Module Name
AWS OpenSSL FIPS Provider
Caveat
When operated in FIPS mode. No assurance of the minimum strength of generated keys.
Security Level Exceptions
- Physical Security: N/A
- Design Assurance: Level 3
Embodiment
Multi-Chip Stand Alone
Description
The Module is a software library providing a C-language application program interface (API) for use by applications that require cryptographic functionality. The Module is classified under FIPS 140-2 as a software module, with a multi-chip standalone module embodiment. The physical cryptographic boundary is the general-purpose computer on which the module is installed.
Tested Configuration(s)
- Amazon Linux 2 on Intel Xeon Platinum 8275CL (Cascade Lake) with PAA
- Amazon Linux 2 on Intel Xeon Platinum 8275CL (Cascade Lake) without PAA
- Amazon Linux 2 running on AWS EC2 c6g instance with AWS Graviton 2 with PAA
- Amazon Linux 2 running on AWS EC2 c6g instance with AWS Graviton 2 without PAA
- Amazon Linux 2 running on AWS EC2 c7g instance with AWS Graviton 3 with PAA
- Amazon Linux 2 running on AWS EC2 c7g instance with AWS Graviton 3 without PAA
- Amazon Linux 2023 on Intel Xeon Platinum 8275CL (Cascade Lake) with PAA
- Amazon Linux 2023 on Intel Xeon Platinum 8275CL (Cascade Lake) without PAA
- Amazon Linux 2023 running on AWS EC2 c6g instance with AWS Graviton 2 with PAA
- Amazon Linux 2023 running on AWS EC2 c6g instance with AWS Graviton 2 without PAA
- Amazon Linux 2023 running on AWS EC2 c7g instance with AWS Graviton 3 with PAA
- Amazon Linux 2023 running on AWS EC2 c7g instance with AWS Graviton 3 without PAA
- Debian 11.5 running on Dell Inspiron 7591 with Intel i7(x64) with PAA
- Debian 11.5 running on Dell Inspiron 7591 with Intel i7(x64) without PAA
- FreeBSD 13.1 running on Dell Inspiron 7591 with Intel i7(x64) with PAA
- FreeBSD 13.1 running on Dell Inspiron 7591 with Intel i7(x64) without PAA
- macOS 11.5.2 running on Apple i7 Mac Mini with Intel i7(x64) with PAA
- macOS 11.5.2 running on Apple i7 Mac Mini with Intel i7(x64) without PAA
- macOS 11.5.2 running on Apple M1 Mac Mini with M1 with PAA
- macOS 11.5.2 running on Apple M1 Mac Mini with M1 without PAA
- Ubuntu Linux 22.04.1 LTS running on Dell Inspiron 7591 with Intel i7(x64) with PAA
- Ubuntu Linux 22.04.1 LTS running on Dell Inspiron 7591 with Intel i7(x64) without PAA
- Windows 10 running on Dell Inspiron 7591 with Intel i7(x64) with PAA
- Windows 10 running on Dell Inspiron 7591 with Intel i7(x64) without PAA (single-user mode)
Approved Algorithms
| AES |
Certs. #A4086 and #A6725 |
| CKG |
vendor affirmed |
| CVL |
Certs. #A4086 and #A6725 |
| DRBG |
Certs. #A4086 and #A6725 |
| DSA |
Certs. #A4086 and #A6725 |
| ECDSA |
Certs. #A4086 and #A6725 |
| HMAC |
Certs. #A4086 and #A6725 |
| KAS-RSA-SSC |
Certs. #A4086 and #A6725 |
| KAS-SSC |
Certs. #A4086 and #A6725 |
| KBKDF |
Certs. #A4086 and #A6725 |
| KDA |
Certs. #A4086 and #A6725 |
| KMAC |
Certs. #A4086 and #A6725 |
| KTS |
AES Certs. #A4086 and #A6725; key establishment methodology provides between 128 and 256 bits of encryption strength |
| KTS |
AES Certs. #A4086 and #A6725 and AES Certs. #A4086 and #A6725; key establishment methodology provides between 128 and 256 bits of encryption strength |
| KTS |
AES Certs. #A4086 and #A6725 and HMAC Certs. #A4086 and #A6725; key establishment methodology provides between 128 and 256 bits of encryption strength |
| KTS |
Triple-DES Certs. #A4086 and #A6725 and HMAC Certs. #A4086 and #A6725; key establishment methodology provides 112 bits of encryption strength |
| KTS-RSA |
Certs. #A4086 and #A6725; key establishment methodology provides between 112 and 256 bits of encryption strength |
| PBKDF |
Certs. #A4086 and #A6725 |
| RSA |
Certs. #A4086 and #A6725 |
| SHA-3 |
Certs. #A4086 and #A6725 |
| SHS |
Certs. #A4086 and #A6725 |
| Triple-DES |
Certs. #A4086 and #A6725 |