All modules
CMVP Validated Module · FIPS 140-3 Security Policy

VMware VMkernel Cryptographic Module 2.0

Certificate#4815StandardFIPS 140-3Level1TypeSoftwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorVMware, Inc.
High review priority  ·  exposes kernel crypto consumer  ·  Linux kernel upstream has published 10212 CVEs since this module's initial validation  ·  last validated 22 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date9/25/2029
CaveatNone
VendorVMware, Inc.

Approved Algorithms (13)

AlgorithmACVP Cert
AES-CBCA2792
AES-CBC-CS3A2792
AES-CTRA2792
AES-ECBA2792
AES-GCMA2792
AES-XTS Testing Revision 2.0A2792
Counter DRBGA2792
HMAC-SHA-1A2792
HMAC-SHA2-256A2792
HMAC-SHA2-512A2792
SHA-1A2792
SHA2-256A2792
SHA2-512A2792

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for VMware VMkernel Cryptographic Module 2.0
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Status Output<br/>self-test<br/>Show Status</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>kernel<br/>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C3 --> I3 --> R3 --> E3
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C3,C6 clue;
  class I3,I6 infer;
  class R3,R6 risk;
  class E3,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for VMware VMkernel Cryptographic Module 2.0
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Status Output<br/>self-test<br/>Show Status</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>kernel<br/>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C3,C6 clueLow;

Security Policy, page by page

Page 1

VMware VMkernel Cryptographic Module 2.0 Document Version: 1.2

Page 2

VMware VMkernel Cryptographic Module 2.0 – Security Policy Document Table of contents

Page 3
ISO/IEC 24759 Section 6. [Number Below]FIPS 140-3 Section TitleSecurity Level
1General1
2Cryptographic Module Specification1
3Cryptographic Module Interfaces1
4Roles, Services, and Authentication1
5Software/Firmware Security1
6Operational Environment1
7Physical SecurityN/A
8Non-invasive SecurityN/A
9Sensitive Security Parameters Management1
10Self-tests1
11Life-Cycle Assurance1
12Mitigation of Other AttacksN/A

VMware VMkernel Cryptographic Module 2.0 – Security Policy Document VMkernel Cryptographic Module 2.0 (software version 2.0), herein after referred as the module, the cryptographic module, or the software module, meets overall Security Level 1 requirements. Table 1 below lists the level of validation for each area in the FIPS PUB 140-3. Table 1 –Security Levels

Page 4
#Operating SystemHardware PlatformProcessorPAA/Acceleration
1ESXi 8.0Dell EMC PowerEdge R650Intel Xeon Gold 6330 2.00GHzWithout PAA
CAVP CertAlgorithm and StandardMode/MethodDescription/Key Size(s)/Key Strengths(s)Use / Function
A2792AES-CBC FIPS PUB 197AES-CBCKey Size: 128, 192, 256 bits Strengths: 128, 192, 256 bitsSymmetric key encryption and decryption
A2792AES-CBC-CS3 FIPS PUB 197AES-CBC-CS3Key Size: 128, 192, 256 bits Strengths: 128, 192, 256 bitsSymmetric key encryption and decryption
A2792AES-CTR FIPS PUB 197AES-CTRKey Size: 128, 192, 256 bits Strengths: 128, 192, 256 bitsSymmetric key encryption and decryption
A2792AES-ECB FIPS PUB 197AES-ECBKey Size: 128, 192, 256 bits Strengths: 128, 192, 256 bitsSymmetric key encryption and decryption
A2792AES-GCM NIST SP 800-38DAES-GCMKey Size: 128, 192, 256 bits Strengths: 128, 192, 256 bitsSymmetric key encryption and decryption

VMware VMkernel Cryptographic Module 2.0

Page 5
CAVP CertAlgorithm and StandardMode/MethodDescription/Key Size(s)/Key Strengths(s)Use / Function
A2792AES-XTS TestingAES-XTSKey Size: 128, 256 Strengths: 128, 256 bitsKey Size: 128, 256Symmetric key encryption and decryption
Revision 2.0 NIST SP 800-38EStrengths: 128, 256 bits
A2792HMAC-SHA-1 (FIPS PUB 198-1)SHA-1Key Size: 160, bits Strength: 160 bitsAuthentication
A2792HMAC-SHA2-256 (FIPS PUB 198-1)SHA2-256Key Size: 256 bits Strength: 256 bitsIntegrity test
A2792HMAC-SHA2-512 (FIPS PUB 198-1)SHA2-512Key Size: 512 bits Strength: 512 bitsAuthentication
A2792SHA-1 (FIPS 180-4)SHA-1N/AHashing
A2792SHA2-256 (FIPS 180-4)SHA2-256N/AHashing
A2792SHA2-512 (FIPS 180-4)SHA2-512N/AHashing
A2792Counter DRBG (NIST SP 800- 90Ar1)CTR_DRBGKey Size: AES-256 Strength: 256 bitsRandom bit generation

VMware VMkernel Cryptographic Module 2.0 – Security Policy Document The module does not implement and use any non-approved algorithms and thus does not support the following: Non-Approved Algorithms Allowed in the Approved Mode of Operation, Non-Approved Algorithms Allowed in the Approved Mode of Operation with No Security Claimed and Non-Approved Algorithms Not Allowed in the Approved Mode of Operation. The cryptographic module runs only in an Approved mode of operation. The module does not support a non-Approved mode of operation. Below is a block diagram showing the location of the module components with respect to the ESXi operating system and the applications which interact with the module. The diagram includes the cryptographic boundary containing the module components (red dotted outline) and also depicts the physical perimeter of the module (the GPC, i.e. the TOEPP).

Page 6

VMware VMkernel Cryptographic Module 2.0

Page 7

VMware VMkernel Cryptographic Module 2.0 – Security Policy Document The module complies with IG C.I by explicitly checking that Key_1 ≠ Key_2 before using the keys in the XTS-AES algorithm to process data with them.

Page 8
Physical portLogical InterfaceData that Passes over port/interface
N/AData InputThe module accepts data input through the input arguments of the API functions
Data OutputThe module produces data output through the parameter of the API functions
Control InputThe module accepts control input through the input arguments of the API functions used to control the module
Status OutputThe module produces status output through the return values for function calls and error messages
Power inputThe module is initialized by powering on the underlying host platform

VMware VMkernel Cryptographic Module 2.0

Page 9
RoleServiceInputOutput
Crypto OfficerInitialization of the moduleNoneNone
Crypto OfficerRun self-testsAPI commandThe results of each self-test
Crypto OfficerEncryptionKey and plaintext input via APIEncrypted data
Crypto OfficerDecryptionKey and ciphertext input via APIPlaintext data
Crypto OfficerHashingData input via APIHash of the input data
Crypto OfficerMessage Authentication Code (MAC) GenerationKey input via API Data input via APIMAC of the input data
Crypto OfficerDeterministic Random Bit Generation (DRBG)Seed input via APIRandom bits
Crypto OfficerShow version (includes Show Status)API commandThe module version will be output to the log
Crypto OfficerPerform zeroisationReboot OS; Cycle host power; API callThe module version will be output to the log or a success code returned (in case of an API call)

VMware VMkernel Cryptographic Module 2.0

Page 10
ServiceDescriptionApproved Security FunctionsKeys and/or SSPsRolesAccess rights to Keys and/or SSPsIndicator
Initialization of the module.---Crypto Officer-The module is running
Run self-tests-All per Table 3 CAVP Cert. #A2792All per Table 9Crypto OfficerEThe self-test results are output in the log
EncryptionEncrypt plaintext using supplied key and algorithm specificationAES modes: ECB, CTR, CTS, CBC, and GCM CAVP Cert. #A2792AES keys: 128-bit, 192-bit, 256-bitCrypto OfficerWEZReturn values indicate success or error
AES mode:AES keys:
XTS128-bit,
CAVP Cert. #A2792256-bit
DecryptionDecrypt ciphertext using supplied key and algorithm specificationAES modes: ECB, CTR, CTS, CBC, and GCM CAVP Cert. #A2792AES keys: 128-bit, 192-bit, 256-bitCrypto OfficerWEZReturn values indicate success or error
AES mode:AES keys:
XTS128-bit,
CAVP Cert. #A2792256-bit
HashingCompute and return a message digest using SHA algorithmSHA-1, SHA2-256, SHA2-512 CAVP Cert. #A2792-Crypto Officer-Return values indicate success or error
Message Authentication Code (MAC) GenerationCompute and return a hashed message authentication codeHMAC SHA-1, SHA2-256, SHA2-512 CAVP Cert. #A2792HMAC key, 160-bit, 256- bitCrypto OfficerWEZReturn values indicate success or error

VMware VMkernel Cryptographic Module 2.0 – Security Policy Document

Page 11
ServiceDescriptionApproved Security FunctionsKeys and/or SSPsRolesAccess rights to Keys and/or SSPsIndicator
Random Bit GenerationGenerate random bits by using the DRBGCTR_DRBG (AES-CTR 256) CAVP Cert. #A2792DRBG seed: 384-bit DRBG Entropy Input: 256-bitCrypto OfficerWEZReturn values indicate success or error
Show versionShow the module name and version--Crypto Officer-The module name and
(includes Showversion are output in the
Status)log
Perform zeroisationZeroisation of the module on demand by power- cycling the host platform, rebooting the OS or via an API call--Crypto OfficerZThe module name and version are output in the log or a success code returned (in case of an API call)

VMware VMkernel Cryptographic Module 2.0 – Security Policy Document The module does not implement any non-approved services.

Page 12

VMware VMkernel Cryptographic Module 2.0 – Security Policy Document Section 5. Software/Firmware Security For the purposes of a FIPS 140-3 level 1 validation, the cryptographic module consists of two object files, cryptoloader and crypto_fips. The module performs no communications other than with the consuming host application (the process that invokes the module services via the module’s API), which can be considered as the host for the module. The module runs a HMAC-SHA2-256 integrity verification during initialization by the host application. The module also runs the Known Answer Test (KAT) for HMAC-SHA2-256 prior to running the integrity check. The CO can reload the module to run the integrity test on demand. The module does not support software loading.

Page 13

VMware VMkernel Cryptographic Module 2.0 – Security Policy Document Section 6. Operational Environment VMware VMkernel Cryptographic Module 2.0, a software module, runs on the VMware ESXi operating system and the Dell EMC PowerEdge R650 with Intel Xeon Gold 6330 2.00GHz, which is classified as a modifiable OE. The requirements under ISO/IEC 19790, section 7.6 “Operational environment”, are met by the module.

Page 14

VMware VMkernel Cryptographic Module 2.0 – Security Policy Document Section 7. Physical Security Per ISO/IEC 19790:2012 classification, this is a multi-chip standalone cryptographic module. The appliance the software module runs on has a production grade chassis.

Page 15

VMware VMkernel Cryptographic Module 2.0 – Security Policy Document Section 8. Non-invasive Security The module does not implement any non-invasive security mitigations and thus the requirements per this section do not apply to the module.

Page 16
Key/SSP Name/ TypeStrengthSecurity Function and Cert. NumberGenerationImport /ExportEstablishmentStorageZeroisationUse & related keys
AES key for modes: ECB, CTR, CTS, CBC, and GCM (CSP)128, 192, 256-bits key with 128, 192, 256-bits strengthECB, CTR, CTS, CBC, and GCM, CAVP Cert. #A2792N/AImported only, The key is not exported from the module MD/EEN/ARAM in plaintextReboot OS; Cycle host power; API callEncryption, Decryption
AES XTS Key (CSP)128, 256- bits key with 128, 256 bits strengthXTS. CAVP Cert. #A2792N/AImported only, The key is not exported from the module MD/EEN/ARAM in plaintextReboot OS; Cycle host power; API callEncryption, Decryption
HMAC key (CSP)160-bit, 256-bit, 512-bitSHA-1, SHA2-256, 512, CAVP Cert. #A2792N/AImported only, The key is not exported from the module MD/EEN/ARAM in plaintextReboot OS; Cycle host power; API callMessage Authentication

VMware VMkernel Cryptographic Module 2.0

Page 17
Key/SSP Name/ TypeStrengthSecurity Function and Cert. NumberGenerationImport /ExportEstablishmentStorageZeroisationUse & related keys
DRBG Entropy Input (CSP)Used to seed the DRBGENT (P)N/AImported only, The SSP is not exported from the module MD/EEN/ARAM in plaintextReboot OS; Cycle host power; API callRandom number generation
DRBG seed (CSP)Seed used to derive the internal state of the DRBGCTR_DRBG, CAVP Cert. #A2792Constructed internally per SP800-90Ar1 DRBGThe SSP is not exported from the module MD/EEN/ARAM in plaintextReboot OS; Cycle host power; API callRandom number generation
DRBG.InternalState_V (CSP)V (128- bits) CAVP Cert. #A2792CTR_DRBG, CAVP Cert. #A2792Generated internally per SP800-90Ar1 DRBGDoes not enter or exit the module MD/EEN/ARAM in plaintextReboot OS; Cycle host power; API callRandom number generation
DRBG.InternalState_Key (CSP)256-bits CAVP Cert. #A2792CTR_DRBG, CAVP Cert. #A2792Generated internally per SP800-90Ar1 DRBGDoes not enter or exit the module MD/EEN/ARAM in plaintextReboot OS; Cycle host power; API callRandom number generation

VMware VMkernel Cryptographic Module 2.0 – Security Policy Document The module also comprises of the following non-SSP: Software Integrity Key: HMAC key; 256-bits; Hardcoded in the module at manufacture and never zeroised. Verifies the integrity of the module upon initialization. The module contains an AES-CTR based DRBG for random bit generation. The module does not implement a non-approved DRBG. memory and are never stored on persistent memory. The module zeroises SSPs by overwriting them with zeros. There are API functions that will zeroise any SSPs related to a specific cryptographic operation. Successful completion of the cryptographic operation/service is the implicit indicator of successful zeroisation in

Page 18
Entropy sourcesMinimum number of bits of entropyDetails
ENT (P)0.421389 bits of entropy per bitFIPS 140-3 IG 9.3.A Scenario 1 (b)

VMware VMkernel Cryptographic Module 2.0

Page 19
Table, extracted as text (did not parse into structured rows)
VMware VMkernel Cryptographic Module 2.0 – Security Policy Document Section 10. Self-tests When the module is loaded, all self-tests are run automatically before the module becomes operational. If any of the self-tests fail, the module enters the error state. While in the error state, the module cannot perform any cryptographic operations. When the module enters the error state due to a failing self-test, the name of the self-test is shown/printed in the log. To clear the error, the module must be reloaded. Below is the list of self-tests performed by the cryptographic module. The module performs an HMAC-SHA2-256 KAT prior to performing the software integrity test. Pre-operational Self-Tests (POSTs): •    Software Integrity Test (HMAC-SHA2-256) Conditional Self-Tests: •    Cryptographic Algorithm Self-Tests (CASTs): •    AES KATs o   AES CBC 128-bit Encrypt KAT o   AES CBC 128-bit Decrypt KAT o   AES CTR 128-bit Encrypt KAT o   AES CTR 128-bit Decrypt KAT o   AES CBC-CS 128-bit Encrypt KAT o   AES CBC-CS 128-bit Decrypt KAT o   AES ECB 128-bit Encrypt KAT o   AES ECB 128-bit Decrypt KAT o   AES GCM 256-bit Encrypt KAT o   AES GCM 256-bit Decrypt KAT o   AES XTS 256-bit Encrypt KAT o   AES XTS 256-bit Decrypt KAT •    HMAC KATs o   HMAC-SHA1 KAT o   HMAC-SHA2-256 KAT o   HMAC-SHA2-512 KAT •    NIST SP800-90Ar1 CTR_DRBG KAT •    ENT (P) NIST SP 800-90B Health Tests •    Critical Functions Test: Performed for the DRBG, as per SP800-90A, Section 11: •    Instantiation Test •    Generation Test •    Reseed Test •    Uninstantiate Test
Page 20

VMware VMkernel Cryptographic Module 2.0 – Security Policy Document Section 11. Life-cycle Assurance Distribution and Installation VMware VMkernel Cryptographic Module 2.0 is distributed internal to VMware, it is not available to VMware customers. The operator of the module, the Crypto Officer, does not install the module. It is shipped pre-installed by the manufacturer, VMware as part of the VMware ESXi. Configuration The module does not require any configuration for operating in the Approved mode. Initialization and startup When the ESXi operating system starts, the module is automatically loaded and initialized. Verification of the module The module name and version is printed in the log upon successful initialization. The log message contains: “VmkCrypto version 2.0 successfully initialized.” Destruction and Zeroisation The module will remain on the ESXi operating system until the operating system is removed or replaced. When the ESXi operating system is removed or replaced, the module will be erased along with the operating system. Any SSPs in the module will be zeroised at that time.

Page 21

VMware VMkernel Cryptographic Module 2.0 – Security Policy Document Section 12. Mitigation of Other Attacks The module does not implement mitigation of other attacks and thus the requirements per this section do not apply to it.

Page 22

VMware VMkernel Cryptographic Module 2.0 – Security Policy Document Acronyms

AESAdvanced Encryption Standard
APIApplication Program Interface
CASTCryptographic Algorithm Self-Test
CBCCipher Block Chaining
CFBCipher Feedback
COCrypto-Officer
CSPCritical Security Parameter
CTRCounter
CTSCipher-Text Stealing
CVLComponent Validation List
DRBGDeterministic Random Bit Generation
ECBElectronic Code Book
FIPSFederal Information Processing Standard
GCMGalois/Counter Mode
GPCGeneral Purpose Computer
HMAC(Keyed-)Hash Messages Authentication Code
ISO/IECInternational Organization for Standardization/ International Electrotechnical Commission
KATKnown Answer Test
LEDLight Emitting Diode
MACMessage Authentication Code
NISTNational Institute of Standards and Technology
OEOperational Environment
OSOperation System
Page 23

VMware VMkernel Cryptographic Module 2.0 – Security Policy Document

PAAProcessor Algorithm Acceleration
POSTPre-operational Self-Test
PUBPublication
SHASecure Hash Algorithm
SHSSecure Hash Standard
SSPSensitive Security Parameter
SPSpecial Publication
XORExclusive OR
XTSXEX-based tweaked-codebook mode with ciphertext stealing
Page 24

END OF DOCUMENT VMware and the VMware logo are registered trademarks or trademarks of VMware, Inc. and its subsidiaries in the United States and other jurisdictions. All other marks and names mentioned herein may be trademarks of their respective companies. VMware products are covered by one or more patents listed at vmware.com/go/patents. Item No: vmw-wp-tech-temp-uslet-word-2021 8/21