Entrust Security Kernel Version 7.0
Certificate
| Certificate number | 308 |
|---|---|
| Standard | FIPS 140-1 |
| Status | historical |
| Overall level | 2 |
| Module type | Software |
| Embodiment | Multi-chip standalone |
| Vendor | Entrust, Inc. · website |
| Software versions | 7.0 |
Module description
The Kernel is a C++ class library of cryptographic functions bound together by a common object-oriented Application Programming Interface (API). Depending on the configuration and runtime environment of the Kernel, the algorithms may be implemented in software, hardware, or a combination of both. The industry standard Cryptoki API, as described in PKCS #11, is used as the internal interface to hardware-based cryptographic tokens. Decisions are made at runtime whether to perform operations via cryptoki or in software, based on a table that records the crypto capabilities of particular hardware devices. This table is built up at runtime by querying the actual token through Cryptoki.
Security level exceptions
- Roles and Services: Level 2*
- EMI/EMC: Level 3
- Key Management: Level 2*
- Operating System Security: Tested as meeting Level 2 with Microsoft Windows NT 4.0 with SP6a, TCSEC C3-2-rated on a Compaq ProLiant 7000 Server
- *When operated in the FIPS mode
Approved algorithms
Other algorithms
DES (Cert. #56); DES MAC; RC2; RC4; IDEA; MD5; MD2; RIPEMD-160; HMAC-MD5; HMAC-RIPEMD-160; CAST; CAST3; CAST5; Diffie-Hellman (key agreement); Ephemeral-Static Diffie-Hellman; ECDSA (vendor affirmed; non-compliant)
Validation history
| Date | Type | Lab |
|---|---|---|
| 2003-03-07 | Initial | DOMUS |
| 2014-05-28 | Update |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2003-03-07, 2014-05-28