All modules
CMVP Validated Module · FIPS 140-3 Security Policy

NSS cryptography module for AlmaLinux 9

Certificate#5031StandardFIPS 140-3Level1TypeSoftwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorCloudlinux Inc., TuxCare division
Low review priority  ·  no TCB surface named  ·  NSS upstream has published 0 CVEs since this module's initial validation  ·  last validated 13 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date6/24/2030
CaveatWhen operated in approved mode and installed, initialized and configured as specified in section 11 of the Security Policy.
VendorCloudlinux Inc., TuxCare division

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for NSS cryptography module for AlmaLinux 9
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>update<br/>Recovery</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Status Output</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>IKEV<br/>HTTPS</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for NSS cryptography module for AlmaLinux 9
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>update<br/>Recovery</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Status Output</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>IKEV<br/>HTTPS</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Cloudlinux Inc., TuxCare division NSS cryptography module for AlmaLinux 9 Prepared by: atsec information security corporation

4516 Seton Center Pkwy, Suite 250

Austin, TX 78759 Document version: 1.1 www.atsec.com Last update: 2025-06-23

Page 2
Table of Contents
#SectionPage
Page 3

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 4
List of Tables
ItemPage
Table 1: Security Levels6
Table 2: Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets)9
Table 3: Tested Operational Environments - Software, Firmware, Hybrid10
Table 4: Modes List and Description10
Table 5: Approved Algorithms15
Table 6: Vendor-Affirmed Algorithms16
Table 7: Non-Approved, Not Allowed Algorithms18
Table 8: Security Function Implementations21
Table 9: Entropy Certificates23
Table 10: Entropy Sources24
Table 11: Ports and Interfaces26
Table 12: Roles27
Table 13: Approved Services32
Table 14: Non-Approved Services35
Table 15: Storage Areas40
Table 16: SSP Input-Output Methods40
Table 17: SSP Zeroization Methods41
Table 18: SSP Table 145
Table 19: SSP Table 248
Table 20: Pre-Operational Self-Tests49
Table 21: Conditional Self-Tests56
Table 22: Pre-Operational Periodic Information56
Table 23: Conditional Periodic Information60
Table 24: Error States60
Page 5
List of Figures
ItemPage
Figure 1: Block Diagram9
Page 6
SectionTitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication1
5Software/Firmware security1
6Operational environment1
7Physical securityN/A
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacks1
Overall Level1
1.1 Overview

This document is the non-proprietary FIPS 140-3 Security Policy for version 3.90.0-b84457b0165f79bf of the NSS cryptography module for AlmaLinux 9. It contains the security rules under which the module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for an overall Security Level 1 module. including this notice. Other documentation is proprietary to their authors.

1.2 Security Levels
1.3 Additional Information

This security police describes the features and design of the module named NSS cryptography module for AlmaLinux 9 using the terminology contained in the FIPS 140-3 specification. The FIPS 140-3 Security © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 7

Requirements for Cryptographic Module specifies the security requirements that will be satisfied by a cryptographic module utilized within a security system protecting sensitive but unclassified information. The NIST/CCCS Cryptographic Module Validation Program (CMVP) validates cryptographic module to FIPS 140-3. Validated products are accepted by the Federal agencies of both the USA and Canada for the protection of sensitive or designated information. including this notice. Other documentation is proprietary of their authors. The further refining of the Security Policy document was conducted iteratively throughout the conformance testing, wherein the Security Policy was submitted to the vendor, who would edit, modify, and add technical contents. The vendor would also supply additional documentation, which the laboratory formatted into the existing Security Policy, and resubmitted to the vendor for their final editing. © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 8
2 Cryptographic Module Specification
2.1 Description

Purpose and Use: The NSS cryptography module for AlmaLinux 9 (hereafter referred to as “the module”) is defined as a software module in a multi-chip standalone embodiment. It provides a C language application program interface (API) designed to support cross-platform development of security-enabled client and server applications. Applications built with NSS can support SSLv3, TLS, IKEv2, PKCS#5, PKCS#7, PKCS#11, PKCS#12, S/MIME, X.509 v3 certificates, and other security standards supporting FIPS 140-3 validated cryptographic algorithms. It combines a vertical stack of Linux components intended to limit the external interface each separate component may provide. Module Type: Software Module Embodiment: MultiChipStand Module Characteristics: Cryptographic Boundary: The cryptographic boundary consists only of the Softoken and Freebl libraries along with their associated integrity check values as listed in Section 2.2. If any other NSS API outside of these two libraries is invoked, the user is not interacting with the module specified in this Security Policy. Tested Operational Environment’s Physical Perimeter (TOEPP): The TOEPP of the module is defined as the general-purpose computer on which the module is installed. © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 9
Package or File NameSoftware/ Firmware VersionFeaturesIntegrity Test
libsoftokn3.so, libfreeblpriv3.so, libsoftokn3.chk, libfreeblpriv3.chk3.90.0- b84457b0165f79bfN/AHMAC-SHA-256
2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification

Page 10
Operating SystemHardware PlatformProcessorsPAA/PAIHypervisor or Host OSVersion(s)
AlmaLinux 9.2Amazon Web Services (AWS) m5.metalIntel Cascade Lake Xeon Platinum 8259CLYesN/A3.90.0- b84457b0165f79bf
AlmaLinux 9.2Amazon Web Services (AWS) m5.metalIntel Cascade Lake Xeon Platinum 8259CLNoN/A3.90.0- b84457b0165f79bf
Mode NameDescriptionTypeStatus Indicator
ApprovedAutomatically entered whenever an approved service is requested.ApprovedThe approved mode indicator maps to the approved service indicator which is CKS_NSS_FIPS_OK(1) or CRC_OK as stated in Section 4.
Non- ApprovedAutomatically entered whenever a non- approved service is requested.Non- ApprovedThe Non-Approved mode indicator maps to the non-approved service indicator which is CKS_NSS_FIPS_NOT_OK(0) or an error as stated in Section 4.

Tested Operational Environments - Software, Firmware, Hybrid: Table 3: Tested Operational Environments - Software, Firmware, Hybrid Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid: N/A for this module. CMVP makes no statement as to the correct operation of the module or the security strengths of the generated keys when so ported if the specific operational environment is not listed on the validation certificate.

2.3 Excluded Components

There are no components within the cryptographic boundary excluded from the FIPS 140-3 requirements.

2.4 Modes of Operation

Modes List and Description: Table 4: Modes List and Description After passing all pre-operational self-tests and cryptographic algorithm self-tests executed on start-up, the module automatically transitions to the approved mode. No operator intervention is required to reach this point. © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 11
AlgorithmCAVP CertPropertiesReference
AES-CBCA5128Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBCA5135Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS1A5133Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CMACA5128Direction - Generation, Verification Key Length - 128, 192, 256SP 800-38B
AES-CMACA5130Direction - Generation, Verification Key Length - 128, 192, 256SP 800-38B
AES-CTRA5128Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CTRA5135Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA5128Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA5135Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-GCMA5128Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 192, 256SP 800-38D
AES-GCMA5135Direction - Decrypt, Encrypt IV Generation - External, Internal IV Generation Mode - 8.2.1, 8.2.2 Key Length - 128, 192, 256SP 800-38D

Mode Change Instructions and Status: The module automatically switches between the approved and non-approved modes depending on the services requested by the operator. The status indicator of the mode of operation is equivalent to the indicator of the service that was requested.

2.5 Algorithms

Approved Algorithms: © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 12
AlgorithmCAVP CertPropertiesReference
AES-KWA5128Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-KWA5129Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-KWA5134Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-KWPA5128Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-KWPA5129Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-KWPA5134Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
ECDSA KeyGen (FIPS186-5)A5128Curve - P-256, P-384, P-521 Secret Generation Mode - testing candidatesFIPS 186-5
ECDSA SigGen (FIPS186-5)A5128Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512 Component - NoFIPS 186-5
ECDSA SigGen (FIPS186-5)A5136Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512 Component - NoFIPS 186-5
ECDSA SigVer (FIPS186-5)A5128Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512FIPS 186-5
ECDSA SigVer (FIPS186-5)A5136Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512FIPS 186-5
Hash DRBGA5128Prediction Resistance - No, Yes Mode - SHA2-256SP 800-90A Rev. 1
Hash DRBGA5136Prediction Resistance - No, Yes Mode - SHA2-256SP 800-90A Rev. 1

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 13
AlgorithmCAVP CertPropertiesReference
HMAC-SHA2- 224A5128Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 224A5136Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 256A5128Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 256A5136Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 384A5128Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 384A5136Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512A5128Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512A5136Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
KAS-ECC-SSC Sp800-56Ar3A5128Domain Parameter Generation Methods - P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KAS-FFC-SSC Sp800-56Ar3A5128Domain Parameter Generation Methods - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP- 2048, MODP-3072, MODP-4096, MODP-6144, MODP- 8192 Scheme - dhEphem - KAS Role - initiator, responderSP 800-56A Rev. 3
KDA HKDF Sp800-56Cr1A5127Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224- 65336 Increment 8 HMAC Algorithm - SHA-1, SHA2-224, SHA2-256, SHA2- 384, SHA2-512SP 800-56C Rev. 2
KDF IKEv2 (CVL)A5132Diffie-Hellman Shared Secret Length - Diffie-Hellman Shared Secret Length: 224, 2048, 8192 Derived Keying Material Length - Derived Keying Material Length: 1056, 3072SP 800-135 Rev. 1

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 14
AlgorithmCAVP CertProperties Hash Algorithm - SHA-1, SHA2-256, SHA2-384, SHA2- 512Reference
KDF SP800-108A5131KDF Mode - Counter, Double Pipeline Iteration, Feedback Supported Lengths - Supported Lengths: 8, 72, 128, 776, 3456, 4096SP 800-108 Rev. 1
PBKDFA5128Iteration Count - Iteration Count: 1000-10000 Increment 1 Password Length - Password Length: 8-128 Increment 1SP 800-132
PBKDFA5136Iteration Count - Iteration Count: 1000-10000 Increment 1 Password Length - Password Length: 8-128 Increment 1SP 800-132
RSA KeyGen (FIPS186-5)A5128Key Generation Mode - probable Modulo - 2048, 3072, 4096, 8192 Primality Tests - 2pow100 Private Key Format - standardFIPS 186-5
RSA KeyGen (FIPS186-5)A5136Key Generation Mode - probable Modulo - 2048, 3072, 4096, 8192 Primality Tests - 2pow100 Private Key Format - standardFIPS 186-5
RSA SigGen (FIPS186-5)A5128Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pssFIPS 186-5
RSA SigGen (FIPS186-5)A5136Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pssFIPS 186-5
RSA SigVer (FIPS186-2)A5128Signature Type - PKCS 1.5, PKCSPSS Modulo - 1536FIPS 186-4
RSA SigVer (FIPS186-2)A5136Signature Type - PKCS 1.5, PKCSPSS Modulo - 1536FIPS 186-4
RSA SigVer (FIPS186-4)A5128Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024FIPS 186-4
RSA SigVer (FIPS186-4)A5136Signature Type - PKCS 1.5, PKCSPSS Modulo - 1024FIPS 186-4
RSA SigVer (FIPS186-5)A5128Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pssFIPS 186-5

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 15
AlgorithmCAVP CertPropertiesReference
RSA SigVer (FIPS186-5)A5136Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pssFIPS 186-5
Safe Primes Key GenerationA5128Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192SP 800-56A Rev. 3
SHA2-224A5128Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-224A5136Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-256A5128Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-256A5136Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-384A5128Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-384A5136Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512A5128Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512A5136Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
TLS v1.2 KDF RFC7627 (CVL)A5128Hash Algorithm - SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
TLS v1.2 KDF RFC7627 (CVL)A5136Hash Algorithm - SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1

Table 5: Approved Algorithms © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 16
NamePropertiesImplementationReference
Cryptographic Key Generation (Symmetric keys)AES, HMAC, key-derivation key sizes:112-256 bits Strength:112-256 bitsNSS cryptography module for AlmaLinux 9SP 800-133r2 Section 4 and 6.1
Cryptographic Key Generation (RSA)RSA modulus sizes:2048, 3072, 4096 bits Strength:112-150 bitsNSS cryptography module for AlmaLinux 9SP 800-133r2 Section 4 and 5.1
Cryptographic Key Generation (Safe Primes)Safe Primes:MODP-2048, MODP- 3072, MODP-4096, MODP-6144, MODP-8192, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192 Strength:112-200 bitsNSS cryptography module for AlmaLinux 9SP 800-133r2 Section 4 and 5.2
Cryptographic Key Generation (ECDSA)ECDSA curves:P-256, P-384, P-521 Strength:112-256 bitsNSS cryptography module for AlmaLinux 9SP 800-133r2 Section 4 and 5.1
NameUse and Function
MD2, MD5, SHA-1Message digest
RC2, RC4, DES, Triple-DES, CDMF, Camellia, SEED, ChaCha20(-Poly1305)Encryption, Decryption

The table above lists all approved cryptographic algorithms of the module, including specific key lengths employed for approved services in Section 4.3, and implemented modes or methods of operation of the algorithms. Vendor-Affirmed Algorithms: Table 6: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: The module does not implement non-approved algorithms that are allowed in the approved mode of operation. Non-Approved, Allowed Algorithms with No Security Claimed: The module does not implement non-approved algorithms that are allowed in the approved mode of operation with no security claimed. Non-Approved, Not Allowed Algorithms: © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 17
NameUse and Function
AES GCM (external IV)Encryption
CBC-MAC, AES XCBC-MAC, AES XCBC-MAC- 96Message authentication
HMAC (MD2, MD5, SHA-1; < 112-bit keys)Message authentication
HMAC/SSLv3 MAC (constant-time implementation)Message authentication
MD2, MD5, SHA-1, SHA-224, SHA-256, SHA- 384, SHA-512, DES, Triple-DES, AES, Camellia, SEEDKey derivation
ANS X9.63 KDF, SSL 3 PRF, IKEv1 PRF, TLS 1.0/1.1 KDFKey derivation
KBKDF, HKDF, TLS 1.2 KDF, IKEv2 KDF (< 112-bit keys)Key derivation
KBKDF (MD2, MD5)Key derivation
TLS 1.2 KDF (without extended master secret)Key derivation
IKEv2 KDF (MD2, MD5)Key derivation
PKCS#5 PBE, PKCS#12 PBEPassword-based key derivation
PBKDF2 (< 8 characters password; < 128-bit salt; < 1000 iterations; < 112-bit keys)Password-based key derivation
J-PAKEShared secret computation
DH (FIPS 186-type groups)Shared secret computation, Key pair generation
ECDH (P-192)Shared Secret Computation
ECDH (X25519)Shared secret computation
DSASignature generation, Signature verification, Parameter generation, Parameter verification, Key pair generation
RSA (primitive; PKCS#1 v1.5 or PSS with MD2, MD5, SHA-1)Signature generation, Signature verification
RSA (< 2048-bit keys)Signature generation

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 18
NameUse and Function
RSA (< 1024-bit keys)Signature verification
ECDSA (P-192)Key Pair Generation, Signature generation, Signature verification
ECDSA (component; SHA-1)Signature generation, Signature verification
RSAAsymmetric encryption, Asymmetric decryption
RSA (< 2048 bits; > 4096 bits)Key pair generation
Ed25519, X25519Key pair generation
Symmetric key generation (< 112 bits)Secret key generation
NameTypeDescriptionPropertiesAlgorithms
Encryption with AESBC-UnAuthEncryption using AESKeys:128, 192, 256 bits with 128- 256 bits of key strengthAES-CBC: (A5128, A5135) AES-CBC-CS1: (A5128, A5133) AES-CTR: (A5128, A5135) AES-ECB: (A5128, A5135)
Decryption with AESBC-UnAuthDecryption using AESKeys:128, 192, 256 bits with 128- 256 bits of key strengthAES-CBC: (A5128, A5135) AES-CTR: (A5128, A5135) AES-ECB: (A5128, A5135) AES-CBC-CS1: (A5133)
Authenticated Encryption with AESBC-AuthAuthenticated encryption using AESKeys:128, 192, 256 bits with 128- 256 bits of key strengthAES-GCM: (A5128, A5135)

Table 7: Non-Approved, Not Allowed Algorithms The table above lists all the non-approved cryptographic algorithms of the module employed by the nonapproved services in Section 4.4.

2.6 Security Function Implementations

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 19
NameTypeDescriptionPropertiesAlgorithms
Authenticated Decryption with AESBC-AuthAuthenticated decryption using AESKeys:128, 192, 256 bits with 128- 256 bits of key strengthAES-GCM: (A5128, A5135)
Key Derivation with PBKDFPBKDFKey derivation using PBKDFDerived keys:112- 256 bitsPBKDF: (A5128, A5136)
Key Derivation with KBKDFKBKDFKey derivation using KBKDFDerived keys:112- 256 bitsKDF SP800-108: (A5131)
Key Derivation with HKDFKAS-56CKDFKey derivation using HKDFDerived keys:112- 256 bitsKDA HKDF Sp800-56Cr1: (A5127)
Key Derivation with TLS 1.2 KDFKAS-135KDFKey derivation using TLS 1.2 KDFDerived keys:112- 256 bitsTLS v1.2 KDF RFC7627: (A5136, A5128)
Key Derivation with IKEv2 KDFKAS-135KDFKey derivation using IKEv2 KDFDerived keys:112- 256 bitsKDF IKEv2: (A5132)
Key Wrapping with AESKTS-WrapKey wrapping using AESKeys:128, 192, 256 bits with 128- 256 bits of key strength; Compliant with IG D.GAES-KW: (A5128, A5129, A5134) AES-KWP: (A5128, A5129, A5134) AES-GCM: (A5128, A5135)
Key Unwrapping with AESKTS-WrapKey unwrapping using AESKeys:128, 192, 256 bits with 128- 256 bits of key strength; Compliant with IG D.GAES-KW: (A5128, A5129, A5134) AES-KWP: (A5128, A5129, A5134) AES-GCM: (A5128, A5135)
Message Authentication with HMACMACMessage authentication using HMACKeys:112-256 bits with 112-256 bits of key strengthHMAC-SHA2-224: (A5128, A5136) HMAC-SHA2-256: (A5128, A5136) HMAC-SHA2-384: (A5128, A5136) HMAC-SHA2-512: (A5128, A5136)

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 20
NameTypeDescriptionPropertiesAlgorithms
Message Authentication with CMACMACMessage authentication using CMACKeys:128, 192, 256 bits with 128- 256 bits of key strengthAES-CMAC: (A5128, A5130)
Random Number Generation with Hash_DRBGDRBGRandom number generation using Hash_DRBGHash:SHA2-256Hash DRBG: (A5128, A5136)
Shared Secret Computation with KAS-ECC-SSCKAS-SSCShared secret computation using KAS-ECC-SSCCurves:P-256, P- 384, P-521 with 128, 192 and 256 bits of strength; Compliant with IG D.F scenario 2(1)KAS-ECC-SSC Sp800-56Ar3: (A5128)
Shared Secret Computation with KAS-FFC-SSCKAS-SSCShared secret computation using KAS-FFC-SSCKeys:MODP- 2048, MODP- 3072, MODP- 4096, MODP- 6144, MODP- 8192, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192 with 112-200 bits of key strength; Compliant with IG D.F scenario 2(1)KAS-FFC-SSC Sp800-56Ar3: (A5128)
Signature Generation with RSADigSig-SigGenSignature generation using RSAKeys:2048, 3072, 4096 bits with 112-150 bits of key strengthRSA SigGen (FIPS186-5): (A5128, A5136)
Signature Generation with ECDSADigSig-SigGenSignature generation using ECDSACurves:P-256, P- 384, P-521 with 112-256 bits of strengthECDSA SigGen (FIPS186-5): (A5128, A5136)
Signature Verification with RSADigSig-SigVerSignature verification using RSAKeys:1024, 1280, 1536, 1792, 2048, 3072, 4096 bits with 80-150 bits of key strengthRSA SigVer (FIPS186-2): (A5128, A5136) RSA SigVer (FIPS186-4): (A5128, A5136) RSA SigVer

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 21
NameTypeDescriptionPropertiesAlgorithms
(FIPS186-5): (A5128, A5136)
Signature Verification with ECDSADigSig-SigVerSignature verification using ECDSACurves:P-256, P- 384, P-521 with 112-256 bits of strengthECDSA SigVer (FIPS186-5): (A5128, A5136)
Symmetric Key Generation with Hash_DRBGCKGDirect symmetric key generation using Hash_DRBGKeys:112-256 bits with 112-256 bits of key strength; Compliant with SP800-133r2 section 6.1Hash DRBG: (A5128, A5136)
Key Pair Generation with RSACKGKey pair generation using RSAKeys:2048, 3072, 4096 bits with 112-150 bits of key strengthRSA KeyGen (FIPS186-5): (A5128, A5136)
Key Pair Generation with ECDSACKGKey pair generation using ECDSACurves:P-256, P- 384, P-521 with 128, 192 and 256 bits of strengthECDSA KeyGen (FIPS186-5): (A5128)
Key Pair Generation with Safe PrimesCKGKey pair generation using Safe PrimesKeys:MODP- 2048, MODP- 3072, MODP- 4096, MODP- 6144, MODP- 8192, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192 with 112-200 bits of key strengthSafe Primes Key Generation: (A5128)
Message Digest with SHASHAMessage digest using SHASHA2-224: (A5128, A5136) SHA2-256: (A5128, A5136) SHA2-384: (A5128, A5136) SHA2-512: (A5128, A5136)

Table 8: Security Function Implementations © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 22
2.7 Algorithm Specific Information
2.7.1 AES GCM IV

The Crypto Officer shall consider the following requirements and restrictions when using the module. For TLS 1.2, the module offers the AES GCM implementation and uses the context of Scenario 1 of FIPS 140-3 IG C.H. NSS is compliant with SP 800-52r2 Section 3.3.1 and the mechanism for IV generation is compliant with RFC 5288 and 8446. The module does not implement the TLS protocol. The module’s implementation of AES GCM is used together with an application that runs outside the module’s cryptographic boundary. The design of the TLS protocol implicitly ensures that the counter (the nonce_explicit part of the IV) does not exhaust the maximum number of possible values for a given session key. In the event the module’s power is lost and restored, the consuming application must ensure that a new key for use with the AES GCM key encryption or decryption under this scenario shall be established. Alternatively, the Crypto Officer can use the module’s API to perform AES GCM encryption using internal IV generation that complies with Scenario 2 of the IG C.H. These IVs are always at least 96 bits and generated using the approved DRBG internal to the module’s boundary. Additionally, the module offers an internal deterministic IV generation mode compliant with Scenario 3 of FIPS 140-3 IG C.H. The size of the fixed (name) field used by this IV generation mode is at least 32 bits. The module then internally generates a 32 bit or longer deterministic non-repetitive counter. The module explicitly ensures that this counter is monotonically increasing at each invocation of the AES-GCM for the same encryption key, and that this counter does not exhaust all its possible values. The generated GCM IV is at least 96 bits in length. In case the module’s power is lost and then restored, a new key for use with the AES-GCM encryption/decryption shall be established. Finally, for TLS 1.3, the AES GCM implementation uses the context of Scenario 5 of FIPS 140-3 IG C.H. The protocol that provides this compliance is TLS 1.3, defined in RFC8446 of August 2018, using the cipher-suites that explicitly select AES GCM as the encryption/decryption cipher (Appendix B.4 of RFC8446). The module supports acceptable AES GCM cipher suites from Section 3.3.1 of SP800-52r2. TLS 1.3 employs separate 64-bit sequence numbers, one for protocol records that are received, and one for protocol records that are sent to a peer. These sequence numbers are set at zero at the beginning of a TLS 1.3 connection and each time when the AES-GCM key is changed. After reading or writing a record, the respective sequence number is incremented by one. The protocol specification determines that the sequence number should not wrap, and if this condition is observed, then the protocol implementation must either trigger a re-key of the session (i.e., a new key for AES-GCM), or terminate the connection.

2.7.2 Key Derivation using SP 800-132 PBKDF2

The module provides password-based key derivation (PBKDF2), compliant with SP 800-132. The module supports option 1a from Section 5.4 of SP 800-132, in which the Master Key (MK) or a segment of it is used directly as the Data Protection Key (DPK). In accordance to SP 800-132 and FIPS 140-3 IG D.N, the following requirements shall be met: • Derived keys shall only be used in storage applications. The MK shall not be used for other purposes. The module enforces the length of the MK or DPK to be of 112 bits or more for the service to be approved. © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 23
Cert NumberVendor Name
E127Cloudlinux Inc., TuxCare division
2.7.3 SP 800-56Ar3 Assurances

To comply with the assurances found in Section 5.6.2 of SP 800-56Ar3, the operator must use the module together with an application that implements the TLS protocol. Additionally, the module’s approved Key Pair Generation service (see Section 4.3) must be used to generate ephemeral DiffieHellman or EC Diffie-Hellman key pairs, or the key pairs must be obtained from another FIPS-validated module. As part of this service, the module will internally perform the full public key validation of the generated public key. The module’s shared secret computation service will internally perform the full public key validation of the peer public key, complying with Sections 5.6.2.2.1 and 5.6.2.2.2 of SP 800-56Ar3.

2.7.4 FIPS 140-3 IG C.F Compliance

The module supports RSA Signature Verification for 1024, 1280, 1536 and 1792-bit keys. This is allowed by FIPS 140-3 IG C.F. Specifically, 1280 and 1792 cannot be ACVP tested but are approved for signature verification in IG C.F. The 1024-bit modulus has been CAVP tested for RSA signature verification in compliance with FIPS 1864, while the 1536-bit modulus has been CAVP tested for RSA signature verification in compliance with FIPS 186-2. For all other approved moduli (namely 2048, 3072, and 4096 bit keys) supported by the module, RSA signature verification is approved and CAVP tested in compliance with FIPS 186-5.

2.8 RBG and Entropy

Table 9: Entropy Certificates © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 24
NameTypeOperational EnvironmentSample SizeEntropy per SampleConditioning Component
Userspace CPU Time Jitter RNG Entropy Source Version 3.4.0Non- PhysicalAlmaLinux 9.2 on Amazon Web Services (AWS) m5.metal on Intel Xeon Platinum 8259CL; AlmaLinux 9.2 on Amazon Web Services (AWS) a1.metal on AWS Graviton64 bitsSHA3-256 (Cert. A4026), HMAC- SHA2-512-DRBG (Cert. A4025)

Table 10: Entropy Sources The module employs a Deterministic Random Bit Generator (DRBG) implementation based on SP 80090Ar1. This DRBG is used internally by the module (e.g. to generate symmetric keys, seeds for asymmetric key pairs, and random numbers for security functions). It can also be accessed using the specified API functions. The DRBG implemented is a SHA-256 Hash_DRBG, seeded by the entropy source described in the table above. It does not employ prediction resistance. The DRBG is instantiated with a 384-bits long entropy input (corresponding to 384 bits of entropy). Additionally, the DRBG is reseeded with a 256-bits long entropy input (corresponding to 256 bits of

2.9 Key Generation

The module implements Cryptographic Key Generation (CKG, vendor affirmed), compliant with SP 800133r2. When random values are required, they are obtained from the SP 800-90Ar1 approved DRBG, compliant with Section 4 of SP 800-133r2. The following methods are implemented:

Page 25

Intermediate key generation values are not output from the module and are explicitly zeroized after processing the service.

2.10 Key Establishment

The module provides Diffie-Hellman (DH) and Elliptic Curve Diffie-Hellman (ECDH) shared secret computation compliant with SP800-56Ar3, in accordance with scenario 2 (1) of FIPS 140-3 IG D.F. For Diffie-Hellman, the module supports the use of the safe primes defined in RFC 3526 (IKE) and RFC

7919 (TLS). Note that the module only implements domain parameter generation, key pair generation

and verification, and shared secret computation. No other part of the IKE or TLS protocols is implemented (with the exception of the TLS 1.2 KDF and IKEv2 PRF): IKE (RFC 3526):

200 resp. 128-256 bits of security strength in an approved mode of operation.

The module also provides the following key transport mechanisms:

2.11 Industry Protocols

For DH, the module supports the use of the safe primes defined in RFC 3526 (IKE) and RFC 7919 (TLS) as listed in Section 2.10. Note that the module only implements domain parameter generation, key pair generation and verification, and shared secret computation. No other part of the IKE or TLS protocols is implemented (with the exception of the TLS 1.2 KDF (RFC 7627) and IKEv2 KDF). TLS 1.2 KDF (RFC 7627) and IKEv2 implementations shall only be used to generate secret keys in the context of the TLS 1.2 and IKE protocols respectively. No other parts of the TLS and IKE protocols, other than the KDFs, have been tested by the CAVP or CMVP. © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 26
Physical PortLogical Interface(s)Data That Passes
N/AData InputAPI input parameters
N/AData OutputAPI output parameters
N/AControl InputAPI function calls, API input parameters for control input
N/AStatus OutputAPI return codes
3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

Table 11: Ports and Interfaces The logical interfaces are the APIs through which the applications request services. The module does not © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 27
NameTypeOperator TypeAuthentication Methods
Crypto OfficerRoleCONone
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
EncryptionEncrypt a plaintextCKS_NSS_FIPS_ OK (1)AES key, plaintextCiphertex tEncryption with AESCrypto Officer - AES Key: W,E
DecryptionDecrypt a ciphertextCKS_NSS_FIPS_ OK (1)AES key, ciphertex tPlaintextDecryption with AESCrypto Officer - AES Key: W,E
Authenticate d EncryptionEncrypt a plaintextCKS_NSS_FIPS_ OK (1)AES key, IV, plaintextCiphertex t, MAC tagAuthenticate d Encryption with AESCrypto Officer - AES Key: W,E
Authenticate d DecryptionDecrypt a ciphertextCKS_NSS_FIPS_ OK (1)AES key, IV, MAC tag, ciphertex tPlaintext or failAuthenticate d Decryption with AESCrypto Officer - AES Key: W,E
4 Roles, Services, and Authentication

N/A for this module. The module does not support authentication for roles.

4.2 Roles

Table 12: Roles The module supports the Crypto Officer role only. This sole role is implicitly and always assumed by the operator of the module. No support is provided for multiple concurrent operators or a maintenance role.

4.3 Approved Services

W,E W,E W,E t © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 28
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Key Derivation from a KDKDerive a key from a key- derivation keyCKS_NSS_FIPS_ OK (1)Key- derivatio n keyKBKDF Derived keyKey Derivation with KBKDFCrypto Officer - Key- Derivation Key: W,E - KBKDF Derived Key: G
Key Derivation from a Shared SecretDerive a key from a shared secretCKS_NSS_FIPS_ OK (1)Shared secretHKDF Derived key; TLS Derived key; IKE Derived keyKey Derivation with HKDF Key Derivation with TLS 1.2 KDF Key Derivation with IKEv2 KDFCrypto Officer - Shared Secret: W,E - HKDF Derived Key: G - TLS Derived Key: G - IKE Derived Key: G
Password- Based Key DerivationDerive a key from a passwordCKS_NSS_FIPS_ OK (1)Passwor d, salt, iteration countPBKDF Derived keyKey Derivation with PBKDFCrypto Officer - Password: W,E - PBKDF Derived Key: G
Key WrappingWrap a CSPCKS_NSS_FIPS_ OK (1)AES key, any CSP (except for passwor d)Wrapped CSPKey Wrapping with AESCrypto Officer - AES Key: W,E
Key UnwrappingUnwrap a CSPCKS_NSS_FIPS_ OK (1)AES key, Wrapped CSPAny CSP (except for password )Key Unwrapping with AESCrypto Officer - AES Key: W,E
HMAC MessageCompute a MAC tagCKS_NSS_FIPS_ OK (1)HMAC keyMAC tagMessage AuthenticatioCrypto Officer

W,E d) ) © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 29
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Authenticatio nn with HMAC- HMAC Key: W,E
AES-based Message Authenticatio nCompute a MAC tagCKS_NSS_FIPS_ OK (1)AES keyMAC tagMessage Authenticatio n with CMACCrypto Officer - AES Key: W,E
Message DigestCompute a message digestCKS_NSS_FIPS_ OK (1)MessageDigest valueMessage Digest with SHACrypto Officer
Random Number GenerationGenerate random bytesCKR_OKOutput lengthRandom bytesRandom Number Generation with Hash_DRBGCrypto Officer - Entropy Input: W,E - DRBG Seed: G,E - Internal State (V, C): G,W,E
Shared Secret Computation (DH)Compute a shared secretCKS_NSS_FIPS_ OK (1)DH private key (owner), DH public key (peer)Shared secretShared Secret Computation with KAS- FFC-SSCCrypto Officer - DH Private Key: W,E - DH Public Key: W,E - Shared Secret: G
Shared Secret Computation (ECDH)Compute a shared secretCKS_NSS_FIPS_ OK (1)EC private key (owner), EC public key (peer)Shared secretShared Secret Computation with KAS- ECC-SSCCrypto Officer - EC Private Key: W,E - EC Public Key: W,E - Shared Secret: G
RSA Signature GenerationGenerate a signatureCKS_NSS_FIPS_ OK (1)RSA private key, messageSignatureSignature Generation with RSACrypto Officer - RSA Private Key: W,E

C): G,W,E © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 30
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
ECDSA Signature GenerationGenerate a signatureCKS_NSS_FIPS_ OK (1)EC private key, messageSignatureSignature Generation with ECDSACrypto Officer - EC Private Key: W,E
RSA Signature VerificationVerify a signatureCKS_NSS_FIPS_ OK (1)RSA public key, message , signaturePass/failSignature Verification with RSACrypto Officer - RSA Public Key: W,E
ECDSA Signature VerificationVerify a signatureCKS_NSS_FIPS_ OK (1)EC public key, message , signaturePass/failSignature Verification with ECDSACrypto Officer - EC Public Key: W,E
Key Pair Generation with Safe PrimesGenerate a key pairCKS_NSS_FIPS_ OK (1)GroupDH public key, DH private keyKey Pair Generation with Safe PrimesCrypto Officer - DH Private Key: G - DH Public Key: G - Intermediat e key generation value: G,E,Z
Key Pair Generation with RSAGenerate a key pairCKS_NSS_FIPS_ OK (1)Modulus bitsRSA public key, RSA private keyKey Pair Generation with RSACrypto Officer - RSA Private Key: G - RSA Public Key: G - Intermediat e key generation value: G,E,Z

, W,E , G,E,Z G G,E,Z © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 31
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
Key Pair Generation with ECDSAGenerate a key pairCKS_NSS_FIPS_ OK (1)CurveEC public key, EC private keyKey Pair Generation with ECDSACrypto Officer - EC Private Key: G - EC Public Key: G - Intermediat e key generation value: G,E,Z
Symmetric Key GenerationGenerate a secret keyCKS_NSS_FIPS_ OK (1)Key sizeAES key, HMAC key or key- derivation keySymmetric Key Generation with Hash_DRBGCrypto Officer - AES Key: G - HMAC Key: G - Key- Derivation Key: G
Show VersionReturn the module name and version informationNoneN/AModule name and version informatio nNoneCrypto Officer
Show StatusReturn the module statusNoneN/AModule statusNoneCrypto Officer
Self-TestPerform the CASTs and integrity testsNoneN/APass/failNoneCrypto Officer
ZeroizationZeroize all SSPsN/AAny SSPNoneNoneCrypto Officer - AES Key: Z - HMAC Key: Z - Key- Derivation Key: Z

G,E,Z Z © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 32
NameDescriptio nIndicatorInputsOutputsSecurity FunctionsSSP Access
- Shared Secret: Z - Password: Z - KBKDF Derived Key: Z - PBKDF Derived Key: Z - HKDF Derived Key: Z - TLS Derived Key: Z - IKE Derived Key: Z - Entropy Input: Z - DRBG Seed: Z - Internal State (V, C): Z - DH Private Key: Z - DH Public Key: Z - EC Private Key: Z - EC Public Key: Z - RSA Private Key: Z - RSA Public Key: Z - Intermediat e key generation value: Z

Z C): Z Z Table 13: Approved Services © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 33
NameDescriptionAlgorithmsRole
Message DigestCompute a message digestMD2, MD5, SHA-1CO
EncryptionEncrypt a plaintextRC2, RC4, DES, Triple-DES, CDMF, Camellia, SEED, ChaCha20(-Poly1305) AES GCM (external IV)CO
DecryptionDecrypt a ciphertextRC2, RC4, DES, Triple-DES, CDMF, Camellia, SEED, ChaCha20(-Poly1305)CO
Message AuthenticationCompute a MAC tagCBC-MAC, AES XCBC-MAC, AES XCBC- MAC-96 HMAC (MD2, MD5, SHA-1; < 112-bit keys)CO

The table above lists the approved services in this module, the algorithms involved, the Sensitive Security Parameters (SSPs) involved and how they are accessed, the roles that can request the service, and the respective service indicator. In this table, CO specifies the Crypto Officer role. The module provides services to operators that assume the available role. All services are described in detail in the API documentation (manual pages). The service tables define the services that utilize approved and non-approved security functions in this module. For the respective tables, the convention below applies when specifying the access permissions (types) that the service has for each SSP. • Generate (G): The module generates or derives the SSP. • Read (R): The SSP is read from the module (e.g. the SSP is output). • Write (W): The SSP is updated, imported, or written to the module. • Execute (E): The module uses the SSP in performing a cryptographic operation. • Zeroize (Z): The module zeroizes the SSP. • N/A: The module does not access any SSP or key during its operation. To interact with the module, a calling application must use the FIPS token APIs provided by Softoken. The FIPS token API layer can be used to retrieve the approved service indicator for the module. This indicator consists of four independent service indicators:

  1. The session indicator, which must be used for all cryptographic services except the key (pair) generation and key derivation services. It can be accessed by invoking the NSC_NSSGetFIPSStatus function with the CKT_NSS_SESSION_LAST_CHECK parameter. If the output parameter is set to CKS_NSS_FIPS_OK (1), the service was approved.
  2. The object indicator, which must be used for the key (pair) generation and key derivation services. It can be accessed by invoking the NSC_NSSGetFIPSStatus function with the CKT_NSS_OBJECT_CHECK parameter and the output derived key. If the output parameter is set to CKS_NSS_FIPS_OK (1), the service was approved.
  3. The DRBG service indicator, which must be used for the DRBG service. It can be accessed by invoking the C_SeedRandom or C_GenerateRandom functions. If any of these functions returns CKR_OK, the service was approved. Any other service indicator value not listed above such as CKS_NSS_FIPS_NOT_OK (0) indicates that non-approved service is called. Also, for DRBG service, an error returned by the specified APIs indicates that the service was not approved.
4.4 Non-Approved Services

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 34
NameDescriptionAlgorithmsRole
HMAC/SSLv3 MAC (constant-time implementation)
Key DerivationDerive a key from a key- derivation key or a shared secretMD2, MD5, SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, DES, Triple-DES, AES, Camellia, SEED ANS X9.63 KDF, SSL 3 PRF, IKEv1 PRF, TLS 1.0/1.1 KDF KBKDF, HKDF, TLS 1.2 KDF, IKEv2 KDF (< 112-bit keys) KBKDF (MD2, MD5) TLS 1.2 KDF (without extended master secret) IKEv2 KDF (MD2, MD5)CO
Password-Based Key DerivationDerive a key from a passwordPKCS#5 PBE, PKCS#12 PBE PBKDF2 (< 8 characters password; < 128- bit salt; < 1000 iterations; < 112-bit keys)CO
Shared Secret ComputationCompute a shared secretJ-PAKE DH (FIPS 186-type groups) ECDH (P-192) ECDH (X25519)CO
Signature GenerationGenerate a signatureDSA RSA (primitive; PKCS#1 v1.5 or PSS with MD2, MD5, SHA-1) RSA (< 2048-bit keys) ECDSA (component; SHA-1) ECDSA (P-192)CO
Signature VerificationVerify a signatureDSA RSA (primitive; PKCS#1 v1.5 or PSS with MD2, MD5, SHA-1) RSA (< 1024-bit keys) ECDSA (component; SHA-1) ECDSA (P-192)CO
Asymmetric EncryptionEncrypt a plaintextRSACO
Asymmetric DecryptionDecrypt a plaintextRSACO
Parameter GenerationGenerate domain parametersDSACO
Parameter VerificationVerify domain parametersDSACO

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 35
NameDescriptionAlgorithmsRole
Key Pair GenerationGenerate a key pairDSA DH (FIPS 186-type groups) RSA (< 2048 bits; > 4096 bits) Ed25519, X25519 ECDSA (P-192)CO
Secret Key GenerationGenerate a secret keySymmetric key generation (< 112 bits)CO

Table 14: Non-Approved Services The table above lists the non-approved services in this module, the algorithms involved, and the roles that can request the service. In this table, CO specifies the Crypto Officer role.

4.5 External Software/Firmware Loaded

The module does not load external software or firmware. © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 36
5 Software/Firmware Security
5.1 Integrity Techniques

Each software component of the module has an associated HMAC-SHA2-256 integrity check value. The integrity of the module is verified by comparing the HMAC-SHA2-256 values calculated at run time with the integrity values embedded in the check files that were computed at build time. If the integrity test fails, the module enters the Power-On Error state.

5.2 Initiate on Demand

Integrity tests are performed as part of the pre-operational self-tests, which are executed when the module is initialized. The integrity tests may be invoked on-demand by unloading and subsequently reinitializing the module, which will perform (among others) the software integrity tests. © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 37
6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Modifiable How Requirements are Satisfied: The module shall be installed as stated in Section 11.2. If properly installed, operating system provides process isolation and memory protection mechanisms that ensure appropriate separation for memory access among the processes on the system. Each process has control over its own data and uncontrolled access to the data of other processes is prevented. There are no concurrent operators.

6.2 Configuration Settings and Restrictions

Instrumentation tools like the ptrace system call, gdb and strace, userspace live patching, as well as other tracing mechanisms offered by the Linux environment such as ftrace or systemtap, shall not be used in the operational environment. The use of any of these tools implies that the cryptographic module is running in a non-validated operational environment. © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 38
7 Physical Security

The module is comprised of software only and therefore this section is not applicable. © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 39
8 Non-Invasive Security

This module does not implement any non-invasive security mechanism and therefore this section is not applicable. © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 40
Storage Area NameDescriptionPersistence Type
RAMTemporary storage for SSPs used by the module as part of service execution. The module does not perform persistent storage of SSPsDynamic
NameFromToFormat TypeDistribution TypeEntry TypeSFI or Algorithm
API input parameters (plaintext)Calling application within TOEPPCryptographic modulePlaintextManualElectronic
API input parameters (encrypted)Calling application within TOEPPCryptographic moduleEncryptedManualElectronicKey Unwrapping with AES
API output parameters (plaintext)Cryptographic moduleCalling application within TOEPPPlaintextManualElectronic
API output parameters (encrypted)Cryptographic moduleCalling application within TOEPPEncryptedManualElectronicKey Wrapping with AES
9 Sensitive Security Parameters Management
9.1 Storage Areas

Table 15: Storage Areas SSPs imported, generated, derived, or otherwise established by the module are stored in RAM while the module is operational. The operator application can use these SSPs to perform cryptographic operations, or export them as described in Section 9.2. The module maintains internal separation of the SSPs (including CSPs) in approved and non-approved modes of operation using an internal isFIPS flag for each SSP. This flag indicates whether the SSP can be used in approved or non-approved services.

9.2 SSP Input-Output Methods

Table 16: SSP Input-Output Methods CSPs (with the exception of passwords) can only be imported to and exported from the module when they are wrapped using an approved security function (e.g. AES KW or KWP). PSPs can be imported and exported in plaintext. Import and export is performed using API input and output parameters. © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 41
Zeroization MethodDescriptionRationaleOperator Initiation
Destroy ObjectDestroys the SSP represented by the objectMemory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable. The completion of the zeroization routine indicates that the zeroization procedure succeeded.By calling the C_DestroyObject function.
AutomaticAutomatically zeroized by the module when no longer neededMemory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable.N/A
Module resetDe-allocates the volatile memory used to store SSPsVolatile memory used by the module is overwritten within nanoseconds when the module is unloaded. Module unloaded indicates that the zeroization procedure succeeded.Unloading and reloading the module
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
AES KeyAES key used for encryption, decryption, and computing MAC tags128, 192, 256 bits - 128, 192, 256 bitsSymmetric key - CSPSymmetric Key Generation with Hash_DRB GEncryption with AES Decryption with AES Authenticated Encryption with AES Authenticated Decryption with AES Key Wrapping with AES Key Unwrapping with AES Message Authenticatio n with CMAC

Table 17: SSP Zeroization Methods All data output is inhibited during zeroization. Memory is deallocated after zeroization. © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 42
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
HMAC KeyHMAC key used for computing MAC tags112-256 bits - 112- 256 bitsSymmetric key - CSPSymmetric Key Generation with Hash_DRB GMessage Authenticatio n with HMAC
Key- Derivation KeySymmetric key used to derive symmetric keys112-4096 bits - 112- 256 bitsSymmetric key - CSPSymmetric Key Generation with Hash_DRB GKey Derivation with KBKDF
Shared SecretShared secret generated by (EC) Diffie- Hellman256-8192 bits - 112- 256 bitsShared secret - CSPShared Secret Computatio n with KAS- ECC-SSC Shared Secret Computatio n with KAS- FFC-SSCKey Derivation with HKDF Key Derivation with TLS 1.2 KDF Key Derivation with IKEv2 KDF
PasswordPassword used to derive symmetric keys8-128 character s - N/APassword - CSPKey Derivation with PBKDF
PBKDF Derived KeySymmetric key derived from a password112-4096 bits - 112- 256 bitsSymmetric key - CSPKey Derivation with PBKDF
KBKDF Derived KeySymmetric key derived from a key- derivation key112-4096 bits - 112- 256 bitsSymmetric key - CSPKey Derivation with KBKDF
HKDF Derived KeySymmetric key derived from a shared112-4096 bits - 112- 256 bitsSymmetric key - CSPKey Derivation with HKDF

G G © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 43
NameDescription secret with HKDFSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
TLS Derived KeySymmetric key derived from a shared secret with TLS 1.2 KDF112-4096 bits - 112- 256 bitsSymmetric key - CSPKey Derivation with TLS 1.2 KDF
IKE Derived KeySymmetric key derived from a shared secret with IKEv2 KDF112-4096 bits - 112- 256 bitsSymmetric key - CSPKey Derivation with IKEv2 KDF
Entropy InputEntropy input used to seed the DRBG128-384 bits - 128- 256 bitsEntropy input - CSPRandom Number Generation with Hash_DRBG
DRBG SeedDRBG seed derived from entropy input440 bits - 256 bitsSeed - CSPRandom Number Generation with Hash_DRB GRandom Number Generation with Hash_DRBG
Internal State (V, C)Internal state of the Hash_DRB G880 bits - 256 bitsInternal state - CSPRandom Number Generation with Hash_DRB GRandom Number Generation with Hash_DRBG
DH Private KeyPrivate key used for Diffie- Hellman2048- 8192 bits - 112-200 bitsPrivate key - CSPKey Pair Generation with Safe PrimesShared Secret Computation with KAS- FFC-SSC
DH Public KeyPublic key used for Diffie- Hellman2048- 8192 bits - 112-200 bitsPublic key - PSPKey Pair Generation with Safe PrimesShared Secret Computation with KAS- FFC-SSC

G G © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 44
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
EC Private KeyPrivate key used for EC Diffie- Hellman and signature generation with ECDSAP-256, P- 384, P- 521 - 128, 192, 256 bitsPrivate key - CSPKey Pair Generation with ECDSAShared Secret Computation with KAS- ECC-SSC Signature Generation with ECDSA
EC Public KeyPublic key used for EC Diffie- Hellman and signature verification with ECDSAP-256, P- 384, P- 521 - 128, 192, 256 bitsPublic key - PSPKey Pair Generation with ECDSAShared Secret Computation with KAS- ECC-SSC Signature Verification with ECDSA
RSA Private KeyPrivate key used for RSA signature generation2048, 3072, 4096 bits - 112-150 bitsPrivate key - CSPKey Pair Generation with RSASignature Generation with RSA
RSA Public KeyPublic key used for RSA signature verificationKeyGen: 2048, 3072, 4096 bits; SigVer: 1024, 1280, 1536, 1792, 2048, 3072, 4096 bits - KeyGen: 112-150 bits; SigVer: 80-150 bitsPublic key - PSPKey Pair Generation with RSASignature Verification with RSA
Intermediat e key generation valueTemporary value generated during key256-8192 bits - 112- 256 bitsIntermediat e value - CSPKey Pair Generation with RSA Key Pair Generation with ECDSAKey Pair Generation with RSA Key Pair Generation with ECDSA

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 45
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
generation servicesKey Pair Generation with Safe PrimesKey Pair Generation with Safe Primes
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
AES KeyAPI input parameters (encrypted) API output parameters (encrypted)RAM:PlaintextUntil explicitly zeroized by operatorDestroy Object Module reset
HMAC KeyAPI input parameters (encrypted) API output parameters (encrypted)RAM:PlaintextUntil explicitly zeroized by operatorDestroy Object Module reset
Key- Derivation KeyAPI input parameters (encrypted) API output parameters (encrypted)RAM:PlaintextUntil explicitly zeroized by operatorDestroy Object Module resetKBKDF Derived Key:Derivation Of
Shared SecretAPI input parameters (encrypted) API output parameters (encrypted)RAM:PlaintextUntil explicitly zeroized by operatorDestroy Object Module resetDH Private Key:Derived From DH Public Key:Derived From EC Private Key:Derived From EC Public Key:Derived From HKDF Derived Key:Derivation Of TLS Derived Key:Derivation Of IKE Derived Key:Derivation Of

Table 18: SSP Table 1 © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 46
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
PasswordAPI input parameters (plaintext)RAM:PlaintextFor the duration of the serviceDestroy Object Module resetPBKDF Derived Key:Derivation Of
PBKDF Derived KeyAPI output parameters (encrypted)RAM:PlaintextUntil explicitly zeroized by operatorDestroy Object Module resetPassword:Derived From
KBKDF Derived KeyAPI output parameters (encrypted)RAM:PlaintextUntil explicitly zeroized by operatorDestroy Object Module resetKey-Derivation Key:Derived From
HKDF Derived KeyAPI output parameters (encrypted)RAM:PlaintextUntil explicitly zeroized by operatorDestroy Object Module resetShared Secret:Derived From
TLS Derived KeyAPI output parameters (encrypted)RAM:PlaintextUntil explicitly zeroized by operatorDestroy Object Module resetShared Secret:Derived From
IKE Derived KeyAPI output parameters (encrypted)RAM:PlaintextUntil explicitly zeroized by operatorDestroy Object Module resetShared Secret:Derived From
Entropy InputRAM:PlaintextFrom generation until DRBG Seed is createdAutomatic Module resetDRBG Seed:Derivation Of
DRBG SeedRAM:PlaintextWhile the DRBG is instantiatedAutomatic Module resetEntropy Input:Derived From Internal State (V, C):Generation Of
Internal State (V, C)RAM:PlaintextWhile the module is operationalModule resetDRBG Seed:Generated From
DH Private KeyAPI input parameters (encrypted)RAM:PlaintextUntil explicitly zeroized by operatorDestroy ObjectDH Public Key:Paired With Intermediate key

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 47
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
API output parameters (encrypted)Module resetgeneration value:Generated From
DH Public KeyAPI input parameters (plaintext) API output parameters (plaintext)RAM:PlaintextUntil explicitly zeroized by operatorDestroy Object Module resetDH Private Key:Paired With Intermediate key generation value:Generated From
EC Private KeyAPI input parameters (encrypted) API output parameters (encrypted)RAM:PlaintextUntil explicitly zeroized by operatorDestroy Object Module resetEC Public Key:Paired With Intermediate key generation value:Generated From
EC Public KeyAPI input parameters (plaintext) API output parameters (plaintext)RAM:PlaintextUntil explicitly zeroized by operatorDestroy Object Module resetEC Private Key:Paired With Intermediate key generation value:Generated From
RSA Private KeyAPI input parameters (encrypted) API output parameters (encrypted)RAM:PlaintextUntil explicitly zeroized by operatorDestroy Object Module resetRSA Public Key:Paired With Intermediate key generation value:Generated From
RSA Public KeyAPI input parameters (plaintext) API output parameters (plaintext)RAM:PlaintextUntil explicitly zeroized by operatorDestroy Object Module resetRSA Private Key:Paired With Intermediate key generation value:Generated From
Intermediate key generation valueRAM:PlaintextFor the duration of the serviceAutomaticDH Private Key:Generation Of DH Public Key:Generation Of EC Private Key:Generation Of EC Public Key:Generation Of RSA Private Key:Generation Of

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 48

Name

Input - Output

Storage

Storage Duration

Zeroization

Related SSPs RSA Public Key:Generation Of

9.5 Transitions

The SHA-1 algorithm as implemented by the module will be non-approved for all purposes, starting January 1, 2030. © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 49
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
HMAC- SHA2-256 (A5128)256-bit keyMessage authenticationSW/FW IntegrityModule becomes operational and services are available for useIntegrity test for libsoftokn3.so and libfreeblpriv3.so
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
SHA2-224 (A5128)512-bit messageKATCASTModule becomes operational and services are available for useMessage DigestModule initialization
SHA2-224 (A5136)512-bit messageKATCASTModule becomes operational and servicesMessage DigestModule initialization
10 Self-Tests
10.1 Pre-Operational Self-Tests

Table 20: Pre-Operational Self-Tests Each software component of the module has an associated HMAC-SHA2-256 integrity check value. The software integrity tests ensure that the module is not corrupted. The HMAC-SHA2-256 algorithm goes through a CAST before the software integrity tests are performed. Upon initialization, the module immediately performs all Freebl cryptographic algorithm self-tests (CASTs) as specified in the Conditional Self-Tests table. When all those self-tests pass successfully, the module automatically performs the pre-operational integrity test on the libfreeblpriv3.so file using its associated check value. Then, the module performs the RSA CAST in the Softoken library, followed by the pre-operational integrity test on the libsoftokn3.so file using its associated check value. Finally, all remaining CASTs for the algorithms implemented in Softoken are executed (see the Conditional Self-Tests table). Only if all CASTs and pre-operational integrity tests passed successfully, the module transitions to the operational state. No operator intervention is required to reach this point. While the module is executing the self-tests, services are not available, and data output (via the data output interface) is inhibited until the tests are successfully completed. If any of the self-tests fails, an error message is returned, and the module transitions to an error state.

10.2 Conditional Self-Tests

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 50
Algorithm or TestTest PropertiesTest MethodTest TypeIndicator are available for useDetailsConditions
SHA2-256 (A5128)512-bit messageKATCASTModule becomes operational and services are available for useMessage DigestModule initialization
SHA2-256 (A5136)512-bit messageKATCASTModule becomes operational and services are available for useMessage DigestModule initialization
SHA2-384 (A5128)512-bit messageKATCASTModule becomes operational and services are available for useMessage DigestModule initialization
SHA2-384 (A5136)512-bit messageKATCASTModule becomes operational and services are available for useMessage DigestModule initialization
SHA2-512 (A5128)512-bit messageKATCASTModule becomes operational and services are available for useMessage DigestModule initialization
SHA2-512 (A5136)512-bit messageKATCASTModule becomes operational and services are available for useMessage DigestModule initialization
AES-ECB (A5128)128, 192, 256- bit keyKATCASTModule becomes operational and servicesEncryption and decryptionModule initialization

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 51
Algorithm or TestTest PropertiesTest MethodTest TypeIndicator are available for useDetailsConditions
AES-ECB (A5135)128, 192, 256- bit keyKATCASTModule becomes operational and services are available for useEncryption and decryptionModule initialization
AES-CBC (A5128)128, 192, 256- bit keyKATCASTModule becomes operational and services are available for useEncryption and decryptionModule initialization
AES-CBC (A5135)128, 192, 256- bit keyKATCASTModule becomes operational and services are available for useEncryption and decryptionModule initialization
AES-GCM (A5128)128, 192, 256- bit keyKATCASTModule becomes operational and services are available for useEncryption and decryptionModule initialization
AES-GCM (A5135)128, 192, 256- bit keyKATCASTModule becomes operational and services are available for useEncryption and decryptionModule initialization
AES-CMAC (A5128)128, 192, 256- bit keyKATCASTModule becomes operational and services are available for useMessage AuthenticationModule initialization
HMAC-SHA2- 224 (A5128)288-bit keyKATCASTModule becomes operational and servicesMessage AuthenticationModule initialization

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 52
Algorithm or TestTest PropertiesTest MethodTest TypeIndicator are available for useDetailsConditions
HMAC-SHA2- 224 (A5136)288-bit keyKATCASTModule becomes operational and services are available for useMessage AuthenticationModule initialization
HMAC-SHA2- 256 (A5128)288-bit keyKATCASTModule becomes operational and services are available for useMessage AuthenticationModule initialization
HMAC-SHA2- 256 (A5136)288-bit keyKATCASTModule becomes operational and services are available for useMessage AuthenticationModule initialization
HMAC-SHA2- 384 (A5128)288-bit keyKATCASTModule becomes operational and services are available for useMessage AuthenticationModule initialization
HMAC-SHA2- 384 (A5136)288-bit keyKATCASTModule becomes operational and services are available for useMessage AuthenticationModule initialization
HMAC-SHA2- 512 (A5128)288-bit keyKATCASTModule becomes operational and services are available for useMessage AuthenticationModule initialization
HMAC-SHA2- 512 (A5136)288-bit keyKATCASTModule becomes operational and servicesMessage AuthenticationModule initialization

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 53
Algorithm or TestTest PropertiesTest MethodTest TypeIndicator are available for useDetailsConditions
KDF SP800- 108 (A5131)HMAC-SHA2- 256 in counter modeKATCASTModule becomes operational and services are available for useKey DerivationModule initialization
KDA HKDF Sp800-56Cr1 (A5127)SHA2-256KATCASTModule becomes operational and services are available for useKey DerivationModule initialization
TLS v1.2 KDF RFC7627 (A5128)SHA2-256KATCASTModule becomes operational and services are available for useKey DerivationModule initialization
TLS v1.2 KDF RFC7627 (A5136)SHA2-256KATCASTModule becomes operational and services are available for useKey DerivationModule initialization
KDF IKEv2 (A5132)SHA-1, SHA- 256, SHA- 384, SHA-512KATCASTModule becomes operational and services are available for useKey DerivationModule initialization
PBKDF (A5128)SHA2-256 with 5 iterations, 128-bit salt and 14 characters passwordKATCASTModule becomes operational and services are available for useKey DerivationModule initialization
PBKDF (A5136)SHA2-256 with 5 iterations,KATCASTModule becomes operationalKey DerivationModule initialization

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 54
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
128-bit salt and 14 characters passwordand services are available for use
Hash DRBG (A5128)SHA-256 without prediction resistanceKATCASTModule becomes operational and services are available for useInstantiate Generate; Reseed Generate (compliant to SP 800- 90Ar1 Section 11.3)Module initialization
Hash DRBG (A5136)SHA-256 without prediction resistanceKATCASTModule becomes operational and services are available for useInstantiate Generate; Reseed Generate (compliant to SP 800- 90Ar1 Section 11.3)Module initialization
KAS-FFC- SSC Sp800- 56Ar3 (A5128)ffdhe2048KATCASTModule becomes operational and services are available for useShared Secret ComputationModule initialization
KAS-ECC- SSC Sp800- 56Ar3 (A5128)P-256KATCASTModule becomes operational and services are available for useShared Secret ComputationModule initialization
RSA SigGen (FIPS186-5) (A5128)PKCS#1 v1.5 with SHA2- 256, SHA2- 384, SHA2- 512, and 2048-bit keyKATCASTModule becomes operational and services are available for useSignature GenerationModule initialization
RSA SigGen (FIPS186-5) (A5136)PKCS#1 v1.5 with SHA2- 256, SHA2- 384, SHA2- 512, and 2048-bit keyKATCASTModule becomes operational and services are available for useSignature GenerationModule initialization

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 55
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
RSA SigVer (FIPS186-5) (A5128)PKCS#1 v1.5 with SHA2- 256, SHA2- 384, SHA2- 512, and 2048-bit keyKATCASTModule becomes operational and services are available for useSignature VerificationModule initialization
RSA SigVer (FIPS186-5) (A5136)PKCS#1 v1.5 with SHA2- 256, SHA2- 384, SHA2- 512, and 2048-bit keyKATCASTModule becomes operational and services are available for useSignature VerificationModule initialization
ECDSA SigGen (FIPS186-5) (A5128)SHA2-256 and P-256KATCASTModule becomes operational and services are available for useSignature GenerationModule initialization
ECDSA SigGen (FIPS186-5) (A5136)SHA2-256 and P-256KATCASTModule becomes operational and services are available for useSignature GenerationModule initialization
ECDSA SigVer (FIPS186-5) (A5128)SHA2-256 and P-256KATCASTModule becomes operational and services are available for useSignature VerificationModule initialization
ECDSA SigVer (FIPS186-5) (A5136)SHA2-256 and P-256KATCASTModule becomes operational and services are available for useSignature VerificationModule initialization
Safe Primes Key Generation (A5128)N/APCTPCTSuccessful key pair generationPCT according to section 5.6.2.1.4 of [SP800-56Ar3]Key Pair Generation with Safe Primes

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 56
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
ECDSA KeyGen (FIPS186-5) (A5128), SP 800-56A Rev. 3 PCTN/APCTPCTSuccessful key pair generationPCT according to section 5.6.2.1.4 of SP 800-56A Rev. 3Key Pair Generation with ECDSA
ECDSA KeyGen (FIPS186-5) (A5128), signature PCTSHA-256PCTPCTSuccessful key pair generationSignature Generation and Signature VerificationKey Pair Generatio with ECDSA
RSA KeyGen (FIPS186-5) (A5128)PKCS#1 v1.5 with SHA-256PCTPCTSuccessful key pair generationSignature Generation and Signature VerificationKey Pair Generation with RSA
RSA KeyGen (FIPS186-5) (A5136)PKCS#1 v1.5 with SHA-256PCTPCTSuccessful key pair generationSignature Generation and Signature VerificationKey Pair Generation with RSA
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2-256 (A5128)Message authenticationSW/FW IntegrityOn demandManually

Table 21: Conditional Self-Tests The module performs self-tests on all FIPS approved cryptographic algorithms as part of the approved services supported in the approved mode of operation, using the tests shown in the Conditional SelfTests table above. Upon generation of a key pair, the module will perform a pair-wise consistency test (PCT) as shown in the table above, which provides some assurance that the generated key pair is well formed. For DH and EC key pairs, these tests consist of the PCT described in Section 5.6.2.1.4 of SP 800-56Ar3. For RSA and EC key pairs, this test consists of a signature generation and a signature verification operation. Note that two PCTs are performed for EC key pairs.

10.3 Periodic Self-Test Information

Table 22: Pre-Operational Periodic Information © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 57
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
SHA2-224 (A5128)KATCASTOn demandManually
SHA2-224 (A5136)KATCASTOn demandManually
SHA2-256 (A5128)KATCASTOn demandManually
SHA2-256 (A5136)KATCASTOn demandManually
SHA2-384 (A5128)KATCASTOn demandManually
SHA2-384 (A5136)KATCASTOn demandManually
SHA2-512 (A5128)KATCASTOn demandManually
SHA2-512 (A5136)KATCASTOn demandManually
AES-ECB (A5128)KATCASTOn demandManually
AES-ECB (A5135)KATCASTOn demandManually
AES-CBC (A5128)KATCASTOn demandManually
AES-CBC (A5135)KATCASTOn demandManually
AES-GCM (A5128)KATCASTOn demandManually
AES-GCM (A5135)KATCASTOn demandManually
AES-CMAC (A5128)KATCASTOn demandManually
HMAC-SHA2-224 (A5128)KATCASTOn demandManually

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 58
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2-224 (A5136)KATCASTOn demandManually
HMAC-SHA2-256 (A5128)KATCASTOn demandManually
HMAC-SHA2-256 (A5136)KATCASTOn demandManually
HMAC-SHA2-384 (A5128)KATCASTOn demandManually
HMAC-SHA2-384 (A5136)KATCASTOn demandManually
HMAC-SHA2-512 (A5128)KATCASTOn demandManually
HMAC-SHA2-512 (A5136)KATCASTOn demandManually
KDF SP800-108 (A5131)KATCASTOn demandManually
KDA HKDF Sp800-56Cr1 (A5127)KATCASTOn demandManually
TLS v1.2 KDF RFC7627 (A5128)KATCASTOn demandManually
TLS v1.2 KDF RFC7627 (A5136)KATCASTOn demandManually
KDF IKEv2 (A5132)KATCASTOn demandManually
PBKDF (A5128)KATCASTOn demandManually
PBKDF (A5136)KATCASTOn demandManually
Hash DRBG (A5128)KATCASTOn demandManually
Hash DRBG (A5136)KATCASTOn demandManually

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 59
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
KAS-FFC-SSC Sp800-56Ar3 (A5128)KATCASTOn demandManually
KAS-ECC-SSC Sp800-56Ar3 (A5128)KATCASTOn demandManually
RSA SigGen (FIPS186-5) (A5128)KATCASTOn demandManually
RSA SigGen (FIPS186-5) (A5136)KATCASTOn demandManually
RSA SigVer (FIPS186-5) (A5128)KATCASTOn demandManually
RSA SigVer (FIPS186-5) (A5136)KATCASTOn demandManually
ECDSA SigGen (FIPS186-5) (A5128)KATCASTOn demandManually
ECDSA SigGen (FIPS186-5) (A5136)KATCASTOn demandManually
ECDSA SigVer (FIPS186-5) (A5128)KATCASTOn demandManually
ECDSA SigVer (FIPS186-5) (A5136)KATCASTOn demandManually
Safe Primes Key Generation (A5128)PCTPCTOn demandManually
ECDSA KeyGen (FIPS186-5) (A5128), SP 800- 56A Rev. 3 PCTPCTPCTOn demandManually

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 60
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
ECDSA KeyGen (FIPS186-5) (A5128), signature PCTPCTPCTOn demandManually
RSA KeyGen (FIPS186-5) (A5128)PCTPCTOn demandManually
RSA KeyGen (FIPS186-5) (A5136)PCTPCTOn demandManually
NameDescriptionConditionsRecovery MethodIndicator
Power- On ErrorAn error occurred during the self-tests executed on power-onSoftware integrity test failure or CAST failureRestart of the moduleModule will not load
PCT ErrorAn error occurred during a PCTPCT failureRestart of the moduleModule stops functioning (sftk_fatalError is set to TRUE)

Table 23: Conditional Periodic Information

10.4 Error States

Table 24: Error States In any error state, the output interface is inhibited, and the module accepts no more inputs or requests.

10.5 Operator Initiation of Self-Tests

The software integrity tests and CASTs can be invoked on demand by unloading and subsequently reinitializing the module. The PCTs can be invoked on demand by requesting the Key Pair Generation service. © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 61
11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

Before the nss-softokn-3.90.0-6.el9_2.tuxcare.1 and nss-softokn-freebl-3.90.0-6.el9_2.tuxcare.1 RPM packages are installed, the AlmaLinux 9 system must operate in the approved mode. This can be achieved by:

11.2 Administrator Guidance

The version of the RPMs containing the FIPS validated Module is stated in section 11.1. The RPM packages forming the Module can be installed by standard tools recommended for the installation of RPM packages on an AlmaLinux system (for example, dnf and rpm). All RPM packages are signed with the TuxCare build key, which is an RSA 4096-bit key using SHA-256 signatures. The signature is automatically verified upon installation of the RPM package. If the signature cannot be validated, the RPM tool rejects the installation of the package. In such a case, the Crypto Officer is requested to obtain a new copy of the module's RPMs from TuxCare.

11.3 Non-Administrator Guidance

There is no non-administrator guidance.

11.4 End of Life

As the module does not persistently store SSPs, secure sanitization of the module consists of unloading the module. This will zeroize all SSPs in volatile memory. Then, if desired, the nss-softokn-3.90.06.el9_2.tuxcare.1 and nss-softokn-freebl-3.90.0-6.el9_2.tuxcare.1 RPM packages can be uninstalled from the AlmaLinux 9 systems. © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 62
12 Mitigation of Other Attacks
12.1 Attack List

Timing attacks on RSA

Page 63
Table, extracted as text (did not parse into structured rows)
Appendix A. Glossary and Abbreviations AES                     Advanced Encryption Standard CAVP                    Cryptographic Algorithm Validation Program CBC                     Cipher Block Chaining CMAC                    Cipher-based Message Authentication Code CMVP                    Cryptographic Module Validation Program CSP                     Critical Security Parameter CTR                     Counter Mode DRBG                    Deterministic Random Bit Generator ECB                     Electronic Code Book FIPS                    Federal Information Processing Standards Publication GCM                     Galois Counter Mode HMAC                    Hash Message Authentication Code KAT                     Known Answer Test KW                      AES Key Wrap MAC                     Message Authentication Code NIST                    National Institute of Science and Technology PAA                     Processor Algorithm Acceleration PAI                     Processor Algorithm Implementation PR                      Prediction Resistance PSP                     Public Security Parameter PSS                     Probabilistic Signature Scheme RNG                     Random Number Generator RSA                     Rivest, Shamir, Adleman SHA                     Secure Hash Algorithm SSP                     Sensitive Security Parameter XTS                     XEX-based Tweaked-codebook mode with cipher text Stealing © 2025 Cloudlinux Inc., TuxCare division/atsec information security.
Page 64

Appendix B. References FIPS140-3 FIPS PUB 140-3 - Security Requirements For Cryptographic Modules March 2019 https://doi.org/10.6028/NIST.FIPS.140-3 FIPS140-3_IG Implementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program January 2024 https://csrc.nist.gov/csrc/media/Projects/cryptographic-module-validationprogram/documents/fips%20140-3/FIPS%20140-3%20IG.pdf FIPS180-4 Secure Hash Standard (SHS) March 2012 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf FIPS186-2 Digital Signature Standard (DSS) January 2000 https://csrc.nist.gov/files/pubs/fips/186-2/final/docs/fips186-2.pdf FIPS186-4 Digital Signature Standard (DSS) July 2013 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-4.pdf FIPS186-5 Digital Signature Standard (DSS) February 2023 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-5.pdf FIPS197 Advanced Encryption Standard November 2001 https://csrc.nist.gov/publications/fips/fips197/fips-197.pdf FIPS198-1 The Keyed Hash Message Authentication Code (HMAC) July 2008 https://csrc.nist.gov/publications/fips/fips198-1/FIPS-198-1_final.pdf SP800-38A NIST Special Publication 800-38A - Recommendation for Block Cipher Modes of Operation Methods and Techniques December 2001 https://csrc.nist.gov/publications/nistpubs/800-38a/sp800-38a.pdf SP800-38B NIST Special Publication 800-38B - Recommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication May 2005 https://csrc.nist.gov/publications/detail/sp/800-38b/final SP800-38D NIST Special Publication 800-38D - Recommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC November 2007 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38d.pdf SP800-38E NIST Special Publication 800-38E - Recommendation for Block Cipher Modes of Operation: The XTS AES Mode for Confidentiality on Storage Devices January 2010 https://csrc.nist.gov/publications/nistpubs/800-38E/nist-sp-800-38E.pdf SP800-38F NIST Special Publication 800-38F - Recommendation for Block Cipher Modes of Operation: Methods for Key Wrapping December 2012 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38F.pdf SP800-52rev2 NIST Special Publication 800-52

Page 65

August 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Cr2.pdf SP800-90Arev1 NIST Special Publication 800-90A