808bits

Entrust GUTS Security Kernel 6.1

FIPS 140-1 certificate #243 · Entrust, Inc. · data as of 2026-09-03

Entrust GUTS Security Kernel 6.1, from Entrust, Inc., holds FIPS 140-1 certificate #243 at overall level 2. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Validation Sunsetting Policy - FIPS 140-1 Certificate. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode

Certificate

Certificate number243
StandardFIPS 140-1
Statushistorical
Overall level2
Module typeSoftware
EmbodimentMulti-chip standalone
VendorEntrust, Inc. · website
Software versions6.1

Module description

Quoted from the NIST CMVP entry for this certificate.

The Kernel is a C++ class library of cryptographic functions bound together by a common object-oriented Application Programming Interface (API). Depending on the configuration and runtime environment of the Kernel, the algorithms may be implemented in software, hardware, or a combination of both. The industry standard Cryptoki API, as described in PKCS #11, is used as the internal interface to hardware-based cryptographic tokens. Decisions are made at runtime whether to perform operations via cryptoki or in software, based on a table that records the crypto capabilities of particular hardware devices. This table is built up at runtime by querying the actual token through Cryptoki.

Security level exceptions

  • Roles and Services: Level 2*
  • EMI/EMC: Level 3
  • Key Management: Level 2*
  • Operating System Security: Tested as meeting Level 2 with Microsoft Windows NT 4.0 with SP6a, TCSEC C2-rated on a Compaq Proliant 7000 Server
  • *When operated in FIPS mode

Approved algorithms (5)

AlgorithmCAVP certificates
AES10
DSA/SHA-1
HMAC-SHA-1vendor affirmed
RSAvendor affirmed
Triple-DES6

Other algorithms

DES (Cert. #56); DES MAC; RC2; RC4; IDEA; MD5; MD2; RIPEMD-160; HMAC-MD5; HMAC-RMD160; CAST; CAST3; CAST5; Diffie-Hellman (key agreement); Ephemeral-Static Diffie-Hellman; ECDSA (non-compliant)

Validation history

DateTypeLab
2002-08-15InitialDOMUS
2003-05-27Update
2014-05-28Update

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2002-08-15, 2003-05-27, 2014-05-28

Source documents