808bits

BoringCrypto

FIPS 140-2 certificate #2964 · Google, Inc. · data as of 2026-08-28
Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When installed, initialized and configured as specified in Section 12.1 of the Security Policy and operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy

Certificate

Certificate number2964
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorGoogle, Inc. · website
Software versions24e5886c0edfc409c8083d10f9f1120111efd6f5

Module description

A software library that contains cryptographic functionality to serve BoringSSL and other user-space applications.

Security level exceptions

  • Physical Security: N/A
  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES4558
CVL1240
DRBG1507
ECDSA1112
HMAC3011
KTS
RSA2485
SHS3736
Triple-DES2428

Allowed algorithms

NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 256 bits of encryption strength)

Tested configurations

  • Ubuntu Linux 14.04 LTS running on Intel Xeon E5 without PAA (clang Compiler Version 4.0.0)
  • Ubuntu Linux 15.04 running on POWER8 without PAA (clang Compiler Version 4.0.0)
  • Ubuntu Linux 16.04 running on Intel Xeon E5 with PAA (clang Compiler Version 4.0.0)
  • Ubuntu Linux 17.04 running on POWER8 with PAA (clang Compiler Version 4.0.0)
  • Ubuntu Linux 17.04 running on POWER9 with PAA (clang Compiler Version 4.0.0) (single-user mode)

Validation history

DateTypeLab
2017-07-19InitialAcumen Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2017-07-19

Source documents