From 7682fe119708ceb55219ee51ec126588fee2385d Mon Sep 17 00:00:00 2001 From: Paolo Matarazzo <74918781+paolomatarazzo@users.noreply.github.com> Date: Fri, 4 Nov 2022 08:25:46 -0400 Subject: [PATCH] updates --- .../threat-protection/fips-140-validation.md | 56 +++---------------- 1 file changed, 7 insertions(+), 49 deletions(-) diff --git a/windows/security/threat-protection/fips-140-validation.md b/windows/security/threat-protection/fips-140-validation.md index 1c66b1816e..b24bfe9bae 100644 --- a/windows/security/threat-protection/fips-140-validation.md +++ b/windows/security/threat-protection/fips-140-validation.md @@ -66,7 +66,7 @@ The following tables identify the cryptographic modules used in an operating sys ### Modules used by Windows clients -Expand each operating system section for more details. +For more details, expand each operating system section.
@@ -87,7 +87,6 @@ Validated Editions: Home, Pro, Enterprise, Education
-
Windows 10, version 1803 @@ -105,7 +104,6 @@ Validated Editions: Home, Pro, Enterprise, Education
-
Windows 10, version 1709 @@ -124,7 +122,6 @@ Validated Editions: Home, Pro, Enterprise, Education, S, Surface Hub, Mobile
-
Windows 10, version 1703 @@ -150,7 +147,6 @@ Validated Editions: Home, Pro, Enterprise, Education, S, Surface Hub, Mobile
-
Windows 10, version 1607 @@ -175,7 +171,6 @@ Validated Editions: Home, Pro, Enterprise, Enterprise LTSB, Mobile
-
Windows 10, version 1511 @@ -204,7 +199,6 @@ Validated Editions: Home, Pro, Enterprise, Enterprise LTSB, Mobile, Surface Hub
-
Windows 10, version 1507 @@ -234,7 +228,6 @@ Validated Editions: Home, Pro, Enterprise, Enterprise LTSB, Mobile, and Surface
-
Windows 8.1 @@ -254,7 +247,6 @@ Validated Editions: RT, Pro, Enterprise, Phone, Embedded
-
Windows 8 @@ -276,7 +268,6 @@ Validated Editions: RT, Home, Pro, Enterprise, Phone
-
Windows 7 @@ -295,7 +286,6 @@ Validated Editions: Windows 7, Windows 7 SP1
-
Windows Vista SP1 @@ -313,7 +303,6 @@ Validated Editions: Ultimate Edition
-
Windows Vista @@ -329,7 +318,6 @@ Validated Editions: Ultimate Edition
-
Windows XP SP3 @@ -341,7 +329,6 @@ Validated Editions: Ultimate Edition
-
Windows XP SP2 @@ -353,7 +340,6 @@ Validated Editions: Ultimate Edition
-
Windows XP SP1 @@ -363,7 +349,6 @@ Validated Editions: Ultimate Edition
-
Windows XP @@ -373,7 +358,6 @@ Validated Editions: Ultimate Edition
-
Windows 2000 SP3 @@ -384,7 +368,6 @@ Validated Editions: Ultimate Edition
-
Windows 2000 SP2 @@ -395,7 +378,6 @@ Validated Editions: Ultimate Edition
-
Windows 2000 SP1 @@ -405,7 +387,6 @@ Validated Editions: Ultimate Edition
-
Windows 2000 @@ -415,7 +396,6 @@ Validated Editions: Ultimate Edition
-
Windows 95 and Windows 98 @@ -425,7 +405,6 @@ Validated Editions: Ultimate Edition
-
Windows NT 4.0 @@ -437,7 +416,7 @@ Validated Editions: Ultimate Edition ### Modules used by Windows Server -Expand each operating system section for more details. +For more details, expand each operating system section.
@@ -458,7 +437,6 @@ Validated Editions: Standard, Datacenter
-
Windows Server, version 1803 @@ -476,7 +454,6 @@ Validated Editions: Standard, Datacenter
-
Windows Server, version 1709 @@ -495,7 +472,6 @@ Validated Editions: Standard, Datacenter
-
Windows Server 2016 @@ -514,7 +490,6 @@ Validated Editions: Standard, Datacenter, Storage Server
-
Windows Server 2012 R2 @@ -538,7 +513,6 @@ Validated Editions: Server, Storage Server,
-
Windows Server 2012 @@ -557,7 +531,6 @@ Validated Editions: Server, Storage Server |Enhanced Cryptographic Provider (RSAENH.DLL)|[6.2.9200][sp-1894]|[1894](https://csrc.nist.gov/groups/stm/cmvp/documents/140-1/1401val2013.htm#1894)|FIPS approved algorithms: AES (Cert. [#2196][aes-2196]); HMAC (Cert. [#1346][hmac-1346]); RSA (Cert. [#1132][rsa-1132]); SHS (Cert. [#1902][shs-1902]); Triple-DES (Cert. [#1386][tdes-1386])

Other algorithms: AES (Cert. [#2196][aes-2196], key wrapping; key establishment methodology provides between 128 bits and 256 bits of encryption strength); DES; MD2; MD4; MD5; RC2; RC4; RSA (key wrapping; key establishment methodology provides between 112 bits and 150 bits of encryption strength; non-compliant less than 112 bits of encryption strength); Triple-DES (Cert. [#1386][tdes-1386], key wrapping; key establishment methodology provides 112 bits of encryption strength; non-compliant less than 112 bits of encryption strength)|

-
Windows Server 2008 R2 @@ -574,7 +547,6 @@ Validated Editions: Server, Storage Server
-
Windows Server 2008 @@ -590,7 +562,6 @@ Validated Editions: Server, Storage Server
-
Windows Server 2003 SP2 @@ -602,7 +573,6 @@ Validated Editions: Server, Storage Server
-
Windows Server 2003 SP1 @@ -614,7 +584,6 @@ Validated Editions: Server, Storage Server
-
Windows Server 2003 @@ -628,6 +597,9 @@ Validated Editions: Server, Storage Server ## Other Products +For more details, expand each product section. + +
Windows Embedded Compact 7 and Windows Embedded Compact 8 @@ -638,7 +610,6 @@ Validated Editions: Server, Storage Server
-
Windows CE 6.0 and Windows Embedded Compact 7 @@ -648,7 +619,6 @@ Validated Editions: Server, Storage Server
-
Outlook Cryptographic Provider @@ -661,7 +631,7 @@ Validated Editions: Server, Storage Server ## Cryprtographic algorithms The following tables are organized by cryptographic algorithms with their modes, states, and key sizes. For each algorithm implementation (operating system / platform), there is a link to the Cryptographic Algorithm Validation Program (CAVP) issued certificate.\ -Expand each section for more details. +For more details, expand each algorithm section.
@@ -721,7 +691,6 @@ Expand each section for more details.
-
Deterministic Random Bit Generator (DRBG) @@ -750,7 +719,6 @@ Expand each section for more details.
-
Digital Signature Algorithm (DSA) @@ -784,7 +752,6 @@ Expand each section for more details.
-
Elliptic Curve Digital Signature Algorithm (ECDSA) @@ -818,7 +785,6 @@ Expand each section for more details.
-
Keyed-Hash Message Authentication Code (HMAC) @@ -867,7 +833,6 @@ Expand each section for more details.
-
Key Agreement Scheme (KAS) @@ -892,7 +857,6 @@ Expand each section for more details.
-
SP 800-108 Key-Based Key Derivation Functions (KBKDF) @@ -914,7 +878,6 @@ Expand each section for more details.
-
Random Number Generator (RNG) @@ -928,7 +891,6 @@ Expand each section for more details.
-
RSA @@ -996,7 +958,6 @@ Expand each section for more details.
-
Secure Hash Standard (SHS) @@ -1028,11 +989,10 @@ Expand each section for more details. |
  • **SHA-1** (BYTE-only)
  • **SHA-256** (BYTE-only)
  • **SHA-384** (BYTE-only)
  • **SHA-512** (BYTE-only)|Windows Server 2003 SP2 Enhanced Cryptographic Provider (RSAENH) [#613][shs-613]

    Windows Server 2003 SP1 Enhanced Cryptographic Provider (RSAENH) [#364][shs-364]| |

  • **SHA-1** (BYTE-only)|Windows Server 2003 SP2 Enhanced DSS and Diffie-Hellman Cryptographic Provider [#611][shs-611]

    Windows Server 2003 SP2 Kernel Mode Cryptographic Module (fips.sys) [#610][shs-610]

    Windows Server 2003 SP1 Enhanced DSS and Diffie-Hellman Cryptographic Provider (DSSENH) [#385][shs-385]

    Windows Server 2003 SP1 Kernel Mode Cryptographic Module (fips.sys) [#371][shs-371]

    Windows Server 2003 Enhanced DSS and Diffie-Hellman Cryptographic Provider (DSSENH) [#181][shs-181]

    Windows Server 2003 Kernel Mode Cryptographic Module (fips.sys) [#177][shs-177]

    Windows Server 2003 Enhanced Cryptographic Provider (RSAENH) [#176][shs-176]| |

  • **SHA-1** (BYTE-only)
  • **SHA-256** (BYTE-only)
  • **SHA-384** (BYTE-only)
  • **SHA-512** (BYTE-only)|Windows CE 6.0 and Windows CE 6.0 R2 and Windows Mobile Enhanced Cryptographic Provider (RSAENH) [#589][shs-589]

    Windows CE and Windows Mobile 6 and Windows Mobile 6.5 Enhanced Cryptographic Provider (RSAENH) [#578][shs-578]

    Windows CE 5.00 and Windows CE 5.01 Enhanced

    Cryptographic Provider (RSAENH) [#305][shs-305]| -|

  • **SHA-1** (BYTE-only)|Windows XP Microsoft Enhanced Cryptographic Provider [#83][shs-83]

    Crypto Driver for Windows 2000 (fips.sys) [#35](http:/csrc.nist.gov/groups/stm/cavp/documents/shs/shaval.html#35)

    Windows 2000 Microsoft Outlook Cryptographic Provider (EXCHCSP.DLL) SR-1A (3821) [#32][shs-32]

    Windows 2000 RSAENH.DLL [#24][shs-24]

    Windows 2000 RSABASE.DLL [#23][shs-23]

    Windows NT 4 SP6 RSAENH.DLL [#21][shs-21]

    Windows NT 4 SP6 RSABASE.DLL [#20][shs-20]| +|

  • **SHA-1** (BYTE-only)|Windows XP Microsoft Enhanced Cryptographic Provider [#83][shs-83]

    Crypto Driver for Windows 2000 (fips.sys) [#35][shs-35]

    Windows 2000 Microsoft Outlook Cryptographic Provider (EXCHCSP.DLL) SR-1A (3821) [#32][shs-32]

    Windows 2000 RSAENH.DLL [#24][shs-24]

    Windows 2000 RSABASE.DLL [#23][shs-23]

    Windows NT 4 SP6 RSAENH.DLL [#21][shs-21]

    Windows NT 4 SP6 RSABASE.DLL [#20][shs-20]|

  • -
    Triple DES @@ -1060,7 +1020,6 @@ Expand each section for more details.
    -
    SP 800-132 Password-Based Key Derivation Function (PBKDF) @@ -1071,7 +1030,6 @@ Expand each section for more details.
    -
    Component Validation List