NSSCryptoModuleSpec/Section 9: Self Tests: Difference between revisions

From MozillaWiki
Jump to navigation Jump to search
mNo edit summary
mNo edit summary
Line 13: Line 13:
|-
|-
|  
|  
'''List every error state & error indicator''' - Document all error states associated with each self-test, and indicate for each error state the expected error indicator.
'''List every error state & error indicator'''  
- Document all error states associated with  
each self-test, and indicate for each error  
state the expected error indicator.
|| [http://wiki.mozilla.org/VE_09#VE.09.04.01 VE.09.04.01 ] ||  
|| [http://wiki.mozilla.org/VE_09#VE.09.04.01 VE.09.04.01 ] ||  
{| border="1" cellpadding="2"
{| border="1" cellpadding="2"
|+
|+
|-
|-
|'''CKR_USER_NOT_LOGGED_IN''' || User has not logged in by supplying their password to the FIPS-140-1 PKCS#11 module.
|'''CKR_USER_NOT_LOGGED_IN''' || User has not logged  
in by supplying their password to the  
FIPS-140-2 PKCS#11 module.
|-  
|-  
|'''CKR_DEVICE_ERROR''' ||  Crypographic operation failure
|'''CKR_DEVICE_ERROR''' ||  Crypographic operation failure
Line 30: Line 35:
|  
|  
'''Module in Error State''':
'''Module in Error State''':
Ensure that cryptographic operations cannot be performed while the module is in the error state. See VE02.06.01 for the vendor design requirement.
Ensure that cryptographic operations cannot
be performed while the module is in the  
error state. See VE02.06.01 for the vendor  
design requirement.
||  
||  
[http://wiki.mozilla.org/VE_09#VE.09.05.01 VE.09.05.01 ]  [http://wiki.mozilla.org/VE_09#VE.09.06.01 VE.09.06.01 ]  
[http://wiki.mozilla.org/VE_09#VE.09.05.01 VE.09.05.01 ]  [http://wiki.mozilla.org/VE_09#VE.09.06.01 VE.09.06.01 ]  
||  
||  
'''Power-up Self Test''':
'''Power-up Self Test''':
[http://www.mozilla.org/projects/security/pki/nss/fips/nss-source/mozilla/security/nss/lib/softoken/fipstokn.c.html#FC_Initialize PKCS#11 Initialization]: As part of the PKCS#11 initialization of the FIPS-140-2 module, any error return
[http://www.mozilla.org/projects/security/pki/nss/fips/nss-source/mozilla/security/nss/lib/softoken/fipstokn.c.dep.html#FC_Initialize 'PKCS#11 Initialization']:  
from the battery of self tests will put the PKCS#11
As part of the PKCS#11 initialization of the  
module in the fatalError state. The fatalError state
FIPS-140-2 module, any error return
will inhibit further cryptographic operations.
from the battery of self tests will put the  
PKCS#11 module in the fatalError state.  
The fatalError state will inhibit further  
cryptographic operations.
||
||
|-
|-
|
|
'''List of mandatory & optional self-tests performed by the module''' - Provide a list of all self-tests, both mandatory and optional, that the module can perform. This list must include both power-up tests and conditional tests.  
'''List of mandatory & optional self-tests  
performed by the module''' - Provide a list  
of all self-tests, both mandatory and optional,  
that the module can perform. This list must  
include both power-up tests and conditional  
tests.  
||  
||  
[http://wiki.mozilla.org/VE_09#VE.09.07.01 VE.09.07.01 ]  
[http://wiki.mozilla.org/VE_09#VE.09.07.01 VE.09.07.01 ]  
Line 63: Line 79:
and resume normal operation.'''  
and resume normal operation.'''  
|| [http://wiki.mozilla.org/VE_09#VE.09.07.02 VE.09.07.02 ] ||  
|| [http://wiki.mozilla.org/VE_09#VE.09.07.02 VE.09.07.02 ] ||  
 
For fatal error conditions CKR_DEVICE_ERROR  
For fatal error conditions CKR_DEVICE_ERROR and CKR_HOST_MEMORY
and CKR_HOST_MEMORY the only way to clear  
the only way to clear the condition is to reboot the module. Upon
the condition is to reboot the module. Upon
restart the power-up tests shall be initiated automatically
restart the power-up tests shall be  
and do not require operator intervention.   
initiated automatically and does not require
operator intervention.   
||
||
|-
|-
|  
|  
'''Describe self-test initiation on demand''' requires that the running of power-up self-tests not involve any inputs from or actions by the operator.
'''Describe self-test initiation on demand'''
requires that the running of power-up  
self-tests not involve any inputs from  
actions by the operator.
|| [http://wiki.mozilla.org/VE_09#VE.09.09.01 VE.09.09.01 ] ||
|| [http://wiki.mozilla.org/VE_09#VE.09.09.01 VE.09.09.01 ] ||
 
'''The products will not have a user  
'''The products will not have a user visible way to initiate
visible way to initiate these tests  
these tests other than restarting the program.'''
other than restarting the program.'''
||
||
|-
|-
|  
|  
'''Document cryptographic algorithm's known answer test:'''
'''Document cryptographic algorithm's known  
The vendor shall document the indicator that the module outputs upon
answer test''' The vendor shall document the
indicator that the module outputs upon
successful completion of the power-up self-tests.
successful completion of the power-up self-tests.
|| [http://wiki.mozilla.org/VE_09#VE.09.10.01 VE.09.10.01 ] ||
|| [http://wiki.mozilla.org/VE_09#VE.09.10.01 VE.09.10.01 ] ||


[http://www.mozilla.org/projects/security/pki/nss/fips/nss-source/mozilla/security/nss/lib/softoken/fipstokn.c.html Power Up Self Test Code] This is demonstrated throughout
[http://www.mozilla.org/projects/security/pki/nss/fips/nss-source/mozilla/security/nss/lib/softoken/fipstokn.c.html Power Up Self Test Code] This is  
the self test module. Each of the following functions declares
demonstrated throughout the self test
static key material at the beginning of each test and upon  
module. Each of the following functions
declares static key material at the  
beginning of each test and upon  
successful completion returns CKR_OK:
successful completion returns CKR_OK:


Line 112: Line 135:
'''The products will not have a user visible way to initiate
'''The products will not have a user visible way to initiate
these tests other than restarting the program.'''
these tests other than restarting the program.'''
||
||
|-
|-
Line 118: Line 140:
'''All self tests shall use a known answer'''.  
'''All self tests shall use a known answer'''.  
|| [http://wiki.mozilla.org/VE_09#VE.09.13.01 VE.09.13.01 ] ||
|| [http://wiki.mozilla.org/VE_09#VE.09.13.01 VE.09.13.01 ] ||
a known answer is shall be conducted for all cryptographic functions (e.g., encryption, decryption, authentication and random number generation) of each Approved cryptographic algorithm self test.
a known answer is shall be conducted for
all cryptographic functions (e.g., encryption,  
decryption, authentication and random  
number generation) of each Approved  
cryptographic algorithm self test.
||
||
|-
|-
|  
|  


'''If the calculated output does not equal the known answer, the known-answer test shall fail.'''
'''If the calculated output does not  
equal the known answer, the  
known-answer test shall fail.'''
|| [http://wiki.mozilla.org/VE_09#VE.09.16.01 VE.09.16.01 ] ||  
|| [http://wiki.mozilla.org/VE_09#VE.09.16.01 VE.09.16.01 ] ||  


CKR_DEVICE_ERROR is returned when ever the calculated output does not equal  
CKR_DEVICE_ERROR is returned when  
the known answer.  
ever the calculated output does not  
equal the known answer.  


||
||
|-
|-
|  
|  
'''specify the method used to compare the calculated output with the known answer.'''
'''specify the method used to compare the  
calculated output with the known answer.'''
|| [http://wiki.mozilla.org/VE_09#VE.09.17.01 VE.09.17.01 ] ||  
|| [http://wiki.mozilla.org/VE_09#VE.09.17.01 VE.09.17.01 ] ||  


PORT_Memcmp is used to compare the computed cipher text with the known
PORT_Memcmp is used to compare the computed  
ciphertext.  
cipher text with the known ciphertext.  
[http://www.mozilla.org/projects/security/pki/nss/fips/nss-source/mozilla/security/nss/lib/softoken/fipstest.c.dep.html                      sftk_fipsPowerUpSelfTest]
[http://www.mozilla.org/projects/security/pki/nss/fips/nss-source/mozilla/security/nss/lib/softoken/fipstest.c.dep.html                      sftk_fipsPowerUpSelfTest]
When keys are used for encryption/decryption the  
When keys are used for encryption/decryption  
[http://www.mozilla.org/projects/security/pki/nss/fips/nss-source/mozilla/security/nss/lib/softoken/pkcs11c.c.dep.html#sftk_PairwiseConsistencyCheck  'Pairwise Consistency Check Self Tests'] are used.  
the [http://www.mozilla.org/projects/security/pki/nss/fips/nss-source/mozilla/security/nss/lib/softoken/pkcs11c.c.dep.html#sftk_PairwiseConsistencyCheck  'Pairwise Consistency Check Self Tests']  
are used.  
||
||
|-
|-

Revision as of 23:11, 16 September 2005

Document Description

 DTR 

Section

Assesment

Status

List every error state & error indicator - Document all error states associated with each self-test, and indicate for each error state the expected error indicator.

VE.09.04.01
CKR_USER_NOT_LOGGED_IN User has not logged

in by supplying their password to the FIPS-140-2 PKCS#11 module.

CKR_DEVICE_ERROR Crypographic operation failure
CKR_HOST_MEMORY Memory allocation failure
CKR_OK Success, no error

Module in Error State: Ensure that cryptographic operations cannot be performed while the module is in the error state. See VE02.06.01 for the vendor design requirement.

VE.09.05.01 VE.09.06.01

Power-up Self Test: 'PKCS#11 Initialization': As part of the PKCS#11 initialization of the FIPS-140-2 module, any error return from the battery of self tests will put the PKCS#11 module in the fatalError state. The fatalError state will inhibit further cryptographic operations.

List of mandatory & optional self-tests performed by the module - Provide a list of all self-tests, both mandatory and optional, that the module can perform. This list must include both power-up tests and conditional tests.

VE.09.07.01

[http://www.mozilla.org/projects/security/pki/nss/fips/nss-source/mozilla/security/nss/lib/softoken/fipstest.c.html Power up Self Test Code]

Power up SelfTest Design

No operator call backs have been implemented at any point within the power-up self tests. These tests are mandatory for the FIPS-140-2 mode of operation.

For each error condition, document the actions neccessary to clear the condition and resume normal operation.

VE.09.07.02

For fatal error conditions CKR_DEVICE_ERROR and CKR_HOST_MEMORY the only way to clear the condition is to reboot the module. Upon restart the power-up tests shall be initiated automatically and does not require operator intervention.

Describe self-test initiation on demand requires that the running of power-up self-tests not involve any inputs from actions by the operator.

VE.09.09.01

The products will not have a user visible way to initiate these tests other than restarting the program.

Document cryptographic algorithm's known answer test The vendor shall document the indicator that the module outputs upon successful completion of the power-up self-tests.

VE.09.10.01

Power Up Self Test Code This is demonstrated throughout the self test module. Each of the following functions declares static key material at the beginning of each test and upon successful completion returns CKR_OK:


sftk_fips_RC2_PowerUpSelfTest sftk_fips_RC4_PowerUpSelfTest sftk_fips_DES_PowerUpSelfTest sftk_fips_DES3_PowerUpSelfTest sftk_fips_MD2_PowerUpSelfTest sftk_fips_MD5_PowerUpSelfTest sftk_fips_SHA1_PowerUpSelfTest sftk_fips_RSA_PowerUpSelfTest sftk_fips_DSA_PowerUpSelfTest sftk_fips_AES_PowerUpSelfTest sftk_fipsPowerUpSelfTest

Procedure by which an operator can initiate the power-up self-tests

VE.09.12.01

The products will not have a user visible way to initiate these tests other than restarting the program.

All self tests shall use a known answer.

VE.09.13.01

a known answer is shall be conducted for

all cryptographic functions (e.g., encryption, 

decryption, authentication and random number generation) of each Approved cryptographic algorithm self test.

If the calculated output does not equal the known answer, the known-answer test shall fail.

VE.09.16.01

CKR_DEVICE_ERROR is returned when ever the calculated output does not equal the known answer.

specify the method used to compare the calculated output with the known answer.

VE.09.17.01

PORT_Memcmp is used to compare the computed cipher text with the known ciphertext. sftk_fipsPowerUpSelfTest When keys are used for encryption/decryption the 'Pairwise Consistency Check Self Tests' are used.

VE.09.17.02
VE.09.18.01
VE.09.18.02
VE.09.19.01
VE.09.19.02
VE.09.20.01
VE.09.20.02 (N/A)
VE.09.22.01
VE.09.22.02
VE.09.22.03
VE.09.24.01 (N/A)
VE.09.27.01
VE.09.28.01
VE.09.31.01
VE.09.32.01
VE.09.33.01
VE.09.35.01
VE.09.35.02
VE.09.40.01 (N/A)
VE.09.40.02 (N/A)
VE.09.42.01
VE.09.43.01
VE.09.45.01 (N/A)
VE.09.45.02
VE.09.46.01
VE.09.46.02 (N/A)

Return to: NSSCryptoModuleSpec