From af0f80f44c3b114c2d5a535a90ca1e3fc47fc7ba Mon Sep 17 00:00:00 2001 From: MSRobertD <43757104+MSRobertD@users.noreply.github.com> Date: Wed, 3 Jan 2024 19:46:46 -0800 Subject: [PATCH] More fit and finish --- .../certification/toc.yml | 4 +- .../fips-140-windows-server-2016.md | 8 ++- .../fips-140-windows-server-2019.md | 8 ++- .../fips-140-windows-server-semi-annual.md | 24 ++++----- .../validations/fips-140-windows10.md | 52 ++++++++----------- .../validations/fips-140-windows11.md | 4 +- 6 files changed, 45 insertions(+), 55 deletions(-) diff --git a/windows/security/security-foundations/certification/toc.yml b/windows/security/security-foundations/certification/toc.yml index 3e3715f587..46fb96819c 100644 --- a/windows/security/security-foundations/certification/toc.yml +++ b/windows/security/security-foundations/certification/toc.yml @@ -1,5 +1,5 @@ items: -- name: FIPS 140 validation overview +- name: FIPS 140 validation href: fips-140-validation.md - name: Windows FIPS approved mode href: use-windows-in-fips-approved-mode.md @@ -21,5 +21,5 @@ items: href: ./validations/fips-140-windows-server-previous.md - name: Other products href: ./validations/fips-140-other-products.md -- name: Common Criteria certifications +- name: Common Criteria certification href: windows-platform-common-criteria.md \ No newline at end of file diff --git a/windows/security/security-foundations/certification/validations/fips-140-windows-server-2016.md b/windows/security/security-foundations/certification/validations/fips-140-windows-server-2016.md index 2f1bb4fe1d..d5396256a4 100644 --- a/windows/security/security-foundations/certification/validations/fips-140-windows-server-2016.md +++ b/windows/security/security-foundations/certification/validations/fips-140-windows-server-2016.md @@ -12,9 +12,9 @@ ms.collection: tier3 The following tables list the completed FIPS 140 validations of cryptographic modules used in Windows Server 2016, organized by major release of the operating system. The linked Security Policy document for each module provides details on the module capabilities and the policies the operator must follow to use the module in its FIPS approved mode of operation. For information on using the overall operating system in its FIPS approved mode, see [Use Windows in a FIPS 140 Approved Mode of Operation](../use-windows-in-fips-approved-mode.md). For details on the FIPS approved algorithms used by each module, including CAVP algorithm certificates, see the module's linked Security Policy document or CMVP module certificate. -## Windows Server 2016, build 10.0.14393.1770 +## Windows Server 2016 -Validated Editions: Standard, Datacenter, Storage Server +Build: 10.0.14393.1770. Validated Editions: Standard, Datacenter, Storage Server. |Cryptographic Module (linked to Security Policy document)|CMVP Certificate #|Validated Algorithms| |--- |--- |--- | @@ -24,9 +24,7 @@ Validated Editions: Standard, Datacenter, Storage Server |[Code Integrity][sp-3510] (ci.dll)|[#3510][certificate-3510]|FIPS Approved: AES, RSA, and SHS| |[Secure Kernel Code Integrity][sp-3513] (skci.dll)|[#3513][certificate-3513]|FIPS Approved: RSA and SHS; Other Allowed: MD5| -## Windows Server 2016, build 10.0.14393 - -Validated Editions: Standard, Datacenter, Storage Server +Build: 10.0.14393. Validated Editions: Standard, Datacenter, Storage Server. |Cryptographic Module (linked to Security Policy document)|CMVP Certificate #|Validated Algorithms| |--- |--- |--- | diff --git a/windows/security/security-foundations/certification/validations/fips-140-windows-server-2019.md b/windows/security/security-foundations/certification/validations/fips-140-windows-server-2019.md index e0da6d3597..6f55688f62 100644 --- a/windows/security/security-foundations/certification/validations/fips-140-windows-server-2019.md +++ b/windows/security/security-foundations/certification/validations/fips-140-windows-server-2019.md @@ -12,9 +12,9 @@ ms.collection: tier3 The following tables list the completed FIPS 140 validations of cryptographic modules used in Windows Server 2019, organized by major release of the operating system. The linked Security Policy document for each module provides details on the module capabilities and the policies the operator must follow to use the module in its FIPS approved mode of operation. For information on using the overall operating system in its FIPS approved mode, see [Use Windows in a FIPS 140 Approved Mode of Operation](../use-windows-in-fips-approved-mode.md). For details on the FIPS approved algorithms used by each module, see its linked Security Policy document or module certificate. -## Windows Server 2019, builds 10.0.17763.10021 and 10.0.17763.10127 +## Windows Server 2019 -Validated Edition: Datacenter Core +Builds: 10.0.17763.10021 and 10.0.17763.10127. Validated Edition: Datacenter Core |Cryptographic Module (linked to Security Policy document)|CMVP Certificate #|Validated Algorithms| |--- |--- |--- | @@ -27,9 +27,7 @@ Validated Edition: Datacenter Core |[Virtual TPM]|Pending [(in process)][in-process]|| |[Windows OS Loader][sp-4545]|[#4545][certificate-4545]|FIPS Approved: AES, RSA, and SHS; Other Allowed: NDRNG| -## Windows Server 2019, build 10.0.17763.107 - -Validated Editions: Standard Core, Datacenter Core +Build: 10.0.17763.107. Validated Editions: Standard Core, Datacenter Core |Cryptographic Module (linked to Security Policy document)|Version|CMVP Certificate #|Validated Algorithms| |--- |--- |--- |--- | diff --git a/windows/security/security-foundations/certification/validations/fips-140-windows-server-semi-annual.md b/windows/security/security-foundations/certification/validations/fips-140-windows-server-semi-annual.md index 1f835b0abd..8a18361758 100644 --- a/windows/security/security-foundations/certification/validations/fips-140-windows-server-semi-annual.md +++ b/windows/security/security-foundations/certification/validations/fips-140-windows-server-semi-annual.md @@ -13,9 +13,9 @@ ms.collection: tier3 The following tables list the completed FIPS 140 validations of cryptographic modules used in Windows Server semi-annual releases, organized by major release of the operating system. The linked Security Policy document for each module provides details on the module capabilities and the policies the operator must follow to use the module in its FIPS approved mode of operation. For information on using the overall operating system in its FIPS approved mode, see [Use Windows in a FIPS 140 Approved Mode of Operation](../use-windows-in-fips-approved-mode.md). For details on the FIPS approved algorithms used by each module, including CAVP algorithm certificates, see the module's linked Security Policy document or CMVP module certificate. -## Windows Server, version 2004 (May 2020 Update), build 10.0.19041 +## Windows Server, version 2004 (May 2020 Update) -Validated Editions: Standard Core, Datacenter Core +Build: 10.0.19041. Validated Editions: Standard Core, Datacenter Core |Cryptographic Module (linked to Security Policy document)|CMVP Certificate #|Validated Algorithms| |--- |--- |--- | @@ -28,9 +28,9 @@ Validated Editions: Standard Core, Datacenter Core |[Virtual TPM][sp-4537]|[#4537][certificate-4537]|FIPS Approved: AES, CKG, CVL, DRBG, ECDSA, HMAC, KAS, KBKDF, KTS, RSA, and SHS; Other Allowed: NDRNG| |[Windows OS Loader][sp-4339]|[#4339][certificate-4339]|FIPS Approved: AES, CKG, DRBG, RSA, and SHS; Other Allowed: NDRNG| -## Windows Server, version 1909 (November 2019 Update), build 10.0.18363 +## Windows Server, version 1909 (November 2019 Update) -Validated Editions: Standard Core, Datacenter Core +Build: 10.0.18363. Validated Editions: Standard Core, Datacenter Core |Cryptographic Module (linked to Security Policy document)|CMVP Certificate #|Validated Algorithms| |--- |--- |--- | @@ -43,9 +43,9 @@ Validated Editions: Standard Core, Datacenter Core |[Virtual TPM][sp-4537]|[#4537][certificate-4537]|FIPS Approved: AES, CKG, CVL, DRBG, ECDSA, HMAC, KAS, KBKDF, KTS, RSA, and SHS; Other Allowed: NDRNG| |[Windows OS Loader][sp-4339]|[#4339][certificate-4339]|FIPS Approved: AES, CKG, DRBG, RSA, and SHS; Other Allowed: NDRNG| -## Windows Server, version 1903 (May 2019 Update), build 10.0.18362 +## Windows Server, version 1903 (May 2019 Update) -Validated Editions: Standard Core, Datacenter Core +Build: 10.0.18362. Validated Editions: Standard Core, Datacenter Core |Cryptographic Module (linked to Security Policy document)|CMVP Certificate #|Validated Algorithms| |--- |--- |--- | @@ -58,9 +58,9 @@ Validated Editions: Standard Core, Datacenter Core |[Virtual TPM][sp-4537]|[#4537][certificate-4537]|FIPS Approved: AES, CKG, CVL, DRBG, ECDSA, HMAC, KAS, KBKDF, KTS, RSA, and SHS; Other Allowed: NDRNG| |[Windows OS Loader][sp-4339]|[#4339][certificate-4339]|FIPS Approved: AES, CKG, DRBG, RSA, and SHS; Other Allowed: NDRNG| -## Windows Server, version 1809, build 10.0.17763 +## Windows Server, version 1809 -Validated Editions: Standard Core, Datacenter Core +Build: 10.0.17763. Validated Editions: Standard Core, Datacenter Core |Cryptographic Module (linked to Security Policy document)|CMVP Certificate #|Validated Algorithms| |--- |--- |--- | @@ -73,9 +73,9 @@ Validated Editions: Standard Core, Datacenter Core |[Virtual TPM][sp-3690]|[#3690][certificate-3690]|FIPS Approved: AES, CKG, CVL, DRBG, ECDSA, HMAC, KAS, KBKDF, KTS, RSA, and SHS; Other Allowed: NDRNG| |[Windows OS Loader][sp-3615]|[#3615][certificate-3615]|FIPS Approved: AES, CKG, DRBG, RSA, and SHS; Other Allowed: NDRNG| -## Windows Server, version 1803, build 10.0.17134 +## Windows Server, version 1803 -Validated Editions: Standard Core, Datacenter Core +Build: 10.0.17134. Validated Editions: Standard Core, Datacenter Core |Cryptographic Module (linked to Security Policy document)|CMVP Certificate #|Validated Algorithms| |--- |--- |--- | @@ -87,9 +87,9 @@ Validated Editions: Standard Core, Datacenter Core |[Secure Kernel Code Integrity][sp-3096]|[#3096][certificate-3096]|FIPS Approved: AES, RSA, and SHS| |[Windows OS Loader][sp-3480]|[#3480][certificate-3480]|FIPS Approved: AES, CKG, DRBG, RSA, and SHS; Other Allowed: NDRNG| -## Windows Server, version 1709, build 10.0.16299 +## Windows Server, version 1709 -Validated Editions: Standard Core, Datacenter Core +Build: 10.0.16299. Validated Editions: Standard Core, Datacenter Core |Cryptographic Module (linked to Security Policy document)|CMVP Certificate #|Validated Algorithms| |--- |--- |--- | diff --git a/windows/security/security-foundations/certification/validations/fips-140-windows10.md b/windows/security/security-foundations/certification/validations/fips-140-windows10.md index 07954c320f..cf564b63c2 100644 --- a/windows/security/security-foundations/certification/validations/fips-140-windows10.md +++ b/windows/security/security-foundations/certification/validations/fips-140-windows10.md @@ -13,9 +13,9 @@ ms.collection: tier3 The following tables list the completed FIPS 140 validations of cryptographic modules used in Windows 10, organized by major release of the operating system. The linked Security Policy document for each module provides details on the module capabilities and the policies the operator must follow to use the module in its FIPS approved mode of operation. For information on using the overall operating system in its FIPS approved mode, see [Use Windows in a FIPS 140 Approved Mode of Operation](../use-windows-in-fips-approved-mode.md). For details on the FIPS approved algorithms used by each module, including CAVP algorithm certificates, see the module's linked Security Policy document or CMVP module certificate. -## Windows 10, version 2004 (May 2020 Update), build 10.0.19041 +## Windows 10, version 2004 (May 2020 Update) -Validated Editions: Home, Pro, Enterprise, Education +Build: 10.0.19041. Validated Editions: Home, Pro, Enterprise, Education |Cryptographic Module (linked to Security Policy document)|CMVP Certificate #|Validated Algorithms| |--- |--- |--- | @@ -30,9 +30,9 @@ Validated Editions: Home, Pro, Enterprise, Education |[Virtual TPM][sp-4537]|[#4537][certificate-4537]|FIPS Approved: AES, CKG, CVL, DRBG, ECDSA, HMAC, KAS, KBKDF, KTS, RSA, and SHS; Other Allowed: NDRNG| |[Windows Resume][sp-4348]|[#4348][certificate-4348]|FIPS Approved: AES, HMAC, KBKDF, RSA, and SHS| -## Windows 10, version 1909 (November 2019 Update), build 10.0.18363 +## Windows 10, version 1909 (November 2019 Update) -Validated Editions: Home, Pro, Enterprise, Education +Build: 10.0.18363. Validated Editions: Home, Pro, Enterprise, Education |Cryptographic Module (linked to Security Policy document)|CMVP Certificate #|Validated Algorithms| |--- |--- |--- | @@ -47,9 +47,9 @@ Validated Editions: Home, Pro, Enterprise, Education |[Virtual TPM][sp-4537]|[#4537][certificate-4537]|FIPS Approved: AES, CKG, CVL, DRBG, ECDSA, HMAC, KAS, KBKDF, KTS, RSA, and SHS; Other Allowed: NDRNG| |[Windows Resume][sp-4348]|[#4348][certificate-4348]|FIPS Approved: AES, HMAC, KBKDF, RSA, and SHS| -## Windows 10, version 1903 (May 2019 Update), build 10.0.18362 +## Windows 10, version 1903 (May 2019 Update) -Validated Editions: Home, Pro, Enterprise, Education +Build: 10.0.18362. Validated Editions: Home, Pro, Enterprise, Education |Cryptographic Module (linked to Security Policy document)|CMVP Certificate #|Validated Algorithms| |--- |--- |--- | @@ -63,9 +63,9 @@ Validated Editions: Home, Pro, Enterprise, Education |[Virtual TPM][sp-4537]|[#4537][certificate-4537]|FIPS Approved: AES, CKG, CVL, DRBG, ECDSA, HMAC, KAS, KBKDF, KTS, RSA, and SHS; Other Allowed: NDRNG| |[Windows Resume][sp-4348]|[#4348][certificate-4348]|FIPS Approved: AES, HMAC, KBKDF, RSA, and SHS| -## Windows 10, version 1809 (October 2018 Update), build 10.0.17763 +## Windows 10, version 1809 (October 2018 Update) -Validated Editions: Home, Pro, Enterprise, Education +Build: 10.0.17763. Validated Editions: Home, Pro, Enterprise, Education |Cryptographic Module (linked to Security Policy document)|CMVP Certificate #|Validated Algorithms| |--- |--- |--- | @@ -78,9 +78,9 @@ Validated Editions: Home, Pro, Enterprise, Education |[Virtual TPM][sp-3690]|[#3690][certificate-3690]|FIPS Approved: AES, CKG, CVL, DRBG, ECDSA, HMAC, KAS, KBKDF, KTS, RSA, and SHS; Other Allowed: NDRNG| |[Windows OS Loader][sp-3615]|[#3615][certificate-3615]|FIPS Approved: AES, CKG, DRBG, RSA, and SHS; Other Allowed: NDRNG| -## Windows 10, version 1803 (April 2018 Update), build 10.0.17134 +## Windows 10, version 1803 (April 2018 Update) -Validated Editions: Home, Pro, Enterprise, Education +Build: 10.0.17134. Validated Editions: Home, Pro, Enterprise, Education |Cryptographic Module (linked to Security Policy document)|CMVP Certificate #|Validated Algorithms| |--- |--- |--- | @@ -92,9 +92,9 @@ Validated Editions: Home, Pro, Enterprise, Education |[Secure Kernel Code Integrity][sp-3096]|[#3096][certificate-3096]|FIPS Approved: AES, RSA, and SHS| |[Windows OS Loader][sp-3480]|[#3480][certificate-3480]|FIPS Approved: AES, CKG, DRBG, RSA, and SHS; Other Allowed: NDRNG| -## Windows 10, version 1709 (Fall Creators Update), build 10.0.16299 +## Windows 10, version 1709 (Fall Creators Update) -Validated Editions: Home, Pro, Enterprise, Education, S, Surface Hub, Mobile +Build: 10.0.16299. Validated Editions: Home, Pro, Enterprise, Education, S, Surface Hub, Mobile |Cryptographic Module (linked to Security Policy document)|CMVP Certificate #|Validated Algorithms| |--- |--- |--- | @@ -107,9 +107,9 @@ Validated Editions: Home, Pro, Enterprise, Education, S, Surface Hub, Mobile |[Windows Resume][sp-3091]|[#3091][certificate-3091]|FIPS Approved: AES, RSA, and SHS| |[Windows OS Loader][sp-3194]|[#3194][certificate-3194]|FIPS Approved: AES, RSA, and SHS; Other Allowed: NDRNG| -## Windows 10, version 1703 (Creators Update), build 10.0.15063 +## Windows 10, version 1703 (Creators Update) -Validated Editions: Home, Pro, Enterprise, Education, S, Surface Hub, Mobile +Build: 10.0.15063. Validated Editions: Home, Pro, Enterprise, Education, S, Surface Hub, Mobile |Cryptographic Module (linked to Security Policy document)|CMVP Certificate #|Validated Algorithms| |--- |--- |--- | @@ -122,9 +122,9 @@ Validated Editions: Home, Pro, Enterprise, Education, S, Surface Hub, Mobile |[Windows OS Loader][sp-3090]|[#3090][certificate-3090]|FIPS Approved: AES, RSA, and SHS| |[Windows Resume][sp-3091]
*Applies only to Home, Pro, Enterprise, Education, and S Editions.*|[#3091][certificate-3091]|FIPS Approved: AES, RSA, and SHS| -## Windows 10, version 1607 (Anniversary Update), build 10.0.14393.1770 +## Windows 10, version 1607 (Anniversary Update) -Validated Editions: Windows 10 (Home/Consumer), Pro, Enterprise, Enterprise LTSB, Mobile +Build: 10.0.14393.1770. Validated Editions: Windows 10 (Home/Consumer), Pro, Enterprise, Enterprise LTSB, Mobile |Cryptographic Module (linked to Security Policy document)|CMVP Certificate #|Validated Algorithms| |--- |--- |--- | @@ -134,9 +134,7 @@ Validated Editions: Windows 10 (Home/Consumer), Pro, Enterprise, Enterprise LTSB |[Code Integrity][sp-3510] (ci.dll)|[#3510][certificate-3510]|FIPS Approved: AES, RSA, and SHS| |[Secure Kernel Code Integrity][sp-3513] (skci.dll)
*Applies only to Pro, Enterprise, and Enterprise LTSB Editions.*|[#3513][certificate-3513]|FIPS Approved: RSA and SHS; Other Allowed: MD5| -## Windows 10, version 1607 (Anniversary Update), build 10.0.14393 - -Validated Editions: Windows 10 (Home/Consumer), Pro, Enterprise, Enterprise LTSB, Mobile +Build: 10.0.14393. Validated Editions: Windows 10 (Home/Consumer), Pro, Enterprise, Enterprise LTSB, Mobile |Cryptographic Module (linked to Security Policy document)|CMVP Certificate #|Validated Algorithms| |--- |--- |--- | @@ -149,9 +147,9 @@ Validated Editions: Windows 10 (Home/Consumer), Pro, Enterprise, Enterprise LTSB |[Kernel Mode Cryptographic Primitives Library][sp-2936] (cng.sys)|[#2936][certificate-2936]|FIPS Approved: AES, CVL, DRBG, DSA, ECDSA, HMAC, KAS, KBKDF, KTS, PBKDF, RSA, SHS, and Triple-DES; Other Allowed: HMAC-MD5, MD5, and NDRNG| |[Secure Kernel Code Integrity][sp-2938] (skci.dll)
*Applies only to Pro, Enterprise, and Enterprise LTSB Editions.*|[#2938][certificate-2938]|FIPS Approved: RSA and SHS; Other Allowed: MD5| -## Windows 10, version 1511 (November Update), build 10.0.10586.1176 +## Windows 10, version 1511 (November Update) -Validated Editions: Home, Pro, Enterprise, Enterprise LTSB, Mobile, Surface Hub +Build: 10.0.10586.1176. Validated Editions: Home, Pro, Enterprise, Enterprise LTSB, Mobile, Surface Hub |Cryptographic Module (linked to Security Policy document)|CMVP Certificate #|Validated Algorithms| |--- |--- |--- | @@ -160,9 +158,7 @@ Validated Editions: Home, Pro, Enterprise, Enterprise LTSB, Mobile, Surface Hub |[Boot Manager][sp-3447]|[#3447][certificate-3447]|FIPS Approved: AES, HMAC, PBKDF, RSA, and SHS| |[Code Integrity][sp-3469] (ci.dll)|[#3469][certificate-3469]|FIPS Approved: AES, RSA, and SHS| -## Windows 10, version 1511 (November Update), build 10.0.10586 - -Validated Editions: Home, Pro, Enterprise, Enterprise LTSB, Mobile, Surface Hub +Build: 10.0.10586. Validated Editions: Home, Pro, Enterprise, Enterprise LTSB, Mobile, Surface Hub |Cryptographic Module (linked to Security Policy document)|CMVP Certificate #|Validated Algorithms| |--- |--- |--- | @@ -175,9 +171,9 @@ Validated Editions: Home, Pro, Enterprise, Enterprise LTSB, Mobile, Surface Hub |[Kernel Mode Cryptographic Primitives Library][sp-2605] (cng.sys)|[#2605][certificate-2605]|FIPS Approved: AES, CVL, DRBG, DSA, ECDSA, HMAC, KAS, KBKDF, KTS, PBKDF, RSA, SHS, and Triple-DES; Other Allowed: HMAC-MD5, MD5, and NDRNG| |[Secure Kernel Code Integrity][sp-2607] (skci.dll)
*Applies only to Enterprise and Enterprise LTSB Editions.*|[#2607][certificate-2607]|FIPS Approved: RSA and SHS| -## Windows 10, version 1507, build 10.0.10240.17643 +## Windows 10, version 1507 -Validated Editions: Enterprise LTSB +Build: 10.0.10240.17643. Validated Editions: Enterprise LTSB |Cryptographic Module (linked to Security Policy document)|CMVP Certificate #|Validated Algorithms| |--- |--- |--- | @@ -186,9 +182,7 @@ Validated Editions: Enterprise LTSB |[Boot Manager][sp-3415]|[#3415][certificate-3415]|FIPS Approved: AES, HMAC, PBKDF, RSA, and SHS| |[Code Integrity][sp-3437] (ci.dll)|[#3437][certificate-3437]|FIPS Approved: AES, RSA, and SHS| -## Windows 10, version 1507, build 10.0.10240 - -Validated Editions: Home, Pro, Enterprise, Enterprise LTSB, Mobile, and Surface Hub +Build: 10.0.10240. Validated Editions: Home, Pro, Enterprise, Enterprise LTSB, Mobile, and Surface Hub |Cryptographic Module (linked to Security Policy document)|CMVP Certificate #|Validated Algorithms| |--- |--- |--- | diff --git a/windows/security/security-foundations/certification/validations/fips-140-windows11.md b/windows/security/security-foundations/certification/validations/fips-140-windows11.md index 7ce96896c8..f2ef949ae6 100644 --- a/windows/security/security-foundations/certification/validations/fips-140-windows11.md +++ b/windows/security/security-foundations/certification/validations/fips-140-windows11.md @@ -13,9 +13,9 @@ ms.collection: tier3 The following tables list the completed FIPS 140 validations of cryptographic modules used in Windows 11, organized by major release of the operating system. The linked Security Policy document for each module provides details on the module capabilities and the policies the operator must follow to use the module in its FIPS approved mode of operation. For information on using the overall operating system in its FIPS approved mode, see [Use Windows in a FIPS 140 Approved Mode of Operation](../use-windows-in-fips-approved-mode.md). For details on the FIPS approved algorithms used by each module, including CAVP algorithm certificates, see the module's linked Security Policy document or CMVP module certificate. -## Windows 11, version 21H2, build 10.0.22000 +## Windows 11, version 21H2 -Validated Edition: Windows 11 +Build: 10.0.22000. Validated Edition: Windows 11 |Cryptographic Module (linked to Security Policy document)|CMVP Certificate #|Validated Algorithms| |--- |--- |--- |