Module Name
Onclave FIPS Object Module for OpenSSL
Historical Reason
Moved to historical list due to sunsetting
Caveat
When operated in FIPS mode. No assurance of the minimum strength of generated keys.
Security Level Exceptions
- Roles, Services, and Authentication: Level 2
- Physical Security: N/A
- Design Assurance: Level 3
- Mitigation of Other Attacks: N/A
Embodiment
Multi-Chip Stand Alone
Description
The Onclave FIPS Object Module for OpenSSL is a general-purpose cryptographic module integrated in Onclave's and third-party products to provide FIPS 140-2 validated cryptography for the protection of sensitive information.
Tested Configuration(s)
- Debian 9 running on Dell PowerEdge R440 with Intel® Xeon® Silver 4214R with PAA
- Debian 9 running on Dell PowerEdge R440 with Intel® Xeon® Silver 4214R without PAA (single user mode)
Approved Algorithms
AES |
Cert. #A843 |
CKG |
vendor affirmed |
DRBG |
Cert. #A843 |
DSA |
Cert. #A843 |
ECDSA |
Cert. #A843 |
HMAC |
Cert. #A843 |
KAS-SSC |
vendor affirmed |
RSA |
Certs. #A843 |
SHS |
Cert. #A843 |
Triple-DES |
Cert. #A843 |
Allowed Algorithms
RSA (key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength)