All modules
CMVP Validated Module · FIPS 140-3 Security Policy

CiscoSSL FIPS Provider

Certificate#4891StandardFIPS 140-3Level1TypeFirmwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorCisco Systems, Inc
Medium review priority  ·  no TCB surface named  ·  last validated 20 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeFirmware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date11/17/2029
CaveatInterim validation. When operated in approved mode. No assurance of the minimum strength of generated SSPs (e.g., keys)
VendorCisco Systems, Inc

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for CiscoSSL FIPS Provider
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Recovery</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Status Output</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>SSH<br/>IKEV</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for CiscoSSL FIPS Provider
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Recovery</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Status Output</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>SSH<br/>IKEV</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Cisco Systems, Inc CiscoSSL FIPS Provider Americas Headquarters: Cisco Systems, Inc., 170 West Tasman Drive, San Jose, CA 95134-1706 USA

Page 2
Table of Contents
#SectionPage
Page 4
List of Tables
ItemPage
Table 1: Security Levels5
Table 2: Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets)7
Table 3: Tested Operational Environments - Software, Firmware, Hybrid7
Table 4: Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid7
Table 5: Modes List and Description8
Table 6: Approved Algorithms - PAA14
Table 7: Approved Algorithms - Non-PAA19
Table 8: Vendor-Affirmed Algorithms20
Table 9: Non-Approved, Not Allowed Algorithms20
Table 10: Security Function Implementations27
Table 11: Entropy Sources29
Table 12: Ports and Interfaces30
Table 13: Roles31
Table 14: Approved Services36
Table 15: Non-Approved Services37
Table 16: Storage Areas38
Table 17: SSP Input-Output Methods38
Table 18: SSP Zeroization Methods39
Table 19: SSP Table 143
Table 20: SSP Table 247
Table 21: Pre-Operational Self-Tests48
Table 22: Conditional Self-Tests58
Table 23: Pre-Operational Periodic Information58
Table 24: Conditional Periodic Information64
Table 25: Error States64
Figure 1: Block Diagram6
Page 5
SectionTitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication1
5Software/Firmware security1
6Operational environment1
7Physical security1
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacks1
Overall Level1
1.1 Overview

FIPS Provider, firmware version 8.0. This Security Policy is provided in accordance with ISO/IEC 19790 Annex B, FIPS 140-3, and SP 800-140B. This Security Policy was prepared as part of the Level 1 FIPS 140-3 validation of the CiscoSSL FIPS provider, and the module meets the overall Level 1 requirements. The following table lists the level of validation for each area in the FIPS PUB 140-3.

1.2 Security Levels
2.1 Description

Purpose and Use: The CiscoSSL FIPS Provider is a firmware library that provides cryptographic services to a vast array of Cisco's networking and collaboration products. The cryptographic module provides the cipher operations and Key Derivation functions to support the following protocols: IKEv2/IPSec, sRTP, SSH, TLS, SNMPv3, ANS X9.42, and ANS X.9.63. Full implementations of these protocols are not supported by the module. No parts of the protocols, other than the KDF, have been tested by the CAVP or CMVP. The tested module version is 8.0. The overall security level is 1. The object code in the object module file is incorporated into the runtime executable application at the time the binary executable is generated. The module is provided in an executable form

Page 6

(as fips.so shared object). The module performs no communications other than with the consuming host application (the process that invokes the module services via the module’s API), which can be considered as the host for the module. Module Type: Firmware Module Embodiment: MultiChipStand Module Characteristics: Cryptographic Boundary: The cryptographic boundary of the module is the CiscoSSL FIPS Provider, a dynamically loadable library. The module is comprised of a single object module file called fips.so. The module performs no communication other than with the calling application via APIs that invoke the module. Tested Operational Environment’s Physical Perimeter (TOEPP): The module’s TOEPP is the physical perimeter of the tested platforms listed in Table “Tested Operational Environments - Software, Firmware, Hybrid” below. The components of the TOEPP include: Hardware components [Cisco UCS, Storage, RAM, Network Interface Cards]. The module’s block diagram is shown in Figure 1 below. The dashed orange border in the figure denotes the cryptographic boundary of the module. The green border denotes the TOEPP of the module. TOEPP Figure 1: Block Diagram

Page 7
Package or File NameSoftware/ Firmware VersionFeaturesIntegrity Test
fips.so8.0HMAC SHA2-256
Operating SystemHardware PlatformProcessorsPAA/PAIHypervisor or Host OSVersion(s)
Cisco IOS-XE 17.14Cisco Unified Computing System (UCS)Intel Xeon Gold 6244YesESXi 7.08.0
Cisco IOS-XE 17.14Cisco Unified Computing System (UCS)Intel Xeon Gold 6244NoESXi 7.08.0
OperatingHardware
SystemPlatform
N/AN/A
2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification

2.3 Excluded Components

There are no components excluded from the module.

Page 8
Mode NameDescriptionTypeStatus Indicator
Approved ModeProvides services approved by FIPS 140-3ApprovedReturns 1 when approved services are run successfully
Non- Approved ModeProvides services not approved for use in FIPS 140-3Non- ApprovedReturns 3, ED25519, ED448, X25519, X448 when non-approved services are run successfully
AlgorithmCAVP CertPropertiesReference
AES-CBCA3032Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS1A3032Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS2A3032Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS3A3032Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CCMA3032Key Length - 128, 192, 256SP 800-38C
AES-CFB1A3032Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
2.4 Modes of Operation

Modes List and Description: Table 5: Modes List and Description The module supports both approved and non-approved modes of operation. The module will only enter the approved mode if the module is reloaded and the call to SELF_TEST_post() succeeds, and only approved services are invoked. The module enters non-approved mode when a non-approved service is invoked. Mode Change Instructions and Status: When a non-approved service is invoked while in approved mode of operation, the module implicitly transitions to a non-approved mode. Similarly, when a call to an approved service is made while in non-approved mode of operation, the module transitions to approved mode of operation. The mode can be identified by the indicator, as listed in the table “Modes List and Description” above.

2.5 Algorithms
Page 9
AlgorithmCAVP CertPropertiesReference
AES-CFB128A3032Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB8A3032Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CMACA3032Direction - Generation, Verification Key Length - 128, 192, 256SP 800-38B
AES-CTRA3032Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA3032Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-GCMA3032Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GMACA3032Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-KWA3032Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-KWPA3032Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-OFBA3032Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-XTS Testing Revision 2.0A3032Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38E
Counter DRBGA3032Prediction Resistance - Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - No, YesSP 800-90A Rev. 1
DSA KeyGen (FIPS186-4)A3032L - 2048, 3072 N - 224, 256FIPS 186-4
DSA PQGGen (FIPS186-4)A3032L - 2048, 3072 N - 224, 256 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2- 512/256FIPS 186-4
DSA PQGVer (FIPS186-4)A3032L - 1024, 2048, 3072 N - 160, 224, 256 Hash Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256FIPS 186-4
DSA SigGen (FIPS186-4)A3032L - 2048, 3072 N - 224, 256 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2- 512/256FIPS 186-4
Page 10
AlgorithmCAVP CertPropertiesReference
DSA SigVer (FIPS186-4)A3032L - 1024, 2048, 3072 N - 160, 224, 256 Hash Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256FIPS 186-4
ECDSA KeyGen (FIPS186-4)A3032Curve - P-256, P-384, P-521 Secret Generation Mode - Testing CandidatesFIPS 186-4
ECDSA KeyVer (FIPS186-4)A3032Curve - P-256, P-384, P-521FIPS 186-4
ECDSA SigGen (FIPS186-4)A3032Component - No, Yes Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2- 512/256FIPS 186-4
ECDSA SigVer (FIPS186-4)A3032Component - No Curve - P-256, P-384, P-521 Hash Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256FIPS 186-4
Hash DRBGA3032Prediction Resistance - Yes Mode - SHA-1, SHA2-224, SHA2-256, SHA2- 384, SHA2-512, SHA2-512/224, SHA2- 512/256SP 800-90A Rev. 1
HMAC DRBGA3032Prediction Resistance - Yes Mode - SHA-1, SHA2-224, SHA2-256, SHA2- 384, SHA2-512, SHA2-512/224, SHA2- 512/256SP 800-90A Rev. 1
HMAC-SHA-1A3032Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2-224A3032Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2-256A3032Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2-384A3032Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2-512A3032Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/224A3032Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/256A3032Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA3-224A3032Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA3-256A3032Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
Page 11
AlgorithmCAVP CertPropertiesReference
HMAC-SHA3-384A3032Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA3-512A3032Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
KAS-ECC CDH- Component SP800-56Ar3 (CVL)A3032Curve - P-256, P-384, P-521SP 800-56A Rev. 3
KAS-ECC-SSC Sp800-56Ar3A3032Domain Parameter Generation Methods - P- 256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KAS-FFC-SSC Sp800-56Ar3A3032Domain Parameter Generation Methods - FB, FC, ffdhe2048, ffdhe3072, ffdhe4096, modp- 2048, modp-3072, modp-4096 Scheme - dhEphem - KAS Role - initiator, responderSP 800-56A Rev. 3
KAS-IFC-SSCA3032Modulo - 2048, 3072, 4096, 6144, 8192 Key Generation Methods - rsakpg1-basic, rsakpg1-crt, rsakpg1-prime-factor, rsakpg2- basic, rsakpg2-crt, rsakpg2-prime-factor Scheme - KAS1 - KAS Role - initiator, responder KAS2 - KAS Role - initiator, responderSP 800-56A Rev. 3
KDA HKDF SP800- 56Cr2A3032Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8 HMAC Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512SP 800-56C Rev. 2
KDA OneStep SP800-56Cr2A3032Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8SP 800-56C Rev. 2
KDA TwoStep SP800-56Cr2A3032MAC Salting Methods - default, random KDF Mode - feedback Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8SP 800-56C Rev. 2
KDF ANS 9.42 (CVL)A3032KDF Type - DER Hash Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2-512/224,SP 800-135 Rev. 1
Page 12
AlgorithmCAVP CertProperties SHA2-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512 Key Data Length - Key Data Length: 8-4096 Increment 8Reference
KDF ANS 9.63 (CVL)A3032Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512 Key Data Length - Key Data Length: 128, 4096SP 800-135 Rev. 1
KDF IKEv2 (CVL)A3032Diffie-Hellman Shared Secret Length - Diffie- Hellman Shared Secret Length: 2048 Derived Keying Material Length - Derived Keying Material Length: 3072 Hash Algorithm - SHA-1SP 800-135 Rev. 1
KDF SNMP (CVL)A3032Password Length - Password Length: 256, 64SP 800-135 Rev. 1
KDF SP800-108A3032KDF Mode - Counter, Feedback Supported Lengths - Supported Lengths: 8, 72, 128, 776, 3456, 4096SP 800-108 Rev. 1
KDF SRTP (CVL)A3032AES Key Length - 128, 192, 256SP 800-135 Rev. 1
KDF SSH (CVL)A3032Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512SP 800-135 Rev. 1
KMAC-128A3032Message Length - Message Length: 0-65536 Increment 8 Key Data Length - Key Data Length: 128-1024 Increment 8SP 800-185
KMAC-256A3032Message Length - Message Length: 0-65536 Increment 8 Key Data Length - Key Data Length: 128-1024 Increment 8SP 800-185
KTS-IFCA3032Modulo - 2048, 3072, 4096, 6144 Key Generation Methods - rsakpg1-basic, rsakpg1-crt, rsakpg1-prime-factor, rsakpg2- basic, rsakpg2-crt, rsakpg2-prime-factor Scheme - KTS-OAEP-basic - KAS Role - initiator, responder Key Transport Method - Key Length - 1024SP 800-56B Rev. 2
PBKDFA3032Iteration Count - Iteration Count: 1-10000 Increment 1 Password Length - Password Length: 8-128 Increment 8SP 800-132
RSA KeyGen (FIPS186-4)A3032Key Generation Mode - B.3.6 Modulo - 2048, 3072, 4096FIPS 186-4
Page 13
AlgorithmCAVP CertProperties Primality Tests - Table C.2 Private Key Format - StandardReference
RSA SigGen (FIPS186-4)A3032Signature Type - ANSI X9.31, PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096FIPS 186-4
RSA Signature Primitive (CVL)A3032Private Key Format - crtFIPS 186-4
RSA SigVer (FIPS186-4)A3032Signature Type - ANSI X9.31, PKCS 1.5, PKCSPSS Modulo - 1024, 2048, 3072, 4096FIPS 186-4
Safe Primes Key GenerationA3032Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, modp-2048, modp-3072, modp- 4096SP 800-56A Rev. 3
Safe Primes Key VerificationA3032Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, modp-2048, modp-3072, modp- 4096SP 800-56A Rev. 3
SHA-1A3032Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-224A3032Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-256A3032Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-384A3032Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-512A3032Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-512/224A3032Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-512/256A3032Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA3-224A3032Message Length - Message Length: 0-65536 Increment 8FIPS 202
SHA3-256A3032Message Length - Message Length: 0-65536 Increment 8FIPS 202
SHA3-384A3032Message Length - Message Length: 0-65536 Increment 8FIPS 202
SHA3-512A3032Message Length - Message Length: 0-65536 Increment 8FIPS 202
SHAKE-128A3032Output Length - Output Length: 16-65536 Increment 8FIPS 202
SHAKE-256A3032Output Length - Output Length: 16-65536 Increment 8FIPS 202
TLS v1.2 KDF RFC7627 (CVL)A3032Hash Algorithm - SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
Page 14
AlgorithmCAVP CertPropertiesReference
TLS v1.3 KDF (CVL)A3032HMAC Algorithm - SHA2-256, SHA2-384 KDF Running Modes - DHE, PSK, PSK-DHESP 800-135 Rev. 1
TDES-CBCA3032Direction - DecryptSP 800-67 Rev. 2
TDES-CMACA3032Direction - VerificationSP 800-67 Rev. 2
TDES-ECBA3032Direction - DecryptSP 800-67 Rev. 2
AlgorithmCAVP CertPropertiesReference
AES-CBCA3252Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS1A3252Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS2A3252Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS3A3252Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CCMA3252Key Length - 128, 192, 256SP 800-38C
AES-CFB1A3252Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB128A3252Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB8A3252Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CMACA3252Direction - Generation, Verification Key Length - 128, 192, 256SP 800-38B
AES-CTRA3252Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA3252Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-GCMA3252Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GMACA3252Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-KWA3252Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-KWPA3252Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F

Table 6: Approved Algorithms - PAA Non-PAA

Page 15
AlgorithmCAVP CertPropertiesReference
AES-OFBA3252Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-XTS Testing Revision 2.0A3252Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38E
Counter DRBGA3252Prediction Resistance - Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - No, YesSP 800-90A Rev. 1
DSA KeyGen (FIPS186-4)A3252L - 2048, 3072 N - 224, 256FIPS 186-4
DSA PQGGen (FIPS186-4)A3252L - 2048, 3072 N - 224, 256 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2- 512/256FIPS 186-4
DSA PQGVer (FIPS186-4)A3252L - 1024, 2048, 3072 N - 160, 224, 256 Hash Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256FIPS 186-4
DSA SigGen (FIPS186-4)A3252L - 2048, 3072 N - 224, 256 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2- 512/256FIPS 186-4
DSA SigVer (FIPS186-4)A3252L - 1024, 2048, 3072 N - 160, 224, 256 Hash Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256FIPS 186-4
ECDSA KeyGen (FIPS186-4)A3252Curve - P-256, P-384, P-521 Secret Generation Mode - Testing CandidatesFIPS 186-4
ECDSA KeyVer (FIPS186-4)A3252Curve - P-256, P-384, P-521FIPS 186-4
ECDSA SigGen (FIPS186-4)A3252Component - No, Yes Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2- 512/256FIPS 186-4
ECDSA SigVer (FIPS186-4)A3252Component - No Curve - P-256, P-384, P-521 Hash Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256FIPS 186-4
Hash DRBGA3252Prediction Resistance - Yes Mode - SHA-1, SHA2-224, SHA2-256, SHA2-SP 800-90A Rev. 1
Page 16
AlgorithmCAVP CertProperties 384, SHA2-512, SHA2-512/224, SHA2- 512/256Reference
HMAC DRBGA3252Prediction Resistance - Yes Mode - SHA-1, SHA2-224, SHA2-256, SHA2- 384, SHA2-512, SHA2-512/224, SHA2- 512/256SP 800-90A Rev. 1
HMAC-SHA-1A3252Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2-224A3252Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2-256A3252Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2-384A3252Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2-512A3252Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/224A3252Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/256A3252Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA3-224A3252Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA3-256A3252Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA3-384A3252Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA3-512A3252Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
KAS-ECC CDH- Component SP800-56Ar3 (CVL)A3252Curve - P-256, P-384, P-521SP 800-56A Rev. 3
KAS-ECC-SSC Sp800-56Ar3A3252Domain Parameter Generation Methods - P- 256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KAS-FFC-SSC Sp800-56Ar3A3252Domain Parameter Generation Methods - FB, FC, ffdhe2048, ffdhe3072, ffdhe4096, modp- 2048, modp-3072, modp-4096 Scheme - dhEphem - KAS Role - initiator, responderSP 800-56A Rev. 3
KAS-IFC-SSCA3252Modulo - 2048, 3072, 4096, 6144, 8192 Key Generation Methods - rsakpg1-basic,SP 800-56A Rev. 3
Page 17
AlgorithmCAVP CertProperties rsakpg1-crt, rsakpg1-prime-factor, rsakpg2- basic, rsakpg2-crt, rsakpg2-prime-factor Scheme - KAS1 - KAS Role - initiator, responder KAS2 - KAS Role - initiator, responderReference
KDA HKDF SP800- 56Cr2A3252Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8 HMAC Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512SP 800-56C Rev. 2
KDA OneStep SP800-56Cr2A3252Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8SP 800-56C Rev. 2
KDA TwoStep SP800-56Cr2A3252MAC Salting Methods - default, random KDF Mode - feedback Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8SP 800-56C Rev. 2
KDF ANS 9.42 (CVL)A3252KDF Type - DER Hash Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3- 384, SHA3-512 Key Data Length - Key Data Length: 8-4096 Increment 8SP 800-135 Rev. 1
KDF ANS 9.63 (CVL)A3252Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512 Key Data Length - Key Data Length: 128, 4096SP 800-135 Rev. 1
KDF IKEv2 (CVL)A3252Diffie-Hellman Shared Secret Length - Diffie- Hellman Shared Secret Length: 2048 Derived Keying Material Length - Derived Keying Material Length: 3072 Hash Algorithm - SHA-1SP 800-135 Rev. 1
KDF SNMP (CVL)A3252Password Length - Password Length: 256, 64SP 800-135 Rev. 1
KDF SP800-108A3252KDF Mode - Counter, Feedback Supported Lengths - Supported Lengths: 8, 72, 128, 776, 3456, 4096SP 800-108 Rev. 1
KDF SRTP (CVL)A3252AES Key Length - 128, 192, 256SP 800-135 Rev. 1
Page 18
AlgorithmCAVP CertPropertiesReference
KDF SSH (CVL)A3252Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512SP 800-135 Rev. 1
KMAC-128A3252Message Length - Message Length: 0-65536 Increment 8 Key Data Length - Key Data Length: 128-1024 Increment 8SP 800-185
KMAC-256A3252Message Length - Message Length: 0-65536 Increment 8 Key Data Length - Key Data Length: 128-1024 Increment 8SP 800-185
KTS-IFCA3252Modulo - 2048, 3072, 4096, 6144 Key Generation Methods - rsakpg1-basic, rsakpg1-crt, rsakpg1-prime-factor, rsakpg2- basic, rsakpg2-crt, rsakpg2-prime-factor Scheme - KTS-OAEP-basic - KAS Role - initiator, responder Key Transport Method - Key Length - 1024SP 800-56B Rev. 2
PBKDFA3252Iteration Count - Iteration Count: 1-10000 Increment 1 Password Length - Password Length: 8-128 Increment 8SP 800-132
RSA KeyGen (FIPS186-4)A3252Key Generation Mode - B.3.6 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Private Key Format - StandardFIPS 186-4
RSA SigGen (FIPS186-4)A3252Signature Type - ANSI X9.31, PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096FIPS 186-4
RSA Signature Primitive (CVL)A3252Private Key Format - crtFIPS 186-4
RSA SigVer (FIPS186-4)A3252Signature Type - ANSI X9.31, PKCS 1.5, PKCSPSS Modulo - 1024, 2048, 3072, 4096FIPS 186-4
Safe Primes Key GenerationA3252Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, modp-2048, modp-3072, modp- 4096SP 800-56A Rev. 3
Safe Primes Key VerificationA3252Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, modp-2048, modp-3072, modp- 4096SP 800-56A Rev. 3
SHA-1A3252Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-224A3252Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
Page 19
AlgorithmCAVP CertPropertiesReference
SHA2-256A3252Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-384A3252Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-512A3252Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-512/224A3252Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-512/256A3252Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA3-224A3252Message Length - Message Length: 0-65536 Increment 8FIPS 202
SHA3-256A3252Message Length - Message Length: 0-65536 Increment 8FIPS 202
SHA3-384A3252Message Length - Message Length: 0-65536 Increment 8FIPS 202
SHA3-512A3252Message Length - Message Length: 0-65536 Increment 8FIPS 202
SHAKE-128A3252Output Length - Output Length: 16-65536 Increment 8FIPS 202
SHAKE-256A3252Output Length - Output Length: 16-65536 Increment 8FIPS 202
TLS v1.2 KDF RFC7627 (CVL)A3252Hash Algorithm - SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
TLS v1.3 KDF (CVL)A3252HMAC Algorithm - SHA2-256, SHA2-384 KDF Running Modes - DHE, PSK, PSK-DHESP 800-135 Rev. 1
TDES-CBCA3252Direction - DecryptSP 800-67 Rev. 2
TDES-CMACA3252Direction - VerificationSP 800-67 Rev. 2
TDES-ECBA3252Direction - DecryptSP 800-67 Rev. 2
NamePropertiesImplementationReference
CKG Section 4CiscoSSL FIPS Provider Cryptographic ImplementationSection 4 of NIST SP 800-133 rev2
CKG Section 4CiscoSSL FIPS Provider Cryptographic Implementation Non-PAASection 4 of NIST SP 800-133 rev2

Table 7: Approved Algorithms - Non-PAA The module implements the cryptographic algorithms listed in the above tables. The module also supports RSA KeyGen, SigGen and SigVer with modulus size greater than 4096, where CAVP testing is not available. Vendor-Affirmed Algorithms:

Page 20
NamePropertiesImplementationReference
CKG Section 5CiscoSSL FIPS Provider Cryptographic ImplementationSection 5 of NIST SP 800-133 rev2
CKG Section 5CiscoSSL FIPS Provider Cryptographic Implementation Non-PAASection 5 of NIST SP 800-133 rev2
CKG Section 6.2CiscoSSL FIPS Provider Cryptographic ImplementationSection 6 of NIST SP 800-133 rev2
CKG Section 6.2CiscoSSL FIPS Provider Cryptographic Implementation Non-PAASection 6 of NIST SP 800-133 rev2
CKG Section 6.1CiscoSSL FIPS Provider Cryptographic ImplementationSection 6 of NIST SP 800-133 rev2
CKG Section 6.1CiscoSSL FIPS Provider Cryptographic Implementation Non-PAASection 6 of NIST SP 800-133 rev2
NameUse and Function
EdDSA KeyGenAsymmetric Key Generation (Ed25519, Ed448, X25519, and X448)
EdDSA SigGenSignature generation using Edwards curves (ED25519, ED448)
EdDSA SigVerSignature verification using Edwards curves (ED25519, ED448)
RSA PrimitivesRSA Signature generation, verification, encrypt and decrypt primitives
NameTypeDescriptionPropertiesAlgorithms
Random Number GenerationDRBGUsed for random number andCounter DRBG Hash DRBG HMAC DRBG Counter DRBG

Table 8: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: N/A for this module. There are no non-approved and allowed algorithms, hence the table is excluded. Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. There are no algorithms that are non-approved but allowed with no security claimed, hence the table is excluded. Non-Approved, Not Allowed Algorithms: Table 9: Non-Approved, Not Allowed Algorithms

2.6 Security Function Implementations
Page 21
NameTypeDescriptionPropertiesAlgorithms
symmetric key generationHash DRBG HMAC DRBG
Asymmetric Key GenerationAsymKeyPair- KeyGenUsed to generate DSA, ECDSA, RSA, DH, ECDH, keysDSA KeyGen (FIPS186-4) ECDSA KeyGen (FIPS186-4) RSA KeyGen (FIPS186-4) DSA PQGGen (FIPS186-4) Safe Primes Key Generation DSA KeyGen (FIPS186-4) ECDSA KeyGen (FIPS186-4) RSA KeyGen (FIPS186-4) DSA PQGGen (FIPS186-4) Safe Primes Key Generation
Key Derivation Function (KDF)KAS-135KDF KAS-56CKDF KBKDF PBKDFUsed to derive keys using KBKDF, PBKDF2, HKDF, SP 800-56C rev2, One-Step KDF (KDA), Two- Step KDF (KDA), SP 800-135 rev1 TLS 1.2, SSHv2, SNMPv3, SRTP, IKEv2, ANSI X9.63- 2001, ANSI X9.42-2001 KDFs and TLS 1.3 KDFKDA HKDF SP800-56Cr2 KDF ANS 9.42 KDF ANS 9.63 KDF IKEv2 KDF SNMP KDF SP800- 108 KDF SRTP KDF SSH PBKDF TLS v1.2 KDF RFC7627 TLS v1.3 KDF KDA HKDF SP800-56Cr2 KDF ANS 9.42 KDF ANS 9.63 KDF IKEv2 KDF SNMP KDF SP800-
Page 22
NameTypeDescriptionPropertiesAlgorithms
108 KDF SRTP KDF SSH PBKDF TLS v1.2 KDF RFC7627 TLS v1.3 KDF KDA OneStep SP800-56Cr2 KDA TwoStep SP800-56Cr2 KDA OneStep SP800-56Cr2 KDA TwoStep SP800-56Cr2
Symmetric Encrypt/DecryptBC-Auth BC-UnAuthUsed to encrypt or decrypt data. TDES: decrypt only. Executes using AES EDK/TDES DK (passed in by the calling application)AES-CBC AES-CBC-CS1 AES-CBC-CS2 AES-CBC-CS3 AES-CCM AES-CFB1 AES-CFB128 AES-CFB8 AES-CTR AES-ECB AES-GCM AES-GMAC AES-OFB AES-XTS Testing Revision 2.0 AES-CBC AES-CBC-CS1 AES-CBC-CS2 AES-CBC-CS3 AES-CCM AES-CFB1 AES-CFB128 AES-CFB8 AES-CTR AES-ECB AES-GCM AES-GMAC AES-OFB AES-XTS Testing Revision 2.0
Page 23
NameTypeDescriptionPropertiesAlgorithms
TDES-CBC TDES-ECB TDES-CBC TDES-ECB
Message Digest (SHS)SHAUsed to generate a SHA-1, SHA-2, or SHA-3 message digestSHA-1 SHA2-224 SHA2-256 SHA2-384 SHA2-512 SHA2-512/224 SHA2-512/256 SHA3-224 SHA3-256 SHA3-384 SHA3-512 SHA-1 SHA2-224 SHA2-256 SHA2-384 SHA2-512 SHA2-512/224 SHA2-512/256 SHA3-224 SHA3-256 SHA3-384 SHA3-512 SHAKE-128 SHAKE-256 SHAKE-128 SHAKE-256
Keyed Hash (HMAC/KMAC/CMAC)MACUsed to generate or verify data integrity with HMAC, KMAC or CMAC. TDES: verify only. Executes using HMAC , KMAC, AES or TDES Key (passed in by the calling application)HMAC-SHA-1 HMAC-SHA2- 224 HMAC-SHA2- 256 HMAC-SHA2- 384 HMAC-SHA2- 512 HMAC-SHA2- 512/224 HMAC-SHA2- 512/256 HMAC-SHA3- 224 HMAC-SHA3- 256
Page 24
NameTypeDescriptionPropertiesAlgorithms
HMAC-SHA3- 384 HMAC-SHA3- 512 HMAC-SHA-1 HMAC-SHA2- 224 HMAC-SHA2- 256 HMAC-SHA2- 384 HMAC-SHA2- 512 HMAC-SHA2- 512/224 HMAC-SHA2- 512/256 HMAC-SHA3- 224 HMAC-SHA3- 256 HMAC-SHA3- 384 HMAC-SHA3- 512 KMAC-128 KMAC-256 KMAC-128 KMAC-256 AES-CMAC AES-CMAC TDES-CMAC TDES-CMAC
Key Wrapping (KW)BC-UnAuthUsed to encrypt a key value on behalf of the calling application. Executes using AES Key Wrapping Key (passed in by the calling application). Key sizes 128, 192 and 256 providing 128,AES-KW AES-KWP AES-KW AES-KWP
Page 25
NameTypeDescriptionPropertiesAlgorithms
192 and 256 bits of encryption strength. AES- KW, AES-KWP is CAVP tested per FIPS 140-3 IG D.G.
Key Agreement/Agreement Component (SP 800- 56A rev3, SP 800-56B rev2)KAS-SSCUsed to perform key agreement primitives on behalf of the calling application (does not establish keys into the module). Executes using DH Private, DH Public, EC DH Private, EC DH Public, RSA SGK, RSA SVK (passed in by the calling application). For ECC: Curves P-256, P-384 and P- 521 providing 128 to 256 bits of encryption strength. For FFC: 2048, 3072 and 4096 bit keys providing 112 to 152 bits of security strength. For IFC: 2048, 3072, 4096, 6144, 8192 bit modulusKAS-ECC CDH- Component SP800-56Ar3 KAS-ECC-SSC Sp800-56Ar3 KAS-FFC-SSC Sp800-56Ar3 KAS-IFC-SSC KAS-ECC CDH- Component SP800-56Ar3 KAS-ECC-SSC Sp800-56Ar3 KAS-FFC-SSC Sp800-56Ar3 KAS-IFC-SSC
Page 26
NameTypeDescriptionPropertiesAlgorithms
providing 112 to 200 bits of encryption strength. The module follows SP 800-56A rev3 KAS- ECC-SSC (FIPS 140-3 IG D.F Scenario 2 path 1), SP 800-56A rev3 KAS-FFC-SSC (FIPS 140-3 IG D.F Scenario 2 path 1) and SP 800-56B rev2 KAS-IFC-SSC (FIPS 140-3 IG D.F Scenario 1 path 1)
Digital SignatureDigSig-SigGen DigSig-SigVerUsed to generate or verify RSA, DSA, ECDSA, digital signatures. Executes using RSA SGK, RSA SVK; DSA SGK, DSA SVK; ECDSA SGK, ECDSA SVK, (passed in by the calling application)DSA SigGen (FIPS186-4) DSA SigVer (FIPS186-4) ECDSA SigGen (FIPS186-4) ECDSA SigVer (FIPS186-4) RSA SigGen (FIPS186-4) DSA SigGen (FIPS186-4) DSA SigVer (FIPS186-4) ECDSA SigGen (FIPS186-4) ECDSA SigVer (FIPS186-4) RSA SigGen (FIPS186-4) DSA PQGVer (FIPS186-4) DSA PQGVer (FIPS186-4)
Page 27
NameTypeDescriptionPropertiesAlgorithms
RSA Signature Primitive RSA SigVer (FIPS186-4) RSA Signature Primitive RSA SigVer (FIPS186-4)
Asymmetric Key VerificationAsymKeyPair- KeyVerUsed to verify ECDSA public key and SafePrime keysECDSA KeyVer (FIPS186-4) Safe Primes Key Verification ECDSA KeyVer (FIPS186-4) Safe Primes Key Verification
Key TransportKTS-EncapUsed for key transport, supports KTS- OAEP. 2048, 3072, 4096 and 6144 bit modulus providing 112 to 176 bits of encryption strength. The module follows SP 800-56B rev2 KTS-IFC (FIPS 140-3 IG D.G).KTS-IFC KTS-IFC

D.G). Table 10: Security Function Implementations

2.7 Algorithm Specific Information

AES GCM IV Generation In the case of AES-GCM, the IV generation method is user-selectable, and the value can be computed in more than one manner as follows:

Page 28
  1. TLS 1.2: The module’s AES-GCM implementation conforms to IG C.H, scenario #1, following RFC 5288. The module is compatible with TLS 1.2 protocol and provides the primitives to support the AES GCM cipher suites from SP 800-52 rev1 Section 3.3.1. The counter portion of the IV is set by the module within its cryptographic boundary. When the IV exhausts the maximum number of possible values for a given session key, the first party, client or server, to encounter this condition will trigger a handshake to establish a new encryption key in accordance with RFC 5246 for TLS 1.2, respectively.
  2. IKEv2: The module’s AES-GCM implementation conforms to IG C.H, scenario #1 following RFC 7296 for IPSec/IKEv2. The AES GCM IV is generated according to RFC5282. The counter portion of the IV is set by the module within its cryptographic boundary. When the IV exhausts the maximum number of possible values for a given session key, the first party, client or server, to encounter this condition will trigger a handshake to establish a new encryption key. In case the module’s power is lost and then restored, a new key for use with the AES GCM encryption/decryption shall be established.
  3. TLS 1.3: The module’s AES-GCM implementation conforms to IG C.H Scenario#5. The module is compatible with TLS v1.3 and provides support for the acceptable GCM cipher suites from Section 8.4 of RFC 8446 and confirms that the IV is generated and used within the protocol’s implementation. The counter portion of the IV is set by the module within its cryptographic boundary. In case the module’s power is lost and then restored, a new key for use with the AES GCM encryption/decryption must be established.
  4. Non-protocol specific usage: The module’s AES-GCM implementation conforms to IG C.H, scenario #3, when operating in approved mode of operation, AES GCM, IVs are generated both internally and deterministically and are a minimum of 96-bits in length as specified in SP 800-38D, Section 8.2.1. The selection of the IV construction method is the responsibility of the user of this cryptographic module. Note: Externally generated IVs are not allowed for AES-GCM encryption. PBKDF In line with the requirements of SP 800-132 and FIPS 140-3 IG D.N, keys generated using the approved PBKDF must only be used for storage applications. The algorithm uses option 1a as specified in SP 800-132 Section 5.4. Any other use of the approved PBKDF is non-conformant. In approved mode the module enforces that any password used must encode to at least 14 bytes (112 bits) and that the salt is at least 16 bytes (128 bits) long. The iteration count associated with the PBKDF should be as large as practical. As the module is a general-purpose firmware module, it is not possible to anticipate all the levels of use for the PBKDF, however a user of the module should also note that a password should at least contain enough entropy to be unguessable and contain enough entropy to reflect the security strength required for the key being generated. AES-XTS
Page 29
NameTypeOperational EnvironmentSample SizeEntropy per SampleConditioning Component
N/ANon-PhysicalN/AN/A

In line with the requirements of SP 800-38E and FIPS 140-3 IG C.I, the keys are generated independently according to Section 6.3 of SP 800-133 rev2 and verification of the keys (key1 ≠ key2) is performed before using them in the AES-XTS algorithm. Key Agreement The module implements the following CAVP tested key agreement methods: SP 800-56A rev3 KAS-ECC-SSC (FIPS 140-3 IG D.F Scenario 2 path

  1. SP 800-56A rev3 KAS-FFC-SSC (FIPS 140-3 IG D.F Scenario 2 path
  2. SP 800-56B rev2 KAS-IFC-SSC (FIPS 140-3 IG D.F Scenario 1 path
  3. SHA3 and SHAKE Per FIPS 140-3 IG C.C, all SHA3 and SHAKE functions are tested on all the operational environments. The higher-level algorithms using SHA3 (HMAC-SHA3) are also tested on all the operational environments. RSA Per FIPS 140-3 IG C.F, RSA SigGen is tested with 2048, 3072, 4096-bit modulus and RSA SigVer is tested with 1024, 2048, 3072, 4096-bit modulus. The module also supports RSA KeyGen, SigGen and SigVer with modulus size greater than 4096, for which CAVP testing is not available. Legacy use algorithms Per SP 800-131A rev2, TDES-CBC/TDES-ECB Decrypt, TDES-CMAC Verification, DSA/ECDSA/RSA SigVer using SHA-1 is allowed for legacy use.
2.8 RBG and Entropy

N/A for this module. Table 11: Entropy Sources N/A for this module. The module passively receives entropy from outside the boundary. The caveat “No assurance of the minimum strength of generated SSPs (e.g., keys)” applies to this module. Applications shall use entropy sources that meet the security strength required for the random number generation mechanism as shown in [SP 800-90A rev1] Table 2 (Hash_DRBG, HMAC_DRBG, CTR_DRBG). A minimum of 112-bits of entropy must be supplied. This entropy

Page 30
Physical PortLogical Interface(s)Data That Passes
N/AData InputAPI entry point data input stack parameters
N/AData OutputAPI output parameters resulting from call execution
N/AControl InputAPI entry point and corresponding stack parameters
N/AStatus OutputAPI return value resulting from call execution

is supplied by means of callback functions. Those functions must return an error if the minimum entropy strength cannot be met.

2.9 Key Generation

The module generates symmetric and asymmetric keys following the sections of SP 800-133 rev2 as specified in Table “Vendor-Affirmed Algorithms” above. Private and secret keys as well as seeds and entropy input are provided to the module by the calling application and are destroyed when released by the appropriate API function calls. Keys residing in internally allocated data structures (during the lifetime of an API call) can only be accessed using the module defined API. The operating system protects application space from unauthorized access. Only the calling application that creates or imports keys can use or export such keys. All API functions (Module Services) are executed by the calling application invoking an API. Each API either succeeds or fails and is logically non-interruptible from the point of view of the calling application. The module supports generation of ECDSA, RSA, DSA, EC Diffie-Hellman and Diffie-Hellman key pairs per Section 5 in SP 800-133 rev2. The output of SP 800-90A rev1 random bit generator is used for generating the seed used in asymmetric key generation. The module also complies with Sections 6.1 and 6.2 of SP 800-133 rev2.

2.10 Key Establishment

The module implements key agreement methods per FIPS 140-3 IG D.F and key transport methods per FIPS 140-3 IG D.G (SP 800-38F AES-KW and AES-KWP, SP 800-56B rev2 KTSIFC). Detailed information is provided in Table “Security Function Implementations” Section above.

2.11 Industry Protocols

In reference to FIPS 140-3 IG D.C, the module implements the KDFs of SSH, TLS, IKE, SRTP, SNMP, ANS X9.42 and ANS X9.63 but no parts of the protocols other than the approved cryptographic algorithms and the KDFs have been tested by the CAVP and CMVP.

3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

Table 12: Ports and Interfaces

Page 31
NameTypeOperator TypeAuthentication Methods
Crypto-OfficerRoleCrypto-OfficerNone
UserRoleUserNone
NameDescripti onIndicat orInputsOutputsSecurity FunctionsSSP Access
Random Number GenerationUsed for random number and symmetri c key generatio n1DRBG struct (RBG State); DRBG_S eedStatus return; Random valueRandom Number GenerationCrypto- Officer - DRBG_C: W,E - Entropy Input: W,E,Z

The logical interface is a C-language application program interface (API). The Data Input interface consists of the input parameters of the API functions. The Data Output interface consists of the output parameters of the API functions. The Control Input interface consists of the actual API functions. The Status Output interface includes the return values of the API

3.2 Control Interface Not Inhibited

Please note that the module does not support a control output interface and is not applicable for this module.

4 Roles, Services, and Authentication

N/A for this module. The module does not implement authentication mechanisms and does not allow concurrent operators.

4.2 Roles

Table 13: Roles The module meets all FIPS 140-3 level 1 requirements for Roles. The Module implements both a User Role (User) as well as the Crypto Officer (CO) role. The User and Crypto Officer roles are implicitly assumed by the application accessing services implemented by the Module.

4.3 Approved Services
Page 32
NameDescripti onIndicat orInputsOutputsSecurity FunctionsSSP Access
- DRBG_Ke y: W,E - DRBG_Se ed: G,E,Z - DRBG_V: W,E
Asymmetric Key GenerationGenerate asymmet ric key pairs1ECDSA: curve identifier. DSA, RSA: domain paramete r targetsStatus return; general digital signature private and public keysAsymmetric Key GenerationCrypto- Officer - RSA SGK: G,R - ECDSA SGK: G,R - DSA SGK: G,R - RSA SVK: G,R - ECDSA SVK: G,R - DSA SVK: G,R - RSA KDK: G,R - RSA KEK: G,R
Key Derivation Function (KDF)Used to derive keys using KBKDF, PBKDF2, HKDF, SP 800- 56C rev2 One-Step KDF (KDA), SP 800- 56C rev2 Two-Step KDF (KDA), SP 800- 135 rev11Key agreemen t shared secret; flagsStatus return; derived keying materialKey Derivation Function (KDF)Crypto- Officer - KDF Derived Key: G,R
Page 33
NameDescripti onIndicat orInputsOutputsSecurity FunctionsSSP Access
TLS 1.2, SSHv2, SNMPv3, SRTP, IKEv2, ANSI X9.6- 2001, ANSI X9.42- 2001 KDFs and TLS 1.3 KDF
Symmetric Encrypt/Dec ryptUsed to encrypt or decrypt data. Executes using AES EDK (passed in by the calling applicatio n)1Encryptio n or decryptio n key; plaintext or ciphertext data; flagsStatus return. Plaintext or ciphertext dataSymmetric Encrypt/DecryptCrypto- Officer - AES EDK: W,E - AES GCM: W,E - AES XTS: W,E - AES Key Wrapping: W,E - TDES DK: W,E
Message Digest (SHS)Used to generate a SHA-1, SHA-2, or SHA-3 message digest1Data to be hashedStatus return. Hashed dataMessage Digest (SHS)Crypto- Officer
Keyed HashUsed to generate or verify data integrity with HMAC, KMAC or CMAC. Executes using1Data to be hashed and keying materialStatus return; MAC output value.Keyed Hash (HMAC/KMAC/C MAC)Crypto- Officer - HMAC Key: W,E - KMAC Key: W,E - AES CMAC: W,E - TDES
Page 34
NameDescripti onIndicat orInputsOutputsSecurity FunctionsSSP Access
HMAC, KMAC or AES Key (passed in by the calling applicatio n)CMAC: W,E
Key Wrapping (KW)Used to encrypt a key value on behalf of the calling applicatio n. Executes using AES Key Wrapping Key (passed in by the calling applicatio n). AES- KW, AES- KWP is CAVP tested per FIPS 140-3 IG D.G.1Keying materialEncrypted keyKey Wrapping (KW)Crypto- Officer - AES Key Wrapping: W,E
Key Agreement/ Agreement Component (SP 800- 56A rev3)Used to perform key agreeme nt primitives on behalf of the calling applicatio n (does not1Key structs (key agreemen t keys); flagsStatus return; key agreement shared secretKey Agreement/Agree ment Component (SP 800-56A rev3, SP 800- 56B rev2)Crypto- Officer - DH Private: W,E - EC DH Private: W,E - RSA SGK: W,E - DH Public:
Page 35
NameDescripti onIndicat orInputsOutputsSecurity FunctionsSSP Access
establish keys into the module). Executes using DH Private, DH Public, EC DH Private, EC DH Public, RSA SGK, RSA SVK (passed in by the calling applicatio n)W,E - EC DH Public: W,E - RSA SVK: W,E
Digital SignatureUsed to generate or verify RSA, DSA, ECDSA, digital signature s. Executes using RSA SGK, RSA SVK; DSA SGK, DSA SVK; ECDSA SGK, ECDSA SVK, (passed1Sign: signing key; message. Verify: signature value; flags; sizesStatus return; Signature valueDigital SignatureCrypto- Officer - RSA SGK: W,E - RSA SVK: W,E - DSA SGK: W,E - DSA SVK: W,E - ECDSA SGK: W,E - ECDSA SVK: W,E
Page 36
NameDescripti onIndicat orInputsOutputsSecurity FunctionsSSP Access
in by the calling applicatio n)
Asymmetric Key VerificationUsed to verify ECDSA keys1Public KeyStatus returnAsymmetric Key VerificationCrypto- Officer - ECDSA SVK: W,E
Module initializationThe module is initialized when the provider is loaded1N/AN/ANoneCrypto- Officer
Perform Self-TestPerform self-tests on demand1N/ASuccess/fai lure messageNoneCrypto- Officer
Key TransportUsed for Key Transport1Key to be transporte dEncrypted keyKey TransportCrypto- Officer - RSA KDK: W,E - RSA KEK: W,E
Show Module Name and VersionUsed to output module name and versionN/AN/Aname: CiscoSSL FIPS Provider version: 8.0NoneCrypto- Officer
Show StatusUsed to output module statusN/AN/Astatus: activeNoneCrypto- Officer

n) Table 14: Approved Services The module meets all FIPS 140-3 level 1 requirements for Services. The initialization process is described in the Secure Distribution, Operation, and User Guidance section of this document. CO services with associated input and output are listed in the above table. All the services provided by the module can be accessed by both the User and the Crypto Officer roles. The User Role (User) can load the module and call any of the API functions. The Crypto Officer Role (CO) is responsible for installation of the module on the host computer system and calling of any API functions.

Page 37
NameDescriptionAlgorithmsRole
Edwards curves Key GenerationKey pair generation using Edwards curves (ED25519, ED448, X25519, X448)EdDSA KeyGenCO, User
Edwards curves Digital Signature GenerationSignature generation using Edwards curves (ED25519, ED448)EdDSA SigGenCO, User
Edwards curves Digital Signature VerificationSignature verification using Edwards curves (ED25519, ED448)EdDSA SigVerCO, User
RSA PrimitivesRSA Sign, verify, encrypt, decrypt without hashing/paddingRSA PrimitivesCO, User
4.4 Non-Approved Services

Table 15: Non-Approved Services The module implements non-approved services mentioned in the above table. For these specific services, the service indicators ‘3, ED25519, ED448, X25519, X448’ indicates that the service is non-approved.

4.5 External Software/Firmware Loaded

Not Applicable for this module.

5 Software/Firmware Security
5.1 Integrity Techniques

The module runs a HMAC SHA2-256 integrity verification on the shared object file (fips.so) during initialization by the host application. The module also runs the self-test for HMAC SHA2-

256 prior to running the integrity check.
5.2 Initiate on Demand

The operator can initiate on-demand integrity test by calling SELF_TEST_post() or rebooting the host platform.

5.3 Additional Information

The public verification key used for firmware integrity test is not an SSP.

6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Non-Modifiable

Page 38
Storage Area NameDescriptionPersistence Type
RAMVolatile MemoryDynamic
NameFromToFormat TypeDistribution TypeEntry TypeSFI or Algorithm
API InputCalling processAPI input parametersPlaintextManualElectronic
API OutputAPI output parametersCalling processPlaintextManualElectronic

How Requirements are Satisfied: The module was tested on the platforms listed in Table 2 for the purposes of this FIPS 140-3 validation. The module is expected to execute correctly on any production grade CPU with commonly used operating system. No operational environment restrictions are required for operation in the approved mode. CiscoSSL FIPS Provider is a Firmware module and classified as a non-modifiable OE. The requirements under ISO/IEC 19790, section 7.6 “Operational environment”, are met by the module for Level 1 firmware requirements.

7 Physical Security

Not Applicable for this module.

8 Non-Invasive Security

Not Applicable for this module.

9 Sensitive Security Parameters Management
9.1 Storage Areas

Table 16: Storage Areas The module stores DRBG state values for the lifetime of the DRBG instance. The module uses CSPs passed in by the calling application on the stack. The module does not store any CSP persistently (beyond the lifetime of an API call), except for DRBG state values used for the module’s default key generation service. The module implements SP 800-90A rev1 compliant DRBG services for creation of symmetric keys, and for generation of DSA, elliptic curve, and RSA keys as shown in Table 4. The calling application is responsible for storage of generated keys returned by the module.

9.2 SSP Input-Output Methods

Table 17: SSP Input-Output Methods

Page 39
Zeroization MethodDescriptionRationaleOperator Initiation
OPENSSL_cleanse()API call clears the temporarily stored CSPsZeroized SSPs will no longer be accessible through API callsAllowed
Power CyclePower Cycle zeroizes all stored SSPsOperating System zeroizes all the stored SSPsAllowed
NameDescripti onSize - StrengthType - CategoryGenerat ed ByEstablis hed ByUsed By
RSA SGKUsed to generate Digital Signature s2048, 3072, 4096 bits - 112, 128, 152 bitsSignature Generation Key - CSPAsymme tric Key Generati onDigital Signature
RSA KDKUsed in Asymmetr ic Key Operation to to decrypt keys2048, 3072 4096 bits - 112, 128, 152 bitsKey Transport Key - CSPAsymme tric Key Generati onKey Transport
DSA SGKUsed to generate Digital Signature s2048, 3072 bits - 112, 128 bitsSignature Generation Key - CSPAsymme tric Key Generati onDigital Signature

All CSPs enter the module’s boundary in plaintext as API parameters, associated by memory location. However, none crosses the physical parameter. The module does not output CSPs, other than as explicit results of key generation services or keys passed into the module by the calling application.

9.3 SSP Zeroization Methods

Table 18: SSP Zeroization Methods Zeroization of sensitive data is performed automatically by API function calls for temporarily stored CSPs. The calling application is responsible for parameters passed in and out of the module. Successful completion of the zeroization service is determined by clean execution of OPENSSL_cleanse() without any errors being returned or a successful reboot of the host platform. s

Page 40
NameDescripti onSize - StrengthType - CategoryGenerat ed ByEstablis hed ByUsed By
ECDSA SGKUsed to generate Digital Signature s256, 384, 521 bits - 128, 192, 256 bitsSignature Generation Key - CSPAsymme tric Key Generati onDigital Signature
DH PrivateUsed for Key Agreeme nt2048, 3072 bits - 112, 128 bitsKey Agreement Key - CSPAsymme tric Key Generati onKey Agreement/Agre ement Component (SP 800-56A rev3, SP 800-56B rev2)
EC DH PrivateUsed for Key Agreeme nt256, 384, 521 bits - 128, 192, 256 bitsKey Agreement Key - CSPAsymme tric Key Generati onKey Agreement/Agre ement Component (SP 800-56A rev3, SP 800-56B rev2)
AES EDKUsed for Symmetri c encrypt and decrypt operation s128, 192, 256 bits - 128, 192, 256 bitsSymmetric Key - CSPRandom Number Generati onSymmetric Encrypt/Decrypt
AES CMACUsed for MAC calculatio n and verificatio n128, 192, 256 bits - 128, 192, 256 bitsSymmetric Key - CSPRandom Number Generati onKeyed Hash (HMAC/KMAC/C MAC)
AES GCMUsed for authentic ated cipher operation s128, 192, 256 bits - 128, 192, 256 bitsSymmetric Key - CSPRandom Number Generati onSymmetric Encrypt/Decrypt
AES XTSUsed for cipher operation128, 256 bits - 128, 256 bitsSymmetric Key - CSPRandom Number Generati onSymmetric Encrypt/Decrypt
AES Key WrappingUsed for key wrapping128, 192, 256 bits - 128, 192, 256 bitsSymmetric Key - CSPRandom Number Generati onKey Wrapping (KW)
Page 41
NameDescripti onSize - StrengthType - CategoryGenerat ed ByEstablis hed ByUsed By
HMAC KeyUsed for MAC generatio n and verificatio n128 to 524288 bits - greater than 128 bitsKeyed Hash - CSPRandom Number Generati onKeyed Hash (HMAC/KMAC/C MAC)
KMAC KeyUsed for MAC generatio n256, 512 bits - 128, 256 bitsKeyed Hash - CSPKeyed Hash (HMAC/KMAC/C MAC)
DRBG_CElement of Hash DRBG state, defined per FIPS 140-3 IG D.L440-888 bits - 160-256 bitsDRBG State - CSPRandom Number Generati onRandom Number Generation
Entropy InputEntropy input from an external source used for DRBG seeding, defined per FIPS 140-3 IG D.L128-2^35 - 128 - 256Entropy Input - CSPRandom Number Generation
DRBG_K eyElement of CTR DRBG or HMAC DRBG state, defined per FIPS 140-3 IG D.LCTR_DR BG: 128- 256, HMAC DRBG: 128-256 - CTR_DR BG: 128 - 256, HMAC DRBG: 160 - 256CTR_DRBG_ Key, HMAC_DRBG _Key - CSPRandom Number Generati onRandom Number Generation
DRBG_S eedSeed used for DRBG Instantiati128-256 - 128 - 256DRBG Seed - CSPRandom Number Generati onRandom Number Generation
Page 42
NameDescripti onSize - StrengthType - CategoryGenerat ed ByEstablis hed ByUsed By
on and Reseed, defined per FIPS 140-3 IG D.L
DRBG_VElement of CTR, Hash or HMAC DRBG state, defined per FIPS 140-3 IG D.LCTR_DR BG: 128- 256, Hash DRBG: 128-256, HMAC DRBG: 128-256 - CTR_DR BG: 128 - 256, Hash DRBG: 128 - 256, HMAC DRBG: 128 - 256DRBG State - CSPRandom Number Generati onRandom Number Generation
RSA SVKRSA signature verificatio n public key1024, 2048, 3072, 4096 bits - 80, 112, 128, 152 bitsVerification Key - PSPAsymme tric Key Generati onDigital Signature
RSA KEKRSA key encryptio n (public key transport) key2048, 3072, 4096 bits - 112, 128, 152 bitsEncryption Key - PSPAsymme tric Key Generati onKey Transport
DSA SVKDSA signature verificatio n key1024, 2048, 3072 bits - 80, 112, 128 bitsVerification Key - PSPAsymme tric Key Generati onDigital Signature
ECDSA SVKECDSA signature233, 283, 409, 571, 233, 283,Verification Key - PSPAsymme tric KeyDigital Signature
Page 43
NameDescripti onSize - StrengthType - CategoryGenerat ed ByEstablis hed ByUsed By
verificatio n key409, 571, 224, 256, 384, 521 - 112, 128, 192, 256 bitsGenerati on
DH PublicDH public key agreemen t key2048, 3072 bits - 112, 128 bitsPublic Key Agreement Key - PSPAsymme tric Key Generati onKey Agreement/Agre ement Component (SP 800-56A rev3, SP 800-56B rev2)
EC DH PublicEC DH public key agreemen t key256, 384, 521 bits - 128, 192, 256 bitsPublic Key Agreement Key - PSPAsymme tric Key Generati onKey Agreement/Agre ement Component (SP 800-56A rev3, SP 800-56B rev2)
KDF Derived KeyKey derived from KDFs128, 256 bits - 128, 256 bitsDerived Key - CSPKey Derivati on Function (KDF)Key Derivation Function (KDF)
TDES DKTDES Decryptio n key168 bits - 112 bitsSymmetric Key - CSPRandom Number Generati onSymmetric Encrypt/Decrypt
TDES CMACUsed for MAC verificatio n168 bits - 112 bitsVerification Key - PSPRandom Number Generati onKeyed Hash (HMAC/KMAC/C MAC)
NameInput - Outpu tStorageStorage Duratio nZeroizationRelated SSPs
RSA SGKAPI Input API Outpu tRAM:Plainte xtUntil zeroize d by reboot or API callOPENSSL_cleans e() Power CycleRSA SVK:Paired With
Page 44
NameInput - Outpu tStorageStorage Duratio nZeroizationRelated SSPs
RSA KDKAPI Input API Outpu tRAM:Plainte xtUntil zeroize d by reboot or API callOPENSSL_cleans e() Power CycleRSA KEK:Paired With
DSA SGKAPI Input API Outpu tRAM:Plainte xtUntil zeroize d by reboot or API callOPENSSL_cleans e() Power CycleDSA SVK:Paired With
ECDSA SGKAPI Input API Outpu tRAM:Plainte xtUntil zeroize d by reboot or API callOPENSSL_cleans e() Power CycleECDSA SVK:Paired With
DH PrivateAPI Input API Outpu tRAM:Plainte xtUntil zeroize d by reboot or API callOPENSSL_cleans e() Power CycleDH Public:Paired With
EC DH PrivateAPI Input API Outpu tRAM:Plainte xtUntil zeroize d by reboot or API callOPENSSL_cleans e() Power CycleEC DH Public:Paired With
AES EDKAPI Input API Outpu tRAM:Plainte xtUntil zeroize d by reboot or API callOPENSSL_cleans e() Power Cycle
AES CMACAPI Input API Outpu tRAM:Plainte xtUntil zeroize d by reboot or API callOPENSSL_cleans e() Power Cycle
Page 45
NameInput - Outpu tStorageStorage Duratio nZeroizationRelated SSPs
AES GCMAPI Input API Outpu tRAM:Plainte xtUntil zeroize d by reboot or API callOPENSSL_cleans e() Power Cycle
AES XTSAPI Input API Outpu tRAM:Plainte xtUntil zeroize d by reboot or API callOPENSSL_cleans e() Power Cycle
AES Key WrappingAPI Input API Outpu tRAM:Plainte xtUntil zeroize d by reboot or API callOPENSSL_cleans e() Power Cycle
HMAC KeyAPI Input API Outpu tRAM:Plainte xtUntil zeroize d by reboot or API callOPENSSL_cleans e() Power Cycle
KMAC KeyAPI Input API Outpu tRAM:Plainte xtUntil zeroize d by reboot or API callOPENSSL_cleans e() Power Cycle
DRBG_CAPI Input API Outpu tRAM:Plainte xtUntil zeroize d by reboot or API callOPENSSL_cleans e() Power CycleDRBG_Seed:Derived From DRBG_V:Used With
Entropy InputAPI InputRAM:Plainte xtUntil zeroize d by reboot or API callOPENSSL_cleans e() Power CycleDRBG_Seed:Constitu ent
Page 46
NameInput - Outpu tStorageStorage Duratio nZeroizationRelated SSPs
DRBG_KeyAPI Input API Outpu tRAM:Plainte xtUntil zeroize d by reboot or API callOPENSSL_cleans e() Power CycleDRBG_Seed:Derived From DRBG_V:Used With
DRBG_See dRAM:Plainte xtUntil zeroize d by reboot or API callOPENSSL_cleans e() Power CycleDRBG_C:Derives DRBG_Key:Derives DRBG_V:Derives Entropy Input:Incorporates
DRBG_VAPI Input API Outpu tRAM:Plainte xtUntil zeroize d by reboot or API callOPENSSL_cleans e() Power CycleDRBG_Seed:Derived From DRBG_Key:Used With
RSA SVKAPI Input API Outpu tRAM:Plainte xtUntil zeroize d by reboot or API callOPENSSL_cleans e() Power CycleRSA SGK:Paired With
RSA KEKAPI Input API Outpu tRAM:Plainte xtUntil zeroize d by reboot or API callOPENSSL_cleans e() Power CycleRSA KDK:Paired With
DSA SVKAPI Input API Outpu tRAM:Plainte xtUntil zeroize d by reboot or API callOPENSSL_cleans e() Power CycleDSA SGK:Paired With
ECDSA SVKAPI Input API Outpu tRAM:Plainte xtUntil zeroize d by reboot or API callOPENSSL_cleans e() Power CycleECDSA SGK:Paired With
Page 47
NameInput - Outpu tStorageStorage Duratio nZeroizationRelated SSPs
DH PublicAPI Input API Outpu tRAM:Plainte xtUntil zeroize d by reboot or API callOPENSSL_cleans e() Power CycleDH Private:Paired With
EC DH PublicAPI Input API Outpu tRAM:Plainte xtUntil zeroize d by reboot or API callOPENSSL_cleans e() Power CycleEC DH Private:Paired With
KDF Derived KeyAPI Outpu tUntil zeroize d by reboot or API callOPENSSL_cleans e() Power Cycle
TDES DKAPI Input API Outpu tRAM:Plainte xtUntil zeroize d by reboot or API callOPENSSL_cleans e() Power Cycle
TDES CMACAPI Input API Outpu tRAM:Plainte xtUntil zeroize d by reboot or API callOPENSSL_cleans e() Power Cycle
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
HMAC- SHA2-256 (A3032)256 bitsFirmware Integrity TestSW/FW IntegrityReturns 1 when power upThe SELF_TEST_post() function performs all power-up self-tests listed above with no
10.1 Pre-Operational Self-Tests
Page 48
Algorithm or TestTest PropertiesTest MethodTest TypeIndicator self tests succeedDetails operator intervention required when the module loads, returning a “1” if all power-up self-tests succeed, and a “0” otherwise. The power-up self- tests may also be performed on-demand by calling this function and interpretation of the return code is the responsibility of the calling application
HMAC- SHA2-256 (A3252)256 bitsFirmware Integrity TestSW/FW IntegrityReturns 1 when power up self tests succeedThe SELF_TEST_post() function performs all power-up self-tests listed above with no operator intervention required when the module loads, returning a “1” if all power-up self-tests succeed, and a “0” otherwise. The power-up self- tests may also be performed on-demand by calling this function and interpretation of the return code is the responsibility of the calling application
Algorith m or TestTest PropertiesTest Metho dTest TypeIndicatorDetailsConditions
AES-ECB (A3032)128 bitsKATCAS TReturns 1 on successful completio nEncrypt KATUpon power-up and call of SELF_TEST_post( ) function
AES-ECB (A3252)128 bitsKATCAS TReturns 1 onEncrypt KATUpon power-up and call of

Table 21: Pre-Operational Self-Tests (CASTs) before it is operational. The module is single threaded and will not return to the calling application until the CASTs are complete. If the self-tests fail, the module goes to an error state and subsequent calls to the module will fail and thus no further cryptographic operations are possible. The CO can clear the error state by restarting the host platform.

10.2 Conditional Self-Tests
Page 49
Algorith m or TestTest PropertiesTest Metho dTest TypeIndicator successful completio nDetailsConditions SELF_TEST_post( ) function
AES- GCM (A3032)256 bitsKATCAS TReturns 1 on successful completio nEncrypt KATUpon power-up and call of SELF_TEST_post( ) function
AES- GCM (A3252)256 bitsKATCAS TReturns 1 on successful completio nEncrypt KATUpon power-up and call of SELF_TEST_post( ) function
AES- CMAC (A3032)128, 192, 256 bitsKATCAS TReturns 1 on successful completio nGenerate KATUpon power-up and call of SELF_TEST_post( ) function
AES- CMAC (A3252)128, 192, 256 bitsKATCAS TReturns 1 on successful completio nGenerate KATUpon power-up and call of SELF_TEST_post( ) function
Counter DRBG (A3032)AES-128 with derivation functionKATCAS TReturns 1 on successful completio nInstantiate, Generate, ReseedUpon power-up and call of SELF_TEST_post( ) function
Counter DRBG (A3252)AES-128 with derivation functionKATCAS TReturns 1 on successful completio nInstantiate, Generate, ReseedUpon power-up and call of SELF_TEST_post( ) function
Hash DRBG (A3032)SHA2-256KATCAS TReturns 1 on successful completio nInstantiate, Generate, ReseedUpon power-up and call of SELF_TEST_post( ) function
Hash DRBG (A3252)SHA2-256KATCAS TReturns 1 on successful completio nInstantiate, Generate, ReseedUpon power-up and call of SELF_TEST_post( ) function
Page 50
Algorith m or TestTest PropertiesTest Metho dTest TypeIndicatorDetailsConditions
HMAC DRBG (A3032)SHA-1KATCAS TReturns 1 on successful completio nInstantiate, Generate, ReseedUpon power-up and call of SELF_TEST_post( ) function
HMAC DRBG (A3252)SHA-1KATCAS TReturns 1 on successful completio nInstantiate, Generate, ReseedUpon power-up and call of SELF_TEST_post( ) function
DSA SigGen (FIPS186- 4) (A3032)2048-bit with SHA2-256KATCAS TReturns 1 on successful completio nSignUpon power-up and call of SELF_TEST_post( ) function
DSA SigGen (FIPS186- 4) (A3252)2048-bit with SHA2-256KATCAS TReturns 1 on successful completio nSignUpon power-up and call of SELF_TEST_post( ) function
DSA SigVer (FIPS186- 4) (A3032)2048-bit with SHA2-256KATCAS TReturns 1 on successful completio nVerifyUpon power-up and call of SELF_TEST_post( ) function
DSA SigVer (FIPS186- 4) (A3252)2048-bit with SHA2-256KATCAS TReturns 1 on successful completio nVerifyUpon power-up and call of SELF_TEST_post( ) function
ECDSA SigGen (FIPS186- 4) (A3032)P-256 with SHA2-256KATCAS TReturns 1 on successful completio nSignUpon power-up and call of SELF_TEST_post( ) function
ECDSA SigGen (FIPS186- 4) (A3252)P-256 with SHA2-256KATCAS TReturns 1 on successful completio nSignUpon power-up and call of SELF_TEST_post( ) function
ECDSA SigVer (FIPS186- 4) (A3032)P-256 with SHA2-256KATCAS TReturns 1 on successful completio nVerifyUpon power-up and call of SELF_TEST_post( ) function
Page 51
Algorith m or TestTest PropertiesTest Metho dTest TypeIndicatorDetailsConditions
ECDSA SigVer (FIPS186- 4) (A3252)P-256 with SHA2-256KATCAS TReturns 1 on successful completio nVerifyUpon power-up and call of SELF_TEST_post( ) function
RSA SigGen (FIPS186- 4) (A3032)k=2048 with SHA2-256KATCAS TReturns 1 on successful completio nSignUpon power-up and call of SELF_TEST_post( ) function
RSA SigGen (FIPS186- 4) (A3252)k=2048 with SHA2-256KATCAS TReturns 1 on successful completio nSignUpon power-up and call of SELF_TEST_post( ) function
RSA SigVer (FIPS186- 4) (A3032)k=2048 with SHA2-256KATCAS TReturns 1 on successful completio nVerifyUpon power-up and call of SELF_TEST_post( ) function
RSA SigVer (FIPS186- 4) (A3252)k=2048 with SHA2-256KATCAS TReturns 1 on successful completio nVerifyUpon power-up and call of SELF_TEST_post( ) function
KAS- FFC-SSC Sp800- 56Ar3 (A3032)L=2048/N=25 6KATCAS TReturns 1 on successful completio ndhEphem Shared Secret (Z) Computatio nUpon power-up and call of SELF_TEST_post( ) function
KAS- FFC-SSC Sp800- 56Ar3 (A3252)L=2048/N=25 6KATCAS TReturns 1 on successful completio ndhEphem Shared Secret (Z) Computatio nUpon power-up and call of SELF_TEST_post( ) function
KAS- ECC-SSC Sp800- 56Ar3 (A3032)P-256KATCAS TReturns 1 on successful completio nEphemeral Unified Shared Secret (Z) Computatio nUpon power-up and call of SELF_TEST_post( ) function
KAS- ECC-SSC Sp800-P-256KATCAS TReturns 1 on successfulEphemeral Unified Shared Secret (Z)Upon power-up and call of SELF_TEST_post( ) function
Page 52
Algorith m or Test 56Ar3 (A3252)Test PropertiesTest Metho dTest TypeIndicator completio nDetails Computatio nConditions
KAS-IFC- SSC (A3032)k=2048KATCAS TReturns 1 on successful completio n[SP 800- 56B rev2] Section 8.2.2 RSA Primitive Computatio nUpon power-up and call of SELF_TEST_post( ) function
KAS-IFC- SSC (A3252)k=2048KATCAS TReturns 1 on successful completio n[SP 800- 56B rev2] Section 8.2.2 RSA Primitive Computatio nUpon power-up and call of SELF_TEST_post( ) function
SHA-1 (A3032)SHA-1KATCAS TReturns 1 on successful completio nSimple SHA KATUpon power-up and call of SELF_TEST_post( ) function
SHA-1 (A3252)SHA-1KATCAS TReturns 1 on successful completio nSimple SHA KATUpon power-up and call of SELF_TEST_post( ) function
SHA2- 512 (A3032)SHA2-512KATCAS TReturns 1 on successful completio nSimple SHA KATUpon power-up and call of SELF_TEST_post( ) function
SHA2- 512 (A3252)SHA2-512KATCAS TReturns 1 on successful completio nSimple SHA KATUpon power-up and call of SELF_TEST_post( ) function
SHA3- 256 (A3032)SHA3-256KATCAS TReturns 1 on successful completio nSimple SHA KATUpon power-up and call of SELF_TEST_post( ) function
SHA3- 256 (A3252)SHA3-256KATCAS TReturns 1 on successfulSimple SHA KATUpon power-up and call of SELF_TEST_post( ) function
Page 53
Algorith m or TestTest PropertiesTest Metho dTest TypeIndicator completio nDetailsConditions
HMAC- SHA2- 256 (A3032)SHA2-256 with a 256-bit keyKATCAS TReturns 1 on successful completio nGenerateUpon power-up and call of SELF_TEST_post( ) function
HMAC- SHA2- 256 (A3252)SHA2-256 with a 256-bit keyKATCAS TReturns 1 on successful completio nGenerateUpon power-up and call of SELF_TEST_post( ) function
KDF SP800- 108 (A3032)HMAC-SHA2- 256KATCAS TReturns 1 on successful completio n[S P800- 108 rev1] Section 4.1 KAT for a Counter Mode KDFUpon power-up and call of SELF_TEST_post( ) function
KDF SP800- 108 (A3252)HMAC-SHA2- 256KATCAS TReturns 1 on successful completio n[SP 800- 108 rev1] Section 4.1 KAT for a Counter Mode KDFUpon power-up and call of SELF_TEST_post( ) function
KDA OneStep SP800- 56Cr2 (A3032)SHA2-224KATCAS TReturns 1 on successful completio n[SP 800- 56C rev2] Section 4 OneStep KDF (AKA OpenSSL single-step or SS-KDF)Upon power-up and call of SELF_TEST_post( ) function
KDA OneStep SP800- 56Cr2 (A3252)SHA2-224KATCAS TReturns 1 on successful completio n[SP 800- 56C rev2] Section 4 OneStep KDF (AKA OpenSSL single-step or SS-KDF)Upon power-up and call of SELF_TEST_post( ) function
KDA TwoStep SP800- 56Cr2 (A3032)SHA2-256KATCAS TReturns 1 on successful completio n[SP 800- 56C rev2] Section 5 TwoStepUpon power-up and call of SELF_TEST_post( ) function
Page 54
Algorith m or TestTest PropertiesTest Metho dTest TypeIndicatorDetails KDF (HKDF variant)Conditions
KDA TwoStep SP800- 56Cr2 (A3252)SHA2-256KATCAS TReturns 1 on successful completio n[SP 800- 56C rev2] Section 5 TwoStep KDF (HKDF variant)Upon power-up and call of SELF_TEST_post( ) function
PBKDF (A3032)SHA2-256, 24-byte password, 36- byte salt, iteration count of 4096KATCAS TReturns 1 on successful completio n[SP 800- 132] Section 5.3 KAT of Master Key derivationUpon power-up and call of SELF_TEST_post( ) function
PBKDF (A3252)SHA2-256, 24-byte password, 36- byte salt, iteration count of 4096KATCAS TReturns 1 on successful completio n[SP 800- 132] Section 5.3 KAT of Master Key derivationUpon power-up and call of SELF_TEST_post( ) function
TLS v1.3 KDF (A3032)Fixed input KATKATCAS TReturns 1 on successful completio n[RFC8446] Section 7.1 TLS v1.3 KDF KATUpon power-up and call of SELF_TEST_post( ) function
TLS v1.3 KDF (A3252)Fixed input KATKATCAS TReturns 1 on successful completio n[RFC8446] Section 7.1 TLS v1.3 KDF KATUpon power-up and call of SELF_TEST_post( ) function
TLS v1.2 KDF RFC7627 (A3032)Fixed input KATKATCAS TReturns 1 on successful completio n[SP 800- 135 rev1] Section 4.2.2 TLS 1.2 KATUpon power-up and call of SELF_TEST_post( ) function
TLS v1.2 KDF RFC7627 (A3252)Fixed input KATKATCAS TReturns 1 on successful completio n[SP 800- 135 rev1] Section 4.2.2 TLS 1.2 KATUpon power-up and call of SELF_TEST_post( ) function
DSA KeyGen (FIPS186- 4) (A3032)PCT performed using the generated key pairPCTPCTReturns 1 on successful completio nSign, VerifyPerformed on FFC (DSA, KAS-FFC- SSC) key pair generation, prior to returning the key
Page 55
Algorith m or TestTest PropertiesTest Metho dTest TypeIndicatorDetailsConditions pair on conclusion of the call
DSA KeyGen (FIPS186- 4) (A3252)PCT performed using the generated key pairPCTPCTReturns 1 on successful completio nSign, VerifyPerformed on FFC (DSA, KAS-FFC- SSC) key pair generation, prior to returning the key pair on conclusion of the call
ECDSA KeyGen (FIPS186- 4) (A3032)PCT performed using the generated key pairPCTPCTReturns 1 on successful completio nSign, VerifyPerformed on ECC (ECDSA, KAS- ECC CDH- Component, KAS- ECC-SSC) key pair generation, prior to returning the key pair on conclusion of the call
ECDSA KeyGen (FIPS186- 4) (A3252)PCT performed using the generated key pairPCTPCTReturns 1 on successful completio nSign, VerifyPerformed on ECC (ECDSA, KAS- ECC CDH- Component, KAS- ECC-SSC) key pair generation, prior to returning the key pair on conclusion of the call
RSA KeyGen (FIPS186- 4) (A3032)PCT performed using the generated key pairPCTPCTReturns 1 on successful completio nSign, VerifyPerformed on IFC (RSA, KAS-IFC- SSC, KTS-IFC) key pair generation, prior to returning the key pair on conclusion of the call
RSA KeyGen (FIPS186- 4) (A3252)PCT performed using the generated key pairPCTPCTReturns 1 on successful completio nSign, VerifyPerformed on IFC (RSA, KAS-IFC- SSC, KTS-IFC) key pair generation, prior to returning the key pair on conclusion of the call
Page 56
Algorith m or TestTest PropertiesTest Metho dTest TypeIndicatorDetailsConditions
KDF ANS 9.42 (A3032)Fixed input KATKATCAS TReturns 1 on successful completio n[SP 800- 135 rev1] Section 5.1 ANSI X9.42-2001 KDF KATUpon power-up and call of SELF_TEST_post( ) function
KDF ANS 9.63 (A3032)Fixed input KATKATCAS TReturns 1 on successful completio n[SP 800- 135 rev1] Section 5.1 X9.63-2001 KDF KATUpon power-up and call of SELF_TEST_post( ) function
KDF IKEv2 (A3032)Fixed input KATKATCAS TReturns 1 on successful completio n[SP 800- 135 rev1] Section 4.1.2 IKEv2 KDF KATUpon power-up and call of SELF_TEST_post( ) function
KDF SNMP (A3032)Fixed input KATKATCAS TReturns 1 on successful completio n[SP 800- 135 rev1] Section 5.4 SNMPv3 KDF KATUpon power-up and call of SELF_TEST_post( ) function
KDF SRTP (A3032)Fixed input KATKATCAS TReturns 1 on successful completio n[SP 800- 135 rev1] Section 5.3 SRTP KDF KATUpon power-up and call of SELF_TEST_post( ) function
KDF SSH (A3032)SHA1KATCAS TReturns 1 on successful completio n[SP 800- 135 rev1] Section 5.2 SSHv2 KDF KATUpon power-up and call of SELF_TEST_post( ) function
KDF ANS 9.42 (A3252)Fixed input KATKATCAS TReturns 1 on successful completio n[SP 800- 135 rev1] Section 5.1 ANSI X9.42-2001 KDF KATUpon power-up and call of SELF_TEST_post( ) function
KDF ANS 9.63 (A3252)Fixed input KATKATCAS TReturns 1 on successful completio n[SP 800- 135 rev1] Section 5.1 X9.63-2001 KDF KATUpon power-up and call of SELF_TEST_post( ) function
KDF IKEv2 (A3252)Fixed input KATKATCAS TReturns 1 on successful[SP 800- 135 rev1] SectionUpon power-up and call of
Page 57
Algorith m or TestTest PropertiesTest Metho dTest TypeIndicator completio nDetails 4.1.2 IKEv2 KDF KATConditions SELF_TEST_post( ) function
KDF SNMP (A3252)Fixed input KATKATCAS TReturns 1 on successful completio n[SP 800- 135 rev1] Section 5.4 SNMPv3 KDF KATUpon power-up and call of SELF_TEST_post( ) function
KDF SRTP (A3252)Fixed input KATKATCAS TReturns 1 on successful completio n[SP 800- 135 rev1] Section 5.3 SRTP KDF KATUpon power-up and call of SELF_TEST_post( ) function
KDF SSH (A3252)SHA1KATCAS TReturns 1 on successful completio n[SP 800- 135 rev1] Section 5.2 SSHv2 KDF KATUpon power-up and call of SELF_TEST_post( ) function
TDES- CBC (A3032)Keying Option: 1KATCAS TReturns 1 on successful completio nDecrypt KATUpon power-up and call of SELF_TEST_post( ) function
TDES- CMAC (A3032)Keying Option: 1KATCAS TReturns 1 on successful completio nVerify KATUpon power-up and call of SELF_TEST_post( ) function
TDES- CBC (A3252)Keying Option: 1KATCAS TReturns 1 on successful completio nDecrypt KATUpon power-up and call of SELF_TEST_post( ) function
TDES- CMAC (A3252)Keying Option: 1KATCAS TReturns 1 on successful completio nVerify KATUpon power-up and call of SELF_TEST_post( ) function
AES-ECB (A3032)128 bitsKATCAS TReturns 1 on successful completio nDecrypt KATUpon power-up and call of SELF_TEST_post( ) function
AES-ECB (A3252)128 bitsKATCAS TReturns 1 on successfulDecrypt KATUpon power-up and call of
Page 58
Algorith m or TestTest PropertiesTest Metho dTest TypeIndicator completio nDetailsConditions SELF_TEST_post( ) function
AES- GCM (A3032)256 bitsKATCAS TReturns 1 on successful completio nDecrypt KATUpon power-up and call of SELF_TEST_post( ) function
AES- GCM (A3252)256 bitsKATCAS TReturns 1 on successful completio nDecrypt KATUpon power-up and call of SELF_TEST_post( ) function
AES- CMAC (A3032)128, 192, 256 bitsKATCAS TReturns 1 on successful completio nVerify KATUpon power-up and call of SELF_TEST_post( ) function
AES- CMAC (A3252)128, 192, 256 bitsKATCAS TReturns 1 on successful completio nVerify KATUpon power-up and call of SELF_TEST_post( ) function
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2- 256 (A3032)Firmware Integrity TestSW/FW IntegrityOn reboot or SELF_TEST_post() function callManual or reboot
HMAC-SHA2- 256 (A3252)Firmware Integrity TestSW/FW IntegrityOn reboot or SELF_TEST_post() function callManual or reboot

d n n n n Table 22: Conditional Self-Tests The SELF_TEST_post() function performs all self-tests listed above with no operator intervention required when the module loads. The module returns a “1” if all self-tests succeed, and a “0” otherwise. The pre-operational and conditional self-tests may also be performed ondemand by calling this function and interpretation of the return code is the responsibility of the calling application. Table 23: Pre-Operational Periodic Information

Page 59
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-ECB (A3032)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
AES-ECB (A3252)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
AES-GCM (A3032)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
AES-GCM (A3252)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
AES-CMAC (A3032)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
AES-CMAC (A3252)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
Counter DRBG (A3032)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
Counter DRBG (A3252)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
Hash DRBG (A3032)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
Hash DRBG (A3252)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
HMAC DRBG (A3032)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
HMAC DRBG (A3252)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
DSA SigGen (FIPS186-4) (A3032)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
DSA SigGen (FIPS186-4) (A3252)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
DSA SigVer (FIPS186-4) (A3032)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
Page 60
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
DSA SigVer (FIPS186-4) (A3252)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
ECDSA SigGen (FIPS186-4) (A3032)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
ECDSA SigGen (FIPS186-4) (A3252)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
ECDSA SigVer (FIPS186-4) (A3032)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
ECDSA SigVer (FIPS186-4) (A3252)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
RSA SigGen (FIPS186-4) (A3032)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
RSA SigGen (FIPS186-4) (A3252)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
RSA SigVer (FIPS186-4) (A3032)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
RSA SigVer (FIPS186-4) (A3252)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
KAS-FFC-SSC Sp800-56Ar3 (A3032)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
KAS-FFC-SSC Sp800-56Ar3 (A3252)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
KAS-ECC-SSC Sp800-56Ar3 (A3032)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
KAS-ECC-SSC Sp800-56Ar3 (A3252)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
KAS-IFC-SSC (A3032)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
KAS-IFC-SSC (A3252)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
Page 61
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
SHA-1 (A3032)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
SHA-1 (A3252)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
SHA2-512 (A3032)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
SHA2-512 (A3252)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
SHA3-256 (A3032)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
SHA3-256 (A3252)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
HMAC-SHA2- 256 (A3032)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
HMAC-SHA2- 256 (A3252)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
KDF SP800- 108 (A3032)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
KDF SP800- 108 (A3252)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
KDA OneStep SP800-56Cr2 (A3032)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
KDA OneStep SP800-56Cr2 (A3252)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
KDA TwoStep SP800-56Cr2 (A3032)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
KDA TwoStep SP800-56Cr2 (A3252)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
PBKDF (A3032)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
Page 62
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
PBKDF (A3252)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
TLS v1.3 KDF (A3032)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
TLS v1.3 KDF (A3252)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
TLS v1.2 KDF RFC7627 (A3032)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
TLS v1.2 KDF RFC7627 (A3252)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
DSA KeyGen (FIPS186-4) (A3032)PCTPCTOn reboot or SELF_TEST_post() function callManual or reboot
DSA KeyGen (FIPS186-4) (A3252)PCTPCTOn reboot or SELF_TEST_post() function callManual or reboot
ECDSA KeyGen (FIPS186-4) (A3032)PCTPCTOn reboot or SELF_TEST_post() function callManual or reboot
ECDSA KeyGen (FIPS186-4) (A3252)PCTPCTOn reboot or SELF_TEST_post() function callManual or reboot
RSA KeyGen (FIPS186-4) (A3032)PCTPCTOn reboot or SELF_TEST_post() function callManual or reboot
RSA KeyGen (FIPS186-4) (A3252)PCTPCTOn reboot or SELF_TEST_post() function callManual or reboot
KDF ANS 9.42 (A3032)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
KDF ANS 9.63 (A3032)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
KDF IKEv2 (A3032)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
Page 63
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
KDF SNMP (A3032)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
KDF SRTP (A3032)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
KDF SSH (A3032)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
KDF ANS 9.42 (A3252)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
KDF ANS 9.63 (A3252)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
KDF IKEv2 (A3252)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
KDF SNMP (A3252)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
KDF SRTP (A3252)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
KDF SSH (A3252)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
TDES-CBC (A3032)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
TDES-CMAC (A3032)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
TDES-CBC (A3252)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
TDES-CMAC (A3252)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
AES-ECB (A3032)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
AES-ECB (A3252)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
Page 64
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-GCM (A3032)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
AES-GCM (A3252)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
AES-CMAC (A3032)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
AES-CMAC (A3252)KATCASTOn reboot or SELF_TEST_post() function callManual or reboot
NameDescriptionConditionsRecovery MethodIndicator
Error StateError State is entered when self tests failFailure of self testsRestarting the module0

Table 24: Conditional Periodic Information

10.4 Error States

Table 25: Error States If any self-test fails, an internal flag is set to prevent subsequent invocation of any cryptographic function calls. The module will only enter the Approved mode if the module is reloaded and the call to SELF_TEST_post() succeeds. The CAST used to perform the approved integrity technique is passed before the execution of the pre-operational firmware integrity test (HMACSHA2-256).

10.5 Operator Initiation of Self-Tests

The operator can initiate the self-tests by calling SELF_TEST_post() or rebooting the host platform.

11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

Per FIPS 140-3 classification, this is a multi-chip standalone cryptographic module. CiscoSSL FIPS Provider 8.0 is a C language-based firmware module that runs on production grade chassis. A complete revision history of the source code is collaborated by Bitbucket, and version controlled by Git. Code changes are tracked by commits tied to a username. All User

Page 65

documents are tracked in Cisco Document Central which requires username/password and access permission. Coverity runs static analysis on the source code before committing to the secure repository. Secure Distribution The module is distributed only for use by Cisco personnel and as such is accessible only from the secure Cisco internal repository. Only authorized Cisco personnel have access to the module. The SHA512 fingerprint of the validated distribution tarball file can be obtained by contacting Cisco. Secure Initialization The module is ready to use after extracting it from the distribution tarball. The operating system loads the module into its user space. The initialization sequence starts with a check of the integrity of the runtime executable using a HMAC-SHA2-256 digest computed at build time. If the computed HMAC-SHA2-256 digest matches the stored known digest, then the cryptographic algorithm self-tests are performed. If any self-test fails, an internal global error flag is set to prevent subsequent invocation of any cryptographic function calls. Any such failure is a hard error that can only be recovered by reloading the module. Upon encountering a failure, the module will return an integer of 0. The module will only enter the Approved mode if the module is reloaded and the call to SELF_TEST_post() succeeds. The function call “. /openssl list providers” returns the name and the version of the module. Secure Operation The tested operating systems segregate user processes into separate process spaces. Each process space is an independent virtual memory area that is logically separated from all other processes by the operating system firmware and hardware. The module functions entirely within the process space of the process that invokes it. Additional information on switching between approved and non-approved mode is provided under “Mode Change Instructions and Status” in Section 2.4 of this SP.

11.2 Administrator Guidance

An additional guidance document, if required, can be obtained by contacting Cisco Systems, Inc. using the information posted on the validation certificate.

11.3 Non-Administrator Guidance

Not Applicable for this module.

11.4 Design and Rules

If CTR_DRBG is used, then the caller shall ensure that the derivation function is enabled.

Page 66
12 Mitigation of Other Attacks
12.1 Attack List

The module implements two mitigations against timing-based side-channel attacks, namely Constant time Implementations and Blinding.

12.2 Mitigation Effectiveness

Constant-time Implementations protect cryptographic implementations in the Module against timing analysis since such attacks exploit differences in execution time depending on the cryptographic operation, and constant-time implementations ensure that the variations in execution time cannot be traced back to the key, CSP or secret data. Numeric Blinding protects the RSA, DSA and ECDSA algorithms from timing attacks. These algorithms are vulnerable to such attacks since attackers can measure the time of signature operations or RSA decryption. To mitigate this the Module generates a random blinding factor which is provided as an input to the decryption/signature operation and is discarded once the operation has completed and resulted in an output. This makes it difficult for attackers to attempt timing attacks on such operations without the knowledge of the blinding factor and therefore the execution time cannot be correlated to the RSA/DSA/ECDSA key.