All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Canonical Ltd. Ubuntu 24.04 OpenSSL Cryptographic Module

Certificate#5115StandardFIPS 140-3Level1TypeSoftwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorCanonical Ltd.
Medium review priority  ·  no TCB surface named  ·  OpenSSL upstream has published 38 CVEs since this module's initial validation  ·  last validated 6 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date1/5/2031
CaveatWhen operated in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.
VendorCanonical Ltd.

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Canonical Ltd. Ubuntu 24.04 OpenSSL Cryptographic Module
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Recovery<br/>update</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Status Output</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>SSH<br/>HTTPS</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Canonical Ltd. Ubuntu 24.04 OpenSSL Cryptographic Module
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Recovery<br/>update</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Status Output</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>SSH<br/>HTTPS</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Canonical Ltd. Canonical Ltd. Ubuntu 24.04 OpenSSL Cryptographic Module Version 3.0.13-0ubuntu3+Fips1 Document Version: 1.2 Last Updated: 2025-12-16 Prepared by: Prepared for: atsec information security corporation Canonical Ltd.

4516 Seton Center Parkway, Suite 250 110 Southwark Street, Blue Fin Building, 5th Floor

Austin, TX 78759 London, SE1 0SU www.atsec.com www.canonical.com

Page 2
Table of Contents
#SectionPage
Page 3

© 2025 Canonical Ltd. / atsec information security.

Page 4

© 2025 Canonical Ltd. / atsec information security.

Page 5
List of Tables
ItemPage
Table 1: Security Levels6
Table 2: Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets)8
Table 3: Tested Operational Environments - Software, Firmware, Hybrid9
Table 4: Modes List and Description9
Table 5: Approved Algorithms12
Table 6: Vendor-Affirmed Algorithms12
Table 7: Non-Approved, Not Allowed Algorithms13
Table 8: Security Function Implementations21
Table 9: Entropy Certificates23
Table 10: Entropy Sources24
Table 11: Ports and Interfaces26
Table 12: Roles27
Table 13: Approved Services32
Table 14: Non-Approved Services33
Table 15: Storage Areas39
Table 16: SSP Input-Output Methods39
Table 17: SSP Zeroization Methods40
Table 18: SSP Table 144
Table 19: SSP Table 247
Table 20: Pre-Operational Self-Tests49
Table 21: Conditional Self-Tests63
Table 22: Pre-Operational Periodic Information64
Table 23: Conditional Periodic Information70
Table 24: Error States70
Figure 1: Block Diagram8
Page 6
SectionTitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication1
5Software/Firmware security1
6Operational environment1
7Physical securityN/A
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacks1
Overall Level1
1.1 Overview

This document is the non-proprietary FIPS 140-3 Security Policy for version 3.0.130ubuntu3+Fips1 of the Canonical Ltd. Ubuntu 24.04 OpenSSL Cryptographic Module. It contains the security rules under which the module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for an overall Security Level 1 whole and intact and including this notice. Other documentation is proprietary to their authors.

1.2 Security Levels
1.3 Additional Information

In preparing the Security Policy document, the laboratory formatted the vendorsupplied documentation for consolidation without altering the technical statements therein contained. The further refining of the Security Policy document was conducted iteratively throughout the conformance testing, wherein the Security Policy was submitted to the vendor, who would then edit, modify, and add technical contents. The vendor would also supply additional documentation, which the laboratory formatted into the existing Security Policy, and resubmitted to the vendor for their final editing. © 2025 Canonical Ltd. / atsec information security.

Page 7
2 Cryptographic Module Specification
2.1 Description

Purpose and Use: The Canonical Ltd. Ubuntu 24.04 OpenSSL Cryptographic Module (hereafter referred to as “the module”) is defined as a software module in a multi-chip standalone embodiment. It provides a C language application program interface (API) for use by other applications that require cryptographic functionality. The module consists of one software component, the “FIPS provider” i.e., fips.so, which implements the FIPS requirements, and the cryptographic functionality provided to the operator. Module Type: Software Module Embodiment: MultiChipStand Module Characteristics Cryptographic Boundary: Components in white are only included in the diagram for informational purposes. They are not included in the cryptographic boundary (and therefore not part of the module’s validation). For example, the kernel is responsible for managing system calls issued by the module itself, as well as other applications using the module for cryptographic services. Tested Operational Environment’s Physical Perimeter (TOEPP): Figure 1 shows a block diagram that represents the design of the module when the module is operational and providing services to other user space applications. In this diagram, the physical perimeter of the operational environment (a general-purpose computer on which the module is installed) is indicated by a purple dashed line. The cryptographic boundary is represented by the component in the orange block, that is, the shared library implementing the FIPS provider (fips.so). The connecting lines indicate the flow of data between the cryptographic module and its operator application, through the logical interfaces defined in Section 3. © 2025 Canonical Ltd. / atsec information security.

Page 8
Package or File NameSoftware/ Firmware VersionFeaturesIntegrity Test
fips.so on Ubuntu 24.04 with Xeon Gold 62263.0.13-0ubuntu3+Fips1N/AHMAC-SHA-256
fips.so on Ubuntu 24.04 with AWS Graviton33.0.13-0ubuntu3+Fips1N/AHMAC-SHA-256
fips.so on Ubuntu 24.04 with IBM Telum3.0.13-0ubuntu3+Fips1N/AHMAC-SHA-256
2.2 Tested and Vendor Affirmed Module Version and

Identification Tested Module Identification

Page 9
Operating SystemHardware PlatformProcessorsPAA/PAIHypervisor or Host OSVersion(s)
Ubuntu 24.04Supermicro SYS-1019P-WTRIntel Xeon Gold 6226YesN/A3.0.13- 0ubuntu3+Fips1
Ubuntu 24.04Supermicro SYS-1019P-WTRIntel Xeon Gold 6226NoN/A3.0.13- 0ubuntu3+Fips1
Ubuntu 24.04Amazon Web Services (AWS) c7g.metalAWS Graviton3YesN/A3.0.13- 0ubuntu3+Fips1
Ubuntu 24.04Amazon Web Services (AWS) c7g.metalAWS Graviton3NoN/A3.0.13- 0ubuntu3+Fips1
Ubuntu 24.04IBM z16IBM TelumYesN/A3.0.13- 0ubuntu3+Fips1
Ubuntu 24.04IBM z16IBM TelumNoN/A3.0.13- 0ubuntu3+Fips1
Mode NameDescriptionTypeStatus Indicator
Approved modeAutomatically entered whenever an approved service is requestedApprovedEquivalent to the indicator of the requested service listed in section 4.3
Non-approved modeAutomatically entered whenever a non-approved service is requestedNon- ApprovedEquivalent to the indicator of the requested service listed in section 4.4

Tested Operational Environments - Software, Firmware, Hybrid: Table 3: Tested Operational Environments - Software, Firmware, Hybrid Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid: N/A for this module.

2.3 Excluded Components

There are no components excluded from the module.

2.4 Modes of Operation

Modes List and Description: 4.3 4.4 Table 4: Modes List and Description The module supports two modes of operation: (1) the approved mode of operation, in which the approved or vendor affirmed services are available as specified in the non-approved services are available as specified in the Non-Approved Services table. Mode Change Instructions and Status: The module automatically switches between the approved and non-approved modes © 2025 Canonical Ltd. / atsec information security.

Page 10
AlgorithmCAVP CertPropertiesReference
AES-CBCA5747, A5748, A5749, A5774, A5775, A5776, A5927-SP 800-38A
AES-CBC-CS1A5747, A5748, A5749, A5774, A5775, A5776, A5927-SP 800-38A
AES-CBC-CS2A5747, A5748, A5749, A5774, A5775, A5776, A5927-SP 800-38A
AES-CBC-CS3A5747, A5748, A5749, A5774, A5775, A5776, A5927-SP 800-38A
AES-CCMA5747, A5748, A5749, A5774, A5775, A5776, A5927-SP 800-38C
AES-CFB1A5747, A5748, A5749, A5774, A5775, A5776, A5927-SP 800-38A
AES-CFB128A5747, A5748, A5749, A5774, A5775, A5776, A5927-SP 800-38A
AES-CFB8A5747, A5748, A5749, A5774, A5775, A5776, A5927-SP 800-38A
AES-CMACA5747, A5748, A5749, A5774, A5775, A5776, A5927-SP 800-38B
AES-CTRA5747, A5748, A5749, A5774, A5775, A5776, A5927-SP 800-38A
AES-ECBA5747, A5748, A5749, A5751, A5752, A5753, A5754, A5755, A5774, A5775, A5776, A5927, A5932-SP 800-38A
AES-GCMA5759, A5760, A5761, A5762, A5763, A5764, A5765, A5766, A5767, A5777, A5781, A5782, A5783, A5928, A5929, A5930-SP 800-38D
AES-GMACA5759, A5760, A5761, A5762, A5763, A5764, A5765, A5766, A5767, A5777, A5781, A5782, A5783, A5928, A5929, A5930-SP 800-38D
AES-KWA5747, A5748, A5749, A5774, A5775, A5776, A5927-SP 800-38F
AES-KWPA5747, A5748, A5749, A5774, A5775, A5776, A5927-SP 800-38F
AES-OFBA5747, A5748, A5749, A5774, A5775, A5776, A5927-SP 800-38A
AES-XTS Testing Revision 2.0A5747, A5748, A5749, A5774, A5775, A5776, A5927-SP 800-38E
Counter DRBGA5746-SP 800-90A Rev. 1
ECDSA KeyGen (FIPS186-5)A5745, A5750, A5768, A5769, A5770, A5771, A5778, A5931-FIPS 186-5
ECDSA KeyVer (FIPS186-4)A5745, A5750, A5768, A5769, A5770, A5771, A5778, A5931-FIPS 186-4
ECDSA KeyVer (FIPS186-5)A5745, A5750, A5768, A5769, A5770, A5771, A5778, A5931-FIPS 186-5
ECDSA SigGen (FIPS186-5)A5750, A5756, A5768, A5769, A5770, A5771, A5778, A5780, A5931, A5933-FIPS 186-5

Degraded Mode Description: The module does not implement a degraded mode of operation.

2.5 Algorithms

Approved Algorithms: The table below lists all implemented modes or methods of operation for the approved cryptographic algorithms of the module that are employed for approved services (Approved Services table). © 2025 Canonical Ltd. / atsec information security.

Page 11
AlgorithmCAVP CertPropertiesReference
ECDSA SigVer (FIPS186-4)A5750, A5756, A5768, A5769, A5770, A5771, A5778, A5780, A5931, A5933-FIPS 186-4
ECDSA SigVer (FIPS186-5)A5750, A5756, A5768, A5769, A5770, A5771, A5778, A5780, A5931, A5933-FIPS 186-5
Hash DRBGA5746-SP 800-90A Rev. 1
HMAC DRBGA5746-SP 800-90A Rev. 1
HMAC-SHA-1A5750, A5768, A5769, A5770, A5771, A5778, A5931-FIPS 198-1
HMAC-SHA2-224A5750, A5768, A5769, A5770, A5771, A5778, A5931-FIPS 198-1
HMAC-SHA2-256A5750, A5768, A5769, A5770, A5771, A5778, A5779, A5931-FIPS 198-1
HMAC-SHA2-384A5750, A5768, A5769, A5770, A5771, A5778, A5931-FIPS 198-1
HMAC-SHA2-512A5750, A5768, A5769, A5770, A5771, A5778, A5931-FIPS 198-1
HMAC-SHA2- 512/224A5750, A5768, A5769, A5770, A5771, A5778, A5931-FIPS 198-1
HMAC-SHA2- 512/256A5750, A5768, A5769, A5770, A5771, A5778, A5931-FIPS 198-1
HMAC-SHA3-224A5756, A5780, A5933-FIPS 198-1
HMAC-SHA3-256A5756, A5780, A5933-FIPS 198-1
HMAC-SHA3-384A5756, A5780, A5933-FIPS 198-1
HMAC-SHA3-512A5756, A5780, A5933-FIPS 198-1
KAS-ECC-SSC Sp800-56Ar3A5750, A5768, A5769, A5770, A5771, A5778, A5931-SP 800-56A Rev. 3
KAS-FFC-SSC Sp800-56Ar3A5773-SP 800-56A Rev. 3
KDA HKDF SP800- 56Cr2A5758-SP 800-56C Rev. 2
KDA OneStep SP800-56Cr2A5744-SP 800-56C Rev. 2
KDA TwoStep SP800-56Cr2A5744-SP 800-56C Rev. 2
KDF ANS 9.42 (CVL)A5750, A5756, A5768, A5769, A5770, A5771, A5778, A5780, A5931, A5933-SP 800-135 Rev. 1
KDF ANS 9.63 (CVL)A5750, A5768, A5769, A5770, A5771, A5778, A5931-SP 800-135 Rev. 1
KDF SP800-108A5772-SP 800-108 Rev. 1
KDF SSH (CVL)A5751, A5752, A5753, A5754, A5755, A5932-SP 800-135 Rev. 1
KMAC-128A5756, A5780, A5933-SP 800-185
KMAC-256A5756, A5780, A5933-SP 800-185
PBKDFA5750, A5756, A5768, A5769, A5770, A5771, A5778, A5780, A5931, A5933-SP 800-132

© 2025 Canonical Ltd. / atsec information security.

Page 12
AlgorithmCAVP CertPropertiesReference
RSA KeyGen (FIPS186-5)A5750, A5768, A5769, A5770, A5771, A5778, A5931-FIPS 186-5
RSA SigGen (FIPS186-5)A5750, A5756, A5768, A5769, A5770, A5771, A5778, A5780, A5931, A5933-FIPS 186-5
RSA SigVer (FIPS186-4)A5750, A5768, A5769, A5770, A5771, A5778, A5931-FIPS 186-4
RSA SigVer (FIPS186-5)A5750, A5756, A5768, A5769, A5770, A5771, A5778, A5780, A5931, A5933-FIPS 186-5
Safe Primes Key GenerationA5773-SP 800-56A Rev. 3
Safe Primes Key VerificationA5773-SP 800-56A Rev. 3
SHA-1A5750, A5768, A5769, A5770, A5771, A5778, A5931-FIPS 180-4
SHA2-224A5750, A5768, A5769, A5770, A5771, A5778, A5931-FIPS 180-4
SHA2-256A5750, A5768, A5769, A5770, A5771, A5778, A5779, A5931-FIPS 180-4
SHA2-384A5750, A5768, A5769, A5770, A5771, A5778, A5931-FIPS 180-4
SHA2-512A5750, A5768, A5769, A5770, A5771, A5778, A5931-FIPS 180-4
SHA2-512/224A5750, A5768, A5769, A5770, A5771, A5778, A5931-FIPS 180-4
SHA2-512/256A5750, A5768, A5769, A5770, A5771, A5778, A5931-FIPS 180-4
SHA3-224A5756, A5780, A5933-FIPS 202
SHA3-256A5756, A5780, A5933-FIPS 202
SHA3-384A5756, A5780, A5933-FIPS 202
SHA3-512A5756, A5780, A5933-FIPS 202
SHAKE-128A5756, A5780, A5933-FIPS 202
SHAKE-256A5756, A5780, A5933-FIPS 202
TLS v1.2 KDF RFC7627 (CVL)A5750, A5768, A5769, A5770, A5771, A5778, A5931-SP 800-135 Rev. 1
TLS v1.3 KDF (CVL)A5758-SP 800-135 Rev. 1
NamePropertiesImplementationReference
Asymmetric Cryptographic Key Generation (CKG)Key Type:AsymmetricN/ASP 800-133Rev2 section 4, example 1

Table 5: Approved Algorithms Vendor-Affirmed Algorithms: Table 6: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: N/A for this module. Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. Non-Approved, Not Allowed Algorithms: © 2025 Canonical Ltd. / atsec information security.

Page 13
NameUse and Function
AES GCM (external IV)Encryption
DSASignature Generation, Signature Verification, Key Pair Generation, Key Pair Verification
ECDSA with curve P-192, B-163, K-163Key Pair Generation
ECDSA with curve B-163, K-163Key Pair Verification
ECDSA with curve P-192Signature Generation
ECDSA with curve B-163, B-233, B-283, B-409, B- 571, K-163, K-233, K-283, K-409, K-571Signature Generation, Signature Verification
RSA and ECDSA (pre-hashed message)Signature Generation (pre-hashed message), Signature Verification (pre-hashed message)
RSA X9.31Signature Generation, Signature Verification
RSA primitiveAsymmetric Encryption, Asymmetric Decryption
RSA-OAEPAsymmetric Encryption, Asymmetric Decryption
RSASVESecret Value Encapsulation, Secret Value Decapsulation

Name Encryption with AES

Type BC-UnAuth

Description SP 800-38A and SP 800-38E. Encryption

Properties

Algorithms AES-CBC: (A5747, A5748, A5749, A5774, A5775, A5776, A5927) AES-CBC-CS1: (A5747, A5748, A5749, A5774, A5775, A5776, A5927) AES-CBC-CS2: (A5747, A5748, A5749, A5774, A5775, A5776, A5927) AES-CBC-CS3: (A5747, A5748, A5749, A5774, A5775, A5776, A5927) AES-CFB1: (A5747, A5748, A5749, A5774, A5775, A5776, A5927) AES-CFB128: (A5747, A5748, A5749, A5774, A5775, A5776, A5927) AES-CFB8: (A5747,

Table 7: Non-Approved, Not Allowed Algorithms

2.6 Security Function Implementations

© 2025 Canonical Ltd. / atsec information security.

Page 14

Name Decryption with AES

Type BC-UnAuth

Description SP 800-38A and SP 800-38E. Decryption

Properties

Algorithms A5748, A5749, A5774, A5775, A5776, A5927) AES-CTR: (A5747, A5748, A5749, A5774, A5775, A5776, A5927) AES-ECB: (A5747, A5748, A5749, A5751, A5752, A5753, A5754, A5755, A5774, A5775, A5776, A5927, A5932) AES-OFB: (A5747, A5748, A5749, A5774, A5775, A5776, A5927) AES-XTS Testing Revision 2.0: (A5747, A5748, A5749, A5774, A5775, A5776, A5927) AES-CBC: (A5747, A5748, A5749, A5774, A5775, A5776, A5927) AES-CBC-CS1: (A5747, A5748, A5749, A5774, A5775, A5776, A5927) AES-CBC-CS2: (A5747, A5748, A5749, A5774, A5775, A5776, A5927) AES-CBC-CS3: (A5747, A5748, A5749, A5774, A5775, A5776, A5927) AES-CFB1: (A5747, A5748, A5749, A5774, A5775, A5776, A5927) AES-CFB128: (A5747, A5748, A5749, A5774, A5775, A5776, A5927)

© 2025 Canonical Ltd. / atsec information security.

Page 15

Name Authenticated Encryption with AES Authenticated Decryption with AES

Type BC-Auth BC-Auth

Description SP 800-38D. Authenticated encryption SP 800-38D. Authenticated decryption

Properties

Algorithms AES-CFB8: (A5747, A5748, A5749, A5774, A5775, A5776, A5927) AES-CTR: (A5747, A5748, A5749, A5774, A5775, A5776, A5927) AES-ECB: (A5747, A5748, A5749, A5751, A5752, A5753, A5754, A5755, A5774, A5775, A5776, A5927, A5932) AES-OFB: (A5747, A5748, A5749, A5774, A5775, A5776, A5927) AES-XTS Testing Revision 2.0: (A5747, A5748, A5749, A5774, A5775, A5776, A5927) AES-CCM: (A5747, A5748, A5749, A5774, A5775, A5776, A5927) AES-GCM: (A5759, A5760, A5761, A5762, A5763, A5764, A5765, A5766, A5767, A5777, A5781, A5782, A5783, A5928, A5929, A5930) AES-KW: (A5747, A5748, A5749, A5774, A5775, A5776, A5927) AES-KWP: (A5747, A5748, A5749, A5774, A5775, A5776, A5927) AES-CCM: (A5747, A5748, A5749, A5774, A5775, A5776, A5927) AES-GCM: (A5759, A5760, A5761,

© 2025 Canonical Ltd. / atsec information security.

Page 16

Name Message Authentication Generation with AES Message Authentication Generation with HMAC

Type MAC MAC

Description SP 800-38B and SP 800-38D Message authentication generation FIPS 198-1. Message authentication generation

Properties

Algorithms A5762, A5763, A5764, A5765, A5766, A5767, A5777, A5781, A5782, A5783, A5928, A5929, A5930) AES-KW: (A5747, A5748, A5749, A5774, A5775, A5776, A5927) AES-KWP: (A5747, A5748, A5749, A5774, A5775, A5776, A5927) AES-CMAC: (A5747, A5748, A5749, A5774, A5775, A5776, A5927) AES-GMAC: (A5759, A5760, A5761, A5762, A5763, A5764, A5765, A5766, A5767, A5777, A5781, A5782, A5783, A5928, A5929, A5930) HMAC-SHA-1: (A5750, A5768, A5769, A5770, A5771, A5778, A5931) HMAC-SHA2-224: (A5750, A5768, A5769, A5770, A5771, A5778, A5931) HMAC-SHA2-256: (A5750, A5768, A5769, A5770, A5771, A5778, A5779, A5931) HMAC-SHA2-384: (A5750, A5768, A5769, A5770, A5771, A5778, A5931) HMAC-SHA2-512: (A5750, A5768, A5769, A5770, A5771, A5778,

© 2025 Canonical Ltd. / atsec information security.

Page 17
Name Message Authentication Generation with KMAC Random Number Generation with DRBG Signature Generation with ECDSAType MAC DRBG DigSig-SigGenDescription SP 800-185. Message authentication generation SP 800-90ARev1. Random number generation FIPS 186-5. Signature generationPropertiesAlgorithms A5931) HMAC-SHA2- 512/224: (A5750, A5768, A5769, A5770, A5771, A5778, A5931) HMAC-SHA2- 512/256: (A5750, A5768, A5769, A5770, A5771, A5778, A5931) HMAC-SHA3-224: (A5756, A5780, A5933) HMAC-SHA3-256: (A5756, A5780, A5933) HMAC-SHA3-384: (A5756, A5780, A5933) HMAC-SHA3-512: (A5756, A5780, A5933) KMAC-128: (A5756, A5780, A5933) KMAC-256: (A5756, A5780, A5933) Counter DRBG: (A5746) Hash DRBG: (A5746) HMAC DRBG: (A5746) ECDSA SigGen (FIPS186-5): (A5750, A5756, A5768, A5769, A5770, A5771, A5778, A5780, A5931, A5933)
Signature Generation with RSADigSig-SigGenFIPS 186-5. Signature generationIG C.F:RSA SigGen was CAVP tested with moduli sizes 2048, 3072, 4096 bits. The module supports moduli sizes larger than 4096 bits, up to 16384 bits.RSA SigGen (FIPS186-5): (A5750, A5756, A5768, A5769, A5770, A5771, A5778, A5780, A5931, A5933)

© 2025 Canonical Ltd. / atsec information security.

Page 18
Name Signature Verification with ECDSAType DigSig-SigVerDescription FIPS 186-5. Signature verificationPropertiesAlgorithms ECDSA SigVer (FIPS186-5): (A5750, A5756, A5768, A5769, A5770, A5771, A5778, A5780, A5931, A5933)
Signature Verification with RSADigSig-SigVerFIPS 186-5. Signature verificationIG C.F:RSA SigVer was CAVP tested with moduli sizes 2048, 3072, 4096 bits. The module supports moduli sizes larger than 4096 bits, up to 16384 bits.RSA SigVer (FIPS186-5): (A5750, A5756, A5768, A5769, A5770, A5771, A5778, A5780, A5931, A5933)
Key Pair Generation with ECDSAAsymKeyPair- KeyGen CKGFIPS 186-5. Key pair generationECDSA KeyGen (FIPS186-5): (A5745, A5750, A5768, A5769, A5770, A5771, A5778, A5931) Asymmetric Cryptographic Key Generation (CKG): ()
Key Pair Generation with RSAAsymKeyPair- KeyGen CKGFIPS 186-5. Key pair generationIG C.F:RSA KeyGen was CAVP tested with moduli sizes of 2048, 3072, 4096, 6144, 8192 bits. The module supports moduli sizes larger than 8192 bits, up to 16384 bits. The number of Miller- Rabin tests is compliant with Table B.1 of FIPS 186-5.RSA KeyGen (FIPS186-5): (A5750, A5768, A5769, A5770, A5771, A5778, A5931) Asymmetric Cryptographic Key Generation (CKG): ()
Key Pair Generation with Safe PrimesAsymKeyPair- KeyGen CKGSP 800-56Ar3. Key pair generationSafe Primes Key Generation: (A5773) Asymmetric Cryptographic Key Generation (CKG): ()
Key Pair Verification with ECDSAAsymKeyPair- KeyVerFIPS 186-5 and FIPS186-4. Key verificationECDSA KeyVer (FIPS186-4): (A5745, A5750, A5768, A5769, A5770, A5771,

© 2025 Canonical Ltd. / atsec information security.

Page 19

Name Key Pair Verification with Safe Primes Key Derivation with KBKDF Key Derivation with KDA OneStep Key Derivation with KDA TwoStep Key Derivation with KDA HKDF Key Derivation with ANS X9.42 KDF Key Derivation with X9.63 KDF Key Derivation with SSH KDF Key Derivation with TLS 1.2 KDF Key Derivation with TLS 1.3 KDF Key Derivation with PBKDF2

Type AsymKeyPair- KeyVer KBKDF KAS-56CKDF KAS-56CKDF KAS-56CKDF KAS-135KDF KAS-135KDF KAS-135KDF KAS-135KDF KAS-135KDF PBKDF

Description SP 800-56Ar3. Key pair verification SP 800-108r1. Key derivation SP 800-56Cr2. Key derivation SP 800-56Cr2. Key derivation SP 800-56Cr2. Key derivation SP 800-135r1. Key derivation SP 800-135r1. Key derivation SP 800-135r1. Key derivation SP 800-135r1. Key derivation RFC 8446. Key derivation SP 800-132. Key derivation

Properties

Algorithms A5778, A5931) ECDSA KeyVer (FIPS186-5): (A5745, A5750, A5768, A5769, A5770, A5771, A5778, A5931) Safe Primes Key Verification: (A5773) KDF SP800-108: (A5772) KDA OneStep SP800-56Cr2: (A5744) KDA TwoStep SP800-56Cr2: (A5744) KDA HKDF SP800- 56Cr2: (A5758) KDF ANS 9.42: (A5750, A5756, A5768, A5769, A5770, A5771, A5778, A5780, A5931, A5933) KDF ANS 9.63: (A5750, A5768, A5769, A5770, A5771, A5778, A5931) KDF SSH: (A5751, A5752, A5753, A5754, A5755, A5932) TLS v1.2 KDF RFC7627: (A5750, A5768, A5769, A5770, A5771, A5778, A5931) TLS v1.3 KDF: (A5758) PBKDF: (A5750, A5756, A5768, A5769, A5770, A5771, A5778, A5780, A5931, A5933)

© 2025 Canonical Ltd. / atsec information security.

Page 20

Name Shared Secret Computation Message Digest with SHA Message Digest with SHAKE

Type KAS-SSC SHA XOF

Description SP 800-56Ar3. Shared secret computation FIPS 180-4 and FIPS 202. Message digest FIPS 202. Message digest

Properties

Algorithms KAS-ECC-SSC Sp800-56Ar3: (A5750, A5768, A5770, A5771, A5778, A5931, A5769) KAS-FFC-SSC Sp800-56Ar3: (A5773) SHA-1: (A5750, A5768, A5769, A5770, A5771, A5778, A5931) SHA2-224: (A5750, A5768, A5769, A5770, A5771, A5778, A5931) SHA2-256: (A5750, A5768, A5769, A5770, A5771, A5778, A5779, A5931) SHA2-384: (A5750, A5768, A5769, A5770, A5771, A5778, A5931) SHA2-512: (A5750, A5768, A5769, A5770, A5771, A5778, A5931) SHA2-512/224: (A5750, A5768, A5769, A5770, A5771, A5778, A5931) SHA2-512/256: (A5750, A5771, A5778, A5931, A5768, A5769, A5770) SHA3-224: (A5756, A5780, A5933) SHA3-256: (A5756, A5780, A5933) SHA3-384: (A5756, A5780, A5933) SHA3-512: (A5756, A5780, A5933) SHAKE-128: (A5756, A5780, A5933) SHAKE-256: (A5756, A5780, A5933)

© 2025 Canonical Ltd. / atsec information security.

Page 21
NameTypeDescriptionPropertiesAlgorithms
Signature Verification with RSA (Legacy)DigSig-SigVerFIPS 186-4. Legacy digital signature verificationIG C.M:Legacy AlgorithmsRSA SigVer (FIPS186-4): (A5750, A5768, A5770, A5771, A5778, A5931) Modulo: 1024 Hash Algorithm: SHA-1 RSA SigVer (FIPS186-4): (A5769) Modulo : 1024 Hash Algorithm: SHA-1
Signature Verification with ECDSA (Legacy)DigSig-SigVerFIPS 186-4. Legacy digital signature verificationIG C.M:Legacy AlgorithmsECDSA SigVer (FIPS186-4): (A5750, A5756, A5768, A5769, A5770, A5771, A5778, A5780, A5931, A5933) Curve: P-192 Hash Algorithm: SHA-1

Table 8: Security Function Implementations

2.7 Algorithm Specific Information
2.7.1 AES GCM IV

For TLS 1.2, the module offers the AES GCM implementation and uses the context of Scenario 1 of FIPS 140-3 IG C.H. The module is compliant with SP 800-52r2 Section

3.3.1 and the mechanism for IV generation is compliant with RFC 5288 and 8446.

The module does not implement the TLS protocol. The module’s implementation of AES GCM is used together with an application that runs outside the module’s cryptographic boundary. The design of the TLS protocol implicitly ensures that the counter (the nonce_explicit part of the IV) does not exhaust the maximum number of possible values for a given session key. In the event the module’s power is lost and restored, the consuming application must ensure that a new key for use with the AES GCM key encryption or decryption under this scenario shall be established. Alternatively, the Crypto Officer can use the module’s API to perform AES GCM encryption using internal IV generation. These IVs are always 96 bits and generated using the approved DRBG internal to the module’s boundary in compliance with Scenario 2 of IG C.H. © 2025 Canonical Ltd. / atsec information security.

Page 22

The module also provides a non-approved AES GCM encryption service which accepts arbitrary external IVs from the operator. The service can be requested by invoking the EVP_EncryptInit_ex2 API function with a non-NULL iv value. When this is the case, the API will set a non-approved service indicator as described in Section 4.3. Finally, for TLS 1.3, the AES GCM implementation uses the context of Scenario 5 of FIPS 140-3 IG C.H. The protocol that provides this compliance is TLS 1.3, defined in RFC8446 of August 2018, using the cipher-suites that explicitly select AES GCM as the encryption/decryption cipher (Appendix B.4 of RFC8446). The module supports acceptable AES GCM cipher suites from Section 3.3.1 of SP800-52r2. The module’s implementation of AES GCM is used together with an application that runs outside the module’s cryptographic boundary. The design of the TLS protocol implicitly ensures that the counter (the nonce_explicit part of the IV) does not exhaust the maximum number of possible values for a given session key

2.7.2 AES XTS

In accordance to FIPS 140-3 IG C.I, the module implements a check that ensures, before performing any cryptographic operation, that the two AES keys used in AES XTS mode are not identical. As the module does not generate symmetric keys, the check is performed when keys are input the service APIs. Key_1 and Key_2 shall be generated and/or established independently according to the rules for component symmetric keys from NIST SP 800-133rev2, Sec. 6.3. In addition, Section 4 of SP 800-38E states that the length of a single data unit encrypted or decrypted with AES XTS shall not exceed 2²⁰ AES blocks, that is 16MB, of data per XTS instance. The XTS mode shall only be used for the cryptographic protection of data on storage devices. It shall not be used for other purposes, such as the encryption of data in transit.

2.7.3 Key Derivation using SP 800-132 PBKDF2

The module provides password-based key derivation (PBKDF2), compliant with SP 800-132. The module supports option 1a from Section 5.4 of SP 800-132, in which the Master Key (MK) or a segment of it is used directly as the Data Protection Key (DPK). In accordance to SP 800-132 and FIPS 140-3 IG D.N, the following requirements shall be met:

Derived keys shall only be used in storage applications. The MK shall not be used for other purposes. The module accepts a minimum length of 112 bits for the MK or DPK .
Passwords or passphrases, used as an input for the PBKDF2, shall not be used as cryptographic keys.
The minimum length of the password or passphrase accepted by the module is 8 characters. Assuming the worst-case scenario of all digits, this results in the estimated probability of guessing the password to be at most 10-8. Combined with © 2025 Canonical Ltd. / atsec information security.
Page 23
CertVendor
NumberName
E218Canonical

the minimum iteration count as described below, this provides an acceptable trade-off between user experience and security against brute-force attacks.

2.7.4 Compliance to SP 800-56Arev3 Assurances

The module offers DH and ECDH shared secret computation services compliant to the SP 800-56ARev3 and meeting IG D.F scenario 2 path (1). In order to meet the required assurances listed in section 5.6 of SP 800-56Arev3, the module shall be used together with an application that implements the “TLS protocol” and the following steps shall be performed.

  1. The entity using the module, must use the module's "Key pair generation" service for generating DH/ECDH ephemeral keys. This meets the assurances required by key pair owner defined in the section 5.6.2.1 of SP 800-56ARev3.
  2. As part of the module's shared secret computation (SSC) service, the module internally performs the public key validation on the peer's public key passed in as input to the SSC function. This meets the public key validity assurance required by the sections 5.6.2.2.2 of SP 800-56ARev3.
  3. The module does not support static keys therefore the "assurance of peer's possession of private key" is not applicable.
2.7.5 Authenticated Encryption/Decryption

The module does not establish SSPs using an approved key transport scheme (KTS). However, it does offer approved authenticated algorithms that can be used by an external operator/application as part of an approved KTS.

2.7.6 KAS-SSC

The module does not establish SSPs using an approved key agreement scheme (KAS). However, it does offer some or all of the underlying KAS cryptographic functionality to be used by an external operator/application as part of an approved KAS.

2.8 RBG and Entropy

Table 9: Entropy Certificates © 2025 Canonical Ltd. / atsec information security.

Page 24
NameTypeOperational EnvironmentSample SizeEntropy per SampleConditioning Component
OpenSSL CPU Time JitterNon- PhysicalUbuntu 24.04 on Supermicro SYS-1019P-WTR on Intel Xeon Gold 6226; Ubuntu 24.04 on Amazon Web Services (AWS) c7g.metal on AWS Graviton3; Ubuntu 24.04 on IBM Telum on IBM z16256Full entropySHA3-256 (A5588); Counter DRBG (kernel) (A5588, A5591, A5592, A5593, A5594, A5595, A5599, A5600, A5601, A5602, A5603, A5606, A5607, A5608, A5609, A5610, A5611); Counter DRBG (A5746)

Table 10: Entropy Sources The module implements a primary DRBG (AES-256-CTR-DRBG (5746)) which acts as the conditioning component for the entropy source mentioned in the above table. It is only used internally by the module to seed the secondary DRBGs which can be of type (CTR, Hash, HMAC). The module complies with the Public Use Document for ESV certificate E218 by reading entropy data from the EVP_RAND_generate() function of the primary DRBG, which corresponds to the GetEntropy() conceptual interface. The operational environment on the ESV certificate is identical to the operating system described in this document. There are no maintenance requirements for the entropy source. As per the Public Use document of entropy certificate E218, the entropy source provides full entropy of 256 bits. When the module needs random data for internal purposes it uses two separate instances of AES-256 CTR_DRBG DRBG based on use case. i.e., it uses the “private DRBG” accessed via RAND_priv_bytes () for asymmetric key generation, signature generation, or other SSP use cases and it uses the “public DRBG” accessed via RAND_bytes() when it needs to generate IV or other non-SSP use cases. When an external caller needs the random data, they can access it via “Random Number Generation” service of the module and they have a choice between Hash, HMAC or CTR_DRBG listed in the Approved Algorithms table.

2.9 Key Generation

The module implements asymmetric key pair generation compliant with SP 800-133 Rev. 2 as listed in the Security Function Implementations table. When random values are required, they are obtained from the SP 800-90A Rev. 1 approved DRBG, compliant with Section 4 of SP 800-133 Rev. 2 (without XOR). Intermediate key generation values are not output from the module and are explicitly zeroized after processing the service. The key derivation methods implemented by the module are specified in the Security Function Implementations table. © 2025 Canonical Ltd. / atsec information security.

Page 25
2.10 Key Establishment

Key Establishment methods are specified in the Security Function Implementations table.

2.11 Industry Protocols

The module implements the SSH KDF (CVL) for use in the SSH protocol (RFC 4253 and RFC 6668). GCM with internal IV generation in the approved mode is compliant with versions 1.2 and 1.3 of the TLS protocol (RFC 5288 and 8446) and shall only be used in conjunction with the TLS protocol. Additionally, the module implements the TLS 1.2 and TLS 1.3 key derivation functions for use in the TLS protocol. For Diffie-Hellman, the module supports the use of the safe primes defined in RFC

3526 (IKE) and RFC 7919 (TLS). Note that the module only implements key pair

generation, key pair verification, and shared secret computation. No other part of the IKE or TLS protocols is implemented (with the exception of the TLS 1.2 KDF (CVL) and

1.3 KDF (CVL)):
2.12 Additional Information

Not applicable. © 2025 Canonical Ltd. / atsec information security.

Page 26
Physical PortLogical Interface(s)Data That Passes
N/AData InputAPI input parameters
N/AData OutputAPI output parameters
N/AControl InputAPI function calls
N/AStatus OutputAPI return codes, error queue
3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

Table 11: Ports and Interfaces As a software-only module, the module does not have physical ports. Physical Ports are interpreted to be the physical ports of the hardware platform on which it runs. The module does not implement a control output interface.

3.2 Trusted Channel Specification
3.3 Control Interface Not Inhibited
3.4 Additional Information

Not applicable. © 2025 Canonical Ltd. / atsec information security.

Page 27
NameTypeOperator TypeAuthentication Methods
Crypto OfficerRoleCONone
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
Message DigestCompute a message digest0MessageMessage digestMessage Digest with SHA Message Digest with SHAKECrypto Officer
Symmetric EncryptionEncrypt a plaintext0AES Key, plaintext, IVCiphertextEncryption with AESCrypto Officer - AES Key: W,E
Symmetric DecryptionDecrypt a ciphertext0AES Key, ciphertext, IVPlaintextDecryption with AESCrypto Officer - AES Key: W,E
Authenticated Symmetric EncryptionEncrypt and authenticate a plaintext0AES Key, plaintext, IVCiphertext, MAC tagAuthenticated Encryption with AESCrypto Officer - AES Key: W,E
Authenticated Symmetric DecryptionDecrypt and authenticate a ciphertext0AES Key, ciphertext, MAC tag, IVPlaintext or FailureAuthenticated Decryption with AESCrypto Officer - AES Key: W,E
AES Message Authentication GenerationCompute a MAC tag using AES0AES Key, messageMAC tagMessage Authentication Generation with AESCrypto Officer - AES Key: W,E
HMAC Message Authentication GenerationCompute a MAC tag using HMAC0HMAC Key, messageMAC tagMessage Authentication Generation with HMACCrypto Officer - HMAC Key: W,E
KMAC Message Authentication GenerationCompute a MAC tag using KMAC0KMAC Key, messageMAC tagMessage Authentication Generation with KMACCrypto Officer - KMAC Key: W,E
4 Roles, Services, and Authentication
4.2 Roles

Table 12: Roles The module supports the Crypto Officer role only. This sole role is implicitly and always assumed by the operator of the module. No support is provided for a maintenance role.

4.3 Approved Services

© 2025 Canonical Ltd. / atsec information security.

Page 28
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
TLS KDF Key DerivationTLS key derivation0Shared SecretTLS Derived KeyKey Derivation with TLS 1.2 KDF Key Derivation with TLS 1.3 KDFCrypto Officer - Shared Secret: W,E - TLS Derived Key: G,R
KBKDF Key DerivationDerive a key from a key- derivation key0Key- Derivation KeyKBKDF Derived KeyKey Derivation with KBKDFCrypto Officer - Key- Derivation Key: W,E - KBKDF Derived Key: G,R
ANS X9.42 Key DerivationDerive a key from a shared secret0Shared SecretANS X9.42 Derived KeyKey Derivation with ANS X9.42 KDFCrypto Officer - ANS X9.42 Derived Key: G,R - Shared Secret: W,E
ANS X9.63 Key DerivationDerive a key from a shared secret0Shared SecretANS X9.63 Derived KeyKey Derivation with X9.63 KDFCrypto Officer - Shared Secret: W,E - ANS X9.63 Derived Key: G,R
HKDF Key DerivationDerive a key from a shared secret0Shared SecretHKDF Derived keyKey Derivation with KDA HKDFCrypto Officer - Shared Secret: W,E - HKDF Derived Key: G,R
OneStep KDA Key DerivationDerive a key from a shared secret0Shared SecretKDA OneStep Derived KeyKey Derivation with KDA OneStepCrypto Officer - Shared Secret: W,E - KDA OneStep Derived Key: G,R
TwoStep KDA Key DerivationDerive a key from a shared secret0Shared SecretKDA TwoStep Derived KeyKey Derivation with KDA TwoStepCrypto Officer - Shared Secret: W,E - KDA TwoStep Derived Key: G,R
SSH KDF key derivationDerive a key from a shared secret0Shared SecretSSH KDF Derived KeyKey Derivation with SSH KDFCrypto Officer - Shared Secret: W,E - SSH KDF

G,R G,R G,R G,R G,R G,R © 2025 Canonical Ltd. / atsec information security.

Page 29
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access Derived Key: G,R
PBKDF Key DerivationDerive a key from a password0PasswordPBKDF Derived KeyKey Derivation with PBKDF2Crypto Officer - Password: W,E - PBKDF Derived Key: G,R
Random Number GenerationGenerate random number0Number of bitsRandom numberRandom Number Generation with DRBGCrypto Officer - Entropy Input: W,E - DRBG Seed: G,E - DRBG Internal State (V, Key): G,E - DRBG Internal State (V, C): G,E
KAS-FFC-SSC Shared Secret ComputationCompute a shared secret0DH Private Key (owner), DH Public Key (peer)Shared SecretShared Secret ComputationCrypto Officer - Shared Secret: G,R - DH Private Key: W,E - DH Public Key: W,E
KAS-ECC-SSC Shared Secret ComputationCompute a shared secret0EC Private Key (owner), EC Public Key (peer)Shared SecretShared Secret ComputationCrypto Officer - Shared Secret: G,R - EC Private Key: W,E - EC Public Key: W,E
RSA Digital Signature GenerationGenerate a digital signature with RSA0RSA Private Key, message, hash algorithmSignatureSignature Generation with RSACrypto Officer - RSA Private Key: W,E
ECDSA Digital Signature GenerationGenerate a digital signature with ECDSA0EC Private Key, message, hash algorithmSignatureSignature Generation with ECDSACrypto Officer - EC Private Key: W,E
RSA Digital Signature VerificationVerify a digital signature using RSA0RSA Public Key, message, signature, hash algorithmPass or FailSignature Verification with RSA Signature Verification with RSA (Legacy)Crypto Officer - RSA Public Key: W,E

G,R G,R G,E (V, C): G,E © 2025 Canonical Ltd. / atsec information security.

Page 30
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
ECDSA Digital Signature VerificationVerify a digital signature using ECDSA0EC Public Key, message, signature, hash algorithmPass or FailSignature Verification with ECDSA Signature Verification with ECDSA (Legacy)Crypto Officer - EC Public Key: W,E
RSA Key Pair GenerationGenerate an RSA key pair0Modulus bitsModule Generated RSA Private Key, Module Generated RSA Public KeyKey Pair Generation with RSACrypto Officer - Module Generated RSA Private Key: G,R - Module Generated RSA Public Key: G,R - Intermediate Key Generation Value: G,E,Z
ECDSA Key Pair GenerationGenerate an EC key pair0CurveModule Generated EC Private Key, Module Generated EC Public KeyKey Pair Generation with ECDSACrypto Officer - Module Generated EC Private Key: G,R - Module Generated EC Public Key: G,R - Intermediate Key Generation Value: G,E,Z
Safe Primes Key Pair GenerationGenerate an DH key pair0GroupModule Generated DH Private Key, Module Generated DH Public KeyKey Pair Generation with Safe PrimesCrypto Officer - Module Generated DH Private Key: G,R - Module Generated DH Public Key: G,R - Intermediate Key Generation Value: G,E,Z
ECDSA Key Pair VerificationVerify an EC key pair0EC Private Key, EC Public KeyPass or FailKey Pair Verification with ECDSACrypto Officer - EC Private Key: W,E - EC Public Key: W,E

G,R G,R © 2025 Canonical Ltd. / atsec information security.

Page 31
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
Safe Prime Key Pair VerificationVerify a DH key pair0DH Private Key, DH Public KeyPass or FailKey Pair Verification with Safe PrimesCrypto Officer - DH Private Key: W,E - DH Public Key: W,E
Show VersionReturn the name and version information0NoneModule name and versionNoneCrypto Officer
Show StatusReturn the module status0NoneModule statusNoneCrypto Officer
Self-TestPerform the CASTs and integrity test0NonePass or Fail of self-testsNoneCrypto Officer
ZeroizationZeroize any SSP0An SSPNoneNoneCrypto Officer - AES Key: Z - HMAC Key: Z - KMAC Key: Z - Key- Derivation Key: Z - Shared Secret: Z - Password: Z - PBKDF Derived Key: Z - KBKDF Derived Key: Z - ANS X9.42 Derived Key: Z - ANS X9.63 Derived Key: Z - HKDF Derived Key: Z - KDA OneStep Derived Key: Z - KDA TwoStep Derived Key: Z - TLS Derived Key: Z - SSH KDF Derived Key: Z - Entropy Input: Z - DRBG Internal State (V, Key): Z - DRBG Seed:

© 2025 Canonical Ltd. / atsec information security.

Page 32

Name

Description

Indicator

Inputs

Outputs

Security Functions

SSP Access Z - DH Private Key: Z - DH Public Key: Z - EC Private Key: Z - EC Public Key: Z - RSA Private Key: Z - RSA Public Key: Z - Module Generated DH Private Key: Z - Module Generated DH Public Key: Z - Module Generated EC Private Key: Z - Module Generated EC Public Key: - Module Generated RSA Private Key: Z - Module Generated RSA Public Key: Z

Z Table 13: Approved Services The module provides services to operators that assume the available role. All services are described in detail in the API documentation (manual pages). The Approved Services table and the Non-Approved Services table define the services that utilize approved and non-approved security functions in this module. For the respective tables, the convention below applies when specifying the access permissions (types) that the service has for each SSP.

Generate (G): The module generates or derives the SSP.
Read (R): The SSP is read from the module (e.g., the SSP is output).
Write (W): The SSP is updated, imported, or written to the module.
Execute(E): The module uses the SSP in performing a cryptographic operation.
Zeroize (Z): The module zeroizes the SSP.

To interact with the module, a calling application must use the EVP API layer provided by OpenSSL. This layer will delegate the request to the FIPS provider, which will in © 2025 Canonical Ltd. / atsec information security.

Page 33
NameDescriptionAlgorithmsRole
EncryptionAES GCM (external IV)AES GCM (external IV)CO
Key Pair GenerationKey pair generationDSA ECDSA with curve P-192, B-163, K-163CO
Key Pair VerificationKey pair verificationDSA ECDSA with curve B-163, K-163CO
Signature GenerationSignature generationDSA ECDSA with curve P-192 ECDSA with curve B-163, B-233, B-283, B-409, B- 571, K-163, K-233, K-283, K-409, K-571 RSA and ECDSA (pre-hashed message) RSA X9.31CO
Signature VerificationSignature verificationDSA ECDSA with curve B-163, B-233, B-283, B-409, B- 571, K-163, K-233, K-283, K-409, K-571 RSA and ECDSA (pre-hashed message) RSA X9.31CO
Asymmetric EncryptionAsymmetric encryptionRSA primitive RSA-OAEPCO
Asymmetric DecryptionAsymmetric decryptionRSA primitive RSA-OAEPCO
Secret Value EncapsulationSecret value encapsulationRSASVECO
Secret Value Un- encapsulationSecret value un- encapsulationRSASVECO

turn perform the requested service. Additionally, this EVP API layer can be used to retrieve the approved service indicator for the module. The cryptographic module provides an approved service indicator in the form of an OpenSSL provider gettable parameter called UBUNTU_OSSL_PROV_FIPS_PARAM_UNAPPROVED_USAGE. This parameter will be equal to 0 if the requested service is an approved security service, otherwise it will be set to 1. The operator is responsible to query the value of such gettable parameter after calling the requested service.

4.4 Non-Approved Services

Table 14: Non-Approved Services In the table above, CO specifies the Crypto Officer role.

4.5 External Software/Firmware Loaded

The module does not have the capability of loading software or firmware from an external source. © 2025 Canonical Ltd. / atsec information security.

Page 34
4.6 Bypass Actions and Status
4.7 Cryptographic Output Actions and Status
4.8 Additional Information

Not applicable. © 2025 Canonical Ltd. / atsec information security.

Page 35
5 Software/Firmware Security
5.1 Integrity Techniques

The integrity of the module is verified by comparing a HMAC-SHA2-256 value calculated at run time with the HMAC-SHA2-256 value embedded in the fips.so file that was computed at build time.

5.2 Initiate on Demand

Integrity tests are performed as part of the pre-operational self-tests, which are executed when the module is initialized. The integrity test may be invoked on-demand by unloading and subsequently re-initializing the module, or by calling the OSSL_PROVIDER_self_test function. This will perform (among others) the software integrity test.

5.3 Open-Source Parameters
5.4 Additional Information

Not applicable. © 2025 Canonical Ltd. / atsec information security.

Page 36
6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Modifiable How Requirements are Satisfied: The module shall be installed as stated in Section 11. If properly installed, the operating system provides process isolation and memory protection mechanisms that ensure appropriate separation for memory access among the processes on the system. Each process has control over its own data and uncontrolled access to the data of other processes is prevented.

6.2 Configuration Settings and Restrictions

Instrumentation tools like the ptrace system call, gdb and strace, userspace live patching, as well as other tracing mechanisms offered by the Linux environment such as ftrace or systemtap, shall not be used in the operational environment. The use of any of these tools implies that the cryptographic module is running in a non-validated operational environment.

6.3 Additional Information

There are no concurrent operators. © 2025 Canonical Ltd. / atsec information security.

Page 37
7 Physical Security

The module is comprised of software only, and therefore this section is not applicable. © 2025 Canonical Ltd. / atsec information security.

Page 38
8 Non-Invasive Security
8.1 Mitigation Techniques

This module does not implement any non-invasive security mechanism, and therefore this section is not applicable.

8.2 Effectiveness
8.3 Additional Information

Not applicable. © 2025 Canonical Ltd. / atsec information security.

Page 39
Storage Area NameDescriptionPersistence Type
RAMTemporary storage for SSPs used by the module as part of service execution. The module does not perform persistent storage of SSPs.Dynamic

Name API input parameters API output parameters

From Operator calling application (TOEPP) Cryptographic module

To Cryptographic module Operator calling application (TOEPP)

Format Type Plaintext Plaintext

Distribution Type Manual Manual

Entry Type Electronic Electronic

SFI or Algorithm

Zeroization MethodDescriptionRationaleOperator Initiation
Free cipher handleZeroizes the SSPs contained within the cipher handle: EVP_CIPHER_CTX_free() clears and frees symmetric cipher context, EVP_MAC_CTX_free() clears and frees MAC context, EVP_KDF_CTX_free() clears and frees KDF context, EVP_RAND_CTX_free() clears and frees DRBG context, EVP_PKEY_free() clears and frees asymmetric key pair structuresMemory occupied by SSPs is overwritten with zeroes and then it is released, which renders the SSP values irretrievable. The completion of the zeroization routine indicates that theBy calling the cipher related zeroization API
9 Sensitive Security Parameters Management
9.1 Storage Areas

Table 15: Storage Areas Table 16: SSP Input-Output Methods running on the same operational environment. This corresponds to manual distribution, electronic entry/output (“CM Software to/from App via TOEPP Path”) per FIPS 140-3 IG 9.5.A Table 1. There is no entry or output of cryptographically protected SSPs can be entered into the module via API input parameters, when required by a immediately after generation of the SSP. © 2025 Canonical Ltd. / atsec information security.

Page 40
Zeroization MethodDescriptionRationale zeroization procedure succeeded.Operator Initiation
AutomaticAutomatically zeroized by the module when no longer neededMemory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable.N/A
Module resetDe-allocates the volatile memory used to store SSPsVolatile memory used by the module is overwritten within nanoseconds when power is removed.By unloading and reloading the module

Name AES Key HMAC Key KMAC Key Key- Derivation Key

Description Used for encryption, decryption, and message authentication Used for hash- based message authentication Used for message authentication Used for key derivation

Size - Strength 128, 192, 256 bits - 128, 192, 256 bits 112-524288 bits - 112- 256 bits 128-1024 bits - 112- 256 bits 112-4096 bits - 112- 256 bits

Type - Category Symmetric key - CSP Symmetric key - CSP Symmetric key - CSP Symmetric key - CSP

Generated By

Established By

Used By Encryption with AES Decryption with AES Authenticated Encryption with AES Authenticated Decryption with AES Message Authentication Generation with AES Message Authentication Generation with HMAC Message Authentication Generation with KMAC Key Derivation with KBKDF

Table 17: SSP Zeroization Methods system calls. The operator is responsible for calling the appropriate destruction functions provided in the module's API. The destruction functions, listed above, the regular memory de-allocation operating system call. All data output is inhibited during zeroization. © 2025 Canonical Ltd. / atsec information security.

Page 41

Name Shared Secret Password PBKDF Derived Key KBKDF Derived Key ANS X9.42 Derived Key ANS X9.63 Derived Key HKDF Derived Key KDA OneStep Derived Key

Description Generated by shared secret computation and used for key derivation Used for password-based key derivation Generated by password-based key derivation Generated by key-based key derivation Generated by ANS X9.42 key derivation Generated by ANS X9.63 key derivation Generated by HKDF key derivation Generated by OneStep KDA key derivation

Size - Strength 224-8192 bits - 112- 256 bits At least 8 characters - N/A 112-4096 bits - 112- 256 bits 112-4096 bits - 112- 256 bits 128-4096 bits - 112- 256 bits 128-4096 bits - 112- 256 bits 224-8192 bits - 112- 256 bits 2048 bits - 112-256 bits

Type - Category Shared secret - CSP Password - CSP Symmetric key - CSP Symmetric key - CSP Symmetric key - CSP Symmetric key - CSP Symmetric key - CSP Symmetric key - CSP

Generated By Key Derivation with PBKDF2 Key Derivation with KBKDF Key Derivation with ANS X9.42 KDF Key Derivation with X9.63 KDF Key Derivation with KDA HKDF Key Derivation with KDA OneStep

Established By Shared Secret Computation

Used By Key Derivation with KDA OneStep Key Derivation with KDA TwoStep Key Derivation with KDA HKDF Key Derivation with ANS X9.42 KDF Key Derivation with X9.63 KDF Key Derivation with SSH KDF Key Derivation with TLS 1.2 KDF Key Derivation with TLS 1.3 KDF Key Derivation with PBKDF2

© 2025 Canonical Ltd. / atsec information security.

Page 42

Name KDA TwoStep Derived Key TLS Derived Key SSH KDF Derived Key Entropy Input DRBG Internal State (V, Key) DRBG Internal State (V, C) DRBG Seed DH Private Key

Description Generated by TwoStep KDA key derivation Generated by TLS KDF key derivation Generated by SSH KDF key derivation Used for random number generation and seeding a DRBG (compliant with IG D.L) Used for random number generation (compliant with IG D.L) Used for random number generation (compliant with IG D.L) Used for random number generation (compliant with IG D.L) Used for shared secret computation and key pair verification

Size - Strength 2048 bits - 112-256 bits 112-1024 bits - 112- 256 bits 112-256 bits - 112-256 bits 128-384 bits - 128-256 bits Counter DRBG: 256, 320, 348 bits; HMAC DRBG: 320, 512, 1024 bits - Counter DRBG: 128, 192, 256 bits; HMAC DRBG: 128, 256 bits 880, 1776 bits - 128, 256 bits 128-256 bits - 128-256 bits 2048-8192 bits - 112- 200 bits

Type - Category Symmetric key - CSP Symmetric key - CSP Symmetric key - CSP Entropy input - CSP Internal state - CSP Internal state - CSP Seed - CSP Private key - CSP

Generated By Key Derivation with KDA TwoStep Key Derivation with TLS 1.2 KDF Key Derivation with TLS 1.3 KDF Key Derivation with SSH KDF Random Number Generation with DRBG Random Number Generation with DRBG Random Number Generation with DRBG

Established By

Used By Random Number Generation with DRBG Random Number Generation with DRBG Random Number Generation with DRBG Random Number Generation with DRBG Key Pair Verification with Safe Primes Shared Secret Computation

© 2025 Canonical Ltd. / atsec information security.

Page 43

Name DH Public Key EC Private Key EC Public Key RSA Private Key RSA Public Key Module Generated DH Private Key Module Generated DH Public Key Module Generated EC Private Key Module Generated EC Public Key

Description Used for shared secret computation and key pair verification Used for shared secret computation, digital signature generation, and key pair verification Used for shared secret computation, signature verification, and key pair verification Used for signature generation Used for signature verification DH private key generated by the module DH public key generated by the module EC private key generated by the module EC public key generated by the module

Size - Strength 2048-8192 bits - 112- 200 bits P-224, P-256, P-384, P-521, K-233, K-283, K-409, K-571, B-233, B-283, B-409, B-571 bits - 112- 256 bits P-192, P-224, P-256, P-384, P-521, K-163, K-233, K-283, K-409, K-571, B-163, B-233, B-283, B-409, B-571 bits - 80-256 bits 2048-16384 bits - 112- 256 bits 1024-16384 bits - 80-256 bits 2048-8192 bits - 112- 200 bits 2048-8192 bits - 112- 200 bits P-224, P-256, P-384, P-521, K-233, K-283, K-409, K-571, B-233, B-283, B-409, B-571 bits - 112- 256 bits P-224, P-256, P-384, P-521, K-163, K-233, K-283, K-409,

Type - Category Public key - PSP Private key - CSP Public key - PSP Private key - CSP Public key - PSP Private key - CSP Public key - PSP Private key - CSP Public key - PSP

Generated By Key Pair Generation with Safe Primes Key Pair Generation with Safe Primes Key Pair Generation with ECDSA Key Pair Generation with ECDSA

Established By

Used By Key Pair Verification with Safe Primes Shared Secret Computation Signature Generation with ECDSA Key Pair Verification with ECDSA Shared Secret Computation Signature Verification with ECDSA Key Pair Verification with ECDSA Shared Secret Computation Signature Generation with RSA Signature Verification with RSA

© 2025 Canonical Ltd. / atsec information security.

Page 44

Name Module Generated RSA Private Key Module Generated RSA Public Key Intermediate Key Generation Value

Description RSA private key generated by the module RSA public key generated by the module Used for key pair generation

Size - Strength K-571, B-163, B-233, B-283, B-409, B-571 bits - 112- 256 bits 2048-16384 bits - 112- 256 bits 2048-16384 bits - 112- 256 bits 224-16384 bits - 112- 256 bits

Type - Category Private key - CSP Public key - PSP Intermediate value - CSP

Generated By Key Pair Generation with RSA Key Pair Generation with RSA Key Pair Generation with ECDSA Key Pair Generation with RSA Key Pair Generation with Safe Primes

Established By

Used By Key Pair Generation with ECDSA Key Pair Generation with RSA Key Pair Generation with Safe Primes

Name AES Key HMAC Key KMAC KeyInput - Output API input parameters API input parameters API input parametersStorage RAM:Plaintext RAM:Plaintext RAM:PlaintextStorage Duration From service invocation to service completion From service invocation to service completion From service invocation to service completionZeroization Free cipher handle Module reset Free cipher handle Module reset Free cipher handle Module resetRelated SSPs
Key-Derivation KeyAPI input parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetKBKDF Derived Key:Derives
Shared SecretAPI input parameters API output parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetDH Private Key:Generated From DH Public Key:Generated From EC Private

Table 18: SSP Table 1 © 2025 Canonical Ltd. / atsec information security.

Page 45
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs Key:Generated From EC Public Key:Generated From
PasswordAPI input parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetPBKDF Derived Key:Derives
PBKDF Derived KeyAPI output parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetPassword:Derived From
KBKDF Derived KeyAPI output parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetKey-Derivation Key:Derived From
ANS X9.42 Derived KeyAPI output parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetShared Secret:Derived From
ANS X9.63 Derived KeyAPI output parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetShared Secret:Derived From
HKDF Derived KeyAPI output parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetShared Secret:Derived From
KDA OneStep Derived KeyAPI output parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetShared Secret:Derived From
KDA TwoStep Derived KeyAPI output parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetShared Secret:Derived From
TLS Derived KeyAPI output parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetShared Secret:Derived From
SSH KDF Derived KeyAPI output parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetShared Secret:Derived From
Entropy InputRAM:PlaintextFrom service invocation to service completionAutomaticDRBG Seed:Generates
DRBG Internal State (V, Key)RAM:PlaintextFrom DRBG instantiation to un-Free cipher handleDRBG Seed:Generated From

© 2025 Canonical Ltd. / atsec information security.

Page 46
Name DRBG Internal State (V, C) DRBG SeedInput - OutputStorage RAM:Plaintext RAM:PlaintextStorage Duration instantiation or internal zeroization From DRBG instantiation to un- instantiation or internal zeroization From service invocation to service completionZeroization Module reset Free cipher handle Module reset Free cipher handle Module resetRelated SSPs DRBG Seed:Generated From DRBG Internal State (V, Key):Generates DRBG Internal State (V, C):Generates Entropy Input:Generated From
DH Private KeyAPI input parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetDH Public Key:Paired With Shared Secret:Derives
DH Public KeyAPI input parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetDH Private Key:Paired With Shared Secret:Generates
EC Private KeyAPI input parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetEC Public Key:Paired With Shared Secret:Generates
EC Public KeyAPI input parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetEC Private Key:Paired With Shared Secret:Generates
RSA Private KeyAPI input parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetRSA Public Key:Paired With
RSA Public KeyAPI input parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetRSA Private Key:Paired With
Module Generated DH Private KeyAPI output parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetModule Generated DH Public Key:Paired With Intermediate Key Generation Value:Generated From
Module Generated DH Public KeyAPI output parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetModule Generated DH Private Key:Paired With Intermediate Key Generation Value:Generated From

© 2025 Canonical Ltd. / atsec information security.

Page 47
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
Module Generated EC Private KeyAPI output parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetModule Generated EC Public Key:Paired With Intermediate Key Generation Value:Generated From
Module Generated EC Public KeyAPI output parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetModule Generated EC Private Key:Paired With Intermediate Key Generation Value:Generated From
Module Generated RSA Private KeyAPI output parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetModule Generated RSA Public Key:Paired With Intermediate Key Generation Value:Generated From
Module Generated RSA Public KeyAPI output parametersRAM:PlaintextFrom service invocation to service completionFree cipher handle Module resetModule Generated RSA Private Key:Paired With Intermediate Key Generation Value:Generated From
Intermediate Key Generation ValueRAM:PlaintextFrom service invocation to service completionAutomaticModule Generated DH Private Key:Generates Module Generated DH Public Key:Generates Module Generated EC Private Key:Generates Module Generated EC Public Key:Generates Module Generated RSA Private Key:Generates Module Generated RSA Public Key:Generates

Table 19: SSP Table 2 The tables above summarize the Sensitive Security Parameters (SSPs) that are used by the cryptographic services implemented in the module in the approved services (Approved Services table). SSPs, including CSPs, are directly imported as input parameters and exported as output parameters from the module. Because these SSPs are only transiently used for a specific service, they are, by definition, exclusive between approved and nonapproved services. © 2025 Canonical Ltd. / atsec information security.

Page 48
9.5 Transitions

The SHA-1 algorithm, as implemented by the module, will be non-approved for all purposes starting January 1, 2031.

9.6 Additional Information

Not applicable. © 2025 Canonical Ltd. / atsec information security.

Page 49
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
HMAC-SHA2- 256 (A5750)256-bit keyMessage AuthenticationSW/FW IntegrityModule becomes operational and services are available for useIntegrity test for fips.so
HMAC-SHA2- 256 (A5768)256-bit keyMessage AuthenticationSW/FW IntegrityModule becomes operational and services are available for useIntegrity test for fips.so
HMAC-SHA2- 256 (A5769)256-bit keyMessage AuthenticationSW/FW IntegrityModule becomes operational and services are available for useIntegrity test for fips.so
HMAC-SHA2- 256 (A5770)256-bit keyMessage AuthenticationSW/FW IntegrityModule becomes operational and services are available for useIntegrity test for fips.so
HMAC-SHA2- 256 (A5771)256-bit keyMessage AuthenticationSW/FW IntegrityModule becomes operational and services are available for useIntegrity test for fips.so
HMAC-SHA2- 256 (A5778)256-bit keyMessage AuthenticationSW/FW IntegrityModule becomes operational and services are available for useIntegrity test for fips.so
HMAC-SHA2- 256 (A5779)256-bit keyMessage AuthenticationSW/FW IntegrityModule becomes operational and services are available for useIntegrity test for fips.so
HMAC-SHA2- 256 (A5931)256-bit keyMessage AuthenticationSW/FW IntegrityModule becomes operational and services are available for useIntegrity test for fips.so
10 Self-Tests
10.1 Pre-Operational Self-Tests

Table 20: Pre-Operational Self-Tests The module performs pre-operational tests automatically when the module is powered on. The pre-operational self-tests ensure that the module is not corrupted. The module transitions to the operational state only after the pre-operational selftests are passed successfully. The integrity of the shared library component of the module is verified by comparing an HMAC-SHA2-256 value calculated at run time with the corresponding HMAC value embedded in the fips.so file that was computed at build time. If the software integrity test fails, the module transitions to the error state (Section 10.3). The HMAC and SHA2-256 algorithms go through their respective CASTs before the software integrity test is performed. © 2025 Canonical Ltd. / atsec information security.

Page 50
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-ECB (A5747)Decrypt with 256- bit keyKATCASTModule becomes operational and services are available for useSymmetric operationTest runs at power-on before the integrity test
AES-ECB (A5748)Decrypt with 256- bit keyKATCASTModule becomes operational and services are available for useSymmetric operationTest runs at power-on before the integrity test
AES-ECB (A5749)Decrypt with 256- bit keyKATCASTModule becomes operational and services are available for useSymmetric operationTest runs at power-on before the integrity test
AES-ECB (A5751)Decrypt with 256- bit keyKATCASTModule becomes operational and services are available for useSymmetric operationTest runs at power-on before the integrity test
AES-ECB (A5752)Decrypt with 256- bit keyKATCASTModule becomes operational and services are available for useSymmetric operationTest runs at power-on before the integrity test
AES-ECB (A5753)Decrypt with 256- bit keyKATCASTModule becomes operational and services are available for useSymmetric operationTest runs at power-on before the integrity test
AES-ECB (A5754)Decrypt with 256- bit keyKATCASTModule becomes operational and services are available for useSymmetric operationTest runs at power-on before the integrity test
AES-ECB (A5755)Decrypt with 256- bit keyKATCASTModule becomes operational and services are available for useSymmetric operationTest runs at power-on before the integrity test
AES-ECB (A5774)Decrypt with 256- bit keyKATCASTModule becomes operational and services are available for useSymmetric operationTest runs at power-on before the integrity test
AES-ECB (A5775)Decrypt with 256- bit keyKATCASTModule becomes operational and services are available for useSymmetric operationTest runs at power-on before the integrity test
AES-ECB (A5776)Decrypt with 256- bit keyKATCASTModule becomes operational and services are available for useSymmetric operationTest runs at power-on before the integrity test
AES-ECB (A5927)Decrypt with 256- bit keyKATCASTModule becomes operational andSymmetric operationTest runs at power-on
10.2 Conditional Self-Tests

© 2025 Canonical Ltd. / atsec information security.

Page 51
Algorithm or TestTest PropertiesTest MethodTest TypeIndicator services are available for useDetailsConditions before the integrity test
AES-ECB (A5932)Decrypt with 256- bit keyKATCASTModule becomes operational and services are available for useSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A5759)Encrypt/Decrypt with 256-bit key, 96- bit (internal IV)KATCASTModule becomes operational and services are available for useSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A5760)Encrypt/Decrypt with 256-bit key, 96- bit (internal IV)KATCASTModule becomes operational and services are available for useSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A5761)Encrypt/Decrypt with 256-bit key, 96- bit (internal IV)KATCASTModule becomes operational and services are available for useSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A5762)Encrypt/Decrypt with 256-bit key, 96- bit (internal IV)KATCASTModule becomes operational and services are available for useSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A5763)Encrypt/Decrypt with 256-bit key, 96- bit (internal IV)KATCASTModule becomes operational and services are available for useSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A5764)Encrypt/Decrypt with 256-bit key, 96- bit (internal IV)KATCASTModule becomes operational and services are available for useSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A5765)Encrypt/Decrypt with 256-bit key, 96- bit (internal IV)KATCASTModule becomes operational and services are available for useSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A5766)Encrypt/Decrypt with 256-bit key, 96- bit (internal IV)KATCASTModule becomes operational and services are available for useSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A5767)Encrypt/Decrypt with 256-bit key, 96- bit (internal IV)KATCASTModule becomes operational and services are available for useSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A5777)Encrypt/Decrypt with 256-bit key, 96- bit (internal IV)KATCASTModule becomes operational and services are available for useSymmetric operationTest runs at power-on before the integrity test

© 2025 Canonical Ltd. / atsec information security.

Page 52
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-GCM (A5781)Encrypt/Decrypt with 256-bit key, 96- bit (internal IV)KATCASTModule becomes operational and services are available for useSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A5782)Encrypt/Decrypt with 256-bit key, 96- bit (internal IV)KATCASTModule becomes operational and services are available for useSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A5783)Encrypt/Decrypt with 256-bit key, 96- bit (internal IV)KATCASTModule becomes operational and services are available for useSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A5928)Encrypt/Decrypt with 256-bit key, 96- bit (internal IV)KATCASTModule becomes operational and services are available for useSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A5929)Encrypt/Decrypt with 256-bit key, 96- bit (internal IV)KATCASTModule becomes operational and services are available for useSymmetric operationTest runs at power-on before the integrity test
AES-GCM (A5930)Encrypt/Decrypt with 256-bit key, 96- bit (internal IV)KATCASTModule becomes operational and services are available for useSymmetric operationTest runs at power-on before the integrity test
SHA-1 (A5750)3-byte messageKATCASTModule becomes operational and services are available for useMessage digestTest runs at power-on before the integrity test
SHA-1 (A5768)3-byte messageKATCASTModule becomes operational and services are available for useMessage digestTest runs at power-on before the integrity test
SHA-1 (A5769)3-byte messageKATCASTModule becomes operational and services are available for useMessage digestTest runs at power-on before the integrity test
SHA-1 (A5770)3-byte messageKATCASTModule becomes operational and services are available for useMessage digestTest runs at power-on before the integrity test
SHA-1 (A5771)3-byte messageKATCASTModule becomes operational and services are available for useMessage digestTest runs at power-on before the integrity test
SHA-1 (A5778)3-byte messageKATCASTModule becomes operational and services are available for useMessage digestTest runs at power-on before the integrity test

© 2025 Canonical Ltd. / atsec information security.

Page 53
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
SHA-1 (A5931)3-byte messageKATCASTModule becomes operational and services are available for useMessage digestTest runs at power-on before the integrity test
SHA2-512 (A5750)3-byte messageKATCASTModule becomes operational and services are available for useMessage digestTest runs at power-on before the integrity test
SHA2-512 (A5768)3-byte messageKATCASTModule becomes operational and services are available for useMessage digestTest runs at power-on before the integrity test
SHA2-512 (A5769)3-byte messageKATCASTModule becomes operational and services are available for useMessage digestTest runs at power-on before the integrity test
SHA2-512 (A5770)3-byte messageKATCASTModule becomes operational and services are available for useMessage digestTest runs at power-on before the integrity test
SHA2-512 (A5771)3-byte messageKATCASTModule becomes operational and services are available for useMessage digestTest runs at power-on before the integrity test
SHA2-512 (A5778)3-byte messageKATCASTModule becomes operational and services are available for useMessage digestTest runs at power-on before the integrity test
SHA2-512 (A5931)3-byte messageKATCASTModule becomes operational and services are available for useMessage digestTest runs at power-on before the integrity test
SHA3-256 (A5756)4-byte messageKATCASTModule becomes operational and services are available for useMessage digestTest runs at power-on before the integrity test
SHA3-256 (A5780)4-byte messageKATCASTModule becomes operational and services are available for useMessage digestTest runs at power-on before the integrity test
SHA3-256 (A5933)4-byte messageKATCASTModule becomes operational and services are available for useMessage digestTest runs at power-on before the integrity test
HMAC-SHA2- 256 (A5750)SHA2-256KATCASTModule becomes operational and services are available for useMessage authenticationTest runs at power-on before the integrity test

© 2025 Canonical Ltd. / atsec information security.

Page 54
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
HMAC-SHA2- 256 (A5768)SHA2-256KATCASTModule becomes operational and services are available for useMessage authenticationTest runs at power-on before the integrity test
HMAC-SHA2- 256 (A5769)SHA2-256KATCASTModule becomes operational and services are available for useMessage authenticationTest runs at power-on before the integrity test
HMAC-SHA2- 256 (A5770)SHA2-256KATCASTModule becomes operational and services are available for useMessage authenticationTest runs at power-on before the integrity test
HMAC-SHA2- 256 (A5771)SHA2-256KATCASTModule becomes operational and services are available for useMessage authenticationTest runs at power-on before the integrity test
HMAC-SHA2- 256 (A5778)SHA2-256KATCASTModule becomes operational and services are available for useMessage authenticationTest runs at power-on before the integrity test
HMAC-SHA2- 256 (A5779)SHA2-256KATCASTModule becomes operational and services are available for useMessage authenticationTest runs at power-on before the integrity test
HMAC-SHA2- 256 (A5931)SHA2-256KATCASTModule becomes operational and services are available for useMessage authenticationTest runs at power-on before the integrity test
Counter DRBG (A5746)128 bit keys, DF, with PRKATCASTModule becomes operational and services are available for useCompliant with SP 800-90Ar1Test runs at power-on before the integrity test
HMAC DRBG (A5746)HMAC-SHA-1, with PRKATCASTModule becomes operational and services are available for useCompliant with SP 800-90Ar1Test runs at power-on before the integrity test
Hash DRBG (A5746)SHA2-256, with PRKATCASTModule becomes operational and services are available for useCompliant with SP 800-90Ar1Test runs at power-on before the integrity test
KAS-ECC-SSC Sp800-56Ar3 (A5750)P-256 curveKATCASTModule becomes operational and services are available for useShared secret computationTest runs at power-on before the integrity test
KAS-ECC-SSC Sp800-56Ar3 (A5768)P-256 curveKATCASTModule becomes operational and services are available for useShared secret computationTest runs at power-on before the integrity test

© 2025 Canonical Ltd. / atsec information security.

Page 55
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
KAS-ECC-SSC Sp800-56Ar3 (A5769)P-256 curveKATCASTModule becomes operational and services are available for useShared secret computationTest runs at power-on before the integrity test
KAS-ECC-SSC Sp800-56Ar3 (A5770)P-256 curveKATCASTModule becomes operational and services are available for useShared secret computationTest runs at power-on before the integrity test
KAS-ECC-SSC Sp800-56Ar3 (A5771)P-256 curveKATCASTModule becomes operational and services are available for useShared secret computationTest runs at power-on before the integrity test
KAS-ECC-SSC Sp800-56Ar3 (A5778)P-256 curveKATCASTModule becomes operational and services are available for useShared secret computationTest runs at power-on before the integrity test
KAS-ECC-SSC Sp800-56Ar3 (A5931)P-256 curveKATCASTModule becomes operational and services are available for useShared secret computationTest runs at power-on before the integrity test
KAS-FFC-SSC Sp800-56Ar3 (A5773)ffdhe2048KATCASTModule becomes operational and services are available for useShared secret computationTest runs at power-on before the integrity test
KDF SP800- 108 (A5772)HMAC-SHA2-256 with 128-bit key, 24- bit saltKATCASTModule becomes operational and services are available for useKey based key derivationTest runs at power-on before the integrity test
KDA OneStep SP800-56Cr2 (A5744)SHA2-224KATCASTModule becomes operational and services are available for useShared secret key derivationTest runs at power-on before the integrity test
KDA TwoStep SP800-56Cr2 (A5744)SHA2-256KATCASTModule becomes operational and services are available for useShared secret key derivationTest runs on power-on before the integrity test
KDF ANS 9.42 (A5750)SHA-1KATCASTModule becomes operational and services are available for useIndustry-based ANS X9.42 key derivationTest runs at power-on before the integrity test
KDF ANS 9.42 (A5756)SHA-1KATCASTModule becomes operational and services are available for useIndustry-based ANS X9.42 key derivationTest runs at power-on before the integrity test
KDF ANS 9.42 (A5768)SHA-1KATCASTModule becomes operational and services are available for useIndustry-based ANS X9.42 key derivationTest runs at power-on before the integrity test

© 2025 Canonical Ltd. / atsec information security.

Page 56
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
KDF ANS 9.42 (A5769)SHA-1KATCASTModule becomes operational and services are available for useIndustry-based ANS X9.42 key derivationTest runs at power-on before the integrity test
KDF ANS 9.42 (A5770)SHA-1KATCASTModule becomes operational and services are available for useIndustry-based ANS X9.42 key derivationTest runs at power-on before the integrity test
KDF ANS 9.42 (A5771)SHA-1KATCASTModule becomes operational and services are available for useIndustry-based ANS X9.42 key derivationTest runs at power-on before the integrity test
KDF ANS 9.42 (A5778)SHA-1KATCASTModule becomes operational and services are available for useIndustry-based ANS X9.42 key derivationTest runs at power-on before the integrity test
KDF ANS 9.42 (A5780)SHA-1KATCASTModule becomes operational and services are available for useIndustry-based ANS X9.42 key derivationTest runs at power-on before the integrity test
KDF ANS 9.42 (A5931)SHA-1KATCASTModule becomes operational and services are available for useIndustry-based ANS X9.42 key derivationTest runs at power-on before the integrity test
KDF ANS 9.42 (A5933)SHA-1KATCASTModule becomes operational and services are available for useIndustry-based ANS X9.42 key derivationTest runs at power-on before the integrity test
KDF ANS 9.63 (A5750)SHA2-256KATCASTModule becomes operational and services are available for useIndustry-based ANS X9.42 key derivationTest runs at power-on before the integrity test
KDF ANS 9.63 (A5768)SHA2-256KATCASTModule becomes operational and services are available for useIndustry-based ANS X9.42 key derivationTest runs at power-on before the integrity test
KDF ANS 9.63 (A5769)SHA2-256KATCASTModule becomes operational and services are available for useIndustry-based ANS X9.42 key derivationTest runs at power-on before the integrity test
KDF ANS 9.63 (A5770)SHA2-256KATCASTModule becomes operational and services are available for useIndustry-based ANS X9.42 key derivationTest runs at power-on before the integrity test
KDF ANS 9.63 (A5771)SHA2-256KATCASTModule becomes operational and services are available for useIndustry-based ANS X9.42 key derivationTest runs at power-on before the integrity test

© 2025 Canonical Ltd. / atsec information security.

Page 57
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
KDF ANS 9.63 (A5778)SHA2-256KATCASTModule becomes operational and services are available for useIndustry-based ANS X9.42 key derivationTest runs at power-on before the integrity test
KDF ANS 9.63 (A5931)SHA2-256KATCASTModule becomes operational and services are available for useIndustry-based ANS X9.42 key derivationTest runs at power-on before the integrity test
TLS v1.2 KDF RFC7627 (A5750)SHA2-256KATCASTModule becomes operational and services are available for useIndustry-based TLS v1.2 KDF key derivationTest runs at power-on before the integrity test
TLS v1.2 KDF RFC7627 (A5768)SHA2-256KATCASTModule becomes operational and services are available for useIndustry-based TLS v1.2 KDF key derivationTest runs at power-on before the integrity test
TLS v1.2 KDF RFC7627 (A5769)SHA2-256KATCASTModule becomes operational and services are available for useIndustry-based TLS v1.2 KDF key derivationTest runs at power-on before the integrity test
TLS v1.2 KDF RFC7627 (A5770)SHA2-256KATCASTModule becomes operational and services are available for useIndustry-based TLS v1.2 KDF key derivationTest runs at power-on before the integrity test
TLS v1.2 KDF RFC7627 (A5771)SHA2-256KATCASTModule becomes operational and services are available for useIndustry-based TLS v1.2 KDF key derivationTest runs at power-on before the integrity test
TLS v1.2 KDF RFC7627 (A5778)SHA2-256KATCASTModule becomes operational and services are available for useIndustry-based TLS v1.2 KDF key derivationTest runs at power-on before the integrity test
TLS v1.2 KDF RFC7627 (A5931)SHA2-256KATCASTModule becomes operational and services are available for useIndustry-based TLS v1.2 KDF key derivationTest runs at power-on before the integrity test
TLS v1.3 KDF (A5758)SHA2-256KATCASTModule becomes operational and services are available for useIndustry-based TLS v1.3 KDF key derivationTest runs at power-on before the integrity test
KDF SSH (A5751)SHA-1KATCASTModule becomes operational and services are available for useIndustry-based SSH KDF key derivationTest runs at power-on before the integrity test
KDF SSH (A5752)SHA-1KATCASTModule becomes operational and services are available for useIndustry-based SSH KDF key derivationTest runs at power-on before the integrity test

© 2025 Canonical Ltd. / atsec information security.

Page 58
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
KDF SSH (A5753)SHA-1KATCASTModule becomes operational and services are available for useIndustry-based SSH KDF key derivationTest runs at power-on before the integrity test
KDF SSH (A5754)SHA-1KATCASTModule becomes operational and services are available for useIndustry-based SSH KDF key derivationTest runs at power-on before the integrity test
KDF SSH (A5755)SHA-1KATCASTModule becomes operational and services are available for useIndustry-based SSH KDF key derivationTest runs at power-on before the integrity test
KDF SSH (A5932)SHA-1KATCASTModule becomes operational and services are available for useIndustry-based SSH KDF key derivationTest runs at power-on before the integrity test
PBKDF (A5750)SHA2-256 with 4096 iterations and 288- bit saltKATCASTModule becomes operational and services are available for usePassword-based key derivationTest runs at power-on before the integrity test
PBKDF (A5756)SHA2-256 with 4096 iterations and 288- bit saltKATCASTModule becomes operational and services are available for usePassword-based key derivationTest runs at power-on before the integrity test
PBKDF (A5768)SHA2-256 with 4096 iterations and 288- bit saltKATCASTModule becomes operational and services are available for usePassword-based key derivationTest runs at power-on before the integrity test
PBKDF (A5769)SHA2-256 with 4096 iterations and 288- bit saltKATCASTModule becomes operational and services are available for usePassword-based key derivationTest runs at power-on before the integrity test
PBKDF (A5770)SHA2-256 with 4096 iterations and 288- bit saltKATCASTModule becomes operational and services are available for usePassword-based key derivationTest runs at power-on before the integrity test
PBKDF (A5771)SHA2-256 with 4096 iterations and 288- bit saltKATCASTModule becomes operational and services are available for usePassword-based key derivationTest runs at power-on before the integrity test
PBKDF (A5778)SHA2-256 with 4096 iterations and 288- bit saltKATCASTModule becomes operational and services are available for usePassword-based key derivationTest runs at power-on before the integrity test
PBKDF (A5780)SHA2-256 with 4096 iterations and 288- bit saltKATCASTModule becomes operational and services are available for usePassword-based key derivationTest runs at power-on before the integrity test

© 2025 Canonical Ltd. / atsec information security.

Page 59
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
PBKDF (A5931)SHA2-256 with 4096 iterations and 288- bit saltKATCASTModule becomes operational and services are available for usePassword-based key derivationTest runs at power-on before the integrity test
PBKDF (A5933)SHA2-256 with 4096 iterations and 288- bit saltKATCASTModule becomes operational and services are available for usePassword-based key derivationTest runs at power-on before the integrity test
KDA HKDF SP800-56Cr2 (A5758)SHA2-256KATCASTModule becomes operational and services are available for useShared secret key derivationTest runs at power-on before the integrity test
ECDSA SigGen (FIPS186-5) (A5750)SHA2-256 with P- 224, B-233KATCASTModule becomes operational and services are available for useDigital signature generationTest runs at power-on before the integrity test
ECDSA SigGen (FIPS186-5) (A5756)SHA2-256 with P- 224, B-233KATCASTModule becomes operational and services are available for useDigital signature generationTest runs at power-on before the integrity test
ECDSA SigGen (FIPS186-5) (A5768)SHA2-256 with P- 224, B-233KATCASTModule becomes operational and services are available for useDigital signature generationTest runs at power-on before the integrity test
ECDSA SigGen (FIPS186-5) (A5769)SHA2-256 with P- 224, B-233KATCASTModule becomes operational and services are available for useDigital signature generationTest runs at power-on before the integrity test
ECDSA SigGen (FIPS186-5) (A5770)SHA2-256 with P- 224, B-233KATCASTModule becomes operational and services are available for useDigital signature generationTest runs at power-on before the integrity test
ECDSA SigGen (FIPS186-5) (A5771)SHA2-256 with P- 224, B-233KATCASTModule becomes operational and services are available for useDigital signature generationTest runs at power-on before the integrity test
ECDSA SigGen (FIPS186-5) (A5778)SHA2-256 with P- 224, B-233KATCASTModule becomes operational and services are available for useDigital signature generationTest runs at power-on before the integrity test
ECDSA SigGen (FIPS186-5) (A5780)SHA2-256 with P- 224, B-233KATCASTModule becomes operational and services are available for useDigital signature generationTest runs at power-on before the integrity test
ECDSA SigGen (FIPS186-5) (A5931)SHA2-256 with P- 224, B-233KATCASTModule becomes operational and services are available for useDigital signature generationTest runs at power-on before the integrity test

© 2025 Canonical Ltd. / atsec information security.

Page 60
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
ECDSA SigGen (FIPS186-5) (A5933)SHA2-256 with P- 224, B-233KATCASTModule becomes operational and services are available for useDigital signature generationTest runs at power-on before the integrity test
ECDSA SigVer (FIPS186-5) (A5750)SHA2-256 with P- 256, B-233KATCASTModule becomes operational and services are available for useDigital signature verificationTest runs at power-on before the integrity test
ECDSA SigVer (FIPS186-5) (A5756)SHA2-256 with P- 256, B-233KATCASTModule becomes operational and services are available for useDigital signature verificationTest runs at power-on before the integrity test
ECDSA SigVer (FIPS186-5) (A5768)SHA2-256 with P- 256, B-233KATCASTModule becomes operational and services are available for useDigital signature verificationTest runs at power-on before the integrity test
ECDSA SigVer (FIPS186-5) (A5769)SHA2-256 with P- 256, B-233KATCASTModule becomes operational and services are available for useDigital signature verificationTest runs at power-on before the integrity test
ECDSA SigVer (FIPS186-5) (A5770)SHA2-256 with P- 256, B-233KATCASTModule becomes operational and services are available for useDigital signature verificationTest runs at power-on before the integrity test
ECDSA SigVer (FIPS186-5) (A5771)SHA2-256 with P- 256, B-233KATCASTModule becomes operational and services are available for useDigital signature verificationTest runs at power-on before the integrity test
ECDSA SigVer (FIPS186-5) (A5778)SHA2-256 with P- 256, B-233KATCASTModule becomes operational and services are available for useDigital signature verificationTest runs at power-on before the integrity test
ECDSA SigVer (FIPS186-5) (A5780)SHA2-256 with P- 256, B-233KATCASTModule becomes operational and services are available for useDigital signature verificationTest runs at power-on before the integrity test
ECDSA SigVer (FIPS186-5) (A5931)SHA2-256 with P- 256, B-233KATCASTModule becomes operational and services are available for useDigital signature verificationTest runs at power-on before the integrity test
ECDSA SigVer (FIPS186-5) (A5933)SHA2-256 with P- 256, B-233KATCASTModule becomes operational and services are available for useDigital signature verificationTest runs at power-on before the integrity test
RSA SigGen (FIPS186-5) (A5750)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operational and services are available for useDigital signature generationTest runs at power-on before the integrity test

© 2025 Canonical Ltd. / atsec information security.

Page 61
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
RSA SigGen (FIPS186-5) (A5756)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operational and services are available for useDigital signature generationTest runs at power-on before the integrity test
RSA SigGen (FIPS186-5) (A5768)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operational and services are available for useDigital signature generationTest runs at power-on before the integrity test
RSA SigGen (FIPS186-5) (A5769)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operational and services are available for useDigital signature generationTest runs at power-on before the integrity test
RSA SigGen (FIPS186-5) (A5770)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operational and services are available for useDigital signature generationTest runs at power-on before the integrity test
RSA SigGen (FIPS186-5) (A5771)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operational and services are available for useDigital signature generationTest runs at power-on before the integrity test
RSA SigGen (FIPS186-5) (A5778)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operational and services are available for useDigital signature generationTest runs at power-on before the integrity test
RSA SigGen (FIPS186-5) (A5780)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operational and services are available for useDigital signature generationTest runs at power-on before the integrity test
RSA SigGen (FIPS186-5) (A5931)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operational and services are available for useDigital signature generationTest runs at power-on before the integrity test
RSA SigGen (FIPS186-5) (A5933)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operational and services are available for useDigital signature generationTest runs at power-on before the integrity test
RSA SigVer (FIPS186-5) (A5750)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operational and services are available for useDigital signature verificationTest runs at power-on before the integrity test
RSA SigVer (FIPS186-5) (A5756)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operational and services are available for useDigital signature verificationTest runs at power-on before the integrity test
RSA SigVer (FIPS186-5) (A5768)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operational and services are available for useDigital signature verificationTest runs at power-on before the integrity test

© 2025 Canonical Ltd. / atsec information security.

Page 62
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
RSA SigVer (FIPS186-5) (A5769)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operational and services are available for useDigital signature verificationTest runs at power-on before the integrity test
RSA SigVer (FIPS186-5) (A5770)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operational and services are available for useDigital signature verificationTest runs at power-on before the integrity test
RSA SigVer (FIPS186-5) (A5771)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operational and services are available for useDigital signature verificationTest runs at power-on before the integrity test
RSA SigVer (FIPS186-5) (A5778)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operational and services are available for useDigital signature verificationTest runs at power-on before the integrity test
RSA SigVer (FIPS186-5) (A5780)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operational and services are available for useDigital signature verificationTest runs at power-on before the integrity test
RSA SigVer (FIPS186-5) (A5931)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operational and services are available for useDigital signature verificationTest runs at power-on before the integrity test
RSA SigVer (FIPS186-5) (A5933)PKCS#1 v1.5 with 2048 bit key and SHA2-256KATCASTModule becomes operational and services are available for useDigital signature verificationTest runs at power-on before the integrity test
ECDSA KeyGen (FIPS186-5) (A5745)SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
ECDSA KeyGen (FIPS186-5) (A5750)SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
ECDSA KeyGen (FIPS186-5) (A5768)SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
ECDSA KeyGen (FIPS186-5) (A5769)SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
ECDSA KeyGen (FIPS186-5) (A5770)SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation

© 2025 Canonical Ltd. / atsec information security.

Page 63
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
ECDSA KeyGen (FIPS186-5) (A5771)SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
ECDSA KeyGen (FIPS186-5) (A5778)SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
ECDSA KeyGen (FIPS186-5) (A5931)SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
RSA KeyGen (FIPS186-5) (A5750)PKCS#1 v1.5 with SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
RSA KeyGen (FIPS186-5) (A5768)PKCS#1 v1.5 with SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
RSA KeyGen (FIPS186-5) (A5769)PKCS#1 v1.5 with SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
RSA KeyGen (FIPS186-5) (A5770)PKCS#1 v1.5 with SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
RSA KeyGen (FIPS186-5) (A5771)PKCS#1 v1.5 with SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
RSA KeyGen (FIPS186-5) (A5778)PKCS#1 v1.5 with SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
RSA KeyGen (FIPS186-5) (A5931)PKCS#1 v1.5 with SHA2-256PCTPCTSuccessful key pair generationSignature generation & verificationKey pair generation
Safe Primes Key Generation (A5773)Section 5.6.2.1.4 of SP800-56Arev3PCTPCTSuccessful key pair generationSP 800-56ARev3, 5.6.2.1.4Key pair generation

Table 21: Conditional Self-Tests The module performs self-tests on all approved cryptographic algorithms as part of the approved services supported in the approved mode of operation, using the tests shown in the table above. The CASTs can be performed on demand by unloading and re-initializing the module. Data output through the data output interface is inhibited during the self-tests. If any of these tests fails, the module transitions to the error state. © 2025 Canonical Ltd. / atsec information security.

Page 64
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2-256 (A5750)Message AuthenticationSW/FW IntegrityOn demandManually
HMAC-SHA2-256 (A5768)Message AuthenticationSW/FW IntegrityOn demandManually
HMAC-SHA2-256 (A5769)Message AuthenticationSW/FW IntegrityOn demandManually
HMAC-SHA2-256 (A5770)Message AuthenticationSW/FW IntegrityOn demandManually
HMAC-SHA2-256 (A5771)Message AuthenticationSW/FW IntegrityOn demandManually
HMAC-SHA2-256 (A5778)Message AuthenticationSW/FW IntegrityOn demandManually
HMAC-SHA2-256 (A5779)Message AuthenticationSW/FW IntegrityOn demandManually
HMAC-SHA2-256 (A5931)Message AuthenticationSW/FW IntegrityOn demandManually
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-ECB (A5747)KATCASTOn DemandManually
AES-ECB (A5748)KATCASTOn DemandManually
AES-ECB (A5749)KATCASTOn DemandManually
AES-ECB (A5751)KATCASTOn DemandManually
AES-ECB (A5752)KATCASTOn DemandManually
AES-ECB (A5753)KATCASTOn DemandManually
AES-ECB (A5754)KATCASTOn DemandManually
AES-ECB (A5755)KATCASTOn DemandManually
AES-ECB (A5774)KATCASTOn DemandManually
AES-ECB (A5775)KATCASTOn DemandManually
AES-ECB (A5776)KATCASTOn DemandManually
AES-ECB (A5927)KATCASTOn DemandManually
AES-ECB (A5932)KATCASTOn DemandManually
AES-GCM (A5759)KATCASTOn DemandManually
AES-GCM (A5760)KATCASTOn DemandManually
AES-GCM (A5761)KATCASTOn DemandManually
AES-GCM (A5762)KATCASTOn DemandManually
AES-GCM (A5763)KATCASTOn DemandManually
AES-GCM (A5764)KATCASTOn DemandManually
AES-GCM (A5765)KATCASTOn DemandManually
AES-GCM (A5766)KATCASTOn DemandManually
AES-GCM (A5767)KATCASTOn DemandManually
AES-GCM (A5777)KATCASTOn DemandManually
10.3 Periodic Self-Test Information

Table 22: Pre-Operational Periodic Information © 2025 Canonical Ltd. / atsec information security.

Page 65
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-GCM (A5781)KATCASTOn DemandManually
AES-GCM (A5782)KATCASTOn DemandManually
AES-GCM (A5783)KATCASTOn DemandManually
AES-GCM (A5928)KATCASTOn DemandManually
AES-GCM (A5929)KATCASTOn DemandManually
AES-GCM (A5930)KATCASTOn DemandManually
SHA-1 (A5750)KATCASTOn DemandManually
SHA-1 (A5768)KATCASTOn DemandManually
SHA-1 (A5769)KATCASTOn DemandManually
SHA-1 (A5770)KATCASTOn DemandManually
SHA-1 (A5771)KATCASTOn DemandManually
SHA-1 (A5778)KATCASTOn DemandManually
SHA-1 (A5931)KATCASTOn DemandManually
SHA2-512 (A5750)KATCASTOn DemandManually
SHA2-512 (A5768)KATCASTOn DemandManually
SHA2-512 (A5769)KATCASTOn DemandManually
SHA2-512 (A5770)KATCASTOn DemandManually
SHA2-512 (A5771)KATCASTOn DemandManually
SHA2-512 (A5778)KATCASTOn DemandManually
SHA2-512 (A5931)KATCASTOn DemandManually
SHA3-256 (A5756)KATCASTOn DemandManually
SHA3-256 (A5780)KATCASTOn DemandManually
SHA3-256 (A5933)KATCASTOn DemandManually
HMAC-SHA2-256 (A5750)KATCASTOn DemandManually
HMAC-SHA2-256 (A5768)KATCASTOn DemandManually
HMAC-SHA2-256 (A5769)KATCASTOn DemandManually
HMAC-SHA2-256 (A5770)KATCASTOn DemandManually
HMAC-SHA2-256 (A5771)KATCASTOn DemandManually
HMAC-SHA2-256 (A5778)KATCASTOn DemandManually
HMAC-SHA2-256 (A5779)KATCASTOn DemandManually
HMAC-SHA2-256 (A5931)KATCASTOn DemandManually
Counter DRBG (A5746)KATCASTOn DemandManually
HMAC DRBG (A5746)KATCASTOn DemandManually

© 2025 Canonical Ltd. / atsec information security.

Page 66
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
Hash DRBG (A5746)KATCASTOn DemandManually
KAS-ECC-SSC Sp800-56Ar3 (A5750)KATCASTOn DemandManually
KAS-ECC-SSC Sp800-56Ar3 (A5768)KATCASTOn DemandManually
KAS-ECC-SSC Sp800-56Ar3 (A5769)KATCASTOn DemandManually
KAS-ECC-SSC Sp800-56Ar3 (A5770)KATCASTOn DemandManually
KAS-ECC-SSC Sp800-56Ar3 (A5771)KATCASTOn DemandManually
KAS-ECC-SSC Sp800-56Ar3 (A5778)KATCASTOn DemandManually
KAS-ECC-SSC Sp800-56Ar3 (A5931)KATCASTOn DemandManually
KAS-FFC-SSC Sp800-56Ar3 (A5773)KATCASTOn DemandManually
KDF SP800-108 (A5772)KATCASTOn DemandManually
KDA OneStep SP800-56Cr2 (A5744)KATCASTOn DemandManually
KDA TwoStep SP800-56Cr2 (A5744)KATCASTOn DemandManually
KDF ANS 9.42 (A5750)KATCASTOn DemandManually
KDF ANS 9.42 (A5756)KATCASTOn DemandManually
KDF ANS 9.42 (A5768)KATCASTOn DemandManually
KDF ANS 9.42 (A5769)KATCASTOn DemandManually
KDF ANS 9.42 (A5770)KATCASTOn DemandManually
KDF ANS 9.42 (A5771)KATCASTOn DemandManually
KDF ANS 9.42 (A5778)KATCASTOn DemandManually

© 2025 Canonical Ltd. / atsec information security.

Page 67
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
KDF ANS 9.42 (A5780)KATCASTOn DemandManually
KDF ANS 9.42 (A5931)KATCASTOn DemandManually
KDF ANS 9.42 (A5933)KATCASTOn DemandManually
KDF ANS 9.63 (A5750)KATCASTOn DemandManually
KDF ANS 9.63 (A5768)KATCASTOn DemandManually
KDF ANS 9.63 (A5769)KATCASTOn DemandManually
KDF ANS 9.63 (A5770)KATCASTOn DemandManually
KDF ANS 9.63 (A5771)KATCASTOn DemandManually
KDF ANS 9.63 (A5778)KATCASTOn DemandManually
KDF ANS 9.63 (A5931)KATCASTOn DemandManually
TLS v1.2 KDF RFC7627 (A5750)KATCASTOn DemandManually
TLS v1.2 KDF RFC7627 (A5768)KATCASTOn DemandManually
TLS v1.2 KDF RFC7627 (A5769)KATCASTOn DemandManually
TLS v1.2 KDF RFC7627 (A5770)KATCASTOn DemandManually
TLS v1.2 KDF RFC7627 (A5771)KATCASTOn DemandManually
TLS v1.2 KDF RFC7627 (A5778)KATCASTOn DemandManually
TLS v1.2 KDF RFC7627 (A5931)KATCASTOn DemandManually
TLS v1.3 KDF (A5758)KATCASTOn DemandManually
KDF SSH (A5751)KATCASTOn DemandManually
KDF SSH (A5752)KATCASTOn DemandManually
KDF SSH (A5753)KATCASTOn DemandManually
KDF SSH (A5754)KATCASTOn DemandManually
KDF SSH (A5755)KATCASTOn DemandManually
KDF SSH (A5932)KATCASTOn DemandManually
PBKDF (A5750)KATCASTOn DemandManually
PBKDF (A5756)KATCASTOn DemandManually
PBKDF (A5768)KATCASTOn DemandManually

© 2025 Canonical Ltd. / atsec information security.

Page 68
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
PBKDF (A5769)KATCASTOn DemandManually
PBKDF (A5770)KATCASTOn DemandManually
PBKDF (A5771)KATCASTOn DemandManually
PBKDF (A5778)KATCASTOn DemandManually
PBKDF (A5780)KATCASTOn DemandManually
PBKDF (A5931)KATCASTOn DemandManually
PBKDF (A5933)KATCASTOn DemandManually
KDA HKDF SP800- 56Cr2 (A5758)KATCASTOn DemandManually
ECDSA SigGen (FIPS186-5) (A5750)KATCASTOn DemandManually
ECDSA SigGen (FIPS186-5) (A5756)KATCASTOn DemandManually
ECDSA SigGen (FIPS186-5) (A5768)KATCASTOn DemandManually
ECDSA SigGen (FIPS186-5) (A5769)KATCASTOn DemandManually
ECDSA SigGen (FIPS186-5) (A5770)KATCASTOn DemandManually
ECDSA SigGen (FIPS186-5) (A5771)KATCASTOn DemandManually
ECDSA SigGen (FIPS186-5) (A5778)KATCASTOn DemandManually
ECDSA SigGen (FIPS186-5) (A5780)KATCASTOn DemandManually
ECDSA SigGen (FIPS186-5) (A5931)KATCASTOn DemandManually
ECDSA SigGen (FIPS186-5) (A5933)KATCASTOn DemandManually
ECDSA SigVer (FIPS186-5) (A5750)KATCASTOn DemandManually
ECDSA SigVer (FIPS186-5) (A5756)KATCASTOn DemandManually
ECDSA SigVer (FIPS186-5) (A5768)KATCASTOn DemandManually
ECDSA SigVer (FIPS186-5) (A5769)KATCASTOn DemandManually
ECDSA SigVer (FIPS186-5) (A5770)KATCASTOn DemandManually
ECDSA SigVer (FIPS186-5) (A5771)KATCASTOn DemandManually
ECDSA SigVer (FIPS186-5) (A5778)KATCASTOn DemandManually
ECDSA SigVer (FIPS186-5) (A5780)KATCASTOn DemandManually

© 2025 Canonical Ltd. / atsec information security.

Page 69
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
ECDSA SigVer (FIPS186-5) (A5931)KATCASTOn DemandManually
ECDSA SigVer (FIPS186-5) (A5933)KATCASTOn DemandManually
RSA SigGen (FIPS186-5) (A5750)KATCASTOn DemandManually
RSA SigGen (FIPS186-5) (A5756)KATCASTOn DemandManually
RSA SigGen (FIPS186-5) (A5768)KATCASTOn DemandManually
RSA SigGen (FIPS186-5) (A5769)KATCASTOn DemandManually
RSA SigGen (FIPS186-5) (A5770)KATCASTOn DemandManually
RSA SigGen (FIPS186-5) (A5771)KATCASTOn DemandManually
RSA SigGen (FIPS186-5) (A5778)KATCASTOn DemandManually
RSA SigGen (FIPS186-5) (A5780)KATCASTOn DemandManually
RSA SigGen (FIPS186-5) (A5931)KATCASTOn DemandManually
RSA SigGen (FIPS186-5) (A5933)KATCASTOn DemandManually
RSA SigVer (FIPS186-5) (A5750)KATCASTOn DemandManually
RSA SigVer (FIPS186-5) (A5756)KATCASTOn DemandManually
RSA SigVer (FIPS186-5) (A5768)KATCASTOn DemandManually
RSA SigVer (FIPS186-5) (A5769)KATCASTOn DemandManually
RSA SigVer (FIPS186-5) (A5770)KATCASTOn DemandManually
RSA SigVer (FIPS186-5) (A5771)KATCASTOn DemandManually
RSA SigVer (FIPS186-5) (A5778)KATCASTOn DemandManually
RSA SigVer (FIPS186-5) (A5780)KATCASTOn DemandManually
RSA SigVer (FIPS186-5) (A5931)KATCASTOn DemandManually
RSA SigVer (FIPS186-5) (A5933)KATCASTOn DemandManually
ECDSA KeyGen (FIPS186-5) (A5745)PCTPCTOn DemandManually

© 2025 Canonical Ltd. / atsec information security.

Page 70
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
ECDSA KeyGen (FIPS186-5) (A5750)PCTPCTOn DemandManually
ECDSA KeyGen (FIPS186-5) (A5768)PCTPCTOn DemandManually
ECDSA KeyGen (FIPS186-5) (A5769)PCTPCTOn DemandManually
ECDSA KeyGen (FIPS186-5) (A5770)PCTPCTOn DemandManually
ECDSA KeyGen (FIPS186-5) (A5771)PCTPCTOn DemandManually
ECDSA KeyGen (FIPS186-5) (A5778)PCTPCTOn DemandManually
ECDSA KeyGen (FIPS186-5) (A5931)PCTPCTOn DemandManually
RSA KeyGen (FIPS186-5) (A5750)PCTPCTOn DemandManually
RSA KeyGen (FIPS186-5) (A5768)PCTPCTOn DemandManually
RSA KeyGen (FIPS186-5) (A5769)PCTPCTOn DemandManually
RSA KeyGen (FIPS186-5) (A5770)PCTPCTOn DemandManually
RSA KeyGen (FIPS186-5) (A5771)PCTPCTOn DemandManually
RSA KeyGen (FIPS186-5) (A5778)PCTPCTOn DemandManually
RSA KeyGen (FIPS186-5) (A5931)PCTPCTOn DemandManually
Safe Primes Key Generation (A5773)PCTPCTOn DemandManually
NameDescriptionConditionsRecovery MethodIndicator
ErrorThe module immediately stops functioningSoftware integrity test failure CAST failure PCT failureRe-initialization of the moduleModule will not load; Module is aborted for PCT failure

Table 23: Conditional Periodic Information The module does not implement periodic self-tests.

10.4 Error States

Table 24: Error States If the module fails any of the self-tests, the module enters the error state. In the error state, the module immediately stops functioning and ends the application process. Consequently, the data output interface is inhibited, and the module accepts no more inputs or requests (as the module is no longer running). © 2025 Canonical Ltd. / atsec information security.

Page 71

Regarding the PCT failure, an OSSL_PROV_PARAM_STATUS parameter can be queried from the FIPS provider to check the status of the cryptographic module. The table above lists the error states and the status indicator values that explain the error that has occurred.

10.5 Operator Initiation of Self-Tests

The software integrity tests and cryptographic algorithm self-tests can be invoked on demand by resetting the module or by invoking the OSSL_PROVIDER_self_test method. The pair-wise consistency tests can be invoked on demand by requesting the key pair generation service.

10.6 Additional Information

Not applicable. © 2025 Canonical Ltd. / atsec information security.

Page 72
11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

The binaries of the FIPS validated module are contained in the following Ubuntu packages for delivery:

openssl-fips-module- 3.0.13-0ubuntu3+Fips1_amd64.deb for X86_64
openssl-fips-module- 3.0.13-0ubuntu3+Fips1_arm64.deb for ARM64
openssl-fips-module- 3.0.13-0ubuntu3+Fips1_s390x.deb for s390x

Once the operating environment is configured following the instructions provided, the Crypto Officer can install the Ubuntu packages containing the module listed below - Ubuntu packages using the Advanced Package Tool (APT) with the following command: $ sudo apt-get install openssl-fips-module-3 All the Ubuntu packages are associated with hashes for integrity check. The integrity of the Ubuntu package is automatically verified by the packing tool during the installation of the module. The Crypto Officer shall not install the package if the integrity fails. After the openssl-fips-module-3 package is installed, the Crypto Officer must execute the openssl list -providers command. The Crypto Officer must ensure that the FIPS provider is listed in the output as follows: fips name: Ubuntu 24.04 OpenSSL Cryptographic Module version: 3.0.13-0ubuntu3+Fips1 status: active The cryptographic boundary consists only of the FIPS provider as listed. If any other OpenSSL or third-party provider is invoked, the user is not interacting with the module specified in this Security Policy. After, the module needs to be set to run in the FIPS validated configuration. This can be enabled automatically via the Ubuntu Advantage tool after attaching your subscription. (1) To install the tool type the following commands: $ sudo apt update $ sudo apt install ubuntu-advantage-tools (2) To activate the Ubuntu Pro subscription run: $ sudo pro attach <your_pro_token> (3) To enable Approved mode run: © 2025 Canonical Ltd. / atsec information security.

Page 73

$ sudo pro enable fips (4) To verify that Approved mode is enabled run: $ sudo pro status The pro client will install the necessary packages for the Approved mode, including the kernel and the bootloader. After this step you MUST reboot to put the system into Approved mode. The reboot will boot into FIPS supported kernel and create the /proc/sys/crypto/fips_enabled entry which tells the FIPS certified modules to run in Approved mode. If you do not reboot after installing and configuring the bootloader, Approved mode is not yet enabled. To verify that FIPS is enabled after the reboot check the /proc/sys/crypto/fips_enabled file and ensure it is set to 1. If it is set to 0, the FIPS modules will not run in Approved mode. If the file is missing, the FIPS kernel is not installed, you can verify that FIPS has been properly enabled with the pro status command.

11.2 Administrator Guidance

The Approved and non-Approved modes of operation are specified in section 2.4. The administrative functions are specified in the Approved Services table. All the logical interfaces are specified in section 3.1. The requirements and restrictions that shall be considered when operating the module in approved mode are specified in section 2.7 and section 6. The installation, initialization, and startup procedures specified in section 11.1 shall be followed.

11.3 Non-Administrator Guidance

There is no non-administrator guidance.

11.4 Design and Rules
11.5 Maintenance Requirements
11.6 End of Life

As the module does not persistently store SSPs, secure sanitization of the module consists of unloading the module. This will zeroize all SSPs in volatile memory. Then, if desired, the Ubuntu packages can be uninstalled from the Ubuntu 24.04 system. © 2025 Canonical Ltd. / atsec information security.

Page 74
11.7 Additional Information

Not applicable. © 2025 Canonical Ltd. / atsec information security.

Page 75
12 Mitigation of Other Attacks
12.1 Attack List

Certain cryptographic subroutines and algorithms are vulnerable to timing analysis. The module mitigates this vulnerability by using constant-time implementations. This includes, but is not limited to:

Big number operations: computing GCDs, modular inversion, multiplication, division, and modular exponentiation (using Montgomery multiplication).
Elliptic curve point arithmetic: addition and multiplication (using the Montgomery ladder).
Vector-based AES implementations.
12.2 Mitigation Effectiveness

RSA, ECDSA, ECDH, and DH employ blinding techniques to further impede timing and power analysis.

12.3 Guidance and Constraints

No configuration is needed to enable the aforementioned countermeasures.

12.4 Additional Information

Not applicable. © 2025 Canonical Ltd. / atsec information security.

Page 76

Appendix A. Glossary and Abbreviations

AESAdvanced Encryption Standard
AES-NIAdvanced Encryption Standard New Instructions
APIApplication Programming Interface
CASTCryptographic Algorithm Self-Test
CAVPCryptographic Algorithm Validation Program
CBCCipher Block Chaining
CCMCounter with Cipher Block Chaining-Message Authentication Code
CFBCipher Feedback
CKGCryptographic Key Generation
CMACCipher-based Message Authentication Code
CMVPCryptographic Module Validation Program
CPACFCP Assist for Cryptographic Functions
CSPCritical Security Parameter
CTRCounter
CTSCiphertext Stealing
DHDiffie-Hellman
DRBGDeterministic Random Bit Generator
ECBElectronic Code Book
ECCElliptic Curve Cryptography
ECDHElliptic Curve Diffie-Hellman
ECDSAElliptic Curve Digital Signature Algorithm
EVPEnvelope
FFCFinite Field Cryptography
FIPSFederal Information Processing Standards
GCMGalois Counter Mode
GMACGalois Counter Mode Message Authentication Code
HKDFHMAC-based Key Derivation Function
HMACKeyed-Hash Message Authentication Code
IKEInternet Key Exchange © 2025 Canonical Ltd. / atsec information security.
Page 77
KASKey Agreement Scheme
KATKnown Answer Test
KBKDFKey-based Key Derivation Function
KMACKECCAK Message Authentication Code
KWKey Wrap
KWPKey Wrap with Padding
MACMessage Authentication Code
NISTNational Institute of Science and Technology
OAEPOptimal Asymmetric Encryption Padding
OFBOutput Feedback
PAAProcessor Algorithm Acceleration
PCTPair-wise Consistency Test
PBKDF2Password-based Key Derivation Function v2
PKCSPublic-Key Cryptography Standards
PSSProbabilistic Signature Scheme
RSADPRSA Decryption Primitive
RSAEPRSA Encryption Primitive
RSARivest, Shamir, Addleman
SHASecure Hash Algorithm
SSCShared Secret Computation
SSHSecure Shell
SSPSensitive Security Parameter
TLSTransport Layer Security
XOFExtendable Output Function
XTSXEX-based Tweaked-codebook mode with cipher text Stealing © 2025 Canonical Ltd. / atsec information security.
Page 78
ANS X9.42-2001Public Key Cryptography for the Financial Services Industry: Agreement of Symmetric Keys Using Discrete Logarithm Cryptography 2001 https://webstore.ansi.org/standards/ascx9/ansix9422001
ANS X9.63-2001Public Key Cryptography for the Financial Services Industry, Key Agreement and Key Transport Using Elliptic Curve Cryptography 2001 https://webstore.ansi.org/standards/ascx9/ansix9632001
FIPS 140-3FIPS PUB 140-3 - Security Requirements For Cryptographic Modules March 2019 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-3.pdf
FIPS 140-3 IGImplementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program https://csrc.nist.gov/Projects/cryptographic-module-validation-program/fips- 140-3-ig-announcements
FIPS 180-4Secure Hash Standard (SHS) March 2012 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf
FIPS 186-5Digital Signature Standard (DSS) February 2023 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-5.pdf
FIPS 197Advanced Encryption Standard November 2001 https://csrc.nist.gov/publications/fips/fips197/fips-197.pdf
FIPS 198-1The Keyed Hash Message Authentication Code (HMAC) July 2008 https://csrc.nist.gov/publications/fips/fips198-1/FIPS-198-1_final.pdf
FIPS 202SHA-3 Standard: Permutation-Based Hash and Extendable-Output Functions August 2015 https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.202.pdf
PKCS#1Public Key Cryptography Standards (PKCS) #1: RSA Cryptography Specifications Version 2.1 February 2003 http://www.ietf.org/rfc/rfc3447.txt
RFC 3526More Modular Exponential (MODP) Diffie-Hellman groups for Internet Key Exchange (IKE) May 2003 https://www.ietf.org/rfc/rfc3526.txt
RFC 5288AES Galois Counter Mode (GCM) Cipher Suites for TLS August 2008 https://www.ietf.org/rfc/rfc5288.txt
RFC 7919Negotiated Finite Field Diffie-Hellman Ephemeral Parameters for Transport Layer Security (TLS) August 2016 https://www.ietf.org/rfc/rfc7919.txt © 2025 Canonical Ltd. / atsec information security.
Page 79
RFC 8446The Transport Layer Security (TLS) Protocol Version 1.3 August 2018 https://www.ietf.org/rfc/rfc8446.txt
SP 800-38ARecommendation for Block Cipher Modes of Operation Methods and Techniques December 2001 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38a- add.pdf
SP 800-38ARecommendation for Block Cipher Modes of Operation: Three Variants of
AddendumCiphertext Stealing for CBC Mode October 2010 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38a- add.pdf
SP 800-38BRecommendation for Block Cipher Modes of Operation: The CMAC Mode for Authentication May 2005 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38B.pdf
SP 800-38CRecommendation for Block Cipher Modes of Operation: the CCM Mode for Authentication and Confidentiality May 2004 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38c.pdf
SP 800-38DRecommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC November 2007 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38d.pdf
SP 800-38ERecommendation for Block Cipher Modes of Operation: The XTS AES Mode for Confidentiality on Storage Devices https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38e.pdf
SP 800-38FRecommendation for Block Cipher Modes of Operation: Methods for Key Wrapping December 2012 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38F.pdf
SP 800-52r2Guidelines for the Selection, Configuration, and Use of Transport Layer Security (TLS) Implementations August 2019 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-52r2.pdf
SP 800-56Ar3Recommendation for Pair-Wise Key Establishment Schemes Using Discrete Logarithm Cryptography April 2018 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Ar3.pdf
SP 800-56Cr1Recommendation for Key-Derivation Methods in Key-Establishment Schemes August 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Cr1.pdf
SP 800-56Cr2Recommendation for Key-Derivation Methods in Key-Establishment Schemes August 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-56Cr2.pdf © 2025 Canonical Ltd. / atsec information security.
Page 80
SP 800-90Ar1Recommendation for Random Number Generation Using Deterministic Random Bit Generators June 2015 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90Ar1.pdf
SP 800-90BRecommendation for the Entropy Sources Used for Random Bit Generation January 2018 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-90B.pdf
SP 800-108r1NIST Special Publication 800-108 - Recommendation for Key Derivation Using Pseudorandom Functions August 2022 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-108r1.pdf
SP 800-132Recommendation for Password-Based Key Derivation - Part 1: Storage Applications December 2010 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-132.pdf
SP 800-133r2Recommendation for Cryptographic Key Generation June 2020 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-133r2.pdf
SP 800-135r1Recommendation for Existing Application-Specific Key Derivation Functions December 2011 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800- 135r1.pdf
SP 800-140Br1CMVP Security Policy Requirements November 2023 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-140Br1.pdf © 2025 Canonical Ltd. / atsec information security.