| Standard | FIPS 140-3 |
|---|---|
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Status | Active |
| Sunset date | 10/20/2026 |
| Caveat | Interim validation. When operated in approved mode. When installed, initialized and configured as specified in Section 11 of the Security Policy. The module generates cryptographic keys whose strengths are modified by available entropy. |
| Vendor | Red Hat, Inc. |
flowchart LR
%% Deterministic review-risk graph for Red Hat Enterprise Linux 9 gnutls
%% Review prompts and evidence gaps, NOT vulnerability findings.
subgraph CMVP["CMVP-disclosed clues"]
C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>update</i>"]
C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>Status Output<br/>Show status</i>"]
C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>IKEV<br/>HTTPS</i>"]
C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i>"]
end
subgraph Inference["Derived inference"]
I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
end
subgraph Risk["Reviewer question"]
R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
end
subgraph Evidence["Evidence needed to close"]
E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
end
C2 --> I2 --> R2 --> E2
C3 --> I3 --> R3 --> E3
C5 --> I5 --> R5 --> E5
C6 --> I6 --> R6 --> E6
classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
class C2,C3,C5,C6 clue;
class I2,I3,I5,I6 infer;
class R2,R3,R5,R6 risk;
class E2,E3,E5,E6 evidence;flowchart LR
%% Deterministic clue tier for Red Hat Enterprise Linux 9 gnutls
%% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
subgraph CMVP["CMVP-disclosed clues (deterministic)"]
C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>update</i><br/>src: text:keyword"]
C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>Status Output<br/>Show status</i><br/>src: text:keyword"]
C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>IKEV<br/>HTTPS</i><br/>src: text:keyword"]
C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i><br/>src: text:keyword"]
end
classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
class C2,C3,C5,C6 clueLow;Red Hat Enterprise Linux 9 gnutls version 3.7.6-074d015ce201f434 document version 1.2 Last update: 2025-07-14 Prepared by: atsec information security corporation
4516 Seton Center Parkway, Suite 250
Austin, TX 78759 www.atsec.com © 2025 Red Hat, Inc./ atsec information security.
| # | Section | Page |
|---|
© 2025 Red Hat, Inc. / atsec information security.
3 of 46
| ISO/IEC 24759 Section 6. [Number Below] | FIPS 140-3 Section Title | Security Level |
|---|---|---|
| 1 | General | 1 |
| 2 | Cryptographic Module Specification | 1 |
| 3 | Cryptographic Module Interfaces | 1 |
| 4 | Roles, Services, and Authentication | 1 |
| 5 | Software/Firmware Security | 1 |
| 6 | Operational Environment | 1 |
| 7 | Physical Security | Not Applicable |
| 8 | Non-invasive Security | Not Applicable |
| 9 | Sensitive Security Parameter Management | 1 |
| 10 | Self-tests | 1 |
| 11 | Life-cycle Assurance | 1 |
| 12 | Mitigation of Other Attacks | 1 |
| Overall | 1 |
This document is the non-proprietary FIPS 140-3 Security Policy for version 3.7.6-074d015ce201f434 of the Red Hat Enterprise Linux 9 gnutls cryptographic module. It has a one-to-one mapping to the [SP 800-140B] starting with section B.2.1 named “General” that maps to section 1 in this document and ending with section B.2.12 named “Mitigation of other attacks” that maps to section 12 in this document. It contains the security rules under which the module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for an Overall Security Level 1 module.
Table 1 - Security Levels © 2025 Red Hat, Inc. / atsec information security.
4 of 46
| # | Operating System | Hardware Platform | Processor | PAA/ Acceleration |
|---|---|---|---|---|
| 1 | Red Hat Enterprise Linux 9 | Dell PowerEdge R440 | Intel® Xeon® Silver 4216 | With PAA (AES-NI, SHA Extensions) |
| 2 | Red Hat Enterprise Linux 9 | Dell PowerEdge R440 | Intel® Xeon® Silver 4216 | Without PAA |
| 3 | Red Hat Enterprise Linux 9 | IBM z16 3931-A01 | IBM z16 | With PAI (CPACF) |
| 4 | Red Hat Enterprise Linux 9 | IBM z16 3931-A01 | IBM z16 | Without PAI |
| 5 | Red Hat Enterprise Linux 9 with PowerVM FW1040.00 with VIOS 3.1.3.00 | IBM 9080-HEX | IBM POWER10 | With PAI (ISA, Altivec) |
| 6 | Red Hat Enterprise Linux 9 with PowerVM FW1040.00 with VIOS 3.1.3.00 | IBM 9080-HEX | IBM POWER10 | Without PAI |
| # | Operating System | Hardware Platform | |||
|---|---|---|---|---|---|
| 1 | Red Hat Enterprise Linux 9 | Intel® Xeon® E5 |
Component
Description
The Red Hat Enterprise Linux 9 gnutls cryptographic module (hereafter referred to as “the module”) is a software library. The module is an open-source, general-purpose set of libraries designed to support cross-platform development of security-enabled client and server applications. The module is a multiple-chip standalone cryptographic module.
The module version is 3.7.6-074d015ce201f434 of the Red Hat Enterprise Linux 9 gnutls cryptographic module.
The module has been tested on the following platforms with the corresponding module variants and configuration options with and without PAA: Table 2 - Tested Operational Environments In addition to the configurations tested by the atsec CST laboratory, vendor-affirmed testing was performed on the following platforms for the module by F5, Inc. Table 3 - Vendor Affirmed Operation Environments Note: The CMVP makes no statement as to the correct operation of the module or the security strengths of the generated keys when so ported if the specific operational environment is not listed on the validation certificate. © 2025 Red Hat, Inc. / atsec information security.
5 of 46
| /usr/lib64/libgnutls.so.30 Note: libgmp is statically linked to libgnutls | Provides the API for the calling applications to request cryptographic services, and implements the TLS protocol, DRBG, RSA Key Generation, Diffie-Hellman and EC Diffie-Hellman. |
|---|---|
| /usr/lib64/libnettle.so.8 | Provides the cryptographic algorithm implementations, including AES, SHA, HMAC, RSA Digital Signature, DSA and ECDSA. |
| /usr/lib64/libhogweed.so.6 | Provides primitives used by libgnutls and libnettle to support the asymmetric cryptographic operations. |
| /usr/lib64/.libgnutls.so.30.hmac | The .hmac file contain the HMAC-SHA2-256 values of the libraries for integrity check during the power-up. |
| CAVP Cert | Algorithm and Standard | Mode/Method | Description/Key Size(s)/Key Strength(s) | Use/Function |
|---|---|---|---|---|
| Certs. #A4827, | AES | CBC | 128, 192, 256-bit keys | Symmetric encryption; |
| #A4828, | FIPS197, SP800- | with 128-256 bits key | Symmetric decryption | |
| #A4833, #A5572, #A5573, #A5574 | 38A | strength | ||
| Cert. #A4842 | AES | ECB | 128, 192, 256-bit keys | Symmetric encryption; |
| FIPS197, SP800- | with 128-256 bits key | Symmetric decryption | ||
| 38A | strength | |||
| Certs. #A4827, | AES | CCM | 128, 256-bit keys with | Symmetric encryption; |
| #A5572, #A5573 | SP800-38C | 128 or 256 bits key | Symmetric decryption; | |
| strength | Authenticated encryption; Authenticated decryption | |||
| Certs. #A4830, | AES | CFB8 | 128, 192, 256-bit keys | Symmetric encryption; |
| #A4831, #A4836 | FIPS197, SP800- | with 128 or 256 bits key | Symmetric decryption | |
| 38A | strength | |||
| Certs. #A4827, | AES | CMAC | 128, 256-bit keys with | Message authentication |
| #A4828, | SP800-38B | 128 or 256 bits key | code (MAC); | |
| #A4833, | strength | Message authentication | ||
| #A5572, #A5573 | code verification | |||
| Certs. #A4827, | AES | GCM | 128, 256-bit keys with | Symmetric encryption and |
| #A4828, | SP800-38D | 128 or 256 bits key | decryption in the context of | |
| #A4833, | strength | the Transport Layer Security | ||
| #A5572, #A5573, #A5574 | (TLS) network protocol |
Table 4 – Cryptographic Module Components When the module starts up successfully, after passing all the pre-operational and conditional cryptographic algorithms self-tests (CASTs), the module is operating in the approved mode of operation by default and can only be transitioned into the non-Approved mode by calling one of the non-Approved services listed in Table 10. Please see section 4 for the details on service indicator provided by the module that identifies when an approved service is called.
The table below lists all security functions of the module, including specific key size(s) employed for approved or vendor-affirmed security functions, and implemented modes of operation. © 2025 Red Hat, Inc. / atsec information security.
6 of 46
| CAVP Cert | Algorithm and Standard | Mode/Method | Description/Key Size(s)/Key Strength(s) | Use/Function |
|---|---|---|---|---|
| Cert. #A4833 | AES | GMAC | 128, 256-bit keys with | Message authentication code (MAC); Message authentication code verification |
| SP800-38D | 128 or 256 bits key strength | |||
| Cert. #A4834 | AES | XTS | 256, 512-bit keys with | Symmetric encryption (for data storage); Symmetric decryption (for data storage) |
| SP800-38E | 128 or 256 bits key strength | |||
| Vendor Affirmed | CKG | Key pair generation (FIPS- | RSA: 2048, 3072, 4096- | Key pair generation |
| SP800-133rev2 | 186-4, SP800-56Arev3, | bit keys with 112-149 | ||
| SP800-90Arev1) | bits key strength ECDSA/ECDH: P-256, P- 384, P-521 elliptic curves with 128-256 bits key strength Safe Primes: 2048, 3072, 4096, 6144, 8192-bit keys with 112-200 bits of key strength | |||
| Cert. #A4833 | DRBG | CTR_DRBG: | 256-bit keys with 256 | Random number generation |
| SP800-90Arev1 | AES-256 without DF, without PR | bits key strength | ||
| Cert. #A4833 | ECDSA | ECDSA KeyGen (B.4.2 | P-256, P-384, | Key pair generation |
| FIPS186-4 | Testing Candidates) | P-521 elliptic curves with 128-256 bits key strength | ||
| ECDSA KeyVer | P-256, P-384, P-521 elliptic curves with 128-256 bits key strength | Public key verification | ||
| SHA-224, SHA-256, SHA- | P-256, P-384, P-521 | Digital signature generation | ||
| 384, SHA-512 | elliptic curves with 128- 256 bits key strength | |||
| SHA-1, SHA-224, | P-256, P-384, P-521 | Digital signature verification | ||
| SHA-256, SHA-384, SHA- | elliptic curves with 128- | |||
| 512 | 256 bits key strength | |||
| Certs. #A4828, | HMAC | SHA-1, SHA-224, | 112-524288 bit keys with | Message authentication code (MAC); Message authentication code verification |
| #A4833, #A5575 | FIPS198-1 | SHA-256, SHA-384, SHA- 512 | 112-256 key strength | |
| Cert. #A4833 | KAS-ECC-SSC | ECC | P-256, P-384, P-521 | EC Diffie-Hellman shared secret computation; Transport Layer Security (TLS) network protocol |
| SP800-56Arev3 | Ephemeral Unified | elliptic curves keys with | ||
| Scheme | 128-256 bits key strength |
© 2025 Red Hat, Inc. / atsec information security.
7 of 46
| CAVP Cert | Algorithm and Standard | Mode/Method | Description/Key Size(s)/Key Strength(s) | Use/Function |
|---|---|---|---|---|
| Cert. #A4833 | KAS-FFC-SSC | Safe Prime Groups: | 2048, 3072, 4096, 6144, | Diffie-Hellman shared secret computation; Transport Layer Security (TLS) network protocol |
| SP800-56Arev3 | ffdhe2048, ffdhe3072, | 8192-bit keys with 112- | ||
| ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192 | 200 bits key strength | |||
| Cert. #A4832 | KDA HKDF | SHA-224, SHA-256, SHA- | Derived key with 112 to | HKDF key derivation; Transport Layer Security (TLS) network protocol |
| SP800-56Crev1 | 384, SHA-512 | 256 bits of key strength | ||
| Cert. #A4833 | TLS v1.2 KDF | TLS v1.2 with SHA-256, | Derived key with 112 to | TLS key derivation |
| RFC7627 SP800-135rev1 (CVL) | SHA-384 | 256 bits of key strength | ||
| Certs. #A4827, | AES CCM SP800- | KTS per IG D.G | 128, 256-bit keys with | Key wrapping; Key unwrapping (as part of the cipher suites |
| #A5572, #A5573 | 38C | 128 or 256 bits of key strength | ||
| Certs. #A4827, | AES GCM SP800- | KTS per IG D.G | 128, 256-bit keys with | in the TLS protocol) |
| #A4828, | 38D | 128 or 256 bits of key | ||
| #A4833, #A5572, #A5573, #A5574 | strength | |||
| AES | AES CBC and | KTS per IG D.G | 128, 256-bit keys with | |
| Certs. | HMAC | 128 or 256 bits of key | ||
| #A4827, | SP800-38A, | strength | ||
| #A4828, #A4833, #A5572, #A5573, #A5574 HMAC Certs. #A4828, #A4833, #A5575 | FIPS198-1 | |||
| Cert. #A4833 | PBKDF | HMAC-SHA-1, HMAC-SHA- | 112-256 bits | Password-based key derivation |
| SP800-132 | 224, HMAC-SHA-256, | 14-128 characters with | ||
| HMAC-SHA-384, HMAC- | password strength | |||
| SHA-512 | between 1014 and 10128 | |||
| Cert. #A4833 | RSA | RSA KeyGen (B.3.2 | 2048, 3072, 4096-bit | Key pair generation |
| FIPS186-4 | Random Provable Primes) | keys with 112-149 bits | ||
| FIPS 140-3 IG C.F | key strength | |||
| RSA SigGen PKCS#1v1.5: | 2048, 3072, 4096-bit | Digital signature generation | ||
| SHA-224, SHA-256, SHA- | keys with 112-149 bits | |||
| 384, SHA-512 | key strength | |||
| RSA SigGen | 2048, 3072, 4096-bit | |||
| PSS: SHA-256, SHA-384, | keys with 112-149 bits | |||
| SHA-512 | key strength |
© 2025 Red Hat, Inc. / atsec information security.
8 of 46
| CAVP Cert | Algorithm and Standard | Mode/Method RSA SigVer PKCS#1v1.5: SHA-1, SHA-224, SHA-256, SHA-384, SHA-512 RSA SigVer PSS: SHA-256, SHA-384, SHA-512 | Description/Key Size(s)/Key Strength(s) 2048, 3072, 4096-bit keys with 112-149 bits key strength 2048, 3072, 4096-bit keys with 112-149 bits key strength | Use/Function Digital signature verification |
|---|---|---|---|---|
| Cert. #A4833 | Safe Primes Key | Safe Prime Groups: | 2048, 3072, 4096, 6144, | Key pair generation |
| Generation | ffdhe2048, ffdhe3072, | 8192-bit keys with 112- | ||
| SP800-56Arev3 | ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192 | 200 bits key strength | ||
| Certs. #A4829, | SHA-3 | SHA3-224, SHA3-256, | N/A | Message digest |
| #A4835 | FIPS202 FIPS 140-3 IG C.C | SHA3-384, SHA3-512 | ||
| Certs. #A4828, | SHA | SHA-1, SHA-224, | N/A | Message digest |
| #A4833, #A5575 | FIPS180-4 | SHA-256, SHA-384, SHA- 512 |
| Algorithm/Functions | Use/Function |
|---|---|
| AES GCM not in the context of the TLS protocol | Symmetric encryption; Symmetric decryption |
| Blowfish | Symmetric encryption; Symmetric decryption |
| Camellia | Symmetric encryption; Symmetric decryption |
| CAST | Symmetric encryption; Symmetric decryption |
| ChaCha20 | Symmetric encryption; Symmetric decryption |
| Chacha20 and Poly1305 | Authenticated encryption; Authenticated decryption |
| DES | Symmetric encryption; Symmetric decryption |
Non-Approved Algorithms Allowed in the Approved Mode of Operation: The module does not implement any Non-Approved Algorithms Allowed in the Approved Mode of Operation. Non-Approved Algorithms Allowed in the Approved Mode of Operation with No Security Claimed: The module does not implement any non-Approved but Allowed algorithm in Approved mode of operation with no security claimed. Non-Approved Algorithms Not Allowed in the Approved Mode of Operation: The table below lists Non-Approved security functions that are not Allowed in the Approved Mode of Operation. © 2025 Red Hat, Inc. / atsec information security.
9 of 46
| Algorithm/Functions | Use/Function |
|---|---|
| Diffie-Hellman with keys generated with domain parameters other than safe primes | Key agreement; Diffie-Hellman shared secret computation |
| DSA | Key pair generation; Domain parameter generation; Digital signature generation; Digital signature verification |
| ECDSA with curves not listed in Table 5 | Key pair generation; Public key verification; Digital signature generation; Digital signature verification |
| EC Diffie-Hellman with curves not listed in Table 5 | Key agreement; EC Diffie-Hellman shared secret computation |
| GOST | Symmetric encryption; Symmetric decryption; Message digest |
| HMAC with keys smaller than 112-bit | Message authentication code (MAC) |
| HMAC with GOST | Message authentication code (MAC) |
| MD2, MD4, MD5 | Message digest; Message authentication code (MAC) |
| PBKDF with non-approved message digest algorithms | Password-based key derivation |
| RC2, RC4 | Symmetric encryption; Symmetric decryption |
| RMD160 | Message digest; Message authentication code (MAC) |
| RSA with keys smaller than 2048 bits or greater than 4096 bits. | Key pair generation; Digital signature generation |
| RSA with keys smaller than 1024 bits or greater than 4096 bits. | Digital signature verification |
| RSA encryption and decryption with any key sizes. | Key encapsulation; Key un-encapsulation |
| Salsa20 | Symmetric encryption; Symmetric decryption |
| SM3 | Message digest |
| Serpent | Symmetric encryption; Symmetric decryption |
| SHA-1 | Digital signature generation |
| STREEBOG | Message digest; Message authentication code (MAC) |
| Triple-DES | Symmetric encryption; Symmetric decryption |
| Twofish | Symmetric encryption; Symmetric decryption |
| UMAC | Message authentication code (MAC) |
| Yarrow | Random number generation |
Table 6 - Non-Approved Algorithms Not Allowed in the Approved Mode of Operation
The software block diagram below shows the module, its interfaces with the operational environment and the delimitation of its cryptographic boundary. © 2025 Red Hat, Inc. / atsec information security.
10 of 46
Figure 1
11 of 46
| Physical Port | Logical Interface1 | Data that passes over port/interface |
|---|---|---|
| As a software-only module, the module does not have physical ports. Physical Ports are interpreted to be the physical ports of the hardware platform on which it runs. | Data Input | API input parameters |
| Data Output | API output parameters | |
| Control Input | API function calls for control | |
| Status Output | API return codes, status parameters |
The logical interfaces are the API through which the applications request services. The following table summarizes the logical interfaces: Table 7 - Ports and Interfaces © 2025 Red Hat, Inc. / atsec information security.
12 of 46
| Role | Service | Input | Output | |
|---|---|---|---|---|
| Crypto Officer (CO) | Authenticated encryption | Key, Plaintext, IV | Ciphertext, MAC tag | |
| Authenticated decryption | Key, Ciphertext, IV, MAC tag | Plaintext | ||
| Diffie-Hellman shared secret computation | Private key, public key from peer | Shared secret | ||
| Digital signature generation | Message, hash algorithm, private key | Digital signature | ||
| Digital signature verification | Message, signature, hash algorithm, public key | Verification result | ||
| Domain parameter generation | Domain parameters input | Generated domain parameters | ||
| EC Diffie-Hellman shared secret computation | Private key, public key from peer | Shared secret | ||
| HKDF key derivation | Shared secret | HKDF derived key | ||
| Key pair generation | RSA key size, Diffie-Hellman Safe Prime or Elliptic Curve, enabled-curve2 | Key pair | ||
| Key agreement | Private key, public key from peer | Derived key | ||
| Key encapsulation | Key to be encapsulated, Key encapsulating key | Encapsulated key | ||
| Key un-encapsulation | Encapsulated key, Key encapsulating key | Unencapsulated key | ||
| Key wrapping | Key to be wrapped, Key wrapping key | Wrapped key | ||
| Key unwrapping | Wrapped key, Key unwrapping key | Unwrapped key | ||
| Message authentication code (MAC) | HMAC key or AES key, message | MAC tag | ||
| Message authentication code verification | HMAC key or AES key, message, MAC tag | Pass/fail | ||
| Message digest | Message | Digest of the message | ||
| Password-based key derivation | Password or passphrase, salt, iteration count | PBKDF Derived key | ||
| Public key verification | Key pair | Return codes/log messages | ||
| Random number generation | Number of bits | Random number | ||
| Self-tests | N/A | Result of self-test (pass/fail) | ||
| Symmetric decryption | Key, Ciphertext | Plaintext | ||
| Symmetric encryption | Key, Plaintext | Ciphertext | ||
| Show module name and version | N/A | Name and version information |
The module supports the Crypto Officer role only. This sole role is implicitly assumed by the operator of the module when performing a service. The module does not support
Table below describes the authorized role(s) in which the service can be performed with specification
2 The enabled-curve input parameter can be adjusted relying on the crypto-policies package provided as part of the RHEL
OS. The usage of crypto-policies is discouraged by the vendor. Further info can be found at the vendor's documentation. © 2025 Red Hat, Inc. / atsec information security.
13 of 46
| Show status | N/A | Return codes and/or log messages |
|---|---|---|
| TLS key derivation | TLS pre-master secret | Derived key |
| Transport Layer Security (TLS) network protocol | Cipher-suites, Digital Certificate, Public and Private Keys, Application Data | Return codes and/or log messages, Application data |
| Zeroization | Context containing SSPs | N/A |
| Service Cryptographic Services | Description | Approved Security Functions | Keys and/or SSPs | Roles | Access rights to Keys and/or SSPs | Indicator |
|---|---|---|---|---|---|---|
| Symmetric encryption | Perform AES encryption | AES-CBC AES-ECB AES-CCM AES-CFB8 AES-CMAC AES-GMAC AES-XTS | AES key | CO | W, E | GNUTLS_FIPS140 _OP_APPROVED |
Table 8 - Roles, Service Commands, Input and Output
FIPS 140-3 does not require an authentication mechanism for level 1 modules. Therefore, the module does not implement an authentication mechanism for Crypto Officer. The Crypto Officer role is authorized to access all services provided by the module (see Table - Approved Services and Table - Non-Approved Services below). The table below lists all approved services that can be used in the approved mode of operation. The following convention is used to specify access rights to an SSP:
14 of 46
Service Symmetric decryption Authenticated encryption Authenticated decryption Key wrapping Key unwrapping Key pair generation Digital signature generation
Description Perform AES decryption Encrypt a plaintext Decrypt a ciphertext Key wrapping (as part of the cipher suites in the TLS protocol) Key unwrapping (as part of the cipher suites in the TLS protocol) Generate RSA, ECDSA/ECDH and DH key pairs Generate RSA and ECDSA signature See Table 5 for SHA sizes
Approved Security Functions AES-CBC AES-ECB AES-CCM AES-GCM AES-CFB8 AES-CMAC AES-GMAC AES-XTS AES-CCM AES-CCM AES-CCM AES-GCM AES-CBC, HMAC AES-CCM AES-GCM AES-CBC, HMAC CKG DRBG ECDSA RSA Safe Primes Key generation DRBG ECDSA SHA RSA
Keys and/or SSPs AES key AES key AES key AES key AES key, HMAC key AES key AES key, HMAC key Module-generated RSA public key, Module generated RSA private key Module-generated ECDSA public key, Module generated ECDSA private key Module-generated Diffie-Hellman public key, Module-generated Diffie-Hellman private keys Module-generated EC Diffie-Hellman public key, Module-generated EC Diffie-Hellman private keys “enabled-curve” parameter DRBG internal state (V value, key) RSA private key DRBG internal state (V value, key) ECDSA private key
Roles
Access rights to Keys and/or SSPs W, E W, E W, E W, E W, E W, E W, E G, E, R G, E, R G, E, R G, E, R W, E W, E W, E
Indicator GNUTLS_FIPS140 _OP_APPROVED GNUTLS_FIPS140 _OP_APPROVED GNUTLS_FIPS140 _OP_APPROVED GNUTLS_FIPS140 _OP_APPROVED GNUTLS_FIPS140 _OP_APPROVED GNUTLS_FIPS140 _OP_APPROVED GNUTLS_FIPS140 _OP_APPROVED
© 2025 Red Hat, Inc. / atsec information security.
15 of 46
Service Digital signature verification Public key verification Random number generation Message digest Message authentication code (MAC) Message authentication code verification Diffie-Hellman shared secret computation EC Diffie-Hellman shared secret computation TLS key derivation HKDF key derivation Password-based key derivation
Description Verify RSA, and ECDSA signature See Table 5 for SHA sizes Verify ECDSA public key Generate random bitstrings Compute SHA hashes Compute HMAC Compute AES- based CMAC Compute AES- based GMAC Verify MAC tag Compute a shared secret Compute a shared secret Perform TLS key derivation Perform key derivation using HKDF (in the context of TLS 1.3) Perform password- based key derivation
Approved Security Functions RSA ECDSA SHA ECDSA DRBG SHA Compute HMAC CMAC with AES GMAC with AES HMAC or GMAC with AES or CMAC with AES KAS-FFC-SSC KAS-ECC-SSC TLS v1.2 KDF RFC7627 KDA HKDF PBKDF
Keys and/or SSPs RSA public key ECDSA public key ECDSA public key Entropy input DRBG internal state (V value, key) DRBG seed None HMAC key AES key AES key AES key or HMAC key Diffie-Hellman public key, Diffie- Hellman private key Diffie-Hellman Shared secret EC Diffie-Hellman public key, EC Diffie-Hellman private key EC Diffie-Hellman Shared secret TLS pre-master secret TLS master secret TLS derived key Diffie-Hellman shared secret or EC Diffie-Hellman shared secret HKDF derived key Password/passphr ase PBKDF derived key
Roles
Access rights to Keys and/or SSPs W, E W, E W, E E, G E, G N/A W, E W, E W, E G, R W, E G, R W, E E, G G, R W, E G, R W, E G, R
Indicator GNUTLS_FIPS140 _OP_APPROVED GNUTLS_FIPS140 _OP_APPROVED GNUTLS_FIPS140 _OP_APPROVED GNUTLS_FIPS140 _OP_APPROVED GNUTLS_FIPS140 _OP_APPROVED GNUTLS_FIPS140 _OP_APPROVED GNUTLS_FIPS140 _OP_APPROVED GNUTLS_FIPS140 _OP_APPROVED GNUTLS_FIPS140 _OP_APPROVED GNUTLS_FIPS140 _OP_APPROVED GNUTLS_FIPS140 _OP_APPROVED GNUTLS_FIPS140 _OP_APPROVED GNUTLS_FIPS140 _OP_APPROVED
© 2025 Red Hat, Inc. / atsec information security.
16 of 46
| Service Network Protocol Service | Description | Approved Security Functions | Keys and/or SSPs | Roles | Access rights to Keys and/or SSPs | Indicator |
|---|---|---|---|---|---|---|
| Transport Layer Security (TLS) network protocol | Establish TLS session | Supported cipher suites in FIPS- validated configuration (see Appendix A for the complete list of valid cipher suites) | RSA public key, RSA private key, ECDSA public key, ECDSA private key | CO | W, E | GNUTLS_FIPS140 _OP_APPROVED |
| Other FIPS-Related Services | TLS pre-master secret, TLS master secret, Diffie Hellman private key, Diffie-Hellman public key, EC Diffie Hellman public key, EC Diffie-Hellman private key, TLS derived key, HKDF derived key | W, E, G | ||||
| Show status | Show module status | N/A | None | CO | N/A | N/A |
| Self-tests | Perform self-tests | AES, Diffie- Hellman, EC Diffie- Hellman, ECDSA, DRBG, HMAC, RSA, SHS, HKDF, PBKDF, TLS v1.2 KDF RFC7627 | None | N/A | N/A | |
| Show module name and version | Show module name and version | N/A | None | N/A | N/A | |
| Zeroization | Zeroize SSPs | N/A | Any SSPs | All SSPs: Z | N/A |
| Service Cryptographic Services | Description | Algorithms Accessed | Role |
|---|---|---|---|
| Symmetric encryption | Compute the cipher for encryption | AES GCM not in the context of the TLS protocol Blowfish Camellia CAST ChaCha20 DES GOST RC2, RC4 Salsa20 Serpent Triple-DES Twofish | CO |
The table below lists all non-Approved services that can only be used in the non-Approved mode of operation. © 2025 Red Hat, Inc. / atsec information security.
17 of 46
Service Cryptographic Services Symmetric decryption Key pair generation Digital signature generation Digital signature verification Domain parameter generation Message digest Message authentication code (MAC) Key agreement Key encapsulation Key un- encapsulation Diffie-Hellman shared secret computation
Description Compute the cipher for decryption Generate RSA, DSA, and ECDSA key pairs Sign RSA, DSA, and ECDSA signatures Verify RSA, DSA, and ECDSA signatures Generate domain parameter Compute message digest Compute HMAC Perform key agreement Perform RSA key encapsulation Perform RSA key un- encapsulation Perform DH shared secret computation
Algorithms Accessed AES GCM not in the context of the TLS protocol Blowfish Camellia CAST ChaCha20 DES GOST RC2, RC4 Salsa20 Serpent Triple-DES Twofish DSA ECDSA with curves not listed in Table 5 RSA with keys smaller than 2048 bits or greater than 4096 bits DSA ECDSA with curves not listed in Table 5 RSA with keys smaller than 2048 bits or greater than 4096 bits DSA ECDSA with curves not listed in Table 5 RSA with keys smaller than 1024 bits or greater than 4096 bits DSA GOST MD2, MD4, MD5 RMD160 SM3 STREEBOG HMAC with keys smaller than 112-bit HMAC with GOST MD2, MD4, MD5 RMD160 STREEBOG UMAC Diffie-Hellman with keys generated with domain parameters other than safe primes EC Diffie-Hellman with curves not listed in Table 5 RSA encryption and decryption with any key sizes RSA encryption and decryption with any key sizes Diffie-Hellman with keys generated with domain parameters other than safe primes
Role
© 2025 Red Hat, Inc. / atsec information security.
18 of 46
Service Cryptographic Services EC Diffie-Hellman shared secret computation Password-based key derivation Public key verification Transport Layer Security (TLS) network protocol
Description Perform ECDH shared secret computation Perform password-based key derivation Verify ECDSA public key Establish non-supported TLS channel
Algorithms Accessed EC Diffie-Hellman with curves not listed in Table 5 PBKDF using non-approved message digest algorithms ECDSA with curves not listed in Table 5 Non-supported cipher suite (see Appendix A for the complete list of valid cipher)
Role
© 2025 Red Hat, Inc. / atsec information security.
19 of 46
The integrity of the module is verified by comparing an HMAC-SHA2-256 value calculated at run time with the HMAC value stored in the .hmac file that was computed at build time for each software component of the module listed in section
The module provides the Self-Test service to perform self-tests on demand which includes the preoperational test (i.e., integrity test) and the cryptographic algorithm self-tests (CASTs). The SelfTests service can be called on demand by invoking the gnutls_fips140_run_self_tests() function which will perform integrity tests and the cryptographic algorithms self-tests. Additionally, the SelfTest service can be invoked by powering-off and reloading the module. During the execution of the on-demand self-tests, services are not available, and no data output is possible.
The module consists of executable code in the form of libgnutls, libnettle, libgmp and libhogweed shared libraries as stated in section 2. © 2025 Red Hat, Inc. / atsec information security.
20 of 46
The module operates in a modifiable operational environment per FIPS 140-3 level 1 specification: the module executes on a general-purpose operating system (Red Hat Enterprise Linux 9), which allows modification, loading, and execution of software that is not part of the validated module.
See Section 2.3. The Red Hat Enterprise Linux operating system is used as the basis of other products which include but are not limited to:
The module shall be installed as stated in Section 11. If properly installed, the operating system provides process isolation and memory protection mechanisms that ensure appropriate separation for memory access among the processes on the system. Each process has control over its own data and uncontrolled access to the data of other processes is prevented. There are no concurrent operators. The module does not have the capability of loading software or firmware from an external source. Instrumentation tools like the ptrace system call, gdb and strace, userspace live patching, as well as other tracing mechanisms offered by the Linux environment such as ftrace or systemtap, shall not be used in the operational environment. The use of any of these tools implies that the cryptographic module is running in a non-validated operational environment. © 2025 Red Hat, Inc. / atsec information security.
21 of 46
The module is comprised of software only and therefore this section is Not Applicable (N/A). © 2025 Red Hat, Inc. / atsec information security.
22 of 46
This module does not implement any non-invasive security mechanism and therefore this section is Not Applicable (N/A). © 2025 Red Hat, Inc. / atsec information security.
23 of 46
| Key / SSP Name / Type | Strength | Security Function and Cert. Number | Generation | Import/Export | Establis hment | Storag e | Zeroization | Use & related keys |
|---|---|---|---|---|---|---|---|---|
| AES key | AES-XTS: 128, 256 bits; Other modes: 128, 192, 256 bits | AES-CBC, AES- CCM, AES- CFB8, AES- CMAC, AES-ECB AES-GCM, AES- GMAC, AES- XTS, Certs. #A4827, #A4828, #A4830, #A4831, #A4833, #A4834, #A4836, #A4842, #A5572, #A5573, #A5574 | N/A | MD/EE Import: CM from TOEPP Path. Passed to the module via API parameters in plaintext (P) format. Export: None | N/A | RAM | gnutls_cipher_ deinit() gnutls_aead_ci pher_deinit() | Use: Symmetric encryption; Symmetric decryption; Message authentication code (MAC); Message authentication code verification; Authenticated encryption; Authenticated decryption; Key wrapping; Key unwrapping Related SSPs: N/A |
| HMAC key | 112–256 bits | HMAC Certs. #A4828, #A4833, #A5575 | N/A | MD/EE Import: CM from TOEPP Path. Passed to the module via API parameters in plaintext (P) format. Export: None | N/A | RAM | gnutls_hmac_ deinit() | Use: Message Authentication Code (MAC); Message authentication code verification; Key wrapping; Key unwrapping Related SSPs: N/A |
| Module- generated RSA public key | 112 to 256 bits | DRBG, RSA: Cert. #A4833 | Generated using the FIPS 186-4 key generation method; the random value used in key generation is obtained from the SP800- 90Arev1 DRBG. | MD/EE Import: None Export: CM to TOEPP Path. Passed from the module via API parameters in plaintext (P) format. | N/A | RAM | gnutls_privkey _deinit() gnutls_x509_p rivkey_deinit() gnutls_rsa_par ams_deinit() | Use: Key pair generation Related SSPs: DRBG internal state (V value, key); Module- generated RSA private key |
| Module- generated RSA private key | 112 to 256 bits | DRBG, RSA: Cert. #A4833 | Generated using the FIPS 186-4 key generation method; the random value used in key generation is obtained from the SP800- 90Arev1 DRBG. | MD/EE Import: None Export: CM to TOEPP Path. Passed from the module via API parameters in plaintext (P) format. | N/A | RAM | gnutls_privkey _deinit() gnutls_x509_p rivkey_deinit() gnutls_rsa_par ams_deinit() | Use: Key pair generation Related SSPs: DRBG internal state (V value, key); Module- generated RSA public key |
Table 11 summarizes the SSPs that are used by the cryptographic services implemented in the © 2025 Red Hat, Inc. / atsec information security.
24 of 46
| Key / SSP Name / Type | Strength | Security Function and Cert. Number | Generation | Import/Export | Establis hment | Storag e | Zeroization | Use & related keys |
|---|---|---|---|---|---|---|---|---|
| RSA public key | 112 to 256 bits | RSA Cert. #A4833 | N/A | MD/EE Import: CM from TOEPP Path. Passed to the module via API parameters in plaintext (P) format. Export: None | N/A | RAM | gnutls_privkey _deinit() gnutls_x509_p rivkey_deinit() gnutls_rsa_par ams_deinit() | Use: Digital signature verification; Transport Layer Security (TLS) network protocol Related SSPs: RSA private key |
| RSA private key | 112 to 256 bits | RSA Cert. #A4833 | N/A | MD/EE Import: CM from TOEPP Path. Passed to the module via API parameters in plaintext (P) format. Export: None | N/A | RAM | gnutls_privkey _deinit() gnutls_x509_p rivkey_deinit() gnutls_rsa_par ams_deinit() | Use: Digital signature generation; Transport Layer Security (TLS) network protocol Related SSPs: RSA public key |
| Module- generated ECDSA public key | 112, 192, 256 bits | DRBG, ECDSA: Cert. #A4833 | Generated using the FIPS 186-4 key generation method; the random value used in key generation is obtained from the SP800- 90Arev1 DRBG. | MD/EE Import: None Export: CM to TOEPP Path. Passed from the module via API parameters in plaintext (P) format. | N/A | RAM | gnutls_privkey _deinit() gnutls_x509_p rivkey_deinit() gnutls_rsa_par ams_deinit() | Use: Key pair generation Related SSPs: DRBG internal state (V value, key); Module- generated ECDSA private key |
| Module- generated ECDSA private key | 112, 192, 256 bits | DRBG, ECDSA: Cert. #A4833 | Generated using the FIPS 186-4 key generation method; the random value used in key generation is obtained from the SP800- 90Arev1 DRBG. | MD/EE Import: None Export: CM to TOEPP Path. Passed from the module via API parameters in plaintext (P) format. | N/A | RAM | gnutls_privkey _deinit() gnutls_x509_p rivkey_deinit() gnutls_rsa_par ams_deinit() | Use: Key pair generation Related SSPs: DRBG internal state (V value, key); Module- generated ECDSA public key |
| ECDSA public key | 128, 192, 256 bits | ECDSA Cert. #A4833 | N/A | MD/EE Import: CM from TOEPP Path. Passed to the module via API parameters in plaintext (P) format. Export: None | N/A | RAM | gnutls_privkey _deinit() gnutls_x509_p rivkey_deinit() gnutls_rsa_par ams_deinit() | Use: Digital signature verification; Public key verification; Transport Layer Security (TLS) network protocol Related SSPs: DRBG internal state (V value, key); ECDSA private key |
© 2025 Red Hat, Inc. / atsec information security.
25 of 46
| Key / SSP Name / Type | Strength | Security Function and Cert. Number | Generation | Import/Export | Establis hment | Storag e | Zeroization | Use & related keys |
|---|---|---|---|---|---|---|---|---|
| ECDSA private key | 128, 192, 256 bits | ECDSA Cert. #A4833 | N/A | MD/EE Import: CM from TOEPP Path. Passed to the module via API parameters in plaintext (P) format. Export: None | N/A | RAM | gnutls_privkey _deinit() gnutls_x509_p rivkey_deinit() gnutls_rsa_par ams_deinit() | Use: Digital signature generation; Public key verification; Transport Layer Security (TLS) network protocol Related SSPs: DRBG internal state (V value, key); ECDSA public key |
| Module- generated Diffie- Hellman public key | 112-200 bits | KAS-FFC-SSC DRBG Cert. #A4833 | Generated using the SP 800-56Arev3 Safe Primes key generation method; random values are obtained from the SP800- 90Arev1 DRBG. | MD/EE Export: CM to TOEPP Path. Passed from the module via API parameters in plaintext (P) format. Import: None | N/A | RAM | gnutls_dh_par ams_deinit() gnutls_pk_par ams_clear() | Use: Key pair generation; Transport Layer Security (TLS) network protocol Related SSPs: Module- generated Diffie- Hellman private key; DRBG internal state (V value, key); TLS pre-master secret |
| Module- generated Diffie- Hellman private key | 112-200 bits | KAS-FFC-SSC DRBG Cert. #A4833 | Generated using the SP 800-56Arev3 Safe Primes key generation method; random values are obtained from the SP800- 90Arev1 DRBG. | MD/EE Export: CM to TOEPP Path. Passed from the module via API parameters in plaintext (P) format. Import: None | N/A | RAM | gnutls_dh_par ams_deinit() gnutls_pk_par ams_clear() | Use: Key pair generation; Transport Layer Security (TLS) network protocol Related SSPs: Module- generated Diffie- Hellman public key; DRBG internal state (V value, key); TLS pre-master secret |
| Diffie- Hellman public key | 112-200 bits | KAS-FFC-SSC Cert. #A4833 | N/A | MD/EE Import: CM from TOEPP Path. Passed to the module via API parameters in plaintext (P) format. Export: None | N/A | RAM | gnutls_dh_par ams_deinit() gnutls_pk_par ams_clear() | Use: Diffie- Hellman shared secret computation; Transport Layer Security (TLS) network protocol Related keys: Diffie-Hellman private key; Diffie-Hellman shared secret |
| Diffie- Hellman private key | 112-200 bits | KAS-FFC-SSC Cert. #A4833 | N/A | MD/EE Import: CM from TOEPP Path. Passed to the module via API parameters | N/A | RAM | gnutls_dh_par ams_deinit() gnutls_pk_par ams_clear() | Use: Diffie- Hellman shared secret computation; Transport Layer Security (TLS) network protocol Related keys: Diffie-Hellman |
© 2025 Red Hat, Inc. / atsec information security.
26 of 46
| Key / SSP Name / Type | Strength | Security Function and Cert. Number | Generation | Import/Export in plaintext (P) format. Export: None | Establis hment | Storag e | Zeroization | Use & related keys public key; Diffie- Hellman shared secret |
|---|---|---|---|---|---|---|---|---|
| Module- generated EC Diffie- Hellman public key | 128, 192, 256 bits | KAS-ECC-SSC DRBG Cert. #A4833 | Generated internally by the module using the ECDSA key generation method compliant with [FIPS186-4] and [SP800- 56Arev3]; the random value used in key generation is obtained from the SP800- 90Arev1 DRBG | MD/EE Export: CM to TOEPP Path. Passed from the module via API parameters in plaintext (P) format. Import: None | N/A | RAM | gnutls_pk_par ams_clear() | Use: Key pair generation; Transport Layer Security (TLS) network protocol Related keys: Module- generated EC Diffie-Hellman private key; DRBG internal state (V value, key); TLS pre- master secret |
| Module- generated EC Diffie- Hellman private key | 128, 192, 256 bits | KAS-ECC-SSC DRBG Cert. #A4833 | Generated internally by the module using the ECDSA key generation method compliant with [FIPS186-4] and [SP800- 56Arev3]; the random value used in key generation is obtained from the SP800- 90Arev1 DRBG | MD/EE Export: CM to TOEPP Path. Passed from the module via API parameters in plaintext (P) format. Import: None | N/A | RAM | gnutls_pk_par ams_clear() | Use: Key pair generation; Transport Layer Security (TLS) network protocol Related keys: Module- generated EC Diffie-Hellman public key; DRBG internal state (V value, key); TLS pre-master secret |
| EC Diffie- Hellman public key | 128, 192, 256 bits | KAS-ECC-SSC Cert. #A4833 | N/A | MD/EE Import: CM from TOEPP Path. Passed to the module via API parameters in plaintext (P) format. Export: None | N/A | RAM | gnutls_pk_par ams_clear() | Use: EC Diffie- Hellman shared secret computation; Transport Layer Security (TLS) network protocol Related keys: EC Diffie-Hellman private key; EC Diffie-Hellman shared secret |
| EC Diffie- Hellman private key | 128, 192, 256 bits | KAS-ECC-SSC Cert. #A4833 | N/A | MD/EE Import: CM from TOEPP Path. Passed to the module via API | N/A | RAM | gnutls_pk_par ams_clear() | Use: EC Diffie- Hellman shared secret computation; Transport Layer Security (TLS) network protocol |
© 2025 Red Hat, Inc. / atsec information security.
27 of 46
| Key / SSP Name / Type | Strength | Security Function and Cert. Number | Generation | Import/Export parameters in plaintext (P) format. Export: None | Establis hment | Storag e | Zeroization | Use & related keys Related keys: EC Diffie-Hellman public key; EC Diffie-Hellman shared secret |
|---|---|---|---|---|---|---|---|---|
| Diffie- Hellman shared secret | 112 to 200 bits | KAS-FFC-SSC Cert. #A4833 | N/A | MD/EE Import: CM from TOEPP Path. Passed to the module via API parameters in plaintext (P) format. Export: CM to TOEPP Path. Passed from the module via API parameters in plaintext (P) format. | Generate d during the Diffie- Hellman key agreeme nt and shared secret computat ion per SP800- 56Arev3. | RAM | zeroize_key() | Use: Diffie- Hellman shared secret computation; HKDF key derivation Related keys: Diffie-Hellman public key; Diffie- Hellman private key |
| EC Diffie- Hellman shared secret | 112 to 256 bits | KAS-ECC-SSC Cert. #A4833 | N/A | MD/EE Import: CM from TOEPP Path. Passed to the module via API parameters in plaintext (P) format. Export: CM to TOEPP Path. Passed from the module via API parameters in plaintext (P) format. | Generate d during the EC Diffie- Hellman key agreeme nt and shared secret computat ion per SP800- 56Arev3. | RAM | zeroize_key() | Use: EC Diffie- Hellman shared secret computation; HKDF key derivation Related keys: EC Diffie-Hellman public key; EC Diffie-Hellman private key |
| PBKDF password or passphrase | Password strength 1014 - 10128 | PBKDF Cert. #A4833 | N/A (key material is entered via API parameters) | MD/EE Import: CM to TOEPP Path. Passed to the module via API parameters in plaintext (P) format. Export: None | N/A | RAM | Internal PBKDF state is zeroized automatically when function returns. | Use: Password- based key derivation Related keys: PBKDF derived key |
| PBKDF derived key | 112-256 bits | PBKDF Cert. #A4833 | Derived during the PBKDF | MD/EE Import: None Export: CM from TOEPP Path. Passed from the module via API parameters in | N/A | RAM | zeroize_key() | Use: Password- based key derivation Related keys: PBKDF password or passphrase |
© 2025 Red Hat, Inc. / atsec information security.
28 of 46
| Key / SSP Name / Type | Strength | Security Function and Cert. Number | Generation | Import/Export plaintext (P) format. | Establis hment | Storag e | Zeroization | Use & related keys |
|---|---|---|---|---|---|---|---|---|
| HKDF derived key | 112 to 256 bits | KDA HKDF Cert. #A4832 | Derived (as part of TLSv1.3) with KDA HKDF | MD/EE Import: None Export: CM from TOEPP Path. Passed from the module via API parameters in plaintext (P) format. | N/A | RAM | gnutls_deinit() | Use: HKDF key derivation; Transport Layer Security (TLS) network protocol Related keys: Diffie-Hellman shared secret, EC Diffie-Hellman shared secret |
| Entropy input IG D.L compliant | 112 to 337 bits | DRBG Cert. #A4833 ESV Cert. #E47 | Obtained from the SP 800- 90B compliant Non-Physical Entropy Source | Import: None Export: None it remains within the cryptographic boundary. | N/A | RAM | gnutls_global_ deinit() | Use: Random number generation Related keys: DRBG seed |
| DRBG internal state (V value, key) IG D.L compliant | 128 to 256 bits | DRBG Cert. #A4833 | Generated from the DRBG seed as defined in SP800- 90Arev1 | Import: None Export: None | N/A | RAM | gnutls_global_ deinit() | Use: Random number generation Related keys: DRBG seed, Module- generated ECDSA public key, Module- generated ECDSA private key, Module- generated RSA public key, Module- generated RSA private key, Module- generated Diffie- Hellman public key, Module- generated Diffie- Hellman private key, Module- generated EC Diffie-Hellman public key, Module- generated EC Diffie-Hellman private key |
| DRBG seed IG D.L compliant | 128 to 256 bits | DRBG Cert. #A4833 ESV Cert. #E47 | Derived from entropy input as defined in SP800- 90Arev1 | Import: None Export: None it remains within the cryptographic boundary. | N/A | RAM | gnutls_global_ deinit() | Use: Random number generation Related keys: Entropy input; DRBG internal state (V value, key) |
© 2025 Red Hat, Inc. / atsec information security.
29 of 46
| Key / SSP Name / Type | Strength | Security Function and Cert. Number | Generation | Import/Export | Establis hment | Storag e | Zeroization | Use & related keys |
|---|---|---|---|---|---|---|---|---|
| TLS pre- master secret | DH 112 to 256 bits ECDH 112 to 256 bits | TLS v1.2 KDF RFC7627 Certs. #A4833 | N/A | MD/EE Import: CM to TOEPP Path. Passed to the module via API parameters in plaintext (P) format. Export: None | Key agreeme nt for Diffie- Hellman or EC Diffie- Hellman and shared secret computat ion per SP800- 56Arev3 | RAM | gnutls_deinit() | Use: TLS key derivation, Transport Layer Security (TLS) network protocol Related keys: TLS master secret |
| TLS master secret | 112 to 256 bits | TLS v1.2 KDF RFC7627 Certs. #A4833 | Derived from TLS pre- master secret using TLS v1.2 KDF RFC7627per SP800- 135rev1. | MD/EE Import: None Export: None | N/A | RAM | gnutls_deinit() | Use: TLS key derivation, Transport Layer Security (TLS) network protocol Related keys: TLS pre-master secret, TLS derived key |
| TLS derived key | 112 to 256 bits | TLS v1.2 KDF RFC7627 Certs. A4833 | Derived from TLS master secret using TLS v1.2 KDF RFC7627 per SP800- 135rev1. | MD/EE Import: None Export: CM from TOEPP Path. Passed from the module via API parameters in plaintext (P) format. | N/A | RAM | gnutls_deinit() | Use: TLS key derivation, Transport Layer Security (TLS) network protocol Related keys: TLS pre-master secret, TLS master secret |
| Entropy Source | Minimum number of bits of entropy | Details | |
|---|---|---|---|
| SP 800-90B compliant Non- Physical Entropy Source (ESV cert. E47) | 225 bits of entropy in the 256-bit output | Userspace CPU Jitter 2.2.0 entropy source with LFSR as the non-vetted conditioning component is located within the physical perimeter of the module but outside the cryptographic boundary of the module. |
The module employs a Deterministic Random Bit Generator (DRBG) based on [SP800-90ARev1] for the generation of random value used in asymmetric keys, and for providing a RNG service to calling applications. The approved DRBG provided by the module is the CTR_DRBG with AES-256. The DRBG does not employ prediction resistance or a derivation function. The module uses an SP800-90Bcompliant Entropy Source specified in the table below to seed the DRBG. Table 12 - Non-Deterministic Random Number Generation Specification The module generates SSPs (e.g., keys) whose strengths are modified by available entropy. © 2025 Red Hat, Inc. / atsec information security.
30 of 46
In accordance with FIPS 140-3 IG D.H, the cryptographic module performs Cryptographic Key Generation (CKG) for asymmetric keys according to section 5.1 and 5.2 of [SP800-133rev2] according to section 6.1 of [SP800-133rev2] (vendor affirmed) by obtaining a random bit string directly from an approved [SP800-90Arev1] DRBG and that can support the required security strength requested by the caller (without any V, as described in Additional Comments 2 of IG D.H).
SSPs are provided to the module via API input parameters in plaintext form and output via API output parameters in plaintext form within the physical perimeter of the operational environment. This is allowed by [FIPS140-3_IG] IG 9.5.A, according to the “CM Software to/from App via TOEPP Path” entry on the Key Establishment Table. The module does not support entry or output of cryptographically protected SSPs.
The module provides Diffie-Hellman and EC Diffie-Hellman shared secret computation compliant with SP800- 56Arev3, in accordance with scenario 2 (1) of IG D.F and used as part of the TLS protocol key exchange in accordance with scenario 2 (2) of IG D.F; that is, the shared secret computation (KAS-FFC-SSC and KAS-ECC-SSC) followed by the derivation of the keying material using SP800-135rev1 KDF and SP800-56Crev1 KDF. © 2025 Red Hat, Inc. / atsec information security.
31 of 46
For Diffie-Hellman, the module supports the use of safe primes from RFC7919 for domain parameters and key generation, which are used in the TLS key agreement implemented by the module.
Symmetric keys, public and private keys are provided to the module by the calling application via API input parameters and are destroyed by the module when invoking the appropriate API function calls. The module does not perform persistent storage of SSPs. The SSPs are temporarily stored in the RAM in plaintext form. SSPs are provided to the module by the calling process and are destroyed when released by the appropriate zeroization function calls.
The memory occupied by SSPs is allocated by regular memory allocation operating system calls. The application that is acting as the CO is responsible for calling the appropriate zeroization © 2025 Red Hat, Inc. / atsec information security.
32 of 46
functions provided in the module's API and listed in Table 11. Calling the gnutls_deinit() will zeroize the SSPs stored in the TLS protocol internal state and also invoke the corresponding API functions listed in Table 11 to zeroize SSPs. The zeroization functions overwrite the memory occupied by SSPs with “zeros” and deallocate the memory with the regular memory deallocation operating system call. The completion of a zeroization routine(s) will indicate that a zeroization procedure succeeded. All data output is inhibited during zeroization. © 2025 Red Hat, Inc. / atsec information security.
33 of 46
| Algorithm | Test |
|---|---|
| AES | KAT AES CBC mode with 128-bit and 256-bit keys, encryption and decryption (separately tested) KAT AES CFB8 mode with 256-bit key, encryption and decryption (separately tested) KAT AES GCM mode with 256-bit key, encryption and decryption (separately tested) KAT AES XTS mode with 256-bit keys, encryption and decryption (separately tested) KAT AES-CMAC with 256-bit key size MAC generation |
| Diffie-Hellman | Primitive “Z” Computation KAT with ffdhe3072 |
| DRBG | KAT CTR_DRBG with AES with 256-bit keys without DF, without PR |
| DRBG | Health tests according to section 11.3 of [SP800-90Arev1] |
| EC Diffie-Hellman | Primitive “Z” Computation KAT with P-256 curve |
| ECDSA | KAT ECDSA with P-256 using SHA-256, P-384 using SHA-384, and P-521 using SHA-512, signature generation and verification (separately tested) |
| HKDF KDA | KAT with SHA-256 |
| HMAC | KAT HMAC-SHA-1, HMAC-SHA-224, HMAC-SHA-256, HMAC-SHA-384, HMAC-SHA-512 |
| PBKDF KDF | KAT with SHA-256 with 4096 iterations and 288-bit salt |
| RSA | KAT RSA PKCS#1 v1.5 with 2048-bit key using SHA-256, signature generation and verification (separately tested) |
| SHA-3 | KAT SHA3-224, SHA3-256, SHA3-384, SHA3-512 |
The module performs the pre-operational self-test and CASTs automatically when the module is loaded into memory. Pre-operational self-test ensure that the module is not corrupted, and the CASTs ensure that the cryptographic algorithms work as expected. While the module is executing the self-tests, the module services are not available, and input and output are inhibited. The module is not available for use by the calling application until the pre-operational self-test and the CASTs are completed successfully. After the pre-operational test and the CASTs succeed, the module becomes operational. If any of the pre-operational test or any of the CASTs fail an error message is returned, and the module transitions to the error state.
The module performs the following pre-operational tests: the integrity test of the shared libraries that comprise the module using HMAC-SHA2-256. The details of integrity test are provided in section 5.1. Prior the first use, a CAST is executed for the algorithms used in the Pre-operational Self-Tests.
The following sub-sections describe the conditional self-tests supported by the module. If one of the conditional self-tests fail, the module transitions to the ‘Error’ state and a corresponding error indication is given. The entropy source performs its required self-tests; those are not listed here, as the entropy source is not part of the cryptographic boundary of the module.
The module performs cryptographic algorithm self-tests (CASTs) on all approved cryptographic algorithms. The CASTs consist of Known Answer Tests for all the approved cryptographic algorithms. © 2025 Red Hat, Inc. / atsec information security.
34 of 46
| Algorithm | Test |
|---|---|
| TLS v1.2 KDF RFC7627 | KAT with SHA-256 |
| Algorithm | Test |
|---|---|
| ECDSA key generation | PCT using SHA-256, signature generation and verification. |
| RSA key generation | PCT using PKCS#1 v1.5 with SHA-256, signature generation and verification |
| Diffie-Hellman key generation | PCT according to section 5.6.2.1.4 of [SP800-56Arev3] |
| EC Diffie-Hellman key generation | Covered by ECDSA PCT as allowed by IG 10.3.A additional comment 1 |
| Error State | Cause of Error | Status Indicator |
|---|---|---|
| Error State | When the integrity tests or KAT fail at power-up. | GNUTLS_E_SELF_TEST_ERROR (-400) |
| When the KAT of DRBG fails during pre-operational tests | GNUTLS_E_RANDOM_FAILED (-206) | |
| When the new generated key pair fails the PCT | GNUTLS_E_PK_GENERATION_ERROR (-403) | |
| When the module is in error state and caller requests cryptographic operations | GNUTLS_E_LIB_IN_ERROR_STATE (-402) |
Table 13 - Conditional Cryptographic Algorithm Self-Tests
The module performs the Pair-wise Consistency Tests (PCT) shown in the following table. If any of Table 14 - Pairwise Consistency Test
The module provides the Self-Test service to perform self-tests on demand which includes the preTests service can be called on demand by invoking the gnutls_fips140_run_self_tests() function which will perform integrity tests and the cryptographic algorithms self-tests. Additionally, the SelfTest service can be invoked by powering-off and reloading the module. During the execution of the on-demand self-tests, services are not available, and no data output is possible. error code to indicate the error and enters error state. Any further cryptographic operations and the data output via the data output interface are inhibited. The calling application can obtain the module state by calling the gnutls_fips140_get_operation_state() API function. The function returns The following table shows the error codes and the corresponding condition: Table 15 - Error States Self-test errors transition the module into an error state that keeps the module operational but prevents any cryptographic related operations. The module must be restarted and perform the per© 2025 Red Hat, Inc. / atsec information security.
35 of 46
operational self-test and the CASTs to recover from these errors. If failures persist, the module must be re-installed. © 2025 Red Hat, Inc. / atsec information security.
36 of 46
| Processor Architecture | RPM Packages |
|---|---|
| Intel 64-bit | gnutls-gnutls-3.7.6-21.el9_2.1.x86_64.rpm nettle-3.8-3.el9_0.x86_64.rpm |
| IBM z16 64-bit | gnutls-3.7.6-21.el9_2.1.s390x.rpm nettle-3.8-3.el9_0.s390x.rpm |
| IBM POWER10 64-bit | gnutls-3.7.6-21.el9_2.1.ppc64le.rpm nettle-3.8-3.el9_0.ppc64le.rpm |
The module is distributed as a part of the Red Hat Enterprise Linux 9 (RHEL 9) package in the form of:
For secure sanitization of the cryptographic module, the module needs first to be powered off, which will zeroize all keys and CSPs in volatile memory. Then, for actual deprecation, the module shall be upgraded to a newer version that is FIPS 140-3 validated. The module does not possess persistent storage of SSPs, so further sanitization steps are not needed.
The binaries of the 'Red Hat Enterprise Linux 9 gnutls version 3.7.6-074d015ce201f434’ are contained in the RPM packages for delivery listed below. Before the 'Red Hat Enterprise Linux 9 gnutls’ RPM packages are installed, the RHEL 9 system must operate in Approved mode. This can be achieved by:
The TLS protocol implementation provides both server and client sides. In order to operate in the approved mode, digital certificates used for server and client authentication shall comply with the © 2025 Red Hat, Inc. / atsec information security.
37 of 46
restrictions of key size and message digest algorithms imposed by [SP800-131Arev2]. In addition, as required also by [SP800-131Arev2], Diffie-Hellman with keys smaller than 2048 bits must not be used. The TLS protocol lacks the support to negotiate the used Diffie-Hellman key sizes. To ensure full support for all TLS protocol versions, the TLS client implementation of the module accepts DiffieHellman key sizes smaller than 2048 bits offered by the TLS server. For complying with the requirement to not allow Diffie-Hellman key sizes smaller than 2048 bits, the Crypto Officer must ensure that:
The AES algorithm in XTS mode can be only used for the cryptographic protection of data on storage devices, as specified in [SP800-38E]. The length of a single data unit encrypted with the XTS-AES shall not exceed 2²⁰ AES blocks, that is 16MB of data. The module implements a check that ensures, before performing any cryptographic operation, that the two AES keys used in AES XTS mode are not identical (in compliance with IG C.I). Note: AES-XTS shall be used with 128 and 256-bit keys only. AES-XTS with 192-bit keys is not an Approved service.
The module implements AES GCM for being used in the TLS v1.2 and v1.3 protocols. AES GCM IV generation is in compliance with [FIPS140-3_IG] IG C.H for both protocols as follows:
The module provides password-based key derivation (PBKDF), compliant with SP800-132 and IG D.N. The module supports option 1a from section 5.4 of [SP800-132], in which the Master Key (MK) or a segment of it is used directly as the Data Protection Key (DPK). In accordance with [SP800-132], the following requirements shall be met. © 2025 Red Hat, Inc. / atsec information security.
38 of 46
To comply with the assurances listed in section 5.6.2 of SP 800-56ARev3, the module shall be used together with an application that implements the "TLS protocol" and the following steps shall be performed.
39 of 46
RSA is vulnerable to timing attacks. In a setup where attackers can measure the time of RSA decryption or signature operations, blinding is always used to protect the RSA operation from that attack. The internal API function of rsa_blind() and rsa_unblind() are called by the module for RSA signature generation and RSA decryption operations. The module generates a random blinding factor and include this random value in the RSA operations to prevent RSA timing attacks. © 2025 Red Hat, Inc. / atsec information security.
40 of 46
| Cipher Suite | ID | Reference |
|---|---|---|
| TLS_DH_RSA_WITH_AES_128_CBC_SHA | { 0x00, 0x31 } | RFC3268 |
| TLS_DHE_RSA_WITH_AES_128_CBC_SHA | { 0x00, 0x33 } | RFC3268 |
| TLS_DH_RSA_WITH_AES_256_CBC_SHA | { 0x00, 0x37 } | RFC3268 |
| TLS_DHE_RSA_WITH_AES_256_CBC_SHA | { 0x00, 0x39 } | RFC3268 |
| TLS_DH_RSA_WITH_AES_128_CBC_SHA256 | { 0x00,0x3F } | RFC5246 |
| TLS_DHE_RSA_WITH_AES_128_CBC_SHA256 | { 0x00,0x67 } | RFC5246 |
| TLS_DH_RSA_WITH_AES_256_CBC_SHA256 | { 0x00,0x69 } | RFC5246 |
| TLS_DHE_RSA_WITH_AES_256_CBC_SHA256 | { 0x00,0x6B } | RFC5246 |
| TLS_PSK_WITH_AES_128_CBC_SHA | { 0x00, 0x8C } | RFC4279 |
| TLS_PSK_WITH_AES_256_CBC_SHA | { 0x00, 0x8D } | RFC4279 |
| TLS_DHE_RSA_WITH_AES_128_GCM_SHA256 | { 0x00, 0x9E } | RFC5288 |
| TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 | { 0x00, 0x9F } | RFC5288 |
| TLS_DH_RSA_WITH_AES_128_GCM_SHA256 | { 0x00, 0xA0 } | RFC5288 |
| TLS_DH_RSA_WITH_AES_256_GCM_SHA384 | { 0x00, 0xA1 } | RFC5288 |
| TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA | { 0xC0, 0x04 } | RFC4492 |
| TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA | { 0xC0, 0x05 } | RFC4492 |
| TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA | { 0xC0, 0x09 } | RFC4492 |
| TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA | { 0xC0, 0x0A } | RFC4492 |
| TLS_ECDH_RSA_WITH_AES_128_CBC_SHA | { 0xC0, 0x0E } | RFC4492 |
| TLS_ECDH_RSA_WITH_AES_256_CBC_SHA | { 0xC0, 0x0F } | RFC4492 |
| TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA | { 0xC0, 0x13 } | RFC4492 |
| TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA | { 0xC0, 0x14 } | RFC4492 |
| TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256 | { 0xC0, 0x23 } | RFC5289 |
| TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384 | { 0xC0, 0x24 } | RFC5289 |
| TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA256 | { 0xC0, 0x25 } | RFC5289 |
| TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA384 | { 0xC0, 0x26 } | RFC5289 |
| TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 | { 0xC0, 0x27 } | RFC5289 |
| TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 | { 0xC0, 0x28 } | RFC5289 |
Appendix A. TLS Cipher Suites The module supports the following cipher suites for the TLS protocol version 1.0, 1.1, 1.2 and 1.3, compliant with section 3.3.1 of [SP800-52rev2]. Each cipher suite defines the key exchange algorithm, the bulk encryption algorithm (including the symmetric key size) and the MAC algorithm. © 2025 Red Hat, Inc. / atsec information security.
41 of 46
| Cipher Suite | ID | Reference |
|---|---|---|
| TLS_ECDH_RSA_WITH_AES_128_CBC_SHA256 | { 0xC0, 0x29 } | RFC5289 |
| TLS_ECDH_RSA_WITH_AES_256_CBC_SHA384 | { 0xC0, 0x2A } | RFC5289 |
| TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 | { 0xC0, 0x2B } | RFC5289 |
| TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 | { 0xC0, 0x2C } | RFC5289 |
| TLS_ECDH_ECDSA_WITH_AES_128_GCM_SHA256 | { 0xC0, 0x2D } | RFC5289 |
| TLS_ECDH_ECDSA_WITH_AES_256_GCM_SHA384 | { 0xC0, 0x2E } | RFC5289 |
| TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 | { 0xC0, 0x2F } | RFC5289 |
| TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 | { 0xC0, 0x30 } | RFC5289 |
| TLS_ECDH_RSA_WITH_AES_128_GCM_SHA256 | { 0xC0, 0x31 } | RFC5289 |
| TLS_ECDH_RSA_WITH_AES_256_GCM_SHA384 | { 0xC0, 0x32 } | RFC5289 |
| TLS_DHE_RSA_WITH_AES_128_CCM | { 0xC0, 0x9E } | RFC6655 |
| TLS_DHE_RSA_WITH_AES_256_CCM | { 0xC0, 0x9F } | RFC6655 |
| TLS_DHE_RSA_WITH_AES_128_CCM_8 | { 0xC0, 0xA2 } | RFC6655 |
| TLS_DHE_RSA_WITH_AES_256_CCM_8 | { 0xC0, 0xA3 } | RFC6655 |
| TLS_AES_128_GCM_SHA256 | { 0x13, 0x01 } | RFC8446 |
| TLS_AES_256_GCM_SHA384 | { 0x13, 0x02 } | RFC8446 |
| TLS_AES_128_CCM_SHA256 | { 0x13, 0x04 } | RFC8446 |
| TLS_AES_128_CCM_8_SHA256 | { 0x13, 0x05 } | RFC8446 |
© 2025 Red Hat, Inc. / atsec information security.
42 of 46
Appendix B. Glossary and Abbreviations AES Advanced Encryption Standard AES-NI Advanced Encryption Standard New Instructions CAVP Cryptographic Algorithm Validation Program CBC Cipher Block Chaining CCM Counter with Cipher Block Chaining-Message Authentication Code CFB Cipher Feedback CKG Cryptographic Key Generation CMAC Cipher-based Message Authentication Code CMVP Cryptographic Module Validation Program CPACF CP Assist for Cryptographic Functions CSP Critical Security Parameter CTR Counter Mode DES Data Encryption Standard DF Derivation Function DSA Digital Signature Algorithm DRBG Deterministic Random Bit Generator ECB Electronic Code Book ECC Elliptic Curve Cryptography FFC Finite Field Cryptography FIPS Federal Information Processing Standards Publication GCM Galois Counter Mode GMAC Galois Counter Mode Message Authentication Code HMAC Hash Message Authentication Code KAS Key Agreement Scheme KAT Known Answer Test KW AES Key Wrap MAC Message Authentication Code NIST National Institute of Science and Technology PAA Processor Algorithm Acceleration PAI Processor Algorithm Implementation PBKDF2 Password-based Key Derivation Function v2 PKCS Public-Key Cryptography Standards PCT Pairwise Consistency Test PR Prediction Resistance RNG Random Number Generator RSA Rivest, Shamir, Addleman SHA Secure Hash Algorithm SHS Secure Hash Standard © 2025 Red Hat, Inc. / atsec information security.
43 of 46
| FIPS140-3 | FIPS PUB 140-3 - Security Requirements For Cryptographic Modules March 2019 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-3.pdf |
| FIPS140-3_IG | Implementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program March 2024 https://csrc.nist.gov/csrc/media/Projects/cryptographic-module-validation- program/documents/fips%20140-3/FIPS%20140-3%20IG.pdf |
| FIPS180-4 | Secure Hash Standard (SHS) August 2015 http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf |
| FIPS186-4 | Digital Signature Standard (DSS) July 2013 http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-4.pdf |
| FIPS197 | Advanced Encryption Standard November 2001 http://csrc.nist.gov/publications/fips/fips197/fips-197.pdf |
| FIPS198-1 | The Keyed Hash Message Authentication Code (HMAC) July 2008 http://csrc.nist.gov/publications/fips/fips198-1/FIPS-198-1_final.pdf |
| FIPS202 | SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions August 2015 http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.202.pdf |
| PKCS#1 | Public Key Cryptography Standards (PKCS) #1: RSA Cryptography Specifications Version 2.1 February 2003 http://www.ietf.org/rfc/rfc3447.txt |
| SP800-38A | NIST Special Publication 800-38A - Recommendation for Block Cipher Modes of Operation Methods and Techniques December 2001 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38a.pdf |
| SP800-38B | NIST Special Publication 800-38B - Recommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication May 2005 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38b.pdf |
| SP800-38C | NIST Special Publication 800-38C - Recommendation for Block Cipher Modes of Operation: the CCM Mode for Authentication and Confidentiality July 2007 http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38c.pdf |
| SP800-38D | NIST Special Publication 800-38D - Recommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC November 2007 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38d.pdf © 2025 Red Hat, Inc. / atsec information security. 44 of 46 |
| SP800-38E | NIST Special Publication 800-38E - Recommendation for Block Cipher Modes of Operation: The XTS AES Mode for Confidentiality on Storage Devices January 2010 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38e.pdf |
| SP800-52rev2 | NIST Special Publication 800-52 Revision 2 - Guidelines for the Selection, Configuration, and Use of Transport Layer Security (TLS) Implementations August 2019 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-52r2.pdf |
| SP800- | NIST Special Publication 800-56A Revision 3 - Recommendation for Pair |
| 56ARev3 | Wise Key Establishment Schemes Using Discrete Logarithm Cryptography April 2018 https://doi.org/10.6028/NIST.SP.800-56Ar3 |
| SP800- | Recommendation for Key Derivation through Extraction-then-Expansion |
| 56CRev2 | August 2020 https://doi.org/10.6028/NIST.SP.800-56Cr2 |
| SP800-57rev5 | NIST Special Publication 800-57 Part 1 Revision 5 - Recommendation for Key Management Part 1: General May 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r5.pdf |
| SP800- | NIST Special Publication 800-90A - Revision 1 - Recommendation for |
| 90ARev1 | Random Number Generation Using Deterministic Random Bit Generators June 2015 http://dx.doi.org/10.6028/NIST.SP.800-90Ar1 |
| SP800-90B | NIST Special Publication 800-90B - Recommendation for the Entropy Sources Used for Random Bit Generation January 2018 https://doi.org/10.6028/NIST.SP.800-90B |
| SP800- | NIST Special Publication 800-131 Revision 2 - Transitions: |
| 131Arev2 | Recommendation for Transitioning the Use of Cryptographic Algorithms and Key Lengths March 2019 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar2.pdf |
| SP800-132 | NIST Special Publication 800-132 - Recommendation for Password- Based Key Derivation - Part 1: Storage Applications December 2010 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-132.pdf |
| SP800- | NIST Special Publication 800-133 - Recommendation for Cryptographic |
| 133Rev2 | Key Generation June 2020 https://doi.org/10.6028/NIST.SP.800-133r2 |
SP800-135rev1 NIST Special Publication 800-135 Revision 1 - Recommendation for Existing Application-Specific Key Derivation Functions December 2011 http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-135r1.pdf © 2025 Red Hat, Inc. / atsec information security.
45 of 46
| SP800-140B | NIST Special Publication 800-140B - CMVP Security Policy Requirements March 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-140B.pdf |
| RFC8446 | The Transport Layer Security (TLS) Protocol Version 1.3 August 2018 https://www.ietf.org/rfc/rfc8446.txt |
| RFC7919 | Negotiated Finite Field Diffie-Hellman Ephemeral Parameters for Transport Layer Security (TLS) August 2016 https://www.ietf.org/rfc/rfc7919.txt |
| RFC3526 | More Modular Exponential (MODP) Diffie-Hellman groups for Internet Key Exchange (IKE) May 2003 https://www.ietf.org/rfc/rfc3526.txt |
| RFC7627 | Transport Layer Security (TLS) Session Hash and Extended Master Secret Extension September 2015 https://www.ietf.org/rfc/rfc7627.txt © 2025 Red Hat, Inc. / atsec information security. 46 of 46 |