All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Red Hat Enterprise Linux 8 Kernel Cryptographic API

Certificate#5089StandardFIPS 140-3Level1TypeSoftwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorRed Hat, Inc.
Medium review priority  ·  exposes kernel crypto consumer  ·  Linux kernel upstream has published 3932 CVEs since this module's initial validation  ·  last validated 8 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date11/3/2030
CaveatWhen operated in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs. The module generates random strings whose strengths are modified by available entropy.
VendorRed Hat, Inc.

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Red Hat Enterprise Linux 8 Kernel Cryptographic API
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Recovery</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>IKEV<br/>IPSEC<br/>HTTPS</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Red Hat Enterprise Linux 8 Kernel Cryptographic API
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Recovery</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>IKEV<br/>IPSEC<br/>HTTPS</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Red Hat, Inc. Red Hat Enterprise Linux 8 Kernel Cryptographic API Document Version: 1.1 Last Modified: 22/10/2025 Prepared by: atsec information security corporation

4516 Seton Center Parkway, Suite 250

Austin, TX 78759 www.atsec.com © 2025 Red Hat, Inc./ atsec information security corporation.

Page 2
Table of Contents
#SectionPage
Page 3

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 4
List of Tables
ItemPage
Table 1: Security Levels5
Table 3: Tested Operational Environments - Software, Firmware, Hybrid8
Table 4: Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid8
Table 5: Modes List and Description9
Table 6: Approved Algorithms16
Table 7: Non-Approved, Not Allowed Algorithms16
Table 8: Security Function Implementations20
Table 9: Entropy Certificates21
Table 10: Entropy Sources21
Table 11: Ports and Interfaces23
Table 12: Roles24
Table 13: Approved Services28
Table 14: Non-Approved Services29
Table 15: Storage Areas34
Table 16: SSP Input-Output Methods34
Table 17: SSP Zeroization Methods35
Table 18: SSP Table 136
Table 19: SSP Table 237
Table 20: Pre-Operational Self-Tests39
Table 21: Conditional Self-Tests62
Table 22: Pre-Operational Periodic Information62
Table 23: Conditional Periodic Information69
Table 24: Error States69
Figure 1: Block Diagram7
Page 5
SectionTitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication1
5Software/Firmware security1
6Operational environment1
7Physical securityN/A
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacksN/A
Overall Level1
1.1 Overview

This document is the non-proprietary FIPS 140-3 Security Policy for version kernel 4.18.0477.72.1.el8_8; libkcapi 1.2.0-3.el8_8 of the Red Hat Enterprise Linux 8 Kernel Cryptographic API module. It contains the security rules under which the module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for an overall Security Level 1 module. intact and including this notice. Other documentation is proprietary to their authors.

1.1.1 How this Security Policy was prepared

In preparing the Security Policy document, the laboratory formatted the vendor-supplied documentation for consolidation without altering the technical statements therein contained. The further refining of the Security Policy document was conducted iteratively throughout the conformance testing, wherein the Security Policy was submitted to the vendor, who would then edit, modify, and add technical contents. The vendor would also supply additional documentation, which the laboratory formatted into the existing Security Policy, and resubmitted to the vendor for their final editing.

1.2 Security Levels

Table 1: Security Levels © 2025 Red Hat, Inc./ atsec information security corporation.

Page 6
2 Cryptographic Module Specification
2.1 Description

Purpose and Use: The Red Hat Enterprise Linux 8 Kernel Cryptographic API (hereafter referred to as “the module”) provides a C language application program interface (API) for use by other (kernel space and user space) processes that require cryptographic functionality. The module operates on a general-purpose computer as part of the Linux kernel. Its cryptographic functionality can be accessed using the Linux Kernel Crypto API. Module Type: Software Module Embodiment: MultiChipStand Cryptographic Boundary: The cryptographic boundary of the module is defined as the kernel binary and the kernel crypto object files, the libkcapi library, and the sha512hmac binary, which is used to verify the integrity of the software components. In addition, the cryptographic boundary contains the .hmac files which store the expected integrity values for each of the software components. Tested Operational Environment’s Physical Perimeter (TOEPP): The TOEPP of the module is defined as the general-purpose computer on which the module is installed. The PAA/PAI provided by the processor is located within the module’s physical perimeter and outside of the module’s cryptographic boundary. © 2025 Red Hat, Inc./ atsec information security corporation.

Page 7
Package or File NameSoftware/ Firmware VersionFeaturesIntegrity Test
/boot/vmlinuz-4.18.0-477.72.1.el8_8.x86_64; *.ko and *.ko.xz files in /usr/lib/modules/4.18.0- 477.72.1.el8_8.x86_64/kernel/crypto *.ko and *.ko.xz files in /usr/lib/modules/4.18.0-4.18.0- 477.72.1.el8_8; 1.2.0-3.el8_8N/AHMAC- SHA2-512; RSA signature verification
2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification

Page 8

Package or File Name 477.72.1.el8_8.x86_64/kernel/arch/x86/crypto; /usr/lib64/libkcapi.so.1.2.0, /usr/bin/sha512hmac

Software/ Firmware Version

Features

Integrity Test

Operating SystemHardware PlatformProcessorsPAA/PAIHypervisor or Host OSVersion(s)
Red Hat Enterprise Linux 8Dell PowerEdge R440Intel Xeon Silver 4216YesN/A4.18.0- 477.72.1.el8_8; 1.2.0-3.el8_8
Red Hat Enterprise Linux 8Dell PowerEdge R440Intel Xeon Silver 4216NoN/A4.18.0- 477.72.1.el8_8; 1.2.0-3.el8_8
Operating SystemHardware Platform
Red Hat Enterprise Linux 8Intel Xeon E5
Mode NameDescriptionTypeStatus Indicator
Approved modeAutomatically entered whenever an approvedApprovedFor all approved algorithms except GCM: respective approved service function returns indicator 0; For GCM:

Table 2: Tested Module Identification

2.3 Excluded Components

There are no components within the cryptographic boundary excluded from the FIPS 140-3 requirements.

2.4 Modes of Operation

Modes List and Description: © 2025 Red Hat, Inc./ atsec information security corporation.

Page 9
Mode NameDescription service is requestedTypeStatus Indicator crypto_aead_get_flags(tfm) has the CRYPTO_TFM_ FIPS_COMPLIANCE flag set
Non- approved modeAutomatically entered whenever a non-approved service is requestedNon- ApprovedNo service indicator required for non- approved services per IG 2.4.C
AlgorithmCAVP CertPropertiesReference
AES-CBCA5720Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBCA5726Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBCA5729Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS3A5723Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC-CS3A5733Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CCMA5720Key Length - 128, 192, 256SP 800-38C
AES-CCMA5729Key Length - 128, 192, 256SP 800-38C
AES-CFB128A5722Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CFB128A5732Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CMACA5720Direction - Generation, Verification Key Length - 128, 192, 256SP 800-38B
AES-CMACA5729Direction - Generation, Verification Key Length - 128, 192, 256SP 800-38B

Table 5: Modes List and Description After the module is powered on, it performs all the pre-operational self-tests and cryptographic algorithm self-tests without operator intervention. Only after all the self-tests are successful, the module automatically transitions to the approved mode. Mode Change Instructions and Status: The module automatically switches between the approved and non-approved modes depending on the services requested by the operator. The status indicator of the mode of operation is equivalent to the indicator of the service that was requested. The module does not implement a degraded mode of operation.

2.5 Algorithms

Approved Algorithms: © 2025 Red Hat, Inc./ atsec information security corporation.

Page 10
AlgorithmCAVP CertPropertiesReference
AES-CTRA5720Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CTRA5726Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CTRA5729Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA5720Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA5724Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA5725Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA5726Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA5727Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA5728Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA5729Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA5730Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA5731Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-GCMA5720Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GCMA5724Direction - Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GCMA5725Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GCMA5726Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GCMA5727Direction - Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GCMA5728Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GCMA5729Direction - Decrypt, Encrypt IV Generation - ExternalSP 800-38D

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 11
AlgorithmCAVP CertProperties IV Generation Mode - 8.2.1 Key Length - 128, 192, 256Reference
AES-GCMA5730Direction - Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GCMA5731Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GMACA5720Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GMACA5729Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-XTS Testing Revision 2.0A5720Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38E
AES-XTS Testing Revision 2.0A5726Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38E
AES-XTS Testing Revision 2.0A5729Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38E
Counter DRBGA5720Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
Counter DRBGA5724Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
Counter DRBGA5725Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
Counter DRBGA5726Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
Counter DRBGA5727Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
Counter DRBGA5728Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
Counter DRBGA5729Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
Counter DRBGA5730Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 12
AlgorithmCAVP CertPropertiesReference
Counter DRBGA5731Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
Hash DRBGA5720Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-90A Rev. 1
Hash DRBGA5724Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-90A Rev. 1
Hash DRBGA5725Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-90A Rev. 1
Hash DRBGA5726Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-90A Rev. 1
Hash DRBGA5727Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-90A Rev. 1
Hash DRBGA5728Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-90A Rev. 1
Hash DRBGA5729Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-90A Rev. 1
Hash DRBGA5730Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-90A Rev. 1
Hash DRBGA5731Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-90A Rev. 1
Hash DRBGA5734Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-90A Rev. 1
Hash DRBGA5735Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-90A Rev. 1
Hash DRBGA5736Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-90A Rev. 1
HMAC DRBGA5720Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-90A Rev. 1
HMAC DRBGA5724Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-90A Rev. 1
HMAC DRBGA5725Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-90A Rev. 1

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 13
AlgorithmCAVP CertPropertiesReference
HMAC DRBGA5726Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-90A Rev. 1
HMAC DRBGA5727Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-90A Rev. 1
HMAC DRBGA5728Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-90A Rev. 1
HMAC DRBGA5729Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-90A Rev. 1
HMAC DRBGA5730Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-90A Rev. 1
HMAC DRBGA5731Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-90A Rev. 1
HMAC DRBGA5734Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-90A Rev. 1
HMAC DRBGA5735Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-90A Rev. 1
HMAC DRBGA5736Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-90A Rev. 1
HMAC-SHA-1A5720Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA-1A5734Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA-1A5735Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA-1A5736Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2-224A5720Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2-224A5734Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2-224A5735Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2-224A5736Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2-256A5720Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2-256A5734Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2-256A5735Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 14
AlgorithmCAVP CertPropertiesReference
HMAC-SHA2-256A5736Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2-384A5720Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2-384A5734Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2-384A5735Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2-384A5736Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2-512A5720Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2-512A5734Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2-512A5735Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA2-512A5736Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA3-224A5721Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA3-256A5721Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA3-384A5721Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
HMAC-SHA3-512A5721Key Length - Key Length: 112- 524288 Increment 8FIPS 198-1
RSA SigVer (FIPS186- 5)A5720Signature Type - PKCS 1.5 Modulo - 3072FIPS 186-5
RSA SigVer (FIPS186- 5)A5734Signature Type - PKCS 1.5 Modulo - 3072FIPS 186-5
RSA SigVer (FIPS186- 5)A5735Signature Type - PKCS 1.5 Modulo - 3072FIPS 186-5
RSA SigVer (FIPS186- 5)A5736Signature Type - PKCS 1.5 Modulo - 3072FIPS 186-5
SHA-1A5720Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA-1A5734Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA-1A5735Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA-1A5736Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-224A5720Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 15
AlgorithmCAVP CertPropertiesReference
SHA2-224A5734Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-224A5735Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-224A5736Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-256A5720Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-256A5734Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-256A5735Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-256A5736Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-384A5720Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-384A5734Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-384A5735Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-384A5736Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-512A5720Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-512A5734Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-512A5735Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-512A5736Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA3-224A5721Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 202

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 16
AlgorithmCAVP CertPropertiesReference
SHA3-256A5721Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 202
SHA3-384A5721Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 202
SHA3-512A5721Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 202
NameUse and Function
AES-GCM with external IVEncryption with external IV (not compliant to FIPS 140-3 IG C.H)
KBKDF (libkcapi)Key derivation with implementation not tested by CAVP
HKDF (libkcapi)Key derivation with implementation not tested by CAVP
PBKDF2 (libkcapi)Password-based key derivation with implementation not tested by CAVP
RSAEncryption primitive; Decryption primitive (not compliant to SP 800-56Br2)
RSA with PKCS#1 v1.5 paddingSignature generation (pre-hashed message); Signature verification (pre-hashed message)
NameTypeDescriptionPropertiesAlgorithms
Encryption with AESBC-UnAuthEncrypt a plaintext with AESKey size(s):128, 192, 256 bits (XTS mode 128 and 256 bits only)AES-CBC: (A5720, A5726, A5729) AES-CBC-CS3: (A5723, A5733) AES-CFB128: (A5722, A5732)

Table 6: Approved Algorithms Vendor-Affirmed Algorithms: N/A for this module. Non-Approved, Allowed Algorithms: N/A for this module. Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. Non-Approved, Not Allowed Algorithms: Table 7: Non-Approved, Not Allowed Algorithms

2.6 Security Function Implementations

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 17
NameTypeDescriptionPropertiesAlgorithms
AES-CTR: (A5720, A5726, A5729) AES-ECB: (A5720, A5724, A5725, A5726, A5727, A5728, A5729, A5730, A5731) AES-XTS Testing Revision 2.0: (A5720, A5726, A5729)
Decryption with AESBC-UnAuthDecrypt a ciphertext with AESKey size(s):128, 192, 256 bits (XTS mode 128 and 256 bits only)AES-CBC: (A5720, A5726, A5729) AES-CBC-CS3: (A5723, A5733) AES-CFB128: (A5722, A5732) AES-CTR: (A5720, A5726, A5729) AES-ECB: (A5720, A5724, A5725, A5726, A5727, A5728, A5729, A5730, A5731) AES-XTS Testing Revision 2.0: (A5720, A5726, A5729)
HashingSHACompute a message digestSHA-1:N/A SHA2-224:N/A SHA2-256:N/A SHA2-384:N/A SHA2-512:N/A SHA3-224:N/A SHA3-256:N/A SHA3-384:N/A SHA3-512:N/ASHA-1: (A5720, A5734, A5735, A5736) SHA2-224: (A5720, A5734, A5735, A5736) SHA2-256: (A5720, A5734, A5735, A5736) SHA2-384: (A5720, A5734, A5735, A5736) SHA2-512: (A5720, A5734, A5735, A5736) SHA3-224: (A5721) SHA3-256: (A5721)

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 18
NameTypeDescriptionPropertiesAlgorithms
SHA3-384: (A5721) SHA3-512: (A5721)
Message authenticationMACCompute a MAC tag for authenticationHMAC key size(s):112- 524288 bits (112-256 bits) AES key size(s):128, 192, 256 bitsAES-CMAC: (A5720, A5729) AES-GMAC: (A5720, A5729) HMAC-SHA-1: (A5720, A5734, A5735, A5736) HMAC-SHA2- 224: (A5720, A5734, A5735, A5736) HMAC-SHA2- 256: (A5720, A5734, A5735, A5736) HMAC-SHA2- 384: (A5720, A5734, A5735, A5736) HMAC-SHA2- 512: (A5720, A5734, A5735, A5736) HMAC-SHA3- 224: (A5721) HMAC-SHA3- 256: (A5721) HMAC-SHA3- 384: (A5721) HMAC-SHA3- 512: (A5721)
Random number generation with DRBGsDRBGGenerate random numbers from DRBGsCounter DRBG:128, 192, 256 bits HMAC DRBG:128, 256 bits Hash DRBG:128, 256 bitsCounter DRBG: (A5720, A5724, A5725, A5726, A5727, A5728, A5729, A5730, A5731) Hash DRBG: (A5720, A5724, A5725, A5726, A5727, A5728, A5729, A5730, A5731, A5734, A5735, A5736) HMAC DRBG: (A5720, A5724, A5725, A5726, A5727, A5728,

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 19
NameTypeDescriptionPropertiesAlgorithms
A5729, A5730, A5731, A5734, A5735, A5736)
Signature verification with RSADigSig-SigVerVerify a signature with RSAPadding:PKCS#1 v1.5 Hashes:SHA-256 Key size(s):3072 bits (128 bits)RSA SigVer (FIPS186-5): (A5720, A5734, A5735, A5736)
Authenticated encryption with AESBC-AuthEncrypt and authenticate a plaintext with AESKey size(s):128, 192, 256 bitsAES-CCM: (A5720, A5729) AES-GCM: (A5724, A5727, A5730) AES-CBC: (A5720, A5726, A5729) AES-CTR: (A5720, A5726, A5729) HMAC-SHA-1: (A5720, A5734, A5735, A5736) HMAC-SHA2- 256: (A5720, A5734, A5735, A5736) HMAC-SHA2- 384: (A5720, A5734, A5735, A5736) HMAC-SHA2- 512: (A5720, A5734, A5735, A5736)
Authenticated decryption with AESBC-AuthDecrypt and authenticate a ciphertext with AESKey size(s):128, 192, 256 bitsAES-CCM: (A5720, A5729) AES-GCM: (A5720, A5725, A5726, A5728, A5729, A5731) AES-CBC: (A5720, A5726, A5729) AES-CTR: (A5720, A5726, A5729) HMAC-SHA-1: (A5720, A5734, A5735, A5736) HMAC-SHA2- 256: (A5720, A5734, A5735,

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 20
NameTypeDescriptionPropertiesAlgorithms
A5736) HMAC-SHA2- 384: (A5720, A5734, A5735, A5736) HMAC-SHA2- 512: (A5720, A5734, A5735, A5736)

Table 8: Security Function Implementations

2.7 Algorithm Specific Information
2.7.1 AES GCM IV

The Crypto Officer shall consider the following requirements and restrictions when using the module. For IPsec, the module offers the AES GCM implementation and uses the context of Scenario

1 of FIPS 140-3 IG C.H. The mechanism for IV generation is compliant with RFC 4106. IVs

generated using this mechanism may only be used in the context of AES GCM encryption within the IPsec protocol. The module does not implement IPsec. The module’s implementation of AES GCM is used together with an application that runs outside the module’s cryptographic boundary. This application must use RFC 7296 compliant IKEv2 to establish the shared secret SKEYSEED from which the AES GCM encryption keys are derived. The design of the IPsec protocol implicitly ensures that the counter (the nonce_explicit part of the IV) does not exhaust the maximum number of possible values for a given session key. In the event the module’s power is lost and restored, the consuming application must ensure that a new key for use with the AES GCM key encryption or decryption under this scenario shall be established. The module also provides a non-approved AES GCM encryption service which accepts arbitrary external IVs from the operator. This service can be requested by invoking the crypto_aead_encrypt API function with an AES GCM handle. When this is the case, the API will not set an approved service indicator, as described in Section 4.3.

2.7.2 AES XTS

The length of a single data unit encrypted or decrypted with AES XTS shall not exceed 220 AES blocks, that is 16MB, of data per XTS instance. An XTS instance is defined in Section 4 of SP 800-38E. To meet the requirement stated in IG C.I, the module implements a check to ensure that the two AES keys used in AES XTS mode are not identical. The XTS mode shall only be used for the cryptographic protection of data on storage devices. It shall not be used for other purposes, such as the encryption of data in transit. © 2025 Red Hat, Inc./ atsec information security corporation.

Page 21
CertVendor
NumberName
E174Red Hat, Inc.
NameTypeOperational EnvironmentSample SizeEntropy per SampleConditioning Component
RHEL 8 Kernel CPU Time Jitter RNG Entropy SourceNon- PhysicalRed Hat Enterprise Linux 8 on Dell PowerEdge R44064 bits57.30 bitsLinear-Feedback Shift Register (LFSR)
2.7.3 RSA

For RSA signature verification, the module supports modulus size 3072 bits. The supported modulus size has been CAVP tested.

2.7.4 SHA-3

The module provides SHA-3 hash functions compliant with IG C.C. Every implementation of each SHA-3 function was tested and validated on all the module’s operating environments. SHAKE functions are not implemented. SHA-3 hash functions are also used as part of a higher-level algorithm for HMAC.

2.8 RBG and Entropy

Table 9: Entropy Certificates Table 10: Entropy Sources The module implements three different Deterministic Random Bit Generator (DRBG) implementations based on SP 800-90Ar1: CTR_DRBG, Hash_DRBG, and HMAC_DRBG. Each of these DRBG implementations can be instantiated by the operator of the module. When instantiated, these DRBGs can be used to generate random numbers for external usage. Additionally, the module employs a specific HMAC-SHA2-512 DRBG implementation for internal purposes (e.g. to generate initialization vectors). This DRBG is initially seeded with

384 output bits from the entropy source (343 bits of entropy) and reseeded with 256 output

bits from the entropy source (229 bits of entropy).

2.9 Key Generation

The module does not provide key generation.

2.10 Key Establishment

The module does not provide key establishment.

2.11 Industry Protocols

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 22

AES GCM with internal IV generation in the approved mode is compliant with RFC 4106 and shall only be used in conjunction with the IPsec protocol. No parts of this protocol, other than the AES GCM implementation, have been tested by the CAVP and CMVP. © 2025 Red Hat, Inc./ atsec information security corporation.

Page 23
Physical PortLogical Interface(s)Data That Passes
N/AData InputAPI data input parameters, AF_ALG type sockets
N/AData OutputAPI data output parameters, AF_ALG type sockets
N/AControl InputAPI function calls, API control input parameters, AF_ALG type sockets, kernel command line
N/AStatus OutputAPI return values, AF_ALG type sockets, kernel logs
3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

Table 11: Ports and Interfaces The logical interfaces are the APIs through which the applications request services. These logical interfaces are logically separated from each other by the API design, AF_ALG type socket that allows the applications running in the user space to request cryptographic services from the module. The module does not support a control output interface. © 2025 Red Hat, Inc./ atsec information security corporation.

Page 24
NameTypeOperator TypeAuthentication Methods
Crypto OfficerRoleCONone
NameDescript ionIndicatorInputsOutputsSecurity Function sSSP Access
Message digestCompute a message digestcrypto_shash_init returns 0Messag eDigest valueHashingCrypto Officer
Encryptio nEncrypt a plaintextcrypto_skcipher_se tkey returns 0AES key, plainte xtCiphertextEncryptio n with AESCrypto Officer - AES key: W,E
Decryptio nDecrypt a ciphertex tcrypto_skcipher_se tkey returns 0AES key, ciphert extPlaintextDecryptio n with AESCrypto Officer - AES key: W,E
Authentic ated encryptio nEncrypt and authentic ate a plaintextFor all except AES GCM: crypto_aead_setke y returns 0; For AES GCM: crypto_aead_get_fl ags(tfm) has the CRYPTO_TFM_ FIPS_COMPLIANCE flag setAES key, plainte xtCiphertext , MAC tagAuthentic ated encryptio n with AESCrypto Officer - AES key: W,E
Authentic atedEncrypt and authenticFor all except AES GCM: crypto_aead_setkeAES key, ciphertPlaintext or failureAuthentic ated decryptioCrypto Officer
4 Roles, Services, and Authentication

N/A for this module. The module does not implement authentication.

4.2 Roles

Table 12: Roles The module supports the Crypto Officer role only. This sole role is implicitly and always assumed by the operator of the module. No support is provided for multiple concurrent operators.

4.3 Approved Services

s © 2025 Red Hat, Inc./ atsec information security corporation.

Page 25
NameDescript ionIndicatorInputsOutputsSecurity Function sSSP Access
decryptio nate a ciphertex ty returns 0; For AES GCM: crypto_aead_get_fl ags(tfm) has the CRYPTO_TFM_ FIPS_COMPLIANCE flag setext, MAC tagn with AES- AES key: W,E
Message authentic ation generatio nCompute a MAC tagcrypto_shash_init returns 0AES: AES key, messag e; HMAC: HMAC key, messag eMAC tagMessage authentic ationCrypto Officer - AES key: W,E - HMAC key: W,E
Message authentic ation verificatio nCompute a MAC tagcrypto_shash_init returns 0AES: AES key, messag e, MAC tag; HMAC: HMAC key, messag e, MAC tagSuccess/Fa ilureMessage authentic ationCrypto Officer - AES key: W,E - HMAC key: W,E
Random number generatio nGenerate random bytescrypto_rng_get_byt es returns 0Output lengthRandom bytesRandom number generatio n with DRBGsCrypto Officer - Entropy input: W,E - CTR_DR BG Seed: G,E - HMAC_D RBG Seed: G,E - Hash_DR BG Seed: G,E -

s e G,E G,E G,E © 2025 Red Hat, Inc./ atsec information security corporation.

Page 26
NameDescript ionIndicatorInputsOutputsSecurity Function sSSP Access CTR_DR BG Internal State (V, Key): G,W,E - HMAC_D RBG Internal State (V, Key): G,W,E - Hash_DR BG Internal State (V, C): G,W,E
Error detection codeCompute an EDC (crc32, crct10dif)NoneMessag eEDCNoneCrypto Officer
Compress ionCompres s data (deflate, lz4, lz4hc, lzo, zlibdeflat e, zstd)NoneDataCompress ed dataNoneCrypto Officer
Generic system callUse the kernel to perform various non- cryptogra phic operation sNoneIdentifi er, various argume ntsVarious return valuesNoneCrypto Officer
Show versionReturn the module name and version informati onNoneN/AModule name and versionNoneCrypto Officer

s G,W,E G,W,E C): G,W,E s © 2025 Red Hat, Inc./ atsec information security corporation.

Page 27
NameDescript ionIndicatorInputsOutputsSecurity Function sSSP Access
Show statusReturn the module statusNoneN/AModule statusNoneCrypto Officer
Self-testPerform the CASTs and integrity testsNoneN/APass/failEncryptio n with AES Decryptio n with AES Hashing Message authentic ation Random number generatio n with DRBGs Signature verificatio n with RSA Authentic ated encryptio n with AES Authentic ated decryptio n with AESCrypto Officer
Zeroizatio nZeroize all SSPsNoneAny SSPN/ANoneCrypto Officer - AES key: Z - HMAC key: Z - Entropy input: Z - CTR_DR BG Internal State (V, Key): Z - HMAC_D RBG

s © 2025 Red Hat, Inc./ atsec information security corporation.

Page 28

Name

Descript ion

Indicator

Inputs

Outputs

Security Function s

SSP Access Internal State (V, Key): Z - Hash_DR BG Internal State (V, C): Z - CTR_DR BG Seed: Z - Hash_DR BG Seed: Z - HMAC_D RBG Seed: Z

NameDescriptionAlgorithmsRole
AES GCM external IV encryptionEncrypt a plaintext using AES GCM with an external IVAES-GCM with external IVCO
Key derivationDerive a key from a key- derivation key or a shared secretKBKDF (libkcapi) HKDF (libkcapi)CO
Password-based key derivationDerive a key from a passwordPBKDF2 (libkcapi)CO
RSA encryption primitiveCompute the raw RSA encryption of a plaintextRSACO
RSA decryption primitiveCompute the raw RSA decryption of a cipertextRSACO
RSA signature generation (pre-hashed message)Generate a digital signature for a pre-hashed messageRSA with PKCS#1 v1.5 paddingCO

s C): Z Table 13: Approved Services The table above lists the approved services. The following convention is used to specify access rights to SSPs:

4.4 Non-Approved Services

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 29
NameDescriptionAlgorithmsRole
RSA signature verification (pre-hashed message)Verify a digital signature for a pre-hashed messageRSA with PKCS#1 v1.5 paddingCO

Table 14: Non-Approved Services

4.5 External Software/Firmware Loaded

The module does not load external software or firmware. © 2025 Red Hat, Inc./ atsec information security corporation.

Page 30
5 Software/Firmware Security
5.1 Integrity Techniques

The static kernel binary is integrity tested using an HMAC-SHA2-512 calculation performed by the sha512hmac utility (which utilizes the module’s HMAC and SHA-512 implementations). An HMAC-SHA2-512 calculation is also performed on the sha512hmac utility and the libkcapi library to verify their integrity. The libkcapi checks the integrity of the binary of the sha512hmac utility first. The sha512hmac utility is then used to perform an HMAC-SHA2-512 calculation of the kernel’s binary to verify its integrity. After the integrity of the kernel’s binary has been verified, the self-test for the RSA signature verification implementation is run. Upon the successful run of this self-test, the RSA signature verification implementation of the kernel (with PKCS#1 v1.5 padding, SHA-256, and a 3072-bit key) is used to verify the integrity of the crypto object files listed in Section

2.2 and loaded at start-up.
5.2 Initiate on Demand

Integrity tests are performed as part of the pre-operational self-tests, which are executed when the module is initialized. The integrity tests can be invoked on demand by unloading and subsequently re-initializing the module, which will perform (among others) the software integrity tests. © 2025 Red Hat, Inc./ atsec information security corporation.

Page 31
6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Modifiable How Requirements are Satisfied: The operating system provides process isolation and memory protection mechanisms that ensure appropriate separation for memory access among the processes on the system. Each process has control over its own data and uncontrolled access to the data of other processes is prevented.

6.2 Configuration Settings and Restrictions

The module shall be installed as stated in Section 11.1. Instrumentation tools like the ptrace system call, gdb and strace, as well as other tracing mechanisms offered by the Linux environment such as ftrace or systemtap, shall not be used in the operational environments. The use of any of these tools implies that the cryptographic module is running in a non-validated operational environment.

6.3 Additional Information

The Red Hat Enterprise Linux operating system is used as the basis of other products which include but are not limited to:

Page 32
7 Physical Security

The module is comprised of software only and therefore this Section is not applicable. © 2025 Red Hat, Inc./ atsec information security corporation.

Page 33
8 Non-Invasive Security

This module does not implement any non-invasive security mechanism and therefore this Section is not applicable. © 2025 Red Hat, Inc./ atsec information security corporation.

Page 34
Storage Area NameDescriptionPersistence Type
RAMTemporary storage for SSPs used by the module as part of service executionDynamic

Name API input parameters; AF_ALG_typ e sockets (input)

From Operator calling applicatio n (TOEPP)

To Cryptographi c module

Format Type Plaintex t

Distributio n Type Manual

Entry Type Electroni c

SFI or Algorith m

Zeroization MethodDescriptionRationaleOperator Initiation
Free cipher handleZeroizes the SSPs contained within the cipher handleMemory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable. The completion of the zeroization routine indicates that the zeroization procedure succeeded.By calling the appropriate zeroization functions: AES key: crypto_free_skcipher and crypto_free_aead; HMAC key: crypto_free_shash and crypto_free_ahash; DRBG internal state: crypto_free_rng; DRBG seed: crypto_free_rng; Entropy input string: crypto_free_rng
Remove power from the moduleDe-allocates the volatile memory used to store SSPsVolatile memory used by the module is overwritten within nanoseconds when power is removed. Module power off indicates that the zeroization procedure succeeded. TheBy removing power
9 Sensitive Security Parameters Management
9.1 Storage Areas

Table 15: Storage Areas The module does not perform persistent storage of SSPs. The SSPs are temporarily stored in the RAM in plaintext form. SSPs are provided to the module by the calling process and are destroyed when released by the appropriate zeroization function calls.

9.2 SSP Input-Output Methods

m Table 16: SSP Input-Output Methods © 2025 Red Hat, Inc./ atsec information security corporation.

Page 35

Zeroization Method

Description

Rationale successful removal of power implicitly indicates that the zeroization is complete.

Operator Initiation

NameDescripti onSize - Strengt hType - CategoryGenerat ed ByEstablish ed ByUsed By
AES keyAES key used for encryption , decryption , and computing MAC tags.128, 192, 256 bits - 128, 192, 256 bitsSymmetric Key - CSPEncryption with AES Decryption with AES Authenticat ed encryption with AES Authenticat ed decryption with AES
HMAC keyHMAC key.112- 524288 bits - 112-256 bitsAuthenticati on key - CSPMessage authenticati on
Entropy inputEntropy input used to seed the DRBGs. Compliant with IG D.L.128-384 bits - 114-343 bitsEntropy input - CSPRandom number generation with DRBGs
CTR_DRBG SeedDRBG seed derived from entropy input. Compliant with IG D.L.256, 320, 384 bits - 128, 192, 256 bitsSeed - CSPRandom number generatio n with DRBGsRandom number generation with DRBGs
Hash_DRB G SeedDRBG seed derived from440, 888 bitsSeed - CSPRandom number generatioRandom number

Table 17: SSP Zeroization Methods All data output is inhibited during zeroization.

9.4 SSPs

h D.L. D.L. © 2025 Red Hat, Inc./ atsec information security corporation.

Page 36
NameDescripti onSize - Strengt hType - CategoryGenerat ed ByEstablish ed ByUsed By
entropy input. Compliant with IG D.L.- 128, 256 bitsn with DRBGsgeneration with DRBGs
HMAC_DR BG SeedDRBG seed derived from entropy input. Compliant with IG D.L.440, 888 bits - 128, 256 bitsSeed - CSPRandom number generatio n with DRBGsRandom number generation with DRBGs
HMAC_DR BG Internal State (V, Key)Internal state of HMAC DRBG instance. Compliant with IG D.L.320, 512, 1024 bits - 128, 256 bitsInternal state - CSPRandom number generatio n with DRBGsRandom number generation with DRBGs
CTR_DRBG Internal State (V, Key)Internal state of Counter DRBG instance. Compliant with IG D.L.256, 320, 384 bits - 128, 192, 256 bitsInternal state - CSPRandom number generatio n with DRBGsRandom number generation with DRBGs
Hash_DRB G Internal State (V, C)Internal state of Hash DRBG instance. Compliant with IG D.L.880, 1776 bits - 128, 256 bitsInternal state - CSPRandom number generatio n with DRBGsRandom number generation with DRBGs
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
AES keyAPI input parameters; AF_ALG_type sockets (input)RAM:PlaintextUntil cipher handle is freed or module powered offFree cipher handle Remove power from the module
HMAC keyAPI input parameters; AF_ALG_typeRAM:PlaintextUntil cipher handle is freed orFree cipher handle Remove

h D.L. D.L. D.L. D.L. D.L. Table 18: SSP Table 1 © 2025 Red Hat, Inc./ atsec information security corporation.

Page 37
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
sockets (input)module powered offpower from the module
Entropy inputRAM:PlaintextFrom generation until DRBG seed/reseedFree cipher handle Remove power from the moduleCTR_DRBG Seed:Derives Hash_DRBG Seed:Derives HMAC_DRBG Seed:Derives
CTR_DRBG SeedRAM:PlaintextWhile the DRBG is being instantiatedFree cipher handle Remove power from the moduleEntropy input:Derived From CTR_DRBG Internal State (V, Key):Derives
Hash_DRBG SeedRAM:PlaintextWhile the DRBG is being instantiatedFree cipher handle Remove power from the moduleEntropy input:Derived From Hash_DRBG Internal State (V, C):Derives
HMAC_DRBG SeedRAM:PlaintextWhile the DRBG is being instantiatedFree cipher handle Remove power from the moduleEntropy input:Derived From HMAC_DRBG Internal State (V, Key):Derives
HMAC_DRBG Internal State (V, Key)RAM:PlaintextFrom DRBG instantiation until DRBG is un- instantiatedFree cipher handle Remove power from the moduleHMAC_DRBG Seed:Derived From
CTR_DRBG Internal State (V, Key)RAM:PlaintextFrom DRBG instantiation until DRBG is un- instantiatedFree cipher handle Remove power from the moduleCTR_DRBG Seed:Derived From
Hash_DRBG Internal State (V, C)RAM:PlaintextFrom DRBG instantiation until DRBG is un- instantiatedFree cipher handle Remove power from the moduleHash_DRBG Seed:Derived From
9.5 Transitions

The SHA-1 algorithm as implemented by the module will be non-approved for all purposes, starting January 1, 2031. © 2025 Red Hat, Inc./ atsec information security corporation.

Page 38

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 39
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
HMAC- SHA2-512 (A5736)128-bit keyMessage AuthenticationSW/FW IntegrityModule becomes operational and services are available for use.Integrity test for kernel binary, libkcapi components and sha512hmac binary
RSA SigVer (FIPS186-5) (A5720)3072-bit key with SHA- 256Signature VerificationSW/FW IntegrityModule becomes operational and services are available for use.Integrity test for kernel object files
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
SHA-1 (A5720)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA-1 (A5734)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
10 Self-Tests
10.1 Pre-Operational Self-Tests

Table 20: Pre-Operational Self-Tests The pre-operational software integrity tests are performed automatically when the module is powered on, before the module transitions into the operational state. The algorithms used CASTs before the integrity test is performed. While the module is executing the self-tests, services are not available, and data output (via the data output interface) is inhibited until the pre-operational software integrity self-tests are successfully completed. The module transitions to the operational state only after the pre-operational self-tests are passed successfully.

10.2 Conditional Self-Tests

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 40
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
SHA-1 (A5735)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA-1 (A5736)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA2-224 (A5720)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA2-224 (A5734)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA2-224 (A5735)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA2-224 (A5736)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA2-256 (A5720)0-8184 bit messagesKATCASTModule becomes operationalMessage digestModule initialization

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 41
Algorithm or TestTest PropertiesTest MethodTest TypeIndicator and services are available for use.DetailsConditions
SHA2-256 (A5734)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA2-256 (A5735)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA2-256 (A5736)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA2-384 (A5720)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA2-384 (A5734)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA2-384 (A5735)0-8184 bit messagesKATCASTModule becomes operational and services areMessage digestModule initialization

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 42
Algorithm or TestTest PropertiesTest MethodTest TypeIndicator available for use.DetailsConditions
SHA2-384 (A5736)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA2-512 (A5720)0-8184 bit messageKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA2-512 (A5734)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA2-512 (A5735)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA2-512 (A5736)0-8184 bit messagesKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA3-224 (A5721)0-8184 bit messageKATCASTModule becomes operational and services are available for use.Message digestModule initialization

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 43
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
SHA3-256 (A5721)0-8184 bit messageKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA3-384 (A5721)0-8184 bit messageKATCASTModule becomes operational and services are available for use.Message digestModule initialization
SHA3-512 (A5721)0-8184 bit messageKATCASTModule becomes operational and services are available for use.Message digestModule initialization
AES-ECB (A5720) - Encrypt128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.EncryptionModule initialization
AES-ECB (A5724) - Encrypt128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.EncryptionModule initialization
AES-ECB (A5725) - Encrypt128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.EncryptionModule initialization
AES-ECB (A5726) - Encrypt128, 192, 256 bit keysKATCASTModule becomes operationalEncryptionModule initialization

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 44
Algorithm or TestTest PropertiesTest MethodTest TypeIndicator and services are available for use.DetailsConditions
AES-ECB (A5727) - Encrypt128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.EncryptionModule initialization
AES-ECB (A5728) - Encrypt128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.EncryptionModule initialization
AES-ECB (A5730) - Encrypt128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.EncryptionModule initialization
AES-ECB (A5731) - Encrypt128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.EncryptionModule initialization
AES-ECB (A5729) - Encrypt128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.EncryptionModule initialization
AES-CBC (A5720) - Encrypt128, 192, 256 bit keysKATCASTModule becomes operational and services areEncryptionModule initialization

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 45
Algorithm or TestTest PropertiesTest MethodTest TypeIndicator available for use.DetailsConditions
AES-CBC (A5726) - Encrypt128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.EncryptionModule initialization
AES-CBC- CS3 (A5733) - Encrypt128 bit keysKATCASTModule becomes operational and services are available for use.EncryptionModule initialization
AES- CFB128 (A5732) - Encrypt128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.EncryptionModule initialization
AES-CTR (A5720) - Encrypt128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.EncryptionModule initialization
AES-CTR (A5729) - Encrypt128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.EncryptionModule initialization
AES-CCM (A5729) - Encrypt128, 192, 256 bit keys; 128- bit IVsKATCASTModule becomes operational and services are available for use.EncryptionModule initialization

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 46
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-GCM (A5720) - Encrypt128, 192, 256 bit keys, 96-bit IVsKATCASTModule becomes operational and services are available for use.EncryptionModule initialization
AES-GCM (A5724) - Encrypt128, 192, 256 bit keys, 96-bit IVsKATCASTModule becomes operational and services are available for use.EncryptionModule initialization
AES-GCM (A5725) - Encrypt128, 192, 256 bit keys, 96-bit IVsKATCASTModule becomes operational and services are available for use.EncryptionModule initialization
AES-GCM (A5726) - Encrypt128, 192, 256 bit keys, 96-bit IVsKATCASTModule becomes operational and services are available for use.EncryptionModule initialization
AES-GCM (A5727) - Encrypt128, 192, 256 bit keys, 96-bit IVsKATCASTModule becomes operational and services are available for use.EncryptionModule initialization
AES-GCM (A5728) - Encrypt128, 192, 256 bit keys, 96-bit IVsKATCASTModule becomes operational and services are available for use.EncryptionModule initialization
AES-GCM (A5729) - Encrypt128, 192, 256 bitKATCASTModule becomes operationalEncryptionModule initialization

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 47
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
keys, 96-bit IVsand services are available for use.
AES-GCM (A5730) - Encrypt128, 192, 256 bit keys, 96-bit IVsKATCASTModule becomes operational and services are available for use.EncryptionModule initialization
AES-GCM (A5731) - Encrypt128, 192, 256 bit keys, 96-bit IVsKATCASTModule becomes operational and services are available for use.EncryptionModule initialization
AES-XTS Testing Revision 2.0 (A5720) - Encrypt128 and 256 bit keysKATCASTModule becomes operational and services are available for use.EncryptionModule initialization
AES-XTS Testing Revision 2.0 (A5729) - Encrypt128 and 256 bit keysKATCASTModule becomes operational and services are available for use.EncryptionModule initialization
AES-ECB (A5720) - Decrypt128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.DecryptionModule initialization
AES-ECB (A5724) - Decrypt128, 192, 256 bit keysKATCASTModule becomes operational and services areDecryptionModule initialization

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 48
Algorithm or TestTest PropertiesTest MethodTest TypeIndicator available for use.DetailsConditions
AES-ECB (A5725) - Decrypt128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.DecryptionModule initialization
AES-ECB (A5726) - Decrypt128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.DecryptionModule initialization
AES-ECB (A5727) - Decrypt128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.DecryptionModule initialization
AES-ECB (A5728) - Decrypt128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.DecryptionModule initialization
AES-ECB (A5730) - Decrypt128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.DecryptionModule initialization
AES-ECB (A5731) - Decrypt128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.DecryptionModule initialization

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 49
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-ECB (A5729) - Decrypt128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.DecryptionModule initialization
AES-CBC (A5720) - Decrypt128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.DecryptionModule initialization
AES-CBC (A5726) - Decrypt128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.DecryptionModule initialization
AES-CBC- CS3 (A5733) - Decrypt128 bit keysKATCASTModule becomes operational and services are available for use.DecryptionModule initialization
AES- CFB128 (A5732) - Decrypt128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.DecryptionModule initialization
AES-CTR (A5720) - Decrypt128, 192, 256 bit keysKATCASTModule becomes operational and services are available for use.DecryptionModule initialization
AES-CTR (A5729) - Decrypt128, 192, 256 bit keysKATCASTModule becomes operationalDecryptionModule initialization

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 50
Algorithm or TestTest PropertiesTest MethodTest TypeIndicator and services are available for use.DetailsConditions
AES-CCM (A5729) - Decrypt128, 192, 256 bit keys; 128- bit IVsKATCASTModule becomes operational and services are available for use.DecryptionModule initialization
AES-GCM (A5720) - Decrypt128, 192, 256 bit keys, 96-bit IVsKATCASTModule becomes operational and services are available for use.DecryptionModule initialization
AES-GCM (A5724) - Decrypt128, 192, 256 bit keys, 96-bit IVsKATCASTModule becomes operational and services are available for use.DecryptionModule initialization
AES-GCM (A5725) - Decrypt128, 192, 256 bit keys, 96-bit IVsKATCASTModule becomes operational and services are available for use.DecryptionModule initialization
AES-GCM (A5726) - Decrypt128, 192, 256 bit keys, 96-bit IVsKATCASTModule becomes operational and services are available for use.DecryptionModule initialization
AES-GCM (A5727) - Decrypt128, 192, 256 bit keys, 96-bit IVsKATCASTModule becomes operational and services areDecryptionModule initialization

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 51
Algorithm or TestTest PropertiesTest MethodTest TypeIndicator available for use.DetailsConditions
AES-GCM (A5728) - Decrypt128, 192, 256 bit keys, 96-bit IVsKATCASTModule becomes operational and services are available for use.DecryptionModule initialization
AES-GCM (A5729) - Decrypt128, 192, 256 bit keys, 96-bit IVsKATCASTModule becomes operational and services are available for use.DecryptionModule initialization
AES-GCM (A5730) - Decrypt128, 192, 256 bit keys, 96-bit IVsKATCASTModule becomes operational and services are available for use.DecryptionModule initialization
AES-GCM (A5731) - Decrypt128, 192, 256 bit keys, 96-bit IVsKATCASTModule becomes operational and services are available for use.DecryptionModule initialization
AES-XTS Testing Revision 2.0 (A5720) - Decrypt128 and 256 bit keysKATCASTModule becomes operational and services are available for use.DecryptionModule initialization
AES-XTS Testing Revision 2.0 (A5729) - Decrypt128 and 256 bit keysKATCASTModule becomes operational and services are available for use.DecryptionModule initialization

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 52
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-CMAC (A5729)128 and 256 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC-SHA- 1 (A5720)32-64 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC-SHA- 1 (A5734)32-64 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC-SHA- 1 (A5735)32-64 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC-SHA- 1 (A5736)32-64 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA2-224 (A5720)32-1048 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA2-224 (A5734)32-1048 bit keysKATCASTModule becomes operationalMessage authenticationModule initialization

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 53
Algorithm or TestTest PropertiesTest MethodTest TypeIndicator and services are available for use.DetailsConditions
HMAC- SHA2-224 (A5735)32-1048 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA2-224 (A5736)32-1048 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA2-256 (A5720)32-64 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA2-256 (A5734)32-64 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA2-256 (A5735)32-64 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA2-256 (A5736)32-64 bit keysKATCASTModule becomes operational and services areMessage authenticationModule initialization

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 54
Algorithm or TestTest PropertiesTest MethodTest TypeIndicator available for use.DetailsConditions
HMAC- SHA2-384 (A5720)32-1048 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA2-384 (A5734)32-1048 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA2-384 (A5735)32-1048 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA2-384 (A5736)32-1048 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA2-512 (A5720)32-1048 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization. Before integrity test.
HMAC- SHA2-512 (A5734)32-1048 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization. Before integrity test.

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 55
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
HMAC- SHA2-512 (A5735)32-1048 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization. Before integrity test.
HMAC- SHA2-512 (A5736)32-1048 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization. Before integrity test.
HMAC- SHA3-224 (A5721)32-1048 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA3-256 (A5721)32-1048 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA3-384 (A5721)32-1048 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
HMAC- SHA3-512 (A5721)32-1048 bit keysKATCASTModule becomes operational and services are available for use.Message authenticationModule initialization
Counter DRBG (A5720)128, 192, 256 bit keys With/withoutKATCASTModule becomes operationalinstantiate, reseed, generateModule initialization

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 56
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
PR; Health test per section 11.3 of SP 800- 90Arev1and services are available for use.
Counter DRBG (A5724)128, 192, 256 bit keys With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.instantiate, reseed, generateModule initialization
Counter DRBG (A5725)128, 192, 256 bit keys With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.instantiate, reseed, generateModule initialization
Counter DRBG (A5726)128, 192, 256 bit keys With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.instantiate, reseed, generateModule initialization
Counter DRBG (A5727)128, 192, 256 bit keys With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.instantiate, reseed, generateModule initialization
Counter DRBG (A5728)128, 192, 256 bit keys With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.instantiate, reseed, generateModule initialization
Counter DRBG (A5729)128, 192, 256 bit keys With/without PR; Health test per section 11.3KATCASTModule becomes operational and services areinstantiate, reseed, generateModule initialization

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 57
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
of SP 800- 90Arev1available for use.
Counter DRBG (A5730)128, 192, 256 bit keys With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.instantiate, reseed, generateModule initialization
Counter DRBG (A5731)128, 192, 256 bit keys With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.instantiate, reseed, generateModule initialization
Hash DRBG (A5720)SHA-256 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.instantiate, reseed, generateModule initialization
Hash DRBG (A5724)SHA-256 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.instantiate, reseed, generateModule initialization
Hash DRBG (A5725)SHA-256 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.instantiate, reseed, generateModule initialization
Hash DRBG (A5726)SHA-256 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.instantiate, reseed, generateModule initialization

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 58
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
Hash DRBG (A5727)SHA-256 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.instantiate, reseed, generateModule initialization
Hash DRBG (A5728)SHA-256 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.instantiate, reseed, generateModule initialization
Hash DRBG (A5729)SHA-256 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.instantiate, reseed, generateModule initialization
Hash DRBG (A5730)SHA-256 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.instantiate, reseed, generateModule initialization
Hash DRBG (A5731)SHA-256 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.instantiate, reseed, generateModule initialization
Hash DRBG (A5734)SHA-256 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.instantiate, reseed, generateModule initialization
Hash DRBG (A5735)SHA-256 With/without PR; HealthKATCASTModule becomes operationalinstantiate, reseed, generateModule initialization

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 59
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
test per section 11.3 of SP 800- 90Arev1and services are available for use.
Hash DRBG (A5736)SHA-256 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.instantiate, reseed, generateModule initialization
HMAC DRBG (A5720)SHA-256, SHA512 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.instantiate, reseed, generateModule initialization
HMAC DRBG (A5724)SHA-256, SHA512 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.instantiate, reseed, generateModule initialization
HMAC DRBG (A5725)SHA-256, SHA512 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.instantiate, reseed, generateModule initialization
HMAC DRBG (A5726)SHA-256, SHA512 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.instantiate, reseed, generateModule initialization
HMAC DRBG (A5727)SHA-256, SHA512 With/without PR; Health test per section 11.3KATCASTModule becomes operational and services areinstantiate, reseed, generateModule initialization

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 60
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
of SP 800- 90Arev1available for use.
HMAC DRBG (A5728)SHA-256, SHA512 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.instantiate, reseed, generateModule initialization
HMAC DRBG (A5729)SHA-256, SHA512 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.instantiate, reseed, generateModule initialization
HMAC DRBG (A5730)SHA-256, SHA512 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.instantiate, reseed, generateModule initialization
HMAC DRBG (A5731)SHA-256, SHA512 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.instantiate, reseed, generateModule initialization
HMAC DRBG (A5734)SHA-256, SHA512 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.instantiate, reseed, generateModule initialization
HMAC DRBG (A5735)SHA-256, SHA512 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.instantiate, reseed, generateModule initialization

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 61
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
HMAC DRBG (A5736)SHA-256, SHA512 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operational and services are available for use.instantiate, reseed, generateModule initialization
RSA SigVer (FIPS186-5) (A5720)4096-bit key with SHA- 256KATCASTModule becomes operational and services are available for use.VerifyModule initialization. Before integrity test.
RSA SigVer (FIPS186-5) (A5734)4096-bit key with SHA- 256KATCASTModule becomes operational and services are available for use.VerifyModule initialization. Before integrity test.
RSA SigVer (FIPS186-5) (A5735)4096-bit key with SHA- 256KATCASTModule becomes operational and services are available for use.VerifyModule initialization. Before integrity test.
RSA SigVer (FIPS186-5) (A5736)4096-bit key with SHA- 256KATCASTModule becomes operational and services are available for use.VerifyModule initialization. Before integrity test.
Entropy Source RCT initialization1024 samplesRCTCASTModule becomes operational and services are available for use.Entropy source start- up testEntropy source initialization
Entropy Source APT initialization1024 samplesAPTCASTModule becomes operationalEntropy source start- up testEntropy source initialization

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 62
Algorithm or TestTest PropertiesTest MethodTest TypeIndicator and services are available for use.DetailsConditions
Entropy Source continuous RCTCutoff C = 61RCTCASTEntropy source is operationalEntropy source continuous testContinuously
Entropy Source continuous APTCutoff C = 355APTCASTEntropy source is operationalEntropy source continuous testContinuously
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2- 512 (A5736)Message AuthenticationSW/FW IntegrityOn demandManually
RSA SigVer (FIPS186-5) (A5720)Signature VerificationSW/FW IntegrityOn demandManually
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
SHA-1 (A5720)KATCASTOn demandManually
SHA-1 (A5734)KATCASTOn demandManually
SHA-1 (A5735)KATCASTOn demandManually
SHA-1 (A5736)KATCASTOn demandManually
SHA2-224 (A5720)KATCASTOn demandManually
SHA2-224 (A5734)KATCASTOn demandManually
SHA2-224 (A5735)KATCASTOn demandManually
SHA2-224 (A5736)KATCASTOn demandManually
SHA2-256 (A5720)KATCASTOn demandManually

Table 21: Conditional Self-Tests The module performs self-tests on all approved cryptographic algorithms as part of the approved services supported in the approved mode of operation, using the tests shown in the table above. Services are not available, and data output (via the data output interface) is inhibited during the conditional self-tests. If any of these tests fails, the module transitions to the Error State.

10.3 Periodic Self-Test Information

Table 22: Pre-Operational Periodic Information © 2025 Red Hat, Inc./ atsec information security corporation.

Page 63
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
SHA2-256 (A5734)KATCASTOn demandManually
SHA2-256 (A5735)KATCASTOn demandManually
SHA2-256 (A5736)KATCASTOn demandManually
SHA2-384 (A5720)KATCASTOn demandManually
SHA2-384 (A5734)KATCASTOn demandManually
SHA2-384 (A5735)KATCASTOn demandManually
SHA2-384 (A5736)KATCASTOn demandManually
SHA2-512 (A5720)KATCASTOn demandManually
SHA2-512 (A5734)KATCASTOn demandManually
SHA2-512 (A5735)KATCASTOn demandManually
SHA2-512 (A5736)KATCASTOn demandManually
SHA3-224 (A5721)KATCASTOn demandManually
SHA3-256 (A5721)KATCASTOn demandManually
SHA3-384 (A5721)KATCASTOn demandManually
SHA3-512 (A5721)KATCASTOn demandManually
AES-ECB (A5720) - EncryptKATCASTOn demandManually
AES-ECB (A5724) - EncryptKATCASTOn demandManually
AES-ECB (A5725) - EncryptKATCASTOn demandManually
AES-ECB (A5726) - EncryptKATCASTOn demandManually
AES-ECB (A5727) - EncryptKATCASTOn demandManually
AES-ECB (A5728) - EncryptKATCASTOn demandManually

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 64
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-ECB (A5730) - EncryptKATCASTOn demandManually
AES-ECB (A5731) - EncryptKATCASTOn demandManually
AES-ECB (A5729) - EncryptKATCASTOn demandManually
AES-CBC (A5720) - EncryptKATCASTOn demandManually
AES-CBC (A5726) - EncryptKATCASTOn demandManually
AES-CBC-CS3 (A5733) - EncryptKATCASTOn demandManually
AES-CFB128 (A5732) - EncryptKATCASTOn demandManually
AES-CTR (A5720) - EncryptKATCASTOn demandManually
AES-CTR (A5729) - EncryptKATCASTOn demandManually
AES-CCM (A5729) - EncryptKATCASTOn demandManually
AES-GCM (A5720) - EncryptKATCASTOn demandManually
AES-GCM (A5724) - EncryptKATCASTOn demandManually
AES-GCM (A5725) - EncryptKATCASTOn demandManually
AES-GCM (A5726) - EncryptKATCASTOn demandManually
AES-GCM (A5727) - EncryptKATCASTOn demandManually
AES-GCM (A5728) - EncryptKATCASTOn demandManually

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 65
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-GCM (A5729) - EncryptKATCASTOn demandManually
AES-GCM (A5730) - EncryptKATCASTOn demandManually
AES-GCM (A5731) - EncryptKATCASTOn demandManually
AES-XTS Testing Revision 2.0 (A5720) - EncryptKATCASTOn demandManually
AES-XTS Testing Revision 2.0 (A5729) - EncryptKATCASTOn demandManually
AES-ECB (A5720) - DecryptKATCASTOn demandManually
AES-ECB (A5724) - DecryptKATCASTOn demandManually
AES-ECB (A5725) - DecryptKATCASTOn demandManually
AES-ECB (A5726) - DecryptKATCASTOn demandManually
AES-ECB (A5727) - DecryptKATCASTOn demandManually
AES-ECB (A5728) - DecryptKATCASTOn demandManually
AES-ECB (A5730) - DecryptKATCASTOn demandManually
AES-ECB (A5731) - DecryptKATCASTOn demandManually
AES-ECB (A5729) - DecryptKATCASTOn demandManually
AES-CBC (A5720) - DecryptKATCASTOn demandManually
AES-CBC (A5726) - DecryptKATCASTOn demandManually

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 66
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-CBC-CS3 (A5733) - DecryptKATCASTOn demandManually
AES-CFB128 (A5732) - DecryptKATCASTOn demandManually
AES-CTR (A5720) - DecryptKATCASTOn demandManually
AES-CTR (A5729) - DecryptKATCASTOn demandManually
AES-CCM (A5729) - DecryptKATCASTOn demandManually
AES-GCM (A5720) - DecryptKATCASTOn demandManually
AES-GCM (A5724) - DecryptKATCASTOn demandManually
AES-GCM (A5725) - DecryptKATCASTOn demandManually
AES-GCM (A5726) - DecryptKATCASTOn demandManually
AES-GCM (A5727) - DecryptKATCASTOn demandManually
AES-GCM (A5728) - DecryptKATCASTOn demandManually
AES-GCM (A5729) - DecryptKATCASTOn demandManually
AES-GCM (A5730) - DecryptKATCASTOn demandManually
AES-GCM (A5731) - DecryptKATCASTOn demandManually
AES-XTS Testing Revision 2.0 (A5720) - DecryptKATCASTOn demandManually
AES-XTS Testing Revision 2.0 (A5729) - DecryptKATCASTOn demandManually

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 67
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-CMAC (A5729)KATCASTOn demandManually
HMAC-SHA-1 (A5720)KATCASTOn demandManually
HMAC-SHA-1 (A5734)KATCASTOn demandManually
HMAC-SHA-1 (A5735)KATCASTOn demandManually
HMAC-SHA-1 (A5736)KATCASTOn demandManually
HMAC-SHA2- 224 (A5720)KATCASTOn demandManually
HMAC-SHA2- 224 (A5734)KATCASTOn demandManually
HMAC-SHA2- 224 (A5735)KATCASTOn demandManually
HMAC-SHA2- 224 (A5736)KATCASTOn demandManually
HMAC-SHA2- 256 (A5720)KATCASTOn demandManually
HMAC-SHA2- 256 (A5734)KATCASTOn demandManually
HMAC-SHA2- 256 (A5735)KATCASTOn demandManually
HMAC-SHA2- 256 (A5736)KATCASTOn demandManually
HMAC-SHA2- 384 (A5720)KATCASTOn demandManually
HMAC-SHA2- 384 (A5734)KATCASTOn demandManually
HMAC-SHA2- 384 (A5735)KATCASTOn demandManually
HMAC-SHA2- 384 (A5736)KATCASTOn demandManually
HMAC-SHA2- 512 (A5720)KATCASTOn demandManually
HMAC-SHA2- 512 (A5734)KATCASTOn demandManually
HMAC-SHA2- 512 (A5735)KATCASTOn demandManually
HMAC-SHA2- 512 (A5736)KATCASTOn demandManually
HMAC-SHA3- 224 (A5721)KATCASTOn demandManually
HMAC-SHA3- 256 (A5721)KATCASTOn demandManually
HMAC-SHA3- 384 (A5721)KATCASTOn demandManually
HMAC-SHA3- 512 (A5721)KATCASTOn demandManually

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 68
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
Counter DRBG (A5720)KATCASTOn demandManually
Counter DRBG (A5724)KATCASTOn demandManually
Counter DRBG (A5725)KATCASTOn demandManually
Counter DRBG (A5726)KATCASTOn demandManually
Counter DRBG (A5727)KATCASTOn demandManually
Counter DRBG (A5728)KATCASTOn demandManually
Counter DRBG (A5729)KATCASTOn demandManually
Counter DRBG (A5730)KATCASTOn demandManually
Counter DRBG (A5731)KATCASTOn demandManually
Hash DRBG (A5720)KATCASTOn demandManually
Hash DRBG (A5724)KATCASTOn demandManually
Hash DRBG (A5725)KATCASTOn demandManually
Hash DRBG (A5726)KATCASTOn demandManually
Hash DRBG (A5727)KATCASTOn demandManually
Hash DRBG (A5728)KATCASTOn demandManually
Hash DRBG (A5729)KATCASTOn demandManually
Hash DRBG (A5730)KATCASTOn demandManually
Hash DRBG (A5731)KATCASTOn demandManually
Hash DRBG (A5734)KATCASTOn demandManually
Hash DRBG (A5735)KATCASTOn demandManually
Hash DRBG (A5736)KATCASTOn demandManually
HMAC DRBG (A5720)KATCASTOn demandManually
HMAC DRBG (A5724)KATCASTOn demandManually
HMAC DRBG (A5725)KATCASTOn demandManually
HMAC DRBG (A5726)KATCASTOn demandManually

© 2025 Red Hat, Inc./ atsec information security corporation.

Page 69
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC DRBG (A5727)KATCASTOn demandManually
HMAC DRBG (A5728)KATCASTOn demandManually
HMAC DRBG (A5729)KATCASTOn demandManually
HMAC DRBG (A5730)KATCASTOn demandManually
HMAC DRBG (A5731)KATCASTOn demandManually
HMAC DRBG (A5734)KATCASTOn demandManually
HMAC DRBG (A5735)KATCASTOn demandManually
HMAC DRBG (A5736)KATCASTOn demandManually
RSA SigVer (FIPS186-5) (A5720)KATCASTOn demandManually
RSA SigVer (FIPS186-5) (A5734)KATCASTOn demandManually
RSA SigVer (FIPS186-5) (A5735)KATCASTOn demandManually
RSA SigVer (FIPS186-5) (A5736)KATCASTOn demandManually
Entropy Source RCT initializationRCTCASTOn demandManually
Entropy Source APT initializationAPTCASTOn demandManually
Entropy Source continuous RCTRCTCASTOn demandManually
Entropy Source continuous APTAPTCASTOn demandManually
NameDescriptionConditionsRecovery MethodIndicator
Error StateThe Linux kernel immediately stops executingAny self-test failureRestart of the moduleKernel Panic

Table 23: Conditional Periodic Information

10.4 Error States

Table 24: Error States © 2025 Red Hat, Inc./ atsec information security corporation.

Page 70

In the Error State, the output interface is inhibited, and the module accepts no more inputs or requests (as the module is no longer running).

10.5 Operator Initiation of Self-Tests

All self-tests, with the exception of the continuous health tests, can be invoked on demand by unloading and subsequently re-initializing the module. © 2025 Red Hat, Inc./ atsec information security corporation.

Page 71
11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

The module is distributed as a part of the Red Hat Enterprise Linux 8 (RHEL 8) package in the form of the kernel-4.18.0-477.72.1.el8_8, libkcapi-1.2.0-3.el8_8, and libkcapi-hmaccalc1.2.0-3.el8_8 RPM packages. The module can achieve the FIPS validated configuration as follows.

11.2 Administrator Guidance

After installation of the kernel-4.18.0-477.72.1.el8_8, libkcapi-1.2.0-3.el8_8, and libkcapihmaccalc-1.2.0-3.el8_8 RPM packages, the Crypto Officer must execute the “cat /proc/sys/crypto/fips_name” command. The Crypto Officer must ensure that the proper name is listed in the output as follows: Red Hat Enterprise Linux 8 - Kernel Cryptographic API Then, the Crypto Officer must execute the “cat /proc/sys/crypto/fips_version” and “rpm -q libkcapi” commands. These commands must output the following (one line per output): 4.18.0-477.72.1.el8_8.x86_64 libkcapi-1.2.0-3.el8_8.x86_64

11.3 Non-Administrator Guidance

There is no non-administrator guidance.

11.4 End of Life

As the module does not persistently store SSPs, secure sanitization of the module consists of unloading the module. This will zeroize all SSPs in volatile memory. Then, if desired, the kernel-4.18.0-477.72.1.el8_8, libkcapi-1.2.0-3.el8_8, and libkcapi-hmaccalc-1.2.0-3.el8_8 RPM packages can be uninstalled from the RHEL 8 system. © 2025 Red Hat, Inc./ atsec information security corporation.

Page 72
12 Mitigation of Other Attacks

The module does not offer mitigation of other attacks and therefore this Section is not applicable. © 2025 Red Hat, Inc./ atsec information security corporation.

Page 73

Appendix A. Glossary and Abbreviations

AESAdvanced Encryption Standard
APIApplication Programming Interface
CASTCryptographic Algorithm Self-Test
CAVPCryptographic Algorithm Validation Program
CBCCipher Block Chaining
CCMCounter with Cipher Block Chaining-Message Authentication Code
CFBCipher Feedback
CMACCipher-based Message Authentication Code
CMVPCryptographic Module Validation Program
CSPCritical Security Parameter
CTRCounter
DRBGDeterministic Random Bit Generator
ECBElectronic Code Book
FIPSFederal Information Processing Standards
GCMGalois Counter Mode
GMACGalois Counter Mode Message Authentication Code
HMACKeyed-Hash Message Authentication Code
IPsecInternet Protocol Security
KATKnown Answer Test
MACMessage Authentication Code
NISTNational Institute of Science and Technology
PAAProcessor Algorithm Acceleration
PKCSPublic-Key Cryptography Standards
RSARivest, Shamir, Addleman
SHASecure Hash Algorithm
SSPSensitive Security Parameter
XTSXEX-based Tweaked-codebook mode with cipher text Stealing © 2025 Red Hat, Inc./ atsec information security corporation.
Page 74
FIPS 140-3FIPS PUB 140-3 - Security Requirements For Cryptographic Modules March 2019 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-3.pdf
FIPS 140-3 IGImplementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program 10 October 2024 https://csrc.nist.gov/Projects/cryptographic-module-validation-program/fips- 140-3-ig-announcements
FIPS 180-4Secure Hash Standard (SHS) March 2012 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf
FIPS 186-5Digital Signature Standard (DSS) February 2023 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-5.pdf
FIPS 198-1The Keyed Hash Message Authentication Code (HMAC) July 2008 https://csrc.nist.gov/publications/fips/fips198-1/FIPS-198-1_final.pdf
FIPS 202SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions August 2015 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.202.pdf
PKCS#1Public Key Cryptography Standards (PKCS) #1: RSA Cryptography Specifications Version 2.1 February 2003 https://www.ietf.org/rfc/rfc3447.txt
SP 800-38ARecommendation for Block Cipher Modes of Operation Methods and Techniques December 2001 https://csrc.nist.gov/publications/nistpubs/800-38a/sp800-38a.pdf
SP 800-38BRecommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication May 2005 https://csrc.nist.gov/publications/nistpubs/800-38B/SP_800-38B.pdf
SP 800-38CRecommendation for Block Cipher Modes of Operation: the CCM Mode for Authentication and Confidentiality May 2004 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800- 38c.pdf
SP 800-38DRecommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC November 2007 https://csrc.nist.gov/publications/nistpubs/800-38D/SP-800-38D.pdf © 2025 Red Hat, Inc./ atsec information security corporation.
Page 75

SP 800-38E Recommendation for Block Cipher Modes of Operation: The XTS AES Mode for Confidentiality on Storage Devices January 2010 https://csrc.nist.gov/publications/nistpubs/800-38E/nist-sp-800-38E.pdf SP 800-90Ar1 Recommendation for Random Number Generation Using Deterministic Random Bit Generators June 2015 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90Ar1.pdf © 2025 Red Hat, Inc./ atsec information security corporation.