All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Oracle Linux 9 GnuTLS Cryptographic Module

Certificate#5037StandardFIPS 140-3Level1TypeSoftwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorOracle Corporation
Low review priority  ·  no TCB surface named  ·  GnuTLS upstream has published 9 CVEs since this module's initial validation  ·  last validated 10 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date7/2/2030
CaveatWhen operated in approved mode and installed, initialized and configured as specified in Section 11.1 of the Security Policy.
VendorOracle Corporation

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Oracle Linux 9 GnuTLS Cryptographic Module
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Recovery<br/>Update</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>HTTPS<br/>library named: gnutls</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Oracle Linux 9 GnuTLS Cryptographic Module
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Recovery<br/>Update</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>HTTPS<br/>library named: gnutls</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Oracle Corporation Oracle Linux 9 GnuTLS Cryptographic Module Software Version: 3.7.6-39e2433a29b33b55 Prepared by: atsec information security corporation

4516 Seton Center Pkwy, Suite 250

Austin, TX 78759 www.atsec.com Document Version 1.4. ©Oracle Corporation

Page 2

Title: Oracle 9 GnuTLS Cryptographic Module Security Policy Date: August 28th, 2025 Contributing Authors: Oracle Linux Engineering Security Evaluations – Global Product Security atsec information security Oracle Corporation World Headquarters

2300 Oracle Way

Austin, TX 78741 U.S.A. Worldwide Inquiries: Phone: +1.650.506.7000 Fax: +1.650.506.7200 www.oracle.com hereof are subject to change without notice. This document is not warranted to be error-free, nor subject to any other warranties or conditions, whether expressed orally or implied in law, including implied warranties and conditions of merchantability or fitness for a particular purpose. Oracle specifically disclaim any liability with respect to this document and no contractual obligations are formed either directly or indirectly by Oracle and Java are registered trademarks of Oracle and/or its affiliates. Other names may be trademarks of their respective owners. Oracle Linux 9 GnuTLS Cryptographic Module Security Policy i

Page 3
Table of Contents
#SectionPage
Page 4

Oracle Linux 9 GnuTLS Cryptographic Module Security Policy iii

Page 5
List of Tables
ItemPage
Table 1: Security Levels1
Table 2: Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets)3
Table 3: Tested Operational Environments - Software, Firmware, Hybrid3
Table 4: Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid3
Table 5: Modes List and Description4
Table 6: Approved Algorithms7
Table 7: Vendor-Affirmed Algorithms7
Table 8: Non-Approved, Not Allowed Algorithms8
Table 9: Security Function Implementations10
Table 10: Entropy Certificates12
Table 11: Entropy Sources12
Table 12: Ports and Interfaces14
Table 13: Roles15
Table 14: Approved Services19
Table 15: Non-Approved Services21
Table 16: Storage Areas26
Table 17: SSP Input-Output Methods26
Table 18: SSP Zeroization Methods26
Table 19: SSP Table 128
Table 20: SSP Table 230
Table 21: Pre-Operational Self-Tests31
Table 22: Conditional Self-Tests35
Table 23: Pre-Operational Periodic Information35
Table 24: Conditional Periodic Information36
Table 25: Error States37
Page 6
List of Figures
ItemPage
Figure 1: Cryptographic Boundary2
Page 7
SectionTitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication1
5Software/Firmware security1
6Operational environment1
7Physical securityN/A
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacksN/A
Overall Level1
1.1 Overview

This document is the non-proprietary FIPS 140-3 Security Policy for version 3.7.6-39e2433a29b33b55 of the Oracle

9 GnuTLS Cryptographic Module. It contains the security rules under which the module must operate and

describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for an overall Security Level 1 module.

1.2 Security Levels
1.3 Additional Information

This Security Policy describes the features and design of the module named GnuTLS Cryptographic Module using the terminology contained in the FIPS 140-3 specification. The FIPS 140-3 Security Requirements for Cryptographic Module specifies the security requirements that will be satisfied by a cryptographic module utilized within a security system protecting sensitive but unclassified information. The NIST/CCCS Cryptographic Module Validation Program (CMVP) validates cryptographic module to FIPS 140-3. Validated products are accepted by the Federal agencies of both the USA and Canada for the protection of sensitive or designated information. this notice. Other documentation is proprietary to their authors. In preparing the Security Policy document, the laboratory formatted the vendor-supplied documentation for consolidation without altering the technical statements therein contained. The further refining of the Security Policy document was conducted iteratively throughout the conformance testing, wherein the Security Policy was submitted to the vendor, who would then edit, modify, and add technical contents. The vendor would also supply additional documentation, which the laboratory formatted into the existing Security Policy, and resubmitted to the vendor for their final editing. Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 8
2 Cryptographic Module Specification
2.1 Description

Purpose and Use: The Oracle 9 GnuTLS Cryptographic Module (hereafter referred to as “the module”) is a cryptographic module that provides cryptographic services to applications running in the user space of the underlying operating system through a C language Application Program Interface (API). Module Type: Software Module Embodiment: MultiChipStand Cryptographic Boundary: Figure 1 shows the cryptographic boundary of the module, its interfaces with the operational environment and the information flow between the module and operator (depicted through the arrows). The module components consist of the libgnutls.so.30, libnettle.so.8, libhogweed.so.6, and libgmp.so.10. The module integrity is verified for each of the component separately using HMAC at power on by comparing with the pre-computed HMAC values stored in .libgnutls.so.30.hmac file Tested Operational Environment’s Physical Perimeter (TOEPP): The TOEPP of the module is defined as the general-purpose computer on which the module is installed. Figure 1: Cryptographic Boundary Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 9
Package or File NameSoftware/ Firmware VersionFeaturesIntegrity Test
libgnutls.so.30; libnettle.so.8; libhogweed.so.6; libgmp.so.10 (statically linked to libgnutls); libgnutls.so.30.hmac on ORACLE SERVER X9-2c with Intel(R) Xeon(R) Platinum 83583.7.6-39e2433a29b33b55N/AHMAC-SHA-256
libgnutls.so.30; libnettle.so.8; libhogweed.so.6; libgmp.so.10 (statically linked to libgnutls); libgnutls.so.30.hmac on ORACLE SERVER E4-2c with AMD EPYC 7J133.7.6-39e2433a29b33b55N/AHMAC-SHA-256
libgnutls.so.30; libnettle.so.8; libhogweed.so.6; libgmp.so.10 (statically linked to libgnutls); libgnutls.so.30.hmac on ORACLE SERVER A1-2c with Ampere(R) Altra(R) Q80-303.7.6-39e2433a29b33b55N/AHMAC-SHA-256
Operating SystemHardware PlatformProcessorsPAA/PAIHypervisor or Host OSVersion(s)
Oracle Linux 9ORACLE SERVER X9-2cIntel(R) Xeon(R) Platinum 8358YesKVM on Oracle Linux 83.7.6-39e2433a29b33b55
Oracle Linux 9ORACLE SERVER E4-2cAMD EPYC 7J13YesKVM on Oracle Linux 83.7.6-39e2433a29b33b55
Oracle Linux 9ORACLE SERVER A1-2cAmpere(R) Altra(R) Q80-30YesKVM on Oracle Linux 83.7.6-39e2433a29b33b55
Operating SystemHardware Platform
Oracle Linux 9Oracle X Series Servers
Oracle Linux 9Oracle E Series Servers
Oracle Linux 9Oracle A Series Servers
Oracle Linux 9Marvell T93 LiquidIO III (ARM v8.x) SmartNIC
Oracle Linux 9Pensando DSC-200-R (ARM v8.x) SmartNIC
Oracle Linux 9Marvell Liquid IO II (MIPS64) SmartNIC
Oracle Linux 9Nvidia Bluefield-3 (ARM v8.x) SmartNIC
2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification

Page 10
Mode NameDescriptionTypeStatus Indicator
Approved modeAutomatically entered whenever an approved service is requestedApprovedEquivalent to the indicator of the requested service as defined in section 4.3
Non-approved modeAutomatically entered whenever a non-approved service is requestedNon- ApprovedEquivalent to the indicator of the requested service as defined in section 4.3
AlgorithmCAVP CertPropertiesReference
AES-CBCA4743Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBCA4744Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBCA4745Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBCA4746Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBCA4751Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBCA4755Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CCMA4743Key Length - 128, 256SP 800-38C
AES-CCMA4755Key Length - 128, 256SP 800-38C
AES-CFB8A4748Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB8A4749Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB8A4754Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CMACA4743Direction - Generation, Verification Key Length - 128, 256SP 800-38B
AES-CMACA4746Direction - Generation, Verification Key Length - 128, 256SP 800-38B
2.3 Excluded Components

There are no components within the cryptographic boundary excluded from the FIPS 140-3 requirements.

2.4 Modes of Operation

Modes List and Description: Table 5: Modes List and Description Mode Change Instructions and Status: When the module starts up successfully, after passing the pre-operational and all conditional cryptographic algorithms self-tests (CASTs), the module is operating in the approved mode of operation by default and can only be transitioned into the non-approved mode by calling one of the non-approved services listed in Non-Approved Services table. Please see Section 4 or the details on service indicator provided by the module that identifies when

2.5 Algorithms

Approved Algorithms: Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 11
AlgorithmCAVP CertPropertiesReference
AES-CMACA4751Direction - Generation, Verification Key Length - 128, 256SP 800-38B
AES-ECBA4751Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-GCMA4743Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 256SP 800-38D
AES-GCMA4744Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 256SP 800-38D
AES-GCMA4745Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 256SP 800-38D
AES-GCMA4746Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 256SP 800-38D
AES-GCMA4751Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 256SP 800-38D
AES-GCMA4755Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 256SP 800-38D
AES-GMACA4751Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 256SP 800-38D
AES-XTS Testing Revision 2.0A4752-SP 800-38E
Counter DRBGA4751Prediction Resistance - No Mode - AES-256 Derivation Function Enabled - NoSP 800-90A Rev. 1
ECDSA KeyGen (FIPS186-4)A4751Curve - P-256, P-384, P-521FIPS 186-4
ECDSA KeyVer (FIPS186-4)A4751Curve - P-256, P-384, P-521FIPS 186-4
ECDSA SigGen (FIPS186-4)A4751Component - No Curve - P-256, P-384, P-521FIPS 186-4
ECDSA SigVer (FIPS186-4)A4751Component - No Curve - P-256, P-384, P-521FIPS 186-4
HMAC-SHA-1A4746Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA-1A4751Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA-1A4755Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-224A4746Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-224A4751Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-224A4755Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-256A4746Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-256A4751Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-256A4755Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-384A4746Key Length - Key Length: 112-524288 Increment 8FIPS 198-1

Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 12
AlgorithmCAVP CertPropertiesReference
HMAC-SHA2-384A4751Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-384A4755Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512A4746Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512A4751Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2-512A4755Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
KAS-ECC-SSC Sp800- 56Ar3A4751Domain Parameter Generation Methods - P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KAS-FFC-SSC Sp800- 56Ar3A4751Domain Parameter Generation Methods - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192 Scheme - dhEphem - KAS Role - initiator, responderSP 800-56A Rev. 3
KDA HKDF Sp800- 56Cr1A4750Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-65336 Increment 8 HMAC Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512SP 800-56C Rev. 2
PBKDFA4751Iteration Count - Iteration Count: 1000-10000 Increment 1 Password Length - Password Length: 8-128 Increment 1SP 800-132
RSA KeyGen (FIPS186-4)A4751Key Generation Mode - B.3.2 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Private Key Format - StandardFIPS 186-4
RSA SigGen (FIPS186-4)A4751Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186-4)A4751Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096FIPS 186-4
Safe Primes Key GenerationA4751Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP- 2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192SP 800-56A Rev. 3
SHA-1A4746Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA-1A4751Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA-1A4755Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-224A4746Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-224A4751Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-224A4755Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-256A4746Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-256A4751Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-256A4755Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-384A4746Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-384A4751Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-384A4755Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512A4746Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512A4751Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512A4755Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA3-224A4747-FIPS 202
SHA3-224A4753-FIPS 202
SHA3-256A4747-FIPS 202
SHA3-256A4753-FIPS 202
SHA3-384A4747-FIPS 202
SHA3-384A4753-FIPS 202
SHA3-512A4747-FIPS 202
SHA3-512A4753-FIPS 202

Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 13
AlgorithmCAVP CertPropertiesReference
TLS v1.2 KDF RFC7627 (CVL)A4751-SP 800-135 Rev. 1
NamePropertiesImplementationReference
CKGKey Type:Symmetric and Asymmetric RSA (asymmetric):2048, 3072, 4096 bits with 112, 128, 149 bits of key strength. ECDSA (asymmetric):P-224, P-256, P 384, P-521 elliptic curves with 112-256 bits of key strength Safe Primes (asymmetric):ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP- 2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192 2048, 3072, 4096, 6144, 8192- bit keys (112-200 bits of key strength) CTR_DRBG (symmetric):112-256 bit keys (112-256 bits of strength)N/ASP 800-133r2 section 4 example 1
NameUse and Function
BlowfishSymmetric Encryption; Symmetric Decryption
CamelliaSymmetric Encryption; Symmetric Decryption
CASTSymmetric Encryption; Symmetric Decryption
ChaCha20Symmetric Encryption; Symmetric Decryption
Chacha20 and Poly1305Authenticated Encryption; Authenticated Decryption
CMAC with Triple-DESMessage Authentication Code (MAC)
DESSymmetric Encryption; Symmetric Decryption
Diffie-Hellman using keys generated with domain parameters other than safe primesShared Secret Computation
DSAKey Generation; Domain Parameter Generation; Digital Signature Generation; Digital Signature Verification
ECDSA with curves not listed in the Approved Algorithms TableKey Generation; Public Key Verification
ECDSA with curves/hash functions not listed in the Approved Algorithms TableDigital Signature Generation; Digital Signature Verification
EC Diffie-Hellman with curves not listed in the Approved Algorithms TableShared Secret Computation
GMAC with keys not listed in the Approved Algorithms TableMessage Authentication Code (MAC)
GOSTSymmetric Encryption; Symmetric Decryption; Message Digest
HMAC with keys smaller than 112-bitMessage Authentication Code (MAC)
HMAC with GOSTMessage Authentication Code (MAC)
MD2, MD4, MD5Message Digest; Message Authentication Code (MAC)
PBKDF with non-approved message digest algorithms or using input parameters not meeting requirements stated in section 2.7Key Derivation
RC2, RC4Symmetric Encryption; Symmetric Decryption
RMD160Message Digest; Message Authentication Code (MAC)
RSA with keys smaller than 2048 bits.Key Generation
RSA with keys smaller than 2048 bits and/or hash functions not listed in the Approved Algorithms TableDigital Signature Generation; Digital Signature Verification
RSA encryption and decryption with any key sizesKey Encapsulation; Key Un-encapsulation
Salsa20Symmetric Encryption; Symmetric Decryption
SEEDSymmetric Encryption; Symmetric Decryption

Vendor-Affirmed Algorithms: Table 7: Vendor-Affirmed Algorithms Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 14
NameUse and Function
SerpentSymmetric Encryption; Symmetric Decryption
SRPKey Agreement
STREEBOGMessage Digest; Message Authentication Code (MAC)
Triple-DESSymmetric Encryption; Symmetric Decryption
TwofishSymmetric Encryption; Symmetric Decryption
UMACMessage Authentication Code (MAC)
YarrowRandom Number Generation
DRBG generation of keys smaller than 112 bitsRandom Number Generation
Non-supported cipher suites (see Appendix A for the complete list of valid cipher suites)Transport Layer Security (TLS) network protocol
AES GCM with keys not listed in the Approved Algorithms TableAuthenticated Encryption; Authenticated Decryption
NameTypeDescriptionPropertiesAlgorithms
KAS-ECC-SSCKAS-SSCShared Secret ComputationCurves:P-224, P-256, P-384, P-521 elliptic curves with 112-256 bits of key strength Compliance: Compliant with IG D.F scenario 2(1)KAS-ECC-SSC Sp800-56Ar3: (A4751)
KAS-FFC-SSCKAS-SSCShared Secret ComputationKeys:2048, 3072, 4096, 6144, 8192-bit keys with 112-200 bits of key strength Compliance:Compliant with IG D.F scenario 2(1)KAS-FFC-SSC Sp800-56Ar3: (A4751)
AES CBC with HMACKTS-WrapKey Wrapping, Key UnwrappingKeys:128, 192, 256 bits with 128-256 bits of key strength Compliance:Compliant with IG D.GAES-CBC: (A4743, A4744, A4745, A4746, A4751, A4755) HMAC-SHA-1: (A4746, A4751, A4755) HMAC-SHA2-224: (A4746, A4751, A4755) HMAC-SHA2-256: (A4746, A4751, A4755) HMAC-SHA2-384: (A4746, A4751, A4755) HMAC-SHA2-512: (A4746, A4751, A4755)
AES CCM (Key Wrapping/Unwrapping)KTS-WrapKey Wrapping, Key UnwrappingKeys:128 and 256 bits with 128 and 256 bits of key strength Compliance:Compliant with IG D.GAES-CCM: (A4743, A4755)
AES GCM (Key Wrapping/Unwrapping)KTS-WrapKey Wrapping, Key UnwrappingKeys:128 and 256 bits with 128 and 256 bits of key strength Compliance:Compliant with IG D.GAES-GCM: (A4743, A4744, A4745, A4746, A4751, A4755)
AES CCM (Authenticated Encryption/Decryption)BC-AuthAuthenticated Encryption/DecryptionKeys:128 and 256 bits with 128 and 256 bits of key strengthAES-CCM: (A4743, A4755)

Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 15
NameTypeDescriptionPropertiesAlgorithms
AES GCM (Authenticated Encryption/Decryption)BC-AuthAuthenticated Encryption/DecryptionKeys:128 and 256 bits with 128 and 256 bits of key strengthAES-GCM: (A4743, A4744, A4745, A4746, A4751, A4755)
AES-CBCBC-UnAuthEncryption/DecryptionKeys:128, 192, 256 bits with 128-256 bits of key strengthAES-CBC: (A4743, A4744, A4745, A4746, A4751, A4755)
AES-CMACMACMessage authentication code (MAC)Keys:128 and 256 bits with 128 and 256 bits of key strengthAES-CMAC: (A4743, A4746, A4751)
HMACMACMessage authentication code (MAC)Keys:112-524288 bits with 112-256 bits of key strengthHMAC-SHA-1: (A4746, A4751, A4755) HMAC-SHA2-224: (A4746, A4751, A4755) HMAC-SHA2-256: (A4746, A4751, A4755) HMAC-SHA2-384: (A4746, A4751, A4755) HMAC-SHA2-512: (A4746, A4751, A4755)
HashesSHAHashingSHA-1: (A4746, A4751, A4755) SHA2-224: (A4746, A4751, A4755) SHA2-256: (A4746, A4751, A4755) SHA2-384: (A4746, A4751, A4755) SHA2-512: (A4746, A4751, A4755) SHA3-224: (A4747, A4753) SHA3-256: (A4747, A4753) SHA3-384: (A4747, A4753) SHA3-512: (A4747, A4753)
AES-CFB8BC-UnAuthEncryption/DecryptionKeys:128, 192, 256 bits with 128-256 bits of key strengthAES-CFB8: (A4748, A4749, A4754)
AES-XTSBC-UnAuthEncryption/DecryptionKeys:128, 256 bits with 128 and 256 bits of key strengthAES-XTS Testing Revision 2.0: (A4752)
AES-GMACMACMessage authentication code (MAC)Keys:128 and 256 bits with 128 and 256 bits of key strengthAES-GMAC: (A4751)
Counter DRBGDRBGRandom Number GenerationCompliance:Compliant with SP800-90ARev1Counter DRBG: (A4751)
ECDSA Signature GenerationDigSig-SigGenSignature GenerationCurves: P-224, P-256, P- 384, P-521 Hashes:SHA2-224, SHA2- 256, SHA2-384, SHA2-512ECDSA SigGen (FIPS186-4): (A4751)
ECDSA Key GenerationCKGKey GenerationCurves:P-224, P-256, P-384, P-521ECDSA KeyGen (FIPS186-4): (A4751)
ECDSA Signature VerificationDigSig-SigVerSignature VerificationCurves: P-224, P-256, P- 384, P-521 Hashes:SHA2-224, SHA2- 256, SHA2-384, SHA2-512ECDSA SigVer (FIPS186-4): (A4751)
ECDSA Key VerificationAsymKeyPair-KeyVerKey VerificationCurves:P-224, P-256, P-384, P-521ECDSA KeyVer (FIPS186-4): (A4751)
RSA Signature GenerationDigSig-SigGenSignature GenerationKeys:2048-16384 bits Hashes:SHA2-224, SHA2- 256, SHA2-384, SHA2-512RSA SigGen (FIPS186-4): (A4751)

Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 16
NameTypeDescriptionPropertiesAlgorithms
RSA Key GenerationCKGKey GenerationKeys:2048-15360 bitsRSA KeyGen (FIPS186-4): (A4751)
RSA Signature VerificationDigSig-SigVerSignature VerificationKeys:1024-16384 bits Hashes:SHA2-224, SHA2- 256, SHA2-384, SHA2-512RSA SigVer (FIPS186-4): (A4751)
Safe Primes Key GenerationCKGKey GenerationGroups:MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192Safe Primes Key Generation: (A4751)
HKDF Key DerivationKAS-56CKDFKey DerivationHKDF derived key:112-256 bits with 112-256 bits of key strengthKDA HKDF Sp800-56Cr1: (A4750)
Password-based Key DerivationPBKDFKey DerivationPBKDF Derived key:112- 4096 bits with 112-256 bits of key strengthPBKDF: (A4751)
TLS 1.2 Key DerivationKAS-135KDFKey DerivationDerived secret::112-256 bits with112-256 bits of key strengthTLS v1.2 KDF RFC7627: (A4751)
AES-ECBBC-UnAuthEncryption/DecryptionKeys:128, 192, 256 bitsAES-ECB: (A4751)
TLS HandshakeKAS-FullKey AgreementCurves:P-224, P-256, P-384, P-521 elliptic curves with 112-256 bits of key strength Keys:2048, 3072, 4096, 6144, 8192-bit keys with 112-200 bits of key strength Compliance:Compliant with IG D.F scenario 2(2)KAS-ECC-SSC Sp800-56Ar3: (A4751) KAS-FFC-SSC Sp800-56Ar3: (A4751) KDA HKDF Sp800-56Cr1: (A4750) TLS v1.2 KDF RFC7627: (A4751)
Symmetric Key Generation with Counter DRBGCKGSymmetric Key GenerationKeys:112-256 bits with 112- 256 bits of key strength Compliance:SP 800-133r2 section 6.1Counter DRBG: (A4751)

Table 9: Security Function Implementations

2.7 Algorithm Specific Information
2.7.1 AES GCM IV

The Crypto Officer shall consider the following requirements and restrictions when using the module. For TLS 1.2, the module offers the AES GCM implementation and uses the context of Scenario 1 of FIPS 140-3 IG C.H. The module is compliant with SP 800-52r2 Section 3.3.1 and the mechanism for IV generation is compliant with RFC 5288 and 8446. The design of the TLS protocol implicitly ensures that the counter (the nonce_explicit part of the IV) does not exhaust the maximum number of possible values for a given session key. In the event the module’s power is lost and restored, the consuming application must ensure that a new key for use with the AES GCM key encryption or decryption under this scenario shall be established. Alternatively, the Crypto Officer can use the module’s API to perform AES GCM encryption using internal IV generation. These IVs are always 96 bits and generated using the approved DRBG internal to the module’s boundary. This is in compliance with Scenario 2 of FIPS 140-3 IG C.H. Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 17

Finally, for TLS 1.3, the AES GCM implementation uses the context of Scenario 5 of FIPS 140-3 IG C.H. The protocol that provides this compliance is TLS 1.3, defined in RFC8446 of August 2018, using the cipher-suites that explicitly select AES GCM as the encryption/decryption cipher (Appendix B.4 of RFC8446). The module supports acceptable AES GCM cipher suites from Section 3.3.1 of SP800-52r2. TLS 1.3 employs separate 64-bit sequence numbers, one for protocol records that are received, and one for protocol records that are sent to a peer. These sequence numbers are set at zero at the beginning of a TLS 1.3 connection and each time when the AES-GCM key is changed. After reading or writing a record, the respective sequence number is incremented by one. The protocol specification determines that the sequence number should not wrap, and if this condition is observed, then the protocol implementation must either trigger a re-key of the session (i.e., a new key for AES-GCM), or terminate the connection. The IV generated in both TLS 1.2 and TLS 1.3 scenarios is only used within the context of the TLS protocol implementation.

2.7.2 Key Derivation using SP 800-132 PBKDF2

The module provides password-based key derivation (PBKDF2), compliant with SP 800-132. The module supports option 1a from Section 5.4 of SP 800-132, in which the Master Key (MK) or a segment of it is used directly as the Data Protection Key (DPK). In accordance with [SP800-132], the module ensures that the following requirements are met when running the PBKDF approved service.

2.7.3 AES XTS

The length of a single data unit encrypted or decrypted with AES XTS shall not exceed 220 AES blocks, that is 16MB, of data per XTS instance. An XTS instance is defined in Section 4 of SP 800-38E. To meet the requirement stated in IG C.I, the module implements a check to ensure that the two AES keys used in AES XTS mode are not identical. The XTS mode shall only be used for the cryptographic protection of data on storage devices. It shall not be used for other purposes, such as the encryption of data in transit.

2.7.4 SP 800-56Ar3 Assurances

The module offers DH and ECDH shared secret computation services compliant to the SP 800-56Ar3. To meet the required assurances listed in section 5.6 of SP 800-56Ar3, the module shall be used together with an application that implements the “TLS protocol” and the following steps shall be performed. Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 18
Cert NumberVendor Name
E99Oracle Corporation
NameTypeOperational EnvironmentSample SizeEntropy per SampleConditioning Component
Oracle User Space CPU Time Jitter RNG Entropy SourceNon- PhysicalOracle Linux 9 on KVM on Oracle Linux 8 on AMD AMD EPYC(TM) 7001 Series AMD EPYC 7J13; Ampere Ampere(R) Altra(R) Ampere(R) Altra(R) Q80-30; Intel Ice Lake Intel(R) Xeon(R) Platinum 8358256 bits256 bitsAES-256 CTR DRBG (CAVP cert #A4751)
2.8 RBG and Entropy

Table 10: Entropy Certificates Table 11: Entropy Sources RNG Information: The module employs a Deterministic Random Bit Generator (DRBG) based on SP 800-90Ar1 for keys and random numbers for security functions (e.g. ECDSA signature generation), and server and client random numbers for the TLS protocol. In addition, the module provides a Random Number Generation service to calling applications. The DRBG supports the CTR_DRBG with AES-256, without a derivation function and without prediction resistance. The module uses an [SP800-90B]-compliant entropy source specified in the Entropy Source table. This entropy source is located within the physical perimeter, but outside of the cryptographic boundary of the module. The module obtains 384 bits to seed the DRBG, and 256 bits to reseed it, sufficient to provide a DRBG with 256 bits of security strength.

2.9 Key Generation

The module implements key generation methods according to SP 800-133r2 section 4 example 1, without the use of V. The key generation methods are specified in the Vendor Affirmed Algorithms table and the Security Function Implementations table. Additionally, the module implements key derivation methods according to section 6.2 of SP 800-133r2. The key derivation methods are specified in the Security Function Implementations table.

2.10 Key Establishment

The module implements SSP agreement, compliant with IG D.F scenario 2(1) and scenario 2(2). Additionally, the module implements SSP transport, compliant with IG D.G. The Key Establishment methods are specified in the Security Function Implementations table. Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 19
2.11 Industry Protocols

The module implements KDF for the TLS protocol TLSv1.2. No parts of the TLS 1.2, other than the key derivation functions mentioned above, have been tested by the CAVP and CMVP. The module implements HKDF for the TLS protocol TLSv1.3. Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 20
Physical PortLogical Interface(s)Data That Passes
N/AData InputAPI input parameters, kernel I/O network or files on filesystem, TLS protocol input messages.
N/AData OutputAPI output parameters, kernel I/O network or files on filesystem, TLS protocol output messages.
N/AControl InputAPI function calls, API input parameters for control.
N/AStatus OutputAPI return codes, API output parameters for status output.
3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

Table 12: Ports and Interfaces The logical interfaces are the APIs through which the applications request services. These logical interfaces are logically separated from each other by the API design. The module does not implement a control output interface.

3.2 Trusted Channel Specification

The module does not implement a trusted channel.

3.3 Control Interface Not Inhibited

The module does not implement a control output interface. Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 21
NameTypeOperator TypeAuthentication Methods
Crypto OfficerRoleCONone
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
Message DigestCompute a message digestGNUTLS_FIPS140_OP_APPROVEDMessageDigest valueHashesCrypto Officer
EncryptionEncrypt a plaintextGNUTLS_FIPS140_OP_APPROVEDAES Key, plaintextCiphertextAES-CBC AES-CFB8 AES-XTS AES-ECBCrypto Officer - AES Key: W,E
DecryptionDecrypt a ciphertextGNUTLS_FIPS140_OP_APPROVEDAES Key, ciphertextPlaintextAES-CBC AES-CFB8 AES-XTS AES-ECBCrypto Officer - AES Key: W,E
Authenticated DecryptionAuthenticated DecryptionGNUTLS_FIPS140_OP_APPROVEDAES key, IV, MAC tag, ciphertextPlaintext or failureAES CCM (Authenticated Encryption/Decryption) AES GCM (Authenticated Encryption/Decryption)Crypto Officer - AES Key: W,E
Authenticated EncryptionAuthenticated EncryptionGNUTLS_FIPS140_OP_APPROVEDAES Key, IV, plaintextCiphertext, MAC tagAES CCM (Authenticated Encryption/Decryption) AES GCM (Authenticated Encryption/Decryption)Crypto Officer - AES Key: W,E
AES Message AuthenticationMessage AuthenticationGNUTLS_FIPS140_OP_APPROVEDAES Key, messageMAC tagAES-CMAC AES-GMACCrypto Officer - AES Key: W,E
HMAC Message AuthenticationMessage AuthenticationGNUTLS_FIPS140_OP_APPROVEDHMAC Key, messageMAC tagHMACCrypto Officer - HMAC Key: W,E
ECDH Shared Secret ComputationCompute a shared secretGNUTLS_FIPS140_OP_APPROVEDEC Private Key, EC Public KeyShared secretKAS-ECC-SSCCrypto Officer - EC Private Key: W,E - EC Public Key: W,E - Shared Secret: G,R
Key DerivationDerive a keyGNUTLS_FIPS140_OP_APPROVEDShared SecretHKDF derived keyHKDF Key Derivation TLS 1.2 Key DerivationCrypto Officer - Shared Secret: W,E - TLS Pre- Master Secret: W,E - TLS Master Secret: W,E - TLS Derived
4 Roles, Services, and Authentication

The module does not implement authentication for roles.

4.2 Roles

Table 13: Roles The module supports the Crypto Officer role only. This sole role is implicitly and always assumed by the operator of the module. The module does not support multiple concurrent operators.

4.3 Approved Services

W,E W,E Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 22
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access Secret: G,R - HKDF Derived Key: G,R
Password-Based Key DerivationDerive a key from a passwordGNUTLS_FIPS140_OP_APPROVEDPasswordPBKDF derived keyPassword-based Key DerivationCrypto Officer - Password: W,E - PBKDF Derived Key: G,R
DH Key Pair GenerationKey Pair GenerationGNUTLS_FIPS140_OP_APPROVEDDH GroupModule generated DH private key, Module generated DH public keySafe Primes Key GenerationCrypto Officer - Module Generated DH Public Key: G,R - Module Generated DH Private Key: G,R - Intermediate Key Generation Value: G
EC Key Pair GenerationKey Pair GenerationGNUTLS_FIPS140_OP_APPROVEDCurveModule generated EC private key, Module generated EC public keyECDSA Key GenerationCrypto Officer - Module Generated EC Public Key: G,R - Module Generated EC Private Key: G,R - Intermediate Key Generation Value: G
RSA Key Pair GenerationKey Pair GenerationGNUTLS_FIPS140_OP_APPROVEDModulusModule generated RSA private key, Module generated RSA public keyRSA Key GenerationCrypto Officer - Module Generated RSA Private Key: G,R - Module Generated RSA Public Key: G,R - Intermediate Key Generation Value: G,R
Public Key VerificationVerify an EC public keyGNUTLS_FIPS140_OP_APPROVEDEC public keyReturn codes/log messagesECDSA Key VerificationCrypto Officer - EC Private Key: W,E - EC Public Key: W,E
Key WrappingWrap a keyGNUTLS_FIPS140_OP_APPROVEDAES Key, key to be wrappedWrapped keyAES CCM (Key Wrapping/Unwrapping) AES CBC with HMAC AES GCM (Key Wrapping/Unwrapping)Crypto Officer - AES Key: W,E

G,R W,E G,R G,R G,R Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 23
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
Key UnwrappingUnwrap a keyGNUTLS_FIPS140_OP_APPROVEDAES Key, key to be unwrappedUnwrapped keyAES CCM (Key Wrapping/Unwrapping) AES CBC with HMAC AES GCM (Key Wrapping/Unwrapping)Crypto Officer - AES Key: W,E
Random Number GenerationGenerate random bytesGNUTLS_FIPS140_OP_APPROVEDOutput lengthRandom bytesCounter DRBGCrypto Officer - Entropy Input: W,E - DRBG Seed: G,E - Internal State (V, Key): G,E
Signature VerificationVerify a digital signatureGNUTLS_FIPS140_OP_APPROVEDMessage, EC Public Key or RSA Public Key, signature, hash algorithmPass/failECDSA Signature Verification RSA Signature VerificationCrypto Officer - EC Public Key: W,E - RSA Public Key: W,E
Signature GenerationSignature GenerationGNUTLS_FIPS140_OP_APPROVEDMessage, EC Private Key or RSA Private Key, hash algorithmSignatureECDSA Signature Generation RSA Signature GenerationCrypto Officer - EC Private Key: W,E - RSA Private Key: W,E
Show VersionReturn the module name and version informationNoneN/AModule name and versionNoneCrypto Officer
Show StatusReturn the module statusNoneN/AModule statusNoneCrypto Officer
Self-TestPerform the CASTs and integrity testsNoneN/APass/FailKAS-ECC-SSC KAS-FFC-SSC AES CCM (Key Wrapping/Unwrapping) AES GCM (Key Wrapping/Unwrapping) AES-CBC AES-CMAC HMAC Hashes AES-CFB8 AES-XTS AES-GMAC Counter DRBG ECDSA Signature Generation ECDSA Key Generation ECDSA Signature Verification RSA Signature Generation RSA Key Generation RSA Signature Verification Safe Primes Key Generation HKDF Key Derivation Password-based Key Derivation TLS 1.2 Key Derivation AES-ECB AES CCM (Authenticated Encryption/Decryption)Crypto Officer

G,E G,E Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 24
NameDescriptionIndicatorInputsOutputsSecurity Functions AES GCM (Authenticated Encryption/Decryption)SSP Access
ZeroizationZeroize all SSPsNoneAny SSPN/ANoneCrypto Officer - Module- generated AES Key: Z - AES Key: Z - Module- generated HMAC Key: Z - HMAC Key: Z - Shared Secret: Z - Password: Z - Entropy Input: Z - DRBG Seed: Z - Internal State (V, Key): Z - DH Public Key: Z - DH Private Key: Z - Module Generated DH Public Key: Z - Module Generated DH Private Key: Z - EC Private Key: Z - EC Public Key: Z - Module Generated EC Private Key: Z - Module Generated EC Public Key: Z - RSA Private Key: Z - RSA Public Key: Z - Module Generated RSA Private Key: Z - Module Generated RSA Public Key: Z - Intermediate Key Generation Value: Z - TLS Pre- Master Secret: Z - TLS Master Secret: Z - TLS Derived Secret: Z

Z Z Z Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 25
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access - PBKDF Derived Key: Z - HKDF Derived Key: Z
Transport Layer Security (TLS) Network ProtocolProvide supported cipher suites in approved modeGNUTLS_FIPS140_OP_APPROVEDCipher-suites, Digital Certificate, Public and Private Keys, Application DataReturn codes and/or log messages, Application dataAES CBC with HMAC AES-CBC Hashes ECDSA Signature Generation ECDSA Key Generation ECDSA Signature Verification ECDSA Key Verification RSA Signature Generation RSA Signature Verification Safe Primes Key Generation TLS Handshake AES CCM (Authenticated Encryption/Decryption) AES GCM (Authenticated Encryption/Decryption)Crypto Officer - AES Key: W,E - HMAC Key: W,E - RSA Public Key: W,E - RSA Private Key: W,E - EC Public Key: W,E - EC Private Key: W,E - Module Generated DH Public Key: G,E - Module Generated DH Private Key: G,E - Module Generated EC Private Key: G,E - Module Generated EC Public Key: G,E - TLS Master Secret: G,E - TLS Pre- Master Secret: G,E - TLS Derived Secret: G,R - HKDF Derived Key: G,R
Symmetric Key GenerationGenerate a keyGNUTLS_FIPS140_OP_APPROVEDN/AModule generated AES key, Module generated HMAC keySymmetric Key Generation with Counter DRBGCrypto Officer - Module- generated AES Key: G,R - Module- generated HMAC Key: G,R
DH Shared Secret ComputationCompute a shared secretGNUTLS_FIPS140_OP_APPROVEDDH Public Key, DH Private KeyShared secretKAS-FFC-SSCCrypto Officer - DH Public Key: W,E - DH Private Key: W,E - Shared Secret: G,R

G,E G,E G,E G,R G,R Table 14: Approved Services The following convention is used to specify access rights to SSPs: • Generate (G): The module generates or derives the SSP. Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 26
NameDescriptionAlgorithmsRole
Symmetric Key GenerationGenerate symmetric key other than AES and HMAC keysDRBG generation of keys smaller than 112 bitsCO
Symmetric Encryption/DecryptionCompute the cipher for encryption and decryptionBlowfish Camellia CAST ChaCha20 DES GOST RC2, RC4 Salsa20 SEED Serpent Triple-DES TwofishCO
Asymmetric Key GenerationGenerate RSA, DSA, and ECDSA key pairsDSA ECDSA with curves not listed in the Approved Algorithms Table RSA with keys smaller than 2048 bits.CO
Digital Signature GenerationSign RSA, DSA, and ECDSA signaturesDSA ECDSA with curves/hash functions not listed in the Approved Algorithms Table RSA with keys smaller than 2048 bits and/or hash functions not listed in the Approved Algorithms TableCO
Digital Signature VerificationVerify RSA, DSA, and ECDSA signaturesDSA ECDSA with curves/hash functions not listed in the Approved Algorithms Table RSA with keys smaller than 2048 bits and/or hash functions not listed in the Approved Algorithms TableCO
Message DigestCompute message digestMD2, MD4, MD5 RMD160 STREEBOGCO
Message Authentication Code (MAC)Compute MACCMAC with Triple-DES GMAC with keys not listed in the Approved Algorithms Table HMAC with keys smaller than 112-bit HMAC with GOST UMACCO
Key Encapsulation/Un- encapsulationPerform RSA key encapsulation/un-encapsulationRSA encryption and decryption with any key sizesCO
Key DerivationPerform key derivationPBKDF with non-approved message digest algorithms or using input parameters not meeting requirements stated in section 2.7CO
Transport Layer Security (TLS) network protocolProvide non-supported cipher suitesNon-supported cipher suites (see Appendix A for the complete list of valid cipher suites)CO
Random Number GenerationGenerate random numbersYarrow DRBG generation of keys smaller than 112 bitsCO
Key AgreementPerform key agreementSRPCO
Page 27
NameDescriptionAlgorithmsRole
Authenticated Encryption/DecryptionPerform authenticated encryption or decryptionChacha20 and Poly1305 AES GCM with keys not listed in the Approved Algorithms TableCO
Shared Secret ComputationPerform shared secret computationDiffie-Hellman using keys generated with domain parameters other than safe primes EC Diffie-Hellman with curves not listed in the Approved Algorithms TableCO
Public Key VerificationVerify ECDSA public keysECDSA with curves not listed in the Approved Algorithms TableCO

Table 15: Non-Approved Services

4.5 External Software/Firmware Loaded

The module does not load external software or firmware. Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 28
5 Software/Firmware Security
5.1 Integrity Techniques

The integrity of the module is verified by comparing an HMAC-SHA2-256 value calculated at run time with the HMAC value stored in the .hmac file that was computed at build time for the software components of the module listed in section 2. If the HMAC values do not match, the test fails, and the module enters the error state.

5.2 Initiate on Demand

The module provides the Self-Test service to perform self-tests on demand which includes the pre-operational test (i.e., integrity test) and the cryptographic algorithm self-tests (CASTs). The Self-Tests service can be called on demand by invoking the gnutls_fips140_run_self_tests() function which will perform integrity tests and the cryptographic algorithms self-tests. Additionally, the Self-Test service can be invoked by powering-off and reloading the module. During the execution of the on-demand self-tests, services are not available, and no data output is possible. Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 29
6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Modifiable How Requirements are Satisfied: The operating system provides process isolation and memory protection mechanisms that ensure appropriate separation for memory access among the processes on the system. Each process has control over its own data and uncontrolled access to the data of other processes is prevented.

6.2 Configuration Settings and Restrictions

The module shall be installed as stated in Section 11.1. There are no concurrent operators. The module does not have the capability of loading software or firmware from an external source. Instrumentation tools like the ptrace system call, gdb and strace, userspace live patching, as well as other tracing mechanisms offered by the Linux environment such as ftrace or systemtap, shall not be used in the operational environment. The use of any of these tools implies that the cryptographic module is running in a non-validated operational environment. Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 30
7 Physical Security

The module is comprised of software only and therefore this section is not applicable. Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 31
8 Non-Invasive Security

This module does not implement any non-invasive security mechanism and therefore this section is not applicable. Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 32
Storage Area NameDescriptionPersistence Type
RAMTemporary storage for SSPs used by the module as part of service execution. The module does not perform persistent storage of SSPs.Dynamic

Name API input parameters API output parameters

From Operating calling application (TOEPP) Cryptographic module

To Cryptographic module Operator calling application (TOEPP)

Format Type Plaintext Plaintext

Distribution Type Manual Manual

Entry Type Electronic Electronic

SFI or Algorithm

Zeroization MethodDescriptionRationaleOperator Initiation
Free Cipher HandleZeroizes the SSPs referenced. In the function nameMemory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable.By calling the appropriate zeroization functions: AES Key: gnutls_cipher_deinit(); AES Key: gnutls_aead_cipher_deinit(); HMAC Key: gnutls_hmac_deinit(); RSA Public and Private Keys: gnutls_privkey_deinit(), gnutls_x509_privkey_deinit(), gnutls_rsa_params_deinit(); ECDSA Public and Private Keys: gnutls_privkey_deinit(), gnutls_x509_privkey_deinit(), gnutls_rsa_params_deinit(); Diffie-Hellman Public and Private Keys: gnutls_dh_params_deinit(); TLS Pre-master Secret: gnutls_deinit(); TLS Master Secret: gnutls_deinit(); TLS Derived Secret: gnutls_deinit(); Diffie-Hellman Public and Private Keys: gnutls_pk_params_clear(); EC Diffie-Hellman Public and Private Keys: gnutls_pk_params_clear(); Diffie-Hellman Shared Secret: zeroize key(); EC Diffie-Hellman Shared Secret: zeroize key(); All SSPs: gnutls_global_deinit()
Module ResetDe-allocates the volatile memory used to store SSPsMemory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievableBy unloading and reloading the module.
AutomaticAutomatically zeroized by the module when no longer neededAutomatically zeroized by the module when no longer neededN/A
9 Sensitive Security Parameters Management
9.1 Storage Areas

Table 16: Storage Areas Table 17: SSP Input-Output Methods API output parameters in the plaintext form within the physical perimeter of the operational environment. This is allowed by [FIPS140-3_IG] IG 9.5.A. Table 18: SSP Zeroization Methods All data output is inhibited during zeroization. Once the zeroization is started, all data output via the data output interface is inhibited until the zeroization is completed successfully. Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 33

Name Module- generated AES Key AES Key Module- generated HMAC Key HMAC Key Shared Secret Password PBKDF Derived Key Entropy Input DRBG Seed Internal State (V, Key) DH Public Key DH Private Key Module Generated DH Public Key Module Generated DH Private Key EC Private Key

Description AES key generated during Symmetric Key Generation AES key used for encryption, decryption, authenticated encryption, authenticated decryption and computing MAC tags HMAC key generated during Symmetric Key Generation HMAC Key Shared secret generated by DH/ECDH PBKDF password PBKDF2 derived key Entropy input used to seed the DRBGs DRBG seed derived from entropy input as defined in SP 800-90Ar1 Internal state of CTR_DRBG Public key used for DH Private key used for DH DH public key generated by the module DH private key generated by the module Private key used for ECDSA signature generation and Shared Secret Computation

Size - Strength 128, 192, 256 bits - 128, 192, 256 bits 128, 192, 256 bits - 128, 192, 256 bits HMAC key generated during Symmetric Key Generation - 112- 256 bits 112-524288 bits - 112-256 bits 224-8192 bits - 112-256 bits 112-256 bits - N/A 112-4096 bits - 112-256 bits 128-448 bits - 128-256 bits 128, 192, 256 bits - 128-256 bits 128, 192, 256 bits - 128-256 bits 2048, 3072, 4096, 6144, 8192 bits - 112-200 bits 2048, 3072, 4096, 6144, 8192 bits - 112-200 bits 2048, 3072, 4096, 6144, 8192 bits - 112-200 bits 2048, 3072, 4096, 6144, 8192 bits - 112-200 bits P-224, P-256, P- 384, P-521 - 128- 256 bits

Type - Category Symmetric key - CSP Symmetric key - CSP Authentication key - CSP Authentication key - CSP Shared secret - CSP Password - CSP Derived Key - CSP Entropy - CSP SEED - CSP DRBG Internal state - CSP Public key - PSP Private key - CSP Public key - PSP Private key - CSP Private key - CSP

Generated By Symmetric Key Generation with Counter DRBG Symmetric Key Generation with Counter DRBG Password-based Key Derivation Counter DRBG Counter DRBG Safe Primes Key Generation Safe Primes Key Generation

Established By KAS-ECC-SSC KAS-FFC-SSC

Used By AES CCM (Key Wrapping/Unwrapping) AES CBC with HMAC AES GCM (Key Wrapping/Unwrapping) AES-CBC AES-CMAC AES-CFB8 AES-XTS AES-GMAC AES CCM (Authenticated Encryption/Decryption) AES GCM (Authenticated Encryption/Decryption) HMAC HKDF Key Derivation TLS 1.2 Key Derivation KDA HKDF Sp800-56Cr1 (A4750) Password-based Key Derivation Counter DRBG Counter DRBG Counter DRBG KAS-FFC-SSC KAS-FFC-SSC TLS Handshake TLS Handshake KAS-ECC-SSC

9.4 SSPs

Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 34

Name EC Public Key Module Generated EC Private Key Module Generated EC Public Key RSA Private Key RSA Public Key Module Generated RSA Private Key Module Generated RSA Public Key TLS Pre-Master Secret TLS Master Secret TLS Derived Secret Intermediate Key Generation Value HKDF Derived Key

Description Public key used for ECDSA signature verification primitive and Shared Secret Computation EC private key generated by the module EC public key generated by the module Private key used for RSA signature generation Public key used for RSA signature verification RSA private key generated by the module RSA public key generated by the module TLS pre-master secret used for deriving the TLS master secret TLS master secret used for deriving the TLS derived secret TLS derived secret, derived from TLS master secret Intermediate key generation value HKDF derived key

Size - Strength P-224, P-256, P- 384, P-521 - 128- 256 bits P-224, P-256, P- 384, P-521 - 128- 256 bits P-224, P-256, P- 384, P-521 - 128- 256 bits 2048, 3072, 4096 bits - 112, 128, 150 bits 1024, 2048, 3072, 4096 bits - 80, 112, 128, 150 bits 2048, 3072, 4096 bits - 112, 128, 150 bits 2048, 3072, 4096 bits - 112, 128, 150 bits 112-256 bits - N/A 112-256 bits - N/A 112-256 bits - 112-256 bits 224-4096 bits - 112-256 bits 112-256 - 112-256 bits

Type - Category Public key - PSP Private key - CSP Public key - PSP Private key - CSP Public key - PSP Private key - CSP Public key - PSP TLS Pre-master secret - CSP TLS Master secret - CSP Symmetric key - CSP Intermediate value - CSP Derived key - CSP

Generated By ECDSA Key Generation ECDSA Key Generation RSA Key Generation RSA Key Generation TLS 1.2 Key Derivation TLS 1.2 Key Derivation ECDSA Key Generation RSA Key Generation Safe Primes Key Generation KDA HKDF Sp800-56Cr1 (A4750)

Established By KAS-ECC-SSC KAS-FFC-SSC

Used By KAS-ECC-SSC TLS Handshake TLS Handshake RSA Signature Generation RSA Signature Verification TLS Handshake TLS Handshake TLS Handshake ECDSA Key Generation RSA Key Generation Safe Primes Key Generation

NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
Module-generated AES KeyAPI output parametersRAM:PlaintextFor the duration of the serviceFree Cipher Handle Module ResetInternal State (V, Key):Generated from
AES KeyAPI input parametersRAM:PlaintextFor the duration of the serviceFree Cipher Handle Module Reset
Module-generated HMAC KeyAPI output parametersRAM:PlaintextFor the duration of the serviceFree Cipher Handle Module ResetInternal State (V, Key):Generated from
HMAC KeyAPI input parametersRAM:PlaintextFor the duration of the serviceFree Cipher Handle Module Reset

Table 19: SSP Table 1 Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 35
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
Shared SecretAPI output parametersRAM:PlaintextFor the duration of the serviceFree Cipher Handle Module ResetDH Public Key:Used With DH Private Key:Used With EC Private Key:Used With EC Public Key:Used With
PasswordAPI input parametersRAM:PlaintextFor the duration of the serviceFree Cipher Handle Module ResetPBKDF Derived Key:Derivation of
PBKDF Derived KeyAPI output parametersRAM:PlaintextFor the duration of the serviceFree Cipher Handle Module ResetPassword:Derived From
Entropy InputRAM:PlaintextFrom generation until DRBG seed is createdAutomaticDRBG Seed:Generation of
DRBG SeedRAM:PlaintextWhile the DRBG is being instantiatedAutomaticEntropy Input:Derived From Internal State (V, Key):Generation of
Internal State (V, Key)RAM:PlaintextFrom DRBG instantiation until DRBG terminationAutomaticDRBG Seed:Generated From Module-generated AES Key:Generation Of Module-generated HMAC Key:Generation Of
DH Public KeyAPI input parametersRAM:PlaintextFor the duration of the serviceFree Cipher Handle Module ResetDH Private Key:Paired With Shared Secret:Generation Of
DH Private KeyAPI input parametersRAM:PlaintextFor the duration of the serviceFree Cipher Handle Module ResetDH Public Key:Paired With Shared Secret:Generation Of
Module Generated DH Public KeyAPI output parametersRAM:PlaintextFor the duration of the serviceFree Cipher Handle Module ResetModule Generated DH Private Key:Paired With Intermediate Key Generation Value:Generated From
Module Generated DH Private KeyAPI output parametersRAM:PlaintextFor the duration of the serviceFree Cipher Handle Module ResetModule Generated DH Public Key:Paired With Intermediate Key Generation Value:Generated From
EC Private KeyAPI input parametersRAM:PlaintextFor the duration of the serviceFree Cipher Handle Module ResetEC Public Key:Paired With Shared Secret:Generation Of
EC Public KeyAPI input parametersRAM:PlaintextFor the duration of the serviceFree Cipher Handle Module ResetEC Private Key:Paired With Shared Secret:Generation Of
Module Generated EC Private KeyAPI output parametersRAM:PlaintextFor the duration of the serviceFree Cipher Handle Module ResetModule Generated EC Public Key:Paired With Intermediate Key Generation Value:Generated From
Module Generated EC Public KeyAPI output parametersRAM:PlaintextFor the duration of the serviceFree Cipher Handle Module ResetModule Generated EC Private Key:Paired With Intermediate Key Generation Value:Generated From
RSA Private KeyAPI input parametersRAM:PlaintextFor the duration of the serviceFree Cipher Handle Module ResetRSA Public Key:Paired With
RSA Public KeyAPI input parametersRAM:PlaintextFor the duration of the serviceFree Cipher Handle Module ResetRSA Private Key:Paired With
Module Generated RSA Private KeyAPI output parametersRAM:PlaintextFor the duration of the serviceFree Cipher Handle Module ResetModule Generated RSA Public Key:Paired With

Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 36
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
Module Generated RSA Public KeyAPI output parametersRAM:PlaintextFor the duration of the serviceFree Cipher Handle Module ResetModule Generated RSA Private Key:Paired With
TLS Pre-Master SecretRAM:PlaintextFor the duration of the serviceFree Cipher Handle Module ResetTLS Master Secret:Generation Of DH Public Key:Used With DH Private Key:Used With EC Private Key:Used With EC Public Key:Used With
TLS Master SecretRAM:PlaintextFor the duration of the serviceFree Cipher Handle Module ResetTLS Pre-Master Secret:Derived From TLS Derived Secret:Derivation Of
TLS Derived SecretAPI output parametersRAM:PlaintextFor the duration of the serviceFree Cipher Handle Module ResetTLS Master Secret:Derived From
Intermediate Key Generation ValueRAM:PlaintextFor the duration of the serviceAutomaticModule Generated DH Public Key:Generation Of Module Generated DH Private Key:Generation Of Module Generated EC Private Key:Generation Of Module Generated EC Public Key:Generation Of Module Generated RSA Private Key:Generation Of Module Generated RSA Public Key:Generation Of
HKDF Derived KeyAPI output parametersRAM:PlaintextFor the duration of the serviceFree Cipher HandleShared Secret:Derived From
9.5 Transitions

The SHA-1 algorithm as implemented by the module will be non-approved for all purposes, starting January 1, 2031. The RSA, ECDSA algorithm as implemented by the module conforms to FIPS 186-4, which has been superseded by FIPS 186-5. FIPS 186-4 will be withdrawn on February 3, 2024. Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 37
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
HMAC-SHA2-256 (A4746)256-bit keyMessage AuthenticationSW/FW IntegrityModule becomes operational and services are available for useIntegrity test for libgnutls.so.30, libnettle.so.8, libhogweed.so.6, libgmp.so.10
HMAC-SHA2-256 (A4751)256-bit keyMessage AuthenticationSW/FW IntegrityModule becomes operational and services are available for useIntegrity test for libgnutls.so.30, libnettle.so.8, libhogweed.so.6, libgmp.so.10
HMAC-SHA2-256 (A4755)256-bit keyMessage AuthenticationSW/FW IntegrityModule becomes operational and services are available for useIntegrity test for libgnutls.so.30, libnettle.so.8, libhogweed.so.6, libgmp.so.10
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
ECDSA KeyGen (FIPS186-4) (A4751)SHA2-256Signature generation and Signature verificationPCTSuccessful key generationSignature generation and verificationKey pair generation
RSA KeyGen (FIPS186-4) (A4751)SHA2-256Signature generation and Signature verificationPCTSuccessful key generationSignature generation and verificationKey pair generation
Safe Primes Key Generation (A4751)N/ADiffie-Hellman key generationPCTSuccessful key generationPCT according to section 5.6.2.1.4 of [SP800-56Ar3]Key pair generation
SHA3-224 (A4747)SHA3-224KAT SHA3-224CASTModule is operational and services are available for useMessage DigestModule initialization
SHA3-224 (A4753)SHA3-224KAT SHA3-224CASTModule is operational and services are available for useMessage DigestModule initialization
AES-CBC (A4743)256-bit keysEncrypt/Decrypt KAT for CBCCASTModule is operational and services are available for useEncryption/DecryptionModule initialization
AES-CBC (A4744)256-bit keysEncrypt/Decrypt KAT for CBCCASTModule is operational and services are available for useEncryption/DecryptionModule initialization
AES-CBC (A4745)256-bit keysEncrypt/Decrypt KAT for CBCCASTModule is operational and services are available for useEncryption/DecryptionModule initialization
10 Self-Tests
10.1 Pre-Operational Self-Tests

Table 21: Pre-Operational Self-Tests The pre-operational software integrity test is performed automatically (after the CASTs) when the module is powered on, before the module transitions into the operational state. While the module is executing the self-tests, services are not available, and data output (via the data output interface) is inhibited until the tests are successfully completed. The module transitions to the operational state only after the pre-operational self-test has passed successfully. If the pre-operational self-test fails, the module transitions to the error state.

10.2 Conditional Self-Tests

Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 38
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-CBC (A4746)256-bit keysEncrypt/Decrypt KAT for CBCCASTModule is operational and services are available for useEncryption/DecryptionModule initialization
AES-CBC (A4751)256-bit keysEncrypt/Decrypt KAT for CBCCASTModule is operational and services are available for useEncryption/DecryptionModule initialization
AES-CBC (A4755)256-bit keysEncrypt/Decrypt KAT for CBCCASTModule is operational and services are available for useEncryption/DecryptionModule initialization
AES-CFB8 (A4748)256-bit keysEncrypt/Decrypt KAT for CFB8CASTModule is operational and services are available for useEncryption/DecryptionModule initialization
AES-CFB8 (A4749)256-bit keysEncrypt/Decrypt KAT for CFB8CASTModule is operational and services are available for useEncryption/DecryptionModule initialization
AES-CFB8 (A4754)256-bit keysEncrypt/Decrypt KAT for CFB8CASTModule is operational and services are available for useEncryption/DecryptionModule initialization
AES-GCM (A4743)256-bit keysEncrypt/Decrypt KAT for GCMCASTModule is operational and services are available for useEncryption/DecryptionModule initialization
AES-GCM (A4744)256-bit keysEncrypt/Decrypt KAT for GCMCASTModule is operational and services are available for useEncryption/DecryptionModule initialization
AES-GCM (A4745)256-bit keysEncrypt/Decrypt KAT for GCMCASTModule is operational and services are available for useEncryption/DecryptionModule initialization
AES-GCM (A4746)256-bit keysEncrypt/Decrypt KAT for GCMCASTModule is operational and services are available for useEncryption/DecryptionModule initialization
AES-GCM (A4751)256-bit keysEncrypt/Decrypt KAT for GCMCASTModule is operational and services are available for useEncryption/DecryptionModule initialization
AES-GCM (A4755)256-bit keysEncrypt/Decrypt KAT for GCMCASTModule is operational and services are available for useEncryption/DecryptionModule initialization
AES-XTS Testing Revision 2.0 (A4752)256-bit keysEncrypt/Decrypt KAT for XTSCASTModule is operational and services are available for useEncryption/DecryptionModule initialization
KDA HKDF Sp800-56Cr1 (A4750)HMAC-SHA2- 256KAT with HMAC-SHA2-256 for HKDFCASTModule is operational and services are available for useKey DerivationModule initialization
TLS v1.2 KDF RFC7627 (A4751)HMAC-SHA2- 256KAT with HMAC-SHA2-256 for TLS 1.2 KDFCASTModule is operational andKey DerivationModule initialization

Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 39
Algorithm or TestTest PropertiesTest MethodTest TypeIndicator services are available for useDetailsConditions
PBKDF (A4751)HMAC-SHA2- 256KAT with HMAC-SHA2-256 for PBKDFCASTModule is operational and services are available for useKey DerivationModule initialization
Counter DRBG (A4751)256-bit key; Health testsCTR_DRBG with AES without DF, without PR KAT; SP800- 90Ar1 Section 11.3 Health TestCASTModule is operational and services are available for useKAT CTR_DRBG with AES with 256-bit keys without DF, without PR; Health testsModule initialization
KAS-FFC-SSC Sp800-56Ar3 (A4751)3072-bit keyPrimitive "Z" computation KATCASTModule is operational and services are available for useShared Secret ComputationModule initialization
KAS-ECC-SSC Sp800-56Ar3 (A4751)Curve P-256Primitive "Z" computation KATCASTModule is operational and services are available for useShared Secret ComputationModule initialization
ECDSA SigGen (FIPS186-4) (A4751)Curve P-256 and SHA2-256KAT ECDSA with P-256 using SHA2-256CASTModule is operational and services are available for useSignature GenerationModule initialization
ECDSA SigVer (FIPS186-4) (A4751)Curve P-256 and SHA2-256KAT ECDSA with P-256 using SHA2-256CASTModule is operational and services are available for useSignature VerificationModule initialization
HMAC-SHA-1 (A4746)128-bit keyHMAC KAT with 128-bit keyCASTModule is operational and services are available for useMACModule initialization
HMAC-SHA-1 (A4751)128-bit keyHMAC KAT with 128-bit keyCASTModule is operational and services are available for useMACModule initialization
HMAC-SHA-1 (A4755)128-bit keyHMAC KAT with 128-bit keyCASTModule is operational and services are available for useMACModule initialization
RSA SigGen (FIPS186-4) (A4751)SHA2-256RSA KAT with PKCS#1 v1.5 with SHA-256 and 2048-bit keyCASTModule is operational and services are available for useSignature generationModule initialization
RSA SigVer (FIPS186-4) (A4751)SHA2-256RSA KAT with PKCS#1 v1.5 with SHA-256 and 2048-bit keyCASTModule is operational and services are available for useSignature verificationModule initialization
HMAC-SHA2-224 (A4746)160-bit keyHMAC KAT with 160-bit keyCASTModule is operational and services are available for useMACModule initialization
HMAC-SHA2-224 (A4751)160-bit keyHMAC KAT with 160-bit keyCASTModule is operational and services are available for useMACModule initialization
HMAC-SHA2-224 (A4755)160-bit keyHMAC KAT with 160-bit keyCASTModule is operational and services are available for useMACModule initialization

Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 40
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
HMAC-SHA2-256 (A4746)160-bit keyHMAC KAT with 160-bit keyCASTModule is operational and services are available for useMACModule initialization
HMAC-SHA2-256 (A4751)160-bit keyHMAC KAT with 160-bit keyCASTModule is operational and services are available for useMACModule initialization
HMAC-SHA2-256 (A4755)160-bit keyHMAC KAT with 160-bit keyCASTModule is operational and services are available for useMACModule initialization
HMAC-SHA2-384 (A4746)160-bit keyHMAC KAT with 160-bit keyCASTModule is operational and services are available for useMACModule initialization
HMAC-SHA2-384 (A4751)160-bit keyHMAC KAT with 160-bit keyCASTModule is operational and services are available for useMACModule initialization
HMAC-SHA2-384 (A4755)160-bit keyHMAC KAT with 160-bit keyCASTModule is operational and services are available for useMACModule initialization
HMAC-SHA2-512 (A4746)160-bit keyHMAC KAT with 160-bit keyCASTModule is operational and services are available for useMACModule initialization
HMAC-SHA2-512 (A4751)160-bit keyHMAC KAT with 160-bit keyCASTModule is operational and services are available for useMACModule initialization
HMAC-SHA2-512 (A4755)160-bit keyHMAC KAT with 160-bit keyCASTModule is operational and services are available for useMACModule initialization
SHA3-256 (A4747)SHA3-256KAT SHA3-256CASTModule is operational and services are available for useMessage DigestModule initialization
SHA3-256 (A4753)SHA3-256KAT SHA3-256CASTModule is operational and services are available for useMessage DigestModule initialization
SHA3-384 (A4747)SHA3-384KAT SHA3-384CASTModule is operational and services are available for useMessage DigestModule initialization
SHA3-384 (A4753)SHA3-384KAT SHA3-384CASTModule is operational and services are available for useMessage DigestModule initialization
SHA3-512 (A4747)SHA3-512KAT SHA3-512CASTModule is operational and services are available for useMessage DigestModule initialization
SHA3-512 (A4753)SHA3-512KAT SHA3-512CASTModule is operational andMessage DigestModule initialization

Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 41

Algorithm or Test

Test Properties

Test Method

Test Type

Indicator services are available for use

Details

Conditions

Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2-256 (A4746)Message AuthenticationSW/FW IntegrityOn demandManually
HMAC-SHA2-256 (A4751)Message AuthenticationSW/FW IntegrityOn demandManually
HMAC-SHA2-256 (A4755)Message AuthenticationSW/FW IntegrityOn demandManually
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
ECDSA KeyGen (FIPS186-4) (A4751)Signature generation and Signature verificationPCTOn demandManually
RSA KeyGen (FIPS186-4) (A4751)Signature generation and Signature verificationPCTOn demandManually
Safe Primes Key Generation (A4751)Diffie-Hellman key generationPCTOn demandManually
SHA3-224 (A4747)KAT SHA3-224CASTOn demandManually
SHA3-224 (A4753)KAT SHA3-224CASTOn demandManually
AES-CBC (A4743)Encrypt/Decrypt KAT for CBCCASTOn demandManually
AES-CBC (A4744)Encrypt/Decrypt KAT for CBCCASTOn demandManually
AES-CBC (A4745)Encrypt/Decrypt KAT for CBCCASTOn demandManually
AES-CBC (A4746)Encrypt/Decrypt KAT for CBCCASTOn demandManually
AES-CBC (A4751)Encrypt/Decrypt KAT for CBCCASTOn demandManually
AES-CBC (A4755)Encrypt/Decrypt KAT for CBCCASTOn demandManually
AES-CFB8 (A4748)Encrypt/Decrypt KAT for CFB8CASTOn demandManually
AES-CFB8 (A4749)Encrypt/Decrypt KAT for CFB8CASTOn demandManually
AES-CFB8 (A4754)Encrypt/Decrypt KAT for CFB8CASTOn demandManually
AES-GCM (A4743)Encrypt/Decrypt KAT for GCMCASTOn demandManually
AES-GCM (A4744)Encrypt/Decrypt KAT for GCMCASTOn demandManually
AES-GCM (A4745)Encrypt/Decrypt KAT for GCMCASTOn demandManually
AES-GCM (A4746)Encrypt/Decrypt KAT for GCMCASTOn demandManually
AES-GCM (A4751)Encrypt/Decrypt KAT for GCMCASTOn demandManually

Table 22: Conditional Self-Tests If any conditional self-test fails, the module transitions to the error state.

10.3 Periodic Self-Test Information

Table 23: Pre-Operational Periodic Information Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 42
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-GCM (A4755)Encrypt/Decrypt KAT for GCMCASTOn demandManually
AES-XTS Testing Revision 2.0 (A4752)Encrypt/Decrypt KAT for XTSCASTOn demandManually
KDA HKDF Sp800-56Cr1 (A4750)KAT with HMAC-SHA2-256 for HKDFCASTOn demandManually
TLS v1.2 KDF RFC7627 (A4751)KAT with HMAC-SHA2-256 for TLS 1.2 KDFCASTOn demandManually
PBKDF (A4751)KAT with HMAC-SHA2-256 for PBKDFCASTOn demandManually
Counter DRBG (A4751)CTR_DRBG with AES without DF, without PR KAT; SP800-90Ar1 Section 11.3 Health TestCASTOn demandManually
KAS-FFC-SSC Sp800-56Ar3 (A4751)Primitive "Z" computation KATCASTOn demandManually
KAS-ECC-SSC Sp800-56Ar3 (A4751)Primitive "Z" computation KATCASTOn demandManually
ECDSA SigGen (FIPS186-4) (A4751)KAT ECDSA with P-256 using SHA2-256CASTOn demandManually
ECDSA SigVer (FIPS186-4) (A4751)KAT ECDSA with P-256 using SHA2-256CASTOn demandManually
HMAC-SHA-1 (A4746)HMAC KAT with 128-bit keyCASTOn demandManually
HMAC-SHA-1 (A4751)HMAC KAT with 128-bit keyCASTOn demandManually
HMAC-SHA-1 (A4755)HMAC KAT with 128-bit keyCASTOn demandManually
RSA SigGen (FIPS186-4) (A4751)RSA KAT with PKCS#1 v1.5 with SHA-256 and 2048-bit keyCASTOn demandManually
RSA SigVer (FIPS186-4) (A4751)RSA KAT with PKCS#1 v1.5 with SHA-256 and 2048-bit keyCASTOn demandManually
HMAC-SHA2-224 (A4746)HMAC KAT with 160-bit keyCASTOn demandManually
HMAC-SHA2-224 (A4751)HMAC KAT with 160-bit keyCASTOn demandManually
HMAC-SHA2-224 (A4755)HMAC KAT with 160-bit keyCASTOn demandManually
HMAC-SHA2-256 (A4746)HMAC KAT with 160-bit keyCASTOn demandManually
HMAC-SHA2-256 (A4751)HMAC KAT with 160-bit keyCASTOn demandManually
HMAC-SHA2-256 (A4755)HMAC KAT with 160-bit keyCASTOn demandManually
HMAC-SHA2-384 (A4746)HMAC KAT with 160-bit keyCASTOn demandManually
HMAC-SHA2-384 (A4751)HMAC KAT with 160-bit keyCASTOn demandManually
HMAC-SHA2-384 (A4755)HMAC KAT with 160-bit keyCASTOn demandManually
HMAC-SHA2-512 (A4746)HMAC KAT with 160-bit keyCASTOn demandManually
HMAC-SHA2-512 (A4751)HMAC KAT with 160-bit keyCASTOn demandManually
HMAC-SHA2-512 (A4755)HMAC KAT with 160-bit keyCASTOn demandManually
SHA3-256 (A4747)KAT SHA3-256CASTOn demandManually
SHA3-256 (A4753)KAT SHA3-256CASTOn demandManually
SHA3-384 (A4747)KAT SHA3-384CASTOn demandManually
SHA3-384 (A4753)KAT SHA3-384CASTOn demandManually
SHA3-512 (A4747)KAT SHA3-512CASTOn demandManually
SHA3-512 (A4753)KAT SHA3-512CASTOn demandManually

Table 24: Conditional Periodic Information Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 43
NameDescriptionConditionsRecovery MethodIndicator
ErrorThe module stops functioning and ends the Application processWhen the Pre- Operational Self- Test or a CAST fails When a PCT fails Crypto operations requested in the Error stateThe module must be restarted and successfully perform the pre-operational self-test and the CASTs to recover from these errors.GNUTLS_E_SELF_TEST_ERROR (-400); GNUTLS_E_RANDOM_FAILED (-206); GNUTLS_E_PK_GENERATION_ERROR (-403); GNUTLS_E_LIB_IN_ERROR_STATE (-402)
10.4 Error States

Table 25: Error States In the error state, the data output interface is inhibited, and the module accepts no more inputs or requests (as the module is no longer running). The calling application can obtain the module state by calling the gnutls_fips140_get_operation_state() API function.

10.5 Operator Initiation of Self-Tests

The module provides the Self-Test service to perform self-tests on demand which includes the pre-operational test (i.e., integrity test) and CASTs. The Self-Tests service can be called on demand by invoking the gnutls_fips140_run_self_tests() function which will perform integrity tests and the cryptographic algorithms selftests. Additionally, the Self-Test service can be invoked by powering-off and reloading the module. During the execution of the on-demand self-tests, services are not available, and no data output is possible. The PCTs can be invoked on demand by requesting the Asymmetric Key Generation service. Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 44
11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

The module is distributed as a part of the Oracle Linux 9 (OL9) RPM in the form of gnutls-3.7.6-21.0.1.el9_2_fips, nettle-3.8-3.el9_0, gmp-6.2.0-10.el9 RPM packages that are in the “Oracle Linux 9 Security Validation (Update 3)” yum repository (ol9_u3_security_validation). Note: libhogweed is provided by nettle-3.8-3.el9_0. The Oracle Linux 9 system FIPS validated configuration can be achieved by:

11.2 Administrator Guidance

The Approved and non-Approved modes of operation are specified in section 2.4. The administrative functions are specified in the Approved Services table. All the logical interfaces are specified in section 3.1. The requirements and restrictions that shall be considered when operating the module in approved mode are specified in section 2.7 (for algorithm-specific information) and section 6 (for operational environment). The installation, initialization, and startup procedures specified in section 11.1 shall be followed.

11.3 Non-Administrator Guidance

The module does not have any guidance for non-administrator.

11.4 End of Life

As the module does not persistently store SSPs, secure sanitization of the module consists of unloading the module. This will zeroize all SSPs in volatile memory. Then, if desired, the gnutls-3.7.6-21.0.1.el9_2_fips, nettle-3.83.el9_0, gmp-6.2.0-10.el9 RPM packages can be uninstalled from the Oracle Linux 9 system. Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 45
12 Mitigation of Other Attacks

The module does not offer mitigation of other attacks. Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 46
Cipher SuiteIDReference
TLS_DH_RSA_WITH_AES_128_CBC_SHA{ 0x00, 0x31 }RFC3268
TLS_DHE_RSA_WITH_AES_128_CBC_SHA{ 0x00, 0x33 }RFC3268
TLS_DH_RSA_WITH_AES_256_CBC_SHA{ 0x00, 0x37 }RFC3268
TLS_DHE_RSA_WITH_AES_256_CBC_SHA{ 0x00, 0x39 }RFC3268
TLS_DH_RSA_WITH_AES_128_CBC_SHA256{ 0x00,0x3F }RFC5246
TLS_DHE_RSA_WITH_AES_128_CBC_SHA256{ 0x00,0x67 }RFC5246
TLS_DH_RSA_WITH_AES_256_CBC_SHA256{ 0x00,0x69 }RFC5246
TLS_DHE_RSA_WITH_AES_256_CBC_SHA256{ 0x00,0x6B }RFC5246
TLS_PSK_WITH_AES_128_CBC_SHA{ 0x00, 0x8C }RFC4279
TLS_PSK_WITH_AES_256_CBC_SHA{ 0x00, 0x8D }RFC4279
TLS_DHE_RSA_WITH_AES_128_GCM_SHA256{ 0x00, 0x9E }RFC5288
TLS_DHE_RSA_WITH_AES_256_GCM_SHA384{ 0x00, 0x9F }RFC5288
TLS_DH_RSA_WITH_AES_128_GCM_SHA256{ 0x00, 0xA0 }RFC5288
TLS_DH_RSA_WITH_AES_256_GCM_SHA384{ 0x00, 0xA1 }RFC5288
TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA{ 0xC0, 0x04 }RFC4492
TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA{ 0xC0, 0x05 }RFC4492
TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA{ 0xC0, 0x09 }RFC4492
TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA{ 0xC0, 0x0A }RFC4492
TLS_ECDH_RSA_WITH_AES_128_CBC_SHA{ 0xC0, 0x0E }RFC4492
TLS_ECDH_RSA_WITH_AES_256_CBC_SHA{ 0xC0, 0x0F }RFC4492
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA{ 0xC0, 0x13 }RFC4492
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA{ 0xC0, 0x14 }RFC4492
TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256{ 0xC0, 0x23 }RFC5289
TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384{ 0xC0, 0x24 }RFC5289
TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA256{ 0xC0, 0x25 }RFC5289
TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA384{ 0xC0, 0x26 }RFC5289
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256{ 0xC0, 0x27 }RFC5289
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384{ 0xC0, 0x28 }RFC5289
TLS_ECDH_RSA_WITH_AES_128_CBC_SHA256{ 0xC0, 0x29 }RFC5289
TLS_ECDH_RSA_WITH_AES_256_CBC_SHA384{ 0xC0, 0x2A }RFC5289

Appendix A. TLS Cipher Suites The module supports the following cipher suites for the TLS protocol version 1.2 and 1.3, compliant with section

3.3.1 of [SP800-52rev2]. Each cipher suite defines the key exchange algorithm, the bulk encryption algorithm

(including the symmetric key size) and the MAC algorithm. Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 47
Cipher SuiteIDReference
TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256{ 0xC0, 0x2B }RFC5289
TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384{ 0xC0, 0x2C }RFC5289
TLS_ECDH_ECDSA_WITH_AES_128_GCM_SHA256{ 0xC0, 0x2D }RFC5289
TLS_ECDH_ECDSA_WITH_AES_256_GCM_SHA384{ 0xC0, 0x2E }RFC5289
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256{ 0xC0, 0x2F }RFC5289
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384{ 0xC0, 0x30 }RFC5289
TLS_ECDH_RSA_WITH_AES_128_GCM_SHA256{ 0xC0, 0x31 }RFC5289
TLS_ECDH_RSA_WITH_AES_256_GCM_SHA384{ 0xC0, 0x32 }RFC5289
TLS_DHE_RSA_WITH_AES_128_CCM{ 0xC0, 0x9E }RFC6655
TLS_DHE_RSA_WITH_AES_256_CCM{ 0xC0, 0x9F }RFC6655
TLS_DHE_RSA_WITH_AES_128_CCM_8{ 0xC0, 0xA2 }RFC6655
TLS_DHE_RSA_WITH_AES_256_CCM_8{ 0xC0, 0xA3 }RFC6655
TLS_AES_128_GCM_SHA256{ 0x13, 0x01 }RFC8446
TLS_AES_256_GCM_SHA384{ 0x13, 0x02 }RFC8446
TLS_AES_128_CCM_SHA256{ 0x13, 0x04 }RFC8446
TLS_AES_128_CCM_8_SHA256{ 0x13, 0x05 }RFC8446

Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 48
AESAdvanced Encryption Standard
AES-NIAdvanced Encryption Standard New Instructions
APIApplication Programming Interface
CASTCryptographic Algorithm Self-Test
CAVPCryptographic Algorithm Validation Program
CBCCipher Block Chaining
CCMCounter with Cipher Block Chaining-Message Authentication Code
CFBCipher Feedback
CMACCipher-based Message Authentication Code
CMVPCryptographic Module Validation Program
CSPCritical Security Parameter
CTRCounter
DHDiffie-Hellman
DRBGDeterministic Random Bit Generator
ECBElectronic Code Book
ECCElliptic Curve Cryptography
ECDHElliptic Curve Diffie-Hellman
ECDSAElliptic Curve Digital Signature Algorithm
FFCFinite Field Cryptography
FIPSFederal Information Processing Standards
GCMGalois Counter Mode
GMACGalois Counter Mode Message Authentication Code
HKDFHMAC-based Key Derivation Function
HMACKeyed-Hash Message Authentication Code
KATKnown Answer Test
MACMessage Authentication Code
NISTNational Institute of Science and Technology
PAAProcessor Algorithm Acceleration
PBKDF2Password-based Key Derivation Function v2
PKCSPublic-Key Cryptography Standards
RSARivest, Shamir, Adleman
SHASecure Hash Algorithm
SSCShared Secret Computation
SSPSensitive Security Parameter
TOEPPTested Operational Environment’s Physical Perimeter
XTSXEX-based Tweaked-codebook mode with cipher text Stealing

Appendix B. Glossary and Abbreviations Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 49
FIPS 140-3FIPS PUB 140-3 - Security Requirements For Cryptographic Modules March 2019 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-3.pdf
FIPS 140-3 IGImplementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program https://csrc.nist.gov/Projects/cryptographic-module-validation-program/fips-140-3-ig- announcements
FIPS 180-4Secure Hash Standard (SHS) March 2012 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf
FIPS 186-4Digital Signature Standard (DSS) July 2013 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-4.pdf
FIPS 186-5Digital Signature Standard (DSS) February 2023 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-5.pdf
FIPS 197Advanced Encryption Standard November 2001 https://csrc.nist.gov/publications/fips/fips197/fips-197.pdf
FIPS 198-1The Keyed Hash Message Authentication Code (HMAC) July 2008 https://csrc.nist.gov/publications/fips/fips198-1/FIPS-198-1_final.pdf
FIPS 202SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions August 2015 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.202.pdf
PKCS#1Public Key Cryptography Standards (PKCS) #1: RSA Cryptography Specifications Version 2.1 February 2003 https://www.ietf.org/rfc/rfc3447.txt
RFC 3526More Modular Exponential (MODP) Diffie-Hellman groups for Internet Key Exchange (IKE) May 2003 https://www.ietf.org/rfc/rfc3526.txt
RFC 5288AES Galois Counter Mode (GCM) Cipher Suites for TLS August 2008 https://www.ietf.org/rfc/rfc5288.txt
RFC 7919Negotiated Finite Field Diffie-Hellman Ephemeral Parameters for Transport Layer Security (TLS) August 2016 https://www.ietf.org/rfc/rfc7919.txt
RFC 8446The Transport Layer Security (TLS) Protocol Version 1.3 August 2018 https://www.ietf.org/rfc/rfc8446.txt
SP 800-38ARecommendation for Block Cipher Modes of Operation Methods and Techniques December 2001 https://csrc.nist.gov/publications/nistpubs/800-38a/sp800-38a.pdf

Appendix C. References Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 50
SP 800-38BRecommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication May 2005 https://csrc.nist.gov/publications/nistpubs/800-38B/SP_800-38B.pdf
SP 800-38CRecommendation for Block Cipher Modes of Operation: the CCM Mode for Authentication and Confidentiality May 2004 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38c.pdf
SP 800-38DRecommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC November 2007 https://csrc.nist.gov/publications/nistpubs/800-38D/SP-800-38D.pdf
SP 800-38ERecommendation for Block Cipher Modes of Operation: The XTS AES Mode for Confidentiality on Storage Devices January 2010 https://csrc.nist.gov/publications/nistpubs/800-38E/nist-sp-800-38E.pdf
SP 800-52r2Guidelines for the Selection, Configuration, and Use of Transport Layer Security (TLS) Implementations August 2019 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-52r2.pdf
SP 800-56Ar3Recommendation for Pair-Wise Key Establishment Schemes Using Discrete Logarithm Cryptography April 2018 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Ar3.pdf
SP 800-56Cr1Recommendation for Key-Derivation Methods in Key-Establishment Schemes August 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Cr1.pdf
SP 800-56Cr2Recommendation for Key-Derivation Methods in Key-Establishment Schemes August 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Cr2.pdf
SP 800-90Ar1Recommendation for Random Number Generation Using Deterministic Random Bit Generators June 2015 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90Ar1.pdf
SP 800-90BRecommendation for the Entropy Sources Used for Random Bit Generation January 2018 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90B.pdf
SP 800-108r1NIST Special Publication 800-108 - Recommendation for Key Derivation Using Pseudorandom Functions August 2022 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-108r1.pdf
SP 800-132Recommendation for Password-Based Key Derivation - Part 1: Storage Applications December 2010 https://csrc.nist.gov/publications/nistpubs/800-132/nist-sp800-132.pdf
SP 800-133r2Recommendation for Cryptographic Key Generation June 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-133r2.pdf
SP 800-135r1Recommendation for Existing Application-Specific Key Derivation Functions December 2011 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-135r1.pdf

Oracle Linux 9 GnuTLS Cryptographic Module Security Policy

Page 51

SP 800-140B

CMVP Security Policy Requirements March 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-140B.pdf

Oracle Linux 9 GnuTLS Cryptographic Module Security Policy