808bits

Microsoft Windows Server 2008 Kernel Mode Security Support Provider Interface (ksecdd.sys)

FIPS 140-2 certificate #1007 · Microsoft Corporation · data as of 2026-08-28
Historical. RNG SP800-131A Revision 1 Transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode with Windows Server 2008 OS Loader (winload.exe) validated to FIPS 140-2 under Cert. #1005 operating in FIPS mode

Certificate

Certificate number1007
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-chip standalone
VendorMicrosoft Corporation · website
Software versions6.0.6001.18709, 6.0.6001.18272, 6.0.6001.18796, 6.0.6001.22202, 6.0.6001.22450, 6.0.6001.22987, 6.0.6001.23069, 6.0.6002.18005, 6.0.6002.18051, 6.0.6002.18541, 6.0.6002.18643, 6.0.6002.22152, 6.0.6002.22742 and 6.0.6002.22869

Module description

KSECDD.SYS runs as a kernel mode export driver, and provides cryptographic services, through their documented interfaces, to Windows Vista kernel components. It supports several cryptographic algorithms accessible via a FIPS function table request irp (I/O request packet).

Approved algorithms

AlgorithmCAVP certificate
AES739, 757
ECDSA83
HMAC413
RNG435
RSA353, 358
SHS753
Triple-DES656

Other algorithms

AES (GCM and GMAC; non-compliant); DES; Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 150 bits of encryption strength; non-compliant less than 112 bits of encryption strength); EC Diffie-Hellman (key agreement; key establishment methodology provides between 128 and 256 bits of encryption strength); MD2; MD4; MD5; HMAC MD5; RC2; RC4; RNG (SP 800-90 Dual-EC; non-compliant); RSA (key wrapping: key establishment methodology provides between 112 and 150 bits of encryption strength; non-compliant less than 112 bits of encryption strength)

Tested configurations

  • Microsoft Windows Server 2008 (IA64 version) (single-user mode)
  • Microsoft Windows Server 2008 (x64 version)
  • Microsoft Windows Server 2008 (x86 Version)

Validation history

DateTypeLab
2008-08-15InitialSAIC-VA
2009-02-23Update
2009-07-30Update
2009-10-16Update
2012-02-09UpdateSAIC-VA
2012-09-27UpdateSAIC-VA

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2008-08-15, 2009-02-23, 2009-07-30, 2009-10-16, 2012-02-09, 2012-09-27

Source documents