808bits

PGP Software Developer's Kit (SDK) Cryptographic Module

FIPS 140-2 certificate #1049 · PGP Corporation · data as of 2026-08-28
Historical. RNG SP800-131A Revision 1 Transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode

Certificate

Certificate number1049
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-chip standalone
VendorPGP Corporation · website
Software versions3.10.3 and 3.11.0

Module description

The PGP SDK Cryptographic Module is a FIPS 140-2 validated software only cryptographic module. The module implements the cryptographic functions for PGP products including: PGP Whole Disk Encryption, PGP NetShare, PGP Command Line, PGP Universal, and PGP Desktop. It includes a wide range of field-tested and standards-based encryption, digital signature, and encoding algorithms as well as a variety of secure network protocol implementations. The PGP SDK offers developers this same cryptographic library that is at the heart of PGP products.

Approved algorithms

AlgorithmCAVP certificate
AES453
DSA183
HMAC216
RNG238
RSA172
SHS516
Triple-DES471

Other algorithms

AES (EME2 mode; non-compliant); DSA (FIPS 186-3 with SHA-256; non-compliant); CAST-5; IDEA; Two-Fish; Blow-Fish; ARC4-128; MD5; HMAC-MD5; RIPEMD60; ElGamal; RSA (key wrapping; key establishment methodology provides between 112 and 128 bits of encryption strength); Shamir Threshold Secret Sharing

Tested configurations

  • Mac OS X 10.5 (single-user mode)
  • Windows XP Professional SP2

Validation history

DateTypeLab
2008-10-27InitialAEGISOLVE, Inc.
2008-12-03Update

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2008-10-27, 2008-12-03

Source documents