808bits

Splunk Phantom Cryptographic Module

FIPS 140-2 certificate #3320 · Splunk, Inc. · data as of 2026-08-28
Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode

Certificate

Certificate number3320
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorSplunk, Inc. · website
Software versions1.0

Module description

The Splunk Phantom Cryptographic Module is a statically linked object module, providing cryptographic functionality to Splunk’s Phantom series of applications. Phantom solutions provide security automation and orchestration functionality.

Security level exceptions

  • Physical Security: N/A
  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES5441, 5442
CKGvendor affirmed
CVL1883
DRBG2125
DSA1399
ECDSA1446
HMAC3599
RSA2917
SHS4361
Triple-DES2734

Allowed algorithms

NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 270 bits of encryption strength)

Tested configurations

  • CentOS 6 running on a Dell PowerEdge 440 (Intel Xeon Silver ) with PAA
  • CentOS 6 running on a Dell PowerEdge 440 (Intel Xeon Silver) without PAA (single-user mode)
  • Red Hat Enterprise Linux Server 7.4 running on a Dell PowerEdge 440 (Intel Xeon Silver) with PAA
  • Red Hat Enterprise Linux Server 7.4 running on a Dell PowerEdge 440 (Intel Xeon Silver) without PAA

Validation history

DateTypeLab
2018-11-06InitialBOOZ ALLEN HAMILTON

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2018-11-06

Source documents