- Supports the certificate-evidence field for tested algorithm implementations.
References and citations
- Provides CMVP transition and approved-mode treatment for legacy signature verification, algorithm self-tests, and module submissions.
"approved algorithms only for legacy decryption"
- Supports procurement caution around FIPS 140-3 compliant products and the warning not to use the CMVP historical list for procurement decisions.
"Historical list should not be used for procurement decisions"
- Supports cited-source review of SHA-1 and SHA-2 family hash claims and their validation evidence.
"SHA-1, SHA-224, SHA-256, SHA-384, SHA-512"
- Records withdrawal of FIPS 186-4 on February 3, 2024 and supersession by FIPS 186-5.
- Supports change-control tracking where signature implementations move from FIPS 186-4 dependencies to FIPS 186-5 claims.
"implementation schedule for cryptographic modules"
- Supports careful wording for SHA-3 and SHAKE entries so XOF approval is not overstated as ordinary hash-function use.
"approved uses will be specified in NIST Special Publications"
- Sets December 31, 2030 as the SHA-1 transition date and describes the CMVP historical-list consequence.
- Lists FIPS 203, FIPS 204, and FIPS 205 as final and NIST IR 8547 as a draft.
- Provides the final operation-specific transition status for three-key Triple-DES and other algorithms.
- Provides the current operation-specific treatment for three-key Triple-DES and SKIPJACK.
"only approved for decryption, unwrapping or CMAC verification for legacy use"