CKM_DSA
Firmware 7.9.0 and Newer Summary
FIPS approved? |
Yes |
Supported functions |
Sign | Verify |
Functions restricted from FIPS use |
Cannot sign | Can verify only if PP45 enabled |
Minimum key length (bits) |
1024 |
Minimum key length for FIPS use (bits) |
2048 |
Minimum legacy key length for FIPS use (bits) |
1024 |
Maximum key length (bits) |
3072 |
Block size |
0 |
Digest size |
0 |
Key types |
DSA |
Algorithms |
DSA |
Modes |
None |
Flags |
None |
NOTE Using Luna HSM Firmware 7.9.0 or newer, signature verification is permitted in FIPS approved configuration, as long as partition policy 45: Allow ECDSA/RSA Prehash SigVer is set to 1 on the partition.
Firmware 7.8.7-7.8.9 Summary
FIPS approved? |
Yes |
Supported functions |
Sign | Verify |
Functions restricted from FIPS use |
Cannot sign |
Minimum key length (bits) |
1024 |
Minimum key length for FIPS use (bits) |
2048 |
Minimum legacy key length for FIPS use (bits) |
1024 |
Maximum key length (bits) |
3072 |
Block size |
0 |
Digest size |
0 |
Key types |
DSA |
Algorithms |
DSA |
Modes |
None |
Flags |
None |
Firmware 7.8.4 and Older Summary
FIPS approved? |
Yes |
Supported functions |
Sign | Verify |
Functions restricted from FIPS use |
None |
Minimum key length (bits) |
1024 |
Minimum key length for FIPS use (bits) |
2048 |
Minimum legacy key length for FIPS use (bits) |
1024 |
Maximum key length (bits) |
3072 |
Block size |
0 |
Digest size |
0 |
Key types |
DSA |
Algorithms |
DSA |
Modes |
None |
Flags |
None |