMAC-SHA2-224 HMAC-SHA2-224 HMAC-SHA2-256 HMAC-SHA2-256 HMAC-SHA2-256 HMAC-SHA2-256 HMAC-SHA2-256 HMAC-SHA2-256 HMAC-SHA2-256 HMAC-SHA2-256 HMAC-SHA2-384 HMAC-SHA2-384 HMAC-SHA2-384 HMAC-SHA2-384 HMAC-SHA2-384 HMAC-SHA2-384 HMAC-SHA2-384 HMAC-SHA2-512 HMAC-SHA2-512 HMAC-SHA2-512 HMAC-SHA2-512 HMAC-SHA2-512 HMAC-SHA2-512 HMAC-SHA2-512 HMAC-SHA2- 512/224 HMAC-SHA2- 512/224 HMAC-SHA2- 512/224 HMAC-SHA2- 512/224 HMAC-SHA2- 512/224 HMAC-SHA2- 512/224 HMAC-SHA2- 512/224 HMAC-SHA2- 512/256 HMAC-SHA2- 512/256 HMAC-SHA2- 512/256

© 2024 Canonical Ltd. / atsec information security.

Page 41
NameTypeDescriptionPropertiesAlgorithms HMAC-SHA2- 512/256 HMAC-SHA2- 512/256 HMAC-SHA2- 512/256 HMAC-SHA2- 512/256 HMAC-SHA3-224 HMAC-SHA3-224 HMAC-SHA3-224 HMAC-SHA3-256 HMAC-SHA3-256 HMAC-SHA3-256 HMAC-SHA3-384 HMAC-SHA3-384 HMAC-SHA3-384 HMAC-SHA3-512 HMAC-SHA3-512 HMAC-SHA3-512 KMAC-128 KMAC-128 KMAC-128 KMAC-256 KMAC-256 KMAC-256
Shared secret computationKAS-SSCShared secret computationKAS-FFC-SSC Sp800- 56Ar3:MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192 (112-200 bits) KAS-ECC-SSC Sp800-56Ar3:P-224, P-256, P-384, P-521, K-233, K-283, K-409, K-571, B-233, B- 283, B-409, B-571 (112, 128, 192, 256 bits)KAS-FFC-SSC Sp800-56Ar3 KAS-ECC-SSC Sp800-56Ar3 KAS-ECC-SSC Sp800-56Ar3 KAS-ECC-SSC Sp800-56Ar3 KAS-ECC-SSC Sp800-56Ar3 KAS-ECC-SSC Sp800-56Ar3 KAS-ECC-SSC Sp800-56Ar3 KAS-ECC-SSC Sp800-56Ar3 KAS-ECC-SSC Sp800-56Ar3
Key derivationKAS-135KDF KAS-56CKDF KBKDFKey derivationKDF ANS 9.42:112- 4096 bits (112-256 bits) KDF ANS 9.63:128- 4096 bits (128-256KDF ANS 9.42 KDF ANS 9.42 KDF ANS 9.42 KDF ANS 9.42 KDF ANS 9.42

© 2024 Canonical Ltd. / atsec information security.

Page 42
NameTypeDescriptionProperties bits) TLS v1.2 KDF RFC7627:TLS derived secret (112- 256 bits) KDA OneStep SP800- 56Cr2:Shared secret (224-2048 bits) KDA HKDF Sp800- 56Cr1:224-2048 bits (112-256 bits) TLS v1.3 KDF:TLS derived secret (112- 256 bits) KDF SSH:112-256 bits KDF SP800- 108:112-4096 bits (112-256 bits)Algorithms KDF ANS 9.42 KDF ANS 9.42 KDF ANS 9.42 KDF ANS 9.42 KDF ANS 9.42 KDF ANS 9.63 KDF ANS 9.63 KDF ANS 9.63 KDF ANS 9.63 KDF ANS 9.63 KDF ANS 9.63 KDF ANS 9.63 TLS v1.2 KDF RFC7627 TLS v1.2 KDF RFC7627 TLS v1.2 KDF RFC7627 TLS v1.2 KDF RFC7627 TLS v1.2 KDF RFC7627 TLS v1.2 KDF RFC7627 TLS v1.2 KDF RFC7627 KDA OneStep SP800-56Cr2 KDA HKDF Sp800- 56Cr1 TLS v1.3 KDF KDF SSH KDF SSH KDF SSH KDF SSH KDF SSH KDF SSH KDF SP800-108
Message digestSHA XOFMessage digestSHA-1:N/A SHA2-224:N/A SHA2-256:N/A SHA2-384:N/A SHA2-512:N/A SHA2-512/224:N/A SHA2-512/256:N/A SHA3-224:N/A SHA3-256:N/A SHA3-384:N/A SHA3-512:N/A SHAKE-128:N/A SHAKE-256:N/ASHA-1 SHA-1 SHA-1 SHA-1 SHA-1 SHA-1 SHA-1 SHA2-224 SHA2-224 SHA2-224 SHA2-224 SHA2-224 SHA2-224 SHA2-224

© 2024 Canonical Ltd. / atsec information security.

Page 43

Name

Type

Description

Properties

Algorithms SHA2-256 SHA2-256 SHA2-256 SHA2-256 SHA2-256 SHA2-256 SHA2-256 SHA2-256 SHA2-384 SHA2-384 SHA2-384 SHA2-384 SHA2-384 SHA2-384 SHA2-384 SHA2-512 SHA2-512 SHA2-512 SHA2-512 SHA2-512 SHA2-512 SHA2-512 SHA2-512/224 SHA2-512/224 SHA2-512/224 SHA2-512/224 SHA2-512/224 SHA2-512/224 SHA2-512/224 SHA2-512/256 SHA2-512/256 SHA2-512/256 SHA2-512/256 SHA2-512/256 SHA2-512/256 SHA2-512/256 SHA3-224 SHA3-224 SHA3-224 SHA3-256 SHA3-256 SHA3-256 SHA3-384 SHA3-384 SHA3-384 SHA3-512 SHA3-512 SHA3-512 SHAKE-128 SHAKE-128 SHAKE-128 SHAKE-256

© 2024 Canonical Ltd. / atsec information security.

Page 44
NameTypeDescriptionPropertiesAlgorithms SHAKE-256 SHAKE-256
Password-based key derivationPBKDFDeriving keys from a password-based KDFPBKDF:112-256 bitsPBKDF PBKDF PBKDF PBKDF PBKDF PBKDF PBKDF PBKDF PBKDF PBKDF
Random number generationDRBGRandom number generationCounter DRBG:128, 192, 256 bits HMAC DRBG:128, 256 bits Hash DRBG:128, 256 bitsCounter DRBG HMAC DRBG Hash DRBG

Table 8: Security Function Implementations

2.7 Algorithm Specific Information
2.7.1 AES GCM IV

For TLS 1.2, the module offers the AES GCM implementation and uses the context of Scenario 1 of FIPS 140-3 IG C.H. The module is compliant with SP 800-52r2 Section

3.3.1 and the mechanism for IV generation is compliant with RFC 5288 and 8446.

The module does not implement the TLS protocol. The module’s implementation of AES GCM is used together with an application that runs outside the module’s cryptographic boundary. The design of the TLS protocol implicitly ensures that the counter (the nonce_explicit part of the IV) does not exhaust the maximum number of possible values for a given session key. In the event the module’s power is lost and restored, the consuming application must ensure that a new key for use with the AES GCM key encryption or decryption under this scenario shall be established. Alternatively, the Crypto Officer can use the module’s API to perform AES GCM encryption using internal IV generation. These IVs are always 96 bits and generated using the approved DRBG internal to the module’s boundary in compliance with Scenario 2 of IG C.H. The module also provides a non-approved AES GCM encryption service which accepts arbitrary external IVs from the operator. The service can be requested by invoking the EVP_EncryptInit_ex2 API function with a non-NULL iv value. When this is the case, the API will set a non-approved service indicator as described in Section 4.3. Finally, for TLS 1.3, the AES GCM implementation uses the context of Scenario 5 of FIPS 140-3 IG C.H. The protocol that provides this compliance is TLS 1.3, defined in © 2024 Canonical Ltd. / atsec information security.

Page 45

RFC8446 of August 2018, using the cipher-suites that explicitly select AES GCM as the encryption/decryption cipher (Appendix B.4 of RFC8446). The module supports acceptable AES GCM cipher suites from Section 3.3.1 of SP800-52r2. The module’s implementation of AES GCM is used together with an application that runs outside the module’s cryptographic boundary. The design of the TLS protocol implicitly ensures that the counter (the nonce_explicit part of the IV) does not exhaust the maximum number of possible values for a given session key

2.7.2 AES XTS

In accordance to FIPS 140-3 IG C.I, the module implements a check that ensures, before performing any cryptographic operation, that the two AES keys used in AES XTS mode are not identical. In addition, Section 4 of SP 800-38E states that the length of a single data unit encrypted or decrypted with AES XTS shall not exceed 2²⁰ AES blocks, that is 16MB, of data per XTS instance. The XTS mode shall only be used for the cryptographic protection of data on storage devices. It shall not be used for other purposes, such as the encryption of data in transit.

2.7.3 Key Derivation using SP 800-132 PBKDF2

The module provides password-based key derivation (PBKDF2), compliant with SP 800-132. The module supports option 1a from Section 5.4 of SP 800-132, in which the Master Key (MK) or a segment of it is used directly as the Data Protection Key (DPK). In accordance to SP 800-132 and FIPS 140-3 IG D.N, the following requirements shall be met:

Derived keys shall only be used in storage applications. The MK shall not be used for other purposes. The module accepts a minimum length of 112 bits for the MK or DPK .
Passwords or passphrases, used as an input for the PBKDF2, shall not be used as cryptographic keys.
The minimum length of the password or passphrase accepted by the module is 8 characters. Assuming the worst-case scenario of all digits, this results in the estimated probability of guessing the password to be at most 10 -8. Combined with the minimum iteration count as described below, this provides an acceptable trade-off between user experience and security against brute-force attacks.
A portion of the salt, with a length of at least 128 bits (this is verified by the module to determine the service is approved), shall be generated randomly using the SP 800-90Ar1 DRBG provided by the module.
The iteration count shall be selected as large as possible, as long as the time required to generate the key using the entered password is acceptable for the users. The module only allows minimum iteration count to be 1000. © 2024 Canonical Ltd. / atsec information security.
Page 46
CertVendor
NumberName
E62Canonical Ltd.
NameTypeOperational EnvironmentSample SizeEntropy per SampleConditioning Component
Canonical OpenSSL FIPS provider CPU Time Jitter Entropy source (version 2.2.0)Non- PhysicalUbuntu 22.04 on Supermicro SYS- 1019P-WTR with Intel Xeon Gold 6226; Ubuntu 22.04 on Amazon Web Services (AWS) c6g.metal with AWS Graviton2; Ubuntu 22.04 on IBM z15 with IBM z1564 bitsFull entropyAES-256-CTR- DRBG (A3814); AES-256-CTR- DRBG (A3970)
2.7.4 Compliance to SP 800-56Arev3 Assurances

The module offers DH and ECDH shared secret computation services compliant to the SP 800-56ARev3 and meeting IG D.F scenario 2 path (1). The key agreement schemes provided by the module are dhEphem and Unified Model, pertaining to the C(2e, 0s) schemes in section 6.1.2 . In order to meet the required assurances listed in section

5.6 of SP 800-56Arev3, the module shall be used together with an application that

implements the “TLS protocol” and the following steps shall be performed.

  1. The entity using the module, must use the module's "Key pair generation" service for generating DH/ECDH ephemeral keys. This meets the assurances required by key pair owner defined in the section 5.6.2.1 of SP 800-56ARev3.
  2. As part of the module's shared secret computation (SSC) service, the module internally performs the public key validation on the peer's public key passed in as input to the SSC function. This meets the public key validity assurance required by the sections 5.6.2.2.2 of SP 800-56ARev3.
  3. The module does not support static keys therefore the "assurance of peer's possession of private key" is not applicable.
2.7.5 Legacy Algorithms

The module utilizes the following legacy algorithms as defined in SP 800-131Arev2:

SHA-1 for RSA Signature Verification and ECDSA Signature Verification purposes.
RSA Signature Verification, under FIPS 186-4, allows verifying signatures with a bit size of 1024, along with the approved modulus sizes of 2048, 3072, and 4096 bits.
ECDSA Signature Verification, under FIPS 186-4, allows verifying elliptic curve- based signatures with curve P-192, in addition to the approved curves of P-224, P- 256, P-384, and P-521.
2.8 RBG and Entropy

Table 9: Entropy Certificates Table 10: Entropy Sources © 2024 Canonical Ltd. / atsec information security.

Page 47

The module employs two Deterministic Random Bit Generator (DRBG) implementations based on SP 800-90Ar1. These DRBGs are used internally by the module (e.g. to generate seeds for asymmetric key pairs and random numbers for security functions). They can also be accessed using the specified API functions. The following parameters are used:

  1. Private DRBG: AES-256 CTR_DRBG with derivation function. This DRBG is used to generate secret random values (e.g. during asymmetric key pair generation). It can be accessed using RAND_priv_bytes.
  2. Public DRBG: AES-256 CTR_DRBG with derivation function. This DRBG is used to generate general purpose random values that do not need to remain secret (e.g. initialization vectors). It can be accessed using RAND_bytes. The public and private DRBGs are seeded with 384 bits of entropy and 256 bits of entropy are used to reseed each of the private and public DRBGs. The highest SSP security strength generated by the module is 256 bits. These DRBGs will always employ prediction resistance. More information regarding the configuration and design of these DRBGs can be found in the module’s manual pages.
2.9 Key Generation

The module implements Cryptographic Key Generation (CKG, vendor affirmed), compliant with SP 800-133r2. When random values are required, they are obtained from the SP 800-90Ar1 approved DRBG, compliant with Section 4 of SP 800-133r2. This method does not use the value V as described in Additional Comment 2 of FIPS 140-3 IG D.H. The following methods are implemented:

Safe primes key pair generation: compliant with SP 800-133r2, Section 5.2, which maps to SP 800-56Ar3. The method described in Section 5.6.1.1.4 of SP 800-56Ar3 (“Testing Candidates”) is used.
RSA key pair generation: compliant with SP 800-133r2, Section 5.1, which maps to FIPS 186-4. The method described in Appendix B.3.6 of FIPS 186-4 (“Probable Primes with Conditions Based on Auxiliary Probable Primes”) is used.
ECC (ECDH and ECDSA) key pair generation: compliant with SP 800-133r2, Section 5.1, which maps to FIPS 186-4. The method described in Appendix B.4.2 of FIPS 186-4 (“Testing Candidates”) is used.

Intermediate key generation values are not output from the module and are explicitly zeroized after processing the service. Additionally, the module implements the following key derivation methods: • KBKDF: compliant with SP 800-108r1. This implementation can be used to derive secret keys from a pre-existing key-derivation-key. © 2024 Canonical Ltd. / atsec information security.

Page 48
KDA OneStep, HKDF: compliant with SP 800-56Cr2. These implementations shall only be used to derive secret keys in the context of an SP 800-56Ar3 key agreement scheme.
ANS X9.42 KDF (CVL), ANS X9.63 KDF (CVL): compliant with SP 800-135r1. These implementations shall only be used to derive secret keys in the context of an ANS X9.42-2001 resp. ANS X9.63- 2001 key agreement scheme.
SSH KDF (CVL), TLS 1.2 KDF (CVL), TLS 1.3 KDF (CVL): compliant with SP 800-135r1 and RFC 8446. These implementations shall only be used to derive secret keys in the context of the SSH, TLS 1.2, or TLS 1.3 protocols, respectively.
PBKDF2: compliant with option 1a of SP 800-132. This implementation shall only be used to derive keys for use in storage applications.
2.10 Key Establishment

The module implements SSP agreement and SSP transport methods as listed in the SFI table. The module provides Diffie-Hellman (DH) and Elliptic Curve Diffie-Hellman (ECDH) shared secret computation compliant with SP800-56Ar3, in accordance with scenario 2 (1) of FIPS 140-3 IG D.F. According to FIPS 140-3 IG D.B, for shared secret computation, the key sizes of DH provide 112-200 bits of security strength, while the key sizes of ECDH provide 112-

256 bits of security strength in Approved mode of operation.

The module also supports the AES KW and AES KWP key wrapping mechanisms compliant with IG D.G and SP 800-38F. These algorithms can be used to wrap SSPs with a security strength of 128, 192, or 256 bits, depending on the wrapping key size.

2.11 Industry Protocols

The module implements the SSH KDF (CVL) for use in the SSH protocol (RFC 4253 and RFC 6668). GCM with internal IV generation in the approved mode is compliant with versions 1.2 and 1.3 of the TLS protocol (RFC 5288 and 8446) and shall only be used in conjunction with the TLS protocol. Additionally, the module implements the TLS 1.2 and TLS 1.3 key derivation functions for use in the TLS protocol. For Diffie-Hellman, the module supports the use of the safe primes defined in RFC

3526 (IKE) and RFC 7919 (TLS). Note that the module only implements key pair

generation, key pair verification, and shared secret computation. No other part of the IKE or TLS protocols is implemented (with the exception of the TLS 1.2 KDF (CVL) and

1.3 KDF (CVL)):

• IKE (RFC 3526): MODP-2048 (ID = 14), MODP-3072 (ID = 15), MODP-4096 (ID = 16), MODP-6144 (ID = 17), MODP-8192 (ID = 18) © 2024 Canonical Ltd. / atsec information security.

Page 49

• TLS (RFC 7919): ffdhe2048 (ID = 256), ffdhe3072 (ID = 257), ffdhe4096 (ID = 258), ffdhe6144 (ID = 259), ffdhe8192 (ID = 260) For Elliptic Curve Diffie-Hellman, the module supports the NIST-defined P-224, P-256, P-384, and P-521 curves. No parts of the SSH, TLS, or IKE protocols, other than those mentioned above, have been tested by the CAVP or CMVP.

2.12 Additional Information

Not applicable. © 2024 Canonical Ltd. / atsec information security.

Page 50
Physical PortLogical Interface(s)Data That Passes
As a software-only module, the module does not have physical ports. Physical Ports are interpreted to be the physical ports of the hardware platform on which it runs.Data InputAPI input parameters
As a software-only module, the module does not have physical ports. Physical Ports are interpreted to be the physical ports of the hardware platform on which it runs.Data OutputAPI output parameters
As a software-only module, the module does not have physical ports. Physical Ports are interpreted to be the physical ports of the hardware platform on which it runs.Control InputAPI function calls
As a software-only module, the module does not have physical ports. Physical Ports are interpreted to be the physical ports of the hardware platform on which it runs.Status OutputAPI return codes, error queue
3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

Table 11: Ports and Interfaces The logical interfaces are the APIs through which the applications request services. These logical interfaces are logically separated from each other by the API design. The table above summarizes the logical interfaces.

3.2 Trusted Channel Specification

Not applicable. Not applicable.

3.4 Additional Information

Not applicable. © 2024 Canonical Ltd. / atsec information security.

Page 51
NameTypeOperator TypeAuthentication Methods
Crypto OfficerRoleCONone
NameDescript ionIndicatorInputsOutput sSecurity FunctionsSSP Access
Message digestComput e a message digestUBUNTU_OSSL_PROV_FIPS_PARAM_UNA PPROVED_USAGE returns 0Messag eMessag e digestMessage digestCrypto Officer
Symmetri c encryptio nEncrypt a plaintextUBUNTU_OSSL_PROV_FIPS_PARAM_UNA PPROVED_USAGE returns 0AES key, Plainte xtCiphert extSymmetri c encryptio nCrypto Officer - AES key: W,E
Symmetri c decryptio nDecrypt a cipherte xtUBUNTU_OSSL_PROV_FIPS_PARAM_UNA PPROVED_USAGE returns 0AES key, Ciphert extPlaintex tSymmetri c decryptio nCrypto Officer - AES key: W,E
Authentic ated symmetric encryptio nEncrypt and authenti cate a plaintextUBUNTU_OSSL_PROV_FIPS_PARAM_UNA PPROVED_USAGE returns 0AES key, Plainte xt, IVCiphert ext, MAC tagSymmetri c encryptio nCrypto Officer - AES key: W,E
Authentic ated symmetric decryptio nDecrypt and authenti cate a cipherte xtUBUNTU_OSSL_PROV_FIPS_PARAM_UNA PPROVED_USAGE returns 0AES key, Ciphert ext, MAC tagPlaintex t or FailureSymmetri c decryptio nCrypto Officer - AES key: W,E
Key wrappingPerform AES- based key wrappin gUBUNTU_OSSL_PROV_FIPS_PARAM_UNA PPROVED_USAGE returns 0AES key, Key to be wrappe dWrappe d keyKey wrappingCrypto Officer - AES key: W,E
4 Roles, Services, and Authentication
4.2 Roles

Table 12: Roles The module supports the Crypto Officer role only. This sole role is implicitly and always assumed by the operator of the module. No support is provided for a maintenance role.

4.3 Approved Services

g d © 2024 Canonical Ltd. / atsec information security.

Page 52
NameDescript ionIndicatorInputsOutput sSecurity FunctionsSSP Access
Key unwrappi ngPerform AES- based key unwrapp ingUBUNTU_OSSL_PROV_FIPS_PARAM_UNA PPROVED_USAGE returns 0AES key, Key to unwrapUnwrap ped keyKey unwrappi ngCrypto Officer - AES key: W,E
AES- based message authentic ation generatio nComput e a MAC tag using AESUBUNTU_OSSL_PROV_FIPS_PARAM_UNA PPROVED_USAGE returns 0AES key, Messag eMAC tagMessage authentic ationCrypto Officer - AES key: W,E
AES- based message authentic ation verificatio nVerify a MAC tag using AESUBUNTU_OSSL_PROV_FIPS_PARAM_UNA PPROVED_USAGE returns 0AES key, Messag e, MAC tagPass/fai lMessage authentic ationCrypto Officer - AES key: W,E
HMAC- based message authentic ation generatio nComput e a MAC tag using HMACUBUNTU_OSSL_PROV_FIPS_PARAM_UNA PPROVED_USAGE returns 0HMAC key, Messag eMAC tagMessage authentic ationCrypto Officer - HMAC key: W,E
HMAC- based message authentic ation verificatio nVerify a MAC tag using HMACUBUNTU_OSSL_PROV_FIPS_PARAM_UNA PPROVED_USAGE returns 0HMAC key, Messag e, MAC tagPass/fai lMessage authentic ationCrypto Officer - HMAC key: W,E
KMAC- based message authentic ation generatio nComput e a MAC tag using KMACUBUNTU_OSSL_PROV_FIPS_PARAM_UNA PPROVED_USAGE returns 0KMAC key, Messag eMAC tagMessage authentic ationCrypto Officer - KMAC key: W,E
KMAC- based message authentic ation verificatio nVerify MAC tag using KMACUBUNTU_OSSL_PROV_FIPS_PARAM_UNA PPROVED_USAGE returns 0KMAC key, Messag e, MAC tagPass/fai lMessage authentic ationCrypto Officer - KMAC key: W,E

n n n n n n © 2024 Canonical Ltd. / atsec information security.

Page 53
NameDescript ionIndicatorInputsOutput sSecurity FunctionsSSP Access
TLS-based key derivationTLS key derivatio nUBUNTU_OSSL_PROV_FIPS_PARAM_UNA PPROVED_USAGE returns 0Shared secretTLS Derived keyKey derivationCrypto Officer - Shared secret: W,E - TLS Derived key: G,R
Key-based key derivationDerive a key from a key- derivatio n keyUBUNTU_OSSL_PROV_FIPS_PARAM_UNA PPROVED_USAGE returns 0Key- derivati on keyKBKDF Derived keyKey derivationCrypto Officer - Key- derivatio n key: W,E - KBKDF Derived key: G,R
ANS X9.42 key derivationDerive a key from a shared secretUBUNTU_OSSL_PROV_FIPS_PARAM_UNA PPROVED_USAGE returns 0Shared secretANS X9.42 Derived keyKey derivationCrypto Officer - Shared secret: W,E - ANS X9.42 Derived key: G,R
ANS X9.63 key derivationDerive a key from a shared secretUBUNTU_OSSL_PROV_FIPS_PARAM_UNA PPROVED_USAGE returns 0Shared secretANS X9.63 Derived keyKey derivationCrypto Officer - Shared secret: W,E - ANS X9.63 Derived key: G,R
HKDF key derivationDerive a key from a shared secretUBUNTU_OSSL_PROV_FIPS_PARAM_UNA PPROVED_USAGE returns 0Shared secretHKDF Derived keyKey derivationCrypto Officer - Shared secret: W,E - HKDF Derived key: G,R
OneStep KDA key derivationDerive a key from a shared secretUBUNTU_OSSL_PROV_FIPS_PARAM_UNA PPROVED_USAGE returns 0Shared secretOneSte p KDA Derived keyKey derivationCrypto Officer - Shared secret: W,E - OneStep

W,E W,E W,E W,E W,E W,E © 2024 Canonical Ltd. / atsec information security.

Page 54
NameDescript ionIndicatorInputsOutput sSecurity FunctionsSSP Access KDA Derived key: G,R
SSH KDF key derivationDerive a key from a shared secretUBUNTU_OSSL_PROV_FIPS_PARAM_UNA PPROVED_USAGE returns 0Shared secretSSH KDF Derived keyKey derivationCrypto Officer - Shared secret: W,E - SSH KDF Derived key: G,R
Password- based key derivationDerive a key from a passwor dUBUNTU_OSSL_PROV_FIPS_PARAM_UNA PPROVED_USAGE returns 0Passwo rdPBKDF Derived keyPassword- based key derivationCrypto Officer - Passwor d: W,E,Z - PBKDF Derived key: G,R
Random number generatio nGenerat e random numberUBUNTU_OSSL_PROV_FIPS_PARAM_UNA PPROVED_USAGE returns 0Numbe r of bitsRandom numberRandom number generatio nCrypto Officer - Entropy input: W,E - DRBG Internal state (V, Key): G,W,E - DRBG Internal state (V, C): G,W,E - DRBG seed: G,W,E
Diffie- Hellman shared secret computati onComput e a shared secretUBUNTU_OSSL_PROV_FIPS_PARAM_UNA PPROVED_USAGE returns 0DH private key (owner) , DH public key (peer)Shared secretShared secret computati onCrypto Officer - DH private key: W,E - DH public key: W,E - Shared secret: G,R
EC Diffie- HellmanComput e aUBUNTU_OSSL_PROV_FIPS_PARAM_UNA PPROVED_USAGE returns 0EC privateShared secretShared secretCrypto Officer

W,E d d: W,E,Z W,E G,W,E C): G,W,E G,W,E G,R © 2024 Canonical Ltd. / atsec information security.

Page 55
Name shared secret computati onDescript ion shared secretIndicatorInputs key (owner) , EC public key (peer)Output sSecurity Functions computati onSSP Access - EC private key: W,E - EC public key: W,E - Shared secret: G,R
RSA Digital signature generatio nGenerat e a digital signatur e with RSAUBUNTU_OSSL_PROV_FIPS_PARAM_UNA PPROVED_USAGE returns 0RSA private key, Messag e, Hash algorith mSignatu reDigital signature generatio nCrypto Officer - RSA private key: W,E
ECDSA digital signature generatio nGenerat e a digital signatur e with ECDSAUBUNTU_OSSL_PROV_FIPS_PARAM_UNA PPROVED_USAGE returns 0EC private key, Messag e, Hash algorith mSignatu reDigital signature generatio nCrypto Officer - EC private key: W,E
RSA Digital signature verificatio nVerify a digital signatur e using RSAUBUNTU_OSSL_PROV_FIPS_PARAM_UNA PPROVED_USAGE returns 0RSA public key, Messag e, Signatu re, Hash algorith mPass or FailDigital signature verificatio nCrypto Officer - RSA public key: W,E
ECDSA digital signature verificatio nVerify a digital signatur e using RSAUBUNTU_OSSL_PROV_FIPS_PARAM_UNA PPROVED_USAGE returns 0EC public key, Messag e, Signatu re, Hash algorith mPass or FailDigital signature verificatio nCrypto Officer - EC public key: W,E
RSA key pair generatio nGenerat e an RSA key pairUBUNTU_OSSL_PROV_FIPS_PARAM_UNA PPROVED_USAGE returns 0Key lengthRSA private key, RSA public keyKey pair generatio nCrypto Officer - RSA private key: G,R - RSA public

G,R m m m m © 2024 Canonical Ltd. / atsec information security.

Page 56
NameDescript ionIndicatorInputsOutput sSecurity FunctionsSSP Access key: G,R - Intermed iate key generati on value: G,E,Z
ECDSA key pair generatio nGenerat e an EC key pairUBUNTU_OSSL_PROV_FIPS_PARAM_UNA PPROVED_USAGE returns 0Key lengthEC private key, EC public keyKey pair generatio nCrypto Officer - EC private key: G,R - EC public key: G,R - Intermed iate key generati on value: G,E,Z
Safe primes key pair generatio nGenerat e an DH key pairUBUNTU_OSSL_PROV_FIPS_PARAM_UNA PPROVED_USAGE returns 0GroupDH private key, DH public keyKey pair generatio nCrypto Officer - DH private key: G,R - DH public key: G,R - Intermed iate key generati on value: G,E,Z
ECDSA key pair verificatio nVerify an EC key pairUBUNTU_OSSL_PROV_FIPS_PARAM_UNA PPROVED_USAGE returns 0EC private key, EC public keyPass or FailKey pair verificatio nCrypto Officer - EC private key: E,W - EC public key: E,W
Safe prime key pair verificatio nVerify a DH key pairUBUNTU_OSSL_PROV_FIPS_PARAM_UNA PPROVED_USAGE returns 0DH private key, DH public keyPass or FailKey pair verificatio nCrypto Officer - DH private key: E,W - DH public key: E,W

G,E,Z G,E,Z G,E,Z © 2024 Canonical Ltd. / atsec information security.

Page 57
NameDescript ionIndicatorInputsOutput sSecurity FunctionsSSP Access
Show versionReturn the name and version informat ionUBUNTU_OSSL_PROV_FIPS_PARAM_UNA PPROVED_USAGE returns 0NoneModule name and versionNoneCrypto Officer
Show statusReturn the module statusUBUNTU_OSSL_PROV_FIPS_PARAM_UNA PPROVED_USAGE returns 0NoneModule statusNoneCrypto Officer
Self-testPerform the CASTs and integrity testNoneNonePass or Fail of self- testsNoneCrypto Officer
Zeroizatio nZeroize any SSPNoneAn SSPNoneNoneCrypto Officer - AES key: Z - HMAC key: Z - KMAC key: Z - Key- derivatio n key: Z - Shared secret: Z - Passwor d: Z - PBKDF Derived key: Z - KBKDF Derived key: Z - ANS X9.42 Derived key: Z - ANS X9.63 Derived key: Z - HKDF Derived key: Z -

d: Z © 2024 Canonical Ltd. / atsec information security.

Page 58

Name

Descript ion

Indicator

Inputs

Output s

Security Functions

SSP Access OneStep KDA Derived key: Z - TLS Derived key: Z - Entropy input: Z - DRBG Internal state (V, Key): Z - DRBG Internal state (V, C): Z - DRBG seed: Z - DH private key: Z - DH public key: Z - EC private key: Z - EC public key: Z - RSA private key: Z - RSA public key: Z - Intermed iate key generati on value: Z

C): Z Z Table 13: Approved Services The module provides services to operators that assume the available role. All services are described in detail in the API documentation (manual pages). The Approved Services table and the Non-Approved Services table define the services that utilize approved and non-approved security functions in this module. For the respective tables, the convention below applies when specifying the access permissions (types) that the service has for each SSP. © 2024 Canonical Ltd. / atsec information security.

Page 59
NameDescriptionAlgorithmsRole
EncryptionAES GCM (external IV)AES GCM (external IV)CO
DSAKey pair generation; Key pair verification; Signature generation; Signature verificationDSACO
ECDSA with curve P- 192Key pair generationECDSA with curve P- 192CO
RSA and ECDSA (pre- hashed message)Signature generation (pre-hashed message); Signature verification (pre-hashed message)RSA and ECDSA (pre- hashed message)CO
RSA X9.31Signature generation; Signature verificationRSA X9.31CO
RSA primitiveAsymmetric encryption; Asymmetric decryptionRSA primitiveCO
RSA-OAEPAsymmetric encryption; Asymmetric decryptionRSA-OAEPCO
RSASVESecret value encapsulation; Secret value decapsulationRSASVECO
Generate (G): The module generates or derives the SSP.
Read (R): The SSP is read from the module (e.g., the SSP is output).
Write (W): The SSP is updated, imported, or written to the module.
Execute(E): The module uses the SSP in performing a cryptographic operation.
Zeroize (Z): The module zeroizes the SSP.
N/A: The module does not access any SSP or key during its operation.

To interact with the module, a calling application must use the EVP API layer provided by OpenSSL. This layer will delegate the request to the FIPS provider, which will in turn perform the requested service. Additionally, this EVP API layer can be used to retrieve the approved service indicator for the module. The cryptographic module provides an approved service indicator in the form of an OpenSSL provider gettable parameter called UBUNTU_OSSL_PROV_FIPS_PARAM_UNAPPROVED_USAGE. This parameter will be equal to 0 if the requested service is an approved security service, otherwise it will be set to 1. The operator is responsible to query the value of such gettable parameter after calling the requested service.

4.4 Non-Approved Services

Table 14: Non-Approved Services The table above lists the non-approved services in this module, the algorithms involved, the roles that can request the service. In this table, CO specifies the Crypto Officer role.

4.5 External Software/Firmware Loaded

The module does not have the capability of loading software or firmware from an external source.

4.6 Bypass Actions and Status

Not applicable. © 2024 Canonical Ltd. / atsec information security.

Page 60
4.7 Cryptographic Output Actions and Status
4.8 Additional Information

Not applicable. © 2024 Canonical Ltd. / atsec information security.

Page 61
5 Software/Firmware Security
5.1 Integrity Techniques

The integrity of the module is verified by comparing a HMAC-SHA2-256 value calculated at run time with the HMAC-SHA2-256 value embedded in the fips.so file that was computed at build time.

5.2 Initiate on Demand

Integrity tests are performed as part of the pre-operational self-tests, which are executed when the module is initialized. The integrity test may be invoked on-demand by unloading and subsequently re-initializing the module, or by calling the OSSL_PROVIDER_self_test function. This will perform (among others) the software integrity test.

5.3 Open-Source Parameters
5.4 Additional Information

Not applicable. © 2024 Canonical Ltd. / atsec information security.

Page 62
6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Modifiable How Requirements are Satisfied: The module shall be installed as stated in Section 11. If properly installed, the operating system provides process isolation and memory protection mechanisms that ensure appropriate separation for memory access among the processes on the system. Each process has control over its own data and uncontrolled access to the data of other processes is prevented.

6.2 Configuration Settings and Restrictions

Instrumentation tools like the ptrace system call, gdb and strace, userspace live patching, as well as other tracing mechanisms offered by the Linux environment such as ftrace or systemtap, shall not be used in the operational environment. The use of any of these tools implies that the cryptographic module is running in a non-validated operational environment.

6.3 Additional Information

There are no concurrent operators. © 2024 Canonical Ltd. / atsec information security.

Page 63

Temp/Voltage Type LowTemperature HighTemperature LowVoltage HighVoltage

Temperature or Voltage

EFP or EFT

Result

Temperature Type LowTemperature HighTemperature

Temperature

7 Physical Security

The module is comprised of software only, and therefore this section is not applicable.

7.1 Mechanisms and Actions Required
7.2 User Placed Tamper Seals

Number: Not applicable. Placement: Not applicable. Surface Preparation: Not applicable. Operator Responsible for Securing Unused Seals: Not applicable. Part Numbers: Not applicable.

7.3 Filler Panels
7.4 Fault Induction Mitigation

Not applicable. Table 15: EFP/EFT Information Not applicable.

7.6 Hardness Testing Temperature Ranges

Table 16: Hardness Testing Temperatures Not applicable. © 2024 Canonical Ltd. / atsec information security.

Page 64
7.7 Additional Information

Not applicable. © 2024 Canonical Ltd. / atsec information security.

Page 65
8 Non-Invasive Security
8.1 Mitigation Techniques

This module does not implement any non-invasive security mechanism, and therefore this section is not applicable.

8.2 Effectiveness
8.3 Additional Information

Not applicable. © 2024 Canonical Ltd. / atsec information security.

Page 66
Storage Area NameDescriptionPersistence Type
RAMTemporary storage for SSPs used by the module as part of service execution. The module does not perform persistent storage of SSPsDynamic

Name API input parameters API output parameters

From Operator calling application (TOEPP) Cryptographic module

To Cryptographic module Operator calling application (TOEPP)

Format Type Plaintext Plaintext

Distribution Type Manual Manual

Entry Type Electronic Electronic

SFI or Algorithm

Zeroization MethodDescriptionRationaleOperator Initiation
Free cipher handleZeroizes the SSPs contained within the cipher handle: EVP_CIPHER_CTX_free() clears and frees symmetric cipher context, EVP_MAC_CTX_free() clears and frees MAC context, EVP_KDF_CTX_free() clears and frees KDF context, EVP_RAND_CTX_free() clears and frees DRBG context, EVP_PKEY_free() clears and frees asymetric key pair structuresMemory occupied by SSPs is overwritten with zeroes and then it is released, which renders the SSP values irretrievable. The completion of the zeroization routine indicates that the zeroization procedure succeededBy calling the cipher related zeroization API
9 Sensitive Security Parameters Management
9.1 Storage Areas

Table 17: Storage Areas Table 18: SSP Input-Output Methods running on the same operational environment. This corresponds to manual distribution, electronic entry/output (“CM Software to/from App via TOEPP Path”) per FIPS 140-3 IG 9.5.A Table 1. There is no entry or output of cryptographically protected SSPs can be entered into the module via API input parameters, when required by a immediately after generation of the SSP (see Section 9.2). © 2024 Canonical Ltd. / atsec information security.

Page 67
Zeroization MethodDescriptionRationaleOperator Initiation
AutomaticAutomatically zeroized by the module when no longer neededMemory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable.N/A
Module resetDe-allocates the volatile memory used to store SSPsVolatile memory used by the module is overwritten within nanoseconds when power is removed.By unloading and reloading the module

Name AES key HMAC key KMAC key Key- derivation key Shared secret Password PBKDF Derived key

Description Used for encryption, decryption, and message authentication Used for hash- based message authentication Used for message authentication Used for key derivation Generated by shared secret computation and used for key derivation Used for password- based key derivation Generated from password-

Size - Strength 128, 192, 256 bits - 128, 192, 256 bits 112-524288 bits - 112-256 bits 128-1024 bits - 128-256 bits 112-4096 bits - 112-256 bits 224-8192 bits - 112-256 bits At least 8 characters - N/A 112-256 bits - 112-256 bits

Type - Category Symmetric key - CSP Symmetric key - CSP Symmetric key - CSP Symmetric key - CSP Shared secret - CSP Password - CSP Symmetric key - CSP

Generated By Key derivation

Established By Shared secret computation

Used By Symmetric encryption Symmetric decryption Message authentication Message authentication Message authentication Key derivation Key derivation Password- based key derivation Key derivation

Table 19: SSP Zeroization Methods system calls. The operator is responsible for calling the appropriate destruction functions provided in the module's API. The destruction functions, listed above, the regular memory de-allocation operating system call. All data output is inhibited during zeroization. © 2024 Canonical Ltd. / atsec information security.

Page 68

Name KBKDF Derived key ANS X9.42 Derived key ANS X9.63 Derived key HKDF Derived key OneStep KDA Derived key TLS Derived key Entropy input DRBG Internal state (V, Key) DRBG Internal state (V, C) DRBG seed

Description based key derivation Generated from key-based key derivation Generated from ANS X9.42 key derivation Generated from ANS X9.63 key derivation Generated from HKDF key derivation Generated from OneStep KDA key derivation Generated by TLS-based key derivation Used for random number generation and seeding a DRBG (compliant with IG D.L) Used for random number generation (compliant with IG D.L) Used for random number generation (compliant with IG D.L) Used for random number generation

Size - Strength 112-256 bits - 112-256 bits 112-256 bits - 112-256 bits 112-256 bits - 112-256 bits 112-256 bits - 112-256 bits 112-256 bits - 112-256 bits 112-256 bits - 112-256 bits 128-384 bits - 128-256 bits CTR_DRBG: 256, 320, 348 bits; HMAC_DRBG: 320, 512, 1024 bits - CTR_DRBG: 128, 192, 256 bits; HMAC_DRBG: 128, 256 bits 880, 1776 bits - 128, 256 bits 128-256 bits - 128-256 bits

Type - Category Symmetric key - CSP Symmetric key - CSP Symmetric key - CSP Symmetric key - CSP Symmetric key - CSP Symmetric key - CSP Entropy Input - CSP Internal state - CSP Internal state - CSP Seed - CSP

Generated By Key derivation Key derivation Key derivation Key derivation Key derivation Key derivation Random number generation Random number generation Random number generation

Established By

Used By Key derivation Key derivation Key derivation Key derivation Key derivation Key derivation Random number generation Random number generation Random number generation Random number generation

© 2024 Canonical Ltd. / atsec information security.

Page 69

Name DH private key DH public key EC private key EC public key RSA private key RSA public key Intermediate key generation value SSH KDF Derived key

Description (compliant with IG D.L) Used for shared secret computation and key pair verification Used for shared secret computation and key pair verification Used for shared secret computation, digital signature generation, and key pair verification Used for shared secret computation, signature verification, and key pair verification Used for signature generation Used for signature verification Used for key pair generation Generated from SSH KDF key derivation

Size - Strength 2048-8192 bits - 112-200 bits 2048-8192 bits - 112-200 bits P-224, P-256, P- 384, P-521, K- 233, K-283, K- 409, K-571, B- 233, B- 283, B- 409, B-571 bits - 112, 128, 192, 256 bits P-192, P-224, P- 256, P-384, P- 521, K-163, K- 233, K-283, K- 409, K-571, B- 163, B-233, B- 283, B-409, B- 571 bits - 96, 112, 128, 192, 256 bits 2048-16384 bits - 112-256 bits 1024-16384 bits - 80-256 bits 112-16384 bits - 112-256 bits 112-256 bits - 112-256 bits

Type - Category Private key - CSP Public key - PSP Private key - CSP Public key - PSP Private key - CSP Public key - PSP intermediate key generation value - CSP Symmetric key - CSP

Generated By Key pair generation Key pair generation Key pair generation Key pair generation Key pair generation Key pair generation Key pair generation Key derivation

Established By

Used By Shared secret computation Key pair verification Shared secret computation Key pair verification Digital signature generation Shared secret computation Key pair verification Digital signature verification Shared secret computation Key pair verification Digital signature generation Digital signature verification Key pair generation

Table 20: SSP Table 1 © 2024 Canonical Ltd. / atsec information security.

Page 70
Name AES key HMAC key KMAC keyInput - Output API input parameters API input parameters API input parametersStorage RAM:Plaintext RAM:Plaintext RAM:PlaintextStorage Duration From service invocation to service completion From service invocation to service completion From service invocation to service completionZeroization Free cipher handle Module reset Free cipher handle Module reset Free cipher handle Module resetRelated SSPs
Key-derivation keyAPI input parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetKBKDF Derived key:Derives
Shared secretAPI input parameters API output parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetDH private key:Generated From DH public key:Generated From EC private key:Generated From EC public key:Generated From OneStep KDA Derived key:Derives HKDF Derived key:Derives ANS X9.42 Derived key:Derives ANS X9.63 Derived key:Derives TLS Derived key:Derives SSH KDF Derived key:Derives
PasswordAPI input parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetPKBDF Derived key:Derives
PBKDF Derived keyAPI output parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetPassword:Derived From
KBKDF Derived keyAPI output parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetKey derivation key:Derived From

© 2024 Canonical Ltd. / atsec information security.

Page 71
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
ANS X9.42 Derived keyAPI output parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetShared secret:Derived From
ANS X9.63 Derived keyAPI output parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetShared secret:Derived From
HKDF Derived keyAPI output parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetShared secret:Derived From
OneStep KDA Derived keyAPI output parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetShared secret:Derived From
TLS Derived keyAPI output parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetShared secret:Derived From
Entropy inputRAM:PlaintextFrom service invocation to service completionAutomatic Module resetDRBG seed:Generates
DRBG Internal state (V, Key)RAM:PlaintextFrom DRBG instantiation to un- instantiation or internal zeroizationFree cipher handle Module resetDRBG seed:Generated From
DRBG Internal state (V, C)RAM:PlaintextFrom DRBG instantiation to un- instantiation or internal zeroizationFree cipher handle Module resetDRBG seed:Generated From
DRBG seedRAM:PlaintextFrom service invocation to service completionAutomatic Module resetDRBG Internal state (V, Key):Generates DRBG Internal state (V, C):Generates
DH private keyAPI input parameters API output parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetDH public key:Paired With Intermediate key generation value:Generated From Shared secret:Generates
DH public keyAPI input parameters API output parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetDH private key:Paired With Intermediate key generation value:Generated From Shared secret:Generates

© 2024 Canonical Ltd. / atsec information security.

Page 72
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
EC private keyAPI input parameters API output parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetEC public key:Paired With Intermediate key generation value:Generated By Shared secret:Generates
EC public keyAPI input parameters API output parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetEC private key:Paired With Intermediate key generation value:Generated By Shared secret:Generates
RSA private keyAPI input parameters API output parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetRSA public key:Paired With Intermediate key generation value:Generated By
RSA public keyAPI input parameters API output parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetRSA private key:Paired With Intermediate key generation value:Generated From
Intermediate key generation valueRAM:PlaintextFrom service invocation to service completionAutomaticRSA private key:Generates EC private key:Generates DH private key:Generates RSA public key:Generates EC public key:Generates DH public key:Generates
SSH KDF Derived keyAPI output parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetShared secret:Derived From

Table 21: SSP Table 2 The tables above summarize the Sensitive Security Parameters (SSPs) that are used by the cryptographic services implemented in the module in the approved services (Approved Services table). SSPs, including CSPs, are directly imported as input parameters and exported as output parameters from the module. Because these SSPs are only transiently used for a specific service, they are, by definition, exclusive between approved and nonapproved services. © 2024 Canonical Ltd. / atsec information security.

Page 73
9.5 Transitions

The SHA-1 algorithm, as implemented by the module, will be non-approved for all purposes starting January 1, 2030. The RSA algorithm as implemented by the module conforms to FIPS 186-4, which has been superseded by FIPS 186-5. FIPS 186-4 has been withdrawn since February 3, 2024.

9.6 Additional Information

Not applicable. © 2024 Canonical Ltd. / atsec information security.

Page 74
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
HMAC-SHA2- 256 (A3962)256-bit keyMessage AuthenticationSW/FW IntegrityModule becomes operational and services are available for useIntegrity test for fips.so
HMAC-SHA2- 256 (A3963)256-bit keyMessage AuthenticationSW/FW IntegrityModule becomes operational and services are available for useIntegrity test for fips.so
HMAC-SHA2- 256 (A3977)256-bit keyMessage AuthenticationSW/FW IntegrityModule becomes operational and services are available for useIntegrity test for fips.so
HMAC-SHA2- 256 (A3983)256-bit keyMessage AuthenticationSW/FW IntegrityModule becomes operational and services are available for useIntegrity test for fips.so
HMAC-SHA2- 256 (A3993)256-bit keyMessage AuthenticationSW/FW IntegrityModule becomes operational and services are available for useIntegrity test for fips.so
HMAC-SHA2- 256 (A4003)256-bit keyMessage AuthenticationSW/FW IntegrityModule becomes operational and services are available for useIntegrity test for fips.so
HMAC-SHA2- 256 (A4004)256-bit keyMessage AuthenticationSW/FW IntegrityModule becomes operational and services are available for useIntegrity test for fips.so
HMAC-SHA2- 256 (A4005)256-bit keyMessage AuthenticationSW/FW IntegrityModule becomes operational and services are available for useIntegrity test for fips.so
10 Self-Tests
10.1 Pre-Operational Self-Tests

Table 22: Pre-Operational Self-Tests The module performs pre-operational tests automatically when the module is powered on. The pre-operational self-tests ensure that the module is not corrupted. The module transitions to the operational state only after the pre-operational selftests are passed successfully. The integrity of the shared library component of the module is verified by comparing an HMAC-SHA2-256 value calculated at run time with the corresponding HMAC value embedded in the fips.so file that was computed at build time. If the software integrity test fails, the module transitions to the error state (Section 10.3). The HMAC and SHA2-256 algorithms go through their respective CASTs before the software integrity test is performed. © 2024 Canonical Ltd. / atsec information security.

Page 75
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
SHA-1 (A3962)24-bit messageKATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA-1 (A3977)24-bit messageKATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA-1 (A3983)24-bit messageKATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA-1 (A3993)24-bit messageKATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA-1 (A4003)24-bit messageKATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA-1 (A4004)24-bit messageKATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA-1 (A4005)24-bit messageKATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA2-512 (A3962)24-bit messageKATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA2-512 (A3977)24-bit messageKATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA2-512 (A3983)24-bit messageKATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA2-512 (A3993)24-bit messageKATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
10.2 Conditional Self-Tests

© 2024 Canonical Ltd. / atsec information security.

Page 76
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
SHA2-512 (A4003)24-bit messageKATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA2-512 (A4004)24-bit messageKATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA2-512 (A4005)24-bit messageKATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA3-256 (A3964)32-bit messageKATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA3-256 (A3972)32-bit messageKATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
SHA3-256 (A3979)32-bit messageKATCASTModule becomes operationalMessage digestTest runs at power-on before the integrity test
AES-GCM (A3961)Encrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A3974)Encrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A3975)Encrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A3976)Encrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A3988)Encrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A3989)Encrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test

© 2024 Canonical Ltd. / atsec information security.

Page 77
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-GCM (A3990)Encrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A3994)Encrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A3995)Encrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A3996)Encrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A3997)Encrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A3998)Encrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A3999)Encrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A4000)Encrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A4001)Encrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A4002)Encrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A3961)Decrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A3974)Decrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test

© 2024 Canonical Ltd. / atsec information security.

Page 78
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-GCM (A3975)Decrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A3976)Decrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A3988)Decrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A3989)Decrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A3990)Decrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A3994)Decrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A3995)Decrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A3996)Decrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A3997)Decrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A3998)Decrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A3999)Decrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A4000)Decrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test

© 2024 Canonical Ltd. / atsec information security.

Page 79
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-GCM (A4001)Decrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A4002)Decrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-ECB (A3958)Decrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-ECB (A3959)Decrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-ECB (A3960)Decrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-ECB (A3971)Decrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-ECB (A3973)Decrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-ECB (A3978)Decrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-ECB (A3980)Decrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-ECB (A3981)Decrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-ECB (A3982)Decrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-ECB (A3984)Decrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test

© 2024 Canonical Ltd. / atsec information security.

Page 80
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-ECB (A3985)Decrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-ECB (A3986)Decrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
AES-ECB (A3987)Decrypt with 256-bit keyKATCASTModule becomes operationalSymmetric operationTest runs at power-on before the integrity test
KDF SP800- 108 (A3991)HMAC-SHA2-256 in counter modeKATCASTModule becomes operationalKey based key derivationTest runs at power-on before the integrity test
KDA OneStep SP800-56Cr2 (A3965)SHA2-224KATCASTModule becomes operationalShared secret key derivationTest runs at power-on before the integrity test
KDA HKDF Sp800-56Cr1 (A3969)SHA2-256KATCASTModule becomes operationalShared secret key derivationTest runs at power-on before the integrity test
KDF ANS 9.42 (A3962)SHA-1KATCASTModule becomes operationalIndustry-based ANS X9.42 key derivationTest runs at power-on before the integrity test
KDF ANS 9.42 (A3964)SHA-1KATCASTModule becomes operationalIndustry-based ANS X9.42 key derivationTest runs at power-on before the integrity test
KDF ANS 9.42 (A3972)SHA-1KATCASTModule becomes operationalIndustry-based ANS X9.42 key derivationTest runs at power-on before the integrity test
KDF ANS 9.42 (A3977)SHA-1KATCASTModule becomes operationalIndustry-based ANS X9.42 key derivationTest runs at power-on before the integrity test
KDF ANS 9.42 (A3979)SHA-1KATCASTModule becomes operationalIndustry-based ANS X9.42 key derivationTest runs at power-on before the integrity test
KDF ANS 9.42 (A3983)SHA-1KATCASTModule becomes operationalIndustry-based ANS X9.42 key derivationTest runs at power-on before the integrity test

© 2024 Canonical Ltd. / atsec information security.

Page 81
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
KDF ANS 9.42 (A3993)SHA-1KATCASTModule becomes operationalIndustry-based ANS X9.42 key derivationTest runs at power-on before the integrity test
KDF ANS 9.42 (A4003)SHA-1KATCASTModule becomes operationalIndustry-based ANS X9.42 key derivationTest runs at power-on before the integrity test
KDF ANS 9.42 (A4004)SHA-1KATCASTModule becomes operationalIndustry-based ANS X9.42 key derivationTest runs at power-on before the integrity test
KDF ANS 9.42 (A4005)SHA-1KATCASTModule becomes operationalIndustry-based ANS X9.42 key derivationTest runs at power-on before the integrity test
KDF ANS 9.63 (A3962)SHA2-256KATCASTModule becomes operationalIndustry-based ANS X9.63 key derivationTest runs at power-on before the integrity test
KDF ANS 9.63 (A3977)SHA2-256KATCASTModule becomes operationalIndustry-based ANS X9.63 key derivationTest runs at power-on before the integrity test
KDF ANS 9.63 (A3983)SHA2-256KATCASTModule becomes operationalIndustry-based ANS X9.63 key derivationTest runs at power-on before the integrity test
KDF ANS 9.63 (A3993)SHA2-256KATCASTModule becomes operationalIndustry-based ANS X9.63 key derivationTest runs at power-on before the integrity test
KDF ANS 9.63 (A4003)SHA2-256KATCASTModule becomes operationalIndustry-based ANS X9.63 key derivationTest runs at power-on before the integrity test
KDF ANS 9.63 (A4004)SHA2-256KATCASTModule becomes operationalIndustry-based ANS X9.63 key derivationTest runs at power-on before the integrity test
KDF ANS 9.63 (A4005)SHA2-256KATCASTModule becomes operationalIndustry-based ANS X9.63 key derivationTest runs at power-on before the integrity test
KDF SSH (A3971)SHA-1KATCASTModule becomes operationalIndustry-based SSH KDF key derivationTest runs at power-on before the integrity test

© 2024 Canonical Ltd. / atsec information security.

Page 82
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
KDF SSH (A3978)SHA-1KATCASTModule becomes operationalIndustry-based SSH KDF key derivationTest runs at power-on before the integrity test
KDF SSH (A3984)SHA-1KATCASTModule becomes operationalIndustry-based SSH KDF key derivationTest runs at power-on before the integrity test
KDF SSH (A3985)SHA-1KATCASTModule becomes operationalIndustry-based SSH KDF key derivationTest runs at power-on before the integrity test
KDF SSH (A3986)SHA-1KATCASTModule becomes operationalIndustry-based SSH KDF key derivationTest runs at power-on before the integrity test
KDF SSH (A3987)SHA-1KATCASTModule becomes operationalIndustry-based SSH KDF key derivationTest runs at power-on before the integrity test
TLS v1.2 KDF RFC7627 (A3962)SHA2-256KATCASTModule becomes operationalIndustry-based TLS v1.2 KDF key derivationTest runs at power-on before the integrity test
TLS v1.2 KDF RFC7627 (A3977)SHA2-256KATCASTModule becomes operationalIndustry-based TLS v1.2 KDF key derivationTest runs at power-on before the integrity test
TLS v1.2 KDF RFC7627 (A3983)SHA2-256KATCASTModule becomes operationalIndustry-based TLS v1.2 KDF key derivationTest runs at power-on before the integrity test
TLS v1.2 KDF RFC7627 (A3993)SHA2-256KATCASTModule becomes operationalIndustry-based TLS v1.2 KDF key derivationTest runs at power-on before the integrity test
TLS v1.2 KDF RFC7627 (A4003)SHA2-256KATCASTModule becomes operationalIndustry-based TLS v1.2 KDF key derivationTest runs at power-on before the integrity test
TLS v1.2 KDF RFC7627 (A4004)SHA2-256KATCASTModule becomes operationalIndustry-based TLS v1.2 KDF key derivationTest runs at power-on before the integrity test
TLS v1.2 KDF RFC7627 (A4005)SHA2-256KATCASTModule becomes operationalIndustry-based TLS v1.2 KDF key derivationTest runs at power-on before the integrity test

© 2024 Canonical Ltd. / atsec information security.

Page 83
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
TLS v1.3 KDF (A3969)SHA2-256KATCASTModule becomes operationalIndustry-based TLS v1.3 KDF key derivationTest runs at power-on before the integrity test
PBKDF (A3962)SHA2-256 with 4096 iterations and 288- bit saltKATCASTModule becomes operationalPassword-based key derivationTest runs at power-on before the integrity test
PBKDF (A3964)SHA2-256 with 4096 iterations and 288- bit saltKATCASTModule becomes operationalPassword-based key derivationTest runs at power-on before the integrity test
PBKDF (A3972)SHA2-256 with 4096 iterations and 288- bit saltKATCASTModule becomes operationalPassword-based key derivationTest runs at power-on before the integrity test
PBKDF (A3977)SHA2-256 with 4096 iterations and 288- bit saltKATCASTModule becomes operationalPassword-based key derivationTest runs at power-on before the integrity test
PBKDF (A3979)SHA2-256 with 4096 iterations and 288- bit saltKATCASTModule becomes operationalPassword-based key derivationTest runs at power-on before the integrity test
PBKDF (A3983)SHA2-256 with 4096 iterations and 288- bit saltKATCASTModule becomes operationalPassword-based key derivationTest runs at power-on before the integrity test
PBKDF (A3993)SHA2-256 with 4096 iterations and 288- bit saltKATCASTModule becomes operationalPassword-based key derivationTest runs at power-on before the integrity test
PBKDF (A4003)SHA2-256 with 4096 iterations and 288- bit saltKATCASTModule becomes operationalPassword-based key derivationTest runs at power-on before the integrity test
PBKDF (A4004)SHA2-256 with 4096 iterations and 288- bit saltKATCASTModule becomes operationalPassword-based key derivationTest runs at power-on before the integrity test
PBKDF (A4005)SHA2-256 with 4096 iterations and 288- bit saltKATCASTModule becomes operationalPassword-based key derivationTest runs at power-on before the integrity test
Counter DRBG (A3970)AES-128 with derivation function and prediction resistanceKATCASTModule becomes operationalCompliant with SP 800-90Ar1Test runs at power-on before the integrity test

© 2024 Canonical Ltd. / atsec information security.

Page 84
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
HMAC DRBG (A3970)HMAC-SHA-1 with prediction resistanceKATCASTModule becomes operationalCompliant with SP 800-90Ar1Test runs at power-on before the integrity test
KAS-FFC-SSC Sp800-56Ar3 (A3992)ffdhe2048KATCASTModule becomes operationalShared secret computationTest runs at power-on before the integrity test
KAS-ECC-SSC Sp800-56Ar3 (A3962)P-256KATCASTModule becomes operationalShared secret computationTest runs at power-on before the integrity test
KAS-ECC-SSC Sp800-56Ar3 (A3968)P-256KATCASTModule becomes operationalShared secret computationTest runs at power-on before the integrity test
KAS-ECC-SSC Sp800-56Ar3 (A3977)P-256KATCASTModule becomes operationalShared secret computationTest runs at power-on before the integrity test
KAS-ECC-SSC Sp800-56Ar3 (A3983)P-256KATCASTModule becomes operationalShared secret computationTest runs at power-on before the integrity test
KAS-ECC-SSC Sp800-56Ar3 (A3993)P-256KATCASTModule becomes operationalShared secret computationTest runs at power-on before the integrity test
KAS-ECC-SSC Sp800-56Ar3 (A4003)P-256KATCASTModule becomes operationalShared secret computationTest runs at power-on before the integrity test
KAS-ECC-SSC Sp800-56Ar3 (A4004)P-256KATCASTModule becomes operationalShared secret computationTest runs at power-on before the integrity test
KAS-ECC-SSC Sp800-56Ar3 (A4005)P-256KATCASTModule becomes operationalShared secret computationTest runs at power-on before the integrity test
HMAC-SHA3- 512 (A3964)SHA3-512KATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test
HMAC-SHA3- 512 (A3972)SHA3-512KATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test

© 2024 Canonical Ltd. / atsec information security.

Page 85
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
HMAC-SHA3- 512 (A3979)SHA3-512KATCASTModule becomes operationalMessage authenticationTest runs at power-on before the integrity test
RSA SigGen (FIPS186-4) (A3962)PKCS#1 v1.5 with SHA2-256 and 2048- bit keyKATCASTModule becomes operationalDigital signature generationTest runs at power-on before the integrity test
RSA SigGen (FIPS186-4) (A3977)PKCS#1 v1.5 with SHA2-256 and 2048- bit keyKATCASTModule becomes operationalDigital signature generationTest runs at power-on before the integrity test
RSA SigGen (FIPS186-4) (A3983)PKCS#1 v1.5 with SHA2-256 and 2048- bit keyKATCASTModule becomes operationalDigital signature generationTest runs at power-on before the integrity test
RSA SigGen (FIPS186-4) (A3993)PKCS#1 v1.5 with SHA2-256 and 2048- bit keyKATCASTModule becomes operationalDigital signature generationTest runs at power-on before the integrity test
RSA SigGen (FIPS186-4) (A4003)PKCS#1 v1.5 with SHA2-256 and 2048- bit keyKATCASTModule becomes operationalDigital signature generationTest runs at power-on before the integrity test
RSA SigGen (FIPS186-4) (A4004)PKCS#1 v1.5 with SHA2-256 and 2048- bit keyKATCASTModule becomes operationalDigital signature generationTest runs at power-on before the integrity test
RSA SigGen (FIPS186-4) (A4005)PKCS#1 v1.5 with SHA2-256 and 2048- bit keyKATCASTModule becomes operationalDigital signature generationTest runs at power-on before the integrity test
RSA SigVer (FIPS186-4) (A3962)PKCS#1 v1.5 with SHA2-256 and 2048- bit keyKATCASTModule becomes operationalDigital signature verificationTest runs at power-on before the integrity test
RSA SigVer (FIPS186-4) (A3977)PKCS#1 v1.5 with SHA2-256 and 2048- bit keyKATCASTModule becomes operationalDigital signature verificationTest runs at power-on before the integrity test
RSA SigVer (FIPS186-4) (A3983)PKCS#1 v1.5 with SHA2-256 and 2048- bit keyKATCASTModule becomes operationalDigital signature verificationTest runs at power-on before the integrity test
RSA SigVer (FIPS186-4) (A3993)PKCS#1 v1.5 with SHA2-256 and 2048- bit keyKATCASTModule becomes operationalDigital signature verificationTest runs at power-on before the integrity test

© 2024 Canonical Ltd. / atsec information security.

Page 86
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
RSA SigVer (FIPS186-4) (A4003)PKCS#1 v1.5 with SHA2-256 and 2048- bit keyKATCASTModule becomes operationalDigital signature verificationTest runs at power-on before the integrity test
RSA SigVer (FIPS186-4) (A4004)PKCS#1 v1.5 with SHA2-256 and 2048- bit keyKATCASTModule becomes operationalDigital signature verificationTest runs at power-on before the integrity test
RSA SigVer (FIPS186-4) (A4005)PKCS#1 v1.5 with SHA2-256 and 2048- bit keyKATCASTModule becomes operationalDigital signature verificationTest runs at power-on before the integrity test
ECDSA SigGen (FIPS186-4) (A3962)Curves P-224, B-233 with SHA2-256KATCASTModule becomes operationalDigital signature generationTest runs at power-on before the integrity test
ECDSA SigGen (FIPS186-4) (A3964)Curves P-224, B-233 with SHA2-256KATCASTModule becomes operationalDigital signature generationTest runs at power-on before the integrity test
ECDSA SigGen (FIPS186-4) (A3966)Curves P-224, B-233 with SHA2-256KATCASTModule becomes operationalDigital signature generationTest runs at power-on before the integrity test
ECDSA SigGen (FIPS186-4) (A3967)Curves P-224, B-233 with SHA2-256KATCASTModule becomes operationalDigital signature generationTest runs at power-on before the integrity test
ECDSA SigGen (FIPS186-4) (A3972)Curves P-224, B-233 with SHA2-256KATCASTModule becomes operationalDigital signature generationTest runs at power-on before the integrity test
ECDSA SigGen (FIPS186-4) (A3977)Curves P-224, B-233 with SHA2-256KATCASTModule becomes operationalDigital signature generationTest runs at power-on before the integrity test
ECDSA SigGen (FIPS186-4) (A3979)Curves P-224, B-233 with SHA2-256KATCASTModule becomes operationalDigital signature generationTest runs at power-on before the integrity test
ECDSA SigGen (FIPS186-4) (A3983)Curves P-224, B-233 with SHA2-256KATCASTModule becomes operationalDigital signature generationTest runs at power-on before the integrity test
ECDSA SigGen (FIPS186-4) (A3993)Curves P-224, B-233 with SHA2-256KATCASTModule becomes operationalDigital signature generationTest runs at power-on before the integrity test

© 2024 Canonical Ltd. / atsec information security.

Page 87
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
ECDSA SigGen (FIPS186-4) (A4003)Curves P-224, B-233 with SHA2-256KATCASTModule becomes operationalDigital signature generationTest runs at power-on before the integrity test
ECDSA SigGen (FIPS186-4) (A4004)Curves P-224, B-233 with SHA2-256KATCASTModule becomes operationalDigital signature generationTest runs at power-on before the integrity test
ECDSA SigGen (FIPS186-4) (A4005)Curves P-224, B-233 with SHA2-256KATCASTModule becomes operationalDigital signature generationTest runs at power-on before the integrity test
ECDSA SigVer (FIPS186-4) (A3962)Curves P-224, B-233 with SHA2-256KATCASTModule becomes operationalDigital signature verificationTest runs at power-on before the integrity test
ECDSA SigVer (FIPS186-4) (A3964)Curves P-224, B-233 with SHA2-256KATCASTModule becomes operationalDigital signature verificationTest runs at power-on before the integrity test
ECDSA SigVer (FIPS186-4) (A3966)Curves P-224, B-233 with SHA2-256KATCASTModule becomes operationalDigital signature verificationTest runs at power-on before the integrity test
ECDSA SigVer (FIPS186-4) (A3967)Curves P-224, B-233 with SHA2-256KATCASTModule becomes operationalDigital signature verificationTest runs at power-on before the integrity test
ECDSA SigVer (FIPS186-4) (A3972)Curves P-224, B-233 with SHA2-256KATCASTModule becomes operationalDigital signature verificationTest runs at power-on before the integrity test
ECDSA SigVer (FIPS186-4) (A3977)Curves P-224, B-233 with SHA2-256KATCASTModule becomes operationalDigital signature verificationTest runs at power-on before the integrity test
ECDSA SigVer (FIPS186-4) (A3979)Curves P-224, B-233 with SHA2-256KATCASTModule becomes operationalDigital signature verificationTest runs at power-on before the integrity test
ECDSA SigVer (FIPS186-4) (A3983)Curves P-224, B-233 with SHA2-256KATCASTModule becomes operationalDigital signature verificationTest runs at power-on before the integrity test
ECDSA SigVer (FIPS186-4) (A3993)Curves P-224, B-233 with SHA2-256KATCASTModule becomes operationalDigital signature verificationTest runs at power-on before the integrity test

© 2024 Canonical Ltd. / atsec information security.

Page 88
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
ECDSA SigVer (FIPS186-4) (A4003)Curves P-224, B-233 with SHA2-256KATCASTModule becomes operationalDigital signature verificationTest runs at power-on before the integrity test
ECDSA SigVer (FIPS186-4) (A4004)Curves P-224, B-233 with SHA2-256KATCASTModule becomes operationalDigital signature verificationTest runs at power-on before the integrity test
ECDSA SigVer (FIPS186-4) (A4005)Curves P-224, B-233 with SHA2-256KATCASTModule becomes operationalDigital signature verificationTest runs at power-on before the integrity test
Safe Primes Key Generation (A3992)SHA-1 password length 24 characters, master key length of 200 bits, iteration count of 4096, and salt length of 288 bitsPCTPCTSuccessful key pair generationPublic key re- computation and comparison with the existing public key per SP800-56Arev3, section 5.6.2.1.4Key pair generation
RSA KeyGen (FIPS186-4) (A3962)PKCS#1 v1.5 with SHA2-256PCTPCTSuccessful key pair generationGeneration of an RSA key pairKey pair generation
RSA KeyGen (FIPS186-4) (A3977)PKCS#1 v1.5 with SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
RSA KeyGen (FIPS186-4) (A3983)PKCS#1 v1.5 with SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
RSA KeyGen (FIPS186-4) (A3993)PKCS#1 v1.5 with SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
RSA KeyGen (FIPS186-4) (A4003)PKCS#1 v1.5 with SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
RSA KeyGen (FIPS186-4) (A4004)PKCS#1 v1.5 with SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
RSA KeyGen (FIPS186-4) (A4005)PKCS#1 v1.5 with SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
ECDSA KeyGen (FIPS186-4) (A3962)SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
ECDSA KeyGen (FIPS186-4) (A3966)SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation

© 2024 Canonical Ltd. / atsec information security.

Page 89
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
ECDSA KeyGen (FIPS186-4) (A3977)SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
ECDSA KeyGen (FIPS186-4) (A3983)SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
ECDSA KeyGen (FIPS186-4) (A3993)SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
ECDSA KeyGen (FIPS186-4) (A4003)SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
ECDSA KeyGen (FIPS186-4) (A4004)SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
ECDSA KeyGen (FIPS186-4) (A4005)SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2-256 (A3962)Message AuthenticationSW/FW IntegrityOn demandManually
HMAC-SHA2-256 (A3963)Message AuthenticationSW/FW IntegrityOn demandManually
HMAC-SHA2-256 (A3977)Message AuthenticationSW/FW IntegrityOn demandManually
HMAC-SHA2-256 (A3983)Message AuthenticationSW/FW IntegrityOn demandManually
HMAC-SHA2-256 (A3993)Message AuthenticationSW/FW IntegrityOn demandManually

Table 23: Conditional Self-Tests The module performs self-tests on all approved cryptographic algorithms as part of the approved services supported in the approved mode of operation, using the tests shown in the table above. The CASTs can be performed on demand by unloading and re-initializing the module. Data output through the data output interface is inhibited during the self-tests. If any of these tests fails, the module transitions to the error state.

10.3 Periodic Self-Test Information

© 2024 Canonical Ltd. / atsec information security.

Page 90
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2-256 (A4003)Message AuthenticationSW/FW IntegrityOn demandManually
HMAC-SHA2-256 (A4004)Message AuthenticationSW/FW IntegrityOn demandManually
HMAC-SHA2-256 (A4005)Message AuthenticationSW/FW IntegrityOn demandManually
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
SHA-1 (A3962)KATCASTOn DemandManually
SHA-1 (A3977)KATCASTOn DemandManually
SHA-1 (A3983)KATCASTOn DemandManually
SHA-1 (A3993)KATCASTOn DemandManually
SHA-1 (A4003)KATCASTOn DemandManually
SHA-1 (A4004)KATCASTOn DemandManually
SHA-1 (A4005)KATCASTOn DemandManually
SHA2-512 (A3962)KATCASTOn DemandManually
SHA2-512 (A3977)KATCASTOn DemandManually
SHA2-512 (A3983)KATCASTOn DemandManually
SHA2-512 (A3993)KATCASTOn DemandManually
SHA2-512 (A4003)KATCASTOn DemandManually
SHA2-512 (A4004)KATCASTOn DemandManually
SHA2-512 (A4005)KATCASTOn DemandManually
SHA3-256 (A3964)KATCASTOn DemandManually
SHA3-256 (A3972)KATCASTOn DemandManually
SHA3-256 (A3979)KATCASTOn DemandManually
AES-GCM (A3961)KATCASTOn DemandManually
AES-GCM (A3974)KATCASTOn DemandManually
AES-GCM (A3975)KATCASTOn DemandManually
AES-GCM (A3976)KATCASTOn DemandManually
AES-GCM (A3988)KATCASTOn DemandManually
AES-GCM (A3989)KATCASTOn DemandManually
AES-GCM (A3990)KATCASTOn DemandManually
AES-GCM (A3994)KATCASTOn DemandManually
AES-GCM (A3995)KATCASTOn DemandManually
AES-GCM (A3996)KATCASTOn DemandManually
AES-GCM (A3997)KATCASTOn DemandManually
AES-GCM (A3998)KATCASTOn DemandManually
AES-GCM (A3999)KATCASTOn DemandManually
AES-GCM (A4000)KATCASTOn DemandManually
AES-GCM (A4001)KATCASTOn DemandManually
AES-GCM (A4002)KATCASTOn DemandManually

Table 24: Pre-Operational Periodic Information © 2024 Canonical Ltd. / atsec information security.

Page 91
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-GCM (A3961)KATCASTOn DemandManually
AES-GCM (A3974)KATCASTOn DemandManually
AES-GCM (A3975)KATCASTOn DemandManually
AES-GCM (A3976)KATCASTOn DemandManually
AES-GCM (A3988)KATCASTOn DemandManually
AES-GCM (A3989)KATCASTOn DemandManually
AES-GCM (A3990)KATCASTOn DemandManually
AES-GCM (A3994)KATCASTOn DemandManually
AES-GCM (A3995)KATCASTOn DemandManually
AES-GCM (A3996)KATCASTOn DemandManually
AES-GCM (A3997)KATCASTOn DemandManually
AES-GCM (A3998)KATCASTOn DemandManually
AES-GCM (A3999)KATCASTOn DemandManually
AES-GCM (A4000)KATCASTOn DemandManually
AES-GCM (A4001)KATCASTOn DemandManually
AES-GCM (A4002)KATCASTOn DemandManually
AES-ECB (A3958)KATCASTOn DemandManually
AES-ECB (A3959)KATCASTOn DemandManually
AES-ECB (A3960)KATCASTOn DemandManually
AES-ECB (A3971)KATCASTOn DemandManually
AES-ECB (A3973)KATCASTOn DemandManually
AES-ECB (A3978)KATCASTOn DemandManually
AES-ECB (A3980)KATCASTOn DemandManually
AES-ECB (A3981)KATCASTOn DemandManually
AES-ECB (A3982)KATCASTOn DemandManually
AES-ECB (A3984)KATCASTOn DemandManually
AES-ECB (A3985)KATCASTOn DemandManually
AES-ECB (A3986)KATCASTOn DemandManually
AES-ECB (A3987)KATCASTOn DemandManually
KDF SP800-108 (A3991)KATCASTOn DemandManually
KDA OneStep SP800-56Cr2 (A3965)KATCASTOn DemandManually
KDA HKDF Sp800- 56Cr1 (A3969)KATCASTOn DemandManually
KDF ANS 9.42 (A3962)KATCASTOn DemandManually
KDF ANS 9.42 (A3964)KATCASTOn DemandManually
KDF ANS 9.42 (A3972)KATCASTOn DemandManually

© 2024 Canonical Ltd. / atsec information security.

Page 92
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
KDF ANS 9.42 (A3977)KATCASTOn DemandManually
KDF ANS 9.42 (A3979)KATCASTOn DemandManually
KDF ANS 9.42 (A3983)KATCASTOn DemandManually
KDF ANS 9.42 (A3993)KATCASTOn DemandManually
KDF ANS 9.42 (A4003)KATCASTOn DemandManually
KDF ANS 9.42 (A4004)KATCASTOn DemandManually
KDF ANS 9.42 (A4005)KATCASTOn DemandManually
KDF ANS 9.63 (A3962)KATCASTOn DemandManually
KDF ANS 9.63 (A3977)KATCASTOn DemandManually
KDF ANS 9.63 (A3983)KATCASTOn DemandManually
KDF ANS 9.63 (A3993)KATCASTOn DemandManually
KDF ANS 9.63 (A4003)KATCASTOn DemandManually
KDF ANS 9.63 (A4004)KATCASTOn DemandManually
KDF ANS 9.63 (A4005)KATCASTOn DemandManually
KDF SSH (A3971)KATCASTOn DemandManually
KDF SSH (A3978)KATCASTOn DemandManually
KDF SSH (A3984)KATCASTOn DemandManually
KDF SSH (A3985)KATCASTOn DemandManually
KDF SSH (A3986)KATCASTOn DemandManually
KDF SSH (A3987)KATCASTOn DemandManually
TLS v1.2 KDF RFC7627 (A3962)KATCASTOn DemandManually
TLS v1.2 KDF RFC7627 (A3977)KATCASTOn DemandManually
TLS v1.2 KDF RFC7627 (A3983)KATCASTOn DemandManually
TLS v1.2 KDF RFC7627 (A3993)KATCASTOn DemandManually
TLS v1.2 KDF RFC7627 (A4003)KATCASTOn DemandManually

© 2024 Canonical Ltd. / atsec information security.

Page 93
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
TLS v1.2 KDF RFC7627 (A4004)KATCASTOn DemandManually
TLS v1.2 KDF RFC7627 (A4005)KATCASTOn DemandManually
TLS v1.3 KDF (A3969)KATCASTOn DemandManually
PBKDF (A3962)KATCASTOn DemandManually
PBKDF (A3964)KATCASTOn DemandManually
PBKDF (A3972)KATCASTOn DemandManually
PBKDF (A3977)KATCASTOn DemandManually
PBKDF (A3979)KATCASTOn DemandManually
PBKDF (A3983)KATCASTOn DemandManually
PBKDF (A3993)KATCASTOn DemandManually
PBKDF (A4003)KATCASTOn DemandManually
PBKDF (A4004)KATCASTOn DemandManually
PBKDF (A4005)KATCASTOn DemandManually
Counter DRBG (A3970)KATCASTOn DemandManually
HMAC DRBG (A3970)KATCASTOn DemandManually
KAS-FFC-SSC Sp800-56Ar3 (A3992)KATCASTOn DemandManually
KAS-ECC-SSC Sp800-56Ar3 (A3962)KATCASTOn DemandManually
KAS-ECC-SSC Sp800-56Ar3 (A3968)KATCASTOn DemandManually
KAS-ECC-SSC Sp800-56Ar3 (A3977)KATCASTOn DemandManually
KAS-ECC-SSC Sp800-56Ar3 (A3983)KATCASTOn DemandManually
KAS-ECC-SSC Sp800-56Ar3 (A3993)KATCASTOn DemandManually
KAS-ECC-SSC Sp800-56Ar3 (A4003)KATCASTOn DemandManually
KAS-ECC-SSC Sp800-56Ar3 (A4004)KATCASTOn DemandManually

© 2024 Canonical Ltd. / atsec information security.

Page 94
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
KAS-ECC-SSC Sp800-56Ar3 (A4005)KATCASTOn DemandManually
HMAC-SHA3-512 (A3964)KATCASTOn DemandManually
HMAC-SHA3-512 (A3972)KATCASTOn DemandManually
HMAC-SHA3-512 (A3979)KATCASTOn DemandManually
RSA SigGen (FIPS186-4) (A3962)KATCASTOn DemandManually
RSA SigGen (FIPS186-4) (A3977)KATCASTOn DemandManually
RSA SigGen (FIPS186-4) (A3983)KATCASTOn DemandManually
RSA SigGen (FIPS186-4) (A3993)KATCASTOn DemandManually
RSA SigGen (FIPS186-4) (A4003)KATCASTOn DemandManually
RSA SigGen (FIPS186-4) (A4004)KATCASTOn DemandManually
RSA SigGen (FIPS186-4) (A4005)KATCASTOn DemandManually
RSA SigVer (FIPS186-4) (A3962)KATCASTOn DemandManually
RSA SigVer (FIPS186-4) (A3977)KATCASTOn DemandManually
RSA SigVer (FIPS186-4) (A3983)KATCASTOn DemandManually
RSA SigVer (FIPS186-4) (A3993)KATCASTOn DemandManually
RSA SigVer (FIPS186-4) (A4003)KATCASTOn DemandManually
RSA SigVer (FIPS186-4) (A4004)KATCASTOn DemandManually
RSA SigVer (FIPS186-4) (A4005)KATCASTOn DemandManually
ECDSA SigGen (FIPS186-4) (A3962)KATCASTOn DemandManually
ECDSA SigGen (FIPS186-4) (A3964)KATCASTOn DemandManually
ECDSA SigGen (FIPS186-4) (A3966)KATCASTOn DemandManually
ECDSA SigGen (FIPS186-4) (A3967)KATCASTOn DemandManually

© 2024 Canonical Ltd. / atsec information security.

Page 95
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
ECDSA SigGen (FIPS186-4) (A3972)KATCASTOn DemandManually
ECDSA SigGen (FIPS186-4) (A3977)KATCASTOn DemandManually
ECDSA SigGen (FIPS186-4) (A3979)KATCASTOn DemandManually
ECDSA SigGen (FIPS186-4) (A3983)KATCASTOn DemandManually
ECDSA SigGen (FIPS186-4) (A3993)KATCASTOn DemandManually
ECDSA SigGen (FIPS186-4) (A4003)KATCASTOn DemandManually
ECDSA SigGen (FIPS186-4) (A4004)KATCASTOn DemandManually
ECDSA SigGen (FIPS186-4) (A4005)KATCASTOn DemandManually
ECDSA SigVer (FIPS186-4) (A3962)KATCASTOn DemandManually
ECDSA SigVer (FIPS186-4) (A3964)KATCASTOn DemandManually
ECDSA SigVer (FIPS186-4) (A3966)KATCASTOn DemandManually
ECDSA SigVer (FIPS186-4) (A3967)KATCASTOn DemandManually
ECDSA SigVer (FIPS186-4) (A3972)KATCASTOn DemandManually
ECDSA SigVer (FIPS186-4) (A3977)KATCASTOn DemandManually
ECDSA SigVer (FIPS186-4) (A3979)KATCASTOn DemandManually
ECDSA SigVer (FIPS186-4) (A3983)KATCASTOn DemandManually
ECDSA SigVer (FIPS186-4) (A3993)KATCASTOn DemandManually
ECDSA SigVer (FIPS186-4) (A4003)KATCASTOn DemandManually
ECDSA SigVer (FIPS186-4) (A4004)KATCASTOn DemandManually
ECDSA SigVer (FIPS186-4) (A4005)KATCASTOn DemandManually
Safe Primes Key Generation (A3992)PCTPCTOn DemandManually
RSA KeyGen (FIPS186-4) (A3962)PCTPCTOn DemandManually
RSA KeyGen (FIPS186-4) (A3977)PCTPCTOn DemandManually

© 2024 Canonical Ltd. / atsec information security.

Page 96
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
RSA KeyGen (FIPS186-4) (A3983)PCTPCTOn DemandManually
RSA KeyGen (FIPS186-4) (A3993)PCTPCTOn DemandManually
RSA KeyGen (FIPS186-4) (A4003)PCTPCTOn DemandManually
RSA KeyGen (FIPS186-4) (A4004)PCTPCTOn DemandManually
RSA KeyGen (FIPS186-4) (A4005)PCTPCTOn DemandManually
ECDSA KeyGen (FIPS186-4) (A3962)PCTPCTOn DemandManually
ECDSA KeyGen (FIPS186-4) (A3966)PCTPCTOn DemandManually
ECDSA KeyGen (FIPS186-4) (A3977)PCTPCTOn DemandManually
ECDSA KeyGen (FIPS186-4) (A3983)PCTPCTOn DemandManually
ECDSA KeyGen (FIPS186-4) (A3993)PCTPCTOn DemandManually
ECDSA KeyGen (FIPS186-4) (A4003)PCTPCTOn DemandManually
ECDSA KeyGen (FIPS186-4) (A4004)PCTPCTOn DemandManually
ECDSA KeyGen (FIPS186-4) (A4005)PCTPCTOn DemandManually
NameDescriptionConditionsRecovery MethodIndicator
ErrorThe module immediately stops functioningSoftware integrity test failure CAST failure PCT failureRe-initialization of the moduleModule will not load; Module is aborted for PCT failure

Table 25: Conditional Periodic Information The module does not implement periodic self-tests.

10.4 Error States

Table 26: Error States If the module fails any of the self-tests, the module enters the error state. In the error state, the module immediately stops functioning and ends the application process. Consequently, the data output interface is inhibited, and the module accepts no more inputs or requests (as the module is no longer running). Regarding the PCT failure, an OSSL_PROV_PARAM_STATUS parameter can be queried from the FIPS provider to check the status of the cryptographic module. © 2024 Canonical Ltd. / atsec information security.

Page 97

The table above lists the error states and the status indicator values that explain the error that has occurred.

10.5 Operator Initiation of Self-Tests

The software integrity tests and cryptographic algorithm self-tests can be invoked on demand by resetting the module or by invoking the OSSL_PROVIDER_self_test method. The pair-wise consistency tests can be invoked on demand by requesting the key pair generation service.

10.6 Additional Information

Not applicable. © 2024 Canonical Ltd. / atsec information security.

Page 98
11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

The binaries of the FIPS validated module are contained in the following Ubuntu packages for delivery:

openssl-fips-module-3_3.0.5-0ubuntu0.1+Fips2.1_amd64.deb for X86_64
openssl-fips-module-3_3.0.5-0ubuntu0.1+Fips2.1_arm64.deb for ARM64
openssl-fips-module-3_3.0.5-0ubuntu0.1+Fips2.1_s390x.deb for s390x

Once the operating environment is configured following the instructions provided, the Crypto Officer can install the Ubuntu packages containing the module listed below - Ubuntu packages using the Advanced Package Tool (APT) with the following command: $ sudo apt-get install openssl-fips-module-3 All the Ubuntu packages are associated with hashes for integrity check. The integrity of the Ubuntu package is automatically verified by the packing tool during the installation of the module. The Crypto Officer shall not install the package if the integrity fails. After the openssl-fips-module-3 package is installed, the Crypto Officer must execute the openssl list -providers command. The Crypto Officer must ensure that the FIPS provider is listed in the output as follows: fips name: Ubuntu 22.04 OpenSSL Cryptographic Module version: 3.0.5-0ubuntu0.1+Fips2.1 status: active The cryptographic boundary consists only of the FIPS provider as listed. If any other OpenSSL or third-party provider is invoked, the user is not interacting with the module specified in this Security Policy. After, the module needs to be set to run in the FIPS validated configuration. This can be enabled automatically via the Ubuntu Advantage tool after attaching your subscription. (1) To install the tool type the following commands: $ sudo apt update $ sudo apt install ubuntu-advantage-tools (2) To activate the Ubuntu Pro subscription run: $ sudo pro attach <your_pro_token> (3) To enable Approved mode run: © 2024 Canonical Ltd. / atsec information security.

Page 99

$ sudo pro enable fips (4) To verify that Approved mode is enabled run: $ sudo pro status The pro client will install the necessary packages for the Approved mode, including the kernel and the bootloader. After this step you MUST reboot to put the system into Approved mode. The reboot will boot into FIPS supported kernel and create the /proc/sys/crypto/fips_enabled entry which tells the FIPS certified modules to run in Approved mode. If you do not reboot after installing and configuring the bootloader, Approved mode is not yet enabled. To verify that FIPS is enabled after the reboot check the /proc/sys/crypto/fips_enabled file and ensure it is set to 1. If it is set to 0, the FIPS modules will not run in Approved mode. If the file is missing, the FIPS kernel is not installed, you can verify that FIPS has been properly enabled with the pro status command.

11.2 Administrator Guidance

The Crypto Officer shall follow this Security Policy to configure the operational environment and install the module to be operated as a FIPS 140-3 validated module. In addition, the Crypto Officer shall consider the following requirements and restrictions provided in Section 2.7 when using the module.

11.3 Non-Administrator Guidance

There is no non-administrator guidance.

11.4 Design and Rules
11.5 Maintenance Requirements
11.6 End of Life

As the module does not persistently store SSPs, secure sanitization of the module consists of unloading the module. This will zeroize all SSPs in volatile memory. Then, if desired, the Ubuntu packages can be uninstalled from the Ubuntu 22.04 system.

11.7 Additional Information

Not applicable. © 2024 Canonical Ltd. / atsec information security.

Page 100
12 Mitigation of Other Attacks
12.1 Attack List

Certain cryptographic subroutines and algorithms are vulnerable to timing analysis. The module mitigates this vulnerability by using constant-time implementations. This includes, but is not limited to:

Big number operations: computing GCDs, modular inversion, multiplication, division, and modular exponentiation (using Montgomery multiplication).
Elliptic curve point arithmetic: addition and multiplication (using the Montgomery ladder).
Vector-based AES implementations.
12.2 Mitigation Effectiveness

RSA, ECDSA, ECDH, and DH employ blinding techniques to further impede timing and power analysis.

12.3 Guidance and Constraints

No configuration is needed to enable the aforementioned countermeasures.

12.4 Additional Information

Not applicable. © 2024 Canonical Ltd. / atsec information security.

Page 101

Appendix A. Glossary and Abbreviations

AESAdvanced Encryption Standard
AES-NIAdvanced Encryption Standard New Instructions
APIApplication Programming Interface
CASTCryptographic Algorithm Self-Test
CAVPCryptographic Algorithm Validation Program
CBCCipher Block Chaining
CCMCounter with Cipher Block Chaining-Message Authentication Code
CFBCipher Feedback
CKGCryptographic Key Generation
CMACCipher-based Message Authentication Code
CMVPCryptographic Module Validation Program
CPACFCP Assist for Cryptographic Functions
CSPCritical Security Parameter
CTRCounter
CTSCiphertext Stealing
DHDiffie-Hellman
DRBGDeterministic Random Bit Generator
ECBElectronic Code Book
ECCElliptic Curve Cryptography
ECDHElliptic Curve Diffie-Hellman
ECDSAElliptic Curve Digital Signature Algorithm

ENT (NP) Non-physical Entropy Source

EVPEnvelope
FFCFinite Field Cryptography
FIPSFederal Information Processing Standards
GCMGalois Counter Mode
GMACGalois Counter Mode Message Authentication Code
HKDFHMAC-based Key Derivation Function
HMACKeyed-Hash Message Authentication Code © 2024 Canonical Ltd. / atsec information security.
Page 102
IKEInternet Key Exchange
KASKey Agreement Scheme
KATKnown Answer Test
KBKDFKey-based Key Derivation Function
KMACKECCAK Message Authentication Code
KWKey Wrap
KWPKey Wrap with Padding
MACMessage Authentication Code
NISTNational Institute of Science and Technology
OAEPOptimal Asymmetric Encryption Padding
OFBOutput Feedback
PAAProcessor Algorithm Acceleration
PCTPair-wise Consistency Test

PBKDF2 Password-based Key Derivation Function v2

PKCSPublic-Key Cryptography Standards
PSSProbabilistic Signature Scheme
RSADPRSA Decryption Primitive
RSAEPRSA Encryption Primitive
RSARivest, Shamir, Addleman
SHASecure Hash Algorithm
SSCShared Secret Computation
SSHSecure Shell
SSPSensitive Security Parameter
TLSTransport Layer Security
XOFExtendable Output Function
XTSXEX-based Tweaked-codebook mode with cipher text Stealing © 2024 Canonical Ltd. / atsec information security.
Page 103

Appendix B. References ANS X9.42-2001 Public Key Cryptography for the Financial Services Industry: Agreement of Symmetric Keys Using Discrete Logarithm Cryptography 2001 https://webstore.ansi.org/standards/ascx9/ansix9422001 ANS X9.63-2001 Public Key Cryptography for the Financial Services Industry, Key Agreement and Key Transport Using Elliptic Curve Cryptography 2001 https://webstore.ansi.org/standards/ascx9/ansix9632001

FIPS 140-3FIPS PUB 140-3 - Security Requirements For Cryptographic Modules March 2019 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-3.pdf
FIPS 140-3 IGImplementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program https://csrc.nist.gov/Projects/cryptographic-module-validation-program/fips-140-3- ig-announcements
FIPS 180-4Secure Hash Standard (SHS) March 2012 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf
FIPS 186-4Digital Signature Standard (DSS) February 2023 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-4.pdf
FIPS 197Advanced Encryption Standard November 2001 https://csrc.nist.gov/publications/fips/fips197/fips-197.pdf
FIPS 198-1The Keyed Hash Message Authentication Code (HMAC) July 2008 https://csrc.nist.gov/publications/fips/fips198-1/FIPS-198-1_final.pdf
FIPS 202SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions August 2015 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.202.pdf
PKCS#1Public Key Cryptography Standards (PKCS) #1: RSA Cryptography Specifications Version 2.1 February 2003 http://www.ietf.org/rfc/rfc3447.txt
RFC 3526More Modular Exponential (MODP) Diffie-Hellman groups for Internet Key Exchange (IKE) May 2003 https://www.ietf.org/rfc/rfc3526.txt
RFC 5288AES Galois Counter Mode (GCM) Cipher Suites for TLS August 2008 https://www.ietf.org/rfc/rfc5288.txt
RFC 7919Negotiated Finite Field Diffie-Hellman Ephemeral Parameters for Transport Layer Security (TLS) August 2016 https://www.ietf.org/rfc/rfc7919.txt © 2024 Canonical Ltd. / atsec information security.
Page 104
RFC 8446The Transport Layer Security (TLS) Protocol Version 1.3 August 2018 https://www.ietf.org/rfc/rfc8446.txt
SP 800-38ARecommendation for Block Cipher Modes of Operation Methods and Techniques December 2001 https://csrc.nist.gov/publications/nistpubs/800-38a/sp800-38a.pdf
SP 800-38ARecommendation for Block Cipher Modes of Operation: Three Variants of
AddendumCiphertext Stealing for CBC Mode October 2010 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38a-add.pdf
SP 800-38BRecommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication May 2005 https://csrc.nist.gov/publications/nistpubs/800-38B/SP_800-38B.pdf
SP 800-38CRecommendation for Block Cipher Modes of Operation: the CCM Mode for Authentication and Confidentiality May 2004 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38c.pdf
SP 800-38DRecommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC November 2007 https://csrc.nist.gov/publications/nistpubs/800-38D/SP-800-38D.pdf
SP 800-38ERecommendation for Block Cipher Modes of Operation: The XTS AES Mode for Confidentiality on Storage Devices January 2010 https://csrc.nist.gov/publications/nistpubs/800-38E/nist-sp-800-38E.pdf
SP 800-38FRecommendation for Block Cipher Modes of Operation: Methods for Key Wrapping December 2012 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38F.pdf
SP 800-52r2Guidelines for the Selection, Configuration, and Use of Transport Layer Security (TLS) Implementations August 2019 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-52r2.pdf
SP 800-56Ar3Recommendation for Pair-Wise Key Establishment Schemes Using Discrete Logarithm Cryptography April 2018 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Ar3.pdf
SP 800-56Cr1Recommendation for Key-Derivation Methods in Key-Establishment Schemes August 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Cr1.pdf
SP 800-56Cr2Recommendation for Key-Derivation Methods in Key-Establishment Schemes August 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Cr2.pdf © 2024 Canonical Ltd. / atsec information security.
Page 105
SP 800-90Ar1Recommendation for Random Number Generation Using Deterministic Random Bit Generators June 2015 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90Ar1.pdf
SP 800-90BRecommendation for the Entropy Sources Used for Random Bit Generation January 2018 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90B.pdf
SP 800-108r1NIST Special Publication 800-108 - Recommendation for Key Derivation Using Pseudorandom Functions August 2022 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-108r1.pdf
SP 800-132Recommendation for Password-Based Key Derivation - Part 1: Storage Applications December 2010 https://csrc.nist.gov/publications/nistpubs/800-132/nist-sp800-132.pdf
SP 800-133r2Recommendation for Cryptographic Key Generation June 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-133r2.pdf
SP 800-135r1Recommendation for Existing Application-Specific Key Derivation Functions December 2011 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-135r1.pdf
SP 800-140BCMVP Security Policy Requirements March 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-140B.pdf © 2024 Canonical Ltd. / atsec information security.