What does each validation certificate prove?
The CMVP implementation guidance draws a clear line between certificate types. CAVP tests and validates cryptographic algorithm implementations; the algorithm validation certificate states the implementation name, implementation version, and tested operational environment.
CMVP tests and validates cryptographic modules. A module validation certificate states the validated cryptographic module name, version, and tested operational environment. That module-level evidence is separate from the algorithm certificate, even when the module uses CAVP-tested algorithms.
- Use CAVP evidence for the tested algorithm implementation, such as an AES, hash, signature, KDF, MAC, or DRBG implementation.
- Use CMVP evidence for a FIPS 140-3 cryptographic module claim, including the module boundary, security policy, approved services, status, and caveats.
- Do not convert a CAVP algorithm certificate into a product-level or module-level FIPS 140-3 validation claim.
Distinguishes CAVP algorithm validation certificates from CMVP cryptographic module validation certificates.
Public search page for checking algorithm validation records before citing a CAVP certificate.
Public search page for checking FIPS 140-3 and FIPS 140-2 cryptographic module validation records.