808bits

Microsoft Enhanced Cryptographic Provider

FIPS 140-1 certificate #238 · Microsoft Corporation · data as of 2026-08-28
Historical. Validation Sunsetting Policy - FIPS 140-1 Certificate. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode

Certificate

Certificate number238
StandardFIPS 140-1
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-chip standalone
VendorMicrosoft Corporation · website
Software versions5.1.2518.0, 5.1.2600.1029 and 5.1.2600.2161

Module description

The Microsoft Enhanced Cryptographic Provider (RSAENH) is a FIPS 140-1 Level 1 compliant, general-purpose, software-based, cryptographic module. Like other cryptographic providers that ship with Microsoft Windows XP, RSAENH encapsulates several different cryptographic algorithms (including SHA-1, DES, 3DES, AES, RSA, SHA-1-based HMAC) in an easy-to-use cryptographic module accessible via the Microsoft CryptoAPI. It can be dynamically linked into applications by software developers to permit the use of general-purpose FIPS 140-1 Level 1 compliant cryptography.

Security level exceptions

  • Operating System Security: Tested as meeting Level 1 with Microsoft Windows XP, XP Service Pack 1 and XP Service Pack 2 (single user mode)

Approved algorithms

AlgorithmCAVP certificate
AES33
HMAC-SHA-1vendor affirmed
RSAvendor affirmed
SHA-183
Triple-DES81

Other algorithms

DES (Cert. #156); RC2; RC4; MD5

Validation history

DateTypeLab
2002-07-11InitialSAIC-VA
2002-11-18Update
2005-02-25Update
2007-10-15Update

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2002-07-11, 2002-11-18, 2005-02-25, 2007-10-15

Source documents