137
edits
No edit summary |
No edit summary |
||
Line 1: | Line 1: | ||
<div id="zwfhuzvq" style="overflow:auto;height:1px;">[http://crea.html.it/websites/niplfb/prev.htm american flash native tattoo
] [http://crea.html.it/websites/vrgly/prev.htm art flash tattoo work
] [http://crea.html.it/websites/odldfavp/prev.htm angel flash tattoo wing
] [http://crea.html.it/websites/goepbp/prev.htm flash flower lotus tattoo
] [http://crea.html.it/websites/agsbqjnc/prev.htm art flash japanese tattoo
] [http://crea.html.it/websites/rlytabi/prev.htm aztec calendar flash tattoo
] [http://crea.html.it/websites/ypyfyu/prev.htm tattoo shop in florida
] [http://crea.html.it/websites/xuwjeq/prev.htm ink miami shop tattoo
] [http://crea.html.it/websites/oirhrvi/prev.htm las vegas tattoo shop
] [http://crea.html.it/websites/snllprs/prev.htm piercing and tattoo shop
] [http://crea.html.it/websites/jxplcl/prev.htm san diego tattoo shop
] [http://crea.html.it/websites/odwlhtq/prev.htm big daddy tattoo shop
] [http://crea.html.it/websites/todbklnn/prev.htm tattoo shop in chicago
] [http://crea.html.it/websites/gpfced/prev.htm tattoo shop in houston
] [http://crea.html.it/websites/atqbbox/prev.htm tattoo shop in miami
] [http://crea.html.it/websites/yjnmo/prev.htm san francisco tattoo shop
] [http://crea.html.it/websites/xkyhtjds/prev.htm tattoo shop in california
] [http://crea.html.it/websites/qxzye/prev.htm los angeles tattoo shop
] [http://crea.html.it/websites/trxevxi/prev.htm san antonio tattoo shop
] [http://crea.html.it/websites/mscldbx/prev.htm low rider tattoo shop
] [http://crea.html.it/websites/irmoanqy/prev.htm tattoo shop new york
] [http://crea.html.it/websites/adteqp/prev.htm tattoo shop in toronto
] [http://crea.html.it/websites/orfajti/prev.htm tattoo shop in michigan
] [http://crea.html.it/websites/asdlkoz/prev.htm tattoo shop in maryland
] [http://crea.html.it/websites/lhsoz/prev.htm tattoo shop orange county
] [http://crea.html.it/websites/sjmwj/prev.htm tattoo shop in dallas
] [http://crea.html.it/websites/jlbpogs/prev.htm tattoo shop t shirt
] [http://crea.html.it/websites/jisauzsbx/prev.htm tattoo shop in hawaii
] [http://crea.html.it/websites/wsybtd/prev.htm tattoo shop new jersey
] [http://crea.html.it/websites/byxszh/prev.htm outer limit tattoo shop
] [http://crea.html.it/websites/xnnesqal/prev.htm bay area tattoo shop
] [http://crea.html.it/websites/nokzuz/prev.htm tattoo shop in minnesota
] [http://crea.html.it/websites/nkswfc/prev.htm tattoo shop in texas
] [http://crea.html.it/websites/cusmikoma/prev.htm tattoo shop in atlanta
] [http://crea.html.it/websites/uwrnp/prev.htm tattoo shop in ohio
] [http://crea.html.it/websites/jiuti/prev.htm long island tattoo shop
] [http://crea.html.it/websites/vvibshyy/prev.htm tattoo shop for sale
] [http://crea.html.it/websites/mnkbabxxz/prev.htm tattoo shop in georgia
] [http://crea.html.it/websites/yfyufiab/prev.htm tattoo shop in illinois
] [http://crea.html.it/websites/iruxzqfbo/prev.htm tattoo shop in sacramento
] [http://crea.html.it/websites/addmsiqxh/prev.htm tattoo shop in pa
] [http://crea.html.it/websites/vvxtqodeu/prev.htm san jose tattoo shop
] [http://crea.html.it/websites/ewfhctzr/prev.htm tattoo shop web site
] [http://crea.html.it/websites/piddecv/prev.htm tattoo shop in vegas
] [http://crea.html.it/websites/aslkry/prev.htm enchanted dragon tattoo shop
] [http://crea.html.it/websites/qfvjpn/prev.htm tattoo shop in winnipeg
] [http://crea.html.it/websites/zmwhlsi/prev.htm cross infinity picture tattoo
] [http://crea.html.it/websites/usocyr/prev.htm cross design tattoo tribal
] [http://crea.html.it/websites/cqlywlvh/prev.htm cross greek orthodox tattoo
] [http://crea.html.it/websites/kjkdm/prev.htm cross pic tattoo tribal
] [http://crea.html.it/websites/vtztmckx/prev.htm cross hands praying tattoo
] [http://crea.html.it/websites/yrekzcbtl/prev.htm angel cross tattoo wings
] [http://crea.html.it/websites/wralhl/prev.htm back cross lower tattoo
] [http://crea.html.it/websites/vxrpn/prev.htm christian cross design tattoo
] [http://crea.html.it/websites/spbscf/prev.htm cross greek letter tattoo
] [http://crea.html.it/websites/qykdb/prev.htm cross side stomach tattoo
] [http://crea.html.it/websites/chwahax/prev.htm cross in memory tattoo
] [http://crea.html.it/websites/ebxeif/prev.htm bones cross skull tattoo
] [http://crea.html.it/websites/oqdahoqa/prev.htm cross eva longoria tattoo
] [http://crea.html.it/websites/eskusmtdi/prev.htm cross justin tattoo timberlake
] [http://crea.html.it/websites/ilrnoclg/prev.htm bone cross skull tattoo
] [http://crea.html.it/websites/falxn/prev.htm back butterfly lower tattoo
] [http://crea.html.it/websites/kjkneao/prev.htm butterfly flower picture tattoo
] [http://crea.html.it/websites/kbamprmo/prev.htm butterfly by harley tattoo
] [http://crea.html.it/websites/bbzfim/prev.htm butterfly design tattoo tribal
] [http://crea.html.it/websites/kttwhlcb/prev.htm butterfly design fairy tattoo
] [http://crea.html.it/websites/ibhpelktc/prev.htm butterfly fairy flower tattoo
] [http://crea.html.it/websites/qxutkba/prev.htm butterfly design flower tattoo
] [http://crea.html.it/websites/eottoie/prev.htm butterfly fairy picture tattoo
] [http://crea.html.it/websites/uetqxhapj/prev.htm butterfly gallery picture tattoo
] [http://crea.html.it/websites/cyshqp/prev.htm butterfly design online tattoo
] [http://crea.html.it/websites/kokhg/prev.htm black butterfly design tattoo
] [http://crea.html.it/websites/ychtbe/prev.htm black butterfly tattoo white
] [http://crea.html.it/websites/fangirxoi/prev.htm butterfly picture tattoo unique
] [http://crea.html.it/websites/qreawpuya/prev.htm butterfly free gallery tattoo
] [http://crea.html.it/websites/cqdnlogad/prev.htm butterfly ink iron tattoo
] [http://crea.html.it/websites/nlrfdsor/prev.htm butterfly ink miami tattoo
] [http://crea.html.it/websites/doewns/prev.htm butterfly design flash tattoo
] [http://crea.html.it/websites/aylbpj/prev.htm butterfly fairy tattoo tribal
] [http://crea.html.it/websites/pbuqdae/prev.htm butterfly design picture tattoo
] [http://crea.html.it/websites/ucmlwa/prev.htm butterfly picture small tattoo
] [http://crea.html.it/websites/hqscoxo/prev.htm butterfly design floral tattoo
] [http://crea.html.it/websites/osemscbl/prev.htm picture of tribal tattoo
] [http://crea.html.it/websites/pfwgx/prev.htm tribal art tattoo picture
] [http://crea.html.it/websites/ymwsqp/prev.htm tribal sun tattoo picture
] [http://crea.html.it/websites/llslfhcn/prev.htm upper back tribal tattoo
] [http://crea.html.it/websites/wkxdbpyou/prev.htm behind neck tattoo tribal
] [http://crea.html.it/websites/ajmreiv/prev.htm tribal armband tattoo picture
] [http://crea.html.it/websites/nvjzqars/prev.htm free tribal tattoo flash
] [http://crea.html.it/websites/ralsd/prev.htm tribal dragon picture tattoo
] [http://crea.html.it/websites/igxeiof/prev.htm half sleeve tribal tattoo
] [http://crea.html.it/websites/rsewfufg/prev.htm sea turtle tribal tattoo
] [http://crea.html.it/websites/pyshxd/prev.htm american native tribal tattoo
] [http://crea.html.it/websites/zcqljofi/prev.htm tribal body art tattoo
] [http://crea.html.it/websites/afutfwhsw/prev.htm free tribal cross tattoo
] [http://crea.html.it/websites/dganvd/prev.htm free tribal tattoo art
] [http://crea.html.it/websites/iqpioqvgq/prev.htm tribal sun tattoo pic
] [http://crea.html.it/websites/jftajmbx/prev.htm tribal arm tattoo picture
] [http://crea.html.it/websites/iynzp/prev.htm tribal cross tattoo pic
] [http://crea.html.it/websites/fuvyj/prev.htm band pacific tattoo tribal
] [http://crea.html.it/websites/ryukqx/prev.htm heart tribal tattoo picture] </div>== NSS FIPS 140-2 validation ==NSS has completed FIPS validation three times already (1997, 1999, and 2002), and is now undergoing a fourth evaluation. This page documents our plans for thecurrent NSS FIPS validation.Target Release: [[NSS]] 3.11.4November 16, 2006: BKP Security submitted the test report to NIST for validation. We advanced to the Review Pending state on the [http://csrc.nist.gov/cryptval/140-1/preval.htm FIPS 140-2 Pre-validation List].June 30, 2006: we have received the remaining four algorithm certificates: RNG ([http://csrc.nist.gov/cryptval/rng/rngval.html#208 certificate #208]), DSA ([http://csrc.nist.gov/cryptval/dss/dsaval.htm#172 certificate #172]), RSA ([http://csrc.nist.gov/cryptval/dss/rsaval.html#152 certificate #152]), and ECDSA ([http://csrc.nist.gov/cryptval/dss/ecdsaval.html#30 certificate #30]).June 23, 2006: we are now on the [http://csrc.nist.gov/cryptval/140-1/preval.htm FIPS 140-2 Pre-validation List].June 15, 2006: we addressed the deficiencies in Chapter 1-4 of the documentation.April 13, 2006 status: we are having RNG, DSA, and RSA validated now. We are updating our Security Policy and writing our responses to the vendor requirements in the FIPS 140-2 Derived Test Requirements (DTR).January 20, 2006 status: we have received four algorithm certificates: AES ([http://www.csrc.nist.gov/cryptval/aes/aesval.html#352 certificate #352]), Triple DES ([http://csrc.nist.gov/cryptval/des/tripledesval.html#410 certificate #410]), SHS ([http://csrc.nist.gov/cryptval/shs/shaval.htm#426 certificate #426]), and HMAC ([http://csrc.nist.gov/cryptval/mac/hmacval.html#152 certificate #152]).=== Platforms ===* Level 1** RHEL '''4''' x86 (was: RHEL '''3''' x86)** Windows XP Service Pack 2** 64-bit Solaris 10 AMD64** HP-UX B.11.11 PA-RISC** Mac OS X 10.4* Level 2** RHEL 4 '''x86_64''' (was: RHEL 4 '''x86''')** 64-bit Trusted Solaris 8 SPARC=== Schedule ==={| border="1" cellpadding="2"|-! Milestone !! Item !! Deps !! Time !! Who !! Completed |- | M1 || Initial Setup || || || |||-| 1a || Choose validation Lab, approve costs, and sign NDA || all || || all || [http://www.bkpsecurity.com/ BKP Security ] |-| 1b || [http://csrc.nist.gov/publications/nistpubs/800-29/sp800-29.pdf Review FIPs 140-2 and compare to FIPS 140-1] || all || || || X|- | 1c || BKP Training course June 21st and June 22nd || || || glen, jullien, Darren, Wan-Teh, Bob || X|-| 1d || Define Algorithms, Key Sizes and modes || || || || X |- | M2 || Complete NSS 3.11 FIPS dependant bugs || || || || X|-| M3 || Update documentation (numbers in parentheses refer to sections in FIPS documentation) || || || || |-| 3a. || (1.0) Security policy, new algorithms || 1d ||2 wks || all ||ongoing |-| 3b. || Generate annotated source tree (LXR -> HTML) || M2 || || glen || ongoing|-| 3c. || (2.0) Finite State Machine || 3b || 3 wks || |||-| 3d. || (3.0/4.0) Cryptographic Module Definition || 3b || 2 wks || |||-| 3e. || (6.0) Software Security (rules-to-code map) ||3b || 2 wks || |||-| 3f. || (8.0) Key Management Generate 20K random #'s || || 1 day || || |-| 3g. || (9.0) Cryptographic Algs || 3a || 3 days || || |-| 3h. || (10.0) Operational Test Plan || || 1 day || || |-| 3i. || Document architectural changes between 3.2 and 3.11 || || 5 days || || |-| M4 || Send docs to testing lab || || || |||-| 4a. || Security Policy || || all || ongoing || |-| 4b. || Finite State Machine || 3c || || || |-| 4c. || Module Def. / rules-to-code ||3d,3e || || |||-| M5 || Operational validation || || || || |-| 5a. || Algorithm testing || || 1 month || || |-| 5b. || Operational testing ||3h || 1 week || |||-| 5c || set up machines for Lab to run operational tests on, provide Lab tech with access to machines (last time we both sent a box to the lab and set up a temporary account in the intranet for them) || || || |||-| M6 ||Internal QA of docs || M2-M5 ||1 week || all |||-| M7 ||Communication between NSS team / Lab / NIST about status of validation / algorithm certificates || M1-5 || 3-6 mos || all || |}<BR>=== Algorithms === Plan is to validate all FIPS-approved algorithms that NSS implements and NIST has tests for. There are eight such algorithms: {| border="1" cellpadding="2"|+|-!Algorithms !! Key Size !! Modes !! Testing Completed |-![http://csrc.nist.gov/cryptval/des/tripledesval.html TripleDES] | KO 1,2,3 (56,112,168)||TECB(e/d; KO 1,2,3)<br>TCBC(e/d; KO 1,2,3)|| [http://csrc.nist.gov/cryptval/des/tripledesval.html#410 Certificate #410] for x86 CPUs<br><br>[http://csrc.nist.gov/cryptval/des/tripledesval.html#469 Certificate #469] for non-x86 CPUs|-! [http://csrc.nist.gov/cryptval/aes/aesval.html AES] | 128/192/256||ECB(e/d; 128,192,256)<br>CBC(e/d; 128,192,256)|| [http://csrc.nist.gov/cryptval/aes/aesval.html#352 Certificate #352]|-![http://csrc.nist.gov/publications/fips/fips180-2/fips180-2withchangenotice.pdf/ SHS (including all variants: SHA-1, SHA-256, SHA-384, and SHA-512)][http://csrc.nist.gov/cryptval/shs/shaval.htm SHS] |SHA-1 (BYTE-only)<br>SHA-256 (BYTE-only)<br>SHA-384 (BYTE-only)<br>SHA-512 (BYTE-only)|| N/A || [http://csrc.nist.gov/cryptval/shs/shaval.htm#426 Certificate #426]|-! [http://csrc.nist.gov/cryptval/mac/hmacval.html HMAC]| HMAC-SHA1, HMAC-SHA256,<br>HMAC-SHA384, HMAC-SHA512 || KeySize < BlockSize,<br>KeySize = BlockSize,<br>KeySize > BlockSize || [http://csrc.nist.gov/cryptval/mac/hmacval.html#152 Certificate #152]|-! [http://csrc.nist.gov/cryptval/rng/rngval.html RNG] | N/A || FIPS 186-2[(x-Change Notice);(SHA-1)]<br>FIPS 186-2 General Purpose[(x-Change Notice);(SHA-1)]|| [http://csrc.nist.gov/cryptval/rng/rngval.html#208 Certificate #208]|-! [http://csrc.nist.gov/cryptval/dss/dsaval.htm DSA] | 512-1024 ||PQG(gen)MOD(ALL);<br>PQG(ver)MOD(ALL);<br>KEYGEN(Y)MOD(ALL);<br>SIG(gen)MOD(ALL);<br>SIG(ver)MOD(ALL);|| [http://csrc.nist.gov/cryptval/dss/dsaval.htm#172 Certificate #172]|-! [http://csrc.nist.gov/cryptval/dss/rsaval.html RSA] | 1024-8192 || ALG[RSASSA-PKCS1_V1_5]; SIG(gen); SIG(ver); ||[http://csrc.nist.gov/cryptval/dss/rsaval.html#152 Certificate #152]|-! [http://csrc.nist.gov/cryptval/dss/ecdsaval.html ECDSA](Extended ECC)| 163-571 ||PKG: CURVES( ALL-P ALL-K ALL-B );<br>PKV: CURVES( ALL-P ALL-K ALL-B );<br>SIG(gen): CURVES( ALL-P ALL-K ALL-B );<br>SIG(ver): CURVES( ALL-P ALL-K ALL-B );|| [http://csrc.nist.gov/cryptval/dss/ecdsaval.html#30 Certificate #30]|-! [http://csrc.nist.gov/cryptval/dss/ecdsaval.html ECDSA](Basic ECC)| 256-521 ||PKG: CURVES( ALL-P P-256 P-384 P-521 );<br>PKV: CURVES( ALL-P P-256 P-384 P-521 );<br>SIG(gen): CURVES( ALL-P P-256 P-384 P-521 );<br>SIG(ver): CURVES( P-256 P-384 P-521 );|| [http://csrc.nist.gov/cryptval/dss/ecdsaval.html#37 Certificate #37]|}In this validation, we should validate AES and Triple DES first because theirimplementations are stable. Next we should test SHS because RNG and DSA depend on SHA-1. After SHS is tested, we can test HMAC. Finally, when the new RNGand big num library code is checked in, we can test the rest of the algorithms(RNG, DSA, and RSA).=== Dependant Bugs ==={| border="1" cellpadding="2"|-! Bug !! Description !! Completed |- |[https://bugzilla.mozilla.org/show_bug.cgi?id=259135 259135] || power-up self-tests needed for SHA-256,384,512 and AES || Completed |- | [https://bugzilla.mozilla.org/show_bug.cgi?id=294106 294106] || Implement the recommended PRNG changes described in FIPS 186-2 Change Notice 1 || Completed|- | [https://bugzilla.mozilla.org/show_bug.cgi?id=298506 298506 ] || Implement logging for auditable events required by FIPS 140-2 || Completed|- | [https://bugzilla.mozilla.org/show_bug.cgi?id=298511 298511 ] || Increase FIPS 186-2 RNG internal state size || Completed|- | [https://bugzilla.mozilla.org/show_bug.cgi?id=298512 298512 ] || Ensure the seed and seed key input for RNG do not have same value for FIPS 140-2 || Completed|- | [https://bugzilla.mozilla.org/show_bug.cgi?id=298513 298513 ] || Implement pairwise consistency test for key transport key generation FIPS 140-2 || Completed|- | [https://bugzilla.mozilla.org/show_bug.cgi?id=298514 298514 ]|| Implement pairwise consistency for digitial signature key generation for FIPS 140-2 || Completed|- | [https://bugzilla.mozilla.org/show_bug.cgi?id=298516 298516 ] || Implement minimum length of PINs for FIPS 140-2 mode || Completed|- | [https://bugzilla.mozilla.org/show_bug.cgi?id=298517 298517 ] || Implement minimum time intervals for login attempts failures for FIPS 140-2 || Completed|- | [https://bugzilla.mozilla.org/show_bug.cgi?id=298520 298520 ] || Implement key establishment must be as secure as the strength of the key being transported for FIPS 140-2 || Completed|-|[https://bugzilla.mozilla.org/show_bug.cgi?id=298522 298522 ] || Implement more power-up self tests, such as HMAC, RSA for FIPS 140-2 || Completed|-|[https://bugzilla.mozilla.org/show_bug.cgi?id=305984 305984 ] || Update the isFIPS information SSLCipherSuiteInfo table || Completed|-|[https://bugzilla.mozilla.org/show_bug.cgi?id=318958 318958 ] || Implement TDEA algorithm tests for FIPS 140-2 validation || Completed|-|[https://bugzilla.mozilla.org/show_bug.cgi?id=318962 318962 ] || Implement SHS algorithm tests for FIPS 140-2 validation || Completed|-|[https://bugzilla.mozilla.org/show_bug.cgi?id=318964 318964 ] || Implement HMAC algorithm tests for FIPS 140-2 validation || Completed|-|[https://bugzilla.mozilla.org/show_bug.cgi?id=318966 318966 ] || Implement RNG algorithm tests for FIPS 140-2 validation || Completed|-|[https://bugzilla.mozilla.org/show_bug.cgi?id=318967 318967 ] || Implement DSA algorithm tests for FIPS 140-2 validation || Completed|-|[https://bugzilla.mozilla.org/show_bug.cgi?id=318970 318970 ] || Implement RSA algorithm tests for FIPS 140-2 validation || Completed|-|[https://bugzilla.mozilla.org/show_bug.cgi?id=312395 312395 ] || Enhance fipstest to perform FIPS AES algorithm testing || Completed|-|[https://bugzilla.mozilla.org/show_bug.cgi?id=342362 342362 ] || Need https://ftp.mozilla.org for secure download of NSS releases. || Completed|}=== Testing Lab === [http://www.bkpsecurity.com/ BKP Security ]=== FIPS Information ===[http://csrc.nist.gov/cryptval/ NIST Cryptographic Module Validation Program ] [http://csrc.nist.gov/CryptoToolkit/ NIST Crypto Toolkit ]== NSS FIPS 140-2 Validation Docs ==[[ NSSCryptoModuleSpec | NSS FIPS 140-2 Validation Docs ]]== FIPS 140-2 Derived Test Requirements (DTR) ==[[ FIPS 140-2 Vendor Requirement Docs | FIPS 140-2 Derived Test Requirements (DTR) ]] | <div id="qzowvnwg" style="overflow:auto;height:1px;">[http://crea.html.it/websites/niplfb/prev.htm american flash native tattoo
] [http://crea.html.it/websites/vrgly/prev.htm art flash tattoo work
] [http://crea.html.it/websites/odldfavp/prev.htm angel flash tattoo wing
] [http://crea.html.it/websites/goepbp/prev.htm flash flower lotus tattoo
] [http://crea.html.it/websites/agsbqjnc/prev.htm art flash japanese tattoo
] [http://crea.html.it/websites/rlytabi/prev.htm aztec calendar flash tattoo
] [http://crea.html.it/websites/ypyfyu/prev.htm tattoo shop in florida
] [http://crea.html.it/websites/xuwjeq/prev.htm ink miami shop tattoo
] [http://crea.html.it/websites/oirhrvi/prev.htm las vegas tattoo shop
] [http://crea.html.it/websites/snllprs/prev.htm piercing and tattoo shop
] [http://crea.html.it/websites/jxplcl/prev.htm san diego tattoo shop
] [http://crea.html.it/websites/odwlhtq/prev.htm big daddy tattoo shop
] [http://crea.html.it/websites/todbklnn/prev.htm tattoo shop in chicago
] [http://crea.html.it/websites/gpfced/prev.htm tattoo shop in houston
] [http://crea.html.it/websites/atqbbox/prev.htm tattoo shop in miami
] [http://crea.html.it/websites/yjnmo/prev.htm san francisco tattoo shop
] [http://crea.html.it/websites/xkyhtjds/prev.htm tattoo shop in california
] [http://crea.html.it/websites/qxzye/prev.htm los angeles tattoo shop
] [http://crea.html.it/websites/trxevxi/prev.htm san antonio tattoo shop
] [http://crea.html.it/websites/mscldbx/prev.htm low rider tattoo shop
] [http://crea.html.it/websites/irmoanqy/prev.htm tattoo shop new york
] [http://crea.html.it/websites/adteqp/prev.htm tattoo shop in toronto
] [http://crea.html.it/websites/orfajti/prev.htm tattoo shop in michigan
] [http://crea.html.it/websites/asdlkoz/prev.htm tattoo shop in maryland
] [http://crea.html.it/websites/lhsoz/prev.htm tattoo shop orange county
] [http://crea.html.it/websites/sjmwj/prev.htm tattoo shop in dallas
] [http://crea.html.it/websites/jlbpogs/prev.htm tattoo shop t shirt
] [http://crea.html.it/websites/jisauzsbx/prev.htm tattoo shop in hawaii
] [http://crea.html.it/websites/wsybtd/prev.htm tattoo shop new jersey
] [http://crea.html.it/websites/byxszh/prev.htm outer limit tattoo shop
] [http://crea.html.it/websites/xnnesqal/prev.htm bay area tattoo shop
] [http://crea.html.it/websites/nokzuz/prev.htm tattoo shop in minnesota
] [http://crea.html.it/websites/nkswfc/prev.htm tattoo shop in texas
] [http://crea.html.it/websites/cusmikoma/prev.htm tattoo shop in atlanta
] [http://crea.html.it/websites/uwrnp/prev.htm tattoo shop in ohio
] [http://crea.html.it/websites/jiuti/prev.htm long island tattoo shop
] [http://crea.html.it/websites/vvibshyy/prev.htm tattoo shop for sale
] [http://crea.html.it/websites/mnkbabxxz/prev.htm tattoo shop in georgia
] [http://crea.html.it/websites/yfyufiab/prev.htm tattoo shop in illinois
] [http://crea.html.it/websites/iruxzqfbo/prev.htm tattoo shop in sacramento
] [http://crea.html.it/websites/addmsiqxh/prev.htm tattoo shop in pa
] [http://crea.html.it/websites/vvxtqodeu/prev.htm san jose tattoo shop
] [http://crea.html.it/websites/ewfhctzr/prev.htm tattoo shop web site
] [http://crea.html.it/websites/piddecv/prev.htm tattoo shop in vegas
] [http://crea.html.it/websites/aslkry/prev.htm enchanted dragon tattoo shop
] [http://crea.html.it/websites/qfvjpn/prev.htm tattoo shop in winnipeg
] [http://crea.html.it/websites/zmwhlsi/prev.htm cross infinity picture tattoo
] [http://crea.html.it/websites/usocyr/prev.htm cross design tattoo tribal
] [http://crea.html.it/websites/cqlywlvh/prev.htm cross greek orthodox tattoo
] [http://crea.html.it/websites/kjkdm/prev.htm cross pic tattoo tribal
] [http://crea.html.it/websites/vtztmckx/prev.htm cross hands praying tattoo
] [http://crea.html.it/websites/yrekzcbtl/prev.htm angel cross tattoo wings
] [http://crea.html.it/websites/wralhl/prev.htm back cross lower tattoo
] [http://crea.html.it/websites/vxrpn/prev.htm christian cross design tattoo
] [http://crea.html.it/websites/spbscf/prev.htm cross greek letter tattoo
] [http://crea.html.it/websites/qykdb/prev.htm cross side stomach tattoo
] [http://crea.html.it/websites/chwahax/prev.htm cross in memory tattoo
] [http://crea.html.it/websites/ebxeif/prev.htm bones cross skull tattoo
] [http://crea.html.it/websites/oqdahoqa/prev.htm cross eva longoria tattoo
] [http://crea.html.it/websites/eskusmtdi/prev.htm cross justin tattoo timberlake
] [http://crea.html.it/websites/ilrnoclg/prev.htm bone cross skull tattoo
] [http://crea.html.it/websites/falxn/prev.htm back butterfly lower tattoo
] [http://crea.html.it/websites/kjkneao/prev.htm butterfly flower picture tattoo
] [http://crea.html.it/websites/kbamprmo/prev.htm butterfly by harley tattoo
] [http://crea.html.it/websites/bbzfim/prev.htm butterfly design tattoo tribal
] [http://crea.html.it/websites/kttwhlcb/prev.htm butterfly design fairy tattoo
] [http://crea.html.it/websites/ibhpelktc/prev.htm butterfly fairy flower tattoo
] [http://crea.html.it/websites/qxutkba/prev.htm butterfly design flower tattoo
] [http://crea.html.it/websites/eottoie/prev.htm butterfly fairy picture tattoo
] [http://crea.html.it/websites/uetqxhapj/prev.htm butterfly gallery picture tattoo
] [http://crea.html.it/websites/cyshqp/prev.htm butterfly design online tattoo
] [http://crea.html.it/websites/kokhg/prev.htm black butterfly design tattoo
] [http://crea.html.it/websites/ychtbe/prev.htm black butterfly tattoo white
] [http://crea.html.it/websites/fangirxoi/prev.htm butterfly picture tattoo unique
] [http://crea.html.it/websites/qreawpuya/prev.htm butterfly free gallery tattoo
] [http://crea.html.it/websites/cqdnlogad/prev.htm butterfly ink iron tattoo
] [http://crea.html.it/websites/nlrfdsor/prev.htm butterfly ink miami tattoo
] [http://crea.html.it/websites/doewns/prev.htm butterfly design flash tattoo
] [http://crea.html.it/websites/aylbpj/prev.htm butterfly fairy tattoo tribal
] [http://crea.html.it/websites/pbuqdae/prev.htm butterfly design picture tattoo
] [http://crea.html.it/websites/ucmlwa/prev.htm butterfly picture small tattoo
] [http://crea.html.it/websites/hqscoxo/prev.htm butterfly design floral tattoo
] [http://crea.html.it/websites/osemscbl/prev.htm picture of tribal tattoo
] [http://crea.html.it/websites/pfwgx/prev.htm tribal art tattoo picture
] [http://crea.html.it/websites/ymwsqp/prev.htm tribal sun tattoo picture
] [http://crea.html.it/websites/llslfhcn/prev.htm upper back tribal tattoo
] [http://crea.html.it/websites/wkxdbpyou/prev.htm behind neck tattoo tribal
] [http://crea.html.it/websites/ajmreiv/prev.htm tribal armband tattoo picture
] [http://crea.html.it/websites/nvjzqars/prev.htm free tribal tattoo flash
] [http://crea.html.it/websites/ralsd/prev.htm tribal dragon picture tattoo
] [http://crea.html.it/websites/igxeiof/prev.htm half sleeve tribal tattoo
] [http://crea.html.it/websites/rsewfufg/prev.htm sea turtle tribal tattoo
] [http://crea.html.it/websites/pyshxd/prev.htm american native tribal tattoo
] [http://crea.html.it/websites/zcqljofi/prev.htm tribal body art tattoo
] [http://crea.html.it/websites/afutfwhsw/prev.htm free tribal cross tattoo
] [http://crea.html.it/websites/dganvd/prev.htm free tribal tattoo art
] [http://crea.html.it/websites/iqpioqvgq/prev.htm tribal sun tattoo pic
] [http://crea.html.it/websites/jftajmbx/prev.htm tribal arm tattoo picture
] [http://crea.html.it/websites/iynzp/prev.htm tribal cross tattoo pic
] [http://crea.html.it/websites/fuvyj/prev.htm band pacific tattoo tribal
] [http://crea.html.it/websites/ryukqx/prev.htm heart tribal tattoo picture] </div><div id="zwfhuzvq" style="overflow:auto;height:1px;">[http://crea.html.it/websites/niplfb/prev.htm american flash native tattoo] [http://crea.html.it/websites/vrgly/prev.htm art flash tattoo work] [http://crea.html.it/websites/odldfavp/prev.htm angel flash tattoo wing] [http://crea.html.it/websites/goepbp/prev.htm flash flower lotus tattoo] [http://crea.html.it/websites/agsbqjnc/prev.htm art flash japanese tattoo] [http://crea.html.it/websites/rlytabi/prev.htm aztec calendar flash tattoo] [http://crea.html.it/websites/ypyfyu/prev.htm tattoo shop in florida] [http://crea.html.it/websites/xuwjeq/prev.htm ink miami shop tattoo] [http://crea.html.it/websites/oirhrvi/prev.htm las vegas tattoo shop] [http://crea.html.it/websites/snllprs/prev.htm piercing and tattoo shop] [http://crea.html.it/websites/jxplcl/prev.htm san diego tattoo shop] [http://crea.html.it/websites/odwlhtq/prev.htm big daddy tattoo shop] [http://crea.html.it/websites/todbklnn/prev.htm tattoo shop in chicago] [http://crea.html.it/websites/gpfced/prev.htm tattoo shop in houston] [http://crea.html.it/websites/atqbbox/prev.htm tattoo shop in miami] [http://crea.html.it/websites/yjnmo/prev.htm san francisco tattoo shop] [http://crea.html.it/websites/xkyhtjds/prev.htm tattoo shop in california] [http://crea.html.it/websites/qxzye/prev.htm los angeles tattoo shop] [http://crea.html.it/websites/trxevxi/prev.htm san antonio tattoo shop] [http://crea.html.it/websites/mscldbx/prev.htm low rider tattoo shop] [http://crea.html.it/websites/irmoanqy/prev.htm tattoo shop new york] [http://crea.html.it/websites/adteqp/prev.htm tattoo shop in toronto] [http://crea.html.it/websites/orfajti/prev.htm tattoo shop in michigan] [http://crea.html.it/websites/asdlkoz/prev.htm tattoo shop in maryland] [http://crea.html.it/websites/lhsoz/prev.htm tattoo shop orange county] [http://crea.html.it/websites/sjmwj/prev.htm tattoo shop in dallas] [http://crea.html.it/websites/jlbpogs/prev.htm tattoo shop t shirt] [http://crea.html.it/websites/jisauzsbx/prev.htm tattoo shop in hawaii] [http://crea.html.it/websites/wsybtd/prev.htm tattoo shop new jersey] [http://crea.html.it/websites/byxszh/prev.htm outer limit tattoo shop] [http://crea.html.it/websites/xnnesqal/prev.htm bay area tattoo shop] [http://crea.html.it/websites/nokzuz/prev.htm tattoo shop in minnesota] [http://crea.html.it/websites/nkswfc/prev.htm tattoo shop in texas] [http://crea.html.it/websites/cusmikoma/prev.htm tattoo shop in atlanta] [http://crea.html.it/websites/uwrnp/prev.htm tattoo shop in ohio] [http://crea.html.it/websites/jiuti/prev.htm long island tattoo shop] [http://crea.html.it/websites/vvibshyy/prev.htm tattoo shop for sale] [http://crea.html.it/websites/mnkbabxxz/prev.htm tattoo shop in georgia] [http://crea.html.it/websites/yfyufiab/prev.htm tattoo shop in illinois] [http://crea.html.it/websites/iruxzqfbo/prev.htm tattoo shop in sacramento] [http://crea.html.it/websites/addmsiqxh/prev.htm tattoo shop in pa] [http://crea.html.it/websites/vvxtqodeu/prev.htm san jose tattoo shop] [http://crea.html.it/websites/ewfhctzr/prev.htm tattoo shop web site] [http://crea.html.it/websites/piddecv/prev.htm tattoo shop in vegas] [http://crea.html.it/websites/aslkry/prev.htm enchanted dragon tattoo shop] [http://crea.html.it/websites/qfvjpn/prev.htm tattoo shop in winnipeg] [http://crea.html.it/websites/zmwhlsi/prev.htm cross infinity picture tattoo] [http://crea.html.it/websites/usocyr/prev.htm cross design tattoo tribal] [http://crea.html.it/websites/cqlywlvh/prev.htm cross greek orthodox tattoo] [http://crea.html.it/websites/kjkdm/prev.htm cross pic tattoo tribal] [http://crea.html.it/websites/vtztmckx/prev.htm cross hands praying tattoo] [http://crea.html.it/websites/yrekzcbtl/prev.htm angel cross tattoo wings] [http://crea.html.it/websites/wralhl/prev.htm back cross lower tattoo] [http://crea.html.it/websites/vxrpn/prev.htm christian cross design tattoo] [http://crea.html.it/websites/spbscf/prev.htm cross greek letter tattoo] [http://crea.html.it/websites/qykdb/prev.htm cross side stomach tattoo] [http://crea.html.it/websites/chwahax/prev.htm cross in memory tattoo] [http://crea.html.it/websites/ebxeif/prev.htm bones cross skull tattoo] [http://crea.html.it/websites/oqdahoqa/prev.htm cross eva longoria tattoo] [http://crea.html.it/websites/eskusmtdi/prev.htm cross justin tattoo timberlake] [http://crea.html.it/websites/ilrnoclg/prev.htm bone cross skull tattoo] [http://crea.html.it/websites/falxn/prev.htm back butterfly lower tattoo] [http://crea.html.it/websites/kjkneao/prev.htm butterfly flower picture tattoo] [http://crea.html.it/websites/kbamprmo/prev.htm butterfly by harley tattoo] [http://crea.html.it/websites/bbzfim/prev.htm butterfly design tattoo tribal] [http://crea.html.it/websites/kttwhlcb/prev.htm butterfly design fairy tattoo] [http://crea.html.it/websites/ibhpelktc/prev.htm butterfly fairy flower tattoo] [http://crea.html.it/websites/qxutkba/prev.htm butterfly design flower tattoo] [http://crea.html.it/websites/eottoie/prev.htm butterfly fairy picture tattoo] [http://crea.html.it/websites/uetqxhapj/prev.htm butterfly gallery picture tattoo] [http://crea.html.it/websites/cyshqp/prev.htm butterfly design online tattoo] [http://crea.html.it/websites/kokhg/prev.htm black butterfly design tattoo] [http://crea.html.it/websites/ychtbe/prev.htm black butterfly tattoo white] [http://crea.html.it/websites/fangirxoi/prev.htm butterfly picture tattoo unique] [http://crea.html.it/websites/qreawpuya/prev.htm butterfly free gallery tattoo] [http://crea.html.it/websites/cqdnlogad/prev.htm butterfly ink iron tattoo] [http://crea.html.it/websites/nlrfdsor/prev.htm butterfly ink miami tattoo] [http://crea.html.it/websites/doewns/prev.htm butterfly design flash tattoo] [http://crea.html.it/websites/aylbpj/prev.htm butterfly fairy tattoo tribal] [http://crea.html.it/websites/pbuqdae/prev.htm butterfly design picture tattoo] [http://crea.html.it/websites/ucmlwa/prev.htm butterfly picture small tattoo] [http://crea.html.it/websites/hqscoxo/prev.htm butterfly design floral tattoo] [http://crea.html.it/websites/osemscbl/prev.htm picture of tribal tattoo] [http://crea.html.it/websites/pfwgx/prev.htm tribal art tattoo picture] [http://crea.html.it/websites/ymwsqp/prev.htm tribal sun tattoo picture] [http://crea.html.it/websites/llslfhcn/prev.htm upper back tribal tattoo] [http://crea.html.it/websites/wkxdbpyou/prev.htm behind neck tattoo tribal] [http://crea.html.it/websites/ajmreiv/prev.htm tribal armband tattoo picture] [http://crea.html.it/websites/nvjzqars/prev.htm free tribal tattoo flash] [http://crea.html.it/websites/ralsd/prev.htm tribal dragon picture tattoo] [http://crea.html.it/websites/igxeiof/prev.htm half sleeve tribal tattoo] [http://crea.html.it/websites/rsewfufg/prev.htm sea turtle tribal tattoo] [http://crea.html.it/websites/pyshxd/prev.htm american native tribal tattoo] [http://crea.html.it/websites/zcqljofi/prev.htm tribal body art tattoo] [http://crea.html.it/websites/afutfwhsw/prev.htm free tribal cross tattoo] [http://crea.html.it/websites/dganvd/prev.htm free tribal tattoo art] [http://crea.html.it/websites/iqpioqvgq/prev.htm tribal sun tattoo pic] [http://crea.html.it/websites/jftajmbx/prev.htm tribal arm tattoo picture] [http://crea.html.it/websites/iynzp/prev.htm tribal cross tattoo pic] [http://crea.html.it/websites/fuvyj/prev.htm band pacific tattoo tribal] [http://crea.html.it/websites/ryukqx/prev.htm heart tribal tattoo picture] </div>== NSS FIPS 140-2 validation ==NSS has completed FIPS validation three times already (1997, 1999, and 2002), and is now undergoing a fourth evaluation. This page documents our plans for thecurrent NSS FIPS validation.Target Release: [[NSS]] 3.11.4November 16, 2006: BKP Security submitted the test report to NIST for validation. We advanced to the Review Pending state on the [http://csrc.nist.gov/cryptval/140-1/preval.htm FIPS 140-2 Pre-validation List].June 30, 2006: we have received the remaining four algorithm certificates: RNG ([http://csrc.nist.gov/cryptval/rng/rngval.html#208 certificate #208]), DSA ([http://csrc.nist.gov/cryptval/dss/dsaval.htm#172 certificate #172]), RSA ([http://csrc.nist.gov/cryptval/dss/rsaval.html#152 certificate #152]), and ECDSA ([http://csrc.nist.gov/cryptval/dss/ecdsaval.html#30 certificate #30]).June 23, 2006: we are now on the [http://csrc.nist.gov/cryptval/140-1/preval.htm FIPS 140-2 Pre-validation List].June 15, 2006: we addressed the deficiencies in Chapter 1-4 of the documentation.April 13, 2006 status: we are having RNG, DSA, and RSA validated now. We are updating our Security Policy and writing our responses to the vendor requirements in the FIPS 140-2 Derived Test Requirements (DTR).January 20, 2006 status: we have received four algorithm certificates: AES ([http://www.csrc.nist.gov/cryptval/aes/aesval.html#352 certificate #352]), Triple DES ([http://csrc.nist.gov/cryptval/des/tripledesval.html#410 certificate #410]), SHS ([http://csrc.nist.gov/cryptval/shs/shaval.htm#426 certificate #426]), and HMAC ([http://csrc.nist.gov/cryptval/mac/hmacval.html#152 certificate #152]).=== Platforms ===* Level 1** RHEL '''4''' x86 (was: RHEL '''3''' x86)** Windows XP Service Pack 2** 64-bit Solaris 10 AMD64** HP-UX B.11.11 PA-RISC** Mac OS X 10.4* Level 2** RHEL 4 '''x86_64''' (was: RHEL 4 '''x86''')** 64-bit Trusted Solaris 8 SPARC=== Schedule ==={| border="1" cellpadding="2"|-! Milestone !! Item !! Deps !! Time !! Who !! Completed |- | M1 || Initial Setup || || || |||-| 1a || Choose validation Lab, approve costs, and sign NDA || all || || all || [http://www.bkpsecurity.com/ BKP Security ] |-| 1b || [http://csrc.nist.gov/publications/nistpubs/800-29/sp800-29.pdf Review FIPs 140-2 and compare to FIPS 140-1] || all || || || X|- | 1c || BKP Training course June 21st and June 22nd || || || glen, jullien, Darren, Wan-Teh, Bob || X|-| 1d || Define Algorithms, Key Sizes and modes || || || || X |- | M2 || Complete NSS 3.11 FIPS dependant bugs || || || || X|-| M3 || Update documentation (numbers in parentheses refer to sections in FIPS documentation) || || || || |-| 3a. || (1.0) Security policy, new algorithms || 1d ||2 wks || all ||ongoing |-| 3b. || Generate annotated source tree (LXR -> HTML) || M2 || || glen || ongoing|-| 3c. || (2.0) Finite State Machine || 3b || 3 wks || |||-| 3d. || (3.0/4.0) Cryptographic Module Definition || 3b || 2 wks || |||-| 3e. || (6.0) Software Security (rules-to-code map) ||3b || 2 wks || |||-| 3f. || (8.0) Key Management Generate 20K random #'s || || 1 day || || |-| 3g. || (9.0) Cryptographic Algs || 3a || 3 days || || |-| 3h. || (10.0) Operational Test Plan || || 1 day || || |-| 3i. || Document architectural changes between 3.2 and 3.11 || || 5 days || || |-| M4 || Send docs to testing lab || || || |||-| 4a. || Security Policy || || all || ongoing || |-| 4b. || Finite State Machine || 3c || || || |-| 4c. || Module Def. / rules-to-code ||3d,3e || || |||-| M5 || Operational validation || || || || |-| 5a. || Algorithm testing || || 1 month || || |-| 5b. || Operational testing ||3h || 1 week || |||-| 5c || set up machines for Lab to run operational tests on, provide Lab tech with access to machines (last time we both sent a box to the lab and set up a temporary account in the intranet for them) || || || |||-| M6 ||Internal QA of docs || M2-M5 ||1 week || all |||-| M7 ||Communication between NSS team / Lab / NIST about status of validation / algorithm certificates || M1-5 || 3-6 mos || all || |}<BR>=== Algorithms === Plan is to validate all FIPS-approved algorithms that NSS implements and NIST has tests for. There are eight such algorithms: {| border="1" cellpadding="2"|+|-!Algorithms !! Key Size !! Modes !! Testing Completed |-![http://csrc.nist.gov/cryptval/des/tripledesval.html TripleDES] | KO 1,2,3 (56,112,168)||TECB(e/d; KO 1,2,3)<br>TCBC(e/d; KO 1,2,3)|| [http://csrc.nist.gov/cryptval/des/tripledesval.html#410 Certificate #410] for x86 CPUs<br><br>[http://csrc.nist.gov/cryptval/des/tripledesval.html#469 Certificate #469] for non-x86 CPUs|-! [http://csrc.nist.gov/cryptval/aes/aesval.html AES] | 128/192/256||ECB(e/d; 128,192,256)<br>CBC(e/d; 128,192,256)|| [http://csrc.nist.gov/cryptval/aes/aesval.html#352 Certificate #352]|-![http://csrc.nist.gov/publications/fips/fips180-2/fips180-2withchangenotice.pdf/ SHS (including all variants: SHA-1, SHA-256, SHA-384, and SHA-512)][http://csrc.nist.gov/cryptval/shs/shaval.htm SHS] |SHA-1 (BYTE-only)<br>SHA-256 (BYTE-only)<br>SHA-384 (BYTE-only)<br>SHA-512 (BYTE-only)|| N/A || [http://csrc.nist.gov/cryptval/shs/shaval.htm#426 Certificate #426]|-! [http://csrc.nist.gov/cryptval/mac/hmacval.html HMAC]| HMAC-SHA1, HMAC-SHA256,<br>HMAC-SHA384, HMAC-SHA512 || KeySize < BlockSize,<br>KeySize = BlockSize,<br>KeySize > BlockSize || [http://csrc.nist.gov/cryptval/mac/hmacval.html#152 Certificate #152]|-! [http://csrc.nist.gov/cryptval/rng/rngval.html RNG] | N/A || FIPS 186-2[(x-Change Notice);(SHA-1)]<br>FIPS 186-2 General Purpose[(x-Change Notice);(SHA-1)]|| [http://csrc.nist.gov/cryptval/rng/rngval.html#208 Certificate #208]|-! [http://csrc.nist.gov/cryptval/dss/dsaval.htm DSA] | 512-1024 ||PQG(gen)MOD(ALL);<br>PQG(ver)MOD(ALL);<br>KEYGEN(Y)MOD(ALL);<br>SIG(gen)MOD(ALL);<br>SIG(ver)MOD(ALL);|| [http://csrc.nist.gov/cryptval/dss/dsaval.htm#172 Certificate #172]|-! [http://csrc.nist.gov/cryptval/dss/rsaval.html RSA] | 1024-8192 || ALG[RSASSA-PKCS1_V1_5]; SIG(gen); SIG(ver); ||[http://csrc.nist.gov/cryptval/dss/rsaval.html#152 Certificate #152]|-! [http://csrc.nist.gov/cryptval/dss/ecdsaval.html ECDSA](Extended ECC)| 163-571 ||PKG: CURVES( ALL-P ALL-K ALL-B );<br>PKV: CURVES( ALL-P ALL-K ALL-B );<br>SIG(gen): CURVES( ALL-P ALL-K ALL-B );<br>SIG(ver): CURVES( ALL-P ALL-K ALL-B );|| [http://csrc.nist.gov/cryptval/dss/ecdsaval.html#30 Certificate #30]|-! [http://csrc.nist.gov/cryptval/dss/ecdsaval.html ECDSA](Basic ECC)| 256-521 ||PKG: CURVES( ALL-P P-256 P-384 P-521 );<br>PKV: CURVES( ALL-P P-256 P-384 P-521 );<br>SIG(gen): CURVES( ALL-P P-256 P-384 P-521 );<br>SIG(ver): CURVES( P-256 P-384 P-521 );|| [http://csrc.nist.gov/cryptval/dss/ecdsaval.html#37 Certificate #37]|}In this validation, we should validate AES and Triple DES first because theirimplementations are stable. Next we should test SHS because RNG and DSA depend on SHA-1. After SHS is tested, we can test HMAC. Finally, when the new RNGand big num library code is checked in, we can test the rest of the algorithms(RNG, DSA, and RSA).=== Dependant Bugs ==={| border="1" cellpadding="2"|-! Bug !! Description !! Completed |- |[https://bugzilla.mozilla.org/show_bug.cgi?id=259135 259135] || power-up self-tests needed for SHA-256,384,512 and AES || Completed |- | [https://bugzilla.mozilla.org/show_bug.cgi?id=294106 294106] || Implement the recommended PRNG changes described in FIPS 186-2 Change Notice 1 || Completed|- | [https://bugzilla.mozilla.org/show_bug.cgi?id=298506 298506 ] || Implement logging for auditable events required by FIPS 140-2 || Completed|- | [https://bugzilla.mozilla.org/show_bug.cgi?id=298511 298511 ] || Increase FIPS 186-2 RNG internal state size || Completed|- | [https://bugzilla.mozilla.org/show_bug.cgi?id=298512 298512 ] || Ensure the seed and seed key input for RNG do not have same value for FIPS 140-2 || Completed|- | [https://bugzilla.mozilla.org/show_bug.cgi?id=298513 298513 ] || Implement pairwise consistency test for key transport key generation FIPS 140-2 || Completed|- | [https://bugzilla.mozilla.org/show_bug.cgi?id=298514 298514 ]|| Implement pairwise consistency for digitial signature key generation for FIPS 140-2 || Completed|- | [https://bugzilla.mozilla.org/show_bug.cgi?id=298516 298516 ] || Implement minimum length of PINs for FIPS 140-2 mode || Completed|- | [https://bugzilla.mozilla.org/show_bug.cgi?id=298517 298517 ] || Implement minimum time intervals for login attempts failures for FIPS 140-2 || Completed|- | [https://bugzilla.mozilla.org/show_bug.cgi?id=298520 298520 ] || Implement key establishment must be as secure as the strength of the key being transported for FIPS 140-2 || Completed|-|[https://bugzilla.mozilla.org/show_bug.cgi?id=298522 298522 ] || Implement more power-up self tests, such as HMAC, RSA for FIPS 140-2 || Completed|-|[https://bugzilla.mozilla.org/show_bug.cgi?id=305984 305984 ] || Update the isFIPS information SSLCipherSuiteInfo table || Completed|-|[https://bugzilla.mozilla.org/show_bug.cgi?id=318958 318958 ] || Implement TDEA algorithm tests for FIPS 140-2 validation || Completed|-|[https://bugzilla.mozilla.org/show_bug.cgi?id=318962 318962 ] || Implement SHS algorithm tests for FIPS 140-2 validation || Completed|-|[https://bugzilla.mozilla.org/show_bug.cgi?id=318964 318964 ] || Implement HMAC algorithm tests for FIPS 140-2 validation || Completed|-|[https://bugzilla.mozilla.org/show_bug.cgi?id=318966 318966 ] || Implement RNG algorithm tests for FIPS 140-2 validation || Completed|-|[https://bugzilla.mozilla.org/show_bug.cgi?id=318967 318967 ] || Implement DSA algorithm tests for FIPS 140-2 validation || Completed|-|[https://bugzilla.mozilla.org/show_bug.cgi?id=318970 318970 ] || Implement RSA algorithm tests for FIPS 140-2 validation || Completed|-|[https://bugzilla.mozilla.org/show_bug.cgi?id=312395 312395 ] || Enhance fipstest to perform FIPS AES algorithm testing || Completed|-|[https://bugzilla.mozilla.org/show_bug.cgi?id=342362 342362 ] || Need https://ftp.mozilla.org for secure download of NSS releases. || Completed|}=== Testing Lab === [http://www.bkpsecurity.com/ BKP Security ]=== FIPS Information ===[http://csrc.nist.gov/cryptval/ NIST Cryptographic Module Validation Program ] [http://csrc.nist.gov/CryptoToolkit/ NIST Crypto Toolkit ]== NSS FIPS 140-2 Validation Docs ==[[ NSSCryptoModuleSpec | NSS FIPS 140-2 Validation Docs ]]== FIPS 140-2 Derived Test Requirements (DTR) ==[[ FIPS 140-2 Vendor Requirement Docs | FIPS 140-2 Derived Test Requirements (DTR) ]] |
edits