| Standard | FIPS 140-3 |
|---|---|
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Status | Active |
| Sunset date | 5/1/2030 |
| Caveat | When operated in approved mode and installed, initialized and configured as specified in Section 11 of the Security Policy. |
| Vendor | Amazon Web Services, Inc. |
flowchart LR
%% Deterministic review-risk graph for Amazon Linux 2023 NSS Cryptographic Module
%% Review prompts and evidence gaps, NOT vulnerability findings.
subgraph CMVP["CMVP-disclosed clues"]
C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>update<br/>Recovery</i>"]
C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>UnAuth<br/>Status Output<br/>Show Status</i>"]
C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>IKEV<br/>IPSEC</i>"]
C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i>"]
end
subgraph Inference["Derived inference"]
I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
end
subgraph Risk["Reviewer question"]
R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
end
subgraph Evidence["Evidence needed to close"]
E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
end
C2 --> I2 --> R2 --> E2
C3 --> I3 --> R3 --> E3
C5 --> I5 --> R5 --> E5
C6 --> I6 --> R6 --> E6
classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
class C2,C3,C5,C6 clue;
class I2,I3,I5,I6 infer;
class R2,R3,R5,R6 risk;
class E2,E3,E5,E6 evidence;flowchart LR
%% Deterministic clue tier for Amazon Linux 2023 NSS Cryptographic Module
%% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
subgraph CMVP["CMVP-disclosed clues (deterministic)"]
C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>update<br/>Recovery</i><br/>src: text:keyword"]
C3["[low] Self-test / status surface (referenced in text)<br/><i>UnAuth<br/>Status Output<br/>Show Status</i><br/>src: text:keyword"]
C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>IKEV<br/>IPSEC</i><br/>src: text:keyword"]
C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i><br/>src: text:keyword"]
end
classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
class C2,C3,C5,C6 clueLow;Amazon Web Services, Inc. Amazon Linux 2023 NSS Cryptographic Module FIPS 140 -3 Non -Proprietary Security Policy Document Version 1. 2 Last update: 202 5-12 -08 Prepared by: atsec information security corporation
4516 Seton Center Pkwy, Suite 250
Austin, TX 78759 www.atsec.com
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y Table of Contents © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 2 o f 4 9
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 3 o f 4 9
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y List of Tables Ta b le 2 : Te s t e d Mo d u le Id e n t ific a t io n – So ft wa re , Firm wa re , Hyb rid (Exe c u t a b le Co d e Se t s ) 1 1 © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 4 o f 4 9
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y List of Figures © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 5 o f 4 9
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y Amazon is a registered trademark of Amazon Web Services, Inc. or its affiliates. © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 6 o f 4 9
| Section | Title | Security Level |
|---|---|---|
| 1 | General | 1 |
| 2 | Cryptographic module specification | 1 |
| 3 | Cryptographic module interfaces | 1 |
| 4 | Roles, services, and authentication | 1 |
| 5 | Software/Firmware security | 1 |
| 6 | Operational environment | 1 |
| 7 | Physical security | N/A |
| 8 | Non-invasive security | N/A |
| 9 | Sensitive security parameter management | 1 |
| 10 | Self-tests | 1 |
| 11 | Life-cycle assurance | 1 |
| 12 | Mitigation of other attacks | 1 |
| Overall Level | 1 |
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y
This document is the non -proprietary FIPS 140 -3 Security Policy for version 3.90.0 3e9a8358c972db98 of the Amazon Linux 2023 NSS Cryptographic Module. It contains the security rules under which the module must operate and describes how this module meets the requirements as specified in FIPS PUB 140 -3 (Federal Information Processing Standards Publication 140 -3) for an overall Security Level 1 module. This Non -Proprietary Security Policy may be reproduced and distributed, but only whole and intact and including this notice. Other documentation is proprietary to their authors.
This Security Policy describes the features and design of the module named Amazon Linux
2023 NSS Cryptographic Module using the terminology contained in the FIPS 140 -3
specification. The FIPS 140 -3 Security Requirements for Cryptographic Module specifies the security requirements that will be satisfied by a cryptogra phic module utilized within a security system protecting sensitive but unclassified information. The NIST/CCCS Cryptographic Module Validation Program (CMVP) validates cryptographic module to FIPS
140 -3. Validated products are accepted by the Federal agenc ies of both the USA and Canada
for the protection of sensitive or designated information. This Non -Proprietary Security Policy may be reproduced and distributed, but only whole and intact and including this notice. Other documentation is proprietary to their authors. The vendor has provided the non -proprietary Security Policy of the cryptographic module, which was further consolidated into this document by atsec information security together with other vendor -supplied documentation. In preparing the Security Policy doc ument, the laboratory formatted the vendor -supplied documentation for consolidation without altering the technical statements therein contained. The further refining of the Security Policy © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 7 o f 4 9
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y d o c u m e n t wa s c o n d u c t e d it e ra t ive ly t h ro u g h o u t t h e c o n fo rm a n c e t e s t in g , wh e re in t h e Se c u rit y Po lic y wa s s u b m it t e d t o t h e ve n d o r, wh o wo u ld t h e n e d it , m o d ify, a n d a d d t e c h n ic a l c o n t e n t s . Th e ve n d o r wo u ld a ls o s u p p ly a d d it io n a l d o c u m e n t a t io n , wh ic h t h e la b o ra t o ry fo rm a t t e d in t o t h e e xis t in g Se c u rit y Po lic y, a n d re s u b m it t e d t o t h e ve n d o r fo r t h e ir fin a l e d it in g . © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 8 o f 4 9
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y
Purpose and Use: The Amazon Linux 2023 NSS Cryptographic Module (hereafter referred to as “the module”) provides a C language application program interface (API) designed to support cross platform development of security -enabled client and server applications. Applications built with NSS can support SSLv3, TLS, IKEv2, PKCS#5, PKCS#7, PKCS#11, PKCS#12, S/MIME, X.509 v3 certificates, and other security standards supporting FIPS 140 -3 validated cryptographic algorithms. It combines a vertical stack of Linux components intended to limit the external interface each separate component may provide. Module Type : Software Module Embodiment : MultiChipStand Module Characteristics : Cryptographic Boundary: Figure 1 shows a block diagram that represents the design of the module when the module is operational and providing services to other user space applications. In this diagram, the physical perimeter of the operational environment (a general -purpose comput er on which the module is installed) is indicated by a purple dashed line. © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 9 o f 4 9
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y Figure 1: Block Diagram The cryptographic boundary is represented by the components painted in orange blocks, which consists of two software components:
| Package or File Name | Software/ Firmware Version | Features | Integrity Test |
|---|---|---|---|
| libsoftokn3.so | 3.90.0 -3e9a8358c972db98 | N/A | DSA signature verification using 2048 -bit key and SHA-256 |
| libfreeblpriv3.so | 3.90.0 -3e9a8358c972db98 | N/A | DSA signature verification using 2048 -bit key and SHA-256 |
| Operating System | Hardware Platform | Processors | PAA/PAI | Hypervisor or Host OS | Version(s) |
|---|---|---|---|---|---|
| Amazon Linux 2023 | EC2 c7g.metal | AWS Graviton3 | Yes | N/A | 3.90.0 -3e9a8358c972db98 |
| Amazon Linux 2023 | EC2 c6i.metal | Intel Xeon Platinum 8375C | Yes | N/A | 3.90.0 -3e9a8358c972db98 |
| Amazon Linux 2023 | EC2 c7g.metal | AWS Graviton3 | No | N/A | 3.90.0 -3e9a8358c972db98 |
| Amazon Linux 2023 | EC2 c6i.metal | Intel Xeon Platinum 8375C | No | N/A | 3.90.0 -3e9a8358c972db98 |
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y
Tested Module Identification
There are no components excluded from the requirements of the FIPS 140 -3 standard.
Modes List and Description: © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 1 1 o f 4 9
| Mode Name | Description | Type | Status Indicator |
|---|---|---|---|
| Approved mode of operation | Automatically entered whenever an approved service is requested | Approved | Equivalent to the indicator of the requested service as defined in section 4.3 |
| Non-approved mode of operation | Automatically entered whenever a non - approved service is requested | Non- Approved | Equivalent to the indicator of the requested service as defined in section 4.3 |
| Algorithm | CAVP Cert | Properties | Reference |
|---|---|---|---|
| AES-CBC | A4576, A4583, A4585 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38A |
| AES-CBC-CS1 | A4581 | Direction - decrypt, encrypt Key Length - 128, 192, 256 | SP 800-38A |
| AES-CMAC | A4578 | Direction - Generation, Verification Key Length - 128, 192, 256 | SP 800-38B |
| AES-CTR | A4576, A4585 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38A |
| AES-ECB | A4576, A4583, A4585 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38A |
| AES-GCM | A4576, A4585 | Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 192, 256 | SP 800-38D |
| AES-GCM | A4583 | Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256 | SP 800-38D |
| AES-KW | A4577, A4582, A4584 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38F |
| AES-KWP | A4577, A4582, A4584 | Direction - Decrypt, Encrypt Key Length - 128, 192, 256 | SP 800-38F |
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y 4.3 4.3 Table 4: Modes List and Description After passing all pre -operational self -tests and cryptographic algorithm self -tests executed on start -up, the module automatically transitions to the approved mode. No operator intervention is required to reach this point. Mode Change Instructions and Status: The module automatically switches between the approved and non -approved modes depending on the services requested by the operator. The status indicator of the mode of The module does not implement a degraded mode of operation.
Approved Algorithms: © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 1 2 o f 4 9
| Algorithm | CAVP Cert | Properties | Reference |
|---|---|---|---|
| DSA SigVer (FIPS186-4) | A4576 | L - 2048 N - 224, 256 Hash Algorithm - SHA-1, SHA2-224, SHA2 -256, SHA2-384, SHA2 -512 | FIPS 186-4 |
| ECDSA KeyGen (FIPS186-4) | A4576 | Curve - P-256, P-384, P-521 Secret Generation Mode - Extra Bits | FIPS 186-4 |
| ECDSA SigGen (FIPS186-4) | A4576 | Component - No Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2 -256, SHA2 -384, SHA2 -512 | FIPS 186-4 |
| ECDSA SigVer (FIPS186-4) | A4576 | Component - No Curve - P-256, P-384, P-521 Hash Algorithm - SHA-1, SHA2-224, SHA2 -256, SHA2 -384, SHA2 -512 | FIPS 186-4 |
| Hash DRBG | A4576 | Prediction Resistance - No, Yes Mode - SHA2-256 | SP 800-90A Rev. 1 |
| HMAC-SHA2-224 | A4576 | Key Length - Key Length: 112 -524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA2-256 | A4576 | Key Length - Key Length: 112 -524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA2-384 | A4576 | Key Length - Key Length: 112 -524288 Increment 8 | FIPS 198-1 |
| HMAC-SHA2-512 | A4576 | Key Length - Key Length: 112 -524288 Increment 8 | FIPS 198-1 |
| KAS-ECC-SSC Sp800-56Ar3 | A4576 | Domain Parameter Generation Methods - P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responder | SP 800-56A Rev. 3 |
| KAS-FFC-SSC Sp800-56Ar3 | A4576 | Domain Parameter Generation Methods - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP -2048, MODP -3072, MODP - 4096, MODP -6144, MODP -8192 Scheme - dhEphem - KAS Role - initiator, responder | SP 800-56A Rev. 3 |
| KDA HKDF Sp800-56Cr1 | A4575 | Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224 -65336 Increment 8 HMAC Algorithm - SHA2-224, SHA2 -256, SHA2 -384, SHA2 -512 | SP 800-56C Rev. 2 |
| KDF IKEv2 (CVL) | A4580 | Diffie-Hellman Shared Secret Length - Diffie-Hellman Shared Secret Length: 224, 2048, 8192 Derived Keying Material Length - Derived Keying Material Length: 1056, 3072 Hash Algorithm - SHA-1, SHA2-256, SHA2 -384, SHA2 -512 | SP 800-135 Rev. 1 |
| KDF SP800-108 | A4579 | KDF Mode - Counter, Double Pipeline Iteration, Feedback Supported Lengths - Supported Lengths: 8, 72, 128, 776, 3456, 4096 | SP 800-108 Rev. 1 |
| KDF TLS (CVL) | A4576 | TLS Version - v1.0/1.1 | SP 800-135 Rev. 1 |
| PBKDF | A4576 | Iteration Count - Iteration Count: 1000 -10000 Increment 1 Password Length - Password Length: 8 -128 Increment 1 | SP 800-132 |
| RSA KeyGen (FIPS186-4) | A4576 | Key Generation Mode - B.3.3 Modulo - 2048, 3072, 4096 Primality Tests - Table C.3 Private Key Format - Standard | FIPS 186-4 |
| RSA SigGen (FIPS186-4) | A4576 | Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096 | FIPS 186-4 |
| RSA SigVer (FIPS186-2) | A4576 | Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024, 1536 | FIPS 186-4 |
| RSA SigVer (FIPS186-4) | A4576 | Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096 | FIPS 186-4 |
| Safe Primes Key Generation | A4576 | Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP -2048, MODP -3072, MODP -4096, MODP -6144, MODP-8192 | SP 800-56A Rev. 3 |
| SHA2-224 | A4576 | Message Length - Message Length: 0 -65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 1 3 o f 4 9
| Algorithm | CAVP Cert | Properties | Reference |
|---|---|---|---|
| SHA2-256 | A4576 | Message Length - Message Length: 0 -65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA2-384 | A4576 | Message Length - Message Length: 0 -65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| SHA2-512 | A4576 | Message Length - Message Length: 0 -65536 Increment 8 Large Message Sizes - 1, 2, 4, 8 | FIPS 180-4 |
| TLS v1.2 KDF RFC7627 (CVL) | A4576 | Hash Algorithm - SHA2-256, SHA2 -384, SHA2 -512 | SP 800-135 Rev. 1 |
| Name | Properties | Implementation | Reference |
|---|---|---|---|
| Cryptographic Key Generation (CKG) | Key Type :Symmetric and Asymmetric | N/A | SP 800-133r2 Section 4, 5.1, 5.2, 6.1 |
| Name | Caveat | Use and Function |
|---|---|---|
| MD5 | Allowed per IG 2.4.A. | Message digest used in TLS 1.0/1.1 KDF only |
| Name | Use and Function |
|---|---|
| RC2, RC4, DES, Triple -DES, CDMF, Camellia, SEED, ChaCha20( -Poly1305) | Encryption, Decryption |
| AES GCM (external IV) | Encryption |
| CBC-MAC, AES XCBC-MAC, AES XCBC-MAC-96 | Message Authentication |
| HMAC (MD2, MD5, SHA -1; < 112 -bit keys) | Message Authentication |
| HMAC/SSLv3 MAC (constant -time implementation) | Message Authentication |
| MD2, MD5, SHA -1, SHA-224, SHA-256, SHA-384, SHA-512, DES, Triple -DES, AES, Camellia, SEED, ANS X9.63 KDF (SHA -1, SHA-224, SHA-256, SHA-384, SHA-512), SSL 3 PRF (MD5, SHA - 1), IKEv1 PRF (AES XCBC -MAC, MD2, MD5, SHA -1, SHA-224, SHA-256, SHA-384, SHA-512) | Key Derivation |
| KBKDF, HKDF, TLS 1.0/1.1 KDF, TLS 1.2 KDF, IKEv2 KDF (< 112 -bit keys) | Key Derivation |
| KBKDF (MD2, MD5) | Key Derivation |
| TLS 1.2 KDF (without extended master secret) | Key Derivation |
| IKEv2 KDF (MD2, MD5) | Key Derivation |
| PKCS#5 PBE, PKCS#12 PBE | Password-based Key Derivation |
| PBKDF2 (password<8 characters, salt<128 bits, iteration count<1000, or key<112 bits) | Password-based Key Derivation |
| J-PAKE | Shared Secret Computation |
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y Table 5: Approved Algorithms Vendor -Affirmed Algorithms: Table 6: Vendor -Affirmed Algorithms Non -Approved, Allowed Algorithms: N/A for this module. Non -Approved, Allowed Algorithms with No Security Claimed: Table 7: Non -Approved, Allowed Algorithms with No Security Claimed Non -Approved, Not Allowed Algorithms: © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 1 4 o f 4 9
| Name | Use and Function |
|---|---|
| DH (Shared secret computation; FIPS 186 -type groups) | Shared Secret Computation |
| ECDH (Shared secret computation; P -192) | Shared Secret Computation |
| DSA (SigGen) | Signature Generation |
| RSA (SigGen primitive; PKCS#1 v1.5 or PSS with MD2, MD5) | Signature Generation |
| ECDSA (SigGen; P-192) | Signature Generation |
| RSA (encryption) | Asymmetric Encryption |
| DSA (parameter generation) | Parameter Generation |
| DH (KeyGen, FIPS 186 -type groups) | Key Pair Generation |
| RSA (KeyGen, modulus < 2048 bits) | Key Pair Generation |
| ECDSA (KeyGen, P -192) | Key Pair Generation |
| Symmetric Key Generation (< 112 bits) | Secret Key Generation |
| MD2, MD5, SHA -1 | Message Digest |
| RSA (SigVer primitive; PKCS#1 v1.5 or PSS with MD2, MD5) | Signature Verification |
| ECDSA (SigVer; P -192) | Signature verification |
| RSA (decryption) | Asymmetric Decryption |
| DSA (parameter verification) | Parameter verification |
| DSA (key pair generation) | Key Pair Generation |
| Name | Type | Description | Properties | Algorithms |
|---|---|---|---|---|
| SHA | SHA | Hash function | Reference:FIPS 180 -4 | SHA2-224 SHA2-256 SHA2-384 SHA2-512 |
| AES (ECB, CBC, CBC- CS1, CTR) | BC-UnAuth | Block cipher | References:FIPS 197, SP 800-38A, SP 800 - 38A Addendum | AES-ECB AES-ECB AES-ECB AES-CBC AES-CBC AES-CBC AES-CBC-CS1 AES-CTR AES-CTR |
| AES (KW, KWP) | BC-Auth | Block cipher | References:FIPS 197, SP 800-38F | AES-KW AES-KWP AES-KW AES-KWP |
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y Table 8: Non -Approved, Not Allowed Algorithms
© 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 1 5 o f 4 9
| Name | Type | Description | Properties | Algorithms AES-KW AES-KWP |
|---|---|---|---|---|
| AES (GCM, encryption, internal IV) | BC-Auth | Block cipher | References:FIPS 197, SP 800-38D | AES-GCM AES-GCM AES-GCM |
| AES (CMAC) | MAC | Message authentication code based on AES | References:FIPS 197, SP 800-38B | AES-CMAC |
| HMAC | MAC | Keyed-hash message authentication code | Reference:FIPS 198 -1 | HMAC-SHA2-256 HMAC-SHA2-384 HMAC-SHA2-512 HMAC-SHA2-224 |
| KBKDF | KBKDF | Key-based key derivation function | Reference:SP 800 - 108r1 | KDF SP800-108 |
| TLS 1.0/1.1 KDF, TLS 1.2 KDF (CVL) | KAS-135KDF | KDF component | Reference:SP 800 - 135r1 | KDF TLS TLS v1.2 KDF RFC7627 |
| HKDF | KAS-56CKDF | HMAC-based key derivation function | Reference:SP 800 - 56Cr1 | KDA HKDF Sp800 - 56Cr1 |
| PBKDF2 | PBKDF | Password-based key derivation function | Reference:SP 800 -132 | PBKDF |
| Hash DRBG | DRBG | Random number generation | Reference:SP 800 - 90Ar1 Compliance:SP800 - 90ARev1 | Hash DRBG |
| KAS-FFC-SSC | KAS-SSC | Diffie-Helman shared secret computation | Reference:SP 800 - 56Ar3 Compliance:IG D.F Scenario 2(1) | KAS-FFC-SSC Sp800- 56Ar3 |
| KAS-ECC-SSC | KAS-SSC | EC Diffie-Helman shared secret computation | Reference:SP 800 - 56Ar3 Compliance:IG D.F Scenario 2(1) | KAS-ECC-SSC Sp800- 56Ar3 |
| DSA SigVer (Legacy) | DigSig-SigVer | DSA signature verification | Reference:FIPS 186 -4 Compliance:FIPS 140 - 3 IG C.M legacy algorithms | DSA SigVer (FIPS186 - 4) L: 2048 bits N: 256 Hash Algorithm: SHA2-256 |
| RSA SigGen | DigSig-SigGen | RSA signature generation | Reference:FIPS 186 -4 | RSA SigGen (FIPS186- 4) |
| RSA SigVer | DigSig-SigVer | RSA signature verification | Reference:FIPS 186 -4 | RSA SigVer (FIPS186 - 4) |
| ECDSA SigGen | DigSig-SigGen | ECDSA signature generation | Reference:FIPS 186 -4 | ECDSA SigGen (FIPS186-4) |
| ECDSA SigVer | DigSig-SigVer | ECDSA signature verification | Reference:FIPS 186 -4 | ECDSA SigVer (FIPS186-4) |
| AES (GCM, decryption, external IV) | BC-Auth | Block cipher | References:FIPS 197, SP 800-38D | AES-GCM AES-GCM AES-GCM |
| AES-KW, AES-KWP, AES-GCM (KTS, key wrapping) | KTS-Wrap | Key wrapping | Reference:SP 800 - 38F, SP 800 -38D Compliance:IG D.G Caveat:key establishment methodology provides between 128 and 256 | AES-KW AES-KWP AES-KW AES-KWP AES-KW AES-KWP AES-GCM |
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 1 6 o f 4 9
| Name | Type | Description | Properties bits of security strength | Algorithms AES-GCM AES-GCM |
|---|---|---|---|---|
| AES-KW, AES-KWP, AES-GCM (KTS, key unwrapping) | KTS-Wrap | Key unwrapping | Reference:SP 800 -38D Compliance:IG D.G Keys :128, 192, 256 bits with 128 -256 bits of keys strength Caveat:key establishment methodology provides between 128 and 256 bits of security strength | AES-GCM AES-GCM AES-GCM AES-KW AES-KWP AES-KW AES-KWP AES-KW AES-KWP |
| Hash DRBG (symmetric key generation) | CKG | Symmetric Key Generation | Reference:SP 800 - 133r2 section 6.1 | Hash DRBG |
| RSA KeyGen (key pair generation) | AsymKeyPair -KeyGen CKG | Key pair generation with RSA | Reference:FIPS 186 -4 | RSA KeyGen (FIPS186 - 4) |
| ECDSA KeyGen (key pair generation) | AsymKeyPair -KeyGen CKG | Key pair generation with ECDSA | Reference:FIPS 186 -4 | ECDSA KeyGen (FIPS186-4) |
| Safe Primes Key Generation (key pair generation) | AsymKeyPair -KeyGen CKG | Key pair generation with Safe Primes | Reference:SP800 - 56Ar3 | Safe Primes Key Generation |
| IKEv2 KDF (CVL) | KAS-135KDF | KDF component | Reference:SP 800 - 135r1 | KDF IKEv2 |
| RSA SigVer (Legacy) | DigSig-SigVer | Legacy digital signature verification | Reference:FIPS186 -2, FIPS186-4 Compliance:FIPS 140 - 3 IG C.M legacy algorithms | RSA SigVer (FIPS186 - 2) RSA SigVer (FIPS186 - 4) Modulo: 1024 Hash Algorithm: SHA - 1 |
| ECDSA SigVer (Legacy) | DigSig-SigVer | Legacy digital signature verification | Reference:FIPS186 -4 Compliance:FIPS 140 - 3 IG C.M legacy algorithms | ECDSA SigVer (FIPS186-4) Hash Algorithm: SHA - 1 |
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y Table 9: Security Function Implementations
The Crypto Officer shall consider the following requirements and restrictions when using the module. For TLS 1.2, the module offers the AES GCM implementation and uses the context of mechanism for IV generation is compliant with RFC 5288 and 8446. The module does not implement the TLS protocol. The module’s implementation of AES GCM is used together with an application that runs outside the module’s cryptographic boundary. The design of the TLS protocol implicitly ensures that the counter (the nonce _explicit part of the IV) does not exhaust the maximum number of possible values for a given session key. In the event the module’s power is lost and restored, the consuming application must ensure that a new key for use with the AES GCM key encryption or decryption under this scenario shall be established. © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 1 7 o f 4 9
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y Alt e rn a t ive ly, t h e Cryp t
3 IG C.H. Th e p ro t o c o l t h a t p ro vid e s t h is c o m p lia n c e is TLS 1 .3 , d e fin e d in RFC8 4 4 6 o f
Au g u s t 2 0 1 8 , u s in g t h e c ip h e r-s u it e s t h a t e xp lic it ly s e le c t AES GCM a s t h e e n c ryp t io n /d e c ryp t io n c ip h e r (Ap p e n d ix B.4 o f RFC8 4 4 6 ). Th e m o d u le s u p p o rt s a c c e p t a b le AES GCM c ip h e r s u it e s fro m Se c t io n 3 .3 .1 o f SP8 0 0 -5 2 r2 . TLS 1 .3 e m p lo ys s e p a ra t e 6 4 -b it s e q u e n c e n u m b e rs , o n e fo r p ro t o c o l re c o rd s t h a t a re re c e ive d , a n d o n e fo r p ro t o c o l re c o rd s t h a t a re s e n t t o a p e e r. Th e s e s e q u e n c e n u m b e rs a re s e t a t ze ro a t t h e b e g in n in g o f a TLS
1 .3 c o n n e c t io n a n d e a c h t im e wh e n t h e AES-GCM ke y is c h a n g e d . Aft e r re a d in g o r writ in g a
re c o rd , t h e re s p e c t ive s e q u e n c e n u m b e r is in c re m e n t e d b y o n e . Th e p ro t o c o l s p e c ific a t io n d e t e rm in e s t h a t t h e s e q u e n c e n u m b e r s h o u ld n o t wra p , a n d if t h is c o n d it io n is o b s e rve d , t h e n t h e p ro t o c o l im p le m e n t a t io n m u s t e it h e r t rig g e r a re -ke y o f t h e s e s s io n (i.e ., a n e w ke y fo r AES-GCM) o r t e rm in a t e t h e c o n n e c t io n .
The module provides password -based key derivation (PBKDF2), compliant with SP 800 -132. The module supports option 1a from Section 5.4 of SP 800 -132, in which the Master Key (MK) or a segment of it is used directly as the Data Protection Key (DPK). In accor dance to SP 800 -132 and FIPS 140 -3 IG D.N, the following requirements shall be met:
| Cert | Vendor |
|---|---|
| Number | Name |
| E124 | Amazon |
| Name | Type | Operational Environment | Sample Size | Entropy per Sample | Conditioning Component |
|---|---|---|---|---|---|
| Amazon Userspace CPU Time Jitter RNG Entropy Source | Non- Physical | Amazon Linux 2023 on EC2 c7g.metal on AWS Graviton3; Amazon Linux 2023 on EC2 c6i.metal on Intel Xeon Platinum 8375C | 256 bits | Full entropy | SHA3-256 (A4551); HMAC-SHA-512 DRBG (A4551) |
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y
To comply with the assurances found in Section 5.6.2 of SP 800 -56Ar3, the operator must use the module together with an application that implements the TLS protocol. Additionally, the module’s approved Key Pair Generation service (see the Approved Services table) must be used to generate ephemeral Diffie -Hellman or EC Diffie -Hel lman key pairs, or the key pairs must be obtained from another FIPS -validated module. As part of this service, the module will internally perform the full public key validation of the generated public key. The module’s shared secret computation service will internally perform the full public key validation of the peer public key, complying with Sections 5.6.2.2.1 and 5.6.2.2.2 of SP 800 56Ar3.
The module does not establish SSPs using an approved key agreement scheme (KAS). However, it does offer some or all of the underlying KAS cryptographic functionality to be used by an external operator/application as part of an approved KAS.
Algorithms designated as “Legacy” can only be used on data that was generated prior to the Legacy Date specified in FIPS 140 -3 IG C.M .
Table 10 : Entropy Certificates Table 11 : Entropy Sources The module employs a Deterministic Random Bit Generator (DRBG) implementation based on SP 800 -90Ar1. This DRBG is used internally by the module (e.g. to generate symmetric keys, seeds for asymmetric key pairs, and random numbers for security functions). It can also be accessed using the specified API functions. The DRBG implemented is a SHA -256 Hash_DRBG, seeded by the entropy source described in the Entropy Sources table. It does not employ prediction resistance. The DRBG is seeded with 440 bits of entropy and reseeded with 440 bits. The entropy source is located within the module’s physical perimeter, but outside of the module’s cryptographic boundary.
The module implements the key generation methods as specified in the Vendor -Affirmed Cryptographic Algorithms table and the Security Function Implementations table. © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 1 9 o f 4 9
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y
The module implements the SSP establishment methods as specified in the Security Function Implementations table.
GCM with internal IV generation in the approved mode is compliant with versions 1.2 and 1.3 of the TLS protocol (RFC 5288 and 8446) and shall only be used in conjunction with the TLS protocol. Additionally, the module implements the TLS 1.0/1.1 and 1.2 key derivation functions for use in the TLS protocol. The module implements the IKEv2 key derivation function for use in the IPSec protocol (RFC 5996). For Diffie -Hellman, the module supports the use of the following safe primes: • IKE (RFC 3 5 2 6 ): MODP-2 0 4 8 (ID = 1 4 ), MODP-3 0 7 2 (ID = 1 5 ), MODP-4 0 9 6 (ID =
• TLS (RFC 7 9 1 9 ): ffd h e 2 0 4 8 (ID = 2 5 6 ), ffd h e 3 0 7 2 (ID = 2 5 7 ), ffd h e 4 0 9 6 (ID =
No o t h e r p a rt s o f t h e TLS o r IPSe c p ro t o c o ls , o t h e r t h a n t h e KDFs m e n t io n e d a b o ve , h a ve b e e n t e s t e d b y t h e CAVP a n d CMVP. © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 2 0 o f 4 9
| Physical Port | Logical Interface(s) | Data That Passes |
|---|---|---|
| N/A | Data Input | API input parameters |
| N/A | Data Output | API output parameters |
| N/A | Control Input | API function calls, API input parameters for control input |
| N/A | Status Output | API return codes |
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y
Table 12 : Ports and Interfaces The module does not have a control output interface. © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 2 1 o f 4 9
| Name | Type | Operator Type | Authentication Methods |
|---|---|---|---|
| Crypto Officer | Role | CO | None |
| Name | Description | Indicator | Inputs | Outputs | Security Functions | SSP Access |
|---|---|---|---|---|---|---|
| Message Digest | Compute a message digest | CKS_NSS_FIPS_OK | Message | Digest value | SHA | Crypto Officer |
| Encryption | Encrypt a plaintext | CKS_NSS_FIPS_OK | AES key, plaintext | Ciphertext | AES (ECB, CBC, CBC- CS1, CTR) | Crypto Officer - AES key: W,E |
| Decryption | Decrypt a ciphertext | CKS_NSS_FIPS_OK | AES key, ciphertext | Plaintext | AES (ECB, CBC, CBC- CS1, CTR) | Crypto Officer - AES key: W,E |
| Authenticated Encryption | Encrypt a plaintext | CKS_NSS_FIPS_OK | Inputs of GCM: AES key, IV, plaintext; Inputs of KW, KWP: AES key, plaintext | Outputs of GCM: Ciphertext, MAC tag; Outputs of KW, KWP: Ciphertext | AES (KW, KWP) AES (GCM, encryption, internal IV) | Crypto Officer - AES key: W,E |
| Authenticated Decryption | Decrypt a ciphertext | CKS_NSS_FIPS_OK | Inputs of GCM: AES key, IV, MAC tag, ciphertext; Inputs of KW, KWP: AES key, ciphertext | Outputs of GCM: Plaintext or fail; Outputs of KW, KWP: Plaintext | AES (KW, KWP) AES (GCM, decryption, external IV) | Crypto Officer - AES key: W,E |
| Key Wrapping | Wrap a CSP | CKS_NSS_FIPS_OK | Inputs of KW, KWP: AES key, any CSP (except for password); Inputs of GCM: AES key, IV, any CSP (except for password) | Outputs of KW, KWP: Wrapped CSP; Outputs of GCM: Wrapped CSP, MAC tag | AES-KW, AES- KWP, AES- GCM (KTS, key wrapping) | Crypto Officer - AES key: W,E |
| Key Unwrapping | Unwrap a CSP | CKS_NSS_FIPS_OK | Inputs of GCM: AES key, IV, | Outputs of GCM: | AES-KW, AES- KWP, AES- | Crypto Officer |
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y
Table 13 : Roles The module supports the Crypto Officer role only. This sole role is implicitly and always assumed by the operator of the module. No support is provided for multiple concurrent operators.
W,E W,E © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 2 2 o f 4 9
| Name | Description | Indicator | Inputs MAC tag, wrapped CSP; Inputs of KW, KWP: AES key, wrapped CSP | Outputs Unwrapped CSP or fail; Outputs of KW, KWP: Unwrapped CSP | Security Functions GCM (KTS, key unwrapping) | SSP Access - AES key: W,E |
|---|---|---|---|---|---|---|
| Message Authentication | Compute a MAC tag | CKS_NSS_FIPS_OK | Inputs of AES - CMAC: AES key, message. Inputs of HMAC: HMAC key, message | MAC tag | AES (CMAC) HMAC | Crypto Officer - AES key: W,E - HMAC key: W,E |
| Password- based Key Derivation | Derive a key from a password | CKS_NSS_FIPS_OK | Password, salt, iteration count | PBKDF derived key | PBKDF2 | Crypto Officer - Password: W,E - PBKDF derived key: G |
| Random Number Generation | Generate random bytes | CKR_OK | Output length | Random bytes | Hash DRBG | Crypto Officer - Entropy input: W,E - DRBG seed: G,E - Internal state (V, C): G,W,E |
| Shared Secret Computation | Compute a shared secret | CKS_NSS_FIPS_OK | Inputs of KAS - FFC-SSC: DH private key (owner), DH public key (peer). Inputs of KAS-ECC-SSC: EC private key (owner), EC public key (peer) | Shared secret | KAS-FFC-SSC KAS-ECC-SSC | Crypto Officer - EC private key: W,E - EC public key: W,E - Shared secret: G - DH private key: W,E - DH public key: W,E |
| Signature Generation | Generate a signature | CKS_NSS_FIPS_OK | Inputs of RSA SigGen: RSA private key, message. Inputs of ECDSA SigGen: EC private key, message | Signature | RSA SigGen ECDSA SigGen | Crypto Officer - RSA private key: W,E - EC private key: W,E |
| Signature Verification | Verify a signature | Indicator of DSA SigVer: CKR_OK. Indicator of RSA SigVer: CKS_NSS_FIPS_OK. Indicator of ECDSA SigVer: CKS_NSS_FIPS_OK | Inputs of DSA SigVer: DSA public key, message, signature. Inputs of RSA SigVer: RSA public key, message, signature. Inputs of ECDSA SigVer: EC public key, | Pass/fail | DSA SigVer (Legacy) RSA SigVer ECDSA SigVer RSA SigVer (Legacy) ECDSA SigVer (Legacy) | Crypto Officer - DSA public key: W,E - RSA public key: W,E - EC public key: W,E |
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y W,E W,E G G,E G,W,E © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 2 3 o f 4 9
| Name | Description | Indicator | Inputs message, signature. | Outputs | Security Functions | SSP Access |
|---|---|---|---|---|---|---|
| Secret Key Generation | Generate a symmetric key | CKS_NSS_FIPS_OK | Key size | AES key, HMAC key, or Key - derivation key | Hash DRBG (symmetric key generation) | Crypto Officer - AES key: G - HMAC key: G - Key- derivation key: G |
| Key Pair Generation | Generate a key pair | CKS_NSS_FIPS_OK | Safe Primes Key Generation: Group; RSA KeyGen: Modulus size; ECDSA KeyGen: Curve | Safe Primes Key Generation: DH public & private key; RSA KeyGen: RSA public & private key; ECDSA KeyGen: EC public & private key | RSA KeyGen (key pair generation) ECDSA KeyGen (key pair generation) Safe Primes Key Generation (key pair generation) | Crypto Officer - DH private key: G - DH public key: G - EC private key: G - EC public key: G - RSA private key: G - RSA public key: G - Intermediate key generation value: G,E,Z |
| Show Version | Return the module name and version information | None | N/A | Module name and version information | None | Crypto Officer |
| Show Status | Return the module status | None | N/A | Module status | None | Crypto Officer |
| Self-Test | Perform the CASTs and integrity tests | None | N/A | Pass/fail | SHA AES (ECB, CBC, CBC- CS1, CTR) AES (GCM, encryption, internal IV) AES (CMAC) HMAC KBKDF TLS 1.0/1.1 KDF, TLS 1.2 KDF (CVL) HKDF PBKDF2 Hash DRBG KAS-FFC-SSC KAS-ECC-SSC DSA SigVer (Legacy) RSA SigGen RSA SigVer ECDSA SigGen ECDSA SigVer | Crypto Officer |
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y G © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 2 4 o f 4 9
| Name | Description | Indicator | Inputs | Outputs | Security Functions AES (GCM, decryption, external IV) Hash DRBG (symmetric key generation) RSA KeyGen (key pair generation) ECDSA KeyGen (key pair generation) Safe Primes Key Generation (key pair generation) IKEv2 KDF (CVL) RSA SigVer (Legacy) ECDSA SigVer (Legacy) | SSP Access |
|---|---|---|---|---|---|---|
| Zeroization | Zeroize any SSP | None | Any SSP | None | None | Crypto Officer - AES key: Z - HMAC key: Z - Key- derivation key: Z - Shared secret: Z - Password: Z - PBKDF derived key: Z - Entropy input: Z - DRBG seed: Z - Internal state (V, C): Z - DH private key: Z - DH public key: Z - EC private key: Z - EC public key: Z - DSA public key: Z - RSA private key: Z - RSA public key: Z - Intermediate |
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y Z Z Z Z © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 2 5 o f 4 9
| Name | Description | Indicator | Inputs | Outputs | Security Functions | SSP Access key generation value: Z - HKDF Derived key: Z - KBKDF derived key: Z - TLS derived key: Z - IKEv2 derived key: Z |
|---|---|---|---|---|---|---|
| Key-based Key Derivation | Derive a key from a key - derivation key | CKS_NSS_FIPS_OK | Key-derivation key | KBKDF derived key | KBKDF | Crypto Officer - Key- derivation key: W,E - KBKDF derived key: G |
| HMAC-based Key Derivation | Derive a key from a shared secret | CKS_NSS_FIPS_OK | Shared secret | HKDF derived key | HKDF | Crypto Officer - Shared secret: W,E - HKDF Derived key: G |
| IKEv2 Key Derivation | Derived a key from a shared secret | CKS_NSS_FIPS_OK | Shared secret | IKEv2 derived key | IKEv2 KDF (CVL) | Crypto Officer - Shared secret: W,E - IKEv2 derived key: G |
| TLS Key Derivation | Derive a key from a shared secret | CKS_NSS_FIPS_OK | Shared secret | TLS derived key | TLS 1.0/1.1 KDF, TLS 1.2 KDF (CVL) | Crypto Officer - Shared secret: W,E - TLS derived key: G |
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y Z Z Z G G G Table 14 : Approved Services The following convention is used to specify access rights to SSPs:
1 . Th e s e s s io n in d ic a t o r, wh ic h m u s t b e u s e d fo r a ll c ryp t o g ra p h ic s e rvic e s e xc e p t
t h e Ke y De riva t io n s e rvic e . It c a n b e a c c e s s e d b y in vo kin g t h e © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 2 6 o f 4 9
| Name | Description | Algorithms | Role |
|---|---|---|---|
| Message Digest | Compute a message digest | MD2, MD5, SHA -1 | CO |
| Encryption | Encrypt a plaintext | RC2, RC4, DES, Triple -DES, CDMF, Camellia, SEED, ChaCha20( - Poly1305) AES GCM (external IV) | CO |
| Decryption | Decrypt a ciphertext | RC2, RC4, DES, Triple -DES, CDMF, Camellia, SEED, ChaCha20( - Poly1305) | CO |
| Message Authentication | Compute a MAC tag | CBC-MAC, AES XCBC-MAC, AES XCBC-MAC-96 HMAC (MD2, MD5, SHA -1; < 112 -bit keys) HMAC/SSLv3 MAC (constant -time implementation) | CO |
| Key Derivation | Derive a key from a key-derivation key or a shared secret | MD2, MD5, SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, DES, Triple-DES, AES, Camellia, SEED, ANS X9.63 KDF (SHA -1, SHA-224, SHA-256, SHA-384, SHA-512), SSL 3 PRF (MD5, SHA -1), IKEv1 PRF (AES XCBC-MAC, MD2, MD5, SHA -1, SHA-224, SHA-256, SHA-384, SHA-512) KBKDF, HKDF, TLS 1.0/1.1 KDF, TLS 1.2 KDF, IKEv2 KDF (< 112 -bit keys) KBKDF (MD2, MD5) TLS 1.2 KDF (without extended master secret) IKEv2 KDF (MD2, MD5) | CO |
| Password-Based Key Derivation | Derive a key from a password | PKCS#5 PBE, PKCS#12 PBE PBKDF2 (password<8 characters, salt<128 bits, iteration count<1000, or key<112 bits) | CO |
| Shared Secret Computation | Compute a shared secret | J-PAKE DH (Shared secret computation; FIPS 186 -type groups) ECDH (Shared secret computation; P -192) | CO |
| Signature Generation | Generate a signature | DSA (SigGen) RSA (SigGen primitive; PKCS#1 v1.5 or PSS with MD2, MD5) ECDSA (SigGen; P-192) | CO |
| Asymmetric Encryption | Encrypt a plaintext | RSA (encryption) | CO |
| Asymmetric Decryption | Decrypt a plaintext | RSA (decryption) | CO |
| Parameter Generation | Generate domain parameters | DSA (parameter generation) | CO |
| Parameter Verification | Verify domain parameters | DSA (parameter verification) | CO |
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y NSC_NSSGe t FIPSSt a t u s fu n c t io n wit h t h e CKT_NSS_SESSION_LAST_CHECK p a ra m e t e r. If t h e o u t p u t p a ra m e t e r is s e t t o CKS_NSS_FIPS_OK (1 ), t h e s e rvic e wa s a p p ro ve d .
2 . Th e o b je c t in d ic a t o r, wh ic h m u s t b e u s e d fo r t h e Ke y De riva t io n s e rvic e . It c a n b e
a c c e s s e d b y in vo kin g t h e NSC_NSSGe t FIPSSt a t u s fu n c t io n wit h t h e CKT_NSS_OBJECT_CHECK p a ra m e t e r a n d t h e o u t p u t d e rive d ke y. If t h e o u t p u t p a ra m e t e r is s e t t o CKS_NSS_FIPS_OK (1 ), t h e s e rvic e wa s a p p ro ve d .
3 . Th e Ra n d o m Nu m b e r Ge n e ra t io n s e rvic e in d ic a t o r, wh ic h m u s t b e u s e d fo r t h e
Ra n d o m Nu m b e r Ge n e ra t io n s e rvic e . It c a n b e a c c e s s e d b y in vo kin g t h e C_Se e d Ra n d o m o r C_Ge n e ra t e Ra n d o m fu n c t io n s . If a n y o f t h e s e fu n c t io n s re t u rn s CKR_OK, t h e s e rvic e wa s a p p ro ve d .
4 . Th e DSA Sig n a t u re Ve rific a t io n in d ic a t o r, wh ic h m u s t b e u s e d fo r t h e DSA
Sig n a t u re Ve rific a t io n s e rvic e . It c a n b e a c c e s s e d b y in vo kin g t h e C_Ve rifyIn it fu n c t io n wit h a n y CKM_DSA_* m e c h a n is m p a ra m e t e r. If t h is fu n c t io n re t u rn s CKR_OK, t h e s e rvic e wa s a p p ro ve d .
© 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 2 7 o f 4 9
| Name | Description | Algorithms | Role |
|---|---|---|---|
| Key Pair Generation | Generate a key pair | DH (KeyGen, FIPS 186 -type groups) RSA (KeyGen, modulus < 2048 bits) ECDSA (KeyGen, P -192) DSA (key pair generation) | CO |
| Secret Key Generation | Generate a symmetric key | Symmetric Key Generation (< 112 bits) | CO |
| Signature Verification | Verify a signature | RSA (SigVer primitive; PKCS#1 v1.5 or PSS with MD2, MD5) ECDSA (SigVer; P-192) | CO |
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y Table 15 : Non -Approved Services The indicator value for the non -approved services specified in the Non -Approved Services table is CKS_NSS_FIPS_NOT_OK (0).
The module does not load external software or firmware. © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 2 8 o f 4 9
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y
The integrity of the module is verified by performing DSA signature verification with a 2048 bit key and SHA -256. Each software component of the module has an associated integrity check value, which contains the DSA signature of the shared library.
Integrity tests are performed as part of the pre -operational self -tests, which are executed when the module is initialized. The integrity tests may be invoked on -demand by unloading and subsequently re -initializing the module, which will perform (among oth ers) the software integrity tests. © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 2 9 o f 4 9
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y
Type of Operational Environment: Modifiable How Requirements are Satisfied: Any SSPs contained within the module are protected by the process isolation and memory separation mechanisms provided by the Linux kernel, and only the module has control over these SSPs.
The module shall be installed as stated in Section 11. If properly installed, the operating system provides process isolation and memory protection mechanisms that ensure appropriate separation for memory access among the processes on the system. Each proc ess has control over its own data and uncontrolled access to the data of other processes is prevented. Instrumentation tools like the ptrace system call, gdb and strace, userspace live patching, as well as other tracing mechanisms offered by the Linux environment such as ftrace or systemtap, shall not be used in the operational environment. The use of any of these tools implies that the cryptographic module is running in a non -validated operational environment. © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 3 0 o f 4 9
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y
The module is comprised of software only and therefore this section is not applicable. © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 3 1 o f 4 9
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y
This module does not implement any non -invasive security mechanism and therefore this section is not applicable. © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 3 2 o f 4 9
| Storage Area Name | Description | Persistence Type |
|---|---|---|
| RAM | Temporary storage for SSPs used by the module as part of service execution. | Dynamic |
| Name API input parameters (plaintext) | From Calling application within TOEPP | To Cryptographic module | Format Type Plaintext | Distribution Type Manual | Entry Type Electronic | SFI or Algorithm |
|---|---|---|---|---|---|---|
| API input parameters (encrypted) | Calling application within TOEPP | Cryptographic module | Encrypted | Manual | Electronic u | AES-KW, AES-KWP, AES-GCM (KTS, key nwrapping) |
| API output parameters (plaintext) | Cryptographic module | Calling application within TOEPP | Plaintext | Manual | Electronic | |
| API output parameters (encrypted) | Cryptographic module | Calling application within TOEPP | Encrypted | Manual | Electronic | AES-KW, AES-KWP, AES-GCM (KTS, key wrapping) |
| Zeroization Method | Description | Rationale | Operator Initiation |
|---|---|---|---|
| Destroy Object | Destroys the SSP represented by the object | Memory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable. The completion of the zeroization routine indicates that the zeroization procedure succeeded. | By calling the C_DestroyObject function |
| Automatic | Automatically zeroized by the module when no longer needed | Memory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable | N/A |
| Remove power from the module | De-allocates the volatile memory used to store SSPs | Volatile memory used by the module is overwritten within nanoseconds when power is removed. Module power off indicates that the zeroization procedure succeeded. | By removing power |
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y
Table 16 : Storage Areas The module does not perform persistent storage of SSPs. SSPs are provided to the module (encrypted) unwrapping) Table 17 : SSP Input -Output Methods CSPs (with the exception of passwords) can only be imported to and exported from the module when they are wrapped (encrypted) using an approved security function (e.g. AES KW or KWP). PSPs can be imported and exported in plaintext. Import and export is per formed using API input and output parameters. The module only supports SSP entry and output to and from the calling application running on the same operational environment. Table 18 : SSP Zeroization Methods © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 3 3 o f 4 9
Name AES key HMAC key Key- derivation key Shared secret Password HKDF Derived key Entropy input DRBG seed Internal state (V, C) DH private key
Description AES key used for encryption, decryption, and computing MAC tags HMAC key used for computing MAC tags Symmetric key used to derive symmetric keys Shared secret generated by (EC) Diffie - Hellman Password used to derive symmetric keys Symmetric key derived from a shared secret Entropy input used to seed the DRBG DRBG seed derived from entropy input Internal state of the Hash_DRBG instance Private key used for Diffie - Hellman
Size - Strength 128, 192, 256 bits - 128, 192, 256 bits 112-524288 bits - 112-256 bits 112-4096 bits - 112- 256 bits 256-8192 bits - 112- 256 bits 8-128 characters - N/A 2048 bits - 112-256 bits 440 bits - 440 bits 440 bits - 256 bits 880 bits - 256 bits 2048-8192 bits - 112- 200 bits
Type - Category Symmetric key - CSP Symmetric key - CSP Symmetric key - CSP Shared secret - CSP Password - CSP Symmetric key - CSP Entropy input - CSP Seed - CSP Internal state - CSP Private key - CSP
Generated By Hash DRBG (symmetric key generation) Hash DRBG (symmetric key generation) Hash DRBG (symmetric key generation) HKDF Hash DRBG Hash DRBG Safe Primes Key Generation (key pair generation)
Established By KAS-FFC-SSC KAS-ECC- SSC
Used By AES (ECB, CBC, CBC-CS1, CTR) AES (KW, KWP) AES (GCM, encryption, internal IV) AES (CMAC) AES (GCM, decryption, external IV) AES-KW, AES- KWP, AES-GCM (KTS, key wrapping) AES-KW, AES- KWP, AES-GCM (KTS, key unwrapping) HMAC KBKDF TLS 1.0/1.1 KDF, TLS 1.2 KDF (CVL) HKDF IKEv2 KDF (CVL) PBKDF2 Hash DRBG Hash DRBG Hash DRBG KAS-FFC-SSC
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y All d a t a o u t p u t is in h ib it e d d u rin g ze ro iza t io n . Me m o ry is d e a llo c a t e d a ft e r ze ro iza t io n .
© 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 3 4 o f 4 9
Name DH public key EC private key EC public key DSA public key RSA private key RSA public key Intermediate key generation value KBKDF derived key TLS derived key IKEv2 derived key PBKDF derived key
Description Public key used for Diffie - Hellman Private key used for ECDH and ECDSA Public key used for ECDH and ECDSA Public key used for DSA signature verification Private key used for RSA signature generation Public key used for RSA signature verification Temporary value generated during symmetric key and key pair generation services Symmetric key derived from a key-derivation key Symmetric key derived from a shared secret Symmetric key derived from a shared secret Symmetric key derived from a password
Size - Strength 2048-8192 bits - 112- 200 bits P-256, P-384, P-521 - 128, 192, 256 bits P-256, P-384, P-521 - 128, 192, 256 bits (1024, 160), (2048, 224), (2048, 256), (3072, 256) - 80, 112, 128 bits 2048-4096 bits - 112- 150 bits Signature verification: 1024 - 4096 bits; Key pair generation: 2048 - 4096 bits - Signature verification: 80 - 150 bits; Key pair generation: 112 - 150 bits 112-8192 bits - 112- 256 bits 112-4096 bits - 112- 256 bits 112-256 bits - 112- 256 bits 112-256 bits - 112- 256 bits 128-2048 bits - 112- 256 bits
Type - Category Public key - PSP Private key - CSP Public key - PSP Public key - PSP Private key - CSP Public key - PSP Intermediate value - CSP Symmetric key - CSP Symmetric key - CSP Symmetric key - CSP Symmetric key - CSP
Generated By Safe Primes Key Generation (key pair generation) ECDSA KeyGen (key pair generation) ECDSA KeyGen (key pair generation) RSA KeyGen (key pair generation) RSA KeyGen (key pair generation) RSA KeyGen (key pair generation) ECDSA KeyGen (key pair generation) Safe Primes Key Generation (key pair generation) KBKDF TLS 1.0/1.1 KDF, TLS 1.2 KDF (CVL) IKEv2 KDF (CVL) PBKDF2
Established By
Used By KAS-FFC-SSC KAS-ECC-SSC ECDSA SigGen KAS-ECC-SSC ECDSA SigVer ECDSA SigVer (Legacy) DSA SigVer (Legacy) RSA SigGen RSA SigVer RSA SigVer (Legacy) RSA KeyGen (key pair generation) ECDSA KeyGen (key pair generation) Safe Primes Key Generation (key pair generation)
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y Table 19 : SSP Table 1 © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 3 5 o f 4 9
| Name AES key HMAC key | Input - Output API input parameters (encrypted) API output parameters (encrypted) API input parameters (encrypted) API output parameters (encrypted) | Storage RAM:Plaintext RAM:Plaintext | Storage Duration Until explicitly zeroized by operator Until explicitly zeroized by operator | Zeroization Destroy Object Remove power from the module Destroy Object Remove power from the module | Related SSPs |
|---|---|---|---|---|---|
| Key-derivation key | API input parameters (encrypted) | RAM:Plaintext | Until explicitly zeroized by operator | Destroy Object Remove power from the module | KBKDF derived key:Used to derive |
| Shared secret | API input parameters (encrypted) API output parameters (encrypted) | RAM:Plaintext | Until explicitly zeroized by operator | Destroy Object Remove power from the module | DH private key:Established using DH public key:Established using EC private key:Established using EC public key:Established using TLS derived key:Used to derive IKEv2 derived key:Used to derive HKDF Derived key:Used to derive |
| Password | API input parameters (plaintext) | RAM:Plaintext | For the duration of the service | Destroy Object Remove power from the module | PBKDF derived key:Used to derive |
| HKDF Derived key | API output parameters (encrypted) | RAM:Plaintext | Until explicitly zeroized by operator | Destroy Object Remove power from the module | Shared secret:Derived From |
| Entropy input | RAM:Plaintext | From generation until DRBG seed is created | Automatic Remove power from the module | DRBG seed:Used to derive | |
| DRBG seed | RAM:Plaintext | While the DRBG is instantiated | Automatic Remove power from the module | Entropy input:Derived From Internal state (V, C):Used to generate | |
| Internal state (V, C) | RAM:Plaintext | While the module is operational | Remove power from the module | DRBG seed:Generated from | |
| DH private key | API input parameters (encrypted) API output parameters (encrypted) | RAM:Plaintext | Until explicitly zeroized by operator | Destroy Object Remove power from the module | DH public key:Paired With Intermediate key generation value:Generated from |
| DH public key | API input parameters (plaintext) API output parameters (plaintext) | RAM:Plaintext | Until explicitly zeroized by operator | Destroy Object Remove power from the module | DH private key:Paired With Intermediate key generation value:Generated from |
| EC private key | API input parameters (encrypted) API output | RAM:Plaintext | Until explicitly zeroized by operator | Destroy Object Remove power from the module | EC public key:Paired With Intermediate key generation value:Generated from |
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 3 6 o f 4 9
| Name | Input - Output parameters (encrypted) | Storage | Storage Duration | Zeroization | Related SSPs |
|---|---|---|---|---|---|
| EC public key | API input parameters (plaintext) API output parameters (plaintext) | RAM:Plaintext | Until explicitly zeroized by operator | Destroy Object Remove power from the module | EC private key:Paired With Intermediate key generation value:Generated from |
| DSA public key | API input parameters (plaintext) | RAM:Plaintext | Until explicitly zeroized by operator | Destroy Object Remove power from the module | |
| RSA private key | API input parameters (encrypted) API output parameters (encrypted) | RAM:Plaintext | Until explicitly zeroized by operator | Destroy Object Remove power from the module | RSA public key:Paired With Intermediate key generation value:Generated from |
| RSA public key | API input parameters (plaintext) API output parameters (plaintext) | RAM:Plaintext | Until explicitly zeroized by operator | Destroy Object Remove power from the module | RSA private key:Paired With Intermediate key generation value:Generated from |
| Intermediate key generation value | RAM:Plaintext | For the duration of the service | Automatic | DH private key:Created during generation of DH public key:Created during generation of EC private key:Created during generation of EC public key:Created during generation of RSA private key:Created during generation of RSA public key:Created during generation of | |
| KBKDF derived key | API output parameters (encrypted) | RAM:Plaintext | For the duration of the service | Destroy Object Remove power from the module | Key-derivation key:Derived From |
| TLS derived key | API output parameters (encrypted) | RAM:Plaintext | For the duration of the service | Destroy Object Remove power from the module | Shared secret:Derived From |
| IKEv2 derived key | API output parameters (encrypted) | RAM:Plaintext | For the duration of the service | Destroy Object Remove power from the module | Shared secret:Derived From |
| PBKDF derived key | API output parameters (encrypted) | RAM:Plaintext | For the duration of the service | Destroy Object Remove power from the module | Password:Derived From |
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y Table 20 : SSP Table 2
The SHA -1 algorithm as implemented by the module will be non -approved for all purposes, starting January 1, 203 1. The ECDSA, and RSA algorithms as implemented by the module conform to FIPS 186 -4, which has been superseded by FIPS 186 -5. The transition started on July 25, 2023, and ended on February 4, 2024 . FIPS 186 -4 was withdrawn on February 3, 2024. © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 3 7 o f 4 9
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 3 8 o f 4 9
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details |
|---|---|---|---|---|---|
| DSA SigVer (FIPS186-4) (A4576) | 2048-bit key with SHA-256 | Signature Verification | SW/FW Integrity | Module becomes operational | Integrity test for libfreeblpriv3.so and libfsoftokn3.so |
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | Conditions |
|---|---|---|---|---|---|---|
| SHA-1 (A4576) | 512-bit message | KAT | CAST | Module becomes operational and services are available for use | Message Digest | Freebl initialization |
| SHA2-224 (A4576) | 512-bit message | KAT | CAST | Module becomes operational and services are available for use | Message Digest | Freebl initialization |
| SHA2-256 (A4576) | 512-bit message | KAT | CAST | Module becomes operational and services are available for use | Message Digest | Freebl initialization |
| SHA2-384 (A4576) | 512-bit message | KAT | CAST | Module becomes operational and services are available for use | Message Digest | Freebl initialization |
| SHA2-512 (A4576) | 512-bit message | KAT | CAST | Module becomes operational and | Message Digest | Freebl initialization |
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y
Upon initialization, the module immediately performs all Freebl cryptographic algorithm self tests (CASTs) as specified in the Conditional Self -Tests table. When all those self -tests pass successfully, the module automatically performs the pre -operational integrity test on the libfreeblpriv3.so file using its associated check value. Then, the module performs the DSA CAST in the Softoken library, followed by the the pre operational integrity test on the libsoftokn3.so file using its associated check value. Finally, all remaining CASTs for the algorithms implemented in Softoken are exec uted (see the Conditional Self -Tests table). Only if all CASTs and pre -operational integrity tests passed successfully, the module transitions to the operational state. No operator intervention is required to reach this point. While the module is executing the self -tests, services are not available, and data output (via the data output interface) is inhibited until the tests are successfully completed. If any of the self -tests fail an error message is returned, and the module tr ansitions to an error state.
10.1 Pre -Operational Self -Tests
Table 21 : Pre -Operational Self -Tests Each software component of the module has an associated integrity check value, which contains the DSA signature of the shared library. The software integrity tests ensure that the module is not corrupted. The DSA and SHA -256 algorithms go through their res pective CASTs before the software integrity tests are performed.
© 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 3 9 o f 4 9
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator services are available for use | Details | Conditions |
|---|---|---|---|---|---|---|
| AES-ECB (A4576) | 128, 192, 256 -bit key, 128-bit plaintext | KAT | CAST | Module becomes operational and services are available for use | Encryption, Decryption | Freebl initialization |
| AES-ECB (A4583) | 128, 192, 256 -bit key, 128-bit plaintext | KAT | CAST | Module becomes operational and services are available for use | Encryption, Decryption | Freebl initialization |
| AES-ECB (A4585) | 128, 192, 256 -bit key, 128-bit plaintext | KAT | CAST | Module becomes operational and services are available for use | Encryption, Decryption | Freebl initialization |
| AES-CBC (A4576) | 128, 192, 256 -bit key, 128-bit plaintext | KAT | CAST | Module becomes operational and services are available for use | Encryption, Decryption | Freebl initialization |
| AES-CBC (A4581) | 128, 192, 256 -bit key, 128-bit plaintext | KAT | CAST | Module becomes operational and services are available for use | Encryption, Decryption | Freebl initialization |
| AES-CBC (A4583) | 128, 192, 256 -bit key, 128-bit plaintext | KAT | CAST | Module becomes operational and services are available for use | Encryption, Decryption | Freebl initialization |
| AES-CBC (A4585) | 128, 192, 256 -bit key, 128-bit plaintext | KAT | CAST | Module becomes operational and services are available for use | Encryption, Decryption | Freebl initialization |
| AES-GCM (A4576) | 128, 192, 256 -bit key, 128-bit IV, 128 -bit plaintext, 112 -bit additional data | KAT | CAST | Module becomes operational and services are available for use | Encryption, Decryption | Freebl initialization |
| AES-GCM (A4583) | 128, 192, 256 -bit key, 128-bit IV, 128 -bit plaintext, 112 -bit additional data | KAT | CAST | Module becomes operational and services are available for use | Encryption, Decryption | Freebl initialization |
| AES-GCM (A4585) | 128, 192, 256 -bit key, 128-bit IV, 128 -bit plaintext, 112 -bit additional data | KAT | CAST | Module becomes operational and services are available for use | Encryption, Decryption | Freebl initialization |
| AES-CMAC (A4578) | 128, 192, 256 -bit key, 128-bit message | KAT | CAST | Module becomes operational and services are available for use | Message Authentication | Freebl initialization |
| HMAC-SHA-1 (A4576) | 288-bit key | KAT | CAST | Module becomes operational and services are available for use | Message Authentication | Freebl initialization |
| HMAC-SHA2- 224 (A4576) | 288-bit key | KAT | CAST | Module becomes operational and services are available for use | Message Authentication | Freebl initialization |
| HMAC-SHA2- 256 (A4576) | 288-bit key | KAT | CAST | Module becomes operational and services are available for use | Message Authentication | Freebl initialization |
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 4 0 o f 4 9
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | Conditions |
|---|---|---|---|---|---|---|
| HMAC-SHA2- 384 (A4576) | 288-bit key | KAT | CAST | Module becomes operational and services are available for use | Message Authentication | Freebl initialization |
| HMAC-SHA2- 512 (A4576) | 288-bit key | KAT | CAST | Module becomes operational and services are available for use | Message Authentication | Freebl initialization |
| KDF SP800-108 (A4579) | Counter mode HMAC SHA-256 576-bit input key | KAT | CAST | Module becomes operational and services are available for use | Key Derivation | Softoken initialization |
| KDA HKDF Sp800-56Cr1 (A4575) | SHA-256, 512 -bit input secret | KAT | CAST | Module becomes operational and services are available for use | Key Derivation | Softoken initialization |
| KDF TLS (A4576) | 288-bit input secret | KAT | CAST | Module becomes operational and services are available for use | Key Derivation | Freebl initialization |
| TLS v1.2 KDF RFC7627 (A4576) | SHA-256, 288 -bit input secret | KAT | CAST | Module becomes operational and services are available for use | Key Derivation | Freebl initialization |
| KDF IKEv2 (A4580) | SHA-1, SHA-256, SHA- 384, SHA-512; 80, 128, 144 -bit input secret | KAT | CAST | Module becomes operational and services are available for use | Key Derivation | Softoken initialization |
| PBKDF (A4576) | SHA-256, 14 - character password, 128-bit salt, Iteration count: 5 | KAT | CAST | Module becomes operational and services are available for use | Key Derivation | Softoken initialization |
| Hash DRBG (A4576) | SHA-256 without prediction resistance | KAT | CAST | Module becomes operational and services are available for use | Instantiate, Generate, Reseed, Generate (compliant to SP 800 -90A Section 11.3) | Freebl initialization |
| KAS-FFC-SSC Sp800-56Ar3 (A4576) | 2048-bit key | KAT | CAST | Module becomes operational and services are available for use | Shared Secret Computation | Freebl initialization |
| KAS-ECC-SSC Sp800-56Ar3 (A4576) | P-256 | KAT | CAST | Module becomes operational and services are available for use | Shared Secret Computation | Freebl initialization |
| DSA SigVer (FIPS186-4) (A4576) | 1024-bit key | KAT | CAST | Module becomes operational and services are available for use | Signature verification | Freebl initialization |
| RSA SigGen (FIPS186-4) (A4576) | PKCS#1 v1.5 with SHA-256, SHA-384, SHA-512, 2048 -bit key | KAT | CAST | Module becomes operational and services are available for use | Signature Generation | Softoken initialization |
| RSA SigVer (FIPS186-4) (A4576) | PKCS#1 v1.5 with SHA-256, SHA-384, SHA-512, 2048 -bit key | KAT | CAST | Module becomes operational and services are available for use | Signature Verification | Softoken initialization |
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 4 1 o f 4 9
| Algorithm or Test | Test Properties | Test Method | Test Type | Indicator | Details | Conditions |
|---|---|---|---|---|---|---|
| ECDSA SigGen (FIPS186-4) (A4576) | SHA-256, P-256 | KAT | CAST | Module becomes operational and services are available for use | Signature Generation | Freebl initialization |
| ECDSA SigVer (FIPS186-4) (A4576) | SHA-256, P-256 | KAT | CAST | Module becomes operational and services are available for use | Signature Verification | Freebl initialization |
| Safe Primes Key Generation (A4576) | N/A | PCT | PCT | Successful key pair generation | SP 800-56Ar3 section 5.6.2.1.4 | Key pair generation |
| RSA KeyGen (FIPS186-4) (A4576) | PKCS#1 v1.5 with SHA-256 | PCT | PCT | Successful key pair generation | Signature Generation & Signature Verification | Key pair generation |
| ECDSA KeyGen (FIPS186-4) (A4576) | ECDSA KeyGen: SHA - 256; EC KeyGen for ECDH | PCT | PCT | Successful key pair generation | Signature Generation & Signature Verification; SP 800-56Ar3 section 5.6.2.1.4 | Key pair generation |
| Algorithm or Test | Test Method | Test Type | Period | Periodic Method |
|---|---|---|---|---|
| DSA SigVer (FIPS186 - 4) (A4576) | Signature Verification | SW/FW Integrity | On demand | Manually |
| Algorithm or Test | Test Method | Test Type | Period | Periodic Method |
|---|---|---|---|---|
| SHA-1 (A4576) | KAT | CAST | On demand | Manually |
| SHA2-224 (A4576) | KAT | CAST | On demand | Manually |
| SHA2-256 (A4576) | KAT | CAST | On demand | Manually |
| SHA2-384 (A4576) | KAT | CAST | On demand | Manually |
| SHA2-512 (A4576) | KAT | CAST | On demand | Manually |
| AES-ECB (A4576) | KAT | CAST | On demand | Manually |
| AES-ECB (A4583) | KAT | CAST | On demand | Manually |
| AES-ECB (A4585) | KAT | CAST | On demand | Manually |
| AES-CBC (A4576) | KAT | CAST | On demand | Manually |
| AES-CBC (A4581) | KAT | CAST | On demand | Manually |
| AES-CBC (A4583) | KAT | CAST | On demand | Manually |
| AES-CBC (A4585) | KAT | CAST | On demand | Manually |
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y 5.6.2.1.4 Table 22 : Conditional Self -Tests The module performs self -tests on all approved cryptographic algorithms as part of the approved services supported in the approved mode of operation, using the tests shown in the Conditional Self -Tests table. Upon generation of a key pair, the module will perform a pair -wise consistency test (PCT), as shown in the Conditional Self -Tests table, which provides some assurance that the generated key pair is well formed. For DH and EC key pairs, these tests consist of the PCT of a signature generation and a signature verification operation. Note that two PCTs are
Table 23 : Pre -Operational Periodic Information © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 4 2 o f 4 9
| Algorithm or Test | Test Method | Test Type | Period | Periodic Method |
|---|---|---|---|---|
| AES-GCM (A4576) | KAT | CAST | On demand | Manually |
| AES-GCM (A4583) | KAT | CAST | On demand | Manually |
| AES-GCM (A4585) | KAT | CAST | On demand | Manually |
| AES-CMAC (A4578) | KAT | CAST | On demand | Manually |
| HMAC-SHA-1 (A4576) | KAT | CAST | On demand | Manually |
| HMAC-SHA2-224 (A4576) | KAT | CAST | On demand | Manually |
| HMAC-SHA2-256 (A4576) | KAT | CAST | On demand | Manually |
| HMAC-SHA2-384 (A4576) | KAT | CAST | On demand | Manually |
| HMAC-SHA2-512 (A4576) | KAT | CAST | On demand | Manually |
| KDF SP800-108 (A4579) | KAT | CAST | On demand | Manually |
| KDA HKDF Sp800 - 56Cr1 (A4575) | KAT | CAST | On demand | Manually |
| KDF TLS (A4576) | KAT | CAST | On demand | Manually |
| TLS v1.2 KDF RFC7627 (A4576) | KAT | CAST | On demand | Manually |
| KDF IKEv2 (A4580) | KAT | CAST | On demand | Manually |
| PBKDF (A4576) | KAT | CAST | On demand | Manually |
| Hash DRBG (A4576) | KAT | CAST | On demand | Manually |
| KAS-FFC-SSC Sp800- 56Ar3 (A4576) | KAT | CAST | On demand | Manually |
| KAS-ECC-SSC Sp800- 56Ar3 (A4576) | KAT | CAST | On demand | Manually |
| DSA SigVer (FIPS186 - 4) (A4576) | KAT | CAST | On demand | Manually |
| RSA SigGen (FIPS186 - 4) (A4576) | KAT | CAST | On demand | Manually |
| RSA SigVer (FIPS186 - 4) (A4576) | KAT | CAST | On demand | Manually |
| ECDSA SigGen (FIPS186-4) (A4576) | KAT | CAST | On demand | Manually |
| ECDSA SigVer (FIPS186-4) (A4576) | KAT | CAST | On demand | Manually |
| Safe Primes Key Generation (A4576) | PCT | PCT | On demand | Manually |
| RSA KeyGen (FIPS186 - 4) (A4576) | PCT | PCT | On demand | Manually |
| ECDSA KeyGen (FIPS186-4) (A4576) | PCT | PCT | On demand | Manually |
| Name | Description | Conditions | Recovery Method | Indicator |
|---|---|---|---|---|
| Power-On Error | An error occurred during the self - tests executed on power -on | Software integrity test failure CAST failure | Restart of the module | Module will not load |
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y Table 24 : Conditional Periodic Information
© 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 4 3 o f 4 9
| Name | Description | Conditions | Recovery Method | Indicator |
|---|---|---|---|---|
| PCT Error | An error occurred during a PCT | PCT failure | Restart of the module | Module stops functioning (sftk_fatalError is set to TRUE) |
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y Table 25 : Error States In any error state, the output interface is inhibited, and the module accepts no more inputs or requests.
10.5 Operator Initiation of Self -Tests
The software integrity tests and CASTs can be invoked on demand by unloading and subsequently re -initializing the module. The PCTs can be invoked on demand by requesting the Key Pair Generation service. © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 4 4 o f 4 9
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y
The module is distributed as a part of the Amazon Linux 2023 package in the form of the nss -softokn -3.90.0 -6.amzn2023.0. 1 and nss -softokn -freebl -3.90.0 -6.amzn2023.0. 1 RPM packages. The Netscape Portable Runtime (NSPR) package nspr -4.35.0 -6.amzn2023.0. 1 is a prerequisite for the module. Before the RPM packages are installed, the Amazon Linux 2023 system must operate in the FIPS validated configuration. To achieve this, the Crypto Officer must execute the fips -mode setup --enable command, then, restart the system. More information can be f ound at the vendor documentation . The Crypto Officer must verify the Amazon Linux 2023 system operates in the FIPS validated configuration by executing the fips -mode -setup --check command, which should output “FIPS mode is enabled.”
After installation of the RPM packages, the Crypto Officer must execute the “Show Version” service by accessing the CKA_NSS_VALIDATION_MODULE_ID attribute of the CKO_NSS_VALIDATION object in the default slot. The object attribute must contain the value Amazon Linux 2023 nss 3.90.0 -3e9a8358c972db98 Alternatively, the /usr/lib64/nss/unsupported -tools/validation tool is provided as a convenience by the nss -tools -3.90.0 -6.amzn2023.0. 1 RPM package. This tool performs the same steps, and outputs the FIPS module identifier as above. The cryptographic boundary consists only of the Softoken and Freebl libraries along with their associated integrity check values as listed in the Tested Module Identification table. If any other NSS API outside of these two libraries is invoked, the user i s not interacting with the module specified in this Security Policy.
There is no non -administrator guidance.
As the module does not persistently store SSPs, secure sanitization of the module consists of unloading the module. This will zeroize all SSPs in volatile memory. Then, if desired, the nss softokn -3.90.0 -6.amzn2023.0. 1 and nss -softokn -freebl -3.90.0 -6.amzn2023.0. 1 RPM packages can be uninstalled from the Amazon Linux 2023 systems. © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 4 5 o f 4 9
| Attack | Mitigation Mechanism | Specific Limit |
|---|---|---|
| Timing attacks on RSA | RSA blinding Timing attack on RSA was first demonstrated by Paul Kocher in 1996, who contributed the mitigation code to our module. Most recently Boneh and Brumley showed that RSA blinding is an effective defense against timing attacks on RSA. | None |
| Cache-timing attacks on the modular exponentiation operation used in RSA | Cache invariant modular exponentiation This is a variant of a modular exponentiation implementation that Colin Percival showed to defend against cache -timing attacks | This mechanism requires intimate knowledge of the cache line sizes of the processor. The mechanism may be ineffective when the module is running on a processor whose cache line sizes are unknown. |
| Arithmetic errors in RSA signatures | Double -checking RSA signatures Arithmetic errors in RSA signatures might leak the private key. Ferguson and Schneier recommend that every RSA signature generation should verify the signature just generated. | None |
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y Appendix A. Glossary and Abbreviations
| AES | Advanced Encryption Standard |
| AES -NI | Advanced Encryption Standard New Instructions |
| CAVP | Cryptographic Algorithm Validation Program |
| CAST | Cryptographic Algorithm Self -Test |
| CBC | Cipher Block Chaining |
| CMAC | Cipher -based Message Authentication Code |
| CMVP | Cryptographic Module Validation Program |
| CSP | Critical Security Parameter |
| CTR | Counter Mode |
| DES | Data Encryption Standard |
| DSA | Digital Signature Algorithm |
| DRBG | Deterministic Random Bit Generator |
| ECB | Electronic Code Book |
| ECC | Elliptic Curve Cryptography |
| FIPS | Federal Information Processing Standards Publication |
| GCM | Galois Counter Mode |
| HMAC | Hash Message Authentication Code |
| KAT | Known Answer Test |
| KW | AES Key Wrap |
| KWP | AES Key Wrap with Padding |
| MAC | Message Authentication Code |
| NIST | National Institute of Science and Technology |
| OS | Operating System |
| PAA | Processor Algorithm Acceleration |
| PCT | Pair -Wise Consistency Test |
| PSP | Public Security Parameter |
| PSS | Probabilistic Signature Scheme |
| RNG | Random Number Generator |
| RSA | Rivest, Shamir, Addleman |
| SHA | Secure Hash Algorithm © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 4 7 o f 4 9 |
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y Appendix B. References FIPS140 -3 FIPS PUB 140 -3 - Security Requirements for Cryptographic Modules March 2019 https://doi.org/10.6028/NIST.FIPS.140 -3 FIPS140 -3_IG Implementation Guidance for FIPS PUB 140 -3 and the Cryptographic Module Validation Program January 2024 https://csrc.nist.gov/Projects/cryptographic -module -validation program/fips -140 -3-ig -announcements FIPS180 -4 Secure Hash Standard (SHS) March 2012 http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180 -4.pdf FIPS186 -4 Digital Signature Standard (DSS) July 2013 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186 -4.pdf FIPS186 -5 Digital Signature Standard (DSS) February 2023 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186 -5.pdf FIPS197 Advanced Encryption Standard November 2001 http://csrc.nist.gov/publications/fips/fips197/fips -197.pdf FIPS198 -1 The Keyed Hash Message Authentication Code (HMAC) July 2008 http://csrc.nist.gov/publications/fips/fips198 -1/FIPS-198 -1_final.pdf PKCS#1 Public Key Cryptography Standards (PKCS) #1: RSA Cryptography Specifications Version 2.1 February 2003 http://www.ietf.org/rfc/rfc3447.txt SP800 -38A Special Publication 800 -38A - Recommendation for Block Cipher Modes of Operation Methods and Techniques December 2001 http://csrc.nist.gov/publications/nistpubs/800 -38a/sp800 -38a.pdf SP800 -38B NIST Special Publication 800 -38B - Recommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication May 2005 http://csrc.nist.gov/publications/nistpubs/800 -38B/SP_800 -38B.pdf SP800 -38D NIST Special Publication 800 -38D - Recommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC November 2007 http://csrc.nist.gov/publications/nistpubs/800 -38D/SP -800 -38D.pdf SP800 -38F NIST Special Publication 800 -38F - Recommendation for Block Cipher Modes of Operation: Methods for Key Wrapping December 2012 http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800 -38F.pdf © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 4 8 o f 4 9
Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y SP800 -56Ar3 NIST Special Publication 800 -56A Revision 3 - Recommendation for Pair Wise Key Establishment Schemes Using Discrete Logarithm Cryptography April 2018 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800 56Ar3.pdf SP800 -56Cr2 NIST Special Publication 800 -56C Revision 2 - Recommendation for Key -Derivation Methods in Key -Establishment Schemes August 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800 56Cr2.pdf SP800 -90Ar1 NIST Special Publication 800 -90A - Revision 1 - Recommendation for Random Number Generation Using Deterministic Random Bit Generators June 2015 http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800 90Ar1.pdf SP800 -90B NIST Special Publication 800 -90B - Recommendation for the Entropy Sources Used for Random Bit Generation January 2018 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800 90B.pdf SP800 -108r1 NIST Special Publication 800 -108 Revision 1 - Transitions: Recommendation for Key Derivation Using Pseudorandom Functions August 2022 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800 108r1.pdf SP800 -131Ar1 NIST Special Publication 800 -131A Revision 1 - Transitions: Recommendation for Transitioning the Use of Cryptographic Algorithms and Key Lengths November 2015 http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800 131Ar1.pdf SP800 -133r2 NIST Special Publication 800 -133rev2 - Recommendation for Cryptographic Key Generation June 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800 133r2.pdf SP800 -135r1 NIST Special Publication 800 -135 Revision 1 - Recommendation for Existing Application -Specific Key Derivation Functions December 2011 http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800 135r1.pdf © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 4 9 o f 4 9