All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Red Hat Enterprise Linux 9 Kernel Cryptographic API

Certificate#5034StandardFIPS 140-3Level1TypeSoftwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorRed Hat, Inc.
Medium review priority  ·  exposes kernel crypto consumer  ·  Linux kernel upstream has published 6636 CVEs since this module's initial validation  ·  last validated 13 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date6/29/2030
CaveatWhen operated in approved mode. The module generates random numbers whose strengths are modified by available entropy. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs
VendorRed Hat, Inc.

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Red Hat Enterprise Linux 9 Kernel Cryptographic API
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Recovery</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>IKEV<br/>IPSEC</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Red Hat Enterprise Linux 9 Kernel Cryptographic API
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Recovery</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>IKEV<br/>IPSEC</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Red Hat, Inc. Red Hat Enterprise Linux 9 Kernel Cryptographic API Document Version: 1.1 Last Modified: 06/23/2025 Prepared by: atsec information security corporation

4516 Seton Center Pkwy, Suite 250

Austin, TX 78759 www.atsec.com © 2024 Red Hat, Inc./ atsec information security.

Page 2
Table of Contents
#SectionPage
Page 3

© 2024 Red Hat, Inc./ atsec information security.

Page 4
List of Tables
ItemPage
Table 1: Security Levels5
Table 3: Tested Operational Environments - Software, Firmware, Hybrid8
Table 4: Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid8
Table 5: Modes List and Description9
Table 6: Approved Algorithms19
Table 7: Non-Approved, Not Allowed Algorithms19
Table 8: Security Function Implementations24
Table 9: Entropy Certificates25
Table 10: Entropy Sources25
Table 11: Ports and Interfaces27
Table 12: Roles28
Table 13: Approved Services33
Table 14: Non-Approved Services33
Table 15: Storage Areas38
Table 16: SSP Input-Output Methods38
Table 17: SSP Zeroization Methods39
Table 18: SSP Table 140
Table 19: SSP Table 241
Table 20: Pre-Operational Self-Tests42
Table 21: Conditional Self-Tests68
Table 22: Pre-Operational Periodic Information69
Table 23: Conditional Periodic Information75
Table 24: Error States76
Figure 1: Block Diagram7
Page 5
SectionTitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication1
5Software/Firmware security1
6Operational environment1
7Physical securityN/A
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacksN/A
Overall Level1
1.1 Overview

This document is the non-proprietary FIPS 140-3 Security Policy for version kernel 5.14.0284.57.1.el9_2; libkcapi 1.3.1-3.el9 of the Red Hat Enterprise Linux 9 Kernel Cryptographic API module. It contains the security rules under which the module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for an overall Security Level 1 module. intact and including this notice. Other documentation is proprietary to their authors.

1.1.1 How this Security Policy was prepared

which was further consolidated into this document by atsec information security together with other vendor-supplied documentation. In preparing the Security Policy document, the laboratory formatted the vendor-supplied documentation for consolidation without altering the technical statements therein contained. The further refining of the Security Policy document was conducted iteratively throughout the conformance testing, wherein the Security Policy was submitted to the vendor, who would then edit, modify, and add technical contents. The vendor would also supply additional documentation, which the laboratory formatted into the existing Security Policy, and resubmitted to the vendor for their final editing.

1.2 Security Levels

Table 1: Security Levels © 2024 Red Hat, Inc./ atsec information security.

Page 6
2 Cryptographic Module Specification
2.1 Description

Purpose and Use: The Red Hat Enterprise Linux 9 Kernel Cryptographic API (hereafter referred to as “the module”) provides a C language application program interface (API) for use by other (kernel space and user space) processes that require cryptographic functionality. The module operates on a general-purpose computer as part of the Linux kernel. Its cryptographic functionality can be accessed using the Linux Kernel Crypto API. Module Type: Software Module Embodiment: MultiChipStand Cryptographic Boundary: The cryptographic boundary of the module is defined as the kernel binary and the kernel crypto object files, the libkcapi library, and the sha512hmac binary, which is used to verify the integrity of the software components. In addition, the cryptographic boundary contains the .hmac files which store the expected integrity values for each of the software components. Tested Operational Environment’s Physical Perimeter (TOEPP): The TOEPP of the module is defined as the general-purpose computer on which the module is installed. © 2024 Red Hat, Inc./ atsec information security.

Page 7
Package or File NameSoftware/ Firmware VersionFeature sIntegrity Test
/boot/vmlinuz-5.14.0-284.57.1.el9_2.x86_64 /boot/vmlinuz-5.14.0-284.57.1.el9_2.s390x /boot/vmlinuz-5.14.0-284.57.1.el9_2.ppc64le5.14.0- 284.57.1.el9_ 2N/AHMAC- SHA-512
*.ko and *.ko.xz files in /usr/lib/modules/5.14.0- 284.57.1.el9_2.x86_64/kernel/crypto *.ko and *.ko.xz files in /usr/lib/modules/5.14.0- 284.57.1.el9_2.x86_64/kernel/arch/x86/crypto *.ko and *.ko.xz files in /usr/lib/modules/5.14.0- 284.57.1.el9_2.s390x/kernel/crypto *.ko and *.ko.xz files in /usr/lib/modules/5.14.0- 284.57.1.el9_2.s390x/kernel/arch/s390x/crypto *.ko and *.ko.xz files in /usr/lib/modules/5.14.0- 284.57.1.el9_2.ppc64le/kernel/crypto *.ko and5.14.0- 284.57.1.el9_ 2N/ARSA signature verificatio n
2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification

Page 8
Package or File Name *.ko.xz files in /usr/lib/modules/5.14.0- 284.57.1.el9_2.ppc64le/kernel/arch/powerpc/cryp toPackage or File NameSoftware/ Firmware VersionFeature sIntegrity Test
/usr/lib64/libkcapi.so.1.3.1, /usr/bin/sha512hmac1.3.1-3.el9N/AHMAC SHA-512
Operating SystemHardware PlatformProcessorsPAA/PAIHypervisor or Host OSVersion(s)
Red Hat Enterprise Linux 9Dell PowerEdge R440Intel(R) Xeon(R) Silver 4216YesN/A5.14.0- 284.57.1.el9_2; 1.3.1-3.el9
Red Hat Enterprise Linux 9Dell PowerEdge R440Intel(R) Xeon(R) Silver 4216NoN/A5.14.0- 284.57.1.el9_2; 1.3.1-3.el9
Red Hat Enterprise Linux 9IBM z16 3931-A01IBM z16YesN/A5.14.0- 284.57.1.el9_2; 1.3.1-3.el9
Red Hat Enterprise Linux 9IBM z16 3931-A01IBM z16NoN/A5.14.0- 284.57.1.el9_2; 1.3.1-3.el9
Red Hat Enterprise Linux 9IBM 9080- HEXIBM POWER10YesPowerVM FW1040.00 with VIOS 3.1.3.005.14.0- 284.57.1.el9_2; 1.3.1-3.el9
Red Hat Enterprise Linux 9IBM 9080- HEXIBM POWER10NoPowerVM FW1040.00 with VIOS 3.1.3.005.14.0- 284.57.1.el9_2; 1.3.1-3.el9
Operating SystemHardware Platform
Red Hat Enterprise Linux 9Intel(R) Xeon(R) E5

Table 2: Tested Module Identification

Page 9
Mode NameDescriptionTypeStatus Indicator
Approved modeAutomatically entered whenever an approved service is requested.ApprovedEquivalent to the indicator of the requested service as defined in section 4.3
Non- approved modeAutomatically entered whenever a non-approved service is requested.Non- ApprovedEquivalent to the indicator of the requested service as defined in section 4.3
AlgorithmCAVP CertPropertiesReference
AES-CBCA5081Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBCA5088Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBCA5091Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBCA5561Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBCA5562Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBCA5565Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS3A5085Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
2.3 Excluded Components

There are no components within the cryptographic boundary excluded from the FIPS 140-3 requirements.

2.4 Modes of Operation

Modes List and Description: Table 5: Modes List and Description After passing all pre-operational self-tests and cryptographic algorithm self-tests executed on start-up, the module automatically transitions to the approved mode. Mode Change Instructions and Status: The module automatically switches between the approved and non-approved modes depending on the services requested by the operator. The status indicator of the mode of

2.5 Algorithms

Approved Algorithms: © 2024 Red Hat, Inc./ atsec information security.

Page 10
AlgorithmCAVP CertPropertiesReference
AES-CBC-CS3A5096Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS3A5570Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CCMA5081Key Length - 128, 192, 256SP 800-38C
AES-CCMA5091Key Length - 128, 192, 256SP 800-38C
AES-CCMA5562Key Length - 128, 192, 256SP 800-38C
AES-CCMA5565Key Length - 128, 192, 256SP 800-38C
AES-CFB128A5083Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB128A5094Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB128A5568Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CMACA5081Direction - Generation, Verification Key Length - 128, 192, 256SP 800-38B
AES-CMACA5091Direction - Generation, Verification Key Length - 128, 192, 256SP 800-38B
AES-CMACA5562Direction - Generation, Verification Key Length - 128, 192, 256SP 800-38B
AES-CMACA5565Direction - Generation, Verification Key Length - 128, 192, 256SP 800-38B
AES-CTRA5081Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CTRA5088Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CTRA5091Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CTRA5561Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CTRA5562Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CTRA5565Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA5081Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA5086Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA5087Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA5088Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA5089Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA5090Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA5091Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA5092Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A

© 2024 Red Hat, Inc./ atsec information security.

Page 11
AlgorithmCAVP CertPropertiesReference
AES-ECBA5093Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA5562Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA5563Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA5564Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA5565Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA5566Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA5567Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-GCMA5081Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GCMA5086Direction - Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GCMA5087Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GCMA5088Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GCMA5089Direction - Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GCMA5090Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GCMA5091Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GCMA5092Direction - Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GCMA5093Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D

© 2024 Red Hat, Inc./ atsec information security.

Page 12
AlgorithmCAVP CertPropertiesReference
AES-GCMA5562Direction - Decrypt, Encrypt IV Generation - External Key Length - 128, 192, 256SP 800-38D
AES-GCMA5563Direction - Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GCMA5564Direction - Decrypt, Encrypt IV Generation - External Key Length - 128, 192, 256SP 800-38D
AES-GCMA5565Direction - Decrypt, Encrypt IV Generation - External Key Length - 128, 192, 256SP 800-38D
AES-GCMA5566Direction - Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GCMA5567Direction - Decrypt, Encrypt IV Generation - External Key Length - 128, 192, 256SP 800-38D
AES-GMACA5081Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GMACA5091Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GMACA5562Direction - Decrypt, Encrypt IV Generation - External Key Length - 128, 192, 256SP 800-38D
AES-GMACA5565Direction - Decrypt, Encrypt IV Generation - External Key Length - 128, 192, 256SP 800-38D
AES-OFBA5084Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-OFBA5095Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-OFBA5569Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-XTS Testing Revision 2.0A5081Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38E
AES-XTS Testing Revision 2.0A5088Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38E
AES-XTS Testing Revision 2.0A5091Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38E
AES-XTS Testing Revision 2.0A5561Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38E
AES-XTS Testing Revision 2.0A5562Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38E

© 2024 Red Hat, Inc./ atsec information security.

Page 13
AlgorithmCAVP CertPropertiesReference
AES-XTS Testing Revision 2.0A5565Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38E
Counter DRBGA5081Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
Counter DRBGA5086Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
Counter DRBGA5087Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
Counter DRBGA5088Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
Counter DRBGA5089Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
Counter DRBGA5090Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
Counter DRBGA5091Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
Counter DRBGA5092Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
Counter DRBGA5093Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
Counter DRBGA5562Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
Counter DRBGA5563Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
Counter DRBGA5564Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
Counter DRBGA5565Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
Counter DRBGA5566Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
Counter DRBGA5567Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
Hash DRBGA5081Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1

© 2024 Red Hat, Inc./ atsec information security.

Page 14
AlgorithmCAVP CertPropertiesReference
Hash DRBGA5086Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
Hash DRBGA5087Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
Hash DRBGA5088Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
Hash DRBGA5089Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
Hash DRBGA5090Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
Hash DRBGA5091Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
Hash DRBGA5092Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
Hash DRBGA5093Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
Hash DRBGA5097Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
Hash DRBGA5098Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
Hash DRBGA5099Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
Hash DRBGA5563Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
Hash DRBGA5564Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
Hash DRBGA5565Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
Hash DRBGA5566Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
Hash DRBGA5567Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
HMAC DRBGA5081Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
HMAC DRBGA5086Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
HMAC DRBGA5087Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
HMAC DRBGA5088Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
HMAC DRBGA5089Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
HMAC DRBGA5090Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
HMAC DRBGA5091Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
HMAC DRBGA5092Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
HMAC DRBGA5093Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1

© 2024 Red Hat, Inc./ atsec information security.

Page 15
AlgorithmCAVP CertPropertiesReference
HMAC DRBGA5097Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
HMAC DRBGA5098Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
HMAC DRBGA5099Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
HMAC DRBGA5563Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
HMAC DRBGA5564Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
HMAC DRBGA5565Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
HMAC DRBGA5566Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
HMAC DRBGA5567Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
HMAC-SHA-1A5081Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA-1A5097Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA-1A5098Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA-1A5099Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA-1A5565Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2-224A5081Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2-224A5097Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2-224A5098Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2-224A5099Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2-224A5565Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2-256A5081Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2-256A5097Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2-256A5098Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2-256A5099Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2-256A5565Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2-384A5081Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2-384A5097Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1

© 2024 Red Hat, Inc./ atsec information security.

Page 16
AlgorithmCAVP CertPropertiesReference
HMAC-SHA2-384A5098Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2-384A5099Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2-384A5565Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2-512A5081Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2-512A5097Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2-512A5098Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2-512A5099Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2-512A5565Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA3-224A5082Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA3-224A5571Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA3-256A5082Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA3-256A5571Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA3-384A5082Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA3-384A5571Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA3-512A5082Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA3-512A5571Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
RSA SigVer (FIPS186- 4)A5081Signature Type - PKCS 1.5 Modulo - 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186- 4)A5097Signature Type - PKCS 1.5 Modulo - 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186- 4)A5098Signature Type - PKCS 1.5 Modulo - 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186- 4)A5099Signature Type - PKCS 1.5 Modulo - 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186- 4)A5565Signature Type - PKCS 1.5 Modulo - 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186- 5)A5081Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5FIPS 186-5
RSA SigVer (FIPS186- 5)A5097Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5FIPS 186-5
RSA SigVer (FIPS186- 5)A5098Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5FIPS 186-5
RSA SigVer (FIPS186- 5)A5099Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5FIPS 186-5

© 2024 Red Hat, Inc./ atsec information security.

Page 17
AlgorithmCAVP CertPropertiesReference
RSA SigVer (FIPS186- 5)A5565Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5FIPS 186-5
SHA-1A5081Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA-1A5097Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA-1A5098Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA-1A5099Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA-1A5565Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-224A5081Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-224A5097Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-224A5098Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-224A5099Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-224A5565Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-256A5081Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-256A5097Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-256A5098Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-256A5099Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-256A5565Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-384A5081Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4

© 2024 Red Hat, Inc./ atsec information security.

Page 18
AlgorithmCAVP CertPropertiesReference
SHA2-384A5097Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-384A5098Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-384A5099Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-384A5565Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-512A5081Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-512A5097Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-512A5098Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-512A5099Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-512A5565Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA3-224A5082Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 202
SHA3-224A5571Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 202
SHA3-256A5082Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 202
SHA3-256A5571Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 202
SHA3-384A5082Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 202
SHA3-384A5571Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 202
SHA3-512A5082Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 202

© 2024 Red Hat, Inc./ atsec information security.

Page 19
AlgorithmCAVP CertPropertiesReference
SHA3-512A5571Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 202
NameUse and Function
AES GCM with external IVEncryption
KBKDF (libkcapi)Key derivation
HKDF (libkcapi)Key derivation
PBKDF2 (libkcapi)Password-based key derivation
RSAEncryption primitive; Decryption primitive
RSA with PKCS#1 v1.5 paddingSignature generation (pre-hashed message); Signature verification (pre-hashed message); Key encapsulation; Key un-encapsulation
NameTypeDescriptionPropertiesAlgorithms
Encryption with AESBC-UnAuthEncrypt a plaintext with AESKey size(s):128, 192, 256 bits (XTS mode 128 and 256 bits only)AES-CBC: (A5081, A5088, A5091, A5561, A5562, A5565) AES-CBC-CS3: (A5085, A5096, A5570) AES-CFB128: (A5083, A5094, A5568) AES-CTR: (A5081, A5088, A5091, A5561, A5562, A5565) AES-ECB:

Table 6: Approved Algorithms Vendor-Affirmed Algorithms: N/A for this module. Non-Approved, Allowed Algorithms: N/A for this module. Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. Non-Approved, Not Allowed Algorithms: Table 7: Non-Approved, Not Allowed Algorithms

2.6 Security Function Implementations

© 2024 Red Hat, Inc./ atsec information security.

Page 20
NameTypeDescriptionPropertiesAlgorithms
(A5081, A5086, A5087, A5088, A5089, A5090, A5091, A5092, A5093, A5562, A5563, A5564, A5565, A5566, A5567) AES-OFB: (A5084, A5095, A5569) AES-XTS Testing Revision 2.0: (A5081, A5088, A5091, A5561, A5562, A5565)
Decryption with AESBC-UnAuthDecrypt a ciphertext with AESKey size(s):128, 192, 256 bits (XTS mode 128 and 256 bits only)AES-CBC: (A5081, A5088, A5091, A5561, A5562, A5565) AES-CBC-CS3: (A5085, A5096, A5570) AES-CFB128: (A5083, A5094, A5568) AES-CTR: (A5081, A5088, A5091, A5561, A5562, A5565) AES-ECB: (A5081, A5086, A5087, A5088, A5089, A5090, A5091, A5092, A5093, A5562, A5563, A5564, A5565, A5566, A5567) AES-OFB: (A5084, A5095, A5569) AES-XTS Testing Revision 2.0: (A5081, A5088, A5091, A5561, A5562, A5565)
HashingSHACompute a message digestSHA-1: (A5081, A5097, A5098, A5099, A5565)

© 2024 Red Hat, Inc./ atsec information security.

Page 21
NameTypeDescriptionPropertiesAlgorithms
SHA2-224: (A5081, A5097, A5098, A5099, A5565) SHA2-256: (A5081, A5097, A5098, A5099, A5565) SHA2-384: (A5081, A5097, A5098, A5099, A5565) SHA2-512: (A5081, A5097, A5098, A5099, A5565) SHA3-224: (A5082, A5571) SHA3-256: (A5082, A5571) SHA3-384: (A5082, A5571) SHA3-512: (A5082, A5571)
Message authenticationMACCompute a MAC tag for authenticationHMAC key size(s):112- 524288 bits (112-256 bits) AES key size(s):128, 192, 256 bitsAES-CMAC: (A5081, A5091, A5562, A5565) AES-GMAC: (A5081, A5091, A5562, A5565) HMAC-SHA-1: (A5081, A5097, A5098, A5099, A5565) HMAC-SHA2- 224: (A5081, A5097, A5098, A5099, A5565) HMAC-SHA2- 256: (A5081, A5097, A5098, A5099, A5565) HMAC-SHA2- 384: (A5081, A5097, A5098, A5099, A5565) HMAC-SHA2- 512: (A5081, A5097, A5098, A5099, A5565) HMAC-SHA3- 224: (A5082,

© 2024 Red Hat, Inc./ atsec information security.

Page 22
NameTypeDescriptionPropertiesAlgorithms
A5571) HMAC-SHA3- 256: (A5082, A5571) HMAC-SHA3- 384: (A5082, A5571) HMAC-SHA3- 512: (A5082, A5571)
Random number generation with DRBGsDRBGGenerate random numbers from DRBGsCounter DRBG: (A5081, A5086, A5087, A5088, A5089, A5090, A5091, A5092, A5093, A5562, A5563, A5564, A5565, A5566, A5567) Hash DRBG: (A5081, A5086, A5087, A5088, A5089, A5090, A5091, A5092, A5093, A5097, A5098, A5099, A5563, A5564, A5565, A5566, A5567) HMAC DRBG: (A5081, A5086, A5087, A5088, A5089, A5090, A5091, A5092, A5093, A5097, A5098, A5099, A5563, A5564, A5565, A5566, A5567)
Signature verification with RSADigSig-SigVerVerify a signature with RSAPadding:PKCS#1 v1.5 Hashes:SHA1, SHA-224, SHA- 256, SHA-384, SHA-512 Key size(s):2048, 3072, 4096 bits (112, 128, 150 bits)RSA SigVer (FIPS186-4): (A5081, A5097, A5098, A5099, A5565) RSA SigVer (FIPS186-5): (A5081, A5097, A5098, A5099, A5565)

© 2024 Red Hat, Inc./ atsec information security.

Page 23
NameTypeDescriptionPropertiesAlgorithms
Authenticated encryption with AESBC-AuthEncrypt and authenticate a plaintext with AESKey size(s):128, 192, 256 bitsAES-CCM: (A5081, A5091, A5562, A5565) AES-GCM: (A5081, A5086, A5087, A5088, A5089, A5090, A5091, A5092, A5093, A5562, A5563, A5564, A5565, A5566, A5567)
Authenticated decryption with AESBC-AuthDecrypt and authenticate a ciphertext with AESKey size(s):128, 192, 256 bitsAES-CCM: (A5081, A5091, A5562, A5565) AES-GCM: (A5081, A5087, A5088, A5090, A5091, A5092, A5086, A5089, A5093, A5562, A5563, A5564, A5565, A5566, A5567)
AES CCMKTS-WrapKey wrapping; Key unwrappingKey size(s):128, 192, 256 bitsAES-CCM: (A5081, A5091, A5562, A5565)
AES GCM with internal IVKTS-WrapKey wrappingKey size(s):128, 192, 256 bitsAES-GCM: (A5086, A5089, A5092, A5563, A5566)
AES GCM with external IVKTS-WrapKey unwrappingKey sizes(s):128, 192, 256 bitsAES-GCM: (A5081, A5087, A5090, A5091, A5093, A5562, A5564, A5565, A5567, A5088)
AES CBC with HMAC SHA-1, HMAC SHA-256, HMAC SHA-384, or HMAC SHA- 512KTS-WrapKey wrapping; Key unwrappingKey sizes(s):128, 192, 256 bitsAES-CBC: (A5081, A5088, A5091, A5561, A5562, A5565) HMAC-SHA-1: (A5081, A5097, A5098, A5099, A5565) HMAC-SHA2- 256: (A5081, A5097, A5098, A5099, A5565) HMAC-SHA2- 384: (A5081, A5097, A5098,

© 2024 Red Hat, Inc./ atsec information security.

Page 24
NameTypeDescriptionPropertiesAlgorithms
A5099, A5565) HMAC-SHA2- 512: (A5081, A5097, A5098, A5099, A5565)
AES CTR with HMAC SHA-1, HMAC SHA-256, HMAC SHA-384, or HMAC SHA- 512KTS-WrapKey wrapping; Key unwrappingKey size(s):128, 192, 256 bitsAES-CTR: (A5081, A5088, A5091, A5561, A5562, A5565) HMAC-SHA-1: (A5081, A5097, A5098, A5099, A5565) HMAC-SHA2- 256: (A5081, A5097, A5098, A5099, A5565) HMAC-SHA2- 384: (A5081, A5097, A5098, A5099, A5565) HMAC-SHA2- 512: (A5081, A5097, A5098, A5099, A5565)

Table 8: Security Function Implementations

2.7 Algorithm Specific Information
2.7.1 AES GCM IV

The Crypto Officer shall consider the following requirements and restrictions when using the module. For IPsec, the module offers the AES GCM implementation and uses the context of Scenario

1 of FIPS 140-3 IG C.H. The mechanism for IV generation is compliant with RFC 4106. IVs

generated using this mechanism may only be used in the context of AES GCM encryption within the IPsec protocol. The module does not implement IPsec. The module’s implementation of AES GCM is used together with an application that runs outside the module’s cryptographic boundary. This application must use RFC 7296 compliant IKEv2 to establish the shared secret SKEYSEED from which the AES GCM encryption keys are derived. The design of the IPsec protocol implicitly ensures that the counter (the nonce_explicit part of the IV) does not exhaust the maximum number of possible values for a given session key. In the event the module’s power is lost and restored, the consuming application must ensure that a new key for use with the AES GCM key encryption or decryption under this scenario shall be established. © 2024 Red Hat, Inc./ atsec information security.

Page 25
CertVendor
NumberName
E54Red Hat, Inc.
NameTypeOperational EnvironmentSample SizeEntropy per SampleConditioning Component
RHEL Kernel CPU Time Jitter RNG Entropy SourceNon- PhysicalRed Hat Enterprise Linux 9 on Dell PowerEdge R440 on Intel(R) Xeon(R) Silver 4216; Red Hat Enterprise Linux 9 on IBM z16 3931-A01 on IBM z16; Red Hat Enterprise Linux 9 on PowerVM FW1040.00 with VIOS 3.1.3.00 on IBM 9080 HEX on IBM POWER1064 bits59.62 bitsLinear- Feedback Shift Register (LFSR)

The module also provides a non-approved AES GCM encryption service which accepts arbitrary external IVs from the operator. This service can be requested by invoking the crypto_aead_encrypt API function with an AES GCM handle. When this is the case, the API will not set an approved service indicator, as described in section 4.3.

2.7.2 AES XTS

The length of a single data unit encrypted or decrypted with AES XTS shall not exceed 220 AES blocks, that is 16MB, of data per XTS instance. An XTS instance is defined in Section 4 of SP 800-38E. To meet the requirement stated in IG C.I, the module implements a check to ensure that the two AES keys used in AES XTS mode are not identical. The XTS mode shall only be used for the cryptographic protection of data on storage devices. It shall not be used for other purposes, such as the encryption of data in transit.

2.7.3 Legacy Use

Digital signature verification using SHA-1 is allowed for legacy use only. These legacy algorithms can only be used on data that was generated prior to the Legacy Date specified in FIPS 140-3 IG C.M.

2.8 RBG and Entropy

Table 9: Entropy Certificates Table 10: Entropy Sources The module implements three different Deterministic Random Bit Generator (DRBG) implementations based on SP 800-90Ar1: CTR_DRBG, Hash_DRBG, and HMAC_DRBG. Each of these DRBG implementations can be instantiated by the operator of the module. When instantiated, these DRBGs can be used to generate random numbers for external usage. © 2024 Red Hat, Inc./ atsec information security.

Page 26

The DRBG is initially seeded with 384 output bits from the entropy source (357 bits of entropy) and reseeded with 256 output bits from the entropy source (238 bits of entropy). The module does not offer any service to directly get entropy source output. The entropy source is always internally accessed by the module’s DRBG for seeding and reseeding.

2.9 Key Generation

The module does not provide key generation.

2.10 Key Establishment

As permitted by IG D.G, the module provides key transport methods either by using an approved authenticated encryption mode or by a combination of any approved symmetric encryption mode and an approved authentication method. Specifically, the module provides the following key transport methods: • Key wrapping using AES GCM with internal IV with a security strength of 128, 192, or

256 bits.
2.11 Industry Protocols

AES GCM with internal IV generation in the approved mode is compliant with RFC 4106 and shall only be used in conjunction with the IPsec protocol. No parts of this protocol, other than the AES GCM implementation, have been tested by the CAVP and CMVP. © 2024 Red Hat, Inc./ atsec information security.

Page 27
Physical PortLogical Interface(s)Data That Passes
N/AData InputAPI data input parameters, AF_ALG type sockets
N/AData OutputAPI output parameters, AF_ALG type sockets
N/AControl InputAPI function calls, API control input parameters, AF_ALG type sockets, kernel command line
N/AStatus OutputAPI return values, AF_ALG type sockets, kernel logs
3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

Table 11: Ports and Interfaces The logical interfaces are the APIs through which the applications request services. These logical interfaces are logically separated from each other by the API design. © 2024 Red Hat, Inc./ atsec information security.

Page 28
NameTypeOperator TypeAuthentication Methods
Crypto OfficerRoleCONone
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Acce ss
Message digestCompute a message digestcrypto_shash_init returns 0Messag eDigest valueHashingCrypt o Office r
Key wrappingWrap a keycrypto_skcipher_setk ey returns 0; crypto_shash_init returns 0AES key, key to be wrappe dwrapped keyAES CCM AES GCM with internal IV AES GCM with external IV AES CBC with HMAC SHA-1, HMAC SHA-256, HMAC SHA-384, or HMAC SHA-512 AES CTR with HMAC SHA-1, HMAC SHA-256, HMACCrypt o Office r - AES key: W,E - HMAC key: W,E
4 Roles, Services, and Authentication

N/A for this module. The module does not implement authentication.

4.2 Roles

Table 12: Roles The module supports the Crypto Officer role only. This sole role is implicitly and always assumed by the operator of the module. No support is provided for multiple concurrent operators.

4.3 Approved Services

© 2024 Red Hat, Inc./ atsec information security.

Page 29
NameDescripti onIndicatorInputsOutputsSecurity Functions SHA-384, or HMAC SHA-512SSP Acce ss
Key unwrappin gUnwrap a keycrypto_skcipher_setk ey returns 0; crypto_shash_init returns 0AES key, key to be unwrap pedunwrapp ed keyAES CCM AES GCM with internal IV AES GCM with external IV AES CBC with HMAC SHA-1, HMAC SHA-256, HMAC SHA-384, or HMAC SHA-512 AES CTR with HMAC SHA-1, HMAC SHA-256, HMAC SHA-384, or HMAC SHA-512Crypt o Office r - AES key: W,E - HMAC key: W,E
EncryptionEncrypt a plaintextcrypto_skcipher_setk ey returns 0AES key, plaintex tCipherte xtEncryption with AESCrypt o Office r - AES key: W,E
DecryptionDecrypt a ciphertextcrypto_skcipher_setk ey returns 0AES key, cipherte xtPlaintextDecryption with AESCrypt o Office r - AES key: W,E
Authentica ted encryptionEncrypt and authentic ate a plaintextFor all except AES GCM: crypto_aead_setkey returns 0; For AES GCM: crypto_aead_get_fla gs(tfm) has the CRYPTO_TFM_AES key, plaintex tCipherte xt, MAC tagAuthentica ted encryption with AESCrypt o Office r - AES key: W,E

t r W,E W,E © 2024 Red Hat, Inc./ atsec information security.

Page 30
NameDescripti onIndicator FIPS_COMPLIANCE flag setInputsOutputsSecurity FunctionsSSP Acce ss
Authentica ted decryptionEncrypt and authentic ate a ciphertextFor all except AES GCM: crypto_aead_setkey returns 0; For AES GCM: crypto_aead_get_fla gs(tfm) has the CRYPTO_TFM_ FIPS_COMPLIANCE flag setAES key, cipherte xt, MAC tagPlaintext or failureAuthentica ted decryption with AESCrypt o Office r - AES key: W,E
Message authentica tionCompute a MAC tagcrypto_shash_init returns 0AES: AES key, messag e; HMAC: HMAC key, messag eMAC tagMessage authentica tionCrypt o Office r - AES key: W,E - HMAC key: W,E
Random number generationGenerate random bytescrypto_rng_get_byte s returns 0Output lengthRandom bytesRandom number generation with DRBGsCrypt o Office r - Entro py input: W,E - DRBG seed: G,E - DRBG Intern al state (V, Key): G,W, E - DRBG Intern al state

W,E W,E G,E (V, G,W, E © 2024 Red Hat, Inc./ atsec information security.

Page 31
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Acce ss
(V, C): G,W, E
Signature verificatio nVerify a digital signaturepkcs7_verify returns 0Messag e, public key, signatur ePass/failSignature verificatio n with RSACrypt o Office r - RSA publi c key: W,E
Error detection codeCompute an EDC (crc32, crct10dif)NoneMessag eEDCNoneCrypt o Office r
Compressi onCompress data (deflate, lz4, lz4hc, lzo, zlibdeflate , zstd)NoneDataCompres sed dataNoneCrypt o Office r
Generic system callUse the kernel to perform various non- cryptogra phic operationsNoneIdentifie r, various argume ntsVarious return valuesNoneCrypt o Office r
Show versionReturn the module name and version informatio nNoneN/AModule name and versionNoneCrypt o Office r
Show statusReturn the module statusNoneN/AModule statusNoneCrypt o Office r
Self-testPerform the CASTs and integrity testsNoneN/APass/failEncryption with AES Decryption with AES Hashing Message authentica tion RandomCrypt o Office r

(V, C): G,W, E W,E n r © 2024 Red Hat, Inc./ atsec information security.

Page 32
NameDescripti onIndicatorInputsOutputsSecurity Functions number generation with DRBGs Signature verificatio n with RSA Authentica ted encryption with AES Authentica ted decryption with AESSSP Acce ss
Zeroizatio nZeroize all SSPsNoneAny SSPN/ANoneCrypt o Office r - AES key: Z - HMAC key: Z - Entro py input: Z - DRBG Intern al state (V, Key): Z - DRBG Intern al state (V, C): Z - RSA publi c key: Z

r Z Z Z (V, Z (V, C): Z Z © 2024 Red Hat, Inc./ atsec information security.

Page 33
NameDescriptionAlgorithmsRole
AES GCM external IV encryptionEncrypt a plaintext using AES GCM with an external IVAES GCM with external IVCO
Key derivationDerive a key from a key- derivation key or a shared secretKBKDF (libkcapi) HKDF (libkcapi)CO
Password-based key derivationDerive a key from a passwordPBKDF2 (libkcapi)CO
RSA encryption primitiveCompute the raw RSA encryption of a plaintextRSACO
RSA decryption primitiveCompute the raw RSA decryption of a cipertextRSACO
RSA signature generation (pre-hashed message)Generate a digital signature for a pre-hashed messageRSA with PKCS#1 v1.5 paddingCO
RSA signature verification (pre-hashed message)Verify a digital signature for a pre-hashed messageRSA with PKCS#1 v1.5 paddingCO
Key encapsulationEncapsulate a secret key using RSA with PKCS#1 v1.5 paddingRSA with PKCS#1 v1.5 paddingCO
Key un-encapsulationUn-encapsulate a secret key using RSA with PKCS#1 v1.5 paddingRSA with PKCS#1 v1.5 paddingCO

Table 13: Approved Services The table above lists the approved services. The following convention is used to specify access rights to SSPs:

4.4 Non-Approved Services

Table 14: Non-Approved Services

4.5 External Software/Firmware Loaded

The module does not load external software or firmware. © 2024 Red Hat, Inc./ atsec information security.

Page 34
5 Software/Firmware Security
5.1 Integrity Techniques

The Linux kernel binary is integrity tested using an HMAC SHA-512 calculation performed by the sha512hmac utility (which utilizes the module’s HMAC and SHA-512 implementations). An HMAC SHA-512 calculation is also performed on the sha512hmac utility and the libkcapi library to verify their integrity. The kernel crypto object files listed in section 2.2 are loaded on start-up by the module and verified using RSA signature verification with PKCS#1 v1.5 padding, SHA-256, and a 3072-bit key.

5.2 Initiate on Demand

Integrity tests are performed as part of the pre-operational self-tests, which are executed when the module is initialized. The integrity tests can be invoked on demand by unloading and subsequently re-initializing the module, which will perform (among others) the software integrity tests. © 2024 Red Hat, Inc./ atsec information security.

Page 35
6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Modifiable How Requirements are Satisfied: The operating system provides process isolation and memory protection mechanisms that ensure appropriate separation for memory access among the processes on the system. Each process has control over its own data and uncontrolled access to the data of other processes is prevented.

6.2 Configuration Settings and Restrictions

The module shall be installed as stated in Section 11.1. Instrumentation tools like the ptrace system call, gdb and strace, as well as other tracing mechanisms offered by the Linux environment such as ftrace or systemtap, shall not be used in the operational environments. The use of any of these tools implies that the cryptographic module is running in a non-validated operational environment.

6.3 Additional Information

The Red Hat Enterprise Linux operating system is used as the basis of other products which include but are not limited to:

Page 36
7 Physical Security

The module is comprised of software only and therefore this section is not applicable. © 2024 Red Hat, Inc./ atsec information security.

Page 37
8 Non-Invasive Security

This module does not implement any non-invasive security mechanism and therefore this section is not applicable. © 2024 Red Hat, Inc./ atsec information security.

Page 38
Storage Area NameDescriptionPersistence Type
RAMTemporary storage for SSPs used by the module as part of service executionDynamic

Name API input parameters; AF_ALG_typ e sockets (input)

From Operator calling applicatio n (TOEPP)

To Cryptographi c module

Format Type Plaintex t

Distributio n Type Manual

Entry Type Electroni c

SFI or Algorith m

Zeroization MethodDescriptionRationaleOperator Initiation
Free cipher handleZeroizes the SSPs contained within the cipher handleMemory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable. The completion of the zeroization routine indicates that the zeroization procedure succeeded.By calling the appropriate zeroization functions: AES key: crypto_free_skcipher and crypto_free_aead; HMAC key: crypto_free_shash and crypto_free_ahash; DRBG internal state: crypto_free_rng; RSA public key: public_key_free
Remove power from the moduleDe-allocates the volatile memory used to store SSPsVolatile memory used by the module is overwritten within nanoseconds when power is removed. Module power off indicates that the zeroization procedure succeeded. TheBy removing power
9 Sensitive Security Parameters Management
9.1 Storage Areas

Table 15: Storage Areas The module does not perform persistent storage of SSPs. The SSPs are temporarily stored in the RAM in plaintext form. SSPs are provided to the module by the calling process and are destroyed when released by the appropriate zeroization function calls.

9.2 SSP Input-Output Methods

m Table 16: SSP Input-Output Methods © 2024 Red Hat, Inc./ atsec information security.

Page 39

Zeroization Method

Description

Rationale successful removal of power implicitly indicates that the zeroization is complete.

Operator Initiation

NameDescripti onSize - StrengthType - CategoryGenerate d ByEstablish ed ByUsed By
AES keyAES key used for encryption, decryption, and computing MAC tags128, 192, 256 bits - 128, 192, 256 bitsSymmetric Key - CSPEncryption with AES Decryption with AES Authenticate d encryption with AES Authenticate d decryption with AES AES CCM AES GCM with internal IV AES GCM with external IV AES CBC with HMAC SHA-1, HMAC SHA- 256, HMAC SHA-384, or HMAC SHA- 512 AES CTR with HMAC SHA-1, HMAC SHA- 256, HMAC SHA-384, or HMAC SHA- 512
HMAC keyHMAC key112-256 bits - 112- 256 bitsAuthenticati on key - CSPMessage authenticati on

Table 17: SSP Zeroization Methods All data output is inhibited during zeroization.

9.4 SSPs

© 2024 Red Hat, Inc./ atsec information security.

Page 40
NameDescripti onSize - StrengthType - CategoryGenerate d ByEstablish ed ByUsed By
Entrop y inputEntropy input used to seed the DRBGs128-448 bits - 128- 256 bitsEntropy input - CSPRandom number generation with DRBGs
DRBG seedDRBG seed derived from entropy inputCTR_DRBG: 128, 192, 256 bits; Hash_DRBG : 128, 256 bits; HMAC_DRB G: 128, 256 bits - CTR_DRBG: 128, 192, 256 bits; Hash_DRBG : 128, 256 bits; HMAC_DRB G: 128, 256 bitsSeed - CSPRandom number generatio n with DRBGsRandom number generation with DRBGs
DRBG Intern al state (V, Key)Internal state of CTR_DRBG and HMAC_DRB G instancesCTR_DRBG: 128, 192, 256 bits; HMAC_DRB G: 128, 256 bits - CTR_DRBG: 128, 192, 256 bits; HMAC_DRB G: 128, 256 bitsInternal state - CSPRandom number generatio n with DRBGsRandom number generation with DRBGs
DRBG Intern al state (V, C)Internal state of Hash_DRB G instancesHash_DRBG : 128, 256 bits - Hash_DRBG : 128, 256 bitsInternal state - CSPRandom number generatio n with DRBGsRandom number generation with DRBGs
RSA public keyPublic key used for RSA signature verification2048, 3072, 4096 bits - 112, 128, 150 bitsPublic key - PSPSignature verification with RSA

Table 18: SSP Table 1 © 2024 Red Hat, Inc./ atsec information security.

Page 41
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
AES keyAPI input parameters; AF_ALG_type sockets (input)RAM:PlaintextUntil cipher handled is freed or module powered offFree cipher handle Remove power from the module
HMAC keyAPI input parameters; AF_ALG_type sockets (input)RAM:PlaintextUntil cipher handled is freed or module powered offFree cipher handle Remove power from the module
Entropy inputRAM:PlaintextFrom generation until DRBG seed/reseedFree cipher handle Remove power from the moduleDRBG seed:Derives
DRBG seedRAM:PlaintextWhile the DRBG is being instantiatedFree cipher handle Remove power from the moduleEntropy input:Derived From DRBG Internal state (V, Key):Derives
DRBG Internal state (V, Key)RAM:PlaintextFrom DRBG instantiation until DRBG terminationFree cipher handle Remove power from the moduleDRBG seed:Derived From
DRBG Internal state (V, C)RAM:PlaintextFrom DRBG instantiation until DRBG terminationFree cipher handle Remove power from the moduleDRBG seed:Derived From
RSA public keyAPI input parameters; AF_ALG_type sockets (input)RAM:PlaintextUntil cipher handled is freed or module powered offFree cipher handle Remove power from the module
9.5 Transitions

The SHA-1 algorithm as implemented by the module will be non-approved for all purposes except signature verification, starting January 1, 2031. The RSA algorithm with SHA-1 as implemented by the module conforms to FIPS 186-4. FIPS 186-4 was withdrawn on February 3, 2024 but FIPS 140-3 IG C.K allows RSA signature verification with SHA-1 under FIPS 186-4 to still be approved. © 2024 Red Hat, Inc./ atsec information security.

Page 42
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
HMAC- SHA2-512 (A5099)128-bit keyMessage AuthenticationSW/FW IntegrityModule becomes operational and services are available for use.Integrity test for vmlinuz, libkcapi components and sha512hmac binary
RSA SigVer (FIPS186-5) (A5081)3072-bit key with SHA- 256Signature VerificationSW/FW IntegrityModule becomes operational and services are available for use.Integrity test for kernel object files
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
SHA-1 (A5081)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA-1 (A5097)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
10 Self-Tests
10.1 Pre-Operational Self-Tests

Table 20: Pre-Operational Self-Tests The pre-operational software integrity tests are performed automatically when the module is powered on, before the module transitions into the operational state. The algorithms used CASTs before the integrity test is performed. While the module is executing the self-tests, services are not available, and data output (via the data output interface) is inhibited until the pre-operational software integrity self-tests are successfully completed. The module transitions to the operational state only after the pre-operational self-tests are passed successfully.

10.2 Conditional Self-Tests

© 2024 Red Hat, Inc./ atsec information security.

Page 43
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
SHA-1 (A5098)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA-1 (A5099)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA2-224 (A5081)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA2-224 (A5097)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA2-224 (A5098)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA2-224 (A5099)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA2-256 (A5081)0-8184 bit messagesKATCASTModule becomes operationalMessage digestModule initialization

© 2024 Red Hat, Inc./ atsec information security.

Page 44
Algorithm or TestTest PropertiesTest MethodTest TypeIndicator and services are available for use.DetailsConditions
SHA2-256 (A5097)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA2-256 (A5098)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA2-256 (A5099)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA2-384 (A5081)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA2-384 (A5097)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA2-384 (A5098)0-8184 bit messagesKATCASTModule becomes operational and services areMessage digestModule initialization

© 2024 Red Hat, Inc./ atsec information security.

Page 45
Algorithm or TestTest PropertiesTest MethodTest TypeIndicator available for use.DetailsConditions
SHA2-384 (A5099)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA2-512 (A5081)0-8184 bit messageKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA2-512 (A5097)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA2-512 (A5098)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA2-512 (A5099)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA3-224 (A5082)0-8184 bit messageKATCASTModule becomes operational and services are available for use.Message digestModule initialization

© 2024 Red Hat, Inc./ atsec information security.

Page 46
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
SHA3-256 (A5082)0-8184 bit messageKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA3-384 (A5082)0-8184 bit messageKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA3-512 (A5082)0-8184 bit messageKATCASTModule becomes operational and services are available for use.Message digestModule initialization
AES-ECB (A5081)128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.Encryption, DecryptionModule initialization
AES-ECB (A5086)128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.Encryption, DecryptionModule initialization
AES-ECB (A5087)128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.Encryption, DecryptionModule initialization
AES-ECB (A5088)128, 192, 256 bit keysKATCASTModule becomes operationalEncryption, DecryptionModule initialization

© 2024 Red Hat, Inc./ atsec information security.

Page 47
Algorithm or TestTest PropertiesTest MethodTest TypeIndicator and services are available for use.DetailsConditions
AES-ECB (A5089)128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.Encryption, DecryptionModule initialization
AES-ECB (A5090)128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.Encryption, DecryptionModule initialization
AES-ECB (A5092)128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.Encryption, DecryptionModule initialization
AES-ECB (A5093)128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.Encryption, DecryptionModule initialization
AES-ECB (A5091)128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.Encryption, DecryptionModule initialization
AES-CBC (A5081)128, 192, 256 bit keysKATCASTModule becomes operational and services areEncryption, DecryptionModule initialization

© 2024 Red Hat, Inc./ atsec information security.

Page 48
Algorithm or TestTest PropertiesTest MethodTest TypeIndicator available for use.DetailsConditions
AES-CBC (A5088)128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.Encryption, DecryptionModule initialization
AES-CBC- CS3 (A5096)128 bit keysKATCASTModule becomes operational and services are available for use.Encryption, DecryptionModule initialization
AES-OFB (A5095)128 bit keysKATCASTModule becomes operational and services are available for use.Encryption, DecryptionModule initialization
AES- CFB128 (A5094)128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.Encryption, DecryptionModule initialization
AES-CTR (A5081)128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.Encryption, DecryptionModule initialization
AES-CTR (A5091)128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.Encryption, DecryptionModule initialization

© 2024 Red Hat, Inc./ atsec information security.

Page 49
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-CCM (A5091)128, 192, 256 bit keys; 128-bit IVsKATCASTModule becomes operational and services are available for use.Encryption, DecryptionModule initialization
AES-GCM (A5081)128, 192, 256 bit keys, 96-bit IVsKATCASTModule becomes operational and services are available for use.Encryption, DecryptionModule initialization
AES-GCM (A5086)128, 192, 256 bit keys, 96-bit IVsKATCASTModule becomes operational and services are available for use.EncryptionModule initialization
AES-GCM (A5087)128, 192, 256 bit keys, 96-bit IVsKATCASTModule becomes operational and services are available for use.Encryption, DecryptionModule initialization
AES-GCM (A5088)128, 192, 256 bit keys, 96-bit IVsKATCASTModule becomes operational and services are available for use.Encryption, DecryptionModule initialization
AES-GCM (A5089)128, 192, 256 bit keys, 96-bit IVsKATCASTModule becomes operational and services are available for use.EncryptionModule initialization
AES-GCM (A5090)128, 192, 256 bit keys, 96-bit IVsKATCASTModule becomes operationalEncryption, DecryptionModule initialization

© 2024 Red Hat, Inc./ atsec information security.

Page 50
Algorithm or TestTest PropertiesTest MethodTest TypeIndicator and services are available for use.DetailsConditions
AES-GCM (A5091)128, 192, 256 bit keys, 96-bit IVsKATCASTModule becomes operational and services are available for use.Encryption, DecryptionModule initialization
AES-GCM (A5092)128, 192, 256 bit keys, 96-bit IVsKATCASTModule becomes operational and services are available for use.EncryptionModule initialization
AES-GCM (A5093)128, 192, 256 bit keys, 96-bit IVsKATCASTModule becomes operational and services are available for use.Encryption, DecryptionModule initialization
AES-XTS Testing Revision 2.0 (A5081)128 and 256 bit keysKATCASTModule becomes operational and services are available for use.Encryption, DecryptionModule initialization
AES-XTS Testing Revision 2.0 (A5091)128 and 256 bit keysKATCASTModule becomes operational and services are available for use.Encryption, DecryptionModule initialization
AES-CMAC (A5091)128 and 256 bit keysKATCASTModule becomes operational and services areMessage authenticationModule initialization

© 2024 Red Hat, Inc./ atsec information security.

Page 51
Algorithm or TestTest PropertiesTest MethodTest TypeIndicator available for use.DetailsConditions
HMAC- SHA-1 (A5081)32-64 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA-1 (A5097)32-64 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA-1 (A5098)32-64 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA-1 (A5099)32-64 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA2-224 (A5081)32-1048 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA2-224 (A5097)32-1048 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization

© 2024 Red Hat, Inc./ atsec information security.

Page 52
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
HMAC- SHA2-224 (A5098)32-1048 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA2-224 (A5099)32-1048 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA2-256 (A5081)32-64 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA2-256 (A5097)32-64 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA2-256 (A5098)32-64 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA2-256 (A5099)32-64 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA2-384 (A5081)32-1048 bit keysKATCASTModule becomes operationalMessage authenticationModule initialization

© 2024 Red Hat, Inc./ atsec information security.

Page 53
Algorithm or TestTest PropertiesTest MethodTest TypeIndicator and services are available for use.DetailsConditions
HMAC- SHA2-384 (A5097)32-1048 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA2-384 (A5098)32-1048 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA2-384 (A5099)32-1048 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA2-512 (A5081)32-1048 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA2-512 (A5097)32-1048 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA2-512 (A5098)32-1048 bit keysKATCASTModule becomes operational and services areMessage authenticationModule initialization

© 2024 Red Hat, Inc./ atsec information security.

Page 54
Algorithm or TestTest PropertiesTest MethodTest TypeIndicator available for use.DetailsConditions
HMAC- SHA2-512 (A5099)32-1048 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA3-224 (A5082)32-1048 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA3-256 (A5082)32-1048 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA3-384 (A5082)32-1048 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA3-512 (A5082)32-1048 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
Counter DRBG (A5081)128, 192, 256 bit keys With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization

© 2024 Red Hat, Inc./ atsec information security.

Page 55
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
Counter DRBG (A5086)128, 192, 256 bit keys With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
Counter DRBG (A5087)128, 192, 256 bit keys With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
Counter DRBG (A5088)128, 192, 256 bit keys With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
Counter DRBG (A5089)128, 192, 256 bit keys With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
Counter DRBG (A5090)128, 192, 256 bit keys With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
Counter DRBG (A5091)128, 192, 256 bit keys With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
Counter DRBG (A5092)128, 192, 256 bit keys With/withoutKATCASTModule becomes operationalSeed, GenerateModule initialization

© 2024 Red Hat, Inc./ atsec information security.

Page 56
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
PR; Health test per section 11.3 of SP 800- 90Arev1and services are available for use.
Counter DRBG (A5093)128, 192, 256 bit keys With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
Hash DRBG (A5081)SHA-256 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
Hash DRBG (A5086)SHA-256 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
Hash DRBG (A5087)SHA-256 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
Hash DRBG (A5088)SHA-256 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
Hash DRBG (A5089)SHA-256 With/without PR; Health test per section 11.3KATCASTModule becomes operational and services areSeed, GenerateModule initialization

© 2024 Red Hat, Inc./ atsec information security.

Page 57
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
of SP 800- 90Arev1available for use.
Hash DRBG (A5090)SHA-256 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
Hash DRBG (A5091)SHA-256 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
Hash DRBG (A5092)SHA-256 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
Hash DRBG (A5093)SHA-256 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
Hash DRBG (A5097)SHA-256 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
Hash DRBG (A5098)SHA-256 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization

© 2024 Red Hat, Inc./ atsec information security.

Page 58
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
Hash DRBG (A5099)SHA-256 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
HMAC DRBG (A5081)SHA-256, SHA512 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
HMAC DRBG (A5086)SHA-256, SHA512 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
HMAC DRBG (A5087)SHA-256, SHA512 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
HMAC DRBG (A5088)SHA-256, SHA512 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
HMAC DRBG (A5089)SHA-256, SHA512 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
HMAC DRBG (A5090)SHA-256, SHA512 With/withoutKATCASTModule becomes operationalSeed, GenerateModule initialization

© 2024 Red Hat, Inc./ atsec information security.

Page 59
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
PR; Health test per section 11.3 of SP 800- 90Arev1and services are available for use.
HMAC DRBG (A5091)SHA-256, SHA512 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
HMAC DRBG (A5092)SHA-256, SHA512 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
HMAC DRBG (A5093)SHA-256, SHA512 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
HMAC DRBG (A5097)SHA-256, SHA512 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
HMAC DRBG (A5098)SHA-256, SHA512 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
HMAC DRBG (A5099)SHA-256, SHA512 With/without PR; Health test per section 11.3KATCASTModule becomes operational and services areSeed, GenerateModule initialization

© 2024 Red Hat, Inc./ atsec information security.

Page 60
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
of SP 800- 90Arev1available for use.
RSA SigVer (FIPS186- 5) (A5081)4096-bit key with SHA- 256KATCASTModule becomes operational and services are available for use.VerifyModule initialization
RSA SigVer (FIPS186- 5) (A5097)4096-bit key with SHA- 256KATCASTModule becomes operational and services are available for use.VerifyModule initialization
RSA SigVer (FIPS186- 5) (A5098)4096-bit key with SHA- 256KATCASTModule becomes operational and services are available for use.VerifyModule initialization
Entropy source, start-up RCT1024 samplesRCTCASTModule becomes operational and services are available for use.Entropy source start- up testEntropy source initialization
Entropy source, start-up APT1024 samplesAPTCASTModule becomes operational and services are available for use.Entropy source start- up testEntropy source initialization
Entropy source, continuous RCTCutoff C = 61RCTCASTEntropy source is operationalEntropy source continuous testContinuously
Entropy source, continuous APTCutoff C = 355APTCASTEntropy source is operationalEntropy source continuous testContinuously

© 2024 Red Hat, Inc./ atsec information security.

Page 61
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
SHA-1 (A5565)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA2-224 (A5565)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA2-256 (A5565)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA2-384 (A5565)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA2-512 (A5565)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA3-224 (A5571)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA3-256 (A5571)0-8184 bit messagesKATCASTModule becomes operationalMessage digestModule initialization

© 2024 Red Hat, Inc./ atsec information security.

Page 62
Algorithm or TestTest PropertiesTest MethodTest TypeIndicator and services are available for use.DetailsConditions
SHA3-384 (A5571)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA3-512 (A5571)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
HMAC- SHA-1 (A5565)32-64 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA2-224 (A5565)32-1048 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA2-256 (A5565)32-64 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA2-384 (A5565)32-1048 bit keysKATCASTModule becomes operational and services areMessage authenticationModule initialization

© 2024 Red Hat, Inc./ atsec information security.

Page 63
Algorithm or TestTest PropertiesTest MethodTest TypeIndicator available for use.DetailsConditions
HMAC- SHA2-512 (A5565)32-1048 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA3-224 (A5571)32-1048 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA3-256 (A5571)32-1048 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA3-384 (A5571)32-1048 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA3-512 (A5571)32-1048 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
Counter DRBG (A5562)128, 192, 256 bit keys With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization

© 2024 Red Hat, Inc./ atsec information security.

Page 64
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
Counter DRBG (A5563)128, 192, 256 bit keys With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
Counter DRBG (A5564)128, 192, 256 bit keys With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
Counter DRBG (A5565)128, 192, 256 bit keys With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
Counter DRBG (A5566)128, 192, 256 bit keys With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
Counter DRBG (A5567)128, 192, 256 bit keys With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
Hash DRBG (A5563)SHA-256 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
Hash DRBG (A5564)SHA-256 With/without PR; HealthKATCASTModule becomes operationalSeed, GenerateModule initialization

© 2024 Red Hat, Inc./ atsec information security.

Page 65
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
test per section 11.3 of SP 800- 90Arev1and services are available for use.
Hash DRBG (A5565)SHA-256 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
Hash DRBG (A5566)SHA-256 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
Hash DRBG (A5567)SHA-256 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
HMAC DRBG (A5563)SHA-256, SHA512 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
HMAC DRBG (A5564)SHA-256, SHA512 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
HMAC DRBG (A5565)SHA-256, SHA512 With/without PR; Health test per section 11.3KATCASTModule becomes operational and services areSeed, GenerateModule initialization

© 2024 Red Hat, Inc./ atsec information security.

Page 66
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
of SP 800- 90Arev1available for use.
HMAC DRBG (A5566)SHA-256, SHA512 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
HMAC DRBG (A5567)SHA-256, SHA512 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.Seed, GenerateModule initialization
AES-ECB (A5562)128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.Encryption, DecryptionModule initialization
AES-ECB (A5563)128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.Encryption, DecryptionModule initialization
AES-ECB (A5564)128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.Encryption, DecryptionModule initialization
AES-ECB (A5565)128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.Encryption, DecryptionModule initialization

© 2024 Red Hat, Inc./ atsec information security.

Page 67
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-ECB (A5566)128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.Encryption, DecryptionModule initialization
AES-ECB (A5567)128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.Encryption, DecryptionModule initialization
AES-CBC (A5561)128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.Encryption, DecryptionModule initialization
AES-GCM (A5562)128, 192, 256 bit keys, 96-bit IVsKATCASTModule becomes operational and services are available for use.Encryption, DecryptionModule initialization
AES-GCM (A5563)128, 192, 256 bit keys, 96-bit IVsKATCASTModule becomes operational and services are available for use.Encryption, DecryptionModule initialization
AES-GCM (A5564)128, 192, 256 bit keys, 96-bit IVsKATCASTModule becomes operational and services are available for use.Encryption, DecryptionModule initialization
AES-GCM (A5565)128, 192, 256 bit keys, 96-bit IVsKATCASTModule becomes operationalEncryption, DecryptionModule initialization

© 2024 Red Hat, Inc./ atsec information security.

Page 68
Algorithm or TestTest PropertiesTest MethodTest TypeIndicator and services are available for use.DetailsConditions
AES-GCM (A5566)128, 192, 256 bit keys, 96-bit IVsKATCASTModule becomes operational and services are available for use.Encryption, DecryptionModule initialization
AES-GCM (A5567)128, 192, 256 bit keys, 96-bit IVsKATCASTModule becomes operational and services are available for use.Encryption, DecryptionModule initialization
RSA SigVer (FIPS186- 5) (A5099)4096-bit key with SHA- 256KATCASTModule becomes operational and services are available for use.VerifyModule initialization
RSA SigVer (FIPS186- 5) (A5565)4096-bit key with SHA- 256KATCASTModule becomes operational and services are available for use.VerifyModule initialization

Table 21: Conditional Self-Tests The module performs self-tests on all approved cryptographic algorithms as part of the approved services supported in the approved mode of operation, using the tests shown in the table above. Services are not available, and data output (via the data output interface) is inhibited during the conditional self-tests. If any of these tests fails, the module transitions to the Error State.

10.3 Periodic Self-Test Information

© 2024 Red Hat, Inc./ atsec information security.

Page 69
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2- 512 (A5099)Message AuthenticationSW/FW IntegrityOn demandManually
RSA SigVer (FIPS186-5) (A5081)Signature VerificationSW/FW IntegrityOn demandManually
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
SHA-1 (A5081)KATCASTOn demandManually
SHA-1 (A5097)KATCASTOn demandManually
SHA-1 (A5098)KATCASTOn demandManually
SHA-1 (A5099)KATCASTOn demandManually
SHA2-224 (A5081)KATCASTOn demandManually
SHA2-224 (A5097)KATCASTOn demandManually
SHA2-224 (A5098)KATCASTOn demandManually
SHA2-224 (A5099)KATCASTOn demandManually
SHA2-256 (A5081)KATCASTOn demandManually
SHA2-256 (A5097)KATCASTOn demandManually
SHA2-256 (A5098)KATCASTOn demandManually
SHA2-256 (A5099)KATCASTOn demandManually
SHA2-384 (A5081)KATCASTOn demandManually
SHA2-384 (A5097)KATCASTOn demandManually
SHA2-384 (A5098)KATCASTOn demandManually
SHA2-384 (A5099)KATCASTOn demandManually
SHA2-512 (A5081)KATCASTOn demandManually
SHA2-512 (A5097)KATCASTOn demandManually
SHA2-512 (A5098)KATCASTOn demandManually
SHA2-512 (A5099)KATCASTOn demandManually
SHA3-224 (A5082)KATCASTOn demandManually
SHA3-256 (A5082)KATCASTOn demandManually

Table 22: Pre-Operational Periodic Information © 2024 Red Hat, Inc./ atsec information security.

Page 70
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
SHA3-384 (A5082)KATCASTOn demandManually
SHA3-512 (A5082)KATCASTOn demandManually
AES-ECB (A5081)KATCASTOn demandManually
AES-ECB (A5086)KATCASTOn demandManually
AES-ECB (A5087)KATCASTOn demandManually
AES-ECB (A5088)KATCASTOn demandManually
AES-ECB (A5089)KATCASTOn demandManually
AES-ECB (A5090)KATCASTOn demandManually
AES-ECB (A5092)KATCASTOn demandManually
AES-ECB (A5093)KATCASTOn demandManually
AES-ECB (A5091)KATCASTOn demandManually
AES-CBC (A5081)KATCASTOn demandManually
AES-CBC (A5088)KATCASTOn demandManually
AES-CBC-CS3 (A5096)KATCASTOn demandManually
AES-OFB (A5095)KATCASTOn demandManually
AES-CFB128 (A5094)KATCASTOn demandManually
AES-CTR (A5081)KATCASTOn demandManually
AES-CTR (A5091)KATCASTOn demandManually
AES-CCM (A5091)KATCASTOn demandManually
AES-GCM (A5081)KATCASTOn demandManually
AES-GCM (A5086)KATCASTOn demandManually
AES-GCM (A5087)KATCASTOn demandManually
AES-GCM (A5088)KATCASTOn demandManually
AES-GCM (A5089)KATCASTOn demandManually
AES-GCM (A5090)KATCASTOn demandManually

© 2024 Red Hat, Inc./ atsec information security.

Page 71
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-GCM (A5091)KATCASTOn demandManually
AES-GCM (A5092)KATCASTOn demandManually
AES-GCM (A5093)KATCASTOn demandManually
AES-XTS Testing Revision 2.0 (A5081)KATCASTOn demandManually
AES-XTS Testing Revision 2.0 (A5091)KATCASTOn demandManually
AES-CMAC (A5091)KATCASTOn demandManually
HMAC-SHA-1 (A5081)KATCASTOn demandManually
HMAC-SHA-1 (A5097)KATCASTOn demandManually
HMAC-SHA-1 (A5098)KATCASTOn demandManually
HMAC-SHA-1 (A5099)KATCASTOn demandManually
HMAC-SHA2- 224 (A5081)KATCASTOn demandManually
HMAC-SHA2- 224 (A5097)KATCASTOn demandManually
HMAC-SHA2- 224 (A5098)KATCASTOn demandManually
HMAC-SHA2- 224 (A5099)KATCASTOn demandManually
HMAC-SHA2- 256 (A5081)KATCASTOn demandManually
HMAC-SHA2- 256 (A5097)KATCASTOn demandManually
HMAC-SHA2- 256 (A5098)KATCASTOn demandManually
HMAC-SHA2- 256 (A5099)KATCASTOn demandManually
HMAC-SHA2- 384 (A5081)KATCASTOn demandManually
HMAC-SHA2- 384 (A5097)KATCASTOn demandManually
HMAC-SHA2- 384 (A5098)KATCASTOn demandManually
HMAC-SHA2- 384 (A5099)KATCASTOn demandManually
HMAC-SHA2- 512 (A5081)KATCASTOn demandManually
HMAC-SHA2- 512 (A5097)KATCASTOn demandManually

© 2024 Red Hat, Inc./ atsec information security.

Page 72
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2- 512 (A5098)KATCASTOn demandManually
HMAC-SHA2- 512 (A5099)KATCASTOn demandManually
HMAC-SHA3- 224 (A5082)KATCASTOn demandManually
HMAC-SHA3- 256 (A5082)KATCASTOn demandManually
HMAC-SHA3- 384 (A5082)KATCASTOn demandManually
HMAC-SHA3- 512 (A5082)KATCASTOn demandManually
Counter DRBG (A5081)KATCASTOn demandManually
Counter DRBG (A5086)KATCASTOn demandManually
Counter DRBG (A5087)KATCASTOn demandManually
Counter DRBG (A5088)KATCASTOn demandManually
Counter DRBG (A5089)KATCASTOn demandManually
Counter DRBG (A5090)KATCASTOn demandManually
Counter DRBG (A5091)KATCASTOn demandManually
Counter DRBG (A5092)KATCASTOn demandManually
Counter DRBG (A5093)KATCASTOn demandManually
Hash DRBG (A5081)KATCASTOn demandManually
Hash DRBG (A5086)KATCASTOn demandManually
Hash DRBG (A5087)KATCASTOn demandManually
Hash DRBG (A5088)KATCASTOn demandManually
Hash DRBG (A5089)KATCASTOn demandManually
Hash DRBG (A5090)KATCASTOn demandManually
Hash DRBG (A5091)KATCASTOn demandManually
Hash DRBG (A5092)KATCASTOn demandManually
Hash DRBG (A5093)KATCASTOn demandManually
Hash DRBG (A5097)KATCASTOn demandManually

© 2024 Red Hat, Inc./ atsec information security.

Page 73
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
Hash DRBG (A5098)KATCASTOn demandManually
Hash DRBG (A5099)KATCASTOn demandManually
HMAC DRBG (A5081)KATCASTOn demandManually
HMAC DRBG (A5086)KATCASTOn demandManually
HMAC DRBG (A5087)KATCASTOn demandManually
HMAC DRBG (A5088)KATCASTOn demandManually
HMAC DRBG (A5089)KATCASTOn demandManually
HMAC DRBG (A5090)KATCASTOn demandManually
HMAC DRBG (A5091)KATCASTOn demandManually
HMAC DRBG (A5092)KATCASTOn demandManually
HMAC DRBG (A5093)KATCASTOn demandManually
HMAC DRBG (A5097)KATCASTOn demandManually
HMAC DRBG (A5098)KATCASTOn demandManually
HMAC DRBG (A5099)KATCASTOn demandManually
RSA SigVer (FIPS186-5) (A5081)KATCASTOn demandManually
RSA SigVer (FIPS186-5) (A5097)KATCASTOn demandManually
RSA SigVer (FIPS186-5) (A5098)KATCASTOn demandManually
Entropy source, start-up RCTRCTCASTOn demandManually
Entropy source, start-up APTAPTCASTOn demandManually
Entropy source, continuous RCTRCTCASTOn demandManually
Entropy source, continuous APTAPTCASTOn demandManually
SHA-1 (A5565)KATCASTOn demandManually
SHA2-224 (A5565)KATCASTOn demandManually
SHA2-256 (A5565)KATCASTOn demandManually

© 2024 Red Hat, Inc./ atsec information security.

Page 74
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
SHA2-384 (A5565)KATCASTOn demandManually
SHA2-512 (A5565)KATCASTOn demandManually
SHA3-224 (A5571)KATCASTOn demandManually
SHA3-256 (A5571)KATCASTOn demandManually
SHA3-384 (A5571)KATCASTOn demandManually
SHA3-512 (A5571)KATCASTOn demandManually
HMAC-SHA-1 (A5565)KATCASTOn demandManually
HMAC-SHA2- 224 (A5565)KATCASTOn demandManually
HMAC-SHA2- 256 (A5565)KATCASTOn demandManually
HMAC-SHA2- 384 (A5565)KATCASTOn demandManually
HMAC-SHA2- 512 (A5565)KATCASTOn demandManually
HMAC-SHA3- 224 (A5571)KATCASTOn demandManually
HMAC-SHA3- 256 (A5571)KATCASTOn demandManually
HMAC-SHA3- 384 (A5571)KATCASTOn demandManually
HMAC-SHA3- 512 (A5571)KATCASTOn demandManually
Counter DRBG (A5562)KATCASTOn demandManually
Counter DRBG (A5563)KATCASTOn demandManually
Counter DRBG (A5564)KATCASTOn demandManually
Counter DRBG (A5565)KATCASTOn demandManually
Counter DRBG (A5566)KATCASTOn demandManually
Counter DRBG (A5567)KATCASTOn demandManually
Hash DRBG (A5563)KATCASTOn demandManually
Hash DRBG (A5564)KATCASTOn demandManually
Hash DRBG (A5565)KATCASTOn demandManually
Hash DRBG (A5566)KATCASTOn demandManually

© 2024 Red Hat, Inc./ atsec information security.

Page 75
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
Hash DRBG (A5567)KATCASTOn demandManually
HMAC DRBG (A5563)KATCASTOn demandManually
HMAC DRBG (A5564)KATCASTOn demandManually
HMAC DRBG (A5565)KATCASTOn demandManually
HMAC DRBG (A5566)KATCASTOn demandManually
HMAC DRBG (A5567)KATCASTOn demandManually
AES-ECB (A5562)KATCASTOn demandManually
AES-ECB (A5563)KATCASTOn demandManually
AES-ECB (A5564)KATCASTOn demandManually
AES-ECB (A5565)KATCASTOn demandManually
AES-ECB (A5566)KATCASTOn demandManually
AES-ECB (A5567)KATCASTOn demandManually
AES-CBC (A5561)KATCASTOn demandManually
AES-GCM (A5562)KATCASTOn demandManually
AES-GCM (A5563)KATCASTOn demandManually
AES-GCM (A5564)KATCASTOn demandManually
AES-GCM (A5565)KATCASTOn demandManually
AES-GCM (A5566)KATCASTOn demandManually
AES-GCM (A5567)KATCASTOn demandManually
RSA SigVer (FIPS186-5) (A5099)KATCASTOn demandManually
RSA SigVer (FIPS186-5) (A5565)KATCASTOn demandManually

Table 23: Conditional Periodic Information

10.4 Error States

© 2024 Red Hat, Inc./ atsec information security.

Page 76
NameDescriptionConditionsRecovery MethodIndicator
Error StateThe Linux kernel immediately stops executingAny self-test failureRestart of the moduleKernel Panic

Table 24: Error States In the Error State, the output interface is inhibited, and the module accepts no more inputs or requests (as the module is no longer running).

10.5 Operator Initiation of Self-Tests

All self-tests, with the exception of the continuous health tests, can be invoked on demand by unloading and subsequently re-initializing the module. © 2024 Red Hat, Inc./ atsec information security.

Page 77
11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

The module is distributed as a part of the Red Hat Enterprise Linux 9 (RHEL 9) package in the form of the kernel-5.14.0-284.57.1.el9_2, libkcapi-1.3.1-3.el9, and libkcapi-hmaccalc1.3.1-3.el9 RPM packages. The module can achieve the approved mode by:

11.2 Administrator Guidance

After installation of the kernel-5.14.0-284.57.1.el9_2, libkcapi-1.3.1-3.el9, and libkcapihmaccalc-1.3.1-3.el9 RPM packages, the Crypto Officer must execute the “cat /proc/sys/crypto/fips_name” command. The Crypto Officer must ensure that the proper name is listed in the output as follows: Red Hat Enterprise Linux 9 - Kernel Cryptographic API Then, the Crypto Officer must execute the “cat /proc/sys/crypto/fips_version” and “rpm -q libkcapi” commands. These commands must output the following for each tested operational environment (one line per output): Dell PowerEdge R440: 5.14.0-284.57.1.el9_2.x86_64 libkcapi-1.3.1-3.el9.x86_64 IBM z16 3931-A01: 5.14.0-284.57.1.el9_2.s390x libkcapi-1.3.1-3.el9.s390x IBM 9080-HEX: 5.14.0-284.57.1.el9_2.ppc64le libkcapi-1.3.1-3.el9.ppc64le

11.3 Non-Administrator Guidance

There is no non-administrator guidance. © 2024 Red Hat, Inc./ atsec information security.

Page 78
11.4 Design and Rules

Not applicable for this module.

11.5 Maintenance Requirements

There are no maintenance requirements.

11.6 End of Life

As the module does not persistently store SSPs, secure sanitization of the module consists of unloading the module. This will zeroize all SSPs in volatile memory. Then, if desired, the kernel-5.14.0-284.57.1.el9_2, libkcapi-1.3.1-3.el9, and libkcapi-hmaccalc-1.3.1-3.el9 RPM packages can be uninstalled from the RHEL 9 system. © 2024 Red Hat, Inc./ atsec information security.

Page 79
12 Mitigation of Other Attacks

The module does not offer mitigation of other attacks and therefore this section is not applicable. © 2024 Red Hat, Inc./ atsec information security.

Page 80

Appendix A. Glossary and Abbreviations

AESAdvanced Encryption Standard
AES-NIAdvanced Encryption Standard New Instructions
APIApplication Programming Interface
CASTCryptographic Algorithm Self-Test
CAVPCryptographic Algorithm Validation Program
CBCCipher Block Chaining
CCMCounter with Cipher Block Chaining-Message Authentication Code
CFBCipher Feedback
CMACCipher-based Message Authentication Code
CMVPCryptographic Module Validation Program
CSPCritical Security Parameter
CTRCounter
DRBGDeterministic Random Bit Generator
ECBElectronic Code Book
ENT (NP)Non-physical Entropy Source
FIPSFederal Information Processing Standards
GCMGalois Counter Mode
GMACGalois Counter Mode Message Authentication Code
HMACKeyed-Hash Message Authentication Code
IPsecInternet Protocol Security
KATKnown Answer Test
MACMessage Authentication Code
NISTNational Institute of Science and Technology
PAAProcessor Algorithm Acceleration
PKCSPublic-Key Cryptography Standards
RSARivest, Shamir, Addleman
SHASecure Hash Algorithm
SSPSensitive Security Parameter
XTSXEX-based Tweaked-codebook mode with cipher text Stealing © 2024 Red Hat, Inc./ atsec information security.
Page 81
FIPS 140-3FIPS PUB 140-3 - Security Requirements For Cryptographic Modules March 2019 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-3.pdf
FIPS 140-3 IGImplementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program https://csrc.nist.gov/Projects/cryptographic-module-validation-program/fips- 140-3-ig-announcements
FIPS 180-4Secure Hash Standard (SHS) March 2012 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf
FIPS 186-5Digital Signature Standard (DSS) February 2023 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-5.pdf
FIPS 197Advanced Encryption Standard November 2001 https://csrc.nist.gov/publications/fips/fips197/fips-197.pdf
FIPS 198-1The Keyed Hash Message Authentication Code (HMAC) July 2008 https://csrc.nist.gov/publications/fips/fips198-1/FIPS-198-1_final.pdf
FIPS 202SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions August 2015 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.202.pdf
PKCS#1Public Key Cryptography Standards (PKCS) #1: RSA Cryptography Specifications Version 2.1 February 2003 https://www.ietf.org/rfc/rfc3447.txt
RFC 5288AES Galois Counter Mode (GCM) Cipher Suites for TLS August 2008 https://www.ietf.org/rfc/rfc5288.txt
SP 800-38ARecommendation for Block Cipher Modes of Operation Methods and Techniques December 2001 https://csrc.nist.gov/publications/nistpubs/800-38a/sp800-38a.pdf
SP 800-38ARecommendation for Block Cipher Modes of Operation: Three
AddendumVariants of Ciphertext Stealing for CBC Mode October 2010 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38a- add.pdf
SP 800-38BRecommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication May 2005 https://csrc.nist.gov/publications/nistpubs/800-38B/SP_800-38B.pdf © 2024 Red Hat, Inc./ atsec information security.
Page 82
SP 800-38CRecommendation for Block Cipher Modes of Operation: the CCM Mode for Authentication and Confidentiality May 2004 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800- 38c.pdf
SP 800-38DRecommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC November 2007 https://csrc.nist.gov/publications/nistpubs/800-38D/SP-800-38D.pdf
SP 800-38ERecommendation for Block Cipher Modes of Operation: The XTS AES Mode for Confidentiality on Storage Devices January 2010 https://csrc.nist.gov/publications/nistpubs/800-38E/nist-sp-800-38E.pdf
SP 800-38FRecommendation for Block Cipher Modes of Operation: Methods for Key Wrapping December 2012 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38F.pdf
SP 800-90Ar1Recommendation for Random Number Generation Using Deterministic Random Bit Generators June 2015 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90Ar1.pdf
SP 800-90BRecommendation for the Entropy Sources Used for Random Bit Generation January 2018 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90B.pdf
SP 800-Transitioning the Use of Cryptographic Algorithms and Key
131Ar2Lengths March 2019 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800- 131Ar2.pdf
SP 800-133r2Recommendation for Cryptographic Key Generation June 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-133r2.pdf
SP 800-140BCMVP Security Policy Requirements March 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-140B.pdf © 2024 Red Hat, Inc./ atsec information security.