All modules
CMVP Validated Module · FIPS 140-3 Security Policy

OpenSSL Cryptographic Module

Certificate#5023StandardFIPS 140-3Level1TypeSoftwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorF5, Inc.
Medium review priority  ·  no TCB surface named  ·  OpenSSL upstream has published 39 CVEs since this module's initial validation  ·  last validated 13 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date6/7/2030
CaveatWhen operated in approved mode, installed, initialized and configured as specified in Section 11 of the Security Policy. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs
VendorF5, Inc.

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for OpenSSL Cryptographic Module
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Recovery<br/>upgrade</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>status output<br/>UnAuth</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>SSH<br/>HTTPS</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for OpenSSL Cryptographic Module
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Recovery<br/>upgrade</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>status output<br/>UnAuth</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>SSH<br/>HTTPS</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

F5, Inc. OpenSSL Cryptographic Module Prepared by: atsec information security corporation

4516 Seton Center Parkway, Suite 250

Austin, TX 78759 www.atsec.com

Page 3
Table of Contents
#SectionPage
Page 5
List of Tables
ItemPage
Table : Security Levels7
Table : Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets)9
Table : Tested Operational Environments - Software, Firmware, Hybrid9
Table : Modes List and Description10
Table : Approved Algorithms12
Table : Vendor-Affirmed Algorithms12
Table : Non-Approved, Allowed Algorithms with No Security Claimed12
Table : Non-Approved, Not Allowed Algorithms14
Table : Security Function Implementations16
Table : Entropy Certificates17
Table : Entropy Sources18
Table : Ports and Interfaces20
Table : Roles21
Table : Approved Services26
Table : Non-Approved Services28
Table : Storage Areas33
Table : SSP Input-Output Methods33
Table : SSP Zeroization Methods33
Table : SSP Table 137
Table : SSP Table 238
Table : Pre-Operational Self-Tests39
Table : Conditional Self-Tests41
Table : Pre-Operational Periodic Information41
Table : Conditional Periodic Information42
Table : Error States42
Figure 1: Block Diagram8
Page 6

F5® is Registered trademarks of F5, Inc. Intel® Xeon® and Intel® Atom® processors are Registered trademarks of Intel Corporation. ____________________________________________________________________________________________________________________

Page 7
SectionTitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication1
5Software/Firmware security1
6Operational environment1
7Physical securityN/A
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacksN/A
Overall Level1
1.1 Overview

This document is the non-proprietary FIPS 140-3 Security Policy that contains the security rules under which the OpenSSL Cryptographic Module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for an Overall

1.2 Security Levels

Table 1: Security Levels ____________________________________________________________________________________________________________________ © 2025 F5, Inc.

Page 8
2 Cryptographic Module Specification
2.1 Description

Purpose and Use: The OpenSSL Cryptographic Module (hereafter referred to as “the module”) is a cryptographic library offering various cryptographic mechanisms to be used by OpenSSL application running on F5 VELOS system controller and blade. The module provides cryptographic services to applications through an Application Program Interface (API). The module also interacts with the underlying operating system via system calls. Module Type: Software Module Embodiment: MultiChipStand Cryptographic Boundary: The software block diagram Figure 1 shows the module, its interfaces with the operational environment and the delimitation of its cryptographic boundary with bold black perimeter. The software components of the cryptographic module are listed in Table - Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets). Figure 1: Block Diagram ____________________________________________________________________________________________________________________ © 2025 F5, Inc.

Page 9
Package or File NameSoftware/ Firmware VersionFeaturesIntegrity Test
libcrypto.so.1.0.2zc and .libcrypto.so.1.0.2zc.hmac1.0.2zc-fipsN/AHMAC-SHA2-256
Operating SystemHardware PlatformProcessorsPAA/PAIHypervisor or Host OSVersion(s)
F5OS-C 1.6.0VELOS Controller CX410Intel Atom C3758 Denverton-NSYesN/A1.0.2zc-fips
F5OS-C 1.6.0VELOS Controller CX410Intel Atom C3758 Denverton-NSNoN/A1.0.2zc-fips
F5OS-C 1.6.0VELOS Blade BX110Intel Xeon D-2177NT Skylake-DYesN/A1.0.2zc-fips
F5OS-C 1.6.0VELOS Blade BX110Intel Xeon D-2177NT Skylake-DNoN/A1.0.2zc-fips
Mode NameDescriptionTypeStatus Indicator
Approved modeOnly approved security functions or vendor affirmedApprovedThe status output from the FIPS_set_indicator_status service call is provided. To read this indicator, the calling application must register a callback function using `FIPS_register_indicator_callback'. The

Tested Operational Environment’s Physical Perimeter (TOEPP): The module is aimed to run on a generalpurpose computer; the physical perimeter is the surface of the case of the target platform, as shown with orange dotted lines in the diagram Figure 1. The components of the TOEPP are listed in Table - Tested Operational Environments - Software, Firmware, Hybrid. The entropy source located within the module’s physical perimeter is outside of the module’s cryptographic boundary (see Figure 1).

2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification

2.3 Excluded Components
2.4 Modes of Operation

Modes List and Description: ____________________________________________________________________________________________________________________ © 2025 F5, Inc.

Page 10
Mode NameDescription security functions can be used.TypeStatus Indicator callback function should take the input of the form "char *" which is the form of the indicator being output by the module.
Non- Approved modeOnly non-approved security functions can be usedNon- ApprovedNo service indicator
AlgorithmCAVP CertPropertiesReference
AES-CBCA4782Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBCA4783Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CTRA4782Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA4782Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA4783Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-GCMA4782Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GCMA4783Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GMACA4782Direction - Decrypt, Encrypt IV Generation - InternalSP 800-38D

Table 4: Modes List and Description Mode Change Instructions and Status: The module enters the approved mode after pre-operational self-tests succeed. The module automatically switches between the approved and non-approved modes depending on the services requested by the operator. The status indicator of the mode of operation is equivalent to the indicator of the service that was requested.

2.5 Algorithms
Page 11
AlgorithmCAVP CertPropertiesReference
IV Generation Mode - 8.2.1 Key Length - 128, 192, 256
AES-GMACA4783Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
Counter DRBGA4782Prediction Resistance - No, Yes Mode - AES-256 Derivation Function Enabled - No, YesSP 800-90A Rev. 1
Counter DRBGA4783Prediction Resistance - No Mode - AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
ECDSA KeyGen (FIPS186- 4)A4782Curve - P-256, P-384FIPS 186-4
ECDSA KeyVer (FIPS186-4)A4782Curve - P-256, P-384FIPS 186-4
ECDSA SigGen (FIPS186-4)A4782Component - No Curve - P-256, P-384FIPS 186-4
ECDSA SigVer (FIPS186-4)A4782Component - No Curve - P-256, P-384FIPS 186-4
HMAC-SHA-1A4782Key Length - Key Length: 8, 16, 64, 128, 1024FIPS 198-1
HMAC-SHA-1A4783Key Length - Key Length: 8, 16, 64, 128, 1024FIPS 198-1
HMAC-SHA2-256A4782Key Length - Key Length: 8, 16, 64, 128, 1024FIPS 198-1
HMAC-SHA2-384A4782Key Length - Key Length: 8, 16, 64, 128, 1024FIPS 198-1
KAS-ECC-SSC Sp800-56Ar3A4782Domain Parameter Generation Methods - P-256, P-384 Scheme - staticUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KDF SSH (CVL)A4782Cipher - AES-128, AES-256SP 800-135 Rev. 1
KDF TLS (CVL)A4782TLS Version - v1.0/1.1SP 800-135 Rev. 1
RSA KeyGen (FIPS186-4)A4782Key Generation Mode - B.3.3 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Private Key Format - StandardFIPS 186-4
Page 12
AlgorithmCAVP CertPropertiesReference
RSA SigGen (FIPS186-4)A4782Signature Type - PKCS 1.5 Modulo - 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186-4)A4782Signature Type - PKCS 1.5 Modulo - 2048, 3072, 4096FIPS 186-4
SHA-1A4782-FIPS 180-4
SHA-1A4783-FIPS 180-4
SHA2-256A4782-FIPS 180-4
SHA2-384A4782-FIPS 180-4
TLS v1.2 KDF RFC7627 (CVL)A4782-SP 800-135 Rev. 1
NamePropertiesImplementationReference
Cryptographic Key Generation (CKG)Key Type:AsymmetricN/ARandom bit strings required for generating the cryptographic keys is compliant with section 4 example 1 of SP800-133r2
NameCaveatUse and Function
MD5Allowed per IG 2.4.AMessage digest used in TLS 1.0 / 1.1 KDF only

Table 5: Approved Algorithms There are algorithms, modes, and key/moduli sizes that have been CAVP-tested but are not used by any approved service of the module. Only the algorithms, modes/methods, and key lengths/curves/moduli shown in this table are used by an approved service of the module. Vendor-Affirmed Algorithms: Table 6: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: N/A for this module. The module does not implement any Non-Approved Allowed algorithms in the Approved mode of operation. Non-Approved, Allowed Algorithms with No Security Claimed: Table 7: Non-Approved, Allowed Algorithms with No Security Claimed Non-Approved, Not Allowed Algorithms: ____________________________________________________________________________________________________________________ © 2025 F5, Inc.

Page 13
NameUse and Function
AES with OFB, CCM, CFB, XTS, KW modesSymmetric encryption and decryption
Blowfish, Camellia, CAST5, DES, IDEA, RC2, RC4, SEED, SM2, SM4, Triple-DESSymmetric encryption and decryption
SHA2-224, SHA2-512, SM3, MD4, MD5 (outside of TLS), MDC2, RIPEMD, WhirlpoolMessage digest
HMAC-SHA2-224, HMAC-SHA2-512, AES CMAC, Triple-DES CMACMessage authentication
PKCS #1 v1.5 scheme with 1024 and greater than 4096 up to 16384 modulus, for all SHA sizesRSA signature generation and verification
Probabilistic Signature Scheme (PSS), ANSI X9.31 schemesRSA signature generation and verification
PKCS #1 v1.5 scheme with modulus size 2048, 3072, 4096 bits with SHA-1, SHA2-224, SHA2-512RSA signature generation
PKCS #1 v1.5 scheme with modulus size 2048, 3072, 4096 bits with SHA2-224, SHA2-512RSA signature verification
ECDSA with P-224, P-521ECDSA key generation / verification
ECDSA with curves P-256, P-384 with SHA-1 SHA2-224, SHA2- 512ECDSA signature generation / verification
ECDSA using SM2Digital signature generation and verification
RSA with modulus sizes up to 16384 bitsRSA encrypt / decrypt
DSA with all key and SHA sizesDSA domain parameter generation, domain parameter verification, key pair generation, signature generation and verification
HMAC_DRBG and Hash_DRBG for all SHA sizesRandom number generation
CTR_DRBG with AES-128, AES-192Random number generation
ANSI X9.31 RNGRandom number generation
Diffie-HellmanShared secret computation
EC Diffie-Hellman Ephemeral Unified with curves other than P- 256, P-384, without KDF. EC Diffie-Hellman without KDF or using onePassDH / StaticUnified schemesShared secret computation
Key Derivation function in the context of TLS using SHA2-224 / SHA2-512TLS KDF
Key Derivation function in the context of SSH using SHA-1 / SHA2-224 / SHA2-512SSH KDF
Page 14
NameUse and Function
PKCS #1 v1.5 with keys other than 2048 / 3072 / 4096-bit using SHA2-256, SHA2-384RSA signature generation and verification
NameTypeDescriptionPropertiesAlgorithms
EC Diffie-Hellman Shared Secret ComputationKAS-SSC[SP800-56ARev3] Shared Secret Computation used in Key Agreement Scheme (KAS) IG D.F scenario 2 (path 1)Curves:P-256, P-384 with strength 128 and 192-bitsKAS-ECC-SSC Sp800-56Ar3: (A4782)
AES-Key WrappingKTS-WrapFIPS [197, SP800- 38F],IG D.G. key wrapping and unwrapping, in the context of the TLS protocol, are provided by the TLS record layer using an approved authenticated encryption mode.Keys:128 / 256-bit AES key with security strength from 128 and 256- bitsAES-GCM: (A4783, A4782)
Encryption with AESBC-UnAuthEncryption using AESKeys:128, 192, 256 bits with 128-256 bits of key strengthAES-CBC: (A4783, A4782) AES-ECB: (A4783, A4782) AES-CTR: (A4782)
Decryption with AESBC-UnAuthDecryption using AESKeys:128, 192, 256 bits with 128-256 bits of key strengthAES-CBC: (A4783, A4782) AES-ECB: (A4783, A4782) AES-CTR: (A4782)
ECC key pair generationAsymKeyPair- KeyGenECDSA / ECDH key pair generationCurves:P-256 and P- 384 curves with security strength 128 and 192-bitsECDSA KeyGen (FIPS186-4): (A4782)
ECC public key verificationAsymKeyPair- KeyVer[FIPS 186-4] key verification using ECDSA and EC Diffie-Hellman keysCurves:P-256 and P- 384 with strength 128 and 192-bitsECDSA KeyVer (FIPS186-4): (A4782)

Table 8: Non-Approved, Not Allowed Algorithms ____________________________________________________________________________________________________________________ © 2025 F5, Inc.

Page 15
NameTypeDescriptionPropertiesAlgorithms
ECDSA signature generationDigSig-SigGen[FIPS 186-4] Digital signature generation using ECDSACurves:P-256, P- 384 with security strength 128 and 192- bits Hashes:SHA2-256, SHA2-384ECDSA SigGen (FIPS186-4): (A4782) ECDSA / ECDH key pair : P-256, P-384
ECDSA signature verificationDigSig-SigVer[FIPS 186-4] Signature verification using ECDSACurves:P-256 and P- 384 with security strength 128 and 192- bits Hashes:SHA2-256, SHA2-384ECDSA SigVer (FIPS186-4): (A4782)
Message digestSHA[FIPS180-4] Message digest using SHAN/A:N/ASHA-1: (A4783, A4782) SHA2-256: (A4782) SHA2-384: (A4782)
Message authentication generation with HMACMACMessage authentication generation using HMACSHA algorithm:SHA- 1, SHA2-256, SHA2- 384,HMAC-SHA-1: (A4783, A4782) HMAC-SHA2-256: (A4782) HMAC-SHA2-384: (A4782)
Message authentication verification with HMACMACMessage authentication verification using HMACSHA algorithm:SHA- 1, SHA2-256, SHA2- 384,HMAC-SHA-1: (A4783, A4782) HMAC-SHA2-256: (A4782) HMAC-SHA2-384: (A4782)
Key derivationKAS-135KDFKey derivation using protocol KDFDerived keys:112 to 256 bitsKDF SSH: (A4782) KDF TLS: (A4782) TLS v1.2 KDF RFC7627: (A4782)
RSA key generationAsymKeyPair- KeyGen[FIPS 186-4] B.3.3 Probable primes with standard key formatKeys:2048 / 3072 / 4096-bit with security strength from 112 to 150-bitsRSA KeyGen (FIPS186-4): (A4782)
Message authentication generation with AESMACMessage authentication generation using AESKeys:128 /192 / 256 bits with security strength from 128 to 256 bitsAES-GMAC: (A4783, A4782)
Page 16
NameTypeDescriptionPropertiesAlgorithms
Message authentication verification with AESMACMessage authentication verification using AESKeys:128 /192 / 256 bits with security strength from 128 to 256 bitsAES-GMAC: (A4783, A4782)
Authenticated encryption with AES GCMBC-AuthAuthenticated encryption using AESKeys:128 or 256 bits with 128 or 256 bits of strength Authenticated Encryption: Internal IV Mode 8.2.1AES-GCM: (A4783, A4782)
Authenticated decryption with AES GCMBC-AuthAuthenticated decryption using AESKeys:128 or 256 bits with 128 or 256 bits of strength. Authenticated Decryption: External IVAES-GCM: (A4783, A4782)
Random Number GenerationDRBGRandom number generation using DRBG with AES-236 in CTR modeSeed, V and key values :Security strength 256-bitsCounter DRBG: (A4783, A4782)
RSA signature generationDigSig-SigGenPKCS 1.5 digital signature generation using RSA with SHA- 256, SHA-384Keys:2048 / 3072 / 4096-bit with security strength from 112 to 150-bits Hashes:SHA2-256, SHA2-384RSA SigGen (FIPS186-4): (A4782)
RSA signature verificationDigSig-SigVerPKCS 1.5 digital signature verification using RSA with SHA- 256, SHA-384Keys:2048 / 3072 / 4096-bit with security strength from 112 to 150-bits Hashes:SHA2-256, SHA2-384RSA SigVer (FIPS186-4): (A4782)
RSA signature verification (legacy)DigSig-SigVerPKCS 1.5 digital signature verification using RSA with SHA- 1Publications:FIPS 140-3 IG C.M legacy algorithms Keys:2048 / 3072 / 4096-bit with security strength from 112 to 150-bits Hashes: SHA-1RSA SigVer (FIPS186-4): (A4782)

Table 9: Security Function Implementations ____________________________________________________________________________________________________________________ © 2025 F5, Inc.

Page 17
CertVendor
NumberName
E85F5
2.7 Algorithm Specific Information

AES GCM Use: The IV for AES-GCM is constructed in compliance with IG C.H scenario 1a (TLS 1.2) and scenario 1d (SSHv2).

For TLS 1.2, the module offers the AES-GCM implementation and uses the context of Scenario 1 of IG C.H. The module is compliant with SP800-52Rev2 section 3.3.1 and the mechanism for IV generation is compliant with RFC5288. The module does not implement the TLS protocol. The module’s implementation of AES-GCM is used together with an application that runs outside the module’s cryptographic boundary. The design of the TLS protocol implicitly ensures that the counter (the nonce_explicit part of the IV) does not exhaust the maximum number of possible values for a given session key.
For SSHv2, the IV for the module AES-GCM implementation is only used in the context of the AES-GCM mode encryptions. The module is compliant with RFCs 4252, 4253 and 5647. The module does not implement SSH protocol and the module’s implementation of AES-GCM is used together with an application that runs outside the module’s cryptographic boundary. The design of the SSH protocol implicitly ensures that the counter does not exhaust the maximum number of possible values for a given session key and that the no more than 264 -1 ASE-GCM encryptions are performed. When a session is terminated, as new key and a new initial IV shall be derived.
For both TLSv1.2 and SSHv2 protocols, in the event the module’s power is lost and restored, the consuming application must ensure that a new key for use with the AES-GCM key encryption or decryption under this scenario shall be established.

SHA-1 Use: SHA-1 from Message Digest is only approved for non-digital-signature uses (see Table 8 of SP 800-131A rev2). Legacy Use

2.8 RBG and Entropy

Table 10: Entropy Certificates ____________________________________________________________________________________________________________________ © 2025 F5, Inc.

Page 18
NameTypeOperational EnvironmentSample SizeEntropy per SampleConditioning Component
CPU Jitter 3.4.1Non- PhysicalOEs listed in Table 3256 bitsSHA-3 vetted conditioning component. ACVP Cert. A4093

Table 11: Entropy Sources The module entropy source specified in Table Entropy Sources uses jitter variations caused by executing instructions and memory accessed. The operator does not have the ability to modify the F5 entropy source (ES) configuration settings (see details in Public Use Document referenced in section 11.2). The module employs a Deterministic Random Bit Generator (DRBG) based on [SP800-90ARev1] for the generation of random value used in asymmetric keys, and for providing a RNG service to calling applications. The approved DRBG provided by the module is the CTR_DRBG with AES-256. The output of entropy sources provides 256-bits of entropy to seed and reseed SP800-90ARev1 DRBG during initialization (seed) and reseeding (reseed).

2.9 Key Generation

The module implements asymmetric key generation methods according to SP 800-133r2 section 5. The key generation methods are specified in the Security Function Implementations table. The module does not implement symmetric key generation.

2.10 Key Establishment

The module implements SSP agreement, compliant with IG D.F scenario 2 (path 1). Additionally, the module implements SSP transport, compliant with IG D.G. The Key Establishment methods are specified in the Security Function Implementations table.

2.11 Industry Protocols

GCM with internal IV generation in the approved mode is compliant with version 1.2 of the TLS protocol (RFC 5288) and shall only be used in conjunction with the TLS protocol. Additionally, the module implements the TLS 1.2 and SSH key derivation functions for use in the TLS protocol and SSH protocol (RFC 4253 and RFC 6668) respectively. The strength of the derived session key is based on the shared secret and the SHA function used as follows: For deriving session key with 192 bit strength, the TLS/SSH key derivation functions with shared secret based on P-384 curve using SHA-384 should be used. ____________________________________________________________________________________________________________________ © 2025 F5, Inc.

Page 19

For deriving session key with 128 bit strength, • TLS key derivation functions with shared secret based on P-256 curve using SHA-256, SHA-384 or P-

384 curve using SHA-256 should be used.

• SSH key derivation functions with shared secret based on P-256 curve using SHA-1, SHA-256, SHA-

384 or P-384 curve using SHA-1, SHA-256 should be used.

The TLS v1.0 / 1.1 / 1.2 and SSHv2 protocols have not been reviewed or tested by the CAVP or CMVP. ____________________________________________________________________________________________________________________ © 2025 F5, Inc.

Page 20
Physical PortLogical Interface(s)Data That Passes
N/AData InputData inputs are provided in the variables passed in the API and callable service invocations, generally through caller-supplied buffers
N/AData OutputData outputs are provided in the variables passed in the API and callable service invocations, generally through caller-supplied buffers
N/AControl InputControl inputs which control the mode of the module are provided through dedicated parameters.
N/AStatus OutputStatus output is provided in return codes and through messages. Documentation for each API lists possible return codes. A complete list of all return codes returned by the C language APIs within the module is provided in the header files and the API documentation. Messages are also documented in the API documentation.
3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

Table 12: Ports and Interfaces ____________________________________________________________________________________________________________________ © 2025 F5, Inc.

Page 21
NameTypeOperator TypeAuthentication Methods
Crypto OfficerRoleCONone
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
EncryptionExecutes AES- mode encrypt operationAES-ECB, AES- CBC, AES-CTRPlaintext and keyCiphertextEncryption with AESCrypto Officer - AES key : W,E
DecryptionExecutes AES- mode decrypt operationAES-ECB, AES- CBC, AES-CTRCiphertext and keyPlaintextDecryption with AESCrypto Officer - AES key : W,E
Key wrappingExecutes AES- key wrapping or unwrapping operationAES-GCM encrypt / decryptKey wrapping key and key to be wrappedWrapped keyAES-Key WrappingCrypto Officer - AES key : W,E - GCM IV in TLS context: G,W,E - GCM IV in SSH context: G,W,E
Random number generationGenerate Random numberCTR-DRBG- AES-256Number of bitsRandom numbersRandom Number GenerationCrypto Officer - Entropy input string : W,E - DRBG seed : G - DRBG internal state (V and key values) : G
RSA key pair generationGenerate RSA key pairRSA-KEY- GEN-2048, RSA-KEY- GEN-3072,Key sizeKey pairRSA key generationCrypto Officer - RSA private key: G,R
4 Roles, Services, and Authentication

FIPS 140-3 does not require an authentication mechanism for level 1 modules. Therefore, the module does not implement an authentication mechanism for Crypto Officer. The Crypto Officer role is implicitly assumed when accessing all services provided by the module (see Table - Approved Services and Table - Non-Approved Services below).

4.2 Roles
4.3 Approved Services
Page 22
NameDescriptionIndicator RSA-KEY- GEN-4096InputsOutputsSecurity FunctionsSSP Access - RSA public key: G,R
RSA signature generationSign a message with a specified RSA private keyRSA-SIGPrivate key, Message, Hashing algorithmComputed signatureRSA signature generationCrypto Officer - RSA private key: W,E
Authenticated EncryptionAuthenticated EncryptionAES-GCMAES key, plaintextCiphertextAuthenticated encryption with AES GCMCrypto Officer - AES key : W,E - GCM IV in TLS context: G,W,E - GCM IV in SSH context: G,W,E
Authenticated DecryptionAuthenticated DecryptionAES-GCMAES key, ciphertextPlaintextAuthenticated decryption with AES GCMCrypto Officer - AES key : W,E - GCM IV in TLS context: W,E - GCM IV in SSH context: W,E
Message Authentication Generation with AESMAC computationAES-GMACAES key, messageMAC tagMessage authentication generation with AESCrypto Officer - AES key : W,E
Message Authentication Generation with HMACMAC computationMSG-AUTH- HMAC-SHA-1, MSG-AUTH- HMAC-SHA- 256 MSG- AUTH-HMAC- SHA-384HMAC key, messageMAC tagMessage authentication generation with HMACCrypto Officer - HMAC key : W,E
Message Authentication Verification with AESMAC computationAES-GMACAES key, Authenticated message, MAC algorithmMessageMessage authentication verification with AESCrypto Officer - AES key : W,E
Message AuthenticationMAC computationMSG-AUTH- HMAC-SHA-1, MSG-AUTH- HMAC-SHA-HMAC key, Authenticated message,MessageMessage authenticationCrypto Officer - HMAC key : W,E
Page 23
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
Verification with HMAC256 MSG- AUTH-HMAC- SHA-384MAC algorithmverification with HMAC
Message DigestGenerating message digestMESSAGE- DIGEST-SHA-1 MESSAGE- DIGEST-SHA- 256 MESSAGE- DIGEST-SHA- 384MessageMessage digestMessage digestCrypto Officer
ECDSA key pair generationGenerate ECDSA key pairEC-KEYGEN- P-256, EC- KEYGEN-P- 284CurveECDSA key pairECC key pair generationCrypto Officer - ECDSA private key: G,R - ECDSA public key: G,R - EC Diffie- Hellman private key: G,R - EC Diffie- Hellman public key: G,R
ECDSA key pair verificationVerify ECDSA key pairEC-KEY- VERIFY-P-256, EC-KEY- VERIFY-P-384Public keySuccess/ errorECC public key verificationCrypto Officer - ECDSA public key: W - EC Diffie- Hellman public key: W
RSA signature verificationVerify the signature of a message with a specified RSA public key.RSA-VERRSA public key, digital signature, message, Hashing algorithmPass / fail result of digital signature verificationRSA signature verification RSA signature verification (legacy)Crypto Officer - RSA public key: W,E
ECDSA signature generationSign a message with a specified ECDSA private key.ECDSA-SIGN- P-256, ECDSA- SIGN-P-384ECDSA private key, Message, Hashing algorithmComputed signatureECDSA signature generationCrypto Officer - ECDSA private key: W,E
ECDSA signature verificationVerify the signature of a message with a specifiedECDSA- VERIFY-P-256, ECDSA- VERIFY-P-384ECDSA public key, digital signature, message,Digital signature verification resultECDSA signature verificationCrypto Officer - ECDSA public key: W,E
Page 24
NameDescription ECDSA public keyIndicatorInputs Hashing algorithmOutputsSecurity FunctionsSSP Access
EC Diffie- Hellman shared secret computationCalculate a shared secret via the ECDH algorithm.ECDH- COMPUTE- KEY-P-256, ECDH- COMPUTE- KEY-P-384EC public key, EC private keyShared SecretEC Diffie- Hellman Shared Secret ComputationCrypto Officer - EC Diffie- Hellman private key: W - EC Diffie- Hellman shared secret: G,R
Key derivation using TLS pre- primary secretDeriving TLS keysTLS-P-HASH- DERIVATION- SHA-1 TLS-P- HASH- DERIVATION- SHA-256 TLS- P-HASH- DERIVATION SHA-384TLS pre- primary secretTLS primary secretKey derivationCrypto Officer - TLS pre- primary secret : W,E - TLS primary secret: G,R
Key derivation using TLS primary secretDeriving TLS keysTLS-P-HASH- DERIVATION- SHA-1 TLS-P- HASH- DERIVATION- SHA-256 TLS- P-HASH- DERIVATION SHA-384TLS primary secretTLS Derived KeyKey derivationCrypto Officer - TLS primary secret: W,E - TLS derived session key : G,R
Key derivation using SSH shared secretDeriving SSH keysSSH-KEY- HASH- DERIVATION- SHA-256 SSH- KEY-HASH- DERIVATION SHA-384Shared secret, Key lengthSSH derived KeyKey derivationCrypto Officer - SSH derived session key : G,R - SSH shared secret: W,E
Show versionReturn the SW version and the module's nameN/AN/AModule name and versionNoneUnauthenticated Crypto Officer
Show StatusReturn the module statusN/AN/AModule statusNoneUnauthenticated Crypto Officer
Page 25
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
ZeroizationZeroize all non-protected SSPsN/AN/AAll SSPs in the SSPs tableNoneCrypto Officer - AES key : Z - HMAC key : Z - RSA private key: Z - RSA public key: Z - ECDSA private key: Z - ECDSA public key: Z - EC Diffie- Hellman private key: Z - EC Diffie- Hellman public key: Z - EC Diffie- Hellman shared secret: Z - TLS pre- primary secret : Z - TLS primary secret: Z - TLS derived session key : Z - SSH shared secret: Z - SSH derived session key : Z - Entropy input string : Z - DRBG seed : Z - DRBG internal state (V and key values) : Z
Self-testsExecute integrity test. Execute the CASTsIntegrity test, CASTs from sections 10.1 and 10.2N/APass or failEC Diffie- Hellman Shared Secret Computation AES-Key Wrapping Encryption with AES Decryption with AESUnauthenticated Crypto Officer
Page 26
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
ECC key pair generation ECC public key verification ECDSA signature generation ECDSA signature verification Message digest Message authentication generation with HMAC Message authentication verification with HMAC Key derivation RSA key generation Message authentication generation with AES Message authentication verification with AES Authenticated encryption with AES GCM Authenticated decryption with AES GCM Random Number Generation RSA signature generation RSA signature verification

Table 14: Approved Services ____________________________________________________________________________________________________________________ © 2025 F5, Inc.

Page 27
NameDescriptionAlgorithmsRole
Symmetric encryption and decryptionEncryption / decryptionAES with OFB, CCM, CFB, XTS, KW modes Blowfish, Camellia, CAST5, DES, IDEA, RC2, RC4, SEED, SM2, SM4, Triple-DESCrypto Officer
Message digestGenerating message digestSHA2-224, SHA2-512, SM3, MD4, MD5 (outside of TLS), MDC2, RIPEMD, WhirlpoolCrypto Officer
Message authentication code generation and verificationMAC computationHMAC-SHA2-224, HMAC-SHA2-512, AES CMAC, Triple-DES CMACCrypto Officer
RSA key generationGenerating key pairPKCS #1 v1.5 scheme with 1024 and greater than 4096 up to 16384 modulus, for all SHA sizesCrypto Officer
RSA signature generation and verificationGenerating signature, verifying signatureProbabilistic Signature Scheme (PSS), ANSI X9.31 schemes PKCS #1 v1.5 scheme with modulus size 2048, 3072, 4096 bits with SHA-1, SHA2- 224, SHA2-512 PKCS #1 v1.5 scheme with modulus size 2048, 3072, 4096 bits with SHA2-224, SHA2-512 PKCS #1 v1.5 with keys other than 2048 / 3072 / 4096-bit using SHA2-256, SHA2-384Crypto Officer
Key generation / verificationGenerating key pairECDSA with P-224, P-521Crypto Officer
ECDSA signature generation & verificationGenerating signature, verifying signatureECDSA with P-224, P-521 ECDSA with curves P-256, P-384 with SHA- 1 SHA2-224, SHA2-512 ECDSA using SM2Crypto Officer
RSA encrypt / decryptEncryption / decryptionRSA with modulus sizes up to 16384 bitsCrypto Officer

For the above table, the convention below applies when specifying the access permissions (types) that the service has for each SSP. G = Generate: The module generates or derives the SSP. R = Read: The SSP is read from the module (e.g. the SSP is output). W = Write: The SSP is updated, imported, or written to the module. E = Execute: The module uses the SSP in performing a cryptographic operation. Z = Zeroise: The module zeroises the SSP.

4.4 Non-Approved Services
Page 28
NameDescriptionAlgorithmsRole
DSA domain parameter generation, domain parameter verification, key pair generation, signature generation and verificationGenerating key pair, generating signature, verifying signatureDSA with all key and SHA sizesCrypto Officer
Random number generationGenerating deterministic random numberHMAC_DRBG and Hash_DRBG for all SHA sizes CTR_DRBG with AES-128, AES-192 ANSI X9.31 RNGCrypto Officer
Diffie-Hellman shared secret computationCalculate a shared secret via the DH algorithm.Diffie-HellmanCrypto Officer
ECDH shared secret computationCalculating shared secretEC Diffie-Hellman Ephemeral Unified with curves other than P-256, P-384, without KDF. EC Diffie-Hellman without KDF or using onePassDH / StaticUnified schemesCrypto Officer
Key derivationDeriving TLS keys and SSH keysKey Derivation function in the context of TLS using SHA2-224 / SHA2-512 Key Derivation function in the context of SSH using SHA-1 / SHA2-224 / SHA2-512Crypto Officer

Table 15: Non-Approved Services

4.5 External Software/Firmware Loaded
Page 29
5 Software/Firmware Security
5.1 Integrity Techniques

The integrity of the module is verified by comparing a HMAC value calculated at run time on the libcrypto.so.1.0.2zc file, with the HMAC-SHA2-256 value stored in the module file .libcrypto.so.1.0.2zc.hmac that was computed at build time. The HMAC key used for integrity verification is 256 bits in length and is stored as part of the module binary. Integrity tests are performed as part of the Pre-Operational Self-Tests.

5.2 Initiate on Demand

The on-demand integrity test is performed as part of the Pre-Operational Self-Tests by reloading the module. ____________________________________________________________________________________________________________________ © 2025 F5, Inc.

Page 30
6 Operational Environment
6.1 Operational Environment Type and Requirements

F5OS-C consists of a Linux based operating system customized for performance that runs directly on the hardware. Type of Operational Environment: Modifiable How Requirements are Satisfied: The module shall be installed as stated in Section 11.1. If properly installed, the operating system provides process isolation and memory protection mechanisms that ensure appropriate separation for memory access among the processes on the system. Each process has control over its own data, and uncontrolled access to the data of other processes is prevented.

6.2 Configuration Settings and Restrictions

The module runs on a F5OS-C 1.6.0 operating system executing on the hardware and hypervisor specified in Table OEs. The module should be installed as stated in section 11. The operator should confirm that the module is installed correctly by section 11.2. ____________________________________________________________________________________________________________________ © 2025 F5, Inc.

Page 31
7 Physical Security

The module is a software and therefore this section is Not Applicable (N/A). ____________________________________________________________________________________________________________________ © 2025 F5, Inc.

Page 32
8 Non-Invasive Security

Per IG 12.A: Until requirements of SP 800-140F are defined, non-invasive mechanisms fall under ISO / IEC 19790:2012 Section 7.12 Mitigation of other attacks. ____________________________________________________________________________________________________________________ © 2025 F5, Inc.

Page 33
Storage Area NameDescriptionPersistence Type
RAMThe memory occupied by SSPs is allocated by regular memory allocation operating system calls.Dynamic
NameFromToFormat TypeDistribution TypeEntry TypeSFI or Algorithm
API output parametersCM SoftwareApp via TOEPP PathPlaintextManualElectronic
API input parametersApp via TOEPP PathCM SoftwarePlaintextManualElectronic
Zeroization MethodDescriptionRationaleOperator Initiation
Free Cipher HandleZeroizes the SSPs contained within the cipher handleThe destruction functions overwrite the memory occupied by keys with "zeros" and deallocate the memory with the regular memory deallocation operating system call.The application is responsible for calling the appropriate destruction functions provided in the module's API: EVP_CIPHER_CTX_cleanup, HMAC_CTX_cleanup(), FIPS_rsa_free(), EC_KEY_free(), EC_POINT_free(), OPENSSL_cleanse, OPENSSL_free, FIPS_drbg_uninstantiate
Module ResetDe-allocates the volatile memory used to store SSPsVolatile memory used by the module is overwritten within nanoseconds when power is removed.By unloading and reloading the module.
9 Sensitive Security Parameters Management
9.1 Storage Areas
9.2 SSP Input-Output Methods

Table 17: SSP Input-Output Methods The module does not support manual SSP entry or intermediate key generation output. The SSPs are provided same operational environment. This is allowed by [FIPS 140-3_IG] IG 9.5.A Table 1, according to the “CM

9.3 SSP Zeroization Methods

Table 18: SSP Zeroization Methods ____________________________________________________________________________________________________________________ © 2025 F5, Inc.

Page 34
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
AES keyAES key used for encryption, decryption, and computing MAC tagsKey length: 128 to 256-bits - 128 to 256-bitsSymmetric - CSPAES-Key Wrapping Encryption with AES Decryption with AES Message authentication generation with AES Message authentication verification with AES Authenticated encryption with AES GCM Authenticated decryption with AES GCM
HMAC keyHMAC key for Message Authentication Generation and VerificationKey length: 112 to 192-bits - 112 to 192-bitsSymmetric - CSPMessage authentication generation with HMAC Message authentication verification with HMAC
RSA private keyRSA private key used for RSA key generation, signature generationModulus N: 2048, 3072 and 4096- bits - 112 to 150- bitsAsymmetric - CSPRSA key generationRSA signature generation
RSA public keyRSA public key used for RSA key generation, signature verificationModulus N: 2048, 3072 and 4096- bits - 112 to 150- bitsAsymmetric - PSPRSA key generationRSA signature verification
ECDSA private keyECDSA private key used for EC key generation, key verification,Curve size: P- 256, P-384 - 128 and 192-bitsAsymmetric - CSPECC key pair generationECDSA signature generation
9.4 SSPs
Page 35
NameDescription signature generation, shared secret computationSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
ECDSA public keyECDSA public key used for EC key generation, key verification, signature verification, shared secret computationCurve size: P- 256, P-384 - 128 and 192-bitsAsymmetric - PSPECC key pair generationECC public key verification ECDSA signature verification
EC Diffie- Hellman private keyEC Diffie- Hellman private key used for EC key generation, key verification, signature generation, shared secret computationCurve size: P- 256, P-384 - 128 and 192-bitsAsymmetric - CSPECC key pair generationEC Diffie- Hellman Shared Secret Computation ECC public key verification
EC Diffie- Hellman public keyEC Diffie- Hellman public key used for EC key generation, key verification, signature generation, shared secret computationCurve size: P- 256, P-384 - 128 and 192-bitsAsymmetric - PSPECC key pair generationEC Diffie- Hellman Shared Secret Computation ECC public key verification
EC Diffie- Hellman shared secretEC Diffie- Hellman shared secret generated by KAS-ECC-SSCCurve size: P- 256, P-384 - 128 and 192-bitsAsymmetric - CSPEC Diffie- Hellman Shared Secret ComputationEC Diffie- Hellman Shared Secret Computation
TLS pre- primary secretTLS pre-primary secret used for deriving the TLS primary secretECDH Curve size:: P-256, P- 384 - 128 or 192- bitsAsymmetric - CSPKey derivation
TLS primary secretTLS primary secret used for deriving the TLS derived key384-bits - 128 or 192-bitsSymmetric - CSPKey derivationKey derivation
Page 36
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
TLS derived session keyTLS derived session key from TLS primary secretKey length: 128 and 256-bits (AES); HMAC_SHA2- 256, HMAC- SHA2-384 - 128 or 192-bitsSymmetric - CSPKey derivationKey derivation
SSH shared secretSSH shared secret used for deriving the SSH keyCurve size: P- 256, P-384 - 128 or 192-bitsAsymmetric - CSPKey derivation
SSH derived session keySSH derived session keyKey length: 128 and 256-bits (AES); HMAC_SHA1, HMAC-SHA2- 256 - 128 or 192- bitsSymmetric - CSPKey derivationKey derivation
Entropy input stringEntropy input string used to seed the DRBG256 bits - 256 bitsRandom number generation - CSPRandom Number Generation
DRBG seedDRBG seed derived from entropy input as defined in SP 800- 90Ar1256 bits - 256 bitsRandom number generation - CSPRandom Number GenerationRandom Number Generation
DRBG internal state (V and key values)Internal state of CTR_DRBG256 bits - 256 bitsRandom number generation - CSPRandom Number GenerationRandom Number Generation
GCM IV in TLS contextInternal IV generated for GCM to be used for TLS compliant with RFC528896 bits - 96 bitsIV - PSPSP 800-38D section 8.2.1 Deterministic generationAES-Key Wrapping Authenticated encryption with AES GCM Authenticated decryption with AES GCM
GCM IV in SSH contextInternal IV generated for GCM to be used96 bits - 96 bitsIV - PSPSP 800-38D section 8.2.1AES-Key Wrapping Authenticated encryption
Page 37

Name

Description for SSH compliant with RFC5647

Size - Strength

Type - Category

Generated By Deterministic generation

Established By

Used By with AES GCM Authenticated decryption with AES GCM

NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
AES keyAPI output parameters API input parametersRAM:PlaintextFrom handle creation until freeing the cipher handleFree Cipher Handle Module Reset
HMAC keyAPI input parametersRAM:PlaintextFrom handle creation until freeing the cipher handleFree Cipher Handle Module Reset
RSA private keyAPI output parameters API input parametersRAM:PlaintextFrom handle creation until freeing the cipher handleFree Cipher Handle Module ResetRSA public key:Paired With
RSA public keyAPI output parameters API input parametersRAM:PlaintextFrom handle creation until freeing the cipher handleFree Cipher Handle Module ResetRSA private key:Paired With
ECDSA private keyAPI output parameters API input parametersRAM:PlaintextFrom handle creation until freeing the cipher handleFree Cipher Handle Module ResetECDSA public key:Paired With
ECDSA public keyAPI output parameters API input parametersRAM:PlaintextFrom handle creation until freeing the cipher handleFree Cipher Handle Module ResetECDSA private key:Paired With
EC Diffie- Hellman private keyAPI output parameters API input parametersRAM:PlaintextFrom handle creation until freeing the cipher handleFree Cipher Handle Module ResetEC Diffie-Hellman public key:Paired With
EC Diffie- Hellman public keyAPI output parameters API input parametersRAM:PlaintextFrom handle creation until freeing the cipher handleFree Cipher Handle Module ResetEC Diffie-Hellman private key:Paired With

Table 19: SSP Table 1 ____________________________________________________________________________________________________________________ © 2025 F5, Inc.

Page 38
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
EC Diffie- Hellman shared secretAPI output parametersRAM:PlaintextFrom handle creation until freeing the cipher handleFree Cipher Handle Module Reset
TLS pre-primary secretAPI input parametersRAM:PlaintextFrom handle creation until freeing the cipher handleFree Cipher Handle Module ResetTLS primary secret:Used With
TLS primary secretAPI output parameters API input parametersRAM:PlaintextFrom handle creation until freeing the cipher handleFree Cipher Handle Module ResetTLS pre-primary secret :Used With
TLS derived session keyAPI output parametersRAM:PlaintextFrom handle creation until freeing the cipher handleFree Cipher Handle Module ResetTLS primary secret:Derived From
SSH shared secretAPI input parametersRAM:PlaintextFrom handle creation until freeing the cipher handleFree Cipher Handle Module ResetSSH derived session key :Used With
SSH derived session keyAPI output parametersRAM:PlaintextFrom handle creation until freeing the cipher handleFree Cipher Handle Module ResetSSH shared secret:Derived From
Entropy input stringRAM:PlaintextStorage duration during the usage of the CSPModule ResetDRBG seed :Used With
DRBG seedRAM:PlaintextStorage duration during the usage of the CSPFree Cipher Handle Module ResetDRBG internal state (V and key values) :Used With
DRBG internal state (V and key values)RAM:PlaintextStorage duration during the usage of the CSPFree Cipher Handle Module ResetDRBG seed :Used With
GCM IV in TLS contextAPI output parameters API input parametersRAM:PlaintextFrom handle creation until freeing the cipher handleFree Cipher Handle
GCM IV in SSH contextAPI output parameters API input parametersRAM:PlaintextFrom handle creation until freeing the cipher handleFree Cipher Handle

Table 20: SSP Table 2 ____________________________________________________________________________________________________________________ © 2025 F5, Inc.

Page 39
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
HMAC- SHA2-256 (A4782)HMAC key: 256- bitsMessage AuthenticationSW/FW IntegrityModule becomes operationalIntegrity of the module is verified by comparing the HMAC-SHA2-256 value calculated at runtime with the HMAC- SHA2-256 value stored in the module crypto boundary that was computed at build time
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
Counter DRBG (A4783)AES-256 in CTR mode, with derivation function, prediction resistance disabledKATCASTModule becomes operationalSP800-90ARev1 section 11.3 health testsTest run during pre-operational self-test
AES-CBC (A4783)128-bit keyKATCASTModule becomes operationalEncryption / decryptionTest run during pre-operational self-test
AES-GCM (A4783)128-bit keyKATCASTModule becomes operationalEncryption / decryptionTest run during pre-operational self-test
RSA SigGen (FIPS186-4) (A4782)2048 bit key and SHA2- 256KATCASTModule becomes operationalSignature generationTest run during pre-operational self-test
RSA SigVer (FIPS186-4) (A4782)2048 bit key and SHA2- 256KATCASTModule becomes operationalSignature verificationTest run during pre-operational self-test
RSA KeyGen (FIPS186-4) (A4782)4096 bit key and SHA2- 256PCTPCTAsymmetric algorithm is performedCalculation and verification of a digital signatureKey generation

Pre-operational self-tests are performed automatically when the module is loaded into memory. While the module is executing the pre-operational self-tests, services are not available, and input and output are inhibited. The module does not return control to the calling application until the tests are completed. On services are available.

10.2 Conditional Self-Tests
Page 40
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
ECDSA SigGen (FIPS186-4) (A4782)P-256 and SHA2-256KATCASTModule becomes operationalSignature generationTest run during pre-operational self-test
ECDSA SigVer (FIPS186-4) (A4782)P-256 and SHA2-256KATCASTModule becomes operationalSignature verificationTest run during pre-operational self-test
ECDSA KeyGen (FIPS186-4) (A4782)P-256 and SHA2-256PCTPCTAsymmetric algorithm is performedCalculation and verification of a digital signatureKey generation
KAS-ECC-SSC Sp800-56Ar3 (A4782)P-256KATCASTModule becomes operationalShared secret computationTest run during pre-operational self-test
HMAC-SHA- 1 (A4782)HMAC-SHA-1KATCASTModule becomes operationalMACTest run during pre-operational self-test
HMAC- SHA2-256 (A4782)HMAC-SHA2-256KATCASTModule becomes operationalMACTest run during pre-operational self-test
TLS v1.2 KDF RFC7627 (A4782)SHA-256KATCASTModule becomes operationalKey derivation used in the TLS protocolTest run during pre-operational self-test
KDF TLS (A4782)SHA-256KATCASTModule becomes operationalKey derivation used in the TLS protocolTest run during pre-operational self-test
KDF SSH (A4782)SHA-256KATCASTModule becomes operationalKey derivation used in the SSH protocolTest run during pre-operational self-test
HMAC-SHA- 1 (A4783)HMAC-SHA-1KATCASTModule becomes operationalMACTest run during pre-operational self-test
HMAC- SHA2-384 (A4782)HMAC-SHA-384KATCASTModule becomes operationalMACTest run during pre-operational self-test
AES-CBC (A4782)128-bit keyKATCASTModule becomes operationalEncryption / decryptionTest run during pre-operational self-test
Page 41
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-GCM (A4782)128-bit keyKATCASTModule becomes operationalEncryption / decryptionTest run during pre-operational self-test
Counter DRBG (A4782)AES-256 in CTR mode, with / without derivation function, prediction resistance enabled and disabledKATCASTModule becomes operationalSP800-90ARev1 section 11.3 health testsTest run during pre-operational self-test
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2-256 (A4782)Message AuthenticationSW/FW IntegrityDetermined by the operatorModule reload
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
Counter DRBG (A4783)KATCASTOn DemandManually
AES-CBC (A4783)KATCASTOn DemandManually
AES-GCM (A4783)KATCASTOn DemandManually
RSA SigGen (FIPS186-4) (A4782)KATCASTOn DemandManually
RSA SigVer (FIPS186-4) (A4782)KATCASTOn DemandManually
RSA KeyGen (FIPS186-4) (A4782)PCTPCTOn DemandManually
ECDSA SigGen (FIPS186-4) (A4782)KATCASTOn DemandManually
ECDSA SigVer (FIPS186-4) (A4782)KATCASTOn DemandManually
ECDSA KeyGen (FIPS186-4) (A4782)PCTPCTOn DemandManually

Table 22: Conditional Self-Tests Table 23: Pre-Operational Periodic Information ____________________________________________________________________________________________________________________ © 2025 F5, Inc.

Page 42
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
KAS-ECC-SSC Sp800-56Ar3 (A4782)KATCASTOn DemandManually
HMAC-SHA-1 (A4782)KATCASTOn DemandManually
HMAC-SHA2-256 (A4782)KATCASTOn DemandManually
TLS v1.2 KDF RFC7627 (A4782)KATCASTOn DemandManually
KDF TLS (A4782)KATCASTOn DemandManually
KDF SSH (A4782)KATCASTOn DemandManually
HMAC-SHA-1 (A4783)KATCASTOn DemandManually
HMAC-SHA2-384 (A4782)KATCASTOn DemandManually
AES-CBC (A4782)KATCASTOn DemandManually
AES-GCM (A4782)KATCASTOn DemandManually
Counter DRBG (A4782)KATCASTOn DemandManually
NameDescriptionConditionsRecovery MethodIndicator
Halt ErrorModule is no longer operational. The data output is inhibited.HMAC-SHA2-256 KAT failure or HMAC-SHA2-256 integrity test failure Failure of any of the CASTs Failure of any of the PCTsThe module must be re- loadedModule will not load, Error message related to the crypto function listed in Table 18 and the flag 'fips_selftest_fail' is set.Error message a PCT failure for RSA, ECDH or ECDSA pairwise consistency test and the flag 'fips_selftest_fail' is set.

Table 24: Conditional Periodic Information

10.4 Error States

Table 25: Error States ____________________________________________________________________________________________________________________ © 2025 F5, Inc.

Page 43
10.5 Operator Initiation of Self-Tests

The on demand self-tests can be invoked by unloading and subsequently reloading the module. This service performs the same cryptographic algorithm tests executed during pre-operational self-test and module loading. During the execution of the on demand self-tests, crypto services are not available, and no data output or input is possible. ____________________________________________________________________________________________________________________ © 2025 F5, Inc.

Page 44
11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

Startup Procedures: Before the Crypto Officer can configure and use the F5OS-C software on VELOS platforms, the Crypto Officer must license the VELOS system. For automatic VELOS system licensing, the system needs to be able to connect to the F5 licensing server either through the internet or another means of networking. You need to have the Base Registration Key (five sets of characters separated by hyphens) provided by F5, and any add-on keys (two sets of 7 characters separated by a hyphen) that you have purchased. The Base Registration Key with associated add-on keys are pre-installed on a new VELOS system. The activation of the VELOS system license is described in License the system automatically from the CLI (https://techdocs.f5.com/en-us/velos-16-0/velos-systems-installation-upgrade/title-install-before-install-upgrade.html#license-chassis-cli). Installation Process: The Crypto Officer downloads the F5OS-C software image files (ie the module i.e. 1.0.2zc-fips binary and its integrity check file) and deploy it. The VELOS systems (controller or blade platforms) run F5OS-C software packages. After the FIPS validated module license is installed, the command prompt will change to ‘REBOOT REQUIRED’. The Crypto Officer must reboot the BIG-IP for all FIPS-compliant changes to take effect.

11.2 Administrator Guidance

The FIPS validated module activation requires installation of the license referred as ‘FIPS license’. The Crypto Officer should call the show license service (with command "show system licensing"), then verify that the list of license flags includes "FIPS 140 License”. On the BIG-IP product the Crypto Officer should call the dedicated Show version API, fips_get_f5fips_module_version, to ensure that the module identifier and version are shown as: Cryptographic Module and OpenSSL 1.0.2zc-fips. The ESV Public Use Document (PUD) reference for non-physical entropy source is as follows: https://csrc.nist.gov/projects/cryptographic-module-validation-program/entropy-validations/certificate/85

11.3 Non-Administrator Guidance
11.4 Design and Rules

The Crypto Officer shall consider the following requirements and restrictions when using the module. The IV for AES-GCM is constructed in compliance with IG C.H scenario 1a (TLS 1.2) and scenario 1d (SSHv2) in section 2.7.

11.6 End of Life

As the module does not persistently store SSPs, secure sanitization of the module consists of unloading the module. This will zeroize all SSPs in volatile memory. ____________________________________________________________________________________________________________________ © 2025 F5, Inc.

Page 45
12 Mitigation of Other Attacks

The module does not implement security mechanisms to mitigate other attacks. ____________________________________________________________________________________________________________________ © 2025 F5, Inc.

Page 46
Table, extracted as text (did not parse into structured rows)
Appendix A. Glossary and Abbreviations AES             Advanced Encryption Standard AES-NI          Advanced Encryption Standard New Instructions CAVP            Cryptographic Algorithm Validation Program CBC             Cipher Block Chaining CCM             Counter with Cipher Block Chaining-Message Authentication Code CFB             Cipher Feedback CMAC            Cipher-based Message Authentication Code CMVP            Cryptographic Module Validation Program CSP             Critical Security Parameter CTR             Counter Mode DES             Data Encryption Standard DF              Derivation Function DSA             Digital Signature Algorithm DRBG            Deterministic Random Bit Generator ECB             Electronic Code Book ECC             Elliptic Curve Cryptography ESV             Entropy Source Validation FFC             Finite Field Cryptography FIPS            Federal Information Processing Standards Publication GCM             Galois Counter Mode HMAC            Hash Message Authentication Code KAS             Key Agreement Schema KAT             Known Answer Test KW              AES Key Wrap MAC             Message Authentication Code NDF             No Derivation Function NIST            National Institute of Science and Technology OFB             Output Feedback PAA             Processor Algorithm Acceleration PCT             Pairwise Consistency Test ____________________________________________________________________________________________________________________ © 2025 F5, Inc.
Page 47
Table, extracted as text (did not parse into structured rows)
PR              Prediction Resistance PSS             Probabilistic Signature Scheme RNG             Random Number Generator RSA             Rivest, Shamir, Addleman SHA             Secure Hash Algorithm SHS             Secure Hash Standard SSH             Secure Shell TDES            Triple-DES XTS             XEX-based Tweaked-codebook mode with cipher text Stealing ____________________________________________________________________________________________________________________ © 2025 F5, Inc.
Page 48
FIPS140-3FIPS PUB 140-3 - Security Requirements for Cryptographic Modules March 2019 https://doi.org/10.6028/NIST.FIPS.140-3
FIPS140-3_IGImplementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program January 2024 https://csrc.nist.gov/Projects/cryptographic-module-validation-program/fips-140-3-ig- announcements
FIPS180-4Secure Hash Standard (SHS) March 2012 http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf
FIPS186-4Digital Signature Standard (DSS) July 2013 http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-4.pdf
FIPS197Advanced Encryption Standard November 2001 http://csrc.nist.gov/publications/fips/fips197/fips-197.pdf
FIPS198-1The Keyed Hash Message Authentication Code (HMAC) July 2008 http://csrc.nist.gov/publications/fips/fips198-1/FIPS-198-1_final.pdf
FIPS202SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions August 2015 http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.202.pdf
PKCS#1Public Key Cryptography Standards (PKCS) #1: RSA Cryptography Specifications Version 2.1 February 2003 http://www.ietf.org/rfc/rfc3447.txt
RFC3394Advanced Encryption Standard (AES) Key Wrap Algorithm September 2002 http://www.ietf.org/rfc/rfc3394.txt
RFC5649Advanced Encryption Standard (AES) Key Wrap with Padding Algorithm September 2009 http://www.ietf.org/rfc/rfc5649.txt
Page 49
SP800-38ANIST Special Publication 800-38A - Recommendation for Block Cipher Modes of Operation Methods and Techniques December 2001 http://csrc.nist.gov/publications/nistpubs/800-38a/sp800-38a.pdf
SP800-38BNIST Special Publication 800-38B - Recommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication May 2005 http://csrc.nist.gov/publications/nistpubs/800-38B/SP_800-38B.pdf
SP800-38CNIST Special Publication 800-38C - Recommendation for Block Cipher Modes of Operation: the CCM Mode for Authentication and Confidentiality May 2004 http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38c.pdf
SP800-38DNIST Special Publication 800-38D - Recommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC November 2007 http://csrc.nist.gov/publications/nistpubs/800-38D/SP-800-38D.pdf
SP800-38ENIST Special Publication 800-38E - Recommendation for Block Cipher Modes of Operation: The XTS AES Mode for Confidentiality on Storage Devices January 2010 http://csrc.nist.gov/publications/nistpubs/800-38E/nist-sp-800-38E.pdf
SP800-38FNIST Special Publication 800-38F - Recommendation for Block Cipher Modes of Operation: Methods for Key Wrapping December 2012 http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38F.pdf
SP800-38GNIST Special Publication 800-38G - Recommendation for Block Cipher Modes of Operation: Methods for Format - Preserving Encryption March 2016 http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38G.pdf
SP800-56ARev3NIST Special Publication 800-56A Revision 3 - Recommendation for Pair Wise Key Establishment Schemes Using Discrete Logarithm Cryptography April 2018 https://doi.org/10.6028/NIST.SP.800-56Ar3
SP800-56CRev2Recommendation for Key Derivation through Extraction-then-Expansion August 2020 https://doi.org/10.6028/NIST.SP.800-56Cr2
Page 50
SP800-57NIST Special Publication 800-57 Part 1 Revision 4 - Recommendation for Key Management Part 1: General January 2016 http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r4.pdf
SP800-67NIST Special Publication 800-67 Revision 1 - Recommendation for the Triple Data Encryption Algorithm (TDEA) Block Cipher January 2012 http://csrc.nist.gov/publications/nistpubs/800-67-Rev1/SP-800-67-Rev1.pdf
SP800-90ARev1NIST Special Publication 800-90A - Revision 1 - Recommendation for Random Number Generation Using Deterministic Random Bit Generators June 2015 http://dx.doi.org/10.6028/NIST.SP.800-90Ar1
SP800-90B(Second DRAFT) NIST Special Publication 800-90B - Recommendation for the Entropy Sources Used for Random Bit Generation January 2018 https://doi.org/10.6028/NIST.SP.800-90B
SP800-131ANIST Special Publication 800-131A Revision 1- Transitions: Recommendation for Transitioning the Use of Cryptographic Algorithms and Key Lengths November 2015 http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar1.pdf
SP800-132NIST Special Publication 800-132 - Recommendation for Password-Based Key Derivation - Part 1: Storage Applications December 2010 http://csrc.nist.gov/publications/nistpubs/800-132/nist-sp800-132.pdf
SP800-133Rev2NIST Special Publication 800-133 - Recommendation for Cryptographic Key Generation June 2020 https://doi.org/10.6028/NIST.SP.800-133r2
SP800-135Rev1NIST Special Publication 800-135 Revision 1 - Recommendation for Existing Application- Specific Key Derivation Functions December 2011 http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-135r1.pdf
SP800-140BNIST Special Publication 800-140B - CMVP Security Policy Requirements March 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-140B.pdf