808bits

CryptoServer Se-Series Gen2

FIPS 140-2 certificate #2814 · Utimaco IS GmbH · data as of 2026-09-08

CryptoServer Se-Series Gen2, from Utimaco IS GmbH, holds FIPS 140-2 certificate #2814 at overall level 3. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode

Certificate

Certificate number2814
StandardFIPS 140-2
Statushistorical
Overall level3
Module typeHardware
EmbodimentMulti-Chip Embedded
VendorUtimaco IS GmbH · website
Hardware versions5.01.2.0 and 5.01.4.0
Firmware versions5.0.10.1

Module description

Quoted from the NIST CMVP entry for this certificate.

The CryptoServer Se-Series Gen2 Version 5.01.2.0 and 5.01.4.0 is an encapsulated protected security module which is realized as a multi-chip embedded cryptographic module as defined in FIPS 140-2. It's realization meets the overall FIPS 140-2 Level 3 requirements. The primary purpose of this module is to provide secure cryptographic services such as encryption or decryption, hashing, signing and verification of data, random number generation, on-board secure key generation, key storage and further key management functions in a tamper-protected environment.

Approved algorithms (12)

AlgorithmCAVP certificates
AES4028
CVL855, 856
DRBG1202
DSA1091
ECDSA897, 898
HMAC2628
KBKDF97
KTS
RSA2066, 2067
SHS3321, 3322, 3323
Triple-DES2205
Triple-DES MACvendor affirmed

Other algorithms

Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength; non-compliant less than 112 bits of encryption strength); EC Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength; non-compliant less than 112 bits of encryption strength); NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 256 bits of encryption strength); AES MAC (Cert. #4028; non-compliant); DES; ECIES; KDF per PKCS #11 (non-compliant); MD5; MDC-2; RIPEMD-160; RSA (non-compliant); Triple-DES ANSI Retail MAC

Tested configurations

  • N/A

Validation history

DateTypeLab
2017-01-11InitialPenumbra Security, Inc.
2017-01-25UpdatePenumbra Security, Inc.
2018-02-01UpdatePenumbra Security, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2017-01-11, 2017-01-25, 2018-02-01

Source documents