How to prove .Net app FIPS compliance referencing NIST CMVP Certificate
There appears to be no supported version of Windows Server with active FIPS certificates for the Cryptographic Primitives Library and Kernel Mode Cryptographic Primitives Library.
Needing to prove how .Net app is FIPS compliant by referencing the FIPS certificate numbers available in the NIST CMVP for Windows Server. Since the application runs on Windows Server I assume that .Net Framework and IIS derive cryptographic functions from the underlying Windows CNG API. Does the hierarchy of cryptographic functions flow from .Net to the Cryptographic Primitives Library (bcrypt.dll) then to the Kernel Mode Cryptographic Primitives Library (cng.sys)? And does that mean I will have to reference both bcrypt.dll and cng.sys FIPS certificates? If so, I do not see a current FIPS certificate for a supported version of Server 2019 for Cryptographic Primitives Library.