808bits

Unbound Tech EKM Cryptographic Module

FIPS 140-2 certificate #3378 · Unbound Tech · data as of 2026-08-28
Historical. SP 800-56Arev3 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode with two additional Unbound Tech EKM Cryptographic Modules with each EKM Cryptographic Module running in Entry mode, Pair mode, and Auxiliary mode as specified in Section 3.1 of the Security Policy
This caveat mentions binding. A bound module inherits the earliest sunset of the modules it binds to, so the sunset date above can be optimistic.

Certificate

Certificate number3378
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorUnbound Tech · website
Software versions2.0

Module description

Unbound's Enterprise Key Management (EKM) lets you manage and control keys working with any application. This pure-software solution is easy to deploy and maintain, while giving you unmatched levels of security and control for your crypto keys in the cloud. Based on Unbound vHSM technology, the keys are guaranteed to never appear in the clear, not even when generated or while at use - ensuring your most sensitive keys are kept private at all times.

Security level exceptions

  • Roles, Services, and Authentication: Level 2
  • Physical Security: N/A
  • Design Assurance: Level 3

Approved algorithms

AlgorithmCAVP certificate
AES5443, 5444
CKGvendor affirmed
CVL1884, 1885, 1886, 1887, 1888, 1889
DRBG2126
ECDSA1447, 1448
HMAC3600, 3601
KASvendor affirmed
KTS
KTSvendor affirmed
RSA2918, 2919
SHS4362

Allowed algorithms

EC Diffie-Hellman (key agreement; key establishment methodology provides 128 bits of encryption strength); NDRNG; RSA (key unwrapping; key establishment methodology provides between 112 and 256 bits of encryption strength)

Tested configurations

  • Red Hat Enterprise Linux 7.3 on ESXi 6.5 running on Gigabyte GA-6LISL / Intel Core i3 with PAA
  • Red Hat Enterprise Linux 7.3 on ESXi 6.5 running on Gigabyte GA-6LISL / Intel Core i3 without PAA (single-user mode)
  • Red Hat Enterprise Linux 7.3 running on Gigabyte GA-6LISL / Intel Core i3 with PAA
  • Red Hat Enterprise Linux 7.3 running on Gigabyte GA-6LISL / Intel Core i3 without PAA
  • Windows Server 2016 on ESXi 6.5 running on Gigabyte GA-6LISL / Intel Core i3 with PAA
  • Windows Server 2016 on ESXi 6.5 running on Gigabyte GA-6LISL / Intel Core i3 without PAA
  • Windows Server 2016 running on Gigabyte GA-6LISL / Intel Core i3 with PAA
  • Windows Server 2016 running on Gigabyte GA-6LISL / Intel Core i3 without PAA

Validation history

DateTypeLab
2019-02-19InitialUL Verification Services, Inc.
2020-04-24UpdateUL Verification Services, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2019-02-19, 2020-04-24

Source documents