808bits

Windows Embedded Compact Cryptographic Primitives Library (bcrypt.dll)

FIPS 140-2 certificate #1989 · Microsoft Corporation · data as of 2026-09-15

Windows Embedded Compact Cryptographic Primitives Library (bcrypt.dll), from Microsoft Corporation, holds FIPS 140-2 certificate #1989 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy.

Certificate

Certificate number1989
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-chip standalone
VendorMicrosoft Corporation · website
Software versions7.00.1687

Module description

Quoted from the NIST CMVP entry for this certificate.

The Microsoft Windows Cryptographic Primitives Library is a general purpose, software-based, cryptographic module. The primitive provider functionality is offered through one cryptographic module, BCRYPT.DLL (version 7.00.1687), subject to FIPS-140-2 validation. BCRYPT.DLL provides cryptographic services, through its documented interfaces, to Windows Embedded Compact 7 components and applications running on Windows Embedded Compact 7.

Approved algorithms (8)

AlgorithmCAVP certificates
AES2023
DRBG193
DSA645
ECDSA295
HMAC1364
RSA1051
SHS1773
Triple-DES1307

Other algorithms

DES; Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 150 bits of encryption strength; non-compliant less than 112 bits of encryption strength); DES; Dual-EC DRBG (non-compliant); EC Diffie-Hellman (key agreement; key establishment methodology provides between 128 and 256 bits of encryption strength); MD2; MD4; MD5; RC2; RC4; RSA key transport (key agreement; key establishment methodology provides between 112 and 150 bits of encryption strength; non-compliant less than 112 bits of encryption strength)

Tested configurations

  • Windows Embedded Compact 7 running on a Freescale i.MX27 Development Kit with Freescale i.MX27 CPU
  • Windows Embedded Compact 7 running on a Samsung SMDK6410 Development Kit with Samsung SMDK6410 CPU
  • Windows Embedded Compact 7 running on a Sigma Designs Vantage 8654 Development Kit with a Sigma Designs SMP8654 (MIPSII) CPU
  • Windows Embedded Compact 7 running on a Sigma Designs Vantage 8654 Development Kit with a Sigma Designs SMP8654 (MIPSII_FP) CPU
  • Windows Embedded Compact 7 running on a TI OMAP TMDSEVM3530 with Texas Instruments EVM3530 CPU
  • Windows Embedded Compact 7 running on an eBox-330-A with MSTI PDX-600 CPU (single-user mode)

Validation history

DateTypeLab
2013-08-13InitialSAIC-VA

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2013-08-13

Source documents