All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Amazon Linux 2023 NSS Cryptographic Module

Certificate#5014StandardFIPS 140-3Level1TypeSoftwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorAmazon Web Services, Inc.
Low review priority  ·  no TCB surface named  ·  NSS upstream has published 0 CVEs since this module's initial validation  ·  last validated 5 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date5/1/2030
CaveatWhen operated in approved mode and installed, initialized and configured as specified in Section 11 of the Security Policy.
VendorAmazon Web Services, Inc.

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Amazon Linux 2023 NSS Cryptographic Module
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>update<br/>Recovery</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>UnAuth<br/>Status Output<br/>Show Status</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>IKEV<br/>IPSEC</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Amazon Linux 2023 NSS Cryptographic Module
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>update<br/>Recovery</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>UnAuth<br/>Status Output<br/>Show Status</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>IKEV<br/>IPSEC</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Amazon Web Services, Inc. Amazon Linux 2023 NSS Cryptographic Module FIPS 140 -3 Non -Proprietary Security Policy Document Version 1. 2 Last update: 202 5-12 -08 Prepared by: atsec information security corporation

4516 Seton Center Pkwy, Suite 250

Austin, TX 78759 www.atsec.com

Page 2

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y Table of Contents © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 2 o f 4 9

Page 3

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 3 o f 4 9

Page 4

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y List of Tables Ta b le 2 : Te s t e d Mo d u le Id e n t ific a t io n – So ft wa re , Firm wa re , Hyb rid (Exe c u t a b le Co d e Se t s ) 1 1 © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 4 o f 4 9

Page 5

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y List of Figures © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 5 o f 4 9

Page 6

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y Amazon is a registered trademark of Amazon Web Services, Inc. or its affiliates. © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 6 o f 4 9

Page 7
SectionTitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication1
5Software/Firmware security1
6Operational environment1
7Physical securityN/A
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacks1
Overall Level1

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y

1.1 Overview

This document is the non -proprietary FIPS 140 -3 Security Policy for version 3.90.0 3e9a8358c972db98 of the Amazon Linux 2023 NSS Cryptographic Module. It contains the security rules under which the module must operate and describes how this module meets the requirements as specified in FIPS PUB 140 -3 (Federal Information Processing Standards Publication 140 -3) for an overall Security Level 1 module. This Non -Proprietary Security Policy may be reproduced and distributed, but only whole and intact and including this notice. Other documentation is proprietary to their authors.

1.2 Security Levels
1.3 Additional Information

This Security Policy describes the features and design of the module named Amazon Linux

2023 NSS Cryptographic Module using the terminology contained in the FIPS 140 -3

specification. The FIPS 140 -3 Security Requirements for Cryptographic Module specifies the security requirements that will be satisfied by a cryptogra phic module utilized within a security system protecting sensitive but unclassified information. The NIST/CCCS Cryptographic Module Validation Program (CMVP) validates cryptographic module to FIPS

140 -3. Validated products are accepted by the Federal agenc ies of both the USA and Canada

for the protection of sensitive or designated information. This Non -Proprietary Security Policy may be reproduced and distributed, but only whole and intact and including this notice. Other documentation is proprietary to their authors. The vendor has provided the non -proprietary Security Policy of the cryptographic module, which was further consolidated into this document by atsec information security together with other vendor -supplied documentation. In preparing the Security Policy doc ument, the laboratory formatted the vendor -supplied documentation for consolidation without altering the technical statements therein contained. The further refining of the Security Policy © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 7 o f 4 9

Page 8

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y d o c u m e n t wa s c o n d u c t e d it e ra t ive ly t h ro u g h o u t t h e c o n fo rm a n c e t e s t in g , wh e re in t h e Se c u rit y Po lic y wa s s u b m it t e d t o t h e ve n d o r, wh o wo u ld t h e n e d it , m o d ify, a n d a d d t e c h n ic a l c o n t e n t s . Th e ve n d o r wo u ld a ls o s u p p ly a d d it io n a l d o c u m e n t a t io n , wh ic h t h e la b o ra t o ry fo rm a t t e d in t o t h e e xis t in g Se c u rit y Po lic y, a n d re s u b m it t e d t o t h e ve n d o r fo r t h e ir fin a l e d it in g . © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 8 o f 4 9

Page 9

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y

2 Cryptographic Module Specification
2.1 Description

Purpose and Use: The Amazon Linux 2023 NSS Cryptographic Module (hereafter referred to as “the module”) provides a C language application program interface (API) designed to support cross platform development of security -enabled client and server applications. Applications built with NSS can support SSLv3, TLS, IKEv2, PKCS#5, PKCS#7, PKCS#11, PKCS#12, S/MIME, X.509 v3 certificates, and other security standards supporting FIPS 140 -3 validated cryptographic algorithms. It combines a vertical stack of Linux components intended to limit the external interface each separate component may provide. Module Type : Software Module Embodiment : MultiChipStand Module Characteristics : Cryptographic Boundary: Figure 1 shows a block diagram that represents the design of the module when the module is operational and providing services to other user space applications. In this diagram, the physical perimeter of the operational environment (a general -purpose comput er on which the module is installed) is indicated by a purple dashed line. © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 9 o f 4 9

Page 10

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y Figure 1: Block Diagram The cryptographic boundary is represented by the components painted in orange blocks, which consists of two software components:

  1. The Softoken library, which provides a PKCS#11 token API (libsoftokn3.so), and its associated integrity check value (libsoftokn3.chk).
  2. The Freebl cryptographic library, which implements most cryptographic algorithms used by Softoken (libfreeblpriv3.so), and its associated integrity check value (libfreeblpriv3.chk). Green lines indicate the flow of data between the cryptographic module and its operator application, through the logical interfaces defined in Section
  3. Components in white are only included in the diagram for informational purposes. They are not included in the cryptographic boundary (and therefore not part of the module’s validation). For example, the kernel is responsible for managing system calls issue d by the module itself, as well as other applications using the module for cryptographic services. Tested Operational Environment’s Physical Perimeter (TOEPP): The TOEPP of the module is defined as the general -purpose computer on which the module is installed. © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 1 0 o f 4 9
Page 11
Package or File NameSoftware/ Firmware VersionFeaturesIntegrity Test
libsoftokn3.so3.90.0 -3e9a8358c972db98N/ADSA signature verification using 2048 -bit key and SHA-256
libfreeblpriv3.so3.90.0 -3e9a8358c972db98N/ADSA signature verification using 2048 -bit key and SHA-256
Operating SystemHardware PlatformProcessorsPAA/PAIHypervisor or Host OSVersion(s)
Amazon Linux 2023EC2 c7g.metalAWS Graviton3YesN/A3.90.0 -3e9a8358c972db98
Amazon Linux 2023EC2 c6i.metalIntel Xeon Platinum 8375CYesN/A3.90.0 -3e9a8358c972db98
Amazon Linux 2023EC2 c7g.metalAWS Graviton3NoN/A3.90.0 -3e9a8358c972db98
Amazon Linux 2023EC2 c6i.metalIntel Xeon Platinum 8375CNoN/A3.90.0 -3e9a8358c972db98

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y

2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification

2.3 Excluded Components

There are no components excluded from the requirements of the FIPS 140 -3 standard.

2.4 Modes of Operation

Modes List and Description: © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 1 1 o f 4 9

Page 12
Mode NameDescriptionTypeStatus Indicator
Approved mode of operationAutomatically entered whenever an approved service is requestedApprovedEquivalent to the indicator of the requested service as defined in section 4.3
Non-approved mode of operationAutomatically entered whenever a non - approved service is requestedNon- ApprovedEquivalent to the indicator of the requested service as defined in section 4.3
AlgorithmCAVP CertPropertiesReference
AES-CBCA4576, A4583, A4585Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS1A4581Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CMACA4578Direction - Generation, Verification Key Length - 128, 192, 256SP 800-38B
AES-CTRA4576, A4585Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA4576, A4583, A4585Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-GCMA4576, A4585Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 192, 256SP 800-38D
AES-GCMA4583Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-KWA4577, A4582, A4584Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-KWPA4577, A4582, A4584Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y 4.3 4.3 Table 4: Modes List and Description After passing all pre -operational self -tests and cryptographic algorithm self -tests executed on start -up, the module automatically transitions to the approved mode. No operator intervention is required to reach this point. Mode Change Instructions and Status: The module automatically switches between the approved and non -approved modes depending on the services requested by the operator. The status indicator of the mode of The module does not implement a degraded mode of operation.

2.5 Algorithms

Approved Algorithms: © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 1 2 o f 4 9

Page 13
AlgorithmCAVP CertPropertiesReference
DSA SigVer (FIPS186-4)A4576L - 2048 N - 224, 256 Hash Algorithm - SHA-1, SHA2-224, SHA2 -256, SHA2-384, SHA2 -512FIPS 186-4
ECDSA KeyGen (FIPS186-4)A4576Curve - P-256, P-384, P-521 Secret Generation Mode - Extra BitsFIPS 186-4
ECDSA SigGen (FIPS186-4)A4576Component - No Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2 -256, SHA2 -384, SHA2 -512FIPS 186-4
ECDSA SigVer (FIPS186-4)A4576Component - No Curve - P-256, P-384, P-521 Hash Algorithm - SHA-1, SHA2-224, SHA2 -256, SHA2 -384, SHA2 -512FIPS 186-4
Hash DRBGA4576Prediction Resistance - No, Yes Mode - SHA2-256SP 800-90A Rev. 1
HMAC-SHA2-224A4576Key Length - Key Length: 112 -524288 Increment 8FIPS 198-1
HMAC-SHA2-256A4576Key Length - Key Length: 112 -524288 Increment 8FIPS 198-1
HMAC-SHA2-384A4576Key Length - Key Length: 112 -524288 Increment 8FIPS 198-1
HMAC-SHA2-512A4576Key Length - Key Length: 112 -524288 Increment 8FIPS 198-1
KAS-ECC-SSC Sp800-56Ar3A4576Domain Parameter Generation Methods - P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KAS-FFC-SSC Sp800-56Ar3A4576Domain Parameter Generation Methods - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP -2048, MODP -3072, MODP - 4096, MODP -6144, MODP -8192 Scheme - dhEphem - KAS Role - initiator, responderSP 800-56A Rev. 3
KDA HKDF Sp800-56Cr1A4575Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224 -65336 Increment 8 HMAC Algorithm - SHA2-224, SHA2 -256, SHA2 -384, SHA2 -512SP 800-56C Rev. 2
KDF IKEv2 (CVL)A4580Diffie-Hellman Shared Secret Length - Diffie-Hellman Shared Secret Length: 224, 2048, 8192 Derived Keying Material Length - Derived Keying Material Length: 1056, 3072 Hash Algorithm - SHA-1, SHA2-256, SHA2 -384, SHA2 -512SP 800-135 Rev. 1
KDF SP800-108A4579KDF Mode - Counter, Double Pipeline Iteration, Feedback Supported Lengths - Supported Lengths: 8, 72, 128, 776, 3456, 4096SP 800-108 Rev. 1
KDF TLS (CVL)A4576TLS Version - v1.0/1.1SP 800-135 Rev. 1
PBKDFA4576Iteration Count - Iteration Count: 1000 -10000 Increment 1 Password Length - Password Length: 8 -128 Increment 1SP 800-132
RSA KeyGen (FIPS186-4)A4576Key Generation Mode - B.3.3 Modulo - 2048, 3072, 4096 Primality Tests - Table C.3 Private Key Format - StandardFIPS 186-4
RSA SigGen (FIPS186-4)A4576Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186-2)A4576Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024, 1536FIPS 186-4
RSA SigVer (FIPS186-4)A4576Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096FIPS 186-4
Safe Primes Key GenerationA4576Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP -2048, MODP -3072, MODP -4096, MODP -6144, MODP-8192SP 800-56A Rev. 3
SHA2-224A4576Message Length - Message Length: 0 -65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 1 3 o f 4 9

Page 14
AlgorithmCAVP CertPropertiesReference
SHA2-256A4576Message Length - Message Length: 0 -65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-384A4576Message Length - Message Length: 0 -65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512A4576Message Length - Message Length: 0 -65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
TLS v1.2 KDF RFC7627 (CVL)A4576Hash Algorithm - SHA2-256, SHA2 -384, SHA2 -512SP 800-135 Rev. 1
NamePropertiesImplementationReference
Cryptographic Key Generation (CKG)Key Type :Symmetric and AsymmetricN/ASP 800-133r2 Section 4, 5.1, 5.2, 6.1
NameCaveatUse and Function
MD5Allowed per IG 2.4.A.Message digest used in TLS 1.0/1.1 KDF only
NameUse and Function
RC2, RC4, DES, Triple -DES, CDMF, Camellia, SEED, ChaCha20( -Poly1305)Encryption, Decryption
AES GCM (external IV)Encryption
CBC-MAC, AES XCBC-MAC, AES XCBC-MAC-96Message Authentication
HMAC (MD2, MD5, SHA -1; < 112 -bit keys)Message Authentication
HMAC/SSLv3 MAC (constant -time implementation)Message Authentication
MD2, MD5, SHA -1, SHA-224, SHA-256, SHA-384, SHA-512, DES, Triple -DES, AES, Camellia, SEED, ANS X9.63 KDF (SHA -1, SHA-224, SHA-256, SHA-384, SHA-512), SSL 3 PRF (MD5, SHA - 1), IKEv1 PRF (AES XCBC -MAC, MD2, MD5, SHA -1, SHA-224, SHA-256, SHA-384, SHA-512)Key Derivation
KBKDF, HKDF, TLS 1.0/1.1 KDF, TLS 1.2 KDF, IKEv2 KDF (< 112 -bit keys)Key Derivation
KBKDF (MD2, MD5)Key Derivation
TLS 1.2 KDF (without extended master secret)Key Derivation
IKEv2 KDF (MD2, MD5)Key Derivation
PKCS#5 PBE, PKCS#12 PBEPassword-based Key Derivation
PBKDF2 (password<8 characters, salt<128 bits, iteration count<1000, or key<112 bits)Password-based Key Derivation
J-PAKEShared Secret Computation

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y Table 5: Approved Algorithms Vendor -Affirmed Algorithms: Table 6: Vendor -Affirmed Algorithms Non -Approved, Allowed Algorithms: N/A for this module. Non -Approved, Allowed Algorithms with No Security Claimed: Table 7: Non -Approved, Allowed Algorithms with No Security Claimed Non -Approved, Not Allowed Algorithms: © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 1 4 o f 4 9

Page 15
NameUse and Function
DH (Shared secret computation; FIPS 186 -type groups)Shared Secret Computation
ECDH (Shared secret computation; P -192)Shared Secret Computation
DSA (SigGen)Signature Generation
RSA (SigGen primitive; PKCS#1 v1.5 or PSS with MD2, MD5)Signature Generation
ECDSA (SigGen; P-192)Signature Generation
RSA (encryption)Asymmetric Encryption
DSA (parameter generation)Parameter Generation
DH (KeyGen, FIPS 186 -type groups)Key Pair Generation
RSA (KeyGen, modulus < 2048 bits)Key Pair Generation
ECDSA (KeyGen, P -192)Key Pair Generation
Symmetric Key Generation (< 112 bits)Secret Key Generation
MD2, MD5, SHA -1Message Digest
RSA (SigVer primitive; PKCS#1 v1.5 or PSS with MD2, MD5)Signature Verification
ECDSA (SigVer; P -192)Signature verification
RSA (decryption)Asymmetric Decryption
DSA (parameter verification)Parameter verification
DSA (key pair generation)Key Pair Generation
NameTypeDescriptionPropertiesAlgorithms
SHASHAHash functionReference:FIPS 180 -4SHA2-224 SHA2-256 SHA2-384 SHA2-512
AES (ECB, CBC, CBC- CS1, CTR)BC-UnAuthBlock cipherReferences:FIPS 197, SP 800-38A, SP 800 - 38A AddendumAES-ECB AES-ECB AES-ECB AES-CBC AES-CBC AES-CBC AES-CBC-CS1 AES-CTR AES-CTR
AES (KW, KWP)BC-AuthBlock cipherReferences:FIPS 197, SP 800-38FAES-KW AES-KWP AES-KW AES-KWP

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y Table 8: Non -Approved, Not Allowed Algorithms

2.6 Security Function Implementations

© 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 1 5 o f 4 9

Page 16
NameTypeDescriptionPropertiesAlgorithms AES-KW AES-KWP
AES (GCM, encryption, internal IV)BC-AuthBlock cipherReferences:FIPS 197, SP 800-38DAES-GCM AES-GCM AES-GCM
AES (CMAC)MACMessage authentication code based on AESReferences:FIPS 197, SP 800-38BAES-CMAC
HMACMACKeyed-hash message authentication codeReference:FIPS 198 -1HMAC-SHA2-256 HMAC-SHA2-384 HMAC-SHA2-512 HMAC-SHA2-224
KBKDFKBKDFKey-based key derivation functionReference:SP 800 - 108r1KDF SP800-108
TLS 1.0/1.1 KDF, TLS 1.2 KDF (CVL)KAS-135KDFKDF componentReference:SP 800 - 135r1KDF TLS TLS v1.2 KDF RFC7627
HKDFKAS-56CKDFHMAC-based key derivation functionReference:SP 800 - 56Cr1KDA HKDF Sp800 - 56Cr1
PBKDF2PBKDFPassword-based key derivation functionReference:SP 800 -132PBKDF
Hash DRBGDRBGRandom number generationReference:SP 800 - 90Ar1 Compliance:SP800 - 90ARev1Hash DRBG
KAS-FFC-SSCKAS-SSCDiffie-Helman shared secret computationReference:SP 800 - 56Ar3 Compliance:IG D.F Scenario 2(1)KAS-FFC-SSC Sp800- 56Ar3
KAS-ECC-SSCKAS-SSCEC Diffie-Helman shared secret computationReference:SP 800 - 56Ar3 Compliance:IG D.F Scenario 2(1)KAS-ECC-SSC Sp800- 56Ar3
DSA SigVer (Legacy)DigSig-SigVerDSA signature verificationReference:FIPS 186 -4 Compliance:FIPS 140 - 3 IG C.M legacy algorithmsDSA SigVer (FIPS186 - 4) L: 2048 bits N: 256 Hash Algorithm: SHA2-256
RSA SigGenDigSig-SigGenRSA signature generationReference:FIPS 186 -4RSA SigGen (FIPS186- 4)
RSA SigVerDigSig-SigVerRSA signature verificationReference:FIPS 186 -4RSA SigVer (FIPS186 - 4)
ECDSA SigGenDigSig-SigGenECDSA signature generationReference:FIPS 186 -4ECDSA SigGen (FIPS186-4)
ECDSA SigVerDigSig-SigVerECDSA signature verificationReference:FIPS 186 -4ECDSA SigVer (FIPS186-4)
AES (GCM, decryption, external IV)BC-AuthBlock cipherReferences:FIPS 197, SP 800-38DAES-GCM AES-GCM AES-GCM
AES-KW, AES-KWP, AES-GCM (KTS, key wrapping)KTS-WrapKey wrappingReference:SP 800 - 38F, SP 800 -38D Compliance:IG D.G Caveat:key establishment methodology provides between 128 and 256AES-KW AES-KWP AES-KW AES-KWP AES-KW AES-KWP AES-GCM

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 1 6 o f 4 9

Page 17
NameTypeDescriptionProperties bits of security strengthAlgorithms AES-GCM AES-GCM
AES-KW, AES-KWP, AES-GCM (KTS, key unwrapping)KTS-WrapKey unwrappingReference:SP 800 -38D Compliance:IG D.G Keys :128, 192, 256 bits with 128 -256 bits of keys strength Caveat:key establishment methodology provides between 128 and 256 bits of security strengthAES-GCM AES-GCM AES-GCM AES-KW AES-KWP AES-KW AES-KWP AES-KW AES-KWP
Hash DRBG (symmetric key generation)CKGSymmetric Key GenerationReference:SP 800 - 133r2 section 6.1Hash DRBG
RSA KeyGen (key pair generation)AsymKeyPair -KeyGen CKGKey pair generation with RSAReference:FIPS 186 -4RSA KeyGen (FIPS186 - 4)
ECDSA KeyGen (key pair generation)AsymKeyPair -KeyGen CKGKey pair generation with ECDSAReference:FIPS 186 -4ECDSA KeyGen (FIPS186-4)
Safe Primes Key Generation (key pair generation)AsymKeyPair -KeyGen CKGKey pair generation with Safe PrimesReference:SP800 - 56Ar3Safe Primes Key Generation
IKEv2 KDF (CVL)KAS-135KDFKDF componentReference:SP 800 - 135r1KDF IKEv2
RSA SigVer (Legacy)DigSig-SigVerLegacy digital signature verificationReference:FIPS186 -2, FIPS186-4 Compliance:FIPS 140 - 3 IG C.M legacy algorithmsRSA SigVer (FIPS186 - 2) RSA SigVer (FIPS186 - 4) Modulo: 1024 Hash Algorithm: SHA - 1
ECDSA SigVer (Legacy)DigSig-SigVerLegacy digital signature verificationReference:FIPS186 -4 Compliance:FIPS 140 - 3 IG C.M legacy algorithmsECDSA SigVer (FIPS186-4) Hash Algorithm: SHA - 1

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y Table 9: Security Function Implementations

2.7 Algorithm Specific Information

The Crypto Officer shall consider the following requirements and restrictions when using the module. For TLS 1.2, the module offers the AES GCM implementation and uses the context of mechanism for IV generation is compliant with RFC 5288 and 8446. The module does not implement the TLS protocol. The module’s implementation of AES GCM is used together with an application that runs outside the module’s cryptographic boundary. The design of the TLS protocol implicitly ensures that the counter (the nonce _explicit part of the IV) does not exhaust the maximum number of possible values for a given session key. In the event the module’s power is lost and restored, the consuming application must ensure that a new key for use with the AES GCM key encryption or decryption under this scenario shall be established. © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 1 7 o f 4 9

Page 18

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y Alt e rn a t ive ly, t h e Cryp t

3 IG C.H. Th e p ro t o c o l t h a t p ro vid e s t h is c o m p lia n c e is TLS 1 .3 , d e fin e d in RFC8 4 4 6 o f

Au g u s t 2 0 1 8 , u s in g t h e c ip h e r-s u it e s t h a t e xp lic it ly s e le c t AES GCM a s t h e e n c ryp t io n /d e c ryp t io n c ip h e r (Ap p e n d ix B.4 o f RFC8 4 4 6 ). Th e m o d u le s u p p o rt s a c c e p t a b le AES GCM c ip h e r s u it e s fro m Se c t io n 3 .3 .1 o f SP8 0 0 -5 2 r2 . TLS 1 .3 e m p lo ys s e p a ra t e 6 4 -b it s e q u e n c e n u m b e rs , o n e fo r p ro t o c o l re c o rd s t h a t a re re c e ive d , a n d o n e fo r p ro t o c o l re c o rd s t h a t a re s e n t t o a p e e r. Th e s e s e q u e n c e n u m b e rs a re s e t a t ze ro a t t h e b e g in n in g o f a TLS

1 .3 c o n n e c t io n a n d e a c h t im e wh e n t h e AES-GCM ke y is c h a n g e d . Aft e r re a d in g o r writ in g a

re c o rd , t h e re s p e c t ive s e q u e n c e n u m b e r is in c re m e n t e d b y o n e . Th e p ro t o c o l s p e c ific a t io n d e t e rm in e s t h a t t h e s e q u e n c e n u m b e r s h o u ld n o t wra p , a n d if t h is c o n d it io n is o b s e rve d , t h e n t h e p ro t o c o l im p le m e n t a t io n m u s t e it h e r t rig g e r a re -ke y o f t h e s e s s io n (i.e ., a n e w ke y fo r AES-GCM) o r t e rm in a t e t h e c o n n e c t io n .

2.7.2 PBKDF2

The module provides password -based key derivation (PBKDF2), compliant with SP 800 -132. The module supports option 1a from Section 5.4 of SP 800 -132, in which the Master Key (MK) or a segment of it is used directly as the Data Protection Key (DPK). In accor dance to SP 800 -132 and FIPS 140 -3 IG D.N, the following requirements shall be met:

Page 19
CertVendor
NumberName
E124Amazon
NameTypeOperational EnvironmentSample SizeEntropy per SampleConditioning Component
Amazon Userspace CPU Time Jitter RNG Entropy SourceNon- PhysicalAmazon Linux 2023 on EC2 c7g.metal on AWS Graviton3; Amazon Linux 2023 on EC2 c6i.metal on Intel Xeon Platinum 8375C256 bitsFull entropySHA3-256 (A4551); HMAC-SHA-512 DRBG (A4551)

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y

2.7.3 SP 800 -56Ar3 Assurances

To comply with the assurances found in Section 5.6.2 of SP 800 -56Ar3, the operator must use the module together with an application that implements the TLS protocol. Additionally, the module’s approved Key Pair Generation service (see the Approved Services table) must be used to generate ephemeral Diffie -Hellman or EC Diffie -Hel lman key pairs, or the key pairs must be obtained from another FIPS -validated module. As part of this service, the module will internally perform the full public key validation of the generated public key. The module’s shared secret computation service will internally perform the full public key validation of the peer public key, complying with Sections 5.6.2.2.1 and 5.6.2.2.2 of SP 800 56Ar3.

2.7.4 KAS -SSC

The module does not establish SSPs using an approved key agreement scheme (KAS). However, it does offer some or all of the underlying KAS cryptographic functionality to be used by an external operator/application as part of an approved KAS.

2.7.5 Legacy Algorithms

Algorithms designated as “Legacy” can only be used on data that was generated prior to the Legacy Date specified in FIPS 140 -3 IG C.M .

2.8 RBG and Entropy

Table 10 : Entropy Certificates Table 11 : Entropy Sources The module employs a Deterministic Random Bit Generator (DRBG) implementation based on SP 800 -90Ar1. This DRBG is used internally by the module (e.g. to generate symmetric keys, seeds for asymmetric key pairs, and random numbers for security functions). It can also be accessed using the specified API functions. The DRBG implemented is a SHA -256 Hash_DRBG, seeded by the entropy source described in the Entropy Sources table. It does not employ prediction resistance. The DRBG is seeded with 440 bits of entropy and reseeded with 440 bits. The entropy source is located within the module’s physical perimeter, but outside of the module’s cryptographic boundary.

2.9 Key Generation

The module implements the key generation methods as specified in the Vendor -Affirmed Cryptographic Algorithms table and the Security Function Implementations table. © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 1 9 o f 4 9

Page 20

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y

2.10 Key Establishment

The module implements the SSP establishment methods as specified in the Security Function Implementations table.

2.11 Industry Protocols

GCM with internal IV generation in the approved mode is compliant with versions 1.2 and 1.3 of the TLS protocol (RFC 5288 and 8446) and shall only be used in conjunction with the TLS protocol. Additionally, the module implements the TLS 1.0/1.1 and 1.2 key derivation functions for use in the TLS protocol. The module implements the IKEv2 key derivation function for use in the IPSec protocol (RFC 5996). For Diffie -Hellman, the module supports the use of the following safe primes: • IKE (RFC 3 5 2 6 ): MODP-2 0 4 8 (ID = 1 4 ), MODP-3 0 7 2 (ID = 1 5 ), MODP-4 0 9 6 (ID =

1 6 ), MODP-6 1 4 4 (ID = 1 7 ), MODP-8 1 9 2 (ID = 1 8 )

• TLS (RFC 7 9 1 9 ): ffd h e 2 0 4 8 (ID = 2 5 6 ), ffd h e 3 0 7 2 (ID = 2 5 7 ), ffd h e 4 0 9 6 (ID =

2 5 8 ), ffd h e 6 1 4 4 (ID = 2 5 9 ), ffd h e 8 1 9 2 (ID = 2 6 0 )

No o t h e r p a rt s o f t h e TLS o r IPSe c p ro t o c o ls , o t h e r t h a n t h e KDFs m e n t io n e d a b o ve , h a ve b e e n t e s t e d b y t h e CAVP a n d CMVP. © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 2 0 o f 4 9

Page 21
Physical PortLogical Interface(s)Data That Passes
N/AData InputAPI input parameters
N/AData OutputAPI output parameters
N/AControl InputAPI function calls, API input parameters for control input
N/AStatus OutputAPI return codes

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y

3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

Table 12 : Ports and Interfaces The module does not have a control output interface. © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 2 1 o f 4 9

Page 22
NameTypeOperator TypeAuthentication Methods
Crypto OfficerRoleCONone
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
Message DigestCompute a message digestCKS_NSS_FIPS_OKMessageDigest valueSHACrypto Officer
EncryptionEncrypt a plaintextCKS_NSS_FIPS_OKAES key, plaintextCiphertextAES (ECB, CBC, CBC- CS1, CTR)Crypto Officer - AES key: W,E
DecryptionDecrypt a ciphertextCKS_NSS_FIPS_OKAES key, ciphertextPlaintextAES (ECB, CBC, CBC- CS1, CTR)Crypto Officer - AES key: W,E
Authenticated EncryptionEncrypt a plaintextCKS_NSS_FIPS_OKInputs of GCM: AES key, IV, plaintext; Inputs of KW, KWP: AES key, plaintextOutputs of GCM: Ciphertext, MAC tag; Outputs of KW, KWP: CiphertextAES (KW, KWP) AES (GCM, encryption, internal IV)Crypto Officer - AES key: W,E
Authenticated DecryptionDecrypt a ciphertextCKS_NSS_FIPS_OKInputs of GCM: AES key, IV, MAC tag, ciphertext; Inputs of KW, KWP: AES key, ciphertextOutputs of GCM: Plaintext or fail; Outputs of KW, KWP: PlaintextAES (KW, KWP) AES (GCM, decryption, external IV)Crypto Officer - AES key: W,E
Key WrappingWrap a CSPCKS_NSS_FIPS_OKInputs of KW, KWP: AES key, any CSP (except for password); Inputs of GCM: AES key, IV, any CSP (except for password)Outputs of KW, KWP: Wrapped CSP; Outputs of GCM: Wrapped CSP, MAC tagAES-KW, AES- KWP, AES- GCM (KTS, key wrapping)Crypto Officer - AES key: W,E
Key UnwrappingUnwrap a CSPCKS_NSS_FIPS_OKInputs of GCM: AES key, IV,Outputs of GCM:AES-KW, AES- KWP, AES-Crypto Officer

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y

4 Roles, Services, and Authentication
4.2 Roles

Table 13 : Roles The module supports the Crypto Officer role only. This sole role is implicitly and always assumed by the operator of the module. No support is provided for multiple concurrent operators.

4.3 Approved Services

W,E W,E © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 2 2 o f 4 9

Page 23
NameDescriptionIndicatorInputs MAC tag, wrapped CSP; Inputs of KW, KWP: AES key, wrapped CSPOutputs Unwrapped CSP or fail; Outputs of KW, KWP: Unwrapped CSPSecurity Functions GCM (KTS, key unwrapping)SSP Access - AES key: W,E
Message AuthenticationCompute a MAC tagCKS_NSS_FIPS_OKInputs of AES - CMAC: AES key, message. Inputs of HMAC: HMAC key, messageMAC tagAES (CMAC) HMACCrypto Officer - AES key: W,E - HMAC key: W,E
Password- based Key DerivationDerive a key from a passwordCKS_NSS_FIPS_OKPassword, salt, iteration countPBKDF derived keyPBKDF2Crypto Officer - Password: W,E - PBKDF derived key: G
Random Number GenerationGenerate random bytesCKR_OKOutput lengthRandom bytesHash DRBGCrypto Officer - Entropy input: W,E - DRBG seed: G,E - Internal state (V, C): G,W,E
Shared Secret ComputationCompute a shared secretCKS_NSS_FIPS_OKInputs of KAS - FFC-SSC: DH private key (owner), DH public key (peer). Inputs of KAS-ECC-SSC: EC private key (owner), EC public key (peer)Shared secretKAS-FFC-SSC KAS-ECC-SSCCrypto Officer - EC private key: W,E - EC public key: W,E - Shared secret: G - DH private key: W,E - DH public key: W,E
Signature GenerationGenerate a signatureCKS_NSS_FIPS_OKInputs of RSA SigGen: RSA private key, message. Inputs of ECDSA SigGen: EC private key, messageSignatureRSA SigGen ECDSA SigGenCrypto Officer - RSA private key: W,E - EC private key: W,E
Signature VerificationVerify a signatureIndicator of DSA SigVer: CKR_OK. Indicator of RSA SigVer: CKS_NSS_FIPS_OK. Indicator of ECDSA SigVer: CKS_NSS_FIPS_OKInputs of DSA SigVer: DSA public key, message, signature. Inputs of RSA SigVer: RSA public key, message, signature. Inputs of ECDSA SigVer: EC public key,Pass/failDSA SigVer (Legacy) RSA SigVer ECDSA SigVer RSA SigVer (Legacy) ECDSA SigVer (Legacy)Crypto Officer - DSA public key: W,E - RSA public key: W,E - EC public key: W,E

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y W,E W,E G G,E G,W,E © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 2 3 o f 4 9

Page 24
NameDescriptionIndicatorInputs message, signature.OutputsSecurity FunctionsSSP Access
Secret Key GenerationGenerate a symmetric keyCKS_NSS_FIPS_OKKey sizeAES key, HMAC key, or Key - derivation keyHash DRBG (symmetric key generation)Crypto Officer - AES key: G - HMAC key: G - Key- derivation key: G
Key Pair GenerationGenerate a key pairCKS_NSS_FIPS_OKSafe Primes Key Generation: Group; RSA KeyGen: Modulus size; ECDSA KeyGen: CurveSafe Primes Key Generation: DH public & private key; RSA KeyGen: RSA public & private key; ECDSA KeyGen: EC public & private keyRSA KeyGen (key pair generation) ECDSA KeyGen (key pair generation) Safe Primes Key Generation (key pair generation)Crypto Officer - DH private key: G - DH public key: G - EC private key: G - EC public key: G - RSA private key: G - RSA public key: G - Intermediate key generation value: G,E,Z
Show VersionReturn the module name and version informationNoneN/AModule name and version informationNoneCrypto Officer
Show StatusReturn the module statusNoneN/AModule statusNoneCrypto Officer
Self-TestPerform the CASTs and integrity testsNoneN/APass/failSHA AES (ECB, CBC, CBC- CS1, CTR) AES (GCM, encryption, internal IV) AES (CMAC) HMAC KBKDF TLS 1.0/1.1 KDF, TLS 1.2 KDF (CVL) HKDF PBKDF2 Hash DRBG KAS-FFC-SSC KAS-ECC-SSC DSA SigVer (Legacy) RSA SigGen RSA SigVer ECDSA SigGen ECDSA SigVerCrypto Officer

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y G © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 2 4 o f 4 9

Page 25
NameDescriptionIndicatorInputsOutputsSecurity Functions AES (GCM, decryption, external IV) Hash DRBG (symmetric key generation) RSA KeyGen (key pair generation) ECDSA KeyGen (key pair generation) Safe Primes Key Generation (key pair generation) IKEv2 KDF (CVL) RSA SigVer (Legacy) ECDSA SigVer (Legacy)SSP Access
ZeroizationZeroize any SSPNoneAny SSPNoneNoneCrypto Officer - AES key: Z - HMAC key: Z - Key- derivation key: Z - Shared secret: Z - Password: Z - PBKDF derived key: Z - Entropy input: Z - DRBG seed: Z - Internal state (V, C): Z - DH private key: Z - DH public key: Z - EC private key: Z - EC public key: Z - DSA public key: Z - RSA private key: Z - RSA public key: Z - Intermediate

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y Z Z Z Z © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 2 5 o f 4 9

Page 26
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access key generation value: Z - HKDF Derived key: Z - KBKDF derived key: Z - TLS derived key: Z - IKEv2 derived key: Z
Key-based Key DerivationDerive a key from a key - derivation keyCKS_NSS_FIPS_OKKey-derivation keyKBKDF derived keyKBKDFCrypto Officer - Key- derivation key: W,E - KBKDF derived key: G
HMAC-based Key DerivationDerive a key from a shared secretCKS_NSS_FIPS_OKShared secretHKDF derived keyHKDFCrypto Officer - Shared secret: W,E - HKDF Derived key: G
IKEv2 Key DerivationDerived a key from a shared secretCKS_NSS_FIPS_OKShared secretIKEv2 derived keyIKEv2 KDF (CVL)Crypto Officer - Shared secret: W,E - IKEv2 derived key: G
TLS Key DerivationDerive a key from a shared secretCKS_NSS_FIPS_OKShared secretTLS derived keyTLS 1.0/1.1 KDF, TLS 1.2 KDF (CVL)Crypto Officer - Shared secret: W,E - TLS derived key: G

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y Z Z Z G G G Table 14 : Approved Services The following convention is used to specify access rights to SSPs:

1 . Th e s e s s io n in d ic a t o r, wh ic h m u s t b e u s e d fo r a ll c ryp t o g ra p h ic s e rvic e s e xc e p t

t h e Ke y De riva t io n s e rvic e . It c a n b e a c c e s s e d b y in vo kin g t h e © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 2 6 o f 4 9

Page 27
NameDescriptionAlgorithmsRole
Message DigestCompute a message digestMD2, MD5, SHA -1CO
EncryptionEncrypt a plaintextRC2, RC4, DES, Triple -DES, CDMF, Camellia, SEED, ChaCha20( - Poly1305) AES GCM (external IV)CO
DecryptionDecrypt a ciphertextRC2, RC4, DES, Triple -DES, CDMF, Camellia, SEED, ChaCha20( - Poly1305)CO
Message AuthenticationCompute a MAC tagCBC-MAC, AES XCBC-MAC, AES XCBC-MAC-96 HMAC (MD2, MD5, SHA -1; < 112 -bit keys) HMAC/SSLv3 MAC (constant -time implementation)CO
Key DerivationDerive a key from a key-derivation key or a shared secretMD2, MD5, SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, DES, Triple-DES, AES, Camellia, SEED, ANS X9.63 KDF (SHA -1, SHA-224, SHA-256, SHA-384, SHA-512), SSL 3 PRF (MD5, SHA -1), IKEv1 PRF (AES XCBC-MAC, MD2, MD5, SHA -1, SHA-224, SHA-256, SHA-384, SHA-512) KBKDF, HKDF, TLS 1.0/1.1 KDF, TLS 1.2 KDF, IKEv2 KDF (< 112 -bit keys) KBKDF (MD2, MD5) TLS 1.2 KDF (without extended master secret) IKEv2 KDF (MD2, MD5)CO
Password-Based Key DerivationDerive a key from a passwordPKCS#5 PBE, PKCS#12 PBE PBKDF2 (password<8 characters, salt<128 bits, iteration count<1000, or key<112 bits)CO
Shared Secret ComputationCompute a shared secretJ-PAKE DH (Shared secret computation; FIPS 186 -type groups) ECDH (Shared secret computation; P -192)CO
Signature GenerationGenerate a signatureDSA (SigGen) RSA (SigGen primitive; PKCS#1 v1.5 or PSS with MD2, MD5) ECDSA (SigGen; P-192)CO
Asymmetric EncryptionEncrypt a plaintextRSA (encryption)CO
Asymmetric DecryptionDecrypt a plaintextRSA (decryption)CO
Parameter GenerationGenerate domain parametersDSA (parameter generation)CO
Parameter VerificationVerify domain parametersDSA (parameter verification)CO

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y NSC_NSSGe t FIPSSt a t u s fu n c t io n wit h t h e CKT_NSS_SESSION_LAST_CHECK p a ra m e t e r. If t h e o u t p u t p a ra m e t e r is s e t t o CKS_NSS_FIPS_OK (1 ), t h e s e rvic e wa s a p p ro ve d .

2 . Th e o b je c t in d ic a t o r, wh ic h m u s t b e u s e d fo r t h e Ke y De riva t io n s e rvic e . It c a n b e

a c c e s s e d b y in vo kin g t h e NSC_NSSGe t FIPSSt a t u s fu n c t io n wit h t h e CKT_NSS_OBJECT_CHECK p a ra m e t e r a n d t h e o u t p u t d e rive d ke y. If t h e o u t p u t p a ra m e t e r is s e t t o CKS_NSS_FIPS_OK (1 ), t h e s e rvic e wa s a p p ro ve d .

3 . Th e Ra n d o m Nu m b e r Ge n e ra t io n s e rvic e in d ic a t o r, wh ic h m u s t b e u s e d fo r t h e

Ra n d o m Nu m b e r Ge n e ra t io n s e rvic e . It c a n b e a c c e s s e d b y in vo kin g t h e C_Se e d Ra n d o m o r C_Ge n e ra t e Ra n d o m fu n c t io n s . If a n y o f t h e s e fu n c t io n s re t u rn s CKR_OK, t h e s e rvic e wa s a p p ro ve d .

4 . Th e DSA Sig n a t u re Ve rific a t io n in d ic a t o r, wh ic h m u s t b e u s e d fo r t h e DSA

Sig n a t u re Ve rific a t io n s e rvic e . It c a n b e a c c e s s e d b y in vo kin g t h e C_Ve rifyIn it fu n c t io n wit h a n y CKM_DSA_* m e c h a n is m p a ra m e t e r. If t h is fu n c t io n re t u rn s CKR_OK, t h e s e rvic e wa s a p p ro ve d .

4.4 Non -Approved Services

© 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 2 7 o f 4 9

Page 28
NameDescriptionAlgorithmsRole
Key Pair GenerationGenerate a key pairDH (KeyGen, FIPS 186 -type groups) RSA (KeyGen, modulus < 2048 bits) ECDSA (KeyGen, P -192) DSA (key pair generation)CO
Secret Key GenerationGenerate a symmetric keySymmetric Key Generation (< 112 bits)CO
Signature VerificationVerify a signatureRSA (SigVer primitive; PKCS#1 v1.5 or PSS with MD2, MD5) ECDSA (SigVer; P-192)CO

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y Table 15 : Non -Approved Services The indicator value for the non -approved services specified in the Non -Approved Services table is CKS_NSS_FIPS_NOT_OK (0).

4.5 External Software/Firmware Loaded

The module does not load external software or firmware. © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 2 8 o f 4 9

Page 29

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y

5 Software/Firmware Security
5.1 Integrity Techniques

The integrity of the module is verified by performing DSA signature verification with a 2048 bit key and SHA -256. Each software component of the module has an associated integrity check value, which contains the DSA signature of the shared library.

5.2 Initiate on Demand

Integrity tests are performed as part of the pre -operational self -tests, which are executed when the module is initialized. The integrity tests may be invoked on -demand by unloading and subsequently re -initializing the module, which will perform (among oth ers) the software integrity tests. © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 2 9 o f 4 9

Page 30

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y

6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Modifiable How Requirements are Satisfied: Any SSPs contained within the module are protected by the process isolation and memory separation mechanisms provided by the Linux kernel, and only the module has control over these SSPs.

6.2 Configuration Settings and Restrictions

The module shall be installed as stated in Section 11. If properly installed, the operating system provides process isolation and memory protection mechanisms that ensure appropriate separation for memory access among the processes on the system. Each proc ess has control over its own data and uncontrolled access to the data of other processes is prevented. Instrumentation tools like the ptrace system call, gdb and strace, userspace live patching, as well as other tracing mechanisms offered by the Linux environment such as ftrace or systemtap, shall not be used in the operational environment. The use of any of these tools implies that the cryptographic module is running in a non -validated operational environment. © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 3 0 o f 4 9

Page 31

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y

7 Physical Security

The module is comprised of software only and therefore this section is not applicable. © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 3 1 o f 4 9

Page 32

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y

8 Non -Invasive Security

This module does not implement any non -invasive security mechanism and therefore this section is not applicable. © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 3 2 o f 4 9

Page 33
Storage Area NameDescriptionPersistence Type
RAMTemporary storage for SSPs used by the module as part of service execution.Dynamic
Name API input parameters (plaintext)From Calling application within TOEPPTo Cryptographic moduleFormat Type PlaintextDistribution Type ManualEntry Type ElectronicSFI or Algorithm
API input parameters (encrypted)Calling application within TOEPPCryptographic moduleEncryptedManualElectronic uAES-KW, AES-KWP, AES-GCM (KTS, key nwrapping)
API output parameters (plaintext)Cryptographic moduleCalling application within TOEPPPlaintextManualElectronic
API output parameters (encrypted)Cryptographic moduleCalling application within TOEPPEncryptedManualElectronicAES-KW, AES-KWP, AES-GCM (KTS, key wrapping)
Zeroization MethodDescriptionRationaleOperator Initiation
Destroy ObjectDestroys the SSP represented by the objectMemory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable. The completion of the zeroization routine indicates that the zeroization procedure succeeded.By calling the C_DestroyObject function
AutomaticAutomatically zeroized by the module when no longer neededMemory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievableN/A
Remove power from the moduleDe-allocates the volatile memory used to store SSPsVolatile memory used by the module is overwritten within nanoseconds when power is removed. Module power off indicates that the zeroization procedure succeeded.By removing power

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y

9 Sensitive Security Parameters Management
9.1 Storage Areas

Table 16 : Storage Areas The module does not perform persistent storage of SSPs. SSPs are provided to the module (encrypted) unwrapping) Table 17 : SSP Input -Output Methods CSPs (with the exception of passwords) can only be imported to and exported from the module when they are wrapped (encrypted) using an approved security function (e.g. AES KW or KWP). PSPs can be imported and exported in plaintext. Import and export is per formed using API input and output parameters. The module only supports SSP entry and output to and from the calling application running on the same operational environment. Table 18 : SSP Zeroization Methods © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 3 3 o f 4 9

Page 34

Name AES key HMAC key Key- derivation key Shared secret Password HKDF Derived key Entropy input DRBG seed Internal state (V, C) DH private key

Description AES key used for encryption, decryption, and computing MAC tags HMAC key used for computing MAC tags Symmetric key used to derive symmetric keys Shared secret generated by (EC) Diffie - Hellman Password used to derive symmetric keys Symmetric key derived from a shared secret Entropy input used to seed the DRBG DRBG seed derived from entropy input Internal state of the Hash_DRBG instance Private key used for Diffie - Hellman

Size - Strength 128, 192, 256 bits - 128, 192, 256 bits 112-524288 bits - 112-256 bits 112-4096 bits - 112- 256 bits 256-8192 bits - 112- 256 bits 8-128 characters - N/A 2048 bits - 112-256 bits 440 bits - 440 bits 440 bits - 256 bits 880 bits - 256 bits 2048-8192 bits - 112- 200 bits

Type - Category Symmetric key - CSP Symmetric key - CSP Symmetric key - CSP Shared secret - CSP Password - CSP Symmetric key - CSP Entropy input - CSP Seed - CSP Internal state - CSP Private key - CSP

Generated By Hash DRBG (symmetric key generation) Hash DRBG (symmetric key generation) Hash DRBG (symmetric key generation) HKDF Hash DRBG Hash DRBG Safe Primes Key Generation (key pair generation)

Established By KAS-FFC-SSC KAS-ECC- SSC

Used By AES (ECB, CBC, CBC-CS1, CTR) AES (KW, KWP) AES (GCM, encryption, internal IV) AES (CMAC) AES (GCM, decryption, external IV) AES-KW, AES- KWP, AES-GCM (KTS, key wrapping) AES-KW, AES- KWP, AES-GCM (KTS, key unwrapping) HMAC KBKDF TLS 1.0/1.1 KDF, TLS 1.2 KDF (CVL) HKDF IKEv2 KDF (CVL) PBKDF2 Hash DRBG Hash DRBG Hash DRBG KAS-FFC-SSC

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y All d a t a o u t p u t is in h ib it e d d u rin g ze ro iza t io n . Me m o ry is d e a llo c a t e d a ft e r ze ro iza t io n .

9.4 SSPs

© 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 3 4 o f 4 9

Page 35

Name DH public key EC private key EC public key DSA public key RSA private key RSA public key Intermediate key generation value KBKDF derived key TLS derived key IKEv2 derived key PBKDF derived key

Description Public key used for Diffie - Hellman Private key used for ECDH and ECDSA Public key used for ECDH and ECDSA Public key used for DSA signature verification Private key used for RSA signature generation Public key used for RSA signature verification Temporary value generated during symmetric key and key pair generation services Symmetric key derived from a key-derivation key Symmetric key derived from a shared secret Symmetric key derived from a shared secret Symmetric key derived from a password

Size - Strength 2048-8192 bits - 112- 200 bits P-256, P-384, P-521 - 128, 192, 256 bits P-256, P-384, P-521 - 128, 192, 256 bits (1024, 160), (2048, 224), (2048, 256), (3072, 256) - 80, 112, 128 bits 2048-4096 bits - 112- 150 bits Signature verification: 1024 - 4096 bits; Key pair generation: 2048 - 4096 bits - Signature verification: 80 - 150 bits; Key pair generation: 112 - 150 bits 112-8192 bits - 112- 256 bits 112-4096 bits - 112- 256 bits 112-256 bits - 112- 256 bits 112-256 bits - 112- 256 bits 128-2048 bits - 112- 256 bits

Type - Category Public key - PSP Private key - CSP Public key - PSP Public key - PSP Private key - CSP Public key - PSP Intermediate value - CSP Symmetric key - CSP Symmetric key - CSP Symmetric key - CSP Symmetric key - CSP

Generated By Safe Primes Key Generation (key pair generation) ECDSA KeyGen (key pair generation) ECDSA KeyGen (key pair generation) RSA KeyGen (key pair generation) RSA KeyGen (key pair generation) RSA KeyGen (key pair generation) ECDSA KeyGen (key pair generation) Safe Primes Key Generation (key pair generation) KBKDF TLS 1.0/1.1 KDF, TLS 1.2 KDF (CVL) IKEv2 KDF (CVL) PBKDF2

Established By

Used By KAS-FFC-SSC KAS-ECC-SSC ECDSA SigGen KAS-ECC-SSC ECDSA SigVer ECDSA SigVer (Legacy) DSA SigVer (Legacy) RSA SigGen RSA SigVer RSA SigVer (Legacy) RSA KeyGen (key pair generation) ECDSA KeyGen (key pair generation) Safe Primes Key Generation (key pair generation)

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y Table 19 : SSP Table 1 © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 3 5 o f 4 9

Page 36
Name AES key HMAC keyInput - Output API input parameters (encrypted) API output parameters (encrypted) API input parameters (encrypted) API output parameters (encrypted)Storage RAM:Plaintext RAM:PlaintextStorage Duration Until explicitly zeroized by operator Until explicitly zeroized by operatorZeroization Destroy Object Remove power from the module Destroy Object Remove power from the moduleRelated SSPs
Key-derivation keyAPI input parameters (encrypted)RAM:PlaintextUntil explicitly zeroized by operatorDestroy Object Remove power from the moduleKBKDF derived key:Used to derive
Shared secretAPI input parameters (encrypted) API output parameters (encrypted)RAM:PlaintextUntil explicitly zeroized by operatorDestroy Object Remove power from the moduleDH private key:Established using DH public key:Established using EC private key:Established using EC public key:Established using TLS derived key:Used to derive IKEv2 derived key:Used to derive HKDF Derived key:Used to derive
PasswordAPI input parameters (plaintext)RAM:PlaintextFor the duration of the serviceDestroy Object Remove power from the modulePBKDF derived key:Used to derive
HKDF Derived keyAPI output parameters (encrypted)RAM:PlaintextUntil explicitly zeroized by operatorDestroy Object Remove power from the moduleShared secret:Derived From
Entropy inputRAM:PlaintextFrom generation until DRBG seed is createdAutomatic Remove power from the moduleDRBG seed:Used to derive
DRBG seedRAM:PlaintextWhile the DRBG is instantiatedAutomatic Remove power from the moduleEntropy input:Derived From Internal state (V, C):Used to generate
Internal state (V, C)RAM:PlaintextWhile the module is operationalRemove power from the moduleDRBG seed:Generated from
DH private keyAPI input parameters (encrypted) API output parameters (encrypted)RAM:PlaintextUntil explicitly zeroized by operatorDestroy Object Remove power from the moduleDH public key:Paired With Intermediate key generation value:Generated from
DH public keyAPI input parameters (plaintext) API output parameters (plaintext)RAM:PlaintextUntil explicitly zeroized by operatorDestroy Object Remove power from the moduleDH private key:Paired With Intermediate key generation value:Generated from
EC private keyAPI input parameters (encrypted) API outputRAM:PlaintextUntil explicitly zeroized by operatorDestroy Object Remove power from the moduleEC public key:Paired With Intermediate key generation value:Generated from

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 3 6 o f 4 9

Page 37
NameInput - Output parameters (encrypted)StorageStorage DurationZeroizationRelated SSPs
EC public keyAPI input parameters (plaintext) API output parameters (plaintext)RAM:PlaintextUntil explicitly zeroized by operatorDestroy Object Remove power from the moduleEC private key:Paired With Intermediate key generation value:Generated from
DSA public keyAPI input parameters (plaintext)RAM:PlaintextUntil explicitly zeroized by operatorDestroy Object Remove power from the module
RSA private keyAPI input parameters (encrypted) API output parameters (encrypted)RAM:PlaintextUntil explicitly zeroized by operatorDestroy Object Remove power from the moduleRSA public key:Paired With Intermediate key generation value:Generated from
RSA public keyAPI input parameters (plaintext) API output parameters (plaintext)RAM:PlaintextUntil explicitly zeroized by operatorDestroy Object Remove power from the moduleRSA private key:Paired With Intermediate key generation value:Generated from
Intermediate key generation valueRAM:PlaintextFor the duration of the serviceAutomaticDH private key:Created during generation of DH public key:Created during generation of EC private key:Created during generation of EC public key:Created during generation of RSA private key:Created during generation of RSA public key:Created during generation of
KBKDF derived keyAPI output parameters (encrypted)RAM:PlaintextFor the duration of the serviceDestroy Object Remove power from the moduleKey-derivation key:Derived From
TLS derived keyAPI output parameters (encrypted)RAM:PlaintextFor the duration of the serviceDestroy Object Remove power from the moduleShared secret:Derived From
IKEv2 derived keyAPI output parameters (encrypted)RAM:PlaintextFor the duration of the serviceDestroy Object Remove power from the moduleShared secret:Derived From
PBKDF derived keyAPI output parameters (encrypted)RAM:PlaintextFor the duration of the serviceDestroy Object Remove power from the modulePassword:Derived From

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y Table 20 : SSP Table 2

9.5 Transitions

The SHA -1 algorithm as implemented by the module will be non -approved for all purposes, starting January 1, 203 1. The ECDSA, and RSA algorithms as implemented by the module conform to FIPS 186 -4, which has been superseded by FIPS 186 -5. The transition started on July 25, 2023, and ended on February 4, 2024 . FIPS 186 -4 was withdrawn on February 3, 2024. © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 3 7 o f 4 9

Page 38

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 3 8 o f 4 9

Page 39
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
DSA SigVer (FIPS186-4) (A4576)2048-bit key with SHA-256Signature VerificationSW/FW IntegrityModule becomes operationalIntegrity test for libfreeblpriv3.so and libfsoftokn3.so
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
SHA-1 (A4576)512-bit messageKATCASTModule becomes operational and services are available for useMessage DigestFreebl initialization
SHA2-224 (A4576)512-bit messageKATCASTModule becomes operational and services are available for useMessage DigestFreebl initialization
SHA2-256 (A4576)512-bit messageKATCASTModule becomes operational and services are available for useMessage DigestFreebl initialization
SHA2-384 (A4576)512-bit messageKATCASTModule becomes operational and services are available for useMessage DigestFreebl initialization
SHA2-512 (A4576)512-bit messageKATCASTModule becomes operational andMessage DigestFreebl initialization

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y

10 Self -Tests

Upon initialization, the module immediately performs all Freebl cryptographic algorithm self tests (CASTs) as specified in the Conditional Self -Tests table. When all those self -tests pass successfully, the module automatically performs the pre -operational integrity test on the libfreeblpriv3.so file using its associated check value. Then, the module performs the DSA CAST in the Softoken library, followed by the the pre operational integrity test on the libsoftokn3.so file using its associated check value. Finally, all remaining CASTs for the algorithms implemented in Softoken are exec uted (see the Conditional Self -Tests table). Only if all CASTs and pre -operational integrity tests passed successfully, the module transitions to the operational state. No operator intervention is required to reach this point. While the module is executing the self -tests, services are not available, and data output (via the data output interface) is inhibited until the tests are successfully completed. If any of the self -tests fail an error message is returned, and the module tr ansitions to an error state.

10.1 Pre -Operational Self -Tests

Table 21 : Pre -Operational Self -Tests Each software component of the module has an associated integrity check value, which contains the DSA signature of the shared library. The software integrity tests ensure that the module is not corrupted. The DSA and SHA -256 algorithms go through their res pective CASTs before the software integrity tests are performed.

10.2 Conditional Self -Tests

© 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 3 9 o f 4 9

Page 40
Algorithm or TestTest PropertiesTest MethodTest TypeIndicator services are available for useDetailsConditions
AES-ECB (A4576)128, 192, 256 -bit key, 128-bit plaintextKATCASTModule becomes operational and services are available for useEncryption, DecryptionFreebl initialization
AES-ECB (A4583)128, 192, 256 -bit key, 128-bit plaintextKATCASTModule becomes operational and services are available for useEncryption, DecryptionFreebl initialization
AES-ECB (A4585)128, 192, 256 -bit key, 128-bit plaintextKATCASTModule becomes operational and services are available for useEncryption, DecryptionFreebl initialization
AES-CBC (A4576)128, 192, 256 -bit key, 128-bit plaintextKATCASTModule becomes operational and services are available for useEncryption, DecryptionFreebl initialization
AES-CBC (A4581)128, 192, 256 -bit key, 128-bit plaintextKATCASTModule becomes operational and services are available for useEncryption, DecryptionFreebl initialization
AES-CBC (A4583)128, 192, 256 -bit key, 128-bit plaintextKATCASTModule becomes operational and services are available for useEncryption, DecryptionFreebl initialization
AES-CBC (A4585)128, 192, 256 -bit key, 128-bit plaintextKATCASTModule becomes operational and services are available for useEncryption, DecryptionFreebl initialization
AES-GCM (A4576)128, 192, 256 -bit key, 128-bit IV, 128 -bit plaintext, 112 -bit additional dataKATCASTModule becomes operational and services are available for useEncryption, DecryptionFreebl initialization
AES-GCM (A4583)128, 192, 256 -bit key, 128-bit IV, 128 -bit plaintext, 112 -bit additional dataKATCASTModule becomes operational and services are available for useEncryption, DecryptionFreebl initialization
AES-GCM (A4585)128, 192, 256 -bit key, 128-bit IV, 128 -bit plaintext, 112 -bit additional dataKATCASTModule becomes operational and services are available for useEncryption, DecryptionFreebl initialization
AES-CMAC (A4578)128, 192, 256 -bit key, 128-bit messageKATCASTModule becomes operational and services are available for useMessage AuthenticationFreebl initialization
HMAC-SHA-1 (A4576)288-bit keyKATCASTModule becomes operational and services are available for useMessage AuthenticationFreebl initialization
HMAC-SHA2- 224 (A4576)288-bit keyKATCASTModule becomes operational and services are available for useMessage AuthenticationFreebl initialization
HMAC-SHA2- 256 (A4576)288-bit keyKATCASTModule becomes operational and services are available for useMessage AuthenticationFreebl initialization

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 4 0 o f 4 9

Page 41
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
HMAC-SHA2- 384 (A4576)288-bit keyKATCASTModule becomes operational and services are available for useMessage AuthenticationFreebl initialization
HMAC-SHA2- 512 (A4576)288-bit keyKATCASTModule becomes operational and services are available for useMessage AuthenticationFreebl initialization
KDF SP800-108 (A4579)Counter mode HMAC SHA-256 576-bit input keyKATCASTModule becomes operational and services are available for useKey DerivationSoftoken initialization
KDA HKDF Sp800-56Cr1 (A4575)SHA-256, 512 -bit input secretKATCASTModule becomes operational and services are available for useKey DerivationSoftoken initialization
KDF TLS (A4576)288-bit input secretKATCASTModule becomes operational and services are available for useKey DerivationFreebl initialization
TLS v1.2 KDF RFC7627 (A4576)SHA-256, 288 -bit input secretKATCASTModule becomes operational and services are available for useKey DerivationFreebl initialization
KDF IKEv2 (A4580)SHA-1, SHA-256, SHA- 384, SHA-512; 80, 128, 144 -bit input secretKATCASTModule becomes operational and services are available for useKey DerivationSoftoken initialization
PBKDF (A4576)SHA-256, 14 - character password, 128-bit salt, Iteration count: 5KATCASTModule becomes operational and services are available for useKey DerivationSoftoken initialization
Hash DRBG (A4576)SHA-256 without prediction resistanceKATCASTModule becomes operational and services are available for useInstantiate, Generate, Reseed, Generate (compliant to SP 800 -90A Section 11.3)Freebl initialization
KAS-FFC-SSC Sp800-56Ar3 (A4576)2048-bit keyKATCASTModule becomes operational and services are available for useShared Secret ComputationFreebl initialization
KAS-ECC-SSC Sp800-56Ar3 (A4576)P-256KATCASTModule becomes operational and services are available for useShared Secret ComputationFreebl initialization
DSA SigVer (FIPS186-4) (A4576)1024-bit keyKATCASTModule becomes operational and services are available for useSignature verificationFreebl initialization
RSA SigGen (FIPS186-4) (A4576)PKCS#1 v1.5 with SHA-256, SHA-384, SHA-512, 2048 -bit keyKATCASTModule becomes operational and services are available for useSignature GenerationSoftoken initialization
RSA SigVer (FIPS186-4) (A4576)PKCS#1 v1.5 with SHA-256, SHA-384, SHA-512, 2048 -bit keyKATCASTModule becomes operational and services are available for useSignature VerificationSoftoken initialization

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 4 1 o f 4 9

Page 42
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
ECDSA SigGen (FIPS186-4) (A4576)SHA-256, P-256KATCASTModule becomes operational and services are available for useSignature GenerationFreebl initialization
ECDSA SigVer (FIPS186-4) (A4576)SHA-256, P-256KATCASTModule becomes operational and services are available for useSignature VerificationFreebl initialization
Safe Primes Key Generation (A4576)N/APCTPCTSuccessful key pair generationSP 800-56Ar3 section 5.6.2.1.4Key pair generation
RSA KeyGen (FIPS186-4) (A4576)PKCS#1 v1.5 with SHA-256PCTPCTSuccessful key pair generationSignature Generation & Signature VerificationKey pair generation
ECDSA KeyGen (FIPS186-4) (A4576)ECDSA KeyGen: SHA - 256; EC KeyGen for ECDHPCTPCTSuccessful key pair generationSignature Generation & Signature Verification; SP 800-56Ar3 section 5.6.2.1.4Key pair generation
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
DSA SigVer (FIPS186 - 4) (A4576)Signature VerificationSW/FW IntegrityOn demandManually
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
SHA-1 (A4576)KATCASTOn demandManually
SHA2-224 (A4576)KATCASTOn demandManually
SHA2-256 (A4576)KATCASTOn demandManually
SHA2-384 (A4576)KATCASTOn demandManually
SHA2-512 (A4576)KATCASTOn demandManually
AES-ECB (A4576)KATCASTOn demandManually
AES-ECB (A4583)KATCASTOn demandManually
AES-ECB (A4585)KATCASTOn demandManually
AES-CBC (A4576)KATCASTOn demandManually
AES-CBC (A4581)KATCASTOn demandManually
AES-CBC (A4583)KATCASTOn demandManually
AES-CBC (A4585)KATCASTOn demandManually

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y 5.6.2.1.4 Table 22 : Conditional Self -Tests The module performs self -tests on all approved cryptographic algorithms as part of the approved services supported in the approved mode of operation, using the tests shown in the Conditional Self -Tests table. Upon generation of a key pair, the module will perform a pair -wise consistency test (PCT), as shown in the Conditional Self -Tests table, which provides some assurance that the generated key pair is well formed. For DH and EC key pairs, these tests consist of the PCT of a signature generation and a signature verification operation. Note that two PCTs are

10.3 Periodic Self -Test Information

Table 23 : Pre -Operational Periodic Information © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 4 2 o f 4 9

Page 43
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-GCM (A4576)KATCASTOn demandManually
AES-GCM (A4583)KATCASTOn demandManually
AES-GCM (A4585)KATCASTOn demandManually
AES-CMAC (A4578)KATCASTOn demandManually
HMAC-SHA-1 (A4576)KATCASTOn demandManually
HMAC-SHA2-224 (A4576)KATCASTOn demandManually
HMAC-SHA2-256 (A4576)KATCASTOn demandManually
HMAC-SHA2-384 (A4576)KATCASTOn demandManually
HMAC-SHA2-512 (A4576)KATCASTOn demandManually
KDF SP800-108 (A4579)KATCASTOn demandManually
KDA HKDF Sp800 - 56Cr1 (A4575)KATCASTOn demandManually
KDF TLS (A4576)KATCASTOn demandManually
TLS v1.2 KDF RFC7627 (A4576)KATCASTOn demandManually
KDF IKEv2 (A4580)KATCASTOn demandManually
PBKDF (A4576)KATCASTOn demandManually
Hash DRBG (A4576)KATCASTOn demandManually
KAS-FFC-SSC Sp800- 56Ar3 (A4576)KATCASTOn demandManually
KAS-ECC-SSC Sp800- 56Ar3 (A4576)KATCASTOn demandManually
DSA SigVer (FIPS186 - 4) (A4576)KATCASTOn demandManually
RSA SigGen (FIPS186 - 4) (A4576)KATCASTOn demandManually
RSA SigVer (FIPS186 - 4) (A4576)KATCASTOn demandManually
ECDSA SigGen (FIPS186-4) (A4576)KATCASTOn demandManually
ECDSA SigVer (FIPS186-4) (A4576)KATCASTOn demandManually
Safe Primes Key Generation (A4576)PCTPCTOn demandManually
RSA KeyGen (FIPS186 - 4) (A4576)PCTPCTOn demandManually
ECDSA KeyGen (FIPS186-4) (A4576)PCTPCTOn demandManually
NameDescriptionConditionsRecovery MethodIndicator
Power-On ErrorAn error occurred during the self - tests executed on power -onSoftware integrity test failure CAST failureRestart of the moduleModule will not load

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y Table 24 : Conditional Periodic Information

10.4 Error States

© 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 4 3 o f 4 9

Page 44
NameDescriptionConditionsRecovery MethodIndicator
PCT ErrorAn error occurred during a PCTPCT failureRestart of the moduleModule stops functioning (sftk_fatalError is set to TRUE)

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y Table 25 : Error States In any error state, the output interface is inhibited, and the module accepts no more inputs or requests.

10.5 Operator Initiation of Self -Tests

The software integrity tests and CASTs can be invoked on demand by unloading and subsequently re -initializing the module. The PCTs can be invoked on demand by requesting the Key Pair Generation service. © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 4 4 o f 4 9

Page 45

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y

11 Life -Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

The module is distributed as a part of the Amazon Linux 2023 package in the form of the nss -softokn -3.90.0 -6.amzn2023.0. 1 and nss -softokn -freebl -3.90.0 -6.amzn2023.0. 1 RPM packages. The Netscape Portable Runtime (NSPR) package nspr -4.35.0 -6.amzn2023.0. 1 is a prerequisite for the module. Before the RPM packages are installed, the Amazon Linux 2023 system must operate in the FIPS validated configuration. To achieve this, the Crypto Officer must execute the fips -mode setup --enable command, then, restart the system. More information can be f ound at the vendor documentation . The Crypto Officer must verify the Amazon Linux 2023 system operates in the FIPS validated configuration by executing the fips -mode -setup --check command, which should output “FIPS mode is enabled.”

11.2 Administrator Guidance

After installation of the RPM packages, the Crypto Officer must execute the “Show Version” service by accessing the CKA_NSS_VALIDATION_MODULE_ID attribute of the CKO_NSS_VALIDATION object in the default slot. The object attribute must contain the value Amazon Linux 2023 nss 3.90.0 -3e9a8358c972db98 Alternatively, the /usr/lib64/nss/unsupported -tools/validation tool is provided as a convenience by the nss -tools -3.90.0 -6.amzn2023.0. 1 RPM package. This tool performs the same steps, and outputs the FIPS module identifier as above. The cryptographic boundary consists only of the Softoken and Freebl libraries along with their associated integrity check values as listed in the Tested Module Identification table. If any other NSS API outside of these two libraries is invoked, the user i s not interacting with the module specified in this Security Policy.

11.3 Non -Administrator Guidance

There is no non -administrator guidance.

11.6 End of Life

As the module does not persistently store SSPs, secure sanitization of the module consists of unloading the module. This will zeroize all SSPs in volatile memory. Then, if desired, the nss softokn -3.90.0 -6.amzn2023.0. 1 and nss -softokn -freebl -3.90.0 -6.amzn2023.0. 1 RPM packages can be uninstalled from the Amazon Linux 2023 systems. © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 4 5 o f 4 9

Page 46
AttackMitigation MechanismSpecific Limit
Timing attacks on RSARSA blinding Timing attack on RSA was first demonstrated by Paul Kocher in 1996, who contributed the mitigation code to our module. Most recently Boneh and Brumley showed that RSA blinding is an effective defense against timing attacks on RSA.None
Cache-timing attacks on the modular exponentiation operation used in RSACache invariant modular exponentiation This is a variant of a modular exponentiation implementation that Colin Percival showed to defend against cache -timing attacksThis mechanism requires intimate knowledge of the cache line sizes of the processor. The mechanism may be ineffective when the module is running on a processor whose cache line sizes are unknown.
Arithmetic errors in RSA signaturesDouble -checking RSA signatures Arithmetic errors in RSA signatures might leak the private key. Ferguson and Schneier recommend that every RSA signature generation should verify the signature just generated.None

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y

12.1 Attack List
Page 47

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y Appendix A. Glossary and Abbreviations

AESAdvanced Encryption Standard
AES -NIAdvanced Encryption Standard New Instructions
CAVPCryptographic Algorithm Validation Program
CASTCryptographic Algorithm Self -Test
CBCCipher Block Chaining
CMACCipher -based Message Authentication Code
CMVPCryptographic Module Validation Program
CSPCritical Security Parameter
CTRCounter Mode
DESData Encryption Standard
DSADigital Signature Algorithm
DRBGDeterministic Random Bit Generator
ECBElectronic Code Book
ECCElliptic Curve Cryptography
FIPSFederal Information Processing Standards Publication
GCMGalois Counter Mode
HMACHash Message Authentication Code
KATKnown Answer Test
KWAES Key Wrap
KWPAES Key Wrap with Padding
MACMessage Authentication Code
NISTNational Institute of Science and Technology
OSOperating System
PAAProcessor Algorithm Acceleration
PCTPair -Wise Consistency Test
PSPPublic Security Parameter
PSSProbabilistic Signature Scheme
RNGRandom Number Generator
RSARivest, Shamir, Addleman
SHASecure Hash Algorithm © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 4 7 o f 4 9
Page 48

Amazon Linux 2023 NSS Cryptographic Module FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y Appendix B. References FIPS140 -3 FIPS PUB 140 -3 - Security Requirements for Cryptographic Modules March 2019 https://doi.org/10.6028/NIST.FIPS.140 -3 FIPS140 -3_IG Implementation Guidance for FIPS PUB 140 -3 and the Cryptographic Module Validation Program January 2024 https://csrc.nist.gov/Projects/cryptographic -module -validation program/fips -140 -3-ig -announcements FIPS180 -4 Secure Hash Standard (SHS) March 2012 http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180 -4.pdf FIPS186 -4 Digital Signature Standard (DSS) July 2013 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186 -4.pdf FIPS186 -5 Digital Signature Standard (DSS) February 2023 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186 -5.pdf FIPS197 Advanced Encryption Standard November 2001 http://csrc.nist.gov/publications/fips/fips197/fips -197.pdf FIPS198 -1 The Keyed Hash Message Authentication Code (HMAC) July 2008 http://csrc.nist.gov/publications/fips/fips198 -1/FIPS-198 -1_final.pdf PKCS#1 Public Key Cryptography Standards (PKCS) #1: RSA Cryptography Specifications Version 2.1 February 2003 http://www.ietf.org/rfc/rfc3447.txt SP800 -38A Special Publication 800 -38A - Recommendation for Block Cipher Modes of Operation Methods and Techniques December 2001 http://csrc.nist.gov/publications/nistpubs/800 -38a/sp800 -38a.pdf SP800 -38B NIST Special Publication 800 -38B - Recommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication May 2005 http://csrc.nist.gov/publications/nistpubs/800 -38B/SP_800 -38B.pdf SP800 -38D NIST Special Publication 800 -38D - Recommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC November 2007 http://csrc.nist.gov/publications/nistpubs/800 -38D/SP -800 -38D.pdf SP800 -38F NIST Special Publication 800 -38F - Recommendation for Block Cipher Modes of Operation: Methods for Key Wrapping December 2012 http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800 -38F.pdf © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 4 8 o f 4 9

Page 49
Table, extracted as text (did not parse into structured rows)
Amazon Linux 2023 NSS Cryptographic Module                                                                          FIPS 1 4 0 -3 No n -Pro p rie t a ry Se c u rit y Po lic y SP800 -56Ar3                   NIST Special Publication 800         -56A Revision 3      - Recommendation for Pair Wise Key Establishment Schemes Using Discrete Logarithm Cryptography April 2018 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800            56Ar3.pdf SP800 -56Cr2                   NIST Special Publication 800         -56C Revision 2      - Recommendation for Key -Derivation Methods in Key           -Establishment Schemes August 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800            56Cr2.pdf SP800 -90Ar1                   NIST Special Publication 800         -90A - Revision 1 - Recommendation for Random Number Generation Using Deterministic Random Bit Generators June 2015 http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800           90Ar1.pdf SP800 -90B                     NIST Special Publication 800         -90B - Recommendation for the Entropy Sources Used for Random Bit Generation January 2018 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800            90B.pdf SP800 -108r1                   NIST Special Publication 800         -108 Revision 1      - Transitions: Recommendation for Key Derivation Using Pseudorandom Functions August 2022 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800            108r1.pdf SP800 -131Ar1                  NIST Special Publication 800         -131A Revision 1       - Transitions: Recommendation for Transitioning the Use of Cryptographic Algorithms and Key Lengths November 2015 http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800           131Ar1.pdf SP800 -133r2                   NIST Special      Publication 800    -133rev2 - Recommendation for Cryptographic Key Generation June 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800            133r2.pdf SP800 -135r1                   NIST Special Publication 800         -135 Revision 1      - Recommendation for Existing Application       -Specific Key Derivation Functions December 2011 http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800           135r1.pdf © 2 0 2 5 Am a zo n We b Se rvice s , In c ./a t s e c in fo rm a t io n s e c u rit y. Th is d o c u m e n t ca n b e re p ro d u ce d a n d d is t rib u t e d o n ly wh o le a n d in t a c t , in clu d in g t h is c o p yrig h t n o t ic e . Pa g e 4 9 o f 4 9