All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Red Hat Enterprise Linux 9 NSS Cryptographic Module

Certificate#5022StandardFIPS 140-3Level1TypeSoftwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorRed Hat, Inc
Low review priority  ·  no TCB surface named  ·  NSS upstream has published 0 CVEs since this module's initial validation  ·  last validated 14 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date5/29/2030
CaveatWhen operated in approved mode and installed, initialized and configured as specified in the Security Policy. The module generates cryptographic keys whose strengths are modified by available entropy. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.
VendorRed Hat, Inc

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Red Hat Enterprise Linux 9 NSS Cryptographic Module
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Recovery</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Show Status</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>IKEV<br/>library named: nss</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Red Hat Enterprise Linux 9 NSS Cryptographic Module
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Recovery</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Show Status</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>IKEV<br/>library named: nss</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Red Hat, Inc Red Hat Enterprise Linux 9 NSS Cryptographic Module Prepared by: atsec information security corporation

4516 Seton Center Pkwy, Suite 250

Page 3
Table of Contents
#SectionPage
Page 5

List of Tables Table 3: Tested Module Identification – Software/Firmware/Hybrid (Executable Code Sets) Error! Bookmark not defined. defined.

Page 7
List of Figures
ItemPage
Figure 1: Block Diagram9
Page 8
SectionTitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication1
5Software/Firmware security1
6Operational environment1
7Physical securityN/A
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacks1
Overall Level1
1.1 Overview

This document is the non-proprietary FIPS 140-3 Security Policy for version 3.90.0-4408e3bb8a34af3a of the Red Hat Enterprise Linux 9 NSS Cryptographic Module. It contains the security rules under which the module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for an overall Security Level 1 module. including this notice. Other documentation is proprietary to their authors.

1.2 Security Levels
Page 9

2 – Cryptographic Module Specification

2.1 Description

Purpose and Use: The Red Hat Enterprise Linux 9 NSS Cryptographic Module (hereafter referred to as “the module”) is defined as a software module in a multi-chip standalone embodiment. It provides a C language application program interface (API) designed to support cross-platform development of security-enabled client and server applications. Applications built with NSS can support SSLv3, TLS, IKEv2, PKCS#5, PKCS#7, PKCS#11, PKCS#12, S/MIME, X.509 v3 certificates, and other security standards supporting FIPS 140-3 validated cryptographic algorithms. It combines a vertical stack of Linux components intended to limit the external interface each separate component may provide. Module Type: Software Module Embodiment: MultiChipStand Cryptographic Boundary: The cryptographic boundary consists only of the Softoken and Freebl libraries along with their associated integrity check values as listed in Section 2.2. If any other NSS API outside of these two libraries is invoked, the user is not interacting with the module specified in this Security Policy. Tested Operational Environment’s Physical Perimeter (TOEPP): The TOEPP of the module is defined as the general-purpose computer on which the module is installed.

Page 10
Package or File NameSoftware/ Firmware VersionFeaturesIntegrity Test
libsoftokn3.so, libfreeblpriv3.so on Dell PowerEdge3.90.0-4408e3bb8a34af3aN/AHMAC-SHA-256
libsoftokn3.so, libfreeblpriv3.so on IBM 9080-HEX3.90.0-4408e3bb8a34af3aN/AHMAC-SHA-256
2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification

Page 11
Package or File NameSoftware/ Firmware VersionFeaturesIntegrity Test
libsoftokn3.so, libfreeblpriv3.so on IBM z16 3931-A013.90.0-4408e3bb8a34af3aN/AHMAC-SHA-256
Operating SystemHardware PlatformProcessorsPAA/PAIHypervisor or Host OSVersion(s)
Red Hat Enterprise Linux 9Dell PowerEdge R440Intel Cascade Lake Xeon Silver 4216YesN/A3.90.0- 4408e3bb8a34af3a
Red Hat Enterprise Linux 9Dell PowerEdge R440Intel Cascade Lake Xeon Silver 4216NoN/A3.90.0- 4408e3bb8a34af3a
Red Hat Enterprise Linux 9IBM 9080- HEXIBM POWER10YesPowerVM FW1040.00 with VIOS 3.1.3.003.90.0- 4408e3bb8a34af3a
Red Hat Enterprise Linux 9IBM 9080- HEXIBM POWER10NoPowerVM FW1040.00 with VIOS 3.1.3.003.90.0- 4408e3bb8a34af3a
Red Hat Enterprise Linux 9IBM z16 3931-A01IBM z16YesN/A3.90.0- 4408e3bb8a34af3a
Red Hat Enterprise Linux 9IBM z16 3931-A01IBM z16NoN/A3.90.0- 4408e3bb8a34af3a

Table 2: Tested Module Identification

Page 12
Operating SystemHardware Platform
Red Hat Enterprise Linux 9Intel(R) Xeon(R) E5
Mode NameDescriptionTypeStatus Indicator
ApprovedAutomatically entered whenever an approved service is requested.ApprovedEquivalent to the indicator of the requested service.
Non- ApprovedAutomatically entered whenever a non- approved service is requested.Non- ApprovedEquivalent to the indicator of the requested service.

Table 4: Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid CMVP makes no statement as to the correct operation of the module or the security strengths of the generated keys when so ported if the specific operational environment is not listed on the validation certificate.

2.3 Excluded Components

There are no components within the cryptographic boundary excluded from the FIPS 140-3 requirements.

2.4 Modes of Operation

Modes List and Description: Table 5: Modes List and Description After passing all pre-operational self-tests and cryptographic algorithm self-tests executed on start-up, the module automatically transitions to the approved mode. No operator intervention is required to reach this point. Mode Change Instructions and Status: The module automatically switches between the approved and non-approved modes depending on the services service that was requested. The module does not implement a degraded mode of operation.

2.5 Algorithms
Page 13
AlgorithmCAVP CertPropertiesReference
AES-CBCA4987Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBCA4994Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS1A4992Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CMACA4989Direction - Generation, Verification Key Length - 128, 192, 256SP 800-38B
AES-CTRA4987Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CTRA4994Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA4987Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA4994Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-GCMA4987Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 192, 256SP 800-38D
AES-GCMA4994Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 192, 256SP 800-38D
AES-GCMA5559Direction - Decrypt, Encrypt IV Generation - External, Internal Key Length - 128, 192, 256 IV Generation Mode - 8.2.1SP 800-38D
AES-KWA4988Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-KWA4993Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
Page 14
AlgorithmCAVP CertPropertiesReference
AES-KWPA4988Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-KWPA4993Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
ECDSA KeyGen (FIPS186-5)A4987Curve - P-256, P-384, P-521 Secret Generation Mode - testing candidatesFIPS 186-5
ECDSA SigGen (FIPS186-5)A4987Curve - P-256, P-384, P-521 Component - No Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2- 512FIPS 186-5
ECDSA SigVer (FIPS186-5)A4987Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2- 512FIPS 186-5
Hash DRBGA4987Prediction Resistance - No, Yes Mode - SHA2-256SP 800-90A Rev. 1
HMAC-SHA-1A4987Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 224A4987Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 256A4987Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 384A4987Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512A4987Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
KAS-ECC-SSC Sp800-56Ar3A4987Domain Parameter Generation Methods - P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KAS-FFC-SSC Sp800-56Ar3A4987Domain Parameter Generation Methods - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192 Scheme -SP 800-56A Rev. 3
Page 15
AlgorithmCAVP CertProperties dhEphem - KAS Role - initiator, responderReference
KDA HKDF Sp800-56Cr1A4986Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-65336 Increment 8 HMAC Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2- 512SP 800-56C Rev. 2
KDF IKEv2 (CVL)A4991Diffie-Hellman Shared Secret Length - Diffie-Hellman Shared Secret Length: 224, 2048, 8192 Derived Keying Material Length - Derived Keying Material Length: 1056, 3072 Hash Algorithm - SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
KDF SP800-108A4990KDF Mode - Counter, Double Pipeline Iteration, Feedback Supported Lengths - Supported Lengths: 8, 72, 128, 776, 3456, 4096SP 800-108 Rev. 1
PBKDFA4987Iteration Count - Iteration Count: 1000-10000 Increment 1 Password Length - Password Length: 8-128 Increment 1SP 800-132
RSA KeyGen (FIPS186-5)A4987Key Generation Mode - probable Modulo - 2048, 3072, 4096, 8192 Primality Tests - 2pow100 Private Key Format - standardFIPS 186-5
RSA SigGen (FIPS186-5)A4987Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pssFIPS 186-5
RSA SigVer (FIPS186-2)A4987Signature Type - PKCS 1.5, PKCSPSS Modulo - 1536FIPS 186-4
RSA SigVer (FIPS186-4)A4987Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024, 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186-5)A4987Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pssFIPS 186-5
Safe Primes Key GenerationA4987Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP- 4096, MODP-6144, MODP-8192SP 800-56A Rev. 3
SHA2-224A4987Large Message Sizes - 1, 2, 4, 8 Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
Page 16
AlgorithmCAVP CertPropertiesReference
SHA2-256A4987Large Message Sizes - 1, 2, 4, 8 Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-384A4987Large Message Sizes - 1, 2, 4, 8 Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-512A4987Large Message Sizes - 1, 2, 4, 8 Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
TLS v1.2 KDF RFC7627 (CVL)A4987Hash Algorithm - SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
NamePropertiesImplementationReference
Symmetric Cryptographic Key Generation (CKG)Key type:SymmetricN/ASP 800-133r2, section 4, example 1, and section 6.1
Asymmetric Cryptographic Key Generation (CKG)Key type:AsymmetricN/ASP 800-133r2, section 4, example 1

Table 6: Approved Algorithms The table above lists all approved cryptographic algorithms of the module, including specific key lengths employed for approved services in Section 4.3, and implemented modes or methods of operation of the algorithms. Vendor-Affirmed Algorithms: Table 7: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: N/A for this module. The module does not implement non-approved algorithms that are allowed in the approved mode of operation. Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. The module does not implement non-approved algorithms that are allowed in the approved mode of operation with no security claimed. Non-Approved, Not Allowed Algorithms:

Page 17
NameUse and Function
MD2, MD5, SHA-1Message digest
RC2, RC4, DES, Triple-DES, CDMF, Camellia, SEED, ChaCha20(- Poly1305)Encryption, Decryption
AES GCM (external IV)Encryption
CBC-MAC, AES XCBC-MAC, AES XCBC-MAC-96Message authentication
HMAC (MD2, MD5, SHA-1; < 112-bit keys)Message authentication
HMAC/SSLv3 MAC (constant-time implementation)Message authentication
MD2, MD5, SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, DES, Triple- DES, AES, Camellia, SEED, ANS X9.63 KDF, SSL 3 PRF, IKEv1 PRF, TLS 1.0/1.1 KDF, TLS KDF without extended master secretKey derivation
KBKDF, HKDF, TLS 1.2 KDF, IKEv2 PRF (< 112-bit keys)Key derivation
KBKDF (MD2, MD5)Key derivation
IKEv2 PRF (MD2, MD5)Key derivation
PKCS#5 PBE, PKCS#12 PBEPassword-based key derivation
PBKDF2 (short password; short salt; insufficient iterations; < 112-bit keys)Password-based key derivation
J-PAKEShared secret computation
KAS-FFC-SSC (FIPS 186-type groups)Shared secret computation
X25519Shared secret computation
DSASignature generation, Signature verification
RSA (primitive; PKCS#1 v1.5 or PSS with MD2, MD5, SHA-1)Signature generation, Signature verification
RSA (< 2048-bit keys)Signature generation
RSA (< 1024-bit keys)Signature verification
ECDSA (component)Signature generation, Signature verification
Page 18
NameUse and Function
RSAAsymmetric encryption, Asymmetric decryption
DSAParameter generation, Parameter verification, Key pair generation
DH (FIPS 186-type groups)Key pair generation
RSA (< 2048 bits; > 4096 bits)Key pair generation
Ed25519, X25519Key pair generation
Symmetric key generation (< 112 bits)Secret key generation
NameTypeDescriptionPropertiesAlgorithms
Encryption with AESBC-UnAuthEncryption using AESKeys:128, 192, 256 bits with 128-256 bits of key strengthAES-CBC AES-CTR AES-ECB AES-CBC-CS1 AES-CBC AES-CTR AES-ECB
Decryption with AESBC-UnAuthDecryption using AESKeys:128, 192, 256 bits with 128-256 bits of key strengthAES-CBC AES-CTR AES-ECB AES-CBC-CS1 AES-CTR AES-CTR AES-ECB
Authenticated Encryption with AESBC-AuthAuthenticated encryption using AESKeys:128, 192, 256 bits with 128-256 bits of key strengthAES-GCM AES-GCM AES-GCM

Table 8: Non-Approved, Not Allowed Algorithms The table above lists all the non-approved cryptographic algorithms of the module employed by the nonapproved services in Section 4.4.

2.6 Security Function Implementations
Page 19
NameTypeDescriptionPropertiesAlgorithms
Authenticated Decryption with AESBC-AuthAuthenticated decryption using AESKeys:128, 192, 256 bits with 128-256 bits of key strengthAES-GCM AES-GCM AES-GCM
Key Derivation with PBKDFPBKDFKey derivation using PBKDFDerived keys:112- 256 bitsPBKDF
Key Derivation with KBKDFKBKDFKey derivation using KBKDFDerived keys:112- 256 bitsKDF SP800-108
Key Derivation with HKDFKAS-56CKDFKey derivation using HKDFDerived keys:112- 256 bitsKDA HKDF Sp800- 56Cr1
Key Derivation with TLS 1.2 KDFKAS-135KDFKey derivation using TLS 1.2 KDFDerived keys:112- 256 bitsTLS v1.2 KDF RFC7627
Key Derivation with IKEv2 KDFKAS-135KDFKey derivation using IKEv2 KDFDerived keys:112- 256 bitsKDF IKEv2
Key Wrapping with AESKTS-WrapKey wrapping using AESKeys:128, 192, 256 bits with 128-256 bits of key strength; Compliant with IG D.GAES-KW AES-KWP AES-KW AES-KWP AES-GCM AES-GCM AES-GCM
Key Unwrapping with AESKTS-WrapKey unwrapping using AESKeys:128, 192, 256 bits with 128-256 bits of key strength; Compliant with IG D.GAES-KW AES-KWP AES-KW AES-KWP AES-GCM AES-GCM AES-GCM
Message Authentication with HMACMACMessage authentication using HMACKeys:112-256 bits with 112-256 bits of key strengthHMAC-SHA-1 HMAC-SHA2-224 HMAC-SHA2-256 HMAC-SHA2-384 HMAC-SHA2-512
Message Authentication with CMACMACMessage authentication using CMACKeys:128, 192, 256 bits with 128-256 bits of key strengthAES-CMAC
Page 20
NameTypeDescriptionPropertiesAlgorithms
Random Number Generation with Hash_DRBGDRBGRandom number generation using Hash_DRBGHash:SHA2-256Hash DRBG
Shared Secret Computation with KAS-ECC-SSCKAS-SSCShared secret computation using KAS-ECC-SSCCurves:P-256, P- 384, P-521 with 128, 192 and 256 bits of strength; Compliant with IG D.F scenario 2(1)KAS-ECC-SSC Sp800-56Ar3
Shared Secret Computation with KAS-FFC-SSCKAS-SSCShared secret computation using KAS-FFC-SSCKeys:MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192 with 112-200 bits of key strength; Compliant with IG D.F scenario 2(1)KAS-FFC-SSC Sp800-56Ar3
Signature Generation with RSADigSig-SigGenSignature generation using RSAKeys:2048, 3072, 4096 bits with 112- 150 bits of key strengthRSA SigGen (FIPS186-5)
Signature Generation with ECDSADigSig-SigGenSignature generation using ECDSACurves:P-256, P- 384, P-521 with 128, 192 and 256 bits of strengthECDSA SigGen (FIPS186-5)
Signature Verification with RSADigSig-SigVerSignature verification using RSAKeys:1024, 1280, 1536, 1792, 2048, 3072, 4096 bits with 80-150 bits of key strengthRSA SigVer (FIPS186-2) RSA SigVer (FIPS186-4) RSA SigVer (FIPS186-5)
Signature Verification with ECDSADigSig-SigVerSignature verification using ECDSACurves:P-256, P- 384, P-521 withECDSA SigVer (FIPS186-5)
Page 21
NameTypeDescriptionPropertiesAlgorithms
128, 192, 256 bits of strength
Symmetric Key Generation with Hash_DRBGCKGDirect symmetric key generation using Hash_DRBGKeys:112-256 bits with 112-256 bits of key strength; Compliant with SP800-133r2 section 6.1Hash DRBG
Key Pair Generation with RSAAsymKeyPair- KeyGenKey pair generation using RSAKeys:2048, 3072, 4096 bits with 112- 150 bits of key strengthRSA KeyGen (FIPS186-5)
Key Pair Generation with ECDSAAsymKeyPair- KeyGenKey pair generation using ECDSACurves:P-256, P- 384, P-521 with 128, 192 and 256 bits of strengthECDSA KeyGen (FIPS186-5)
Key Pair Generation with Safe PrimesAsymKeyPair- KeyGenKey pair generation using Safe PrimesKeys:MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192 with 112-200 bits of key strengthSafe Primes Key Generation
Message Digest with SHASHAMessage digest using SHASHA2-256 SHA2-384 SHA2-512 SHA2-224

Table 9: Security Function Implementations

2.7 Algorithm Specific Information
2.7.1 AES GCM IV

The Crypto Officer shall consider the following requirements and restrictions when using the module.

Page 22

For TLS 1.2, the module offers the AES GCM implementation and uses the context of Scenario 1 of FIPS 140-3 IG C.H. NSS is compliant with SP 800-52r2 Section 3.3.1 and the mechanism for IV generation is compliant with RFC 5288 and 8446. The module does not implement the TLS protocol. The module’s implementation of AES GCM is used together with an application that runs outside the module’s cryptographic boundary. The design of the TLS protocol implicitly ensures that the counter (the nonce_explicit part of the IV) does not exhaust the maximum number of possible values for a given session key. In the event the module’s power is lost and restored, the consuming application must ensure that a new key for use with the AES GCM key encryption or decryption under this scenario shall be established. Alternatively, the Crypto Officer can use the module’s API to perform AES GCM encryption using internal IV generation that complies with Scenario 2 of the IG C.H. These IVs are always at least 96 bits and generated using the approved DRBG internal to the module’s boundary. Additionally, the module offers an internal deterministic IV generation mode compliant with Scenario 3 of FIPS 140-3 IG C.H. The generated GCM IV is at least 96 bits in length where the size of the fixed (name) field is at least 32 bits. The module then internally generates a 32 bit or longer deterministic non-repetitive counter. The module increments the counter monotonically at each invocation of the AES-GCM for the same encryption key. The module explicitly checks for the wrap around and returns an error if wrap around condition is reached. In case the module’s power is lost and then restored, a new key for use with the AES-GCM encryption/decryption shall be established. Finally, for TLS 1.3, the AES GCM implementation uses the context of Scenario 5 of FIPS 140-3 IG C.H. The protocol that provides this compliance is TLS 1.3, defined in RFC8446 of August 2018, using the cipher-suites that explicitly select AES GCM as the encryption/decryption cipher (Appendix B.4 of RFC8446). The module supports acceptable AES GCM cipher suites from Section 3.3.1 of SP800-52r2. TLS 1.3 employs separate 64-bit sequence numbers, one for protocol records that are received, and one for protocol records that are sent to a peer. These sequence numbers are set at zero at the beginning of a TLS 1.3 connection and each time when the AES-GCM key is changed. After reading or writing a record, the respective sequence number is incremented by one. The protocol specification determines that the sequence number should not wrap, and if this condition is observed, then the protocol implementation must either trigger a re-key of the session (i.e., a new key for AESGCM), or terminate the connection.

2.7.2 Key Derivation using SP 800-132 PBKDF2

The module provides password-based key derivation (PBKDF2), compliant with SP 800-132. The module supports option 1a from Section 5.4 of SP 800-132, in which the Master Key (MK) or a segment of it is used directly as the Data Protection Key (DPK). In accordance to SP 800-132 and FIPS 140-3 IG D.N, the following requirements shall be met:

Page 23
CertVendor
NumberName
E47Red Hat, Inc

the value is estimated to be 10-8. Combined with the minimum iteration count as described below, this provides an acceptable trade-off between user experience and security against brute-force attacks.

2.7.3 SP 800-56Ar3 Assurances

To comply with the assurances found in Section 5.6.2 of SP 800-56Ar3, the operator must use the module together with an application that implements the TLS protocol. Additionally, the module’s approved Key Pair Generation service (see Section 4.3) must be used to generate ephemeral Diffie- Hellman or EC Diffie-Hellman key pairs, or the key pairs must be obtained from another FIPS- validated module. As part of this service, the module will internally perform the full public key validation of the generated public key. The module’s shared secret computation service will internally perform the full public key validation of the peer public key, complying with Sections 5.6.2.2.1 and 5.6.2.2.2 of SP 800-56Ar3.

2.7.4 RSA Approved Modulus Size

RSA Signature Verification is approved for 1024, 1280, 1536 and 1792-bit keys in compliance with IG C.F. The

1280 and 1792-bit keys cannot be ACVP tested. However, all modulus sizes in which testing is available have

been tested by the CAVP.

2.7.5 Legacy Use

Digital signature verification using RSA with 1024, 1280, 1536, 1792-bit moduli is allowed for legacy use only. These legacy algorithms can only be used on data that was generated prior to the Legacy Date specified in FIPS 140-3 IG C.M

2.8 RBG and Entropy
Page 24
NameTypeOperational EnvironmentSample SizeEntropy per SampleConditioning Component
Userspace CPU Time Jitter RNG Entropy Source Version 2.2.0Non- PhysicalRed Hat Enterprise Linux 9 on Dell PowerEdge R440 on Intel(R) Xeon(R) Silver 4216; Red Hat Enterprise Linux 9 on IBM z16 3931-A01 on IBM z16; Red Hat Enterprise Linux 9 on PowerVM FW1040.00 with VIOS 3.1.3.00 on IBM 9080 HEX on IBM POWER10256 bits225 bitsHMAC- SHA2-512

Table 11: Entropy Sources The module employs a Deterministic Random Bit Generator (DRBG) implementation based on SP 800-90Ar1. This DRBG is used internally by the module (e.g. to generate symmetric keys, seeds for asymmetric key pairs, and random numbers for security functions). It can also be accessed using the specified API functions. The DRBG implemented is a SHA-256 Hash_DRBG, seeded by the entropy source described in the table above. It does not employ prediction resistance. The module generates SSPs (e.g., keys) whose strengths are modified by available entropy. The module complies with the Public Use Document for ESV certificate E47 by reading entropy data from the get_random() function with the GRND_RANDOM flag set, which corresponds to the GetEntropy() conceptual interface. The operational environment on the ESV certificate is identical to the operating system described in this document. There are no maintenance requirements for the entropy source. The entropy source is located within the module’s physical perimeter, but outside of the module’s cryptographic boundary.

2.9 Key Generation

The module implements Cryptographic Key Generation (CKG, vendor affirmed), compliant with SP 800-133r2. When random values are required, they are obtained from the SP 800-90Ar1 approved DRBG, compliant with Section 4 of SP 800-133r2. The following methods are implemented:

Page 25
2.10 Key Establishment

The module provides Diffie-Hellman (DH) and Elliptic Curve Diffie-Hellman (ECDH) shared secret computation compliant with SP800-56Ar3, in accordance with scenario 2 (1) of FIPS 140-3 IG D.F. For Diffie-Hellman, the module supports the use of the safe primes defined in RFC 3526 (IKE) and RFC 7919 (TLS). Note that the module only implements domain parameter generation, key pair generation and verification, and shared secret computation. No other part of the IKE or TLS protocols is implemented (with the exception of the TLS 1.2 KDF and IKEv2 PRF): IKE (RFC 3526):

2.11 Industry Protocols

For DH, the module supports the use of the safe primes defined in RFC 3526 (IKE) and RFC 7919 (TLS) as listed in Section 2.10. Note that the module only implements domain parameter generation, key pair generation and verification, and shared secret computation. No other part of the IKE or TLS protocols is implemented (with the exception of the TLS 1.2 KDF (RFC 7627) and IKEv2 KDF). No parts of the TLS and IKE protocols, other than the KDFs, have been tested by the CAVP or CMVP.

Page 26

TLS 1.2 KDF (RFC 7627) and IKEv2 implementations shall only be used to generate secret keys in the context of the TLS 1.2 and IKE protocols respectively.

Page 27
Physical PortLogical Interface(s)Data That Passes
As a software-only module, the module does not have physical ports. Physical Ports are interpreted to be the physical ports of the hardware platform on which it runs.Data InputAPI input parameters
As a software-only module, the module does not have physical ports. Physical Ports are interpreted to be the physical ports of the hardware platform on which it runs.Data OutputAPI output parameters
As a software-only module, the module does not have physical ports. Physical Ports are interpreted to be the physical ports of the hardware platform on which it runs.Control InputAPI function calls, API input parameters for control input
As a software-only module, the module does not have physical ports. Physical Ports are interpreted to be the physical ports of the hardware platform on which it runs.Status OutputAPI return codes
3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

Table 12: Ports and Interfaces The logical interfaces are the APIs through which the applications request services. The module does not

Page 28
NameTypeOperator TypeAuthentication Methods
Crypto OfficerRoleCONone
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
EncryptionEncrypt a plaintextCKS_NSS_FIPS_O K (1)AES key, IV, plaintextCiphertextEncryption with AESCrypto Officer - AES Key: W,E
DecryptionDecrypt a ciphertextCKS_NSS_FIPS_O K (1)AES key, IV, ciphertex tPlaintextDecryption with AESCrypto Officer - AES Key: W,E
Authenticated EncryptionEncrypt a plaintextCKS_NSS_ FIPS_OKAES key, IV, plaintextCiphertext, MAC tagAuthenticated Encryption with AESCrypto Officer - AES Key: W,E
Authenticated DecryptionDecrypt a ciphertextCKS_NSS_ FIPS_OKAES key, IV, MAC tag, ciphertex tPlaintext or failAuthenticated Decryption with AESCrypto Officer - AES Key: W,E
4 Roles, Services, and Authentication

N/A for this module. The module does not support authentication for roles.

4.2 Roles

Table 13: Roles The module supports the Crypto Officer role only. This sole role is implicitly and always assumed by the operator of the module. No support is provided for multiple concurrent operators or a maintenance role.

4.3 Approved Services
Page 29
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Key Derivation from a KDKDerive a key from a key- derivation keyCKS_NSS_FIPS_O K (1)Key- derivatio n keyDerived keyKey Derivation with KBKDFCrypto Officer - Key- Derivation Key: W,E - Derived Key : G
Key DerivationDerive a key from a shared secretCKS_NSS_FIPS_O K (1)Shared secretDerived keyKey Derivation with HKDF Key Derivation with TLS 1.2 KDF Key Derivation with IKEv2 KDFCrypto Officer - Shared Secret: W,E - Derived Key : G
Password- Based Key DerivationDerive a key from a passwordCKS_NSS_FIPS_O K (1)Password , salt, iteration countDerived keyKey Derivation with PBKDFCrypto Officer - Password: W,E - Derived Key : G
Key WrappingWrap a CSPCKS_NSS_FIPS_O K (1)AES key, any CSPWrapped CSPKey Wrapping with AESCrypto Officer - AES Key: W,E
Key UnwrappingUnwrap a CSPCKS_NSS_FIPS_O K (1)AES key, Wrapped CSPAny CSPKey Unwrapping with AESCrypto Officer - AES Key: W,E
Message Authenticatio nCompute a MAC tagCKS_NSS_FIPS_O K (1)HMAC keyMAC tagMessage Authenticatio n with HMACCrypto Officer - HMAC Key : W,E
Message Authenticatio n with AESCompute a MAC tagCKS_NSS_FIPS_O K (1)AES keyMAC tagMessage Authenticatio n with CMACCrypto Officer
Page 30
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access - AES Key: W,E
Message DigestCompute a message digestCKS_NSS_FIPS_O K (1)MessageDigest valueMessage Digest with SHACrypto Officer
Random Number GenerationGenerate random bytesCKR_OKOutput lengthRandom bytesRandom Number Generation with Hash_DRBGCrypto Officer - Entropy Input : W,E - DRBG Seed : G,E - Internal State (V, C) : G,W,E
Shared Secret Computation with DHCompute a shared secretCKS_NSS_FIPS_O KDH private key (owner), DH public key (peer)Shared secretShared Secret Computation with KAS- FFC-SSCCrypto Officer - DH Private Key : W,E - DH Public Key : W,E - Shared Secret: G
Shared Secret Computation with ECCCompute a shared secretCKS_NSS_FIPS_O KEC private key (owner), EC public key (peer)Shared secretShared Secret Computation with KAS- ECC-SSCCrypto Officer - EC Private Key : W,E - EC Public Key: W,E - Shared Secret: G
Signature Generation with RSAGenerate a signatureCKS_NSS_FIPS_O KRSA private key, messageSignatureSignature Generation with RSACrypto Officer - RSA Private Key : W,E
Signature Generation with ECDSAGenerate a signatureCKS_NSS_FIPS_O KEC privateSignatureSignature Generation with ECDSACrypto Officer
Page 31
NameDescriptio nIndicatorInputs key, messageOutputsSecurity FunctionsSSP Access - EC Private Key : W,E
Signature Verification with RSAVerify a signatureCKS_NSS_FIPS_O KRSA public key, message, signaturePass/failSignature Verification with RSACrypto Officer - RSA Public Key: W,E
Signature Verification with ECDSAVerify a signatureCKS_NSS_FIPS_O KEC public key, message, signaturePass/failSignature Verification with ECDSACrypto Officer - EC Public Key: W,E
Key Pair Generation with Safe PrimesGenerate a key pairCKS_NSS_FIPS_O KGroupDH public key, DH private keyKey Pair Generation with Safe PrimesCrypto Officer - DH Private Key : G - DH Public Key : G - Intermediat e key generation value : G,E,Z
Key Pair Generation with RSAGenerate a key pairCKS_NSS_FIPS_O KModulus bitsRSA public key, RSA private keyKey Pair Generation with RSACrypto Officer - RSA Private Key : G - RSA Public Key: G - Intermediat e key generation value : G,E,Z
Page 32
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Key Pair Generation with ECDSAGenerate a key pairCKS_NSS_FIPS_O KCurveEC public key, EC private keyKey Pair Generation with ECDSACrypto Officer - EC Private Key : G - EC Public Key: G - Intermediat e key generation value : G,E,Z
Symmetric Key GenerationGenerate a secret keyCKS_NSS_FIPS_O KKey sizeAES key, HMAC key or key- derivation keySymmetric Key Generation with Hash_DRBGCrypto Officer - AES Key: G - HMAC Key : G - Key- Derivation Key: G
Show VersionReturn the module name and version informatio nNoneN/AModule name and version informatio nNoneCrypto Officer
Show StatusReturn the module statusNoneN/AModule statusNoneCrypto Officer
Self-TestPerform the CASTs and integrity testsNoneN/APass/failNoneCrypto Officer
ZeroizationZeroize all SSPsN/AAny SSPNoneNoneCrypto Officer - AES Key: Z - HMAC
Page 33

Name

Descriptio n

Indicator

Inputs

Outputs

Security Functions

SSP Access Key : Z - Key- Derivation Key: Z - Shared Secret: Z - Password: Z - Derived Key : Z - Entropy Input : Z - DRBG Seed : Z - Internal State (V, C) : Z - DH Private Key : Z - DH Public Key : Z - EC Private Key : Z - EC Public Key: Z - RSA Private Key : Z - RSA Public Key: Z - Intermediat e key generation value : Z

Z :Z :Z :Z Z Table 14: Approved Services The table above lists the approved services in this module, the algorithms involved, the Sensitive Security Parameters (SSPs) involved and how they are accessed, the roles that can request the service, and the respective service indicator. In this table, CO specifies the Crypto Officer role. The module provides services to operators that assume the available role. All services are described in detail in the API documentation (manual pages). The service tables define the services that utilize approved and non-

Page 34
NameDescriptionAlgorithmsRole
Message DigestCompute a message digestMD2, MD5, SHA-1CO
EncryptionEncrypt a plaintextRC2, RC4, DES, Triple-DES, CDMF, Camellia, SEED, ChaCha20(-Poly1305) AES GCM (external IV)CO
DecryptionDecrypt a ciphertextRC2, RC4, DES, Triple-DES, CDMF, Camellia, SEED, ChaCha20(-Poly1305)CO
Message AuthenticationCompute a MAC tagCBC-MAC, AES XCBC-MAC, AES XCBC-MAC-96 HMAC (MD2, MD5, SHA-1; < 112-bit keys) HMAC/SSLv3 MAC (constant-time implementation)CO
Key DerivationDerive a key from a key-derivation key or a shared secretMD2, MD5, SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, DES, Triple-DES, AES, Camellia, SEED, ANS X9.63 KDF, SSL 3 PRF, IKEv1 PRF, TLS 1.0/1.1 KDF, TLS KDF without extended master secret KBKDF, HKDF, TLS 1.2 KDF, IKEv2 PRF (< 112-bitCO

approved security functions in this module. For the respective tables, the convention below applies when specifying the access permissions (types) that the service has for each SSP. • Generate (G): The module generates or derives the SSP. • Read (R): The SSP is read from the module (e.g. the SSP is output). • Write (W): The SSP is updated, imported, or written to the module. • Execute (E): The module uses the SSP in performing a cryptographic operation. • Zeroize (Z): The module zeroizes the SSP. • N/A: The module does not access any SSP or key during its operation. To interact with the module, a calling application must use the FIPS token APIs provided by Softoken. The FIPS token API layer can be used to retrieve the approved service indicator for the module. This indicator consists of four independent service indicators:

  1. The session indicator, which must be used for all cryptographic services except the key (pair) generation and key derivation services. It can be accessed by invoking the NSC_NSSGetFIPSStatus function with the CKT_NSS_SESSION_LAST_CHECK parameter. If the output parameter is set to CKS_NSS_FIPS_OK (1), the service was approved.
  2. The object indicator, which must be used for the key (pair) generation and key derivation services. It can be accessed by invoking the NSC_NSSGetFIPSStatus function with the CKT_NSS_OBJECT_CHECK parameter and the output derived key. If the output parameter is set to CKS_NSS_FIPS_OK (1), the service was approved.
  3. The DRBG service indicator, which must be used for the DRBG service. It can be accessed by invoking the C_SeedRandom or C_GenerateRandom functions. If any of these functions returns CKR_OK, the service was approved.
4.4 Non-Approved Services
Page 35
NameDescriptionAlgorithmsRole
keys) KBKDF (MD2, MD5) IKEv2 PRF (MD2, MD5)
Password-Based Key DerivationDerive a key from a passwordPKCS#5 PBE, PKCS#12 PBE PBKDF2 (short password; short salt; insufficient iterations; < 112-bit keys)CO
Shared Secret ComputationCompute a shared secretJ-PAKE KAS-FFC-SSC (FIPS 186-type groups) X25519CO
Signature GenerationGenerate a signatureDSA RSA (primitive; PKCS#1 v1.5 or PSS with MD2, MD5, SHA-1) RSA (< 2048-bit keys) ECDSA (component)CO
Signature VerificationVerify a signatureDSA RSA (< 1024-bit keys) ECDSA (component)CO
Asymmetric EncryptionEncrypt a plaintextRSACO
Asymmetric DecryptionDecrypt a plaintextRSACO
Parameter GenerationGenerate domain parametersDSACO
Parameter VerificationVerify domain parametersDSACO
Key Pair GenerationGenerate a key pairDSA DH (FIPS 186-type groups) RSA (< 2048 bits; > 4096 bits) Ed25519, X25519CO
Secret Key GenerationGenerate a secret keySymmetric key generation (< 112 bits)CO

Table 15: Non-Approved Services The table above lists the non-approved services in this module, the algorithms involved, the roles that can request the service, and the respective service indicator. In this table, CO specifies the Crypto Officer role.

Page 36
4.5 External Software/Firmware Loaded

The module does not load external software or firmware.

Page 37
5 Software/Firmware Security
5.1 Integrity Techniques

Each software component of the module has an associated HMAC-SHA2-256 integrity check value. The integrity of the module is verified by comparing the HMAC-SHA2-256 values calculated at run time with the integrity values embedded in the check files that were computed at build time. If the integrity test fails, the module enters the Power-On Error state.

5.2 Initiate on Demand

Integrity tests are performed as part of the pre-operational self-tests, which are executed when the module is initialized. The integrity tests may be invoked on-demand by unloading and subsequently re-initializing the module, which will perform (among others) the software integrity tests.

Page 38
6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Modifiable How Requirements are Satisfied: The operating system provides process isolation and memory protection mechanisms that ensure appropriate separation for memory access among the processes on the system. Each process has control over its own data and uncontrolled access to the data of other processes is prevented.

6.2 Configuration Settings and Restrictions

The module shall be installed as stated in Section 11.1. If properly installed, the operating system provides process isolation and memory protection mechanisms that ensure appropriate separation for memory access among the processes on the system. Each process has control over its own data and uncontrolled access to the data of other processes is prevented. Instrumentation tools like the ptrace system call, gdb and strace, userspace live patching, as well as other tracing mechanisms offered by the Linux environment such as ftrace or systemtap, shall not be used in the operational environment. The use of any of these tools implies that the cryptographic module is running in a non-validated operational environment.

6.3 Additional Information

The Red Hat Enterprise Linux operating system is used as the basis of other products which include but are not limited to:

Page 39
7 Physical Security

The module is comprised of software only and therefore this section is not applicable.

Page 40
8 Non-Invasive Security

This module does not implement any non-invasive security mechanism and therefore this section is not applicable.

Page 41
Storage Area NameDescriptionPersistence Type
RAMTemporary storage for SSPs used by the module as part of service execution. The module does not perform persistent storage of SSPsDynamic
NameFromToFormat TypeDistribution TypeEntry TypeSFI or Algorithm
API input parameters (plaintext)Calling application within TOEPPCryptographic modulePlaintextManualElectronic
API input parameters (encrypted)Calling application within TOEPPCryptographic moduleEncryptedManualElectronicKey Unwrapping with AES
API output parameters (plaintext)Cryptographic moduleCalling application within TOEPPPlaintextManualElectronic
API output parameters (encrypted)Cryptographic moduleCalling application within TOEPPEncryptedManualElectronicKey Wrapping with AES
9 Sensitive Security Parameters Management
9.1 Storage Areas

Table 16: Storage Areas SSPs imported, generated, derived, or otherwise established by the module are stored in RAM while the module is operational. The operator application can use these SSPs to perform cryptographic operations, or export them as described in Section 9.2. The module maintains internal separation of the SSPs (including CSPs) in approved and non-approved modes of operation using an internal isFIPS flag for each SSP. This flag indicates whether the SSP can be used in approved or non-approved services.

9.2 SSP Input-Output Methods

Table 17: SSP Input-Output Methods

Page 42
Zeroization MethodDescriptionRationaleOperator Initiation
Destroy ObjectDestroys the SSP represented by the objectMemory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable. The completion of the zeroization routine indicates that the zeroization procedure succeeded.By calling the C_DestroyObject function.
AutomaticAutomatically zeroized by the module when no longer neededMemory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable.N/A
Remove power from the moduleDe-allocates the volatile memory used to store SSPsVolatile memory used by the module is overwritten within nanoseconds when power is removed. Module power off indicates that the zeroization procedure succeeded.By removing power
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
AES KeyAES key used for encryption, decryption, and computing MAC tags128, 192, 256 bits - 128, 192, 256 bitsSymmetric key - CSPSymmetric Key Generation with Hash_DRBGEncryption with AES Decryption with AES Authenticated Encryption with AES Authenticated Decryption with AES Key Wrapping

CSPs (with the exception of passwords) can only be imported to and exported from the module when they are wrapped using an approved security function (e.g. AES KW or KWP). PSPs can be imported and exported in plaintext. Import and export is performed using API input and output parameters. Table 18: SSP Zeroization Methods All data output is inhibited during zeroization. Memory is deallocated after zeroization.

Page 43
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By with AES Key Unwrapping with AES Message Authentication with CMAC
HMAC KeyHMAC key used for computing MAC tags112-256 bits - 112- 256 bitsSymmetric key - CSPSymmetric Key Generation with Hash_DRBGMessage Authentication with HMAC
Key- Derivation KeySymmetric key used to derive symmetric keys112-4096 bits - 112- 256 bitsSymmetric key - CSPSymmetric Key Generation with Hash_DRBGKey Derivation with KBKDF
Shared SecretShared secret generated by (EC) Diffie- Hellman256-8192 bits - 112- 256 bitsShared secret - CSPShared Secret Computation with KAS- ECC-SSC Shared Secret Computation with KAS- ECC-SSCKey Derivation with HKDF Key Derivation with TLS 1.2 KDF Key Derivation with IKEv2 KDF
PasswordPassword used to derive symmetric keys8-128 characters - N/APassword - CSPKey Derivation with PBKDF
Derived KeySymmetric key derived from a key- derivation key, shared secret, or password112-4096 bits - 112- 256 bitsSymmetric key - CSPKey Derivation with PBKDF Key Derivation with KBKDF Key Derivation with HKDF Key Derivation
Page 44
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
with TLS 1.2 KDF Key Derivation with IKEv2 KDF
Entropy InputEntropy input used to seed the DRBG128-384 bits - 128- 256 bitsEntropy input - CSPRandom Number Generation with Hash_DRBG
DRBG SeedDRBG seed derived from entropy input440 bits - 256 bitsSeed - CSPRandom Number Generation with Hash_DRBGRandom Number Generation with Hash_DRBG
Internal State (V, C)Internal state of the Hash_DRBG880 bits - 256 bitsInternal state - CSPRandom Number Generation with Hash_DRBGRandom Number Generation with Hash_DRBG
DH Private KeyPrivate key used for Diffie- Hellman2048-8192 bits - 112- 200 bitsPrivate key - CSPKey Pair Generation with Safe PrimesShared Secret Computation with KAS- FFC-SSC
DH Public KeyPublic key used for Diffie- Hellman2048-8192 bits - 112- 200 bitsPublic key - PSPKey Pair Generation with Safe PrimesShared Secret Computation with KAS- FFC-SSC
EC Private KeyPrivate key used for EC Diffie- HellmanP-256, P- 384, P-521 - 128, 192, 256 bitsPrivate key - CSPKey Pair Generation with ECDSAShared Secret Computation with KAS- ECC-SSC Signature Generation with ECDSA
Page 45
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
EC Public KeyPublic key used for EC Diffie- HellmanP-256, P- 384, P-521 - 128, 192, 256 bitsPublic key - PSPKey Pair Generation with ECDSAShared Secret Computation with KAS- ECC-SSC Signature Verification with ECDSA
RSA Private KeyPrivate key used for RSA signature generation2048, 3072, 4096 bits - 112-150 bitsPrivate key - CSPKey Pair Generation with RSASignature Generation with RSA
RSA Public KeyPublic key used for RSA signature verificationKeyGen: 2048, 3072, 4096 bits; SigVer: 1024, 1280, 1536, 1792, 2048, 3072, 4096 bits - KeyGen: 112-150 bits; SigVer: 80- 150 bitsPublic key - PSPKey Pair Generation with RSASignature Verification with RSA
Intermediate key generation valueTemporary value generated during key generation services256-8192 bits - 112- 256 bitsIntermediate value - CSPKey Pair Generation with RSA Key Pair Generation with ECDSA Key Pair Generation with Safe PrimesKey Pair Generation with RSA Key Pair Generation with ECDSA Key Pair Generation with Safe Primes
Page 46
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
AES KeyAPI input parameters (encrypted) API output parameters (encrypted)RAM:PlaintextUntil explicitly zeroized by operatorDestroy Object Remove power from the module
HMAC KeyAPI input parameters (encrypted) API output parameters (encrypted)RAM:PlaintextUntil explicitly zeroized by operatorDestroy Object Remove power from the module
Key- Derivation KeyAPI input parameters (encrypted) API output parameters (encrypted)RAM:PlaintextUntil explicitly zeroized by operatorDestroy Object Remove power from the moduleDerived Key :Derivation Of
Shared SecretAPI input parameters (encrypted) API output parameters (encrypted)RAM:PlaintextUntil explicitly zeroized by operatorDestroy Object Remove power from the moduleDH Private Key :Derived From DH Public Key :Derived From EC Private Key :Derived From EC Public Key:Derived From Derived Key :Derivation Of
PasswordAPI input parameters (plaintext)RAM:PlaintextFor the duration of the serviceDestroy Object Remove power from the moduleDerived Key :Derivation Of
Derived KeyAPI output parameters (encrypted)RAM:PlaintextUntil explicitly zeroized by operatorDestroy Object Remove power from the moduleKey-Derivation Key:Derived From Password:Derived From Shared Secret:Derived From
Page 47
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
Entropy InputRAM:PlaintextFrom generation until DRBG Seed is createdAutomatic Remove power from the moduleDRBG Seed :Derivation Of
DRBG SeedRAM:PlaintextWhile the DRBG is instantiatedAutomatic Remove power from the moduleEntropy Input :Derived From Internal State (V, C) :Generation Of
Internal State (V, C)RAM:PlaintextWhile the module is operationalRemove power from the moduleDRBG Seed :Generated From
DH Private KeyAPI input parameters (encrypted) API output parameters (encrypted)RAM:PlaintextUntil explicitly zeroized by operatorDestroy Object Remove power from the moduleDH Public Key :Paired With Intermediate key generation value :Generated From
DH Public KeyAPI input parameters (plaintext) API output parameters (plaintext)RAM:PlaintextUntil explicitly zeroized by operatorDestroy Object Remove power from the moduleDH Private Key :Paired With Intermediate key generation value :Generated From
EC Private KeyAPI input parameters (encrypted) API output parameters (encrypted)RAM:PlaintextUntil explicitly zeroized by operatorDestroy Object Remove power from the moduleEC Public Key:Paired With Intermediate key generation value :Generated From
EC Public KeyAPI input parameters (plaintext) API output parameters (plaintext)RAM:PlaintextUntil explicitly zeroized by operatorDestroy Object Remove power from the moduleEC Private Key :Paired With Intermediate key generation value :Generated From
RSA Private KeyAPI input parameters (encrypted)RAM:PlaintextUntil explicitly zeroized by operatorDestroy Object RemoveRSA Public Key:Paired With Intermediate key
Page 48
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
API output parameters (encrypted)power from the modulegeneration value :Generated From
RSA Public KeyAPI input parameters (plaintext) API output parameters (plaintext)RAM:PlaintextUntil explicitly zeroized by operatorDestroy Object Remove power from the moduleRSA Private Key :Paired With Intermediate key generation value :Generated From
Intermediate key generation valueRAM:PlaintextFor the duration of the serviceAutomaticDH Private Key :Generation Of DH Public Key :Generation Of EC Private Key :Generation Of EC Public Key:Generation Of RSA Private Key :Generation Of RSA Public Key:Generation Of
9.5 Transitions

The SHA-1 algorithm as implemented by the module will be non-approved for all purposes, starting January 1, 2031.

Page 49
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
HMAC- SHA2-256 (A4987)256-bit keyMessage authenticationSW/FW IntegrityModule becomes operational and services are available for useIntegrity test for libsoftokn3.so and libfreeblpriv3.so
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
SHA-1 (A4987)512-bit messageKATCASTModule becomes operational and services are available for useMessage DigestModule initialization
10 Self-Tests
10.1 Pre-Operational Self-Tests

Table 21: Pre-Operational Self-Tests Each software component of the module has an associated HMAC-SHA2-256 integrity check value. The software integrity tests ensure that the module is not corrupted. The HMAC-SHA2-256 algorithm goes through a CAST before the software integrity tests are performed. Upon initialization, the module immediately performs all Freebl cryptographic algorithm self-tests (CASTs) as specified in the Conditional Self-Tests table. When all those self-tests pass successfully, the module automatically performs the pre-operational integrity test on the libfreeblpriv3.so file using its associated check value. Then, the module performs the RSA CAST in the Softoken library, followed by the pre-operational integrity test on the libsoftokn3.so file using its associated check value. The CAST for the algorithm used in the preoperational self-test (i.e., HMAC-SHA2-256) is performed by the Freebl library, before the Softoken library integrity test. Finally, all remaining CASTs for the algorithms implemented in Softoken are executed (see the Conditional Self-Tests table). Only if all CASTs and pre-operational integrity tests passed successfully, the module transitions to the operational state. No operator intervention is required to reach this point. While the module is executing the self-tests, services are not available, and data output (via the data output interface) is inhibited until the tests are successfully completed. If any of the self-tests fails, an error message is returned, and the module transitions to an error state.

10.2 Conditional Self-Tests
Page 50
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
SHA2-224 (A4987)512-bit messageKATCASTModule becomes operational and services are available for useMessage DigestModule initialization
SHA2-256 (A4987)512-bit messageKATCASTModule becomes operational and services are available for useMessage DigestModule initialization
SHA2-384 (A4987)512-bit messageKATCASTModule becomes operational and services are available for useMessage DigestModule initialization
SHA2-512 (A4987)512-bit messageKATCASTModule becomes operational and services are available for useMessage DigestModule initialization
HMAC- SHA-1 (A4987)288-bit keyKATCASTModule becomes operational and services are available for useMessage AuthenticationModule initialization
HMAC- SHA2-224 (A4987)288-bit keyKATCASTModule becomes operational and services are available for useMessage AuthenticationModule initialization
HMAC- SHA2-256 (A4987)288-bit keyKATCASTModule becomes operational andMessage AuthenticationModule initialization
Page 51
Algorithm or TestTest PropertiesTest MethodTest TypeIndicator services are available for useDetailsConditions
HMAC- SHA2-384 (A4987)288-bit keyKATCASTModule becomes operational and services are available for useMessage AuthenticationModule initialization
HMAC- SHA2-512 (A4987)288-bit keyKATCASTModule becomes operational and services are available for useMessage AuthenticationModule initialization
AES-ECB (A4987)128, 192, 256- bit keyKATCASTModule becomes operational and services are available for useEncryptionModule initialization
AES-ECB (A4987)128, 192, 256- bit keyKATCASTModule becomes operational and services are available for useDecryptionModule initialization
AES-ECB (A4994)128, 192, 256- bit keyKATCASTModule becomes operational and services are available for useEncryptionModule initialization
AES-ECB (A4994)128, 192, 256- bit keyKATCASTModule becomes operational and services are available for useDecryptionModule initialization
Page 52
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-CBC (A4987)128, 192, 256- bit keyKATCASTModule becomes operational and services are available for useEncryptionModule initialization
AES-CBC (A4987)128, 192, 256- bit keyKATCASTModule becomes operational and services are available for useDecryptionModule initialization
AES-CBC (A4994)128, 192, 256- bit keyKATCASTModule becomes operational and services are available for useEncryptionModule initialization
AES-CBC (A4994)128, 192, 256- bit keyKATCASTModule becomes operational and services are available for useDecryptionModule initialization
AES-GCM (A4987)128, 192, 256- bit keyKATCASTModule becomes operational and services are available for useEncryptionModule initialization
AES-GCM (A4987)128, 192, 256- bit keyKATCASTModule becomes operational and services are available for useDecryptionModule initialization
AES-GCM (A4994)128, 192, 256- bit keyKATCASTModule becomes operational andEncryptionModule initialization
Page 53
Algorithm or TestTest PropertiesTest MethodTest TypeIndicator services are available for useDetailsConditions
AES-GCM (A4994)128, 192, 256- bit keyKATCASTModule becomes operational and services are available for useDecryptionModule initialization
AES-GCM (A5559)128, 192, 256- bit keyKATCASTModule becomes operational and services are available for useEncryptionModule initialization
AES-GCM (A5559)128, 192, 256- bit keyKATCASTModule becomes operational and services are available for useDecryptionModule initialization
AES-CMAC (A4989)128, 192, 256- bit keyKATCASTModule becomes operational and services are available for useMessage AuthenticationModule initialization
KDF SP800- 108 (A4990)HMAC-SHA2- 256 in counter modeKATCASTModule becomes operational and services are available for useKey DerivationModule initialization
KDA HKDF Sp800-56Cr1 (A4986)SHA2-256KATCASTModule becomes operational and services are available for useKey DerivationModule initialization
Page 54
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
TLS v1.2 KDF RFC7627 (A4987)SHA2-256KATCASTModule becomes operational and services are available for useKey DerivationModule initialization
KDF IKEv2 (A4991)SHA-1, SHA- 256, SHA-384, SHA-512KATCASTModule becomes operational and services are available for useKey DerivationModule initialization
PBKDF (A4987)SHA2-256 with 5 iterations, 128-bit salt and 14 characters passwordKATCASTModule becomes operational and services are available for useKey DerivationModule initialization
Hash DRBG (A4987)SHA-256 without prediction resistanceKATCASTModule becomes operational and services are available for useInstantiate Generate; Reseed Generate (compliant to SP 800- 90Ar1 Section 11.3)Module initialization
KAS-FFC- SSC Sp800- 56Ar3 (A4987)ffdhe2048KATCASTModule becomes operational and services are available for useShared Secret ComputationModule initialization
KAS-ECC- SSC Sp800- 56Ar3 (A4987)P-256KATCASTModule becomes operational and services are available for useShared Secret ComputationModule initialization
RSA SigGen (FIPS186-5) (A4987)PKCS#1 v1.5 with SHA2- 256, SHA2-384,KATCASTModule becomes operational andSignature GenerationModule initialization
Page 55
Algorithm or TestTest Properties SHA2-512, and 2048-bit keyTest MethodTest TypeIndicator services are available for useDetailsConditions
RSA SigVer (FIPS186-5) (A4987)PKCS#1 v1.5 with SHA2- 256, SHA2-384, SHA2-512, and 2048-bit keyKATCASTModule becomes operational and services are available for useSignature VerificationModule initialization
ECDSA SigGen (FIPS186-5) (A4987)SHA2-256 and P-256KATCASTModule becomes operational and services are available for useSignature GenerationModule initialization
ECDSA SigVer (FIPS186-5) (A4987)SHA2-256 and P-256KATCASTModule becomes operational and services are available for useSignature VerificationModule initialization
Safe Primes Key Generation (A4987)N/APCTPCTSuccessful key pair generationPCT according to section 5.6.2.1.4 of [SP800-56Ar3]Key Pair Generation
ECDSA KeyGen (FIPS186-5) (A4987)N/APCTPCTSuccessful key pair generationPCT according to section 5.6.2.1.4 of [SP800-56Ar3]Key Pair Generation
ECDSA KeyGen (FIPS186-5) (A4987)SHA-256PCTPCTSuccessful key pair generationSignature Generation and Signature VerificationKey Pair Generation
RSA KeyGen (FIPS186-5) (A4987)PKCS#1 v1.5 with SHA-256PCTPCTSuccessful key pair generationSignature Generation and Signature VerificationKey Pair Generation

Table 22: Conditional Self-Tests

Page 56
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2-256 (A4987)Message authenticationSW/FW IntegrityOn demandManually
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
SHA-1 (A4987)KATCASTOn demandManually
SHA2-224 (A4987)KATCASTOn demandManually
SHA2-256 (A4987)KATCASTOn demandManually
SHA2-384 (A4987)KATCASTOn demandManually
SHA2-512 (A4987)KATCASTOn demandManually
HMAC-SHA-1 (A4987)KATCASTOn demandManually
HMAC-SHA2-224 (A4987)KATCASTOn demandManually
HMAC-SHA2-256 (A4987)KATCASTOn demandManually
HMAC-SHA2-384 (A4987)KATCASTOn demandManually
HMAC-SHA2-512 (A4987)KATCASTOn demandManually
AES-ECB (A4987)KATCASTOn demandManually

The module performs self-tests on all FIPS approved cryptographic algorithms as part of the approved services supported in the approved mode of operation, using the tests shown in the Conditional Self-Tests table above. Upon generation of a key pair, the module will perform a pair-wise consistency test (PCT) as shown in the table above, which provides some assurance that the generated key pair is well formed. For DH and EC key pairs, these tests consist of the PCT described in Section 5.6.2.1.4 of SP 800-56Ar3. For RSA and EC key pairs, this test consists of a signature generation and a signature verification operation. Note that two PCTs are performed for EC key pairs.

10.3 Periodic Self-Test Information

Table 23: Pre-Operational Periodic Information

Page 57
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-ECB (A4987)KATCASTOn demandManually
AES-ECB (A4994)KATCASTOn demandManually
AES-ECB (A4994)KATCASTOn demandManually
AES-CBC (A4987)KATCASTOn demandManually
AES-CBC (A4987)KATCASTOn demandManually
AES-CBC (A4994)KATCASTOn demandManually
AES-CBC (A4994)KATCASTOn demandManually
AES-GCM (A4987)KATCASTOn demandManually
AES-GCM (A4987)KATCASTOn demandManually
AES-GCM (A4994)KATCASTOn demandManually
AES-GCM (A4994)KATCASTOn demandManually
AES-GCM (A5559)KATCASTOn demandManually
AES-GCM (A5559)KATCASTOn demandManually
AES-CMAC (A4989)KATCASTOn demandManually
KDF SP800-108 (A4990)KATCASTOn demandManually
KDA HKDF Sp800- 56Cr1 (A4986)KATCASTOn demandManually
TLS v1.2 KDF RFC7627 (A4987)KATCASTOn demandManually
KDF IKEv2 (A4991)KATCASTOn demandManually
PBKDF (A4987)KATCASTOn demandManually
Hash DRBG (A4987)KATCASTOn demandManually
Page 58
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
KAS-FFC-SSC Sp800-56Ar3 (A4987)KATCASTOn demandManually
KAS-ECC-SSC Sp800-56Ar3 (A4987)KATCASTOn demandManually
RSA SigGen (FIPS186-5) (A4987)KATCASTOn demandManually
RSA SigVer (FIPS186-5) (A4987)KATCASTOn demandManually
ECDSA SigGen (FIPS186-5) (A4987)KATCASTOn demandManually
ECDSA SigVer (FIPS186-5) (A4987)KATCASTOn demandManually
Safe Primes Key Generation (A4987)PCTPCTOn demandManually
ECDSA KeyGen (FIPS186-5) (A4987)PCTPCTOn demandManually
ECDSA KeyGen (FIPS186-5) (A4987)PCTPCTOn demandManually
RSA KeyGen (FIPS186-5) (A4987)PCTPCTOn demandManually

Table 24: Conditional Periodic Information

Page 59
NameDescriptionConditionsRecovery MethodIndicator
Power- On ErrorAn error occurred during the self-tests executed on power-onSoftware integrity test failure or CAST failureRestart of the moduleModule will not load
PCT ErrorAn error occurred during a PCTPCT failureRestart of the moduleModule stops functioning (sftk_fatalError is set to TRUE)
10.4 Error States

Table 25: Error States In any error state, the output interface is inhibited, and the module accepts no more inputs or requests.

10.5 Operator Initiation of Self-Tests

The software integrity tests and CASTs can be invoked on demand by unloading and subsequently reinitializing the module. The PCTs can be invoked on demand by requesting the Key Pair Generation service.

Page 60
11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

The module is distributed within the following RPM packages for each of the tested operational environments:

11.2 Administrator Guidance

The version of the RPMs containing the FIPS validated Module is stated in section 11.1. The RPM packages forming the Module can be installed by standard tools recommended for the installation of RPM packages on a Red Hat Enterprise Linux system (for example, dnf, rpm, and the RHN remote management tool). All RPM packages are signed with the Red Hat build key, which is an RSA 4096-bit key using SHA-256 signatures. The signature is automatically verified upon installation of the RPM package. If the signature cannot be validated, the RPM tool rejects the installation of the package. In such a case, the Crypto Officer is requested to obtain a new copy of the module's RPMs from Red Hat.

11.3 Non-Administrator Guidance

There is no non-administrator guidance.

Page 61
11.4 Design and Rules
11.5 Maintenance Requirements

There are no maintenance requirements.

11.6 End of Life

As the module does not persistently store SSPs, secure sanitization of the module consists of unloading the module. This will zeroize all SSPs in volatile memory. Then, if desired, the nss-softokn-3.90.0-6.el9_2 and nsssoftokn-freebl-3.90.0-6.el9_2 RPM packages can be uninstalled from the RHEL 9 systems.

Page 62
12 Mitigation of Other Attacks
12.1 Attack List

Timing attacks on RSA