BoringCrypto
Caveat: When installed, initialized and configured as specified in Section 12.1 of the Security Policy and operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy
Certificate
| Certificate number | 2964 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Google, Inc. · website |
| Software versions | 24e5886c0edfc409c8083d10f9f1120111efd6f5 |
Module description
A software library that contains cryptographic functionality to serve BoringSSL and other user-space applications.
Security level exceptions
- Physical Security: N/A
- Mitigation of Other Attacks: N/A
Approved algorithms
Allowed algorithms
NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 256 bits of encryption strength)
Tested configurations
- Ubuntu Linux 14.04 LTS running on Intel Xeon E5 without PAA (clang Compiler Version 4.0.0)
- Ubuntu Linux 15.04 running on POWER8 without PAA (clang Compiler Version 4.0.0)
- Ubuntu Linux 16.04 running on Intel Xeon E5 with PAA (clang Compiler Version 4.0.0)
- Ubuntu Linux 17.04 running on POWER8 with PAA (clang Compiler Version 4.0.0)
- Ubuntu Linux 17.04 running on POWER9 with PAA (clang Compiler Version 4.0.0) (single-user mode)
Validation history
| Date | Type | Lab |
|---|---|---|
| 2017-07-19 | Initial | Acumen Security |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2017-07-19