2016 Symantec Corporation This document may be freely reproduced & distributed whole & intact including this copyright
notice.
42
SV3800, SV3800B, and SV3800B-20 Security Policy
• SHA-256
• SHA-384
• SHA-512
•
RSA known answer tests (KAT) on both NFPs hardware based
encryption using 2048-bit (encrypt and decrypt)
•
RSA known answer tests (KAT) on software based encryption using
2048-bit (encrypt and decrypt)
•
HMAC known answer tests (KAT) on software using the following digests
•
SHA-1
• SHA-224
• SHA-256
• SHA-384
• SHA-512
•
SHA known answer tests (KAT) on software hash for the following
•
SHA-1
• SHA-224
• SHA-256
• SHA-384
• SHA-512
•
SP 800-90A CTR DRBG known answer test (KAT)
•
TRNG duplicate and zero output tests
•
ECDSA known answer tests (KAT) (P-224, K-233 and SHA512)
All POSTs are run automatically at start-up. If an error is encountered, the system
enters an error state and powers off. The firmware integrity test outputs an error
message to the VGA console, serial console, and front panel LCD. Error messages
for all other POSTs are output to the system log file and to the front panel LCD.
Once the POSTs have passed, the Crypto Officer can enter the PIN to begin the
process of unlocking the secure store and allowing the system to begin operation.
The SV3800 carries out the following conditional self tests:
•
Continuous Random Number Generator test for FIPS approved SP
800-90A CTR DRBG
•
Continuous NDRNG duplicate and zero output tests when seeding SP 800-
90A CTR DRBG
•
Continuous TRNG duplicate and zero output tests
•
RSA pairwise consistency test when generating 186-4 RSA keys in software
•
ECDSA pairwise consistency test when generating 186-4 ECDSA keys in
software
•
Firmware update test (RSA 2048 bit SHA-256)
If an error is encountered in the self tests, the appliance will enter the error state.
Error messages are output to the system log file and to the front panel LCD.