808bits

Okta Cryptographic Module for Mobile

FIPS 140-2 certificate #3344 · Okta, Inc. · data as of 2026-08-28
Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode. The module makes no assurance of the minimum strength of random strings and generated keys. This validation entry is a non-security relevant modification to Cert. #1938.

Certificate

Certificate number3344
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorOkta, Inc. · website
Software versions2.1

Module description

The Okta Cryptographic Module for JavaMobile manages functions for secure key management, data integrity, data at rest encryption, and secure communications for the Okta Multifactor Authentication solution.

Security level exceptions

  • Physical Security: N/A
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES2125, 2126
CKGvendor affirmed
DRBG233, 234
DSA666, 667
ECDSA319, 320
HMAC1296, 1297
RSA1094, 1095
SHS1849, 1850
Triple-DES1351, 1352

Tested configurations

  • Android 4.0 running on a Galaxy Nexus
  • iOS 5.1 running on a iPad 3
  • iOS 6 running on a iPad 3 iOS 7 running on a iPad 3 (single-user mode)

Validation history

DateTypeLab
2018-12-17InitialAEGISOLVE, Inc.
2022-03-08UpdateAEGISOLVE, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2018-12-17, 2022-03-08

Source documents