808bits

ProtectServer Gold (PSG)

FIPS 140-2 certificate #1137 · SafeNet, Inc. · data as of 2026-09-03

ProtectServer Gold (PSG), from SafeNet, Inc., holds FIPS 140-2 certificate #1137 at overall level 3. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. RNG SP800-131A Revision 1 Transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode

Certificate

Certificate number1137
StandardFIPS 140-2
Statushistorical
Overall level3
Module typeHardware
EmbodimentMulti-chip standalone
VendorSafeNet, Inc. · website
Hardware versionsRevision B2 and B3 [1], B4 [2] or C [3]
Firmware versions2.07.00[2], 2.08.00 [1-3] or 3.00.03 [2]

Module description

Quoted from the NIST CMVP entry for this certificate.

The SafeNet PSG Adapter is a high-end intelligent PCI adapter card that provides a wide range of cryptographic functions using firmware and dedicated hardware processors. Access to the PSG is provided via a comprehensive PKCS#11 API, allowing extremely flexible use of the module in a multitude of applications.

Approved algorithms (9)

AlgorithmCAVP certificates
AES921, 1582
DSA329, 488
ECDSA114, 193
HMAC515, 928
RNG529, 851
RSA448, 772
SHS908, 1401
Triple-DES741, 1038
Triple-DES MACvendor affirmed

Other algorithms

AES MAC (AES Certs. #921 and #1582; non-compliant); ARIA, and ARIA MAC; CAST 128; CAST MAC; DES; DES MAC; Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 152 bits of encryption strength; non-compliant less than 112 bits of encryption strength); EC Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength; non-compliant less than 112 bits of encryption strength); ECIES; IDEA; IDEA MAC; MD2; MD5; MD5 HMAC; RC2; RC2 MAC; RC4; RIPEMD-128; RIPEMD-160; RMD128 HMAC; RMD160 HMAC; RSA (key wrapping; key establishment methodology provides between 112 and 152 bits of encryption strength; non-compliant less than 112 bits of encryption strength); SEED; SEED MAC

Validation history

DateTypeLab
2009-05-22InitialSAIC-VA
2009-07-24Update
2011-03-28UpdateSAIC-VA
2011-11-08UpdateSAIC-VA

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2009-05-22, 2009-07-24, 2011-03-28, 2011-11-08

Source documents