Microsoft Windows 8, Microsoft Windows Server 2012, Microsoft Windows RT, Microsoft Surface Windows RT, Microsoft Surface Windows 8 Pro, Microsoft Windows Phone 8, and Microsoft Windows Storage Server 2012 Enhanced DSS and Diffie-Hellman Cryptographic Provider (DSSENH.DLL)
Certificate
| Certificate number | 1893 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-chip standalone |
| Vendor | Microsoft Corporation · website |
| Software versions | 6.2.9200 |
Module description
The Enhanced DSS and Diffie-Hellman Cryptographic Provider (DSSENH.DLL) encapsulates several different cryptographic algorithms in an easy-to-use cryptographic module accessible via the Microsoft CryptoAPI. It can be dynamically linked into applications by software developers to permit the use of general-purpose FIPS 140-2 validated cryptography. This cryptographic module also maintains FIPS 140-2 validation compliance (according to FIPS 140-2 PUB Implementation Guidance G.5) on Microsoft Windows 8, Microsoft Windows 8 Pro, and Microsoft Windows Server 2012 Datacenter.
Security level exceptions
- Design Assurance: Level 2
Approved algorithms
Other algorithms
DES; DES MAC; DES40; DES40 MAC; Diffie-Hellman; MD5; RC2; RC2 MAC; RC4; Triple-DES (Cert. #1386, key wrapping; key establishment methodology provides 112 bits of encryption strength; non-compliant less than 112 bits of encryption strength)
Tested configurations
- Microsoft Windows 8 Enterprise (x64) running on a Dell PowerEdge SC430 without PAA
- Microsoft Windows 8 Enterprise (x64) running on Intel Core i7 with PAA running on an Intel Client Desktop
- Microsoft Windows 8 Enterprise (x86) running on a Dell Dimension C521
- Microsoft Windows 8 Pro (x64) running on an Intel x64 Processor with PAA running on a Microsoft Surface Windows 8 Pro
- Microsoft Windows Phone 8 (ARMv7 Thumb-2) running on a Windows Phone 8
- Microsoft Windows RT (ARMv7 Thumb-2) running on a Microsoft Surface Windows RT
- Microsoft Windows RT (ARMv7 Thumb-2) running on a Qualcomm Tablet
- Microsoft Windows RT (ARMv7 Thumb-2) running on an NVIDIA Tegra 3 Tablet
- Microsoft Windows Server 2012 (x64) running on a Dell PowerEdge SC430 without PAA
- Microsoft Windows Server 2012 (x64) running on Intel Core i7 with PAA running on an Intel Client Desktop
- Microsoft Windows Storage Server 2012 (x64) running on an Intel Maho Bay with PAA
- Microsoft Windows Storage Server 2012 (x64) running on an Intel Maho Bay without PAA (single-user mode)
Validation history
| Date | Type | Lab |
|---|---|---|
| 2013-09-13 | Initial | Leidos Accredited Testing & Evaluation (AT&E) Lab |
| 2015-01-09 | Update | Leidos Accredited Testing & Evaluation (AT&E) Lab |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2013-09-13, 2015-01-09