All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Canonical Ltd. Ubuntu 22.04 Strongswan Cryptographic Module

Certificate#4911StandardFIPS 140-3Level1TypeSoftwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorCanonical Ltd.
Medium review priority  ·  exposes kernel crypto consumer  ·  strongSwan upstream has published 0 CVEs since this module's initial validation  ·  last validated 19 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date12/2/2029
CaveatInterim validation. When installed, initialized and configured as specified in Section 11.1 of the Security Policy with module Canonical Ltd. Ubuntu 22.04 OpenSSL Cryptographic Module validated to FIPS 140-3 under Cert. #4794, operating in the approved mode, and with module Canonical Ltd. Ubuntu 22.04 Kernel Crypto API Cryptographic Module validated to FIPS 140-3 under Cert. #4894, operating in the approved mode.
VendorCanonical Ltd.

Approved Algorithms (217)

AlgorithmACVP Cert
AES-CBCA3958
AES-CBCA3959
AES-CBCA3960
AES-CBCA3973
AES-CBCA3980
AES-CBCA3981
AES-CBCA3982
AES-CCMA3958
AES-CCMA3959
AES-CCMA3960
AES-CCMA3973
AES-CCMA3980
AES-CCMA3981
AES-CCMA3982
AES-GCMA3961
AES-GCMA3974
AES-GCMA3975
AES-GCMA3976
AES-GCMA3988
AES-GCMA3989
AES-GCMA3990
AES-GCMA3994
AES-GCMA3995
AES-GCMA3996
AES-GCMA3997
AES-GCMA3998
AES-GCMA3999
AES-GCMA4000
AES-GCMA4001
AES-GCMA4002
Counter DRBGA3970
ECDSA KeyGen (FIPS186-4)A3962
ECDSA KeyGen (FIPS186-4)A3977
ECDSA KeyGen (FIPS186-4)A3983
ECDSA KeyGen (FIPS186-4)A3993
ECDSA KeyGen (FIPS186-4)A4003
ECDSA KeyGen (FIPS186-4)A4004
ECDSA KeyGen (FIPS186-4)A4005
ECDSA KeyVer (FIPS186-4)A3962
ECDSA KeyVer (FIPS186-4)A3977
ECDSA KeyVer (FIPS186-4)A3983
ECDSA KeyVer (FIPS186-4)A3993
ECDSA KeyVer (FIPS186-4)A4003
ECDSA KeyVer (FIPS186-4)A4004
ECDSA KeyVer (FIPS186-4)A4005
ECDSA SigGen (FIPS186-4)A3962
ECDSA SigGen (FIPS186-4)A3964
ECDSA SigGen (FIPS186-4)A3972
ECDSA SigGen (FIPS186-4)A3977
ECDSA SigGen (FIPS186-4)A3979
ECDSA SigGen (FIPS186-4)A3983
ECDSA SigGen (FIPS186-4)A3993
ECDSA SigGen (FIPS186-4)A4003
ECDSA SigGen (FIPS186-4)A4004
ECDSA SigGen (FIPS186-4)A4005
ECDSA SigVer (FIPS186-4)A3962
ECDSA SigVer (FIPS186-4)A3964
ECDSA SigVer (FIPS186-4)A3972
ECDSA SigVer (FIPS186-4)A3977
ECDSA SigVer (FIPS186-4)A3979
ECDSA SigVer (FIPS186-4)A3983
ECDSA SigVer (FIPS186-4)A3993
ECDSA SigVer (FIPS186-4)A4003
ECDSA SigVer (FIPS186-4)A4004
ECDSA SigVer (FIPS186-4)A4005
HMAC-SHA-1A3962
HMAC-SHA-1A3977
HMAC-SHA-1A3983
HMAC-SHA-1A3993
HMAC-SHA-1A4003
HMAC-SHA-1A4004
HMAC-SHA-1A4005
HMAC-SHA-1A4017
HMAC-SHA2-224A3962
HMAC-SHA2-224A3977
HMAC-SHA2-224A3983
HMAC-SHA2-224A3993
HMAC-SHA2-224A4003
HMAC-SHA2-224A4004
HMAC-SHA2-224A4005
HMAC-SHA2-256A3812
HMAC-SHA2-256A3813
HMAC-SHA2-256A3814
HMAC-SHA2-256A3832
HMAC-SHA2-256A3850
HMAC-SHA2-256A3851
HMAC-SHA2-256A3852
HMAC-SHA2-256A3853
HMAC-SHA2-256A3857
HMAC-SHA2-256A3858
HMAC-SHA2-256A3962
HMAC-SHA2-256A3963
HMAC-SHA2-256A3977
HMAC-SHA2-256A3983
HMAC-SHA2-256A3993
HMAC-SHA2-256A4003
HMAC-SHA2-256A4004
HMAC-SHA2-256A4005
HMAC-SHA2-256A4017
HMAC-SHA2-384A3962
HMAC-SHA2-384A3977
HMAC-SHA2-384A3983
HMAC-SHA2-384A3993
HMAC-SHA2-384A4003
HMAC-SHA2-384A4004
HMAC-SHA2-384A4005
HMAC-SHA2-384A4017
HMAC-SHA2-512A3962
HMAC-SHA2-512A3977
HMAC-SHA2-512A3983
HMAC-SHA2-512A3993
HMAC-SHA2-512A4003
HMAC-SHA2-512A4004
HMAC-SHA2-512A4005
HMAC-SHA2-512A4017
HMAC-SHA2-512/224A3962
HMAC-SHA2-512/224A3977
HMAC-SHA2-512/224A3983
HMAC-SHA2-512/224A3993
HMAC-SHA2-512/224A4003
HMAC-SHA2-512/224A4004
HMAC-SHA2-512/224A4005
HMAC-SHA2-512/256A3962
HMAC-SHA2-512/256A3977
HMAC-SHA2-512/256A3983
HMAC-SHA2-512/256A3993
HMAC-SHA2-512/256A4003
HMAC-SHA2-512/256A4004
KAS-ECC-SSC Sp800-56Ar3A3962
KAS-ECC-SSC Sp800-56Ar3A3977
KAS-ECC-SSC Sp800-56Ar3A3983
KAS-ECC-SSC Sp800-56Ar3A3993
KAS-ECC-SSC Sp800-56Ar3A4003
KAS-ECC-SSC Sp800-56Ar3A4004
KAS-ECC-SSC Sp800-56Ar3A4005
KAS-FFC-SSC Sp800-56Ar3A3992
KDF IKEv2A4017
RSA SigGen (FIPS186-4)A3962
RSA SigGen (FIPS186-4)A3977
RSA SigGen (FIPS186-4)A3983
RSA SigGen (FIPS186-4)A3993
RSA SigGen (FIPS186-4)A4003
RSA SigGen (FIPS186-4)A4004
RSA SigGen (FIPS186-4)A4005
RSA SigVer (FIPS186-4)A3962
RSA SigVer (FIPS186-4)A3977
RSA SigVer (FIPS186-4)A3983
RSA SigVer (FIPS186-4)A3993
RSA SigVer (FIPS186-4)A4003
RSA SigVer (FIPS186-4)A4004
RSA SigVer (FIPS186-4)A4005
Safe Primes Key GenerationA3992
Safe Primes Key VerificationA3992
SHA-1A3962
SHA-1A3977
SHA-1A3983
SHA-1A3993
SHA-1A4003
SHA-1A4004
SHA-1A4005
SHA-1A4017
SHA2-224A3962
SHA2-224A3977
SHA2-224A3983
SHA2-224A3993
SHA2-224A4003
SHA2-224A4004
SHA2-224A4005
SHA2-256A3812
SHA2-256A3813
SHA2-256A3814
SHA2-256A3832
SHA2-256A3850
SHA2-256A3851
SHA2-256A3852
SHA2-256A3853
SHA2-256A3857
SHA2-256A3858
SHA2-256A3962
SHA2-256A3963
SHA2-256A3977
SHA2-256A3983
SHA2-256A3993
SHA2-256A4003
SHA2-256A4004
SHA2-256A4005
SHA2-256A4017
SHA2-384A3962
SHA2-384A3977
SHA2-384A3983
SHA2-384A3993
SHA2-384A4003
SHA2-384A4004
SHA2-384A4005
SHA2-384A4017
SHA2-512A3962
SHA2-512A3977
SHA2-512A3983
SHA2-512A3993
SHA2-512A4003
SHA2-512A4004
SHA2-512A4005
SHA2-512A4017
SHA2-512/224A3962
SHA2-512/224A3977
SHA2-512/224A3983
SHA2-512/224A3993
SHA2-512/224A4003
SHA2-512/224A4004
SHA2-512/224A4005
SHA2-512/256A3962
SHA2-512/256A3977
SHA2-512/256A3983
SHA2-512/256A3993
SHA2-512/256A4003
SHA2-512/256A4004
SHA2-512/256A4005

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Canonical Ltd. Ubuntu 22.04 Strongswan Cryptographic Module
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Update<br/>Recovery</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>selftest<br/>self-test<br/>Status Output</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>SSH<br/>IKEV</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Canonical Ltd. Ubuntu 22.04 Strongswan Cryptographic Module
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Update<br/>Recovery</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>selftest<br/>self-test<br/>Status Output</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>SSH<br/>IKEV</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Canonical Ltd. Ubuntu 22.04 Strongswan Cryptographic Module Version: 5.9.5-2ubuntu2.1+Fips1 Document Version: 1.1 Last Update: 2024-11-27 Prepared by: Prepared for: atsec information security corporation Canonical Ltd.

4516 Seton Center Parkway, Suite 250 110 Southwark Street, Blue Fin Building, 5th Floor

Austin, TX 78759 London, SE1 0SU www.atsec.com www.canonical.com © 2024 Canonical Ltd./ atsec information security.

Page 2
Table of Contents
#SectionPage
Page 3

© 2024 Canonical Ltd./ atsec information security.

3 of 40

Page 4
List of Tables
ItemPage
Table 1 - Security Levels5
Table 2 - Software, Firmware, Hybrid Tested Operating Environments8
Table 3 - Executable Code Sets9
Table 4 - Modes List and Description9
Table 5 - Approved Algorithms12
Table 6 - Entropy12
Table 7 - SSP Generation13
Table 8 - SSP Agreement13
Table 9 - Ports and Interfaces15
Table 10 - Roles16
Table 11 - Approved Services19
Table 12 - Storage Areas24
Table 13 - SSP Input-Output24
Table 14 - SSP Zeroization Methods25
Table 15 - SSP Information First27
Table 16 - SSP Information Second29
Table 17 - Pre-Operational Self-Tests30
Table 18 - Conditional Self-Tests31
Table 19 - Error States32
Figure 1 - Block Diagram7
Page 5
ISO/IEC 24759 Section 6.
[Number Below]FIPS 140-3 Section TitleSecurity Level
1General1
2Cryptographic Module Specification1
3Cryptographic Module Interfaces1
4Roles, Services, and Authentication1
5Software/Firmware Security1
6Operational Environment1
7Physical SecurityNot Applicable
8Non-invasive SecurityNot Applicable
9Sensitive Security Parameter Management1
10Self-tests1
11Life-cycle Assurance1
12Mitigation of Other AttacksNot Applicable

1. General Information 1.1. Overview This document is the non-proprietary FIPS 140-3 Security Policy for version 5.9.5-2ubuntu2.1+Fips1 of the Canonical Ltd. Ubuntu 22.04 Strongswan Cryptographic Module. It contains the security rules under which the module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for an distributed, but only whole and intact and including this notice. Other documentation is proprietary to their authors. 1.2. How this Security Policy was Prepared In preparing the Security Policy document, the laboratory formatted the vendor-supplied documentation for consolidation without altering the technical statements therein contained. The further refining of the Security Policy document was conducted iteratively throughout the conformance testing, wherein the Security Policy was submitted to the vendor, who would then edit, modify, and add technical contents. The vendor would also supply additional documentation, which the laboratory formatted into the existing Security Policy, and resubmitted to the vendor for their final editing. 1.3. Security Levels Table 1 describes the individual security areas of FIPS 140-3, as well as the security levels of those individual areas. Table 1 - Security Levels © 2024 Canonical Ltd./ atsec information security.

5 of 40

Page 6

2. Cryptographic Module Specification 2.1. Description Purpose and Use: The Canonical Ltd. Ubuntu 22.04 Strongswan Cryptographic Module (hereafter referred to as “the module”) provides cryptographic services for the Internet Key Exchange (IKE) protocol in the Ubuntu Operating System user space. The module uses the Canonical Ltd. Ubuntu 22.04 OpenSSL Cryptographic Module as a bound module (also referred to as “the bound OpenSSL module”), which provides the underlying cryptographic algorithms necessary for establishing and maintaining IKE sessions. The Canonical Ltd. Ubuntu 22.04 OpenSSL Cryptographic Module is a FIPS-validated module with certificate #4794. The module also uses the Canonical Ltd. Ubuntu 22.04 Kernel Crypto API Cryptographic Module as a bound module (also referred to as “the bound Kernel Crypto API module”) for performing integrity tests. The Canonical Ltd. Ubuntu 22.04 Kernel Crypto API Cryptographic Module is a FIPS-validated module with certificate #4894. Module Type: Software Module Embodiment: Multi-chip standalone Module Characteristics: N/A Cryptographic Boundary: The cryptographic boundary of the module is defined as the IKEv2 daemon, the libraries and plugins, and the ipsec command. In addition, the cryptographic boundary contains the .hmac files which store the expected integrity values for each of the software components. Tested Operational Environment's Physical Perimeter (TOEPP) The TOEPP of the module is defined as the general-purpose computer on which the module is installed. Picture or Block Diagram © 2024 Canonical Ltd./ atsec information security.

6 of 40

Page 7
OperatingHypervisor or
Hardware PlatformProcessorsPAA/PAI
SystemHost OS
Ubuntu 22.04Supermicro SYS-1019P-WTRIntel Xeon Gold 6226AES-NI, SHA extensionsN/A
Ubuntu 22.04Amazon Web Services (AWS) c6g.metalAWS Graviton2NEON, Crypto ExtensionsN/A
Ubuntu 22.04IBM z15IBM z15CPACFN/A
Ubuntu 22.04Supermicro SYS-1019P-WTRIntel Xeon Gold 6226NoneN/A
Ubuntu 22.04Amazon Web Services (AWS) c6g.metalAWS Graviton2NoneN/A

Figure 1 - Block Diagram 2.2. Version Information Hardware Versions: N/A Software Versions: 5.9.5-2ubuntu2.1+Fips1 Firmware Versions: N/A 2.3. Operating Environments Software, Firmware, Hybrid Tested Operating Environments: © 2024 Canonical Ltd./ atsec information security.

7 of 40

Page 8
OperatingHypervisor or
Hardware PlatformProcessorsPAA/PAI
SystemHost OS
Ubuntu 22.04IBM z15IBM z15NoneN/A
Hybrid
Software/
Package or File NameFirmware VersionFeaturesHardware VersionIntegrity Test
/usr/sbin/ipsec /usr/lib/ipsec/stroke /usr/lib/ipsec/starter /usr/lib/ipsec/charon /usr/lib/ipsec/pool /usr/lib/ipsec/_updown /usr/lib/ipsec/_fipscheck /usr/lib/ipsec/ikev2-kdf-selftest /usr/lib/ipsec/libstrongswan.so.0.0.0 /usr/lib/ipsec/plugins/ libstrongswan-openssl.so /usr/lib/ipsec/libcharon.so.0.0.0 /usr/lib/ipsec/plugins/libstrongswan- fips-prf.so /usr/lib/ipsec/plugins/libstrongswan- nonce.so /usr/lib/ipsec/plugins/libstrongswan- dnskey.so /usr/lib/ipsec/plugins/libstrongswan- pem.so /usr/lib/ipsec/plugins/libstrongswan- pgp.so /usr/lib/ipsec/plugins/libstrongswan- pkcs1.so /usr/lib/ipsec/plugins/libstrongswan- pkcs7.so /usr/lib/ipsec/plugins/libstrongswan- pkcs8.so /usr/lib/ipsec/plugins/libstrongswan- pkcs12.so /usr/lib/ipsec/plugins/libstrongswan- pubkey.so /usr/lib/ipsec/plugins/libstrongswan- sshkey.so /usr/lib/ipsec/plugins/libstrongswan- x509.so /usr/lib/ipsec/plugins/libstrongswan- constraints.so /usr/lib/ipsec/plugins/libstrongswan- revocation.so /usr/lib/ipsec/plugins/libstrongswan- kernel-netlink.so /usr/lib/ipsec/plugins/libstrongswan- socket-default.so5.9.5- 2ubuntu2.1+Fips1N/AN/AHMAC SHA-256

Table 2 - Software, Firmware, Hybrid Tested Operating Environments Executable Code Sets: © 2024 Canonical Ltd./ atsec information security.

8 of 40

Page 9
Hybrid
Software/
Package or File Name /usr/lib/ipsec/plugins/libstrongswan- stroke.so /usr/lib/ipsec/plugins/libstrongswan- attr.so /usr/lib/ipsec/plugins/libstrongswan- resolve.so /usr/lib/ipsec/plugins/libstrongswan- updown.so Kernel Bound ModuleFirmware VersionFeaturesHardware VersionIntegrity Test
/boot/vmlinuz-5.15.0-73-fips5.15.0-73-fipsN/AN/AHMAC SHA-512
*.ko files in /usr/lib/modules/5.15.0- 73-fips/kernel/crypto/ *.ko files in /usr/lib/modules/5.15.0- 73-fips/kernel/arch/x86/crypto/ *.ko files in /usr/lib/modules/5.15.0- 73-fips/kernel/arch/arm64/crypto/ *.ko files in /usr/lib/modules/5.15.0- 73-fips/kernel/arch/s390/crypto/RSA signature verification
/usr/lib/*-linux-gnu/libkcapi.so.1.4.0 /usr/bin/sha512hmac OpenSSL Bound Module1.4.0- 1ubuntu0.1~Fips1HMAC SHA-512
/usr/lib/x86_64-linux-gnu/ossl- modules-3/fips.so3.0.5- 0ubuntu0.1+Fips2.1N/AN/AHMAC-SHA-256
NameDescriptionTypeStatus Indicator
Approved modeAutomatically entered when the module is operational.ApprovedEquivalent to the indicator of the requested service.

Table 3 - Executable Code Sets Vendor Affirmed Operating Environments: N/A 2.4. Excluded Components There are no components within the cryptographic boundary excluded from the FIPS 140-3 requirements. 2.5. Modes of Operation Modes List and Description: Table 4 - Modes List and Description The module enters Approved mode after passing all pre-operational self-tests and cryptographic algorithm self-tests executed on start-up. The approved mode of operation is assumed once the Mode change instructions and status indicators: The Canonical Ltd. Ubuntu 22.04 Strongswan Cryptographic Module implements the approved service indicator relying on a global service indicator (In compliance with IG 2.4.C - Table) which is the successful establishment of the IKE connection. Degraded Mode Description: The module does not implement a degraded mode of operation. © 2024 Canonical Ltd./ atsec information security.

9 of 40

Page 10
Description / Key
Algorithm and
CAVP CertStandardMode / MethodSize(s) / Key StrengthsUse / Function
A40171 OpenSSL Bound ModuleKDF IKEv2 (CVL)HMAC with SHA-1, SHA- 256, SHA-384, SHA-512112-256 bitsKey derivation in the IKEv2 protocol
A3958 A3959 A3960 A3973 A3980 A3981 A3982AES [FIPS 197, SP 800-38A, SP 800-38A Addendum, SP 800-38F]CBC, CCM128, 192, 256 bitsAuthenticated Encryption Authenticated Decryption
A3961 A3974 A3975 A3976 A3988 A3989 A3990 A3994 A3995 A3996 A3997 A3998 A3999 A4000 A4001 A4002AES [FIPS 197, SP 800-38D]GCM (internal IV)128, 192, 256 bitsAuthenticated Encryption
A3961 A3974 A3975 A3976 A3988 A3989 A3990 A3994 A3995 A3996 A3997 A3998 A3999 A4000 A4001 A4002AES [FIPS 197, SP 800-38D]GCM (external IV)128, 192, 256 bitsAuthenticated Decryption
A3970CTR_DRBG [SP 800-90Ar1]AES-128, AES-192, AES-256, with/without derivation function, with/without prediction resistance128, 192, 256 bitsRandom number generation
A3962 A3977 A3983 A3993 A4003 A4004 A4005ECDSA [FIPS 186-4]SHA-224, SHA-256, SHA- 384, SHA-512, SHA- 512/224, SHA-512/256P-224, P-256, P-384, P-521 (112-256 bits)Signature generation
A3964 A3972 A3979SHA3-224, SHA3-256, SHA3-384, SHA3-512
A3962 A3977 A3983 A3993 A4003 A4004 A4005SHA-1, SHA-224, SHA-256, SHA-384, SHA- 512, SHA- 512/224, SHA-512/256P-224, P-256, P-384, P-521 (112-256 bits)Signature verification
A3964 A3972 A3979SHA3- 224, SHA3-256, SHA3-384, SHA3-512

2.6. Algorithms Approved Algorithms: Although HMAC and SHA are implemented by the bound OpenSSL module, the CAVP certificate still contains HMAC and SHA as prerequisite algorithms. © 2024 Canonical Ltd./ atsec information security.

10 of 40

Page 11
Description / Key
Algorithm and
CAVP CertStandardMode / MethodSize(s) / Key StrengthsUse / Function
A3962 A3977 A3983 A3993 A4003 A4004 A4005Appendix B.4.2 Testing CandidatesP-224, P-256, P-384, P-521 (112-256 bits)Key pair generation
A3962 A3977 A3983 A3993 A4003 A4004 A4005N/AP-224, P-256, P-384, P-521 (112-256 bits)Key pair verification
A3962 A3977 A3983 A3993 A4003 A4004 A4005RSA [FIPS 186-4]PKCS#1 v1.5 and PSS with SHA-224, SHA-256, SHA- 384, SHA-512, SHA- 512/224, SHA-512/2562048-16384 bits (112-256 bits)Signature generation
A3962 A3977 A3983 A3993 A4003 A4004 A4005PKCS#1 v1.5 and PSS with SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, SHA- 512/224, SHA-512/2562048-16384 bits (112-256 bits)Signature verification
A3962 A3977 A3983 A3993 A4003 A4004 A4005HMAC [FIPS 198- 1]SHA-1, SHA-224, SHA-256, SHA-384, SHA- 512, SHA- 512/224, SHA-512/256112-524288 bits (112-256 bits)Message authentication
A3962 A3977 A3983 A3993 A4003 A4004 A4005SHA [FIPS 180-4]SHA-1, SHA-224, SHA-256, SHA-384, SHA- 512, SHA- 512/224, SHA-512/256N/AMessage digest
A3963HMAC [FIPS 198- 1]SHA-256112-524288 bits (112-256 bits)Message authentication
SHA [FIPS 180-4]SHA-256N/AMessage digest
A3992KAS-FFC-SSC [SP 800-56Ar3]dhEphem (initiator/responder)MODP-2048, MODP- 3072, MODP-4096, MODP-6144, MODP- 8192, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192 (112-200 bits)Shared secret computation
A3962 A3977 A3983 A3993 A4003 A4004 A4005KAS-ECC-SSC [SP 800-56Ar3]Ephemeral Unified Model (initiator/responder)P-224, P-256, P-384, P-521 (112-256 bits)Shared secret computation
A3992Safe primes [SP 800-56Ar3]SP 800-56Ar3 Section 5.6.1.1.4 Testing CandidatesMODP-2048, MODP- 3072, MODP-4096, MODP-6144, MODP- 8192, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192 (112-200 bits)Key pair generation Key pair verification

© 2024 Canonical Ltd./ atsec information security.

11 of 40

Page 12
Description / Key
Algorithm and
CAVP Cert Kernel Bound ModuleStandardMode / MethodSize(s) / Key StrengthsUse / Function
A3812 A3813 A3814 A3832 A3850 A3851 A3852 A3853 A3857 A3858SHA [FIPS 180-4]SHA-256N/AMessage digest
A3812 A3813 A3814 A3832 A3850 A3851 A3852 A3853 A3857 A3858HMAC [FIPS 198- 1]SHA-256128-524288 bits (128 bits)Message authentication
OperationalEntropy Per
NameTypeSample SizeConditioning Component
EnvironmentSample
OpenSSL CPU Time Jitter RNG Entropy Source (Cert. #E62)Non-physicalSee Table 264 bitsLinear-Feedback Shift Register (LFSR)

Table 5 - Approved Algorithms Vendor Affirmed Algorithms: N/A Non-Approved, Allowed Algorithms: The module does not implement non-approved algorithms allowed in the approved mode of operation. Non-Approved, Allowed Algorithms with No Security Claimed: The module does not implement non-approved algorithms allowed in the approved mode of operation with no security claimed. Non-Approved, Not Allowed Algorithms: The module does not implement non-approved algorithms not allowed in the approved mode of operation. Entropy Information: RNG Information: The module does not implement any random number generator. Instead, it uses the Random Number Generation (RNG) service provided by the bound Canonical Ltd. Ubuntu 22.04 OpenSSL Cryptographic Module, which implements a Deterministic Random Bit Generator (DRBG) based on [SP800-90Ar1]. The DRBG is seeded with 384 bits of entropy and 256 bits of entropy are used to reseed the DRBG. The highest SSP security strength generated by the module is 256 bits. © 2024 Canonical Ltd./ atsec information security.

12 of 40

Page 13
NameTypeProperties
Safe primes key pair generationCKGKey type: Diffie-Hellman key pair Groups: MODP-2048, MODP-3072, MODP4096, MODP-6144, MODP- 8192 Security strength: 112-200 bits Method: SP 800-56Ar3 (safe primes) Section 5.6.1.1.4 Testing Candidates Compliant to SP 800-133r2, Section 5.2. Random seeds are obtained directly from an SP 800-90Arev1 compliant DRBG in compliance with SP 800-133rev2 section 4 (without the use of V, as described in the additional comment 2 of IG D.H).
EC key pair generationCKGKey type: EC Diffie-Hellman key pair Curves: P-224, P-256, P-384, P-521 Security strength: 112, 128, 192, 256 bits Method: FIPS 186-4 Appendix B.4.2 Testing Candidates Compliant to SP 800-133r2, Section 5.1 and 5.2. Random seeds are obtained directly from an SP 800-90Arev1 compliant DRBG in compliance with SP 800-133rev2 section 4 (without the use of V, as described in the additional comment 2 of IG D.H).
NameTypeProperties
Diffie-Hellman key agreement with IKE KDFKASGroups: MODP-2048, MODP-3072, MODP4096, MODP- 6144, MODP-8192 Security strength: 112-200 bits Compliant with Scenario 2 (2) of FIPS 140-3 IG D.F
EC Diffie-Hellman key agreement with IKE KDFKASCurves: P-224, P-256, P-384, P-521 Security strength: 112, 128, 192, 256 bits Compliant with Scenario 2 (2) of FIPS 140-3 IG D.F

2.8. SSP Generation The module implements the key derivation portion of the DH and ECDH key agreement, using the NIST SP 800-135 IKEv2 (CVL) in compliance with Section 6.2 of SP 800-132r2. The DH and ECDH key pairs to be used in the IKEv2 protocol are generated by the bound OpenSSL module. Below are listed the SSP generation methods provided by the bound OpenSSL module: Table 7 - SSP Generation 2.9. SSP Establishment The Canonical Ltd. Ubuntu 22.04 Strongswan Cryptographic Module and the bound OpenSSL module together provide the Diffie Hellman and EC Diffie Hellman key agreement. The Canonical Ltd. Ubuntu

22.04 Strongswan Cryptographic Module only implements the NIST SP 800-135 IKEv2 KDF (CVL) part

of the key agreement using the HMAC portion of the SSP agreement and the bound OpenSSL module provides the shared secret computation. Below are listed the SSP agreement methods provided by the bound OpenSSL module: Table 8 - SSP Agreement The module does not implement any key transport method. 2.10. Design and Rules The module performs pre-operational self-test and cryptographic algorithm self-tests when it is loaded into memory without operator intervention. Pre-operational self-tests ensure that the © 2024 Canonical Ltd./ atsec information security.

13 of 40

Page 14

module is not corrupted and that the cryptographic algorithms work as expected. While the module is executing the self-tests, services are not available, and input and output are inhibited. The module is not available for use until the self-tests complete successfully. If any pre-operational self-test fails, the module will return the error message listed in Table 19, enter the error state and terminate. Therefore, no cryptographic operations or data output are possible. Note: The bound Canonical Ltd. Ubuntu 22.04 OpenSSL Cryptographic Module and the Canonical Ltd. Ubuntu 22.04 Kernel Crypto API Cryptographic Module perform their own pre-operational and cryptographic algorithm self-tests automatically when they are loaded into memory. The Canonical Ltd. Ubuntu 22.04 Strongswan Cryptographic Module ensures that both bound modules complete their pre-operational self-tests successfully. 2.11. Initialisation There are no specific initialization requirements. © 2024 Canonical Ltd./ atsec information security.

14 of 40

Page 15
Physical PortLogical InterfaceData that passes over the port/interface
As a software-only module, the module does not have physical ports. Physical Ports are interpreted to be the physical ports of the hardware platform on which it runs.Data Input/etc/ipsec.secrets file, private key file, certificate files under the /etc/ipsec.d directory, input data received from the network (IKEv2 protocol), input data received from the bound OpenSSL module via its API parameters.
Data OutputOutput data sent through the network (IKEv2 protocol),output data sent to the bound OpenSSL module via its API parameters.
Control InputInvocation of the ipsec command on the command line, control parameters via the ipsec command and the /etc/ipsec.conf file, IKEv2 protocol message requests received from the network.
Status OutputStatus messages returned after execution of the ipsec command, status of processing IKEv2 protocol message requests sent through the network.
Power InputN/A

3. Cryptographic Module Interfaces 3.1. Description Table 9 - Ports and Interfaces The logical interfaces are the APIs through which the applications request services. These logical interfaces are logically separated from each other by the API design. 3.2. Trusted Channel Specification The module does not implement a trusted channel. © 2024 Canonical Ltd./ atsec information security.

15 of 40

Page 16
NameTypeOperator TypeAuthentication Methods
Crypto OfficerRoleCON/A
Security
NameDescriptionIndicatorInputsOutputsFunctionsSSP Access
Start IKEv2 daemonStart IKE daemonSuccessful establishment of the IKE connection.N/ASuccess/F ailN/AN/A
Configure IKEv2 daemonConfigure IKEv2 daemonSuccessful establishment of the IKE connection.Pre-shared Key or Post- Quantum Pre-shared Key RSA public key RSA private key EC public key EC private keySuccess/F ailN/APre-shared Key or Post- Quantum Pre-shared Key; RSA public key; RSA private key; EC public key; EC private key: R
IKE_SA_INIT ExchangeKey exchangeSuccessful establishment of the IKE connection.Private and public keyShared secretDiffie- Hellman (modp2048, modp3072, modp4096, modp6144, modp8192) with key size between 2048 and 8192 bits EC Diffie- Hellman with NIST curves P- 224, P-256, P-384, P- 521DH public key, DH private key, EC public key, EC private key, Shared secret: G, R

4. Roles, Services, and Authentication The module does not implement operator authentication. 4.2. Roles Table 10 - Roles The module supports the Crypto Officer role only. This sole role is implicitly and always assumed by the operator of the module. No support is provided for multiple concurrent operators. 4.3. Approved Services © 2024 Canonical Ltd./ atsec information security.

16 of 40

Page 17
Security
NameDescriptionIndicatorInputsOutputsFunctionsSSP Access
Key derivationSuccessful establishment of the IKE connection.N/ASuccess/F ailSP800- 135r1 IKEv2 KDF (CVL) using HMAC with SHA-1, SHA- 256, SHA- 384 and SHA-512Derivation key (SK_d), Encryption key (SK_ei, SK_er), Authenticat ion key (SK_ai, SK_ar), Authenticat ion payload key (SK_pi, SK_pr), Shared secret: G
IKE_AUTH ExchangeSignature generation Signature verificationSuccessful establishment of the IKE connection.Private and public keySuccess/F ailRSA PKCS#1 v1.5 and PSS with SHA-1, SHA- 224, SHA- 256, SHA- 384, SHA- 512, SHA- 512/224, SHA- 512/256 ECDSA (P- 224, P-256, P-384, P- 521) with SHA-1, SHA- 224, SHA- 256, SHA- 384, SHA- 512, SHA- 512/224, SHA- 512/256RSA public key, RSA private key, EC public key, EC private key, RSA Peer’s public key, Peer’s EC public key: W
Authenticated Encryption Authenticated DecryptionSuccessful establishment of the IKE connection.Encryption key Authenticati on keySuccess/F ailAES-CBC + HMAC with SHA-1, SHA- 256, SHA- 384, SHA- 512 AES-GCM AES-CCMEncryption key (SK_ei, SK_er): W Authenticat ion key (SL_ai, SK_ar): W
CREATE_CHILD _SA ExchangeAuthenticated Encryption Authenticated DecryptionSuccessful establishment of the IKE connection.Encryption key Authenticati on keySuccess/F ailAES-CBC + HMAC with SHA-1, SHA- 256, SHA- 384, SHA-Encryption key (SK_ei, SK_er): W Authenticat

© 2024 Canonical Ltd./ atsec information security.

17 of 40

Page 18
Security
NameDescriptionIndicatorInputsOutputsFunctionsSSP Access
512 AES-GCM AES-CCMion key (SK_ai, SK_ar): W
CREATE_CHILD _SA ExchangeKey exchangeSuccessful establishment of the IKE connection.N/AShared secretDiffie- Hellman (modp2048, modp3072, modp4096, modp6144, modp8192) with key size between 2048 and 8192 bits EC Diffie- Hellman with NIST curves P- 224, P-256, P-384, P- 521DH public key, DH private key, EC public key, EC private key, Shared secret: G
CREATE_CHILD _SA ExchangeKey derivationSuccessful establishment of the IKE connection.Derivation keyDerived keySP800- 135r1 IKEv2 KDF (CVL) using HMAC with SHA-1, SHA- 256, SHA- 384 and SHA-512Derivation key (SK_d): W; New derivation key (SK_d), New encryption key (SK_ei, SK_er), New authenticati on key (SK_ai, SK_ar), New authenticati on payload key (SK_pi, SK_pr): G
INFORMATION AL ExchangeAuthenticated Encryption Authenticated DecryptionSuccessful establishment of the IKE connection.Encryption key Authenticati on keySuccess/F ailAES-CBC + HMAC with SHA-1, SHA- 256, SHA- 384, SHA- 512 AES-GCM AES-CCMEncryption key (SK_ei, SK_er): W Authenticat ion key (SK_ai, SK_ar): W
Show versionReturn the module name and version informationNoneN/AModule name and versionN/AN/A

© 2024 Canonical Ltd./ atsec information security.

18 of 40

Page 19
Security
NameDescriptionIndicatorInputsOutputsFunctionsSSP Access
Show statusReturn the module statusNoneN/AModule statusN/AN/A
Self-testPerform the CASTs and integrity testsNoneN/ASuccess/f ailSee Section 10N/A
ZeroizationClose Security AssociationNoneAny SSPSuccess/F ailN/AAll SSPs: Z
Terminate IKEv2 daemonNoneAny SSPSuccess/F ailN/AAll SSPs: Z

Table 11 - Approved Services Table 11 lists the approved services. The following convention is used to specify access rights to SSPs:

19 of 40

Page 20

5. Software/Firmware Security 5.1. Integrity Techniques The integrity of the module is verified by comparing an HMAC-SHA-256 value calculated at run time with the HMAC value stored in the .hmac file that was computed at build time, for each of the components that comprise the module. The HMAC-SHA-256 algorithm for integrity test is provided by the bound Canonical Ltd. Ubuntu 22.04 Kernel Crypto API Cryptographic Module. If the HMAC values do not match, the test fails and the module enters the error state. 5.2. Initiate on Demand Integrity test is performed as part of the pre-operational self-tests, which are executed when the module is initialized. The integrity test can be invoked on demand by unloading and subsequently reinitializing the module, which will perform (among others) the software integrity tests. © 2024 Canonical Ltd./ atsec information security.

20 of 40

Page 21

6. Operational Environment 6.1. Operational Environment Type and Requirements Type of Operating Environment: modifiable; the module executes as part of a general-purpose operating system (Canonical Ubuntu 22.04), which allows modification, loading, and execution of software that is not part of the validated module. How Requirements are Satisfied: If properly installed, the operating system provides process isolation and memory protection mechanisms that ensure appropriate separation for memory access among the processes on the system. Each process has control over its own data and uncontrolled access to the data of other processes is prevented. Processes that are spawned by the cryptographic module are owned by the module and are not owned by external processes/operators. 6.2. Configuration Settings and Restrictions The module shall be installed as stated in Section 11.1. Instrumentation tools like the ptrace system call, gdb and strace, as well as other tracing mechanisms offered by the Linux environment such as ftrace or systemtap, shall not be used in the operational environment. The use of any of these tools implies that the cryptographic module is running in a nonvalidated operational environment. © 2024 Canonical Ltd./ atsec information security.

21 of 40

Page 22

7. Physical Security The module is comprised of software only and therefore this section is not applicable. © 2024 Canonical Ltd./ atsec information security.

22 of 40

Page 23

8. Non-Invasive Security This module does not implement any non-invasive security mechanism and therefore this section is not applicable. © 2024 Canonical Ltd./ atsec information security.

23 of 40

Page 24
Storage AreaPersistence
Description
NameType
RAMTemporary storage for SSPs used by the module as part of service executionDynamic
FormatDistributionEntryRelated
NameFromTo
TypeTypeTypeSFI
Key filesOperator within TOEPPCryptographic ModulePlaintextManualElectronicN/A
IKE protocol messages (input)Operator within TOEPPCryptographic ModulePlaintextManualElectronicN/A
API parameters (input)OpenSSL bound moduleCryptographic ModulePlaintextManualElectronicN/A
IKE protocol messages (output)Cryptographic ModuleOperator within TOEPPPlaintextManualElectronicN/A
API parameters (output)Cryptographic ModuleOpenSSL bound module OperatorPlaintextManualElectronicN/A
Zeroization MethodDescriptionRationaleOperator Initiation
IKE SA CloseClose of the IKEv2 Security Association (SA)Memory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable.By closing an IKE connection (i.e., the command ipsec down).
IKEv2 Daemon TerminateTermination of the IKEv2 daemon.Memory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable.The command ipsec stop.
Remove power from the moduleDe-allocates the volatile memory used to store SSPs.Volatile memory used by the module is overwritten within nanoseconds when power is removed.By removing power.

9. Sensitive Security Parameters Management 9.1. Storage Areas Table 12 - Storage Areas The module does not perform persistent storage of SSPs. The SSPs are temporarily stored in the RAM in plaintext form. SSPs are provided to the module by the calling process and are destroyed when released by the appropriate zeroization function calls. Public and private keys for IKEv2 authentication are stored in the /etc/ipsec.d/certs and /etc/ipsec.d/private directories, which are within the module’s physical perimeter, but outside its cryptographic boundary. The module does not support manual key entry or intermediate key generation key output. The keys are entered from or output to the module electronically. © 2024 Canonical Ltd./ atsec information security.

24 of 40

Page 25
Type -GeneratedEstablished
NameDescriptionSize - StrengthUsed By
CategoryByBy
RSA private keyRSA private key.2048-16384 bits (112-256 bits)Private KeyN/AN/AIKE_AUTH Exchange Configure IKEv2 daemon
RSA public keyRSA public key.2048-16384 bits (112-256 bits)Public KeyN/AN/AIKE_AUTH Exchange Configure IKEv2 daemon
RSA Peer’s public keyRSA Peer’s public keys.2048-16384 bits (112-256 bits)Public KeyN/AN/AIKE_AUTH Exchange
DH public keyDH public key.MODP-2048, MODP-3072, MODP4096, MODP-6144, MODP-8192 (112-200 bits)Public KeyN/A (Generated by the bound module OpenSSL)N/AIKE_SA_INIT Exchange CREATE_CHILD_SA Exchange
DH private keyDH private key.MODP-2048, MODP-3072, MODP4096, MODP-6144, MODP-8192 (112-200 bits)Private KeyN/A (Generated by the bound module OpenSSL)N/AIKE_SA_INIT Exchange CREATE_CHILD_SA Exchange
Peer’s DH public keyPeer’s DH public key.MODP-2048, MODP-3072, MODP4096, MODP-6144, MODP-8192 (112-200 bits)Public KeyN/AN/AIKE_SA_INIT Exchange CREATE_CHILD_SA Exchange
EC private keyPrivate key for ECDSA or ECDH.P-224, P-256, P- 384, P-521 (112, 128, 192, 256 bits)Private KeyN/A (Generated by the bound module OpenSSL)N/AIKE_SA_INIT Exchange CREATE_CHILD_SA Exchange IKE_AUTH Exchange Configure IKEv2 daemon
EC public keyPublic key for ECDSA or ECDH.P-224, P-256, P- 384, P-521 (112, 128, 192, 256 bits)Public KeyN/A (Generated by the boundN/AIKE_SA_INIT Exchange CREATE_CHILD_SA Exchange

Table 14 - SSP Zeroization Methods The memory occupied by SSPs is allocated by regular memory allocation operating system calls. The module calls appropriate key zeroization functions provided by the bound OpenSSL module and calls its own appropriate key zeroization functions. In both cases, these functions overwrite the memory with zeroes and deallocate the memory with the regular memory deallocation operating system call. All data output is inhibited during zeroization. 9.4. SSPs © 2024 Canonical Ltd./ atsec information security.

25 of 40

Page 26
Type -GeneratedEstablished
NameDescriptionSize - StrengthUsed By
CategoryByBy
module OpenSSL)IKE_AUTH Exchange Configure IKEv2 daemon
Peer’s EC public keyPeer’s public keys for ECDSA or ECDH.P-224, P-256, P- 384, P-521 (112, 128, 192, 256 bits)Public KeyN/AN/AIKE_SA_INIT Exchange CREATE_CHILD_SA Exchange IKE_AUTH Exchange
Shared secretShared secret for DH or ECDH.112-256 bitsShared SecretN/AN/A (Established by the bound module OpenSSL)IKE_SA_INIT Exchange CREATE_CHILD_SA Exchange
Derivation key (SK_d)Derivation key (SK_d) from IKE_SA112-256 bitsSymmetric KeyNIST SP800- 135r1 IKEv2 KDF (CVL)N/AIKE_SA_INIT Exchange CREATE_CHILD_SA Exchange
Encryption key (SK_ei, SK_er)Encryption keys from IKE_SA (SK_ei, SK_er) (AES)112-256 bitsSymmetric KeyNIST SP800- 135r1 IKEv2 KDF (CVL)N/AIKE_SA_INIT Exchange CREATE_CHILD_SA Exchange IKE_AUTH Exchange INFORMATIONAL Exchange
Authentication key (SK_ai, SK_ar)Authentication keys from IKE_SA (SK_ai, SK_ar) (HMAC)112-256 bitsSymmetric KeyNIST SP800- 135r1 IKEv2 KDF (CVL)N/AIKE_SA_INIT Exchange CREATE_CHILD_SA Exchange IKE_AUTH Exchange INFORMATIONAL Exchange
Authentication payload key (SK_pi, SK_pr)Authentication payload keys from IKE_SA (SK_pi, SK_pr) (HMAC)112-256 bitsSymmetric KeyNIST SP800- 135r1 IKEv2 KDF (CVL)N/AIKE_SA_INIT Exchange
New Derivation key (SK_d)New Derivation Key from CHILD_SA (SK_d) (HMAC)112-256 bitsSymmetric KeyNIST SP800- 135r1 IKEv2 KDF (CVL)N/ACREATE_CHILD_SA Exchange
New Encryption key (SK_ei, SK_er)New Encryption keys from CHILD_SA (SK_ei, SK_er) (HMAC)112-256 bitsSymmetric KeyNIST SP800- 135r1 IKEv2 KDF (CVL)N/ACREATE_CHILD_SA Exchange

© 2024 Canonical Ltd./ atsec information security.

26 of 40

Page 27
Type -GeneratedEstablishedUsed By
NameDescriptionSize - Strength
CategoryByBy
New Authentication key (SK_ai, SK_ar)New Authentication keys from CHILD_SA (SK_ai, SK_ar) (HMAC)112-256 bitsSymmetric KeyNIST SP800- 135r1 IKEv2 KDF (CVL)N/ACREATE_CHILD_SA Exchange
New Authentication payload key (SK_pi, SK_pr)New Authentication payload keys from CHILD_SA (SK_pi, SK_pr) (HMAC)112-256 bitsSymmetric KeyNIST SP800- 135r1 IKEv2 KDF (CVL)N/ACREATE_CHILD_SA Exchange
Pre-shared Key or Post- Quantum Pre- shared KeyPre-shared Key or Post- Quantum Pre- shared Key112-256 bitsSymmetric KeyN/AN/AConfigure IKEv2 daemon
StorageRelated
NameInput - OutputStorageType
DurationSSPs
RSA private keyInput: Read from the private key files. Output: To the bound OpenSSL module via API parameters.RAMFor the duration of the service.CSPRSA public key
RSA public keyInput: Read from the host key files. Output: To the network peer via IKE_AUTH exchange message.RAMFor the duration of the service.PSPRSA private key
RSA Peer’s public keyInput: From the network peer via IKE_AUTH exchange message. Output: To the bound OpenSSL module via API parameters.RAMFor the duration of the service.PSPNone
DH public keyInput: From the bound OpenSSL module via API parameters. Output: To the network peer via IKE_SA_INIT or CREATE_CHILD_SA exchange messages.RAMFor the duration of the service.PSPDH private key
DH private keyInput: From the bound OpenSSL module via API parameters. Output: To the bound OpenSSL module via API parameters.RAMFor the duration of the service.CSPDH public key
Peer’s DH public keyInput: From the network peer IKE_SA_INIT or CREATE_CHILD_SA exchange messages Output: To the bound OpenSSL module via API parameters.RAMFor the duration of the service.PSPNone
EC private keyInput ECDSA: Read from the private key files. Output ECDSA: To the bound OpenSSL module via API parameters.RAMFor the duration of the service.CSPEC public key
Input ECDH: From the bound OpenSSL module via API parameters.RAMFor the duration of the service.CSPEC public key

Table 15 - SSP Information First © 2024 Canonical Ltd./ atsec information security.

27 of 40

Page 28
StorageRelated
NameInput - OutputStorageType
Output ECDH: To the bound OpenSSL module via API parameters.DurationSSPs
EC public keyInput ECDSA: Read from the host key files. Output ECDSA: To the network peer via IKE_AUTH exchange message.RAMFor the duration of the service.PSPEC private key
Input ECDH: From the bound OpenSSL module via API parameters. Output ECDH: to the network peer via IKE_SA_INIT or CREATE_CHILD_SA exchange messages.RAMFor the duration of the service.PSPEC private key
Peer’s EC public keyInput ECDSA: From the network peer via IKE_AUTH exchange message. Output ECDSA: To the bound OpenSSL module via API parameters.RAMFor the duration of the service.PSPNone
Input ECDH: From the network peer IKE_SA_INIT or CREATE_CHILD_SA exchange messages. Output ECDH: To the bound OpenSSL module via API parameters.RAMFor the duration of the service.PSPNone
Shared secretInput: From the bound OpenSSL module via API parameters. Output: N/A.RAMFor the duration of the service.CSPDH public key DH private key EC public key EC private key Peer’s DH public key Peer’s EC public key
Derivation key (SK_d)Input: N/A Output: N/ARAMFor the duration of the service.CSPNone
Encryption key (SK_ei, SK_er)Input: N/A Output: To the bound OpenSSL module via API parameters.RAMFor the duration of the service.CSPNone
Authentication key (SK_ai, SK_ar)Input: N/A Output: To the bound OpenSSL module via API parameters.RAMFor the duration of the service.CSPNone
Authentication payload key (SK_pi, SK_pr)Input: N/A Output: To the bound OpenSSL module via API parameters.RAMFor the duration of the service.CSPNone
New Derivation key (SK_d)Input: N/A Output: N/ARAMFor the duration of the service.CSPNone
New Encryption key (SK_ei, SK_er)Input: N/A Output: To the bound Kernel Crypto API module via API parameters.RAMFor the duration of the service.CSPNone

© 2024 Canonical Ltd./ atsec information security.

28 of 40

Page 29
StorageRelated
NameInput - OutputStorageType
DurationSSPs
New Authentication key (SK_ai, SK_ar)Input: N/A Output: To the bound Kernel Crypto API module via API parameters.RAMFor the duration of the service.CSPNone
New Authentication payload key (SK_pi, SK_pr)Input: N/A Output: To the bound Kernel Crypto API module via API parameters.RAMFor the duration of the service.CSPNone
Pre-shared Key or Post-Quantum Pre- shared KeyInput: Read from the private key files. Output: N/A.RAMFor the duration of the service.CSPNone

Table 16 - SSP Information Second 9.5. Transitions The SHA-1 algorithm as implemented by the bound OpenSSL module will be non-approved for all purposes, starting January 1, 2030. The RSA algorithm as implemented by the bound OpenSSL module conforms to FIPS 186-4, which has been superseded by FIPS 186-5. FIPS 186-4 will be withdrawn on February 3, 2024. © 2024 Canonical Ltd./ atsec information security.

29 of 40

Page 30
AlgorithmImplementationTest PropertiesTest MethodTest TypeIndicatorDetails
HMAC SHA-256C256-bit keysHMAC SHA-256 value calculated at run time is compared with the precomputed HMAC SHA-256 value.Software integrityModule becomes operationalIntegrity test performed by the bound Kernel Crypto API module to check the fipscheck tool and the Strongswan executables.
TestTest
AlgorithmImplementationTest TypeIndicatorDetailsConditions
PropertiesMethod
SP800-135r1 IKEv2 KDF (CVL) OpenSSL Bound ModuleCHMAC- SHA-1KATCASTModule is operationalKDF used for IKEv2Module initialization
HMAC SHA- 256C256 bit keysKATCASTModule is operationalMessage authenticationModule initialization
SHA-1C0-8184 bit messagesKATCASTModule is operationalMessage digestModule initialization
SHA-512C0-8184 bit messagesKATCASTModule is operationalMessage digestModule initialization
AES-GCMC256-bit keyKATCASTModule is operationalEncryption, Decryption (separately)Module initialization
CTR_DRBGC128 bit key with derivation function and prediction resistanceKATCASTModule is operationalDRBG generation and reseed Health tests according to section 11.3 of [SP800- 90Ar1]Module initialization
KAS-FFC-SSCCffdhe2048KATCASTModule is operationalShared secret computationModule initialization

10. Self-Tests 10.1. Pre-Operational Self-Tests Table 17 - Pre-Operational Self-Tests powered on, before the module transitions into the operational state. While the module is executing the self-tests, services are not available, and data output (via the data output interface) is inhibited until the tests are successfully completed. The module transitions to the operational state only after the pre-operational self-tests are passed successfully. 10.2. Conditional Self-Tests The module performs the self-test on the following Approved cryptographic algorithm supported in Approved mode using the Known Answer Test (KAT) shown below: © 2024 Canonical Ltd./ atsec information security.

30 of 40

Page 31
TestTest
AlgorithmImplementationTest TypeIndicatorDetailsConditions
PropertiesMethod
KAS-ECC-SSCCP-256KATCASTModule is operationalShared secret computationModule initialization
RSA SigGen/SigverCPKCS#1 v1.5 with SHA-256 and 2048- bit keyKATCASTModule is operationalSignature generation and Signature verificationModule initialization
ECDSA SigGen/SigverCSHA-256 and P-224, B-233KATCASTModule is operationalSignature generation and Signature verificationModule initialization
DH KeyGen (Safe Primes)Cffdhe2048PCTPCTModule is operationalSP800-56Ar3 Section 5.6.2.1.4Key pair generation
RSA KeyGenCPKCS#1 v1.5 padding SHA-256PCTPCTModule is operationalSignature generation and Signature verificationKey pair generation
ECDSA KeyGen Kernel Bound ModuleCSHA-256PCTPCTModule is operationalSignature generation and Signature verificationKey pair generation
HMAC SHA- 256C32, 160, 1048 bit keysKATCASTModule becomes operationalSelf-test for the algorithm provided by the bound Kernel Crypto API module used for the integrity testModule initialization

5.6.2.1.4 Table 18 - Conditional Self-Tests For the KAT, the module calculates the result and compares it with the known answer. If the calculated value does not match the known answer, the KAT fails and the module enters the error state. The module performs self-tests on all approved cryptographic algorithms as part of the approved services supported in the approved mode of operation, using the tests shown in Table 18. Services are not available, and data output (via the data output interface) is inhibited during the self-tests. If any of these tests fails, the module transitions to the error state. 10.3. Periodic Self-Tests The module does not implement any periodic self-tests. 10.4. Error States If the module fails any of the self-tests, it will return an error message to indicate the error and then enter the error state. In the error state, the module immediately stops functioning and ends the © 2024 Canonical Ltd./ atsec information security.

31 of 40

Page 32
Recovery
NameDescriptionConditionsMethodIndicator
Error StateStrongswan stops executingIntegrity Test failureRestart of the moduleipsec: strongswan fips file integrity check failed
KAT failureipsec: strongswan fips ikev2 kdf self-test failed
Self-test failure in Canonical Ltd. Ubuntu 22.04 OpenSSL Cryptographic Moduleipsec start command returns error code 2 with the following cause 'unable to load OpenSSL FIPS provider'. PCT Failure: ipsec status command returns error code 1 or 2 and the OpenSSL bound module's OSSL_PROV_PARAM_STATUS is set to 0.
Self-test failure in Canonical Ltd. Ubuntu 22.04 Kernel Crypto API Cryptographic ModuleKernel panics with message failure “alg: <algo_name>: test failed”.

application process. Consequently, the data output interface is inhibited, and the module accepts no more inputs or requests (as the module is no longer running). The following table shows the list of error messages when the module fails any self-test. Table 19 - Error States To recover from the error state, the module must be restarted and perform self-tests again. If the failure persists, the module must be reinstalled. 10.5. Operator Initiation The software integrity tests, cryptographic algorithm self-tests, and entropy source start-up tests can be invoked on demand by unloading and subsequently re-initializing the module. On-demand selftests can be invoked by powering off and reloading the module, which cause the module to run the self-tests again. During the execution of the on-demand self-tests, services are not available and no data output or input is possible. © 2024 Canonical Ltd./ atsec information security.

32 of 40

Page 33

11. Life-Cycle Assurance 11.1. Startup Procedures The module is distributed as a part of Ubuntu 22.04 in the form of the following deb packages:

33 of 40

Page 34

boot into the FIPS supported kernel and create the /proc/sys/crypto/fips_enabled entry which tells the FIPS certified modules to run in Approved mode. If you do not reboot after installing and configuring the bootloader, Approved mode is not yet enabled. To verify that Approved mode is enabled after the reboot check the /proc/sys/crypto/fips_enabled file and ensure it is set to 1. If it is set to 0, the modules will not run in Approved mode. If the file is missing, the FIPS kernel is not installed, you can verify that FIPS has been properly enabled with the pro status command. The module can only operate in Approved mode as stated in section 3.2. With the operational environment setup as stated in the above section, the following restrictions are applicable. No more cipher addition is possible by configuration or command line options. Configure Charon as specified in ipsec.conf(5), and ipsec.secrets(5) man pages

34 of 40

Page 35

University of Applied Sciences Rapperswil, Switzerland FIPS module name: Canonical Ltd. Ubuntu 22.04 Strongswan Cryptographic Module FIPS module version: 5.9.5-2ubuntu2.1+Fips1 11.2. Administrator Guidance 11.2.1. Managing the IKEv2 Daemon To start the IKEv2 daemon, use the following command: # ipsec start To stop the IKEv2 daemon, use the following command: # ipsec stop To start the IKEv2 daemon automatically at the system boot time, use the following command: # systemctl enable strongswan To prevent the IKEv2 daemon from automatically starting, use the following command: # systemctl disable strongswan See the ipsec(8), ipsec.conf(5) and ipsec.secrets(5) man pages for more information about how to operate the module. 11.2.2. AES GCM IV The Canonical Ltd. Ubuntu 22.04 Strongswan Cryptographic Module is bound to the Canonical Ltd. Ubuntu 22.04 OpenSSL Cryptographic Module which implements AES-GCM. This module, Strongswan, generates the IV for AES-GCM in OpenSSL through the IKEv2 key establishment protocol which is compliant with IG C.H provision 1) (b), "IPSec protocol IV generation". The AES-GCM IV generation is in compliance with [RFC5282]. The module uses the [RFC7296] compliant IKEv2 protocol to establish the shared secret SKEYSEED from which the AES-GCM encryption keys are derived. By the virtue of the lifetime limit (see above Section 11.1.1), the IV is renegotiated before reaching 2^64. The IV does not get stored permanently. In case or normal or abnormal termination of the IKE connection, the SA has to be renegotiated by the module. In the event the module’s power is lost and restored, the operator must ensure that a new key for use with the AES GCM key encryption or decryption under this scenario shall be established. 11.2.3. RSA Signatures To meet the requirement stated in IG C.F, the bound OpenSSL module implements only the FIPS 186-

4 approved modulus sizes of 2048, 3072, and 4096 bits for signature generation. For signature

verification, the bound OpenSSL module implements only the FIPS 186-4 approved modulus sizes of 1024, 2048, 3072, and 4096 bits. Each modulus size was tested, and corresponding certificates can be found detailed in Section 2 for the bound OpenSSL module. © 2024 Canonical Ltd./ atsec information security.

35 of 40

Page 36

11.2.4. Compliance to SP 800-56ARev3 Assurances The bound OpenSSL module offers DH and ECDH shared secret computation services compliant to the SP 800-56ARev3. The Canonical Ltd. Ubuntu 22.04 Strongswan Cryptographic Module implements the NIST SP 800-135 IKEv2 KDF (CVL) part of the key agreement using the HMAC portion of the SSP agreement, while the bound OpenSSL module provides the SP 800-56Arev3-compliant DH and ECDH shared secret computation. Therefore, the module meets the requirements of IG D.F scenario 2 (2). In order to meet the required assurances listed in section 5.6 of SP 800-56ARev3, the following steps are performed.

  1. The entity using the bound OpenSSL module, must use the bound OpenSSL module's "Key pair generation" service for generating DH/ECDH ephemeral keys. This meets the assurances required by key pair owner defined in the section 5.6.2.1 of SP 800-56ARev3.
  2. As part of the bound OpenSSL module's shared secret computation (SSC) service, the bound OpenSSL module internally performs the public key validation on the peer's public key passed in as input to the SSC function. This meets the public key validity assurance required by the sections 5.6.2.2.1/5.6.2.2.2 of SP 800-56ARev3.
  3. The bound OpenSSL module does not support static keys therefore the "assurance of peer's possession of private key" is not applicable. 11.2.5. Legacy Algorithms The module utilizes the following legacy algorithms from the bound OpenSSL module, as defined in SP 800-131Arev2: • SHA-1 for RSA Signature Verification and ECDSA Signature Verification purposes. 11.3. Non-Administrator Guidance There is no non-administrator guidance. 11.4. Maintenance Requirements There are no maintenance requirements. 11.5. End of Life As the module does not persistently store SSPs, secure sanitization of the module consists of unloading the module. This will zeroize all SSPs in volatile memory. Then, the Ubuntu packages can be uninstalled from the Ubuntu 22.04 system. © 2024 Canonical Ltd./ atsec information security.

36 of 40

Page 37

12. Mitigation of Other Attacks The module does not implement security mechanisms to mitigate other attacks. © 2024 Canonical Ltd./ atsec information security.

37 of 40

Page 38
Table, extracted as text (did not parse into structured rows)
Appendix A. Glossary and Abbreviations AES          Advanced Encryption Standard API          Application Programming Interface CAST         Cryptographic Algorithm Self-Test CAVP         Cryptographic Algorithm Validation Program CBC          Cipher Block Chaining CCM          Counter with Cipher Block Chaining-Message Authentication Code CKG          Cryptographic Key Generation CMVP         Cryptographic Module Validation Program CSP          Critical Security Parameter CTR          Counter DH           Diffie-Hellman DRBG         Deterministic Random Bit Generator ECC          Elliptic Curve Cryptography ECDH         Elliptic Curve Diffie-Hellman ECDSA        Elliptic Curve Digital Signature Algorithm ENT (NP)     Non-physical Entropy Source FFC          Finite Field Cryptography FIPS         Federal Information Processing Standards GCM          Galois Counter Mode GMAC         Galois Counter Mode Message Authentication Code HMAC         Keyed-Hash Message Authentication Code IG           Implementation Guidance IKE          Internet Key Exchange IPSEC        Internet Protocol Security KAS          Key Agreement Scheme KAT          Known Answer Test NIST         National Institute of Science and Technology PAA          Processor Algorithm Acceleration PCT          Pair-wise Consistency Test PKCS         Public-Key Cryptography Standards PSS          Probabilistic Signature Scheme RAM          Random Access Memory RNG          Random Number Generator RSA          Rivest, Shamir, Addleman SHA          Secure Hash Algorithm SSC          Shared Secret Computation SSH          Secure Shell SSP          Sensitive Security Parameter TLS          Transport Layer Security TOEPP        Tested Operational Environment's Physical Perimeter © 2024 Canonical Ltd./ atsec information security.

38 of 40

Page 39
FIPS 140-3FIPS PUB 140-3 - Security Requirements For Cryptographic Modules March 2019 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-3.pdf
FIPS 140-3 IGImplementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program https://csrc.nist.gov/Projects/cryptographic-module-validation-program/fips-140- 3-ig-announcements
FIPS 180-4Secure Hash Standard (SHS) March 2012 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf
FIPS 186-4Digital Signature Standard (DSS) February 2013 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-4.pdf
FIPS 186-5Digital Signature Standard (DSS) February 2023 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-5.pdf
FIPS 197Advanced Encryption Standard November 2001 https://csrc.nist.gov/publications/fips/fips197/fips-197.pdf
FIPS 198-1The Keyed Hash Message Authentication Code (HMAC) July 2008 https://csrc.nist.gov/publications/fips/fips198-1/FIPS-198-1_final.pdf
PKCS#1Public Key Cryptography Standards (PKCS) #1: RSA Cryptography Specifications Version 2.1 February 2003 http://www.ietf.org/rfc/rfc3447.txt
RFC 3526More Modular Exponential (MODP) Diffie-Hellman groups for Internet Key Exchange (IKE) May 2003 https://www.ietf.org/rfc/rfc3526.txt
SP 800-38ARecommendation for Block Cipher Modes of Operation Methods and Techniques December 2001 https://csrc.nist.gov/publications/nistpubs/800-38a/sp800-38a.pdf
SP 800-38ARecommendation for Block Cipher Modes of Operation: Three Variants of
AddendumCiphertext Stealing for CBC Mode October 2010 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38a- add.pdf
SP 800-38CRecommendation for Block Cipher Modes of Operation: the CCM Mode for Authentication and Confidentiality May 2004 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38c.pdf © 2024 Canonical Ltd./ atsec information security. 39 of 40
Page 40
SP 800-38DRecommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC November 2007 https://csrc.nist.gov/publications/nistpubs/800-38D/SP-800-38D.pdf
SP 800-38FRecommendation for Block Cipher Modes of Operation: Methods for Key Wrapping December 2012 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38F.pdf
SP 800-56Ar3Recommendation for Pair-Wise Key Establishment Schemes Using Discrete Logarithm Cryptography April 2018 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Ar3.pdf
SP 800-90Ar1Recommendation for Random Number Generation Using Deterministic Random Bit Generators June 2015 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90Ar1.pdf
SP 800-90BRecommendation for the Entropy Sources Used for Random Bit Generation January 2018 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90B.pdf
SP 800-133r2Recommendation for Cryptographic Key Generation June 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-133r2.pdf
SP 800-135r1Recommendation for Existing Application-Specific Key Derivation Functions December 2011 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-135r1.pdf
SP 800-140BCMVP Security Policy Requirements March 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-140B.pdf © 2024 Canonical Ltd./ atsec information security. 40 of 40