All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Riverbed Cryptographic Module

Certificate#5017StandardFIPS 140-3Level1TypeSoftwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorRiverbed Technology, LLC
Low review priority  ·  no TCB surface named  ·  last validated 14 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date5/13/2030
CaveatWhen operated in approved mode. No assurance of the minimum strength of generated keys
VendorRiverbed Technology, LLC

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Riverbed Cryptographic Module
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Recovery</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Unauthenticated</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>HTTPS<br/>library named: openssl</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Riverbed Cryptographic Module
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Recovery</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Unauthenticated</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>HTTPS<br/>library named: openssl</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Riverbed Technology, LLC Riverbed Cryptographic Module Software Version: 2.0.1 FIPS Security Level: 1 Document Version: 0.5 Prepared for: Prepared by: Riverbed Technology, LLC Corsec Security, Inc.

275 Shoreline Drive 12600 Fair Lakes Circle, Suite 210

Redwood City, CA 94065 Fairfax, VA 22033 United States of America United States of America Phone: +1 415.247.8800 Phone: +1 703.267.6050 www.riverbed.com www.corsec.com

Page 2
Table of Contents
#SectionPage
Page 3

Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 4
List of Tables
ItemPage
Table 1: Security Levels6
Table 2: Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets)10
Table 3: Tested Operational Environments - Software, Firmware, Hybrid10
Table 4: Modes List and Description11
Table 5: Approved Algorithms13
Table 6: Vendor-Affirmed Algorithms14
Table 7: Non-Approved, Allowed Algorithms14
Table 8: Non-Approved, Not Allowed Algorithms15
Table 9: Security Function Implementations22
Table 10: Ports and Interfaces26
Table 11: Roles27
Table 12: Approved Services33
Table 13: Non-Approved Services34
Table 14: Storage Areas39
Table 15: SSP Input-Output Methods39
Table 16: SSP Zeroization Methods40
Table 17: SSP Table 141
Table 18: SSP Table 244
Table 19: Pre-Operational Self-Tests45
Table 20: Conditional Self-Tests48
Table 21: Pre-Operational Periodic Information48
Table 22: Conditional Periodic Information49
Table 23: Error States50
Table 24. Acronyms and Abbreviations54
Figure 1. Module Block Diagram (with Cryptographic Boundary)8
Figure 2. GPC Block Diagram9
Page 5
SectionTitleSecurity Level
1General1
2Cryptographic module specification1
1.1 Overview
1.1.1 Abstract

This is a non-proprietary Cryptographic Module Security Policy for the Riverbed Cryptographic Module (software version: 2.0.1) from Riverbed Technology, LLC (Riverbed). This Security Policy describes how the Riverbed Cryptographic Module meets the security requirements of Federal Information Processing Standards (FIPS) Publication 140-3, which details the U.S. and Canadian government requirements for cryptographic modules. More information about the FIPS 140-3 standard and validation program is available on the Cryptographic Module Validation Program (CMVP) website, which is maintained by the National Institute of Standards and Technology (NIST) and the Canadian Centre for Cyber Security (CCCS). This document also describes how to run the module in a secure Approved mode of operation. This policy was prepared as part of the Level 1 FIPS 140-3 validation of the module. The Riverbed Cryptographic Module is referred to in this document as Riverbed Crypto Module or the module.

1.1.2 References

This document deals only with operations and capabilities of the module in the technical terms of a FIPS 140-3 cryptographic module security policy. More information is available on the module from the following sources:

1.1.3 Document Organization

ISO/IEC 19790 Annex B uses the same section naming convention as ISO/IEC 19790 section 7 - Security requirements. For example, Annex B section B.2.1 is named “General” and B.2.2 is named “Cryptographic module specification,” which is the same as ISO/IEC 19790 section 7.1 and section 7.2, respectively. Therefore, the format of this Security Policy is presented in the same order as indicated in Annex B, starting with “General” and ending with “Mitigation of other attacks.” If sections are not applicable, they have been marked as such in this document.

1.2 Security Levels

The Riverbed Cryptographic Module is validated at the FIPS 140-3 section levels shown in the table below. ©2025 Riverbed Technology, LLC

Page 6
SectionTitleSecurity Level
3Cryptographic module interfaces1
4Roles, services, and authentication1
5Software/Firmware security1
6Operational environment1
7Physical securityN/A
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacksN/A
Overall Level1

Table 1: Security Levels ©2025 Riverbed Technology, LLC

Page 7
2.1 Description
2.1.1 Purpose and Use

Since its inception in 2002, Riverbed Technology, LLC has helped the world’s largest organizations maximize the performance of their networks and applications so they can reach the full potential of their IT investments. Riverbed’s products consist of software and hardware focused on network performance monitoring, application performance management, and wide area networks (WANs). The Riverbed Network and Application Performance Platform enables organizations to visualize, optimize, accelerate, and remediate the performance of any network for any application. Only Riverbed addresses performance and visibility holistically with best-in-class WAN optimization, network performance management, application acceleration, and enterprise-grade SD-WAN 1. The Riverbed Cryptographic Module v2.0.1 is a software library providing a C language API 2 for use by Riverbed applications requiring cryptographic functionality. The Riverbed Cryptographic Module offers symmetric encryption/decryption, digital signature generation/verification, hashing, cryptographic key generation, random number generation, message authentication, and key establishment functions to secure data-at-rest/data-inflight and to support secure communications protocols (including TLS 3 1.2/1.3).

2.1.2 Module Type

The Riverbed Cryptographic Module 2.0.1 is a Software module.

2.1.3 Module Embodiment

The Riverbed Cryptographic Module has a MultiChipStand embodiment.

2.1.4 Cryptographic Boundary

The cryptographic boundary is the contiguous perimeter that surrounds all memory-mapped functionality provided by the module when loaded and stored in the host platform’s memory. Figure 2 is a block diagram of the module executing in memory and its interactions with surrounding software components, as well as the module’s cryptographic boundary and Tested Operational Environment’s Physical Perimeter (TOEPP).

1 SD-WAN – Software-Defined Wide Area Network

API – Application Programming Interface

3 TLS – Transport Layer Security

Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 8

Figure 1. Module Block Diagram (with Cryptographic Boundary) The module is entirely contained within the physical perimeter.

2.1.5 Tested Operational Environment’s Physical Perimeter

(TOEPP) As a software cryptographic module, the TOEPP of the cryptographic module is defined by each host platform on which the module is installed. Figure 2 below illustrates a block diagram of a typical GPC (the black dotted line represents the module’s physical perimeter). Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 9
Table, extracted as text (did not parse into structured rows)
Hardware                                  Network                            DVD RAM Management                                 Interface HDD Clock                                                                 SCSI/SATA Generator                                                              Controller LEDs/LCD CPU                                                                                      Serial I/O Hub Audio Cache                      PCI/PCIe Slots                                                           USB BIOS Power                   Graphics                                                 PCI/PCIe Interface                 Controller                                                Slots External Power Supply KEY: BIOS – Basic Input/Output System                 PCIe – PCI express CPU – Central Processing Unit                    HDD – Hard Disk Drive SATA – Serial Advanced Technology Attachment     DVD – Digital Video Disc SCSI – Small Computer System Interface           USB – Universal Serial Bus PCI – Peripheral Component Interconnect          RAM – Random Access Memory LED – Light Emitting Diode                       LCD – Liquid Crystal Display Figure 2. GPC Block Diagram
2.2 Tested and Vendor Affirmed Module Version and

2.2.1 Tested Module Identification – Hardware

This section is only applicable for hardware modules. N/A for this module. Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 10
Package or File NameSoftware/ Firmware VersionFeaturesIntegrity Test
libcrypto.so2.0.1N/AYes
libssl.so2.0.1N/AYes
Operating SystemHardware PlatformProcessorsPAA/PAIHypervisor or Host OSVersion(s)
AlmaLinux 8Riverbed AppResponse 2180Intel Xeon Silver 4110YesN/A2.0.1
AlmaLinux 8Riverbed AppResponse 2180Intel Xeon Silver 4110NoN/A2.0.1

2.2.2 Tested Module Identification – Software, Firmware, Hybrid

(Executable Code Sets) The table below lists the executable code sets of the module. Table 2: Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets)

2.2.3 Tested Module Identification – Hybrid Disjoint Hardware

This section is only applicable to hybrid modules. N/A for this module.

2.2.4 Tested Operational Environments – Software, Firmware,

Hybrid The module was tested and found to be compliant with FIPS 140-3 requirements on the environments listed in the table below. Table 3: Tested Operational Environments - Software, Firmware, Hybrid The module is designed to utilize the AES-NI extended instruction set when available by the host platform’s CPU for processor algorithm acceleration (PAA) of its AES implementation.

2.2.5 Vendor-Affirmed Operational Environments – Software,

Firmware, Hybrid There are no vendor-affirmed operational environments claimed. N/A for this module.

2.3 Excluded Components

The module does not exclude any components from the requirements. Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 11
Mode NameDescriptionTypeStatus Indicator
ApprovedThe module switches between the Approved mode and Non-Approved mode depending on the service executed. The module is in this mode once all pre- operational self-tests have completed successfully, and only Approved services are invoked.ApprovedIndicator API return value = 1
Non- ApprovedThe module will switch to the non-Approved mode upon execution of a non- Approved service.Non- ApprovedIndicator API return value other than 1
AlgorithmCAVP CertPropertiesReference
AES-CBCA5835Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CCMA5835Key Length - 128, 192, 256SP 800-38C
AES-CFB1A5835Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB128A5835Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB8A5835Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CMACA5835Direction - Generation, Verification Key Length - 128, 192, 256SP 800-38B
AES-CTRA5835Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA5835Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
2.4 Modes of Operation
2.4.1 Modes List and Description

described in the table below. Table 4: Modes List and Description Section 4.3 of this Security Policy lists the services that constitute the Approved mode of operation. Section 4.4 below lists the services that constitute the non-Approved mode. When following the guidance in section 11.3 of this Security Policy, CSPs are not shared between Approved and non-Approved services and modes of operation. The module does not support degraded operation.

2.5 Algorithms
2.5.1 Approved Algorithms

The module employs cryptographic algorithm implementations from the following sources:

Page 12
AlgorithmCAVP CertPropertiesReference
AES-GCMA5835Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.2 Key Length - 128, 192, 256SP 800-38D
AES-GMACA5835Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-KWA5835Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-KWPA5835Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-OFBA5835Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-XTS Testing Revision 2.0A5835Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38E
Counter DRBGA5835Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
DSA KeyGen (FIPS186-4)A5835L - 2048, 3072 N - 224, 256FIPS 186-4
DSA PQGGen (FIPS186-4)A5835L - 2048, 3072 N - 224, 256 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512FIPS 186-4
DSA PQGVer (FIPS186-4)A5835L - 1024, 2048, 3072 N - 160, 224, 256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512FIPS 186-4
DSA SigGen (FIPS186-4)A5835L - 2048, 3072 N - 224, 256 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512FIPS 186-4
DSA SigVer (FIPS186-4)A5835L - 2048, 3072 N - 224, 256 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512FIPS 186-4
ECDSA KeyGen (FIPS186-4)A5835Curve - B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571, P-224, P-256, P-384, P-521 Secret Generation Mode - Testing CandidatesFIPS 186-4
ECDSA KeyVer (FIPS186-4)A5835Curve - B-163, B-233, B-283, B-409, B-571, K-163, K-233, K-283, K-409, K-571, P-192, P-224, P-256, P-384, P-521FIPS 186-4
ECDSA SigGen (FIPS186-4)A5835Curve - B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571, P-224, P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512FIPS 186-4
ECDSA SigVer (FIPS186-4)A5835Curve - B-163, B-233, B-283, B-409, B-571, K-163, K-233, K-283, K-409, K-571, P-192, P-224, P-256, P-384, P-521 Hash Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512FIPS 186-4
HMAC-SHA-1A5835Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2-224A5835Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2-256A5835Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2-384A5835Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2-512A5835Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA3-224A5835Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA3-256A5835Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA3-384A5835Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA3-512A5835Key Length - Key Length: 8-524288 Increment 8FIPS 198-1

Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 13
AlgorithmCAVP CertPropertiesReference
KAS-ECC-SSC Sp800- 56Ar3A5835Domain Parameter Generation Methods - B-233, B-283, B-409, B-571, K-233, K-283, K-409, K-571, P-224, P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KAS-FFC-SSC Sp800- 56Ar3A5835Domain Parameter Generation Methods - FB, FC Scheme - dhEphem - KAS Role - initiator, responderSP 800-56A Rev. 3
PBKDFA5835Iteration Count - Iteration Count: 10-10000 Increment 1 Password Length - Password Length: 8-128 Increment 1SP 800-132
RSA KeyGen (FIPS186-4)A5835Key Generation Mode - B.3.3 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Private Key Format - StandardFIPS 186-4
RSA SigGen (FIPS186-4)A5835Signature Type - ANSI X9.31, PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186-4)A5835Signature Type - ANSI X9.31, PKCS 1.5, PKCSPSS Modulo - 1024, 2048, 3072, 4096FIPS 186-4
SHA-1A5835Message Length - Message Length: 0-65528 Increment 8FIPS 180-4
SHA2-224A5835Message Length - Message Length: 0-65528 Increment 8FIPS 180-4
SHA2-256A5835Message Length - Message Length: 0-65528 Increment 8FIPS 180-4
SHA2-384A5835Message Length - Message Length: 0-65528 Increment 8FIPS 180-4
SHA2-512A5835Message Length - Message Length: 0-65528 Increment 8FIPS 180-4
SHA3-224A5835Message Length - Message Length: 0-65528 Increment 8FIPS 202
SHA3-256A5835Message Length - Message Length: 0-65528 Increment 8FIPS 202
SHA3-384A5835Message Length - Message Length: 0-65528 Increment 8FIPS 202
SHA3-512A5835Message Length - Message Length: 0-65528 Increment 8FIPS 202
SHAKE-128A5835Output Length - Output Length: 16-1024 Increment 8FIPS 202
SHAKE-256A5835Output Length - Output Length: 16-1024 Increment 8FIPS 202
TDES-CBCA5835Direction - DecryptSP 800-67 Rev. 2
TDES-CFB1A5835Direction - DecryptSP 800-67 Rev. 2
TDES-CFB64A5835Direction - DecryptSP 800-67 Rev. 2
TDES-CFB8A5835Direction - DecryptSP 800-67 Rev. 2
TDES-CMACA5835Direction - VerificationSP 800-67 Rev. 2
TDES-ECBA5835Direction - DecryptSP 800-67 Rev. 2
TDES-OFBA5835Direction - DecryptSP 800-67 Rev. 2
TLS v1.2 KDF RFC7627 (CVL)A5835Hash Algorithm - SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
TLS v1.3 KDF (CVL)A5836HMAC Algorithm - SHA2-256, SHA2-384 KDF Running Modes - DHE, PSK, PSK-DHESP 800-135 Rev. 1
2.5.2 Vendor-Affirmed Algorithms

The vendor affirms the following cryptographic security methods: Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 14
NamePropertiesImplementationReference
CKG1Key Type:AsymmetricRiverbed Cryptographic Module (libcrypto)SP 800-133 Rev. 2 Section 4.
NamePropertiesImplementationReference
AES-CBCKey unwrapping:128, 192, 256Riverbed Cryptographic Module (libcrypto)FIPS 197, SP 800-38A, FIPS 140-3 IG D.G
AES-CFB1Key unwrapping:128, 192, 256Riverbed Cryptographic Module (libcrypto)FIPS 197, SP 800-38A, FIPS 140-3 IG D.G
AES-CFB128Key unwrapping:128, 192, 256Riverbed Cryptographic Module (libcrypto)FIPS 197, SP 800-38A, FIPS 140-3 IG D.G
AES-CFB8Key unwrapping:128, 192, 256Riverbed Cryptographic Module (libcrypto)FIPS 197, SP 800-38A, FIPS 140-3 IG D.G
AES-CTRKey unwrapping:128, 192, 256Riverbed Cryptographic Module (libcrypto)FIPS 197, SP 800-38A, FIPS 140-3 IG D.G
AES-ECBKey unwrapping:128, 192, 256Riverbed Cryptographic Module (libcrypto)FIPS 197, SP 800-38A, FIPS 140-3 IG D.G
AES-OFBKey unwrapping:128, 192, 256Riverbed Cryptographic Module (libcrypto)FIPS 197, SP 800-38A, FIPS 140-3 IG D.G
TDES-CBC (2-key or 3- key)Key unwrapping:Riverbed Cryptographic Module (libcrypto)SP 800-67 Rev. 2, SP 800-38A, FIPS 140-3 IG D.G
TDES-CFB1 (2-key or 3- key)Key unwrapping:Riverbed Cryptographic Module (libcrypto)SP 800-67 Rev. 2, SP 800-38A, FIPS 140-3 IG D.G
TDES-CFB64 (2-key or 3-key)Key unwrapping:Riverbed Cryptographic Module (libcrypto)SP 800-67 Rev. 2, SP 800-38A, FIPS 140-3 IG D.G
TDES-CFB8 (2-key or 3- key)Key unwrapping:Riverbed Cryptographic Module (libcrypto)SP 800-67 Rev. 2, SP 800-38A, FIPS 140-3 IG D.G
TDES-ECB (2-key or 3- key)Key unwrapping:Riverbed Cryptographic Module (libcrypto)SP 800-67 Rev. 2, SP 800-38A, FIPS 140-3 IG D.G
TDES-OFB (2-key or 3- key)Key unwrapping:Riverbed Cryptographic Module (libcrypto)SP 800-67 Rev. 2, SP 800-38A, FIPS 140-3 IG D.G
2.5.3 Non-Approved, Allowed Algorithms

The table below lists the non-Approved algorithms implemented by the module that are allowed for use in the Approved mode of operation. Table 7: Non-Approved, Allowed Algorithms

2.5.4 Non-Approved, Allowed Algorithms with No Security Claimed

The module does not implement any non-Approved algorithms allowed in the Approved mode of operation for which no security is claimed. N/A for this module. ©2025 Riverbed Technology, LLC

Page 15
NameUse and Function
AES-GCM (non-compliant)Authenticated encryption/decryption using external IV
AES-OCBAuthenticated encryption/decryption
ANSI X9.31 RNG (non- compliant)Random number generation using with 128-bit AES core
ARIAEncryption/decryption
Blake2Encryption/decryption
BlowfishEncryption/decryption
CamelliaEncryption/decryption
CAST, CAST5Encryption/decryption
ChaCha20Encryption/decryption
DESEncryption/decryption
DH (non-compliant)Key agreement (non-compliant with key sizes below 2048)
DRBG (non-compliant)Random bit generation (non-compliant when using Hash_DRBG and HMAC_DRBG)
DSA (non-compliant)Key pair generation; digital signature generation; digital signature verification (non-compliant with key sizes below the minimums for Approved mode)
DSA, ECDSA, and RSA (non- compliant)Digital signature generation (non-compliant when used with SHA-1 outside the TLS protocol)
ECDH (non-compliant)Key agreement (non-compliant with curves P-192, K-163, B-163, and non-NIST curves)
ECDSA (non-compliant)Key pair generation; digital signature generation; digital signature verification (non-compliant with curves P-192, K-163, B-163, and non-NIST curves)
EdDSAKey pair generation; digital signature generation; digital signature verification
HKDFHMAC-based key derivation
IDEAEncryption/decryption
MD2, MD4, MD5Message digest
Poly1305Message authentication code
RC2, RC4, RC5Encryption/decryption
RIPEMDMessage digest
RMD160Message digest
RSA (non-compliant)Key pair generation; digital signature generation; signature verification; key transport (non-compliant with non-approved/untested key sizes, and functions)
SEEDEncryption/decryption
SHA-1 (non-compliant)Signature generation in TLS 1.0/1.1
SM2, SM3Message digest
SM4Encryption/decryption
TLS 1.2 KDF (non- compliant)Key derivation function per (RFC 5246)
Triple-DES (non-compliant)Encryption; MAC generation; key wrapping
WhirlpoolMessage digest
2.5.5 Non-Approved, Not Allowed Algorithms

The table below lists the non-Approved algorithms that are not allowed for use in the Approved mode of operation. Table 8: Non-Approved, Not Allowed Algorithms

2.6 Security Function Implementations

The table below lists the security function implementations for this module. Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 16
NameTypeDescriptionPropertiesAlgorithms
AES for Symmetric Encryption/DecryptionBC-UnAuthAES for the AES key, which is used for symmetric encryption and decryption.Publication:SP 800-38AAES-CBC AES-CFB1 AES-CFB8 AES-CFB128 AES-CTR AES-ECB AES-OFB
AES-CMAC for MAC Generation/VerificationMACAES-CMAC for the AES CMAC key, which is used for MAC generation and verification.Publication:SP 800-38BAES-CMAC
AES-GMAC for MAC Generation/VerificationMACAES for the AES GMAC key, which is used for MAC generation and verification.Publication:SP 800-38DAES-GMAC AES-CTR
AES-CCM for Authenticated Symmetric Encryption/DecryptionBC-AuthAES-CCM for the AES CCM key, which is used for authenticated symmetric encryption and decryption.Publication:SP 800-38CAES-CCM AES-CBC
AES-GCM for Authenticated Symmetric Encryption/DecryptionBC-AuthAES-GCM for the AES GCM key, which is used for authenticated symmetric encryption and decryption.Publication:SP 800-38DAES-GCM AES-CTR Counter DRBG
AES-XTS for Symmetric Encryption/DecryptionBC-UnAuthAES-XTS for the AES XTS key, which is used for symmetric encryption and decryption.Publication:SP 800-38EAES-XTS Testing Revision 2.0 AES-ECB Counter DRBG
KTS-AES+MACKTS-WrapAES-CMAC for the AES CMAC key, which is used for key transport.Publication:Publication: Per FIPS 140-3 Implementation Guidance D.G, any Approved mode of AES with CMAC is an Approved key transport technique. Key Strength:Key establishment methodology provides between 128 and 256 bits of encryption strength.AES-CMAC AES-GMAC HMAC-SHA-1 HMAC-SHA2-224 HMAC-SHA2-256 HMAC-SHA2-384 HMAC-SHA2-512 HMAC-SHA3-224 HMAC-SHA3-256 HMAC-SHA3-384 HMAC-SHA3-512 AES-CBC AES-CFB1 AES-CFB8 AES-CFB128 AES-CTR AES-ECB AES-OFB

Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 17
NameTypeDescriptionPropertiesAlgorithms
KTS-AES-CCMKTS-WrapAES-CCM for the AES CCM key, which is used for key transport.Publication:Per FIPS 140-3 Implementation Guidance D.G, AES-CCM is an Approved key transport technique. Key Strength:Key establishment methodology provides between 128 and 256 bits of encryption strength.AES-CCM AES-CTR
KTS-AES-GCMKTS-WrapAES-GCM for the AES GCM key, which is used for key transport.Publication:Per FIPS 140-3 Implementation Guidance D.G, AES-GCM is an Approved key transport technique. Key Strength:Key establishment methodology provides between 128 and 256 bits of encryption strength.AES-GCM AES-CTR
KTS-AES-KWKTS-WrapAES-KW and AES-KWP for the AES key, which is used for key transport.Publication:SP 800-38F Key Strength:Key establishment methodology provides between 128 and 256 bits of encryption strength.AES-KW AES-KWP
DRBGDRBGDeterministic random bit generatorPublication:SP 800-90ACounter DRBG
DSA KeyGen for DHAsymKeyPair-KeyGenKey generation of the DSA private component and the DSA public component.Publication:FIPS 186-4DSA KeyGen (FIPS186-4) Counter DRBG CKG1
DSA for Digital Signature Verification (legacy)DigSig-SigVerDSA digital signature verification for the DSA public key.Publication:FIPS 186-4 Publication:FIPS 140-3 IG C.MDSA SigVer (FIPS186-4) SHA-1 SHA2-224 SHA2-256 SHA2-384 SHA2-512
ECDSA for Key GenerationAsymKeyPair-KeyGenKey generation of the ECDSA private key and ECDSA public key.Publication:FIPS 186-4ECDSA KeyGen (FIPS186-4) Counter DRBG CKG1
ECDSA KeyGen for ECDHAsymKeyPair-KeyGenKey generation of the ECDH private component and the ECDSA public component.Publication:FIPS 186-4ECDSA KeyGen (FIPS186-4) Counter DRBG CKG1
ECDSA for Key VerificationAsymKeyPair-KeyVerPublic key validationPublication:FIPS 186-4ECDSA KeyVer (FIPS186- 4)

Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 18
NameTypeDescriptionPropertiesAlgorithms
ECDSA for Digital Signature GenerationDigSig-SigGenECDSA digital signature generation for the ECDSA private key.Publication:FIPS 186-4ECDSA SigGen (FIPS186- 4) Counter DRBG SHA2-224 SHA2-256 SHA2-384 SHA2-512
ECDSA for Digital Signature VerificationDigSig-SigVerECDSA digital signature verification for the ECDSA public key.Publication:FIPS 186-4ECDSA SigVer (FIPS186- 4) SHA2-224 SHA2-256 SHA2-384 SHA2-512
HMAC for Message AuthenticationMACMessage AuthenticationPublication:FIPS 198-1HMAC-SHA-1 HMAC-SHA2-224 HMAC-SHA2-256 HMAC-SHA2-384 HMAC-SHA2-512 HMAC-SHA3-224 HMAC-SHA3-384 HMAC-SHA3-512 SHA-1 SHA2-224 SHA2-256 SHA2-384 SHA2-512 SHA3-224 SHA3-256 SHA3-384 SHA3-512
ECDH Shared Secret ComputationKAS-SSCShared secret computation for ECDH.Publication:SP 800-56A Rev. 3 Publication:SP 800-90A Rev. 1 Publication:SP 800-133 Rev. 2 Publication:FIPS 140-3 IG D.F Scenario 2(1)KAS-ECC-SSC Sp800- 56Ar3 ECDSA KeyGen (FIPS186-4) ECDSA KeyVer (FIPS186- 4) SHA2-224 SHA2-256 SHA2-384 SHA2-512 Counter DRBG HMAC-SHA2-224 HMAC-SHA2-256 HMAC-SHA2-384 HMAC-SHA2-512

Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 19
NameTypeDescriptionPropertiesAlgorithms
DH Shared Secret ComputationKAS-SSCShared secret computation for DH.Publication:SP800 56A Rev.3 Publication:SP 800-90A Rev. 1 Publication:SP 800-133 Rev. 2 Publication:FIPS 140-3 IG D.F Scenario 2(1)KAS-FFC-SSC Sp800- 56Ar3 DSA PQGGen (FIPS186- 4) DSA KeyGen (FIPS186-4) SHA2-224 SHA2-256 SHA2-384 SHA2-512 Counter DRBG HMAC-SHA2-224 HMAC-SHA2-256 HMAC-SHA2-384 HMAC-SHA2-512
PBKDFPBKDFPassword-based key derivationPublication: SP 800-132PBKDF SHA-1 SHA2-224 SHA2-256 SHA2-384 SHA2-512 SHA3-224 SHA3-256 SHA3-384 SHA3-512
RSA for Key GenerationAsymKeyPair-KeyGenRSA digital signature generation for the RSA private key.Publication:FIPS 186-4RSA KeyGen (FIPS186-4) Counter DRBG CKG1
RSA for Signature GenerationDigSig-SigGenRSA digital signature generation for the RSA private key.Publication:FIPS 186-4RSA SigGen (FIPS186-4) SHA2-224 SHA2-256 SHA2-384 SHA2-512 Counter DRBG
RSA for Signature VerificationDigSig-SigVerRSA signature verification for the RSA public key.Publication:FIPS 186-4RSA SigVer (FIPS186-4) SHA2-224 SHA2-256 SHA2-384 SHA2-512
SHA/SHAKE for Message DigestSHA XOFMessage DigestPublication:FIPS 180-4SHA-1 SHA2-224 SHA2-256 SHA2-384 SHA2-512 SHA3-224 SHA3-256 SHA3-384 SHA3-512 SHAKE-128 SHAKE-256
TDES for Symmetric Decryption (legacy)BC-UnAuthTDES for the TDES key, which is used for symmetric decryption.Publication:SP 800-67 Rev. 2TDES-CBC TDES-CFB1 TDES-CFB64 TDES-CFB8 TDES-ECB TDES-OFB

Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 20
NameTypeDescriptionPropertiesAlgorithms
TDES for MAC Verification (legacy)MACTDES-CMAC for the TDES CMAC key, which is used for MAC verification.Publication:SP 800-67 Rev. 2TDES-CMAC
TLS1.2-KDF (CVL)KAS-135KDFTLS 1.2 key derivation, used to derive the TLS Session Key (AES key or AES-GCM key) and TLS Authentication Key (HMAC key).Publication :SP 800-135 Rev. 1 Caveat:No part of the TLS v1.2 protocol, other than the KDF, has been tested by the CAVP and CMVP.TLS v1.2 KDF RFC7627 SHA2-256 SHA2-384 SHA2-512
TLS1.3-KDF (CVL)KAS-135KDFTLS 1.3 key derivation, used to derive the TLS Session Key (AES key or AES-GCM key) and TLS Authentication Key (HMAC key).Publication:SP 800-135 Rev. 1 Caveat:No part of the TLS v1.3 protocol, other than the KDF, has been tested by the CAVP and CMVP.TLS v1.3 KDF HMAC-SHA2-256 HMAC-SHA2-384 SHA2-256 SHA2-384
DSA for Domain Parameter GenerationAsymKeyPair-DomParDSA domain parameter generationPublication:Publication: FIPS 186-4DSA PQGVer (FIPS186-4)
DSA for Key GenerationAsymKeyPair-KeyGenDSA key generationPublication:FIPS 186-4DSA KeyGen (FIPS186-4) Counter DRBG CKG1 Key Type: Asymmetric
DSA for Digital Signature GenerationDigSig-SigGenDSA digital signature generation Publication: FIPS 186-4.Publication:FIPS 186-4DSA SigGen (FIPS186-4)
DSA for Domain Parameter Verification (legacy)AsymKeyPair-DomParDSA domain parameter verificationPublication:FIPS 186-4 Publication:FIPS 140-3 IG C.MDSA PQGVer (FIPS186-4)
AES for Unauthenticated Key Unwrap (allowed) (legacy)KTS-WrapAES key unwrap using the AES key (with any Approved unauthenticated mode)Publication:FIPS PUB 197 Publication:SP 800-38C Publication:FIPS 140-3 IG C.M Publication:FIPS 140-3 IG D.G Key Strength: Key establishment methodology provides between 128 and 256 bits of encryption strength.AES-CBC AES-CFB1 AES-CFB8 AES-CFB128 AES-CTR AES-ECB AES-OFB

Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 21
NameTypeDescriptionPropertiesAlgorithms
TDES+MAC for Key Unwrap (legacy)KTS-WrapTDES-CMAC key unwrap using the TDES-CMAC key TDES+HMAC key unwrap using the TDES key and HMAC keyPublication :SP 800-67 Rev. 2 Publication:SP 800-38A Publication:SP 800-38B Publication:FIPS PUB 198-1 Publication:FIPS 140-3 IG C.M Publication:FIPS 140-3 IG D.G Key Strength:Key establishment methodology provides 112 or 168 bits of encryption strength.TDES-CBC TDES-CFB1 TDES-CFB8 TDES-CMAC TDES-ECB TDES-CFB64 TDES-OFB HMAC-SHA-1 HMAC-SHA2-224 HMAC-SHA2-256 HMAC-SHA2-384 HMAC-SHA2-512 HMAC-SHA3-224 HMAC-SHA3-256 HMAC-SHA3-384 HMAC-SHA3-512
TDES for Unauthenticated Key Unwrap (allowed) (legacy)KTS-WrapTDES key unwrap using the TDES key (with any Approved unauthenticated mode)Publication:SP 800-67 Rev. 2 Publication:SP 800-38A Publication:FIPS 140-3 IG C.M Publication:FIPS 140-3 IG D.G Key Strength:Key establishment methodology provides 112 or 168 bits of encryption strength.TDES-CBC TDES-CFB1 TDES-CFB64 TDES-CFB8 TDES-ECB TDES-OFB
AES+MAC for Key Wrap/UnwrapKTS-WrapAES-CMAC key wrap and unwrap using the AES-CMAC key AES- GMAC key wrap and unwrap using the AES- GMAC key AES+HMAC key wrap and unwrap using the AES key and HMAC keyPublication:FIPS PUB 197 Publication:SP 800-38A Publication:SP 800-38B Publication:SP 800-38D Publication:FIPS PUB 198-1 Publication:FIPS PUB 180-4 Publication:FIPS PUB 202 Publication:FIPS 140-3 IG D.G Key Strength:Key establishment methodology provides between 128 and 256 bits of encryption strength.AES-CBC AES-CFB1 AES-CFB128 AES-CFB8 AES-CMAC AES-CTR AES-ECB AES-GMAC AES-OFB HMAC-SHA-1 HMAC-SHA2-224 HMAC-SHA2-256 HMAC-SHA2-384 HMAC-SHA2-512 HMAC-SHA2-512 HMAC-SHA3-224 HMAC-SHA3-256 HMAC-SHA3-384 HMAC-SHA3-512
ECDSA for Key Verification (legacy)AsymKeyPair-KeyVerECDSA key verification using the ECDSA public key (with curves B-163, K-163, and P-192)Publication:FIPS 186-4 Publication:FIPS 140-3 IG C.MECDSA KeyVer (FIPS186- 4)
ECDSA for Digital Signature Verification (legacy)DigSig-SigVerECDSA digital signature verification using the ECDSA public key (with curves B-163, K-163, and P-192)Publication:FIPS 186-4 Publication:FIPS 180-4 Publication:FIPS 140-3 IG C.MECDSA SigVer (FIPS186- 4) SHA2-224 SHA2-256 SHA2-384 SHA2-512

Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 22
NameTypeDescriptionPropertiesAlgorithms
RSA for Signature Verification (legacy)DigSig-SigVerRSA signature verification using the RSA public key (with SHA-1 and/or a 1024-bit modulo)Publication:FIPS 186-4 Publication:FIPS 180-4 Publication:FIPS 140-3 IG C.MRSA SigVer (FIPS186-4) SHA-1 SHA2-224 SHA2-256 SHA2-384 SHA2-512

Table 9: Security Function Implementations

2.7 Algorithm Specific Information
2.7.1 AES-GCM

The module supports internal IV generation using its Approved DRBG. The IV is at least 96 bits in length per section

8.2.2 of NIST SP 800‐38D, and the Approved DRBG generates outputs such that the (key, IV) pair collision

probability is less than 2‐32 per section 8 of NIST SP 800‐38D. The module also supports AES GCM encryption used in the context of the TLS protocol versions 1.2 and 1.3. To meet the AES GCM (key/IV) pair uniqueness requirements from NIST SP 800-38D, the module complies with FIPS 140-3 IG C.H as follows:

1.3 protocol.

The mechanism for IV generation falls into scenario 5 in FIPS 140-3 IG C.H and is compliant with RFC 8446. Each session employs a “per-record nonce”, a 64-bit sequence number (or IV) maintained separately for reading and writing records. Each sequence number is set to 0 at the beginning of a connection and whenever the key is changed (the first record transmitted under a particular traffic key uses sequence number 0), and the appropriate sequence number is incremented by one after reading or writing each record. Because the size of sequence numbers is 64 bits, they should not wrap. If a sequence number needs to wrap, it is the responsibility of the module operator to either re-key with a new key for AES-GCM or terminate the connection. In case the module’s power is lost and then restored, the calling application is responsible for ensuring that a new key for use with the AES-GCM encryption/decryption shall be established. This condition is not enforced by the Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 23

module but is met implicitly. The module does not retain any state across resets or power‐cycles, and AES‐GCM key/IVs are not stored in non‐volatile persistent memory (i.e., disk). Hence, no reconnection can occur without a fresh key establishment operation and the associated SSPs. When a GCM IV is used for decryption, the responsibility for the IV generation lies with the party that performs the AES GCM encryption.

2.7.2 AES-XTS

The length of a single data unit encrypted or decrypted with the AES-XTS shall not exceed 2²⁰ AES blocks; that is,

16 MB of data per AES-XTS instance. An XTS instance is defined in section 4 of NIST SP 800-38E.

In compliance with FIPS 140-3 IG C.I, the module implements a check to ensure that the two AES keys used in the XTS-AES algorithm are not identical. As specified in NIST SP 800-132, AES-XTS mode shall only be used for the cryptographic protection of data on storage devices. The AES-XTS shall not be used for other purposes, such as the encryption of data in transit.

2.7.3 PBKDF2

The module uses PBKDF2 option 1a from section 5.4 of NIST SP 800-132. The iteration count shall be selected as large as possible, as long as the time required to generate the resultant key is acceptable for module operators. The minimum iteration count shall be 1000. The length of the password/passphrase used in the PBKDF shall be of at least 20 characters, and shall consist of lower-case, upper-case, and numeric characters. The upper bound for the probability of guessing the value is estimated to be 1/6220 = 10-36, which is less than 2-112. As specified in NIST SP 800-132, keys derived from passwords/passphrases may only be used in storage applications.

2.8 RNG and Entropy

The cryptographic module invokes a GET command to obtain entropy for random number generation (the module requests 256 bits of entropy from the calling application per request), and then passively receives entropy from the calling application while having no knowledge of the entropy source and exercising no control over the amount or the quality of the obtained entropy. The calling application and its entropy sources are located within the operational environment inside the module’s physical perimeter but outside the cryptographic boundary. Thus, there is no assurance of the minimum strength of the generated keys.

2.9 Key Generation

The cryptographic module uses its counter-based DRBG to generate seeds used for asymmetric key generation. The generated seed is an unmodified output from the DRBG. Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 24
2.10 Key Establishment

The cryptographic module provides the cryptographic primitives necessary to support key agreement schemes and key transport methods utilized by the calling application to establish keys.

2.10.1 Key Agreement Schemes

The module implements the following Approved key agreement schemes (as specified in FIPS 140‐3 IG D.F Scenario 2, path 1) which have been CAVP tested and validated:

2.10.2 Key Transport Methods
Table, extracted as text (did not parse into structured rows)
The module implements the following Approved/allowed key transport methods (as specified in FIPS 140‐3 IG D.G) which have been CAVP tested and validated: •    AES + MAC wrap/unwrap •    AES-CCM wrap/unwrap •    AES-GCM wrap/unwrap •    AES-KW wrap/unwrap •    AES-KWP wrap/unwrap •    AES unwrap (legacy) •    TDES unwrap (legacy) •    TDES + MAC unwrap (legacy) These methods are not used to establish keys into the module. Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC
Page 25
2.11 Industry Protocols

The module supports the following industry protocols in the Approved mode of operation:

2.12 Additional Information

Algorithms designated as “legacy” can only be used on data that was generated prior to the Legacy Date specified in FIPS 140-3 IG C.M. Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 26
Physical PortLogical Interface(s)Data That Passes
N/AData InputAPI input parameters – Includes data to be encrypted/decrypted/signed/verified/hashed, keys to be used in cryptographic services, random seed material for the module’s DRBG, and keying material to be used as input to key establishment services
N/AData OutputAPI output parameters and return values – Includes data that has been encrypted/decrypted/verified, digital signatures, hashes, random values generated by the module’s DRBG, and keys established using module’s key establishment methods
N/AControl InputAPI method calls – Includes API commands invoking cryptographic services, modes/key sizes/etc. used with cryptographic services
N/AStatus OutputAPI output parameters and return/error codes – Includes status information regarding the module and status information regarding the invoked service/operation
3.1 Ports and Interfaces

The module supports the following four logical interfaces: As a software library, the cryptographic module has no direct access to any of the host platform’s physical ports, as it communicates only to the calling application via its well-defined API. A mapping of the FIPS-defined interface to the module’s physical ports and logical interfaces can be found in the table below. Note that the module does Table 10: Ports and Interfaces Data output via the data output interface is inhibited when the module is performing pre-operational and conditional tests, zeroization, or when the module is in the error state. ©2025 Riverbed Technology, LLC

Page 27
NameTypeOperator TypeAuthentication Methods
Crypto OfficerRoleCONone
UserRoleUserNone

4. Roles, Services, and Authentication The module does not support authentication methods; operators implicitly assume an authorized role based on the service selected. N/A for this module.

4.2 Roles

The table below lists the supported roles. Table 11: Roles The module does not support multiple concurrent operators. The calling application that loaded the module is its only operator.

4.3 Approved Services

This module is a software library that provides cryptographic functionality to calling applications. As such, the security functions provided by the module are considered the module’s security services. Indicators for Approved services (in the case of this module, those security functions with algorithm validation certificates and all required self-tests) are provided via API return value. When invoking a security function, the calling application provides inputs via an internal structure, or “context”. Upon each service invocation, the module will determine if the invoked security function is an Approved service. To access the resulting value, the calling application must pass the finalized context to the indicator API associated with that security function (note the indicator check must be performed by the calling application before any context cleanup is performed). The indicator API will return “1” to indicate the usage of an Approved service. Indicators for services providing non-Approved security functions (as well as for services not requiring an indicator) will have a value other than “1”, ensuring that the indicators for Approved services are unambiguous. Additional details on the APIs used for the Approved service indicators are provided in Appendix B below. The keys and Sensitive Security Parameters (SSPs) listed in the table indicate the type of access required using the following notation:

Page 28
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
Show StatusReturn FIPS mode statusAPI call parametersCurrent operational statusN/ANoneCrypto Officer
Perform self- tests on- demandPerform pre- operational self- testsIndicator API return value = 1Indicator API return value = 1StatusNoneCrypto Officer

• Z = Zeroize: The module zeroizes the SSP. Descriptions of the services available are provided in the table below. Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 29

Zeroize

Zeroize and de- allocate memory containing sensitive data

N/A

Restart calling application; reboot or power-cycle host platform

None

None

Crypto Officer - AES key: Z - AES CCM key : Z - AES GCM key : Z - AES XTS key : Z - AES CMAC key : Z - AES GMAC key : Z - Triple-DES key : Z - Triple-DES CMAC key : Z - HMAC key : Z - DSA public key : Z - ECDSA private key : Z - ECDSA public key : Z - RSA private key : Z - RSA public key : Z - DH private component : Z - DH public component : Z - ECDH private component : Z - ECDH public component : Z - Passphrase: Z - AES GCM IV: Z - TLS pre- master secret: Z - TLS master secret: Z - DRBG entropy input: Z

Z Z Z Z Z Z Z Z Z Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 30
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
- DRBG seed: Z - DRBG ‘Key’ value: Z - DSA private key : Z
Perform symmetric encryptionEncrypt plaintext dataIndicator API return value = 1API call parameters, key, plaintextStatus, ciphertextAES for Symmetric Encryption/Decryption AES-XTS for Symmetric Encryption/DecryptionUser - AES key: W,E - AES XTS key : W,E
Perform symmetric decryptionDecrypt ciphertext dataIndicator API return value = 1API call parameters, key, ciphertextStatus, plaintextAES for Symmetric Encryption/Decryption AES-XTS for Symmetric Encryption/Decryption TDES for Symmetric Decryption (legacy)User - AES key: W,E - AES XTS key : W,E - Triple-DES key : W,E
Generate symmetric digestGenerate symmetric digestIndicator API return value = 1API call parameters, key, plaintextStatus, digestAES-CMAC for MAC Generation/Verification TDES for MAC Verification (legacy)User - AES CMAC key : W,E - AES GMAC key : W,E
Verify symmetric digestVerify symmetric digestIndicator API return value = 1API call parameters, digestAPI call parameters, digestAES-CMAC for MAC Generation/Verification AES-GMAC for MAC Generation/VerificationUser - AES GCM key : W,E - AES GCM IV: W,E - Triple-DES CMAC key : W,E
Perform authenticated encryptionEncrypt plaintext using supplied AES GCM key and IVEncrypt plaintext using supplied AES GCM key and IVAPI call parameters, key, plaintextStatus, ciphertext, tabAES-CCM for Authenticated Symmetric Encryption/Decryption AES-GCM for Authenticated Symmetric Encryption/DecryptionUser - AES GCM key : W,E - AES GCM IV: W,E - AES CCM key : W,E
Perform authenticated decryptionDecrypt ciphertext using supplied AES GCM key and IVIndicator API return value = 1Indicator API return value = 1Status, plaintextAES-CCM for Authenticated Symmetric Encryption/Decryption AES-GCM for Authenticated Symmetric Encryption/DecryptionUser - AES CCM key : W,E - AES GCM key : W,E - AES GCM IV: W,E
Generate random numberReturn random bits to the calling applicationIndicator API return value = 1API call parameters, entropy DRBG state valuesStatus, random numberDRBGUser - DRBG entropy input: G,E - DRBG seed: G,E - DRBG ‘V’ value: G,E - DRBG ‘Key’ value: G,E

Z Z W,E G,E Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 31
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
Perform keyed hash operationsCompute a message authentication codeIndicator API return value = 1API call parameters, key, messageStatus, MACHMAC for Message AuthenticationUser - HMAC key : W,E
Generate message digestGenerate a message digestIndicator API return value = 1Indicator API return value = 1Status, digestSHA/SHAKE for Message DigestUser
Generate asymmetric key pairGenerate a public/private key pairIndicator API return value = 1Indicator API return value = 1Status, key pairECDSA for Key Generation RSA for Key Generation DSA for Domain Parameter Generation DSA for Key GenerationUser - ECDSA private key : G - ECDSA public key : G - RSA private key : G - RSA public key : G
Verify ECDSA public keyVerify an ECDSA public keyIndicator API return value = 1API call parameters, keyStatusECDSA for Key Verification ECDSA for Key Verification (legacy)User - ECDSA public key : W
Generate digital signatureGenerate a digital signatureIndicator API return value = 1API call parameters, key, messageStatus, signatureECDSA for Digital Signature Generation RSA for Signature Generation DSA for Digital Signature GenerationUser - ECDSA private key : W,E - RSA private key : W,E
Verify digital signatureVerify a digital signatureIndicator API return value = 1API call parameters, key, signature, messageStatusDSA for Digital Signature Verification (legacy) ECDSA for Digital Signature Verification RSA for Signature Verification ECDSA for Digital Signature Verification (legacy) RSA for Signature Verification (legacy)User - DSA public key : W,E - ECDSA public key : W,E - RSA public key : W,E
Perform key wrapPerform key wrapIndicator API return value = 1API call parameters, encryption key, keyStatus, encrypted keyKTS-AES+MAC KTS-AES-CCM KTS-AES-GCM KTS-AES-KW AES+MAC for Key Wrap/UnwrapUser - AES key: W,E - AES CCM key : W,E - AES CMAC key : W,E - AES GMAC key : W,E - AES GCM key : W,E - AES GCM IV: W,E - HMAC key : W,E

G W,E Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 32
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
Perform key unwrapPerform key unwrapIndicator API return value = 1API call parameters, decryption key, keyStatus, decrypted keyKTS-AES+MAC KTS-AES-CCM KTS-AES-GCM KTS-AES-KW AES for Unauthenticated Key Unwrap (allowed) (legacy) TDES+MAC for Key Unwrap (legacy) TDES for Unauthenticated Key Unwrap (allowed) (legacy) AES+MAC for Key Wrap/UnwrapUser - AES key: W,E - AES CCM key : W,E - AES CMAC key : W,E - AES GMAC key : W,E - AES GCM key : W,E - AES GCM IV: W,E - HMAC key : W,E - Triple-DES key : W,E
Compute shared secretPerform key unwrap Compute DH/ECDH shared secret suitable for use as input to a TLS KDFPerform key unwrap Compute DH/ECDH shared secret suitable for use as input to a TLS KDFAPI call parametersAPI call parametersDSA KeyGen for DH ECDSA KeyGen for ECDH ECDH Shared Secret Computation DH Shared Secret ComputationUser - DH public component : W,E - DH private component : W,E - ECDH private component : W,E - ECDH public component : W,E - TLS pre- master secret: G,E
Derive TLS keysDerive TLS session and integrity keysIndicator API return value = 1API call parameters, TLS pre- master secretStatus, TLS keysTLS1.2-KDF (CVL) TLS1.3-KDF (CVL)User - AES key: G,R - AES GCM key : G,R - AES GCM IV: G,R - HMAC key : G,R - TLS pre- master secret: W,E - TLS master secret: G,E
Derive key via PBKDF2Derive key via PBKDF2Indicator API return value = 1API call parameters, passwordStatus, keyPBKDFUser - Passphrase: W,E - AES key: G,R - Triple-DES key : G,R

W,E W,E G,R W,E G,R Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 33
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
Show versioning informationReturn module versioning informationN/AAPI call parametersModule name, versionNoneCrypto Officer
Generate DSA domain parametersGenerate DSA domain parametersIndicator API return value = 1API call parametersStatus, domain parametersDSA for Domain Parameter GenerationUser
Verify DSA domain parametersVerify DSA domain parametersIndicator API return value = 1API call parametersStatusDSA for Domain Parameter Verification (legacy)User
NameDescriptionAlgorithmsRole
Perform data encryption (non-compliant)Perform symmetric data encryptionARIA Blake2 Blowfish Camellia CAST, CAST5 ChaCha20 DES IDEA RC2, RC4, RC5 SEED SM4 Triple-DES (non-compliant)User
Perform data decryption (non-compliant)Perform symmetric data decryptionARIA Blake2 Blowfish Camellia CAST, CAST5 ChaCha20 DES IDEA RC2, RC4, RC5 SEED SM4User
Perform MAC operations (non-compliant)Perform message authentication operationsPoly1305 Triple-DES (non-compliant)User
Perform hash operation (non-compliant)Perform hash operationMD2, MD4, MD5 RIPEMD RMD160 SHA-1 (non-compliant) SM2, SM3 WhirlpoolUser
Perform digital signature functions (non- compliant)Perform digital signature functionsDSA (non-compliant) ECDSA (non-compliant) EdDSA RSA (non-compliant)User
Perform key agreement functions (non- compliant)Perform key agreement functionsDH (non-compliant) ECDH (non-compliant)User
Perform key wrap (non-compliant)Perform key wrap functionsTriple-DES (non-compliant)User
4.4 Non-Approved Services

The table below lists the non-Approved services available to module operators. Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 34
NameDescriptionAlgorithmsRole
Perform key encapsulation function (non- compliant)Perform key encapsulation functionRSA (non-compliant)User
Perform key un-encapsulation function (non- compliant)Perform key un-encapsulation functionRSA (non-compliant)User
Perform key derivation functions (non- compliant)Perform key derivation functionsHKDF TLS 1.2 KDF (non-compliant)User
Perform authenticated encryption/decryptionPerform authenticated encryption/decryptionAES-GCM (non-compliant) AES-OCBUser
Perform random number generationPerform random number generationANSI X9.31 RNG (non- compliant) DRBG (non-compliant)User
Perform key pair generationPerform key pair generationDSA (non-compliant) DSA, ECDSA, and RSA (non- compliant) ECDSA (non-compliant) EdDSA RSA (non-compliant)User

Table 13: Non-Approved Services

4.5 External Software/Firmware Loaded

The module does not provide the capability to load software from external sources. Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 35
5.1 Integrity Techniques

All software components within the cryptographic boundary are verified using an Approved integrity technique implemented within the cryptographic module itself. The module implements independent HMAC SHA2-256 digest checks to test the integrity of each library file; failure of the integrity test for either library file will cause the module to enter a critical error state. The module’s integrity check is performed automatically at module instantiation (i.e., when the module is loaded into memory for execution) without action from the module operator.

5.2 Initiate on Demand

The CO can initiate the pre-operational tests on demand by re-instantiating the module or issuing the FIPS_selftest() API command. Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 36
6.1 Operational Environment Type and Requirements

The module is a software cryptographic library that executes in a Non-Modifiable operational environment. The cryptographic module has control over its own SSPs. The process and memory management functionality of the host platform’s OS prevents unauthorized access to plaintext private and secret keys, intermediate key generation values and other SSPs by external processes during module execution. The module only allows access to SSPs through its well-defined API. The operational environment provides the capability to separate individual application processes from each other by preventing uncontrolled access to CSPs and uncontrolled modifications of SSPs regardless of whether this data is in the process memory or stored on persistent storage within the operational environment. Processes that are spawned by the module are owned by the module and are not owned by external processes/operators. Please refer to section 2.1 of this document for a list/description of the applicable operational environments. Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 37

7. Physical Security This section is not applicable. Per section 7.7.1 of ISO/IEC 19790:2012, the requirements of this section are “applicable to hardware and firmware modules, and hardware and firmware components of hybrid modules”. Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 38

8. Non-Invasive Security This section is not applicable. There are currently no approved non-invasive mitigation techniques references in Annex F of ISO/IEC 19790. Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 39
Storage Area NameDescriptionPersistence Type
RAMSSPs are stored in the RAMDynamic
NameFromToFormat TypeDistribution TypeEntry TypeSFI or Algorithm
[Input] External to RAM via PlaintextExternalRAMPlaintextAutomatedElectronic
[Output] RAM to External via PlaintextRAMExternalPlaintextAutomatedElectronic
Zeroization MethodDescriptionRationaleOperator Initiation
Remove PowerUpon removing power from the host device, the SSPs in memory are zeroized.Removing power from the host device yields SSPs in memory irretrievable and unusable, effectively zeroizing them.Operator removes power from the host device.
RebootUpon rebooting the host device, the SSPs in memory are zeroized.Rebooting the host device yields SSPs in memory irretrievable and unusable, effectively zeroizing them.Operator reboots the host device

9. Sensitive Security Parameters Management

9.1 Storage Areas

There are no mechanisms within the module’s cryptographic boundary for the persistent storage of SSPs. SSPs are stored in volatile RAM during module operation. The table below lists the storage areas used by the module. Table 14: Storage Areas The module stores DRBG state values for the lifetime of the DRBG instance. The module uses SSPs passed in on the stack by the calling application and does not store these SSPs beyond the lifetime of the API call.

9.2 SSP Input-Output Methods

The table below lists input and output methods for the module’s SSPs. Section 9.4 below selects from the input and output methods listed and specifies the appropriate method(s) in the “Inputs - Outputs” column applicable to each SSP. Table 15: SSP Input-Output Methods

9.3 SSP Zeroization Methods

The table below lists SSP zeroization methods available to module operators. Section 9.4 below selects from the zeroization methods listed and specifies the appropriate method(s) in the “Zeroization” column applicable to each SSP. Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 40
Zeroization MethodDescriptionRationaleOperator Initiation
Power-cycleUpon power-cycling the host device, the SSPs in memory are zeroized.Power-cycling the host device yields SSPs in memory irretrievable and unusable, effectively zeroizing them.Operator power-cycles the host device
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
AES keySymmetric encryption, decryptionBetween 128 and 256 bits - Between 128 and 256 bitsSymmetric Key - CSPPBKDF TLS1.2-KDF (CVL) TLS1.3-KDF (CVL)AES for Symmetric Encryption/Decryption KTS-AES+MAC
AES CCM keyAuthenticated symmetric encryption, decryptionBetween 128 and 256 bits - Between 128 and 256 bitsSymmetric Key - CSPTLS1.2-KDF (CVL) TLS1.3-KDF (CVL)AES-CCM for Authenticated Symmetric Encryption/Decryption KTS-AES-CCM
AES GCM keyAuthenticated symmetric encryption, decryptionBetween 128 and 256 bits - Between 128 and 256 bitsSymmetric Key - CSPTLS1.2-KDF (CVL) TLS1.3-KDF (CVL)AES-GCM for Authenticated Symmetric Encryption/Decryption
AES XTS keySymmetric encryption, decryption128 or 256 bits - 128 or 256 bitsSymmetric Key - CSPAES-XTS for Symmetric Encryption/Decryption
AES CMAC keyMAC generation, verificationBetween 128 and 256 bits - Between 128 and 256 bitsMAC - CSPAES-CMAC for MAC Generation/Verification KTS-AES+MAC
AES GMAC keyMAC generation, verificationBetween 128 and 256 bits - Between 128 and 256 bitsMAC - CSPAES-GMAC for MAC Generation/Verification KTS-AES+MAC
Triple-DES keyTriple-DES keyN/A - N/ASymmetric Key - CSPPBKDFTDES for Symmetric Decryption (legacy)
Triple-DES CMAC keyMAC VerificationN/A - N/AMAC - CSPTDES for MAC Verification (legacy)
HMAC keyKeyed Hash112 bits (minimum) - 112 bits (minimum)MAC - CSPTLS1.2-KDF (CVL) TLS1.3-KDF (CVL)KTS-AES+MAC HMAC for Message Authentication
DSA private keyDigital signature generation2048 or 3072 bits - 112 or 128 bitsPrivate - CSPDSA for Key GenerationDSA for Digital Signature Generation

Table 16: SSP Zeroization Methods At the end of each applicable function call, temporary SSPs in memory are automatically overwritten with zeroes and the space is deallocated. Maintenance of any keys and CSPs that exist outside the module’s cryptographic boundary, including protection and zeroization, are the responsibility of the module operator. The module supports the keys and other SSPs listed in the table below. All SSP imports and exports are electronic and performed within the TOEPP. Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 41
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
DSA public keyDigital signature verificationBetween 2048 and 3072 bits - 112 or 128 bitsPublic - PSPDSA for Digital Signature Verification (legacy)
ECDSA private keyDigital signature generationBetween 224 and 521 bits - Between 112 and 256 bitsPrivate - CSPECDSA for Key GenerationECDSA for Digital Signature Generation
ECDSA public keyDigital signature verificationBetween 224 and 521 bits - Between 112 and 256 bitsPublic - PSPECDSA for Key VerificationECDSA for Digital Signature Verification
RSA private keyDigital signature generationBetween 2048 and 4096 bits - Between 112 and 150 bitsPrivate - CSPRSA for Key GenerationRSA for Signature Generation
RSA public keySignature verificationBetween 2048 and 4096 bits - Between 80 and 150 bitsPublic - PSPRSA for Signature GenerationRSA for Signature Verification RSA for Signature Verification (legacy)
DH private componentDH shared secret computation2048 bits - 112 bitsPrivate - CSPDSA KeyGen for DHKAS-FFC-SSC Sp800-56Ar3 (A5835)
DH public componentDH shared secret computation2048 bits - 112 bitsPublic - PSPDSA KeyGen for DHKAS-FFC-SSC Sp800-56Ar3 (A5835)
ECDH private componentECDH private componentBetween 224 and 521 bits - Between 112 and 256 bitsPrivate - CSPECDSA KeyGen for ECDHKAS-ECC-SSC Sp800-56Ar3 (A5835)
ECDH public componentECDH shared secret computationBetween 224 and 521 bits - Between 112 and 256 bitsPublic - PSPECDSA KeyGen for ECDHKAS-ECC-SSC Sp800-56Ar3 (A5835)
PassphraseInput to PBKDF for key derivationN/a - N/APassphrase - CSPPBKDF
AES GCM IVDerivation of the TLS master secret96 bits - N/AInitialization Vector - CSPDRBGAES-GCM for Authenticated Symmetric Encryption/Decryption
TLS pre- master secretDerivation of the TLS master secret384 bits - N/APre-master Secret - CSPTLS1.2-KDF (CVL) TLS1.3-KDF (CVL)
TLS master secretDerivation of the AES/AES-GCM key and HMAC key used for securing TLS connections384 bits - N/AMaster Secret - CSPTLS1.2-KDF (CVL) TLS1.3-KDF (CVL)
DRBG entropy inputEntropy material for DRBGBetween 128 and 512 bits - N/AEntropy input - CSPDRBG
DRBG seedSeeding material for DRBGBetween 256 and 384 bits - N/ASeed - CSPDRBGDRBG
DRBG ‘V’ valueState value for DRBG128 bits - N/AState Value - CSPDRBGDRBG
DRBG ‘Key’ valueState value for DRBGBetween 128 and 256 bits - N/AState Value - CSPDRBGDRBG

N/A N/A Table 17: SSP Table 1 Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 42
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
AES key[Input] External to RAM via PlaintextRAM:PlaintextUntil the module is unloaded or the power is removed.Remove Power Reboot Power-cycleTLS master secret:Derived From Passphrase:Derived From
AES CCM key[Input] External to RAM via PlaintextRAM:PlaintextUntil the module is unloaded or the power is removedRemove Power Reboot Power-cycleTLS master secret:Derived From
AES GCM key[Input] External to RAM via PlaintextRAM:PlaintextUntil the module is unloaded or the power is removed.Remove Power Reboot Power-cycleTLS master secret:Derived From AES GCM IV:Paired With
AES XTS key[Input] External to RAM via PlaintextRAM:PlaintextUntil the module is unloaded or the power is removed.Remove Power Reboot Power-cycle
AES CMAC key[Input] External to RAM via PlaintextRAM:PlaintextUntil the module is unloaded or the power is removed.Remove Power Reboot Power-cycle
AES GMAC key[Input] External to RAM via PlaintextRAM:PlaintextUntil the module is unloaded or the power is removed.Remove Power Reboot Power-cycle
Triple-DES keyRAM:PlaintextUntil the module is unloaded or the power is removed.Remove Power Reboot Power-cycle
Triple-DES CMAC key[Input] External to RAM via PlaintextRAM:PlaintextUntil the module is unloaded or the power is removed.Remove Power Reboot Power-cycle
HMAC key[Input] External to RAM via PlaintextRAM:PlaintextUntil the module is unloaded or the power is removed.Remove Power Reboot Power-cycleTLS master secret:Derived From
DSA private key[Output] RAM to External via PlaintextRAM:PlaintextUntil the module is unloaded or the power is removed.Remove Power Reboot Power-cycleDSA public key :Paired With
DSA public key[Output] RAM to External via PlaintextRAM:PlaintextUntil the module is unloaded or the power is removed.Remove Power Reboot Power-cycle
ECDSA private key[Output] RAM to External via PlaintextRAM:PlaintextUntil the module is unloaded or the power is removed.Remove Power Reboot Power-cycleECDSA public key :Paired With
ECDSA public key[Output] RAM to External via PlaintextRAM:PlaintextUntil the module is unloaded or the power is removed.Remove Power Reboot Power-cycleECDSA private key :Paired With
RSA private key[Output] RAM to External via PlaintextRAM:PlaintextUntil the module is unloaded or the power is removed.Remove Power Reboot Power-cycleRSA public key :Paired With

Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 43
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
RSA public key[Output] RAM to External via PlaintextRAM:PlaintextUntil the module is unloaded or the power is removed.Remove Power Reboot Power-cycleRSA private key :Paired With
DH private component[Output] RAM to External via PlaintextRAM:PlaintextUntil the module is unloaded or the power is removed.Remove Power Reboot Power-cycleDH public component :Paired With
DH public component[Output] RAM to External via PlaintextRAM:PlaintextUntil the module is unloaded or the power is removed.Remove Power Reboot Power-cycleDH private component :Paired With
ECDH private component[Output] RAM to External via PlaintextRAM:PlaintextUntil the module is unloaded or the power is removed.Remove Power Reboot Power-cycleECDH public component :Paired With
ECDH public component[Output] RAM to External via PlaintextRAM:PlaintextUntil the module is unloaded or the power is removed.Remove Power Reboot Power-cycleECDH private component :Paired With
Passphrase[Input] External to RAM via PlaintextRAM:PlaintextUntil the module is unloaded or the power is removed.Remove Power Reboot Power-cycleAES key:Derived From
AES GCM IV[Input] External to RAM via PlaintextRAM:PlaintextUntil the module is unloaded or the power is removed.Remove Power Reboot Power-cycleAES GCM key :Used With
TLS pre-master secret[Input] External to RAM via PlaintextRAM:PlaintextUntil the module is unloaded or the power is removed.Remove Power Reboot Power-cycleDH private component :Derived From DH public component :Derived From ECDH private component :Derived From ECDH public component :Derived From
TLS master secret[Input] External to RAM via PlaintextRAM:PlaintextUntil the module is unloaded or the power is removed.Remove Power Reboot Power-cycleTLS pre-master secret:Derived From
DRBG entropy input[Input] External to RAM via PlaintextRAM:PlaintextUntil the module is unloaded or the power is removed.Remove Power Reboot Power-cycleDRBG seed:Derived From DRBG ‘V’ value:Derived From DRBG ‘Key’ value:Derived From
DRBG seed[Input] External to RAM via PlaintextRAM:PlaintextUntil the module is unloaded or the power is removed.Remove Power Reboot Power-cycleDRBG entropy input:Derived From
DRBG ‘V’ value[Input] External to RAM via PlaintextRAM:PlaintextUntil the module is unloaded or the power is removed.Remove Power Reboot Power-cycleDRBG seed:Derived From DRBG ‘Key’ value:Used With
DRBG ‘Key’ value[Input] External to RAM via PlaintextRAM:PlaintextUntil the module is unloaded or the power is removed.Remove Power Reboot Power-cycleDRBG seed:Derived From DRBG ‘V’ value:Used With

Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 44

Table 18: SSP Table 2 Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 45
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
HMAC-SHA2-256 (A5835)SHA2-256Software Integrity TestSW/FW IntegrityReturned success or error codeTest for libcrypto. Performed automatically without operator action
HMAC-SHA2-256 (A5835)SHA2-256Software Integrity TestSW/FW IntegrityReturned success or error codeTest for libssl. Performed automatically without operator action
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-CBC (A5835)128 bitKATCASTreturned success or error codeencryptAfter successful software integrity test
AES-ECB (A5835)128 bitKATCASTreturned success or error codedecryptAfter successful software integrity test
AES-CCM (A5835)192 bitKATCASTreturned success or error codeencryptAfter successful software integrity test
AES-CCM (A5835)192 bitKATCASTreturned success or error codedecryptAfter successful software integrity test
AES-GCM (A5835)128 bitKATCASTreturned success or error codeencryptAfter successful software integrity test
AES-GCM (A5835)128 bitKATCASTreturned success or error codedecryptAfter successful software integrity test
AES-XTS Testing Revision 2.0 (A5835)128 bitKATCASTreturned success or error codeencryptAfter successful software integrity test
AES-XTS Testing Revision 2.0 (A5835)128 bitKATCASTreturned success or error codedecryptAfter successful software integrity test
AES-CMAC (A5835)CBC mode, 128- bit; 192-bit; 256- bitKATCASTreturned success or error codeGenerateAfter successful software integrity test
AES-CMAC (A5835)CBC mode, 128- bit; 192-bit; 256- bitKATCASTreturned success or error codeVerifyAfter successful software integrity test
10.1 Pre-Operational Self-Tests

The module performs the pre-operational self-tests listed in the following table. Table 19: Pre-Operational Self-Tests

10.2 Conditional Self-Tests

The module performs the conditional self-tests listed in the following table. Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 46
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
TDES-ECB (A5835)3KeyKATCASTreturned success or error codeEncryptAfter successful software integrity test
TDES-ECB (A5835)3KeyKATCASTreturned success or error codeDecryptAfter successful software integrity test
TDES-CMAC (A5835)CBC mode, 3KeyKATCASTreturned success or error codeGenerateAfter successful software integrity test
TDES-CMAC (A5835)CBC mode, 3KeyKATCASTreturned success or error codeVerifyAfter successful software integrity test
Counter DRBG (A5835)AES, 256-bitKATCASTreturned success or error codeGenerate/Instantiate/ReseedAfter successful software integrity test
DSA SigGen (FIPS186-4) (A5835)2048-bit; SHA2- 256KATCASTreturned success or error codeSignAfter successful software integrity test
DSA SigVer (FIPS186-4) (A5835)2048-bit; SHA2- 256KATCASTreturned success or error codeVerifyAfter successful software integrity test
ECDSA SigVer (FIPS186-4) (A5835)P-224; K-233; SHA-256KATCASTreturned success or error codeVerifyAfter successful software integrity test
RSA SigGen (FIPS186-4) (A5835)2048-bit; SHA2- 256; PKCS#1.5 schemeKATCASTreturned success or error codeSignAfter successful software integrity test
RSA SigVer (FIPS186-4) (A5835)2048-bit; SHA2- 256; PKCS#1.5 schemeKATCASTreturned success or error codeVerifyAfter successful software integrity test
HMAC-SHA-1 (A5835)SHA-1KATCASTreturned success or error codeHashed MessageAfter successful software integrity test
HMAC-SHA2- 224 (A5835)SHA2-224KATCASTreturned success or error codeHashed MessageAfter successful software integrity test
HMAC-SHA2- 256 (A5835)SHA2-256KATCASTreturned success or error codeHashed MessagePrior to the software integrity test
HMAC-SHA2- 384 (A5835)SHA2-384KATCASTreturned success or error codeHashed MessageAfter successful software integrity test
HMAC-SHA2- 512 (A5835)SHA2-512KATCASTreturned success or error codeHashed MessageAfter successful software integrity test
HMAC-SHA3- 224 (A5835)SHA3-224KATCASTreturned success or error codeHashed MessageAfter successful software integrity test
HMAC-SHA3- 256 (A5835)SHA3-256KATCASTreturned success or error codeHashed MessagePrior to the software integrity test
HMAC-SHA3- 384 (A5835)SHA3-384KATCASTreturned success or error codeHashed MessageAfter successful software integrity test

Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 47
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
HMAC-SHA3- 512 (A5835)SHA3-512KATCASTreturned success or error codeHashed MessageAfter successful software integrity test
SHA-1 (A5835)-KATCASTreturned success or error codeHashAfter successful software integrity test
SHA2-224 (A5835)-KATCASTreturned success or error codeHashAfter successful software integrity test
SHA2-256 (A5835)-KATCASTreturned success or error codeHashAfter successful software integrity test
SHA2-384 (A5835)-KATCASTreturned success or error codeHashAfter successful software integrity test
SHA2-512 (A5835)-KATCASTreturned success or error codeHashAfter successful software integrity test
SHA3-224 (A5835)-KATCASTreturned success or error codeHashAfter successful software integrity test
SHA3-256 (A5835)-KATCASTreturned success or error codeHashAfter successful software integrity test
SHA3-384 (A5835)-KATCASTreturned success or error codeHashAfter successful software integrity test
SHA3-512 (A5835)-KATCASTreturned success or error codeHashAfter successful software integrity test
KAS-FFC-SSC Sp800-56Ar3 (A5835)2048-bitKATCASTreturned success or error codeShared Secret “Z” ComputationAfter successful software integrity test
KAS-ECC-SSC Sp800-56Ar3 (A5835)P-224KATCASTreturned success or error codeShared Secret “Z” ComputationAfter successful software integrity test
PBKDF (A5835)SHA2-224KATCASTreturned success or error codeKDFAfter successful software integrity test
TLS v1.2 KDF RFC7627 (A5835)-KATCASTreturned success or error codeKDFAfter successful software integrity test
TLS v1.3 KDF (A5836)-KATCASTreturned success or error codeKDFAfter successful software integrity test
DSA KeyGen (FIPS186-4) (A5835)-PCTPCTreturned success or error codeSign/VerifyWhen an ECDSA key pair is generated for use with sign/verify functions
ECDSA KeyGen (FIPS186-4) (A5835)-PCTPCTreturned success or error codeSign/VerifyWhen an ECDSA key pair is generated for use with sign/verify functions
RSA KeyGen (FIPS186-4) (A5835)-PCTPCTreturned success or error codeSign/VerifyWhen an RSA key pair is generated for use with sign/verify functions

Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 48
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
DH-PCTPCTreturned success or error codeKey AgreementWhen a DSA key pair is generated for use with DH key transport functions
ECDH-PCTPCTreturned success or error codeKey AgreementWhen an ECDSA key pair is generated for use with ECDH key transport functions
ECDSA SigGen (FIPS186-4) (A5835)P-224; K-233; SHA-256KATCASTreturned success or error codeSignAfter successful software integrity test
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2-256 (A5835)Software Integrity TestSW/FW IntegrityOn DemandManually
HMAC-SHA2-256 (A5835)Software Integrity TestSW/FW IntegrityOn DemandManually
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-CBC (A5835)KATCASTOn DemandManually
AES-ECB (A5835)KATCASTOn DemandManually
AES-CCM (A5835)KATCASTOn DemandManually
AES-CCM (A5835)KATCASTOn DemandManually
AES-GCM (A5835)KATCASTOn DemandManually
AES-GCM (A5835)KATCASTOn DemandManually
AES-XTS Testing Revision 2.0 (A5835)KATCASTOn DemandManually
AES-XTS Testing Revision 2.0 (A5835)KATCASTOn DemandManually
AES-CMAC (A5835)KATCASTOn DemandManually
AES-CMAC (A5835)KATCASTOn DemandManually
TDES-ECB (A5835)KATCASTOn DemandManually
TDES-ECB (A5835)KATCASTOn DemandManually
TDES-CMAC (A5835)KATCASTOn DemandManually
TDES-CMAC (A5835)KATCASTOn DemandManually
Counter DRBG (A5835)KATCASTOn DemandManually
DSA SigGen (FIPS186-4) (A5835)KATCASTOn DemandManually
DSA SigVer (FIPS186-4) (A5835)KATCASTOn DemandManually
ECDSA SigVer (FIPS186- 4) (A5835)KATCASTOn DemandManually
RSA SigGen (FIPS186-4) (A5835)KATCASTOn DemandManually
RSA SigVer (FIPS186-4) (A5835)KATCASTOn DemandManually
HMAC-SHA-1 (A5835)KATCASTOn DemandManually

Table 20: Conditional Self-Tests

10.3 Periodic Self-Test Information

The table below specifies the module’s periodic self-test information. Table 21: Pre-Operational Periodic Information Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 49
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2-224 (A5835)KATCASTOn DemandManually
HMAC-SHA2-256 (A5835)KATCASTOn DemandManually
HMAC-SHA2-384 (A5835)KATCASTOn DemandManually
HMAC-SHA2-512 (A5835)KATCASTOn DemandManually
HMAC-SHA3-224 (A5835)KATCASTOn DemandManually
HMAC-SHA3-256 (A5835)KATCASTOn DemandManually
HMAC-SHA3-384 (A5835)KATCASTOn DemandManually
HMAC-SHA3-512 (A5835)KATCASTOn DemandManually
SHA-1 (A5835)KATCASTOn DemandManually
SHA2-224 (A5835)KATCASTOn DemandManually
SHA2-256 (A5835)KATCASTOn DemandManually
SHA2-384 (A5835)KATCASTOn DemandManually
SHA2-512 (A5835)KATCASTOn DemandManually
SHA3-224 (A5835)KATCASTOn DemandManually
SHA3-256 (A5835)KATCASTOn DemandManually
SHA3-384 (A5835)KATCASTOn DemandManually
SHA3-512 (A5835)KATCASTOn DemandManually
KAS-FFC-SSC Sp800- 56Ar3 (A5835)KATCASTOn DemandManually
KAS-ECC-SSC Sp800- 56Ar3 (A5835)KATCASTOn DemandManually
PBKDF (A5835)KATCASTOn DemandManually
TLS v1.2 KDF RFC7627 (A5835)KATCASTOn DemandManually
TLS v1.3 KDF (A5836)KATCASTOn DemandManually
DSA KeyGen (FIPS186-4) (A5835)PCTPCTOn DemandManually
ECDSA KeyGen (FIPS186-4) (A5835)PCTPCTOn DemandManually
RSA KeyGen (FIPS186-4) (A5835)PCTPCTOn DemandManually
DHPCTPCTOn DemandManually
ECDHPCTPCTOn DemandManually
ECDSA SigGen (FIPS186- 4) (A5835)KATCASTOn DemandManually

Table 22: Conditional Periodic Information The CO can initiate the pre-operational self-tests and conditional CASTs on demand for periodic testing of the module by re-instantiating the module or issuing the FIPS_selftest() API command.

10.4 Error States

The table below specifies the module’s error state information. Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 50
NameDescriptionConditionsRecovery MethodIndicator
Critical ErrorModule immediately terminates the calling application and sets an internal flag signaling the error condition. The module disables access to all cryptographic functions, SSPs, and data output services while the error condition persists.Upon failure of any pre- operational or conditional self- test,The module must be re- instantiated by the calling application. The CO should contact Riverbed Technology LLC if errors persist after re- instantiation.Returns error code upon self-test failure; returns failure indicator for subsequent requests for cryptographic services.
Page 51
11.1 Installation, Initialization, and Startup Procedures

The Riverbed Cryptographic Module is not delivered to end-users as a standalone offering. Rather, it is a pre-built integrated component of Riverbed’s application software, and these applications are the sole consumers of the cryptographic services provided by the module. The module and its calling application are delivered pre-installed on one of the Riverbed platforms specified in section 6 above or one where portability is maintained. Riverbed does not provide end-users with any mechanisms to directly access the module, its source code, its APIs, or any information sent to/from the module. The module’s integrity check is performed automatically at module instantiation (i.e., when the module is loaded into memory for execution) without action from the module operator, and end-users have no ability to bypass the automatic integrity check. No setup steps are required to be performed by end-users.

11.2 Administrator Guidance

There are no specific management activities required of the CO role to ensure that the module runs securely. If any irregular activity is observed, or if the module is consistently reporting errors, then Riverbed Customer Support should be contacted. The following list provides additional guidance for the CO:

11.3 Non-Administrator Guidance

The following list provides additional policies for the User role: • The cryptographic module’s services are designed to be provided to a calling application. Excluding the use of the NIST-defined elliptic curves as trusted third-party domain parameters, all other assurances from FIPS PUB 186-5 (including those required of the intended signatory and the signature verifier) are outside the scope of the module and are the responsibility of the calling application. Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 52
Page 53

12. Mitigation of Other Attacks This section is not applicable. The module does not claim to mitigate any attacks beyond the FIPS 140-3 Level 1 requirements for this validation. Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 54
TermDefinition
AESAdvanced Encryption Standard
ANSIAmerican National Standards Institute
APIApplication Programming Interface
CASTCryptographic Algorithm Self-Test
CBCCipher Block Chaining
CCCSCanadian Centre for Cyber Security
CCMCounter withCipher Block Chaining - Message Authentication Code
CFBCipher Feedback
CKGCryptographic Key Generation
CMACCipher-Based Message Authentication Code
CMVPCryptographic Module Validation Program
COCryptographic Officer
CPUCentral Processing Unit
CSPCritical Security Parameter
CTRCounter
CVLComponent Validation List
DEPDefault Entry Point
DESData Encryption Standard
DHDiffie-Hellman
DRBGDeterministic Random Bit Generator
DSADigital Signature Algorithm
ECBElectronic Code Book
ECCElliptic Curve Cryptography
ECC CDHElliptic Curve Cryptography Cofactor Diffie-Hellman
ECDHElliptic Curve Diffie-Hellman
ECDSAElliptic Curve Digital Signature Algorithm
EMI/EMCElectromagnetic Interference /Electromagnetic Compatibility
FFCFinite Field Cryptography
FIPSFederal Information Processing Standard
GCMGalois/Counter Mode

Appendix A. Acronyms and Abbreviations Table 24 provides definitions for the acronyms and abbreviations used in this document. Table 24. Acronyms and Abbreviations ©2025 Riverbed Technology, LLC

Page 55
TermDefinition
GMACGalois Message Authentication Code
GPCGeneral-Purpose Computer
HKDFHMAC-Based Key Derivation Function
HMAC(keyed-) Hash Message Authentication Code
KASKey Agreement Scheme
KATKnown Answer Test
KDFKey Derivation Function
KTSKey Transport Scheme
KWKey Wrap
KWPKey Wrap with Padding
MDMessage Digest
NISTNational Institute of Standards and Technology
OCBOffset Codebook
OFBOutput Feedback
OSOperating System
PBKDFPassword-Based Key Derivation Function
PCTPairwise Consistency Test
PKCSPublic Key Cryptography Standard
PSSProbabilistic Signature Scheme
PUBPublication
RCRivest Cipher
RFCRequest for Comment
RNGRandom Number Generator
RSARivest Shamir Adleman
SHASecure Hash Algorithm
SHAKESecure Hash Algorithm KECCAK
SHSSecure Hash Standard
SPSpecial Publication
TDESTriple Data Encryption Standard
TLSTransport Layer Security
XEXXOR Encrypt XOR
XTSXEX-Based Tweaked-Codebook Mode with Ciphertext Stealing

Riverbed Cryptographic Module 2.0.1 ©2025 Riverbed Technology, LLC

Page 56

Appendix B. Approved Service Indicators This appendix specifies the APIs that are externally accessible and return the Approved service indicators. Synopsis #include <openssl/service_indicator.h> #include <openssl/ssl.h> int EVP_cipher_get_service_indicator(EVP_CIPHER_CTX *ctx); int DSA_get_service_indicator(DSA * ptr_dsa, DSA_MODES_t mode); int RSA_key_get_service_indicator(RSA * ptr_rsa); int PBKDF_get_service_indicator(); int EVP_Digest_get_service_indicator(EVP_MD_CTX *ctx); int EC_key_get_service_indicator(EC_KEY *ec_key); int CMAC_get_service_indicator(CMAC_CTX *cmac_ctx, CMAC_MODE_t mode); int HMAC_get_service_indicator(HMAC_CTX *ctx); int TLSKDF_get_service_indicator(EVP_PKEY_CTX *tls_ctx); int TLS1_3_kdf_get_service_indicator(EVP_MD *md); int TLS1_3_get_service_indicator(SSL *s); int DRBG_get_service_indicator(RAND_DRBG *drbg); Description These APIs are high-level interfaces that return the Approved service indicator value based on the parameter(s) passed to them.

Page 57
Page 58

Prepared by: Corsec Security, Inc.

12600 Fair Lakes Circle, Suite 210

Fairfax, VA 22033 United States of America Phone: +1 703 267 6050 Email: info@corsec.com http://www.corsec.com