808bits

Rosetta CSI sToken

FIPS 140-2 certificate #369 · SPYRUS, Inc. · data as of 2026-09-15

Rosetta CSI sToken, from SPYRUS, Inc., holds FIPS 140-2 certificate #369 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Skipjack is no longer approved. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode

Certificate

Certificate number369
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-chip standalone
VendorSPYRUS, Inc. · website
Software versions4.2.2.0 and 4.2.2.1

Module description

Quoted from the NIST CMVP entry for this certificate.

The Rosetta CSI sToken is a software cryptographic token providing digital signature and encryption services in a PC environment. The Rosetta sToken provides for ease of use, deployment and the assurance provided through independent third party security validation.

Security level exceptions

  • Roles, Services, and Authentication: Level 2
  • EMI/EMC: Level 3
  • Design Assurace: Level 3

Approved algorithms (3)

AlgorithmCAVP certificates
DSA87
SHA-1162
Skipjack12

Other algorithms

DES (Cert #78); DES MAC (Cert #78, vendor affirmed); RC2; RSA (non-compliant); MD5; HMAC-SHA-1 (Cert #162, vendor-affirmed); KEA (key agreement); Triple-DES (Cert #179; non-compliant)

Tested configurations

  • Microsoft Windows 2000

Validation history

DateTypeLab
2003-12-24InitialUL Verification Services, Inc.
2004-10-14Update

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2003-12-24, 2004-10-14

Source documents