All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Rocky Linux 9 OpenSSL FIPS Provider

Certificate#5116StandardFIPS 140-3Level1TypeSoftwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorCtrl IQ, Inc.
Medium review priority  ·  no TCB surface named  ·  OpenSSL upstream has published 38 CVEs since this module's initial validation  ·  last validated 6 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date1/5/2031
CaveatWhen operated in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.
VendorCtrl IQ, Inc.

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Rocky Linux 9 OpenSSL FIPS Provider
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>update<br/>Recovery</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Status Output</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>SSH<br/>HTTPS</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Rocky Linux 9 OpenSSL FIPS Provider
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>update<br/>Recovery</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Status Output</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>SSH<br/>HTTPS</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>kernel</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Ctrl IQ, Inc. Rocky Linux 9 OpenSSL FIPS Provider Prepared by: atsec information security corporation

4516 Seton Center Pkwy, Suite 250

Austin, TX 78759 Document version: 1.1 www.atsec.com Last update: 2026-01-05

Page 2
Table of Contents
#SectionPage
Page 3

© 2025 Ctrl IQ, Inc., atsec information security.

Page 4
List of Tables
ItemPage
Table 1: Security Levels5
Table 2: Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets)7
Table 3: Tested Operational Environments - Software, Firmware, Hybrid7
Table 4: Modes List and Description8
Table 5: Approved Algorithms10
Table 6: Vendor-Affirmed Algorithms10
Table 7: Non-Approved, Not Allowed Algorithms11
Table 8: Security Function Implementations16
Table 9: Entropy Certificates19
Table 10: Entropy Sources19
Table 11: Ports and Interfaces21
Table 12: Roles22
Table 13: Approved Services32
Table 14: Non-Approved Services33
Table 15: Storage Areas38
Table 16: SSP Input-Output Methods38
Table 17: SSP Zeroization Methods39
Table 18: SSP Table 143
Table 19: SSP Table 246
Table 20: Pre-Operational Self-Tests47
Table 21: Conditional Self-Tests49
Table 22: Pre-Operational Periodic Information49
Table 23: Conditional Periodic Information50
Table 24: Error States50
Figure 1: Block Diagram6
Page 5
SectionTitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication1
5Software/Firmware security1
6Operational environment1
7Physical securityN/A
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacks1
Overall Level1
1.1 Overview

This document is the non-proprietary FIPS 140-3 Security Policy for version Rocky9.20250210 of the Rocky Linux 9 OpenSSL FIPS Provider. It contains the security rules under which the module must operate and describes how this module meets the requirements as specified in FIPS PUB 140-3 (Federal Information Processing Standards Publication 140-3) for an overall Security Level 1 module. including this notice.

1.2 Security Levels

Table 1: Security Levels © 2025 Ctrl IQ, Inc., atsec information security.

Page 6
2 Cryptographic Module Specification
2.1 Description

Purpose and Use: The Rocky Linux 9 OpenSSL FIPS Provider (hereafter referred to as “the module”) is defined as a software module in a multi-chip standalone embodiment. It provides a C language application program interface (API) for use by other applications that require cryptographic functionality. The module consists of one software component, the “FIPS provider”, which implements the FIPS requirements and the cryptographic functionality provided to the operator. Module Type: Software Module Embodiment: MultiChipStand Cryptographic Boundary: The cryptographic boundary of the module is defined as the shared library implementing the FIPS provider (fips.so). Tested Operational Environment’s Physical Perimeter (TOEPP): The TOEPP of the module is defined as the general-purpose computer on which the module is installed. The cryptographic boundary (orange) and TOEPP (purple) are schematically represented in Figure 1. Green lines indicate the flow of data between the cryptographic module and its operator application. Components in white are only included in the diagram for informational purposes and are not part of the module’s validation. Figure 1: Block Diagram © 2025 Ctrl IQ, Inc., atsec information security.

Page 7
Package or File NameSoftware/ Firmware VersionFeaturesIntegrity Test
fips.soRocky9.20250210N/AHMAC SHA-256
Operating SystemHardware PlatformProcessorsPAA/PAIHypervisor or Host OSVersion(s)
Rocky Linux 9SuperMicro SuperServer 5039MSIntel Kaby Lake Xeon E3-1270 v6YesN/ARocky9.20250210
Rocky Linux 9SuperMicro SuperServer 5039MSIntel Kaby Lake Xeon E3-1270 v6NoN/ARocky9.20250210
Mode NameDescriptionTypeStatus Indicator
Approve dAutomaticall y entered whenever an approved service is requested.Approve dEquivalent to the indicator of the requested service: Message digest 'EVP_DigestFinal_ex returns 1'; XOF 'EVP_DigestFinalXOF returns 1'; Encryption 'EVP_EncryptFinal_ex returns 1'; Decryption 'EVP_DecryptFinal_ex returns 1'; Authenticated encryption 'AES-GCM: EVP_CIPHER_ROCKY_FIPS_INDICATOR_APPROVED; Others: EVP_EncryptFinal_ex returns 1'; Authenticated decryption 'EVP_DecryptFinal_ex returns 1'; MAC 'HMAC: OSSL_MAC_PARAM_ROCKY_FIPS_INDICATOR_APPROVE D; Others: EVP_MAC_final returns 1'; KDF 'EVP_KDF_ROCKY_FIPS_INDICATOR_APPROVED'; Random number generation 'EVP_RAND_generate returns 1'; Shared secret computation 'EVP_PKEY_ROCKY_FIPS_INDICATOR_APPROVED'; Signature generation/verification
2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification

2.3 Excluded Components

There are no components within the cryptographic boundary excluded from the FIPS 140-3 requirements.

2.4 Modes of Operation

Modes List and Description: © 2025 Ctrl IQ, Inc., atsec information security.

Page 8
Mode NameDescriptionTypeStatus Indicator 'OSSL_RL_FIPSINDICATOR_APPROVED and EVP_PKEY_ROCKY_FIPS_INDICATOR_APPROVED'; Asymmetric Encryption/Decryption 'EVP_PKEY_ROCKY_FIPS_INDICATOR_APPROVED'; Key pair generation 'EVP_PKEY_generate returns 1'; Key pair verification 'EVP_PKEY_public_check or EVP_PKEY_private_check or EVP_PKEY_check returns 1'
Non- Approve dAutomaticall y entered whenever a non- approved service is requested.Non- Approve dThe status indicator depends on the invoked service and is equivalent to its indicator. As there is no non-approved service indicator, if the return code or flag differs from the approved ones it automatically implies the non-approved mode of operation
AlgorithmCAVP CertPropertiesReference
AES-CBCA6603, A6607, A6608-SP 800-38A
AES-CBC-CS1A6603, A6607, A6608-SP 800-38A
AES-CBC-CS2A6603, A6607, A6608-SP 800-38A
AES-CBC-CS3A6603, A6607, A6608-SP 800-38A
AES-CCMA6603, A6607, A6608-SP 800-38C
AES-CFB1A6603, A6607, A6608-SP 800-38A
AES-CFB128A6603, A6607, A6608-SP 800-38A
AES-CFB8A6603, A6607, A6608-SP 800-38A
AES-CMACA6603, A6607, A6608-SP 800-38B
AES-CTRA6603, A6607, A6608-SP 800-38A
AES-ECBA6603, A6607, A6608-SP 800-38A
AES-GCMA6604, A6609, A6610, A6611, A6612, A6613, A6614, A6615, A6616-SP 800-38D
AES-GMACA6604, A6609, A6610, A6611, A6612, A6613, A6614, A6615, A6616-SP 800-38D
AES-KWA6603, A6607, A6608-SP 800-38F
AES-KWPA6603, A6607, A6608-SP 800-38F
AES-OFBA6603, A6607, A6608-SP 800-38A

Table 4: Modes List and Description Once the module is installed and initilized as per Section 11.1, after passing all pre-operational self-tests and conditional self-tests executed on startup, the module automatically transitions to the approved mode. On startup, no operator intervention is required to reach this point. The module automatically switches between the approved and non-approved modes depending on the

2.5 Algorithms

Approved Algorithms: © 2025 Ctrl IQ, Inc., atsec information security.

Page 9
AlgorithmCAVP CertPropertiesReference
AES-XTS Testing Revision 2.0A6603, A6607, A6608-SP 800-38E
Counter DRBGA5957-SP 800-90A Rev. 1
ECDSA KeyGen (FIPS186-5)A6605, A6617, A6618, A6619-FIPS 186-5
ECDSA KeyVer (FIPS186-5)A6605, A6617, A6618, A6619-FIPS 186-5
ECDSA SigGen (FIPS186-5)A6605, A6606, A6617, A6618, A6619-FIPS 186-5
ECDSA SigVer (FIPS186-5)A6605, A6606, A6617, A6618, A6619-FIPS 186-5
EDDSA KeyGenA6328-FIPS 186-5
EDDSA SigGenA6328-FIPS 186-5
EDDSA SigVerA6328-FIPS 186-5
Hash DRBGA5957-SP 800-90A Rev. 1
HMAC DRBGA5957-SP 800-90A Rev. 1
HMAC-SHA-1A6605, A6617, A6618, A6619-FIPS 198-1
HMAC-SHA2-224A6605, A6617, A6618, A6619-FIPS 198-1
HMAC-SHA2-256A6605, A6617, A6618, A6619-FIPS 198-1
HMAC-SHA2-384A6605, A6617, A6618, A6619-FIPS 198-1
HMAC-SHA2-512A6605, A6617, A6618, A6619-FIPS 198-1
HMAC-SHA2-512/224A6605, A6617, A6618, A6619-FIPS 198-1
HMAC-SHA2-512/256A6605, A6617, A6618, A6619-FIPS 198-1
HMAC-SHA3-224A6606-FIPS 198-1
HMAC-SHA3-256A6606-FIPS 198-1
HMAC-SHA3-384A6606-FIPS 198-1
HMAC-SHA3-512A6606-FIPS 198-1
KAS-ECC-SSC Sp800- 56Ar3A6605, A6617, A6618, A6619-SP 800-56A Rev. 3
KAS-FFC-SSC Sp800- 56Ar3A6602-SP 800-56A Rev. 3
KAS-IFC-SSCA6605, A6617, A6618, A6619-SP 800-56A Rev. 3
KDA HKDF SP800- 56Cr2A6601-SP 800-56C Rev. 2
KDA OneStep SP800- 56Cr2A6600-SP 800-56C Rev. 2
KDA TwoStep SP800- 56Cr2A6600-SP 800-56C Rev. 2
KDF ANS 9.42 (CVL)A6605, A6606, A6617, A6618, A6619-SP 800-135 Rev. 1
KDF ANS 9.63 (CVL)A6605, A6606, A6617, A6618, A6619-SP 800-135 Rev. 1
KDF SP800-108A6599-SP 800-108 Rev. 1
KDF SSH (CVL)A6605, A6617, A6618, A6619-SP 800-135 Rev. 1
KTS-IFCA6605, A6617, A6618, A6619-SP 800-56B Rev. 2

© 2025 Ctrl IQ, Inc., atsec information security.

Page 10
AlgorithmCAVP CertPropertiesReference
PBKDFA6605, A6606, A6617, A6618, A6619-SP 800-132
RSA KeyGen (FIPS186-5)A6605, A6617, A6618, A6619-FIPS 186-5
RSA SigGen (FIPS186-5)A6605, A6606, A6617, A6618, A6619-FIPS 186-5
RSA SigVer (FIPS186- 2)A6605, A6617, A6618, A6619-FIPS 186-4
RSA SigVer (FIPS186- 4)A6605, A6617, A6618, A6619-FIPS 186-4
RSA SigVer (FIPS186- 5)A6605, A6606, A6617, A6618, A6619-FIPS 186-5
Safe Primes Key GenerationA6602-SP 800-56A Rev. 3
Safe Primes Key VerificationA6602-SP 800-56A Rev. 3
SHA-1A6605, A6617, A6618, A6619-FIPS 180-4
SHA2-224A6605, A6617, A6618, A6619-FIPS 180-4
SHA2-256A6605, A6617, A6618, A6619-FIPS 180-4
SHA2-384A6605, A6617, A6618, A6619-FIPS 180-4
SHA2-512A6605, A6617, A6618, A6619-FIPS 180-4
SHA2-512/224A6605, A6617, A6618, A6619-FIPS 180-4
SHA2-512/256A6605, A6617, A6618, A6619-FIPS 180-4
SHA3-224A6606-FIPS 202
SHA3-256A6606-FIPS 202
SHA3-384A6606-FIPS 202
SHA3-512A6606-FIPS 202
SHAKE-128A6606-FIPS 202
SHAKE-256A6606-FIPS 202
TLS v1.2 KDF RFC7627 (CVL)A6605, A6617, A6618, A6619-SP 800-135 Rev. 1
TLS v1.3 KDF (CVL)A6601-SP 800-135 Rev. 1
NamePropertiesImplementationReference
Asymmetric Cryptographic Key Generation (CKG)Key type:AsymmetricN/ASP 800-133r2, section 4, example 1

2) 4) 5) Table 5: Approved Algorithms Vendor-Affirmed Algorithms: Table 6: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: N/A for this module. Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. Non-Approved, Not Allowed Algorithms: © 2025 Ctrl IQ, Inc., atsec information security.

Page 11
NameUse and Function
AES-GCM with external IVAuthenticated encryption
HMAC with < 112-bit keysMessage authentication
KBKDF with < 112-bit keysKey derivation
KDA OneStep, HKDF with < 112-bit keysKey derivation
KDA OneStep with SHAKE128, SHAKE256Key derivation
ANS X9.42 KDF, ANS X9.63 KDF with < 112-bit keysKey derivation
ANS X9.42 KDF with SHAKE128, SHAKE256Key derivation
ANS X9.63 KDF with SHA-1, SHAKE128, SHAKE256Key derivation
SSH KDF with SHA-512/224, SHA-512/256, SHA-3, SHAKE128, SHAKE256Key derivation
TLS 1.2 KDF with SHA-1, SHA-224, SHA-512/224, SHA-512/256, SHA-3Key derivation
TLS 1.3 KDF with SHA-1, SHA-224, SHA-512, SHA-512/224, SHA- 512/256, SHA-3Key derivation
PBKDF2 with short password, short salt, insufficient iterations, < 112- bit output keysPassword-based key derivation
RSA-PSS with invalid salt lengthSignature generation / verification
RSA with no paddingSignature generation / verification
RSA and ECDSA with no hashingSignature generation / verification
NameTypeDescriptionPropertiesAlgorithms
Message digestSHACompute a message digestSHA-1: (A6605, A6617, A6618, A6619) SHA2-224: (A6605, A6617, A6618, A6619) SHA2-256: (A6605, A6617, A6618, A6619) SHA2-384: (A6605, A6617, A6618, A6619) SHA2-512: (A6605, A6617, A6618, A6619) SHA2-512/224: (A6605, A6617, A6618, A6619) SHA2-512/256: (A6605, A6617, A6618, A6619) SHA3-224: (A6606) SHA3-256: (A6606)

Table 7: Non-Approved, Not Allowed Algorithms

2.6 Security Function Implementations

© 2025 Ctrl IQ, Inc., atsec information security.

Page 12
NameTypeDescriptionPropertiesAlgorithms
SHA3-384: (A6606) SHA3-512: (A6606)
XOFXOFCompute an extendable output message digestSHAKE-128: (A6606) SHAKE-256: (A6606)
EncryptionBC-UnAuthEncrypt a plaintextAES-CBC: (A6603, A6607, A6608) AES-CBC-CS1: (A6603, A6607, A6608) AES-CBC-CS2: (A6603, A6607, A6608) AES-CBC-CS3: (A6603, A6607, A6608) AES-CFB1: (A6603, A6607, A6608) AES-CFB128: (A6603, A6607, A6608) AES-CFB8: (A6603, A6607, A6608) AES-CTR: (A6603, A6607, A6608) AES-ECB: (A6603, A6607, A6608) AES-OFB: (A6603, A6607, A6608) AES-XTS Testing Revision 2.0: (A6603, A6607, A6608)
DecryptionBC-UnAuthDecrypt a ciphertextAES-CBC: (A6603, A6607, A6608) AES-CBC-CS1: (A6603, A6607, A6608) AES-CBC-CS2: (A6603, A6607, A6608) AES-CBC-CS3: (A6603, A6607, A6608)

© 2025 Ctrl IQ, Inc., atsec information security.

Page 13
NameTypeDescriptionPropertiesAlgorithms
AES-CFB1: (A6603, A6607, A6608) AES-CFB128: (A6603, A6607, A6608) AES-CFB8: (A6603, A6607, A6608) AES-CTR: (A6603, A6607, A6608) AES-ECB: (A6603, A6607, A6608) AES-OFB: (A6603, A6607, A6608) AES-XTS Testing Revision 2.0: (A6603, A6607, A6608)
Authenticated encryptionBC-AuthEncrypt and authenticate a plaintextAES-CCM: (A6603, A6607, A6608) AES-GCM: (A6604, A6609, A6610, A6611, A6612, A6613, A6614, A6615, A6616) AES-KW: (A6603, A6607, A6608) AES-KWP: (A6603, A6607, A6608)
Authenticated decryptionBC-AuthDecrypt and authenticate a ciphertextAES-CCM: (A6603, A6607, A6608) AES-GCM: (A6604, A6609, A6610, A6611, A6612, A6613, A6614, A6615, A6616) AES-KW: (A6603, A6607, A6608) AES-KWP: (A6603, A6607, A6608)
Message authenticationMACCompute a MAC tagAES-CMAC: (A6603, A6607, A6608) AES-GMAC:

© 2025 Ctrl IQ, Inc., atsec information security.

Page 14
NameTypeDescriptionPropertiesAlgorithms
(A6604, A6609, A6610, A6611, A6612, A6613, A6614, A6615, A6616) HMAC-SHA-1: (A6605, A6617, A6618, A6619) HMAC-SHA2-224: (A6605, A6617, A6618, A6619) HMAC-SHA2-256: (A6605, A6617, A6618, A6619) HMAC-SHA2-384: (A6605, A6617, A6618, A6619) HMAC-SHA2-512: (A6605, A6617, A6618, A6619) HMAC-SHA2- 512/224: (A6605, A6617, A6618, A6619) HMAC-SHA2- 512/256: (A6605, A6617, A6618, A6619) HMAC-SHA3-224: (A6606) HMAC-SHA3-256: (A6606) HMAC-SHA3-384: (A6606) HMAC-SHA3-512: (A6606)
Key-based key derivationKBKDFDerive keying material from a key-derivation keyKDF SP800-108: (A6599)
Key-establishment key derivationKAS-56CKDFDerive keying material from a shared secretKDA OneStep SP800-56Cr2: (A6600) KDA TwoStep SP800-56Cr2: (A6600) KDA HKDF SP800-56Cr2: (A6601)
Protocol key derivationKAS-135KDFDerive keying material from a shared secretTLS v1.3 KDF: (A6601) KDF ANS 9.42: (A6605, A6606, A6617, A6618, A6619)

© 2025 Ctrl IQ, Inc., atsec information security.

Page 15
NameTypeDescriptionPropertiesAlgorithms
KDF ANS 9.63: (A6605, A6606, A6617, A6618, A6619) KDF SSH: (A6605, A6617, A6618, A6619) TLS v1.2 KDF RFC7627: (A6605, A6617, A6618, A6619)
Password-based key derivationPBKDFDerive keying material from a passwordPBKDF: (A6605, A6606, A6617, A6618, A6619)
Random number generationDRBGGenerate random bytesCounter DRBG: (A5957) Hash DRBG: (A5957) HMAC DRBG: (A5957)
Shared secret computationKAS-SSCCompute a shared secretKAS-FFC-SSC Sp800-56Ar3: (A6602) KAS-ECC-SSC Sp800-56Ar3: (A6605, A6617, A6618, A6619) KAS-IFC-SSC: (A6605, A6617, A6618, A6619)
Signature generationDigSig-SigGenGenerate a digital signatureECDSA SigGen (FIPS186-5): (A6605, A6606, A6617, A6618, A6619) RSA SigGen (FIPS186-5): (A6605, A6606, A6617, A6618, A6619) EDDSA SigGen: (A6328)
Signature verificationDigSig-SigVerVerify a digital signatureECDSA SigVer (FIPS186-5): (A6605, A6606, A6617, A6618, A6619) RSA SigVer (FIPS186-2): (A6605, A6617, A6618, A6619) RSA SigVer (FIPS186-4):

© 2025 Ctrl IQ, Inc., atsec information security.

Page 16
NameTypeDescriptionPropertiesAlgorithms
(A6605, A6617, A6618, A6619) RSA SigVer (FIPS186-5): (A6605, A6606, A6617, A6618, A6619) EDDSA SigVer: (A6328)
Asymmetric EncryptionAsymKeyPair- EncapAsymmetric encryption using RSAKTS-IFC: (A6605, A6617, A6618, A6619)
Asymmetric DecryptionAsymKeyPair- DecapAsymmetric decryption using RSAKTS-IFC: (A6605, A6617, A6618, A6619)
Key pair generationAsymKeyPair- KeyGen CKGGenerate a key pairSafe Primes Key Generation: (A6602) ECDSA KeyGen (FIPS186-5): (A6605, A6617, A6618, A6619) RSA KeyGen (FIPS186-5): (A6605, A6617, A6618, A6619) EDDSA KeyGen: (A6328) Asymmetric Cryptographic Key Generation (CKG): () Key type: Asymmetric
Key pair verificationAsymKeyPair- KeyVerVerify a key pairSafe Primes Key Verification: (A6602) ECDSA KeyVer (FIPS186-5): (A6605, A6617, A6618, A6619)

Table 8: Security Function Implementations

2.7 Algorithm Specific Information
2.7.1 AES-GCM IV

For TLS 1.2, the module offers the AES GCM implementation and uses the context of Scenario 1 of FIPS 140-3 IG C.H. The module is compliant with SP 800-52 Rev. 2 Section 3.3.1 and the mechanism for IV generation is compliant with RFC 5288 and 8446. © 2025 Ctrl IQ, Inc., atsec information security.

Page 17

The module does not implement the TLS protocol. The module’s implementation of AES GCM is used together with an application that runs outside the module’s cryptographic boundary. The design of the TLS protocol implicitly ensures that the counter (the nonce_explicit part of the IV) does not exhaust the maximum number of possible values for a given session key. In the event the module’s power is lost and restored, the consuming application must ensure that a new key for use with the AES GCM key encryption or decryption under this scenario shall be established. Alternatively, the Crypto Officer can use the module’s API to perform AES GCM encryption using internal IV generation. These IVs are always 96 bits and generated using the approved DRBG internal to the module’s boundary, compliant to Scenario 2 of FIPS 140-3 IG C.H. The module also provides a non-approved AES GCM encryption service which accepts arbitrary external IVs from the operator. This service can be requested by invoking the EVP_EncryptInit_ex2 API function with a non-NULL IV value. When this is the case, the API will set a non-approved service indicator. Finally, for TLS 1.3, the AES GCM implementation uses the context of Scenario 5 of FIPS 140-3 IG C.H. The protocol that provides this compliance is TLS 1.3, defined in RFC8446 of August 2018, using the ciphersuites that explicitly select AES GCM as the encryption/decryption cipher (Appendix B.4 of RFC8446). The module supports acceptable AES GCM cipher suites from Section 3.3.1 of SP 800-52 Rev. 2. The module’s implementation of AES GCM is used together with an application that runs outside the module’s cryptographic boundary. The design of the TLS protocol implicitly ensures that the counter (the nonce_explicit part of the IV) does not exhaust the maximum number of possible values for a given session key.

2.7.2 AES-XTS

The length of a single data unit encrypted or decrypted with AES XTS shall not exceed 2²⁰ AES blocks, that is 16MB, of data per XTS instance. An XTS instance is defined in Section 4 of SP 800-38E. To meet the requirement stated in IG C.I, the module implements a check that ensures, before performing any cryptographic operation, that the two AES keys used in AES XTS mode are not identical. Key_1 and Key_2 shall be generated and/or established independently according to the rules for component symmetric keys from NIST SP 800-133r2, Section 6.3. The XTS mode shall only be used for the cryptographic protection of data on storage devices. It shall not be used for other purposes, such as the encryption of data in transit.

2.7.3 PBKDF2

The module provides password-based key derivation (PBKDF2), compliant with SP 800-132. The module supports option 1a from Section 5.4 of SP 800-132, in which the Master Key (MK) or a segment of it is used directly as the Data Protection Key (DPK). In accordance with SP 800-132 and FIPS 140-3 IG D.N, the following requirements must be met:

Page 18
2.7.4 SP 800-56Ar3 Assurances

To comply with the assurances found in Section 5.6.2 of SP 800-56Ar3, the operator must use the module in the context of the TLS or SSH protocols. Additionally, the module’s approved key pair generation service (see Section 4.3) must be used to generate ephemeral Diffie-Hellman or EC Diffie-Hellman key pairs, or the key pairs must be obtained from another FIPS-validated module. As part of this service, the module will internally perform the full public key validation of the generated public key. The module’s shared secret computation service will internally perform the full public key validation of the peer public key, complying with Sections 5.6.2.2.1 and 5.6.2.2.2 of SP 800-56Ar3.

2.7.5 SP 800-56Br2 Assurances

To comply with the assurances found in Section 6.4 of SP 800-56Br2, the operator must use the module in the context of the TLS or SSH protocols. Additionally, the module’s approved key pair generation service (see Section 4.3) must be used to generate RSA key pairs, or the key pairs must be obtained from another FIPS-validated module. As part of this service, the module will internally perform the key pair validation of the generated public key. The operator must use the EVP_PKEY_public_check() API to perform partial public key validation of the peer public key, complying with Section 6.4.2.2 of SP 800-56Br2. The operator must also confirm the peer’s possession of private key by using any method specified in Section 6.4.2.3 of SP 800-56Br2.

2.7.6 RSA

For RSA key generation, signature generation, and signature verification, the approved modulus sizes of 2048, 3072, and 4096 bits are CAVP tested in compliance with FIPS 186-5. For KAS-IFC-SSC and KTSIFC, the approved modulus sizes of 2048, 3072, 4096, 6144, 8192 are CAVP tested in compliance with SP 800-56Br2. All other RSA modulus sizes listed in this document, and not mentioned above, cannot be tested by CAVP but are approved for RSA key generation, signature generation, and signature verification per FIPS 140-3 IG C.F, and KAS-IFC-SSC and KTS-IFC per SP 800-56Br2.

2.7.7 Legacy Use

RSA signature verification using modulus sizes between 1024 and 2048 bits is allowed for legacy use only. These legacy algorithms can only be used on data that was generated prior to the Legacy Date specified in FIPS 140-3 IG C.M.

2.7.8 Key Agreement

The module does not establish SSPs using an approved key agreement scheme (KAS). However, it does offer some or all of the underlying KAS cryptographic functionality to be used by an external operator/application as part of an approved KAS. © 2025 Ctrl IQ, Inc., atsec information security.

Page 19
CertVendor
NumberName
E208Ctrl IQ, Inc.
NameTypeOperational EnvironmentSample SizeEntropy per SampleConditioning Component
Rocky Linux OpenSSL 3 CPU Time Jitter RNG Entropy SourceNon- PhysicalRocky Linux 9 on Intel Kaby Lake Xeon E3-1270 v6256 bitsfull entropySHA3-256 (A5837); SHA2-512-HMAC-DRBG (A5837); AES-256-CTR- DRBG (A5957)
2.7.9 Key Transport

The module does not establish SSPs using an approved key transport scheme (KTS). However, it does offer approved authenticated algorithms that can be used by an external operator/application as part of an approved KTS.

2.8 RBG and Entropy

Table 9: Entropy Certificates Table 10: Entropy Sources The module implements primary DRBG (AES-256-CTR-DRBG (A5957)) which acts as the conditioning component for the entropy source mentioned in the above table. It is only used internally by the module to seed the secondary DRBGs which can be of type (CTR, Hash, HMAC). The module complies with the Public Use Document for ESV certificate E208 by reading entropy data from the EVP_RAND_generate() function of the primary DRBG, which corresponds to the GetEntropy() conceptual interface. The operational environment on the ESV certificate is identical to the operating system described in this document. There are no maintenance requirements for the entropy source. As per the Public document of entropy certificate E208, the entropy source provides full entropy of 256 bits. When the module needs random data for internal purposes it uses two separate instances of AES-256 CTR_DRBG DRBG based on use case. i.e., it uses the “private DRBG” accessed via RAND_priv_bytes () for asymmetric key generation, signature generation, or other SSP use cases and it uses the “public DRBG” accessed via RAND_bytes() when it needs to generate IV or other non-SSP use cases. When an external caller needs the random data, it can access it via “Random Number Generation” service of the module and it has a choice to choose between Hash, HMAC or CTR DRBG listed in the algorithms table.

2.9 Key Generation

The module implements Cryptographic Key Generation (CKG, vendor affirmed), compliant with SP 800133r2. When random values are required, they are obtained from the SP 800-90Ar1 approved DRBG, compliant with Section 4 of SP 800-133r2. The following methods are implemented:

Page 20
2.10 Key Establishment

The module implements shared secret computation methods, asymmetric encryption and decryption services using RSA with OAEP padding, as listed in the Security Function Implementations table in Section 2.6.

2.11 Industry Protocols

The module implements key derivation functions for usage in the SSH (RFC 4253), TLS 1.2 (RFC 5288), and TLS 1.3 (RFC 8446) protocols. AES-GCM with internal IV generation is offered in the approved mode compliant with TLS 1.2 and TLS 1.3. Finally, the module supports the use of the safe primes defined in RFC 3526 (IKE) and RFC 7919 (TLS) for Diffie-Hellman. No parts of the SSH, TLS, or IKE protocols, other than those mentioned above, have been tested by the CAVP and CMVP. © 2025 Ctrl IQ, Inc., atsec information security.

Page 21
Physical PortLogical Interface(s)Data That Passes
N/AData InputAPI input parameters
N/AData OutputAPI output parameters
N/AControl InputAPI function calls
N/AStatus OutputAPI return codes, error queue
3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

Table 11: Ports and Interfaces The logical interfaces are the APIs through which the applications request services. These logical interfaces are logically separated from each other by the API design. The module does not implement a control output © 2025 Ctrl IQ, Inc., atsec information security.

Page 22
NameTypeOperator TypeAuthentication Methods
Crypto OfficerRoleCONone
NameDescri ptionIndicatorInput sOutpu tsSecurit y Functio nsSSP Access
Messag e digestCompu te a messa ge digestEVP_DigestFinal_ex returns 1Messa geDigest valueMessag e digestCrypto Officer
XOFCompu te an extend able output messa ge digestEVP_DigestFinalXOF returns 1Messa ge, output lengthDigest valueXOFCrypto Officer
Encrypti onEncrypt a plaintex tEVP_EncryptFinal_ex returns 1AES key, plainte xt, IV (if requir ed)Cipher textEncrypti onCrypto Officer - AES key: W,E
Decrypti onDecrypt a ciphert extEVP_DecryptFinal_ex returns 1AES key, cipher text, IV (if requir ed)Plainte xtDecrypti onCrypto Officer - AES key: W,E
Authenti cated encrypti onEncrypt and authent icate aAES-GCM: EVP_CIPHER_ROCKY_FIPS_INDICAT OR_APPROVED; Others: EVP_EncryptFinal_ex returns 1AES key, plainte xt, IVCipher text, MAC tagAuthenti cated encrypti onCrypto Officer - AES key: W,E
4 Roles, Services, and Authentication

The module does not implement any authentication methods.

4.2 Roles

Table 12: Roles No support is provided for multiple concurrent operators.

4.3 Approved Services

W,E © 2025 Ctrl IQ, Inc., atsec information security.

Page 23
NameDescri ption plaintex tIndicatorInput sOutpu tsSecurit y Functio nsSSP Access - DRBG internal state (V, Key): W,E
Authenti cated decrypti onDecrypt and authent icate a ciphert extEVP_DecryptFinal_ex returns 1AES key, cipher text, IV, MAC tagPlainte xt or failureAuthenti cated decrypti onCrypto Officer - AES key: W,E
Messag e authenti cationCompu te a MAC tagHMAC: OSSL_MAC_PARAM_ROCKY_FIPS_IN DICATOR_APPROVED; Others: EVP_MAC_final returns 1AES key or HMAC key, messa geMAC tagMessag e authenti cationCrypto Officer - AES key: W,E - HMAC key: W,E
Key- based key derivatio nDerive keying materia l from a key- derivati on keyEVP_KDF_ROCKY_FIPS_INDICATOR_ APPROVEDKey- deriva tion key, output lengthDerive d keyKey- based key derivatio nCrypto Officer - Key- derivati on key: W,E - Derived key: G,R
Key- establis hment key derivatio nDerive keying materia l from a shared secretEVP_KDF_ROCKY_FIPS_INDICATOR_ APPROVEDShare d secret , output lengthDerive d keyKey- establis hment key derivatio nCrypto Officer - Shared secret: W,E - Derived key: G,R
Protocol key derivatio nDerive keying materia l from a shared secretEVP_KDF_ROCKY_FIPS_INDICATOR_ APPROVEDShare d secret , output lengthDerive d keyProtocol key derivatio nCrypto Officer - Shared secret: W,E - Derived

(V, W,E W,E G,R G,R © 2025 Ctrl IQ, Inc., atsec information security.

Page 24
NameDescri ptionIndicatorInput sOutpu tsSecurit y Functio nsSSP Access key: G,R
Passwor d-based key derivatio nDerive keying materia l from a passwo rdEVP_KDF_ROCKY_FIPS_INDICATOR_ APPROVEDPassw ord, salt, iterati on count, output lengthDerive d keyProtocol key derivatio nCrypto Officer - Passwo rd: W,E - Derived key: G,R
Random number generati onGenera te random bytesEVP_RAND_generate returns 1Outpu t lengthRando m bytesRandom number generati onCrypto Officer - Entropy input: G,E,Z - DRBG seed: G,E,Z - DRBG internal state (V, Key): G,W,E - DRBG internal state (V, C): G,W,E
Shared secret computa tionCompu te a shared secretEVP_PKEY_ROCKY_FIPS_INDICATOR _APPROVEDOwner privat e key, peer public keyShare d secretShared secret computa tionCrypto Officer - DRBG internal state (V, Key): W,E - DH private key: W,E - DH public key: W,E - EC private key: W,E

G,R G,R G,E,Z G,E,Z (V, G,W,E (V, C): G,W,E W,E W,E W,E W,E © 2025 Ctrl IQ, Inc., atsec information security.

Page 25
NameDescri ptionIndicatorInput sOutpu tsSecurit y Functio nsSSP Access - EC public key: W,E - RSA private key: W,E - RSA public key: W,E - Shared secret: G,R
Signatur e generati onGenera te a digital signatu reOSSL_RL_FIPSINDICATOR_APPROVE D and EVP_PKEY_ROCKY_FIPS_INDICATOR _APPROVEDPrivat e key, hash algorit hm, messa geSignat ureSignatur e generati onCrypto Officer - DRBG internal state (V, Key): W,E - EC private key: W,E - EdDSA private key: W,E - RSA private key: W,E
Signatur e verificati onVerify a digital signatu reOSSL_RL_FIPSINDICATOR_APPROVE D and EVP_PKEY_ROCKY_FIPS_INDICATOR _APPROVEDPublic key, hash algorit hm, messa ge, signat urePass/f ailSignatur e verificati onCrypto Officer - EC public key: W,E - EdDSA public key: W,E - RSA public

W,E W,E W,E G,R W,E W,E W,E W,E W,E © 2025 Ctrl IQ, Inc., atsec information security.

Page 26
NameDescri ptionIndicatorInput sOutpu tsSecurit y Functio nsSSP Access key: W,E
Asymme tric Encrypti onPerfor m RSA- based encrypt ion (compli ant with SP 800- 56B Rev. 2))EVP_PKEY_ROCKY_FIPS_INDICATOR _APPROVEDRSA public key, plainte xtCipher textAsymme tric Encrypti onCrypto Officer - RSA public key: W,E
Asymme tric Decrypti onPerfor m RSA- based decrypt ion (compli ant with SP 800- 56B Rev. 2))EVP_PKEY_ROCKY_FIPS_INDICATOR _APPROVEDRSA privat e key, cipher textPlainte xtAsymme tric Decrypti onCrypto Officer - RSA private key: W,E
Key pair generati onGenera te a key pairEVP_PKEY_generate returns 1Group or curve or modul us bitsModul e- gener ated key pairKey pair generati onCrypto Officer - DRBG internal state (V, Key): W,E - Module - generat ed DH private key: G,R - Module - generat ed DH public key:

W,E 2)) 2)) W,E G,R © 2025 Ctrl IQ, Inc., atsec information security.

Page 27

Name

Descri ption

Indicator

Input s

Outpu ts

Securit y Functio ns

SSP Access G,R - Module - generat ed EC private key: G,R - Module - generat ed EC public key: G,R - Module - generat ed EdDSA private key: G,R - Module - generat ed EdDSA public key: G,R - Module - generat ed RSA private key: G,R - Module - generat ed RSA public key: G,R

G,R G,R G,R G,R G,R G,R G,R © 2025 Ctrl IQ, Inc., atsec information security.

Page 28
NameDescri ptionIndicatorInput sOutpu tsSecurit y Functio nsSSP Access - Interme diate key generat ion value: G,E,Z
Key pair verificati onVerify a key pairEVP_PKEY_public_check or EVP_PKEY_private_check or EVP_PKEY_check returns 1Key pairPass/f ailKey pair verificati onCrypto Officer - DH private key: W,E - DH public key: W,E - EC private key: W,E - EC public key: W,E
Show versionReturn the module name and version informa tionNoneN/AModul e name and versio nNoneCrypto Officer
Show statusReturn the module statusNoneN/AModul e statusNoneCrypto Officer
Self-testPerfor m the CASTs and integrit y testsNoneN/APass/f ailMessag e digest Decrypti on Authenti cated encrypti on Authenti cated decrypti onCrypto Officer

G,E,Z W,E W,E W,E W,E © 2025 Ctrl IQ, Inc., atsec information security.

Page 29
NameDescri ptionIndicatorInput sOutpu tsSecurit y Functio nsSSP Access
Key- based key derivatio n Key- establis hment key derivatio n Protocol key derivatio n Passwor d-based key derivatio n Random number generati on Shared secret computa tion Signatur e generati on Signatur e verificati on
Zeroizati onZeroize SSPsNoneAny SSPN/ANoneCrypto Officer - AES key: Z - HMAC key: Z - Key- derivati on key: Z - Shared secret: Z

n n n n e e Z Z © 2025 Ctrl IQ, Inc., atsec information security.

Page 30

Name

Descri ption

Indicator

Input s

Outpu ts

Securit y Functio ns

SSP Access - Passwo rd: Z - Derived key: Z - Entropy input: Z - DRBG seed: Z - DRBG internal state (V, Key): Z - DRBG internal state (V, C): Z - DH private key: Z - DH public key: Z - EC private key: Z - EC public key: Z - EdDSA private key: Z - EdDSA public key: Z - RSA private key: Z - RSA public key: Z - Module - generat

(V, (V, C): Z © 2025 Ctrl IQ, Inc., atsec information security.

Page 31

Name

Descri ption

Indicator

Input s

Outpu ts

Securit y Functio ns

SSP Access ed DH private key: Z - Module - generat ed DH public key: Z - Module - generat ed EC private key: Z - Module - generat ed EC public key: Z - Module - generat ed EdDSA private key: Z - Module - generat ed EdDSA public key: Z - Module - generat ed RSA private key: Z - Module - generat

© 2025 Ctrl IQ, Inc., atsec information security.

Page 32

Name

Descri ption

Indicator

Input s

Outpu ts

Securit y Functio ns

SSP Access ed RSA public key: Z - Interme diate key generat ion value: Z

ContextService Indicator
EVP_CIPHER_CTXOSSL_CIPHER_PARAM_ROCKY_FIPS_INDICATOR
EVP_MAC_CTXOSSL_MAC_PARAM_ROCKY_FIPS_INDICATOR
EVP_KDF_CTXOSSL_KDF_PARAM_ROCKY_FIPS_INDICATOR
EVP_PKEY_CTXOSSL_SIGNATURE_PARAM_ROCKY_FIPS_INDICATOR
EVP_PKEY_CTXOSSL_ASYM_CIPHER_PARAM_ROCKY_FIPS_INDICATOR
EVP_PKEY_CTXOSSL_KEM_PARAM_ROCKY_FIPS_INDICATOR
NameDescriptionAlgorithmsRole
AES-GCM with external IV encryptionEncrypt and authenticate a plaintext using AES-GCM with an external IVAES-GCM with external IVCrypto Officer

Z Table 13: Approved Services For the above table, the convention below applies when specifying the access permissions (types) that the service has for each SSP.

4.4 Non-Approved Services

© 2025 Ctrl IQ, Inc., atsec information security.

Page 33
NameDescriptionAlgorithmsRole
Message authenticationCompute a MAC tagHMAC with < 112-bit keysCrypto Officer
Key-based key derivationDerive keying material from a key-derivation keyKBKDF with < 112-bit keysCrypto Officer
Key-establishment key derivationDerive keying material from a shared secretKDA OneStep, HKDF with < 112- bit keys KDA OneStep with SHAKE128, SHAKE256Crypto Officer
Protocol key derivationDerive keying material from a shared secretANS X9.42 KDF, ANS X9.63 KDF with < 112-bit keys ANS X9.42 KDF with SHAKE128, SHAKE256 ANS X9.63 KDF with SHA-1, SHAKE128, SHAKE256 SSH KDF with SHA-512/224, SHA-512/256, SHA-3, SHAKE128, SHAKE256 TLS 1.2 KDF with SHA-1, SHA- 224, SHA-512/224, SHA-512/256, SHA-3 TLS 1.3 KDF with SHA-1, SHA- 224, SHA-512, SHA-512/224, SHA-512/256, SHA-3Crypto Officer
Password-based key derivationDerive keying material from a passwordPBKDF2 with short password, short salt, insufficient iterations, < 112-bit output keysCrypto Officer
Signature generationGenerate a digital signatureRSA-PSS with invalid salt length RSA with no padding RSA and ECDSA with no hashingCrypto Officer
Signature verificationVerify a digital signatureRSA-PSS with invalid salt length RSA with no padding RSA and ECDSA with no hashingCrypto Officer

Table 14: Non-Approved Services

4.5 External Software/Firmware Loaded

The module does not load external software or firmware. © 2025 Ctrl IQ, Inc., atsec information security.

Page 34
5 Software/Firmware Security
5.1 Integrity Techniques

The integrity of the module is verified by comparing a HMAC-SHA2-256 value calculated at run time with the HMAC-SHA2-256 value embedded in the fips.so file that was computed at build time. The module performs a KAT for the HMAC SHA-256 algorithm in order to test its proper operation before performing the checksum of the fips.so file.

5.2 Initiate on Demand

Integrity tests are performed as part of the pre-operational self-tests, which are executed when the module is initialized. The integrity tests can be invoked on demand by unloading and subsequently re-initializing the module (i.e., rebooting the system), which will perform (among others) the software integrity tests. © 2025 Ctrl IQ, Inc., atsec information security.

Page 35
6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Modifiable How Requirements are Satisfied: Any SSPs contained within the module are protected by the process isolation and memory separation mechanisms, and only the module has control over these SSPs. If properly installed, the operating system provides process isolation and memory protection mechanisms that ensure appropriate separation for memory access among the processes on the system. Each process has control over its own data and uncontrolled access to the data of other processes is prevented.

6.2 Configuration Settings and Restrictions

The module shall be installed as stated in Section 11.1. Instrumentation tools like the ptrace system call, gdb and strace, as well as other tracing mechanisms offered by the Linux environment such as ftrace or systemtap, shall not be used in the operational environments. The use of any of these tools implies that the cryptographic module is running in a nonvalidated operational environment. © 2025 Ctrl IQ, Inc., atsec information security.

Page 36
7 Physical Security

The module is comprised of software only and therefore this section is not applicable. © 2025 Ctrl IQ, Inc., atsec information security.

Page 37
8 Non-Invasive Security

The module does not implement any non-invasive security mechanisms. © 2025 Ctrl IQ, Inc., atsec information security.

Page 38
Storage Area NameDescriptionPersistence Type
Module RAMTemporary storage for SSPs used by the module as part of service executionDynamic
NameFromToFormat TypeDistribution TypeEntry TypeSFI or Algorithm
API input parametersOperator calling application (TOEPP)Module RAMPlaintextManualElectronic
API output parametersModule RAMOperator calling application (TOEPP)PlaintextManualElectronic
Zeroization MethodDescriptionRationaleOperator Initiation
Free cipher handleZeroizes the SSPs contained within the cipher handleMemory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable. The completion of the zeroization routine indicates that the zeroization procedure succeeded.By calling the appropriate zeroization functions: EVP_CIPHER_CTX_free, EVP_MAC_CTX_free, EVP_KDF_CTX_free, EVP_RAND_CTX_free, EVP_PKEY_free
Module resetDe-allocates the volatile memory used to store SSPsVolatile memory used by the module is overwritten within nanoseconds when power is removed. The successful completion of the module reset indicates that zeroization has completed.By unloading and reloading the module
9 Sensitive Security Parameters Management
9.1 Storage Areas

Table 15: Storage Areas The module does not perform persistent storage of SSPs; SSPs in use by the module exist in volatile Table 16: SSP Input-Output Methods operational environment. This corresponds to manual distribution, electronic entry/output (“CM Software to/from App via TOEPP Path”) per FIPS 140-3 IG 9.5.A Table 1. © 2025 Ctrl IQ, Inc., atsec information security.

Page 39
Zeroization MethodDescriptionRationaleOperator Initiation
AutomaticAutomatically zeroized by the module when no longer neededMemory occupied by SSPs is overwritten with zeroes, which renders the SSP values irretrievable. The successful completion of the running service indicates that zeroization was completed.N/A
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablishe d ByUsed By
AES keySymmetric key used for AES operations128, 256 bits (AES-XTS); 128, 192, 256 bits (others) - 128, 256 bits (AES-XTS); 128, 192, 256 bits (others)Symmetric key - CSPEncryption Decryption Authenticate d encryption Authenticate d decryption Message authenticatio n
HMAC keySymmetric key used for HMAC operations112-524288 bits - 112- 256 bitsAuthenticati on key - CSPMessage authenticatio n
Key- derivation keySymmetric key used to derive symmetric keys112-4096 bits - 112-256 bitsSymmetric key - CSPKey-based key derivation
Shared secretShared secret established using KAS- SSC112-8192 bits - 112-256 bitsShared secret - CSPShared secret computatio nKey- establishme nt key derivation Protocol key derivation
PasswordPassword used to derive symmetric keys8-128 characters - N/APassword - CSPPassword- based key derivation
Derived keySymmetric key derived from a key- derivation key, shared112-4096 bits - 112-256 bitsSymmetric key - CSPKey-based key derivation Key- establishme

Table 17: SSP Zeroization Methods All data output is inhibited during zeroization. © 2025 Ctrl IQ, Inc., atsec information security.

Page 40
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablishe d ByUsed By
secret, or passwordnt key derivation Protocol key derivation Password- based key derivation
Entropy inputEntropy input used to seed DRBGs128-384 bits - 128-384 bitsEntropy input - CSPRandom number generationRandom number generation
DRBG seedDRBG seed derived from entropy input and additional dataCTR_DRBG: 256, 320, 384 bits; Hash_DRBG: 440, 888 bits; HMAC_DRB G: 440, 888 bits - CTR_DRBG: 128, 192, 256 bits; Hash_DRBG: 128, 256 bits; HMAC_DRB G: 128, 256 bitsSeed - CSPRandom number generationRandom number generation
DRBG internal state (V, Key)Internal state of CTR_DRBG and HMAC_DRB GCTR_DRBG: 256, 320, 384 bits; HMAC_DRB G: 320, 512, 1024 bits - CTR_DRBG: 128, 192, 256 bits; HMAC_DRB G: 128, 256 bitsInternal state - CSPRandom number generationRandom number generation
DRBG internal state (V, C)Internal state of Hash_DRBGHash_DRBG: 880, 1776 bits - Hash_DRBG: 128, 256 bitsInternal state - CSPRandom number generationRandom number generation
DH private keyPrivate key used for Diffie- Hellmanffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096,Private key - CSPShared secret computation Key pair verification

© 2025 Ctrl IQ, Inc., atsec information security.

Page 41
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablishe d ByUsed By
MODP-6144, MODP-8192 - 112-200 bits
DH public keyPublic key used for Diffie- Hellmanffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192 - 112-200 bitsPublic key - PSPShared secret computation Key pair verification
EC private keyPrivate key used for EC Diffie- Hellman and ECDSAP-224, P- 256, P-384, P-521 - 112, 128, 192, 256 bitsPrivate key - CSPShared secret computation Signature generation Key pair verification
EC public keyPublic key used for EC Diffie- Hellman and ECDSAP-224, P- 256, P-384, P-521 - 112, 128, 192, 256 bitsPublic key - PSPShared secret computation Signature verification Key pair verification
EdDSA private keyPrivate key used for EdDSAEd25519, Ed448 - 128, 224 bitsPrivate key - CSPSignature generation
EdDSA public keyPublic key used for EdDSAEd25519, Ed448 - 128, 224 bitsPublic key - PSPSignature verification
RSA private keyPrivate key used for RSA2048-16384 bits - 112- 256 bitsPrivate key - CSPShared secret computation Signature generation Asymmetric Decryption
RSA public keyPublic key used for RSA1024, 1536, 2048-16384 bits - 80, 96, 112-256 bitsPublic key - PSPShared secret computation Signature verification Asymmetric Encryption
Module- generatedDH private keyffdhe2048, ffdhe3072,Private key - CSPKey pair generation

© 2025 Ctrl IQ, Inc., atsec information security.

Page 42
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablishe d ByUsed By
DH private keygenerated by the moduleffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192 - 112-200 bits
Module- generated DH public keyDH public key generated by the moduleffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192, MODP-2048, MODP-3072, MODP-4096, MODP-6144, MODP-8192 - 112-200 bitsPublic key - PSPKey pair generation
Module- generated EC private keyEC private key generated by the moduleP-224, P- 256, P-384, P-521 - 112, 128, 192, 256 bitsPrivate key - CSPKey pair generation
Module- generated EC public keyEC public key generated by the moduleP-224, P- 256, P-384, P-521 - 112, 128, 192, 256 bitsPublic key - PSPKey pair generation
Module- generated EdDSA private keyEdDSA private key generated by the moduleEd25519, Ed448 - 128, 224 bitsPrivate key - CSPKey pair generation
Module- generated EdDSA public keyEdDSA public key generated by the moduleEd25519, Ed448 - 128, 224 bitsPublic key - PSPKey pair generation
Module- generated RSA private keyRSA private key generated by the module2048-15360 bits - 112- 256 bitsPrivate key - CSPKey pair generation
Module- generated RSA public keyRSA public key generated by the module2048-15360 bits - 112- 256 bitsPublic key - PSPKey pair generation

© 2025 Ctrl IQ, Inc., atsec information security.

Page 43
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablishe d ByUsed By
Intermediat e key generation valueTemporary value generated during key pair generation services224-15360 bits - 112- 256 bitsIntermediate value - CSPKey pair generationKey pair generation
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
AES keyAPI input parametersModule RAM:PlaintextUntil cipher handle is freed or module is resetFree cipher handle Module reset
HMAC keyAPI input parametersModule RAM:PlaintextUntil cipher handle is freed or module is resetFree cipher handle Module reset
Key-derivation keyAPI input parametersModule RAM:PlaintextUntil cipher handle is freed or module is resetFree cipher handle Module resetDerived key:Derives
Shared secretAPI input parameters API output parametersModule RAM:PlaintextUntil cipher handle is freed or module is resetFree cipher handle Module resetDH private key:Established By DH public key:Established By EC private key:Established By EC public key:Established By RSA private key:Established By RSA public key:Established By Derived key:Derives
PasswordAPI input parametersModule RAM:PlaintextUntil cipher handle is freed or module is resetFree cipher handle Module resetDerived key:Derives
Derived keyAPI output parametersModule RAM:PlaintextUntil cipher handle is freed or module is resetFree cipher handle Module resetKey-derivation key:Derived From Shared secret:Derived From Password:Derived From

Table 18: SSP Table 1 © 2025 Ctrl IQ, Inc., atsec information security.

Page 44
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
Entropy inputModule RAM:PlaintextFrom generation until DRBG seed is createdModule reset AutomaticDRBG seed:Derives
DRBG seedModule RAM:PlaintextWhile the DRBG is being instantiatedModule reset AutomaticEntropy input:Derived From DRBG internal state (V, Key):Generates DRBG internal state (V, C):Generates
DRBG internal state (V, Key)Module RAM:PlaintextUntil cipher handle is freed or module is resetFree cipher handle Module resetDRBG seed:Generated From
DRBG internal state (V, C)Module RAM:PlaintextUntil cipher handle is freed or module is resetFree cipher handle Module resetDRBG seed:Generated From
DH private keyAPI input parametersModule RAM:PlaintextUntil cipher handle is freed or module is resetFree cipher handle Module resetDH public key:Paired With Shared secret:Establishes
DH public keyAPI input parametersModule RAM:PlaintextUntil cipher handle is freed or module is resetFree cipher handle Module resetDH private key:Paired With Shared secret:Establishes
EC private keyAPI input parametersModule RAM:PlaintextUntil cipher handle is freed or module is resetFree cipher handle Module resetEC public key:Paired With Shared secret:Establishes
EC public keyAPI input parametersModule RAM:PlaintextUntil cipher handle is freed or module is resetFree cipher handle Module resetEC private key:Paired With Shared secret:Establishes
EdDSA private keyAPI input parametersModule RAM:PlaintextUntil cipher handle is freed or module is resetFree cipher handle Module resetEdDSA public key:Paired With
EdDSA public keyAPI input parametersModule RAM:PlaintextUntil cipher handle is freed or module is resetFree cipher handle Module resetEdDSA private key:Paired With

© 2025 Ctrl IQ, Inc., atsec information security.

Page 45
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
RSA private keyAPI input parametersModule RAM:PlaintextUntil cipher handle is freed or module is resetFree cipher handle Module resetRSA public key:Paired With Shared secret:Establishes
RSA public keyAPI input parametersModule RAM:PlaintextUntil cipher handle is freed or module is resetFree cipher handle Module resetRSA private key:Paired With Shared secret:Establishes
Module- generated DH private keyAPI output parametersModule RAM:PlaintextUntil cipher handle is freed or module is resetFree cipher handle Module resetModule-generated DH public key:Paired With Intermediate key generation value:Generated From
Module- generated DH public keyAPI output parametersModule RAM:PlaintextUntil cipher handle is freed or module is resetFree cipher handle Module resetModule-generated DH private key:Paired With Intermediate key generation value:Generated From
Module- generated EC private keyAPI output parametersModule RAM:PlaintextUntil cipher handle is freed or module is resetFree cipher handle Module resetModule-generated EC public key:Paired With Intermediate key generation value:Generated From
Module- generated EC public keyAPI output parametersModule RAM:PlaintextUntil cipher handle is freed or module is resetFree cipher handle Module resetModule-generated EC private key:Paired With Intermediate key generation value:Generated From
Module- generated EdDSA private keyAPI output parametersModule RAM:PlaintextUntil cipher handle is freed or module is resetFree cipher handle Module resetModule-generated EdDSA public key:Paired With Intermediate key generation value:Generated From
Module- generated EdDSA public keyAPI output parametersModule RAM:PlaintextUntil cipher handle is freed or module is resetFree cipher handle Module resetModule-generated EdDSA private key:Paired With Intermediate key generation value:Generated From

© 2025 Ctrl IQ, Inc., atsec information security.

Page 46
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
Module- generated RSA private keyAPI output parametersModule RAM:PlaintextUntil cipher handle is freed or module is resetFree cipher handle Module resetModule-generated RSA public key:Paired With Intermediate key generation value:Generated From
Module- generated RSA public keyAPI output parametersModule RAM:PlaintextUntil cipher handle is freed or module is resetFree cipher handle Module resetModule-generated RSA private key:Paired With Intermediate key generation value:Generated From
Intermediate key generation valueModule RAM:PlaintextFor the duration of the serviceModule reset AutomaticModule-generated DH private key:Generates Module-generated DH public key:Generates Module-generated EC private key:Generates Module-generated EC public key:Generates Module-generated EdDSA private key:Generates Module-generated EdDSA public key:Generates Module-generated RSA private key:Generates Module-generated RSA public key:Generates
9.5 Transitions

The SHA-1 algorithm as implemented by the module will be non-approved for all purposes, starting January 1, 2031. © 2025 Ctrl IQ, Inc., atsec information security.

Page 47
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
HMAC- SHA2-256Key size: 256 bitsMessage authenticationSW/FW IntegrityModule becomes available and services are available for useIntegrity test of the fips.so shared library
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-GCM - EncryptionKey size: 256 bitsKATCASTModule becomes operationalEncryptionAt power-on, before the integrity test
AES-GCM - DecryptionKey size: 256 bitsKATCASTModule becomes operationalDecryptionAt power-on, before the integrity test
AES-ECBKey size: 128 bitsKATCASTModule becomes operationalDecryptionAt power-on, before the integrity test
SHA-124-bit messageKATCASTModule becomes operationalMessage digestAt power-on, before the integrity test
SHA2-51224-bit messageKATCASTModule becomes operationalMessage digestAt power-on, before the integrity test
SHA3-25632-bit messageKATCASTModule becomes operationalMessage digestAt power-on, before the integrity test
KBKDFHMAC-SHA2- 256 in counter modeKATCASTModule becomes operationalKey derivationAt power-on, before the integrity test
KDA OneStepSHA2-224KATCASTModule becomes operationalKey derivationAt power-on, before the integrity test
KDA HKDFSHA2-256KATCASTModule becomes operationalKey derivationAt power-on, before the integrity test
10 Self-Tests

While the module is executing the self-tests, services are not available, and data output (via the data output interface) is inhibited until the tests are successfully completed. The module does not return control to the calling application until the tests are completed. If any of the self-tests fails, the module immediately transitions to the error state.

10.1 Pre-Operational Self-Tests

Table 20: Pre-Operational Self-Tests The pre-operational software integrity tests are performed automatically when the module is powered on, before the module transitions into the operational state.

10.2 Conditional Self-Tests

© 2025 Ctrl IQ, Inc., atsec information security.

Page 48
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
X9.42 KDFSHA-1KATCASTModule becomes operationalKey derivationAt power-on, before the integrity test
X9.63 KDFSHA2-256KATCASTModule becomes operationalKey derivationAt power-on, before the integrity test
SSH KDFSHA-1KATCASTModule becomes operationalKey derivationAt power-on, before the integrity test
TLS 1.2 KDFSHA2-256KATCASTModule becomes operationalKey derivationAt power-on, before the integrity test
TLS 1.3 KDFSHA2-256KATCASTModule becomes operationalKey derivationAt power-on, before the integrity test
PBKDF2SHA-256 with 4096 iterations, 24-byte password, and 288-bit saltKATCASTModule becomes operationalKey derivationAt power-on, before the integrity test
Counter DRBGAES-128 with prediction resistance, with derivation functionKATCASTModule becomes operationalInstantiate, seed, generate, reseed, generate (compliant to SP 800-90Ar1 Section 11.3)At power-on, before the integrity test
Hash DRBGSHA2-256 with prediction resistanceKATCASTModule becomes operationalInstantiate, seed, generate, reseed, generate (compliant to SP 800-90Ar1 Section 11.3)At power-on, before the integrity test
HMAC DRBGHMAC-SHA-1 with prediction resistanceKATCASTModule becomes operationalInstantiate, seed, generate, reseed, generate (compliant to SP 800-90Ar1 Section 11.3)At power-on, before the integrity test
KAS-FFC- SSCffdhe2048KATCASTModule becomes operationalShared secret computationAt power-on, before the integrity test
KAS-ECC- SSCP-256KATCASTModule becomes operationalShared secret computationAt power-on, before the integrity test
ECDSA SigGen (FIPS186-5)SHA-256 and P-224, P-256, P-384, P-521KATCASTModule becomes operationalSignature generationAt power-on, before the integrity test
ECDSA SigVer (FIPS186-5)SHA-256 and P-224, P-256, P-384, P-521KATCASTModule becomes operationalSignature verificationAt power-on, before the integrity test

© 2025 Ctrl IQ, Inc., atsec information security.

Page 49
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
EdDSA SigGenEd25519, Ed448KATCASTModule becomes operationalSignature generationAt power-on, before the integrity test
EdDSA SigVerEd25519, Ed448KATCASTModule becomes operationalSignature verificationAt power-on, before the integrity test
RSA PKCS#1 v1.5 SigGenSHA-256 and 2048-bit keyKATCASTModule becomes operationalSignature generationAt power-on, before the integrity test
RSA PKCS#1 v1.5 SigVerSHA-256 and 2048-bit keyKATCASTModule becomes operationalSignature verificationAt power-on, before the integrity test
DHN/APCTPCTKey pair generation is successfulSP 800-56Ar3 Section 5.6.2.1.4Key pair generation
ECDSA KeyGen (FIPS186-5)SHA2-256PCTPCTKey pair generation is successfulSignature generation and verificationKey pair generation
EdDSA KeyGenN/APCTPCTKey pair generation is successfulSignature generation and verificationKey pair generation
RSA PKCS#1 v1.5 KeyGenSHA2-256PCTPCTKey pair generation is successfulSignature generation and verificationKey pair generation
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2-256Message authenticationSW/FW IntegrityOn demandManually
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-GCM - EncryptionKATCASTOn demandManually
AES-GCM - DecryptionKATCASTOn demandManually
AES-ECBKATCASTOn demandManually
SHA-1KATCASTOn demandManually
SHA2-512KATCASTOn demandManually
SHA3-256KATCASTOn demandManually
KBKDFKATCASTOn demandManually
KDA OneStepKATCASTOn demandManually
KDA HKDFKATCASTOn demandManually
X9.42 KDFKATCASTOn demandManually

Table 21: Conditional Self-Tests

10.3 Periodic Self-Test Information

Table 22: Pre-Operational Periodic Information © 2025 Ctrl IQ, Inc., atsec information security.

Page 50
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
X9.63 KDFKATCASTOn demandManually
SSH KDFKATCASTOn demandManually
TLS 1.2 KDFKATCASTOn demandManually
TLS 1.3 KDFKATCASTOn demandManually
PBKDF2KATCASTOn demandManually
Counter DRBGKATCASTOn demandManually
Hash DRBGKATCASTOn demandManually
HMAC DRBGKATCASTOn demandManually
KAS-FFC-SSCKATCASTOn demandManually
KAS-ECC-SSCKATCASTOn demandManually
ECDSA SigGen (FIPS186-5)KATCASTOn demandManually
ECDSA SigVer (FIPS186-5)KATCASTOn demandManually
EdDSA SigGenKATCASTOn demandManually
EdDSA SigVerKATCASTOn demandManually
RSA PKCS#1 v1.5 SigGenKATCASTOn demandManually
RSA PKCS#1 v1.5 SigVerKATCASTOn demandManually
DHPCTPCTOn demandManually
ECDSA KeyGen (FIPS186-5)PCTPCTOn demandManually
EdDSA KeyGenPCTPCTOn demandManually
RSA PKCS#1 v1.5 KeyGenPCTPCTOn demandManually
NameDescriptionConditionsRecovery MethodIndicator
Power- up errorAn error occurred during the self- tests executed on power-upSoftware integrity test failure CAST failureModule reinitializationModule will not load (OSSL_PROV_PARAM_STATUS is set to 0)
PCT errorAn error occurred during a PCTPCT failureModule reinitializationModule stops functioning (aborts)

Table 23: Conditional Periodic Information

10.4 Error States

Table 24: Error States In any error state, the output interface is inhibited, and the module accepts no more inputs or requests (as the module is no longer running).

10.5 Operator Initiation of Self-Tests

The pre-operational self-tests and CASTs can be invoked on demand by unloading and subsequently reinitializing the module. The PCTs can be invoked on demand by requesting the key pair generation service. © 2025 Ctrl IQ, Inc., atsec information security.

Page 51
11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

Before the openssl-fips-provider-so-3.0.7-27.el9_2.ciqfips.0.2.7.x86_64 RPM package is installed, the Rocky Linux 9 system must operate in the FIPS validated configuration. This can be achieved by:

11.2 Administrator Guidance

After installation of the openssl-fips-provider-so-3.0.7-27.el9_2.ciqfips.0.2.7.x86_64 RPM package, the Crypto Officer must execute the “openssl list -providers” command. The Crypto Officer must ensure that the FIPS provider is listed in the output as follows: fips name: Rocky Linux 9 - OpenSSL FIPS Provider version: Rocky9.20250210 status: active The cryptographic boundary consists only of the FIPS provider as listed. If any other OpenSSL or thirdparty provider is invoked, the user is not interacting with the module specified in this Security Policy.

11.3 Non-Administrator Guidance

There is no non-administrator guidance.

11.4 Design and Rules
11.5 Maintenance Requirements
11.6 End of Life

As the module does not persistently store SSPs, secure sanitization of the module consists of unloading the module. This will zeroize all SSPs in volatile memory. Then, if desired, the openssl-fips-provider-so3.0.7-27.el9_2.ciqfips.0.2.7.x86_64 RPM package can be uninstalled from the Rocky Linux 9 system. © 2025 Ctrl IQ, Inc., atsec information security.

Page 52
12 Mitigation of Other Attacks

Certain cryptographic subroutines and algorithms are vulnerable to timing analysis. The module mitigates this vulnerability by using constant-time implementations. This includes, but is not limited to:

Page 53
Table, extracted as text (did not parse into structured rows)
A Glossary and Abbreviations AES                        Advanced Encryption Standard API                        Application Programming Interface CAST                       Cryptographic Algorithm Self-Test CAVP                       Cryptographic Algorithm Validation Program CBC                        Cipher Block Chaining CBC-CS                     Cipher Block Chaining with Ciphertext Stealing CCM                        Counter with Cipher Block Chaining-Message Authentication Code CFB                        Cipher Feedback CKG                        Cryptographic Key Generation CMAC                       Cipher-based Message Authentication Code CMVP                       Cryptographic Module Validation Program CSP                        Critical Security Parameter CTR                        Counter CVL                        Component Validation List DH                         Diffie-Hellman DRBG                       Deterministic Random Bit Generator EC                         Elliptic Curve ECB                        Electronic Code Book ECC                        Elliptic Curve Cryptography ECDH                       Elliptic Curve Diffie-Hellman ECDSA                      Elliptic Curve Digital Signature Algorithm EdDSA                      Edwards Curve Digital Signature Algorithm ESV                        Entropy Source Validation EVP                        Envelope FFC                        Finite Field Cryptography FIPS                       Federal Information Processing Standards GCM                        Galois Counter Mode GMAC                       Galois Counter Mode Message Authentication Code HKDF                       HMAC-based Key Derivation Function HMAC                       Keyed-Hash Message Authentication Code IFC                        Integer Factorization Cryptography IG                         Implementation Guidance IKE                        Internet Key Exchange IV                         Initialization Vector KAS                        Key Agreement Scheme KAT                        Known Answer Test KBKDF                      Key-based Key Derivation Function KDA                        Key Derivation Algorithm KDF                        Key Derivation Function KTS                        Key Transport Scheme KW                         Key Wrap KWP                        Key Wrap with Padding MAC                        Message Authentication Code NIST                       National Institute of Science and Technology OAEP                       Optimal Asymmetric Encryption Padding OFB                        Output Feedback PAA                        Processor Algorithm Acceleration PBKDF                      Password-Based Key Derivation Function PCT                        Pair-wise Consistency Test PKCS                       Public-Key Cryptography Standards PSP                        Public Security Parameter PSS                        Probabilistic Signature Scheme RSA                        Rivest Shamir Adleman © 2025 Ctrl IQ, Inc., atsec information security.
Page 54
Table, extracted as text (did not parse into structured rows)
SHA                        Secure Hash Algorithm SSC                        Shared Secret Computation SSH                        Secure Shell SSP                        Sensitive Security Parameter TOEPP                      Tested Operational Environment’s Physical Perimeter XOF                        Extendable Output Function XTS                        XEX-based Tweaked-codebook mode with cipher text Stealing © 2025 Ctrl IQ, Inc., atsec information security.
Page 55

B References ANSI X9.42-2001 Public Key Cryptography for the Financial Services Industry: Agreement of Symmetric Keys Using Discrete Logarithm Cryptography 2001 https://webstore.ansi.org/standards/ascx9/ansix9422001 ANSI X9.63-2001 Public Key Cryptography for the Financial Services Industry, Key Agreement and Key Transport Using Elliptic Curve Cryptography 2001 https://webstore.ansi.org/standards/ascx9/ansix9632001 FIPS 140-3 Security Requirements For Cryptographic Modules March 2019 https://doi.org/10.6028/NIST.FIPS.140-3 FIPS 140-3 IG Implementation Guidance for FIPS PUB 140-3 and the Cryptographic Module Validation Program https://csrc.nist.gov/CSRC/media/Projects/cryptographic-module-validationprogram/documents/fips%20140-3/FIPS%20140-3%20IG.pdf FIPS 180-4 Secure Hash Standard (SHS) August 2015 https://doi.org/10.6028/NIST.FIPS.180-4 FIPS 186-2 Digital Signature Standard (DSS) January 2000 https://doi.org/10.6028/NIST.FIPS.186-2 FIPS 186-4 Digital Signature Standard (DSS) July 2013 https://doi.org/10.6028/NIST.FIPS.186-4 FIPS 186-5 Digital Signature Standard (DSS) February 2023 https://doi.org/10.6028/NIST.FIPS.186-5 FIPS 197 Advanced Encryption Standard (AES) November 2001; Updated May 2023 https://doi.org/10.6028/NIST.FIPS.197-upd1 FIPS 198-1 The Keyed-Hash Message Authentication Code (HMAC) July 2008 https://doi.org/10.6028/NIST.FIPS.198-1 FIPS 202 SHA-3 Standard: Permutation-Based Hash and Extendable- Output Functions August 2015 https://doi.org/10.6028/NIST.FIPS.202 PKCS#1 PKCS #1: RSA Cryptography Specifications Version 2.2 November 2016 https://doi.org/10.17487/RFC8017 RFC 3526 More Modular Exponential (MODP) Diffie-Hellman groups for Internet Key Exchange (IKE) May 2003 https://doi.org/10.17487/RFC3526 RFC 4253 The Secure Shell (SSH) Transport Layer Protocol January 2006 https://doi.org/10.17487/RFC4253 RFC 5288 AES Galois Counter Mode (GCM) Cipher Suites for TLS August 2008 https://doi.org/10.17487/RFC5288 RFC 7627 Transport Layer Security (TLS) Session Hash and Extended Master Secret Extension September 2015 © 2025 Ctrl IQ, Inc., atsec information security.

Page 56

https://doi.org/10.17487/RFC7627 RFC 7919 Negotiated Finite Field Diffie-Hellman Ephemeral Parameters for Transport Layer Security (TLS) August 2016 https://doi.org/10.17487/RFC7919 RFC 8446 The Transport Layer Security (TLS) Protocol Version 1.3 August 2018 https://doi.org/10.17487/RFC8446 SP 800-38A Recommendation for Block Cipher Modes of Operation: Methods and Techniques December 2001 https://doi.org/10.6028/NIST.SP.800-38A SP 800-38A-Add Recommendation for Block Cipher Modes of Operation: Three Variants of Ciphertext Stealing for CBC Mode October 2010 https://doi.org/10.6028/NIST.SP.800-38A-Add SP 800-38B Recommendation for Block Cipher Modes of Operation: the CMAC Mode for Authentication May 2005; Updated October 2016 https://doi.org/10.6028/NIST.SP.800-38B SP 800-38C Recommendation for Block Cipher Modes of Operation: the CCM Mode for Authentication and Confidentiality May 2004; Updated July 2007 https://doi.org/10.6028/NIST.SP.800-38C SP 800-38D Recommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC November 2007 https://doi.org/10.6028/NIST.SP.800-38D SP 800-38E Recommendation for Block Cipher Modes of Operation: the XTS-AES Mode for Confidentiality on Storage Devices January 2010 https://doi.org/10.6028/NIST.SP.800-38E SP 800-38F Recommendation for Block Cipher Modes of Operation: Methods for Key Wrapping December 2012 https://doi.org/10.6028/NIST.SP.800-38F SP 800-52r2 Guidelines for the Selection, Configuration, and Use of Transport Layer Security (TLS) Implementations August 2019 https://doi.org/10.6028/NIST.SP.800-52r2 SP 800-56Ar3 Recommendation for Pair-Wise Key Establishment Schemes Using Discrete Logarithm Cryptography April 2018 https://doi.org/10.6028/NIST.SP.800-56Ar3 SP 800-56Br2 Recommendation for Pair-Wise Key Establishment Schemes Using Discrete Logarithm Cryptography March 2019 https://doi.org/10.6028/NIST.SP.800-56Br2 SP 800-56Cr2 Recommendation for Key-Derivation Methods in Key-Establishment Schemes August 2020 https://doi.org/10.6028/NIST.SP.800-56Cr2 SP 800-90Ar1 Recommendation for Random Number Generation Using Deterministic Random Bit Generators June 2015 © 2025 Ctrl IQ, Inc., atsec information security.

Page 57

https://doi.org/10.6028/NIST.SP.800-90Ar1 SP 800-90B Recommendation for the Entropy Sources Used for Random Bit Generation January 2018 https://doi.org/10.6028/NIST.SP.800-90B SP 800-108r1 Recommendation for Key Derivation Using Pseudorandom Functions August 2022 https://doi.org/10.6028/NIST.SP.800-108r1-upd1 SP 800-131Ar2 Transitioning the Use of Cryptographic Algorithms and Key Lengths Marcy 2019 https://doi.org/10.6028/NIST.SP.800-131Ar2 SP 800-132 Recommendation for Password-Based Key Derivation - Part 1: Storage Applications December 2010 https://doi.org/10.6028/NIST.SP.800-132 SP 800-133r2 Recommendation for Cryptographic Key Generation June 2020 https://doi.org/10.6028/NIST.SP.800-133r2 SP 800-135r1 Recommendation for Existing Application-Specific Key Derivation Functions December 2011 https://doi.org/10.6028/NIST.SP.800-135r1 SP 800-140Br1 Cryptographic Module Validation Program (CMVP) Security Policy Requirements: CMVP Validation Authority Updates to ISO/IEC 24759 and ISO/IEC 19790 Annex B November 2023 https://doi.org/10.6028/NIST.SP.800-140Br1 © 2025 Ctrl IQ, Inc., atsec information security.