Luna® G5 Cryptographic Module
Luna® G5 Cryptographic Module, from SafeNet, Inc., holds FIPS 140-2 certificate #1958 at overall level 2. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.
Certificate
| Certificate number | 1958 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 2 |
| Module type | Hardware |
| Embodiment | Multi-chip standalone |
| Vendor | SafeNet, Inc. · website |
| Hardware versions | LTK-03, Version Code 0102; LTK-03, Version Code 0103 |
| Firmware versions | 6.2.3 and 6.2.5 |
Module description
Quoted from the NIST CMVP entry for this certificate.
Luna® G5 delivers key management in a portable appliance. All key materials are maintained exclusively within the confines of the hardware. The small form-factor and on-board key storage sets the product apart, making it especially attractive to customers who need to physically remove and store the small appliance holding PKI root keys. The appliance directly connects the HSM to the application server via a USB interface.
Security level exceptions
- Physical Security: Level 3
- EMI/EMC: Level 3
- Design Assurance: Level 3
Approved algorithms (11)
| Algorithm | CAVP certificates |
|---|---|
| AES | 2262, 2263 |
| DRBG | 277 |
| DSA | 704 |
| ECDSA | 364, 365 |
| HMAC | 1386, 1387 |
| KAS | 37 |
| KBKDF | 5 |
| RSA | 1159, 1160 |
| SHS | 1947, 1948 |
| Triple-DES | 1414, 1415 |
| Triple-DES MAC | vendor affirmed |
Other algorithms
DES; RC2; RC4; RC5; CAST5; SEED; ARIA; MD2; MD5; HAS-160; DES-MAC; RC2-MAC; RC5-MAC; CAST5-MAC; SSL3-MD5-MAC; SSL3-SHA1-MAC; KCDSA; Diffie-Hellman (key agreement; key establishment methodology provides 112 or 128 bits of encryption strength); HRNG; AES MAC (AES Cert. #2263; non-compliant); AES (Certs. #2262 and #2263, key wrapping; key establishment methodology provides between 128 and 256 bits of encryption strength); Triple-DES (Certs. #1414 and #1415, key wrapping; key establishment methodology provides 112 bits of encryption strength); Generic-Secret generation (non-compliant); SSL Pre-Master generation (non-compliant); RSA (non-compliant); RSA (key wrapping; key establishment methodology provides between 112 and 152 bits of encryption strength; non-compliant less than 112 bits of encryption strength)
Validation history
| Date | Type | Lab |
|---|---|---|
| 2013-06-11 | Initial | EWA - Canada |
| 2015-08-07 | Update | EWA - Canada |
| 2016-01-22 | Update | EWA - Canada |
| 2016-05-12 | Update | EWA - Canada |
| 2017-01-10 | Update | CGI Information Systems & Management Consultants Inc |
| 2017-06-23 | Update | |
| 2017-06-23 | Update |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2013-06-11, 2015-08-07, 2016-01-22, 2016-05-12, 2017-01-10, 2017-06-23, 2017-06-23