Module Name
NetApp Cryptographic Security Module
Caveat
When operated in FIPS mode. No assurance of the minimum strength of generated keys.
Security Level Exceptions
- Physical Security: N/A
- Design Assurance: Level 3
Embodiment
Multi-Chip Stand Alone
Description
The NetApp Cryptographic Security Module is a software library that provides cryptographic services to a vast array of NetApp's storage and networking products.
Tested Configuration(s)
- (Single User Mode)
- ONTAP 9.14.1 running on a NetApp AFF A150 Intel Xeon D-1557 without PAA
- ONTAP 9.14.1 running on a NetApp AFF A150 with an Intel Xeon D-1557 with PAA (AES-NI)
- ONTAP 9.14.1 running on a NetApp AFF A320 Intel Xeon Silver 4114 with PAA (AES-NI)
- ONTAP 9.14.1 running on a NetApp AFF A320 Intel Xeon Silver 4114 without PAA
- ONTAP 9.14.1 running on a NetApp AFF A400 Intel Xeon Silver 4210 with PAA (AES-NI)
- ONTAP 9.14.1 running on a NetApp AFF A400 Intel Xeon Silver 4210 without PAA
- ONTAP 9.14.1 running on a NetApp AFF C250 Intel Xeon D-2164IT with PAA (AES-NI)
- ONTAP 9.14.1 running on a NetApp AFF C250 Intel Xeon D-2164IT without PAA
- ONTAP 9.14.1 running on a NetApp FAS2820 Intel Xeon D-1735TR with PAA (AES-NI)
- ONTAP 9.14.1 running on a NetApp FAS2820 Intel Xeon D-1735TR without PAA
- ONTAP 9.14.1 running on a NetApp FAS9500 Intel Xeon Platinum 8352Y with PAA (AES-NI)
- ONTAP 9.14.1 running on a NetApp FAS9500 Intel Xeon Platinum 8352Y without PAA
- StorageGRID 11.8 running on a NetApp SG110 Intel Xeon Silver 4310 with PAA (AES-NI)
- StorageGRID 11.8 running on a NetApp SG110 Intel Xeon Silver 4310 without PAA
- StorageGRID 11.8 running on a NetApp SG5812 Intel Xeon D-1735TR with PAA (AES-NI)
- StorageGRID 11.8 running on a NetApp SG5812 Intel Xeon D-1735TR without PAA
- StorageGRID 11.8 running on a NetApp SG6160 Intel Xeon Gold 5318Y with PAA (AES-NI)
- StorageGRID 11.8 running on a NetApp SG6160 Intel Xeon Gold 5318Y without PAA
Approved Algorithms
|
|
| AES |
Cert. #A4858 |
| CKG |
vendor affirmed |
| CVL |
Cert. #A4858 |
| DRBG |
Cert. #A4858 |
| DSA |
Cert. #A4858 |
| ECDSA |
Cert. #A4858 |
| HMAC |
Cert. #A4858 |
| KAS-RSA-SSC |
Cert. #A4858 |
| KAS-SSC |
Cert. #A4858 |
| KBKDF |
Cert. #A4858 |
| KDA |
Cert. #A4858 |
| KMAC |
Cert. #A4858 |
| KTS |
AES Cert. #A4858; key establishment methodology provides between 128 and 256 bits of encryption strength |
| KTS |
AES Cert. #A4858 and AES Cert. #A4858; key establishment methodology provides between 128 and 256 bits of encryption strength |
| KTS |
AES Cert. #A4858 and HMAC Cert. #A4858; key establishment methodology provides between 128 and 256 bits of encryption strength |
| KTS |
Triple-DES Cert. #A4858 and HMAC Cert. #A4858; key establishment methodology provides 112 bits of encryption strength |
| KTS-RSA |
Cert #A4858; key establishment methodology provides between 112 and 192 bits of encryption strength |
| PBKDF |
Cert. #A4858 |
| RSA |
Cert. #A4858 |
| SHA-3 |
Cert. #A4858 |
| SHS |
Cert. #A4858 |
| Triple-DES |
Cert. #A4858 |