Module Name
Nutanix Cryptographic Module for OpenSSL
Caveat
When operated in FIPS mode. No assurance of the minimum strength of generated keys
Security Level Exceptions
- Physical Security: N/A
- Design Assurance: Level 3
- Mitigation of Other Attacks: N/A
Embodiment
Multi-Chip Stand Alone
Description
The Nutanix Cryptographic Module for OpenSSL is a cryptographic software library, designated as a multi-chip standalone embodiment, and used in Nutanix, Inc. solutions to provide FIPS 140-2 Approved cryptographic algorithms and TLS secure communication.
Tested Configuration(s)
- CentOS 7.9 on Nutanix Acropolis Hypervisor (AHV) 7.1.1 running on a Nutanix NX-3360-G7 (CVM) with an Intel® Xeon® Gold 6234 with PAA
- CentOS 7.9 on Nutanix Acropolis Hypervisor (AHV) 7.1.1 running on a Nutanix NX-3360-G7 (CVM) with an Intel® Xeon® Gold 6234 without PAA (single-user mode)
- CentOS 7.9 running on a Nutanix NX-3360-G7 (CVM) with an Intel® Xeon® Gold 6234 with PAA
- CentOS 7.9 running on a Nutanix NX-3360-G7 (CVM) with an Intel® Xeon® Gold 6234 without PAA
Approved Algorithms
AES |
Cert. #A1403 |
CKG |
vendor affirmed |
CVL |
Cert. #A1403 |
DRBG |
Cert. #A1403 |
DSA |
Cert. #A1403 |
ECDSA |
Cert. #A1403 |
HMAC |
Cert. #A1403 |
KAS |
KAS-SSC Cert. #A1403, CVL Cert. #A1403 |
KAS-SSC |
Cert. #A1403 |
KTS |
AES Cert. #A1403; key establishment methodology provides between 128 and 256 bits of encryption strength |
KTS |
AES Cert. #A1403 and HMAC Cert. #A1403; key establishment methodology provides between 128 and 256 bits of encryption strength |
RSA |
Cert. #A1403 |
SHS |
Cert. #A1403 |
Triple-DES |
Cert. #A1403 |