808bits

Luna® PCI-E Cryptographic Module

FIPS 140-2 certificate #2036 · SafeNet, Inc. · data as of 2026-08-28
Historical. SP 800-131A transition which disallows key wrapping not compliant to SP 800-38F.. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode and initialized to Overall Level 3 per Security Policy

Certificate

Certificate number2036
StandardFIPS 140-2
Statushistorical
Overall level3
Module typeHardware
EmbodimentMulti-chip embedded
VendorSafeNet, Inc. · website
Hardware versionsVBD-05, Version Code 0103
Firmware versions6.3.1

Module description

The Luna® PCI-E for Luna® IS cryptographic module features powerful cryptographic processing and hardware key management for applications where performance and security are the priority. The multi-chip embedded hardware cryptographic module offers hardware-based key management and cryptographic operations to protect sensitive keys. The cryptographic boundary of the module is defined to encompass all components inside the secure enclosure on the PCI-E card.

Approved algorithms

AlgorithmCAVP certificate
AES1756, 2262, 2282
DRBG277
DSA548, 704, 712
ECDSA233, 364, 369
HMAC1386, 1398
KAS38
KBKDF6
RSA1159, 1173
SHS1947, 1964
Triple-DES1137, 1414, 1430
Triple-DES MAC

Other algorithms

ARIA; AES MAC (Cert. #2282; non-compliant); CAST5; CAST5-MAC; CAST5-ECB; CAST5-CBC; DES; DES MAC; DES-ECB; DES-CBC; GENERIC-SECRET; HAS-160; KCDSA; MD2; MD5; RC2; RC2-MAC; RC2-ECB; RC2-CBC; RC4; RC5; RC5-MAC; RC5-ECB; RC5-CBC; RSA (X-509; non-compliant); SEED; SSL3-MD5-MAC; SSL3-SHA1-MAC; SSL PRE-MASTER; Diffie-Hellman (key agreement; key establishment methodology provides 112 bits of encryption strength; non-compliant less than 112 bits of encryption strength); EC Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength; non-compliant less than 112 bits of encryption strength); RSA (key wrapping; key establishment methodology provides between 112 and 152 bits of encryption strength; non-compliant less than 112 bits of encryption strength); RSA OAEP (key wrapping; key establishment methodology provides between 112 and 152 bits of encryption strength; non-compliant less than 112 bits of encryption strength); AES (Certs. #1756, #2262 and #2282, key wrapping; key establishment methodology provides between 128 and 256 bits of encryption strength); Triple-DES (Certs. #1137, #1414 and #1430, key wrapping; key establishment methodology provides 112 bits of encryption strength; non-compliant less than 112 bits of encryption strength)

Validation history

DateTypeLab
2013-11-13InitialCGI Information Systems & Management Consultants Inc
2017-01-10UpdateCGI Information Systems & Management Consultants Inc
2017-06-23Update
2017-06-23Update

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2013-11-13, 2017-01-10, 2017-06-23, 2017-06-23

Source documents