808bits

Luna® Backup HSM Cryptographic Module

FIPS 140-2 certificate #2429 · SafeNet, Inc. · data as of 2026-08-28
Historical. Moved to historical list in accordance with SP800-131A Revision 1 Transition (AES/TDES key wrapping). Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode and initialized to Overall Level 3 per Security Policy

Certificate

Certificate number2429
StandardFIPS 140-2
Statushistorical
Overall level3
Module typeHardware
EmbodimentMulti-chip standalone
VendorSafeNet, Inc. · website
Hardware versionsLTK-03, Version Code 0102; LTK-03, Version Code 0103
Firmware versions6.10.4, 6.10.7 and 6.10.9

Module description

The Luna® Backup HSM Hardware Security Module (HSM) provides the same level of security as the Luna® SA and Luna® PCI-E HSMs in a convenient, small, low-cost form factor. The Luna Backup HSM ensures that sensitive cryptographic material remains strongly protected in hardware even when not being used. One can easily back up and duplicate keys securely to the Luna Backup HSM for safekeeping in case of emergency, failure or disaster.

Approved algorithms

AlgorithmCAVP certificate
AES2664, 2668
DRBG428
DSA804, 808
ECDSA461, 464
HMAC1655, 1659
KAS44
KBKDF15
RSA1369, 1372
SHS2237, 2241
Triple-DES1598, 1600
Triple-DES MACvendor affirmed

Other algorithms

DES; RC2; RC4; RC5; CAST5; SEED; ARIA; MD2; MD5; HAS-160; DES-MAC; RC2-MAC; RC5-MAC; CAST5-MAC; SSL3-MD5-MAC; SSL3-SHA1-MAC; KCDSA; Diffie-Hellman (key agreement; key establishment methodology provides 112 or 128 bits of encryption strength; non-compliant less than 112 bits of encryption strength); HRNG; AES MAC (AES Cert. #2668; non-compliant); AES (Certs. #2664 and #2668, key wrapping; key establishment methodology provides between 128 and 256 bits of encryption strength); Triple-DES (Certs. #1598 and #1600, key wrapping; key establishment methodology provides 112 bits of encryption strength); GENERIC-SECRET generation (non-compliant); SSL PRE-MASTER generation (non-compliant); RSA (non-compliant); RSA (key wrapping; key establishment methodology provides between 112 and 152 bits of encryption strength; non-compliant less than 112 bits of encryption strength)

Validation history

DateTypeLab
2015-08-11InitialEWA - Canada
2015-09-04UpdateEWA - Canada
2015-10-26UpdateEWA - Canada
2016-01-14UpdateEWA - Canada
2016-01-22UpdateEWA - Canada
2016-05-12UpdateEWA - Canada
2017-01-10UpdateCGI Information Systems & Management Consultants Inc
2017-06-23Update
2017-06-23Update

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2015-08-11, 2015-09-04, 2015-10-26, 2016-01-14, 2016-01-22, 2016-05-12, 2017-01-10, 2017-06-23, 2017-06-23

Source documents