808bits

RSA BSAFE® CNG Cryptographic Primitives Library

FIPS 140-2 certificate #1566 · RSA, The Security Division of EMC · data as of 2026-08-28
Historical. RNG SP800-131A Revision 1 Transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode

Certificate

Certificate number1566
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-chip standalone
VendorRSA, The Security Division of EMC · website
Software versions1.0

Module description

RSA BSAFE® CNG Cryptographic Primitives Library is a drop-in replacement for the Microsoft user-mode CNG (Cryptograpy, Next Generation) provider. It supports a wide range of industry standard encryption algorithms. Software applications written against the Microsoft CNG framework, that do not explicitly request a specific provider, will automatically use the BSAFE CNG cryptographic implementations without modification once the BSAFE CNG Primitive Provider is installed.

Approved algorithms

AlgorithmCAVP certificate
AES1598
DRBG77
DSA493
ECDSA196
HMAC935
RNG855
RSA780
SHS1410
Triple-DES1044

Other algorithms

DES; DESX; Diffie-Hellman; EC Diffie-Hellman; HMAC-MD2; HMAC-MD4; HMAC-MD5; MD2; MD4; MD5; RC2; RC4; RSA (key wrapping; key establishment methodology provides between 112 and 128 bits of encryption strength; non-compliant less than 112 bits of encryption strength)

Tested configurations

  • Microsoft Windows 7 (x86 32-bit)
  • Microsoft Windows 7 (x86_64 64-bit) (single-user mode)

Validation history

DateTypeLab
2011-06-27InitialSAIC-VA
2013-01-24Update

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2011-06-27, 2013-01-24

Source documents