The FIPS tamper seal is a sticker, and applying it is your job
The security policy for FortiGate 7.2 and 7.4, certificate 5481, validated in August, says it in two sentences: “The tamper seals are not applied at the factory prior to shipping. It is the responsibility of the Crypto Officer to apply the seals before use to ensure full FIPS 140-3 compliance.” The seals arrive as a kit called FIPS-SEAL-SILVER. Until someone opens the bag and puts them on, the firewall in the rack is not the module on the certificate.
I run a tracker over the CMVP lists, and for this I pulled the security policy of every active FIPS 140-3 hardware module validated at physical security level 2 in a standalone enclosure. That is sixty certificates, fifty-nine of them with a policy online. I read them next to FIPS 140-2 section 4.5, the implementation guidance on both sides of the transition, and a 2003 paper from the seal vulnerability team at Los Alamos.
Evidence
FIPS 140-2 puts the whole of level 2 physical security in one sentence: “The cryptographic module shall provide evidence of tampering (e.g., on the cover, enclosure, and seal) when physical access to the module is attempted.” For a box with a lid it adds that the lid must be locked with a pick-resistant lock or “protected with tamper-evident seals (e.g., evidence tape or holographic seals)”. Level 3 is where the module has to fight back, with hard potting over the circuitry or an enclosure that breaks the module if you get through it.
Most of the active hardware sits at level 2. Of 481 active hardware certificates on 11 September, 209 are at physical level 2, 130 at level 3, 13 at level 4 and the rest at level 1, which asks for nothing beyond production-grade parts. The level 2 list is firewalls, access points, optical transport gear and self-encrypting drives. The HSM vendors are all at level 3, potted.
The test
The test is in Implementation Guidance 7.3.A, unchanged since September 2020, and it is short enough to quote:
If a module uses tamper evident labels, it shall not be possible to remove or reapply any of the labels without tamper evidence. For example, if the label can be removed without tamper evidence, and the same label can be re-applied without tamper evidence, the assertion fails.
The lab is told to get creative, “chemically, mechanically, thermally”, to lift the label whole and put it back clean, and the section closes by ruling one attacker out: “It is out-of-scope for an attacker to introduce new materials to cover up evidence of the attack.”
So the test is the same label, off and on again. A spare label from the same roll is not part of it. The guidance notes that at levels 3 and 4 the ISO text requires seals to be independently identifiable, which is the polite way of saying serial numbers, and that testing this is outside the scope of the guidance. That puts the serial number requirement one level above the one where nearly everyone uses labels.
By 2003 Roger Johnston’s team at Los Alamos had spent twelve years attacking seals for US agencies and the IAEA, and their summary from that year defines a defeat as opening the seal and resealing “using the original seal or a counterfeit” without detection. On that definition they defeated all 213 seal types they studied, adhesive labels included, with a mean time of 2.7 minutes and a median tool cost of five dollars. Adding a dollar to the price of a seal bought under two seconds of defeat time. The same sticker can pass the CMVP test and fail Johnston’s, since only one of them counts the counterfeit.
The bag
The reason the seals come in a bag is Implementation Guidance 14.4 from 2010, carried into the 140-3 policy template in SP 800-140B. It requires the policy to show where every seal goes, count them, name the part number, and state that the seals “shall be installed for the module to operate in the approved mode of operation”. It also names the operator role responsible for “securing and having control at all times of any unused seals”. The certificate itself carries the caveat that the module is validated with the seals installed as shown in the policy.
The sixty policies do what the template asks and not much more. At least 36 say the crypto officer applies the seals, and seven say the factory does, the Samsung drives and SonicWall among them. The recommended inspection interval for the same requirement runs from every 30 days at Palo Alto Networks and Cisco to every twelve months at Silvus. Samsung says “As often as feasible”, and Fortinet leaves it to the crypto officer, who “must develop an inspection schedule”. Fourteen policies mention that the labels carry serial numbers. None asks the operator to write them down. Ribbon’s SBC 5400 ships with six serialised labels and tells you to apply five, which leaves one in a drawer by design. Juniper wants 24 hours for the adhesive to cure, so a box racked and sealed on Monday afternoon is in approved mode on Tuesday.
I had not expected nine policies from three different vendors to contain the identical sentence “The word FIPS may appear if the label was peeled back”, along with the same description of “special thin gauge vinyl with self-adhesive backing”. A label vendor’s product page for “FIPS 140-2 compliant” seals has the same paragraph with the word “Opened” in place of “FIPS”. The CMVP never validates a seal, only its placement on the module, so the seal is whatever the kit contains.
The obvious objection is that this is working as designed. Level 2 was never meant to resist an attacker, only to leave a mark for an operator in a controlled room, and the adversary for a rack appliance is not a customs smuggler with a hair dryer. I agree, and that is the finding. The level puts the operator in the control loop, and the test excludes the one attack an insider with rack access and a spare label would use. What the policies hand that operator is an interval and a photo. The procedure that would make the seal worth something, from receipt to disposal, is about a page long, and none of the sixty policies contains it.
The potted modules get a different kind of instruction. The Luna T7 policy asks for an inspection on receipt after transport, after unattended storage, after a drop, and after “any un-authorized access to the environment hosting the module”, and tells you to look for bent aluminium and missing epoxy. There is no calendar and no label, and the trigger is an event somebody has to notice. That is the better shape, though it still depends on a photograph from the day the box was opened.
Johnston’s line from 2003 is that a seal is no better than the protocols for using it. The lab tested the sticker. Nobody tested the drawer.