808bits

Luna® PCI-e Cryptographic Module

FIPS 140-2 certificate #2481 · SafeNet, Inc. · data as of 2026-08-28
Historical. Moved to historical list in accordance with SP800-131A Revision 1 Transition (AES/TDES key wrapping). Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: This validation entry is a non-security relevant modification to Cert. #1694

Certificate

Certificate number2481
StandardFIPS 140-2
Statushistorical
Overall level3
Module typeHardware
EmbodimentMulti-Chip Embedded
VendorSafeNet, Inc. · website
Hardware versionsVBD-05-0100, VBD-05-0101 and VBD-05-0103
Firmware versions6.2.1 and 6.2.5

Module description

The Luna PCI-e cryptographic module is a multi-chip embedded hardware cryptographic module in the form of a PCI-Express card that typically resides within a custom computing or secure communications appliance. The cryptographic module is contained in its own secure enclosure that provides physical resistance to tampering. The cryptographic boundary of the module is defined to encompass all components inside the secure enclosure on the PCI-e card.

Approved algorithms

AlgorithmCAVP certificate
AES1743, 1750, 1756
DRBG114
DSA545, 546, 548
ECDSA230, 231, 233
HMAC1021, 1027
KAS23
KBKDFvendor affirmed
RSA865, 870
SHS1531, 1537
Triple-DES1130, 1134, 1137
Triple-DES MAC

Other algorithms

ARIA; AES (Certs. #1743, #1750 and #1756, key wrapping; key establishment methodology provides between 128 and 256 bits of encryption strength); AES MAC (Cert. #1750; non-compliant); CAST5; CAST5-MAC; DES; DES MAC; Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 128 bits of encryption strength); HAS-160; KCDSA; MD2; MD5; RC2; RC2-MAC; RC4; RC5; RC5-MAC; RSA (key wrapping; key establishment methodology provides between 112 and 152 bits of encryption strength; non-compliant less than 112 bits of encryption strength); SEED; Triple-DES (Certs. #1130, #1134 and #1137, key wrapping; key establishment methodology provides 112 bits of encryption strength; non-compliant less than 112 bits of encryption strength)

Validation history

DateTypeLab
2015-12-02InitialEWA - Canada
2017-01-10UpdateCGI Information Systems & Management Consultants Inc
2017-06-23Update
2017-06-23Update

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2015-12-02, 2017-01-10, 2017-06-23, 2017-06-23

Source documents