[Updated 12-19-2016] -- Module Drop Policy
[Updated 06-01-2016][11-12-2015] -- Validation Sunsetting Policy
The CMVP is adopting a five year validation sunsetting policy, effective February 1, 2017. The CMVP will move all validation entries with most recent validation dates** prior to February 1, 2012 and all FIPS 140-1 validation entries from the Active Validation Lists to the Historical Validation List. The Historical Validation List is not to be used for procurement by federal agencies. To maintain compliance with FISMA, agencies that use modules on the Historical List must make a risk management decision whether to continue to use these modules or replace them with compliant modules from the Active Validation Lists.
Through January 31, 2017, vendors may reinstate affected modules in one of the following ways:
Â
**[Note: The most recent validation date for a module is the latest update of the validation certificate as the result of the original submission or any of the available revalidation scenarios (1SUB, 2SUB, 4SUB).]
[12-09-2015] -- Two-key TDEA transition, December 31, 2015
The Cryptographic Technology Group at NIST has confirmed the transition schedule for the Two-key TDEA provided in SP 800-131A. The CMVP will enforce the transition proactively. Accordingly, when the transition takes place the CMVP will proceed as follows:
Â
Â
[Updated 7-1-2016][Updated 11-24-2015][Updated 11-10-2015][03-16-2015] -- X9.31 RNG transition, December 31, 2015
The Cryptographic Technology Group at NIST has confirmed the transition schedule for RNGs (e.g., the X9.31 RNG) provided in SP 800-131A. Accordingly, when the transition takes place the CMVP will proceed as follows:
The CMVP will move all Category 3 and 4 modules to a Legacy Validation List, effective January 31, 2016. The Legacy Validation List is not to be used for procurement by federal agencies. However, impacted vendors who can substantiate a hardship case as the result of this deadline are encouraged to contact the CMVP as early as possible. The CMVP will work with them to minimize the negative impact.
The CMVP will provide vendors with a voluntary process for updating Category 3 and 4 modules on the Legacy Validation List and reinstating them back on the Active Validation Lists:
Â
The CMVP will move all Category 3 and 4 modules to a Legacy Validation List, effective January 31, 2016. The Legacy Validation List is not to be used for procurement by federal agencies. However, impacted vendors who can substantiate a hardship case as the result of this deadline are encouraged to contact the CMVP as early as possible. The CMVP will work with them to minimize the negative impact.
The CMVP will provide vendors with a voluntary process for updating Category 3 and 4 modules on the Legacy Validation List and reinstating them back on the Active Validation Lists:
Â
Â
++[Note:To take advantage of the 1SUB-like process vendors shall work with an accredited CST laboratory. The laboratory shall follow the procedure below:
[08-12-2015] -- NIST requests comments on using the ISO/IEC 19790:2012 standard as the U.S. Federal Standard for cryptographic modules
NIST is seeking public comments on using International Organization for Standardization/International Electrotechnical Commission (ISO/IEC) standards for cryptographic algorithm and cryptographic module testing, conformance, and validation activities, currently specified by Federal Information Processing Standard (FIPS) 140-2. The National Technology Transfer and Advancement Act (NTTAA), Public Law 104-113, directs federal agencies to adopt voluntary consensus standards wherever possible. The responses to this request for information will be used to plan possible changes to the FIPS or in a decision to use all or part of ISO/IEC 19790:2012 for testing, conformance and validation of cryptographic algorithms and modules. The Request for Information (RFI) posted in today’s Federal Register provides additional background, including seven questions that NIST is especially interested in having addressed, as well as NIST’s intentions.
Send public comments to: UseOfISO@nist.gov (also see the address for sending written comments)
Comment period closes: September 28, 2015.
**[Note: in the official RFI in the Federal Register Notice,
the link to the ISO site is incorrect; it should link to
http://www.iso.org/iso/catalogue_detail.htm?csnumber=52906 instead.]
[03-13-2015] -- The Third International Cryptographic Module Conference
The third annual International Cryptographic Module Conference will take place in November of this year. ICMC is a growing forum for global expertise in commercial cryptography. Industry leaders will convene November 4-6, 2015 in Hilton Washington, D.C., Rockville, MD to address the unique challenges faced by those who produce, use, and test cryptographic modules that conform with standards such as FIPS 140-2 and ISO/IEC 19790. Visit ICMC 2015 for complete information.
[Updated 12-09-2014][Updated 08-01-2014][Updated 06-05-2014][Updated 06-07-2007][Updated 01-24-2007][Updated 10-19-2006][Updated 04-19-2006][Updated 01-28-2003][07-18-2002] -- NIST CMVP Fees:
Cost recovery fees are collected for NIST CMVP report review of new module submissions, modified module submissions, and for report reviews that require additional time due to complexity or quality. These fees are referred to as Cost Recovery (CR) and Extended Cost Recovery (ECR). Modules are not validated unless all applicable fees have been collected by NIST Billing. Please see the CMVP Management Manual or CMVP FAQ for further information.
Currently the CR fee is applicable for IG G.8 Scenarios 1A, 1B and 5; the CR fee is not applicable for IG G.8 Scenario's 1, 2, 3 and 4. The ECR fee is applicable per the overall Security Level to all test reports received by NIST CMVP under FIPS 140-2 IG G.8 (all five scenarios).
The current fee structure is as follows:
The CMVP review of report documents will not begin for new report submissions received after September 30, 2014 until the applicable CR fee is collected by NIST Billing. NIST Billing will invoice the CR fee when the submission documents are received. Modules are not validated unless all applicable fees (CR and ECR) have been collected by NIST Billing.
For questions about methods of payments and associated handling fees, contact NIST Billing: Phone: 301-975-3880, FAX: 301-975-8943 and e-mail: billing@nist.gov.
[04-24-2014] -- Heartbleed Vulnerability
Reference: CVE-2014-0160 National Vulnerability Database.
The TLS and DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.
This vulnerability, which may allow the reading of a cryptographic modules private keys, would violate FIPS 140-2 functional security objectives as described in Section 4.3. The CMVP has two objectives to meet: 1) To ensure that the CMVP does not validate any new cryptographic modules that contain this uncorrected vulnerability, and 2) To provide a process by which vendors can quickly patch and re-validate their existing cryptographic modules.
Users of validated cryptographic modules should contact the modules vendor to determine if the Heartbleed vulnerability is applicable and determine if a patch or replacement module is available.
Vendors of validated cryptographic modules for which the Heartbleed vulnerability is applicable should contact a NVLAP Cryptographic and Security Testing Laboratory to validate a corrective patch or replacement module.
[04-24-2014] -- The Second International Cryptographic Module Conference
Bringing experts together from around the world to confer on the topic of cryptographic modules. Discussion on technical topics underlying the implementation of a cryptographic module including physical security, key management, side-channel analysis, key management, cryptographic algorithm implementation testing, standardization (FIPS 140-2, ISO/IEC 19790), validation programs and more. November 19-21, 2014 in Rockville, MD. Register now. Details at: ICMC 2014
Security and Privacy: cryptography, testing & validation
Technologies: hardware, software & firmware