All modules
CMVP Validated Module · FIPS 140-3 Security Policy

SUSE Linux Enterprise Kernel Crypto API Cryptographic Module

Certificate#5112StandardFIPS 140-3Level1TypeSoftwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorSUSE LLC
Medium review priority  ·  exposes kernel crypto consumer  ·  Linux kernel upstream has published 3932 CVEs since this module's initial validation  ·  last validated 7 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date12/17/2030
CaveatWhen operated in approved mode. When installed, initialized and configured as specified in section 11 of the Security Policy. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.
VendorSUSE LLC

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for SUSE Linux Enterprise Kernel Crypto API Cryptographic Module
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>update<br/>Recovery</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>IKEV<br/>IPSEC</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for SUSE Linux Enterprise Kernel Crypto API Cryptographic Module
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>update<br/>Recovery</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>IKEV<br/>IPSEC</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

SUSE LLC SUSE Linux Enterprise Kernel Crypto API Cryptographic Module Prepared by: atsec information security corporation

4516 Seton Center Pkwy, Suite 250

Austin, TX 78759 Document version: 1.1 www.atsec.com Last update: 12-04-2025 © 2025 SUSE, LLC/atsec information security corporation.

Page 2
Table of Contents
#SectionPage
Page 3

© 2025 SUSE, LLC/atsec information security corporation.

Page 4
List of Tables
ItemPage
Table 1: Security Levels5
Table 3: Tested Operational Environments - Software, Firmware, Hybrid9
Table 4: Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid10
Table 5: Modes List and Description10
Table 6: Approved Algorithms16
Table 7: Vendor-Affirmed Algorithms16
Table 8: Non-Approved, Not Allowed Algorithms17
Table 9: Security Function Implementations32
Table 10: Entropy Certificates34
Table 11: Entropy Sources35
Table 12: Ports and Interfaces37
Table 13: Roles38
Table 14: Approved Services46
Table 15: Non-Approved Services47
Table 16: Storage Areas52
Table 17: SSP Input-Output Methods52
Table 18: SSP Zeroization Methods53
Table 19: SSP Table 158
Table 20: SSP Table 261
Table 21: Pre-Operational Self-Tests63
Table 22: Conditional Self-Tests129
Table 23: Pre-Operational Periodic Information129
Table 24: Conditional Periodic Information151
Table 25: Error States152
Figure 1: Block Diagram6
Page 5
SectionTitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication1
5Software/Firmware security1
6Operational environment1
7Physical securityN/A
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacksN/A
Overall Level1
1.1 Overview

This document is the non-proprietary FIPS 140-3 Security Policy for versions 3.5 and 3.6 the SUSE Linux Enterprise Kernel Crypto API Cryptographic Module. It contains the security rules under which the module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for an overall Security Level 1 module. intact and including this notice. Other documentation is proprietary to their authors.

1.1.1 How this Security Policy was prepared

In preparing the Security Policy document, the laboratory formatted the vendor-supplied documentation for consolidation without altering the technical statements therein contained. The further refining of the Security Policy document was conducted iteratively throughout the conformance testing, wherein the Security Policy was submitted to the vendor, who would then edit, modify, and add technical contents. The vendor would also supply additional documentation, which the laboratory formatted into the existing Security Policy, and resubmitted to the vendor for their final editing.

1.2 Security Levels

Table 1: Security Levels © 2025 SUSE, LLC/atsec information security corporation.

Page 6
2 Cryptographic Module Specification
2.1 Description

Purpose and Use: The SUSE Linux Enterprise Kernel Crypto API Cryptographic Module (hereafter referred to as “the module”) provides a C language application program interface (API) for use by other (kernel space and user space) processes that require cryptographic functionality. The module operates on a general-purpose computer as part of the Linux kernel. Its cryptographic functionality can be accessed using the Linux Kernel Crypto API. Module Type: Software Module Embodiment: MultiChipStand Cryptographic Boundary: The cryptographic boundary of the module is defined as the kernel binary and the kernel crypto object files, the libkcapi library, and the fipscheck binary, which is used to verify the integrity of the software components. In addition, the cryptographic boundary contains the .hmac files which store the expected integrity values for each of the software components. Tested Operational Environment’s Physical Perimeter (TOEPP): The TOEPP of the module is defined as the general-purpose computer on which the module is installed. It includes software in kernel and user space, as well as the PAA in the CPU. The TOEPP is indicated by the large thin border in Figure 1. Figure 1: Block Diagram © 2025 SUSE, LLC/atsec information security corporation.

Page 7
Package or File NameSoftware/ Firmware VersionFeaturesIntegrity Test
For AMD and Intel Xeon platforms: /boot/vmlinuz-6.4.0-150600.23.25- default; /boot/.vmlinuz-6.4.0- 150600.23.25-default.hmac; /lib/modules/6.4.0-150600.23.25- default/kernel/crypto/*.ko; /lib/modules/6.4.0-150600.23.25- default/kernel/arch/x86/crypto/*.ko; /usr/lib64/libkcapi.so.0.13.0; /usr/lib64/libkcapi/fipscheck; /usr/lib64/libkcapi/.fipscheck.hmac3.5N/AHMAC-SHA2- 256; RSA signature verification with SHA2-256 and 4096-bit key
For ARM Ampere Altra platform: /boot/Image-6.4.0-150600.23.25- default; /boot/.Image-6.4.0- 150600.23.25-default.hmac; /lib/modules/6.4.0-150600.23.25- default/kernel/crypto/*.ko; /lib/modules/6.4.0-150600.23.25- default/kernel/arch/arm64/crypto/*.ko; /usr/lib64/libkcapi.so.0.13.0; /usr/lib64/libkcapi/fipscheck; /usr/lib64/libkcapi/.fipscheck.hmac3.5N/AHMAC-SHA2- 256; RSA signature verification with SHA2-256 and 4096-bit key
For IBM z/16 platform: /boot/image- 6.4.0-150600.23.25-default; /boot/.image-6.4.0-150600.23.25- default.hmac; /lib/modules/6.4.0- 150600.23.25- default/kernel/crypto/*.ko; /lib/modules/6.4.0-150600.23.25- default/kernel/arch/s390/crypto/*.ko; /usr/lib64/libkcapi.so.0.13.0; /usr/lib64/libkcapi/fipscheck; /usr/lib64/libkcapi/.fipscheck.hmac3.5N/AHMAC-SHA2- 256; RSA signature verification with SHA2-256 and 4096-bit key
For AMD and Intel Xeon platforms: /boot/vmlinuz-6.4.0-150600.10.17-rt; /boot/.vmlinuz-6.4.0-150600.10.17- rt.hmac; /lib/modules/6.4.0- 150600.10.17-rt/kernel/crypto/*.ko; /lib/modules/6.4.0-150600.10.17-3.6N/AHMAC-SHA2- 256; RSA signature verification with SHA2-256
2.2 Tested and Vendor Affirmed Module Version and

Identification Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets): © 2025 SUSE, LLC/atsec information security corporation.

Page 8

Package or File Name rt/kernel/arch/x86/crypto/*.ko; /usr/lib64/libkcapi.so.0.13.0; /usr/lib64/libkcapi/fipscheck; /usr/lib64/libkcapi/.fipscheck.hmac

Software/ Firmware Version

Features

Integrity Test and 4096-bit key

Operating SystemHardware PlatformProcessorsPAA/PAIHypervisor or Host OSVersion(s)
SUSE Linux Enterprise Server 15 SP6SuperMicro SuperChassis 825BTQC- R1K23LPB and Motherboard H12DSi-NT6AMD EPYC(TM) 7343YesN/A3.5 3.6
SUSE Linux Enterprise Server 15 SP6SuperMicro SuperChassis 825BTQC- R1K23LPB and Motherboard H12DSi-NT6AMD EPYC(TM) 7343NoN/A3.5 3.6
SUSE Linux Enterprise Server 15 SP6GIGABYTE R152- P30Ampere® Altra® Q80- 30YesN/A3.5
SUSE Linux Enterprise Server 15 SP6GIGABYTE R152- P30Ampere® Altra® Q80- 30NoN/A3.5
SUSE Linux Enterprise Server 15 SP6IBM z16 A01IBM® Telum(TM)YesN/A3.5
SUSE Linux Enterprise Server 15 SP6IBM z16 A01IBM® Telum(TM)NoN/A3.5

Table 2: Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets) Tested Operational Environments - Software, Firmware, Hybrid: © 2025 SUSE, LLC/atsec information security corporation.

Page 9
Operating SystemHardware PlatformProcessorsPAA/PAIHypervisor or Host OSVersion(s)
SUSE Linux Enterprise Server 15 SP6ASUS RS700-E11- RS4UIntel® Xeon® Gold 5416SYesN/A3.5 3.6
SUSE Linux Enterprise Server 15 SP6ASUS RS700-E11- RS4UIntel® Xeon® Gold 5416SNoN/A3.5 3.6
Operating SystemHardware Platform
SUSE Linux Enterprise Server for SAP 15SP6ASUS RS700-E11-RS4U on Intel® Xeon® Gold 5416S
SUSE Linux Enterprise Desktop 15SP6ASUS RS700-E11-RS4U on Intel® Xeon® Gold 5416S
SUSE Linux Enterprise Server 15SP6DELL PowerEdge R640 on Intel® Xeon® Gold 6234
SUSE Linux Enterprise Server for SAP 15SP6SuperMicro SuperChassis 825BTQCR1K23LPB and Motherboard H12DSi-NT6 on AMD EPYC(TM) 7343
SUSE Linux Enterprise Desktop 15SP6SuperMicro SuperChassis 825BTQCR1K23LPB and Motherboard H12DSi-NT6 on AMD EPYC(TM) 7343
SUSE Linux Enterprise Server 15SP6IBM LinuxONE III Model LT1 QEMU VM on z15
SUSE Linux Enterprise Server 15SP6IBM LinuxONE III Model LT1 on z15
SUSE Linux Enterprise Server for SAP 15SP6QEMU VM on AMD EPYC(TM) 7543P
SUSE Linux Enterprise Server for SAP 15SP6QEMU VM on Intel® Xeon® Gold 5218R
SUSE Linux Enterprise Desktop 15SP6QEMU VM on AMD EPYC(TM) 7543P
SUSE Linux Enterprise Desktop 15SP6QEMU VM on Intel® i7-1195G7

Table 3: Tested Operational Environments - Software, Firmware, Hybrid Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid: © 2025 SUSE, LLC/atsec information security corporation.

Page 10
Operating SystemHardware Platform
SUSE Linux Enterprise Server 15SP6QEMU VM on Intel® Xeon® Gold 6338
SUSE Linux Enterprise Server 15SP6QEMU VM on Ampere® Altra® Q80-30
SUSE Linux Enterprise Server Real Time 15SP6ASUS RS700-E11-RS4U on Intel® Xeon® Gold 5416S
SUSE Linux Enterprise Server Real Time 15SP6SuperMicro SuperChassis 825BTQCR1K23LPB and Motherboard H12DSi-NT6 on AMD EPYC(TM) 7343
SUSE Linux Enterprise Server Real Time 15SP6QEMU VM on AMD EPYC(TM) 7773X
Mode NameDescriptionTypeStatus Indicator
Approved modeAutomatically entered whenever an approved service is requestedApprovedMapped to approved service indicator in Section 4.3 for all approved algorithms except GCM: respective approved service function returns indicator 0. For GCM: crypto_aead_get_flags(tfm) has the CRYPTO_TFM_FIPS_COMPLIANCE flag set
Non- approved modeAutomatically entered whenever a non- approved service is requestedNon- ApprovedNo service indicator required for non- approved services per IG 2.4.C

Table 4: Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid CMVP makes no statement as to the correct operation of the module or the security strengths of the generated keys when so ported if the specific operational environment is not listed on the validation certificate. The module is considered to maintain compliance with the FIPS 140-3 validation for SUSE products when operating on any general-purpose platform/processor that supports the SUSE the allowance FIPS 140-3 management manual [FIPS140-3_MM] section 7.9.1 bullet 1 a i).

2.3 Excluded Components

There are no components within the cryptographic boundary excluded from the FIPS 140-3 requirements.

2.4 Modes of Operation

Modes List and Description: Table 5: Modes List and Description © 2025 SUSE, LLC/atsec information security corporation.

Page 11
AlgorithmCAVP CertPropertiesReference
AES-CBCA5503, A5507, A5510, A5513, A5520, A5521, A5524, A5526, A5530, A5533, A5536, A5661, A5664Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CBC- CS3A5503, A5507, A5510, A5513, A5520, A5521, A5526, A5530, A5533, A5536, A5664Direction - decrypt, encrypt Key Length - 128, 192, 256SP 800-38A
AES-CCMA5503, A5507, A5513, A5520, A5521, A5526, A5530, A5536, A5661, A5664Key Length - 128, 192, 256SP 800-38C
AES-CFB128A5503, A5507, A5513, A5521, A5526, A5530, A5536, A5664Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CMACA5503, A5507, A5513, A5520, A5521, A5526, A5530, A5536, A5661, A5664Direction - Generation, Verification Key Length - 128, 192, 256SP 800-38B
AES-CTRA5503, A5507, A5510, A5513, A5520, A5521, A5524, A5526, A5530, A5533, A5536, A5661, A5664Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA5503, A5505, A5506, A5507, A5508, A5509, A5510, A5511, A5512, A5513, A5514, A5515, A5520, A5521, A5522, A5523, A5524, A5526, A5528, A5529, A5530, A5531, A5532, A5533, A5534, A5535, A5536, A5537,Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A

After passing all pre-operational self-tests and cryptographic algorithm self-tests executed on start-up, the module automatically transitions to the approved mode. No operator intervention is required to reach this point. Mode Change Instructions and Status: The module automatically switches between the approved and non-approved modes depending on the services requested by the operator. The status indicator of the mode of operation is equivalent to the indicator of the service that was requested.

2.5 Algorithms

Approved Algorithms: © 2025 SUSE, LLC/atsec information security corporation.

Page 12
AlgorithmCAVP CertPropertiesReference
A5538, A5661, A5662, A5663, A5664, A5665, A5666
AES-GCMA5503, A5506, A5507, A5509, A5510, A5512, A5513, A5515, A5521, A5523, A5526, A5529, A5530, A5532, A5533, A5535, A5536, A5538, A5661, A5663, A5664, A5666Direction - Decrypt, Encrypt IV Generation - External Key Length - 128, 192, 256SP 800-38D
AES-GCMA5505, A5508, A5511, A5514, A5522, A5528, A5531, A5534, A5537, A5662, A5665Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.2 Key Length - 128, 192, 256SP 800-38D
AES-GMACA5503, A5507, A5513, A5521, A5526, A5530, A5536, A5661, A5664Direction - Decrypt, Encrypt IV Generation - External Key Length - 128, 192, 256SP 800-38D
AES-KWA5503, A5507, A5513, A5521, A5526, A5530, A5536, A5664Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38F
AES-OFBA5503, A5507, A5513, A5521, A5526, A5530, A5536, A5664Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-XTS Testing Revision 2.0A5503, A5507, A5510, A5513, A5520, A5521, A5524, A5526, A5530, A5533, A5536, A5661, A5664Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38E
Counter DRBGA5503, A5505, A5506, A5507, A5508, A5509, A5510, A5511, A5512, A5513, A5514, A5515, A5521, A5522, A5523, A5526, A5528, A5529, A5530, A5531, A5532, A5533, A5534, A5535, A5536, A5537, A5538, A5661, A5662, A5663, A5664, A5665, A5666Prediction Resistance - No, Yes Mode - AES-128, AES- 192, AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
8.2.2 © 2025 SUSE, LLC/atsec information security corporation.
Page 13
AlgorithmCAVP CertPropertiesReference
ECDSA KeyGen (FIPS186-5)A5503, A5526Curve - P-256, P-384 Secret Generation Mode - testing candidatesFIPS 186-5
ECDSA SigVer (FIPS186-4)A5504, A5527Component - No Curve - P-256, P-384 Hash Algorithm - SHA-1FIPS 186-4
ECDSA SigVer (FIPS186-5)A5504, A5527Curve - P-256, P-384 Hash Algorithm - SHA2- 224, SHA2-256, SHA2- 384, SHA2-512FIPS 186-5
Hash DRBGA5503, A5516, A5517, A5518, A5526, A5539, A5540, A5541, A5664Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
HMAC DRBGA5503, A5516, A5517, A5518, A5526, A5539, A5540, A5541, A5664Prediction Resistance - No, Yes Mode - SHA-1, SHA2-256, SHA2-512SP 800-90A Rev. 1
HMAC-SHA-1A5503, A5516, A5517, A5518, A5519, A5520, A5526, A5539, A5540, A5541, A5542, A5664Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 224A5503, A5516, A5517, A5518, A5519, A5520, A5524, A5525, A5526, A5539, A5540, A5541, A5542, A5664Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 256A5503, A5516, A5517, A5518, A5519, A5520, A5524, A5525, A5526, A5539, A5540, A5541, A5542, A5664Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 384A5503, A5516, A5517, A5518, A5525, A5526, A5539, A5540, A5541, A5664Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA2- 512A5503, A5516, A5517, A5518, A5525, A5526, A5539, A5540, A5541, A5664Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3- 224A5503, A5526, A5664Key Length - Key Length: 112-524288 Increment 8FIPS 198-1

© 2025 SUSE, LLC/atsec information security corporation.

Page 14
AlgorithmCAVP CertPropertiesReference
HMAC-SHA3- 256A5503, A5526, A5664Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3- 384A5503, A5526, A5664Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
HMAC-SHA3- 512A5503, A5526, A5664Key Length - Key Length: 112-524288 Increment 8FIPS 198-1
KAS-ECC- SSC Sp800- 56Ar3A5503, A5526Domain Parameter Generation Methods - P- 256, P-384 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KAS-FFC-SSC Sp800- 56Ar3A5503, A5526Domain Parameter Generation Methods - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192 Scheme - dhEphem - KAS Role - initiator, responderSP 800-56A Rev. 3
KDF SP800- 108A5503, A5526KDF Mode - Counter Supported Lengths - Supported Lengths: 112- 4096 Increment 8SP 800-108 Rev. 1
RSA SigVer (FIPS186-4)A5503, A5526, A5664Signature Type - PKCS 1.5 Modulo - 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186-5)A5503, A5526, A5664Modulo - 2048, 3072, 4096 Signature Type - pkcs1v1.5FIPS 186-5
Safe Primes Key GenerationA5503, A5526Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192SP 800-56A Rev. 3

© 2025 SUSE, LLC/atsec information security corporation.

Page 15
AlgorithmCAVP CertPropertiesReference
SHA-1A5503, A5516, A5517, A5518, A5519, A5520, A5526, A5539, A5540, A5541, A5542, A5664Message Length - Message Length: 0- 65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-224A5503, A5516, A5517, A5518, A5519, A5520, A5524, A5525, A5526, A5539, A5540, A5541, A5542, A5664Message Length - Message Length: 0- 65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-256A5503, A5516, A5517, A5518, A5519, A5520, A5524, A5525, A5526, A5539, A5540, A5541, A5542, A5664Message Length - Message Length: 0- 65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-384A5503, A5516, A5517, A5518, A5525, A5526, A5539, A5540, A5541, A5664Message Length - Message Length: 0- 65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA2-512A5503, A5516, A5517, A5518, A5525, A5526, A5539, A5540, A5541, A5664Message Length - Message Length: 0- 65536 Increment 8 Large Message Sizes - 1, 2FIPS 180-4
SHA3-224A5503, A5526, A5664Message Length - Message Length: 0- 65536 Increment 8 Large Message Sizes - 1, 2FIPS 202
SHA3-256A5503, A5526, A5664Message Length - Message Length: 0- 65536 Increment 8 Large Message Sizes - 1, 2FIPS 202
SHA3-384A5503, A5526, A5664Message Length - Message Length: 0- 65536 Increment 8 Large Message Sizes - 1, 2FIPS 202
SHA3-512A5503, A5526, A5664Message Length - Message Length: 0-FIPS 202

© 2025 SUSE, LLC/atsec information security corporation.

Page 16
AlgorithmCAVP CertPropertiesReference
65536 Increment 8 Large Message Sizes - 1, 2
NamePropertiesImplementationReference
Asymmetric Cryptographic Key Generation (CKG)Key Type:AsymmetricN/ASP 800-133 Rev. 2, section 4, example 1
NameUse and Function
AES-GCM with external IVEncryption with external IV (not compliant to FIPS 140-3 IG C.H)
KBKDF (by using the libkcapi)Key derivation with implementation not tested by CAVP
HKDF (by using the libkcapi)Key derivation with implementation not tested by CAVP
PBKDF2 (by using the libkcapi)Password-based key derivation with implementation not tested by CAVP
RSAEncryption primitive; Decryption primitive (not compliant to SP 800- 56Br2)
RSA with PKCS#1 v1.5 paddingSignature generation (pre-hashed message); Signature verification (pre- hashed message); Key encapsulation (not compliant to SP 800-56Br2); Key un-encapsulation (not compliant to SP 800-56Br2)
ECDSASignature generation (pre-hashed message); Signature verification (pre- hashed message)

Table 6: Approved Algorithms Vendor-Affirmed Algorithms: Table 7: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: N/A for this module. Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. Non-Approved, Not Allowed Algorithms: © 2025 SUSE, LLC/atsec information security corporation.

Page 17
NameTypeDescriptionPropertiesAlgorithms
Encryption with AESBC-UnAuthEncrypt a plaintext with AESKey size (XTS):128, 256 bits Security strength (XTS):128, 256 bits Key size (Others):128, 192, 256 bits Security strength (Others):128, 192, 256 bitsAES-CBC: (A5503, A5507, A5510, A5513, A5520, A5521, A5524, A5526, A5530, A5533, A5536, A5661, A5664) AES-CBC- CS3: (A5503, A5507, A5510, A5513, A5520, A5521, A5526, A5530, A5533, A5536, A5664) AES-CFB128: (A5503, A5507, A5513, A5521, A5526, A5530, A5536, A5664) AES-CTR: (A5503, A5507, A5510, A5513, A5520, A5521, A5524, A5526, A5530,

Table 8: Non-Approved, Not Allowed Algorithms

2.6 Security Function Implementations

© 2025 SUSE, LLC/atsec information security corporation.

Page 18
NameTypeDescriptionPropertiesAlgorithms
A5533, A5536, A5661, A5664) AES-ECB: (A5503, A5505, A5506, A5507, A5508, A5509, A5510, A5511, A5512, A5513, A5514, A5515, A5520, A5521, A5522, A5523, A5524, A5526, A5528, A5529, A5530, A5531, A5532, A5533, A5534, A5535, A5536, A5537, A5538, A5661, A5662, A5663, A5664, A5665, A5666) AES-OFB: (A5503, A5507, A5513, A5521, A5526, A5530, A5536, A5664) AES-XTS Testing

© 2025 SUSE, LLC/atsec information security corporation.

Page 19
NameTypeDescriptionPropertiesAlgorithms
Revision 2.0: (A5503, A5507, A5510, A5513, A5520, A5521, A5524, A5526, A5530, A5533, A5536, A5661, A5664)
Decryption with AESBC-UnAuthDecrypt a ciphertext with AESKey size (XTS):128, 256 bits Security strength (XTS):128, 256 bits Key size (Others):128, 192, 256 bits Security strength (Others):128, 192, 256 bitsAES-CBC: (A5503, A5507, A5510, A5513, A5520, A5521, A5524, A5526, A5530, A5533, A5536, A5661, A5664) AES-CBC- CS3: (A5503, A5507, A5510, A5513, A5520, A5521, A5526, A5530, A5533, A5536, A5664) AES-CFB128: (A5503, A5507, A5513, A5521, A5526, A5530, A5536, A5664) AES-CTR:

© 2025 SUSE, LLC/atsec information security corporation.

Page 20
NameTypeDescriptionPropertiesAlgorithms
(A5503, A5507, A5510, A5513, A5520, A5521, A5524, A5526, A5530, A5533, A5536, A5661, A5664) AES-ECB: (A5503, A5505, A5506, A5507, A5508, A5509, A5510, A5511, A5512, A5513, A5514, A5515, A5520, A5521, A5522, A5523, A5524, A5526, A5528, A5529, A5530, A5531, A5532, A5533, A5534, A5535, A5536, A5537, A5538, A5661, A5662, A5663, A5664, A5665, A5666) AES-OFB: (A5503,

© 2025 SUSE, LLC/atsec information security corporation.

Page 21
NameTypeDescriptionPropertiesAlgorithms
A5507, A5513, A5521, A5526, A5530, A5536, A5664) AES-XTS Testing Revision 2.0: (A5503, A5507, A5510, A5513, A5520, A5521, A5524, A5526, A5530, A5533, A5536, A5661, A5664)
Message digestSHACompute a message digestSHA-1: (A5503, A5516, A5517, A5518, A5519, A5520, A5526, A5539, A5540, A5541, A5542, A5664) SHA2-224: (A5503, A5516, A5517, A5518, A5519, A5520, A5524, A5525, A5526, A5539, A5540, A5541, A5542,

© 2025 SUSE, LLC/atsec information security corporation.

Page 22
NameTypeDescriptionPropertiesAlgorithms
A5664) SHA2-256: (A5503, A5516, A5517, A5518, A5519, A5520, A5524, A5525, A5526, A5539, A5540, A5541, A5542, A5664) SHA2-384: (A5503, A5516, A5517, A5518, A5525, A5526, A5539, A5540, A5541, A5664) SHA2-512: (A5503, A5516, A5517, A5518, A5525, A5526, A5539, A5540, A5541, A5664) SHA3-224: (A5503, A5526, A5664) SHA3-256: (A5503, A5526, A5664) SHA3-384: (A5503, A5526, A5664) SHA3-512:

© 2025 SUSE, LLC/atsec information security corporation.

Page 23
NameTypeDescriptionPropertiesAlgorithms
(A5503, A5526, A5664)
Message authenticatio nMACCompute a MAC tag for authenticatio nKey size (HMAC):112- 524288 bits Security strength (HMAC):112-256 bits Key size (AES):128, 192, 256 bits Security strength (AES):128, 192, 256 bitsAES-CMAC: (A5503, A5507, A5513, A5520, A5521, A5526, A5530, A5536, A5661, A5664) AES-GMAC: (A5503, A5507, A5513, A5521, A5526, A5530, A5536, A5661, A5664) HMAC-SHA-1: (A5503, A5516, A5517, A5518, A5519, A5520, A5526, A5539, A5540, A5541, A5542, A5664) HMAC-SHA2- 224: (A5503, A5516, A5517, A5518, A5519, A5520, A5524, A5525, A5526, A5539, A5540, A5541,

© 2025 SUSE, LLC/atsec information security corporation.

Page 24
NameTypeDescriptionPropertiesAlgorithms
A5542, A5664) HMAC-SHA2- 256: (A5503, A5516, A5517, A5518, A5519, A5520, A5524, A5525, A5526, A5539, A5540, A5541, A5542, A5664) HMAC-SHA2- 384: (A5503, A5516, A5517, A5518, A5525, A5526, A5539, A5540, A5541, A5664) HMAC-SHA2- 512: (A5503, A5516, A5517, A5518, A5525, A5526, A5539, A5540, A5541, A5664) HMAC-SHA3- 224: (A5503, A5526, A5664) HMAC-SHA3- 256: (A5503, A5526, A5664) HMAC-SHA3- 384: (A5503, A5526, A5664)

© 2025 SUSE, LLC/atsec information security corporation.

Page 25
NameTypeDescriptionPropertiesAlgorithms
HMAC-SHA3- 512: (A5503, A5526, A5664)
Random number generation with DRBGsDRBGGenerate random numbers from DRBGsCTR-DRBG:Modes: AES- 128, AES-192, AES-256, with derivation function, with/without prediction resistance; Internal state length: 256, 320, 384 bits; Security strength: 128, 192, 256 bits HMAC-DRBG:Modes: SHA- 1, SHA-256, SHA-512 with/without prediction resistance; Internal state length: 320, 512, 1024 bits; Security strength: 128, 256 bits Hash-DRBG:Modes: SHA- 1, SHA-256, SHA-512 with/without prediction resistance; Internal state length: 880, 1776 bits; Security strength: 128, 256 bitsCounter DRBG: (A5503, A5505, A5506, A5507, A5508, A5509, A5510, A5511, A5512, A5513, A5514, A5515, A5521, A5522, A5523, A5526, A5528, A5529, A5530, A5531, A5532, A5533, A5534, A5535, A5536, A5537, A5538, A5661, A5662, A5663, A5664, A5665, A5666) Hash DRBG: (A5503, A5516, A5517, A5518, A5526, A5539, A5540, A5541, A5664) HMAC DRBG:

© 2025 SUSE, LLC/atsec information security corporation.

Page 26
NameTypeDescriptionPropertiesAlgorithms
(A5503, A5516, A5517, A5518, A5526, A5539, A5540, A5541, A5664)
Authenticated encryptionBC-AuthEncrypt and authenticate a plaintextKey size (AES):128, 192, 256 bits Security strength (AES):128, 192, 256 bitsAES-CCM: (A5503, A5507, A5513, A5520, A5521, A5526, A5530, A5536, A5661, A5664) AES-GCM: (A5503, A5505, A5506, A5507, A5508, A5509, A5510, A5511, A5512, A5513, A5514, A5515, A5521, A5522, A5523, A5526, A5528, A5529, A5530, A5531, A5532, A5533, A5534, A5535, A5536, A5537, A5538, A5661, A5662,

© 2025 SUSE, LLC/atsec information security corporation.

Page 27
NameTypeDescriptionPropertiesAlgorithms
A5663, A5664, A5665, A5666) AES-KW: (A5503, A5507, A5513, A5521, A5526, A5530, A5536, A5664) AES-CBC: (A5503, A5507, A5510, A5513, A5520, A5521, A5524, A5526, A5530, A5533, A5536, A5661, A5664) HMAC-SHA-1: (A5503, A5516, A5517, A5518, A5519, A5520, A5526, A5539, A5540, A5541, A5542, A5664) HMAC-SHA2- 224: (A5503, A5516, A5517, A5518, A5519, A5520, A5526, A5539, A5540, A5541,

© 2025 SUSE, LLC/atsec information security corporation.

Page 28
NameTypeDescriptionPropertiesAlgorithms
A5542, A5664) HMAC-SHA2- 256: (A5503, A5516, A5517, A5518, A5519, A5520, A5526, A5539, A5540, A5541, A5542, A5664) HMAC-SHA2- 384: (A5503, A5516, A5517, A5518, A5519, A5520, A5526, A5539, A5540, A5541, A5542, A5664) HMAC-SHA2- 512: (A5503, A5516, A5517, A5518, A5519, A5520, A5526, A5539, A5540, A5541, A5542, A5664)
Authenticated decryptionBC-AuthDecrypt and authenticate a ciphertextKey size:128, 192, 256 bits Security strength:128, 192, 256 bitsAES-CCM: (A5503, A5507, A5513, A5520, A5521, A5526, A5530, A5536,

© 2025 SUSE, LLC/atsec information security corporation.

Page 29
NameTypeDescriptionPropertiesAlgorithms
A5661, A5664) AES-GCM: (A5503, A5505, A5506, A5507, A5508, A5509, A5510, A5511, A5512, A5513, A5514, A5515, A5521, A5522, A5523, A5526, A5528, A5529, A5530, A5531, A5532, A5533, A5534, A5535, A5536, A5537, A5538, A5661, A5662, A5663, A5664, A5665, A5666) AES-KW: (A5503, A5507, A5513, A5521, A5526, A5530, A5536, A5664) AES-CBC: (A5503, A5507, A5510, A5513, A5520,

© 2025 SUSE, LLC/atsec information security corporation.

Page 30
NameTypeDescriptionPropertiesAlgorithms
A5521, A5524, A5526, A5530, A5533, A5536, A5661, A5664) HMAC-SHA-1: (A5503, A5516, A5517, A5518, A5519, A5520, A5526, A5539, A5540, A5541, A5542, A5664) HMAC-SHA2- 224: (A5503, A5516, A5517, A5518, A5519, A5520, A5526, A5539, A5540, A5541, A5542, A5664) HMAC-SHA2- 256: (A5503, A5516, A5517, A5518, A5519, A5520, A5526, A5539, A5540, A5541, A5542, A5664) HMAC-SHA2- 384: (A5503, A5516, A5517,

© 2025 SUSE, LLC/atsec information security corporation.

Page 31
NameTypeDescriptionPropertiesAlgorithms
A5518, A5519, A5520, A5526, A5539, A5540, A5541, A5542, A5664) HMAC-SHA2- 512: (A5503, A5516, A5517, A5518, A5519, A5520, A5526, A5539, A5540, A5541, A5542, A5664)
Key pair generation with ECDSAAsymKeyPair -KeyGen CKGGenerate an asymmetric EC key pairCurves:P-256, P-384 Security strength:128, 192 bits Mode:FIPS 186-5, Section A.2.2 - Rejection SamplingECDSA KeyGen (FIPS186-5): (A5503, A5526) Asymmetric Cryptographi c Key Generation (CKG): ()
Key pair generation with Safe PrimesAsymKeyPair -KeyGen CKGGenerate an asymmetric DH key pair using Diffie- HellmanGroups:ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192 Security strength:112- 200 bits Mode:NIST SP 800-56A Rev. 3, Section 5.6.1.1.3 - Extra Random BitsSafe Primes Key Generation: (A5503, A5526) Asymmetric Cryptographi c Key Generation (CKG): ()
Digital signature verification with ECDSADigSig- SigVerVerify a digital signature using ECDSACurves:P-256, P-384 Hashes:SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512 Security strength:80ECDSA SigVer (FIPS186-4): (A5504, A5527) ECDSA SigVer

© 2025 SUSE, LLC/atsec information security corporation.

Page 32
NameTypeDescriptionPropertiesAlgorithms
(SHA-1); 112, 128, 192, 256 bits (other hashes)(FIPS186-5): (A5504, A5527)
Digital signature verification with RSADigSig- SigVerVerify a signature with RSAPadding:PKCS#1 v1.5 Hashes:SHA-256 Key size(s):4096 bits (149 bits)RSA SigVer (FIPS186-4): (A5503, A5526, A5664) RSA SigVer (FIPS186-5): (A5503, A5526, A5664)
Shared secret computation with DHKAS-SSCCompute a shared secret using Diffie- HellmanGroups:ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192 Security strength:112- 200 bits KAS role:initiator, responder KAS Scheme:dhEphemKAS-FFC-SSC Sp800-56Ar3: (A5503, A5526)
Shared secret computation with ECDHKAS-SSCCompute a shared secret using Elliptic Curve Diffie- HellmanCurves:P-256, P-384 Security strength:128, 192 bits KAS role:initiator, responder KAS scheme:ephemeralUnifie dKAS-ECC-SSC Sp800-56Ar3: (A5503, A5526)
Key derivation with KBKDFKBKDFDerive a symmetric key from a key-derivation keyKDF mode:Counter MAC mode:AES-CMAC with 128-, 192-, 256-bit keys; HMAC with SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA3-224, SHA3-256, SHA3-384, SHA3-512 Derived key length:112- 4096 bits Security strength:112- 256 bitsKDF SP800- 108: (A5503, A5526)

d Table 9: Security Function Implementations © 2025 SUSE, LLC/atsec information security corporation.

Page 33
2.7 Algorithm Specific Information
2.7.1 AES GCM IV

The Crypto Officer shall consider the following requirements and restrictions when using the module. For IPsec, the module offers the AES GCM implementation and uses the context of Scenario

1 of FIPS 140-3 IG C.H. The mechanism for IV generation is compliant with RFC 4106. IVs

generated using this mechanism may only be used in the context of AES GCM encryption within the IPsec protocol. The module does not implement IPsec. The module’s implementation of AES GCM is used together with an application that runs outside the module’s cryptographic boundary. This application must use RFC 7296 compliant IKEv2 to establish the shared secret SKEYSEED from which the AES GCM encryption keys are derived. The design of the IPsec protocol implicitly ensures that the counter (the nonce_explicit part of the IV) does not exhaust the maximum number of possible values for a given session key. In the event the module’s power is lost and restored, the consuming application must ensure that a new key for use with the AES GCM key encryption or decryption under this scenario shall be established. The module also provides a non-approved AES GCM encryption service which accepts arbitrary external IVs from the operator. This service can be requested by invoking the crypto_aead_encrypt API function with an AES GCM handle. Any approved use of the AES GCM service is indicated by the crypto_aead_get_flags(tfm) API returning the CRYPTO_TFM_FIPS_COMPLIANCE flag, as described in section 4.3.

2.7.2 AES XTS

The length of a single data unit encrypted or decrypted with AES XTS shall not exceed 220 AES blocks, that is 16MB, of data per XTS instance. An XTS instance is defined in Section 4 of SP 800-38E. To meet the requirement stated in IG C.I, the module implements a check to ensure that the two AES keys used in AES XTS mode are not identical. As the module does not implement symmetric key generation, this check is performed when the keys are input by the operator. Key_1 and Key_2 shall be generated and/or established independently according to the rules for component symmetric keys from NIST SP 800-133r2, Section 6.3. The XTS mode shall only be used for the cryptographic protection of data on storage devices. It shall not be used for other purposes, such as the encryption of data in transit.

2.7.3 RSA

For RSA signature verification, the module supports modulus size 4096 bits. The supported modulus size has been CAVP tested.

2.7.4 SP 800-56A Rev. 3 Assurances

To comply with the assurances found in Section 5.6.2 of SP 800-56A Rev. 3, the operator must use the Diffie-Hellman and EC Diffie-Hellman shared secret computation algorithms in the context of IETF protocols. Additionally, the module’s approved key pair generation service (see Approved Services table in Section 4.3 Approved Services) must be used to generate ephemeral Diffie-Hellman or EC Diffie-Hellman key pairs, or the key pairs must be obtained from another FIPS-validated module. As part of this service, the module will internally perform the full public key validation of the generated public key. © 2025 SUSE, LLC/atsec information security corporation.

Page 34
CertVendor
NumberName
E206SUSE LLC
E211SUSE LLC
NameTypeOperational EnvironmentSample SizeEntropy per SampleConditioning Component
SUSE Kernel CPU Time Jitter RNGNon- PhysicalSUSE Linux Enterprise Server 15 SP6 on AMD EPYC(TM) 7343; SUSE Linux Enterprise Server 15 SP6 on Ampere® Altra® Q80-30; SUSE Linux Enterprise Server 15 SP6 on IBM® Telum(TM); SUSE Linux Enterprise Server 15 SP6 on Intel® Xeon® Gold 5416S256 bitsFull entropySHA3-256 (A5503)
SUSE Kernel- RT CPU TimeNon- PhysicalSUSE Linux Enterprise Server 15 SP6 on AMD EPYC(TM) 7343; SUSE Linux Enterprise256 bitsFull entropySHA3-256 (A5526)

The module’s shared secret computation service will internally perform the full public key validation of the peer public key, complying with Sections 5.6.2.2.1 and 5.6.2.2.2 of SP 80056A Rev. 3.

2.7.5 Key Agreement

The module does not establish SSPs using an approved key agreement scheme (KAS). However, it does offer some or all of the underlying KAS cryptographic functionality to be used by an external operator/application as part of an approved KAS.

2.7.6 Key Transport

The module does not establish SSPs using an approved key transport scheme (KTS). However, it does offer approved authenticated algorithms that can be used by an external operator/application as part of an approved KTS.

2.7.7 SHA-1

Digital signature generation using SHA-1 is non-approved and not allowed in approved services.

2.8 RBG and Entropy 1

1 The kernel RT and kernel-default modules are compiled within different binaries. For this reason, two separate ESV

validations were performed. Entropy-related source code between the two versions the kernel is the same. © 2025 SUSE, LLC/atsec information security corporation.

Page 35

Name Jitter RNG

Type

Operational Environment Server 15 SP6 on Intel® Xeon® Gold 5416S

Sample Size

Entropy per Sample

Conditioning Component

Table 11: Entropy Sources The module implements three different Deterministic Random Bit Generator (DRBG) implementations based on SP 800-90Ar1: CTR_DRBG, Hash_DRBG, and HMAC_DRBG. Each of these DRBG implementations can be instantiated by the operator of the module. When instantiated, these DRBGs can be used to generate random numbers for external usage. Additionally, the module employs a specific HMAC-SHA2-512 DRBG implementation for internal purposes (e.g. to generate initialization vectors). This DRBG is initially seeded with

384 output bits from the entropy source (384 bits of entropy) and reseeded with 256 output

bits from the entropy source (256 bits of entropy). Outputs of multiple GetEntropy() calls are concatenated to receive the entropy input length greater than 256 bits. The output is truncated to get the entropy input string which is not a multiple of 256. E.g. The 384 bits of entropy source output is obtained by calling the GetEntropy() twice, with each call providing 256 bits of output. The second call output is truncated to 128 bits and concatenated to the 256 bit output from the first call. The module complies with the Public Use Document for ESV certificate E205 by reading entropy data from the jent_kcapi_random() function, which corresponds to the GetEntropy() conceptual interface. The operational environment on the ESV certificate is identical to the operating system described in this document. There are no maintenance requirements for the entropy source.

2.9 Key Generation

The module implements asymmetric key pair generation compliant with SP 800-133 Rev.

  1. When random values are required, they are obtained from the SP 800-90A Rev. 1 approved DRBG, compliant with Section 4 of SP 800-133 Rev. 2 (without XOR): • Safe primes key pair generation: compliant with SP 800-133 Rev. 2, Section 5.2, which maps to SP 800-56A Rev.
  2. The method described in Section 5.6.1.1.4 of SP 800-56A Rev. 3 (“Testing Candidates”) is used. • ECC (ECDH and ECDSA) key pair generation: compliant with SP 800-133 Rev. 2, Section 5.1, which maps to FIPS 186-5. The method described in Appendix A.2.2 of FIPS 186-5 (“Rejection Sampling”) is used. Additionally, the module implements the following key derivation methods: • KBKDF: compliant with SP 800-108 Rev.
  3. This implementation can be used to generate secret keys from a pre-existing key-derivation-key. Intermediate key generation values are not output from the module and are explicitly zeroized after processing the service.
2.10 Key Establishment

The module implements shared secret computation as listed in the Security Function Implementations table in 2.6 Security Function Implementations. © 2025 SUSE, LLC/atsec information security corporation.

Page 36
2.11 Industry Protocols

AES GCM with internal IV generation in the approved mode is compliant with RFC 4106 and shall only be used in conjunction with the IPsec protocol. No parts of this protocol, other than the AES GCM implementation, have been tested by the CAVP and CMVP. © 2025 SUSE, LLC/atsec information security corporation.

Page 37
Physical PortLogical Interface(s)Data That Passes
N/AData InputAPI data input parameters, AF_ALG type sockets
N/AData OutputAPI data output parameters, AF_ALG type sockets
N/AControl InputAPI function calls, API control input parameters, AF_ALG type sockets, kernel command line
N/AStatus OutputAPI return values, AF_ALG type sockets, kernel logs
3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

Table 12: Ports and Interfaces The logical interfaces are the APIs through which the applications request services. These logical interfaces are logically separated from each other by the API design, AF_ALG type socket that allows the applications running in the user space to request cryptographic services from the module. © 2025 SUSE, LLC/atsec information security corporation.

Page 38
NameTypeOperator TypeAuthentication Methods
Crypto OfficerRoleCONone
NameDescrip tionIndicatorInput sOutputsSecurity Functio nsSSP Access
Message digestCompute a message digestcrypto_shash_init returns 0Messa geDigest valueMessage digestCrypto Officer
Encryptio nEncrypt a plaintextcrypto_skcipher_setkey returns 0AES key, plainte xtCiphertex tEncryptio n with AESCrypto Officer - AES key: W,E
Decrypti onDecrypt a cipherte xtcrypto_skcipher_setkey returns 0AES key, ciphert extPlaintextDecrypti on with AESCrypto Officer - AES key: W,E
Authenti cated encryptio nEncrypt and authenti cate a plaintextFor all except AES GCM: crypto_aead_setkey returns 0; For AES GCM: crypto_aead_get_flags(t fm) has the CRYPTO_TFM_ FIPS_COMPLIANCE flag setAES key, plainte xt, IVCiphertex t, MAC tagAuthenti cated encryptio nCrypto Officer - AES key: W,E
Authenti catedDecrypt an authentiFor all except AES GCM: crypto_aead_setkey returns 0; For AES GCM:AES key, ciphertPlaintext or failureAuthenti catedCrypto Officer - AES
4 Roles, Services, and Authentication

The module does not implement authentication.

4.2 Roles

Table 13: Roles No support is provided for multiple concurrent operators.

4.3 Approved Services

W,E W,E © 2025 SUSE, LLC/atsec information security corporation.

Page 39
NameDescrip tionIndicatorInput sOutputsSecurity Functio nsSSP Access
decryptio ncated cipherte xtcrypto_aead_get_flags(t fm) has the CRYPTO_TFM_ FIPS_COMPLIANCE flag setext, MAC tag, IVdecryptio nkey: W,E
Encrypt then MACEncrypt plaintext with AES and use HMAC authenti cate itcrypto_shash_init returns 0AES key, HMAC key, plainte xtCiphertex t, MAC tagAuthenti cated encryptio nCrypto Officer - AES key: W,E - HMAC key: W,E
Decrypt then verifyDecrypt an authenti cated a cipherte xt using AES and HMACcrypto_shash_init returns 0AES key, HMAC key, ciphert ext, MAC tagPlaintext or failureAuthenti cated decryptio nCrypto Officer - AES key: W,E - HMAC key: W,E
Message authentic ation generati onCompute a MAC tagcrypto_shash_init returns 0AES: AES key, messa ge; HMAC: HMAC key, messa geMAC tagMessage authentic ationCrypto Officer - AES key: W,E - HMAC key: W,E
Message authentic ation verificati onCompute a MAC tagcrypto_shash_init returns 0AES: AES key, messa ge, MAC tag; HMAC: HMAC key, messa ge,Success/F ailureMessage authentic ationCrypto Officer - AES key: W,E - HMAC key: W,E

W,E © 2025 SUSE, LLC/atsec information security corporation.

Page 40
NameDescrip tionIndicatorInput s MAC tagOutputsSecurity Functio nsSSP Access
Random number generati onGenerat e random bytescrypto_rng_get_bytes returns 0Output lengthRandom bytesRandom number generati on with DRBGsCrypto Officer - Entropy input: W,E,Z - CTR_DR BG seed: G,E,Z - Hash_D RBG seed: G,E,Z - HMAC_ DRBG seed: G,E,Z - CTR_DR BG Internal state (V, Key): G,W,E - Hash_D RBG Internal state (V, C): G,W,E - HMAC_ DRBG Internal state (V, Key): G,W,E

W,E,Z G,E,Z G,E,Z G,E,Z (V, G,W,E (V, C): G,W,E (V, G,W,E © 2025 SUSE, LLC/atsec information security corporation.

Page 41
NameDescrip tionIndicatorInput sOutputsSecurity Functio nsSSP Access
Key derivatio nDerive a symmetr ic key from a key- derivatio n keycrypto_kdf108_ctr_gene rate returns 0Output lengthDerived keyKey derivatio n with KBKDFCrypto Officer - Key- derivati on key: W,E - Derived key: G,R
DH Key pair generati onGenerat e an asymme tric DH key pair using Diffie- Hellmancrypto_kpp_set_secret() and crypto_kpp_generate_p ublic_key() return 0GroupDH key pairKey pair generati on with Safe PrimesCrypto Officer - Module- generat ed DH private key: G,R - Module- generat ed DH public key: G,R - Interme diate key generati on value: G,E,Z
EC Key pair generati onGenerat e an asymme tric EC key paircrypto_kpp_set_secret() and crypto_kpp_generate_p ublic_key() return 0CurveEC key pairKey pair generati on with ECDSACrypto Officer - Module- generat ed EC private key: G,R - Module- generat

G,R G,R G,R G,E,Z G,R © 2025 SUSE, LLC/atsec information security corporation.

Page 42
NameDescrip tionIndicatorInput sOutputsSecurity Functio nsSSP Access ed EC public key: G,R - Interme diate key generati on value: G,E,Z
Shared secret computa tionCompute a shared secret using (EC) Diffie- Hellmancrypto_kpp_compute_sh ared_secret() returns 0Public key (peer), Private keyShared secretShared secret computa tion with DH Shared secret computa tion with ECDHCrypto Officer - DH private key: W,E - DH public key: W,E - EC private key: W,E - EC public key: W,E - Shared secret: G,R
Error detection codeCompute an EDC (crc32, crct10dif )NoneMessa geEDCNoneCrypto Officer
Compres sionCompres s data (deflate, lz4, lz4hc, lzo,NoneDataCompress ed dataNoneCrypto Officer

G,R G,E,Z W,E W,E G,R ) © 2025 SUSE, LLC/atsec information security corporation.

Page 43
NameDescrip tion zlibdefla te, zstd)IndicatorInput sOutputsSecurity Functio nsSSP Access
Generic system callUse the kernel to perform various non- cryptogr aphic operatio nsNoneIdentifi er, variou s argum entsVarious return valuesNoneCrypto Officer
Show versionReturn the module name and version informati onNoneN/AModule name and versionNoneCrypto Officer
Show statusReturn the module statusNoneN/AModule statusNoneCrypto Officer
Self-testPerform the CASTs and integrity testsNoneN/APass/failEncryptio n with AES Decrypti on with AES Message digest Message authentic ation Random number generati on with DRBGs Authenti cated encryptio n AuthentiCrypto Officer

n © 2025 SUSE, LLC/atsec information security corporation.

Page 44
NameDescrip tionIndicatorInput sOutputsSecurity Functio nsSSP Access
cated decryptio n Digital signature verificati on with ECDSA Digital signature verificati on with RSA Shared secret computa tion with DH Shared secret computa tion with ECDH Key derivatio n with KBKDF
Zeroizati onZeroize all SSPsNoneAny SSPN/ANoneCrypto Officer - AES key: Z - HMAC key: Z - Entropy input: Z - CTR_DR BG Internal state (V, Key): Z - Hash_D RBG Internal state

n (V, © 2025 SUSE, LLC/atsec information security corporation.

Page 45

Name

Descrip tion

Indicator

Input s

Outputs

Security Functio ns

SSP Access (V, C): Z - HMAC_ DRBG Internal state (V, Key): Z - CTR_DR BG seed: Z - Hash_D RBG seed: Z - HMAC_ DRBG seed: Z - Key- derivati on key: Z - Derived key: Z - Interme diate key generati on value: Z - Module- generat ed DH private key: Z - Module- generat ed DH public key: Z - Module- generat

(V, C): Z (V, Z © 2025 SUSE, LLC/atsec information security corporation.

Page 46

Name

Descrip tion

Indicator

Input s

Outputs

Security Functio ns

SSP Access ed EC private key: Z - Module- generat ed EC public key: Z - DH private key: Z - DH public key: Z - EC private key: Z - EC public key: Z - Shared secret: Z

NameDescriptionAlgorithmsRole
AES GCM external IV encryptionEncrypt a plaintext using AES GCM with an external IVAES-GCM with external IVCO
Key derivationDerive a key from a key- derivation key or a shared secretKBKDF (by using the libkcapi) HKDF (by using the libkcapi)CO

Z Table 14: Approved Services The table above lists the approved services. The following convention is used to specify access rights to SSPs:

4.4 Non-Approved Services

© 2025 SUSE, LLC/atsec information security corporation.

Page 47
NameDescriptionAlgorithmsRole
Password-based key derivationDerive a key from a passwordPBKDF2 (by using the libkcapi)CO
RSA encryption primitiveCompute the raw RSA encryption of a plaintextRSACO
RSA decryption primitiveCompute the raw RSA decryption of a ciphertextRSACO
RSA signature generation (pre-hashed message)Generate a digital signature for a pre-hashed messageRSA with PKCS#1 v1.5 padding ECDSACO
RSA signature verification (pre-hashed message)Verify a digital signature for a pre-hashed messageRSA with PKCS#1 v1.5 padding ECDSACO

Table 15: Non-Approved Services

4.5 External Software/Firmware Loaded

The module does not load external software or firmware. © 2025 SUSE, LLC/atsec information security corporation.

Page 48
5 Software/Firmware Security
5.1 Integrity Techniques

The Linux kernel binary is integrity tested using an HMAC-SHA2-256 calculation performed by the fipscheck application (which utilizes the module’s HMAC and SHA-256 implementations). An HMAC-SHA2-256 calculation is also performed on the fipscheck application and the libkcapi library to verify their integrity. The kernel crypto object files listed in section 2.2 are loaded on start-up by the module and verified using RSA signature verification with PKCS#1 v1.5 padding, SHA-256, and a 4096-bit key. The fipscheck application first executes the HMAC-SHA2-256 self-test. After this self-test is successful, the fipscheck application is used to perform an HMAC calculation of the libkcapi library, the kernel binary, and of its own binary to verify their integrity. After the integrity of these components has been verified, the self-test for the RSA signature verification implementation is run. Upon successful run of this self-test, the RSA signature verification implementation of the kernel is used to verify the integrity of the crypto object files listed in section 2.2 and loaded at start-up.

5.2 Initiate on Demand

Integrity tests are performed as part of the pre-operational self-tests, which are executed when the module is initialized. The integrity tests can be invoked on demand by unloading and subsequently re-initializing the module, which will perform (among others) the software integrity tests. © 2025 SUSE, LLC/atsec information security corporation.

Page 49
6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Modifiable How Requirements are Satisfied: The operating system provides process isolation and memory protection mechanisms that ensure appropriate separation for memory access among the processes on the system. Each process has control over its own data and uncontrolled access to the data of other processes is prevented.

6.2 Configuration Settings and Restrictions

The module shall be installed as stated in Section 11.1. Instrumentation tools like the ptrace system call, gdb and strace, as well as other tracing mechanisms offered by the Linux environment such as ftrace or systemtap, shall not be used in the operational environments. The use of any of these tools implies that the cryptographic module is running in a non-validated operational environment. © 2025 SUSE, LLC/atsec information security corporation.

Page 50
7 Physical Security

The module is comprised of software only and therefore this section is not applicable. © 2025 SUSE, LLC/atsec information security corporation.

Page 51
8 Non-Invasive Security

This module does not implement any non-invasive security mechanism and therefore this section is not applicable. © 2025 SUSE, LLC/atsec information security corporation.

Page 52
Storage Area NameDescriptionPersistence Type
RAMTemporary storage for SSPs used by the module as part of service executionDynamic

Name AF_ALG_typ e sockets (input) AF_ALG_typ e sockets (output) API input parameters (input) API output parameters (output)

From Operator calling application (TOEPP), userspace Cryptographi c module Operator calling application (TOEPP), kernel space Cryptographi c module

To Cryptographi c module Operator calling application (TOEPP), userspace Cryptographi c module Operator calling application (TOEPP), kernel space

Format Type Plaintex t Plaintex t Plaintex t Plaintex t

Distributio n Type Manual Manual Manual Manual

Entry Type Electroni c Electroni c Electroni c Electroni c

SFI or Algorith m

9 Sensitive Security Parameters Management
9.1 Storage Areas

Table 16: Storage Areas The module does not perform persistent storage of SSPs. The SSPs are temporarily stored in the RAM in plaintext form. SSPs are provided to the module by the calling process and are destroyed when released by the appropriate zeroization function calls.

9.2 SSP Input-Output Methods

m Table 17: SSP Input-Output Methods © 2025 SUSE, LLC/atsec information security corporation.

Page 53
Zeroization MethodDescriptionRationaleOperator Initiation
AutomaticAutomatically zeroized by the module when no longer neededMemory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable.N/A
Free cipher handleZeroizes the SSPs contained within the cipher handleMemory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable. The completion of the zeroization routine indicates that the zeroization procedure succeeded.By calling the appropriate zeroization functions: AES key: crypto_free_skcipher and crypto_free_aead; HMAC key: crypto_free_shash and crypto_free_ahash; DRBG internal state: crypto_free_rng; DRBG seed: crypto_free_rng; Entropy input string: crypto_free_rng; Key-derivation key, Derived key: kfree_sensitive; Shared secret: crypto_free_kpp
Remove power from the moduleDe-allocates the volatile memory used to store SSPsVolatile memory used by the module is overwritten within nanoseconds when power is removed. Module power off indicates that the zeroization procedure succeeded. The successful removal of power implicitly indicates that the zeroization is complete.By removing power
NameDescripti onSize - Strengt hType - CategoryGenerat ed ByEstablish ed ByUsed By
AES keyAES key used for128, 192, 256Symmetric Key - CSPEncryption with AES

Table 18: SSP Zeroization Methods All data output is inhibited during zeroization. h © 2025 SUSE, LLC/atsec information security corporation.

Page 54
NameDescripti onSize - Strengt hType - CategoryGenerat ed ByEstablish ed ByUsed By
encryption , decryption , and computing MAC tags.bits - 128, 192, 256 bitsDecryption with AES Message authenticati on Authenticat ed encryption Authenticat ed decryption
HMAC keyHMAC key.112- 524288 bits - 112-256 bitsAuthenticati on key - CSPMessage authenticati on
Entropy inputEntropy input used to seed the DRBGs. Compliant with IG D.L.128-384 bits - 128-384 bitsEntropy input - CSPRandom number generation with DRBGs
CTR_DRBG seedDRBG seed derived from entropy input. Compliant with IG D.L.256, 320, 384 bits - 128, 192, 256 bitsSeed - CSPRandom number generatio n with DRBGsRandom number generation with DRBGs
Hash_DRB G seedDRBG seed derived from entropy input. Compliant with IG D.L.440, 888 bits - 128, 256 bitsSeed - CSPRandom number generatio n with DRBGsRandom number generation with DRBGs

h D.L. D.L. D.L. © 2025 SUSE, LLC/atsec information security corporation.

Page 55
NameDescripti onSize - Strengt hType - CategoryGenerat ed ByEstablish ed ByUsed By
HMAC_DR BG seedDRBG seed derived from entropy input. Compliant with IG D.L.440, 888 bits - 128, 256 bitsSeed - CSPRandom number generatio n with DRBGsRandom number generation with DRBGs
CTR_DRBG Internal state (V, Key)Internal state of CTR_DRBG instances. Compliant with IG D.L.256, 320, 384 bits - 128, 192, 256 bitsInternal state - CSPRandom number generatio n with DRBGsRandom number generation with DRBGs
Hash_DRB G Internal state (V, C)Internal state of Hash_DRB G instances. Compliant with IG D.L.880, 1776 bits - 128, 256 bitsInternal state - CSPRandom number generatio n with DRBGsRandom number generation with DRBGs
HMAC_DR BG Internal state (V, Key)Internal state of HMAC_DR BG instances. Compliant with IG D.L.320, 512, 1024 bits - 128, 256 bitsInternal state - CSPRandom number generatio n with DRBGsRandom number generation with DRBGs
Key- derivation keySymmetric key used to derive symmetric keys112- 4096 bits - 112- 256 bitsSymmetric key - CSPKey derivation with KBKDF
Derived keySymmetric key derived from a key-112- 4096 bits - 112- 256 bitsSymmetric key - CSPKey derivation with KBKDFKey derivation with KBKDF

h D.L. D.L. D.L. D.L. © 2025 SUSE, LLC/atsec information security corporation.

Page 56
NameDescripti on derivation keySize - Strengt hType - CategoryGenerat ed ByEstablish ed ByUsed By
Intermedia te key generation valueIntermedia te key pair generation value generated during key generation services (SP 800- 133 Rev. 2 Section 4, 5.1, and 5.2)112- 8912 bits - 112- 256 bitsIntermediat e value - CSPKey pair generatio n with ECDSA Key pair generatio n with Safe PrimesKey pair generation with ECDSA Key pair generation with Safe Primes
Module- generated DH private keyDH private key generated by the moduleffdhe204 8, ffdhe307 2, ffdhe409 6, ffdhe614 4, ffdhe819 2 - 112- 200 bitsPrivate key - CSPKey pair generatio n with Safe PrimesKey pair generation with Safe Primes
Module- generated DH public keyDH public key generated by the moduleffdhe204 8, ffdhe307 2, ffdhe409 6, ffdhe614 4, ffdhe819 2 - 112- 200 bitsPublic key - PSPKey pair generatio n with Safe PrimesKey pair generation with Safe Primes
Module- generated EC private keyEC private key generated by the moduleP-256, P- 384 - 128, 192 bitsPrivate key - CSPKey pair generatio n with ECDSAKey pair generation with ECDSA

h 5.2) 6, 4, 6, 4, © 2025 SUSE, LLC/atsec information security corporation.

Page 57
NameDescripti onSize - Strengt hType - CategoryGenerat ed ByEstablish ed ByUsed By
Module- generated EC public keyEC public key generated by the moduleP-256, P- 384 - 128, 192 bitsPublic key - PSPKey pair generatio n with ECDSAKey pair generation with ECDSA
DH private keyDH private key input to the module and used for shared secret computati onffdhe204 8, ffdhe307 2, ffdhe409 6, ffdhe614 4, ffdhe819 2 - 112- 200 bitsPrivate key - CSPShared secret computatio n with DH
DH public keyDH public key input to the module and used for shared secret computati onffdhe204 8, ffdhe307 2, ffdhe409 6, ffdhe614 4, ffdhe819 2 - 112- 200 bitsPublic key - PSPShared secret computatio n with DH
EC private keyECDH private key input to the module and used for shared secret computati onP-256, P- 384 - 128, 192 bitsPrivate key - CSPShared secret computatio n with ECDH
EC public keyECDH public key input to the module and used for sharedP-256, P- 384 - 128, 192 bitsPublic key - PSPShared secret computatio n with ECDH

h © 2025 SUSE, LLC/atsec information security corporation.

Page 58
NameDescripti on secret computati onSize - Strengt hType - CategoryGenerat ed ByEstablish ed ByUsed By
Shared secretShared secret generated by ECDH/DH shared secret computati on224- 8912 bits - 112- 256 bitsShared Secret - CSPShared secret computati on with DH Shared secret computati on with ECDHShared secret computatio n with DH Shared secret computatio n with ECDH Key derivation with KBKDF
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
AES keyAF_ALG_typ e sockets (input) API input parameters (input)RAM:Plaintex tUntil cipher handle is freed or module powered offFree cipher handle Remove power from the module
HMAC keyAF_ALG_typ e sockets (input) API input parameters (input)RAM:Plaintex tUntil cipher handle is freed or module powered offFree cipher handle Remove power from the module
Entropy inputRAM:Plaintex tFrom generation until DRBG seed/reseedAutomaticCTR_DRBG Seed:Derives Hash_DRBG Seed:Derives HMAC_DRBG Seed:Derives
CTR_DRBG seedRAM:Plaintex tWhile the DRBG is being instantiatedAutomaticEntropy input:Derived From CTR_DRBG

h Table 19: SSP Table 1 © 2025 SUSE, LLC/atsec information security corporation.

Page 59
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs Internal state (V, Key):Derives
Hash_DRBG seedRAM:Plaintex tWhile the DRBG is being instantiatedAutomaticEntropy input:Derived From Hash_DRBG Internal state (V, C):Derives
HMAC_DRB G seedRAM:Plaintex tWhile the DRBG is being instantiatedAutomaticEntropy input:Derived From HMAC_DRBG Internal state (V, Key):Derives
CTR_DRBG Internal state (V, Key)RAM:Plaintex tFrom DRBG instantiation until DRBG is un- instantiatedFree cipher handle Remove power from the moduleCTR_DRBG seed:Derived From
Hash_DRBG Internal state (V, C)RAM:Plaintex tFrom DRBG instantiation until DRBG is un- instantiatedFree cipher handle Remove power from the moduleHash_DRBG seed:Derived From
HMAC_DRB G Internal state (V, Key)RAM:Plaintex tFrom DRBG instantiation until DRBG is un- instantiatedFree cipher handle Remove power from the moduleHMAC_DRBG seed:Derived From
Key- derivation keyAPI input parameters (input)RAM:Plaintex tFrom service invocation until cipherhandl e is freedFree cipher handle Remove power from the moduleDerived key:Derives
Derived keyAPI output parameters (output)RAM:Plaintex tFrom service invocation until cipherhandl e is freedFree cipher handle Remove power from the moduleKey-derivation key:Derived From

© 2025 SUSE, LLC/atsec information security corporation.

Page 60
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
Intermediat e key generation valueRAM:Plaintex tFrom service invocation until it is completedAutomatic Remove power from the moduleModule- generated DH private key:Generates Module- generated DH public key:Generates Module- generated EC private key:Generates Module- generated EC public key:Generates
Module- generated DH private keyAF_ALG_typ e sockets (output) API output parameters (output)RAM:Plaintex tUntil cipher handle is freed or module powered offFree cipher handle Remove power from the moduleIntermediate key generation value:Generated from Module- generated DH public key:Paired With
Module- generated DH public keyAF_ALG_typ e sockets (output) API output parameters (output)RAM:Plaintex tUntil cipher handle is freed or module powered offFree cipher handle Remove power from the moduleIntermediate key generation value:Generated from Module- generated DH private key:Paired With
Module- generated EC private keyAF_ALG_typ e sockets (output) API output parameters (output)RAM:Plaintex tUntil cipher handle is freed or module powered offFree cipher handle Remove power from the moduleIntermediate key generation value:Generated From Module- generated EC public key:Paired With
Module- generated EC public keyAF_ALG_typ e sockets (output) API outputRAM:Plaintex tUntil cipher handle is freed orFree cipher handle RemoveIntermediate key generation value:Generated From Module-

© 2025 SUSE, LLC/atsec information security corporation.

Page 61
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
parameters (output)module powered offpower from the modulegenerated EC private key:Paired With
DH private keyAF_ALG_typ e sockets (input) API input parameters (input)RAM:Plaintex tFree cipher handle Remove power from the moduleDH public key:Paired With Shared secret:Establishe s
DH public keyAF_ALG_typ e sockets (input) API input parameters (input)RAM:Plaintex tFree cipher handle Remove power from the moduleDH private key:Paired With Shared secret:Establishe s
EC private keyAF_ALG_typ e sockets (input) API input parameters (input)RAM:Plaintex tFree cipher handle Remove power from the moduleEC public key:Paired With Shared secret:Establishe s
EC public keyAF_ALG_typ e sockets (input) API input parameters (input)RAM:Plaintex tFree cipher handle Remove power from the moduleEC private key:Paired With Shared secret:Establishe s
Shared secretAF_ALG_typ e sockets (output) API output parameters (output)RAM:Plaintex tFrom service invocation until cipherhandl e is freedFree cipher handle Remove power from the moduleDH private key:Established By DH public key:Established By EC private key:Established By EC public key:Established By

Table 20: SSP Table 2 © 2025 SUSE, LLC/atsec information security corporation.

Page 62
9.5 Transitions

The SHA-1 algorithm as implemented by the module will be non-approved for all purposes, starting January 1, 2031. © 2025 SUSE, LLC/atsec information security corporation.

Page 63
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
HMAC-SHA2- 256 (A5503) - kernel version 3.5256-bit keyMessage AuthenticationSW/FW IntegrityModule becomes operational and services are available for use.Integrity test for kernel binary version 3.5
HMAC-SHA2- 256 (A5503) - fipscheck version 3.5256-bit keyMessage AuthenticationSW/FW IntegrityModule becomes operational and services are available for use.Integrity test for fipscheck application version 3.5
RSA SigVer (FIPS186-5) (A5503) - object files version 3.54096-bit key with SHA2- 256Signature VerificationSW/FW IntegrityModule becomes operational and services are available for use.Integrity test for kernel object files version 3.5
HMAC-SHA2- 256 (A5526) - kernel version 3.6256-bit keyMessage AuthenticationSW/FW IntegrityModule becomes operational and services are available for use.Integrity test for kernel binary version 3.6
HMAC-SHA2- 256 (A5526) - fipscheck version 3.6256-bit keyMessage AuthenticationSW/FW IntegrityModule becomes operational and services are available for use.Integrity test for fipscheck application version 3.6
RSA SigVer (FIPS186-5) (A5526) - object files version 3.64096-bit key with SHA2- 256Signature VerificationSW/FW IntegrityModule becomes operational and services are available for use.Integrity test for kernel object files version 3.6
10 Self-Tests
10.1 Pre-Operational Self-Tests

Table 21: Pre-Operational Self-Tests © 2025 SUSE, LLC/atsec information security corporation.

Page 64
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
SHA-1 (A5503)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization
SHA-1 (A5516)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization
SHA-1 (A5517)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization
SHA-1 (A5518)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization

The pre-operational software integrity tests are performed automatically when the module is powered on, before the module transitions into the operational state. The algorithms used for the integrity test (i.e., HMAC-SHA2-256 and RSA SigVer with 4096 bit key) run their CASTs before the integrity test is performed. While the module is executing the self-tests, services are not available, and data output (via the data output interface) is inhibited until the pre-operational software integrity self-tests are successfully completed. The module transitions to the operational state only after the pre-operational self-tests are passed successfully.

10.2 Conditional Self-Tests

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 65
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
SHA-1 (A5519)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization
SHA-1 (A5520)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization
SHA-1 (A5526)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization
SHA-1 (A5539)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization
SHA-1 (A5540)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization
SHA-1 (A5541)0-8184 bit messagesKATCASTModule becomes operationaMessage DigestModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 66
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicator l and services are available for use.DetailsConditions
SHA-1 (A5542)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization
SHA-1 (A5664)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization
SHA2-256 (A5503)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization
SHA2-256 (A5516)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization
SHA2-256 (A5517)0-8184 bit messagesKATCASTModule becomes operationa l and services areMessage DigestModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 67
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicator available for use.DetailsConditions
SHA2-256 (A5518)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization
SHA2-256 (A5519)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization
SHA2-256 (A5520)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization
SHA2-256 (A5524)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization
SHA2-256 (A5525)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 68
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
SHA2-256 (A5526)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization
SHA2-256 (A5539)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization
SHA2-256 (A5540)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization
SHA2-256 (A5541)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization
SHA2-256 (A5542)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization
SHA2-256 (A5664)0-8184 bit messagesKATCASTModule becomes operationaMessage DigestModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 69
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicator l and services are available for use.DetailsConditions
SHA2-512 (A5503)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization
SHA2-512 (A5516)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization
SHA2-512 (A5517)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization
SHA2-512 (A5518)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization
SHA2-512 (A5525)0-8184 bit messagesKATCASTModule becomes operationa l and services areMessage DigestModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 70
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicator available for use.DetailsConditions
SHA2-512 (A5526)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization
SHA2-512 (A5539)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization
SHA2-512 (A5540)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization
SHA2-512 (A5541)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization
SHA2-512 (A5664)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 71
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
SHA3-224 (A5503)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization
SHA3-224 (A5526)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization
SHA3-224 (A5664)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization
SHA3-256 (A5503)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization
SHA3-256 (A5526)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization
SHA3-256 (A5664)0-8184 bit messagesKATCASTModule becomes operationaMessage DigestModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 72
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicator l and services are available for use.DetailsConditions
SHA3-384 (A5503)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization
SHA3-384 (A5526)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization
SHA3-384 (A5664)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization
SHA3-512 (A5503)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization
SHA3-512 (A5526)0-8184 bit messagesKATCASTModule becomes operationa l and services areMessage DigestModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 73
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicator available for use.DetailsConditions
SHA3-512 (A5664)0-8184 bit messagesKATCASTModule becomes operationa l and services are available for use.Message DigestModule initialization
AES-GCM - Encrypt (A5503)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-GCM - Encrypt (A5505)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-GCM - Encrypt (A5506)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-GCM - Encrypt (A5507)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 74
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
AES-GCM - Encrypt (A5508)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-GCM - Encrypt (A5509)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-GCM - Encrypt (A5510)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-GCM - Encrypt (A5511)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-GCM - Encrypt (A5512)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 75
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
AES-GCM - Encrypt (A5513)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-GCM - Encrypt (A5514)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-GCM - Encrypt (A5515)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-GCM - Encrypt (A5521)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-GCM - Encrypt (A5522)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 76
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
AES-GCM - Encrypt (A5523)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-GCM - Encrypt (A5526)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-GCM - Encrypt (A5528)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-GCM - Encrypt (A5529)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-GCM - Encrypt (A5530)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 77
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
AES-GCM - Encrypt (A5531)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-GCM - Encrypt (A5532)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-GCM - Encrypt (A5533)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-GCM - Encrypt (A5534)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-GCM - Encrypt (A5535)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 78
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
AES-GCM - Encrypt (A5536)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-GCM - Encrypt (A5537)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-GCM - Encrypt (A5538)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-GCM - Encrypt (A5661)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-GCM - Encrypt (A5662)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 79
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
AES-GCM - Encrypt (A5663)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-GCM - Encrypt (A5664)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-GCM - Encrypt (A5665)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-GCM - Encrypt (A5666)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-GCM - Decrypt (A5503)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 80
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
AES-GCM - Decrypt (A5505)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-GCM - Decrypt (A5506)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-GCM - Decrypt (A5507)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-GCM - Decrypt (A5508)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-GCM - Decrypt (A5509)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 81
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
AES-GCM - Decrypt (A5510)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-GCM - Decrypt (A5511)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-GCM - Decrypt (A5512)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-GCM - Decrypt (A5513)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-GCM - Decrypt (A5514)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 82
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
AES-GCM - Decrypt (A5515)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-GCM - Decrypt (A5521)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-GCM - Decrypt (A5522)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-GCM - Decrypt (A5523)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-GCM - Decrypt (A5526)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 83
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
AES-GCM - Decrypt (A5528)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-GCM - Decrypt (A5529)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-GCM - Decrypt (A5530)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-GCM - Decrypt (A5531)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-GCM - Decrypt (A5532)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 84
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
AES-GCM - Decrypt (A5533)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-GCM - Decrypt (A5534)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-GCM - Decrypt (A5535)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-GCM - Decrypt (A5536)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-GCM - Decrypt (A5537)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 85
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
AES-GCM - Decrypt (A5538)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-GCM - Decrypt (A5661)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-GCM - Decrypt (A5662)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-GCM - Decrypt (A5663)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-GCM - Decrypt (A5664)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 86
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
AES-GCM - Decrypt (A5665)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-GCM - Decrypt (A5666)128, 192, 256 bit keys and 96-bit IVsKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-ECB - Encrypt (A5503)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-ECB - Encrypt (A5505)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-ECB - Encrypt (A5506)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 87
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
AES-ECB - Encrypt (A5507)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-ECB - Encrypt (A5508)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-ECB - Encrypt (A5509)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-ECB - Encrypt (A5510)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-ECB - Encrypt (A5511)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 88
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
AES-ECB - Encrypt (A5512)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-ECB - Encrypt (A5513)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-ECB - Encrypt (A5514)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-ECB - Encrypt (A5515)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-ECB - Encrypt (A5520)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 89
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
AES-ECB - Encrypt (A5521)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-ECB - Encrypt (A5522)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-ECB - Encrypt (A5523)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-ECB - Encrypt (A5524)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-ECB - Encrypt (A5526)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 90
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
AES-ECB - Encrypt (A5528)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-ECB - Encrypt (A5529)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-ECB - Encrypt (A5530)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-ECB - Encrypt (A5531)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-ECB - Encrypt (A5532)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 91
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
AES-ECB - Encrypt (A5533)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-ECB - Encrypt (A5534)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-ECB - Encrypt (A5535)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-ECB - Encrypt (A5536)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-ECB - Encrypt (A5537)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 92
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
AES-ECB - Encrypt (A5538)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-ECB - Encrypt (A5661)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-ECB - Encrypt (A5662)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-ECB - Encrypt (A5663)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-ECB - Encrypt (A5664)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 93
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
AES-ECB - Encrypt (A5665)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-ECB - Encrypt (A5666)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.EncryptionModule initialization
AES-ECB - Decrypt (A5503)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-ECB - Decrypt (A5505)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-ECB - Decrypt (A5506)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 94
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
AES-ECB - Decrypt (A5507)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-ECB - Decrypt (A5508)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-ECB - Decrypt (A5509)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-ECB - Decrypt (A5510)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-ECB - Decrypt (A5511)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 95
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
AES-ECB - Decrypt (A5512)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-ECB - Decrypt (A5513)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-ECB - Decrypt (A5514)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-ECB - Decrypt (A5515)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-ECB - Decrypt (A5520)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 96
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
AES-ECB - Decrypt (A5521)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-ECB - Decrypt (A5522)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-ECB - Decrypt (A5523)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-ECB - Decrypt (A5524)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-ECB - Decrypt (A5526)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 97
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
AES-ECB - Decrypt (A5528)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-ECB - Decrypt (A5529)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-ECB - Decrypt (A5530)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-ECB - Decrypt (A5531)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-ECB - Decrypt (A5532)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 98
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
AES-ECB - Decrypt (A5533)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-ECB - Decrypt (A5534)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-ECB - Decrypt (A5535)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-ECB - Decrypt (A5536)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-ECB - Decrypt (A5537)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 99
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
AES-ECB - Decrypt (A5538)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-ECB - Decrypt (A5661)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-ECB - Decrypt (A5662)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-ECB - Decrypt (A5663)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-ECB - Decrypt (A5664)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 100
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
AES-ECB - Decrypt (A5665)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
AES-ECB - Decrypt (A5666)128, 192, 256 bit keysKATCASTModule becomes operationa l and services are available for use.DecryptionModule initialization
HMAC- SHA-1 (A5503)32-64 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization
HMAC- SHA-1 (A5516)32-64 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization
HMAC- SHA-1 (A5517)32-64 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 101
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
HMAC- SHA-1 (A5518)32-64 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization
HMAC- SHA-1 (A5519)32-64 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization
HMAC- SHA-1 (A5520)32-64 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization
HMAC- SHA-1 (A5526)32-64 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization
HMAC- SHA-1 (A5539)32-64 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 102
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
HMAC- SHA-1 (A5540)32-64 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization
HMAC- SHA-1 (A5541)32-64 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization
HMAC- SHA-1 (A5542)32-64 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization
HMAC- SHA-1 (A5664)32-64 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization
HMAC- SHA2-224 (A5503)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 103
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
HMAC- SHA2-224 (A5516)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization
HMAC- SHA2-224 (A5517)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization
HMAC- SHA2-224 (A5518)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization
HMAC- SHA2-224 (A5519)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization
HMAC- SHA2-224 (A5520)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 104
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
HMAC- SHA2-224 (A5524)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization
HMAC- SHA2-224 (A5525)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization
HMAC- SHA2-224 (A5526)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization
HMAC- SHA2-224 (A5539)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization
HMAC- SHA2-224 (A5540)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 105
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
HMAC- SHA2-224 (A5541)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization
HMAC- SHA2-224 (A5542)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization
HMAC- SHA2-224 (A5664)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization
HMAC- SHA2-256 (A5503)32-64 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization. Before integrity test.
HMAC- SHA2-256 (A5516)32-64 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization. Before integrity test.

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 106
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
HMAC- SHA2-256 (A5517)32-64 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization. Before integrity test.
HMAC- SHA2-256 (A5518)32-64 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization. Before integrity test.
HMAC- SHA2-256 (A5519)32-64 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization. Before integrity test.
HMAC- SHA2-256 (A5520)32-64 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization. Before integrity test.
HMAC- SHA2-256 (A5524)32-64 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization. Before integrity test.

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 107
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
HMAC- SHA2-256 (A5525)32-64 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization. Before integrity test.
HMAC- SHA2-256 (A5526)32-64 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization. Before integrity test.
HMAC- SHA2-256 (A5539)32-64 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization. Before integrity test.
HMAC- SHA2-256 (A5540)32-64 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization. Before integrity test.
HMAC- SHA2-256 (A5541)32-64 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization. Before integrity test.

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 108
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
HMAC- SHA2-256 (A5542)32-64 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization. Before integrity test.
HMAC- SHA2-256 (A5664)32-64 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization. Before integrity test.
HMAC- SHA2-384 (A5503)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization
HMAC- SHA2-384 (A5516)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization
HMAC- SHA2-384 (A5517)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 109
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
HMAC- SHA2-384 (A5518)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization
HMAC- SHA2-384 (A5525)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization
HMAC- SHA2-384 (A5526)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization
HMAC- SHA2-384 (A5539)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization
HMAC- SHA2-384 (A5540)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 110
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
HMAC- SHA2-384 (A5541)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization
HMAC- SHA2-384 (A5664)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization
HMAC- SHA2-512 (A5503)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization. Before integrity test.
HMAC- SHA2-512 (A5516)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization. Before integrity test.
HMAC- SHA2-512 (A5517)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization. Before integrity test.

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 111
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
HMAC- SHA2-512 (A5518)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization. Before integrity test.
HMAC- SHA2-512 (A5525)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization. Before integrity test.
HMAC- SHA2-512 (A5526)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization. Before integrity test.
HMAC- SHA2-512 (A5539)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization. Before integrity test.
HMAC- SHA2-512 (A5540)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization. Before integrity test.

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 112
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
HMAC- SHA2-512 (A5541)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization. Before integrity test.
HMAC- SHA2-512 (A5664)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization. Before integrity test.
HMAC- SHA3-224 (A5503)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization
HMAC- SHA3-224 (A5526)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization
HMAC- SHA3-224 (A5664)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 113
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
HMAC- SHA3-256 (A5503)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization
HMAC- SHA3-256 (A5526)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization
HMAC- SHA3-256 (A5664)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization
HMAC- SHA3-384 (A5503)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization
HMAC- SHA3-384 (A5526)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 114
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
HMAC- SHA3-384 (A5664)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization
HMAC- SHA3-512 (A5503)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization
HMAC- SHA3-512 (A5526)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization
HMAC- SHA3-512 (A5664)32-1048 bit keysKATCASTModule becomes operationa l and services are available for use.Message authenticatio nModule initialization
Counter DRBG (A5503)128, 192, 256 bit keys with DF, with/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 115
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
Counter DRBG (A5505)128, 192, 256 bit keys with DF, with/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
Counter DRBG (A5506)128, 192, 256 bit keys with DF, with/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
Counter DRBG (A5507)128, 192, 256 bit keys with DF, with/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
Counter DRBG (A5508)128, 192, 256 bit keys with DF, with/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
Counter DRBG (A5509)128, 192, 256 bit keys with DF, with/without PR; Health test per section 11.3KATCASTModule becomes operationa l and services areInstantiate, Reseed, GenerateModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 116
Algorith m or TestTest Properties of SP 800- 90Arev1Test Metho dTest Typ eIndicator available for use.DetailsConditions
Counter DRBG (A5510)128, 192, 256 bit keys with DF, with/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
Counter DRBG (A5511)128, 192, 256 bit keys with DF, with/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
Counter DRBG (A5512)128, 192, 256 bit keys with DF, with/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
Counter DRBG (A5513)128, 192, 256 bit keys with DF, with/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
Counter DRBG (A5514)128, 192, 256 bit keys with DF, with/without PR; HealthKATCASTModule becomes operationa l and servicesInstantiate, Reseed, GenerateModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 117
Algorith m or TestTest Properties test per section 11.3 of SP 800- 90Arev1Test Metho dTest Typ eIndicator are available for use.DetailsConditions
Counter DRBG (A5515)128, 192, 256 bit keys with DF, with/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
Counter DRBG (A5521)128, 192, 256 bit keys with DF, with/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
Counter DRBG (A5522)128, 192, 256 bit keys with DF, with/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
Counter DRBG (A5523)128, 192, 256 bit keys with DF, with/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
Counter DRBG (A5526)128, 192, 256 bit keys with DF,KATCASTModule becomes operationaInstantiate, Reseed, GenerateModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 118
Algorith m or TestTest Properties with/without PR; Health test per section 11.3 of SP 800- 90Arev1Test Metho dTest Typ eIndicator l and services are available for use.DetailsConditions
Counter DRBG (A5528)128, 192, 256 bit keys with DF, with/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
Counter DRBG (A5529)128, 192, 256 bit keys with DF, with/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
Counter DRBG (A5530)128, 192, 256 bit keys with DF, with/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
Counter DRBG (A5531)128, 192, 256 bit keys with DF, with/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 119
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
Counter DRBG (A5532)128, 192, 256 bit keys with DF, with/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
Counter DRBG (A5533)128, 192, 256 bit keys with DF, with/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
Counter DRBG (A5534)128, 192, 256 bit keys with DF, with/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
Counter DRBG (A5535)128, 192, 256 bit keys with DF, with/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
Counter DRBG (A5536)128, 192, 256 bit keys with DF, with/without PR; Health test per section 11.3KATCASTModule becomes operationa l and services areInstantiate, Reseed, GenerateModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 120
Algorith m or TestTest Properties of SP 800- 90Arev1Test Metho dTest Typ eIndicator available for use.DetailsConditions
Counter DRBG (A5537)128, 192, 256 bit keys with DF, with/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
Counter DRBG (A5538)128, 192, 256 bit keys with DF, with/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
Counter DRBG (A5661)128, 192, 256 bit keys with DF, with/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
Counter DRBG (A5662)128, 192, 256 bit keys with DF, with/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
Counter DRBG (A5663)128, 192, 256 bit keys with DF, with/without PR; HealthKATCASTModule becomes operationa l and servicesInstantiate, Reseed, GenerateModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 121
Algorith m or TestTest Properties test per section 11.3 of SP 800- 90Arev1Test Metho dTest Typ eIndicator are available for use.DetailsConditions
Counter DRBG (A5664)128, 192, 256 bit keys with DF, with/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
Counter DRBG (A5665)128, 192, 256 bit keys with DF, with/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
Counter DRBG (A5666)128, 192, 256 bit keys with DF, with/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
Hash DRBG (A5503)SHA2-256 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
Hash DRBG (A5516)SHA2-256 With/without PR; Health test perKATCASTModule becomes operationa l andInstantiate, Reseed, GenerateModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 122
Algorith m or TestTest Properties section 11.3 of SP 800- 90Arev1Test Metho dTest Typ eIndicator services are available for use.DetailsConditions
Hash DRBG (A5517)SHA2-256 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
Hash DRBG (A5518)SHA2-256 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
Hash DRBG (A5526)SHA2-256 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
Hash DRBG (A5539)SHA2-256 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
Hash DRBG (A5540)SHA2-256 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services areInstantiate, Reseed, GenerateModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 123
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicator available for use.DetailsConditions
Hash DRBG (A5541)SHA2-256 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
Hash DRBG (A5664)SHA2-256 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
HMAC DRBG (A5503)SHA2-256, SHA2-512 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
HMAC DRBG (A5516)SHA2-256, SHA2-512 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
HMAC DRBG (A5517)SHA2-256, SHA2-512 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 124
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
HMAC DRBG (A5518)SHA2-256, SHA2-512 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
HMAC DRBG (A5526)SHA2-256, SHA2-512 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
HMAC DRBG (A5539)SHA2-256, SHA2-512 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
HMAC DRBG (A5540)SHA2-256, SHA2-512 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
HMAC DRBG (A5541)SHA2-256, SHA2-512 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 125
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicatorDetailsConditions
HMAC DRBG (A5664)SHA2-256, SHA2-512 With/without PR; Health test per section 11.3 of SP 800- 90Arev1KATCASTModule becomes operationa l and services are available for use.Instantiate, Reseed, GenerateModule initialization
ECDSA SigVer (FIPS186- 5) (A5504)P-256 with SHA-256KATCASTModule becomes operationa l and services are available for use.VerifyModule initialization
ECDSA SigVer (FIPS186- 5) (A5527)P-256 with SHA-256KATCASTModule becomes operationa l and services are available for use.VerifyModule initialization
RSA SigVer (FIPS186- 5) (A5503)4096-bit key with SHA-256KATCASTModule becomes operationa l and services are available for use.VerifyModule initialization. Before integrity test.
RSA SigVer (FIPS186- 5) (A5526)4096-bit key with SHA-256KATCASTModule becomes operationa l and services are available for use.VerifyModule initialization. Before integrity test.
RSA SigVer4096-bit key with SHA-256KATCASTModule becomes operationaVerifyModule initialization.

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 126
Algorith m or Test (FIPS186- 5) (A5664)Test PropertiesTest Metho dTest Typ eIndicator l and services are available for use.DetailsConditions Before integrity test.
KDF SP800-108 (A5503)512 bit key- derivation key with hmac(sha256 ) deriving a 256 bits of key materialKATCASTModule becomes operationa l and services are available for use.DerivationModule initialization
KDF SP800-108 (A5526)512 bit key- derivation key with hmac(sha256 ) deriving a 256 bits of key materialKATCASTModule becomes operationa l and services are available for use.DerivationModule initialization
KAS-ECC- SSC Sp800- 56Ar3 (A5503)P-256 and P- 384KATCASTModule becomes operationa l and services are available for use.Shared secret computationModule initialization
KAS-ECC- SSC Sp800- 56Ar3 (A5526)P-256 and P- 384KATCASTModule becomes operationa l and services are available for use.Shared secret computationModule initialization
KAS-FFC- SSC Sp800- 56Ar3 (A5503)ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, and ffdhe8192KATCASTModule becomes operationa l and services areShared secret computationModule initialization

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 127
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicator available for use.DetailsConditions
KAS-FFC- SSC Sp800- 56Ar3 (A5526)ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, and ffdhe8192KATCASTModule becomes operationa l and services are available for use.Shared secret computationModule initialization
ECDSA KeyGen (FIPS186- 5) (A5503)PCT according to Section 5.6.2.1.4 of SP 800-56A Rev. 3PCTPCTModule becomes operationa l and services are available for use.Public key recomputatio nDuring operational state of the module when the respective cryptographi c functions are used.
ECDSA KeyGen (FIPS186- 5) (A5526)PCT according to Section 5.6.2.1.4 of SP 800-56A Rev. 3PCTPCTModule becomes operationa l and services are available for use.Public key recomputatio nDuring operational state of the module when the respective cryptographi c functions are used.
Safe Primes Key Generatio n (A5503)PCT according to Section 5.6.2.1.4 of SP 800-56A Rev. 3PCTPCTModule becomes operationa l and services are available for use.Public key recomputatio nDuring operational state of the module when the respective cryptographi c functions are used.
Safe Primes Key Generatio n (A5526)PCT according to Section 5.6.2.1.4 of SP 800-56A Rev. 3PCTPCTModule becomes operationa l and services arePublic key recomputatio nDuring operational state of the module when the respective

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 128
Algorith m or TestTest PropertiesTest Metho dTest Typ eIndicator available for use.DetailsConditions cryptographi c functions are used.
Entropy Source - RCT start- up testCutoff C=61, 1024 samples. Repetition count test according to Section 4.4.1 of SP 800-90BRCTCASTModule becomes operationa l and services are available for use.Entropy source start- up testEntropy source initialization
Entropy Source - APT start- up testCutoff C=355, window W=512, 1024 samples. Adaptive proportion test according to Section 4.4.2 of SP 800-90BAPTCASTModule becomes operationa l and services are available for use.Entropy source start- up testEntropy source initialization
Entropy Source - RCT continuous testIntermittent cutoff C=31, permanent cutoff C=61. Repetition count test according to Section 4.4.1 of SP 800-90BRCTCASTEntropy source is operationa l and services are available for use.Entropy source continuous testContinuously when the entropy source is accessed
Entropy Source - APT continuous testIntermittent cutoff C=325, permanent cutoff C=255, window W=512. Adaptive proportion test according to Section 4.4.2 of SP 800-90BAPTCASTEntropy source is operationa l and services are available for use.Entropy source continuous testContinuously when the entropy source is accessed

d e © 2025 SUSE, LLC/atsec information security corporation.

Page 129
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2- 256 (A5503) - kernel version 3.5Message AuthenticationSW/FW IntegrityOn demandManually
HMAC-SHA2- 256 (A5503) - fipscheck version 3.5Message AuthenticationSW/FW IntegrityOn demandManually
RSA SigVer (FIPS186-5) (A5503) - object files version 3.5Signature VerificationSW/FW IntegrityOn demandManually
HMAC-SHA2- 256 (A5526) - kernel version 3.6Message AuthenticationSW/FW IntegrityOn demandManually
HMAC-SHA2- 256 (A5526) - fipscheck version 3.6Message AuthenticationSW/FW IntegrityOn demandManually
RSA SigVer (FIPS186-5) (A5526) - object files version 3.6Signature VerificationSW/FW IntegrityOn demandManually
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
SHA-1 (A5503)KATCASTOn demandManually
SHA-1 (A5516)KATCASTOn demandManually

Table 22: Conditional Self-Tests The module performs self-tests on all approved cryptographic algorithms as part of the approved services supported in the approved mode of operation, using the tests shown in the table above. Services are not available, and data output (via the data output interface) is inhibited during the conditional self-tests. If any of these tests fails, the module transitions to the Error State.

10.3 Periodic Self-Test Information

3.5 3.6 Table 23: Pre-Operational Periodic Information © 2025 SUSE, LLC/atsec information security corporation.

Page 130
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
SHA-1 (A5517)KATCASTOn demandManually
SHA-1 (A5518)KATCASTOn demandManually
SHA-1 (A5519)KATCASTOn demandManually
SHA-1 (A5520)KATCASTOn demandManually
SHA-1 (A5526)KATCASTOn demandManually
SHA-1 (A5539)KATCASTOn demandManually
SHA-1 (A5540)KATCASTOn demandManually
SHA-1 (A5541)KATCASTOn demandManually
SHA-1 (A5542)KATCASTOn demandManually
SHA-1 (A5664)KATCASTOn demandManually
SHA2-256 (A5503)KATCASTOn demandManually
SHA2-256 (A5516)KATCASTOn demandManually
SHA2-256 (A5517)KATCASTOn demandManually
SHA2-256 (A5518)KATCASTOn demandManually
SHA2-256 (A5519)KATCASTOn demandManually
SHA2-256 (A5520)KATCASTOn demandManually
SHA2-256 (A5524)KATCASTOn demandManually
SHA2-256 (A5525)KATCASTOn demandManually
SHA2-256 (A5526)KATCASTOn demandManually

© 2025 SUSE, LLC/atsec information security corporation.

Page 131
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
SHA2-256 (A5539)KATCASTOn demandManually
SHA2-256 (A5540)KATCASTOn demandManually
SHA2-256 (A5541)KATCASTOn demandManually
SHA2-256 (A5542)KATCASTOn demandManually
SHA2-256 (A5664)KATCASTOn demandManually
SHA2-512 (A5503)KATCASTOn demandManually
SHA2-512 (A5516)KATCASTOn demandManually
SHA2-512 (A5517)KATCASTOn demandManually
SHA2-512 (A5518)KATCASTOn demandManually
SHA2-512 (A5525)KATCASTOn demandManually
SHA2-512 (A5526)KATCASTOn demandManually
SHA2-512 (A5539)KATCASTOn demandManually
SHA2-512 (A5540)KATCASTOn demandManually
SHA2-512 (A5541)KATCASTOn demandManually
SHA2-512 (A5664)KATCASTOn demandManually
SHA3-224 (A5503)KATCASTOn demandManually

© 2025 SUSE, LLC/atsec information security corporation.

Page 132
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
SHA3-224 (A5526)KATCASTOn demandManually
SHA3-224 (A5664)KATCASTOn demandManually
SHA3-256 (A5503)KATCASTOn demandManually
SHA3-256 (A5526)KATCASTOn demandManually
SHA3-256 (A5664)KATCASTOn demandManually
SHA3-384 (A5503)KATCASTOn demandManually
SHA3-384 (A5526)KATCASTOn demandManually
SHA3-384 (A5664)KATCASTOn demandManually
SHA3-512 (A5503)KATCASTOn demandManually
SHA3-512 (A5526)KATCASTOn demandManually
SHA3-512 (A5664)KATCASTOn demandManually
AES-GCM - Encrypt (A5503)KATCASTOn demandManually
AES-GCM - Encrypt (A5505)KATCASTOn demandManually
AES-GCM - Encrypt (A5506)KATCASTOn demandManually
AES-GCM - Encrypt (A5507)KATCASTOn demandManually
AES-GCM - Encrypt (A5508)KATCASTOn demandManually

© 2025 SUSE, LLC/atsec information security corporation.

Page 133
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-GCM - Encrypt (A5509)KATCASTOn demandManually
AES-GCM - Encrypt (A5510)KATCASTOn demandManually
AES-GCM - Encrypt (A5511)KATCASTOn demandManually
AES-GCM - Encrypt (A5512)KATCASTOn demandManually
AES-GCM - Encrypt (A5513)KATCASTOn demandManually
AES-GCM - Encrypt (A5514)KATCASTOn demandManually
AES-GCM - Encrypt (A5515)KATCASTOn demandManually
AES-GCM - Encrypt (A5521)KATCASTOn demandManually
AES-GCM - Encrypt (A5522)KATCASTOn demandManually
AES-GCM - Encrypt (A5523)KATCASTOn demandManually
AES-GCM - Encrypt (A5526)KATCASTOn demandManually
AES-GCM - Encrypt (A5528)KATCASTOn demandManually
AES-GCM - Encrypt (A5529)KATCASTOn demandManually
AES-GCM - Encrypt (A5530)KATCASTOn demandManually
AES-GCM - Encrypt (A5531)KATCASTOn demandManually
AES-GCM - Encrypt (A5532)KATCASTOn demandManually

© 2025 SUSE, LLC/atsec information security corporation.

Page 134
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-GCM - Encrypt (A5533)KATCASTOn demandManually
AES-GCM - Encrypt (A5534)KATCASTOn demandManually
AES-GCM - Encrypt (A5535)KATCASTOn demandManually
AES-GCM - Encrypt (A5536)KATCASTOn demandManually
AES-GCM - Encrypt (A5537)KATCASTOn demandManually
AES-GCM - Encrypt (A5538)KATCASTOn demandManually
AES-GCM - Encrypt (A5661)KATCASTOn demandManually
AES-GCM - Encrypt (A5662)KATCASTOn demandManually
AES-GCM - Encrypt (A5663)KATCASTOn demandManually
AES-GCM - Encrypt (A5664)KATCASTOn demandManually
AES-GCM - Encrypt (A5665)KATCASTOn demandManually
AES-GCM - Encrypt (A5666)KATCASTOn demandManually
AES-GCM - Decrypt (A5503)KATCASTOn demandManually
AES-GCM - Decrypt (A5505)KATCASTOn demandManually
AES-GCM - Decrypt (A5506)KATCASTOn demandManually

© 2025 SUSE, LLC/atsec information security corporation.

Page 135
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-GCM - Decrypt (A5507)KATCASTOn demandManually
AES-GCM - Decrypt (A5508)KATCASTOn demandManually
AES-GCM - Decrypt (A5509)KATCASTOn demandManually
AES-GCM - Decrypt (A5510)KATCASTOn demandManually
AES-GCM - Decrypt (A5511)KATCASTOn demandManually
AES-GCM - Decrypt (A5512)KATCASTOn demandManually
AES-GCM - Decrypt (A5513)KATCASTOn demandManually
AES-GCM - Decrypt (A5514)KATCASTOn demandManually
AES-GCM - Decrypt (A5515)KATCASTOn demandManually
AES-GCM - Decrypt (A5521)KATCASTOn demandManually
AES-GCM - Decrypt (A5522)KATCASTOn demandManually
AES-GCM - Decrypt (A5523)KATCASTOn demandManually

© 2025 SUSE, LLC/atsec information security corporation.

Page 136
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-GCM - Decrypt (A5526)KATCASTOn demandManually
AES-GCM - Decrypt (A5528)KATCASTOn demandManually
AES-GCM - Decrypt (A5529)KATCASTOn demandManually
AES-GCM - Decrypt (A5530)KATCASTOn demandManually
AES-GCM - Decrypt (A5531)KATCASTOn demandManually
AES-GCM - Decrypt (A5532)KATCASTOn demandManually
AES-GCM - Decrypt (A5533)KATCASTOn demandManually
AES-GCM - Decrypt (A5534)KATCASTOn demandManually
AES-GCM - Decrypt (A5535)KATCASTOn demandManually
AES-GCM - Decrypt (A5536)KATCASTOn demandManually
AES-GCM - Decrypt (A5537)KATCASTOn demandManually
AES-GCM - Decrypt (A5538)KATCASTOn demandManually

© 2025 SUSE, LLC/atsec information security corporation.

Page 137
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-GCM - Decrypt (A5661)KATCASTOn demandManually
AES-GCM - Decrypt (A5662)KATCASTOn demandManually
AES-GCM - Decrypt (A5663)KATCASTOn demandManually
AES-GCM - Decrypt (A5664)KATCASTOn demandManually
AES-GCM - Decrypt (A5665)KATCASTOn demandManually
AES-GCM - Decrypt (A5666)KATCASTOn demandManually
AES-ECB - Encrypt (A5503)KATCASTOn demandManually
AES-ECB - Encrypt (A5505)KATCASTOn demandManually
AES-ECB - Encrypt (A5506)KATCASTOn demandManually
AES-ECB - Encrypt (A5507)KATCASTOn demandManually
AES-ECB - Encrypt (A5508)KATCASTOn demandManually
AES-ECB - Encrypt (A5509)KATCASTOn demandManually
AES-ECB - Encrypt (A5510)KATCASTOn demandManually
AES-ECB - Encrypt (A5511)KATCASTOn demandManually

© 2025 SUSE, LLC/atsec information security corporation.

Page 138
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-ECB - Encrypt (A5512)KATCASTOn demandManually
AES-ECB - Encrypt (A5513)KATCASTOn demandManually
AES-ECB - Encrypt (A5514)KATCASTOn demandManually
AES-ECB - Encrypt (A5515)KATCASTOn demandManually
AES-ECB - Encrypt (A5520)KATCASTOn demandManually
AES-ECB - Encrypt (A5521)KATCASTOn demandManually
AES-ECB - Encrypt (A5522)KATCASTOn demandManually
AES-ECB - Encrypt (A5523)KATCASTOn demandManually
AES-ECB - Encrypt (A5524)KATCASTOn demandManually
AES-ECB - Encrypt (A5526)KATCASTOn demandManually
AES-ECB - Encrypt (A5528)KATCASTOn demandManually
AES-ECB - Encrypt (A5529)KATCASTOn demandManually
AES-ECB - Encrypt (A5530)KATCASTOn demandManually
AES-ECB - Encrypt (A5531)KATCASTOn demandManually
AES-ECB - Encrypt (A5532)KATCASTOn demandManually
AES-ECB - Encrypt (A5533)KATCASTOn demandManually

© 2025 SUSE, LLC/atsec information security corporation.

Page 139
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-ECB - Encrypt (A5534)KATCASTOn demandManually
AES-ECB - Encrypt (A5535)KATCASTOn demandManually
AES-ECB - Encrypt (A5536)KATCASTOn demandManually
AES-ECB - Encrypt (A5537)KATCASTOn demandManually
AES-ECB - Encrypt (A5538)KATCASTOn demandManually
AES-ECB - Encrypt (A5661)KATCASTOn demandManually
AES-ECB - Encrypt (A5662)KATCASTOn demandManually
AES-ECB - Encrypt (A5663)KATCASTOn demandManually
AES-ECB - Encrypt (A5664)KATCASTOn demandManually
AES-ECB - Encrypt (A5665)KATCASTOn demandManually
AES-ECB - Encrypt (A5666)KATCASTOn demandManually
AES-ECB - Decrypt (A5503)KATCASTOn demandManually
AES-ECB - Decrypt (A5505)KATCASTOn demandManually
AES-ECB - Decrypt (A5506)KATCASTOn demandManually
AES-ECB - Decrypt (A5507)KATCASTOn demandManually

© 2025 SUSE, LLC/atsec information security corporation.

Page 140
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-ECB - Decrypt (A5508)KATCASTOn demandManually
AES-ECB - Decrypt (A5509)KATCASTOn demandManually
AES-ECB - Decrypt (A5510)KATCASTOn demandManually
AES-ECB - Decrypt (A5511)KATCASTOn demandManually
AES-ECB - Decrypt (A5512)KATCASTOn demandManually
AES-ECB - Decrypt (A5513)KATCASTOn demandManually
AES-ECB - Decrypt (A5514)KATCASTOn demandManually
AES-ECB - Decrypt (A5515)KATCASTOn demandManually
AES-ECB - Decrypt (A5520)KATCASTOn demandManually
AES-ECB - Decrypt (A5521)KATCASTOn demandManually
AES-ECB - Decrypt (A5522)KATCASTOn demandManually
AES-ECB - Decrypt (A5523)KATCASTOn demandManually

© 2025 SUSE, LLC/atsec information security corporation.

Page 141
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-ECB - Decrypt (A5524)KATCASTOn demandManually
AES-ECB - Decrypt (A5526)KATCASTOn demandManually
AES-ECB - Decrypt (A5528)KATCASTOn demandManually
AES-ECB - Decrypt (A5529)KATCASTOn demandManually
AES-ECB - Decrypt (A5530)KATCASTOn demandManually
AES-ECB - Decrypt (A5531)KATCASTOn demandManually
AES-ECB - Decrypt (A5532)KATCASTOn demandManually
AES-ECB - Decrypt (A5533)KATCASTOn demandManually
AES-ECB - Decrypt (A5534)KATCASTOn demandManually
AES-ECB - Decrypt (A5535)KATCASTOn demandManually
AES-ECB - Decrypt (A5536)KATCASTOn demandManually
AES-ECB - Decrypt (A5537)KATCASTOn demandManually

© 2025 SUSE, LLC/atsec information security corporation.

Page 142
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-ECB - Decrypt (A5538)KATCASTOn demandManually
AES-ECB - Decrypt (A5661)KATCASTOn demandManually
AES-ECB - Decrypt (A5662)KATCASTOn demandManually
AES-ECB - Decrypt (A5663)KATCASTOn demandManually
AES-ECB - Decrypt (A5664)KATCASTOn demandManually
AES-ECB - Decrypt (A5665)KATCASTOn demandManually
AES-ECB - Decrypt (A5666)KATCASTOn demandManually
HMAC-SHA-1 (A5503)KATCASTOn demandManually
HMAC-SHA-1 (A5516)KATCASTOn demandManually
HMAC-SHA-1 (A5517)KATCASTOn demandManually
HMAC-SHA-1 (A5518)KATCASTOn demandManually
HMAC-SHA-1 (A5519)KATCASTOn demandManually
HMAC-SHA-1 (A5520)KATCASTOn demandManually
HMAC-SHA-1 (A5526)KATCASTOn demandManually

© 2025 SUSE, LLC/atsec information security corporation.

Page 143
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA-1 (A5539)KATCASTOn demandManually
HMAC-SHA-1 (A5540)KATCASTOn demandManually
HMAC-SHA-1 (A5541)KATCASTOn demandManually
HMAC-SHA-1 (A5542)KATCASTOn demandManually
HMAC-SHA-1 (A5664)KATCASTOn demandManually
HMAC-SHA2- 224 (A5503)KATCASTOn demandManually
HMAC-SHA2- 224 (A5516)KATCASTOn demandManually
HMAC-SHA2- 224 (A5517)KATCASTOn demandManually
HMAC-SHA2- 224 (A5518)KATCASTOn demandManually
HMAC-SHA2- 224 (A5519)KATCASTOn demandManually
HMAC-SHA2- 224 (A5520)KATCASTOn demandManually
HMAC-SHA2- 224 (A5524)KATCASTOn demandManually
HMAC-SHA2- 224 (A5525)KATCASTOn demandManually
HMAC-SHA2- 224 (A5526)KATCASTOn demandManually
HMAC-SHA2- 224 (A5539)KATCASTOn demandManually
HMAC-SHA2- 224 (A5540)KATCASTOn demandManually

© 2025 SUSE, LLC/atsec information security corporation.

Page 144
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2- 224 (A5541)KATCASTOn demandManually
HMAC-SHA2- 224 (A5542)KATCASTOn demandManually
HMAC-SHA2- 224 (A5664)KATCASTOn demandManually
HMAC-SHA2- 256 (A5503)KATCASTOn demandManually
HMAC-SHA2- 256 (A5516)KATCASTOn demandManually
HMAC-SHA2- 256 (A5517)KATCASTOn demandManually
HMAC-SHA2- 256 (A5518)KATCASTOn demandManually
HMAC-SHA2- 256 (A5519)KATCASTOn demandManually
HMAC-SHA2- 256 (A5520)KATCASTOn demandManually
HMAC-SHA2- 256 (A5524)KATCASTOn demandManually
HMAC-SHA2- 256 (A5525)KATCASTOn demandManually
HMAC-SHA2- 256 (A5526)KATCASTOn demandManually
HMAC-SHA2- 256 (A5539)KATCASTOn demandManually
HMAC-SHA2- 256 (A5540)KATCASTOn demandManually
HMAC-SHA2- 256 (A5541)KATCASTOn demandManually
HMAC-SHA2- 256 (A5542)KATCASTOn demandManually

© 2025 SUSE, LLC/atsec information security corporation.

Page 145
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2- 256 (A5664)KATCASTOn demandManually
HMAC-SHA2- 384 (A5503)KATCASTOn demandManually
HMAC-SHA2- 384 (A5516)KATCASTOn demandManually
HMAC-SHA2- 384 (A5517)KATCASTOn demandManually
HMAC-SHA2- 384 (A5518)KATCASTOn demandManually
HMAC-SHA2- 384 (A5525)KATCASTOn demandManually
HMAC-SHA2- 384 (A5526)KATCASTOn demandManually
HMAC-SHA2- 384 (A5539)KATCASTOn demandManually
HMAC-SHA2- 384 (A5540)KATCASTOn demandManually
HMAC-SHA2- 384 (A5541)KATCASTOn demandManually
HMAC-SHA2- 384 (A5664)KATCASTOn demandManually
HMAC-SHA2- 512 (A5503)KATCASTOn demandManually
HMAC-SHA2- 512 (A5516)KATCASTOn demandManually
HMAC-SHA2- 512 (A5517)KATCASTOn demandManually
HMAC-SHA2- 512 (A5518)KATCASTOn demandManually
HMAC-SHA2- 512 (A5525)KATCASTOn demandManually

© 2025 SUSE, LLC/atsec information security corporation.

Page 146
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2- 512 (A5526)KATCASTOn demandManually
HMAC-SHA2- 512 (A5539)KATCASTOn demandManually
HMAC-SHA2- 512 (A5540)KATCASTOn demandManually
HMAC-SHA2- 512 (A5541)KATCASTOn demandManually
HMAC-SHA2- 512 (A5664)KATCASTOn demandManually
HMAC-SHA3- 224 (A5503)KATCASTOn demandManually
HMAC-SHA3- 224 (A5526)KATCASTOn demandManually
HMAC-SHA3- 224 (A5664)KATCASTOn demandManually
HMAC-SHA3- 256 (A5503)KATCASTOn demandManually
HMAC-SHA3- 256 (A5526)KATCASTOn demandManually
HMAC-SHA3- 256 (A5664)KATCASTOn demandManually
HMAC-SHA3- 384 (A5503)KATCASTOn demandManually
HMAC-SHA3- 384 (A5526)KATCASTOn demandManually
HMAC-SHA3- 384 (A5664)KATCASTOn demandManually
HMAC-SHA3- 512 (A5503)KATCASTOn demandManually
HMAC-SHA3- 512 (A5526)KATCASTOn demandManually

© 2025 SUSE, LLC/atsec information security corporation.

Page 147
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA3- 512 (A5664)KATCASTOn demandManually
Counter DRBG (A5503)KATCASTOn demandManually
Counter DRBG (A5505)KATCASTOn demandManually
Counter DRBG (A5506)KATCASTOn demandManually
Counter DRBG (A5507)KATCASTOn demandManually
Counter DRBG (A5508)KATCASTOn demandManually
Counter DRBG (A5509)KATCASTOn demandManually
Counter DRBG (A5510)KATCASTOn demandManually
Counter DRBG (A5511)KATCASTOn demandManually
Counter DRBG (A5512)KATCASTOn demandManually
Counter DRBG (A5513)KATCASTOn demandManually
Counter DRBG (A5514)KATCASTOn demandManually
Counter DRBG (A5515)KATCASTOn demandManually
Counter DRBG (A5521)KATCASTOn demandManually
Counter DRBG (A5522)KATCASTOn demandManually
Counter DRBG (A5523)KATCASTOn demandManually

© 2025 SUSE, LLC/atsec information security corporation.

Page 148
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
Counter DRBG (A5526)KATCASTOn demandManually
Counter DRBG (A5528)KATCASTOn demandManually
Counter DRBG (A5529)KATCASTOn demandManually
Counter DRBG (A5530)KATCASTOn demandManually
Counter DRBG (A5531)KATCASTOn demandManually
Counter DRBG (A5532)KATCASTOn demandManually
Counter DRBG (A5533)KATCASTOn demandManually
Counter DRBG (A5534)KATCASTOn demandManually
Counter DRBG (A5535)KATCASTOn demandManually
Counter DRBG (A5536)KATCASTOn demandManually
Counter DRBG (A5537)KATCASTOn demandManually
Counter DRBG (A5538)KATCASTOn demandManually
Counter DRBG (A5661)KATCASTOn demandManually
Counter DRBG (A5662)KATCASTOn demandManually
Counter DRBG (A5663)KATCASTOn demandManually
Counter DRBG (A5664)KATCASTOn demandManually

© 2025 SUSE, LLC/atsec information security corporation.

Page 149
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
Counter DRBG (A5665)KATCASTOn demandManually
Counter DRBG (A5666)KATCASTOn demandManually
Hash DRBG (A5503)KATCASTOn demandManually
Hash DRBG (A5516)KATCASTOn demandManually
Hash DRBG (A5517)KATCASTOn demandManually
Hash DRBG (A5518)KATCASTOn demandManually
Hash DRBG (A5526)KATCASTOn demandManually
Hash DRBG (A5539)KATCASTOn demandManually
Hash DRBG (A5540)KATCASTOn demandManually
Hash DRBG (A5541)KATCASTOn demandManually
Hash DRBG (A5664)KATCASTOn demandManually
HMAC DRBG (A5503)KATCASTOn demandManually
HMAC DRBG (A5516)KATCASTOn demandManually
HMAC DRBG (A5517)KATCASTOn demandManually
HMAC DRBG (A5518)KATCASTOn demandManually
HMAC DRBG (A5526)KATCASTOn demandManually

© 2025 SUSE, LLC/atsec information security corporation.

Page 150
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC DRBG (A5539)KATCASTOn demandManually
HMAC DRBG (A5540)KATCASTOn demandManually
HMAC DRBG (A5541)KATCASTOn demandManually
HMAC DRBG (A5664)KATCASTOn demandManually
ECDSA SigVer (FIPS186-5) (A5504)KATCASTOn demandManually
ECDSA SigVer (FIPS186-5) (A5527)KATCASTOn demandManually
RSA SigVer (FIPS186-5) (A5503)KATCASTOn demandManually
RSA SigVer (FIPS186-5) (A5526)KATCASTOn demandManually
RSA SigVer (FIPS186-5) (A5664)KATCASTOn demandManually
KDF SP800-108 (A5503)KATCASTOn demandManually
KDF SP800-108 (A5526)KATCASTOn demandManually
KAS-ECC-SSC Sp800-56Ar3 (A5503)KATCASTOn demandManually
KAS-ECC-SSC Sp800-56Ar3 (A5526)KATCASTOn demandManually

© 2025 SUSE, LLC/atsec information security corporation.

Page 151
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
KAS-FFC-SSC Sp800-56Ar3 (A5503)KATCASTOn demandManually
KAS-FFC-SSC Sp800-56Ar3 (A5526)KATCASTOn demandManually
ECDSA KeyGen (FIPS186-5) (A5503)PCTPCTOn demandManually
ECDSA KeyGen (FIPS186-5) (A5526)PCTPCTOn demandManually
Safe Primes Key Generation (A5503)PCTPCTOn demandManually
Safe Primes Key Generation (A5526)PCTPCTOn demandManually
Entropy Source - RCT start-up testRCTCASTOn demandManually
Entropy Source - APT start-up testAPTCASTOn demandManually
Entropy Source - RCT continuous testRCTCASTN/AN/A
Entropy Source - APT continuous testAPTCASTN/AN/A

Table 24: Conditional Periodic Information © 2025 SUSE, LLC/atsec information security corporation.

Page 152
NameDescriptionConditionsRecovery MethodIndicator
Error StateThe Linux kernel immediately stops executingAny self-test failure Failure of pre- operational tests or CASTs Failure of Entropy source Health Tests Failure of PCT testsRestart of the moduleKernel Panic
10.4 Error States

Table 25: Error States In the Error State, the output interface is inhibited, and the module accepts no more inputs or requests (as the module is no longer running).

10.5 Operator Initiation of Self-Tests

All self-tests, with the exception of the continuous health tests, can be invoked on demand by unloading and subsequently re-initializing the module. © 2025 SUSE, LLC/atsec information security corporation.

Page 153
11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

The module is distributed as a part of the SUSE Enterprise Linux SP6 RPM packages in the form of: • kernel-default-6.4.0-150600.23.25.1 (for x86, aarch64, and s390x platforms) • kernel-rt-6.4.0-150600.10.17.1 (for x86 platforms) • libkcapi-tools-0.13.0-150600.17.3.1 (for x86, aarch64, and s390x platforms) • dracut-fips-059+suse.521.g8412a1c0-150600.1.3 (for x86, aarch64, and s390x platforms) The module can achieve FIPS validated configuration by:

  1. Install the dracut-fips RPM package: # zipper install dracut-fips
  2. Recreate the initramfs image: # dracut -f
  3. After regenerating the initrd, the Crypto Officer must append the following parameter in the /etc/default/grub configuration file in the GRUB_CMDLINE_LINUX_DEFAULT line: fips=1
  4. After editing the configuration file, please run the following command to change the setting in the boot loader depending on if the system uses UEFI boot or legacy boot: # grub2-mkconfig -o /boot/efi/EFI/sles/grub.cfg # grub2-mkconfig -o /boot/grub2/grub.cfg If /boot or /boot/efi resides on a separate partition, the kernel parameter boot=<partition of /boot or /boot/efi> must be supplied. The partition can be identified with the command "df /boot" or "df /boot/efi" respectively. For example: # df /boot Filesystem 1K-blocks Used Available Use% Mounted on /dev/sda1 233191 30454 190296 14% /boot The partition of /boot is located on /dev/sda1 in this example. Therefore, the following string needs to be appended in the aforementioned grub file: "boot=/dev/sda1" Reboot to apply these settings.
11.2 Administrator Guidance

After the operating environment is configured as adviced in Section 11.1 to support FIPS operation, the Crypto Officer should check the existence of the file /proc/sys/crypto/fips_enabled, and verify it contains a numeric value “1”. If the file does not exist or does not contain “1”, the operating environment is not configured to support FIPS and the module will not operate as a FIPS validated module properly. Then, the Crypto Officer must execute the following commands, which must output the following: © 2025 SUSE, LLC/atsec information security corporation.

Page 154

# cat /proc/sys/crypto/fips_version 6.4.0-150600.23.25-default (for version 3.5) 6.4.0-150600.10.17-rt (for version 3.6) # rpm -q libkcapi-tools libkcapi-tools-0.13.0-150600.17.3.1 (for versions 3.5 and 3.6) # rpm -q dracut-fips dracut-fips-059+suse.521.g8412a1c0-150600.1.3 (for versions 3.5 and 3.6)

11.3 Non-Administrator Guidance

There is no non-administrator guidance.

11.4 End of Life

As the module does not persistently store SSPs, secure sanitization of the module consists of unloading the module. This will zeroize all SSPs in volatile memory. Then, if desired, the RPMs mentioned in Section 11.1 can be uninstalled from the SUSE Linux Enterprise SP6 system. © 2025 SUSE, LLC/atsec information security corporation.

Page 155
12 Mitigation of Other Attacks

The module does not offer mitigation of other attacks and therefore this section is not applicable. © 2025 SUSE, LLC/atsec information security corporation.

Page 156
Table, extracted as text (did not parse into structured rows)
Appendix A. Glossary and Abbreviations AES                  Advanced Encryption Standard API                  Application Programming Interface CAST                 Cryptographic Algorithm Self-Test CAVP                 Cryptographic Algorithm Validation Program CBC                  Cipher Block Chaining CCM                  Counter with Cipher Block Chaining-Message Authentication Code CFB                  Cipher Feedback CKG                  Cryptographic Key Generation CMAC                 Cipher-based Message Authentication Code CMVP                 Cryptographic Module Validation Program CSP                  Critical Security Parameter CTR                  Counter DH                   Diffie-Hellman DRBG                 Deterministic Random Bit Generator ECB                  Electronic Code Book ECC                  Elliptic Curve Cryptography ECDH                 Elliptic Curve Diffie-Hellman ECDSA                Elliptic Curve Digital Signature Algorithm FFC                  Finite Field Cryptography FIPS                 Federal Information Processing Standards GCM                  Galois Counter Mode GMAC                 Galois Counter Mode Message Authentication Code HMAC                 Keyed-Hash Message Authentication Code IKE                  Internet Key Exchange IPsec                Internet Protocol Security © 2025 SUSE, LLC/atsec information security corporation.
Page 157
Table, extracted as text (did not parse into structured rows)
KAS                  Key Agreement Scheme KAT                  Known Answer Test KBKDF                Key-Based Key Derivation Function KW                   Key Wrap KWP                  Key Wrap with Padding MAC                  Message Authentication Code NIST                 National Institute of Science and Technology OFB                  Output Feedback PAA                  Processor Algorithm Acceleration PAI                  Processor Algorithm Implementation PCT                  Pair-wise Consistency Test PKCS                 Public-Key Cryptography Standards RSA                  Rivest, Shamir, Addleman SHA                  Secure Hash Algorithm SSC                  Shared Secret Computation SSP                  Sensitive Security Parameter TLS                  Transport Layer Security XTS                  XEX-based Tweaked-codebook mode with cipher text Stealing © 2025 SUSE, LLC/atsec information security corporation.
Page 158
FIPS 140-3FIPS PUB 140-3 - Security Requirements For Cryptographic Modules March 2019 https://doi.org/10.6028/NIST.FIPS.140-3
FIPS 140-3 IGImplementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program 2 September 2025 https://csrc.nist.gov/Projects/cryptographic-module-validation-program/fips- 140-3-ig-announcements
FIPS 180-4Secure Hash Standard (SHS) March 2012 https://doi.org/10.6028/NIST.FIPS.180-4
FIPS 186-4Digital Signature Standard (DSS) July 2013 https://doi.org/10.6028/NIST.FIPS.186-4
FIPS 186-5Digital Signature Standard (DSS) February 2023 https://doi.org/10.6028/NIST.FIPS.186-5
FIPS 198-1The Keyed Hash Message Authentication Code (HMAC) July 2008 https://doi.org/10.6028/NIST.FIPS.198-1
FIPS 202SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions August 2015 https://doi.org/10.6028/NIST.FIPS.202
PKCS#1Public Key Cryptography Standards (PKCS) #1: RSA Cryptography Specifications Version 2.1 February 2003 https://www.ietf.org/rfc/rfc3447.txt
RFC 4106The Use of Galois/Counter Mode (GCM) in IPsec Encapsulating Security Payload (ESP) June 2005 https://www.rfc-editor.org/rfc/rfc4106.txt © 2025 SUSE, LLC/atsec information security corporation.
Page 159
RFC 7296Internet Key Exchange Protocol Version 2 (IKEv2) June 2005 https://www.rfc-editor.org/rfc/rfc7296.txt
SP 800-38ARecommendation for Block Cipher Modes of Operation Methods and Techniques December 2001 https://doi.org/10.6028/NIST.SP.800-38A
SP 800-38BRecommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication May 2005 https://doi.org/10.6028/NIST.SP.800-38B
SP 800-38CRecommendation for Block Cipher Modes of Operation: the CCM Mode for Authentication and Confidentiality May 2004 https://doi.org/10.6028/NIST.SP.800-38C
SP 800-38DRecommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC November 2007 https://doi.org/10.6028/NIST.SP.800-38D
SP 800-38ERecommendation for Block Cipher Modes of Operation: The XTS AES Mode for Confidentiality on Storage Devices January 2010 https://doi.org/10.6028/NIST.SP.800-38E
SP 800-38FRecommendation for Block Cipher Modes of Operation: Methods for Key Wrapping December 2012 https://doi.org/10.6028/NIST.SP.800-38F
SP 800-56ARecommendation for Pair-Wise Key-Establishment Schemes Using
Rev. 3Discrete Logarithm Cryptography April 2018 https://doi.org/10.6028/NIST.SP.800-56Ar3
SP 800-90ARecommendation for Random Number Generation Using
Rev. 1Deterministic Random Bit Generators June 2015 https://doi.org/10.6028/NIST.SP.800-90Ar1 © 2025 SUSE, LLC/atsec information security corporation.
Page 160
SP 800-108Recommendation for Key Derivation Using Pseudorandom
Rev. 1Functions August 2022 https://doi.org/10.6028/NIST.SP.800-108r1-upd1
SP 800-133Recommendation for Cryptographic Key Generation
Rev. 2June 2020 https://doi.org/10.6028/NIST.SP.800-133r2 © 2025 SUSE, LLC/atsec information security corporation.