Verify the Security Engine self-tests

The Security Engine contains the Forcepoint Network Security Platform FIPS Library, Forcepoint Network Security Platform FIPS Cryptographic Module, and Forcepoint Network Security Platform Cryptographic Kernel Module. The modules run several self-tests when the Forcepoint Network Security Platform appliance starts.

The modules perform these tests:

  • Cryptographic Algorithm Self-Tests (CAST) implemented as Known Answer Tests (KAT)
  • Forcepoint Network Security Platform FIPS Library self-tests
  • Forcepoint Network Security Platform FIPS Cryptographic Module self-tests
  • Forcepoint Network Security Platform Cryptographic Kernel Module self-tests
Table 1. Forcepoint Network Security Platform FIPS Library self-tests
Algorithm Type Test Method
HMAC-SHA2- 256 SW/FW Integrity Message Authentication
AES-ECB CAST KAT
AES-GCM CAST KAT
Counter DRBG CAST KAT
DSA SigGen (FIPS186-4) CAST KAT
DSA SigVer (FIPS186-4) CAST KAT
ECDSA SigGen (FIPS186-4) CAST KAT
ECDSA SigVer (FIPS186-4) CAST KAT
Hash DRBG CAST KAT
HMAC DRBG CAST KAT
HMAC-SHA2-256 CAST KAT
KASECC-SSC Sp800-56Ar3 CAST KAT
KAS-FFCSSC Sp800-56Ar3 CAST KAT
KAS-IFCSSC CAST KAT
KDF SP800-108 CAST KAT
KDA OneStep SP800-56Cr2 CAST KAT
KDA TwoStep SP800-56Cr2 CAST KAT
KTS-IFC CAST KAT
KTS-IFC CAST KAT
PBKDF CAST KAT
RSA SigGen (FIPS186-4) CAST KAT
RSA SigVer (FIPS186-4) CAST KAT
SHA-1 CAST KAT
SHA2-512 CAST KAT
SHA3-256 CAST KAT
KDF ANS 9.42 CAST KAT
KDF ANS 9.63 CAST KAT
KDF SSH CAST KAT
TLS v1.2 KDF RFC7627 CAST KAT
TLS v1.3 KDF CAST KAT
RSA KeyGen (FIPS186-4) Pair-Wise Consistency Test PCT
ECDSA KeyGen (FIPS186-4) Pair-Wise Consistency Test PCT
DSA KeyGen (FIPS186-4) Pair-Wise Consistency Test PCT
ECDSA SigGen (FIPS186-4) CAST KAT
ECDSA SigVer (FIPS186-4) CAST KAT
HMAC-SHA2-256 CAST KAT
AES-ECB CAST KAT
AES-GCM CAST KAT
AES-GCM CAST KAT
Counter DRBG CAST KAT
DSA SigGen (FIPS186-4) CAST KAT
DSA SigVer (FIPS186-4) CAST KAT
ECDSA SigGen (FIPS186-4) CAST KAT
ECDSA SigVer (FIPS186-4) CAST KAT
Hash DRBG CAST KAT
HMAC DRBG CAST KAT
HMAC-SHA2-256 CAST KAT
KAS-ECC-SSC Sp800-56Ar3 CAST KAT
KAS-FFC-SSC Sp800-56Ar3 CAST KAT
KAS-IFC-SSC CAST KAT
KDF SP800-108 CAST KAT
KDA OneStep SP800-56Cr2 CAST KAT
KDA TwoStep SP800-56Cr2 CAST KAT
KTS-IFC CAST KAT
KTS-IFC CAST KAT
PBKDF CAST KAT
RSA SigGen (FIPS186-4) CAST KAT
RSA SigVer (FIPS186-4) CAST KAT
SHA-1 CAST KAT
SHA2-512 CAST KAT
SHA3-256 CAST KAT
KDF ANS 9.42 CAST KAT
KDF ANS 9.63 CAST KAT
KDF SSH CAST KAT
TLS v1.2 KDF RFC7627 CAST KAT
TLS v1.3 KDF CAST KAT
RSA KeyGen (FIPS186-4) Pair-Wise Consistency Test PCT
ECDSA KeyGen (FIPS186-4) Pair-Wise Consistency Test PCT
DSA KeyGen (FIPS186-4) Pair-Wise Consistency Test PCT
ECDSA SigGen (FIPS186-4) CAST KAT
ECDSA SigVer (FIPS186-4) CAST KAT
Table 2. Forcepoint Network Security Platform FIPS Cryptographic Module self-tests
Algorithm Type Test Method
ECDSA signature verify with NIST P-224 and SHA2-224 Software Integrity  
SHA-1 CAST KAT
SHA2-512 CAST KAT
SHA3-224 CAST KAT
HMAC-SHA2-256 CAST KAT
AES-CBC encryption (128-bit key) CAST KAT
AES-CBC decryption (128-bit key) CAST KAT
AES-CCM encryption (128-bit key) CAST KAT
AES-CCM decryption (128-bit key) CAST KAT
AES-GCM encryption (128-bit key) CAST KAT
AES-GCM decryption (128-bit key) CAST KAT
AES-XTS encryption (128-bit key strength) CAST KAT
AES-XTS decryption (128-bit key strength) CAST KAT
AES-CMAC (192-bit key) CAST KAT
TDES-CBC encryption (192-bit key) CAST KAT
TDES-CBC decryption (192-bit key) CAST KAT
Counter DRBG AES-256 (instantiate, generate and reseed; includes AES-ECB mode encryption) CAST KAT
RSA SigGen 2048-bit with SHA2-256 CAST KAT
RSA SigVer 2048-bit with SHA2-256 CAST KAT
DSA SigGen (P=2048/N=256 with SHA2-224) CAST KAT
DSA SigVer (P=1024/N=160 with SHA2-224) CAST KAT
ECDSA SigGen (NIST P-224 with SHA2-224) CAST KAT
ECDSA SigVer (NIST P-224 with SHA2-224) CAST KAT
KTS-IFC Key Encapsulation 2048-bit (RSA-OAEP) CAST KAT
KTS-IFC Key Un-encapsulation 2048-bit (RSA-OAEP) CAST KAT
KAS-FFC-SSC (P=2048/N=224) CAST KAT
KAS-ECC-SSC (NIST P-224) CAST KAT
KDF SP800-108 (Counter Mode) CAST KAT
KDA HKDF (includes KDF SP800-108 Feedback Mode) CAST KAT
KDF SP800-108 (Double Pipeline Mode) CAST KAT
KDF IKEv1 CAST KAT
KDF IKEv2 CAST KAT
TLS v1.2 KDF RFC7627 CAST KAT
SP 800-90A-r1, (Instantiate/Generate) health tests for Counter DRBG AES-256 CAST KAT
SP 800-90A-r1, (Reseed) health test Counter DRBG AES-256 CAST KAT
SP 800-90B, start-up and continuous health tests (RCT and APT) for JitterEntropy ENT (NP) CAST Fault Detection Tests
Table 3. Forcepoint Network Security Platform Cryptographic Kernel Module self-tests
Algorithm Type Test Method
HMAC-SHA2-256 Software Integrity Message Authentication
AES encryption (AES-CBC, AES-CFB128, AES-ECB, AES-OFB 128, 192, 256) CAST KAT
AES decryption (AES-CBC, AES-CFB128, AES-ECB, AES-OFB 128, 192, 256) CAST KAT
AES-GCM 128 authenticated encryption CAST KAT
AES-GCM 128 authenticated decryption CAST KAT
SHA (SHA-1, SHA2-256, SHA2- 512) CAST KAT
HMAC (HMAC-SHA-1, HMACSHA2-256, HMAC-SHA2- 512) CAST KAT

Check the self-test results in the console.

  • If a cryptographic self-test or a noise source health test fails, an error message is shown on the console and the appliance is restarted automatically. Noise source health tests are automatically executed as part of the self-tests when Forcepoint Network Security Platform FIPS Library and Forcepoint Network Security Platform FIPS Cryptographic Module are loaded.
    FIPS: OpenSSL self-tests FAILED, rebooting…
    Cryptographic Kernel Module self tests failed
    FIPS: Cryptographic module self-tests FAILED, rebooting...
    FIPS: rootfs integrity check FAILED, rebooting…

Next steps

  • If the self-tests succeed, continue configuring the Security Engine.
  • If the problem persists, reset the Security Engine to factory settings.
    To reset the Security Engine, do the following:
    1. Power off the Security Engine.
    2. Power on the Security Engine, and select the System restore options option from the local console boot menu.
    3. Follow the instructions to reset the Security Engine.