808bits

Lenel OnGuard Access Control Cryptographic Module

FIPS 140-2 certificate #3566 · UTC Fire & Security Americas Corporation, Inc. · data as of 2026-08-28
Historical. Moved to historical list due to dependency on certificate #2606. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode with Cryptographic Primitives Library (bcryptprimitives.dll and ncryptsslp.dll) in Microsoft Windows 10, Windows 10 Pro, Windows 10 Enterprise, Windows 10 Enterprise LTSB, Windows 10 Mobile, Windows 10 for Surface Hub validated to FIPS 140-2 under Cert. #2606 operating in FIPS mode or Cryptographic Primitives Library (bcryptprimitives.dll and ncryptsslp.dll) in Microsoft Windows 10, Windows 10 Pro, Windows 10 Enterprise, Windows 10 Enterprise LTSB, Windows 10 Mobile, Windows Server 2016 Standard, Windows Server 2016 Datacenter, Windows Storage Server 2016 validated to FIPS 140-2 under Cert. #2937 operating in FIPS mode

Certificate

Certificate number3566
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorUTC Fire & Security Americas Corporation, Inc. · website
Software versions7.4.457.69 with Critical On-Demand Hot Fix for DE40714 or 7.5.375.1

Module description

Lenel open platform security system integrates seamlessly with video, intrusion, access and fire products and offers remote access and management functionality, and is constantly evolving to meet changing mandates and guidelines. FICAM Architecture options include onboard authentication, ideal for new installations, or an add-on authentication module, perfect for retrofits and architectures where onboard authentication is not available. The OnGuard FICAM security management solution consists of Lenel OnGuard software, Lenel access and door controllers, and HID pivCLASS® software and readers.

Security level exceptions

  • Physical Security: N/A
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES3497, 4064, C500
CKGvendor affirmed
CVL575, 886
DRBG868, 1217
HMAC2233, 2651
KTS
RSA1783, 2193
SHS2886, 3347

Allowed algorithms

NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 150 bits of encryption strength)

Tested configurations

  • Microsoft Windows 10 64-bit running on Precision Workstation T3500 with an Intel Xeon W3670
  • Microsoft Windows Server 2016 64-bit running on Precision Workstation T3500 with an Intel Xeon W3530 (single-user mode)

Validation history

DateTypeLab
2019-11-18InitialUL Verification Services, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2019-11-18

Source documents