808bits

RSA BSAFE® Crypto-J JSAFE and JCE Software Module

FIPS 140-2 certificate #1785 · RSA, The Security Division of EMC · data as of 2026-08-28
Historical. Revocation due to CVE-2019-3738. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode

Certificate

Certificate number1785
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-chip standalone
VendorRSA, The Security Division of EMC · website
Software versions6.0

Module description

RSA BSAFE® Crypto-J security software is designed to help protect sensitive data as it is stored using strong encryption techniques to provide a persistent level of protection. It supports a wide range of industry standard encryption algorithms offering Java developers the flexibility to choose the option most appropriate to meet their requirements.

Security level exceptions

  • Roles, Services, and Authentication: Level 2
  • Design Assurance: Level 3

Approved algorithms

AlgorithmCAVP certificate
AES1911
DRBG160
DSA604
ECDSA271
HMAC1148
PBKDFvendor affirmed
RSA981
SHS1678
Triple-DES1243

Other algorithms

DES; DESX; Diffie-Hellman; Dual EC DRBG; EC Diffie-Hellman; ECIES; HMAC-MD5; MD2; MD4; MD5; RC2; RC4; RC5; RIPEMD160; RNG; RSA (encrypt/decrypt); RSA Keypair Generation MultiPrime

Tested configurations

  • Android 2.2 ARM (32-bit) JRE 6.0 (single-user mode)
  • Windows 7 (64-bit) with Sun JRE 6.0

Validation history

DateTypeLab
2012-08-24InitialSAIC-VA
2013-01-24Update
2016-02-12UpdateLeidos Accredited Testing & Evaluation (AT&E) Lab
2016-05-03UpdateLeidos Accredited Testing & Evaluation (AT&E) Lab

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2012-08-24, 2013-01-24, 2016-02-12, 2016-05-03

Source documents