808bits

Symantec Java Cryptographic Module

FIPS 140-2 certificate #2138 · Symantec Corporation · data as of 2026-09-13

Symantec Java Cryptographic Module, from Symantec Corporation, holds FIPS 140-2 certificate #2138 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. 186-2 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: This module contains the embedded module RSA BSAFE® Crypto-J Software Module validated to FIPS 140-2 under Cert. #1786 operating in FIPS mode. No assurance of the minimum strength of generated keys

Certificate

Certificate number2138
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-chip standalone
VendorSymantec Corporation
Software versions1.2

Module description

Quoted from the NIST CMVP entry for this certificate.

The Symantec Java Cryptographic Module provides a comprehensive set of cryptographic services for Symantec products including, but not limited to, the Symantec Data Loss Prevention Suite.

Security level exceptions

  • Physical Security: N/A

Approved algorithms (9)

AlgorithmCAVP certificates
AES1911
DRBG160
DSA604
ECDSA271
HMAC1148
PBKDFvendor affirmed
RSA981
SHS1678
Triple-DES1243

Other algorithms

Diffie-Hellman (key agreement; key establishment methodology provides 112 bits of encryption strength; non-compliant less than 112 bits of encryption strength); DUAL_EC_DRBG; EC Diffie-Hellman (key agreement; key establishment methodology provides 112 bits of encryption strength; non-compliant less than 112 bits of encryption strength); DES; DESX; ECIES; MD2; MD4; MD5; PRNG; RC2; RC4; RC5; RIPEMD160; RSA Keypair Generation MultiPrime (non-compliant); HMAC-MD5

Tested configurations

  • Microsoft Windows 7 (64-Bit) with Sun JRE 6.0 on a Dell OptiPlex 755 (single-user mode)

Validation history

DateTypeLab
2014-04-29InitialEWA - Canada
2016-07-11UpdateEWA - Canada

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2014-04-29, 2016-07-11

Source documents