Skip to content

Discuss TDs 1012/1013 #94

Description

@jmcdaniels

Note SHA256 for HMAC_DRBG

In order to be listed on the NIAP PCL, evaluations against CPP_FDE_EE_V3.0 must meet the following requirements:

-Each applicable Cryptographic SFR (FCS_) must include at least one selection conforming to Commercial National Security Algorithm (CNSA) Suite V1.0 or V2.0;
ECDH 384
ECDSA 384
DH Key Exchange with minimum 3072-bit modulus
RSA with minimum 3072-bit modulus
AES-256
SHA-384 or SHA-512
ML-KEM-1024
ML-DSA-87
LMS or XMSS (LMS 256-192 preferred) for soft/firmware signature
SHA3-384 or SHA3-512 for hashing in internal hardware
-SHA-256 may be selected for key derivation and may be included in FCS_COP.1/Hash and FCS_COP.1/KeyedHash for that function;
-SHA-256 may be selected in FCS_COP.1/Hash in support of Hash_DRBG in FCS_RBG.1; and
-SHA-1 may not be selected.

Note that evaluations performed in other schemes may select algorithms not conformant to CNSA (or non-algorithmic selections, if applicable) as long as the product can be configured so as not to use those non-conformant algorithms if it wishes to be posted to the NIAP PCL. The Guidance Document must then indicate how to configure the product not to use the algorithms.

Evaluations certified by NIAP must only make CNSA-compliant selections.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

FIT IssueFor resolution by the FDE Interpretation Team.

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions