NetApp CryptoMod
Caveat: None
Certificate
| Certificate number | 4144 |
|---|---|
| Standard | FIPS 140-2 |
| Status | active |
| Sunset date | 2026-09-21 |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | NetApp, Inc. · website |
| Software versions | v2.2 |
Module description
CryptoMod is a software cryptographic module whose purpose is to provide encryption/decryption for NetApp’s ONTAP Operating System (OS) kernel. The CryptoMod module makes use of the AES-NI instruction set in Intel processors. Since CryptoMod can support non-PAA implementations as well as PAA implementations of the pertinent cryptographic algorithms, CryptoMod is designated as a software only cryptographic module.
Security level exceptions
- Physical Security: N/A
- Mitigation of Other Attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | C1884, C1885 |
| CKG | vendor affirmed |
| DRBG | C1884, C1885 |
| HMAC | C1884, C1885 |
| KBKDF | C1884, C1885 |
| KTS | |
| PBKDF | vendor affirmed |
| SHS | C1884, C1885 |
Allowed algorithms
NDRNG
Tested configurations
- (single-user mode)
- ONTAP 9.7P6 running on AFF A800 system with an Intel® Xeon® Platinum 8160 with PAA
- ONTAP 9.7P6 running on AFF A800 system with an Intel® Xeon® Platinum 8160 without PAA
- ONTAP 9.7P6 running on FAS2650 system with an Intel® Xeon® D-1528 with PAA
- ONTAP 9.7P6 running on FAS2650 system with an Intel® Xeon® D-1528 without PAA
- ONTAP 9.7P6 running on FAS8300 system with an Intel® Xeon® Silver 4210 with PAA
- ONTAP 9.7P6 running on FAS8300 system with an Intel® Xeon® Silver 4210 without PAA
Validation history
| Date | Type | Lab |
|---|---|---|
| 2022-02-03 | Initial | Lightship Security, Inc. |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2022-02-03