| Standard | FIPS 140-3 |
|---|---|
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Status | Active |
| Sunset date | 10/28/2029 |
| Caveat | Interim validation. When operated in approved mode. When installed, initialized and configured as specified in Section 11.2 of the Security Policy. The module generates SSPs (e.g., keys) whose strengths are modified by available entropy. |
| Vendor | Red Hat(R), Inc. |
flowchart LR
%% Deterministic review-risk graph for Red Hat Enterprise Linux 9 - OpenSSL FIPS Provider
%% Review prompts and evidence gaps, NOT vulnerability findings.
subgraph CMVP["CMVP-disclosed clues"]
C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>update</i>"]
C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Status Output<br/>Show status<br/>Self-test</i>"]
C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>SSH<br/>HTTPS</i>"]
C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i>"]
end
subgraph Inference["Derived inference"]
I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
end
subgraph Risk["Reviewer question"]
R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
end
subgraph Evidence["Evidence needed to close"]
E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
end
C2 --> I2 --> R2 --> E2
C3 --> I3 --> R3 --> E3
C5 --> I5 --> R5 --> E5
C6 --> I6 --> R6 --> E6
classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
class C2,C3,C5,C6 clue;
class I2,I3,I5,I6 infer;
class R2,R3,R5,R6 risk;
class E2,E3,E5,E6 evidence;flowchart LR
%% Deterministic clue tier for Red Hat Enterprise Linux 9 - OpenSSL FIPS Provider
%% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
subgraph CMVP["CMVP-disclosed clues (deterministic)"]
C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>update</i><br/>src: text:keyword"]
C3["[low] Self-test / status surface (referenced in text)<br/><i>Status Output<br/>Show status<br/>Self-test</i><br/>src: text:keyword"]
C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>SSH<br/>HTTPS</i><br/>src: text:keyword"]
C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i><br/>src: text:keyword"]
end
classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
class C2,C3,C5,C6 clueLow;Red Hat Enterprise Linux 9 - OpenSSL FIPS Provider version 3.0.7-395c1a240fbfffd8 document version 1.5 Last update: 2025-07-08 Prepared by: atsec information security corporation
4516 Seton Center Parkway, Suite 250
Austin, TX 78759 www.atsec.com © 2025 Red Hat, Inc./ atsec information security corporation.
| # | Section | Page |
|---|
© 2025 Red Hat, Inc. / atsec information security corporation.
3 of 48
| ISO/IEC 24759 Section 6. [Number Below] | FIPS 140-3 Section Title | Security Level |
|---|---|---|
| 1 | General | 1 |
| 2 | Cryptographic Module Specification | 1 |
| 3 | Cryptographic Module Interfaces | 1 |
| 4 | Roles, Services, and Authentication | 1 |
| 5 | Software/Firmware Security | 1 |
| 6 | Operational Environment | 1 |
| 7 | Physical Security | Not Applicable |
| 8 | Non-invasive Security | Not Applicable |
| 9 | Sensitive Security Parameter Management | 1 |
| 10 | Self-tests | 1 |
| 11 | Life-cycle Assurance | 1 |
| 12 | Mitigation of Other Attacks | 1 |
This document is the non-proprietary FIPS 140-3 Security Policy for version 3.0.7-395c1a240fbfffd8 of the Red Hat Enterprise Linux 9 - OpenSSL FIPS Provider. It contains the security rules under which the module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for an overall and including this notice. Other documentation is proprietary to their authors.
In preparing the Security Policy document, the laboratory formatted the vendor-supplied documentation for consolidation without altering the technical statements therein contained. The further refining of the Security Policy document was conducted iteratively throughout the conformance testing, wherein the Security Policy was submitted to the vendor, who would then edit, modify, and add technical contents. The vendor would also supply additional documentation, which the laboratory formatted into the existing Security Policy, and resubmitted to the vendor for their final editing.
Table 1 describes the individual security areas of FIPS 140-3, as well as the security levels of those individual areas. © 2025 Red Hat, Inc. / atsec information security corporation.
4 of 48
Overall
Table 1 - Security Levels © 2025 Red Hat, Inc. / atsec information security corporation.
5 of 48
| # | Operating System | Hardware Platform | Processor | PAA/PAI Acceleration |
|---|---|---|---|---|
| 1 | Red Hat Enterprise Linux 9 | Dell PowerEdge R440 | Intel(R) Xeon(R) Silver 4216 | With and without PAA (AES-NI, SHA extensions) |
| 2 | Red Hat Enterprise Linux 9 | IBM z16 3931-A01 | IBM z16 | With and without PAI (CPACF) |
| 3 | Red Hat Enterprise Linux 9 with PowerVM FW1040.00 with VIOS 3.1.3.00 | IBM 9080-HEX | IBM POWER10 | With and without PAI (ISA, Altivec) |
| # | Operating System | Hardware Platform | |||
|---|---|---|---|---|---|
| 1 | Red Hat Enterprise Linux 9 | Intel(R) Xeon(R) E5 |
The Red Hat Enterprise Linux 9 - OpenSSL FIPS Provider (hereafter referred to as “the module”) is defined as a software module in a multi-chip standalone embodiment. It provides a C language application program interface (API) for use by other applications that require cryptographic functionality. The module consists of one software component, the “FIPS provider”, which implements the FIPS requirements and the cryptographic functionality provided to the operator.
The module has been tested on the following platforms with the corresponding module variants and Table 2 - Tested Operational Environments In addition to the configurations tested by the atsec CST laboratory, the vendor affirms testing was performed on the following platforms for the module. Table 3 - Vendor Affirmed Operational Environments Note: the CMVP makes no statement as to the correct operation of the module or the security strengths of the generated SSPs when so ported if the specific operational environment is not listed on the validation certificate.
Table 4 lists all approved cryptographic algorithms of the module, including specific key lengths employed for approved services (Table 9), and implemented modes or methods of operation of the algorithms. The module supports RSA modulus sizes which are not tested by CAVP in compliance with FIPS 140-
© 2025 Red Hat, Inc. / atsec information security corporation.
6 of 48
| CAVP Cert | Algorithm and Standard | Mode / Method | Description / Key Size(s) / Key Strengths | Use / Function |
|---|---|---|---|---|
| A4813 | SHA [FIPS 180-4] | SHA-1, SHA-224, SHA-256, | N/A | Message digest |
| A4823 | SHA-384, SHA-512, SHA- | |||
| A4824 A4825 A4826 A5578 A5585 | 512/224, SHA-512/256 | |||
| A4814 | SHA-3 [FIPS 202] | SHA3-224, SHA3-256, SHA3- | N/A | Message digest |
| A5587 | 384, SHA3-512 | |||
| SHA-3 [FIPS 202] | SHAKE128, SHAKE256 | N/A | XOF | |
| A4809 | AES [FIPS 197, SP | ECB | 128, 192, 256 bits with 128, | Encryption |
| A4810 | 800-38A] | 192, 256 bits of security | Decryption | |
| A4811 A4837 A4838 A4839 A4840 A4841 A5560 A5576 A5579 A5580 A5586 | strength | |||
| A4809 | AES [FIPS 197, SP | CBC, CBC-CTS-CS1, CBC- | 128, 192, 256 bits with 128, | Encryption |
| A4810 | 800-38A, SP 800- | CTS-CS2, CBC-CTS-CS3, | 192, 256 bits of security | Decryption |
| A4811 | 38A Addendum, | CFB1, CFB8, CFB128, CTR, | strength | |
| A5560 | SP 800-38C, SP | OFB, CCM | ||
| A5576 A5580 | 800-38F] | KW, KWP (KTS) | ||
| AES [FIPS 197, SP | XTS | 128, 256 bits with 128, 256 | Encryption | |
| 800-38E] | bits of security strength | Decryption | ||
| AES [FIPS 197, SP | CMAC | 128, 192, 256 bits with 128, | Message | |
| 800-38B] | 192, 256 bits of security strength | authentication | ||
| A4812 | AES [FIPS 197, SP | GCM (internal IV) (KTS) | 128, 192, 256 bits with 128, | Encryption |
| A4815 | 800-38D] | 192, 256 bits of security | ||
| A4816 | strength |
© 2025 Red Hat, Inc. / atsec information security corporation.
7 of 48
| A4817 A4818 A4819 A4820 A4821 A4822 A5577 A5581 A5582 A5583 A5584 | AES [FIPS 197, SP 800-38D] | GCM (external IV) (KTS) | 128, 192, 256 bits with 128, 192, 256 bits of security strength | Decryption |
|---|---|---|---|---|
| A4812 | AES [FIPS 197, SP | GMAC | 128, 192, 256 bits with 128, | Message |
| A4815 | 800-38D] | 192, 256 bits of security | authentication | |
| A4816 A4817 A4818 A4819 A4820 A4821 A4822 A5577 A5581 A5582 A5583 A5584 | strength | |||
| A4813 | HMAC [FIPS 198- | SHA-1, SHA-224, SHA-256, | 112-524288 bits with 112-256 | Message |
| A4823 | 1] | SHA-384, SHA-512, SHA- | bits of security strength | authentication |
| A4824 A4825 A4826 A5578 A5585 | 512/224, SHA-512/256 | |||
| A4814 | SHA3-224, SHA3-256, SHA3- | |||
| A5587 | 384, SHA3-512 | |||
| A4843 | KBKDF [SP 800- | Counter and feedback | 112-4096 bits with 112-256 | KBKDF Key |
| 108r1] | mode, using CMAC and HMAC SHA-1, SHA-224, SHA-256, SHA-384, SHA- 512, SHA-512/224, SHA- 512/256, SHA3-224, SHA3- 256, SHA3-384, SHA3-512 | bits of security strength | derivation | |
| A4844 | KDA OneStep1 [SP | (HMAC) SHA-1, SHA-224, | 224-8192 bits with 112-256 | KDA OneStep Key |
| 800-56Cr2] | SHA-256, SHA-384, SHA- 512, SHA-512/224, SHA- 512/256, SHA3-224, SHA3- 256, SHA3-384, SHA3-512 | bits of security strength | derivation |
1This algorithm is referred to as “Single Step KDF” or “SSKDF” by OpenSSL. © 2025 Red Hat, Inc. / atsec information security corporation.
8 of 48
| A4807 | HKDF [SP 800- 56Cr2] | SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, SHA- 512/224, SHA-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512 | 224-8192 bits with 112-256 bits of security strength | HKDF Key derivation |
|---|---|---|---|---|
| A4813 | ANS X9.42 KDF | AES KW with SHA-1, SHA- | 224-8192 bits with 112-256 | ANS X9.42 KDF Key |
| A4823 | [SP 800-135r1] | 224, SHA-256, SHA-384, | bits of security strength | derivation |
| A4824 | CVL | SHA-512, SHA-512/224, | ||
| A4825 A4826 A5578 A5585 | SHA-512/256 | |||
| A4814 | AES KW with SHA3-224, | |||
| A5587 | SHA3-256, SHA3-384, SHA3- 512 | |||
| A4813 | ANS X9.63 KDF | SHA-224, SHA-256, SHA- | 224-8192 bits with 112-256 | ANS X9.63 KDF Key |
| A4823 | [SP 800-135r1] | 384, SHA-512, SHA- | bits of security strength | derivation |
| A4824 A4825 A4826 A5578 A5585 | CVL | 512/224, SHA-512/256 | ||
| A4814 | SHA3-224, SHA3-256, SHA3- | |||
| A5587 | 384, SHA3-512 | |||
| A4837 | SSH KDF [SP 800- | AES-128, AES-192, AES-256 | 224-8192 bits with 112-256 | SSH KDF Key |
| A4838 | 135r1] | with SHA-1, SHA-224, SHA- | bits of security strength | derivation |
| A4839 A4840 A4841 A5579 A5586 | CVL | 256, SHA-384, SHA-512 | ||
| A4813 | TLS 1.2 KDF [SP | SHA-256, SHA-384, SHA-512 | 224-8192 bits with 112-256 | TLS 1.2 KDF Key |
| A4823 A4824 A4825 A4826 A5578 A5585 | 800-135r1] CVL | bits of security strength | derivation | |
| A4807 | TLS 1.3 KDF [RFC | SHA-256, SHA-384 | 224-8192 bits with 112-256 | TLS 1.3 KDF Key |
| 8446] CVL | bits of security strength | derivation | ||
| A4813 | PBKDF2 [SP 800- | Option 1a with SHA-1, SHA- | 8-128 characters with | Password-based key |
| A4823 | 132] | 224, SHA-256, SHA-384, | password strength between | derivation |
| A4824 | SHA-512, SHA-512/224, | 108 and 10128 | ||
| A4825 A4826 A5578 A5585 | SHA-512/256 |
© 2025 Red Hat, Inc. / atsec information security corporation.
9 of 48
| A4814 | PBKDF2 [SP 800- | Option 1a with SHA3-224, | 8-128 characters with | Password-based key |
|---|---|---|---|---|
| A5587 | 132] | SHA3-256, SHA3-384, SHA3- | password strength between | derivation |
| 512 | 108 and 10128 | |||
| A4808 | CTR_DRBG [SP | AES-128, AES-192, AES-256, | 256, 320, 384 bits with 128, | Random number |
| 800-90Ar1] | with/without derivation | 192, 256 bits of security | generation | |
| function, with/without prediction resistance | strength | |||
| Hash_DRBG [SP | SHA-1, SHA-256, SHA-512 | 880, 1776 bits with 128, 256 | Random number | |
| 800-90Ar1] | with/without prediction resistance | bits of security strength | generation | |
| HMAC_DRBG [SP | SHA-1, SHA-256, SHA-512 | 320, 512, 1024 bits with 128, | Random number | |
| 800-90Ar1] | with/without prediction resistance | 256 bits of security strength | generation | |
| A4813 | KTS-IFC [SP 800- | KTS-OAEP-basic | 2048-15360 bits with 112-256 | Key transport |
| A4823 A4824 A4825 A4826 A5578 A5585 | 56Br2] | bits of security strength | ||
| A4813 | KAS-IFC-SSC | KAS1, KAS2 | 2048-15360 bits with 112-256 | Shared secret |
| A4823 A4824 A4825 A4826 A5578 A5585 | bits of security strength | computation | ||
| A4845 | KAS-FFC-SSC [SP | dhEphem | MODP-2048, MODP-3072, | Shared secret |
| 800-56Ar3] | (initiator/responder) | MODP-4096, MODP-6144, MODP-8192, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192 with 112-200 bits of security strength | computation | |
| A4813 | KAS-ECC-SSC [SP | Ephemeral Unified Model | P-224, P-256, P-384, P-521 | Shared secret |
| A4823 | 800-56Ar3] | (initiator/responder) | with 112, 128, 192, 256 bits of | computation |
| A4824 A4825 A4826 A5578 A5585 | security strength | |||
| A4813 | RSA [FIPS 186-5] | PKCS#1 v1.5 and PSS with | 2048-16384 bits with 112-256 | Signature |
| A4823 A4824 | SHA-224, SHA-256, SHA- 384, SHA-512, SHA- | bits of security strength | generation | |
| A4825 | RSA [FIPS 186-5] | 512/224, SHA-512/256, | 2048-16384 bits with 112-256 | Signature |
| A4826 | SHA3-224, SHA3-256, SHA3- | bits of security strength | verification | |
| A5578 A5585 | 384, SHA3-512 |
© 2025 Red Hat, Inc. / atsec information security corporation.
10 of 48
| A4813 A4823 A4824 A4825 A4826 A5578 A5585 | RSA [FIPS 186-4] | PKCS#1 v1.5 and PSS with SHA-224, SHA-256, SHA- 384, SHA-512, SHA- 512/224, SHA-512/256 | NIST SP 800-131Ar2 Legacy use: 1024 bits with 80 bits of security strength | Signature verification |
|---|---|---|---|---|
| A4813 | ECDSA [FIPS 186- | SHA-224, SHA-256, SHA- | P-224, P-256, P-384, P-521 | Signature generation |
| A4823 | 5] | 384, SHA-512, SHA- | with 112, 128, 192, 256 bits of | |
| A4824 A4825 A4826 A5578 A5585 | 512/224, SHA-512/256, | security strength | ||
| A4814 | SHA3-224, SHA3-256, SHA3- | |||
| A5587 | 384, SHA3-512 | |||
| A4813 | ECDSA [FIPS 186- | SHA-224, SHA-256, SHA- | Signature verification | |
| A4823 | 5] | 384, SHA-512, SHA- | ||
| A4824 A4825 A4826 A5578 A5585 | 512/224, SHA-512/256, | |||
| A4814 | SHA3-224, SHA3-256, SHA3- | |||
| A5587 | 384, SHA3-512 | |||
| A4845 | Safe primes [SP | SP 800-56Ar3 Section | MODP-2048, MODP-3072, | Key pair generation |
| 800-56Ar3] | 5.6.1.1.4 Testing | MODP-4096, MODP-6144, | ||
| Candidates | MODP-8192, ffdhe2048, ffdhe3072, ffdhe4096, | |||
| Safe primes [SP | SP 800-56Ar3 Sections | ffdhe6144, ffdhe8192 with | Key pair verification | |
| 800-56Ar3] | 5.6.2.1.2 and 5.6.2.1.4 | 112-200 bits of security strength | ||
| A4813 | RSA [FIPS 186-5] | FIPS 186-5 Appendix A.1.6 | 2048-15360 bits with 112-256 | Key pair generation |
| A4823 | Probable Primes with | bits of security strength | ||
| A4824 | Conditions Based on | |||
| A4825 A4826 | Auxiliary Probable Primes | |||
| A5578 | ECDSA [FIPS 186- | FIPS 186-5 Appendix A.2.2 | P-224, P-256, P-384, P-521 | Key pair generation |
| A5585 | 5] | Rejection Sampling | with 112, 128, 192, 256 bits of | |
| ECDSA [FIPS 186- 5] | N/A | security strength | Key pair verification | |
| Vendor | CKG [SP 800- | Safe primes | MODP-2048, MODP-3072, | Key pair generation |
| affirme | 133r2 Section 4] | MODP-4096, MODP-6144, | ||
| d | MODP-8192, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192 with 112-200 bits of security strength | |||
| RSA | 2048-16384 bits with 112-256 bits of security strength |
5] © 2025 Red Hat, Inc. / atsec information security corporation.
11 of 48
| ECDSA | P-224, P-256, P-384, P-521 with 112, 128, 192, 256 bits of security strength | |||
|---|---|---|---|---|
| Vendor | RSA [FIPS 186-4] | PKCS#1 v1.5 and PSS with | NIST SP 800-131Ar2 Legacy | Signature verification |
| affirme | SHA3-224, SHA3-256, SHA3- | use: 1024 bits with 80 bits of | ||
| d | [FIPS 140-3 IG C.C] | 384, SHA3-512 | security strength |
| Algorithm / Functions | Use / Function |
|---|---|
| AES GCM (external IV) | Encryption |
| HMAC (< 112-bit keys) | Message authentication |
| KBKDF, KDA OneStep, HKDF, ANS X9.42 KDF, ANS X9.63 KDF (< 112-bit keys) | KBKDF Key derivation KDA OneStep Key derivation HKDF Key derivation ANS X9.42 KDF Key derivation ANS X9.63 KDF Key derivation |
| KDA OneStep (SHAKE128, SHAKE256) | KDA OneStep Key derivation |
| ANS X9.42 KDF (SHAKE128, SHAKE256) | ANS X9.42 KDF Key derivation |
| ANS X9.63 KDF (SHA-1, SHAKE128, SHAKE256) | ANS X9.63 KDF Key derivation |
| SSH KDF (SHA-512/224, SHA-512/256, SHA-3, SHAKE128, SHAKE256) | SSH KDF Key derivation |
| TLS 1.2 KDF (SHA-1, SHA-224, SHA-512/224, SHA-512/256, SHA-3) | TLS 1.2 KDF Key derivation |
| TLS 1.3 KDF (SHA-1, SHA-224, SHA-512, SHA-512/224, SHA-512/256, SHA-3) | TLS 1.3 KDF Key derivation |
| PBKDF2 (short password; short salt; insufficient iterations; < 112-bit keys) | Password-based key derivation |
| RSA and ECDSA (pre-hashed message) | Signature generation component Signature verification component |
| RSA-PSS (invalid salt length) | Signature generation Signature verification |
The module does not offer any non-approved cryptographic algorithms that are allowed in approved services (with or without security claimed). Table 5 lists all non-approved cryptographic algorithms of the module employed by the nonapproved services in Table 10. © 2025 Red Hat, Inc. / atsec information security corporation.
12 of 48
Table 5 - Non-Approved Algorithms Not Allowed in the Approved Mode of Operation
Figure 1 shows a block diagram that represents the design of the module when the module is operational and providing services to other user space applications. In this diagram, the physical perimeter of the operational environment (a general-purpose computer on which the module is installed) is indicated by a purple dashed line. The cryptographic boundary is represented by the component painted in orange block, which consists only of the shared library implementing the FIPS provider (fips.so). Green lines indicate the flow of data between the cryptographic module and its operator application, through the logical interfaces defined in Section 3. Components in white are only included in the diagram for informational purposes. They are not included in the cryptographic boundary (and therefore not part of the module’s validation). For example, the kernel is responsible for managing system calls issued by the module itself, as well as other applications using the module for cryptographic services. Figure 1 – Software Block Diagram
Upon initialization, the module immediately performs all cryptographic algorithm self-tests (CASTs) as specified in Table 13. When all those self-tests pass successfully, the module automatically performs the pre-operational integrity test using the integrity value embedded in the fips.so file. Only if this integrity test also passed successfully, the module transitions to the operational state. No operator intervention is required to reach this point. The module operates in the approved mode of operation by default and can only transition into the non-approved mode by calling one of the nonapproved services listed in Table 10 of the Security Policy. © 2025 Red Hat, Inc. / atsec information security corporation.
13 of 48
In the operational state, the module accepts service requests from calling applications through its logical interfaces. At any point in the operational state, a calling application can end its process, thus causing the module to end its operation. The module supports two modes of operation:
14 of 48
| Physical Port | Logical Interface | Data that passes over port / interface |
|---|---|---|
| As a software-only module, the module does not have physical ports. Physical Ports are interpreted to be the physical ports of the hardware platform on which it runs. | Data Input | API input parameters |
| Data Output | API output parameters | |
| Control Input | API function calls | |
| Status Output | API return codes, error queue |
The logical interfaces are the APIs through which the applications request services. These logical interfaces are logically separated from each other by the API design. Table 6 summarizes the logical interfaces: Table 6 - Ports and Interfaces © 2025 Red Hat, Inc. / atsec information security corporation.
15 of 48
| Role | Service | Input | Output | |
|---|---|---|---|---|
| Crypto Officer | Message digest | Message | Digest value | |
| XOF | Message, output length | Digest value | ||
| Encryption | Plaintext, AES key | Ciphertext | ||
| Decryption | Ciphertext, AES key | Plaintext | ||
| Message authentication | Message, AES key or HMAC key | MAC tag | ||
| KBKDF Key derivation | Key-derivation key | KBKDF Derived key | ||
| KDA OneStep Key derivation | Shared secret | KDA OneStep Derived key | ||
| HKDF Key derivation | Shared secret | HKDF Derived key | ||
| ANS X9.42 KDF Key derivation | Shared secret | ANS X9.42 KDF Derived key | ||
| ANS X9.63 KDF Key derivation | Shared secret | ANS X9.63 KDF Derived key | ||
| SSH KDF Key derivation | Shared secret | SSH KDF Derived key | ||
| TLS 1.2 KDF Key derivation | Shared secret, EMS check | TLS 1.2 KDF Derived key | ||
| TLS 1.3 KDF Key derivation | Shared secret, EMS check | TLS 1.3 KDF Derived key | ||
| Password-based key derivation | Password, salt, iteration count | PBKDF2 Derived key | ||
| Random number generation | Output length | Random bytes | ||
| Shared secret computation | Owner private key, peer public key | Shared secret | ||
| Signature generation component | Pre-hashed message, private key | Signature | ||
| Signature verification component | Pre-hashed message, public key, signature | Pass/fail | ||
| Signature generation | Message, private key, hashing algo | Signature | ||
| Signature verification | Message, public key, signature, hashing algo | Pass/fail | ||
| Key Transport (encapsulation) | RSA public key, plaintext key | Wrapped key |
The module supports the Crypto Officer role only. This sole role is implicitly and always assumed by the operator of the module. No support is provided for multiple concurrent operators or a maintenance role. Table 7 lists the roles supported by the module with corresponding services with input and output parameters. © 2025 Red Hat, Inc. / atsec information security corporation.
16 of 48
| Key pair generation | Key size | Key pair |
|---|---|---|
| Key pair verification | Key pair | Pass/fail |
| Show version | N/A | Name and version information |
| Show status | N/A | Module status |
| Self-test | N/A | Pass/fail results of self-tests |
| Zeroization | Any SSP | N/A |
| Context | Service Indicator |
|---|---|
| EVP_CIPHER_CTX | OSSL_CIPHER_PARAM_REDHAT_FIPS_INDICATOR |
| EVP_MAC_CTX | OSSL_MAC_PARAM_REDHAT_FIPS_INDICATOR |
| EVP_KDF_CTX | OSSL_KDF_PARAM_REDHAT_FIPS_INDICATOR |
| EVP_PKEY_CTX | OSSL_SIGNATURE_PARAM_REDHAT_FIPS_INDICATOR |
| EVP_PKEY_CTX | OSSL_ASYM_CIPHER_PARAM_REDHAT_FIPS_INDICATOR |
| EVP_PKEY_CTX | OSSL_KEM_PARAM_REDHAT_FIPS_INDICATOR |
Key Transport (un- RSA private key, wrapped Plaintext Key encapsulation) key Table 7 - Roles, Service Commands, Input and Output
The module does not support authentication for roles.
The module provides services to operators that assume the available role. All services are described in detail in the API documentation (manual pages). The next tables define the services that utilize approved and non-approved security functions in this module. For the respective tables, the convention below applies when specifying the access permissions (types) that the service has for each SSP.
17 of 48
| Service | Descriptio n | Approved Security Functions | Keys and/or SSPs | Roles | Access rights to Keys and/or SSPs | Indicator |
|---|---|---|---|---|---|---|
| Message digest | Compute a message digest | SHA-1, SHA-224, SHA- 256, SHA-384, SHA- 512, SHA-512/224, SHA-512/256, SHA3- 224, SHA3-256, SHA3- 384, SHA3-512 | N/A | CO | N/A | EVP_DigestFinal_ex returns 1 |
| XOF | Compute the output of an XOF | SHAKE128, SHAKE256 | N/A | CO | N/A | EVP_DigestFinalXOF returns 1 |
| Encryption | Encrypt a plaintext | AES ECB, CBC, CBC- CTS-CS1, CBC-CTS- CS2, CBC-CTS-CS3, CFB1, CFB8, CFB128, CTR, OFB, CCM, KW, KWP, GCM, XTS | AES key | CO | W, E | AES GCM: EVP_CIPHER_REDHAT _FIPS_INDICATOR_APP ROVED Others: EVP_EncryptFinal_ex returns 1 |
| Decryption | Decrypt a ciphertext | CO | W, E | AES GCM: EVP_CIPHER_REDHAT _FIPS_INDICATOR_APP ROVED Others: EVP_DecryptFinal_ex returns 1 | ||
| Message authenticati on | Compute a MAC tag | AES CMAC AES GMAC HMAC SHA-1, HMAC SHA-224, HMAC SHA- 256, HMAC SHA-384, HMAC SHA-512, HMAC SHA-512/224, HMAC SHA-512/256, HMAC SHA3-224, HMAC SHA3-256, HMAC SHA3-384, HMAC SHA3-512 | AES key HMAC key | CO | W, E | HMAC: OSSL_MAC_PARAM_R EDHAT_FIPS_INDICAT OR_APPROVED Others: EVP_MAC_final returns 1 |
| KBKDF Key derivation | Derive a key from a key- derivation key | KBKDF | Key-derivation key | W, E | ||
| KBKDF Derived key | G, R | |||||
| DH Shared secret | W, E | |||||
| ECDH Shared secret | W, E |
Table 9 lists the approved services in this module, the algorithms involved, the Sensitive Security Parameters (SSPs) involved and how they are accessed, the roles that can request the service, and the respective service indicator. In this table, CO specifies the Crypto Officer role. derivation VED © 2025 Red Hat, Inc. / atsec information security corporation.
18 of 48
Service HKDF Key derivation ANS X9.42 KDF Key derivation ANS X9.63 KDF Key derivation SSH KDF Key derivation TLS 1.2 KDF Key derivation
Descriptio n
Approved Security Functions HKDF ANS X9.42 KDF ANS X9.63 KDF SSH KDF TLS 1.2 KDF
Keys and/or SSPs RSA Shared secret KDA OneStep Derived key DH Shared secret ECDH Shared secret RSA Shared secret HKDF Derived key DH Shared secret ECDH Shared secret RSA Shared secret ANS X9.42 KDF Derived key DH Shared secret ECDH Shared secret RSA Shared secret ANS X9.63 KDF Derived key DH Shared secret ECDH Shared secret SSH KDF Derived key DH Shared secret ECDH Shared secret TLS 1.2 KDF Derived key
Roles
Access rights to Keys and/or SSPs W, E G, R W, E W, E W, E G, R W, E W, E W, E G, R W, E W, E W, E G, R W, E W, E G, R W, E W, E G, R
Indicator
© 2025 Red Hat, Inc. / atsec information security corporation.
19 of 48
| Service TLS 1.3 KDF Key derivation | Descriptio n | Approved Security Functions TLS 1.3 KDF | Keys and/or SSPs DH Shared secret ECDH Shared secret TLS 1.3 KDF Derived key | Roles | Access rights to Keys and/or SSPs W, E W, E G, R | Indicator |
|---|---|---|---|---|---|---|
| Password- based key derivation | Derive a key from a password | PBKDF2 | Password | CO | W, E | EVP_KDF_REDHAT_FIP S_INDICATOR_APPRO VED |
| PBKDF2 Derived key | G, R | |||||
| Random number generation | Generate random bytes | CTR_DRBG | Entropy input | CO | W, E | EVP_RAND_generate returns 1 |
| DRBG seed | E, G | |||||
| DRBG Internal state (V, Key) | W, E, G | |||||
| Hash_DRBG | Entropy input | W, E | ||||
| DRBG seed | E, G | |||||
| DRBG Internal state (V, C) | W, E, G | |||||
| HMAC_DRBG | Entropy input | W, E | ||||
| DRBG seed | E, G | |||||
| DRBG Internal state (V, Key) | W, E, G | |||||
| Key transport (encapsulati on) | Key wrapping using KTS- OAEP-basic | RSA-OAEP Encrypt | RSA public key | CO | W, E | EVP_PKEY_REDHAT_FI PS_INDICATOR_APPR OVED |
| Plaintext key | W, E | |||||
| Wrapped key | R | |||||
| Key transport (un- encapsulatio n) | Key unwrapping using KTS- OAEP-basic | RSA-OAEP Decrypt | RSA private key | CO | W, E | |
| Wrapped key | W, E | |||||
| Plaintext key | R | |||||
| KAS-IFC-SSC | RSA private key (owner), RSA public key (peer) | W, E | EVP_PKEY_REDHAT_FI PS_INDICATOR_APPR OVED | |||
| RSA Shared secret | G, R | |||||
| KAS-FFC-SSC | DH private key (owner), DH public key (peer) | W, E |
© 2025 Red Hat, Inc. / atsec information security corporation.
20 of 48
| Service | Descriptio n | Approved Security Functions KAS-ECC-SSC | Keys and/or SSPs DH Shared secret EC private key (owner), EC public key (peer) ECDH Shared secret | Roles | Access rights to Keys and/or SSPs G, R W, E G, R | Indicator |
|---|---|---|---|---|---|---|
| Signature generation | Generate a signature | RSA signature generation/verificatio n (PKCS#1 v1.5 and PSS) ECDSA signature generation/verificatio n | RSA private key EC private key | CO | W, E | RSA: OSSL_RH_FIPSINDICA TOR_APPROVED and EVP_SIGNATURE_RED HAT_FIPS_INDICATOR _APPROVED ECDSA: OSSL_RH_FIPSINDICA TOR_APPROVED |
| Signature verification | Verify a signature | RSA public key EC public key | CO | W, E | ||
| Key pair generation | Generate a key pair | CKG CTR_DRBG, Hash_DRBG, HMAC_DRBG Safe primes key pair generation RSA key pair generation ECDSA key pair generation | DH private key, DH public key RSA private key, RSA public key EC private key, EC public key | CO | G, R | EVP_PKEY_generate returns 1 |
| Intermediate key generation value | G, E, Z | |||||
| Key pair verification Other FIPS-related Services | Verify a key pair | Safe primes key pair verification ECDSA key pair verification | DH private key, DH public key EC private key, EC public key | CO | W, E | EVP_PKEY_public_che ck or EVP_PKEY_private_ch eck or EVP_PKEY_check returns 1 |
| Show version | Return the name and version information | N/A | N/A | CO | N/A | None |
| Show status | Return the module status | N/A | N/A | CO | N/A | None |
© 2025 Red Hat, Inc. / atsec information security corporation.
21 of 48
| Service | Descriptio n | Approved Security Functions | Keys and/or SSPs | Roles | Access rights to Keys and/or SSPs | Indicator |
|---|---|---|---|---|---|---|
| Self-test | Perform the CASTs and integrity test | SHA-1, SHA-224, SHA- 256, SHA-512, SHA3- 256 AES ECB, KW, GCM HMAC KBKDF, KDA OneStep, HKDF, ANS X9.42 KDF, ANS X9.63 KDF, SSH KDF, TLS 1.2 KDF, TLS 1.3 KDF PBKDF2 CTR_DRBG, Hash_DRBG, HMAC_DRBG KAS-FFC-SSC, KAS- ECC-SSC RSA (OAEP and PKCS#1 v1.5) ECDSA See Table 13 for specifics | AES key HMAC key Key-derivation key Password DH private key, DH public key RSA private key, RSA public key EC private key, EC public key DH Shared secret ECDH Shared secret RSA Shared secret KBKDF Derived key KDA OneStep Derived key HKDF Derived key ANS X9.42 KDF Derived key ANS X9.63 KDF Derived key SSH KDF Derived key TLS 1.2 KDF Derived key TLS 1.3 KDF Derived key PBKDF2 Derived key DRBG seed DRBG Internal state (V, Key) DRBG Internal state (V, C) | CO | N/A | None |
| Zeroization | Zeroize all SSPs | N/A | Any SSP | CO | Z | None |
© 2025 Red Hat, Inc. / atsec information security corporation.
22 of 48
| Service | Description | Algorithms Accessed | Role |
|---|---|---|---|
| Encryption | Encrypt a plaintext | AES GCM (external IV) | CO |
| Message authentication | Compute a MAC tag | HMAC (< 112-bit keys) | CO |
| KBKDF Key derivation | Derive a key from a key-derivation key | KBKDF (< 112-bit keys) | CO |
| KDA OneStep Key derivation | Derive a key from a shared secret | KDA OneStep (< 112-bit keys) KDA OneStep (SHAKE128, SHAKE256) | |
| HKDF Key derivation | HKDF (< 112-bit keys) | ||
| ANS X9.42 KDF Key derivation | ANS X9.42 KDF (< 112-bit keys) ANS X9.42 KDF (SHAKE128, SHAKE256) | ||
| ANS X9.63 KDF Key derivation | ANS X9.63 KDF (< 112-bit keys) ANS X9.63 KDF (SHA-1, SHAKE128, SHAKE256) | ||
| SSH KDF Key derivation | SSH KDF (< 112-bit keys) SSH KDF (SHA-512/224, SHA-512/256, SHA-3, SHAKE128, SHAKE256) | ||
| TLS 1.2 KDF Key derivation | TLS 1.2 KDF (< 112-bit keys) TLS 1.2 KDF (SHA-1, SHA-224, SHA-512/224, SHA- 512/256, SHA-3) | ||
| TLS 1.3 KDF Key derivation | TLS 1.3 KDF (< 112-bit keys) TLS 1.3 KDF (SHA-1, SHA-224, SHA-512, SHA-512/224, SHA-512/256, SHA-3) | ||
| Password-based key derivation | Derive a key from a password | PBKDF2 (short password; short salt; insufficient iterations; < 112-bit keys) | CO |
| Signature generation component | Generate a signature | RSA and ECDSA signature generation/verification (pre- hashed message) | CO |
| Signature verification component | Verify a signature | CO | |
| Signature generation | Generate a signature | RSA-PSS (invalid salt length) | CO |
| Signature verification | Verify a signature |
Table 10 lists the non-approved services in this module, the algorithms involved, the roles that can request the service, and the respective service indicator. In this table, CO specifies the Crypto Officer Table 10 - Non-Approved Services © 2025 Red Hat, Inc. / atsec information security corporation.
23 of 48
The integrity of the module is verified by comparing a HMAC SHA-256 value calculated at run time with the HMAC SHA-256 value embedded in the fips.so file that was computed at build time.
Integrity tests are performed as part of the pre-operational self-tests, which are executed when the module is initialized. The integrity test may be invoked on-demand by unloading and subsequently re-initializing the module. This will perform (among others) the software integrity test. © 2025 Red Hat, Inc. / atsec information security corporation.
24 of 48
The module operates in a modifiable operational environment per FIPS 140-3 level 1 specification: the module executes on a general purpose operating system (Red Hat Enterprise Linux 9), which allows modification, loading, and execution of software that is not part of the validated module.
See Section 2.2. The Red Hat Enterprise Linux operating system is used as the basis of other products which include but are not limited to:
The module shall be installed as stated in Section 11. If properly installed, the operating system provides process isolation and memory protection mechanisms that ensure appropriate separation for memory access among the processes on the system. Each process has control over its own data and uncontrolled access to the data of other processes is prevented. There are no concurrent operators. The module does not have the capability of loading software or firmware from an external source. Instrumentation tools like the ptrace system call, gdb and strace, userspace live patching, as well as other tracing mechanisms offered by the Linux environment such as ftrace or systemtap, shall not be used in the operational environment. The use of any of these tools implies that the cryptographic module is running in a non-validated operational environment. © 2025 Red Hat, Inc. / atsec information security corporation.
25 of 48
The module is comprised of software only and therefore this section is not applicable. © 2025 Red Hat, Inc. / atsec information security corporation.
26 of 48
This module does not implement any non-invasive security mechanism and therefore this section is not applicable. © 2025 Red Hat, Inc. / atsec information security corporation.
27 of 48
| Key / SSP Name / Type | Strength | Security Function and Cert. Number | Generation | Import / Export | Esta blish ment | Stor age | Zeroiza tion | Use and related keys |
|---|---|---|---|---|---|---|---|---|
| AES key (CSP) | AES-XTS: 128, 256 bits Rest of modes: 128, 192, 256 bits | AES AES CMAC AES GMAC A4809, A4810, A4811, A4812, A4815, A4816, A4817, A4818, A4819, A4820, A4821, A4822, A4837, A4838, A4839, A4840, A4841, A5560, A5576, A5577, A5579, A5580, A5581, A5582, A5583, A5584, A5586 | N/A | MD/EE Import: API input pa- rameters From: Opera- tor calling ap- plication (TOEPP) To: Crypto- graphic mod- ule Export: None | N/A | RAM | EVP_CI- PHER_CTX_f ree EVP_MAC_C TX_free | Use: Encryption Decryption Message au- thentication Related SSPs: None |
| HMAC key (CSP) | 112-256 bits | HMAC A4813, A4814, A4823, A4824, A4825, A4826, A5578, A5585, A5587 | N/A | MD/EE Import: API input pa- rameters From: Opera- tor calling ap- plication (TOEPP) To: Crypto- graphic mod- ule Export: None | N/A | RAM | EVP_MAC_C TX_free | Use: Message au- thentication Related SSPs: None |
| Key-deriva- tion key (CSP) | 112-256 bits | KBKDF A4843 | N/A | MD/EE Import: API input pa- rameters From: Opera- tor calling ap- plication (TOEPP) To: Crypto- graphic mod- ule Export: None | N/A | RAM | EVP_KDF_CT X_free | Use: KBKDF Key deri- vation Related SSPs: KBKDF Derived key |
Table 11 summarizes the Sensitive Security Parameters (SSPs) that are used by the cryptographic services implemented in the module in the approved services (Table 9). SSPs (including CSPs) are directly imported as input parameters and exported as output parameters from the module. Because these SSPs are only transiently used for a specific service, they are by definition exclusive between approved and non-approved services. © 2025 Red Hat, Inc. / atsec information security corporation.
28 of 48
ECDH Sha- red secret (CSP)
112-256 bits
KAS-ECC-SSC KDA OneStep HKDF ANS X9.42 KDF ANS X9.63 KDF SSH KDF TLS 1.2 KDF TLS 1.3 KDF A4807 A4813 A4814 A4823 A4824 A4825 A4826 A4837 A4838 A4839 A4840 A4841 A4844 A5578 A5579 A5585 A5586 A5587
N/A
MD/EE Import: API input pa- rameters From: Opera- tor calling ap- plication (TOEPP) To: Crypto- graphic mod- ule Export: API output pa- rameters From: Crypto- graphic mod- ule To: Operator calling appli- cation (TOEPP)
SP 800- 56Ar3 (ECDH shared secret compu- tation)
RAM
EVP_KDF_CT X_free
Use: Shared secret computation KDA OneStep Key derivation HKDF Key deri- vation ANS X9.42 KDF Key derivation ANS X9.63 KDF Key derivation SSH KDF Key derivation TLS 1.2 KDF Key derivation TLS 1.3 KDF Key derivation Related SSPs: KDA OneStep Derived key HKDF Derived key ANS X9.42 KDF Derived key
rived key rived key rived key DH private key DH public key © 2025 Red Hat, Inc. / atsec information security corporation.
29 of 48
| RSA Shared secret (CSP) | 112-256 bits | KAS-IFC-SSC KDA OneStep HKDF ANS X9.42 KDF ANS X9.63 KDF SSH KDF TLS 1.2 KDF TLS 1.3 KDF A4807 A4813 A4814 A4823 A4824 A4825 A4826 A4837 A4838 A4839 A4840 A4841 A4844 A5578 A5579 A5585 A5586 A5587 | N/A | MD/EE Import: API input pa- rameters From: Opera- tor calling ap- plication (TOEPP) To: Crypto- graphic mod- ule Export: API output pa- rameters From: Crypto- graphic mod- ule To: Operator calling appli- cation (TOEPP) | SP 800- 56Br2 (IFC shared secret compu- tation) | RAM | EVP_KDF_CT X_free | Use: Shared secret computation KDA OneStep Key derivation HKDF Key deri- vation ANS X9.42 KDF Key derivation ANS X9.63 KDF Key derivation Related SSPs: KDA OneStep Derived key HKDF Derived key ANS X9.42 KDF Derived key ANS X9.63 KDF Derived key RSA private key RSA public key |
|---|---|---|---|---|---|---|---|---|
| Password (CSP) | Password strength: 108 - 10128 | PBKDF2 A4813, A4814, A4823, A4824, A4825, A4826, A5578, A5585, A5587 | N/A | MD/EE Import: API input pa- rameters From: Opera- tor calling ap- plication (TOEPP) To: Crypto- graphic mod- ule Export: None | N/A | RAM | EVP_KDF_CT X_free | Use: Password-based key derivation Related SSPs: PBKDF2 Derived key |
| KBKDF Deri- ved key (CSP) | 112-256 bits | KBKDF A4843 | SP 800-108r1 SP 800-133r2, Sec- tion 6.2 | MD/EE Import: None Export: API output pa- rameters From: Crypto- graphic mod- ule To: Operator | N/A | RAM | EVP_KDF_CT X_free | Use: KBKDF Key deri- vation Related SSPs: Key-derivation key |
rived key rived key rived key © 2025 Red Hat, Inc. / atsec information security corporation.
30 of 48
KDA OneStep Derived key (CSP) HKDF Deri- ved key (CSP) ANS X9.42 KDF De- rived key (CSP) ANS X9.63 KDF De- rived key (CSP) SSH KDF Derived key (CSP) TLS 1.2 KDF Derived key (CSP)
112-256 bits
KDA OneStep A4844 HKDF A4807 ANS X9.42 KDF A4813 A4814 A4823 A4824 A4825 A4826 A5578 A5585 A5587 ANS X9.63 KDF A4813 A4814 A4823 A4824 A4825 A4826 A5578 A5585 A5587 SSH KDF A4837 A4838 A4839 A4840 A4841 A5579 A5586 TLS 1.2 KDF A4813 A4823 A4824 A4825 A4826 A5578 A5585
SP 800-56Cr2 SP 800-133r2, Sec- tion 6.2 SP 800-135r1 SP 800-133r2, Sec- tion 6.2
MD/EE Import: None Export: API output pa- rameters From: Crypto- graphic mod- ule To: Operator calling appli- cation (TOEPP)
N/A
RAM
EVP_KDF_CT X_free
Use: KDA OneStep Key derivation Related SSPs: DH Shared se- cret ECDH Shared se- cret RSA Shared se- cret Use: HKDF Key deri- vation Related SSPs: DH Shared se- cret ECDH Shared se- cret RSA Shared se- cret Use: ANS X9.42 KDF Key derivation Related SSPs: DH Shared se- cret ECDH Shared se- cret RSA Shared se- cret Use: ANS X9.63 KDF Key derivation Related SSPs: DH Shared se- cret ECDH Shared se- cret RSA Shared se- cret Use: SSH KDF Key derivation Related SSPs: DH Shared se- cret ECDH Shared se- cret Use: TLS 1.2 KDF Key derivation Related SSPs: DH Shared se- cret
© 2025 Red Hat, Inc. / atsec information security corporation.
31 of 48
| TLS 1.3 KDF Derived key (CSP) | TLS 1.3 KDF A4807 | Use: TLS 1.3 KDF Key derivation Related SSPs: DH Shared se- cret ECDH Shared se- cret | ||||||
|---|---|---|---|---|---|---|---|---|
| PBKDF2 De- rived key (CSP) | PBKDF2 A4813 A4814 A4823 A4824 A4825 A4826 A5578 A5585 A5587 | SP 800-132 SP 800-133r2, Sec- tion 6.2 | Use: Password-based key derivation Related SSPs: Password | |||||
| Entropy in- put (CSP) | 112-336 bits | CTR_DRBG Hash_DRBG HMAC_DRBG A4808 | N/A | Import: None Export: None | N/A | RAM | EVP_RAND_ CTX_free | Use: Random number generation Related SSPs: DRBG seed |
| DRBG seed (CSP) IG D.L com- pliant | CTR_DRBG: 128, 192, 256 bits Hash_DRBG: 128, 256 bits HMAC_DRBG: 128, 256 bits | CTR_DRBG Hash_DRBG HMAC_DRBG | Import: None Export: None | N/A | RAM | EVP_RAND_ CTX_free | Use: Random number generation Related SSPs: Entropy input DRBG Internal state (V, Key) DRBG Internal state (V, C) | |
| DRBG Inter- nal state (V, Key) (CSP) IG D.L com- pliant | CTR_DRBG HMAC_DRBG A4808 | CTR_DRBG HMAC_DRBG | Import: None Export: None | N/A | RAM | EVP_RAND_ CTX_free | Use: Random number generation Related SSPs: DRBG seed | |
| DRBG Inter- nal state (V, C) (CSP) IG D.L com- pliant | Hash_DRBG A4808 | Hash_DRBG | ||||||
| DH private key (CSP) | 112-200 bits | KAS-FFC-SSC A4845 | SP 800-56Ar3 (safe primes) Section 5.6.1.1.4 Testing Candidates | MD/EE Import: API input pa- rameters From: Opera- tor calling ap- plication (TOEPP) To: Crypto- graphic mod- ule Export: API output pa- rameters From: | N/A | RAM | EVP_PKEY_fr ee | Use: Shared secret computation Key pair genera- tion Key pair verifica- tion Related SSPs: DH public key Intermediate key generation value |
| DH public key (PSP) | 112-200 bits | Use: Shared secret computation Key pair genera- tion |
© 2025 Red Hat, Inc. / atsec information security corporation.
32 of 48
| EC private key (CSP) EC public key (PSP) | 112, 128, 192, 256 bits 112, 128, 192, 256 bits | KAS-ECC-SSC ECDSA A4813, A4814, A4823, A4824, A4825, A4826, A5578, A5585, A5587 | FIPS 186-5 Appen- dix A.2.2 Rejection Sampling | MD/EE Import: API input pa- rameters From: Opera- tor calling ap- plication (TOEPP) To: Crypto- graphic mod- ule Export: API output pa- rameters From: Crypto- graphic mod- ule To: Operator calling appli- cation (TOEPP) | N/A | RAM | EVP_PKEY_fr ee | Use: Shared secret computation Signature gener- ation Key pair genera- tion Key pair verifica- tion Related SSPs: EC public key Intermediate key generation value Use: Shared secret computation Signature verifi- cation Key pair genera- tion Key pair verifica- tion Related SSPs: EC private key Intermediate key generation value |
|---|---|---|---|---|---|---|---|---|
| RSA private key (CSP) | 112-256 bits | RSA KTS- IFC KAS-IFC- SSC A4813, A4823, A4824, A4825, A4826, A5578, A5585 | FIPS 186-5 Appen- dix A.1.6 Probable Primes with Condi- tions Based on Auxiliary Probable Primes | MD/EE Import: API input pa- rameters From: Opera- tor calling ap- plication (TOEPP) To: Crypto- graphic mod- ule Export: API output pa- rameters From: Crypto- graphic mod- ule To: Operator calling appli- cation (TOEPP) | N/A | RAM | EVP_PKEY_fr ee | Use: Key pair genera- tion Shared secret computation Signature gener- ation Key un-encapsu- lation Related SSPs: RSA public key Intermediate key generation value |
| RSA public key (PSP) | Signature veri- fication: 80- 256 bits Others: 112- 256 bits | Use: Key pair genera- tion Shared secret computation Signature verifi- cation Key encapsula- tion |
module tion © 2025 Red Hat, Inc. / atsec information security corporation.
33 of 48
Intermedi- ate key generation value (CSP)
112-256 bits
CKG vendor affirmed
SP 800-133r2 Sec- tion 4, 5.1, and 5.2
Import: None Export: None
N/A
RAM
Automatic
Use: Key pair genera- tion Related SSPs: DH private key DH public key EC private key EC public key RSA private key RSA public key
| Entropy Source | Minimum number of bits of entropy | Details | |
|---|---|---|---|
| SP 800-90B compliant Non-Physical Entropy Source (ESV cert. E48) | 224 bits of entropy in the 256-bit output | OpenSSL CPU Jitter 2.2.0 entropy source is located within the physical perimeter of the module but partially outside the cryptographic boundary of the module. |
The module employs two Deterministic Random Bit Generator (DRBG) implementations based on SP 800-90Ar1. These DRBGs are used internally by the module (e.g. to generate seeds for asymmetric key pairs and random numbers for security functions). They can also be accessed using the specified API functions. The following parameters are used:
800-133r2. When random values are required, they are obtained from the SP 800-90Ar1 approved DRBG, compliant with Section 4 of SP 800-133r2. The following methods are implemented:
34 of 48
The module provides Diffie-Hellman (DH) and Elliptic Curve Diffie-Hellman (ECDH) shared secret computation compliant with SP800-56Ar3, in accordance with scenario 2 (1) of FIPS 140-3 IG D.F. For Diffie-Hellman, the module supports the use of the safe primes defined in RFC 3526 (IKE) and RFC 7919 (TLS). Note that the module only implements key pair generation, key pair verification, and shared secret computation. No other part of the IKE or TLS protocols is implemented (with the exception of the TLS 1.2 and 1.3 KDFs):
According to FIPS 140-3 IG D.B, the key sizes of DH and ECDH provide the following security strengths in the approved mode of operation:
35 of 48
The module offers RSA key wrapping and unwrapping using KTS-OAEP-basic scheme. The implementation supports 2048-15360 bits modulus size, with both key encapsulation and un-encapsulation supported. The module does not implement key confirmation. See section 11.2.4 for operator guidance details. The SSP establishment methodology provides 112 to 256 bits of encryption strength. The module also supports the AES KW, AES KWP, and AES GCM key wrapping mechanisms. These algorithms can be used to wrap SSPs with a security strength between 128 and 256 bits, depending on the wrapping key size.
The module only supports SSP entry and output to and from the calling application running on the same operational environment. This corresponds to manual distribution, electronic entry/output (“CM Software to/from App via TOEPP Path”) per FIPS 140-3 IG 9.5.A Table 1. There is no entry or output of cryptographically protected SSPs. SSPs can be entered into the module via API input parameters in plaintext form, when required by a service. SSPs can also be output from the module via API output parameters, immediately after generation of the SSP (see Section 9.2).
SSPs are provided to the module by the calling application and are destroyed when released by the appropriate API function calls. The module does not perform persistent storage of SSPs.
The memory occupied by SSPs is allocated by regular memory allocation operating system calls. The operator application is responsible for calling the appropriate destruction functions provided in the module’s API. The destruction functions (listed in Table 11) overwrite the memory occupied by SSPs with zeroes and de-allocate the memory with the regular memory de-allocation operating system call. All data output is inhibited during zeroization. © 2025 Red Hat, Inc. / atsec information security corporation.
36 of 48
| Algorithm | Parameters | Condition | Type | Test |
|---|---|---|---|---|
| HMAC | SHA-256 | Initialization (af- ter CASTs) | Pre-operational Integrity Test | MAC tag verification on fips.so file |
| SHA-1 | N/A | Initialization | Cryptographic Algorithm Self-Test | KAT digest generation |
| SHA-512 | N/A | Initialization | Cryptographic Algorithm Self-Test | KAT digest generation |
| SHA3-256 | N/A | Initialization | Cryptographic Algorithm Self-Test | KAT digest generation |
| AES GCM | 256-bit key | Initialization | Cryptographic Algorithm Self-Test | KAT encryption and decryption |
| AES ECB | 128-bit key | Initialization | Cryptographic Algorithm Self-Test | KAT decryption |
| KBKDF | HMAC SHA-256 in counter mode | Initialization | Cryptographic Algorithm Self-Test | KAT key derivation |
| KDA OneStep | SHA-224 | Initialization | Cryptographic Algorithm Self-Test | KAT key derivation |
| HKDF | SHA-256 | Initialization | Cryptographic Algorithm Self-Test | KAT key derivation |
| ANS X9.42 KDF | AES-128 KW with SHA-1 | Initialization | Cryptographic Algorithm Self-Test | KAT key derivation |
| ANS X9.63 KDF | SHA-256 | Initialization | Cryptographic Algorithm Self-Test | KAT key derivation |
| SSH KDF | SHA-1 | Initialization | Cryptographic Algorithm Self-Test | KAT key derivation |
| TLS 1.2 KDF | SHA-256 | Initialization | Cryptographic Algorithm Self-Test | KAT key derivation |
| TLS 1.3 KDF | SHA-256 | Initialization | Cryptographic Algorithm Self-Test | KAT key derivation |
| PBKDF2 | SHA-256 with 4096 iterations and 288-bit salt | Initialization | Cryptographic Algorithm Self-Test | KAT password-based key derivation |
| CTR_DRBG | AES-128 with derivation | Initialization | Cryptographic Algorithm | KAT DRBG generation and reseed |
The module performs pre-operational self-tests and conditional self-tests. While the module is executing the self-tests, services are not available, and data output (via the data output interface) is inhibited until the tests are successfully completed. The module does not return control to the calling application until the tests are completed. Both conditional and pre-operational self-tests can be executed on-demand by unloading and subsequently re-initializing the module. All the self-tests are listed in Table 12, with the respective condition under which those tests are performed. Note that the pre-operational integrity test is only executed after all cryptographic algorithm self-tests (CASTs) executed successfully. © 2025 Red Hat, Inc. / atsec information security corporation.
37 of 48
| Algorithm | Parameters function and prediction re- sistance | Condition | Type Self-Test | Test |
|---|---|---|---|---|
| Hash_DRBG | SHA-256 with prediction resi- stance | Initialization | Cryptographic Algorithm Self-Test | KAT DRBG generation and reseed |
| HMAC_DRBG | SHA-1 with prediction resi- stance | Initialization | Cryptographic Algorithm Self-Test | KAT DRBG generation and reseed |
| KAS-FFC-SSC | ffdhe2048 | Initialization | Cryptographic Algorithm Self-Test | KAT shared secret computation |
| KAS-ECC-SCC | P-256 | Initialization | Cryptographic Algorithm Self-Test | KAT shared secret computation |
| RSA2 | OAEP with 2048-bit key | Initialization | Cryptographic Algorithm Self-Test | KAT key encapsulation and un-en- capsulation |
| RSA | PKCS#1 v1.5 with SHA-256 and 2048-bit key | Initialization | Cryptographic Algorithm Self-Test | KAT signature generation and verifi- cation |
| ECDSA | SHA-256 and P-224, P-256, P- 384, and P-521 | Initialization | Cryptographic Algorithm Self-Test | KAT signature generation and verifi- cation |
| DH | N/A | DH key pair ge- neration | Pair-wise Consistency Test | Section 5.6.2.1.4 pair-wise consi- stency |
| RSA | PKCS#1 v1.5 with SHA-256 | RSA key pair ge- neration | Pair-wise Consistency Test | Sign/verify pair-wise consistency |
| ECDSA | SHA-256 | EC key pair ge- neration | Pair-wise Consistency Test | Sign/verify pair-wise consistency |
The module performs pre-operational tests automatically when the module is powered on. The pre-operational self-tests ensure that the module is not corrupted. The module transitions to the operational state only after the pre-operational self-tests are passed successfully. The types of pre-operational self-tests are described in the next sub-sections.
The integrity of the shared library component of the module is verified by comparing an HMAC SHA-256 value calculated at run time with the HMAC SHA-256 value embedded in the fips.so file that was computed at build time. If the software integrity test fails, the module transitions to the error state (Section 10.3). As mentioned previously, the HMAC and SHA-256 algorithms go through their respective CASTs before the software integrity test is performed.
2 According to FIPS IG 10.3.B and IG D.F scenario 1, this CAST also covers the self-test for the KAS-
IFC implementation. © 2025 Red Hat, Inc. / atsec information security corporation.
38 of 48
| Error State | Cause of Error | Status Indicator |
|---|---|---|
| Error | Software integrity test failure CAST failure | OSSL_PROV_PARAM_STATUS is set to 0 Module will not load |
| PCT failure | Module is aborted |
The module performs self-tests on all approved cryptographic algorithms as part of the approved services supported in the approved mode of operation, using the tests shown in Table 13. Data output through the data output interface is inhibited during the self-tests. If any of these tests fails, the module transitions to the error state (Section 10.3).
Upon generation of a DH, RSA or EC key pair, the module will perform a pair-wise consistency test (PCT) as shown in Table 13, which provides some assurance that the generated key pair is well formed. For DH key pairs, this test consists of the PCT described in Section 5.6.2.1.4 of SP 80056Ar3. For RSA and EC key pairs, this test consists of a signature generation and a signature verification operation. If the test fails, the module transitions to the error state (Section 10.3).
If the module fails any of the self-tests, the module enters the error state. In the error state, the module immediately stops functioning and ends the application process. Consequently, the data output interface is inhibited, and the module accepts no more inputs or requests (as the module is no longer running). Table 14 lists the error states and the status indicator values that explain the error that has occurred. Table 14 – Error States © 2025 Red Hat, Inc. / atsec information security corporation.
39 of 48
The module is distributed as a part of the Red Hat Enterprise Linux 9 (RHEL 9) package in the form of the openssl-3.0.7-18.el9_2 RPM package. Also, the module can be distributed using the opensslfips-provider-3.0.7-2.el9 RPM package.
As the module does not persistently store SSPs, secure sanitization of the module consists of unloading the module. This will zeroize all SSPs in volatile memory. Then, if desired, the installed RPM package can be uninstalled from the RHEL 9 system.
Before the RPM package is installed, the RHEL 9 system must operate in the approved mode. This can be achieved by:
The Crypto Officer shall consider the following requirements and restrictions when using the module. For TLS 1.2, the module offers the AES GCM implementation and uses the context of Scenario 1 of FIPS 140-3 IG C.H. OpenSSL 3 is compliant with SP 800-52r2 Section 3.3.1 and the mechanism for IV generation is compliant with RFC 5288 and 8446. The module does not implement the TLS protocol. The module’s implementation of AES GCM is used together with an application that runs outside the module’s cryptographic boundary. The design of the TLS protocol implicitly ensures that the counter (the nonce_explicit part of the IV) does not exhaust the maximum number of possible values for a given session key. In the event the module’s power is lost and restored, the consuming application must ensure that a new key for use with the AES GCM key encryption or decryption under this scenario shall be established. Alternatively, the Crypto Officer can use the module’s API to perform AES GCM encryption using internal IV generation. These IVs are always 96 bits and generated using the approved DRBG internal to the module’s boundary. This is in compliance with Scenario 2 of FIPS 140-3 IG C.H. © 2025 Red Hat, Inc. / atsec information security corporation.
40 of 48
The module also provides a non-approved AES GCM encryption service which accepts arbitrary external IVs from the operator. This service can be requested by invoking the EVP_EncryptInit_ex2 API function with a non-NULL IV value. When this is the case, the API will set a non-approved service indicator as described in Section 4.3. Finally, for TLS 1.3, the AES GCM implementation uses the context of Scenario 5 of FIPS 140-3 IG C.H. The protocol that provides this compliance is TLS 1.3, defined in RFC8446 of August 2018, using the cipher-suites that explicitly select AES GCM as the encryption/decryption cipher (Appendix B.4 of RFC8446). The module supports acceptable AES GCM cipher suites from Section 3.3.1 of SP800-52r2. TLS 1.3 employs separate 64-bit sequence numbers, one for protocol records that are received, and one for protocol records that are sent to a peer. These sequence numbers are set at zero at the beginning of a TLS 1.3 connection and each time when the AES-GCM key is changed. After reading or writing a record, the respective sequence number is incremented by one. The protocol specification determines that the sequence number should not wrap, and if this condition is observed, then the protocol implementation must either trigger a re-key of the session (i.e., a new key for AES-GCM), or terminate the connection.
The length of a single data unit encrypted or decrypted with AES XTS shall not exceed 220 AES blocks, that is 16MB, of data per XTS instance. An XTS instance is defined in Section 4 of SP 80038E. The XTS mode shall only be used for the cryptographic protection of data on storage devices. It shall not be used for other purposes, such as the encryption of data in transit. In compliance with IG C.I, the module implements the check to ensure that the two AES keys used in AES XTS are not identical.
The module provides password-based key derivation (PBKDF2), compliant with SP 800-132. The module supports option 1a from Section 5.4 of SP 800-132, in which the Master Key (MK) or a segment of it is used directly as the Data Protection Key (DPK). In accordance to SP 800-132 and FIPS 140-3 IG D.N, the following requirements shall be met:
To comply with the assurances found in Section 5.6.2 of SP 800-56Ar3, the operator must use the module together with an application that implements the SSH/TLS protocol. Additionally, the module’s approved key pair generation service (see Table 9) must be used to generate ephemeral Diffie-Hellman or EC Diffie-Hellman key pairs, or the key pairs must be obtained from another FIPSvalidated module. As part of this service, the module will internally perform the full public key validation of the generated public key. © 2025 Red Hat, Inc. / atsec information security corporation.
41 of 48
The module’s shared secret computation service will internally perform the full public key validation of the peer public key, complying with Sections 5.6.2.2.1 and 5.6.2.2.2 of SP 800-56Ar3.
To comply with SP800-56Br2 assurances found in its Section 6 (specifically SP800-56Br2 Section
6.4 Required Assurances) the entity using the module must obtain required assurances listed in
section 6.4 of SP 800-56Br2 by performing the following steps:
Only after the above assurances are successfully met, shall the entity use the peer’s public key to perform the RSA key wrapping (encapsulation) service of the module.
To comply with the assurances found in Section 6.4 of SP 800-56Br2, the module’s approved RSA key pair generation service (see Table 9) must be used to generate the RSA key pairs, or the key pairs must be obtained from another FIPS-validated module. As part of this service, the module will internally perform the key pair validity and the pairwise consistency according to section 6.4.1.1 of SP 800-56Br2. Additionally, the entity requesting the shared secret computation service shall verify the validity of the peer’s public key using the public key validation service of the module (EVP_PKEY_check() API). This service will perform the full public key validation of the peer’s public key, complying with Section 6.4.2.1 of SP 800-56Br2. © 2025 Red Hat, Inc. / atsec information security corporation.
42 of 48
Certain cryptographic subroutines and algorithms are vulnerable to timing analysis. The module mitigates this vulnerability by using constant-time implementations. This includes, but is not limited to:
43 of 48
Appendix A. Glossary and abbreviations AES Advanced Encryption Standard AES-NI Advanced Encryption Standard New Instructions API Application Programming Interface CAST Cryptographic Algorithm Self-Test CAVP Cryptographic Algorithm Validation Program CBC Cipher Block Chaining CCM Counter with Cipher Block Chaining-Message Authentication Code CFB Cipher Feedback CKG Cryptographic Key Generation CMAC Cipher-based Message Authentication Code CMVP Cryptographic Module Validation Program CSP Critical Security Parameter CTR Counter CTS Ciphertext Stealing DH Diffie-Hellman DRBG Deterministic Random Bit Generator ECB Electronic Code Book ECC Elliptic Curve Cryptography ECDH Elliptic Curve Diffie-Hellman ECDSA Elliptic Curve Digital Signature Algorithm EVP Envelope FFC Finite Field Cryptography FIPS Federal Information Processing Standards GCM Galois Counter Mode GMAC Galois Counter Mode Message Authentication Code HKDF HMAC-based Key Derivation Function HMAC Keyed-Hash Message Authentication Code IKE Internet Key Exchange KAS Key Agreement Scheme KAT Known Answer Test KBKDF Key-based Key Derivation Function KTS Key Transport Scheme KW Key Wrap KWP Key Wrap with Padding MAC Message Authentication Code NIST National Institute of Science and Technology OAEP Optimal Asymmetric Encryption Padding OFB Output Feedback © 2025 Red Hat, Inc. / atsec information security corporation.
44 of 48
PAA Processor Algorithm Acceleration PCT Pair-wise Consistency Test PBKDF2 Password-based Key Derivation Function v2 PKCS Public-Key Cryptography Standards PSS Probabilistic Signature Scheme RSA Rivest, Shamir, Addleman SHA Secure Hash Algorithm SSC Shared Secret Computation SSH Secure Shell SSP Sensitive Security Parameter TLS Transport Layer Security XOF Extendable Output Function XTS XEX-based Tweaked-codebook mode with cipher text Stealing © 2025 Red Hat, Inc. / atsec information security corporation.
45 of 48
| ANS X9.42-2001 | Public Key Cryptography for the Financial Services Industry: Agreement of Symmetric Keys Using Discrete Logarithm Cryptography 2001 https://webstore.ansi.org/standards/ascx9/ansix9422001 |
| ANS X9.63-2001 | Public Key Cryptography for the Financial Services Industry, Key Agreement and Key Transport Using Elliptic Curve Cryptography 2001 https://webstore.ansi.org/standards/ascx9/ansix9632001 |
| FIPS 140-3 | FIPS PUB 140-3 - Security Requirements For Cryptographic Modules March 2019 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-3.pdf |
| FIPS 140-3 IG | Implementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program November 2023 https://csrc.nist.gov/Projects/cryptographic-module-validation-program/fips-140-3-ig- announcements |
| FIPS 180-4 | Secure Hash Standard (SHS) August 2015 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf |
| FIPS 186-4 | Digital Signature Standard (DSS) July 2013 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-4.pdf |
| FIPS 186-5 | Digital Signature Standard (DSS) February 2023 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-5.pdf |
| FIPS 197 | Advanced Encryption Standard May 2023 https://csrc.nist.gov/publications/fips/fips197/fips-197.pdf |
| FIPS 198-1 | The Keyed Hash Message Authentication Code (HMAC) July 2008 https://csrc.nist.gov/publications/fips/fips198-1/FIPS-198-1_final.pdf |
| FIPS 202 | SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions August 2015 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.202.pdf |
| PKCS#1 | Public Key Cryptography Standards (PKCS) #1: RSA Cryptography Specifications Version 2.1 February 2003 https://www.ietf.org/rfc/rfc3447.txt |
| RFC 3526 | More Modular Exponential (MODP) Diffie-Hellman groups for Internet Key Exchange (IKE) May 2003 https://www.ietf.org/rfc/rfc3526.txt © 2025 Red Hat, Inc. / atsec information security corporation. 46 of 48 |
| RFC 5288 | AES Galois Counter Mode (GCM) Cipher Suites for TLS August 2008 https://www.ietf.org/rfc/rfc5288.txt |
| RFC 7919 | Negotiated Finite Field Diffie-Hellman Ephemeral Parameters for Transport Layer Security (TLS) August 2016 https://www.ietf.org/rfc/rfc7919.txt |
| RFC 8446 | The Transport Layer Security (TLS) Protocol Version 1.3 August 2018 https://www.ietf.org/rfc/rfc8446.txt |
| SP 800-38A | Recommendation for Block Cipher Modes of Operation Methods and Techniques December 2001 https://csrc.nist.gov/publications/nistpubs/800-38a/sp800-38a.pdf |
| SP 800-38A | Recommendation for Block Cipher Modes of Operation: Three Variants of |
| Addendum | Ciphertext Stealing for CBC Mode October 2010 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38a-add.pdf |
| SP 800-38B | Recommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication May 2005 https://csrc.nist.gov/publications/nistpubs/800-38B/SP_800-38B.pdf |
| SP 800-38C | Recommendation for Block Cipher Modes of Operation: the CCM Mode for Authentication and Confidentiality May 2004 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38c.pdf |
| SP 800-38D | Recommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC November 2007 https://csrc.nist.gov/publications/nistpubs/800-38D/SP-800-38D.pdf |
| SP 800-38E | Recommendation for Block Cipher Modes of Operation: The XTS AES Mode for Confidentiality on Storage Devices January 2010 https://csrc.nist.gov/publications/nistpubs/800-38E/nist-sp-800-38E.pdf |
| SP 800-38F | Recommendation for Block Cipher Modes of Operation: Methods for Key Wrapping December 2012 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38F.pdf |
| SP 800-52r2 | Guidelines for the Selection, Configuration, and Use of Transport Layer Security (TLS) Implementations August 2019 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-52r2.pdf |
| SP 800-56Ar3 | Recommendation for Pair-Wise Key Establishment Schemes Using Discrete Logarithm Cryptography April 2018 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Ar3.pdf © 2025 Red Hat, Inc. / atsec information security corporation. 47 of 48 |
| SP 800-56Br2 | Recommendation for Pair-Wise Key Establishment Schemes Using Discrete Logarithm Cryptography March 2019 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Br2.pdf |
| SP 800-56Cr2 | Recommendation for Key-Derivation Methods in Key-Establishment Schemes August 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Cr2.pdf |
| SP 800-90Ar1 | Recommendation for Random Number Generation Using Deterministic Random Bit Generators June 2015 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90Ar1.pdf |
| SP 800-90B | Recommendation for the Entropy Sources Used for Random Bit Generation January 2018 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90B.pdf |
| SP 800-108r1 | NIST Special Publication 800-108 - Recommendation for Key Derivation Using Pseudorandom Functions August 2022 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-108r1.pdf |
| SP 800-131Ar2 | Transitioning the Use of Cryptographic Algorithms and Key Lengths March 2019 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar2.pdf |
| SP 800-132 | Recommendation for Password-Based Key Derivation - Part 1: Storage Applications December 2010 https://csrc.nist.gov/publications/nistpubs/800-132/nist-sp800-132.pdf |
| SP 800-133r2 | Recommendation for Cryptographic Key Generation June 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-133r2.pdf |
| SP 800-135r1 | Recommendation for Existing Application-Specific Key Derivation Functions December 2011 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-135r1.pdf © 2025 Red Hat, Inc. / atsec information security corporation. 48 of 48 |