RSA BSAFE® Crypto-Kernel
RSA BSAFE® Crypto-Kernel, from RSA, The Security Division of EMC, holds FIPS 140-2 certificate #1159 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.
Caveat: When operated in FIPS mode
Certificate
| Certificate number | 1159 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-chip standalone |
| Vendor | RSA, The Security Division of EMC · website |
| Software versions | 1.3.1 [1] and 1.3.1.1 [2] |
Module description
Quoted from the NIST CMVP entry for this certificate.
RSA BSAFE® Crypto-Kernel is a cryptographic library from RSA, The Security Division of EMC, to provide symmetric encryption, hashing, and message authentication code creation, in the operating system kernel. It provides Advanced Encryption Standard (AES) cipher, SHA-256 message digest, and HMAC capabilities.
Approved algorithms (3)
Other algorithms
AES-XTS
Tested configurations
- Windows Server 2003 SP2 (Itanium 2) [1]
- Windows Server 2003 SP2 (x64 AMD Athlon X2) [2] (single-user mode)
- Windows Server 2003 SP2 (x86 Celeron) [1]
Validation history
| Date | Type | Lab |
|---|---|---|
| 2009-07-29 | Initial | SAIC-VA |
| 2010-08-20 | Update | |
| 2010-09-07 | Update | SAIC-VA |
| 2016-02-12 | Update | Leidos Accredited Testing & Evaluation (AT&E) Lab |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2009-07-29, 2010-08-20, 2010-09-07, 2016-02-12