All modules
CMVP Validated Module · FIPS 140-3 Security Policy

GnuTLS cryptography module for AlmaLinux 9

Certificate#5049StandardFIPS 140-3Level1TypeSoftwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorCloudlinux Inc., TuxCare division
Low review priority  ·  no TCB surface named  ·  GnuTLS upstream has published 9 CVEs since this module's initial validation  ·  last validated 12 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date7/27/2030
CaveatWhen operated in approved mode. When installed, initialized and configured as specified in Section 11 of the Security Policy.
VendorCloudlinux Inc., TuxCare division

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for GnuTLS cryptography module for AlmaLinux 9
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>update<br/>Recovery</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Show Status</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>IKEV<br/>HTTPS</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for GnuTLS cryptography module for AlmaLinux 9
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>update<br/>Recovery</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Show Status</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>IKEV<br/>HTTPS</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Cloudlinux Inc., TuxCare division GnuTLS cryptography module for AlmaLinux 9 Prepared by: atsec information security corporation

4516 Seton Center Pkwy, Suite 250

Austin, TX 78759 Document version: 1.0 www.atsec.com Last update: 2025-05-06

Page 2
Table of Contents
#SectionPage
Page 3

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 4
List of Tables
ItemPage
Table 1: Security Levels6
Table 2: Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets)9
Table 3: Tested Operational Environments - Software, Firmware, Hybrid10
Table 4: Modes List and Description10
Table 5: Approved Algorithms16
Table 6: Vendor-Affirmed Algorithms16
Table 7: Non-Approved, Not Allowed Algorithms18
Table 8: Security Function Implementations25
Table 9: Entropy Certificates27
Table 10: Entropy Sources27
Table 11: Ports and Interfaces30
Table 12: Roles31
Table 13: Approved Services43
Table 14: Non-Approved Services46
Table 15: Storage Areas51
Table 16: SSP Input-Output Methods51
Table 17: SSP Zeroization Methods52
Table 18: SSP Table 158
Table 19: SSP Table 262
Table 20: Pre-Operational Self-Tests63
Table 21: Conditional Self-Tests72
Table 22: Pre-Operational Periodic Information73
Table 23: Conditional Periodic Information76
Table 24: Error States77
Page 5
List of Figures
ItemPage
Figure 1: Block Diagram9
Page 6
SectionTitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication1
5Software/Firmware security1
6Operational environment1
7Physical securityN/A
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacks1
Overall Level1
1.1 Overview

This document is the non-proprietary FIPS 140-3 Security Policy for version 3.7.6-396796fe0a32b434 of GnuTLS cryptography module for AlmaLinux 9. It has a one-to-one mapping to the [SP 800-140Br1] starting with section B.2.1 named “General” that maps to section 1 in this document and ending with section B.2.12 named “Mitigation of other attacks” that maps to section 12 in this document. It contains the security rules under which the module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for an Overall Security Level 1

1.2 Security Levels

Table 1: Security Levels © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 7
1.3 Additional Information

This Security Policy describes the features and design of the module named GnuTLS cryptography module for AlmaLinux 9 using the terminology contained in the FIPS 140-3 specification. The FIPS 140-3 Security Requirements for Cryptographic Module specifies the security requirements that will be satisfied by a cryptographic module utilized within a security system protecting sensitive but unclassified information. The NIST/CCCS Cryptographic Module Validation Program (CMVP) validates cryptographic module to FIPS 140-3. Validated products are accepted by the Federal agencies of both the USA and Canada for the protection of sensitive or designated information. including this notice. Other documentation is proprietary to their authors. In preparing the Security Policy document, the laboratory formatted the vendor-supplied documentation for consolidation without altering the technical statements therein contained. The further refining of the Security Policy document was conducted iteratively throughout the conformance testing, wherein the Security Policy was submitted to the vendor, who would then edit, modify, and add technical contents. The vendor would also supply additional documentation, which the laboratory formatted into the existing Security Policy, and resubmitted to the vendor for their final editing. © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 8
2 Cryptographic Module Specification
2.1 Description

Purpose and Use: The GnuTLS cryptography module for AlmaLinux 9 (hereafter referred to as “the module”) is a software library. The module is an open-source, general-purpose set of libraries designed to support cross-platform development of security-enabled client and server applications. The module is a multiple-chip standalone cryptographic module. Module Type: Software Module Embodiment: MultiChipStand Module Characteristics [O]: Cryptographic Boundary: The block diagram in Figure 1 shows the cryptographic boundary of the module, its interfaces with the operational environment and the flow of information between the module and operator (depicted through the arrows). The module is implemented as a shared library. The cryptographic module boundary consists of the following components:

Page 9
Package or File NameSoftware/ Firmware VersionFeaturesIntegrity Test
/usr/lib64/libgnutls.so.30, /usr/lib64/libnettle.so.8, /usr/lib64/libhogweed.so.6, /usr/lib64/.libgnutls.so.30.hmac. Note: libgmp is statically linked to libgnutls3.7.6- 396796fe0a32b434N/AHMAC SHA2-256
2.2 Tested and Vendor Affirmed Module Version and Identification

The TOEPP is the general-purpose computer on which the module is installed. Tested Module Identification

Page 10
Operating SystemHardware PlatformProcessorsPAA/PAIHypervisor or Host OSVersion(s)
AlmaLinux 9.2Amazon Web Services (AWS) m5.metalIntel Xeon Platinum 8259CLYesN/A3.7.6- 396796fe0a32b434
AlmaLinux 9.2Amazon Web Services (AWS) m5.metalIntel Xeon Platinum 8259CLNoN/A3.7.6- 396796fe0a32b434
Mode NameDescriptionTypeStatus Indicator
Approved modeAutomatically entered when the module starts up successfully, after passing all the pre-operational and conditional cryptographic algorithms self-tests.ApprovedEquivalent to the indicator of the requested service.
Non- approved modeAutomatically entered whenever a non-approved service is requested.Non- ApprovedEquivalent to the indicator of the requested service.

Tested Module Identification – Hybrid Disjoint Hardware: N/A for this module. Tested Operational Environments - Software, Firmware, Hybrid: Table 3: Tested Operational Environments - Software, Firmware, Hybrid Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid: N/A for this module. CMVP makes no statement as to the correct operation of the module or the security strengths of the generated keys when so ported if the specific operational environment is not listed on the validation certificate.

2.3 Excluded Components

The module does not claim any excluded components.

2.4 Modes of Operation

Modes List and Description: Table 4: Modes List and Description © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 11
AlgorithmCAVP CertPropertiesReference
AES-CBCA5114Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBCA5115Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBCA5116Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBCA5117Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBCA5122Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CCMA5114Key Length - 128, 256SP 800-38C
AES-CFB8A5119Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB8A5120Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB8A5125Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A

When the module starts up successfully, after passing all the pre-operational and conditional cryptographic algorithms self-tests (CASTs), the module is operating in the approved mode of operation by default and can only be transitioned into the non-Approved mode by calling one of the non-Approved services listed in Table 15. Please see section 4 for the details on service indicator provided by the module that identifies when an approved service is called. Degraded Mode Description: The module does not implement a degraded mode of operation.

2.5 Algorithms

Approved Algorithms: © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 12
AlgorithmCAVP CertPropertiesReference
AES-CMACA5114Direction - Generation, Verification Key Length - 128, 256SP 800-38B
AES-CMACA5117Direction - Generation, Verification Key Length - 128, 256SP 800-38B
AES-CMACA5122Direction - Generation, Verification Key Length - 128, 256SP 800-38B
AES-ECBA5126Direction - Encrypt Key Length - 256SP 800-38A
AES-GCMA5114Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 256SP 800-38D
AES-GCMA5115Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 256SP 800-38D
AES-GCMA5116Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 256SP 800-38D
AES-GCMA5117Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 256SP 800-38D
AES-GCMA5122Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 256SP 800-38D
AES-GMACA5122Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 256SP 800-38D

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 13
AlgorithmCAVP CertPropertiesReference
AES-XTS Testing Revision 2.0A5123Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38E
Counter DRBGA5122Prediction Resistance - No Mode - AES-256 Derivation Function Enabled - NoSP 800-90A Rev. 1
ECDSA KeyGen (FIPS186-5)A5122Curve - P-256, P-384, P-521 Secret Generation Mode - testing candidatesFIPS 186-5
ECDSA KeyVer (FIPS186-5)A5122Curve - P-256, P-384, P-521FIPS 186-5
ECDSA SigGen (FIPS186-5)A5122Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2- 512 Component - NoFIPS 186-5
ECDSA SigVer (FIPS186-5)A5122Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2- 512FIPS 186-5
HMAC-SHA-1A5117Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA-1A5122Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 224A5117Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 224A5122Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 256A5117Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 256A5122Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 384A5117Key Length - Key Length: 112-524288 Increment 8FIPS 198-1

2.0 © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 14
AlgorithmCAVP CertPropertiesReference
HMAC-SHA2- 384A5122Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512A5117Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512A5122Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
KAS-ECC-SSC Sp800-56Ar3A5122Domain Parameter Generation Methods - P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KAS-FFC-SSC Sp800-56Ar3A5122Domain Parameter Generation Methods - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192 Scheme - dhEphem - KAS Role - initiator, responderSP 800-56A Rev. 3
KDA HKDF Sp800-56Cr1A5121Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-65336 Increment 8 HMAC Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2- 512SP 800-56C Rev. 2
PBKDFA5122Iteration Count - Iteration Count: 1000-10000 Increment 1 Password Length - Password Length: 8-128 Increment 1SP 800-132
RSA KeyGen (FIPS186-5)A5122Key Generation Mode - provable Hash Algorithm - SHA2-384 Modulo - 2048, 3072, 4096 Private Key Format - standardFIPS 186-5
RSA SigGen (FIPS186-5)A5122Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pssFIPS 186-5
RSA SigVer (FIPS186-5)A5122Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5, pssFIPS 186-5

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 15
AlgorithmCAVP CertPropertiesReference
Safe Primes Key GenerationA5122Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP- 4096, MODP-6144, MODP-8192SP 800-56A Rev. 3
SHA-1A5117Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA-1A5122Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-224A5117Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-224A5122Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-256A5117Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-256A5122Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-384A5117Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-384A5122Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512A5117Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA2-512A5122Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 180-4
SHA3-224A5118Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHA3-224A5124Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHA3-256A5118Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 16
AlgorithmCAVP CertPropertiesReference
SHA3-256A5124Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHA3-384A5118Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHA3-384A5124Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHA3-512A5118Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
SHA3-512A5124Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2, 4, 8FIPS 202
TLS v1.2 KDF RFC7627 (CVL)A5122Hash Algorithm - SHA2-256, SHA2-384SP 800-135 Rev. 1
NamePropertiesImplementationReference
Key Pair Generation with RSARSA:2048, 3072, 4096-bit keys with 112-149 bits key strengthGnuTLS cryptography module for AlmaLinux 9 (Generic C)SP 800- 133r2 section 5
Key Pair Generation with ECDSAECDSA:P-256, P-384, P-521 elliptic curves with 128-256 bits key strengthGnuTLS cryptography module for AlmaLinux 9 (Generic C)SP 800- 133r2 section 5
Key Pair Generation with Safe PrimesSafe Primes:ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP- 2048, MODP-3072, MODP-4096, MODP- 6144, MODP-8192 Keys:2048, 3072, 4096, 6144, 8192-bit keys with 112-200 bits key strengthGnuTLS cryptography module for AlmaLinux 9 (Generic C)SP 800- 133r2 section 5

Table 5: Approved Algorithms The above table lists all approved cryptographic algorithms of the module, including specific key lengths employed for approved services, and implemented modes or methods of operation of the algorithms. Vendor-Affirmed Algorithms: Table 6: Vendor-Affirmed Algorithms © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 17
NameUse and Function
BlowfishSymmetric encryption; Symmetric decryption
CamelliaSymmetric encryption; Symmetric decryption
CASTSymmetric encryption; Symmetric decryption
ChaCha20Symmetric encryption; Symmetric decryption
Chacha20, Poly1305 and AES-GCMAuthenticated encryption; Authenticated decryption
DESSymmetric encryption; Symmetric decryption
Diffie-Hellman with keys generated with domain parameters other than safe primesKey agreement; Shared secret computation
DRBG when key length is less than 112 bitsSymmetric key generation
DSAKey generation; Domain parameter generation; Digital signature generation; Digital signature verification
ECDSA with curves not listed in Table "Approved Algorithms"Key generation; Public key verification; Digital signature generation; Digital signature verificatio
EC Diffie-Hellman with curves not listed in Table "Approved Algorithms"Key agreement; Shared secret computation
GOSTSymmetric encryption; Symmetric decryption; Message digest
HMAC with keys smaller than 112-bitMessage authentication code (MAC)

Non-Approved, Allowed Algorithms: N/A for this module. The module does not implement non-approved algorithms that are allowed in the approved mode of operation. Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. The module does not implement any non-approved, allowed algorithm in the approved mode of operation with no security claimed. © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 18
NameUse and Function
HMAC with GOSTMessage authentication code (MAC)
MD2, MD4, MD5Message digest; Message authentication code (MAC)
Non-supported cipher suites (not listed in Appendix A)Transport Layer Security (TLS) Network Protocol
PBKDF with non-approved message digest algorithmsKey derivation
RC2, RC4Symmetric encryption; Symmetric decryption
RMD160Message digest; Message authentication code (MAC)
RSA with keys smaller than 2048 bits or greater than 4096 bits.Key generation; Digital signature generation
RSA with keys smaller than 1024 bits or greater than 4096 bits.Digital signature verification
RSA encryption and decryption with any key sizes.Key encapsulation; Key unencapsulation
Salsa20Symmetric encryption; Symmetric decryption
SM3Hashing
SerpentSymmetric encryption; Symmetric decryption
SHA-1Digital signature generation; Digital Signature Verification
STREEBOGMessage digest; Message authentication code (MAC)
Triple-DESSymmetric encryption; Symmetric decryption
TwofishSymmetric encryption; Symmetric decryption
UMACMessage authentication code (MAC)
YarrowRandom number generation

The above table lists non-Approved security functions that are not allowed in the approved mode of operation. © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 19
NameTypeDescriptionPropertiesAlgorithms
Symmetric Encryption with AESBC-UnAuthEncryption using AESAES-XTS mode keys:128, 256 bits with 128, 256 of key strength Other modes keys:128, 192, 256 bits with 128-256 of key strengthAES-CBC AES-CBC AES-CBC AES-CBC AES-CFB8 AES-CFB8 AES-CBC AES-CFB8 AES-XTS Testing Revision 2.0
Symmetric Decryption with AESBC-UnAuthDecryption using AESAES-XTS mode keys:128, 256 bits keys with 128, 256 of key strength Other modes keys:128, 192, 256 bits keys with 128- 256 of key strengthAES-CBC AES-CBC AES-CBC AES-CBC AES-CFB8 AES-CFB8 AES-CBC AES-CFB8 AES-XTS Testing Revision 2.0
Authenticated Symmetric Encryption with AESBC-AuthAuthenticated encryption using AESKeys:128, 256 bits with 128, 256 bits key strengthAES-CCM
Authenticated Symmetric Decryption with AESBC-AuthAuthenticated decryption using AESKeys:128, 256 bits with 128, 256 bits key strengthAES-CCM
Authenticated Symmetric Encryption (in the context of the TLS 1.2/1.3 protocol) with AES-GCMBC-AuthAuthenticated encryption using AES-GCM (as part of TLS protocol)Keys:128, 256 bits with 128, 256 bits key strengthAES-GCM AES-GCM AES-GCM AES-GCM AES-GCM
2.6 Security Function Implementations

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 20
NameTypeDescriptionPropertiesAlgorithms
Authenticated Symmetric Decryption (in the context of the TLS 1.2/1.3 protocol) with AES-GCMBC-AuthAuthenticated decryption using AES-GCM (as part of TLS protocol)Keys:128, 256 bits with 128, 256 bits key strengthAES-GCM AES-GCM AES-GCM AES-GCM AES-GCM
Message Digest with SHASHAMessage digest using SHASHA-1 SHA2-224 SHA2-384 SHA2-512 SHA3-224 SHA3-256 SHA3-384 SHA3-512 SHA-1 SHA2-224 SHA2-256 SHA2-384 SHA2-512 SHA3-224 SHA3-256 SHA3-384 SHA3-512 SHA2-256
Random Number Generation with CTR_DRBGDRBGRandom number generation using CTR_DRBGKeys:AES-256 bits with 256 bits key strength AES-256:without DF, without PRCounter DRBG AES-ECB
Message Authentication Code (MAC) with HMACMACMessage authentication generation using HMACHash Algorithm:SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512HMAC-SHA-1 HMAC-SHA2-224 HMAC-SHA2-256 HMAC-SHA2-384 HMAC-SHA2-512 HMAC-SHA-1 HMAC-SHA2-224 HMAC-SHA2-256 HMAC-SHA2-384 HMAC-SHA2-512

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 21
NameTypeDescriptionPropertiesAlgorithms
Message Authentication Code (MAC) with AESMACMessage authentication generation using AES CMAC/GMACKeys:128 or 256 bits with 128 or 256 bits of strengthAES-CMAC AES-CMAC AES-CMAC AES-GMAC
Key Pair Generation with RSACKGKey Generation using RSAKeys:2048, 3072, 4096 bits with 112- 149 bits of strength Hash Algorithm:SHA- 384RSA KeyGen (FIPS186-5)
Digital Signature Generation with RSADigSig-SigGenDigital signature generation using RSAKeys:2048, 3072, 4096 bits with 112, 128, 149 bits of strength PKCS#1v1.5:SHA- 224, SHA-256, SHA-384, SHA-512 PSS:SHA-256, SHA-384, SHA-512RSA SigGen (FIPS186-5)
Digital Signature Verification with RSADigSig-SigVerSignature Verification with RSAKeys:2048, 3072, 4096 bits with 112- 149 bits of strength PKCS#1v1.5:SHA- 224, SHA-256, SHA-384, SHA-512 PSS:SHA-256, SHA-384, SHA-512RSA SigVer (FIPS186-5)
Digital Signature Generation with ECDSADigSig-SigGenDigital signature generation using ECDSACurves:P-256, P- 384, P-521 with 128-256 bits of key strength Hash Algorithm:SHA- 224, SHA-256, SHA-384, SHA-512ECDSA SigGen (FIPS186-5)
Digital Signature Verification with ECDSADigSig-SigVerSignature verification using ECDSACurves:P-256, P- 384, P-521 with 128-256 bits ofECDSA SigVer (FIPS186-5)

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 22
NameTypeDescriptionPropertiesAlgorithms
strength Hash Algorithm:SHA2- 224, SHA2-256, SHA2-384, SHA2- 512
Public Key Verification with ECDSAAsymKeyPair- KeyVerPublic key verification using ECDSACurves:P-256, P- 384, P-521 elliptic curves with 128- 256 bits key strength Compliance:B.4.2 Testing CandidatesECDSA KeyVer (FIPS186-5)
Key Pair Generation with ECDSACKGGenerate ECDSA key pairsCurves:P-256, P- 384, P-521 elliptic curves with 128- 256 bits key strengthECDSA KeyGen (FIPS186-5)
Shared Secret Computation with EC Diffie-HellmanKAS-SSCShared secret computation per SP 800-56ARev3Curves:P-256, P- 384, P-521 elliptic curves keys with 128-256 bits key strengthKAS-ECC-SSC Sp800-56Ar3
Shared Secret Computation with Diffie-HellmanKAS-SSCShared secret computation per SP 800-56ARev3Domain Parameter Generation Methods:ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP- 2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192 Keys:2048, 3072, 4096, 6144, 8192- bit keys with 112- 200 bits key strengthKAS-FFC-SSC Sp800-56Ar3

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 23
NameTypeDescriptionPropertiesAlgorithms
Key Derivation with PBKDFPBKDFKey derivation using PBKDFPBKDF Derived key:112 to 256 bits of key strength HMAC Algorithm:SHA-1, SHA2-224, SHA2- 256, SHA2-384, SHA2-512PBKDF
Key Derivation with TLS 1.2 KDFKAS-135KDFKey derivation using TLS KDFTLS Derived Secret:112-256 with 112-256 bits of key strength Hash Algorithm:SHA2- 256, SHA2-384TLS v1.2 KDF RFC7627
Key Derivation (as part of TLSv1.3) with KDA HKDFKAS-56CKDFKey derivation using KDA HKDFHKDF Derived Key:112-256 bits with 112-256 bits key strength HMAC Algorithm:SHA2- 224, SHA2-256, SHA2-384, SHA2- 512KDA HKDF Sp800- 56Cr1
Key Pair Generation with Safe PrimesCKGKey Pair Generation with Safe PrimesSafe Prime Groups::ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP- 2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192 Keys:2048, 3072, 4096, 6144, 8192- bit keys with 112- 200 bits key strengthSafe Primes Key Generation

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 24
NameTypeDescriptionPropertiesAlgorithms
Compliance:SP800- 56Arev3
Key WrappingKTS-WrapKey Wrapping (as part of the cipher suite in the TLS protocol)Keys:AES-CCM 128, 256-bit keys with 128 or 256 bits of key strength; AES-GCM: 128, 256-bit keys with 128 or 256 bits of key strength; AES- CBC and HMAC: 128, 256-bit keys with 128 or 256 bits of key strengthAES-CCM AES-GCM AES-GCM AES-GCM AES-GCM AES-CBC AES-CBC AES-CBC AES-CBC HMAC-SHA-1 HMAC-SHA2-224 HMAC-SHA2-256 HMAC-SHA2-384 HMAC-SHA2-512 AES-CBC AES-GCM HMAC-SHA-1 HMAC-SHA2-224 HMAC-SHA2-256 HMAC-SHA2-384 HMAC-SHA2-512
Key UnwrappingKTS-WrapKey Unwrapping (as part of the cipher suite in the TLS protocol)Keys:AES-CCM 128, 256-bit keys with 128 or 256 bits of key strength; AES-GCM: 128, 256-bit keys with 128 or 256 bits of key strength; AES- CBC and HMAC: 128, 256-bit keys with 128 or 256 bits of key strengthAES-CCM AES-CBC AES-GCM AES-GCM AES-CBC AES-CBC AES-GCM AES-CBC AES-GCM HMAC-SHA-1 HMAC-SHA2-224 HMAC-SHA2-256 HMAC-SHA2-384 HMAC-SHA2-512 AES-CBC AES-GCM HMAC-SHA-1 HMAC-SHA2-224

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 25
NameTypeDescriptionPropertiesAlgorithms
HMAC-SHA2-256 HMAC-SHA2-384 HMAC-SHA2-512
TLS HandshakeKAS-FullKey AgreementCurves:P-256, P- 384, P-521 elliptic curves with 128, 192, 256 bits of strength Keys:MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192; 2048, 3072, 4096, 6144, 8192-bit keys with 112-200 bits of key strength Compliance:IG D.F scenario 2(2)KAS-ECC-SSC Sp800-56Ar3 KAS-FFC-SSC Sp800-56Ar3 KDA HKDF Sp800- 56Cr1

Table 8: Security Function Implementations

2.7 Algorithm Specific Information

AES XTS The AES algorithm in XTS mode can be only used for the cryptographic protection of data on storage devices, as specified in [SP800-38E]. The length of a single data unit encrypted with the XTS-AES shall not exceed 220 AES blocks, that is 16MB of data. To meet the requirement stated in IG C.I, the module implements a check that ensures, before performing any cryptographic operation, that the two AES keys used in AES XTS mode are not identical. Note: AES-XTS shall be used with 128 and 256-bit keys only. AES-XTS with 192-bit keys is not an Approved service. AES-GCM IV The Crypto Officer shall consider the following requirements and restrictions when using the module. © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 26

For TLS 1.2, the module offers the AES GCM implementation and uses the context of Scenario 1 of FIPS 140-3 IG C.H. The module is compliant with SP 800-52r2 Section 3.3.1 and the mechanism for IV generation is compliant with RFC 5288 and 8446. The module’s implementation of AES GCM is used together with an application that runs outside the module’s cryptographic boundary. The design of the TLS protocol implicitly ensures that the counter (the nonce_explicit part of the IV) does not exhaust the maximum number of possible values for a given session key. In the event the module’s power is lost and restored, the consuming application must ensure that a new key for use with the AES GCM key encryption or decryption under this scenario shall be established. Finally, for TLS 1.3, the AES GCM implementation uses the context of Scenario 5 of FIPS 140-3 IG C.H. The protocol that provides this compliance is TLS 1.3, defined in RFC8446 of August 2018, using the cipher-suites that explicitly select AES GCM as the encryption/decryption cipher (Appendix B.4 of RFC8446). The module supports acceptable AES GCM cipher suites from Section 3.3.1 of SP800-52r2. TLS 1.3 employs separate 64-bit sequence numbers, one for protocol records that are received, and one for protocol records that are sent to a peer. These sequence numbers are set at zero at the beginning of a TLS 1.3 connection and each time when the AES-GCM key is changed. After reading or writing a record, the respective sequence number is incremented by one. The protocol specification determines that the sequence number should not wrap, and if this condition is observed, then the protocol implementation must either trigger a re-key of the session (i.e., a new key for AESGCM), or terminate the connection. Key Derivation using SP 800-132 PBKDF The module provides password-based key derivation (PBKDF), compliant with SP800-132. The module supports option 1a from section 5.4 of [SP800-132], in which the Master Key (MK) or a segment of it is used directly as the Data Protection Key (DPK). In accordance with [SP800-132], the following requirements shall be met.

Page 27
Cert NumberVendor Name
E127Cloudlinux Inc., TuxCare division
NameTypeOperational EnvironmentSample SizeEntropy per SampleConditioning Component
Userspace CPU Time Jitter RNG Entropy Source Version 3.4.0Non- PhysicalAlmaLinux 9.2 on Amazon Web Services (AWS) m5.metal on Intel Xeon Platinum 8259CL; AlmaLinux 9.2 on Amazon Web Services (AWS) a1.metal on AWS Graviton64 bitsSHA3-256 (Cert. A4026), HMAC- SHA2-512-DRBG (Cert. A4025)

In order to meet the required assurances listed in section 5.6 of SP 800-56ARev3, the module shall be used together with an application that implements the "TLS protocol" and the following steps shall be performed.

  1. The entity using the module, must use the module's "Key pair generation" service for generating DH/ECDH ephemeral keys. This meets the assurances required by key pair owner defined in the section 5.6.2.1 of SP 800-56ARev3.
  2. As part of the module's shared secret computation (SSC) service, the module internally performs the public key validation on the peer's public key passed in as input to the SSC function. This meets the public key validity assurance required by the sections 5.6.2.2.1/5.6.2.2.2 of SP 800-56ARev3. The module does not support static keys therefore the "assurance of peer's possession of private key" is not applicable.
2.8 RBG and Entropy

Table 9: Entropy Certificates Table 10: Entropy Sources The module employs a Deterministic Random Bit Generator (DRBG) based on [SP800-90ARev1] for the generation of random value used in asymmetric keys, and for providing a RNG service to calling applications. The approved DRBG provided by the module is the CTR_DRBG with AES-256. The DRBG does not employ prediction resistance or a derivation function. The module uses an SP800-90B-compliant Entropy Source specified in the table above to seed the DRBG. The DRBG is instantiated with a 384-bits long entropy input (corresponding to 384 bits of entropy). Additionally, the DRBG is reseeded with a 256-bits long entropy input (corresponding to 256 bits of entropy). © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 28
2.9 Key Generation

In accordance with FIPS 140-3 IG D.H, the cryptographic module performs Cryptographic Key Generation (CKG) for asymmetric keys according to section 5.1 and 5.2 of [SP800-133rev2].

2.10 Key Establishment

The module provides Diffie-Hellman and EC Diffie-Hellman shared secret computation compliant with SP80056Arev3, in accordance with scenario 2 (1) of IG D.F and used as part of the TLS protocol key exchange in accordance with scenario 2 (2) of IG D.F; that is, the shared secret computation (KAS-FFC-SSC and KAS-ECCSSC) followed by key derivation using TLS KDF. For Diffie-Hellman, the module supports the use of safe primes from RFC7919 for domain parameters and key generation, which are used in the TLS key agreement implemented by the module.

Page 29
128 or 256 bits of encryption strength.
2.11 Industry Protocols

The module implements KDF for the TLS protocol TLSv1.0, TLSv1.1, TLSv1.2. No parts of the TLS 1.0/1.1/1.2, other than the key derivation functions mentioned above, have been tested by the CAVP and CMVP. The module implements HKDF for the TLS protocol TLSv1.3. © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 30
Physical PortLogical Interface(s)Data That Passes
As a software-only module, the module does not have physical ports. Physical Ports are interpreted to be the physical ports of the hardware platform on which it runs.Data InputAPI input parameters
As a software-only module, the module does not have physical ports. Physical Ports are interpreted to be the physical ports of the hardware platform on which it runs.Data OutputAPI output parameters
As a software-only module, the module does not have physical ports. Physical Ports are interpreted to be the physical ports of the hardware platform on which it runs.Control InputAPI function calls for control
As a software-only module, the module does not have physical ports. Physical Ports are interpreted to be the physical ports of the hardware platform on which it runs.Status OutputAPI return codes, status parameters
3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

The logical interfaces are the API through which the applications request services. The following table summarizes the logical interfaces: Table 11: Ports and Interfaces All data output via data output interface is inhibited when the module is performing pre-operational test conditional cryptographic algorithms self-tests or zeroization or when the module enters error state. © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 31
NameTypeOperator TypeAuthentication Methods
Crypto OfficerRoleCONone
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
Symmetric EncryptionPerform AES encryptionGNUTLS_FI PS140_OP_ APPROVEDKey, PlaintextCiphertextSymmetric Encryption with AESCrypto Officer - AES key: W,E
Symmetric DecryptionPerform AES decryptionGNUTLS_FI PS140_OP_ APPROVEDKey, CiphertextPlaintextSymmetric Decryption with AESCrypto Officer - AES key: W,E
Authenticated Symmetric EncryptionEncrypt a plaintextGNUTLS_FI PS140_OP_ APPROVEDKey, Plaintext, IVCiphertext, MAC tagAuthenticated Symmetric Encryption with AESCrypto Officer - AES key: W,E
4 Roles, Services, and Authentication

FIPS 140-3 does not require an authentication mechanism for level 1 modules. Therefore, the module does not implement an authentication mechanism for Crypto Officer. The module supports the Crypto Officer role only. The Crypto Officer role is authorized to access all services provided by the module and this sole role is implicitly assumed by the operator of the module when performing a service. N/A for this module. The module does not support authentication.

4.2 Roles

Table 12: Roles The module supports the Crypto Officer role only. This sole role is implicitly and always assumed by the operator of the module.

4.3 Approved Services

W,E W,E © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 32
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
Authenticated Symmetric DecryptionDecrypt a ciphertextGNUTLS_FI PS140_OP_ APPROVEDKey, Ciphertext, IV, MAC tagPlaintextAuthenticated Symmetric Decryption with AESCrypto Officer - AES key: W,E
Key WrappingKey wrapping (as part of the cipher suites in the TLS protocol)GNUTLS_FI PS140_OP_ APPROVEDAES key only or AES key and HMAC key, CSPWrapped CSPKey WrappingCrypto Officer - AES key: W,E Crypto Officer - HMAC key: W,E
Key UnwrappingKey Unwrappin g (as part of the cipher suites in the TLS protocol)GNUTLS_FI PS140_OP_ APPROVEDAES key only or AES key and HMAC key, Wrapped CSPCSPKey UnwrappingCrypto Officer - AES key: W,E Crypto Officer - HMAC key: W,E
Message DigestCompute message digestGNUTLS_FI PS140_OP_ APPROVEDMessageDigest of the messageMessage Digest with SHACrypto Officer
Random Number GenerationGenerate random bitstringsGNUTLS_FI PS140_OP_ APPROVEDNumber of bitsRandom numberRandom Number Generation with CTR_DRBGCrypto Officer - Entropy Input: W,E - DRBG seed: G,E - DRBG internal state (V value, key): G,W,E
Message Authenticatio n CodeCompute HMACGNUTLS_FI PS140_OP_ APPROVEDHMAC key, messageMessage authenticatio n codeMessage Authenticatio n CodeCrypto Officer

G,W,E © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 33
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
(MAC) with HMAC(MAC) with HMAC- HMAC key: W,E
Message Authenticatio n Code (MAC) with AESCompute AES-based CMAC or GMACGNUTLS_FI PS140_OP_ APPROVEDAES key, messageMessage authenticatio n codeMessage Authenticatio n Code (MAC) with AESCrypto Officer - AES key: W,E
Shared Secret Computation with Diffie- HellmanCompute a shared secretGNUTLS_FI PS140_OP_ APPROVEDPrivate key, public key from peerShared secretShared Secret Computation with Diffie- HellmanCrypto Officer - Diffie- Hellman shared secret: G,R - Diffie- Hellman public key: W,E - Diffie- Hellman private key: W,E
Shared Secret Computation with EC Diffie- HellmanCompute a shared secretGNUTLS_FI PS140_OP_ APPROVEDPrivate key, public key from peerShared secretShared Secret Computation with EC Diffie- HellmanCrypto Officer - EC Diffie- Hellman shared secret: G,R - EC Diffie- Hellman public key: W,E - EC Diffie- Hellman private key: W,E
Digital SignatureGenerate RSA signatureGNUTLS_FI PS140_OP_ APPROVEDMessage, hashDigital signatureMessage Digest with SHA DigitalCrypto Officer - RSA

W,E W,E W,E W,E © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 34
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
Generation with RSAalgorithm, private keySignature Generation with RSAprivate key: W,E
Digital Signature Generation with ECDSAGenerate ECDSA signatureGNUTLS_FI PS140_OP_ APPROVEDMessage, hash algorithm, private keyDigital signatureMessage Digest with SHA Digital Signature Generation with ECDSACrypto Officer - ECDSA private key: W,E
Digital Signature Verification with RSAVerify RSAGNUTLS_FI PS140_OP_ APPROVEDMessage, signature, hash algorithm, public keyVerification resultMessage Digest with SHA Digital Signature Verification with RSACrypto Officer - RSA public key: W,E
Digital Signature Verification with ECDSAVerify ECDSA signatureGNUTLS_FI PS140_OP_ APPROVEDMessage, signature, hash algorithm, public keyVerification resultMessage Digest with SHA Digital Signature Verification with ECDSACrypto Officer - ECDSA public key: W,E
Key Pair Generation with RSAGenerate RSA key pairsGNUTLS_FI PS140_OP_ APPROVEDKey sizeKey pairRandom Number Generation with CTR_DRBG Key Pair Generation with RSACrypto Officer - Module- generated RSA private key: G,W,E - Module- generated RSA public key: G,W,E
Key Pair Generation with ECDSAGenerate ECDSA key pairsGNUTLS_FI PS140_OP_ APPROVEDKey size, enabled- curveKey pairRandom Number Generation withCrypto Officer - Module- generated

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 35
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
CTR_DRBG Key Pair Generation with ECDSAECDSA private key: G,W,E - Module- generated ECDSA public key: G,W,E
Key Pair Generation with Safe PrimesGenerate DH key pairsGNUTLS_FI PS140_OP_ APPROVEDKey sizeKey pairRandom Number Generation with CTR_DRBG Key Pair Generation with Safe PrimesCrypto Officer - Module- generated Diffie- Hellman Private Key: G,W,E - Module- generated Diffie- Hellman Public Key: G,W,E
Public Key Verification with ECDSAVerify ECDSA public keyGNUTLS_FI PS140_OP_ APPROVEDKeyReturn codes/log messagesPublic Key Verification with ECDSACrypto Officer - ECDSA public key: W,E
TLS 1.2 Key Derivation (derivation of TLS Master Secret)Perform key derivation using TLS 1.2 KDFGNUTLS_FI PS140_OP_ APPROVEDTLS Pre- master SecretTLS Master secretKey Derivation with TLS 1.2 KDFCrypto Officer - TLS Pre- master Secret: W,E - TLS Master Secret: G,W,E

G,W,E G,W,E W,E G,W,E © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 36
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
TLS 1.2 Key Derivation (derivation of TLS Derived Secret)Perform key derivation using TLS 1.2 KDFGNUTLS_FI PS140_OP_ APPROVEDTLS Master SecretTLS Derived SecretKey Derivation with TLS 1.2 KDFCrypto Officer - TLS Master Secret: W,E - TLS Derived Secret: G,W,E
HKDF Key Derivation (derivation of HKDF Derived Key)Perform key derivation using HKDFGNUTLS_FI PS140_OP_ APPROVEDShared SecretHKDF Derived KeyKey Derivation (as part of TLSv1.3) with KDA HKDFCrypto Officer - HKDF Derived Key: G,R - Diffie- Hellman shared secret: W,E - EC Diffie- Hellman shared secret: W,E
Key Derivation with PBKDFPerform password- based key derivationGNUTLS_FI PS140_OP_ APPROVEDPassword or passphrasePBKDF Derived keyKey Derivation with PBKDFCrypto Officer - PBKDF password or passphrase: W,E - PBKDF Derived key: G
Transport Layer Security (TLS) Network ProtocolProvide supported cipher suites (listed in Appendix A) inGNUTLS_FI PS140_OP_ APPROVEDCipher-suites listed in Appendix A, Digital Certificate, Public and Private Keys,Return codes and/or log messages, Application dataSymmetric Encryption with AES Symmetric Decryption with AES Authenticated SymmetricCrypto Officer - AES key: W,E - HMAC key: W,E - RSA public key:

G,W,E W,E © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 37
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
approved modeApplication DataEncryption with AES Authenticated Symmetric Decryption with AES Authenticated Symmetric Encryption (in the context of the TLS 1.2/1.3 protocol) with AES- GCM Authenticated Symmetric Decryption (in the context of the TLS 1.2/1.3 protocol) with AES- GCM Message Authenticatio n Code (MAC) with HMAC Message Digest with SHA Digital Signature Generation with RSA Digital Signature Generation with ECDSA Digital SignatureW,E - RSA private key: W,E - ECDSA public key: W,E - ECDSA private key: W,E - Module- generated Diffie- Hellman Public Key: G,E - Module- generated Diffie- Hellman Private Key: G,E - Module- generated EC Diffie- Hellman Public Key: G,E - Module- generated EC Diffie- Hellman Private Key: G,E - TLS Pre- master Secret: G,E - TLS Master Secret: G,E - TLS Derived

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 38
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
Verification with RSA Digital Signature Verification with ECDSA Key Pair Generation with Safe Primes Public Key Verification with ECDSA TLS HandshakeSecret: G,E - HKDF Derived Key: G,E
Self-testsPerform self-testsN/AN/AResult of self-test (pass/fail)Symmetric Encryption with AES Symmetric Decryption with AES Authenticated Symmetric Encryption with AES Authenticated Symmetric Decryption with AES Authenticated Symmetric Decryption (in the context of the TLS 1.2/1.3 protocol) with AES- GCM Authenticated Symmetric EncryptionCrypto Officer

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 39
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
(in the context of the TLS 1.2/1.3 protocol) with AES- GCM Message Authenticatio n Code (MAC) with AES Message Authenticatio n Code (MAC) with HMAC Message Digest with SHA Key Derivation with TLS 1.2 KDF Key Derivation (as part of TLSv1.3) with KDA HKDF Key Derivation with PBKDF Digital Signature Generation with RSA Digital Signature Generation with ECDSA Digital Signature Verification

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 40
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
with RSA Digital Signature Verification with ECDSA Key Pair Generation with RSA Key Pair Generation with ECDSA Key Pair Generation with Safe Primes Public Key Verification with ECDSA Shared Secret Computation with Diffie- Hellman Shared Secret Computation with EC Diffie- Hellman Random Number Generation with CTR_DRBG Key Wrapping Key Unwrapping
Show module name and versionShow module name and versionN/AN/AName and version informationNoneCrypto Officer

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 41
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
Show StatusShow module statusN/AN/AReturn codes and/or log messagesNoneCrypto Officer
ZeroizationZeroize SSPsN/AContext containing SSPsN/ANoneCrypto Officer - AES key: Z - HMAC key: Z - Module- generated RSA private key: Z - Module- generated RSA public key: Z - RSA private key: Z - RSA public key: Z - PBKDF password or passphrase: Z - PBKDF Derived key: Z - Module- generated ECDSA private key: Z - Module- generated ECDSA public key: Z - ECDSA

Z Z Z Z Z Z © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 42

Name

Description

Indicator

Inputs

Outputs

Security Functions

SSP Access private key: Z - ECDSA public key: Z - Module- generated EC Diffie- Hellman Private Key: Z - Module- generated EC Diffie- Hellman Public Key: Z - EC Diffie- Hellman private key: Z - EC Diffie- Hellman public key: Z - Module- generated Diffie- Hellman Private Key: Z - Module- generated Diffie- Hellman Public Key: Z - Diffie- Hellman private key: Z - Diffie-

Z Z Z Z Z Z Z Z Z © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 43

Name

Description

Indicator

Inputs

Outputs

Security Functions

SSP Access Hellman public key: Z - Diffie- Hellman shared secret: Z - EC Diffie- Hellman shared secret: Z - Entropy Input: Z - DRBG seed: Z - DRBG internal state (V value, key): Z - TLS Pre- master Secret: Z - HKDF Derived Key: Z - TLS Master Secret: Z - TLS Derived Secret: Z

Z Z Table 13: Approved Services The above table lists all approved services that can be used in the approved mode of operation. For the above table, the convention below applies when specifying the access permissions (types) that the service has for each SSP.

Page 44
NameDescriptionAlgorithmsRole
Symmetric key generationGenerate symmetric key other than AES and HMAC keysDRBG when key length is less than 112 bitsCO
Symmetric encryptionCompute the cipher for encryptionBlowfish Camellia CAST ChaCha20 DES GOST RC2, RC4 Salsa20 Serpent Triple-DES TwofishCO
Symmetric decryptionCompute the cipher for decryptionBlowfish Camellia CAST ChaCha20 DES GOST RC2, RC4 Salsa20 Serpent Triple-DES TwofishCO
Asymmetric key generation with RSAGenerate RSA key pairsRSA with keys smaller than 2048 bits or greater than 4096 bits.CO
Asymmetric key generation with DSAGenerate DSA key pairsDSACO
4.4 Non-Approved Services

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 45
NameDescriptionAlgorithmsRole
Asymmetric key generation with ECDSAGenerate ECDSA key pairsECDSA with curves not listed in Table "Approved Algorithms"CO
Digital signature generationSign RSA, DSA, and ECDSA signaturesDSA ECDSA with curves not listed in Table "Approved Algorithms" RSA with keys smaller than 2048 bits or greater than 4096 bits. SHA-1CO
Digital signature verificationVerify RSA, DSA, and ECDSA signaturesDSA ECDSA with curves not listed in Table "Approved Algorithms" RSA with keys smaller than 1024 bits or greater than 4096 bits. SHA-1CO
Asymmetric key generationGenerate RSA, DSA, and ECDSA key pairsDSA ECDSA with curves not listed in Table "Approved Algorithms" RSA with keys smaller than 1024 bits or greater than 4096 bits.CO
Message digestCompute message digestGOST MD2, MD4, MD5 RMD160 SM3 STREEBOGCO
Message Authentication Code (MAC)Compute HMACHMAC with keys smaller than 112-bit HMAC with GOST MD2, MD4, MD5 RMD160 STREEBOG UMACCO
Key encapsulationPerform RSA key encapsulationRSA encryption and decryption with any key sizes.CO
Key unencapsulationPerform RSA key unencapsulationRSA encryption and decryption with any key sizes.CO

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 46
NameDescriptionAlgorithmsRole
Shared Secret Computation with Diffie-HellmanPerform DH key agreementDiffie-Hellman with keys generated with domain parameters other than safe primesCO
Shared Secret Computation with EC Diffie-HellmanPerform ECDH key agreementEC Diffie-Hellman with curves not listed in Table "Approved Algorithms"CO
Key Derivation with PBKDFPerform password-based key derivationPBKDF with non-approved message digest algorithmsCO
Transport Layer Security (TLS) Network ProtocolProvide non-supported cipher suitesNon-supported cipher suites (not listed in Appendix A)Crypto Officer
Random number generationGenerate random numberYarrowCO
Authenticated encryptionPerform authenticated encryptionChacha20, Poly1305 and AES- GCMCO
Authenticated decryptionPerform authenticated decryptionChacha20, Poly1305 and AES- GCMCO
Domain parameter generationGenerate domain parameterDSACO

The above table lists all non-approved services that can only be used in the non-approved mode of operation.

4.5 External Software/Firmware Loaded

The module does not have the capability of loading software or firmware from an external source. © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 47
5 Software/Firmware Security
5.1 Integrity Techniques

The integrity of the module is verified by comparing an HMAC-SHA2-256 value calculated at run time with the HMAC value stored in the .hmac file that was computed at build time for each software component of the module listed in section

  1. The .hmac file has HMAC value for libgnutls, libnettle and libhogweed listed in section
  2. If the HMAC values do not match, the test fails, and the module enters the error state. Integrity tests are performed as part of the Pre-Operational Self-Tests.
5.2 Initiate on Demand

The module provides the Self-Test service to perform self-tests on demand which includes the pre-operational test (i.e., integrity test) and the cryptographic algorithm self-tests (CASTs). The Self-Tests service can be called on demand by invoking the gnutls_fips140_run_self_tests() function which will perform integrity tests and the cryptographic algorithms self-tests. Additionally, the Self-Test service can be invoked by powering-off and reloading the module. During the execution of the on-demand self-tests, services are not available, and no data output is possible. © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 48
6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Modifiable How Requirements are Satisfied: The module operates in a modifiable operational environment per FIPS 140-3 level 1 specification: the module executes on a general-purpose operating system, which allows modification, loading, and execution of software that is not part of the validated module. The module shall be installed as stated in Section 11. The user should confirm that the module is installed correctly by running: 1. fips-mode-setup --check command to verify that the system is operating in Approved mode 2. check the output of the the gnutls_get_library_config() API, which should output GnuTLS cryptography module for AlmaLinux 9 3.7.6-396796fe0a32b434 If properly installed, the operating system provides process isolation and memory protection mechanisms that ensure appropriate separation for memory access among the processes on the system. Each process has control over its own data and uncontrolled access to the data of other processes is prevented. There are no concurrent operators.

6.2 Configuration Settings and Restrictions

Instrumentation tools like the ptrace system call, gdb and strace, userspace live patching, as well as other tracing mechanisms offered by the Linux environment such as ftrace or systemtap, shall not be used in the operational environment. The use of any of these tools implies that the cryptographic module is running in a non-validated operational environment. © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 49
7 Physical Security

The module is comprised of software only and therefore this section is Not Applicable (N/A). © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 50
8 Non-Invasive Security

This module does not implement any non-invasive security mechanism and therefore this section is Not Applicable (N/A). © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 51
Storage Area NameDescriptionPersistence Type
RAMTemporary storage for SSPs used by the module as part of service execution. The module does not perform persistent storage of SSPsDynamic
NameFromToFormat TypeDistribution TypeEntry TypeSFI or Algorithm
API input parameters (plaintext)Calling application within TOEPPCryptographic modulePlaintextManualElectronic
API output parameters (plaintext)Cryptographic moduleCalling application within TOEPPlaintextManualElectronic
9 Sensitive Security Parameters Management
9.1 Storage Areas

Table 15: Storage Areas plaintext form. SSPs are provided to the module by the calling process and are destroyed when released by the appropriate zeroization function calls. Symmetric keys, public and private keys are provided to the module by the calling application via API input parameters and are destroyed by the module when invoking the appropriate API function calls.

9.2 SSP Input-Output Methods

Table 16: SSP Input-Output Methods parameters in plaintext form within the physical perimeter of the operational environment. This is allowed by [FIPS140-3_IG] IG 9.5.A, according to the “CM Software to/from App via TOEPP Path” entry on the Key Establishment Table. © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 52
Zeroization MethodDescriptionRationaleOperator Initiation
Zeroize ContextThe memory occupied by SSPs is allocated by regular memory allocation operating system calls.Memory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable. The completion of the zeroization routine indicates that the zeroization procedure succeeded.By calling the appropriate zeroization functions: AES Key: gnutls_cipher_deinit() AES Key: gnutls_aead_cipher_deinit() HMAC Key: gnutls_hmac_deinit() RSA Public Key, RSA Private Key: gnutls_privkey_deinit() gnutls_x509_privkey_deinit() gnutls_rsa_params_deinit() ECDSA Public Key, ECDSA Private Key: gnutls_privkey_deinit() gnutls_x509_privkey_deinit() gnutls_rsa_params_deinit() Diffie-Hellman Public Key, Diffie-Hellman private key: gnutls_dh_params_deinit() TLS Pre-master Secret: gnutls_deinit() TLS Master Secret: gnutls_deinit() HKDF Derived Key: gnutls_deinit() Diffie-Hellman Public Key, Diffie-Hellman private key: gnutls_pk_params_clear() EC Diffie-Hellman public key, EC Diffie-Hellman private key: gnutls_pk_params_clear() Diffie-Hellman Shared Secret: zeroize key() EC Diffie-Hellman Shared Secret: zeroize_key() All SSPs: gnutls_global_deinit()
AutomaticAutomatically zeroized by the module when no longer neededMemory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable.N/A
ResetDe-allocates the volatile memory used to store SSPsVolatile memory used by the module is overwritten within nanoseconds when power is removed. Module power off indicates that the zeroization procedure succeeded.Unloading and reloading the module

Table 17: SSP Zeroization Methods © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 53
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
AES keyAES key used for encryption, decryption, and computing MAC tagsAES-XTS, AES- GCM, AES-CCM, AES- CMAC: 128, 256 bits; Other modes: 128, 192, 256 bits - AES-XTS, AES- GCM, AES-CCM, AES- CMAC: 128, 256 bits; Other modes: 128, 192, 256 bitsSymmetric key - CSPSymmetric Encryption with AES Message Authentication Code (MAC) with AES Symmetric Decryption with AES Authenticated Symmetric Encryption with AES Authenticated Symmetric Decryption with AES Authenticated Symmetric Encryption (in the context of the TLS 1.2/1.3 protocol) with AES-GCM Authenticated Symmetric Decryption (in the context of the TLS 1.2/1.3 protocol) with

The memory occupied by SSPs is allocated by regular memory allocation operating system calls. The application that is acting as the CO is responsible for calling the appropriate zeroization functions provided in the module's API and listed in Table 20. Calling the gnutls_deinit() will zeroize the SSPs stored in the TLS protocol internal state and also invoke the corresponding API functions listed in Table 20 to zeroize SSPs. The zeroization functions overwrite the memory occupied by SSPs with “zeros” and deallocate the memory with the regular memory deallocation operating system call. The completion of a zeroization routine(s) will indicate that a zeroization procedure succeeded. All data output is inhibited during zeroization.

9.4 SSPs

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 54
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By AES-GCM Key Wrapping Key Unwrapping
HMAC keyHMAC key used for computing MAC tags112 to 256 bits - 112 to 256 bitsSymmetric key - CSPMessage Authentication Code (MAC) with HMAC Key Wrapping Key Unwrapping
Module- generated RSA private keyRSA private key generated through asymmetric key generation2048, 3072, 4096 bits - 112, 128, 149 bitsPrivate key - CSPKey Pair Generation with RSA
Module- generated RSA public keyRSA public key generated through asymmetric key generation2048, 3072, 4096 bits - 112, 128, 149 bitsPublic key - PSPKey Pair Generation with RSA
RSA private keyRSA private key used for digital signature generation2048, 3072, 4096 bits - 112- 149 bitsPrivate key - CSPDigital Signature Generation with RSA
RSA public keyRSA private key used for digital signature verification2048, 3072, 4096 bits - 112- 149 bitsPublic key - PSPDigital Signature Verification with RSA
PBKDF password or passphrasePassword used to derive symmetric keys14 characters minimum - 10^-14 minimum probabilityPassword - CSPKey Derivation with PBKDF

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 55
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
PBKDF Derived keyKey derived from PBKDF password/passphrase during key derivation128-256 bits - 128- 256 bitsDerived key - CSPKey Derivation with PBKDF
Module- generated ECDSA private keyECDSA private key generated through the asymmetric key generationP-256, P- 384, P-521 - 128, 192, 256 bitsPrivate key - CSPKey Pair Generation with ECDSA
Module- generated ECDSA public keyECDSA private key generated through the asymmetric key generationP-256, P- 384, P-521 - 128, 192, 256 bitsPublic key - PSPKey Pair Generation with ECDSA
ECDSA private keyECDSA private key used for digital signature generationP-256, P- 384, P-521 - 128, 192, 256 bitsPrivate key - CSPDigital Signature Generation with ECDSA Public Key Verification with ECDSA
ECDSA public keyECDSA public key used for digital signature generationP-256, P- 384, P-521 - 128, 192, 256 bitsPublic key - PSPDigital Signature Verification with ECDSA Public Key Verification with ECDSA
Module- generated EC Diffie- Hellman Public KeyEC Diffie-Hellman public key generated during asymmetric key generationP-256, P- 384, P-521 - 128, 192, 256 bitsPublic key - PSPKey Pair Generation with ECDSATLS Handshake
Module- generatedEC Diffie-Hellman private keyP-256, P- 384, P-521Private key - CSPKey Pair GenerationTLS Handshake

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 56
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
EC Diffie- Hellman Private Keygenerated during asymmetric key generation- 128, 192, 256 bitswith ECDSA
EC Diffie- Hellman public keyPublic key used for Shared Secret ComputationP-256, P- 384, P-521 - 128, 192, 256 bitsPublic key - PSPShared Secret Computation with EC Diffie- Hellman
EC Diffie- Hellman private keyPrivate key used for Shared Secret ComputationP-256, P- 384, P-521 - 128, 192, 256 bitsPrivate key - CSPShared Secret Computation with EC Diffie- Hellman
Module- generated Diffie- Hellman Public KeyDiffie-Hellman public key generated during Safe Primes Key Generation2048, 3072, 4096, 6144, 8192 bits - 112- 200 bitsPublic key - PSPKey Pair Generation with Safe PrimesTLS Handshake
Module- generated Diffie- Hellman Private KeyDiffie-Hellman private key generated during Safe Primes Key Generation2048, 3072, 4096, 6144, 8192 bits - 112- 200 bitsPrivate key - CSPKey Pair Generation with Safe PrimesTLS Handshake
Diffie- Hellman public keyPublic key used for Shared Secret Computation2048-8192 bits - 112- 200 bitsPublic key - PSPShared Secret Computation with Diffie- Hellman
Diffie- Hellman private keyPrivate key used for Shared Secret Computation2048-8192 bits - 112- 200 bitsPrivate key - CSPShared Secret Computation with Diffie- Hellman

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 57
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
Diffie- Hellman shared secretShared secret generated by Diffie- Hellman2048-8192 bits - 112 to 200 bitsShared Secret - CSPShared Secret Computation with Diffie- Hellman
EC Diffie- Hellman shared secretShared secret generated by EC Diffie-HellmanP-256, P- 384, P-521 - 128 to 256 bitsShared Secret - CSPShared Secret Computation with EC Diffie- Hellman
Entropy InputEntropy input used to seed the DRBG128-256 bits - 128- 256 bitsEntropy Input - CSPRandom Number Generation with CTR_DRBG
DRBG seedDRBG seed derived from entropy input128 to 256 bits - 128 to 256 bitsSeed - CSPRandom Number Generation with CTR_DRBGRandom Number Generation with CTR_DRBG
DRBG internal state (V value, key)Internal state of the CTR_DRBG384 bits - 128 to 256 bitsInternal State - CSPRandom Number Generation with CTR_DRBGRandom Number Generation with CTR_DRBG
TLS Pre- master SecretTLS Pre-master Secret used for deriving the TLS Master Secret112 to 256 bits - 112 to 256 bitsSecret - CSPShared Secret Computation with Diffie- Hellman Shared Secret Computation with EC Diffie- HellmanTLS Handshake

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 58
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
TLS Master SecretTLS Master Secret used for deriving the TLS Derived Secret384 bits - 384 bitsSecret - CSPKey Derivation with TLS 1.2 KDFTLS Handshake
TLS Derived SecretUsed as encryption key or MAC key112-256 bits - 112- 256 bitsDerived secret - CSPKey Derivation with TLS 1.2 KDFTLS Handshake
HKDF Derived KeyHKDF (used as part of TLS 1.3 protocol) derived key112-256 bits - 112- 256 bitsDerived secret - CSPKey Derivation (as part of TLSv1.3) with KDA HKDFTLS Handshake
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
AES keyAPI input parameters (plaintext)RAM:PlaintextUntil explicitly zeroized by operatorZeroize Context Reset
HMAC keyAPI input parameters (plaintext)RAM:PlaintextUntil explicitly zeroized by operatorZeroize Context Reset
Module- generated RSA private keyAPI output parameters (plaintext)RAM:PlaintextUntil explicitly zeroized by operatorZeroize Context ResetModule-generated RSA public key:Paired With DRBG internal state (V value, key):Derived From
Module- generated RSA public keyAPI output parameters (plaintext)RAM:PlaintextUntil explicitly zeroized by operatorZeroize Context ResetModule-generated RSA private key:Paired With DRBG internal state (V value, key):Derived From

Table 18: SSP Table 1 © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 59
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
RSA private keyAPI input parameters (plaintext)RAM:PlaintextUntil explicitly zeroized by operatorZeroize Context ResetRSA public key:Paired With
RSA public keyAPI input parameters (plaintext)RAM:PlaintextUntil explicitly zeroized by operatorZeroize Context ResetRSA private key:Paired With
PBKDF password or passphraseAPI input parameters (plaintext)RAM:PlaintextFor the duration of the serviceZeroize Context ResetPBKDF Derived key:Derived From
PBKDF Derived keyAPI output parameters (plaintext)RAM:PlaintextUntil explicitly zeroized by operatorZeroize Context ResetPBKDF password or passphrase:Derived From
Module- generated ECDSA private keyAPI output parameters (plaintext)RAM:PlaintextUntil explicitly zeroized by operatorZeroize Context ResetModule-generated ECDSA public key:Paired With DRBG internal state (V value, key):Derived From
Module- generated ECDSA public keyAPI output parameters (plaintext)RAM:PlaintextUntil explicitly zeroized by operatorZeroize Context ResetModule-generated ECDSA private key:Paired With DRBG internal state (V value, key):Derived From
ECDSA private keyAPI input parameters (plaintext)RAM:PlaintextUntil explicitly zeroized by operatorZeroize Context ResetECDSA public key:Paired With
ECDSA public keyAPI input parameters (plaintext)RAM:PlaintextUntil explicitly zeroized by operatorZeroize Context ResetECDSA private key:Paired With
Module- generated EC Diffie-Hellman Public KeyAPI output parameters (plaintext)RAM:PlaintextFor the duration of the serviceZeroize Context ResetModule-generated EC Diffie-Hellman Private Key:Paired With DRBG internal state (V

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 60
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs value, key):Derived From
Module- generated EC Diffie-Hellman Private KeyAPI output parameters (plaintext)RAM:PlaintextFor the duration of the serviceZeroize Context ResetModule-generated EC Diffie-Hellman Public Key:Paired With DRBG internal state (V value, key):Derived From
EC Diffie- Hellman public keyAPI input parameters (plaintext)RAM:PlaintextUntil explicitly zeroized by operatorZeroize Context ResetEC Diffie-Hellman private key:Paired With EC Diffie-Hellman shared secret:Used With
EC Diffie- Hellman private keyAPI input parameters (plaintext)RAM:PlaintextUntil explicitly zeroized by operatorZeroize Context ResetEC Diffie-Hellman public key:Paired With EC Diffie-Hellman shared secret:Used With
Module- generated Diffie-Hellman Public KeyAPI output parameters (plaintext)RAM:PlaintextFor the duration of the serviceZeroize Context ResetModule-generated Diffie-Hellman Private Key:Paired With DRBG internal state (V value, key):Derived From
Module- generated Diffie-Hellman Private KeyAPI output parameters (plaintext)RAM:PlaintextFor the duration of the serviceZeroize Context ResetModule-generated Diffie-Hellman Public Key:Paired With DRBG internal state (V value, key):Derived From
Diffie-Hellman public keyAPI input parameters (plaintext)RAM:PlaintextUntil explicitly zeroized by operatorZeroize Context ResetDiffie-Hellman private key:Paired With Diffie-Hellman shared secret:Used With

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 61
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
Diffie-Hellman private keyAPI input parameters (plaintext) API output parameters (plaintext)RAM:PlaintextUntil explicitly zeroized by operatorZeroize Context ResetDiffie-Hellman public key:Paired With Diffie-Hellman shared secret:Used With
Diffie-Hellman shared secretAPI output parameters (plaintext)RAM:PlaintextUntil explicitly zeroized by operatorZeroize Context ResetDiffie-Hellman public key:Used With Diffie-Hellman private key:Used With
EC Diffie- Hellman shared secretAPI output parameters (plaintext)RAM:PlaintextUntil explicitly zeroized by operatorZeroize Context ResetEC Diffie-Hellman public key:Used With EC Diffie-Hellman private key:Used With
Entropy InputRAM:PlaintextFrom generation until DRBG Seed is createdZeroize Context AutomaticDRBG seed:Derives
DRBG seedRAM:PlaintextWhile the DRBG is instantiatedZeroize Context AutomaticEntropy Input:Derived From
DRBG internal state (V value, key)RAM:PlaintextWhile the module is operationalZeroize Context AutomaticDRBG seed:Used With
TLS Pre- master SecretRAM:PlaintextUntil explicitly zeroized by operatorZeroize Context ResetTLS Master secret:Derived From Module-generated Diffie-Hellman Public Key:Used With Module-generated Diffie-Hellman Private Key:Used With Module-generated EC Diffie-Hellman Public Key:Used With Module-generated EC

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 62
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs Diffie-Hellman Private Key:Used With
TLS Master SecretRAM:PlaintextUntil explicitly zeroized by operatorZeroize Context ResetTLS Pre-master Secret:Derived From TLS Derived Secret:Derived From
TLS Derived SecretAPI output parameters (plaintext)RAM:PlaintextFor the duration of the serviceZeroize Context ResetTLS Master Secret:Derived From
HKDF Derived KeyAPI output parameters (plaintext)RAM:PlaintextFor the duration of the serviceZeroize Context ResetDiffie-Hellman shared secret:Derived From EC Diffie-Hellman shared secret:Derived From

Table 19: SSP Table 2 The tables above summarize the Sensitive Security Parameters (SSPs) that are used by the cryptographic services implemented in the module.

9.5 Transitions

The SHA-1 algorithm as implemented by the module will be non-approved for all purposes, starting January 1, 2030. © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 63
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
HMAC- SHA2-256 (A5122)256-bit keyMessage authenticationSW/FW IntegrityModule becomes operational and services are available for useIntegrity test of the shared libraries that comprise the module (for libgnutls, libnettle and libhogweed)
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-CBC (A5114)128 and 256- bit keysKATCASTModule becomes operational and services are available for useEncryptionModule initialization
AES-CBC (A5115)128 and 256- bit keysKATCASTModule becomes operational and services are available for useEncryptionModule initialization
10 Self-Tests
10.1 Pre-Operational Self-Tests

Table 20: Pre-Operational Self-Tests The module performs the pre-operational self-test and CASTs automatically when the module is loaded into memory. Pre-operational self-test ensure that the module is not corrupted, and the CASTs ensure that the cryptographic algorithms work as expected. While the module is executing the self-tests, the module services are not available, and input and output are inhibited. The module is not available for use by the calling application until the pre-operational self-test and the CASTs are completed successfully. After the preany of the CASTs fail an error message is returned, and the module transitions to the error state.

10.2 Conditional Self-Tests

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 64
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-CBC (A5116)128 and 256- bit keysKATCASTModule becomes operational and services are available for useEncryptionModule initialization
AES-CBC (A5117)128 and 256- bit keysKATCASTModule becomes operational and services are available for useEncryptionModule initialization
AES-CBC (A5122)128 and 256- bit keysKATCASTModule becomes operational and services are available for useEncryptionModule initialization
AES-CBC (A5114)128 and 256- bit keysKATCASTModule becomes operational and services are available for useDecryptionModule initialization
AES-CBC (A5115)128 and 256- bit keysKATCASTModule becomes operational and services are available for useDecryptionModule initialization
AES-CBC (A5116)128 and 256- bit keysKATCASTModule becomes operational and services are available for useDecryptionModule initialization

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 65
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-CBC (A5117)128 and 256- bit keysKATCASTModule becomes operational and services are available for useDecryptionModule initialization
AES-CBC (A5122)128 and 256- bit keysKATCASTModule becomes operational and services are available for useDecryptionModule initialization
AES-CFB8 (A5120)256-bit keysKATCASTModule becomes operational and services are available for useEncryptionModule initialization
AES-CFB8 (A5125)256-bit keysKATCASTModule becomes operational and services are available for useEncryptionModule initialization
AES-CFB8 (A5120)256-bit keysKATCASTModule becomes operational and services are available for useDecryptionModule initialization
AES-CFB8 (A5125)256-bit keysKATCASTModule becomes operational and services are available for useDecryptionModule initialization

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 66
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-GCM (A5114)256-bit keysKATCASTModule becomes operational and services are available for useEncryptionModule initialization
AES-GCM (A5115)256-bit keysKATCASTModule becomes operational and services are available for useEncryptionModule initialization
AES-GCM (A5116)256-bit keysKATCASTModule becomes operational and services are available for useEncryptionModule initialization
AES-GCM (A5117)256-bit keysKATCASTModule becomes operational and services are available for useEncryptionModule initialization
AES-GCM (A5122)256-bit keysKATCASTModule becomes operational and services are available for useEncryptionModule initialization
AES-GCM (A5114)256-bit keysKATCASTModule becomes operational and services are available for useDecryptionModule initialization

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 67
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-GCM (A5115)256-bit keysKATCASTModule becomes operational and services are available for useDecryptionModule initialization
AES-GCM (A5116)256-bit keysKATCASTModule becomes operational and services are available for useDecryptionModule initialization
AES-GCM (A5117)256-bit keysKATCASTModule becomes operational and services are available for useDecryptionModule initialization
AES-GCM (A5122)256-bit keysKATCASTModule becomes operational and services are available for useDecryptionModule initialization
AES-XTS Testing Revision 2.0 (A5123)256-bit keysKATCASTModule becomes operational and services are available for useEncryptionModule initialization
AES-XTS Testing Revision 2.0 (A5123)256-bit keysKATCASTModule becomes operational and services are available for useDecryptionModule initialization

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 68
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-CMAC (A5114)256-bit keysKATCASTModule becomes operational and services are available for useMAC generationModule initialization
AES-CMAC (A5117)256-bit keysKATCASTModule becomes operational and services are available for useMAC generationModule initialization
AES-CMAC (A5122)256-bit keysKATCASTModule becomes operational and services are available for useMAC generationModule initialization
Counter DRBG (A5122)256-bit keys without DF, without PRKATCASTModule becomes operational and services are available for useKAT CTR_DRBG with AES with 256-bit keys without DF, without PRModule initialization
Counter DRBG (A5122)Health testsHealth tests according to section 11.3 of [SP800- 90Ar1]CASTModule is operational and services are available for useHealth testsModule initialization
KAS-FFC- SSC Sp800- 56Ar3 (A5122)ffdhe3072KATCASTModule becomes operational and services are available for usePrimitive “Z” ComputationModule initialization

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 69
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
KAS-ECC- SSC Sp800- 56Ar3 (A5122)P-256KATCASTModule becomes operational and services are available for usePrimitive “Z” ComputationModule initialization
ECDSA SigGen (FIPS186-5) (A5122)P-256 using SHA-256, P- 384 using SHA-384, and P-521 using SHA-512KATCASTModule becomes operational and services are available for useSignature GenerationModule initialization
ECDSA SigVer (FIPS186-5) (A5122)P-256 using SHA-256, P- 384 using SHA-384, and P-521 using SHA-512KATCASTModule becomes operational and services are available for useSignature VerificationModule initialization
KDA HKDF Sp800- 56Cr1 (A5121)SHA-256KATCASTModule becomes operational and services are available for useKey Derivation (as part of TLSv1.3) with KDA HKDFModule initialization
HMAC- SHA-1 (A5117)128-bit keyKATCASTModule becomes operational and services are available for useMessage AuthenticationModule initialization
HMAC- SHA2-224 (A5117)160-bit keyKATCASTModule becomes operational and services are available for useMessage AuthenticationModule initialization

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 70
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
HMAC- SHA2-256 (A5117)160-bit keyKATCASTModule becomes operational and services are available for useMessage AuthenticationModule initialization
HMAC- SHA2-384 (A5117)160-bit keyKATCASTModule becomes operational and services are available for useMessage AuthenticationModule initialization
HMAC- SHA2-512 (A5117)160-bit keyKATCASTModule becomes operational and services are available for useMessage AuthenticationModule initialization
PBKDF (A5122)SHA-256 with 4096 iterations and 288-bit saltKATCASTModule becomes operational and services are available for useKey Derivation with PBKDFModule initialization
RSA SigGen (FIPS186-5) (A5122)RSA PKCS#1 v1.5 with 2048-bit key using SHA-256KATCASTModule becomes operational and services are available for useSignature GenerationModule initialization
RSA SigVer (FIPS186-5) (A5122)RSA PKCS#1 v1.5 with 2048-bit key using SHA-256KATCASTModule becomes operational and services are available for useSignature VerificationModule initialization

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 71
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
SHA3-224 (A5118)32-bit messageKATCASTModule becomes operational and services are available for useMessage DigestModule initialization
SHA3-256 (A5118)32-bit messageKATCASTModule becomes operational and services are available for useMessage DigestModule initialization
SHA3-384 (A5118)64-bit messageKATCASTModule becomes operational and services are available for useMessage DigestModule initialization
SHA3-512 (A5118)136-bit messageKATCASTModule becomes operational and services are available for useMessage DigestModule initialization
TLS v1.2 KDF RFC7627 (A5122)SHA-256KATCASTModule becomes operational and services are available for useKey Derivation with TLS v1.2 KDF RFC7627Module initialization
ECDSA KeyGen (FIPS186-5) (A5122)SHA-256 with the respective curveSignature generation and verificationPCTSuccessful key pair generationSignature generation and verificationKey Pair Generation

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 72
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
RSA KeyGen (FIPS186-5) (A5122)PKCS#1v1.5 with SHA-256Signature generation and verificationPCTSuccessful key pair generationSignature generation and verificationKey Pair Generation
Safe Primes Key Generation (A5122)N/APCT according to section 5.6.2.1.4 of [SP800- 56Arev3]PCTSuccessful key pair generationPCT according to section 5.6.2.1.4 of [SP800-56Arev3]Key Pair Generation
ECDSA KeyGen (FIPS186-5) (A5122)SHA-256 with the respective curveSignature generation and verificationPCTSignature generation and verificationSignature generation PCT that covers key pair generation for EC Diffie- HellmanKey Pair Generation

Table 21: Conditional Self-Tests Conditional Cryptographic Algorithm Tests The module performs self-tests on approved cryptographic algorithms, using the tests shown in the table above. Data output through the data output interface is inhibited during the self-tests. All CASTs performed are in the form of the Known Answer Tests (KATs) and are run prior to performing the integrity test. The KAT includes comparison of the calculated output with the expected known answer, hard coded as part of the test vectors used in the test. If one of the conditional self-tests fail, the module transitions to the ‘Error’ state and a corresponding error indication is given. The entropy source performs its required self-tests; those are not listed here, as the entropy source is not part of the cryptographic boundary of the module. Conditional Pair-Wise Consistency Tests The module implements RSA, ECDSA, DH and ECDH key generation service and performs the respective pairwise consistency test (PCT) using sign and verify functions when the keys are generated. If any of the tests fails, the module returns an error code and enters the Error state. When the module is in the Error state, no data is output, and cryptographic operations are not allowed. © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 73
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2-256 (A5122)Message authenticationSW/FW IntegrityOn demandManually
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-CBC (A5114)KATCASTOn demandManually
AES-CBC (A5115)KATCASTOn demandManually
AES-CBC (A5116)KATCASTOn demandManually
AES-CBC (A5117)KATCASTOn demandManually
AES-CBC (A5122)KATCASTOn demandManually
AES-CBC (A5114)KATCASTOn demandManually
AES-CBC (A5115)KATCASTOn demandManually
AES-CBC (A5116)KATCASTOn demandManually
AES-CBC (A5117)KATCASTOn demandManually
AES-CBC (A5122)KATCASTOn demandManually
AES-CFB8 (A5120)KATCASTOn demandManually
AES-CFB8 (A5125)KATCASTOn demandManually
AES-CFB8 (A5120)KATCASTOn demandManually
AES-CFB8 (A5125)KATCASTOn demandManually
AES-GCM (A5114)KATCASTOn demandManually
AES-GCM (A5115)KATCASTOn demandManually
AES-GCM (A5116)KATCASTOn demandManually
10.3 Periodic Self-Test Information

Table 22: Pre-Operational Periodic Information © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 74
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-GCM (A5117)KATCASTOn demandManually
AES-GCM (A5122)KATCASTOn demandManually
AES-GCM (A5114)KATCASTOn demandManually
AES-GCM (A5115)KATCASTOn demandManually
AES-GCM (A5116)KATCASTOn demandManually
AES-GCM (A5117)KATCASTOn demandManually
AES-GCM (A5122)KATCASTOn demandManually
AES-XTS Testing Revision 2.0 (A5123)KATCASTOn demandManually
AES-XTS Testing Revision 2.0 (A5123)KATCASTOn demandManually
AES-CMAC (A5114)KATCASTOn demandManually
AES-CMAC (A5117)KATCASTOn demandManually
AES-CMAC (A5122)KATCASTOn demandManually
Counter DRBG (A5122)KATCASTOn demandManually
Counter DRBG (A5122)Health tests according to section 11.3 of [SP800-90Ar1]CASTOn demandManually
KAS-FFC-SSC Sp800-56Ar3 (A5122)KATCASTOn demandManually

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 75
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
KAS-ECC-SSC Sp800-56Ar3 (A5122)KATCASTOn demandManually
ECDSA SigGen (FIPS186-5) (A5122)KATCASTOn demandManually
ECDSA SigVer (FIPS186-5) (A5122)KATCASTOn demandManually
KDA HKDF Sp800- 56Cr1 (A5121)KATCASTOn demandManually
HMAC-SHA-1 (A5117)KATCASTOn demandManually
HMAC-SHA2-224 (A5117)KATCASTOn demandManually
HMAC-SHA2-256 (A5117)KATCASTOn demandManually
HMAC-SHA2-384 (A5117)KATCASTOn demandManually
HMAC-SHA2-512 (A5117)KATCASTOn demandManually
PBKDF (A5122)KATCASTOn demandManually
RSA SigGen (FIPS186-5) (A5122)KATCASTOn demandManually
RSA SigVer (FIPS186-5) (A5122)KATCASTOn demandManually
SHA3-224 (A5118)KATCASTOn demandManually
SHA3-256 (A5118)KATCASTOn demandManually

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 76
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
SHA3-384 (A5118)KATCASTOn demandManually
SHA3-512 (A5118)KATCASTOn demandManually
TLS v1.2 KDF RFC7627 (A5122)KATCASTOn demandManually
ECDSA KeyGen (FIPS186-5) (A5122)Signature generation and verificationPCTOn demandManually
RSA KeyGen (FIPS186-5) (A5122)Signature generation and verificationPCTOn demandManually
Safe Primes Key Generation (A5122)PCT according to section 5.6.2.1.4 of [SP800-56Arev3]PCTOn demandManually
ECDSA KeyGen (FIPS186-5) (A5122)Signature generation and verificationPCTOn demandManually
NameDescriptionConditionsRecovery MethodIndicator
Error StateThe module stops functioning and ends the application processWhen the integrity test or KAT fail When the KAT of DRBG fails during CASTs When the newly generated RSA, ECDSA, Diffie- Hellman or EC Diffie-HellmanThe module must be restarted and perform the pre- operational self-test and the CASTs to recover from these errors.GNUTLS_E_SELF_TEST_ERROR (-400); GNUTLS_E_RANDOM_FAILED (-206); GNUTLS_E_PK_GENERATION_ERROR (- 403); GNUTLS_E_LIB_IN_ERROR_STATE (- 402)

Table 23: Conditional Periodic Information This information can be found in Section 5.2.

10.4 Error States

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 77

Name

Description

Conditions key pair fails the PCT When the module is in error state and caller requests cryptographic operations

Recovery Method

Indicator

Table 24: Error States When the module fails any pre-operational self-test or conditional test, the module will return an error code to indicate the error and enters error state. Any further cryptographic operations and the data output via the data output interface are inhibited. The calling application can obtain the module state by calling the gnutls_fips140_get_operation_state() API function. The function returns GNUTLS_FIPS140_OP_ERROR if the Self-test errors transition the module into an error state that keeps the module operational but prevents any cryptographic related operations. The module must be restarted and perform the pre-operational self-test and the CASTs to recover from these errors. If failures persist, the module must be re-installed.

10.5 Operator Initiation of Self-Tests

The module provides the Self-Test service to perform self-tests on demand which includes the pre-operational test (i.e., integrity test) and the cryptographic algorithm self-tests (CASTs). The Self-Tests service can be called on demand by invoking the gnutls_fips140_run_self_tests() function which will perform integrity tests and the cryptographic algorithms self-tests. Additionally, the Self-Test service can be invoked by powering-off and reloading the module. During the execution of the on-demand self-tests, services are not available, and no data output is possible. © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 78
11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

The module is distributed as a part of the GnuTLS cryptography module for AlmaLinux 9 package in the form of the gnutls-3.7.6-23.el9_2.tuxcare.3.x86_64 RPM package for x86 systems. The binaries of the ‘GnuTLS cryptography module for AlmaLinux 9 version 3.7.6-396796fe0a32b434’ are contained in the RPM packages for delivery listed below, which contain the FIPS validated module:

11.2 Administrator Guidance

All the functions, ports and logical interfaces described in this document are available to the Crypto Officer.

11.3 Non-Administrator Guidance

The module implements only the Crypto Officer. There are no requirements for non-administrator guidance.

11.4 End of Life

For secure sanitization of the cryptographic module, the module needs first to be powered off, which will zeroize all keys and CSPs in volatile memory. Then, for actual deprecation, the module shall be upgraded to a newer version that is FIPS 140-3 validated. The module does not possess persistent storage of SSPs, so further sanitization steps are not required. © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 79
12 Mitigation of Other Attacks
12.1 Attack List
12.2 Mitigation Effectiveness

RSA is vulnerable to timing attacks. In a setup where attackers can measure the time of RSA decryption or signature operations, blinding is always used to protect the RSA operation from that attack. The internal API function of rsa_blind() and rsa_unblind() are called by the module for RSA signature generation and RSA decryption operations. The module generates a random blinding factor and include this random value in the RSA operations to prevent RSA timing attacks. © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 80
Cipher SuiteIDReference
TLS_DH_RSA_WITH_AES_128_CBC_SHA{ 0x00, 0x31 }RFC3268
TLS_DHE_RSA_WITH_AES_128_CBC_SHA{ 0x00, 0x33 }RFC3268
TLS_DH_RSA_WITH_AES_256_CBC_SHA{ 0x00, 0x37 }RFC3268
TLS_DHE_RSA_WITH_AES_256_CBC_SHA{ 0x00, 0x39 }RFC3268
TLS_DH_RSA_WITH_AES_128_CBC_SHA256{ 0x00,0x3F }RFC5246
TLS_DHE_RSA_WITH_AES_128_CBC_SHA256{ 0x00,0x67 }RFC5246
TLS_DH_RSA_WITH_AES_256_CBC_SHA256{ 0x00,0x69 }RFC5246
TLS_DHE_RSA_WITH_AES_256_CBC_SHA256{ 0x00,0x6B }RFC5246
TLS_PSK_WITH_AES_128_CBC_SHA{ 0x00, 0x8C }RFC4279
TLS_PSK_WITH_AES_256_CBC_SHA{ 0x00, 0x8D }RFC4279
TLS_DHE_RSA_WITH_AES_128_GCM_SHA256{ 0x00, 0x9E }RFC5288
TLS_DHE_RSA_WITH_AES_256_GCM_SHA384{ 0x00, 0x9F }RFC5288
TLS_DH_RSA_WITH_AES_128_GCM_SHA256{ 0x00, 0xA0 }RFC5288
TLS_DH_RSA_WITH_AES_256_GCM_SHA384{ 0x00, 0xA1 }RFC5288
TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA{ 0xC0, 0x04 }RFC4492
TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA{ 0xC0, 0x05 }RFC4492
TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA{ 0xC0, 0x09 }RFC4492
TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA{ 0xC0, 0x0A }RFC4492
TLS_ECDH_RSA_WITH_AES_128_CBC_SHA{ 0xC0, 0x0E }RFC4492
TLS_ECDH_RSA_WITH_AES_256_CBC_SHA{ 0xC0, 0x0F }RFC4492
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA{ 0xC0, 0x13 }RFC4492
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA{ 0xC0, 0x14 }RFC4492
TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256{ 0xC0, 0x23 }RFC5289
TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384{ 0xC0, 0x24 }RFC5289
TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA256{ 0xC0, 0x25 }RFC5289
TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA384{ 0xC0, 0x26 }RFC5289

Appendix A. TLS Cipher Suites The module supports the following cipher suites for the TLS protocol version 1.0, 1.1, 1.2 and 1.3, compliant with section 3.3.1 of [SP800-52rev2]. Each cipher suite defines the key exchange algorithm, the bulk encryption algorithm (including the symmetric key size) and the MAC algorithm. © 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 81
Cipher SuiteIDReference
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256{ 0xC0, 0x27 }RFC5289
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384{ 0xC0, 0x28 }RFC5289
TLS_ECDH_RSA_WITH_AES_128_CBC_SHA256{ 0xC0, 0x29 }RFC5289
TLS_ECDH_RSA_WITH_AES_256_CBC_SHA384{ 0xC0, 0x2A }RFC5289
TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256{ 0xC0, 0x2B }RFC5289
TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384{ 0xC0, 0x2C }RFC5289
TLS_ECDH_ECDSA_WITH_AES_128_GCM_SHA256{ 0xC0, 0x2D }RFC5289
TLS_ECDH_ECDSA_WITH_AES_256_GCM_SHA384{ 0xC0, 0x2E }RFC5289
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256{ 0xC0, 0x2F }RFC5289
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384{ 0xC0, 0x30 }RFC5289
TLS_ECDH_RSA_WITH_AES_128_GCM_SHA256{ 0xC0, 0x31 }RFC5289
TLS_ECDH_RSA_WITH_AES_256_GCM_SHA384{ 0xC0, 0x32 }RFC5289
TLS_DHE_RSA_WITH_AES_128_CCM{ 0xC0, 0x9E }RFC6655
TLS_DHE_RSA_WITH_AES_256_CCM{ 0xC0, 0x9F }RFC6655
TLS_DHE_RSA_WITH_AES_128_CCM_8{ 0xC0, 0xA2 }RFC6655
TLS_DHE_RSA_WITH_AES_256_CCM_8{ 0xC0, 0xA3 }RFC6655
TLS_AES_128_GCM_SHA256{ 0x13, 0x01 }RFC8446
TLS_AES_256_GCM_SHA384{ 0x13, 0x02 }RFC8446
TLS_AES_128_CCM_SHA256{ 0x13, 0x04 }RFC8446
TLS_AES_128_CCM_8_SHA256{ 0x13, 0x05 }RFC8446

© 2025 Cloudlinux Inc., TuxCare division/atsec information security.

Page 82

Appendix B. Glossary and Abbreviations

AESAdvanced Encryption Standard
CAVPCryptographic Algorithm Validation Program
CBCCipher Block Chaining
CMACCipher-based Message Authentication Code
CMVPCryptographic Module Validation Program
CSPCritical Security Parameter
CTRCounter Mode
DRBGDeterministic Random Bit Generator
ECBElectronic Code Book
FIPSFederal Information Processing Standards Publication
GCMGalois Counter Mode
HMACHash Message Authentication Code
KATKnown Answer Test
KWAES Key Wrap
MACMessage Authentication Code
NISTNational Institute of Science and Technology
PAAProcessor Algorithm Acceleration
PAIProcessor Algorithm Implementation
PRPrediction Resistance
PSPPublic Security Parameter
PSSProbabilistic Signature Scheme
RNGRandom Number Generator
RSARivest, Shamir, Adleman
SHASecure Hash Algorithm
SSPSensitive Security Parameter
XTSXEX-based Tweaked-codebook mode with cipher text Stealing © 2025 Cloudlinux Inc., TuxCare division/atsec information security.
Page 83

Appendix C. References FIPS140-3 FIPS PUB 140-3 - Security Requirements For Cryptographic Modules March 2019 https://doi.org/10.6028/NIST.FIPS.140-3 FIPS140-3_IG Implementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program January 2024 https://csrc.nist.gov/csrc/media/Projects/cryptographic-module-validationprogram/documents/fips%20140-3/FIPS%20140-3%20IG.pdf FIPS180-4 Secure Hash Standard (SHS) March 2012 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf FIPS186-5 Digital Signature Standard (DSS) February 2023 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-5.pdf FIPS197 Advanced Encryption Standard November 2001 https://csrc.nist.gov/publications/fips/fips197/fips-197.pdf FIPS198-1 The Keyed Hash Message Authentication Code (HMAC) July 2008 https://csrc.nist.gov/publications/fips/fips198-1/FIPS-198-1_final.pdf SP800-38A NIST Special Publication 800-38A - Recommendation for Block Cipher Modes of Operation Methods and Techniques December 2001 https://csrc.nist.gov/publications/nistpubs/800-38a/sp800-38a.pdf SP800-38B NIST Special Publication 800-38B - Recommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication May 2005 https://csrc.nist.gov/publications/detail/sp/800-38b/final SP800-38D NIST Special Publication 800-38D - Recommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC November 2007 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38d.pdf SP800-38E NIST Special Publication 800-38E - Recommendation for Block Cipher Modes of Operation: The XTS AES Mode for Confidentiality on Storage Devices January 2010 https://csrc.nist.gov/publications/nistpubs/800-38E/nist-sp-800-38E.pdf SP800-38F NIST Special Publication 800-38F - Recommendation for Block Cipher Modes of Operation: Methods for Key Wrapping December 2012 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38F.pdf SP800-52rev2 NIST Special Publication 800-52

Page 84

SP800-56Crev2 NIST Special Publication 800-56C