All modules
CMVP Validated Module · FIPS 140-3 Security Policy

NetApp StorageGRID Kernel Crypto API

Certificate#5097StandardFIPS 140-3Level1TypeSoftwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorNetApp, Inc.
Medium review priority  ·  exposes kernel crypto consumer  ·  Linux kernel upstream has published 3932 CVEs since this module's initial validation  ·  last validated 8 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date11/29/2030
CaveatWhen operated in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.
VendorNetApp, Inc.

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for NetApp StorageGRID Kernel Crypto API
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>update<br/>Recovery</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>IKEV<br/>IPSEC</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for NetApp StorageGRID Kernel Crypto API
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>update<br/>Recovery</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>IKEV<br/>IPSEC</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

NetApp, Inc. NetApp StorageGRID Kernel Crypto API Prepared by: atsec information security corporation

4516 Seton Center Pkwy, Suite 250

Austin, TX 78759 Document version: 1.1 www.atsec.com Last update: 2025-11-25

Page 2
Table of Contents
#SectionPage
Page 3

List of Tables Table 2: Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets) . 7 © 2025 NetApp, Inc., atsec information security.

Page 4

List of Figures © 2025 NetApp, Inc., atsec information security.

Page 5
SectionTitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication1
5Software/Firmware security1
6Operational environment1
7Physical securityN/A
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacksN/A
Overall Level1
1.1 Overview

This document is the non-proprietary FIPS 140-3 Security Policy for version kernel 6.1.129-1ntap1-amd64; libkcapi 1.4.0-1+ntap0 of the NetApp StorageGRID Kernel Cryptographic API module. It contains the security rules under which the module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for an overall Security Level 1 module. intact and including this notice.

1.2 Security Levels

Table 1: Security Levels © 2025 NetApp, Inc., atsec information security.

Page 6
2 Cryptographic Module Specification
2.1 Description

Purpose and Use: The NetApp StorageGRID Kernel Cryptographic API (hereafter referred to as “the module”) provides a C language application program interface (API) for use by other (kernel space and user space) processes that require cryptographic functionality. The module operates on a general-purpose computer as part of the Linux kernel. Its cryptographic functionality can be accessed using the Linux Kernel Crypto API. Module Type: Software Module Embodiment: MultiChipStand Cryptographic Boundary: The cryptographic boundary of the module is defined as the kernel binary, the libkcapi shared library, and the sha512hmac binary, which is used to verify the integrity of the software components. In addition, the cryptographic boundary contains the .hmac files which store the expected integrity values for each of the software components. The cryptographic boundary is indicated by the small bold border in Figure

  1. Tested Operational Environment’s Physical Perimeter (TOEPP): The TOEPP of the module is defined as the general-purpose computer on which the module is installed. It includes software in kernel and user space, as well as the PAA in the CPU. The TOEPP is indicated by the large thin border in Figure
  2. Figure 1: Block Diagram © 2025 NetApp, Inc., atsec information security.
Page 7
Package or File NameSoftware/ Firmware VersionFeaturesIntegrity Test
/boot/vmlinuz- 6.1.129-1-ntap1- amd64; /usr/bin/kcapi- hasher; /lib/x86_64- linux- gnu/libkcapi.so.1.4.0kernel 6.1.129-1- ntap1-amd64; libkcapi 1.4.0- 1+ntap0N/AHMAC-SHA2-256 (libkcapi.so); HMAC- SHA2-512 (vmlinuz, kcapi-hasher)
Operating SystemHardware PlatformProcessorsPAA/PAIHypervisor or Host OSVersion(s)
StorageGRID 12SG5812Intel Xeon D- 1735TRYeskernel 6.1.129-1- ntap1-amd64; libkcapi 1.4.0- 1+ntap0
StorageGRID 12SG5812Intel Xeon D- 1735TRNokernel 6.1.129-1- ntap1-amd64; libkcapi 1.4.0- 1+ntap0
StorageGRID 12SG6160Intel Xeon Gold 5318YYeskernel 6.1.129-1- ntap1-amd64; libkcapi 1.4.0- 1+ntap0
StorageGRID 12SG6160Intel Xeon Gold 5318YNokernel 6.1.129-1- ntap1-amd64; libkcapi 1.4.0- 1+ntap0
StorageGRID 12SG110Intel Xeon Silver 4310Yeskernel 6.1.129-1- ntap1-amd64; libkcapi 1.4.0- 1+ntap0
StorageGRID 12SG110Intel Xeon Silver 4310Nokernel 6.1.129-1- ntap1-amd64; libkcapi 1.4.0- 1+ntap0

2.2 Tested and Vendor Affirmed Module Version and

Identification Tested Module Identification

Page 8
OperatingHardware
SystemPlatform
StorageGRID 12SGF6112
StorageGRID 12SG1100
StorageGRID 12SG5860
Mode NameDescriptionTypeStatus Indicator
Approved modeAutomatically entered whenever an approved service is requestedApprovedMapped to approved service indicator in Section 4.3 for all approved algorithms except GCM: respective approved service function returns indicator 0. For GCM: crypto_aead_get_flags(tfm) has the CRYPTO_TFM_FIPS_COMPLIANCE flag set
Non- approved modeAutomatically entered whenever a non- approved service is requestedNon- ApprovedNo service indicator required for non-approved services per IG 2.4.C
AlgorithmCAVP CertPropertiesReference
AES-CBCA6242, A6245, A6248, A6251Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A

Table 4: Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid CMVP makes no statement as to the correct operation of the module or the security strengths of the generated keys when so ported if the specific operational environment is not listed on the validation certificate.

2.3 Excluded Components

There are no components excluded from the requirements of the FIPS 140-3 standard.

2.4 Modes of Operation

Modes List and Description: Table 5: Modes List and Description After passing all pre-operational self-tests and cryptographic algorithm self-tests executed on start-up, the module automatically transitions to the approved mode. No operator intervention is required to reach this point. Mode Change Instructions and Status: The module automatically switches between the approved and non-approved modes depending on the services requested by the operator. The status indicator of the mode of operation is equivalent to the indicator of the service that was © 2025 NetApp, Inc., atsec information security.

Page 9
AlgorithmCAVP CertPropertiesReference
AES-CBC-CS3A6242, A6245, A6248, A6251Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CCMA6242, A6245, A6251Key Length - 128, 192, 256SP 800-38C
AES-CFB128A6242, A6245, A6251Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CMACA6242, A6245, A6251Direction - Generation Key Length - 128, 192, 256SP 800-38B
AES-CTRA6242, A6245, A6248, A6251Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA6242, A6243, A6244, A6245, A6246, A6247, A6248, A6249, A6250, A6251, A6252, A6253, A6254, A6255, A6256, A6258, A6259, A6260, A6261, A6262, A6263Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-GCMA6242, A6244, A6245, A6247, A6248, A6250, A6251, A6253, A6254, A6256, A6258, A6260, A6261, A6263Direction - Decrypt, Encrypt IV Generation - External Key Length - 128, 192, 256SP 800-38D
AES-GCMA6243, A6246, A6249, A6252, A6255, A6259, A6262Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256SP 800-38D
AES-GMACA6242, A6245, A6248, A6251, A6254, A6258, A6261Direction - Decrypt, Encrypt IV Generation - External Key Length - 128, 192, 256SP 800-38D
AES-KWA6242, A6245, A6251Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-OFBA6242, A6245, A6251Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-XTS Testing Revision 2.0A6242, A6245, A6248, A6251, A6254, A6257, A6258, A6261Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38E
Counter DRBGA6242, A6243, A6244, A6245, A6246, A6247, A6248, A6249, A6250, A6251, A6252, A6253, A6254, A6255, A6256, A6258, A6259, A6260, A6261, A6262, A6263Prediction Resistance - No, Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
ECDSA KeyGen (FIPS186-5)A6242Curve - P-256, P-384 Secret Generation Mode - testing candidatesFIPS 186-5
Hash DRBGA6242, A6264, A6265, A6266, A6267Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
HMAC DRBGA6242, A6264, A6265, A6266, A6267Prediction Resistance - No, YesSP 800-90A Rev. 1

© 2025 NetApp, Inc., atsec information security.

Page 10
AlgorithmCAVP CertPropertiesReference
Mode - SHA-1, SHA2-256, SHA2-512
HMAC-SHA-1A6242, A6264, A6265, A6266, A6267Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 224A6242, A6264, A6265, A6266, A6267Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 256A6242, A6264, A6265, A6266, A6267Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 384A6242, A6264, A6265, A6266Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512A6242, A6264, A6265, A6266Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3- 224A6242Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3- 256A6242Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3- 384A6242Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3- 512A6242Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
KAS-ECC-SSC Sp800-56Ar3A6242Domain Parameter Generation Methods - P-256, P-384 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KAS-FFC-SSC Sp800-56Ar3A6242Domain Parameter Generation Methods - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192 Scheme - dhEphem - KAS Role - initiator, responderSP 800-56A Rev. 3
KDA OneStep SP800-56Cr2A6242Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224- 2048 Increment 8SP 800-56C Rev. 2
KDF SP800- 108A6242KDF Mode - Counter Supported Lengths - Supported Lengths: 112- 4096 Increment 8SP 800-108 Rev. 1
RSA SigVer (FIPS186-4)A6242Signature Type - PKCS 1.5 Modulo - 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186-5)A6242Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5FIPS 186-5
Safe Primes Key GenerationA6242Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192SP 800-56A Rev. 3

© 2025 NetApp, Inc., atsec information security.

Page 11
AlgorithmCAVP CertPropertiesReference
SHA-1A6242, A6264, A6265, A6266, A6267Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-224A6242, A6264, A6265, A6266, A6267Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-256A6242, A6264, A6265, A6266, A6267Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-384A6242, A6264, A6265, A6266Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-512A6242, A6264, A6265, A6266Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA3-224A6242Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 202
SHA3-256A6242Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 202
SHA3-384A6242Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 202
SHA3-512A6242Message Length - Message Length: 0-65536 Increment 8 Large Message Sizes - 1, 2FIPS 202
NamePropertiesImplementationReference
Asymmetric CKGKey Type:AsymmetricN/ASP 800-133r2, section 4, example 1
NameUse and Function
AES-GCM with external IVEncryption with external IV (not compliant to FIPS 140- 3 IG C.H)
KBKDF in libkcapiKey Derivation with implementation not tested by CAVP

Table 6: Approved Algorithms Vendor-Affirmed Algorithms: Table 7: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: N/A for this module. Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. Non-Approved, Not Allowed Algorithms: © 2025 NetApp, Inc., atsec information security.

Page 12
NameUse and Function
HKDF in libkcapiKey Derivation with implementation not tested by CAVP
PBKDF2 in libkcapiPassword-Based Key Derivation with implementation not tested by CAVP
RSA PKCS#1 v1.5 with pre- hashed messageSignature generation / verification
RSA PKCS#1 v1.5Key encapsulation / un-encapsulation (not compliant to SP 800-56Br2)
RSA primitiveEncryption / decryption (not compliant to SP 800-56Br2)
NameTypeDescriptionPropertiesAlgorithms
EncryptionBC-UnAuthEncrypt a plaintextAES-CBC: (A6242, A6245, A6248, A6251) AES-CBC- CS3: (A6242, A6245, A6248, A6251) AES-CFB128: (A6242, A6245, A6251) AES-CTR: (A6242, A6245, A6248, A6251) AES-ECB: (A6242, A6243, A6244, A6245, A6246, A6247, A6248, A6249, A6250, A6251, A6252, A6253, A6254, A6255, A6256, A6258, A6259, A6260,

Table 8: Non-Approved, Not Allowed Algorithms

2.6 Security Function Implementations

© 2025 NetApp, Inc., atsec information security.

Page 13
NameTypeDescriptionPropertiesAlgorithms
A6261, A6262, A6263) AES-OFB: (A6242, A6245, A6251) AES-XTS Testing Revision 2.0: (A6242, A6245, A6248, A6251, A6254, A6257, A6258, A6261)
DecryptionBC-UnAuthDecrypt a ciphertextAES-CBC: (A6242, A6245, A6248, A6251) AES-CBC- CS3: (A6242, A6245, A6248, A6251) AES-CFB128: (A6242, A6245, A6251) AES-CTR: (A6242, A6245, A6248, A6251) AES-ECB: (A6242, A6243, A6244, A6245, A6246, A6247, A6248, A6249, A6250, A6251, A6252, A6253, A6254, A6255, A6256,

© 2025 NetApp, Inc., atsec information security.

Page 14
NameTypeDescriptionPropertiesAlgorithms
A6258, A6259, A6260, A6261, A6262, A6263) AES-OFB: (A6242, A6245, A6251) AES-XTS Testing Revision 2.0: (A6242, A6245, A6248, A6251, A6254, A6257, A6258, A6261)
Authenticated encryptionBC-AuthEncrypt and authenticate a plaintextAES-CCM: (A6242, A6245, A6251) AES-GCM: (A6242, A6243, A6244, A6245, A6246, A6247, A6248, A6249, A6250, A6251, A6252, A6253, A6254, A6255, A6256, A6258, A6259, A6260, A6261, A6262, A6263) AES-KW: (A6242, A6245, A6251)

© 2025 NetApp, Inc., atsec information security.

Page 15
NameTypeDescriptionPropertiesAlgorithms
Authenticated decryptionBC-AuthDecrypt and authenticate a ciphertextAES-CCM: (A6242, A6245, A6251) AES-GCM: (A6242, A6243, A6244, A6245, A6246, A6247, A6248, A6249, A6250, A6251, A6252, A6253, A6254, A6255, A6256, A6258, A6259, A6260, A6261, A6262, A6263) AES-KW: (A6242, A6245, A6251)
Message digestSHACompute a message digestSHA-1: (A6242, A6264, A6265, A6266, A6267) SHA2-224: (A6242, A6264, A6265, A6266, A6267) SHA2-256: (A6242, A6264, A6265, A6266, A6267) SHA2-384: (A6242, A6264, A6265, A6266)

© 2025 NetApp, Inc., atsec information security.

Page 16
NameTypeDescriptionPropertiesAlgorithms
SHA2-512: (A6242, A6264, A6265, A6266) SHA3-224: (A6242) SHA3-256: (A6242) SHA3-384: (A6242) SHA3-512: (A6242)
Message authentication code generationMACCompute a MAC tagAES-CMAC: (A6242, A6245, A6251) AES-GMAC: (A6242, A6245, A6248, A6251, A6254, A6258, A6261) HMAC-SHA-1: (A6242, A6264, A6265, A6266, A6267) HMAC-SHA2- 224: (A6242, A6264, A6265, A6266, A6267) HMAC-SHA2- 256: (A6242, A6264, A6265, A6266, A6267) HMAC-SHA2- 384: (A6242, A6264, A6265, A6266) HMAC-SHA2- 512: (A6242, A6264, A6265, A6266)

© 2025 NetApp, Inc., atsec information security.

Page 17
NameTypeDescriptionPropertiesAlgorithms
HMAC-SHA3- 224: (A6242) HMAC-SHA3- 256: (A6242) HMAC-SHA3- 384: (A6242) HMAC-SHA3- 512: (A6242)
Message authentication code verificationMACVerify a MAC tagAES-GMAC: (A6242, A6245, A6248, A6251, A6254, A6258, A6261)
Key-based key derivationKBKDFDerive keying material from a key- derivation keyKDF SP800- 108: (A6242)
Key- establishment key derivationKAS-56CKDFDerive keying material from a shared secretKDA OneStep SP800-56Cr2: (A6242)
Random number generationDRBGGenerate random bytesCounter DRBG: (A6242, A6243, A6244, A6245, A6246, A6247, A6248, A6249, A6250, A6251, A6252, A6253, A6254, A6255, A6256, A6258, A6259, A6260, A6261, A6262, A6263) Hash DRBG: (A6242, A6264, A6265, A6266,

© 2025 NetApp, Inc., atsec information security.

Page 18
NameTypeDescriptionPropertiesAlgorithms
A6267) HMAC DRBG: (A6242, A6264, A6265, A6266, A6267)
Shared secret computationKAS-SSCCompute a shared secretFFC security strength:112- 200 bits ECC security strength:128, 192 bits FFC scheme:dhEphem ECC scheme:ephemeralUnified KAS role:initiator, responder Compliance:FIPS 140-3 IG D.F Scenario 2(1)KAS-FFC-SSC Sp800-56Ar3: (A6242) KAS-ECC-SSC Sp800-56Ar3: (A6242)
Digital signature verificationDigSig-SigVerVerify a digital signature on a messageRSA SigVer (FIPS186-4): (A6242) RSA SigVer (FIPS186-5): (A6242)
Key pair generationAsymKeyPair- KeyGen CKGGenerate an asymmetric key pairSafe Primes Key Generation: (A6242) ECDSA KeyGen (FIPS186-5): (A6242) Asymmetric CKG: () Key Type: Asymmetric

Table 9: Security Function Implementations

2.7 Algorithm Specific Information
2.7.1 AES-GCM IV

The module implements AES-GCM IV generation in the context of IPsec, TLS 1.2, and TLS 1.3, compliant with RFC 4106, RFC 5288, and RFC 8446 respectively. These methods fall under Scenario 1 (“TLS/DTLS 1.2 protocol IV generation” and “IPsec-v3 protocol IV generation”) and Scenario 5 (“Provisions of an industry protocol supporting AES-GCM encryption, not included among the acceptable protocols in scenario 1”) of FIPS 140-3 IG C.H. The module is also compliant with SP 800-52r2 Section 3.3.1. IVs generated using these mechanisms may only be used in the context of AES-GCM encryption within their respective protocols. © 2025 NetApp, Inc., atsec information security.

Page 19

The module does not implement IPsec. The module’s implementation of AES-GCM is used together with an application that runs outside the module’s cryptographic boundary. This application must use RFC 7296 compliant IKEv2 to establish the shared secret SKEYSEED from which the AES-GCM encryption keys are derived. The design of the IPsec protocol implicitly ensures that the counter (the nonce_explicit part of the IV) does not exhaust the maximum number of possible values for a given session key. In the event the module’s power is lost and restored, the consuming application must ensure that a new key for use with the AES-GCM key encryption or decryption under this scenario shall be established. The module does not implement TLS. The module’s implementation of AES-GCM is used together with an application that runs outside the module’s cryptographic boundary. This application must use RFC 5288 (TLS 1.2) or RFC 8446 (TLS 1.3) to establish the cryptographic keys and initial values of the initialization vectors. For both TLS 1.2 and TLS 1.3, the nonce_explicit part of the IV does not exhaust the maximum number of possible values for a given session key. The design of the TLS protocol implicitly ensures that the nonce_explicit, or counter portion of the IV does not exhaust the maximum number of possible values for a given encryption key. In the event the module’s power is lost and restored, the consuming application must ensure that a new key for use with the AES-GCM key encryption or decryption under this scenario shall be established. Finally, the module also provides a non-approved AES-GCM encryption service which accepts arbitrary external IVs from the operator. This service can be requested by invoking the crypto_aead_encrypt API function with an AES-GCM handle. When this is the case, the API will not set an approved service indicator, as described in this document.

2.7.2 AES XTS

The length of a single data unit encrypted or decrypted with AES-XTS shall not exceed 220 AES blocks, that is 16MB, of data per XTS instance. An XTS instance is defined in Section 4 of SP 800-38E. The XTS mode shall only be used for the cryptographic protection of data on storage devices. It shall not be used for other purposes, such as the encryption of data in transit. To meet the requirement stated in IG C.I, the module implements a check to ensure that the two AES keys used in AES XTS mode are not identical. As the module does not implement symmetric key generation, this check is performed when the keys are input by the operator. Key_1 and Key_2 shall be generated and/or established independently according to the rules for component symmetric keys from NIST SP 800-133r2, Section 6.3.

2.7.3 RSA

All supported modulus sizes for RSA signature verification have been CAVP tested.

2.7.4 SP 800-56Ar3 Assurances

The module does not establish SSPs using an approved key agreement scheme (KAS). However, it does offer some or all of the underlying KAS cryptographic functionality to be used by an external operator/application as part of an approved KAS. To comply with the assurances found in Section 5.6.2 of SP 800-56Ar3, the operator must use the Diffie-Hellman and Elliptic Curve Diffie-Hellman shared secret computation algorithms with the NVMe and Bluetooth related protocols. Additionally, the module’s approved key pair generation service must be used to generate ephemeral Diffie-Hellman or EC Diffie-Hellman key pairs, or the key pairs must be obtained from another FIPS-validated module. As part of © 2025 NetApp, Inc., atsec information security.

Page 20
CertVendor
NumberName
E223NetApp, Inc.
NameTypeOperational EnvironmentSample SizeEntropy per SampleConditioning Component
NetApp StorageGRID Kernel CPU Time Jitter RNG Entropy SourceNon- PhysicalSee Table 3256 bitsSHA3-256 (A6242)

this service, the module will internally perform the full public key validation of the generated public key. The module’s shared secret computation service will internally perform the full public key validation of the peer DH public key, and the partial public key validation of the peer EC public key, complying with Section 5.6.2.2.2 of SP 800-56Ar3.

2.7.5 Legacy Use

Digital signature verification using SHA-1 is allowed for legacy use only. Digital signature generation using SHA-1 is non-approved and not allowed in approved services. These legacy algorithms can only be used on data that was generated prior to the Legacy Date specified in FIPS 140-3 IG C.M.

2.8 RBG and Entropy

Table 10: Entropy Certificates Table 11: Entropy Sources The module implements three different Deterministic Random Bit Generator (DRBG) implementations based on SP 800-90Ar1: Counter DRBG, Hash DRBG, and HMAC DRBG. Each of these DRBG implementations can be instantiated by the operator of the module, using the parameters listed specified in the Security Function Implementations table. When instantiated, these DRBGs can be used to generate random numbers for external usage. Additionally, the module employs a specific HMAC-SHA-512 DRBG implementation for internal purposes (e.g. to generate asymmetric key pairs). The module complies with the Public Use Document for ESV certificate E223 by reading entropy data from the jent_kcapi_random() function, which corresponds to the GetEntropy() conceptual interface. This function outputs 256 bits of full entropy. The HMAC-SHA-512 DRBG is instantiated with a 384-bit entropy input and reseeded with a 256-bits long entropy input. Outputs of multiple GetEntropy() calls are concatenated to receive the entropy input length greater than 256 bits. The output is truncated to get the entropy input string which is not a multiple of 256. The operational environment on the ESV certificate is identical to the operating system described in this document, and the entropy source is implemented inside the cryptographic boundary. Thus, the module is compliant with scenario 1 of IG 9.3.A. There are no maintenance requirements for the entropy source. © 2025 NetApp, Inc., atsec information security.

Page 21
2.9 Key Generation

The module implements asymmetric key pair generation compliant with SP 800-133r2. When random values are required, they are directly obtained as output from the SP 800-90Ar1 approved DRBG, compliant with Section 4 of SP 800-133r2 (without XOR). The following methods are implemented:

2.10 Key Establishment

The module implements shared secret computation methods as listed in the Security Function Implementations table in Section 2.6.

2.11 Industry Protocols

AES-GCM with internal IV generation in the approved mode is compliant with RFC 4106, RFC 5288, and RFC 8446 and shall only be used in conjunction with the IPsec, TLS 1.2, or TLS 1.3, protocols. Diffie-Hellman and EC Diffie-Hellman shall only be used with the NVMe and Bluetooth related protocols. No other parts of the NVMe, Bluetooth, IPsec, or TLS protocols, other than those mentioned above, have been tested by the CAVP and CMVP. © 2025 NetApp, Inc., atsec information security.

Page 22
Physical PortLogical Interface(s)Data That Passes
N/AData InputAPI data input parameters, AF_ALG type input sockets, SOL_TLS type input sockets
N/AData OutputAPI data output parameters, AF_ALG type output sockets, SOL_TLS type output sockets, /proc/sys/crypto virtual files
N/AControl InputAPI function calls, API control input parameters, AF_ALG type input sockets, SOL_TLS type input sockets
N/AStatus OutputAPI return values, AF_ALG type output sockets, SOL_TLS type output sockets, kernel logs
3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

Table 12: Ports and Interfaces The logical interfaces are the APIs through which the applications request services. These logical interfaces are logically separated from each other by the API design, AF_ALG type socket message types, and SOL_TLS socket types. The module does not implement a control © 2025 NetApp, Inc., atsec information security.

Page 23
NameTypeOperator TypeAuthentication Methods
Crypto OfficerRoleCrypto OfficerNone
NameDescrip tionIndicatorInputsOutput sSecurity Functio nsSSP Access
Encryptio nEncrypt a plaintextcrypto_skcipher_setkey returns 0AES key, plaintex t, IV (if require d)Ciphert extEncryptio nCrypto Officer - AES key: W,E
Decryptio nDecrypt a cipherte xtcrypto_skcipher_setkey returns 0AES key, ciphert ext, IV (if require d)Plaintex tDecryptio nCrypto Officer - AES key: W,E
Authentic ated encryptio nEncrypt a plaintext in an authenti cated modeAES-GCM: crypto_aead_get_flags(t fm) has CRYPTO_ALG_FIPS140_ COMPLIANT set; Others: crypto_aead_setkey returns 0AES key, plaintex t, IV (CCM/G CM)Ciphert ext, MAC tag (CCM/G CM)Authentic ated encryptio nCrypto Officer - AES key: W,E
Authentic ated decryptio nDecrypt a cipherte xt in an authenti cated modecrypto_aead_setkey returns 0AES key, ciphert ext, IV (CCM/G CM), MAC tag (CCM/G CM)Plaintex t or failureAuthentic ated decryptio nCrypto Officer - AES key: W,E
4 Roles, Services, and Authentication

The module does not implement any authentication methods.

4.2 Roles

Table 13: Roles No support is provided for multiple concurrent operators.

4.3 Approved Services

d) d) © 2025 NetApp, Inc., atsec information security.

Page 24
NameDescrip tionIndicatorInputsOutput sSecurity Functio nsSSP Access
Message digestCompute a message digestcrypto_shash_init returns 0Messag eDigest valueMessage digestCrypto Officer
Message authentic ation code generatio nCompute a MAC tagcrypto_shash_init returns 0AES key or HMAC key, messag eMAC tagMessage authentic ation code generatio nCrypto Officer - AES key: W,E - HMAC key: W,E
Message authentic ation code verificati onVerify a MAC tagcrypto_shash_init returns 0AES key, messag e, MAC tagPass/failMessage authentic ation code verificati onCrypto Officer - AES key: W,E
Key- based key derivatio nDerive keying material from a key- derivatio n keycrypto_kdf108_ctr_gene rate returns 0Key- derivati on key, output lengthDerived keyKey- based key derivatio nCrypto Officer - Key- derivati on key: W,E - Derived key: G,R
Key- establish ment key derivatio nDerive keying material from a shared secretcrypto_kdf108_ctr_gene rate returns 0Shared secret, output lengthDerived keyKey- establish ment key derivatio nCrypto Officer - Shared secret: W,E - Derived key: G,R
Random number generatio nGenerate random bytescrypto_rng_get_bytes returns 0Output lengthRandom bytesRandom number generatio nCrypto Officer - Entropy input: G,E,Z - HMAC_D RBG Seed: G,E,Z - HMAC_D RBG internal state (V, Key): G,W,E

G,E,Z G,E,Z G,W,E © 2025 NetApp, Inc., atsec information security.

Page 25
NameDescrip tionIndicatorInputsOutput sSecurity Functio nsSSP Access - Hash_D RBG Seed: G,E,Z - Hash_D RBG internal state (V, C): G,W,E - CTR_DR BG Seed: G,E,Z - CTR_DR BG internal state (V, Key): G,W,E
Shared secret computat ionCompute a shared secretcrypto_kpp_compute_s hared_secret returns 0Owner private key, peer public keyShared secretShared secret computat ionCrypto Officer - DH private key: W,E - DH public key: W,E - EC private key: W,E - EC public key: W,E - Shared secret: G,R
Key pair generatio nGenerate a key paircrypto_kpp_set_secret and crypto_kpp_generate_p ublic_key return 0Group or curveKey pairKey pair generatio nCrypto Officer - DH private key: G,R - DH public key: G,R - EC private

G,E,Z C): G,W,E G,E,Z G,W,E G,R © 2025 NetApp, Inc., atsec information security.

Page 26
NameDescrip tionIndicatorInputsOutput sSecurity Functio nsSSP Access key: G,R - EC public key: G,R - Interme diate key generati on value: G,E,Z
Kernel TLS encryptio nPerform TLS bulk data encrypti onAES-GCM: crypto_aead_get_flags( aead) has CRYPTO_ALG_FIPS140_ COMPLIANT set; Others: setsockopt for SOL_TLS returns 0AES key, plaintex tEncrypt ed TLS recordAuthentic ated encryptio nCrypto Officer - AES key: W,E
Kernel TLS decryptio nPerform TLS bulk data decrypti onsetsockopt for SOL_TLS returns 0AES key, encrypt ed TLS recordPlaintex t or failureAuthentic ated decryptio nCrypto Officer - AES key: W,E
Error detection codeCompute an EDC (crc32, crc32c, crct10dif )NoneMessag eEDCNoneCrypto Officer
Compres sionCompres s data (deflate, lz4, lz4hc, lzo, zlib- deflate, zstd)NoneDataCompre ssed dataNoneCrypto Officer
Generic system callUse the kernel to perform various non- cryptogr aphic operatio nsNoneIdentifi er, various argume ntsVarious return valuesNoneCrypto Officer
Show versionReturn the moduleNoneN/AModule nameNoneCrypto Officer

G,E,Z ) © 2025 NetApp, Inc., atsec information security.

Page 27
NameDescrip tion name and version informati onIndicatorInputsOutput s and versionSecurity Functio nsSSP Access
Show statusReturn the module statusNoneN/AModule statusNoneCrypto Officer
Self-testPerform the CASTs and integrity testsNoneN/APass/Fai lEncryptio n Decryptio n Authentic ated encryptio n Authentic ated decryptio n Message digest Message authentic ation code verificati on Message authentic ation code generatio n Key- based key derivatio n Key- establish ment key derivatio n Random number generatio n Shared secretCrypto Officer

n n n n n n © 2025 NetApp, Inc., atsec information security.

Page 28
NameDescrip tionIndicatorInputsOutput sSecurity Functio nsSSP Access
computat ion Digital signature verificati on Key pair generatio n
Zeroizati onZeroize all SSPsNoneAny SSPN/ANoneCrypto Officer - AES key: Z - HMAC key: Z - Key- derivati on key: Z - Shared secret: Z - Derived key: Z - Entropy input: Z - HMAC_D RBG Seed: Z - HMAC_D RBG internal state (V, Key): Z - Hash_D RBG Seed: Z - Hash_D RBG internal state (V, C): Z - CTR_DR BG

n Z Z C): Z © 2025 NetApp, Inc., atsec information security.

Page 29

Name

Descrip tion

Indicator

Inputs

Output s

Security Functio ns

SSP Access Seed: Z - CTR_DR BG internal state (V, Key): Z - DH public key: Z - DH private key: Z - EC public key: Z - EC private key: Z - Interme diate key generati on value: Z

NameDescriptionAlgorithmsRole
AES-GCM with external IV encryptionEncrypt and authenticate a plaintext using AES-GCM with an external IVAES-GCM with external IVCrypto Officer
Key derivation (libkcapi)Derive a key from a key- derivation key, shared secret, or passwordKBKDF in libkcapi HKDF in libkcapi PBKDF2 in libkcapiCrypto Officer
Pre-hashed message signature generationGenerate a digital signature for a pre-hashed messageRSA PKCS#1 v1.5 with pre-hashed messageCrypto Officer

Table 14: Approved Services The following convention is used to specify access rights to SSPs:

4.4 Non-Approved Services

© 2025 NetApp, Inc., atsec information security.

Page 30
NameDescriptionAlgorithmsRole
Pre-hashed message signature verificationVerify a digital signature for a pre-hashed messageRSA PKCS#1 v1.5 with pre-hashed messageCrypto Officer
Key encapsulationKey encapsulation using RSA PKCS#1 v1.5RSA PKCS#1 v1.5Crypto Officer
Key un-encapsulationKey un-encapsulation using RSA PKCS#1 v1.5RSA PKCS#1 v1.5Crypto Officer
Encryption primitiveCompute the RSA encryption primitiveRSA primitiveCrypto Officer
Decryption primitiveCompute the RSA decryption primitiveRSA primitiveCrypto Officer

Table 15: Non-Approved Services

4.5 External Software/Firmware Loaded

The module does not load external software or firmware. © 2025 NetApp, Inc., atsec information security.

Page 31
5 Software/Firmware Security
5.1 Integrity Techniques

On system boot, the sha512hmac binary first performs an integrity test on itself and the libkcapi library, using the HMAC-SHA2-512 and HMAC-SHA2-256 algorithms (respectively) implemented by the module. Then, the sha512hmac binary performs an integrity test on the kernel binary using the HMAC-SHA2-512 algorithm. These tests are all performed using a key hardcoded in the sha512hmac binary, by recomputing the MAC tags and verifying they are equal to the MAC tags specified in the .hmac file.

5.2 Initiate on Demand

Integrity tests are performed as part of the pre-operational self-tests, which are executed when the module is initialized. The integrity tests can be invoked on demand by unloading and subsequently re-initializing the module (i.e. rebooting the system), which will perform (among others) the software integrity tests. © 2025 NetApp, Inc., atsec information security.

Page 32
6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Modifiable How Requirements are Satisfied: The operating system provides process isolation and memory protection mechanisms that ensure appropriate separation for memory access among the processes on the system. Each process has control over its own data and uncontrolled access to the data of other processes is prevented.

6.2 Configuration Settings and Restrictions

The module shall be installed as stated in Section 11. Instrumentation tools like the ptrace system call, gdb and strace, user space live patching, as well as other tracing mechanisms offered by the Linux environment such as ftrace or systemtap, shall not be used in the operational environment. The use of any of these tools implies that the cryptographic module is running in a non-validated operational environment. © 2025 NetApp, Inc., atsec information security.

Page 33
7 Physical Security

The module is comprised of software only and therefore this section is not applicable. © 2025 NetApp, Inc., atsec information security.

Page 34
8 Non-Invasive Security

This module does not implement any non-invasive security mechanism and therefore this section is not applicable. © 2025 NetApp, Inc., atsec information security.

Page 35
Storage Area NameDescriptionPersistence Type
RAMTemporary storage for SSPs used by the module as part of service executionDynamic
NameFromToFormat TypeDistribution TypeEntry TypeSFI or Algorithm
API input parametersOperator calling application TOEPPRAMPlaintextManualElectronic
AF_ALG type input socketsOperator calling application TOEPPRAMPlaintextManualElectronic
SOL_TLS type input socketsOperator calling application TOEPPRAMPlaintextManualElectronic
API output parametersRAMOperator calling application TOEPPPlaintextManualElectronic
AF_ALG type output socketsRAMOperator calling application TOEPPPlaintextManualElectronic
Zeroization MethodDescriptionRationaleOperator Initiation
Free cipher handleZeroizes the SSPs contained within the cipher handleMemory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable.By calling the appropriate zeroization functions: AES key: crypto_free_skcipher and crypto_free_aead; HMAC key: crypto_free_shash and
9 Sensitive Security Parameters Management
9.1 Storage Areas

Table 16: Storage Areas The module does not perform persistent storage of SSPs. The SSPs are temporarily stored in destroyed when released by the appropriate zeroization function calls. Table 17: SSP Input-Output Methods © 2025 NetApp, Inc., atsec information security.

Page 36
Zeroization MethodDescriptionRationale The completion of the zeroization routine indicates that the zeroization procedure succeeded.Operator Initiation crypto_free_ahash; Key- derivation key: crypto_free_shash; Shared secret: crypto_free_shash; Entropy input: crypto_free_rng; DRBG seed: crypto_free_rng; DRBG internal state: crypto_free_rng; DH public key & DH private key: crypto_free_kpp; EC public key & EC private key: crypto_free_kpp; RSA public key: public_key_free
Remove power from the moduleDe-allocates the volatile memory used to store SSPsVolatile memory used by the module is overwritten within nanoseconds when power is removed. Module power off indicates that the zeroization procedure succeeded.By removing power
AutomaticAutomatically zeroized by the module when no longer neededMemory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable.N/A
NameDescripti onSize - Strengt hType - CategoryGenerated ByEstablish ed ByUsed By
AES keySymmetric key used for AES operations128, 256 bits (AES- XTS); 128, 192, 256 bits (others) - 128, 256 bits (AES- XTS); 128, 192, 256Symmetric key - CSPEncryption Decryption Authenticat ed encryption Authenticat ed decryption Message authenticati on code verification Message authenticati

Table 18: SSP Zeroization Methods All data output is inhibited during zeroization. h © 2025 NetApp, Inc., atsec information security.

Page 37
NameDescripti onSize - Strengt hType - CategoryGenerated ByEstablish ed ByUsed By
bits (others)on code generation
HMAC keySymmetric key used for HMAC operations112- 524288 bits - 112-256 bitsAuthenticati on key - CSPMessage authenticati on code verification Message authenticati on code generation
Key- derivation keySymmetric key used in performin g key derivation112- 4096 bits - 112-256 bitsSymmetric key - CSPKey-based key derivation
Shared secretShared secret generated by (EC) Diffie- HellmanP-256, P- 384 / ffdhe204 8, ffdhe307 2, ffdhe409 6, ffdhe614 4, ffdhe819 2 - 128- 8192 bitsShared secret - CSPShared secret computati onKey- establishme nt key derivation
Derived keySymmetric key produced by a key derivation service.112- 4096 - 112-256Symmetric key - CSPKey-based key derivation Key- establishm ent key derivation
Entropy inputEntropy input used to seed DRBGs128-384 bits - 128-384 bitsEntropy input - CSPRandom number generationRandom number generation
HMAC_DR BG SeedDRBG seed derived from entropy input and additional data440, 888 bits - 128, 256 bitsSeed - CSPRandom number generationRandom number generation

h 6, 4, © 2025 NetApp, Inc., atsec information security.

Page 38
NameDescripti onSize - Strengt hType - CategoryGenerated ByEstablish ed ByUsed By
CTR_DRBG SeedDRBG seed derived from Entropy Input and additional data256, 320, 384 bits - 128, 192, 256 bitsSeed - CSPRandom number generationRandom number generation
Hash_DRB G SeedDRBG seed derived from Entropy Input and additional data440, 888 bits - 128, 256 bitsSeed - CSPRandom number generationRandom number generation
HMAC_DR BG internal state (V, Key)Internal state of HMAC_DR BG320, 512, 1024 bits - 128, 256 bitsInternal state - CSPRandom number generationRandom number generation
CTR_DRBG internal state (V, Key)Internal state of CTR_DRBG256, 320, 348 bits - 128, 192, 256 bitsInternal state - CSPRandom number generationRandom number generation
Hash_DRB G internal state (V, C)Internal state of Hash_DRB G880, 1776 bits - 128, 256 bitsInternal state - CSPRandom number generationRandom number generation
DH private keyPrivate key used for Diffie- Hellmanffdhe204 8, ffdhe307 2, ffdhe409 6, ffdhe614 4, ffdhe819 2 - 112- 200 bitsPrivate key - CSPKey pair generationShared secret computatio n
DH public keyPublic key used for Diffie- Hellmanffdhe204 8, ffdhe307 2, ffdhe409 6,Public key - PSPKey pair generationShared secret computatio n

h 6, 4, 6, © 2025 NetApp, Inc., atsec information security.

Page 39
NameDescripti onSize - Strengt hType - CategoryGenerated ByEstablish ed ByUsed By
ffdhe614 4, ffdhe819 2 - 112- 200 bits
EC private keyPrivate key used for EC Diffie- HellmanP-256, P- 384 - 128, 192 bitsPrivate key - CSPKey pair generationShared secret computatio n
EC public keyPublic key used for EC Diffie- HellmanP-256, P- 384 - 128, 192 bitsPublic key - PSPKey pair generationShared secret computatio n
Intermedi ate key generatio n valueTemporar y value generated during key pair generatio n services256- 8192 bits - 112-200 bitsIntermediat e value - CSPKey pair generation
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
AES keyAPI input parameters AF_ALG type input sockets SOL_TLS type input socketsRAM:PlaintextUntil cipher handle is freed or module is powered offFree cipher handle Remove power from the module
HMAC keyAPI input parameters AF_ALG type input socketsRAM:PlaintextUntil cipher handle is freed or module is powered offFree cipher handle Remove power from the module
Key- derivation keyAPI input parameters AF_ALG type input socketsRAM:PlaintextUntil cipher handle is freed or module is powered offFree cipher handle Remove power from the module
Shared secretAPI input parameters API output parameters AF_ALG type inputRAM:PlaintextUntil cipher handle is freed or module is powered offFree cipher handle Remove power from the module

h 4, Table 19: SSP Table 1 © 2025 NetApp, Inc., atsec information security.

Page 40
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
sockets AF_ALG type output sockets
Derived keyAPI output parameters AF_ALG type output socketsRAM:PlaintextFor the duration of the serviceAutomaticKey-derivation key:Derived From Shared secret:Derived From
Entropy inputRAM:PlaintextFrom generation until DRBG seed/reseedAutomaticDRBG seed:Derivation Of
HMAC_DRBG SeedRAM:PlaintextFrom generation until HMAC_DRBG Seed is createdAutomaticEntropy input:Derived From DRBG internal state (V, Key):Derivation Of DRBG internal state (V, C):Derivation Of
CTR_DRBG SeedRAM:PlaintextFrom generation until DRBG seed is createdAutomaticEntropy input:Derived From
Hash_DRBG SeedRAM:PlaintextFrom generation until DRBG seed is createdAutomaticEntropy input:Derived From
HMAC_DRBG internal state (V, Key)RAM:PlaintextUntil cipher handle is freed or module is powered offFree cipher handle Remove power from the moduleHMAC_DRBG Seed:Derived From
CTR_DRBG internal state (V, Key)RAM:PlaintextUntil cipher handle is freed or module is powered offFree cipher handle Remove power from the moduleCTR_DRBG Seed:Derived From
Hash_DRBG internal state (V, C)RAM:PlaintextUntil cipher handle is freed or module is powered offFree cipher handle Remove power from the moduleHash_DRBG Seed:Derived From

© 2025 NetApp, Inc., atsec information security.

Page 41
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
DH private keyAPI input parameters API output parameters AF_ALG type input sockets AF_ALG type output socketsRAM:PlaintextUntil cipher handle is freed or module is powered offFree cipher handle Remove power from the moduleDH public key:Paired With
DH public keyAPI input parameters API output parameters AF_ALG type input sockets AF_ALG type output socketsRAM:PlaintextUntil cipher handle is freed or module is powered offFree cipher handle Remove power from the moduleDH private key:Paired With
EC private keyAPI input parameters API output parameters AF_ALG type input sockets AF_ALG type output socketsRAM:PlaintextUntil cipher handle is freed or module is powered offFree cipher handle Remove power from the moduleEC public key:Paired With
EC public keyAPI input parameters API output parameters AF_ALG type input sockets AF_ALG type output socketsRAM:PlaintextUntil cipher handle is freed or module is powered offFree cipher handle Remove power from the moduleEC private key:Paired With
Intermediate key generation valueRAM:PlaintextFor the duration of the serviceAutomatic
9.5 Transitions

The SHA-1 algorithm as implemented by the module will be non-approved for all purposes, starting January 1, 2031. © 2025 NetApp, Inc., atsec information security.

Page 42
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
HMAC-SHA2- 512 - kcapi- hasher128-bit keyMessage AuthenticationSW/FW IntegrityModule becomes operationalIntegrity test for kcapi- hasher binary
HMAC-SHA2- 256 - libkcapi256-bit keyMessage AuthenticationSW/FW IntegrityModule becomes operationalIntegrity test for libkcapi shared library
HMAC-SHA2- 512 - vmlinuz128-bit keyMessage AuthenticationSW/FW IntegrityModule becomes operationalIntegrity test for vmlinuz binary
Algorithm or TestTest Properti esTest Metho dTes t Typ eIndicatorDetailsCondition s
AES-CBC Encryption128, 192, 256-bit keysKATCAS TModule is operationalEncryptionModule initializatio n
AES-CBC Decryption128, 192, 256-bit keysKATCAS TModule is operationalDecryptionModule initializatio n
AES-CBC (AESNI_ASM) Encryption128, 192, 256-bit keysKATCAS TModule is operationalEncryptionModule initializatio n
AES-CBC (AESNI_ASM) Decryption128, 192, 256-bit keysKATCAS TModule is operationalDecryptionModule initializatio n
AES-CBC (AESNI_C) Encryption128, 192, 256-bit keysKATCAS TModule is operationalEncryptionModule initializatio n
AES-CBC (AESNI_C) Decryption128, 192, 256-bit keysKATCAS TModule is operationalDecryptionModule initializatio n
10 Self-Tests

While the module is executing the self-tests, services are not available, and data output (via the data output interface) is inhibited until the tests are successfully completed. The module does not return control to the calling application until the tests are completed. If any of the self-tests fails, the module immediately transitions to the error state.

10.1 Pre-Operational Self-Tests

Table 21: Pre-Operational Self-Tests The pre-operational software integrity tests are performed automatically when the module is powered on, before the module transitions into the operational state.

10.2 Conditional Self-Tests

e © 2025 NetApp, Inc., atsec information security.

Page 43
Algorithm or TestTest Properti esTest Metho dTes t Typ eIndicatorDetailsCondition s
AES-CBC-CS3 Encryption128, 192, 256-bit keysKATCAS TModule is operationalEncryptionModule initializatio n
AES-CBC-CS3 Decryption128, 192, 256-bit keysKATCAS TModule is operationalDecryptionModule initializatio n
AES-CBC-CS3 (AESNI_C) Encryption128, 192, 256-bit keysKATCAS TModule is operationalEncryptionModule initializatio n
AES-CBC-CS3 (AESNI_C) Decryption128, 192, 256-bit keysKATCAS TModule is operationalDecryptionModule initializatio n
AES-CCM Authenticated encryption128, 192, 256-bit keys; 56, 64, 72, 80, 88, 96, 112, 128- bit IVsKATCAS TModule is operationalAuthenticat ed encryptionModule initializatio n
AES-CCM Authenticated decryption128, 192, 256-bit keys; 56, 64, 72, 80, 88, 96, 112, 128- bit IVsKATCAS TModule is operationalAuthenticat ed decryptionModule initializatio n
AES-CCM (AESNI_C) Authenticated encryption128, 192, 256-bit keys; 56, 64, 72, 80, 88, 96, 112, 128- bit IVsKATCAS TModule is operationalAuthenticat ed encryptionModule initializatio n
AES-CCM (AESNI_C) Authenticated decryption128, 192, 256-bit keys; 56, 64, 72, 80, 88, 96, 112, 128- bit IVsKATCAS TModule is operationalAuthenticat ed decryptionModule initializatio n
AES-CFB128 Encryption128, 192, 256-bit keysKATCAS TModule is operationalEncryptionModule initializatio n
AES-CFB128 Decryption128, 192, 256-bit keysKATCAS TModule is operationalDecryptionModule initializatio n
AES-CFB128 (AESNI_C) Encryption128, 192, 256-bit keysKATCAS TModule is operationalEncryptionModule initializatio n

e © 2025 NetApp, Inc., atsec information security.

Page 44
Algorithm or TestTest Properti esTest Metho dTes t Typ eIndicatorDetailsCondition s
AES-CFB128 (AESNI_C) Decryption128, 192, 256-bit keysKATCAS TModule is operationalDecryptionModule initializatio n
AES-CTR Encryption128, 192, 256-bit keysKATCAS TModule is operationalEncryptionModule initializatio n
AES-CTR Decryption128, 192, 256-bit keysKATCAS TModule is operationalDecryptionModule initializatio n
AES-CTR (AESNI_ASM) Encryption128, 192, 256-bit keysKATCAS TModule is operationalEncryptionModule initializatio n
AES-CTR (AESNI_ASM) Decryption128, 192, 256-bit keysKATCAS TModule is operationalDecryptionModule initializatio n
AES-ECB Encryption128, 192, 256-bit keysKATCAS TModule is operationalEncryptionModule initializatio n
AES-ECB Decryption128, 192, 256-bit keysKATCAS TModule is operationalDecryptionModule initializatio n
AES-ECB (CTI_C) Encryption128, 192, 256-bit keysKATCAS TModule is operationalEncryptionModule initializatio n
AES-ECB (CTI_C) Decryption128, 192, 256-bit keysKATCAS TModule is operationalDecryptionModule initializatio n
AES-ECB (AESNI_ASM) Encryption128, 192, 256-bit keysKATCAS TModule is operationalEncryptionModule initializatio n
AES-ECB (AESNI_ASM) Decryption128, 192, 256-bit keysKATCAS TModule is operationalDecryptionModule initializatio n
AES-ECB (AESNI_C) Encryption128, 192, 256-bit keysKATCAS TModule is operationalEncryptionModule initializatio n
AES-ECB (AESNI_C) Decryption128, 192, 256-bit keysKATCAS TModule is operationalDecryptionModule initializatio n
AES-GCM Authenticated encryption128, 192, 256-bit keys; 96- bit IVsKATCAS TModule is operationalAuthenticat ed encryptionModule initializatio n
AES-GCM Authenticated decryption128, 192, 256-bit keys; 96- bit IVsKATCAS TModule is operationalAuthenticat ed decryptionModule initializatio n

e © 2025 NetApp, Inc., atsec information security.

Page 45
Algorithm or TestTest Properti esTest Metho dTes t Typ eIndicatorDetailsCondition s
AES-GCM (AESNI_ASM) Authenticated encryption128, 192, 256-bit keys; 96- bit IVsKATCAS TModule is operationalAuthenticat ed encryptionModule initializatio n
AES-GCM (AESNI_ASM) Authenticated decryption128, 192, 256-bit keys; 96- bit IVsKATCAS TModule is operationalAuthenticat ed decryptionModule initializatio n
AES-GCM (AESNI_AVX) Authenticated encryption128, 192, 256-bit keys; 96- bit IVsKATCAS TModule is operationalAuthenticat ed encryptionModule initializatio n
AES-GCM (AESNI_AVX) Authenticated decryption128, 192, 256-bit keys; 96- bit IVsKATCAS TModule is operationalAuthenticat ed decryptionModule initializatio n
AES-GCM (VAES_AVX10_2 56) Authenticated encryption128, 192, 256-bit keys; 96- bit IVsKATCAS TModule is operationalAuthenticat ed encryptionModule initializatio n
AES-GCM (VAES_AVX10_2 56) Authenticated decryption128, 192, 256-bit keys; 96- bit IVsKATCAS TModule is operationalAuthenticat ed decryptionModule initializatio n
AES-GCM (VAES_AVX10_5 12) Authenticated encryption128, 192, 256-bit keys; 96- bit IVsKATCAS TModule is operationalAuthenticat ed encryptionModule initializatio n
AES-GCM (VAES_AVX10_5 12) Authenticated decryption128, 192, 256-bit keys; 96- bit IVsKATCAS TModule is operationalAuthenticat ed decryptionModule initializatio n
AES-OFB Encryption128, 192, 256-bit keysKATCAS TModule is operationalEncryptionModule initializatio n
AES-OFB Decryption128, 192, 256-bit keysKATCAS TModule is operationalDecryptionModule initializatio n
AES-OFB (AESNI_C) Encryption128, 192, 256-bit keysKATCAS TModule is operationalEncryptionModule initializatio n
AES-OFB (AESNI_C) Decryption128, 192, 256-bit keysKATCAS TModule is operationalDecryptionModule initializatio n

e © 2025 NetApp, Inc., atsec information security.

Page 46
Algorithm or TestTest Properti esTest Metho dTes t Typ eIndicatorDetailsCondition s
AES-XTS Testing Revision 2.0 Encryption128, 256- bit keysKATCAS TModule is operationalEncryptionModule initializatio n
AES-XTS Testing Revision 2.0 Decryption128, 256- bit keysKATCAS TModule is operationalDecryptionModule initializatio n
AES-XTS Testing Revision 2.0 (AESNI_ASM) Encryption128, 256- bit keysKATCAS TModule is operationalEncryptionModule initializatio n
AES-XTS Testing Revision 2.0 (AESNI_ASM) Decryption128, 256- bit keysKATCAS TModule is operationalDecryptionModule initializatio n
AES-XTS Testing Revision 2.0 (AESNI_AVX) Encryption128, 256- bit keysKATCAS TModule is operationalEncryptionModule initializatio n
AES-XTS Testing Revision 2.0 (AESNI_AVX) Decryption128, 256- bit keysKATCAS TModule is operationalDecryptionModule initializatio n
AES-XTS Testing Revision 2.0 (VAES_AVX2) Encryption128, 256- bit keysKATCAS TModule is operationalEncryptionModule initializatio n
AES-XTS Testing Revision 2.0 (VAES_AVX2) Decryption128, 256- bit keysKATCAS TModule is operationalDecryptionModule initializatio n
AES-XTS Testing Revision 2.0 (VAES_AVX10_2 56) Encryption128, 256- bit keysKATCAS TModule is operationalEncryptionModule initializatio n
AES-XTS Testing Revision 2.0 (VAES_AVX10_2 56) Decryption128, 256- bit keysKATCAS TModule is operationalDecryptionModule initializatio n
AES-XTS Testing Revision 2.0 (VAES_AVX10_5 12) Encryption128, 256- bit keysKATCAS TModule is operationalEncryptionModule initializatio n
AES-XTS Testing Revision 2.0 (VAES_AVX10_5 12) Decryption128, 256- bit keysKATCAS TModule is operationalDecryptionModule initializatio n
SHA-10-65536- bit messagesKATCAS TModule is operationalMessage DigestModule initializatio n

e © 2025 NetApp, Inc., atsec information security.

Page 47
Algorithm or TestTest Properti esTest Metho dTes t Typ eIndicatorDetailsCondition s
SHA-1 (SSSE3)0-65536- bit messagesKATCAS TModule is operationalMessage DigestModule initializatio n
SHA-1 (AVX)0-65536- bit messagesKATCAS TModule is operationalMessage DigestModule initializatio n
SHA-1 (AVX2)0-65536- bit messagesKATCAS TModule is operationalMessage DigestModule initializatio n
SHA-1 (SHA_NI)0-65536- bit messagesKATCAS TModule is operationalMessage DigestModule initializatio n
SHA2-2240-65536- bit messagesKATCAS TModule is operationalMessage DigestModule initializatio n
SHA2-224 (SSSE3)0-65536- bit messagesKATCAS TModule is operationalMessage DigestModule initializatio n
SHA2-224 (AVX)0-65536- bit messagesKATCAS TModule is operationalMessage DigestModule initializatio n
SHA2-224 (AVX2)0-65536- bit messagesKATCAS TModule is operationalMessage DigestModule initializatio n
SHA2-224 (SHA_NI)0-65536- bit messagesKATCAS TModule is operationalMessage DigestModule initializatio n
SHA2-2560-65536- bit messagesKATCAS TModule is operationalMessage DigestModule initializatio n
SHA2-256 (SSSE3)0-65536- bit messagesKATCAS TModule is operationalMessage DigestModule initializatio n
SHA2-256 (AVX)0-65536- bit messagesKATCAS TModule is operationalMessage DigestModule initializatio n
SHA2-256 (AVX2)0-65536- bit messagesKATCAS TModule is operationalMessage DigestModule initializatio n
SHA2-256 (SHA_NI)0-65536- bit messagesKATCAS TModule is operationalMessage DigestModule initializatio n
SHA2-3840-65536- bit messagesKATCAS TModule is operationalMessage DigestModule initializatio n
SHA2-384 (SSSE3)0-65536- bit messagesKATCAS TModule is operationalMessage DigestModule initializatio n

e © 2025 NetApp, Inc., atsec information security.

Page 48
Algorithm or TestTest Properti esTest Metho dTes t Typ eIndicatorDetailsCondition s
SHA2-384 (AVX)0-65536- bit messagesKATCAS TModule is operationalMessage DigestModule initializatio n
SHA2-384 (AVX2)0-65536- bit messagesKATCAS TModule is operationalMessage DigestModule initializatio n
SHA2-5120-65536- bit messagesKATCAS TModule is operationalMessage DigestModule initializatio n
SHA2-512 (SSSE3)0-65536- bit messagesKATCAS TModule is operationalMessage DigestModule initializatio n
SHA2-512 (AVX)0-65536- bit messagesKATCAS TModule is operationalMessage DigestModule initializatio n
SHA2-512 (AVX2)0-65536- bit messagesKATCAS TModule is operationalMessage DigestModule initializatio n
SHA3-2240-65536- bit messagesKATCAS TModule is operationalMessage DigestModule initializatio n
SHA3-2560-65536- bit messagesKATCAS TModule is operationalMessage DigestModule initializatio n
SHA3-3840-65536- bit messagesKATCAS TModule is operationalMessage DigestModule initializatio n
SHA3-5120-65536- bit messagesKATCAS TModule is operationalMessage DigestModule initializatio n
AES-CMAC128, 192, 256-bit keysKATCAS TModule is operationalMessage Authenticati onModule initializatio n
AES-CMAC (AESNI_C)128, 192, 256-bit keysKATCAS TModule is operationalMessage Authenticati onModule initializatio n
HMAC-SHA-1112- 524288- bit keysKATCAS TModule is operationalMessage Authenticati onModule initializatio n
HMAC-SHA-1 (SHA_NI)112- 524288- bit keysKATCAS TModule is operationalMessage Authenticati onModule initializatio n
HMAC-SHA2- 224112- 524288- bit keysKATCAS TModule is operationalMessage Authenticati onModule initializatio n
HMAC-SHA2- 224 (SHA_NI)112- 524288- bit keysKATCAS TModule is operationalMessage Authenticati onModule initializatio n

e © 2025 NetApp, Inc., atsec information security.

Page 49
Algorithm or TestTest Properti esTest Metho dTes t Typ eIndicatorDetailsCondition s
HMAC-SHA2- 256112- 524288- bit keysKATCAS TModule is operationalMessage Authenticati onBefore integrity test
HMAC-SHA2- 256 (SHA_NI)112- 524288- bit keysKATCAS TModule is operationalMessage Authenticati onBefore integrity test
HMAC-SHA2- 384112- 524288- bit keysKATCAS TModule is operationalMessage Authenticati onModule initializatio n
HMAC-SHA2- 384 (AVX2)112- 524288- bit keysKATCAS TModule is operationalMessage Authenticati onModule initializatio n
HMAC-SHA2- 512112- 524288- bit keysKATCAS TModule is operationalMessage Authenticati onModule initializatio n
HMAC-SHA2- 512 (AVX2)112- 524288- bit keysKATCAS TModule is operationalMessage Authenticati onModule initializatio n
HMAC-SHA3- 224112- 524288- bit keysKATCAS TModule is operationalMessage Authenticati onModule initializatio n
HMAC-SHA3- 256112- 524288- bit keysKATCAS TModule is operationalMessage Authenticati onModule initializatio n
HMAC-SHA3- 384112- 524288- bit keysKATCAS TModule is operationalMessage Authenticati onModule initializatio n
HMAC-SHA3- 512112- 524288- bit keysKATCAS TModule is operationalMessage Authenticati onModule initializatio n
KDF SP800-108SHA2-256KATCAS TModule is operationalKey derivationModule initializatio n
KDA OneStep SP800-56Cr2SHA2-256KATCAS TModule is operationalKey derivationModule initializatio n
Counter DRBGAES-128, AES-192, and AES- 256 with/witho ut prediction resistanceKATCAS TModule is operationalInstantiate, seed, reseed, generate (compliant to SP 800- 90Ar1 Section 11.3)Module initializatio n
Hash DRBGSHA-1, SHA-256, and SHA- 512KATCAS TModule is operationalInstantiate, seed, reseed, generateModule initializatio n

e n n © 2025 NetApp, Inc., atsec information security.

Page 50
Algorithm or TestTest Properti es with/witho ut prediction resistanceTest Metho dTes t Typ eIndicatorDetails (compliant to SP 800- 90Ar1 Section 11.3)Condition s
HMAC DRBGSHA-1, SHA-256, and SHA- 512 with/witho ut prediction resistanceKATCAS TModule is operationalInstantiate, seed, reseed, generate (compliant to SP 800- 90Ar1 Section 11.3)Module initializatio n
KAS-FFC-SSC Sp800-56Ar3ffdhe2048 , ffdhe3072 , ffdhe4096 , ffdhe6144 , ffdhe8192KATCAS TModule is operationalShared secret computatio nModule initializatio n
KAS-ECC-SSC Sp800-56Ar3P-256, P- 384KATCAS TModule is operationalShared secret computatio nModule initializatio n
RSA SigVer (FIPS186-5)PKCS#1 v1.5 with SHA-224, SHA-256, SHA-384, SHA-512 and 2048, 3072, 4096-bit keysKATCAS TModule is operationalSignature verificationModule initializatio n
Entropy Source Start Up APTCutoff C = 325; Window size = 512APTCAS TEntropy source is operationalEntropy source start-up test on 1024 samplesEntropy source initializatio n
Entropy Source Start Up RCTCutoff C = 31RCTCAS TEntropy source is operationalEntropy source start-up test on 1024 samplesEntropy source initializatio n
Entropy Source Continuous APTPermanen t cutoff CAPTCAS Tjent_kcapi_rand om returns 0Entropy sourceContinuou sly as

e , n , , n © 2025 NetApp, Inc., atsec information security.

Page 51
Algorithm or TestTest Properti es = 355; Window size = 512Test Metho dTes t Typ eIndicatorDetails continuous testCondition s entropy is requested
Entropy Source Continuous RCTPermanen t cutoff C = 61RCTCAS Tjent_kcapi_rand om returns 0Entropy source continuous testContinuou sly as entropy is requested
Safe Primes Key Generationffdhe2048 , ffdhe3072 , ffdhe4096 , ffdhe6144 , ffdhe8192PCTPCTKey pair generation is successfulSP 800- 56Ar3 Section 5.6.2.1.4Key pair generation
ECDSA KeyGen (FIPS186-5)P-256, P- 384PCTPCTKey pair generation is successfulSP 800- 56Ar3 Section 5.6.2.1.4Key pair generation
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2- 512 - kcapi- hasherMessage AuthenticationSW/FW IntegrityOn demandManually
HMAC-SHA2- 256 - libkcapiMessage AuthenticationSW/FW IntegrityOn demandManually
HMAC-SHA2- 512 - vmlinuzMessage AuthenticationSW/FW IntegrityOn demandManually
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-CBC EncryptionKATCASTOn demandManually
AES-CBC DecryptionKATCASTOn demandManually

e , 5.6.2.1.4 , , 5.6.2.1.4 Table 22: Conditional Self-Tests Data output through the data output interface is inhibited during the conditional self-tests. The module does not return control to the calling application until the tests are completed. If any of these tests fails, the module transitions to the error state (Section 10.4).

10.3 Periodic Self-Test Information

Table 23: Pre-Operational Periodic Information © 2025 NetApp, Inc., atsec information security.

Page 52
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-CBC (AESNI_ASM) EncryptionKATCASTOn demandManually
AES-CBC (AESNI_ASM) DecryptionKATCASTOn demandManually
AES-CBC (AESNI_C) EncryptionKATCASTOn demandManually
AES-CBC (AESNI_C) DecryptionKATCASTOn demandManually
AES-CBC-CS3 EncryptionKATCASTOn demandManually
AES-CBC-CS3 DecryptionKATCASTOn demandManually
AES-CBC-CS3 (AESNI_C) EncryptionKATCASTOn demandManually
AES-CBC-CS3 (AESNI_C) DecryptionKATCASTOn demandManually
AES-CCM Authenticated encryptionKATCASTOn demandManually
AES-CCM Authenticated decryptionKATCASTOn demandManually
AES-CCM (AESNI_C) Authenticated encryptionKATCASTOn demandManually
AES-CCM (AESNI_C) Authenticated decryptionKATCASTOn demandManually
AES-CFB128 EncryptionKATCASTOn demandManually
AES-CFB128 DecryptionKATCASTOn demandManually
AES-CFB128 (AESNI_C) EncryptionKATCASTOn demandManually
AES-CFB128 (AESNI_C) DecryptionKATCASTOn demandManually
AES-CTR EncryptionKATCASTOn demandManually
AES-CTR DecryptionKATCASTOn demandManually
AES-CTR (AESNI_ASM) EncryptionKATCASTOn demandManually

© 2025 NetApp, Inc., atsec information security.

Page 53
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-CTR (AESNI_ASM) DecryptionKATCASTOn demandManually
AES-ECB EncryptionKATCASTOn demandManually
AES-ECB DecryptionKATCASTOn demandManually
AES-ECB (CTI_C) EncryptionKATCASTOn demandManually
AES-ECB (CTI_C) DecryptionKATCASTOn demandManually
AES-ECB (AESNI_ASM) EncryptionKATCASTOn demandManually
AES-ECB (AESNI_ASM) DecryptionKATCASTOn demandManually
AES-ECB (AESNI_C) EncryptionKATCASTOn demandManually
AES-ECB (AESNI_C) DecryptionKATCASTOn demandManually
AES-GCM Authenticated encryptionKATCASTOn demandManually
AES-GCM Authenticated decryptionKATCASTOn demandManually
AES-GCM (AESNI_ASM) Authenticated encryptionKATCASTOn demandManually
AES-GCM (AESNI_ASM) Authenticated decryptionKATCASTOn demandManually
AES-GCM (AESNI_AVX) Authenticated encryptionKATCASTOn demandManually
AES-GCM (AESNI_AVX) Authenticated decryptionKATCASTOn demandManually
AES-GCM (VAES_AVX10_256) Authenticated encryptionKATCASTOn demandManually
AES-GCM (VAES_AVX10_256) Authenticated decryptionKATCASTOn demandManually

© 2025 NetApp, Inc., atsec information security.

Page 54
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-GCM (VAES_AVX10_512) Authenticated encryptionKATCASTOn demandManually
AES-GCM (VAES_AVX10_512) Authenticated decryptionKATCASTOn demandManually
AES-OFB EncryptionKATCASTOn demandManually
AES-OFB DecryptionKATCASTOn demandManually
AES-OFB (AESNI_C) EncryptionKATCASTOn demandManually
AES-OFB (AESNI_C) DecryptionKATCASTOn demandManually
AES-XTS Testing Revision 2.0 EncryptionKATCASTOn demandManually
AES-XTS Testing Revision 2.0 DecryptionKATCASTOn demandManually
AES-XTS Testing Revision 2.0 (AESNI_ASM) EncryptionKATCASTOn demandManually
AES-XTS Testing Revision 2.0 (AESNI_ASM) DecryptionKATCASTOn demandManually
AES-XTS Testing Revision 2.0 (AESNI_AVX) EncryptionKATCASTOn demandManually
AES-XTS Testing Revision 2.0 (AESNI_AVX) DecryptionKATCASTOn demandManually
AES-XTS Testing Revision 2.0 (VAES_AVX2) EncryptionKATCASTOn demandManually
AES-XTS Testing Revision 2.0 (VAES_AVX2) DecryptionKATCASTOn demandManually
AES-XTS Testing Revision 2.0 (VAES_AVX10_256) EncryptionKATCASTOn demandManually

© 2025 NetApp, Inc., atsec information security.

Page 55
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-XTS Testing Revision 2.0 (VAES_AVX10_256) DecryptionKATCASTOn demandManually
AES-XTS Testing Revision 2.0 (VAES_AVX10_512) EncryptionKATCASTOn demandManually
AES-XTS Testing Revision 2.0 (VAES_AVX10_512) DecryptionKATCASTOn demandManually
SHA-1KATCASTOn demandManually
SHA-1 (SSSE3)KATCASTOn demandManually
SHA-1 (AVX)KATCASTOn demandManually
SHA-1 (AVX2)KATCASTOn demandManually
SHA-1 (SHA_NI)KATCASTOn demandManually
SHA2-224KATCASTOn demandManually
SHA2-224 (SSSE3)KATCASTOn demandManually
SHA2-224 (AVX)KATCASTOn demandManually
SHA2-224 (AVX2)KATCASTOn demandManually
SHA2-224 (SHA_NI)KATCASTOn demandManually
SHA2-256KATCASTOn demandManually
SHA2-256 (SSSE3)KATCASTOn demandManually
SHA2-256 (AVX)KATCASTOn demandManually
SHA2-256 (AVX2)KATCASTOn demandManually
SHA2-256 (SHA_NI)KATCASTOn demandManually
SHA2-384KATCASTOn demandManually
SHA2-384 (SSSE3)KATCASTOn demandManually
SHA2-384 (AVX)KATCASTOn demandManually
SHA2-384 (AVX2)KATCASTOn demandManually
SHA2-512KATCASTOn demandManually
SHA2-512 (SSSE3)KATCASTOn demandManually
SHA2-512 (AVX)KATCASTOn demandManually
SHA2-512 (AVX2)KATCASTOn demandManually
SHA3-224KATCASTOn demandManually
SHA3-256KATCASTOn demandManually
SHA3-384KATCASTOn demandManually
SHA3-512KATCASTOn demandManually
AES-CMACKATCASTOn demandManually
AES-CMAC (AESNI_C)KATCASTOn demandManually
HMAC-SHA-1KATCASTOn demandManually
HMAC-SHA-1 (SHA_NI)KATCASTOn demandManually
HMAC-SHA2-224KATCASTOn demandManually
HMAC-SHA2-224 (SHA_NI)KATCASTOn demandManually
HMAC-SHA2-256KATCASTOn demandManually

© 2025 NetApp, Inc., atsec information security.

Page 56
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2-256 (SHA_NI)KATCASTOn demandManually
HMAC-SHA2-384KATCASTOn demandManually
HMAC-SHA2-384 (AVX2)KATCASTOn demandManually
HMAC-SHA2-512KATCASTOn demandManually
HMAC-SHA2-512 (AVX2)KATCASTOn demandManually
HMAC-SHA3-224KATCASTOn demandManually
HMAC-SHA3-256KATCASTOn demandManually
HMAC-SHA3-384KATCASTOn demandManually
HMAC-SHA3-512KATCASTOn demandManually
KDF SP800-108KATCASTOn demandManually
KDA OneStep SP800-56Cr2KATCASTOn demandManually
Counter DRBGKATCASTOn demandManually
Hash DRBGKATCASTOn demandManually
HMAC DRBGKATCASTOn demandManually
KAS-FFC-SSC Sp800-56Ar3KATCASTOn demandManually
KAS-ECC-SSC Sp800-56Ar3KATCASTOn demandManually
RSA SigVer (FIPS186-5)KATCASTOn demandManually
Entropy Source Start Up APTAPTCASTOn demandManually
Entropy Source Start Up RCTRCTCASTOn demandManually
Entropy Source Continuous APTAPTCASTOn demandManually
Entropy Source Continuous RCTRCTCASTOn demandManually
Safe Primes Key GenerationPCTPCTOn demandManually
ECDSA KeyGen (FIPS186-5)PCTPCTOn demandManually
NameDescriptionConditionsRecovery MethodIndicator
ErrorThe Linux kernel immediately stops executingAny self-test failureRestart of the moduleKernel panic

Table 24: Conditional Periodic Information

10.4 Error States

Table 25: Error States In the error state, the output interface is inhibited, and the module accepts no more inputs or requests (as the module is no longer running). © 2025 NetApp, Inc., atsec information security.

Page 57
10.5 Operator Initiation of Self-Tests

The software integrity tests, CASTs and entropy source start-up tests can be invoked on demand by unloading and subsequently re-initializing the module. The PCTs can be invoked on demand by requesting the key pair generation service. © 2025 NetApp, Inc., atsec information security.

Page 58
11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

The module is distributed as a part of the StorageGRID 12 operating system. The StorageGRID Grid Manager is used to install the module:

  1. Open the sidebar menu and click CONFIGURATION
  2. Under Security, click Security settings
  3. Install the FIPS module using one of the following options: a. Use the “FIPS strict” policy b. Configure and use a custom policy with the “fipsMode” key set to “true”
  4. After enabling the policy, a rolling reboot must be performed; the module is not considered installed until a reboot is performed
11.2 Administrator Guidance

After installation of module, the Crypto Officer must use the StorageGRID Grid Manager to verify the correct name and version of the module:

  1. Open the sidebar menu and click SUPPORT
  2. Under Tools, click Diagnostics
  3. Find the “FIPS module versions” diagnostic and verify the FIPS module name and FIPS module version are listed as follows: NetApp StorageGRID Kernel Crypto API 6.1.129-1-ntap1-amd64 kcapi-tools 1.4.0-1+ntap0 libkcapi1:amd64 1.4.0-1+ntap0 The FIPS module is only installed on a given node if the aforementioned names and versions are displayed for that node.
11.3 Non-Administrator Guidance

There is no non-administrator guidance.

11.4 Design and Rules
11.5 Maintenance Requirements
11.6 End of Life

As the module does not persistently store SSPs, secure sanitization of the module consists of unloading the module. This will zeroize all SSPs in volatile memory. © 2025 NetApp, Inc., atsec information security.

Page 59
12 Mitigation of Other Attacks

The module does not offer mitigation of other attacks and therefore this section is not applicable. © 2025 NetApp, Inc., atsec information security.

Page 60

AES

Advanced Encryption Standard

Table, extracted as text (did not parse into structured rows)
A Glossary and Abbreviations API                     Application Programming Interface CAST                    Cryptographic Algorithm Self-Test CAVP                    Cryptographic Algorithm Validation Program CBC                     Cipher Block Chaining CBC-CS3                 Cipher Block Chaining with Ciphertext Stealing 3 CCM                     Counter with Cipher Block Chaining-Message Authentication Code CFB                     Cipher Feedback CKG                     Cryptographic Key Generation CMAC                    Cipher-based Message Authentication Code CMVP                    Cryptographic Module Validation Program CSP                     Critical Security Parameter CTR                     Counter DH                      Diffie-Hellman DRBG                    Deterministic Random Bit Generator ECB                     Electronic Code Book ECC                     Elliptic Curve Cryptography ECDSA                   Elliptic Curve Digital Signature Algorithm ESV                     Entropy Source Validation FFC                     Finite Field Cryptography FIPS                    Federal Information Processing Standards GCM                     Galois Counter Mode GMAC                    Galois Counter Mode Message Authentication Code HKDF                    HMAC-based Key Derivation Function HMAC                    Keyed-hash Message Authentication Code IG                      Implementation Guidance IPsec                   Internet Protocol Security IV                      Initialization Vector KAS                     Key Agreement Scheme KAT                     Known Answer Test KBKDF                   Key-based Key Derivation Function KDA                     Key Derivation Algorithm KDF                     Key Derivation Function KW                      Key Wrap MAC                     Message Authentication Code NIST                    National Institute of Science and Technology OFB                     Output Feedback PAA                     Processor Algorithm Acceleration PAI                     Processor Algorithm Implementation PBKDF                   Password-Based Key Derivation Function PCT                     Pair-wise Consistency Test PKCS                    Public-Key Cryptography Standard PSP                     Public Security Parameter PUB                     Processing Standards Publication RSA                     Rivest Shamir Adleman SHA                     Secure Hash Algorithm SSC                     Shared Secret Computation SSP                     Sensitive Security Parameter TLS                     Transport Layer Security TOEPP                   Tested Operational Environment’s Physical Perimeter XTS                     XEX-based Tweaked-codebook mode with cipher text Stealing © 2025 NetApp, Inc., atsec information security.
Page 61

B References FIPS 140-3 Security Requirements For Cryptographic Modules March 2019 https://doi.org/10.6028/NIST.FIPS.140-3 FIPS 140-3 IG Implementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program https://csrc.nist.gov/CSRC/media/Projects/cryptographic-modulevalidation-program/documents/fips%20140-3/FIPS%20140-3%20IG.pdf FIPS 180-4 Secure Hash Standard (SHS) August 2015 https://doi.org/10.6028/NIST.FIPS.180-4 FIPS 186-4 Digital Signature Standard (DSS) July 2013 https://doi.org/10.6028/NIST.FIPS.186-4 FIPS 186-5 Digital Signature Standard (DSS) February 2023 https://doi.org/10.6028/NIST.FIPS.186-5 FIPS 197 Advanced Encryption Standard (AES) November 2001; Updated May 2023 https://doi.org/10.6028/NIST.FIPS.197-upd1 FIPS 198-1 The Keyed-Hash Message Authentication Code (HMAC) July 2008 https://doi.org/10.6028/NIST.FIPS.198-1 FIPS 202 SHA-3 Standard: Permutation-Based Hash and ExtendableOutput Functions August 2015 https://doi.org/10.6028/NIST.FIPS.202 PKCS#1 PKCS #1: RSA Cryptography Specifications Version 2.2 November 2016 https://doi.org/10.17487/RFC8017 RFC 4106 The Use of Galois/Counter Mode (GCM) in IPsec Encapsulating Security Payload (ESP) June 2005 https://doi.org/10.17487/RFC4106 RFC 5288 The Transport Layer Security (TLS) Protocol Version 1.2 August 2008 https://doi.org/10.17487/RFC5246 RFC 8446 The Transport Layer Security (TLS) Protocol Version 1.3 August 2018 https://doi.org/10.17487/RFC8446 SP 800-38A Recommendation for Block Cipher Modes of Operation: Methods and Techniques December 2001 https://doi.org/10.6028/NIST.SP.800-38A SP800-38A- Recommendation for Block Cipher Modes of Operation: Three Add Variants of Ciphertext Stealing for CBC Mode October 2010 https://doi.org/10.6028/NIST.SP.800-38A-Add SP 800-38B Recommendation for Block Cipher Modes of Operation: the CMAC Mode for Authentication May 2005; Updated October 2016 https://doi.org/10.6028/NIST.SP.800-38B © 2025 NetApp, Inc., atsec information security.

Page 62

SP 800-38C Recommendation for Block Cipher Modes of Operation: the CCM Mode for Authentication and Confidentiality May 2004; Updated July 2007 https://doi.org/10.6028/NIST.SP.800-38C SP 800-38D Recommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC November 2007 https://doi.org/10.6028/NIST.SP.800-38D SP 800-38E Recommendation for Block Cipher Modes of Operation: the XTSAES Mode for Confidentiality on Storage Devices January 2010 https://doi.org/10.6028/NIST.SP.800-38E SP 800-38F Recommendation for Block Cipher Modes of Operation: Methods for Key Wrapping December 2012 https://doi.org/10.6028/NIST.SP.800-38F SP 800-52r2 Guidelines for the Selection, Configuration, and Use of Transport Layer Security (TLS) Implementations August 2019 https://doi.org/10.6028/NIST.SP.800-52r2 SP 800-56Ar3 Recommendation for Pair-Wise Key-Establishment Schemes Using Discrete Logarithm Cryptography April 2018 https://doi.org/10.6028/NIST.SP.800-56Ar3 SP 800-56Cr2 Recommendation for Key-Derivation Methods in KeyEstablishment Schemes August 2020 https://doi.org/10.6028/NIST.SP.800-56Cr2 SP 800-90Ar1 Recommendation for Random Number Generation Using Deterministic Random Bit Generators June 2015 https://doi.org/10.6028/NIST.SP.800-90Ar1 SP 800-90B Recommendation for the Entropy Sources Used for Random Bit Generation January 2018 https://doi.org/10.6028/NIST.SP.800-90B SP 800-108r1 Recommendation for Key Derivation Using Pseudorandom Functions August 2022 https://doi.org/10.6028/NIST.SP.800-108r1-upd1 SP 800-131Ar2 Transitioning the Use of Cryptographic Algorithms and Key Lengths Marcy 2019 https://doi.org/10.6028/NIST.SP.800-131Ar2 SP 800-133r2 Recommendation for Cryptographic Key Generation June 2020 https://doi.org/10.6028/NIST.SP.800-133r2 SP 800-140Br1 Cryptographic Module Validation Program (CMVP) Security Policy Requirements: CMVP Validation Authority Updates to ISO/IEC 24759 and ISO/IEC 19790 Annex B November 2023 https://doi.org/10.6028/NIST.SP.800-140Br1 © 2025 NetApp, Inc., atsec information security.