eucc-perspectives

FIPS Revalidation Scenarios: Mapping the Right Path for Your Module Changes

VanshikaCertifications, FIPS 140-3

Why the Revalidation Path You Choose Determines Your Cost, Effort and Timeline! Achieving an initial FIPS validation is a major milestone, but it may not be a one-time exercise! As products evolve through patches, new platforms, or branding updates, your cryptographic module must be revalidated to stay on the CMVP Active List. The challenge is not the update itself but choosing …

CMVP Transitions Update (July 2023)

James RamageFIPS 140-3

CMVP algorithm transitions can be a great source of anxiety for vendors who seek to attain or maintain compliance to the FIPS 140-2 and 140-3 standards. A great deal of diligence, patience and persistence are required to continually review and …

ESV and Me!

James RamageEntropy, FIPS 140-3

As of November 7, 2020, the Cryptographic Module Validation Program (CMVP) required that all FIPS 140-2 and FIPS 140-3 module validation submissions include documentation justifying conformance of the entropy source to NIST SP 800-90B, if the module is “either generating the …

OpenSSL and ACVP Parsing

Greg McLearnACVP, FIPS 140-2, Tools

OpenSSL is used in some part by an overwhelmingly large percentage of the enterprise vendor community. Those vendors which need to go through FIPS 140-2 or Common Criteria may find themselves needing to perform algorithm testing and may be presented …