808bits

RSA BSAFE® Crypto-J JSAFE and JCE Software Module

FIPS 140-2 certificate #2057 · RSA, The Security Division of EMC · data as of 2026-08-28
Historical. Revocation due to CVE-2019-3738. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy. No assurance of the minimum strength of generated keys

Certificate

Certificate number2057
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-chip standalone
VendorRSA, The Security Division of EMC · website
Software versions6.1or 6.1.1.0.1

Module description

RSA BSAFE® Crypto-J security software is designed to help protect sensitive data as it is stored using strong encryption techniques to provide a persistent level of protection. It supports a wide range of industry standard encryption algorithms offering Java developers the flexibility to choose the option most appropriate to meet their requirements.

Security level exceptions

  • Design Assurance: Level 3

Approved algorithms

AlgorithmCAVP certificate
AES2249
CVL39
DRBG273
DSA701
ECDSA357
HMAC1378
PBKDFvendor affirmed
RSA1154
SHS1938
Triple-DES1408

Other algorithms

BPS; DES; DESX; Diffie-Hellman; Dual EC DRBG; EC Diffie-Hellman; ECIES; HMAC-MD5; MD2; MD4; MD5; RC2; RC4; RC5; RIPEMD160; RNG; RSA (encrypt/decrypt); RSA Keypair Generation MultiPrime; Shamir's Secret Sharing

Tested configurations

  • JRE 6.0 on Android 2.2 ARM (32-bit) running on Lenovo® Thinkpad® T61 (single-user mode)
  • Oracle® JRE 7.0 on Microsoft® Windows 7™ (64-bit) running on Dell™ Dimension C521

Validation history

DateTypeLab
2013-12-13InitialLeidos Accredited Testing & Evaluation (AT&E) Lab
2014-07-03UpdateLeidos Accredited Testing & Evaluation (AT&E) Lab
2016-02-12UpdateLeidos Accredited Testing & Evaluation (AT&E) Lab
2016-05-10UpdateLeidos Accredited Testing & Evaluation (AT&E) Lab

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2013-12-13, 2014-07-03, 2016-02-12, 2016-05-10

Source documents