| Standard | FIPS 140-3 |
|---|---|
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Status | Active |
| Sunset date | 3/27/2030 |
| Caveat | When operated in approved mode. When installed, initialized and configured as specified in Section 11.1 of the Security Policy. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs. |
| Vendor | Oracle Corporation |
flowchart LR
%% Deterministic review-risk graph for Oracle Linux 9 libgcrypt Cryptographic Module
%% Review prompts and evidence gaps, NOT vulnerability findings.
subgraph CMVP["CMVP-disclosed clues"]
C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Recovery<br/>Update</i>"]
C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Status Output</i>"]
C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>HTTPS<br/>no library/version identified</i>"]
C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i>"]
end
subgraph Inference["Derived inference"]
I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
end
subgraph Risk["Reviewer question"]
R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
end
subgraph Evidence["Evidence needed to close"]
E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
end
C2 --> I2 --> R2 --> E2
C3 --> I3 --> R3 --> E3
C5 --> I5 --> R5 --> E5
C6 --> I6 --> R6 --> E6
classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
class C2,C3,C5,C6 clue;
class I2,I3,I5,I6 infer;
class R2,R3,R5,R6 risk;
class E2,E3,E5,E6 evidence;flowchart LR
%% Deterministic clue tier for Oracle Linux 9 libgcrypt Cryptographic Module
%% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
subgraph CMVP["CMVP-disclosed clues (deterministic)"]
C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Recovery<br/>Update</i><br/>src: text:keyword"]
C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Status Output</i><br/>src: text:keyword"]
C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>HTTPS<br/>no library/version identified</i><br/>src: text:keyword"]
C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i><br/>src: text:keyword"]
end
classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
class C2,C3,C5,C6 clueLow;Oracle Corporation Oracle Linux 9 libgcrypt Cryptographic Module Software Version: 1.10.0-3957adb8de08b15a Prepared by: atsec information security corporation
4516 Seton Center Parkway, Suite 250
Austin, TX 78759 www.atsec.com Document Version 1.4. ©Oracle Corporation
Title: Oracle Linux 9 libgcrypt Cryptographic Module Security Policy Date: October 1st, 2025 Contributing Authors: Oracle Linux Engineering Security Evaluations – Global Product Security atsec information security Oracle Corporation World Headquarters
Austin, TX 78741 U.S.A. Worldwide Inquiries: Phone: +1.650.506.7000 Fax: +1.650.506.7200 www.oracle.com hereof are subject to change without notice. This document is not warranted to be error-free, nor subject to any other warranties or conditions, whether expressed orally or implied in law, including implied warranties and conditions of merchantability or fitness for a particular purpose. Oracle specifically disclaim any liability with respect to this document and no contractual obligations are formed either Oracle and Java are registered trademarks of Oracle and/or its affiliates. Other names may be trademarks of their respective owners. Oracle Linux 9 libgcrypt Cryptographic Module Security Policy i
| # | Section | Page |
|---|
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy iii
| Item | Page |
|---|---|
| Table 1: Security Levels | 1 |
| Table 2: Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets) | 3 |
| Table 3: Tested Operational Environments - Software, Firmware, Hybrid | 3 |
| Table 4: Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid | 4 |
| Table 5: Modes List and Description | 4 |
| Table 6: Approved Algorithms | 19 |
| Table 7: Vendor-Affirmed Algorithms | 20 |
| Table 8: Non-Approved, Not Allowed Algorithms | 20 |
| Table 9: Security Function Implementations | 25 |
| Table 10: Entropy Certificates | 25 |
| Table 11: Ports and Interfaces | 27 |
| Table 12: Roles | 28 |
| Table 13: Approved Services | 31 |
| Table 14: Non-Approved Services | 32 |
| Table 15: Storage Areas | 38 |
| Table 16: SSP Input-Output Methods | 38 |
| Table 17: SSP Zeroization Methods | 39 |
| Table 18: SSP Table 1 | 40 |
| Table 19: SSP Table 2 | 42 |
| Table 20: Pre-Operational Self-Tests | 43 |
| Table 21: Conditional Self-Tests | 61 |
| Table 22: Pre-Operational Periodic Information | 61 |
| Table 23: Conditional Periodic Information | 65 |
| Table 24: Error States | 65 |
| Item | Page |
|---|---|
| Figure 1: Block Diagram | 2 |
| Section | Title | Security Level |
|---|---|---|
| 1 | General | 1 |
| 2 | Cryptographic module specification | 1 |
| 3 | Cryptographic module interfaces | 1 |
| 4 | Roles, services, and authentication | 1 |
| 5 | Software/Firmware security | 1 |
| 6 | Operational environment | 1 |
| 7 | Physical security | N/A |
| 8 | Non-invasive security | N/A |
| 9 | Sensitive security parameter management | 1 |
| 10 | Self-tests | 1 |
| 11 | Life-cycle assurance | 1 |
| 12 | Mitigation of other attacks | 1 |
| Overall Level | 1 |
This document is the non-proprietary FIPS 140-3 Security Policy for version 1.10.0-3957adb8de08b15a of the Oracle Linux 9 libgcrypt Cryptographic Module. It contains the security rules under which the module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for an overall Security Level 1 including this notice. Other documentation is proprietary to their authors.
In preparing the Security Policy document, the laboratory formatted the vendor-supplied documentation for consolidation without altering the technical statements therein contained. The further refining of the Security Policy document was conducted iteratively throughout the conformance testing, wherein the Security Policy was submitted to the vendor, who would then edit, modify, and add technical contents. The vendor would also supply additional documentation, which the laboratory formatted into the existing Security Policy, and resubmitted to the vendor for their final editing.
Table 1: Security Levels Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
Purpose and Use: The Oracle Linux 9 libgcrypt Cryptographic Module (hereafter referred to as “the module”) is a Software multi-chip standalone cryptographic module. The module is a software library implementing general purpose cryptographic algorithms. The module provides cryptographic services to applications running in the user space of the underlying operating system through an application program interface (API). Module Type: Software Module Embodiment: MultiChipStand Cryptographic Boundary: Figure 1 shows the cryptographic boundary of the module in orange, its interfaces with the operational environment and the flow of information between the module and operator (depicted through the arrows). The software component of the cryptographic module is listed in the Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets) table. Tested Operational Environment’s Physical Perimeter (TOEPP): The TOEPP of the module is defined as the general-purpose computer on which the module is installed. Figure 1: Block Diagram Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Package or File Name | Software/ Firmware Version | Features | Integrity Test |
|---|---|---|---|
| libgcrypt.so.20.4.0 on Oracle Linux 9 with Intel(R) Xeon(R) Platinum 8358 | 1.10.0- 3957adb8de08b15a | N/A | HMAC-SHA-256 |
| libgcrypt.so.20.4.0 on Oracle Linux 9 with AMD EPYC 7J13 | 1.10.0- 3957adb8de08b15a | N/A | HMAC-SHA-256 |
| libgcrypt.so.20.4.0 on Oracle Linux 9 with Ampere(R) Altra(R) Q80- 30 | 1.10.0- 3957adb8de08b15a | N/A | HMAC-SHA-256 |
| libgcrypt.so.20.4.0 on Oracle Linux 9 with OCTEON III | 1.10.0- 3957adb8de08b15a | N/A | HMAC-SHA-256 |
| Operating System | Hardware Platform | Processors | PAA/PAI | Hypervisor or Host OS | Version(s) |
|---|---|---|---|---|---|
| Oracle Linux 9 | ORACLE SERVER X9- 2c | Intel(R) Xeon(R) Platinum 8358 | Yes | KVM on Oracle Linux 8 | 1.10.0- 3957adb8de08b15a |
| Oracle Linux 9 | ORACLE SERVER E4- 2c | AMD EPYC 7J13 | Yes | KVM on Oracle Linux 8 | 1.10.0- 3957adb8de08b15a |
| Oracle Linux 9 | ORACLE SERVER A1- 2c | Ampere(R) Altra(R) Q80-30 | Yes | KVM on Oracle Linux 8 | 1.10.0- 3957adb8de08b15a |
| Oracle Linux 9 | ORACLE SERVER X9- 2c | Intel(R) Xeon(R) Platinum 8358 | No | KVM on Oracle Linux 8 | 1.10.0- 3957adb8de08b15a |
| Oracle Linux 9 | ORACLE SERVER E4- 2c | AMD EPYC 7J13 | No | KVM on Oracle Linux 8 | 1.10.0- 3957adb8de08b15a |
| Oracle Linux 9 | ORACLE SERVER A1- 2c | Ampere(R) Altra(R) Q80-30 | No | KVM on Oracle Linux 8 | 1.10.0- 3957adb8de08b15a |
| Oracle Linux 9 | Marvell Liquid IO II (MIPS64) SmartNIC | OCTEON III | No | N/A | 1.10.0- 3957adb8de08b15a |
| Operating System | Hardware Platform |
|---|---|
| Oracle Linux 9 | Oracle X Series Servers |
| Oracle Linux 9 | Oracle E Series Servers |
| Oracle Linux 9 | Oracle A Series Servers |
| Oracle Linux 9 | Marvell T93 LiquidIO III (ARM v8.x) SmartNIC |
| Oracle Linux 9 | Pensando DSC-200-R (ARM v8.x) SmartNIC |
Tested Module Identification
| Operating System | Hardware Platform | |
|---|---|---|
| Oracle Linux 9 | Nvidia Bluefield-3 (ARM v8.x) SmartNIC |
| Mode Name | Description | Type | Status Indicator |
|---|---|---|---|
| Approved mode | Automatically entered whenever an approved service is requested | Approved | Equivalent to the indicator of the requested service as defined in section 4.3 |
| Non-approved mode | Automatically entered whenever a non-approved service is requested | Non- Approved | Equivalent to the indicator of the requested service as defined in section 4.4 |
| Algorithm | CAVP Cert | Properties | Reference |
|---|---|---|---|
| AES-CBC | A4773 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38A |
| AES-CBC | A4774 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38A |
| AES-CBC | A4776 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38A |
| AES-CBC | A4777 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38A |
Table 4: Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid CMVP makes no statement as to the correct operation of the module or the security strengths of the generated keys when so ported if the specific operational environment is not listed on the validation certificate.
There are no components within the cryptographic boundary excluded from the FIPS 140-3 requirements.
Modes List and Description: 4.3 4.4 Table 5: Modes List and Description Mode Change Instructions and Status: After passing all pre-operational self-test and cryptographic algorithm self-tests (CASTs) executed on start-up, the module automatically transitions to the approved mode. No operator intervention is required to reach this point. The module automatically switches between the approved and nonapproved modes.
Approved Algorithms: Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Algorithm | CAVP Cert | Properties | Reference |
|---|---|---|---|
| AES-CCM | A4773 | Key Length - 128, 192, 256 Tag Length - 112, 128, 32, 48, 64, 80, 96 IV Length - IV Length: 56, 64, 72, 80, 88, 96, 104 Payload Length - Payload Length: 0-256 Increment 8 AAD Length - AAD Length: 0, 256, 65536 | SP 800-38C |
| AES-CCM | A4774 | Key Length - 128, 192, 256 Tag Length - 112, 128, 32, 48, 64, 80, 96 IV Length - IV Length: 56, 64, 72, 80, 88, 96, 104 Payload Length - Payload Length: 0-256 Increment 8 AAD Length - AAD Length: 0-524288 Increment 8, AAD Length: 0, 256, 65536 | SP 800-38C |
| AES-CCM | A4776 | Key Length - 128, 192, 256 Tag Length - 112, 128, 32, 48, 64, 80, 96 IV Length - IV Length: 56, 64, 72, 80, 88, 96, 104 Payload Length - Payload Length: 0-256 Increment 8 AAD Length - AAD Length: 0, 256, 65536 | SP 800-38C |
| AES-CCM | A4777 | Key Length - 128, 192, 256 Tag Length - 112, 128, 32, 48, 64, 80, 96 IV Length - IV Length: 56, 64, 72, 80, 88, 96, 104 Payload Length - Payload Length: 0-256 Increment 8 AAD Length - AAD Length: 0, 256, 65536 | SP 800-38C |
| AES-CFB128 | A4773 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38A |
| AES-CFB128 | A4774 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38A |
| AES-CFB128 | A4776 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38A |
| AES-CFB128 | A4777 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38A |
| AES-CFB8 | A4773 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38A |
| AES-CFB8 | A4774 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38A |
| AES-CFB8 | A4776 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38A |
| AES-CFB8 | A4777 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38A |
| AES-CMAC | A4773 | Direction - Generation, Verification Key Length - 128, 192, 256 MAC Length - MAC Length: 128 Message Length - Message Length: 8-524288 Increment 8 | SP 800-38B |
| AES-CMAC | A4774 | Direction - Generation, Verification Key Length - 128, 192, 256 MAC Length - MAC Length: 128 Message Length - Message Length: 8-524288 Increment 8 | SP 800-38B |
| AES-CMAC | A4776 | Direction - Generation, Verification Key Length - 128, 192, 256 MAC Length - MAC Length: 128 Message Length - Message Length: 8-524288 Increment 8 | SP 800-38B |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Algorithm | CAVP Cert | Properties | Reference |
|---|---|---|---|
| AES-CMAC | A4777 | Direction - Generation, Verification Key Length - 128, 192, 256 MAC Length - MAC Length: 128 Message Length - Message Length: 8-524288 Increment 8 | SP 800-38B |
| AES-CTR | A4773 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 Payload Length - Payload Length: 8-128 Increment 8 Supports Counter larger than maximum value - No Incremental Counter - Yes Counter Tests Performed - Yes | SP 800-38A |
| AES-CTR | A4774 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 Payload Length - Payload Length: 8-128 Increment 8 Supports Counter larger than maximum value - No Incremental Counter - Yes Counter Tests Performed - Yes | SP 800-38A |
| AES-CTR | A4776 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 Payload Length - Payload Length: 8-128 Increment 8 Supports Counter larger than maximum value - No Incremental Counter - Yes Counter Tests Performed - Yes | SP 800-38A |
| AES-CTR | A4777 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 Payload Length - Payload Length: 8-128 Increment 8 Supports Counter larger than maximum value - No Incremental Counter - Yes Counter Tests Performed - Yes | SP 800-38A |
| AES-ECB | A4773 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38A |
| AES-ECB | A4774 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38A |
| AES-ECB | A4776 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38A |
| AES-ECB | A4777 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38A |
| AES-KW | A4773 | Direction - Decrypt, Encrypt Cipher - Cipher Key Length - 128, 192, 256 Payload Length - Payload Length: 128-4096 Increment 128 | SP 800-38F |
| AES-KW | A4774 | Direction - Decrypt, Encrypt Cipher - Cipher Key Length - 128, 192, 256 Payload Length - Payload Length: 128-4096 Increment 128 | SP 800-38F |
| AES-KW | A4776 | Direction - Decrypt, Encrypt Cipher - Cipher Key Length - 128, 192, 256 Payload Length - Payload Length: 128-4096 Increment 128 | SP 800-38F |
| AES-KW | A4777 | Direction - Decrypt, Encrypt Cipher - Cipher | SP 800-38F |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Algorithm | CAVP Cert | Properties Key Length - 128, 192, 256 Payload Length - Payload Length: 128-4096 Increment 128 | Reference |
|---|---|---|---|
| AES-OFB | A4773 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38A |
| AES-OFB | A4774 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38A |
| AES-OFB | A4776 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38A |
| AES-OFB | A4777 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38A |
| AES-XTS Testing Revision 2.0 | A4773 | Direction - Decrypt, Encrypt Key Length - 128, 256 Payload Length - Payload Length: 128-65536 Increment 128 Tweak Mode - Hex Data Unit Length Matches Payload Length - Yes | SP 800-38E |
| AES-XTS Testing Revision 2.0 | A4774 | Direction - Decrypt, Encrypt Key Length - 128, 256 Payload Length - Payload Length: 128-65536 Increment 128, Payload Length: 128-65536 Increment 8 Tweak Mode - Hex Data Unit Length Matches Payload Length - Yes | SP 800-38E |
| AES-XTS Testing Revision 2.0 | A4776 | Direction - Decrypt, Encrypt Key Length - 128, 256 Payload Length - Payload Length: 128-65536 Increment 128 Tweak Mode - Hex Data Unit Length Matches Payload Length - Yes | SP 800-38E |
| AES-XTS Testing Revision 2.0 | A4777 | Direction - Decrypt, Encrypt Key Length - 128, 256 Payload Length - Payload Length: 128-65536 Increment 128 Tweak Mode - Hex Data Unit Length Matches Payload Length - Yes | SP 800-38E |
| Counter DRBG | A4773 | Prediction Resistance - No, Yes Supports Reseed - No Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - Yes Additional Input - Additional Input: 0 Entropy Input - Entropy Input: 128, Entropy Input: 192, Entropy Input: 256 Nonce - Nonce: 128, Nonce: 64 Personalization String Length - Personalization String Length: 0 Returned Bits - 1024, 512 | SP 800-90A Rev. 1 |
| Counter DRBG | A4774 | Prediction Resistance - No, Yes Supports Reseed - No Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - Yes Additional Input - Additional Input: 0 Entropy Input - Entropy Input: 128, Entropy Input: 192, Entropy Input: 256 Nonce - Nonce: 128, Nonce: 64 | SP 800-90A Rev. 1 |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Algorithm | CAVP Cert | Properties Personalization String Length - Personalization String Length: 0 Returned Bits - 1024, 512 | Reference |
|---|---|---|---|
| Counter DRBG | A4776 | Prediction Resistance - No, Yes Supports Reseed - No Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - Yes Additional Input - Additional Input: 0 Entropy Input - Entropy Input: 128, Entropy Input: 192, Entropy Input: 256 Nonce - Nonce: 128, Nonce: 64 Personalization String Length - Personalization String Length: 0 Returned Bits - 1024, 512 | SP 800-90A Rev. 1 |
| Counter DRBG | A4777 | Prediction Resistance - No, Yes Supports Reseed - No Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - Yes Additional Input - Additional Input: 0 Entropy Input - Entropy Input: 128, Entropy Input: 192, Entropy Input: 256 Nonce - Nonce: 128, Nonce: 64 Personalization String Length - Personalization String Length: 0 Returned Bits - 1024, 512 | SP 800-90A Rev. 1 |
| ECDSA KeyGen (FIPS186-4) | A4773 | Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - Testing Candidates | FIPS 186-4 |
| ECDSA KeyGen (FIPS186-4) | A4774 | Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - Testing Candidates | FIPS 186-4 |
| ECDSA KeyGen (FIPS186-4) | A4776 | Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - Testing Candidates | FIPS 186-4 |
| ECDSA KeyGen (FIPS186-4) | A4777 | Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - Testing Candidates | FIPS 186-4 |
| ECDSA KeyGen (FIPS186-4) | A4778 | Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - Testing Candidates | FIPS 186-4 |
| ECDSA KeyVer (FIPS186-4) | A4773 | Curve - P-224, P-256, P-384, P-521 | FIPS 186-4 |
| ECDSA KeyVer (FIPS186-4) | A4774 | Curve - P-224, P-256, P-384, P-521 | FIPS 186-4 |
| ECDSA KeyVer (FIPS186-4) | A4776 | Curve - P-224, P-256, P-384, P-521 | FIPS 186-4 |
| ECDSA KeyVer (FIPS186-4) | A4777 | Curve - P-224, P-256, P-384, P-521 | FIPS 186-4 |
| ECDSA KeyVer (FIPS186-4) | A4778 | Curve - P-224, P-256, P-384, P-521 | FIPS 186-4 |
| ECDSA SigGen (FIPS186-4) | A4773 | Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512 | FIPS 186-4 |
| ECDSA SigGen (FIPS186-4) | A4774 | Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, | FIPS 186-4 |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Algorithm | CAVP Cert | Properties SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512 | Reference |
|---|---|---|---|
| ECDSA SigGen (FIPS186-4) | A4776 | Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512 | FIPS 186-4 |
| ECDSA SigGen (FIPS186-4) | A4777 | Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512 | FIPS 186-4 |
| ECDSA SigGen (FIPS186-4) | A4778 | Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512 | FIPS 186-4 |
| ECDSA SigVer (FIPS186-4) | A4773 | Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512 | FIPS 186-4 |
| ECDSA SigVer (FIPS186-4) | A4774 | Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512 | FIPS 186-4 |
| ECDSA SigVer (FIPS186-4) | A4776 | Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512 | FIPS 186-4 |
| ECDSA SigVer (FIPS186-4) | A4777 | Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512 | FIPS 186-4 |
| ECDSA SigVer (FIPS186-4) | A4778 | Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512 | FIPS 186-4 |
| Hash DRBG | A4773 | Prediction Resistance - No, Yes Supports Reseed - No Mode - SHA-1, SHA2-256, SHA2-512 Entropy Input - Entropy Input: 160, Entropy Input: 256 Nonce - Nonce: 160, Nonce: 256 Personalization String Length - Personalization String Length: 0, 160, Personalization String Length: 0, 256 Additional Input - Additional Input: 0, 160, Additional Input: 0, | SP 800-90A Rev. 1 |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Algorithm | CAVP Cert | Properties 256 Returned Bits - 320, 512, 768 | Reference |
|---|---|---|---|
| Hash DRBG | A4774 | Prediction Resistance - No, Yes Supports Reseed - No Mode - SHA-1, SHA2-256, SHA2-512 Entropy Input - Entropy Input: 160, Entropy Input: 256 Nonce - Nonce: 160, Nonce: 256 Personalization String Length - Personalization String Length: 0, 160, Personalization String Length: 0, 256 Additional Input - Additional Input: 0, 160, Additional Input: 0, 256 Returned Bits - 320, 512, 768 | SP 800-90A Rev. 1 |
| Hash DRBG | A4776 | Prediction Resistance - No, Yes Supports Reseed - No Mode - SHA-1, SHA2-256, SHA2-512 Entropy Input - Entropy Input: 160, Entropy Input: 256 Nonce - Nonce: 160, Nonce: 256 Personalization String Length - Personalization String Length: 0, 160, Personalization String Length: 0, 256 Additional Input - Additional Input: 0, 160, Additional Input: 0, 256 Returned Bits - 320, 512, 768 | SP 800-90A Rev. 1 |
| Hash DRBG | A4777 | Prediction Resistance - No, Yes Supports Reseed - No Mode - SHA-1, SHA2-256, SHA2-512 Entropy Input - Entropy Input: 160, Entropy Input: 256 Nonce - Nonce: 160, Nonce: 256 Personalization String Length - Personalization String Length: 0, 160, Personalization String Length: 0, 256 Additional Input - Additional Input: 0, 160, Additional Input: 0, 256 Returned Bits - 320, 512, 768 | SP 800-90A Rev. 1 |
| Hash DRBG | A4778 | Prediction Resistance - No, Yes Supports Reseed - No Mode - SHA-1, SHA2-256, SHA2-512 Entropy Input - Entropy Input: 160, Entropy Input: 256 Nonce - Nonce: 160, Nonce: 256 Personalization String Length - Personalization String Length: 0, 160, Personalization String Length: 0, 256 Additional Input - Additional Input: 0, 160, Additional Input: 0, 256 Returned Bits - 320, 512, 768 | SP 800-90A Rev. 1 |
| HMAC DRBG | A4773 | Prediction Resistance - No, Yes Supports Reseed - No Mode - SHA-1, SHA2-256, SHA2-512 Entropy Input - Entropy Input: 160, Entropy Input: 256 Nonce - Nonce: 160, Nonce: 256 Personalization String Length - Personalization String Length: 0, 160, Personalization String Length: 0, 256 Additional Input - Additional Input: 0, 160, Additional Input: 0, | SP 800-90A Rev. 1 |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Algorithm | CAVP Cert | Properties 256 Returned Bits - 320, 512, 768 | Reference |
|---|---|---|---|
| HMAC DRBG | A4774 | Prediction Resistance - No, Yes Supports Reseed - No Mode - SHA-1, SHA2-256, SHA2-512 Entropy Input - Entropy Input: 160, Entropy Input: 256 Nonce - Nonce: 160, Nonce: 256 Personalization String Length - Personalization String Length: 0, 160, Personalization String Length: 0, 256 Additional Input - Additional Input: 0, 160, Additional Input: 0, 256 Returned Bits - 320, 512, 768 | SP 800-90A Rev. 1 |
| HMAC DRBG | A4776 | Prediction Resistance - No, Yes Supports Reseed - No Mode - SHA-1, SHA2-256, SHA2-512 Entropy Input - Entropy Input: 160, Entropy Input: 256 Nonce - Nonce: 160, Nonce: 256 Personalization String Length - Personalization String Length: 0, 160, Personalization String Length: 0, 256 Additional Input - Additional Input: 0, 160, Additional Input: 0, 256 Returned Bits - 320, 512, 768 | SP 800-90A Rev. 1 |
| HMAC DRBG | A4777 | Prediction Resistance - No, Yes Supports Reseed - No Mode - SHA-1, SHA2-256, SHA2-512 Entropy Input - Entropy Input: 160, Entropy Input: 256 Nonce - Nonce: 160, Nonce: 256 Personalization String Length - Personalization String Length: 0, 160, Personalization String Length: 0, 256 Additional Input - Additional Input: 0, 160, Additional Input: 0, 256 Returned Bits - 320, 512, 768 | SP 800-90A Rev. 1 |
| HMAC DRBG | A4778 | Prediction Resistance - No, Yes Supports Reseed - No Mode - SHA-1, SHA2-256, SHA2-512 Entropy Input - Entropy Input: 160, Entropy Input: 256 Nonce - Nonce: 160, Nonce: 256 Personalization String Length - Personalization String Length: 0, 160, Personalization String Length: 0, 256 Additional Input - Additional Input: 0, 160, Additional Input: 0, 256 Returned Bits - 320, 512, 768 | SP 800-90A Rev. 1 |
| HMAC-SHA-1 | A4772 | MAC - MAC: 160 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA-1 | A4773 | MAC - MAC: 160 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA-1 | A4774 | MAC - MAC: 160 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA-1 | A4775 | MAC - MAC: 160 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Algorithm | CAVP Cert | Properties | Reference |
|---|---|---|---|
| HMAC-SHA-1 | A4776 | MAC - MAC: 160 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA-1 | A4777 | MAC - MAC: 160 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA-1 | A4778 | MAC - MAC: 160 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA2-224 | A4773 | MAC - MAC: 224 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA2-224 | A4774 | MAC - MAC: 224 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA2-224 | A4776 | MAC - MAC: 224 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA2-224 | A4777 | MAC - MAC: 224 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA2-224 | A4778 | MAC - MAC: 224 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA2-256 | A4773 | MAC - MAC: 256 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA2-256 | A4774 | MAC - MAC: 256 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA2-256 | A4776 | MAC - MAC: 256 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA2-256 | A4777 | MAC - MAC: 256 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA2-256 | A4778 | MAC - MAC: 256 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA2-384 | A4773 | MAC - MAC: 384 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA2-384 | A4774 | MAC - MAC: 384 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA2-384 | A4776 | MAC - MAC: 384 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA2-384 | A4777 | MAC - MAC: 384 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA2-384 | A4778 | MAC - MAC: 384 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA2-512 | A4773 | MAC - MAC: 512 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA2-512 | A4774 | MAC - MAC: 512 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA2-512 | A4776 | MAC - MAC: 512 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA2-512 | A4777 | MAC - MAC: 512 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA2-512 | A4778 | MAC - MAC: 512 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA2- 512/224 | A4773 | MAC - MAC: 224 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Algorithm | CAVP Cert | Properties | Reference |
|---|---|---|---|
| HMAC-SHA2- 512/224 | A4774 | MAC - MAC: 224 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA2- 512/224 | A4776 | MAC - MAC: 224 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA2- 512/224 | A4777 | MAC - MAC: 224 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA2- 512/224 | A4778 | MAC - MAC: 224 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA2- 512/256 | A4773 | MAC - MAC: 256 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA2- 512/256 | A4774 | MAC - MAC: 256 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA2- 512/256 | A4776 | MAC - MAC: 256 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA2- 512/256 | A4777 | MAC - MAC: 256 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA2- 512/256 | A4778 | MAC - MAC: 256 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA3-224 | A4773 | MAC - MAC: 224 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA3-224 | A4774 | MAC - MAC: 224 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA3-224 | A4778 | MAC - MAC: 224 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA3-256 | A4773 | MAC - MAC: 256 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA3-256 | A4774 | MAC - MAC: 256 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA3-256 | A4778 | MAC - MAC: 256 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA3-384 | A4773 | MAC - MAC: 384 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA3-384 | A4774 | MAC - MAC: 384 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA3-384 | A4778 | MAC - MAC: 384 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA3-512 | A4773 | MAC - MAC: 512 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA3-512 | A4774 | MAC - MAC: 512 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA3-512 | A4778 | MAC - MAC: 512 Key Length - Key Length: 112-524288 Increment 8 | FIPS 198-1 |
| PBKDF | A4773 | Iteration Count - Iteration Count: 1000-10000000 Increment 1 HMAC Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512 Password Length - Password Length: 8-128 Increment 1 Salt Length - Salt Length: 128-4096 Increment 8 Key Data Length - Key Data Length: 128-4096 Increment 8 | SP 800-132 |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Algorithm | CAVP Cert | Properties | Reference |
|---|---|---|---|
| PBKDF | A4774 | Iteration Count - Iteration Count: 1000-10000000 Increment 1 HMAC Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512 Password Length - Password Length: 8-128 Increment 1 Salt Length - Salt Length: 128-4096 Increment 8 Key Data Length - Key Data Length: 128-4096 Increment 8 | SP 800-132 |
| PBKDF | A4776 | Iteration Count - Iteration Count: 1000-10000000 Increment 1 HMAC Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512 Password Length - Password Length: 8-128 Increment 1 Salt Length - Salt Length: 128-4096 Increment 8 Key Data Length - Key Data Length: 128-4096 Increment 8 | SP 800-132 |
| PBKDF | A4777 | Iteration Count - Iteration Count: 1000-10000000 Increment 1 HMAC Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512 Password Length - Password Length: 8-128 Increment 1 Salt Length - Salt Length: 128-4096 Increment 8 Key Data Length - Key Data Length: 128-4096 Increment 8 | SP 800-132 |
| PBKDF | A4778 | Iteration Count - Iteration Count: 1000-10000000 Increment 1 HMAC Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512 Password Length - Password Length: 8-128 Increment 1 Salt Length - Salt Length: 128-4096 Increment 8 Key Data Length - Key Data Length: 128-4096 Increment 8 | SP 800-132 |
| RSA KeyGen (FIPS186-4) | A4773 | Key Generation Mode - B.3.3 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Info Generated By Server - No Public Exponent Mode - Random Private Key Format - Standard | FIPS 186-4 |
| RSA KeyGen (FIPS186-4) | A4774 | Key Generation Mode - B.3.3 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Info Generated By Server - No Public Exponent Mode - Random Private Key Format - Standard | FIPS 186-4 |
| RSA KeyGen (FIPS186-4) | A4776 | Key Generation Mode - B.3.3 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Info Generated By Server - No Public Exponent Mode - Random Private Key Format - Standard | FIPS 186-4 |
| RSA KeyGen (FIPS186-4) | A4777 | Key Generation Mode - B.3.3 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Info Generated By Server - No | FIPS 186-4 |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Algorithm | CAVP Cert | Properties Public Exponent Mode - Random Private Key Format - Standard | Reference |
|---|---|---|---|
| RSA KeyGen (FIPS186-4) | A4778 | Key Generation Mode - B.3.3 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Info Generated By Server - No Public Exponent Mode - Random Private Key Format - Standard | FIPS 186-4 |
| RSA SigGen (FIPS186-4) | A4773 | Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096 Hash Pair - Hash Algorithm - SHA2-224 | FIPS 186-4 |
| RSA SigGen (FIPS186-4) | A4774 | Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096 Hash Pair - Hash Algorithm - SHA2-224 | FIPS 186-4 |
| RSA SigGen (FIPS186-4) | A4776 | Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096 Hash Pair - Hash Algorithm - SHA2-224 | FIPS 186-4 |
| RSA SigGen (FIPS186-4) | A4777 | Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096 Hash Pair - Hash Algorithm - SHA2-224 | FIPS 186-4 |
| RSA SigGen (FIPS186-4) | A4778 | Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096 Hash Pair - Hash Algorithm - SHA2-224 | FIPS 186-4 |
| RSA SigVer (FIPS186-2) | A4773 | Public Exponent Mode - Fixed Fixed Public Exponent - 010001 Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024, 1536 Hash Pair - Hash Algorithm - SHA2-224 Salt Length - 28 | FIPS 186-4 |
| RSA SigVer (FIPS186-2) | A4774 | Public Exponent Mode - Fixed Fixed Public Exponent - 010001 Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024, 1536 Hash Pair - Hash Algorithm - SHA2-224 Salt Length - 28 | FIPS 186-4 |
| RSA SigVer (FIPS186-2) | A4776 | Public Exponent Mode - Fixed Fixed Public Exponent - 010001 Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024, 1536 Hash Pair - Hash Algorithm - SHA2-224 Salt Length - 28 | FIPS 186-4 |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Algorithm | CAVP Cert | Properties | Reference |
|---|---|---|---|
| RSA SigVer (FIPS186-2) | A4777 | Public Exponent Mode - Fixed Fixed Public Exponent - 010001 Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024, 1536 Hash Pair - Hash Algorithm - SHA2-224 Salt Length - 28 | FIPS 186-4 |
| RSA SigVer (FIPS186-2) | A4778 | Public Exponent Mode - Fixed Fixed Public Exponent - 010001 Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024, 1536 Hash Pair - Hash Algorithm - SHA2-224 Salt Length - 28 | FIPS 186-4 |
| RSA SigVer (FIPS186-4) | A4773 | Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096 Hash Pair - Hash Algorithm - SHA2-224 Salt Length - 28 Public Exponent Mode - Fixed Fixed Public Exponent - 010001 | FIPS 186-4 |
| RSA SigVer (FIPS186-4) | A4774 | Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096 Hash Pair - Hash Algorithm - SHA2-224 Salt Length - 28 Public Exponent Mode - Fixed Fixed Public Exponent - 010001 | FIPS 186-4 |
| RSA SigVer (FIPS186-4) | A4776 | Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096 Hash Pair - Hash Algorithm - SHA2-224 Salt Length - 28 Public Exponent Mode - Fixed Fixed Public Exponent - 010001 | FIPS 186-4 |
| RSA SigVer (FIPS186-4) | A4777 | Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096 Hash Pair - Hash Algorithm - SHA2-224 Salt Length - 28 Public Exponent Mode - Fixed Fixed Public Exponent - 010001 | FIPS 186-4 |
| RSA SigVer (FIPS186-4) | A4778 | Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096 Hash Pair - Hash Algorithm - SHA2-224 Salt Length - 28 Public Exponent Mode - Fixed Fixed Public Exponent - 010001 | FIPS 186-4 |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Algorithm | CAVP Cert | Properties | Reference |
|---|---|---|---|
| SHA-1 | A4772 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA-1 | A4773 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA-1 | A4774 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA-1 | A4775 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA-1 | A4776 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA-1 | A4777 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA-1 | A4778 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA2-224 | A4773 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA2-224 | A4774 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA2-224 | A4776 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA2-224 | A4777 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA2-224 | A4778 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA2-256 | A4773 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA2-256 | A4774 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA2-256 | A4776 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA2-256 | A4777 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA2-256 | A4778 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA2-384 | A4773 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA2-384 | A4774 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA2-384 | A4776 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA2-384 | A4777 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA2-384 | A4778 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA2-512 | A4773 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA2-512 | A4774 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Algorithm | CAVP Cert | Properties | Reference |
|---|---|---|---|
| SHA2-512 | A4776 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA2-512 | A4777 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA2-512 | A4778 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA2-512/224 | A4773 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA2-512/224 | A4774 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA2-512/224 | A4776 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA2-512/224 | A4777 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA2-512/224 | A4778 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA2-512/256 | A4773 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA2-512/256 | A4774 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA2-512/256 | A4776 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA2-512/256 | A4777 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA2-512/256 | A4778 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA3-224 | A4773 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 202 |
| SHA3-224 | A4774 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 202 |
| SHA3-224 | A4778 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 202 |
| SHA3-256 | A4773 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 202 |
| SHA3-256 | A4774 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 202 |
| SHA3-256 | A4778 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 202 |
| SHA3-384 | A4773 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 202 |
| SHA3-384 | A4774 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 202 |
| SHA3-384 | A4778 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 202 |
| SHA3-512 | A4773 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 202 |
| SHA3-512 | A4774 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 202 |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Algorithm | CAVP Cert | Properties | Reference |
|---|---|---|---|
| SHA3-512 | A4778 | Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 202 |
| SHAKE-128 | A4773 | Supports Bit-Oriented Messages - No Supports Empty Message - Yes Supports Bit-Oriented Output - No Output Length - Output Length: 16-65536 Increment 8 | FIPS 202 |
| SHAKE-128 | A4774 | Supports Bit-Oriented Messages - No Supports Empty Message - Yes Supports Bit-Oriented Output - No Output Length - Output Length: 16-65536 Increment 8 | FIPS 202 |
| SHAKE-128 | A4778 | Supports Bit-Oriented Messages - No Supports Empty Message - Yes Supports Bit-Oriented Output - No Output Length - Output Length: 16-65536 Increment 8 | FIPS 202 |
| SHAKE-256 | A4773 | Supports Bit-Oriented Messages - No Supports Empty Message - Yes Supports Bit-Oriented Output - No Output Length - Output Length: 16-65536 Increment 8 | FIPS 202 |
| SHAKE-256 | A4774 | Supports Bit-Oriented Messages - No Supports Empty Message - Yes Supports Bit-Oriented Output - No Output Length - Output Length: 16-65536 Increment 8 | FIPS 202 |
| SHAKE-256 | A4778 | Supports Bit-Oriented Messages - No Supports Empty Message - Yes Supports Bit-Oriented Output - No Output Length - Output Length: 16-65536 Increment 8 | FIPS 202 |
| Name | Properties | Implementation | Reference |
|---|---|---|---|
| CKG | RSA:2048, 3072, 4096 (112, 128, 149 bits) ECDSA:P-224, P-256, P-384, P-512 (112, 128, 192, 256 bits) | Oracle Linux 9 libgcrypt Cryptographic Module (Full Acceleration) | FIPS 186-4, SP 800- 133rev2 Section 5.1 |
| CKG | RSA:2048, 3072, 4096 (112, 128, 149 bits) ECDSA:P-224, P-256, P-384, P-512 (112, 128, 192, 256 bits) | Oracle Linux 9 libgcrypt Cryptographic Module (No Acceleration) | FIPS 186-4, SP 800- 133rev2 Section 5.1 |
| CKG | RSA:2048, 3072, 4096 (112, 128, 149 bits) ECDSA:P-224, P-256, P-384. P-521 (112, 128, 192, 256 bits) | Oracle Linux 9 libgcrypt Cryptographic Module (AESNI AVX) | FIPS 186-4, SP 800- 133rev2 Section 5.1 |
| CKG | RSA:2048, 3072, 4096 (112, 128, 149 bits) ECDSA:P-224, P-256, P-384, P-521 (112, 128, 192, 256 bits) | Oracle Linux 9 libgcrypt Cryptographic Module (SHLD) | FIPS 186-4, SP 800- 133rev2 Section 5.1 |
| CKG | RSA:2048, 3072, 4096 (112, 128, 149 bits) | Oracle Linux 9 libgcrypt Cryptographic Module (SSSE3) | FIPS 186-4, SP 800- 133rev2 Section 5.1 |
Table 6: Approved Algorithms Vendor-Affirmed Algorithms:
| Name | Properties | Implementation | Reference | |
|---|---|---|---|---|
| ECDSA:P-224, P-256, P-384, P-521 (112, 128, 192, 256 bits) |
| Name | Use and Function |
|---|---|
| MD5 | Message digest |
| ECDH noncompliant with SP 800-56Arev3 assurances | Shared secret computation |
| AES GCM noncompliant with IG C.H. | Authenticated symmetric encryption, Authenticated symmetric decryption |
| AES GCM-SIV | Authenticated symmetric encryption, Authenticated symmetric decryption |
| AES OCB | Authenticated symmetric encryption, Authenticated symmetric decryption |
| AES-EAX | Authenticated symmetric encryption, Authenticated symmetric decryption |
| RSA | Signature generation primitive; Signature verification primitive; Encryption primitive; Decryption primitive |
| RSA with non-approved flags that are not listed in Appendix A | Key generation; Signature generation; Signature verification |
| ECDSA | Signature generation primitives, Signature verification primitives |
| ECDSA with non-approved flags that are not listed in Appendix A | Key generation; Key verification; Signature generation; Signature verification |
| Name | Type | Description | Properties | Algorithms |
|---|---|---|---|---|
| Key wrapping using AES CCM | KTS-Wrap | Key wrapping using AES CCM | Key:128, 192, 256-bit keys with 128, 192, 256 bits of key strength, respectively | AES-CCM: (A4773, A4774, A4776, A4777) |
| Key unwrapping using AES CCM | KTS-Wrap | Key unwrapping using AES CCM | Key:128, 192, 256-bit keys with 128, 192, 256 bits of key strength, respectively | AES-CCM: (A4773, A4774, A4776, A4777) |
| Key wrapping using AES KW | KTS-Wrap | Key wrapping using AES KW | Key:128, 192, 256-bit keys with 128, 192, 256 bits of key strength, respectively | AES-KW: (A4773, A4774, A4776, A4777) |
| Key unwrapping using AES KW | KTS-Wrap | Key unwrapping using AES KW | Key:128, 192, 256-bit keys with 128, 192, 256 bits of key strength, respectively | AES-KW: (A4773, A4774, A4776, A4777) |
| Encryption with AES | BC-UnAuth | Encryption using AES | Keys:128, 192, 256-bit keys with 128, 192, 256 bits of key strength, respectively | AES-CBC: (A4773, A4774, A4776, A4777) AES-CFB128: (A4773, A4774, |
Table 7: Vendor-Affirmed Algorithms
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Name | Type | Description | Properties | Algorithms |
|---|---|---|---|---|
| A4776, A4777) AES-CFB8: (A4773, A4774, A4776, A4777) AES-CTR: (A4773, A4774, A4776, A4777) AES-ECB: (A4773, A4774, A4776, A4777) AES-OFB: (A4773, A4774, A4776, A4777) AES-XTS Testing Revision 2.0: (A4773, A4774, A4776, A4777) | ||||
| Authenticated encryption with AES | BC-Auth | Authenticated encryption using AES | Keys:128, 192, 256-bit keys with 128, 192, 256 bits of key strength, respectively | AES-CCM: (A4773, A4774, A4776, A4777) AES-KW: (A4773, A4774, A4776, A4777) |
| Decryption with AES | BC-UnAuth | Decryption using AES | Keys:128, 192, 256-bit keys with 128, 192, 256 bits of key strength, respectively | AES-CBC: (A4773, A4774, A4776, A4777) AES-CFB128: (A4773, A4774, A4776, A4777) AES-CFB8: (A4773, A4774, A4776, A4777) AES-CTR: (A4773, A4774, A4776, A4777) AES-ECB: (A4773, A4774, A4776, A4777) AES-OFB: (A4773, A4774, A4776, A4777) AES-XTS Testing Revision 2.0: (A4773, A4774, A4776, A4777) |
| Authenticated decryption with AES | BC-Auth | Authenticated decryption using AES | Keys:128, 192, 256-bit keys with 128, 192, 256 bits of key strength, respectively | AES-CCM: (A4773, A4774, A4776, A4777) AES-KW: (A4773, A4774, A4776, A4777) |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Name | Type | Description | Properties | Algorithms |
|---|---|---|---|---|
| Key Pair Generation with RSA | CKG | Key pair generation for RSA | Mode:B.3.3 Random Probable Primes Modulus:2048, 3072, 4096 bits (112, 128, 149 bits) | RSA KeyGen (FIPS186-4): (A4773, A4774, A4776, A4777, A4778) |
| Key Pair Generation with ECDSA | CKG | Key pair generation for ECDSA | Mode:B.4.2 Testing Candidates Curves:P-224, P-256, P-384, P-521 (112, 128, 192, 256 bits) | ECDSA KeyGen (FIPS186-4): (A4773, A4774, A4776, A4777, A4778) |
| Public Key Verification with ECDSA | AsymKeyPair- KeyVer | Verify public key for ECDSA | Curves:P-224, P-256, P-384, P-521 (112, 128, 192, 256 bits) | ECDSA KeyVer (FIPS186-4): (A4773, A4774, A4776, A4777, A4778) |
| Signature Generation with RSA | DigSig-SigGen | Digital signature generation using RSA | Padding:PKCS#1 v1.5, PSS Keys:2048, 3072, 4096 bits (112, 128, 149 bits) Hashes:SHA-224, SHA- 256, SHA-384, SHA- 512, SHA-512/224, SHA-512/256 | RSA SigGen (FIPS186-4): (A4773, A4774, A4776, A4777, A4778) |
| Signature Verification with RSA | DigSig-SigVer | Digital signature verification using RSA | Padding:PKCS#1 v1.5, PSS Keys:1024, 1536, 2048, 3072, 4096 bits (80, 96, 112, 128, 149 bits) Hashes:SHA-224, SHA- 256, SHA-384, SHA- 512, SHA-512/224, SHA-512/256 | RSA SigVer (FIPS186-4): (A4773, A4774, A4776, A4777, A4778) RSA SigVer (FIPS186-2): (A4773, A4774, A4776, A4777, A4778) |
| Signature Generation with ECDSA | DigSig-SigGen | Digital signature generation using ECDSA | Curves:P-224, P-256, P-384, P-521 (112, 128, 192, 256 bits) Hashes:SHA-224, SHA- 256, SHA-384, SHA- 512, SHA-512/224, SHA-512/256, SHA3- 224, SHA3-256, SHA3- 384, SHA3-512 | ECDSA SigGen (FIPS186-4): (A4773, A4774, A4776, A4777, A4778) |
| Signature Verification with ECDSA | DigSig-SigVer | Digital signature verification using ECDSA | Curves:P-224, P-256, P-384, P-521 (112, 128, 192, 256 bits) Hashes:SHA-224, SHA- 256, SHA-384, SHA- 512, SHA-512/224, SHA-512/256, SHA3- | ECDSA SigVer (FIPS186-4): (A4773, A4774, A4776, A4777, A4778) |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Name | Type | Description | Properties | Algorithms | |
|---|---|---|---|---|---|
| 224, SHA3-256, SHA3- 384, SHA3-512 | |||||
| Hashes | SHA | Compute a message digest using Secure Hash Algorithms | SHA-1: (A4772, A4773, A4774, A4775, A4776, A4777, A4778) SHA2-224: (A4773, A4774, A4776, A4777, A4778) SHA2-256: (A4773, A4774, A4776, A4777, A4778) SHA2-384: (A4773, A4774, A4776, A4777, A4778) SHA2-512: (A4773, A4774, A4776, A4777, A4778) SHA2-512/224: (A4773, A4774, A4776, A4777, A4778) SHA2-512/256: (A4773, A4774, A4776, A4777, A4778) SHA3-224: (A4773, A4774, A4778) SHA3-256: (A4773, A4774, A4778) SHA3-384: (A4773, A4774, A4778) SHA3-512: (A4773, A4774, A4778) | ||
| Extendable Output Function | XOF | Compute message digest from XOFs | SHAKE-128: (A4773, A4774, A4778) SHAKE-256: (A4773, A4774, A4778) | ||
| Message Authentication Code | MAC | Compute MAC tags using AES-based CMAC or HMAC | Keys:112-256 bits | AES-CMAC: (A4773, A4774, A4776, A4777) HMAC-SHA-1: (A4772, A4773, A4774, A4775, A4776, A4777, A4778) HMAC-SHA2-224: (A4773, A4774, A4776, A4777, |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Name | Type | Description | Properties | Algorithms |
|---|---|---|---|---|
| A4778) HMAC-SHA2-256: (A4773, A4774, A4776, A4777, A4778) HMAC-SHA2-384: (A4773, A4774, A4776, A4777, A4778) HMAC-SHA2-512: (A4773, A4774, A4776, A4777, A4778) HMAC-SHA2- 512/224: (A4773, A4774, A4776, A4777, A4778) HMAC-SHA2- 512/256: (A4773, A4774, A4776, A4777, A4778) HMAC-SHA3-224: (A4773, A4774, A4778) HMAC-SHA3-256: (A4773, A4774, A4778) HMAC-SHA3-384: (A4773, A4774, A4778) HMAC-SHA3-512: (A4773, A4774, A4778) | ||||
| Random Number Generation with DRBG | DRBG | Random number generation using DRBG | Compliance:Compliant with SP800-90Arev1 | Counter DRBG: (A4773, A4774, A4776, A4777) Hash DRBG: (A4773, A4774, A4776, A4777, A4778) HMAC DRBG: (A4773, A4774, A4776, A4777, A4778) |
| Key Derivation with PBKDF | PBKDF | Key derivation using PBKDF | Derived keys:112-256 bits HMAC modes:SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2- 512/256, SHA3-224, | PBKDF: (A4773, A4774, A4776, A4777, A4778) |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Name | Type | Description | Properties | Algorithms | |
|---|---|---|---|---|---|
| SHA3-256, SHA3-384, SHA3-512 |
| Cert Number | Vendor Name | |
|---|---|---|
| E99 | Oracle Corporation |
Table 9: Security Function Implementations
The length of a single data unit encrypted or decrypted with AES XTS shall not exceed 220 AES blocks, that is 16MB, of data per XTS instance. An XTS instance is defined in Section 4 of SP 800-38E. To meet the requirement stated in IG C.I, the module implements a check to ensure that the two AES keys used in AES XTS mode are not identical. The XTS mode shall only be used for the cryptographic protection of data on storage devices. It shall not be used for other purposes, such as the encryption of data in transit.
The module provides password-based key derivation (PBKDF), compliant with SP 800-132. The module supports option 1a from Section 5.4 of SP 800-132, in which the Master Key (MK) or a segment of it is used directly as the Data Protection Key (DPK). In accordance with SP 800-132 and FIPS 140-3 IG D.N, the following requirements shall be met.
Table 10: Entropy Certificates N/A for this module. Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
The module provides an SP 800-90Arev1-compliant Deterministic Random Bit Generator (DRBG) for creation of key components of asymmetric keys, and random number generation. This entropy source is located within the module’s physical perimeter, but outside of the module’s cryptographic boundary. The module obtains 384 bits to seed the DRBG, and 256 bits to reseed it. The seeding (and automatic reseeding) of the DRBG is done with getrandom(). The DRBG supports the Hash_DRBG, HMAC_DRBG, and CTR_DRBG mechanisms. The DRBG is initialized during module initialization; the module loads by default the DRBG and using the HMAC_DRBG mechanism with SHA-256 and without prediction resistance. A different DRBG mechanism can be chosen by invoking the gcry_control(GCRYCTL_DRBG_REINIT) function. The module performs the DRBG health tests as defined in Section 11.3 of SP 800-90Arev1.
The module provides an SP 800-90Arev1-compliant DRBG for the creation of the key components of asymmetric keys, and random number generation. The Cryptographic Key Generation (CKG) methods implemented in the module for Approved Services in the approved mode are compliant with Section 5.1 of SP 800-133rev2. For generating RSA and ECDSA keys, the module implements asymmetric key generation services compliant with FIPS 186-4. A seed (i.e. the random value) used in asymmetric key generation is directly obtained from the SP 800-90Arev1 DRBG. Additionally, according to section 6.2 of SP 800-133rev2, the module implements the PBKDF2 key derivation method compliant with option 1a of SP 800-132. This implementation shall only be used to derive keys for use in storage applications.
As permitted by IG D.G, the module provides key transport either by using an approved authenticated encryption mode or by a combination of any approved symmetric encryption mode and an approved authentication method. The SSP transport methods are specified in the Security Function Implementations table.
The module does not support any industry protocols listed within the publication of SP 800-135rev1. Therefore, this section is not applicable. Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Physical Port | Logical Interface(s) | Data That Passes |
|---|---|---|
| N/A | Data Input | API input parameters for data |
| N/A | Data Output | API output parameters for data |
| N/A | Control Input | API function calls, API input parameters for control input |
| N/A | Status Output | API return codes, API output parameters for status output |
Table 11: Ports and Interfaces The logical interfaces are the APIs through which the applications request services. These logical interfaces are logically separated from each other by the API design. The module does not implement a Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Name | Type | Operator Type | Authentication Methods | ||||
|---|---|---|---|---|---|---|---|
| Crypto Officer | Role | CO | None |
| Name | Descripti on | Indicator | Inputs | Outputs | Security Functions | SSP Access |
|---|---|---|---|---|---|---|
| Symmetric encryption | Perform AES encryptio n | gcry_control() returns 0 | AES key, Plaintext | Cipherte xt | Encryption with AES | Crypto Officer - AES key: W,E |
| Symmetric decryption | Perform AES decryptio n | gcry_control() returns 0 | AES key, Ciphertext | Plaintext | Decryption with AES | Crypto Officer - AES key: W,E |
| Authentica ted symmetric encryption | Authentic ate and encrypt a plaintext using AES | gcry_control() returns 0 | AES key, Plaintext, IV | Cipherte xt, MAC tag | Authentica ted encryption with AES | Crypto Officer - AES key: W,E |
| Authentica ted symmetric decryption | Authentic ate and decrypt a plaintext using AES | gcry_control() returns 0 | AES key, Ciphertext, MAC tag | Plaintext | Authentica ted decryption with AES | Crypto Officer - AES key: W,E |
| RSA Key generation | Generate RSA key pairs | gcry_control() returns 0 | Key size | RSA public key, RSA private key | Key Pair Generation with RSA | Crypto Officer - RSA public key: G,R - RSA private key: G,R |
| ECDSA Key generation | Generate ECDSA key pairs | gcry_control() returns 0 | Key size | ECDSA public key, ECDSA private key | Key Pair Generation with ECDSA | Crypto Officer - ECDSA public key: G,R - ECDSA private key: G,R |
| RSA Digital signature generation | RSA signature generatio n | gcry_control() returns 0 | RSA private key, Message, Hash algorithm | Signatur e | Signature Generation with RSA | Crypto Officer - RSA private key: W,E |
Table 12: Roles The module supports the Crypto Officer role only. This sole role is implicitly and always assumed by the operator of the module. The module does not support multiple concurrent operators.
n W,E n W,E G,R Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Name | Descripti on | Indicator | Inputs | Outputs | Security Functions | SSP Access |
|---|---|---|---|---|---|---|
| ECDSA Digital signature generation | ECDSA signature generatio n | gcry_control() returns 0 | ECDSA private Key, Message, Hash algorithm | Signatur e | Signature Generation with ECDSA | Crypto Officer - ECDSA private key: W,E |
| RSA Digital signature verification | RSA signature verificatio n | gcry_control() returns 0 | Signature, Hash algorithm, RSA public key | Signatur e verificati on result | Signature Verification with RSA | Crypto Officer - RSA public key: W,E |
| ECDSA Digital signature verification | ECDSA signature verificatio n | gcry_control() returns 0 | Signature, Hash algorithm, ECDSA public key | Signatur e verificati on result | Signature Verification with ECDSA | Crypto Officer - ECDSA public key: W,E |
| Public key verification | Verify ECDSA public key | gcry_mpi_ec_curve_p oint() returns 0 | ECDSA public key, ECDSA private key | Return codes/lo g message s | Public Key Verification with ECDSA | Crypto Officer - ECDSA public key: W,E |
| Random number generation | Generate random bitstrings | gcry_randomize(), gcry_random_bytes(), gcry_random_bytes_s ecure() returns 0 | Size | Random number | Random Number Generation with DRBG | Crypto Officer - Entropy input: W,E - DRBG seed: G,E - DRBG internal state: (V value, C value): G,W,E - DRBG internal state: (V value, key): G,W,E |
| Message digest | Compute SHA hashes | gcry_control() returns 0 | Message | Message digest | Hashes Extendable Output Function | Crypto Officer |
| Message authenticat ion code (MAC) | Compute HMAC or AES- based CMAC | gcry_control() returns 0 | Message, Key | MAC tag | Message Authentica tion Code | Crypto Officer - HMAC key: W,E - AES key: W,E |
| Key wrapping | Perform AES- based key wrapping | gcry_control() returns 0 | Key wrapping key, key to be wrapped | Wrappe d key | Key wrapping using AES CCM | Crypto Officer - AES key: W,E |
W,E W,E s W,E G,E G,W,E G,W,E W,E Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Name | Descripti on | Indicator | Inputs | Outputs | Security Functions | SSP Access |
|---|---|---|---|---|---|---|
| Key wrapping using AES KW | ||||||
| Key unwrappin g | Perform AES- based key unwrappi ng | gcry_control() returns 0 | Wrapped key, key unwrapping key | Unwrap ped key | Key unwrappin g using AES CCM Key unwrappin g using AES KW | Crypto Officer - AES key: W,E |
| Key derivation | Perform key derivatio n | gcry_control() returns 0 | Password/passph rase; Derived key | Derived key | Key Derivation with PBKDF | Crypto Officer - Password or passphrase: W,E - Derived key: G,R |
| Show status | Show module status | N/A | None | Current status of the module | None | Crypto Officer |
| Zeroization | Zeroize SSPs | N/A | N/A | N/A | None | Crypto Officer - AES key: Z - HMAC key: Z - Password or passphrase: Z - Derived key: Z - Entropy input: Z - DRBG internal state: (V value, key): Z - DRBG internal state: (V value, C value): Z - DRBG seed: Z - ECDSA public key: Z |
W,E Z Z Z Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Name | Descripti on | Indicator | Inputs | Outputs | Security Functions | SSP Access - ECDSA private key: Z - RSA public key: Z - RSA private key: Z |
|---|---|---|---|---|---|---|
| Self-tests | Perform self-tests | N/A | Booting the module | N/A | None | Unauthentic ated |
| Show module name and version | Show module name and version | N/A | N/A | Display module name and version | None | Unauthentic ated |
Z Table 13: Approved Services For all approved services, GPG_ERR_NO_ERROR (i.e., “0”) return code indicates the service is approved. In case the above-mentioned controls are used in conjunction, the operator is responsible to check that all the called functions return GPG_ERR_NO_ERROR (i.e., “0”). For all non-approved services, a "nonzero" return code indicates the service is not approved. The table above lists the approved services. For each service, the table lists the associated cryptographic algorithm(s), the role to perform the service, the cryptographic keys or CSPs involved, and their access type(s). The following convention is used to specify access rights to SSPs: • Generate (G): The module generates or derives the SSP. • Read (R): The SSP is read from the module (e.g. the SSP is output). • Write (W): The SSP is updated, imported, or written to the module. • Execute (E): The module uses the SSP in performing a cryptographic operation. • N/A: the calling application does not access any CSP or key during its operation. The details of the approved cryptographic algorithms including the CAVP certificate numbers can be found in Section 2.5. In order to check whether it utilizes an approved security function or not, the operator is responsible to invoke the gcry_control() API along with dedicated controls in the form of API input parameters. The module implements the following controls depending on the requested service:
| Name | Description | Algorithms | Role |
|---|---|---|---|
| Authenticated symmetric encryption | AES encryption using non-approved AES modes | AES GCM noncompliant with IG C.H. AES GCM-SIV AES OCB AES-EAX | CO |
| Authenticated symmetric decryption | AES decryption using non-approved AES modes | AES GCM noncompliant with IG C.H. AES GCM-SIV AES OCB AES-EAX | CO |
| Message digest using non- approved algorithms | Message digest | MD5 | CO |
| Shared secret computation | ECDH Shared secret computation | ECDH noncompliant with SP 800-56Arev3 assurances | CO |
| Key generation | Generate RSA/ECDSA key pairs with public key flags not listed in Appendix A | RSA with non-approved flags that are not listed in Appendix A ECDSA with non-approved flags that are not listed in Appendix A | CO |
| Digital signature generation | RSA/ECDSA signature generation with public key flags not listed in Appendix A | RSA with non-approved flags that are not listed in Appendix A ECDSA with non-approved flags that are not listed in Appendix A | CO |
| Digital signature verification | RSA/ECDSA signature verification with public key flags not listed in Appendix A | RSA with non-approved flags that are not listed in Appendix A ECDSA with non-approved flags that are not listed in Appendix A | CO |
| Asymmetric encryption and decryption primitives | RSA encryption and decryption primitives | RSA | CO |
| Signature generation/verification primitives | RSA/ECDSA signature generation/verification primitives | RSA ECDSA | CO |
In addition to that, for the below-mentioned services, the approved service indicator corresponds to the GPG_ERR_NO_ERROR returned from listed functions in the indicator column below. They don’t use gcry_control() API:
the module implements an additional service indicator in the form of a control named GCRYCTL_FIPS_SERVICE_INDICATOR_FUNCTION. The operator is responsible to invoke the gcry_control() API along with the following input parameters: GCRYCTL_FIPS_SERVICE_INDICATOR_FUNCTION control; the name of the API 2 representing the service. The list of APIs is supported by the module can be found in the documentation included in the optional libgcryptdevel package. Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
The integrity of the module is verified by comparing a HMAC SHA-256 values calculated at run time with the HMAC SHA-256 value embedded within the module binary. If the HMAC values do not match, the test fails, and the module enters the Error state.
The integrity test is performed as part of the pre-operational self-test, which is executed when the module is initialized. In addition, the module provides the Self-Test service to perform self-tests on demand which includes the pre-operational test (i.e., integrity test) and cryptographic algorithm self-tests (CASTs). This service can be invoked relying on the gcry_control(GCRYCTL_SELFTEST) API function call or by powering-off and reloading the module. During the execution of the on-demand self-tests, services are not available, and data output or input is not possible. In order to verify whether the self-tests have succeeded and the module is in the Operational state, the calling application may invoke the gcry_control(GCRYTCL_OPERATIONAL_P) API. The function will return TRUE if the module is in the Operational state and FALSE if the module is in the Error state. Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
Type of Operational Environment: Modifiable How Requirements are Satisfied: The module shall be installed as stated in Section 11. If properly installed, the operating system provides process isolation and memory protection mechanisms that ensure appropriate separation for memory access among the processes on the system. Each process has control over its own data, and uncontrolled access to the data of other processes is prevented.
The module shall be installed as stated in Section 11.1. Instrumentation tools like the ptrace system call, gdb and strace, as well as other tracing mechanisms offered by the Linux environment such as ftrace or systemtap, shall not be used in the operational environment. The use of any of these tools implies that the cryptographic module is running in a nonvalidated operational environment. Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
The module is comprised of software only, and therefore this section is not applicable. Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
This module does not implement any non-invasive security mechanism, and therefore this section is not applicable. Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Storage Area Name | Description | Persistence Type | |
|---|---|---|---|
| RAM | Temporary storage for SSPs used by the module as part of service execution | Dynamic |
| Name | From | To | Format Type | Distribution Type | Entry Type | SFI or Algorithm |
|---|---|---|---|---|---|---|
| API input parameters | Operating calling application (TOEPP) | Cryptographic module | Plaintext | Manual | Electronic | |
| API output parameters | Cryptographic module | Operator calling application (TOEPP) | Plaintext | Manual | Electronic |
| Zeroization Method | Description | Rationale | Operator Initiation |
|---|---|---|---|
| Free cipher handle | Zeroizes the SSPs contained within the provided cipher handle | Memory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable. The completion of a zeroization routine will indicate that a zeroization procedure succeeded. | By calling the appropriate zeroization functions: AES key: gcry_cipher_close gcry_free() HMAC key: gcry_mac_close, gcry_free Key-derivation key: gcry_free Derived key: gcry_free RSA keys: gcry_mpi_release, gcry_sexp_release, gcry_free EC keys: gcry_mpi_release, gcry_free, gcry_mpi_point_release, gcry_sexp_release, gcry_ctx_release Entropy input: gcry_ctrl(GCRYCTL_TERM_SECMEM) Internal state: gcry_ctrl(GCRYCTL_TERM_SECMEM) |
| Remove power from the module | De-allocates the volatile memory used to store SSPs | Volatile memory used by the module is overwritten within nanoseconds when power is removed. Module power off indicates that the | By unloading the module |
Table 15: Storage Areas The module does not perform persistent storage of SSPs. The SSPs are temporarily stored in the RAM in Table 16: SSP Input-Output Methods The module does not support manual SSP input or intermediate SSP generation output. The SSPs are in plaintext form within the physical perimeter of the operational environment. This is allowed by FIPS 140-3 IG 9.5.A, according to the “CM Software to/from App via TOEPP Path” entry in the table above. Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
Zeroization Method
Description
Rationale zeroization procedure succeeded.
Operator Initiation
| Name | Description | Size - Strength | Type - Category | Generated By | Established By | Used By | |
|---|---|---|---|---|---|---|---|
| AES key | AES key used for encryption, decryption, and computing MAC tags | XTS: 256, 512 bits; Other modes: 128, 192, 256 bits - XTS: 128, 256 bits; Other modes: 128, 192, 256 bits | Symmetric key - CSP | Key wrapping using AES CCM Key wrapping using AES KW Key unwrapping using AES CCM Key unwrapping using AES KW Encryption with AES Decryption with AES | |||
| HMAC key | HMAC key | 112-256 bits - 112-256 bits | Authentication key - CSP | Message Authentication Code | |||
| Password or passphrase | PBKDF2 password or passphrase | At least 8 characters - N/A | Password or passphrase - CSP | Key Derivation with PBKDF | |||
| Derived key | PBKDF2 derived key | 112-256 bits - 112-256 bits | Symmetric key - CSP | Key Derivation with PBKDF | Key Derivation with PBKDF | ||
| Entropy input | Obtained from the entropy source, used to seed the DRBGs | 128-448 bits (128-256 bits) - 256 bits | Entropy input - CSP | Random Number Generation with DRBG | |||
| DRBG internal state: (V value, key) | Internal state of CTR_DRBG and HMAC_DRBG | CTR_DRBG: 256, 320, 384 bits; HMAC_DRBG: 320, 512, 1024 bits - CTR_DRBG: 128, 192, 256 bits; HMAC_DRBG: 128, 256 bits | Internal state - CSP | Random Number Generation with DRBG | Random Number Generation with DRBG |
Table 17: SSP Zeroization Methods All data output is inhibited during zeroization.
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Name | Description | Size - Strength | Type - Category | Generated By | Established By | Used By |
|---|---|---|---|---|---|---|
| DRBG internal state: (V value, C value) | Internal state of Hash_DRBG | 880, 1776 bits - 128, 256 bits | Internal state - CSP | Random Number Generation with DRBG | Random Number Generation with DRBG | |
| DRBG seed | DRBG seed derived from entropy input | CTR_DRBG: 256, 320, 384 bits; Hash_DRBG: 440, 888 bits; HMAC_DRBG: 440, 888 bits - CTR_DRBG: 128, 192, 256 bits; Hash_DRBG: 128, 256 bits; HMAC_DRBG: 128, 256 bits | Seed - CSP | Random Number Generation with DRBG | Random Number Generation with DRBG | |
| ECDSA public key | Public key used for ECDSA signature verification | P-224, P-256, P- 384, P-521 - 112, 128, 192, 256 bits | Public key - PSP | Key Pair Generation with ECDSA | Key Pair Generation with ECDSA Public Key Verification with ECDSA Signature Verification with ECDSA | |
| ECDSA private key | Private key used for ECDSA signature generation | P-224, P-256, P- 384, P-521 - 112, 128, 192, 256 bits | Private key - CSP | Key Pair Generation with ECDSA | Key Pair Generation with ECDSA Public Key Verification with ECDSA Signature Generation with ECDSA | |
| RSA public key | Public key used for RSA signature verification | 1024, 1536, 2048, 3072, 4096 bits - 80, 96, 112, 128, 140 bits | Public key - PSP | Key Pair Generation with RSA | Key Pair Generation with RSA Signature Verification with RSA | |
| RSA private key | Private key used for RSA signature generation | 2048, 3072, 4096 bits - 112, 128, 140 bits | Private key - CSP | Key Pair Generation with RSA | Key Pair Generation with RSA Signature Generation with RSA |
Table 18: SSP Table 1 Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Name | Input - Output | Storage | Storage Duration | Zeroization | Related SSPs | |
|---|---|---|---|---|---|---|
| AES key | API input parameters | RAM:Plaintext | From service invoked to service completed | Free cipher handle Remove power from the module | ||
| HMAC key | API input parameters | RAM:Plaintext | From service invoked to service completed | Free cipher handle Remove power from the module | ||
| Password or passphrase | API output parameters | RAM:Plaintext | From service invoked to service completed | Free cipher handle Remove power from the module | Derived key:Generates | |
| Derived key | API input parameters | RAM:Plaintext | From service invoked to service completed | Free cipher handle Remove power from the module | Password or passphrase:Derived From | |
| Entropy input | RAM:Plaintext | From service invoked to service completed | Free cipher handle Remove power from the module | DRBG internal state: (V value, key):Generates DRBG internal state: (V value, C value):Generates DRBG seed:Generates | ||
| DRBG internal state: (V value, key) | RAM:Plaintext | From service invoked to service completed | Free cipher handle Remove power from the module | Entropy input:Derived From DRBG seed:Derived From | ||
| DRBG internal state: (V value, C value) | RAM:Plaintext | From service invoked to service completed | Free cipher handle Remove power from the module | Entropy input:Derived From DRBG seed:Derived From | ||
| DRBG seed | RAM:Plaintext | Free cipher handle Remove power from the module | Entropy input:Derived From DRBG internal state: (V value, key):Generates DRBG internal state: (V value, C value):Generates | |||
| ECDSA public key | API input parameters API output parameters | RAM:Plaintext | From service invoked to service completed | Free cipher handle Remove power from the module | DRBG internal state: (V value, key):Derived From ECDSA private key:Paired With | |
| ECDSA private key | API input parameters | RAM:Plaintext | From service invoked to | Free cipher handle | DRBG internal state: (V value, key):Derived |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Name | Input - Output | Storage | Storage Duration | Zeroization | Related SSPs |
|---|---|---|---|---|---|
| API output parameters | service completed | Remove power from the module | From ECDSA public key:Paired With | ||
| RSA public key | API input parameters API output parameters | RAM:Plaintext | From service invoked to service completed | Free cipher handle Remove power from the module | DRBG internal state: (V value, key):Derived From RSA private key:Paired With |
| RSA private key | API input parameters API output parameters | RAM:Plaintext | From service invoked to service completed | Free cipher handle Remove power from the module | RSA public key:Paired With DRBG internal state: (V value, key):Derived From |
The SHA-1 algorithm, as implemented by the module, will be non-approved for all purposes starting January 1, 2031. The RSA and ECDSA algorithms as implemented by the module conforms to FIPS 186-4, which has been superseded by FIPS 186-5. The transition started on July 25, 2023, and ended on February 4, 2024. FIPS 186-4 has been withdrawn since February 3, 2024. Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | ||
|---|---|---|---|---|---|---|---|
| HMAC-SHA2- 256 (A4773) | Key size: 376-bit key | Message Authentication | SW/FW Integrity | The module becomes operational and the services are available for use | Integrity test for libgcrypt.so.20.4.0 |
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | Conditions |
|---|---|---|---|---|---|---|
| AES-ECB (A4773) | AES ECB mode with 128, 192, 256-bit keys, encryption, and decryption (separately tested) | KAT | CAST | The module becomes operational and the services are available for use | Encryption, Decryption | Module initialization or on demand through API function call |
| AES-ECB (A4774) | AES ECB mode with 128, 192, 256-bit keys, encryption, and decryption (separately tested) | KAT | CAST | The module becomes operational and the services are available for use | Encryption, Decryption | Module initialization or on demand through API function call |
| AES-ECB (A4776) | AES ECB mode with 128, 192, 256-bit keys, encryption, and decryption (separately tested) | KAT | CAST | The module becomes operational and the services are available for use | Encryption, Decryption | Module initialization or on demand through API function call |
| AES-ECB (A4777) | AES ECB mode with 128, 192, 256-bit keys, encryption, and decryption (separately tested) | KAT | CAST | The module becomes operational and the services are available for use | Encryption, Decryption | Module initialization or on demand through API function call |
Table 20: Pre-Operational Self-Tests The pre-operational software integrity test is performed automatically when the module is powered on before the module transitions into the Operational state. While the module is executing the self-tests, services are not available, and data output (via the data output interface) is inhibited until the tests are successfully completed. The module transitions to the Operational state only after the pre-operational self-test passes successfully.
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | Conditions |
|---|---|---|---|---|---|---|
| AES-CMAC (A4773) | AES CMAC with 128-bit key, MAC generation | KAT | CAST | The module becomes operational and the services are available for use | Message Authentication | Module initialization or on demand through API function call |
| AES-CMAC (A4774) | AES CMAC with 128-bit key, MAC generation | KAT | CAST | The module becomes operational and the services are available for use | Message Authentication | Module initialization or on demand through API function call |
| AES-CMAC (A4776) | AES CMAC with 128-bit key, MAC generation | KAT | CAST | The module becomes operational and the services are available for use | Message Authentication | Module initialization or on demand through API function call |
| AES-CMAC (A4777) | AES CMAC with 128-bit key, MAC generation | KAT | CAST | The module becomes operational and the services are available for use | Message Authentication | Module initialization or on demand through API function call |
| Counter DRBG (A4773) | CTR_DRBG with AES with 128-bit key with DF, with and without PR | KAT | CAST | The module becomes operational and the services are available for use | Generate, Reseed | Module initialization or on demand through API function call |
| Counter DRBG (A4774) | CTR_DRBG with AES with 128-bit key with DF, with and without PR | KAT | CAST | The module becomes operational and the services are available for use | Generate, Reseed | Module initialization or on demand through API function call |
| Counter DRBG (A4776) | CTR_DRBG with AES with 128-bit key with DF, with and without PR | KAT | CAST | The module becomes operational and the services are available for use | Generate, Reseed | Module initialization or on demand through API function call |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | Conditions |
|---|---|---|---|---|---|---|
| Counter DRBG (A4777) | CTR_DRBG with AES with 128-bit key with DF, with and without PR | KAT | CAST | The module becomes operational and the services are available for use | Generate, Reseed | Module initialization or on demand through API function call |
| Hash DRBG (A4773) | SHA-1 without PR | KAT | CAST | The module becomes operational and the services are available for use | Generate, Reseed | Module initialization or on demand through API function call |
| Hash DRBG (A4774) | SHA-1 without PR | KAT | CAST | The module becomes operational and the services are available for use | Generate, Reseed | Module initialization or on demand through API function call |
| Hash DRBG (A4776) | SHA-1 without PR | KAT | CAST | The module becomes operational and the services are available for use | Generate, Reseed | Module initialization or on demand through API function call |
| Hash DRBG (A4777) | SHA-1 without PR | KAT | CAST | The module becomes operational and the services are available for use | Generate, Reseed | Module initialization or on demand through API function call |
| Hash DRBG (A4778) | SHA-1 without PR | KAT | CAST | The module becomes operational and the services are available for use | Generate, Reseed | Module initialization or on demand through API function call |
| Hash DRBG (A4773) | SHA-256 with and without PR | KAT | CAST | The module becomes operational and the services are available for use | Generate, Reseed | Module initialization or on demand through API function call |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | Conditions |
|---|---|---|---|---|---|---|
| Hash DRBG (A4774) | SHA-256 with and without PR | KAT | CAST | The module becomes operational and the services are available for use | Generate, Reseed | Module initialization or on demand through API function call |
| Hash DRBG (A4776) | SHA-256 with and without PR | KAT | CAST | The module becomes operational and the services are available for use | Generate, Reseed | Module initialization or on demand through API function call |
| Hash DRBG (A4777) | SHA-256 with and without PR | KAT | CAST | The module becomes operational and the services are available for use | Generate, Reseed | Module initialization or on demand through API function call |
| Hash DRBG (A4778) | SHA-256 with and without PR | KAT | CAST | The module becomes operational and the services are available for use | Generate, Reseed | Module initialization or on demand through API function call |
| HMAC DRBG (A4773) | SHA-256 with and without PR | KAT | CAST | The module becomes operational and the services are available for use | Generate, Reseed | Module initialization or on demand through API function call |
| HMAC DRBG (A4774) | SHA-256 with and without PR | KAT | CAST | The module becomes operational and the services are available for use | Generate, Reseed | Module initialization or on demand through API function call |
| HMAC DRBG (A4776) | SHA-256 with and without PR | KAT | CAST | The module becomes operational and the services are available for use | Generate, Reseed | Module initialization or on demand through API function call |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | Conditions |
|---|---|---|---|---|---|---|
| HMAC DRBG (A4777) | SHA-256 with and without PR | KAT | CAST | The module becomes operational and the services are available for use | Generate, Reseed | Module initialization or on demand through API function call |
| HMAC DRBG (A4778) | SHA-256 with and without PR | KAT | CAST | The module becomes operational and the services are available for use | Generate, Reseed | Module initialization or on demand through API function call |
| ECDSA SigGen (FIPS186-4) (A4773) | P-256 with SHA-256 | KAT | CAST | The module becomes operational and the services are available for use | Signature generation | Module initialization or on demand through API function call |
| ECDSA SigGen (FIPS186-4) (A4774) | P-256 with SHA-256 | KAT | CAST | The module becomes operational and the services are available for use | Signature generation | Module initialization or on demand through API function call |
| ECDSA SigGen (FIPS186-4) (A4776) | P-256 with SHA-256 | KAT | CAST | The module becomes operational and the services are available for use | Signature generation | Module initialization or on demand through API function call |
| ECDSA SigGen (FIPS186-4) (A4777) | P-256 with SHA-256 | KAT | CAST | The module becomes operational and the services are available for use | Signature generation | Module initialization or on demand through API function call |
| ECDSA SigGen (FIPS186-4) (A4778) | P-256 with SHA-256 | KAT | CAST | The module becomes operational and the services are available for use | Signature generation | Module initialization or on demand through API function call |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | Conditions |
|---|---|---|---|---|---|---|
| ECDSA SigVer (FIPS186-4) (A4773) | P-256 with SHA-256 | KAT | CAST | The module becomes operational and the services are available for use | Signature verification | Module initialization or on demand through API function call |
| ECDSA SigVer (FIPS186-4) (A4774s) | P-256 with SHA-256 | KAT | CAST | The module becomes operational and the services are available for use | Signature verification | Module initialization or on demand through API function call |
| ECDSA SigVer (FIPS186-4) (A4776) | P-256 with SHA-256 | KAT | CAST | The module becomes operational and the services are available for use | Signature verification | Module initialization or on demand through API function call |
| ECDSA SigVer (FIPS186-4) (A4777) | P-256 with SHA-256 | KAT | CAST | The module becomes operational and the services are available for use | Signature verification | Module initialization or on demand through API function call |
| ECDSA SigVer (FIPS186-4) (A4778) | P-256 with SHA-256 | KAT | CAST | The module becomes operational and the services are available for use | Signature verification | Module initialization or on demand through API function call |
| HMAC- SHA-1 (A4772) | HMAC-SHA-1 | KAT | CAST | The module becomes operational and the services are available for use | Message authentication | Module initialization or on demand through API function call |
| HMAC- SHA-1 (A4773) | HMAC-SHA-1 | KAT | CAST | The module becomes operational and the services are available for use | Message authentication | Module initialization or on demand through API function call |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | Conditions |
|---|---|---|---|---|---|---|
| HMAC- SHA-1 (A4774) | HMAC-SHA-1 | KAT | CAST | The module becomes operational and the services are available for use | Message authentication | Module initialization or on demand through API function call |
| HMAC- SHA-1 (A4776) | HMAC-SHA-1 | KAT | CAST | The module becomes operational and the services are available for use | Message authentication | Module initialization or on demand through API function call |
| HMAC- SHA-1 (A4777) | HMAC-SHA-1 | KAT | CAST | The module becomes operational and the services are available for use | Message authentication | Module initialization or on demand through API function call |
| HMAC- SHA-1 (A4778) | HMAC-SHA-1 | KAT | CAST | The module becomes operational and the services are available for use | Message authentication | Module initialization or on demand through API function call |
| HMAC- SHA2-224 (A4773) | HMAC-SHA-224 | KAT | CAST | The module becomes operational and the services are available for use | Message authentication | Module initialization or on demand through API function call |
| HMAC- SHA2-224 (A4774) | HMAC-SHA-224 | KAT | CAST | The module becomes operational and the services are available for use | Message authentication | Module initialization or on demand through API function call |
| HMAC- SHA2-224 (A4776) | HMAC-SHA-224 | KAT | CAST | The module becomes operational and the services are available for use | Message authentication | Module initialization or on demand through API function call |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | Conditions |
|---|---|---|---|---|---|---|
| HMAC- SHA2-224 (A4777) | HMAC-SHA-224 | KAT | CAST | The module becomes operational and the services are available for use | Message authentication | Module initialization or on demand through API function call |
| HMAC- SHA2-224 (A4778) | HMAC-SHA-224 | KAT | CAST | The module becomes operational and the services are available for use | Message authentication | Module initialization or on demand through API function call |
| HMAC- SHA2-256 (A4773) | HMAC-SHA-256 | KAT | CAST | The module becomes operational and the services are available for use | Message authentication | Module initialization or on demand through API function call |
| HMAC- SHA2-256 (A4774) | HMAC-SHA-256 | KAT | CAST | The module becomes operational and the services are available for use | Message authentication | Module initialization or on demand through API function call |
| HMAC- SHA2-256 (A4776) | HMAC-SHA-256 | KAT | CAST | The module becomes operational and the services are available for use | Message authentication | Module initialization or on demand through API function call |
| HMAC- SHA2-256 (A4777) | HMAC-SHA-256 | KAT | CAST | The module becomes operational and the services are available for use | Message authentication | Module initialization or on demand through API function call |
| HMAC- SHA2-256 (A4778) | HMAC-SHA-256 | KAT | CAST | The module becomes operational and the services are available for use | Message authentication | Module initialization or on demand through API function call |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | Conditions |
|---|---|---|---|---|---|---|
| HMAC- SHA2-384 (A4773) | HMAC-SHA-384 | KAT | CAST | The module becomes operational and the services are available for use | Message authentication | Module initialization or on demand through API function call |
| HMAC- SHA2-384 (A4774) | HMAC-SHA-384 | KAT | CAST | The module becomes operational and the services are available for use | Message authentication | Module initialization or on demand through API function call |
| HMAC- SHA2-384 (A4776) | HMAC-SHA-384 | KAT | CAST | The module becomes operational and the services are available for use | Message authentication | Module initialization or on demand through API function call |
| HMAC- SHA2-384 (A4777) | HMAC-SHA-384 | KAT | CAST | The module becomes operational and the services are available for use | Message authentication | Module initialization or on demand through API function call |
| HMAC- SHA2-384 (A4778) | HMAC-SHA-384 | KAT | CAST | The module becomes operational and the services are available for use | Message authentication | Module initialization or on demand through API function call |
| HMAC- SHA2-512 (A4773) | HMAC-SHA-512 | KAT | CAST | The module becomes operational and the services are available for use | Message authentication | Module initialization or on demand through API function call |
| HMAC- SHA2-512 (A4774) | HMAC-SHA-512 | KAT | CAST | The module becomes operational and the services are available for use | Message authentication | Module initialization or on demand through API function call |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | Conditions |
|---|---|---|---|---|---|---|
| HMAC- SHA2-512 (A4776) | HMAC-SHA-512 | KAT | CAST | The module becomes operational and the services are available for use | Message authentication | Module initialization or on demand through API function call |
| HMAC- SHA2-512 (A4777) | HMAC-SHA-512 | KAT | CAST | The module becomes operational and the services are available for use | Message authentication | Module initialization or on demand through API function call |
| HMAC- SHA2-512 (A4778) | HMAC-SHA-512 | KAT | CAST | The module becomes operational and the services are available for use | Message authentication | Module initialization or on demand through API function call |
| HMAC- SHA3-224 (A4773) | HMAC-SHA3-224 | KAT | CAST | The module becomes operational and the services are available for use | Message authentication | Module initialization or on demand through API function call |
| HMAC- SHA3-224 (A4774) | HMAC-SHA3-224 | KAT | CAST | The module becomes operational and the services are available for use | Message authentication | Module initialization or on demand through API function call |
| HMAC- SHA3-224 (A4773) | HMAC-SHA3-224 | KAT | CAST | The module becomes operational and the services are available for use | Message authentication | Module initialization or on demand through API function call |
| HMAC- SHA3-256 (A4773) | HMAC-SHA3-256 | KAT | CAST | The module becomes operational and the services are available for use | Message authentication | Module initialization or on demand through API function call |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | Conditions |
|---|---|---|---|---|---|---|
| HMAC- SHA3-256 (A4774) | HMAC-SHA3-256 | KAT | CAST | The module becomes operational and the services are available for use | Message authentication | Module initialization or on demand through API function call |
| HMAC- SHA3-256 (A4778) | HMAC-SHA3-256 | KAT | CAST | The module becomes operational and the services are available for use | Message authentication | Module initialization or on demand through API function call |
| HMAC- SHA3-384 (A4773) | HMAC-SHA3-384 | KAT | CAST | The module becomes operational and the services are available for use | Message authentication | Module initialization or on demand through API function call |
| HMAC- SHA3-384 (A4774) | HMAC-SHA3-384 | KAT | CAST | The module becomes operational and the services are available for use | Message authentication | Module initialization or on demand through API function call |
| HMAC- SHA3-384 (A4778) | HMAC-SHA3-384 | KAT | CAST | The module becomes operational and the services are available for use | Message authentication | Module initialization or on demand through API function call |
| HMAC- SHA3-512 (A4773) | HMAC-SHA3-512 | KAT | CAST | The module becomes operational and the services are available for use | Message authentication | Module initialization or on demand through API function call |
| HMAC- SHA3-512 (A4774) | HMAC-SHA3-512 | KAT | CAST | The module becomes operational and the services are available for use | Message authentication | Module initialization or on demand through API function call |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | Conditions |
|---|---|---|---|---|---|---|
| HMAC- SHA3-512 (A4778) | HMAC-SHA3-512 | KAT | CAST | The module becomes operational and the services are available for use | Message authentication | Module initialization or on demand through API function call |
| RSA SigGen (FIPS186-4) (A4773) | PKCS #1 v1.5 with 2048- bit key and SHA-256 | KAT | CAST | The module becomes operational and the services are available for use | Signature generation | Module initialization or on demand through API function call |
| RSA SigGen (FIPS186-4) (A4774) | PKCS #1 v1.5 with 2048- bit key and SHA-256 | KAT | CAST | The module becomes operational and the services are available for use | Signature generation | Module initialization or on demand through API function call |
| RSA SigGen (FIPS186-4) (A4776) | PKCS #1 v1.5 with 2048- bit key and SHA-256 | KAT | CAST | The module becomes operational and the services are available for use | Signature generation | Module initialization or on demand through API function call |
| RSA SigGen (FIPS186-4) (A4777) | PKCS #1 v1.5 with 2048- bit key and SHA-256 | KAT | CAST | The module becomes operational and the services are available for use | Signature generation | Module initialization or on demand through API function call |
| RSA SigGen (FIPS186-4) (A4778) | PKCS #1 v1.5 with 2048- bit key and SHA-256 | KAT | CAST | The module becomes operational and the services are available for use | Signature generation | Module initialization or on demand through API function call |
| RSA SigVer (FIPS186-4) (A4773) | PKCS #1 v1.5 with 2048- bit key and SHA-256 | KAT | CAST | The module becomes operational and the services are available for use | Signature verification | Module initialization or on demand through API function call |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | Conditions |
|---|---|---|---|---|---|---|
| RSA SigVer (FIPS186-4) (A4774) | PKCS #1 v1.5 with 2048- bit key and SHA-256 | KAT | CAST | The module becomes operational and the services are available for use | Signature verification | Module initialization or on demand through API function call |
| RSA SigVer (FIPS186-4) (A4776) | PKCS #1 v1.5 with 2048- bit key and SHA-256 | KAT | CAST | The module becomes operational and the services are available for use | Signature verification | Module initialization or on demand through API function call |
| RSA SigVer (FIPS186-4) (A4777) | PKCS #1 v1.5 with 2048- bit key and SHA-256 | KAT | CAST | The module becomes operational and the services are available for use | Signature verification | Module initialization or on demand through API function call |
| RSA SigVer (FIPS186-4) (A4778) | PKCS #1 v1.5 with 2048- bit key and SHA-256 | KAT | CAST | The module becomes operational and the services are available for use | Signature verification | Module initialization or on demand through API function call |
| SHA-1 (A4772) | SHA-1 | KAT | CAST | The module becomes operational and the services are available for use | Message digest | Module initialization or on demand through API function call |
| SHA-1 (A4773) | SHA-1 | KAT | CAST | The module becomes operational and the services are available for use | Message digest | Module initialization or on demand through API function call |
| SHA-1 (A4774) | SHA-1 | KAT | CAST | The module becomes operational and the services are available for use | Message digest | Module initialization or on demand through API function call |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | Conditions |
|---|---|---|---|---|---|---|
| SHA-1 (A4775) | SHA-1 | KAT | CAST | The module becomes operational and the services are available for use | Message digest | Module initialization or on demand through API function call |
| SHA-1 (A4776) | SHA-1 | KAT | CAST | The module becomes operational and the services are available for use | Message digest | Module initialization or on demand through API function call |
| SHA-1 (A4777) | SHA-1 | KAT | CAST | The module becomes operational and the services are available for use | Message digest | Module initialization or on demand through API function call |
| SHA-1 (A4778) | SHA-1 | KAT | CAST | The module becomes operational and the services are available for use | Message digest | Module initialization or on demand through API function call |
| SHA2-224 (A4773) | SHA-224 | KAT | CAST | The module becomes operational and the services are available for use | Message digest | Module initialization or on demand through API function call |
| SHA2-224 (A4774) | SHA-224 | KAT | CAST | The module becomes operational and the services are available for use | Message digest | Module initialization or on demand through API function call |
| SHA2-224 (A4776) | SHA-224 | KAT | CAST | The module becomes operational and the services are available for use | Message digest | Module initialization or on demand through API function call |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | Conditions |
|---|---|---|---|---|---|---|
| SHA2-224 (A4777) | SHA-224 | KAT | CAST | The module becomes operational and the services are available for use | Message digest | Module initialization or on demand through API function call |
| SHA2-224 (A4778) | SHA-224 | KAT | CAST | The module becomes operational and the services are available for use | Message digest | Module initialization or on demand through API function call |
| SHA2-256 (A4773) | SHA-256 | KAT | CAST | The module becomes operational and the services are available for use | Message digest | Module initialization or on demand through API function call |
| SHA2-256 (A4774) | SHA-256 | KAT | CAST | The module becomes operational and the services are available for use | Message digest | Module initialization or on demand through API function call |
| SHA2-256 (A4776) | SHA-256 | KAT | CAST | The module becomes operational and the services are available for use | Message digest | Module initialization or on demand through API function call |
| SHA2-256 (A4777) | SHA-256 | KAT | CAST | The module becomes operational and the services are available for use | Message digest | Module initialization or on demand through API function call |
| SHA2-256 (A4778) | SHA-256 | KAT | CAST | The module becomes operational and the services are available for use | Message digest | Module initialization or on demand through API function call |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | Conditions |
|---|---|---|---|---|---|---|
| SHA2-384 (A4773) | SHA-384 | KAT | CAST | The module becomes operational and the services are available for use | Message digest | Module initialization or on demand through API function call |
| SHA2-384 (A4774) | SHA-384 | KAT | CAST | The module becomes operational and the services are available for use | Message digest | Module initialization or on demand through API function call |
| SHA2-384 (A4776) | SHA-384 | KAT | CAST | The module becomes operational and the services are available for use | Message digest | Module initialization or on demand through API function call |
| SHA2-384 (A4777) | SHA-384 | KAT | CAST | The module becomes operational and the services are available for use | Message digest | Module initialization or on demand through API function call |
| SHA2-384 (A4778) | SHA-384 | KAT | CAST | The module becomes operational and the services are available for use | Message digest | Module initialization or on demand through API function call |
| SHA2-512 (A4773) | SHA-512 | KAT | CAST | The module becomes operational and the services are available for use | Message digest | Module initialization or on demand through API function call |
| SHA2-512 (A4774) | SHA-512 | KAT | CAST | The module becomes operational and the services are available for use | Message digest | Module initialization or on demand through API function call |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | Conditions |
|---|---|---|---|---|---|---|
| SHA2-512 (A4776) | SHA-512 | KAT | CAST | The module becomes operational and the services are available for use | Message digest | Module initialization or on demand through API function call |
| SHA2-512 (A4778) | SHA-512 | KAT | CAST | The module becomes operational and the services are available for use | Message digest | Module initialization or on demand through API function call |
| PBKDF (A4773) | SHA-1 password length 24 characters, master key length of 200 bits, iteration count of 4096, and salt length of 288 bits; SHA-256 password length 24 characters, master key length of 320 bits, iteration count of 4096, and salt length of 288 bits | KAT | CAST | The module becomes operational and the services are available for use | Key derivation | Module initialization or on demand through API function call |
| PBKDF (A4774) | SHA-1 password length 24 characters, master key length of 200 bits, iteration count of 4096, and salt length of 288 bits; SHA-256 password length 24 characters, master key length of 320 bits, iteration count of 4096, and salt length of 288 bits | KAT | CAST | The module becomes operational and the services are available for use | Key derivation | Module initialization or on demand through API function call |
| PBKDF (A4776) | SHA-1 password length 24 characters, master key length of 200 bits, iteration count of 4096, and salt length of 288 bits; SHA-256 password length 24 characters, master key length of 320 bits, iteration count of 4096, and salt length of 288 bits | KAT | CAST | The module becomes operational and the services are available for use | Key derivation | Module initialization or on demand through API function call |
| PBKDF (A4777) | SHA-1 password length 24 characters, master key length of 200 bits, | KAT | CAST | The module becomes operational | Key derivation | Module initialization or on demand |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Algorithm or Test | Test Properties iteration count of 4096, and salt length of 288 bits; SHA-256 password length 24 characters, master key length of 320 bits, iteration count of 4096, and salt length of 288 bits | Test Method | Test Type | Indicator and the services are available for use | Details | Conditions through API function call |
|---|---|---|---|---|---|---|
| PBKDF (A4778) | SHA-1 password length 24 characters, master key length of 200 bits, iteration count of 4096, and salt length of 288 bits; SHA-256 password length 24 characters, master key length of 320 bits, iteration count of 4096, and salt length of 288 bits | KAT | CAST | The module becomes operational and the services are available for use | Key derivation | Module initialization or on demand through API function call |
| ECDSA KeyGen (FIPS186-4) (A4773) | Signature generation and verification with SHA-256 | PCT | PCT | Successful key generation | Key generation | EC key pair generation |
| ECDSA KeyGen (FIPS186-4) (A4774) | Signature generation and verification with SHA-256 | PCT | PCT | Successful key generation | Key generation | EC key pair generation |
| ECDSA KeyGen (FIPS186-4) (A4776) | Signature generation and verification with SHA-256 | PCT | PCT | Successful key generation | Key generation | EC key pair generation |
| ECDSA KeyGen (FIPS186-4) (A4777) | Signature generation and verification with SHA-256 | PCT | PCT | Successful key generation | Key generation | EC key pair generation |
| ECDSA KeyGen (FIPS186-4) (A4778) | Signature generation and verification with SHA-256 | PCT | PCT | Successful key generation | Key generation | EC key pair generation |
| RSA KeyGen (FIPS186-4) (A4773) | Signature generation of verification with SHA-256 | PCT | PCT | Successful key generation | Key generation | RSA key pair generation |
| RSA KeyGen (FIPS186-4) (A4774) | Signature generation of verification with SHA-256 | PCT | PCT | Successful key generation | Key generation | RSA key pair generation |
| RSA KeyGen | Signature generation of verification with SHA-256 | PCT | PCT | Successful key generation | Key generation | RSA key pair generation |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | Conditions |
|---|---|---|---|---|---|---|
| (FIPS186-4) (A4776) | ||||||
| RSA KeyGen (FIPS186-4) (A4777) | Signature generation of verification with SHA-256 | PCT | PCT | Successful key generation | Key generation | RSA key pair generation |
| RSA KeyGen (FIPS186-4) (A4778) | Signature generation of verification with SHA-256 | PCT | PCT | Successful key generation | Key generation | RSA key pair generation |
| Algorithm or Test | Test Method | Test Type | Period | Periodic Method | |||||
|---|---|---|---|---|---|---|---|---|---|
| HMAC-SHA2-256 (A4773) | Message Authentication | SW/FW Integrity | Whenever module is powered on | Upon every power on |
| Algorithm or Test | Test Method | Test Type | Period | Periodic Method |
|---|---|---|---|---|
| AES-ECB (A4773) | KAT | CAST | On demand | Manually |
| AES-ECB (A4774) | KAT | CAST | On demand | Manually |
| AES-ECB (A4776) | KAT | CAST | On demand | Manually |
| AES-ECB (A4777) | KAT | CAST | On demand | Manually |
| AES-CMAC (A4773) | KAT | CAST | On demand | Manually |
| AES-CMAC (A4774) | KAT | CAST | On demand | Manually |
| AES-CMAC (A4776) | KAT | CAST | On demand | Manually |
| AES-CMAC (A4777) | KAT | CAST | On demand | Manually |
| Counter DRBG (A4773) | KAT | CAST | On demand | Manually |
| Counter DRBG (A4774) | KAT | CAST | On demand | Manually |
| Counter DRBG (A4776) | KAT | CAST | On demand | Manually |
| Counter DRBG (A4777) | KAT | CAST | On demand | Manually |
| Hash DRBG (A4773) | KAT | CAST | On demand | Manually |
| Hash DRBG (A4774) | KAT | CAST | On demand | Manually |
| Hash DRBG (A4776) | KAT | CAST | On demand | Manually |
| Hash DRBG (A4777) | KAT | CAST | On demand | Manually |
| Hash DRBG (A4778) | KAT | CAST | On demand | Manually |
| Hash DRBG (A4773) | KAT | CAST | On demand | Manually |
| Hash DRBG (A4774) | KAT | CAST | On demand | Manually |
| Hash DRBG (A4776) | KAT | CAST | On demand | Manually |
Table 21: Conditional Self-Tests The module performs self-tests on all approved cryptographic algorithms as part of the approved services supported in the approved mode of operation, using the tests shown in table above. Services are not available, and data output (via the data output interface) is inhibited during the self-tests. If any of these tests fails, the module transitions to the Error state.
Table 22: Pre-Operational Periodic Information Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Algorithm or Test | Test Method | Test Type | Period | Periodic Method |
|---|---|---|---|---|
| Hash DRBG (A4777) | KAT | CAST | On demand | Manually |
| Hash DRBG (A4778) | KAT | CAST | On demand | Manually |
| HMAC DRBG (A4773) | KAT | CAST | On demand | Manually |
| HMAC DRBG (A4774) | KAT | CAST | On demand | Manually |
| HMAC DRBG (A4776) | KAT | CAST | On demand | Manually |
| HMAC DRBG (A4777) | KAT | CAST | On demand | Manually |
| HMAC DRBG (A4778) | KAT | CAST | On demand | Manually |
| ECDSA SigGen (FIPS186-4) (A4773) | KAT | CAST | On demand | Manually |
| ECDSA SigGen (FIPS186-4) (A4774) | KAT | CAST | On demand | Manually |
| ECDSA SigGen (FIPS186-4) (A4776) | KAT | CAST | On demand | Manually |
| ECDSA SigGen (FIPS186-4) (A4777) | KAT | CAST | On demand | Manually |
| ECDSA SigGen (FIPS186-4) (A4778) | KAT | CAST | On demand | Manually |
| ECDSA SigVer (FIPS186-4) (A4773) | KAT | CAST | On demand | Manually |
| ECDSA SigVer (FIPS186-4) (A4774s) | KAT | CAST | On demand | Manually |
| ECDSA SigVer (FIPS186-4) (A4776) | KAT | CAST | On demand | Manually |
| ECDSA SigVer (FIPS186-4) (A4777) | KAT | CAST | On demand | Manually |
| ECDSA SigVer (FIPS186-4) (A4778) | KAT | CAST | On demand | Manually |
| HMAC-SHA-1 (A4772) | KAT | CAST | On demand | Manually |
| HMAC-SHA-1 (A4773) | KAT | CAST | On demand | Manually |
| HMAC-SHA-1 (A4774) | KAT | CAST | On demand | Manually |
| HMAC-SHA-1 (A4776) | KAT | CAST | On demand | Manually |
| HMAC-SHA-1 (A4777) | KAT | CAST | On demand | Manually |
| HMAC-SHA-1 (A4778) | KAT | CAST | On demand | Manually |
| HMAC-SHA2-224 (A4773) | KAT | CAST | On demand | Manually |
| HMAC-SHA2-224 (A4774) | KAT | CAST | On demand | Manually |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Algorithm or Test | Test Method | Test Type | Period | Periodic Method |
|---|---|---|---|---|
| HMAC-SHA2-224 (A4776) | KAT | CAST | On demand | Manually |
| HMAC-SHA2-224 (A4777) | KAT | CAST | On demand | Manually |
| HMAC-SHA2-224 (A4778) | KAT | CAST | On demand | Manually |
| HMAC-SHA2-256 (A4773) | KAT | CAST | On demand | Manually |
| HMAC-SHA2-256 (A4774) | KAT | CAST | On demand | Manually |
| HMAC-SHA2-256 (A4776) | KAT | CAST | On demand | Manually |
| HMAC-SHA2-256 (A4777) | KAT | CAST | On demand | Manually |
| HMAC-SHA2-256 (A4778) | KAT | CAST | On demand | Manually |
| HMAC-SHA2-384 (A4773) | KAT | CAST | On demand | Manually |
| HMAC-SHA2-384 (A4774) | KAT | CAST | On demand | Manually |
| HMAC-SHA2-384 (A4776) | KAT | CAST | On demand | Manually |
| HMAC-SHA2-384 (A4777) | KAT | CAST | On demand | Manually |
| HMAC-SHA2-384 (A4778) | KAT | CAST | On demand | Manually |
| HMAC-SHA2-512 (A4773) | KAT | CAST | On demand | Manually |
| HMAC-SHA2-512 (A4774) | KAT | CAST | On demand | Manually |
| HMAC-SHA2-512 (A4776) | KAT | CAST | On demand | Manually |
| HMAC-SHA2-512 (A4777) | KAT | CAST | On demand | Manually |
| HMAC-SHA2-512 (A4778) | KAT | CAST | On demand | Manually |
| HMAC-SHA3-224 (A4773) | KAT | CAST | On demand | Manually |
| HMAC-SHA3-224 (A4774) | KAT | CAST | On demand | Manually |
| HMAC-SHA3-224 (A4773) | KAT | CAST | On demand | Manually |
| HMAC-SHA3-256 (A4773) | KAT | CAST | On demand | Manually |
| HMAC-SHA3-256 (A4774) | KAT | CAST | On demand | Manually |
| HMAC-SHA3-256 (A4778) | KAT | CAST | On demand | Manually |
| HMAC-SHA3-384 (A4773) | KAT | CAST | On demand | Manually |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Algorithm or Test | Test Method | Test Type | Period | Periodic Method |
|---|---|---|---|---|
| HMAC-SHA3-384 (A4774) | KAT | CAST | On demand | Manually |
| HMAC-SHA3-384 (A4778) | KAT | CAST | On demand | Manually |
| HMAC-SHA3-512 (A4773) | KAT | CAST | On demand | Manually |
| HMAC-SHA3-512 (A4774) | KAT | CAST | On demand | Manually |
| HMAC-SHA3-512 (A4778) | KAT | CAST | On demand | Manually |
| RSA SigGen (FIPS186-4) (A4773) | KAT | CAST | On demand | Manually |
| RSA SigGen (FIPS186-4) (A4774) | KAT | CAST | On demand | Manually |
| RSA SigGen (FIPS186-4) (A4776) | KAT | CAST | On demand | Manually |
| RSA SigGen (FIPS186-4) (A4777) | KAT | CAST | On demand | Manually |
| RSA SigGen (FIPS186-4) (A4778) | KAT | CAST | On demand | Manually |
| RSA SigVer (FIPS186-4) (A4773) | KAT | CAST | On demand | Manually |
| RSA SigVer (FIPS186-4) (A4774) | KAT | CAST | On demand | Manually |
| RSA SigVer (FIPS186-4) (A4776) | KAT | CAST | On demand | Manually |
| RSA SigVer (FIPS186-4) (A4777) | KAT | CAST | On demand | Manually |
| RSA SigVer (FIPS186-4) (A4778) | KAT | CAST | On demand | Manually |
| SHA-1 (A4772) | KAT | CAST | On demand | Manually |
| SHA-1 (A4773) | KAT | CAST | On demand | Manually |
| SHA-1 (A4774) | KAT | CAST | On demand | Manually |
| SHA-1 (A4775) | KAT | CAST | On demand | Manually |
| SHA-1 (A4776) | KAT | CAST | On demand | Manually |
| SHA-1 (A4777) | KAT | CAST | On demand | Manually |
| SHA-1 (A4778) | KAT | CAST | On demand | Manually |
| SHA2-224 (A4773) | KAT | CAST | On demand | Manually |
| SHA2-224 (A4774) | KAT | CAST | On demand | Manually |
| SHA2-224 (A4776) | KAT | CAST | On demand | Manually |
| SHA2-224 (A4777) | KAT | CAST | On demand | Manually |
| SHA2-224 (A4778) | KAT | CAST | On demand | Manually |
| SHA2-256 (A4773) | KAT | CAST | On demand | Manually |
| SHA2-256 (A4774) | KAT | CAST | On demand | Manually |
| SHA2-256 (A4776) | KAT | CAST | On demand | Manually |
| SHA2-256 (A4777) | KAT | CAST | On demand | Manually |
| SHA2-256 (A4778) | KAT | CAST | On demand | Manually |
| SHA2-384 (A4773) | KAT | CAST | On demand | Manually |
| SHA2-384 (A4774) | KAT | CAST | On demand | Manually |
| SHA2-384 (A4776) | KAT | CAST | On demand | Manually |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| Algorithm or Test | Test Method | Test Type | Period | Periodic Method |
|---|---|---|---|---|
| SHA2-384 (A4777) | KAT | CAST | On demand | Manually |
| SHA2-384 (A4778) | KAT | CAST | On demand | Manually |
| SHA2-512 (A4773) | KAT | CAST | On demand | Manually |
| SHA2-512 (A4774) | KAT | CAST | On demand | Manually |
| SHA2-512 (A4776) | KAT | CAST | On demand | Manually |
| SHA2-512 (A4778) | KAT | CAST | On demand | Manually |
| PBKDF (A4773) | KAT | CAST | On demand | Manually |
| PBKDF (A4774) | KAT | CAST | On demand | Manually |
| PBKDF (A4776) | KAT | CAST | On demand | Manually |
| PBKDF (A4777) | KAT | CAST | On demand | Manually |
| PBKDF (A4778) | KAT | CAST | On demand | Manually |
| ECDSA KeyGen (FIPS186-4) (A4773) | PCT | PCT | Upon generation of an ECDSA key pair | Upon generation of an ECDSA key pair |
| ECDSA KeyGen (FIPS186-4) (A4774) | PCT | PCT | Upon generation of an ECDSA key pair | Upon generation of an ECDSA key pair |
| ECDSA KeyGen (FIPS186-4) (A4776) | PCT | PCT | Upon generation of an ECDSA key pair | Upon generation of an ECDSA key pair |
| ECDSA KeyGen (FIPS186-4) (A4777) | PCT | PCT | Upon generation of an ECDSA key pair | Upon generation of an ECDSA key pair |
| ECDSA KeyGen (FIPS186-4) (A4778) | PCT | PCT | Upon generation of an ECDSA key pair | Upon generation of an ECDSA key pair |
| RSA KeyGen (FIPS186-4) (A4773) | PCT | PCT | Upon generation of an RSA key pair | Upon generation of an RSA key pair |
| RSA KeyGen (FIPS186-4) (A4774) | PCT | PCT | Upon generation of an RSA key pair | Upon generation of an RSA key pair |
| RSA KeyGen (FIPS186-4) (A4776) | PCT | PCT | Upon generation of an RSA key pair | Upon generation of an RSA key pair |
| RSA KeyGen (FIPS186-4) (A4777) | PCT | PCT | Upon generation of an RSA key pair | Upon generation of an RSA key pair |
| RSA KeyGen (FIPS186-4) (A4778) | PCT | PCT | Upon generation of an RSA key pair | Upon generation of an RSA key pair |
| Name | Description | Conditions | Recovery Method | Indicator |
|---|---|---|---|---|
| Error State | The module immediately stops functioning due to a self-test failure; PCT failure | Software integrity test failure CAST failure PCT failure | Restarting the module | Module will not load; Module stops functioning for PCT failure |
| Fatal Error State | The module immediately enters a non-recoverable error state and automatically transits to shutdown | Random numbers are requested in the error state or cipher operations are requested on a deallocated handle | Restarting the module | Module is aborted and is not available for use |
Table 23: Conditional Periodic Information
Table 24: Error States The table above shows the error codes and the corresponding condition. When the module fails any preOracle Linux 9 libgcrypt Cryptographic Module Security Policy
enter the Error state. Any further cryptographic operation is inhibited. The calling application can obtain the module state by calling the gcry_control(GCRYCTL_OPERATIONAL_P) API function. The function returns FALSE if the module is in the Error state and TRUE if the module is in the Operational state. In the Error state, all data output is inhibited, no cryptographic operation is allowed, and the module accepts no more inputs or requests (as the module is no longer running). Recovery from the Error state includes restarting (i.e., powering off and powering on) of the module or running self-tests. Recovery from the Fatal Error state can only be done by restarting the module.
The software integrity tests, cryptographic algorithm self-tests, and entropy source start-up tests can be invoked on demand by unloading and subsequently re-initializing the module. The pair-wise consistency tests can be invoked on demand by requesting the key pair generation service. Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
The module is distributed as part of the Oracle Linux 9 (OL9) RPM package in the form of libgcrypt1.10.0-10.0.1.el9_2_fips RPM package that is located in the “Oracle Linux 9 Security Validation (Update 3)” yum repository (ol9_u3_security_validation). The operational environment needs to be set up in the FIPS validated configuration by installing the module as follows:
The binaries of the module are contained in the RPM packages for delivery. The Crypto Officer shall follow Section 11.1 to configure the operational environment and install the module to be operated as a FIPS 140-3 validated module. The following RPM packages contain the FIPS validated module:
There is no non-administrator guidance.
As the module does not persistently store SSPs, secure sanitization of the module consists of unloading the module. This will zeroize all SSPs in volatile memory. Then, if desired, the libgcrypt-1.10.010.0.1.el9_2_fips RPM packages can be uninstalled from the Oracle Linux 9 system. Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
The module implements blinding against RSA Timing Attacks. RSA is vulnerable to timing attacks. In a setup where attackers can measure the time of RSA decryption or signature operations, blinding must be used to protect the RSA operation from that attack.
By default, the module uses the following blinding technique: instead of using the RSA decryption directly, a blinded value y = x re mod n is decrypted and the unblinded value x' = y' r−1 mod n returned. The blinding value r is a random value with the size of the modulus n. Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| curve | d | data | e | ecdsa | flags | sig-val |
|---|---|---|---|---|---|---|
| genkey | hash | n | nbits | pkcs1 | private-key | value |
| pss | public-key | q | r | raw | rsa | salt-length |
| rsa-use-e | s |
Listed below are the approved public key flags for an input s-expression: Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| AES | Advanced Encryption Standard |
|---|---|
| AES-NI | Advanced Encryption Standard New Instructions |
| API | Application Programming Interface |
| CAST | Cryptographic Algorithm Self-Test |
| CAVP | Cryptographic Algorithm Validation Program |
| CBC | Cipher Block Chaining |
| CCM | Counter with Cipher Block Chaining-Message Authentication Code |
| CFB | Cipher Feedback |
| CMAC | Cipher-based Message Authentication Code |
| CMVP | Cryptographic Module Validation Program |
| CSP | Critical Security Parameter |
| CTR | Counter |
| DRBG | Deterministic Random Bit Generator |
| ECB | Electronic Code Book |
| ECDH | Elliptic Curve Diffie-Hellman |
| ECDSA | Elliptic Curve Digital Signature Algorithm |
| FIPS | Federal Information Processing Standards |
| GCM | Galois Counter Mode |
| HMAC | Keyed-Hash Message Authentication Code |
| KAT | Known Answer Test |
| MAC | Message Authentication Code |
| NIST | National Institute of Science and Technology |
| PAA | Processor Algorithm Acceleration |
| PBKDF2 | Password-based Key Derivation Function v2 |
| PKCS | Public-Key Cryptography Standards |
| RSA | Rivest, Shamir, Adleman |
| SHA | Secure Hash Algorithm |
| SSP | Sensitive Security Parameter |
| XTS | XEX-based Tweaked-codebook mode with cipher text Stealing |
Appendix B. Glossary and Abbreviations Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| FIPS 140-3 | FIPS PUB 140-3 - Security Requirements For Cryptographic Modules March 2019 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-3.pdf |
|---|---|
| FIPS 140-3 IG | Implementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program https://csrc.nist.gov/Projects/cryptographic-module-validation-program/fips-140-3-ig- announcements |
| FIPS 180-4 | Secure Hash Standard (SHS) March 2012 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf |
| FIPS 186-4 | Digital Signature Standard (DSS) July 2013 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-4.pdf |
| FIPS 186-5 | Digital Signature Standard (DSS) February 2023 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-5.pdf |
| FIPS 197 | Advanced Encryption Standard November 2001 https://csrc.nist.gov/publications/fips/fips197/fips-197.pdf |
| FIPS 198-1 | The Keyed Hash Message Authentication Code (HMAC) July 2008 https://csrc.nist.gov/publications/fips/fips198-1/FIPS-198-1_final.pdf |
| FIPS 202 | SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions August 2015 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.202.pdf |
| SP 800-38A | Recommendation for Block Cipher Modes of Operation Methods and Techniques December 2001 https://csrc.nist.gov/publications/nistpubs/800-38a/sp800-38a.pdf |
| SP 800-38B | Recommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication May 2005 https://csrc.nist.gov/publications/nistpubs/800-38B/SP_800-38B.pdf |
| SP 800-38F | Recommendation for Block Cipher Modes of Operation: Methods for Key Wrapping December 2012 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38F.pdf |
| SP 800-56Ar3 | Recommendation for Pair-Wise Key Establishment Schemes Using Discrete Logarithm Cryptography April 2018 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Ar3.pdf |
| SP 800-90Ar1 | Recommendation for Random Number Generation Using Deterministic Random Bit Generators June 2015 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90Ar1.pdf |
| SP 800-90B | Recommendation for the Entropy Sources Used for Random Bit Generation January 2018 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90B.pdf |
| SP 800-108r1 | NIST Special Publication 800-108 - Recommendation for Key Derivation Using Pseudorandom Functions August 2022 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-108r1.pdf |
Appendix C. References Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
| SP 800-132 | Recommendation for Password-Based Key Derivation - Part 1: Storage Applications December 2010 https://csrc.nist.gov/publications/nistpubs/800-132/nist-sp800-132.pdf |
|---|---|
| SP 800-133r2 | Recommendation for Cryptographic Key Generation June 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-133r2.pdf |
| SP 800-135r1 | Recommendation for Existing Application-Specific Key Derivation Functions December 2011 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-135r1.pdf |
Oracle Linux 9 libgcrypt Cryptographic Module Security Policy