All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Oracle Linux 9 libgcrypt Cryptographic Module

Certificate#4993StandardFIPS 140-3Level1TypeSoftwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorOracle Corporation
Low review priority  ·  no TCB surface named  ·  libgcrypt upstream has published 2 CVEs since this module's initial validation  ·  last validated 8 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date3/27/2030
CaveatWhen operated in approved mode. When installed, initialized and configured as specified in Section 11.1 of the Security Policy. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.
VendorOracle Corporation

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Oracle Linux 9 libgcrypt Cryptographic Module
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Recovery<br/>Update</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Status Output</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>HTTPS<br/>no library/version identified</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Oracle Linux 9 libgcrypt Cryptographic Module
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Recovery<br/>Update</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Status Output</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>HTTPS<br/>no library/version identified</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Oracle Corporation Oracle Linux 9 libgcrypt Cryptographic Module Software Version: 1.10.0-3957adb8de08b15a Prepared by: atsec information security corporation

4516 Seton Center Parkway, Suite 250

Austin, TX 78759 www.atsec.com Document Version 1.4. ©Oracle Corporation

Page 2

Title: Oracle Linux 9 libgcrypt Cryptographic Module Security Policy Date: October 1st, 2025 Contributing Authors: Oracle Linux Engineering Security Evaluations – Global Product Security atsec information security Oracle Corporation World Headquarters

2300 Oracle Way

Austin, TX 78741 U.S.A. Worldwide Inquiries: Phone: +1.650.506.7000 Fax: +1.650.506.7200 www.oracle.com hereof are subject to change without notice. This document is not warranted to be error-free, nor subject to any other warranties or conditions, whether expressed orally or implied in law, including implied warranties and conditions of merchantability or fitness for a particular purpose. Oracle specifically disclaim any liability with respect to this document and no contractual obligations are formed either Oracle and Java are registered trademarks of Oracle and/or its affiliates. Other names may be trademarks of their respective owners. Oracle Linux 9 libgcrypt Cryptographic Module Security Policy i

Page 3
Table of Contents
#SectionPage
Page 4

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy iii

Page 5
List of Tables
ItemPage
Table 1: Security Levels1
Table 2: Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets)3
Table 3: Tested Operational Environments - Software, Firmware, Hybrid3
Table 4: Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid4
Table 5: Modes List and Description4
Table 6: Approved Algorithms19
Table 7: Vendor-Affirmed Algorithms20
Table 8: Non-Approved, Not Allowed Algorithms20
Table 9: Security Function Implementations25
Table 10: Entropy Certificates25
Table 11: Ports and Interfaces27
Table 12: Roles28
Table 13: Approved Services31
Table 14: Non-Approved Services32
Table 15: Storage Areas38
Table 16: SSP Input-Output Methods38
Table 17: SSP Zeroization Methods39
Table 18: SSP Table 140
Table 19: SSP Table 242
Table 20: Pre-Operational Self-Tests43
Table 21: Conditional Self-Tests61
Table 22: Pre-Operational Periodic Information61
Table 23: Conditional Periodic Information65
Table 24: Error States65
Page 6
List of Figures
ItemPage
Figure 1: Block Diagram2
Page 7
SectionTitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication1
5Software/Firmware security1
6Operational environment1
7Physical securityN/A
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacks1
Overall Level1
1.1 Overview

This document is the non-proprietary FIPS 140-3 Security Policy for version 1.10.0-3957adb8de08b15a of the Oracle Linux 9 libgcrypt Cryptographic Module. It contains the security rules under which the module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for an overall Security Level 1 including this notice. Other documentation is proprietary to their authors.

1.1.1 How This Security Policy was Prepared

In preparing the Security Policy document, the laboratory formatted the vendor-supplied documentation for consolidation without altering the technical statements therein contained. The further refining of the Security Policy document was conducted iteratively throughout the conformance testing, wherein the Security Policy was submitted to the vendor, who would then edit, modify, and add technical contents. The vendor would also supply additional documentation, which the laboratory formatted into the existing Security Policy, and resubmitted to the vendor for their final editing.

1.2 Security Levels

Table 1: Security Levels Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 8
2 Cryptographic Module Specification
2.1 Description

Purpose and Use: The Oracle Linux 9 libgcrypt Cryptographic Module (hereafter referred to as “the module”) is a Software multi-chip standalone cryptographic module. The module is a software library implementing general purpose cryptographic algorithms. The module provides cryptographic services to applications running in the user space of the underlying operating system through an application program interface (API). Module Type: Software Module Embodiment: MultiChipStand Cryptographic Boundary: Figure 1 shows the cryptographic boundary of the module in orange, its interfaces with the operational environment and the flow of information between the module and operator (depicted through the arrows). The software component of the cryptographic module is listed in the Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets) table. Tested Operational Environment’s Physical Perimeter (TOEPP): The TOEPP of the module is defined as the general-purpose computer on which the module is installed. Figure 1: Block Diagram Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 9
Package or File NameSoftware/ Firmware VersionFeaturesIntegrity Test
libgcrypt.so.20.4.0 on Oracle Linux 9 with Intel(R) Xeon(R) Platinum 83581.10.0- 3957adb8de08b15aN/AHMAC-SHA-256
libgcrypt.so.20.4.0 on Oracle Linux 9 with AMD EPYC 7J131.10.0- 3957adb8de08b15aN/AHMAC-SHA-256
libgcrypt.so.20.4.0 on Oracle Linux 9 with Ampere(R) Altra(R) Q80- 301.10.0- 3957adb8de08b15aN/AHMAC-SHA-256
libgcrypt.so.20.4.0 on Oracle Linux 9 with OCTEON III1.10.0- 3957adb8de08b15aN/AHMAC-SHA-256
Operating SystemHardware PlatformProcessorsPAA/PAIHypervisor or Host OSVersion(s)
Oracle Linux 9ORACLE SERVER X9- 2cIntel(R) Xeon(R) Platinum 8358YesKVM on Oracle Linux 81.10.0- 3957adb8de08b15a
Oracle Linux 9ORACLE SERVER E4- 2cAMD EPYC 7J13YesKVM on Oracle Linux 81.10.0- 3957adb8de08b15a
Oracle Linux 9ORACLE SERVER A1- 2cAmpere(R) Altra(R) Q80-30YesKVM on Oracle Linux 81.10.0- 3957adb8de08b15a
Oracle Linux 9ORACLE SERVER X9- 2cIntel(R) Xeon(R) Platinum 8358NoKVM on Oracle Linux 81.10.0- 3957adb8de08b15a
Oracle Linux 9ORACLE SERVER E4- 2cAMD EPYC 7J13NoKVM on Oracle Linux 81.10.0- 3957adb8de08b15a
Oracle Linux 9ORACLE SERVER A1- 2cAmpere(R) Altra(R) Q80-30NoKVM on Oracle Linux 81.10.0- 3957adb8de08b15a
Oracle Linux 9Marvell Liquid IO II (MIPS64) SmartNICOCTEON IIINoN/A1.10.0- 3957adb8de08b15a
Operating SystemHardware Platform
Oracle Linux 9Oracle X Series Servers
Oracle Linux 9Oracle E Series Servers
Oracle Linux 9Oracle A Series Servers
Oracle Linux 9Marvell T93 LiquidIO III (ARM v8.x) SmartNIC
Oracle Linux 9Pensando DSC-200-R (ARM v8.x) SmartNIC
2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification

Page 10
Operating SystemHardware Platform
Oracle Linux 9Nvidia Bluefield-3 (ARM v8.x) SmartNIC
Mode NameDescriptionTypeStatus Indicator
Approved modeAutomatically entered whenever an approved service is requestedApprovedEquivalent to the indicator of the requested service as defined in section 4.3
Non-approved modeAutomatically entered whenever a non-approved service is requestedNon- ApprovedEquivalent to the indicator of the requested service as defined in section 4.4
AlgorithmCAVP CertPropertiesReference
AES-CBCA4773Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBCA4774Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBCA4776Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBCA4777Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A

Table 4: Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid CMVP makes no statement as to the correct operation of the module or the security strengths of the generated keys when so ported if the specific operational environment is not listed on the validation certificate.

2.3 Excluded Components

There are no components within the cryptographic boundary excluded from the FIPS 140-3 requirements.

2.4 Modes of Operation

Modes List and Description: 4.3 4.4 Table 5: Modes List and Description Mode Change Instructions and Status: After passing all pre-operational self-test and cryptographic algorithm self-tests (CASTs) executed on start-up, the module automatically transitions to the approved mode. No operator intervention is required to reach this point. The module automatically switches between the approved and nonapproved modes.

2.5 Algorithms

Approved Algorithms: Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 11
AlgorithmCAVP CertPropertiesReference
AES-CCMA4773Key Length - 128, 192, 256 Tag Length - 112, 128, 32, 48, 64, 80, 96 IV Length - IV Length: 56, 64, 72, 80, 88, 96, 104 Payload Length - Payload Length: 0-256 Increment 8 AAD Length - AAD Length: 0, 256, 65536SP 800-38C
AES-CCMA4774Key Length - 128, 192, 256 Tag Length - 112, 128, 32, 48, 64, 80, 96 IV Length - IV Length: 56, 64, 72, 80, 88, 96, 104 Payload Length - Payload Length: 0-256 Increment 8 AAD Length - AAD Length: 0-524288 Increment 8, AAD Length: 0, 256, 65536SP 800-38C
AES-CCMA4776Key Length - 128, 192, 256 Tag Length - 112, 128, 32, 48, 64, 80, 96 IV Length - IV Length: 56, 64, 72, 80, 88, 96, 104 Payload Length - Payload Length: 0-256 Increment 8 AAD Length - AAD Length: 0, 256, 65536SP 800-38C
AES-CCMA4777Key Length - 128, 192, 256 Tag Length - 112, 128, 32, 48, 64, 80, 96 IV Length - IV Length: 56, 64, 72, 80, 88, 96, 104 Payload Length - Payload Length: 0-256 Increment 8 AAD Length - AAD Length: 0, 256, 65536SP 800-38C
AES-CFB128A4773Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB128A4774Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB128A4776Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB128A4777Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB8A4773Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB8A4774Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB8A4776Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB8A4777Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CMACA4773Direction - Generation, Verification Key Length - 128, 192, 256 MAC Length - MAC Length: 128 Message Length - Message Length: 8-524288 Increment 8SP 800-38B
AES-CMACA4774Direction - Generation, Verification Key Length - 128, 192, 256 MAC Length - MAC Length: 128 Message Length - Message Length: 8-524288 Increment 8SP 800-38B
AES-CMACA4776Direction - Generation, Verification Key Length - 128, 192, 256 MAC Length - MAC Length: 128 Message Length - Message Length: 8-524288 Increment 8SP 800-38B

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 12
AlgorithmCAVP CertPropertiesReference
AES-CMACA4777Direction - Generation, Verification Key Length - 128, 192, 256 MAC Length - MAC Length: 128 Message Length - Message Length: 8-524288 Increment 8SP 800-38B
AES-CTRA4773Direction - Decrypt, Encrypt Key Length - 128, 192, 256 Payload Length - Payload Length: 8-128 Increment 8 Supports Counter larger than maximum value - No Incremental Counter - Yes Counter Tests Performed - YesSP 800-38A
AES-CTRA4774Direction - Decrypt, Encrypt Key Length - 128, 192, 256 Payload Length - Payload Length: 8-128 Increment 8 Supports Counter larger than maximum value - No Incremental Counter - Yes Counter Tests Performed - YesSP 800-38A
AES-CTRA4776Direction - Decrypt, Encrypt Key Length - 128, 192, 256 Payload Length - Payload Length: 8-128 Increment 8 Supports Counter larger than maximum value - No Incremental Counter - Yes Counter Tests Performed - YesSP 800-38A
AES-CTRA4777Direction - Decrypt, Encrypt Key Length - 128, 192, 256 Payload Length - Payload Length: 8-128 Increment 8 Supports Counter larger than maximum value - No Incremental Counter - Yes Counter Tests Performed - YesSP 800-38A
AES-ECBA4773Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA4774Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA4776Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA4777Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-KWA4773Direction - Decrypt, Encrypt Cipher - Cipher Key Length - 128, 192, 256 Payload Length - Payload Length: 128-4096 Increment 128SP 800-38F
AES-KWA4774Direction - Decrypt, Encrypt Cipher - Cipher Key Length - 128, 192, 256 Payload Length - Payload Length: 128-4096 Increment 128SP 800-38F
AES-KWA4776Direction - Decrypt, Encrypt Cipher - Cipher Key Length - 128, 192, 256 Payload Length - Payload Length: 128-4096 Increment 128SP 800-38F
AES-KWA4777Direction - Decrypt, Encrypt Cipher - CipherSP 800-38F

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 13
AlgorithmCAVP CertProperties Key Length - 128, 192, 256 Payload Length - Payload Length: 128-4096 Increment 128Reference
AES-OFBA4773Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-OFBA4774Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-OFBA4776Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-OFBA4777Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-XTS Testing Revision 2.0A4773Direction - Decrypt, Encrypt Key Length - 128, 256 Payload Length - Payload Length: 128-65536 Increment 128 Tweak Mode - Hex Data Unit Length Matches Payload Length - YesSP 800-38E
AES-XTS Testing Revision 2.0A4774Direction - Decrypt, Encrypt Key Length - 128, 256 Payload Length - Payload Length: 128-65536 Increment 128, Payload Length: 128-65536 Increment 8 Tweak Mode - Hex Data Unit Length Matches Payload Length - YesSP 800-38E
AES-XTS Testing Revision 2.0A4776Direction - Decrypt, Encrypt Key Length - 128, 256 Payload Length - Payload Length: 128-65536 Increment 128 Tweak Mode - Hex Data Unit Length Matches Payload Length - YesSP 800-38E
AES-XTS Testing Revision 2.0A4777Direction - Decrypt, Encrypt Key Length - 128, 256 Payload Length - Payload Length: 128-65536 Increment 128 Tweak Mode - Hex Data Unit Length Matches Payload Length - YesSP 800-38E
Counter DRBGA4773Prediction Resistance - No, Yes Supports Reseed - No Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - Yes Additional Input - Additional Input: 0 Entropy Input - Entropy Input: 128, Entropy Input: 192, Entropy Input: 256 Nonce - Nonce: 128, Nonce: 64 Personalization String Length - Personalization String Length: 0 Returned Bits - 1024, 512SP 800-90A Rev. 1
Counter DRBGA4774Prediction Resistance - No, Yes Supports Reseed - No Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - Yes Additional Input - Additional Input: 0 Entropy Input - Entropy Input: 128, Entropy Input: 192, Entropy Input: 256 Nonce - Nonce: 128, Nonce: 64SP 800-90A Rev. 1

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 14
AlgorithmCAVP CertProperties Personalization String Length - Personalization String Length: 0 Returned Bits - 1024, 512Reference
Counter DRBGA4776Prediction Resistance - No, Yes Supports Reseed - No Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - Yes Additional Input - Additional Input: 0 Entropy Input - Entropy Input: 128, Entropy Input: 192, Entropy Input: 256 Nonce - Nonce: 128, Nonce: 64 Personalization String Length - Personalization String Length: 0 Returned Bits - 1024, 512SP 800-90A Rev. 1
Counter DRBGA4777Prediction Resistance - No, Yes Supports Reseed - No Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - Yes Additional Input - Additional Input: 0 Entropy Input - Entropy Input: 128, Entropy Input: 192, Entropy Input: 256 Nonce - Nonce: 128, Nonce: 64 Personalization String Length - Personalization String Length: 0 Returned Bits - 1024, 512SP 800-90A Rev. 1
ECDSA KeyGen (FIPS186-4)A4773Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - Testing CandidatesFIPS 186-4
ECDSA KeyGen (FIPS186-4)A4774Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - Testing CandidatesFIPS 186-4
ECDSA KeyGen (FIPS186-4)A4776Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - Testing CandidatesFIPS 186-4
ECDSA KeyGen (FIPS186-4)A4777Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - Testing CandidatesFIPS 186-4
ECDSA KeyGen (FIPS186-4)A4778Curve - P-224, P-256, P-384, P-521 Secret Generation Mode - Testing CandidatesFIPS 186-4
ECDSA KeyVer (FIPS186-4)A4773Curve - P-224, P-256, P-384, P-521FIPS 186-4
ECDSA KeyVer (FIPS186-4)A4774Curve - P-224, P-256, P-384, P-521FIPS 186-4
ECDSA KeyVer (FIPS186-4)A4776Curve - P-224, P-256, P-384, P-521FIPS 186-4
ECDSA KeyVer (FIPS186-4)A4777Curve - P-224, P-256, P-384, P-521FIPS 186-4
ECDSA KeyVer (FIPS186-4)A4778Curve - P-224, P-256, P-384, P-521FIPS 186-4
ECDSA SigGen (FIPS186-4)A4773Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512FIPS 186-4
ECDSA SigGen (FIPS186-4)A4774Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512,FIPS 186-4

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 15
AlgorithmCAVP CertProperties SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512Reference
ECDSA SigGen (FIPS186-4)A4776Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512FIPS 186-4
ECDSA SigGen (FIPS186-4)A4777Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512FIPS 186-4
ECDSA SigGen (FIPS186-4)A4778Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512FIPS 186-4
ECDSA SigVer (FIPS186-4)A4773Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512FIPS 186-4
ECDSA SigVer (FIPS186-4)A4774Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512FIPS 186-4
ECDSA SigVer (FIPS186-4)A4776Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512FIPS 186-4
ECDSA SigVer (FIPS186-4)A4777Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512FIPS 186-4
ECDSA SigVer (FIPS186-4)A4778Component - No Curve - P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512FIPS 186-4
Hash DRBGA4773Prediction Resistance - No, Yes Supports Reseed - No Mode - SHA-1, SHA2-256, SHA2-512 Entropy Input - Entropy Input: 160, Entropy Input: 256 Nonce - Nonce: 160, Nonce: 256 Personalization String Length - Personalization String Length: 0, 160, Personalization String Length: 0, 256 Additional Input - Additional Input: 0, 160, Additional Input: 0,SP 800-90A Rev. 1

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 16
AlgorithmCAVP CertProperties 256 Returned Bits - 320, 512, 768Reference
Hash DRBGA4774Prediction Resistance - No, Yes Supports Reseed - No Mode - SHA-1, SHA2-256, SHA2-512 Entropy Input - Entropy Input: 160, Entropy Input: 256 Nonce - Nonce: 160, Nonce: 256 Personalization String Length - Personalization String Length: 0, 160, Personalization String Length: 0, 256 Additional Input - Additional Input: 0, 160, Additional Input: 0, 256 Returned Bits - 320, 512, 768SP 800-90A Rev. 1
Hash DRBGA4776Prediction Resistance - No, Yes Supports Reseed - No Mode - SHA-1, SHA2-256, SHA2-512 Entropy Input - Entropy Input: 160, Entropy Input: 256 Nonce - Nonce: 160, Nonce: 256 Personalization String Length - Personalization String Length: 0, 160, Personalization String Length: 0, 256 Additional Input - Additional Input: 0, 160, Additional Input: 0, 256 Returned Bits - 320, 512, 768SP 800-90A Rev. 1
Hash DRBGA4777Prediction Resistance - No, Yes Supports Reseed - No Mode - SHA-1, SHA2-256, SHA2-512 Entropy Input - Entropy Input: 160, Entropy Input: 256 Nonce - Nonce: 160, Nonce: 256 Personalization String Length - Personalization String Length: 0, 160, Personalization String Length: 0, 256 Additional Input - Additional Input: 0, 160, Additional Input: 0, 256 Returned Bits - 320, 512, 768SP 800-90A Rev. 1
Hash DRBGA4778Prediction Resistance - No, Yes Supports Reseed - No Mode - SHA-1, SHA2-256, SHA2-512 Entropy Input - Entropy Input: 160, Entropy Input: 256 Nonce - Nonce: 160, Nonce: 256 Personalization String Length - Personalization String Length: 0, 160, Personalization String Length: 0, 256 Additional Input - Additional Input: 0, 160, Additional Input: 0, 256 Returned Bits - 320, 512, 768SP 800-90A Rev. 1
HMAC DRBGA4773Prediction Resistance - No, Yes Supports Reseed - No Mode - SHA-1, SHA2-256, SHA2-512 Entropy Input - Entropy Input: 160, Entropy Input: 256 Nonce - Nonce: 160, Nonce: 256 Personalization String Length - Personalization String Length: 0, 160, Personalization String Length: 0, 256 Additional Input - Additional Input: 0, 160, Additional Input: 0,SP 800-90A Rev. 1

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 17
AlgorithmCAVP CertProperties 256 Returned Bits - 320, 512, 768Reference
HMAC DRBGA4774Prediction Resistance - No, Yes Supports Reseed - No Mode - SHA-1, SHA2-256, SHA2-512 Entropy Input - Entropy Input: 160, Entropy Input: 256 Nonce - Nonce: 160, Nonce: 256 Personalization String Length - Personalization String Length: 0, 160, Personalization String Length: 0, 256 Additional Input - Additional Input: 0, 160, Additional Input: 0, 256 Returned Bits - 320, 512, 768SP 800-90A Rev. 1
HMAC DRBGA4776Prediction Resistance - No, Yes Supports Reseed - No Mode - SHA-1, SHA2-256, SHA2-512 Entropy Input - Entropy Input: 160, Entropy Input: 256 Nonce - Nonce: 160, Nonce: 256 Personalization String Length - Personalization String Length: 0, 160, Personalization String Length: 0, 256 Additional Input - Additional Input: 0, 160, Additional Input: 0, 256 Returned Bits - 320, 512, 768SP 800-90A Rev. 1
HMAC DRBGA4777Prediction Resistance - No, Yes Supports Reseed - No Mode - SHA-1, SHA2-256, SHA2-512 Entropy Input - Entropy Input: 160, Entropy Input: 256 Nonce - Nonce: 160, Nonce: 256 Personalization String Length - Personalization String Length: 0, 160, Personalization String Length: 0, 256 Additional Input - Additional Input: 0, 160, Additional Input: 0, 256 Returned Bits - 320, 512, 768SP 800-90A Rev. 1
HMAC DRBGA4778Prediction Resistance - No, Yes Supports Reseed - No Mode - SHA-1, SHA2-256, SHA2-512 Entropy Input - Entropy Input: 160, Entropy Input: 256 Nonce - Nonce: 160, Nonce: 256 Personalization String Length - Personalization String Length: 0, 160, Personalization String Length: 0, 256 Additional Input - Additional Input: 0, 160, Additional Input: 0, 256 Returned Bits - 320, 512, 768SP 800-90A Rev. 1
HMAC-SHA-1A4772MAC - MAC: 160 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA-1A4773MAC - MAC: 160 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA-1A4774MAC - MAC: 160 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA-1A4775MAC - MAC: 160 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 18
AlgorithmCAVP CertPropertiesReference
HMAC-SHA-1A4776MAC - MAC: 160 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA-1A4777MAC - MAC: 160 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA-1A4778MAC - MAC: 160 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-224A4773MAC - MAC: 224 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-224A4774MAC - MAC: 224 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-224A4776MAC - MAC: 224 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-224A4777MAC - MAC: 224 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-224A4778MAC - MAC: 224 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-256A4773MAC - MAC: 256 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-256A4774MAC - MAC: 256 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-256A4776MAC - MAC: 256 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-256A4777MAC - MAC: 256 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-256A4778MAC - MAC: 256 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-384A4773MAC - MAC: 384 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-384A4774MAC - MAC: 384 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-384A4776MAC - MAC: 384 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-384A4777MAC - MAC: 384 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-384A4778MAC - MAC: 384 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512A4773MAC - MAC: 512 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512A4774MAC - MAC: 512 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512A4776MAC - MAC: 512 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512A4777MAC - MAC: 512 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512A4778MAC - MAC: 512 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/224A4773MAC - MAC: 224 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 19
AlgorithmCAVP CertPropertiesReference
HMAC-SHA2- 512/224A4774MAC - MAC: 224 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/224A4776MAC - MAC: 224 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/224A4777MAC - MAC: 224 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/224A4778MAC - MAC: 224 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/256A4773MAC - MAC: 256 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/256A4774MAC - MAC: 256 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/256A4776MAC - MAC: 256 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/256A4777MAC - MAC: 256 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512/256A4778MAC - MAC: 256 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3-224A4773MAC - MAC: 224 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3-224A4774MAC - MAC: 224 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3-224A4778MAC - MAC: 224 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3-256A4773MAC - MAC: 256 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3-256A4774MAC - MAC: 256 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3-256A4778MAC - MAC: 256 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3-384A4773MAC - MAC: 384 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3-384A4774MAC - MAC: 384 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3-384A4778MAC - MAC: 384 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3-512A4773MAC - MAC: 512 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3-512A4774MAC - MAC: 512 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3-512A4778MAC - MAC: 512 Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
PBKDFA4773Iteration Count - Iteration Count: 1000-10000000 Increment 1 HMAC Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512 Password Length - Password Length: 8-128 Increment 1 Salt Length - Salt Length: 128-4096 Increment 8 Key Data Length - Key Data Length: 128-4096 Increment 8SP 800-132

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 20
AlgorithmCAVP CertPropertiesReference
PBKDFA4774Iteration Count - Iteration Count: 1000-10000000 Increment 1 HMAC Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512 Password Length - Password Length: 8-128 Increment 1 Salt Length - Salt Length: 128-4096 Increment 8 Key Data Length - Key Data Length: 128-4096 Increment 8SP 800-132
PBKDFA4776Iteration Count - Iteration Count: 1000-10000000 Increment 1 HMAC Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512 Password Length - Password Length: 8-128 Increment 1 Salt Length - Salt Length: 128-4096 Increment 8 Key Data Length - Key Data Length: 128-4096 Increment 8SP 800-132
PBKDFA4777Iteration Count - Iteration Count: 1000-10000000 Increment 1 HMAC Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512 Password Length - Password Length: 8-128 Increment 1 Salt Length - Salt Length: 128-4096 Increment 8 Key Data Length - Key Data Length: 128-4096 Increment 8SP 800-132
PBKDFA4778Iteration Count - Iteration Count: 1000-10000000 Increment 1 HMAC Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512 Password Length - Password Length: 8-128 Increment 1 Salt Length - Salt Length: 128-4096 Increment 8 Key Data Length - Key Data Length: 128-4096 Increment 8SP 800-132
RSA KeyGen (FIPS186-4)A4773Key Generation Mode - B.3.3 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Info Generated By Server - No Public Exponent Mode - Random Private Key Format - StandardFIPS 186-4
RSA KeyGen (FIPS186-4)A4774Key Generation Mode - B.3.3 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Info Generated By Server - No Public Exponent Mode - Random Private Key Format - StandardFIPS 186-4
RSA KeyGen (FIPS186-4)A4776Key Generation Mode - B.3.3 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Info Generated By Server - No Public Exponent Mode - Random Private Key Format - StandardFIPS 186-4
RSA KeyGen (FIPS186-4)A4777Key Generation Mode - B.3.3 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Info Generated By Server - NoFIPS 186-4

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 21
AlgorithmCAVP CertProperties Public Exponent Mode - Random Private Key Format - StandardReference
RSA KeyGen (FIPS186-4)A4778Key Generation Mode - B.3.3 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Info Generated By Server - No Public Exponent Mode - Random Private Key Format - StandardFIPS 186-4
RSA SigGen (FIPS186-4)A4773Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096 Hash Pair - Hash Algorithm - SHA2-224FIPS 186-4
RSA SigGen (FIPS186-4)A4774Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096 Hash Pair - Hash Algorithm - SHA2-224FIPS 186-4
RSA SigGen (FIPS186-4)A4776Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096 Hash Pair - Hash Algorithm - SHA2-224FIPS 186-4
RSA SigGen (FIPS186-4)A4777Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096 Hash Pair - Hash Algorithm - SHA2-224FIPS 186-4
RSA SigGen (FIPS186-4)A4778Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096 Hash Pair - Hash Algorithm - SHA2-224FIPS 186-4
RSA SigVer (FIPS186-2)A4773Public Exponent Mode - Fixed Fixed Public Exponent - 010001 Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024, 1536 Hash Pair - Hash Algorithm - SHA2-224 Salt Length - 28FIPS 186-4
RSA SigVer (FIPS186-2)A4774Public Exponent Mode - Fixed Fixed Public Exponent - 010001 Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024, 1536 Hash Pair - Hash Algorithm - SHA2-224 Salt Length - 28FIPS 186-4
RSA SigVer (FIPS186-2)A4776Public Exponent Mode - Fixed Fixed Public Exponent - 010001 Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024, 1536 Hash Pair - Hash Algorithm - SHA2-224 Salt Length - 28FIPS 186-4

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 22
AlgorithmCAVP CertPropertiesReference
RSA SigVer (FIPS186-2)A4777Public Exponent Mode - Fixed Fixed Public Exponent - 010001 Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024, 1536 Hash Pair - Hash Algorithm - SHA2-224 Salt Length - 28FIPS 186-4
RSA SigVer (FIPS186-2)A4778Public Exponent Mode - Fixed Fixed Public Exponent - 010001 Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024, 1536 Hash Pair - Hash Algorithm - SHA2-224 Salt Length - 28FIPS 186-4
RSA SigVer (FIPS186-4)A4773Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096 Hash Pair - Hash Algorithm - SHA2-224 Salt Length - 28 Public Exponent Mode - Fixed Fixed Public Exponent - 010001FIPS 186-4
RSA SigVer (FIPS186-4)A4774Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096 Hash Pair - Hash Algorithm - SHA2-224 Salt Length - 28 Public Exponent Mode - Fixed Fixed Public Exponent - 010001FIPS 186-4
RSA SigVer (FIPS186-4)A4776Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096 Hash Pair - Hash Algorithm - SHA2-224 Salt Length - 28 Public Exponent Mode - Fixed Fixed Public Exponent - 010001FIPS 186-4
RSA SigVer (FIPS186-4)A4777Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096 Hash Pair - Hash Algorithm - SHA2-224 Salt Length - 28 Public Exponent Mode - Fixed Fixed Public Exponent - 010001FIPS 186-4
RSA SigVer (FIPS186-4)A4778Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096 Hash Pair - Hash Algorithm - SHA2-224 Salt Length - 28 Public Exponent Mode - Fixed Fixed Public Exponent - 010001FIPS 186-4

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 23
AlgorithmCAVP CertPropertiesReference
SHA-1A4772Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA-1A4773Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA-1A4774Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA-1A4775Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA-1A4776Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA-1A4777Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA-1A4778Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-224A4773Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-224A4774Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-224A4776Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-224A4777Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-224A4778Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-256A4773Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-256A4774Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-256A4776Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-256A4777Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-256A4778Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-384A4773Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-384A4774Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-384A4776Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-384A4777Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-384A4778Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512A4773Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512A4774Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 24
AlgorithmCAVP CertPropertiesReference
SHA2-512A4776Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512A4777Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512A4778Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/224A4773Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/224A4774Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/224A4776Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/224A4777Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/224A4778Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/256A4773Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/256A4774Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/256A4776Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/256A4777Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512/256A4778Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA3-224A4773Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHA3-224A4774Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHA3-224A4778Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHA3-256A4773Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHA3-256A4774Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHA3-256A4778Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHA3-384A4773Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHA3-384A4774Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHA3-384A4778Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHA3-512A4773Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHA3-512A4774Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 25
AlgorithmCAVP CertPropertiesReference
SHA3-512A4778Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHAKE-128A4773Supports Bit-Oriented Messages - No Supports Empty Message - Yes Supports Bit-Oriented Output - No Output Length - Output Length: 16-65536 Increment 8FIPS 202
SHAKE-128A4774Supports Bit-Oriented Messages - No Supports Empty Message - Yes Supports Bit-Oriented Output - No Output Length - Output Length: 16-65536 Increment 8FIPS 202
SHAKE-128A4778Supports Bit-Oriented Messages - No Supports Empty Message - Yes Supports Bit-Oriented Output - No Output Length - Output Length: 16-65536 Increment 8FIPS 202
SHAKE-256A4773Supports Bit-Oriented Messages - No Supports Empty Message - Yes Supports Bit-Oriented Output - No Output Length - Output Length: 16-65536 Increment 8FIPS 202
SHAKE-256A4774Supports Bit-Oriented Messages - No Supports Empty Message - Yes Supports Bit-Oriented Output - No Output Length - Output Length: 16-65536 Increment 8FIPS 202
SHAKE-256A4778Supports Bit-Oriented Messages - No Supports Empty Message - Yes Supports Bit-Oriented Output - No Output Length - Output Length: 16-65536 Increment 8FIPS 202
NamePropertiesImplementationReference
CKGRSA:2048, 3072, 4096 (112, 128, 149 bits) ECDSA:P-224, P-256, P-384, P-512 (112, 128, 192, 256 bits)Oracle Linux 9 libgcrypt Cryptographic Module (Full Acceleration)FIPS 186-4, SP 800- 133rev2 Section 5.1
CKGRSA:2048, 3072, 4096 (112, 128, 149 bits) ECDSA:P-224, P-256, P-384, P-512 (112, 128, 192, 256 bits)Oracle Linux 9 libgcrypt Cryptographic Module (No Acceleration)FIPS 186-4, SP 800- 133rev2 Section 5.1
CKGRSA:2048, 3072, 4096 (112, 128, 149 bits) ECDSA:P-224, P-256, P-384. P-521 (112, 128, 192, 256 bits)Oracle Linux 9 libgcrypt Cryptographic Module (AESNI AVX)FIPS 186-4, SP 800- 133rev2 Section 5.1
CKGRSA:2048, 3072, 4096 (112, 128, 149 bits) ECDSA:P-224, P-256, P-384, P-521 (112, 128, 192, 256 bits)Oracle Linux 9 libgcrypt Cryptographic Module (SHLD)FIPS 186-4, SP 800- 133rev2 Section 5.1
CKGRSA:2048, 3072, 4096 (112, 128, 149 bits)Oracle Linux 9 libgcrypt Cryptographic Module (SSSE3)FIPS 186-4, SP 800- 133rev2 Section 5.1

Table 6: Approved Algorithms Vendor-Affirmed Algorithms:

Page 26
NamePropertiesImplementationReference
ECDSA:P-224, P-256, P-384, P-521 (112, 128, 192, 256 bits)
NameUse and Function
MD5Message digest
ECDH noncompliant with SP 800-56Arev3 assurancesShared secret computation
AES GCM noncompliant with IG C.H.Authenticated symmetric encryption, Authenticated symmetric decryption
AES GCM-SIVAuthenticated symmetric encryption, Authenticated symmetric decryption
AES OCBAuthenticated symmetric encryption, Authenticated symmetric decryption
AES-EAXAuthenticated symmetric encryption, Authenticated symmetric decryption
RSASignature generation primitive; Signature verification primitive; Encryption primitive; Decryption primitive
RSA with non-approved flags that are not listed in Appendix AKey generation; Signature generation; Signature verification
ECDSASignature generation primitives, Signature verification primitives
ECDSA with non-approved flags that are not listed in Appendix AKey generation; Key verification; Signature generation; Signature verification
NameTypeDescriptionPropertiesAlgorithms
Key wrapping using AES CCMKTS-WrapKey wrapping using AES CCMKey:128, 192, 256-bit keys with 128, 192, 256 bits of key strength, respectivelyAES-CCM: (A4773, A4774, A4776, A4777)
Key unwrapping using AES CCMKTS-WrapKey unwrapping using AES CCMKey:128, 192, 256-bit keys with 128, 192, 256 bits of key strength, respectivelyAES-CCM: (A4773, A4774, A4776, A4777)
Key wrapping using AES KWKTS-WrapKey wrapping using AES KWKey:128, 192, 256-bit keys with 128, 192, 256 bits of key strength, respectivelyAES-KW: (A4773, A4774, A4776, A4777)
Key unwrapping using AES KWKTS-WrapKey unwrapping using AES KWKey:128, 192, 256-bit keys with 128, 192, 256 bits of key strength, respectivelyAES-KW: (A4773, A4774, A4776, A4777)
Encryption with AESBC-UnAuthEncryption using AESKeys:128, 192, 256-bit keys with 128, 192, 256 bits of key strength, respectivelyAES-CBC: (A4773, A4774, A4776, A4777) AES-CFB128: (A4773, A4774,

Table 7: Vendor-Affirmed Algorithms

2.6 Security Function Implementations

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 27
NameTypeDescriptionPropertiesAlgorithms
A4776, A4777) AES-CFB8: (A4773, A4774, A4776, A4777) AES-CTR: (A4773, A4774, A4776, A4777) AES-ECB: (A4773, A4774, A4776, A4777) AES-OFB: (A4773, A4774, A4776, A4777) AES-XTS Testing Revision 2.0: (A4773, A4774, A4776, A4777)
Authenticated encryption with AESBC-AuthAuthenticated encryption using AESKeys:128, 192, 256-bit keys with 128, 192, 256 bits of key strength, respectivelyAES-CCM: (A4773, A4774, A4776, A4777) AES-KW: (A4773, A4774, A4776, A4777)
Decryption with AESBC-UnAuthDecryption using AESKeys:128, 192, 256-bit keys with 128, 192, 256 bits of key strength, respectivelyAES-CBC: (A4773, A4774, A4776, A4777) AES-CFB128: (A4773, A4774, A4776, A4777) AES-CFB8: (A4773, A4774, A4776, A4777) AES-CTR: (A4773, A4774, A4776, A4777) AES-ECB: (A4773, A4774, A4776, A4777) AES-OFB: (A4773, A4774, A4776, A4777) AES-XTS Testing Revision 2.0: (A4773, A4774, A4776, A4777)
Authenticated decryption with AESBC-AuthAuthenticated decryption using AESKeys:128, 192, 256-bit keys with 128, 192, 256 bits of key strength, respectivelyAES-CCM: (A4773, A4774, A4776, A4777) AES-KW: (A4773, A4774, A4776, A4777)

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 28
NameTypeDescriptionPropertiesAlgorithms
Key Pair Generation with RSACKGKey pair generation for RSAMode:B.3.3 Random Probable Primes Modulus:2048, 3072, 4096 bits (112, 128, 149 bits)RSA KeyGen (FIPS186-4): (A4773, A4774, A4776, A4777, A4778)
Key Pair Generation with ECDSACKGKey pair generation for ECDSAMode:B.4.2 Testing Candidates Curves:P-224, P-256, P-384, P-521 (112, 128, 192, 256 bits)ECDSA KeyGen (FIPS186-4): (A4773, A4774, A4776, A4777, A4778)
Public Key Verification with ECDSAAsymKeyPair- KeyVerVerify public key for ECDSACurves:P-224, P-256, P-384, P-521 (112, 128, 192, 256 bits)ECDSA KeyVer (FIPS186-4): (A4773, A4774, A4776, A4777, A4778)
Signature Generation with RSADigSig-SigGenDigital signature generation using RSAPadding:PKCS#1 v1.5, PSS Keys:2048, 3072, 4096 bits (112, 128, 149 bits) Hashes:SHA-224, SHA- 256, SHA-384, SHA- 512, SHA-512/224, SHA-512/256RSA SigGen (FIPS186-4): (A4773, A4774, A4776, A4777, A4778)
Signature Verification with RSADigSig-SigVerDigital signature verification using RSAPadding:PKCS#1 v1.5, PSS Keys:1024, 1536, 2048, 3072, 4096 bits (80, 96, 112, 128, 149 bits) Hashes:SHA-224, SHA- 256, SHA-384, SHA- 512, SHA-512/224, SHA-512/256RSA SigVer (FIPS186-4): (A4773, A4774, A4776, A4777, A4778) RSA SigVer (FIPS186-2): (A4773, A4774, A4776, A4777, A4778)
Signature Generation with ECDSADigSig-SigGenDigital signature generation using ECDSACurves:P-224, P-256, P-384, P-521 (112, 128, 192, 256 bits) Hashes:SHA-224, SHA- 256, SHA-384, SHA- 512, SHA-512/224, SHA-512/256, SHA3- 224, SHA3-256, SHA3- 384, SHA3-512ECDSA SigGen (FIPS186-4): (A4773, A4774, A4776, A4777, A4778)
Signature Verification with ECDSADigSig-SigVerDigital signature verification using ECDSACurves:P-224, P-256, P-384, P-521 (112, 128, 192, 256 bits) Hashes:SHA-224, SHA- 256, SHA-384, SHA- 512, SHA-512/224, SHA-512/256, SHA3-ECDSA SigVer (FIPS186-4): (A4773, A4774, A4776, A4777, A4778)

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 29
NameTypeDescriptionPropertiesAlgorithms
224, SHA3-256, SHA3- 384, SHA3-512
HashesSHACompute a message digest using Secure Hash AlgorithmsSHA-1: (A4772, A4773, A4774, A4775, A4776, A4777, A4778) SHA2-224: (A4773, A4774, A4776, A4777, A4778) SHA2-256: (A4773, A4774, A4776, A4777, A4778) SHA2-384: (A4773, A4774, A4776, A4777, A4778) SHA2-512: (A4773, A4774, A4776, A4777, A4778) SHA2-512/224: (A4773, A4774, A4776, A4777, A4778) SHA2-512/256: (A4773, A4774, A4776, A4777, A4778) SHA3-224: (A4773, A4774, A4778) SHA3-256: (A4773, A4774, A4778) SHA3-384: (A4773, A4774, A4778) SHA3-512: (A4773, A4774, A4778)
Extendable Output FunctionXOFCompute message digest from XOFsSHAKE-128: (A4773, A4774, A4778) SHAKE-256: (A4773, A4774, A4778)
Message Authentication CodeMACCompute MAC tags using AES-based CMAC or HMACKeys:112-256 bitsAES-CMAC: (A4773, A4774, A4776, A4777) HMAC-SHA-1: (A4772, A4773, A4774, A4775, A4776, A4777, A4778) HMAC-SHA2-224: (A4773, A4774, A4776, A4777,

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 30
NameTypeDescriptionPropertiesAlgorithms
A4778) HMAC-SHA2-256: (A4773, A4774, A4776, A4777, A4778) HMAC-SHA2-384: (A4773, A4774, A4776, A4777, A4778) HMAC-SHA2-512: (A4773, A4774, A4776, A4777, A4778) HMAC-SHA2- 512/224: (A4773, A4774, A4776, A4777, A4778) HMAC-SHA2- 512/256: (A4773, A4774, A4776, A4777, A4778) HMAC-SHA3-224: (A4773, A4774, A4778) HMAC-SHA3-256: (A4773, A4774, A4778) HMAC-SHA3-384: (A4773, A4774, A4778) HMAC-SHA3-512: (A4773, A4774, A4778)
Random Number Generation with DRBGDRBGRandom number generation using DRBGCompliance:Compliant with SP800-90Arev1Counter DRBG: (A4773, A4774, A4776, A4777) Hash DRBG: (A4773, A4774, A4776, A4777, A4778) HMAC DRBG: (A4773, A4774, A4776, A4777, A4778)
Key Derivation with PBKDFPBKDFKey derivation using PBKDFDerived keys:112-256 bits HMAC modes:SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2- 512/256, SHA3-224,PBKDF: (A4773, A4774, A4776, A4777, A4778)

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 31
NameTypeDescriptionPropertiesAlgorithms
SHA3-256, SHA3-384, SHA3-512
Cert NumberVendor Name
E99Oracle Corporation

Table 9: Security Function Implementations

2.7 Algorithm Specific Information
2.7.1 AES XTS

The length of a single data unit encrypted or decrypted with AES XTS shall not exceed 220 AES blocks, that is 16MB, of data per XTS instance. An XTS instance is defined in Section 4 of SP 800-38E. To meet the requirement stated in IG C.I, the module implements a check to ensure that the two AES keys used in AES XTS mode are not identical. The XTS mode shall only be used for the cryptographic protection of data on storage devices. It shall not be used for other purposes, such as the encryption of data in transit.

2.7.2 Key Derivation using SP 800-132 PBKDF

The module provides password-based key derivation (PBKDF), compliant with SP 800-132. The module supports option 1a from Section 5.4 of SP 800-132, in which the Master Key (MK) or a segment of it is used directly as the Data Protection Key (DPK). In accordance with SP 800-132 and FIPS 140-3 IG D.N, the following requirements shall be met.

2.8 RBG and Entropy

Table 10: Entropy Certificates N/A for this module. Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 32

The module provides an SP 800-90Arev1-compliant Deterministic Random Bit Generator (DRBG) for creation of key components of asymmetric keys, and random number generation. This entropy source is located within the module’s physical perimeter, but outside of the module’s cryptographic boundary. The module obtains 384 bits to seed the DRBG, and 256 bits to reseed it. The seeding (and automatic reseeding) of the DRBG is done with getrandom(). The DRBG supports the Hash_DRBG, HMAC_DRBG, and CTR_DRBG mechanisms. The DRBG is initialized during module initialization; the module loads by default the DRBG and using the HMAC_DRBG mechanism with SHA-256 and without prediction resistance. A different DRBG mechanism can be chosen by invoking the gcry_control(GCRYCTL_DRBG_REINIT) function. The module performs the DRBG health tests as defined in Section 11.3 of SP 800-90Arev1.

2.9 Key Generation

The module provides an SP 800-90Arev1-compliant DRBG for the creation of the key components of asymmetric keys, and random number generation. The Cryptographic Key Generation (CKG) methods implemented in the module for Approved Services in the approved mode are compliant with Section 5.1 of SP 800-133rev2. For generating RSA and ECDSA keys, the module implements asymmetric key generation services compliant with FIPS 186-4. A seed (i.e. the random value) used in asymmetric key generation is directly obtained from the SP 800-90Arev1 DRBG. Additionally, according to section 6.2 of SP 800-133rev2, the module implements the PBKDF2 key derivation method compliant with option 1a of SP 800-132. This implementation shall only be used to derive keys for use in storage applications.

2.10 Key Establishment

As permitted by IG D.G, the module provides key transport either by using an approved authenticated encryption mode or by a combination of any approved symmetric encryption mode and an approved authentication method. The SSP transport methods are specified in the Security Function Implementations table.

2.11 Industry Protocols

The module does not support any industry protocols listed within the publication of SP 800-135rev1. Therefore, this section is not applicable. Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 33
Physical PortLogical Interface(s)Data That Passes
N/AData InputAPI input parameters for data
N/AData OutputAPI output parameters for data
N/AControl InputAPI function calls, API input parameters for control input
N/AStatus OutputAPI return codes, API output parameters for status output
3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

Table 11: Ports and Interfaces The logical interfaces are the APIs through which the applications request services. These logical interfaces are logically separated from each other by the API design. The module does not implement a Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 34
NameTypeOperator TypeAuthentication Methods
Crypto OfficerRoleCONone
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Access
Symmetric encryptionPerform AES encryptio ngcry_control() returns 0AES key, PlaintextCipherte xtEncryption with AESCrypto Officer - AES key: W,E
Symmetric decryptionPerform AES decryptio ngcry_control() returns 0AES key, CiphertextPlaintextDecryption with AESCrypto Officer - AES key: W,E
Authentica ted symmetric encryptionAuthentic ate and encrypt a plaintext using AESgcry_control() returns 0AES key, Plaintext, IVCipherte xt, MAC tagAuthentica ted encryption with AESCrypto Officer - AES key: W,E
Authentica ted symmetric decryptionAuthentic ate and decrypt a plaintext using AESgcry_control() returns 0AES key, Ciphertext, MAC tagPlaintextAuthentica ted decryption with AESCrypto Officer - AES key: W,E
RSA Key generationGenerate RSA key pairsgcry_control() returns 0Key sizeRSA public key, RSA private keyKey Pair Generation with RSACrypto Officer - RSA public key: G,R - RSA private key: G,R
ECDSA Key generationGenerate ECDSA key pairsgcry_control() returns 0Key sizeECDSA public key, ECDSA private keyKey Pair Generation with ECDSACrypto Officer - ECDSA public key: G,R - ECDSA private key: G,R
RSA Digital signature generationRSA signature generatio ngcry_control() returns 0RSA private key, Message, Hash algorithmSignatur eSignature Generation with RSACrypto Officer - RSA private key: W,E
4 Roles, Services, and Authentication
4.2 Roles

Table 12: Roles The module supports the Crypto Officer role only. This sole role is implicitly and always assumed by the operator of the module. The module does not support multiple concurrent operators.

4.3 Approved Services

n W,E n W,E G,R Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 35
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Access
ECDSA Digital signature generationECDSA signature generatio ngcry_control() returns 0ECDSA private Key, Message, Hash algorithmSignatur eSignature Generation with ECDSACrypto Officer - ECDSA private key: W,E
RSA Digital signature verificationRSA signature verificatio ngcry_control() returns 0Signature, Hash algorithm, RSA public keySignatur e verificati on resultSignature Verification with RSACrypto Officer - RSA public key: W,E
ECDSA Digital signature verificationECDSA signature verificatio ngcry_control() returns 0Signature, Hash algorithm, ECDSA public keySignatur e verificati on resultSignature Verification with ECDSACrypto Officer - ECDSA public key: W,E
Public key verificationVerify ECDSA public keygcry_mpi_ec_curve_p oint() returns 0ECDSA public key, ECDSA private keyReturn codes/lo g message sPublic Key Verification with ECDSACrypto Officer - ECDSA public key: W,E
Random number generationGenerate random bitstringsgcry_randomize(), gcry_random_bytes(), gcry_random_bytes_s ecure() returns 0SizeRandom numberRandom Number Generation with DRBGCrypto Officer - Entropy input: W,E - DRBG seed: G,E - DRBG internal state: (V value, C value): G,W,E - DRBG internal state: (V value, key): G,W,E
Message digestCompute SHA hashesgcry_control() returns 0MessageMessage digestHashes Extendable Output FunctionCrypto Officer
Message authenticat ion code (MAC)Compute HMAC or AES- based CMACgcry_control() returns 0Message, KeyMAC tagMessage Authentica tion CodeCrypto Officer - HMAC key: W,E - AES key: W,E
Key wrappingPerform AES- based key wrappinggcry_control() returns 0Key wrapping key, key to be wrappedWrappe d keyKey wrapping using AES CCMCrypto Officer - AES key: W,E

W,E W,E s W,E G,E G,W,E G,W,E W,E Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 36
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Access
Key wrapping using AES KW
Key unwrappin gPerform AES- based key unwrappi nggcry_control() returns 0Wrapped key, key unwrapping keyUnwrap ped keyKey unwrappin g using AES CCM Key unwrappin g using AES KWCrypto Officer - AES key: W,E
Key derivationPerform key derivatio ngcry_control() returns 0Password/passph rase; Derived keyDerived keyKey Derivation with PBKDFCrypto Officer - Password or passphrase: W,E - Derived key: G,R
Show statusShow module statusN/ANoneCurrent status of the moduleNoneCrypto Officer
ZeroizationZeroize SSPsN/AN/AN/ANoneCrypto Officer - AES key: Z - HMAC key: Z - Password or passphrase: Z - Derived key: Z - Entropy input: Z - DRBG internal state: (V value, key): Z - DRBG internal state: (V value, C value): Z - DRBG seed: Z - ECDSA public key: Z

W,E Z Z Z Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 37
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Access - ECDSA private key: Z - RSA public key: Z - RSA private key: Z
Self-testsPerform self-testsN/ABooting the moduleN/ANoneUnauthentic ated
Show module name and versionShow module name and versionN/AN/ADisplay module name and versionNoneUnauthentic ated

Z Table 13: Approved Services For all approved services, GPG_ERR_NO_ERROR (i.e., “0”) return code indicates the service is approved. In case the above-mentioned controls are used in conjunction, the operator is responsible to check that all the called functions return GPG_ERR_NO_ERROR (i.e., “0”). For all non-approved services, a "nonzero" return code indicates the service is not approved. The table above lists the approved services. For each service, the table lists the associated cryptographic algorithm(s), the role to perform the service, the cryptographic keys or CSPs involved, and their access type(s). The following convention is used to specify access rights to SSPs: • Generate (G): The module generates or derives the SSP. • Read (R): The SSP is read from the module (e.g. the SSP is output). • Write (W): The SSP is updated, imported, or written to the module. • Execute (E): The module uses the SSP in performing a cryptographic operation. • N/A: the calling application does not access any CSP or key during its operation. The details of the approved cryptographic algorithms including the CAVP certificate numbers can be found in Section 2.5. In order to check whether it utilizes an approved security function or not, the operator is responsible to invoke the gcry_control() API along with dedicated controls in the form of API input parameters. The module implements the following controls depending on the requested service:

  1. GCRYCTL_FIPS_SERVICE_INDICATOR_CIPHER - For symmetric algorithms and the related modes.
  2. GCRYCTL_FIPS_SERVICE_INDICATOR_KDF - For KDF operations.
  3. GCRYCTL_FIPS_SERVICE_INDICATOR_PK_FLAGS - For asymmetric operations. 1
  4. GCRYCTL_FIPS_SERVICE_INDICATOR_MD - For digest operations.
  5. GCRYCTL_FIPS_SERVICE_INDICATOR_MAC - For MAC operations. The list of public key flags allowed in approved mode of operation is described in Section 4.4. Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
Page 38
NameDescriptionAlgorithmsRole
Authenticated symmetric encryptionAES encryption using non-approved AES modesAES GCM noncompliant with IG C.H. AES GCM-SIV AES OCB AES-EAXCO
Authenticated symmetric decryptionAES decryption using non-approved AES modesAES GCM noncompliant with IG C.H. AES GCM-SIV AES OCB AES-EAXCO
Message digest using non- approved algorithmsMessage digestMD5CO
Shared secret computationECDH Shared secret computationECDH noncompliant with SP 800-56Arev3 assurancesCO
Key generationGenerate RSA/ECDSA key pairs with public key flags not listed in Appendix ARSA with non-approved flags that are not listed in Appendix A ECDSA with non-approved flags that are not listed in Appendix ACO
Digital signature generationRSA/ECDSA signature generation with public key flags not listed in Appendix ARSA with non-approved flags that are not listed in Appendix A ECDSA with non-approved flags that are not listed in Appendix ACO
Digital signature verificationRSA/ECDSA signature verification with public key flags not listed in Appendix ARSA with non-approved flags that are not listed in Appendix A ECDSA with non-approved flags that are not listed in Appendix ACO
Asymmetric encryption and decryption primitivesRSA encryption and decryption primitivesRSACO
Signature generation/verification primitivesRSA/ECDSA signature generation/verification primitivesRSA ECDSACO

In addition to that, for the below-mentioned services, the approved service indicator corresponds to the GPG_ERR_NO_ERROR returned from listed functions in the indicator column below. They don’t use gcry_control() API:

  1. Random number generation service: gcry_randomize(), gcry_random_bytes(), gcry_random_bytes_secure().
  2. Public key validation service: gcry_mpi_ec_curve_point(). Table 14: Non-Approved Services The table above lists the non-approved services. The details of the non-approved cryptographic algorithms available in non-approved mode can be found in Section 2.5. For the services listed above, Oracle Linux 9 libgcrypt Cryptographic Module Security Policy
Page 39

the module implements an additional service indicator in the form of a control named GCRYCTL_FIPS_SERVICE_INDICATOR_FUNCTION. The operator is responsible to invoke the gcry_control() API along with the following input parameters: GCRYCTL_FIPS_SERVICE_INDICATOR_FUNCTION control; the name of the API 2 representing the service. The list of APIs is supported by the module can be found in the documentation included in the optional libgcryptdevel package. Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 40
5 Software/Firmware Security
5.1 Integrity Techniques

The integrity of the module is verified by comparing a HMAC SHA-256 values calculated at run time with the HMAC SHA-256 value embedded within the module binary. If the HMAC values do not match, the test fails, and the module enters the Error state.

5.2 Initiate on Demand

The integrity test is performed as part of the pre-operational self-test, which is executed when the module is initialized. In addition, the module provides the Self-Test service to perform self-tests on demand which includes the pre-operational test (i.e., integrity test) and cryptographic algorithm self-tests (CASTs). This service can be invoked relying on the gcry_control(GCRYCTL_SELFTEST) API function call or by powering-off and reloading the module. During the execution of the on-demand self-tests, services are not available, and data output or input is not possible. In order to verify whether the self-tests have succeeded and the module is in the Operational state, the calling application may invoke the gcry_control(GCRYTCL_OPERATIONAL_P) API. The function will return TRUE if the module is in the Operational state and FALSE if the module is in the Error state. Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 41
6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Modifiable How Requirements are Satisfied: The module shall be installed as stated in Section 11. If properly installed, the operating system provides process isolation and memory protection mechanisms that ensure appropriate separation for memory access among the processes on the system. Each process has control over its own data, and uncontrolled access to the data of other processes is prevented.

6.2 Configuration Settings and Restrictions

The module shall be installed as stated in Section 11.1. Instrumentation tools like the ptrace system call, gdb and strace, as well as other tracing mechanisms offered by the Linux environment such as ftrace or systemtap, shall not be used in the operational environment. The use of any of these tools implies that the cryptographic module is running in a nonvalidated operational environment. Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 42
7 Physical Security

The module is comprised of software only, and therefore this section is not applicable. Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 43
8 Non-Invasive Security

This module does not implement any non-invasive security mechanism, and therefore this section is not applicable. Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 44
Storage Area NameDescriptionPersistence Type
RAMTemporary storage for SSPs used by the module as part of service executionDynamic
NameFromToFormat TypeDistribution TypeEntry TypeSFI or Algorithm
API input parametersOperating calling application (TOEPP)Cryptographic modulePlaintextManualElectronic
API output parametersCryptographic moduleOperator calling application (TOEPP)PlaintextManualElectronic
Zeroization MethodDescriptionRationaleOperator Initiation
Free cipher handleZeroizes the SSPs contained within the provided cipher handleMemory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable. The completion of a zeroization routine will indicate that a zeroization procedure succeeded.By calling the appropriate zeroization functions: AES key: gcry_cipher_close gcry_free() HMAC key: gcry_mac_close, gcry_free Key-derivation key: gcry_free Derived key: gcry_free RSA keys: gcry_mpi_release, gcry_sexp_release, gcry_free EC keys: gcry_mpi_release, gcry_free, gcry_mpi_point_release, gcry_sexp_release, gcry_ctx_release Entropy input: gcry_ctrl(GCRYCTL_TERM_SECMEM) Internal state: gcry_ctrl(GCRYCTL_TERM_SECMEM)
Remove power from the moduleDe-allocates the volatile memory used to store SSPsVolatile memory used by the module is overwritten within nanoseconds when power is removed. Module power off indicates that theBy unloading the module
9 Sensitive Security Parameters Management
9.1 Storage Areas

Table 15: Storage Areas The module does not perform persistent storage of SSPs. The SSPs are temporarily stored in the RAM in Table 16: SSP Input-Output Methods The module does not support manual SSP input or intermediate SSP generation output. The SSPs are in plaintext form within the physical perimeter of the operational environment. This is allowed by FIPS 140-3 IG 9.5.A, according to the “CM Software to/from App via TOEPP Path” entry in the table above. Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 45

Zeroization Method

Description

Rationale zeroization procedure succeeded.

Operator Initiation

NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
AES keyAES key used for encryption, decryption, and computing MAC tagsXTS: 256, 512 bits; Other modes: 128, 192, 256 bits - XTS: 128, 256 bits; Other modes: 128, 192, 256 bitsSymmetric key - CSPKey wrapping using AES CCM Key wrapping using AES KW Key unwrapping using AES CCM Key unwrapping using AES KW Encryption with AES Decryption with AES
HMAC keyHMAC key112-256 bits - 112-256 bitsAuthentication key - CSPMessage Authentication Code
Password or passphrasePBKDF2 password or passphraseAt least 8 characters - N/APassword or passphrase - CSPKey Derivation with PBKDF
Derived keyPBKDF2 derived key112-256 bits - 112-256 bitsSymmetric key - CSPKey Derivation with PBKDFKey Derivation with PBKDF
Entropy inputObtained from the entropy source, used to seed the DRBGs128-448 bits (128-256 bits) - 256 bitsEntropy input - CSPRandom Number Generation with DRBG
DRBG internal state: (V value, key)Internal state of CTR_DRBG and HMAC_DRBGCTR_DRBG: 256, 320, 384 bits; HMAC_DRBG: 320, 512, 1024 bits - CTR_DRBG: 128, 192, 256 bits; HMAC_DRBG: 128, 256 bitsInternal state - CSPRandom Number Generation with DRBGRandom Number Generation with DRBG

Table 17: SSP Zeroization Methods All data output is inhibited during zeroization.

9.4 SSPs

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 46
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
DRBG internal state: (V value, C value)Internal state of Hash_DRBG880, 1776 bits - 128, 256 bitsInternal state - CSPRandom Number Generation with DRBGRandom Number Generation with DRBG
DRBG seedDRBG seed derived from entropy inputCTR_DRBG: 256, 320, 384 bits; Hash_DRBG: 440, 888 bits; HMAC_DRBG: 440, 888 bits - CTR_DRBG: 128, 192, 256 bits; Hash_DRBG: 128, 256 bits; HMAC_DRBG: 128, 256 bitsSeed - CSPRandom Number Generation with DRBGRandom Number Generation with DRBG
ECDSA public keyPublic key used for ECDSA signature verificationP-224, P-256, P- 384, P-521 - 112, 128, 192, 256 bitsPublic key - PSPKey Pair Generation with ECDSAKey Pair Generation with ECDSA Public Key Verification with ECDSA Signature Verification with ECDSA
ECDSA private keyPrivate key used for ECDSA signature generationP-224, P-256, P- 384, P-521 - 112, 128, 192, 256 bitsPrivate key - CSPKey Pair Generation with ECDSAKey Pair Generation with ECDSA Public Key Verification with ECDSA Signature Generation with ECDSA
RSA public keyPublic key used for RSA signature verification1024, 1536, 2048, 3072, 4096 bits - 80, 96, 112, 128, 140 bitsPublic key - PSPKey Pair Generation with RSAKey Pair Generation with RSA Signature Verification with RSA
RSA private keyPrivate key used for RSA signature generation2048, 3072, 4096 bits - 112, 128, 140 bitsPrivate key - CSPKey Pair Generation with RSAKey Pair Generation with RSA Signature Generation with RSA

Table 18: SSP Table 1 Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 47
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
AES keyAPI input parametersRAM:PlaintextFrom service invoked to service completedFree cipher handle Remove power from the module
HMAC keyAPI input parametersRAM:PlaintextFrom service invoked to service completedFree cipher handle Remove power from the module
Password or passphraseAPI output parametersRAM:PlaintextFrom service invoked to service completedFree cipher handle Remove power from the moduleDerived key:Generates
Derived keyAPI input parametersRAM:PlaintextFrom service invoked to service completedFree cipher handle Remove power from the modulePassword or passphrase:Derived From
Entropy inputRAM:PlaintextFrom service invoked to service completedFree cipher handle Remove power from the moduleDRBG internal state: (V value, key):Generates DRBG internal state: (V value, C value):Generates DRBG seed:Generates
DRBG internal state: (V value, key)RAM:PlaintextFrom service invoked to service completedFree cipher handle Remove power from the moduleEntropy input:Derived From DRBG seed:Derived From
DRBG internal state: (V value, C value)RAM:PlaintextFrom service invoked to service completedFree cipher handle Remove power from the moduleEntropy input:Derived From DRBG seed:Derived From
DRBG seedRAM:PlaintextFree cipher handle Remove power from the moduleEntropy input:Derived From DRBG internal state: (V value, key):Generates DRBG internal state: (V value, C value):Generates
ECDSA public keyAPI input parameters API output parametersRAM:PlaintextFrom service invoked to service completedFree cipher handle Remove power from the moduleDRBG internal state: (V value, key):Derived From ECDSA private key:Paired With
ECDSA private keyAPI input parametersRAM:PlaintextFrom service invoked toFree cipher handleDRBG internal state: (V value, key):Derived

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 48
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
API output parametersservice completedRemove power from the moduleFrom ECDSA public key:Paired With
RSA public keyAPI input parameters API output parametersRAM:PlaintextFrom service invoked to service completedFree cipher handle Remove power from the moduleDRBG internal state: (V value, key):Derived From RSA private key:Paired With
RSA private keyAPI input parameters API output parametersRAM:PlaintextFrom service invoked to service completedFree cipher handle Remove power from the moduleRSA public key:Paired With DRBG internal state: (V value, key):Derived From
9.5 Transitions

The SHA-1 algorithm, as implemented by the module, will be non-approved for all purposes starting January 1, 2031. The RSA and ECDSA algorithms as implemented by the module conforms to FIPS 186-4, which has been superseded by FIPS 186-5. The transition started on July 25, 2023, and ended on February 4, 2024. FIPS 186-4 has been withdrawn since February 3, 2024. Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 49
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
HMAC-SHA2- 256 (A4773)Key size: 376-bit keyMessage AuthenticationSW/FW IntegrityThe module becomes operational and the services are available for useIntegrity test for libgcrypt.so.20.4.0
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-ECB (A4773)AES ECB mode with 128, 192, 256-bit keys, encryption, and decryption (separately tested)KATCASTThe module becomes operational and the services are available for useEncryption, DecryptionModule initialization or on demand through API function call
AES-ECB (A4774)AES ECB mode with 128, 192, 256-bit keys, encryption, and decryption (separately tested)KATCASTThe module becomes operational and the services are available for useEncryption, DecryptionModule initialization or on demand through API function call
AES-ECB (A4776)AES ECB mode with 128, 192, 256-bit keys, encryption, and decryption (separately tested)KATCASTThe module becomes operational and the services are available for useEncryption, DecryptionModule initialization or on demand through API function call
AES-ECB (A4777)AES ECB mode with 128, 192, 256-bit keys, encryption, and decryption (separately tested)KATCASTThe module becomes operational and the services are available for useEncryption, DecryptionModule initialization or on demand through API function call
10 Self-Tests
10.1 Pre-Operational Self-Tests

Table 20: Pre-Operational Self-Tests The pre-operational software integrity test is performed automatically when the module is powered on before the module transitions into the Operational state. While the module is executing the self-tests, services are not available, and data output (via the data output interface) is inhibited until the tests are successfully completed. The module transitions to the Operational state only after the pre-operational self-test passes successfully.

10.2 Conditional Self-Tests

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 50
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-CMAC (A4773)AES CMAC with 128-bit key, MAC generationKATCASTThe module becomes operational and the services are available for useMessage AuthenticationModule initialization or on demand through API function call
AES-CMAC (A4774)AES CMAC with 128-bit key, MAC generationKATCASTThe module becomes operational and the services are available for useMessage AuthenticationModule initialization or on demand through API function call
AES-CMAC (A4776)AES CMAC with 128-bit key, MAC generationKATCASTThe module becomes operational and the services are available for useMessage AuthenticationModule initialization or on demand through API function call
AES-CMAC (A4777)AES CMAC with 128-bit key, MAC generationKATCASTThe module becomes operational and the services are available for useMessage AuthenticationModule initialization or on demand through API function call
Counter DRBG (A4773)CTR_DRBG with AES with 128-bit key with DF, with and without PRKATCASTThe module becomes operational and the services are available for useGenerate, ReseedModule initialization or on demand through API function call
Counter DRBG (A4774)CTR_DRBG with AES with 128-bit key with DF, with and without PRKATCASTThe module becomes operational and the services are available for useGenerate, ReseedModule initialization or on demand through API function call
Counter DRBG (A4776)CTR_DRBG with AES with 128-bit key with DF, with and without PRKATCASTThe module becomes operational and the services are available for useGenerate, ReseedModule initialization or on demand through API function call

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 51
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
Counter DRBG (A4777)CTR_DRBG with AES with 128-bit key with DF, with and without PRKATCASTThe module becomes operational and the services are available for useGenerate, ReseedModule initialization or on demand through API function call
Hash DRBG (A4773)SHA-1 without PRKATCASTThe module becomes operational and the services are available for useGenerate, ReseedModule initialization or on demand through API function call
Hash DRBG (A4774)SHA-1 without PRKATCASTThe module becomes operational and the services are available for useGenerate, ReseedModule initialization or on demand through API function call
Hash DRBG (A4776)SHA-1 without PRKATCASTThe module becomes operational and the services are available for useGenerate, ReseedModule initialization or on demand through API function call
Hash DRBG (A4777)SHA-1 without PRKATCASTThe module becomes operational and the services are available for useGenerate, ReseedModule initialization or on demand through API function call
Hash DRBG (A4778)SHA-1 without PRKATCASTThe module becomes operational and the services are available for useGenerate, ReseedModule initialization or on demand through API function call
Hash DRBG (A4773)SHA-256 with and without PRKATCASTThe module becomes operational and the services are available for useGenerate, ReseedModule initialization or on demand through API function call

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 52
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
Hash DRBG (A4774)SHA-256 with and without PRKATCASTThe module becomes operational and the services are available for useGenerate, ReseedModule initialization or on demand through API function call
Hash DRBG (A4776)SHA-256 with and without PRKATCASTThe module becomes operational and the services are available for useGenerate, ReseedModule initialization or on demand through API function call
Hash DRBG (A4777)SHA-256 with and without PRKATCASTThe module becomes operational and the services are available for useGenerate, ReseedModule initialization or on demand through API function call
Hash DRBG (A4778)SHA-256 with and without PRKATCASTThe module becomes operational and the services are available for useGenerate, ReseedModule initialization or on demand through API function call
HMAC DRBG (A4773)SHA-256 with and without PRKATCASTThe module becomes operational and the services are available for useGenerate, ReseedModule initialization or on demand through API function call
HMAC DRBG (A4774)SHA-256 with and without PRKATCASTThe module becomes operational and the services are available for useGenerate, ReseedModule initialization or on demand through API function call
HMAC DRBG (A4776)SHA-256 with and without PRKATCASTThe module becomes operational and the services are available for useGenerate, ReseedModule initialization or on demand through API function call

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 53
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
HMAC DRBG (A4777)SHA-256 with and without PRKATCASTThe module becomes operational and the services are available for useGenerate, ReseedModule initialization or on demand through API function call
HMAC DRBG (A4778)SHA-256 with and without PRKATCASTThe module becomes operational and the services are available for useGenerate, ReseedModule initialization or on demand through API function call
ECDSA SigGen (FIPS186-4) (A4773)P-256 with SHA-256KATCASTThe module becomes operational and the services are available for useSignature generationModule initialization or on demand through API function call
ECDSA SigGen (FIPS186-4) (A4774)P-256 with SHA-256KATCASTThe module becomes operational and the services are available for useSignature generationModule initialization or on demand through API function call
ECDSA SigGen (FIPS186-4) (A4776)P-256 with SHA-256KATCASTThe module becomes operational and the services are available for useSignature generationModule initialization or on demand through API function call
ECDSA SigGen (FIPS186-4) (A4777)P-256 with SHA-256KATCASTThe module becomes operational and the services are available for useSignature generationModule initialization or on demand through API function call
ECDSA SigGen (FIPS186-4) (A4778)P-256 with SHA-256KATCASTThe module becomes operational and the services are available for useSignature generationModule initialization or on demand through API function call

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 54
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
ECDSA SigVer (FIPS186-4) (A4773)P-256 with SHA-256KATCASTThe module becomes operational and the services are available for useSignature verificationModule initialization or on demand through API function call
ECDSA SigVer (FIPS186-4) (A4774s)P-256 with SHA-256KATCASTThe module becomes operational and the services are available for useSignature verificationModule initialization or on demand through API function call
ECDSA SigVer (FIPS186-4) (A4776)P-256 with SHA-256KATCASTThe module becomes operational and the services are available for useSignature verificationModule initialization or on demand through API function call
ECDSA SigVer (FIPS186-4) (A4777)P-256 with SHA-256KATCASTThe module becomes operational and the services are available for useSignature verificationModule initialization or on demand through API function call
ECDSA SigVer (FIPS186-4) (A4778)P-256 with SHA-256KATCASTThe module becomes operational and the services are available for useSignature verificationModule initialization or on demand through API function call
HMAC- SHA-1 (A4772)HMAC-SHA-1KATCASTThe module becomes operational and the services are available for useMessage authenticationModule initialization or on demand through API function call
HMAC- SHA-1 (A4773)HMAC-SHA-1KATCASTThe module becomes operational and the services are available for useMessage authenticationModule initialization or on demand through API function call

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 55
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
HMAC- SHA-1 (A4774)HMAC-SHA-1KATCASTThe module becomes operational and the services are available for useMessage authenticationModule initialization or on demand through API function call
HMAC- SHA-1 (A4776)HMAC-SHA-1KATCASTThe module becomes operational and the services are available for useMessage authenticationModule initialization or on demand through API function call
HMAC- SHA-1 (A4777)HMAC-SHA-1KATCASTThe module becomes operational and the services are available for useMessage authenticationModule initialization or on demand through API function call
HMAC- SHA-1 (A4778)HMAC-SHA-1KATCASTThe module becomes operational and the services are available for useMessage authenticationModule initialization or on demand through API function call
HMAC- SHA2-224 (A4773)HMAC-SHA-224KATCASTThe module becomes operational and the services are available for useMessage authenticationModule initialization or on demand through API function call
HMAC- SHA2-224 (A4774)HMAC-SHA-224KATCASTThe module becomes operational and the services are available for useMessage authenticationModule initialization or on demand through API function call
HMAC- SHA2-224 (A4776)HMAC-SHA-224KATCASTThe module becomes operational and the services are available for useMessage authenticationModule initialization or on demand through API function call

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 56
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
HMAC- SHA2-224 (A4777)HMAC-SHA-224KATCASTThe module becomes operational and the services are available for useMessage authenticationModule initialization or on demand through API function call
HMAC- SHA2-224 (A4778)HMAC-SHA-224KATCASTThe module becomes operational and the services are available for useMessage authenticationModule initialization or on demand through API function call
HMAC- SHA2-256 (A4773)HMAC-SHA-256KATCASTThe module becomes operational and the services are available for useMessage authenticationModule initialization or on demand through API function call
HMAC- SHA2-256 (A4774)HMAC-SHA-256KATCASTThe module becomes operational and the services are available for useMessage authenticationModule initialization or on demand through API function call
HMAC- SHA2-256 (A4776)HMAC-SHA-256KATCASTThe module becomes operational and the services are available for useMessage authenticationModule initialization or on demand through API function call
HMAC- SHA2-256 (A4777)HMAC-SHA-256KATCASTThe module becomes operational and the services are available for useMessage authenticationModule initialization or on demand through API function call
HMAC- SHA2-256 (A4778)HMAC-SHA-256KATCASTThe module becomes operational and the services are available for useMessage authenticationModule initialization or on demand through API function call

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 57
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
HMAC- SHA2-384 (A4773)HMAC-SHA-384KATCASTThe module becomes operational and the services are available for useMessage authenticationModule initialization or on demand through API function call
HMAC- SHA2-384 (A4774)HMAC-SHA-384KATCASTThe module becomes operational and the services are available for useMessage authenticationModule initialization or on demand through API function call
HMAC- SHA2-384 (A4776)HMAC-SHA-384KATCASTThe module becomes operational and the services are available for useMessage authenticationModule initialization or on demand through API function call
HMAC- SHA2-384 (A4777)HMAC-SHA-384KATCASTThe module becomes operational and the services are available for useMessage authenticationModule initialization or on demand through API function call
HMAC- SHA2-384 (A4778)HMAC-SHA-384KATCASTThe module becomes operational and the services are available for useMessage authenticationModule initialization or on demand through API function call
HMAC- SHA2-512 (A4773)HMAC-SHA-512KATCASTThe module becomes operational and the services are available for useMessage authenticationModule initialization or on demand through API function call
HMAC- SHA2-512 (A4774)HMAC-SHA-512KATCASTThe module becomes operational and the services are available for useMessage authenticationModule initialization or on demand through API function call

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 58
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
HMAC- SHA2-512 (A4776)HMAC-SHA-512KATCASTThe module becomes operational and the services are available for useMessage authenticationModule initialization or on demand through API function call
HMAC- SHA2-512 (A4777)HMAC-SHA-512KATCASTThe module becomes operational and the services are available for useMessage authenticationModule initialization or on demand through API function call
HMAC- SHA2-512 (A4778)HMAC-SHA-512KATCASTThe module becomes operational and the services are available for useMessage authenticationModule initialization or on demand through API function call
HMAC- SHA3-224 (A4773)HMAC-SHA3-224KATCASTThe module becomes operational and the services are available for useMessage authenticationModule initialization or on demand through API function call
HMAC- SHA3-224 (A4774)HMAC-SHA3-224KATCASTThe module becomes operational and the services are available for useMessage authenticationModule initialization or on demand through API function call
HMAC- SHA3-224 (A4773)HMAC-SHA3-224KATCASTThe module becomes operational and the services are available for useMessage authenticationModule initialization or on demand through API function call
HMAC- SHA3-256 (A4773)HMAC-SHA3-256KATCASTThe module becomes operational and the services are available for useMessage authenticationModule initialization or on demand through API function call

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 59
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
HMAC- SHA3-256 (A4774)HMAC-SHA3-256KATCASTThe module becomes operational and the services are available for useMessage authenticationModule initialization or on demand through API function call
HMAC- SHA3-256 (A4778)HMAC-SHA3-256KATCASTThe module becomes operational and the services are available for useMessage authenticationModule initialization or on demand through API function call
HMAC- SHA3-384 (A4773)HMAC-SHA3-384KATCASTThe module becomes operational and the services are available for useMessage authenticationModule initialization or on demand through API function call
HMAC- SHA3-384 (A4774)HMAC-SHA3-384KATCASTThe module becomes operational and the services are available for useMessage authenticationModule initialization or on demand through API function call
HMAC- SHA3-384 (A4778)HMAC-SHA3-384KATCASTThe module becomes operational and the services are available for useMessage authenticationModule initialization or on demand through API function call
HMAC- SHA3-512 (A4773)HMAC-SHA3-512KATCASTThe module becomes operational and the services are available for useMessage authenticationModule initialization or on demand through API function call
HMAC- SHA3-512 (A4774)HMAC-SHA3-512KATCASTThe module becomes operational and the services are available for useMessage authenticationModule initialization or on demand through API function call

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 60
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
HMAC- SHA3-512 (A4778)HMAC-SHA3-512KATCASTThe module becomes operational and the services are available for useMessage authenticationModule initialization or on demand through API function call
RSA SigGen (FIPS186-4) (A4773)PKCS #1 v1.5 with 2048- bit key and SHA-256KATCASTThe module becomes operational and the services are available for useSignature generationModule initialization or on demand through API function call
RSA SigGen (FIPS186-4) (A4774)PKCS #1 v1.5 with 2048- bit key and SHA-256KATCASTThe module becomes operational and the services are available for useSignature generationModule initialization or on demand through API function call
RSA SigGen (FIPS186-4) (A4776)PKCS #1 v1.5 with 2048- bit key and SHA-256KATCASTThe module becomes operational and the services are available for useSignature generationModule initialization or on demand through API function call
RSA SigGen (FIPS186-4) (A4777)PKCS #1 v1.5 with 2048- bit key and SHA-256KATCASTThe module becomes operational and the services are available for useSignature generationModule initialization or on demand through API function call
RSA SigGen (FIPS186-4) (A4778)PKCS #1 v1.5 with 2048- bit key and SHA-256KATCASTThe module becomes operational and the services are available for useSignature generationModule initialization or on demand through API function call
RSA SigVer (FIPS186-4) (A4773)PKCS #1 v1.5 with 2048- bit key and SHA-256KATCASTThe module becomes operational and the services are available for useSignature verificationModule initialization or on demand through API function call

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 61
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
RSA SigVer (FIPS186-4) (A4774)PKCS #1 v1.5 with 2048- bit key and SHA-256KATCASTThe module becomes operational and the services are available for useSignature verificationModule initialization or on demand through API function call
RSA SigVer (FIPS186-4) (A4776)PKCS #1 v1.5 with 2048- bit key and SHA-256KATCASTThe module becomes operational and the services are available for useSignature verificationModule initialization or on demand through API function call
RSA SigVer (FIPS186-4) (A4777)PKCS #1 v1.5 with 2048- bit key and SHA-256KATCASTThe module becomes operational and the services are available for useSignature verificationModule initialization or on demand through API function call
RSA SigVer (FIPS186-4) (A4778)PKCS #1 v1.5 with 2048- bit key and SHA-256KATCASTThe module becomes operational and the services are available for useSignature verificationModule initialization or on demand through API function call
SHA-1 (A4772)SHA-1KATCASTThe module becomes operational and the services are available for useMessage digestModule initialization or on demand through API function call
SHA-1 (A4773)SHA-1KATCASTThe module becomes operational and the services are available for useMessage digestModule initialization or on demand through API function call
SHA-1 (A4774)SHA-1KATCASTThe module becomes operational and the services are available for useMessage digestModule initialization or on demand through API function call

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 62
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
SHA-1 (A4775)SHA-1KATCASTThe module becomes operational and the services are available for useMessage digestModule initialization or on demand through API function call
SHA-1 (A4776)SHA-1KATCASTThe module becomes operational and the services are available for useMessage digestModule initialization or on demand through API function call
SHA-1 (A4777)SHA-1KATCASTThe module becomes operational and the services are available for useMessage digestModule initialization or on demand through API function call
SHA-1 (A4778)SHA-1KATCASTThe module becomes operational and the services are available for useMessage digestModule initialization or on demand through API function call
SHA2-224 (A4773)SHA-224KATCASTThe module becomes operational and the services are available for useMessage digestModule initialization or on demand through API function call
SHA2-224 (A4774)SHA-224KATCASTThe module becomes operational and the services are available for useMessage digestModule initialization or on demand through API function call
SHA2-224 (A4776)SHA-224KATCASTThe module becomes operational and the services are available for useMessage digestModule initialization or on demand through API function call

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 63
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
SHA2-224 (A4777)SHA-224KATCASTThe module becomes operational and the services are available for useMessage digestModule initialization or on demand through API function call
SHA2-224 (A4778)SHA-224KATCASTThe module becomes operational and the services are available for useMessage digestModule initialization or on demand through API function call
SHA2-256 (A4773)SHA-256KATCASTThe module becomes operational and the services are available for useMessage digestModule initialization or on demand through API function call
SHA2-256 (A4774)SHA-256KATCASTThe module becomes operational and the services are available for useMessage digestModule initialization or on demand through API function call
SHA2-256 (A4776)SHA-256KATCASTThe module becomes operational and the services are available for useMessage digestModule initialization or on demand through API function call
SHA2-256 (A4777)SHA-256KATCASTThe module becomes operational and the services are available for useMessage digestModule initialization or on demand through API function call
SHA2-256 (A4778)SHA-256KATCASTThe module becomes operational and the services are available for useMessage digestModule initialization or on demand through API function call

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 64
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
SHA2-384 (A4773)SHA-384KATCASTThe module becomes operational and the services are available for useMessage digestModule initialization or on demand through API function call
SHA2-384 (A4774)SHA-384KATCASTThe module becomes operational and the services are available for useMessage digestModule initialization or on demand through API function call
SHA2-384 (A4776)SHA-384KATCASTThe module becomes operational and the services are available for useMessage digestModule initialization or on demand through API function call
SHA2-384 (A4777)SHA-384KATCASTThe module becomes operational and the services are available for useMessage digestModule initialization or on demand through API function call
SHA2-384 (A4778)SHA-384KATCASTThe module becomes operational and the services are available for useMessage digestModule initialization or on demand through API function call
SHA2-512 (A4773)SHA-512KATCASTThe module becomes operational and the services are available for useMessage digestModule initialization or on demand through API function call
SHA2-512 (A4774)SHA-512KATCASTThe module becomes operational and the services are available for useMessage digestModule initialization or on demand through API function call

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 65
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
SHA2-512 (A4776)SHA-512KATCASTThe module becomes operational and the services are available for useMessage digestModule initialization or on demand through API function call
SHA2-512 (A4778)SHA-512KATCASTThe module becomes operational and the services are available for useMessage digestModule initialization or on demand through API function call
PBKDF (A4773)SHA-1 password length 24 characters, master key length of 200 bits, iteration count of 4096, and salt length of 288 bits; SHA-256 password length 24 characters, master key length of 320 bits, iteration count of 4096, and salt length of 288 bitsKATCASTThe module becomes operational and the services are available for useKey derivationModule initialization or on demand through API function call
PBKDF (A4774)SHA-1 password length 24 characters, master key length of 200 bits, iteration count of 4096, and salt length of 288 bits; SHA-256 password length 24 characters, master key length of 320 bits, iteration count of 4096, and salt length of 288 bitsKATCASTThe module becomes operational and the services are available for useKey derivationModule initialization or on demand through API function call
PBKDF (A4776)SHA-1 password length 24 characters, master key length of 200 bits, iteration count of 4096, and salt length of 288 bits; SHA-256 password length 24 characters, master key length of 320 bits, iteration count of 4096, and salt length of 288 bitsKATCASTThe module becomes operational and the services are available for useKey derivationModule initialization or on demand through API function call
PBKDF (A4777)SHA-1 password length 24 characters, master key length of 200 bits,KATCASTThe module becomes operationalKey derivationModule initialization or on demand

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 66
Algorithm or TestTest Properties iteration count of 4096, and salt length of 288 bits; SHA-256 password length 24 characters, master key length of 320 bits, iteration count of 4096, and salt length of 288 bitsTest MethodTest TypeIndicator and the services are available for useDetailsConditions through API function call
PBKDF (A4778)SHA-1 password length 24 characters, master key length of 200 bits, iteration count of 4096, and salt length of 288 bits; SHA-256 password length 24 characters, master key length of 320 bits, iteration count of 4096, and salt length of 288 bitsKATCASTThe module becomes operational and the services are available for useKey derivationModule initialization or on demand through API function call
ECDSA KeyGen (FIPS186-4) (A4773)Signature generation and verification with SHA-256PCTPCTSuccessful key generationKey generationEC key pair generation
ECDSA KeyGen (FIPS186-4) (A4774)Signature generation and verification with SHA-256PCTPCTSuccessful key generationKey generationEC key pair generation
ECDSA KeyGen (FIPS186-4) (A4776)Signature generation and verification with SHA-256PCTPCTSuccessful key generationKey generationEC key pair generation
ECDSA KeyGen (FIPS186-4) (A4777)Signature generation and verification with SHA-256PCTPCTSuccessful key generationKey generationEC key pair generation
ECDSA KeyGen (FIPS186-4) (A4778)Signature generation and verification with SHA-256PCTPCTSuccessful key generationKey generationEC key pair generation
RSA KeyGen (FIPS186-4) (A4773)Signature generation of verification with SHA-256PCTPCTSuccessful key generationKey generationRSA key pair generation
RSA KeyGen (FIPS186-4) (A4774)Signature generation of verification with SHA-256PCTPCTSuccessful key generationKey generationRSA key pair generation
RSA KeyGenSignature generation of verification with SHA-256PCTPCTSuccessful key generationKey generationRSA key pair generation

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 67
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
(FIPS186-4) (A4776)
RSA KeyGen (FIPS186-4) (A4777)Signature generation of verification with SHA-256PCTPCTSuccessful key generationKey generationRSA key pair generation
RSA KeyGen (FIPS186-4) (A4778)Signature generation of verification with SHA-256PCTPCTSuccessful key generationKey generationRSA key pair generation
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2-256 (A4773)Message AuthenticationSW/FW IntegrityWhenever module is powered onUpon every power on
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-ECB (A4773)KATCASTOn demandManually
AES-ECB (A4774)KATCASTOn demandManually
AES-ECB (A4776)KATCASTOn demandManually
AES-ECB (A4777)KATCASTOn demandManually
AES-CMAC (A4773)KATCASTOn demandManually
AES-CMAC (A4774)KATCASTOn demandManually
AES-CMAC (A4776)KATCASTOn demandManually
AES-CMAC (A4777)KATCASTOn demandManually
Counter DRBG (A4773)KATCASTOn demandManually
Counter DRBG (A4774)KATCASTOn demandManually
Counter DRBG (A4776)KATCASTOn demandManually
Counter DRBG (A4777)KATCASTOn demandManually
Hash DRBG (A4773)KATCASTOn demandManually
Hash DRBG (A4774)KATCASTOn demandManually
Hash DRBG (A4776)KATCASTOn demandManually
Hash DRBG (A4777)KATCASTOn demandManually
Hash DRBG (A4778)KATCASTOn demandManually
Hash DRBG (A4773)KATCASTOn demandManually
Hash DRBG (A4774)KATCASTOn demandManually
Hash DRBG (A4776)KATCASTOn demandManually

Table 21: Conditional Self-Tests The module performs self-tests on all approved cryptographic algorithms as part of the approved services supported in the approved mode of operation, using the tests shown in table above. Services are not available, and data output (via the data output interface) is inhibited during the self-tests. If any of these tests fails, the module transitions to the Error state.

10.3 Periodic Self-Test Information

Table 22: Pre-Operational Periodic Information Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 68
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
Hash DRBG (A4777)KATCASTOn demandManually
Hash DRBG (A4778)KATCASTOn demandManually
HMAC DRBG (A4773)KATCASTOn demandManually
HMAC DRBG (A4774)KATCASTOn demandManually
HMAC DRBG (A4776)KATCASTOn demandManually
HMAC DRBG (A4777)KATCASTOn demandManually
HMAC DRBG (A4778)KATCASTOn demandManually
ECDSA SigGen (FIPS186-4) (A4773)KATCASTOn demandManually
ECDSA SigGen (FIPS186-4) (A4774)KATCASTOn demandManually
ECDSA SigGen (FIPS186-4) (A4776)KATCASTOn demandManually
ECDSA SigGen (FIPS186-4) (A4777)KATCASTOn demandManually
ECDSA SigGen (FIPS186-4) (A4778)KATCASTOn demandManually
ECDSA SigVer (FIPS186-4) (A4773)KATCASTOn demandManually
ECDSA SigVer (FIPS186-4) (A4774s)KATCASTOn demandManually
ECDSA SigVer (FIPS186-4) (A4776)KATCASTOn demandManually
ECDSA SigVer (FIPS186-4) (A4777)KATCASTOn demandManually
ECDSA SigVer (FIPS186-4) (A4778)KATCASTOn demandManually
HMAC-SHA-1 (A4772)KATCASTOn demandManually
HMAC-SHA-1 (A4773)KATCASTOn demandManually
HMAC-SHA-1 (A4774)KATCASTOn demandManually
HMAC-SHA-1 (A4776)KATCASTOn demandManually
HMAC-SHA-1 (A4777)KATCASTOn demandManually
HMAC-SHA-1 (A4778)KATCASTOn demandManually
HMAC-SHA2-224 (A4773)KATCASTOn demandManually
HMAC-SHA2-224 (A4774)KATCASTOn demandManually

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 69
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2-224 (A4776)KATCASTOn demandManually
HMAC-SHA2-224 (A4777)KATCASTOn demandManually
HMAC-SHA2-224 (A4778)KATCASTOn demandManually
HMAC-SHA2-256 (A4773)KATCASTOn demandManually
HMAC-SHA2-256 (A4774)KATCASTOn demandManually
HMAC-SHA2-256 (A4776)KATCASTOn demandManually
HMAC-SHA2-256 (A4777)KATCASTOn demandManually
HMAC-SHA2-256 (A4778)KATCASTOn demandManually
HMAC-SHA2-384 (A4773)KATCASTOn demandManually
HMAC-SHA2-384 (A4774)KATCASTOn demandManually
HMAC-SHA2-384 (A4776)KATCASTOn demandManually
HMAC-SHA2-384 (A4777)KATCASTOn demandManually
HMAC-SHA2-384 (A4778)KATCASTOn demandManually
HMAC-SHA2-512 (A4773)KATCASTOn demandManually
HMAC-SHA2-512 (A4774)KATCASTOn demandManually
HMAC-SHA2-512 (A4776)KATCASTOn demandManually
HMAC-SHA2-512 (A4777)KATCASTOn demandManually
HMAC-SHA2-512 (A4778)KATCASTOn demandManually
HMAC-SHA3-224 (A4773)KATCASTOn demandManually
HMAC-SHA3-224 (A4774)KATCASTOn demandManually
HMAC-SHA3-224 (A4773)KATCASTOn demandManually
HMAC-SHA3-256 (A4773)KATCASTOn demandManually
HMAC-SHA3-256 (A4774)KATCASTOn demandManually
HMAC-SHA3-256 (A4778)KATCASTOn demandManually
HMAC-SHA3-384 (A4773)KATCASTOn demandManually

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 70
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA3-384 (A4774)KATCASTOn demandManually
HMAC-SHA3-384 (A4778)KATCASTOn demandManually
HMAC-SHA3-512 (A4773)KATCASTOn demandManually
HMAC-SHA3-512 (A4774)KATCASTOn demandManually
HMAC-SHA3-512 (A4778)KATCASTOn demandManually
RSA SigGen (FIPS186-4) (A4773)KATCASTOn demandManually
RSA SigGen (FIPS186-4) (A4774)KATCASTOn demandManually
RSA SigGen (FIPS186-4) (A4776)KATCASTOn demandManually
RSA SigGen (FIPS186-4) (A4777)KATCASTOn demandManually
RSA SigGen (FIPS186-4) (A4778)KATCASTOn demandManually
RSA SigVer (FIPS186-4) (A4773)KATCASTOn demandManually
RSA SigVer (FIPS186-4) (A4774)KATCASTOn demandManually
RSA SigVer (FIPS186-4) (A4776)KATCASTOn demandManually
RSA SigVer (FIPS186-4) (A4777)KATCASTOn demandManually
RSA SigVer (FIPS186-4) (A4778)KATCASTOn demandManually
SHA-1 (A4772)KATCASTOn demandManually
SHA-1 (A4773)KATCASTOn demandManually
SHA-1 (A4774)KATCASTOn demandManually
SHA-1 (A4775)KATCASTOn demandManually
SHA-1 (A4776)KATCASTOn demandManually
SHA-1 (A4777)KATCASTOn demandManually
SHA-1 (A4778)KATCASTOn demandManually
SHA2-224 (A4773)KATCASTOn demandManually
SHA2-224 (A4774)KATCASTOn demandManually
SHA2-224 (A4776)KATCASTOn demandManually
SHA2-224 (A4777)KATCASTOn demandManually
SHA2-224 (A4778)KATCASTOn demandManually
SHA2-256 (A4773)KATCASTOn demandManually
SHA2-256 (A4774)KATCASTOn demandManually
SHA2-256 (A4776)KATCASTOn demandManually
SHA2-256 (A4777)KATCASTOn demandManually
SHA2-256 (A4778)KATCASTOn demandManually
SHA2-384 (A4773)KATCASTOn demandManually
SHA2-384 (A4774)KATCASTOn demandManually
SHA2-384 (A4776)KATCASTOn demandManually

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 71
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
SHA2-384 (A4777)KATCASTOn demandManually
SHA2-384 (A4778)KATCASTOn demandManually
SHA2-512 (A4773)KATCASTOn demandManually
SHA2-512 (A4774)KATCASTOn demandManually
SHA2-512 (A4776)KATCASTOn demandManually
SHA2-512 (A4778)KATCASTOn demandManually
PBKDF (A4773)KATCASTOn demandManually
PBKDF (A4774)KATCASTOn demandManually
PBKDF (A4776)KATCASTOn demandManually
PBKDF (A4777)KATCASTOn demandManually
PBKDF (A4778)KATCASTOn demandManually
ECDSA KeyGen (FIPS186-4) (A4773)PCTPCTUpon generation of an ECDSA key pairUpon generation of an ECDSA key pair
ECDSA KeyGen (FIPS186-4) (A4774)PCTPCTUpon generation of an ECDSA key pairUpon generation of an ECDSA key pair
ECDSA KeyGen (FIPS186-4) (A4776)PCTPCTUpon generation of an ECDSA key pairUpon generation of an ECDSA key pair
ECDSA KeyGen (FIPS186-4) (A4777)PCTPCTUpon generation of an ECDSA key pairUpon generation of an ECDSA key pair
ECDSA KeyGen (FIPS186-4) (A4778)PCTPCTUpon generation of an ECDSA key pairUpon generation of an ECDSA key pair
RSA KeyGen (FIPS186-4) (A4773)PCTPCTUpon generation of an RSA key pairUpon generation of an RSA key pair
RSA KeyGen (FIPS186-4) (A4774)PCTPCTUpon generation of an RSA key pairUpon generation of an RSA key pair
RSA KeyGen (FIPS186-4) (A4776)PCTPCTUpon generation of an RSA key pairUpon generation of an RSA key pair
RSA KeyGen (FIPS186-4) (A4777)PCTPCTUpon generation of an RSA key pairUpon generation of an RSA key pair
RSA KeyGen (FIPS186-4) (A4778)PCTPCTUpon generation of an RSA key pairUpon generation of an RSA key pair
NameDescriptionConditionsRecovery MethodIndicator
Error StateThe module immediately stops functioning due to a self-test failure; PCT failureSoftware integrity test failure CAST failure PCT failureRestarting the moduleModule will not load; Module stops functioning for PCT failure
Fatal Error StateThe module immediately enters a non-recoverable error state and automatically transits to shutdownRandom numbers are requested in the error state or cipher operations are requested on a deallocated handleRestarting the moduleModule is aborted and is not available for use

Table 23: Conditional Periodic Information

10.4 Error States

Table 24: Error States The table above shows the error codes and the corresponding condition. When the module fails any preOracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 72

enter the Error state. Any further cryptographic operation is inhibited. The calling application can obtain the module state by calling the gcry_control(GCRYCTL_OPERATIONAL_P) API function. The function returns FALSE if the module is in the Error state and TRUE if the module is in the Operational state. In the Error state, all data output is inhibited, no cryptographic operation is allowed, and the module accepts no more inputs or requests (as the module is no longer running). Recovery from the Error state includes restarting (i.e., powering off and powering on) of the module or running self-tests. Recovery from the Fatal Error state can only be done by restarting the module.

10.5 Operator Initiation of Self-Tests

The software integrity tests, cryptographic algorithm self-tests, and entropy source start-up tests can be invoked on demand by unloading and subsequently re-initializing the module. The pair-wise consistency tests can be invoked on demand by requesting the key pair generation service. Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 73
11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

The module is distributed as part of the Oracle Linux 9 (OL9) RPM package in the form of libgcrypt1.10.0-10.0.1.el9_2_fips RPM package that is located in the “Oracle Linux 9 Security Validation (Update 3)” yum repository (ol9_u3_security_validation). The operational environment needs to be set up in the FIPS validated configuration by installing the module as follows:

11.2 Administrator Guidance

The binaries of the module are contained in the RPM packages for delivery. The Crypto Officer shall follow Section 11.1 to configure the operational environment and install the module to be operated as a FIPS 140-3 validated module. The following RPM packages contain the FIPS validated module:

11.3 Non-Administrator Guidance

There is no non-administrator guidance.

11.4 End of Life

As the module does not persistently store SSPs, secure sanitization of the module consists of unloading the module. This will zeroize all SSPs in volatile memory. Then, if desired, the libgcrypt-1.10.010.0.1.el9_2_fips RPM packages can be uninstalled from the Oracle Linux 9 system. Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 74
12 Mitigation of Other Attacks
12.1 Attack List

The module implements blinding against RSA Timing Attacks. RSA is vulnerable to timing attacks. In a setup where attackers can measure the time of RSA decryption or signature operations, blinding must be used to protect the RSA operation from that attack.

12.2 Mitigation Effectiveness

By default, the module uses the following blinding technique: instead of using the RSA decryption directly, a blinded value y = x re mod n is decrypted and the unblinded value x' = y' r−1 mod n returned. The blinding value r is a random value with the size of the modulus n. Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 75
curveddataeecdsaflagssig-val
genkeyhashnnbitspkcs1private-keyvalue
psspublic-keyqrrawrsasalt-length
rsa-use-es

Listed below are the approved public key flags for an input s-expression: Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 76
AESAdvanced Encryption Standard
AES-NIAdvanced Encryption Standard New Instructions
APIApplication Programming Interface
CASTCryptographic Algorithm Self-Test
CAVPCryptographic Algorithm Validation Program
CBCCipher Block Chaining
CCMCounter with Cipher Block Chaining-Message Authentication Code
CFBCipher Feedback
CMACCipher-based Message Authentication Code
CMVPCryptographic Module Validation Program
CSPCritical Security Parameter
CTRCounter
DRBGDeterministic Random Bit Generator
ECBElectronic Code Book
ECDHElliptic Curve Diffie-Hellman
ECDSAElliptic Curve Digital Signature Algorithm
FIPSFederal Information Processing Standards
GCMGalois Counter Mode
HMACKeyed-Hash Message Authentication Code
KATKnown Answer Test
MACMessage Authentication Code
NISTNational Institute of Science and Technology
PAAProcessor Algorithm Acceleration
PBKDF2Password-based Key Derivation Function v2
PKCSPublic-Key Cryptography Standards
RSARivest, Shamir, Adleman
SHASecure Hash Algorithm
SSPSensitive Security Parameter
XTSXEX-based Tweaked-codebook mode with cipher text Stealing

Appendix B. Glossary and Abbreviations Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 77
FIPS 140-3FIPS PUB 140-3 - Security Requirements For Cryptographic Modules March 2019 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-3.pdf
FIPS 140-3 IGImplementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program https://csrc.nist.gov/Projects/cryptographic-module-validation-program/fips-140-3-ig- announcements
FIPS 180-4Secure Hash Standard (SHS) March 2012 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf
FIPS 186-4Digital Signature Standard (DSS) July 2013 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-4.pdf
FIPS 186-5Digital Signature Standard (DSS) February 2023 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-5.pdf
FIPS 197Advanced Encryption Standard November 2001 https://csrc.nist.gov/publications/fips/fips197/fips-197.pdf
FIPS 198-1The Keyed Hash Message Authentication Code (HMAC) July 2008 https://csrc.nist.gov/publications/fips/fips198-1/FIPS-198-1_final.pdf
FIPS 202SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions August 2015 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.202.pdf
SP 800-38ARecommendation for Block Cipher Modes of Operation Methods and Techniques December 2001 https://csrc.nist.gov/publications/nistpubs/800-38a/sp800-38a.pdf
SP 800-38BRecommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication May 2005 https://csrc.nist.gov/publications/nistpubs/800-38B/SP_800-38B.pdf
SP 800-38FRecommendation for Block Cipher Modes of Operation: Methods for Key Wrapping December 2012 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38F.pdf
SP 800-56Ar3Recommendation for Pair-Wise Key Establishment Schemes Using Discrete Logarithm Cryptography April 2018 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Ar3.pdf
SP 800-90Ar1Recommendation for Random Number Generation Using Deterministic Random Bit Generators June 2015 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90Ar1.pdf
SP 800-90BRecommendation for the Entropy Sources Used for Random Bit Generation January 2018 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90B.pdf
SP 800-108r1NIST Special Publication 800-108 - Recommendation for Key Derivation Using Pseudorandom Functions August 2022 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-108r1.pdf

Appendix C. References Oracle Linux 9 libgcrypt Cryptographic Module Security Policy

Page 78
SP 800-132Recommendation for Password-Based Key Derivation - Part 1: Storage Applications December 2010 https://csrc.nist.gov/publications/nistpubs/800-132/nist-sp800-132.pdf
SP 800-133r2Recommendation for Cryptographic Key Generation June 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-133r2.pdf
SP 800-135r1Recommendation for Existing Application-Specific Key Derivation Functions December 2011 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-135r1.pdf

Oracle Linux 9 libgcrypt Cryptographic Module Security Policy