808bits

Security Builder FIPS Java Module

FIPS 140-2 certificate #2504 · Certicom Corp. · data as of 2026-08-28
Historical. 186-2 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy

Certificate

Certificate number2504
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorCerticom Corp. · website
Software versions2.8 [1], 2.8.7 [2], 2.8.8 [3]

Module description

The Security Builder FIPS Java Module is a standards-based cryptographic toolkit written in Java. It supports optimized Elliptic Curve Cryptography and provides application developers with sophisticated tools to flexibly integrate encryption, digital signatures and other security mechanisms into Java-based applications. The Security Builder FIPS Java Module is intended for use by developers who want government level security and can also be used in conjunction with other Certicom developer toolkits including Security Builder PKI and Security Builder SSL.

Security level exceptions

  • Physical Security: N/A

Approved algorithms

AlgorithmCAVP certificate
AES1411, 3465
DRBG52, 852
DSA455, 978
ECDSA179, 702
HMAC832, 2210
KAS8, 61, 62
RSA687, 1776
SHS1281, 2860
Triple-DES964, 1954

Other algorithms

RNG; ARC2; ARC4; MD2; MD4; MD5; HMAC-MD5; DES; DESX; ECIES; ECQV; RSA (key wrapping; key establishment methodology provides between 112 and 256 bits of encryption strength; non-compliant less than 112 bits of encryption strength); Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength; non-compliant less than 112 bits of encryption strength); EC Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength; non-compliant less than 112 bits of encryption strength); ECMQV (key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength; non-compliant less than 112 bits of encryption strength); NDRNG

Tested configurations

  • CentOS 7.0 with Java JRE 1.8.0 running on a Dell PowerEdge 2950 (single-user mode) [3]
  • Red Hat Linux AS 5.5 32-bit [1, 2]
  • Red Hat Linux AS 5.5 64-bit [1, 2]
  • Solaris 10 64-bit [1, 2]
  • Sun Java Runtime Environments (JRE) 1.5.0 and 1.6.0 running on Solaris 10 32-bit [1, 2]
  • Windows 2008 Server 64-bit [1, 2]
  • Windows Vista 32-bit [1, 2]
  • Windows Vista 64-bit [1, 2]

Validation history

DateTypeLab
2015-12-18InitialEWA - Canada
2016-01-22UpdateEWA - Canada

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2015-12-18, 2016-01-22

Source documents