Symantec PGP Cryptographic Engine
Caveat: When operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy
Certificate
| Certificate number | 3729 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Symantec Corporation · website |
| Software versions | 4.4 |
Module description
The Symantec PGP Cryptographic Engine is a FIPS 140-2 validated software only cryptographic module. The module implements the cryptographic functions for Symantec Encryption products. It includes a wide range of field-tested and standards-based encryption, digital signature, and encoding algorithms as well as a variety of secure network protocol implementations.
Security level exceptions
- Physical Security: N/A
- Design Assurance: Level 3
- Mitigation of Other Attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | C511, C512, C513, C514, C515, C516, C517, C518, C519, C520, C521, C522 |
| CKG | vendor affirmed |
| CVL | C383, C384, C385, C386, C387, C388, C389, C390, C391, C392, C393, C478, C511, C512, C513, C514, C515, C516, C517, C518, C519, C520, C521, C522 |
| DRBG | C511, C512, C513, C514, C515, C516, C517, C518, C519, C520, C521, C522 |
| DSA | C511, C512, C513, C514, C515, C516, C517, C518, C519, C520, C521, C522 |
| ECDSA | C511, C512, C513, C514, C515, C516, C517, C518, C519, C520, C521, C522 |
| HMAC | C511, C512, C513, C514, C515, C516, C517, C518, C519, C520, C521, C522 |
| KBKDF | C511, C512, C513, C514, C515, C516, C517, C518, C519, C520, C521, C522 |
| KTS | |
| KTS | vendor affirmed |
| PBKDF | vendor affirmed |
| RSA | C511, C512, C513, C514, C515, C516, C517, C518, C519, C520, C521, C522, C632, C633, C634, C635, C636, C637, C638, C639, C640, C641, C642, C643 |
| SHS | C511, C512, C513, C514, C515, C516, C517, C518, C519, C520, C521, C522 |
| Triple-DES | C511, C512, C513, C514, C515, C516, C517, C518, C519, C520, C521, C522 |
Allowed algorithms
NDRNG
Tested configurations
- macOS High Sierra 10.13.6 (64-bit) running on Mac mini Server (Mid 2011) with 2 GHz Intel Core i7 with PAA
- macOS High Sierra 10.13.6 (64-bit) running on Mac mini Server (Mid 2011) with 2 GHz Intel Core i7 without PAA
- RHEL 7.5 (64-bit) on VMWare ESXi 6.5.0 running on Dell Precision Tower 7910 with Intel® Xenon® CPU E5-2620 v3 @ 2.4GHz with PAA
- RHEL 7.5 (64-bit) on VMWare ESXi 6.5.0 running on Dell Precision Tower 7910 with Intel® Xenon® CPU E5-2620 v3 @ 2.4GHz without PAA
- Windows 10 Pro (32-bit) kernel on VMWare ESXi 6.5.0 running on Dell Precision Tower 7910 with Intel® Xenon® CPU E5-2620 v3 @ 2.4GHz with PAA
- Windows 10 Pro (32-bit) kernel on VMWare ESXi 6.5.0 running on Dell Precision Tower 7910 with Intel® Xenon® CPU E5-2620 v3 @ 2.4GHz without PAA
- Windows 10 Pro (32-bit) on VMWare ESXi 6.5.0 running on Dell Precision Tower 7910 with Intel® Xenon® CPU E5-2620 v3 @ 2.4GHz with PAA
- Windows 10 Pro (32-bit) on VMWare ESXi 6.5.0 running on Dell Precision Tower 7910 with Intel® Xenon® CPU E5-2620 v3 @ 2.4GHz without PAA
- Windows 10 Pro (64-bit) kernel on VMWare ESXi 6.5.0 running on Dell Precision Tower 7910 with Intel® Xenon® CPU E5-2620 v3 @ 2.4GHz with PAA
- Windows 10 Pro (64-bit) kernel on VMWare ESXi 6.5.0 running on Dell Precision Tower 7910 with Intel® Xenon® CPU E5-2620 v3 @ 2.4GHz without PAA (single-user mode)
- Windows 10 Pro (64-bit) on VMWare ESXi 6.5.0 running on Dell Precision Tower 7910 with Intel® Xenon® CPU E5-2620 v3 @ 2.4GHz with PAA
- Windows 10 Pro (64-bit) on VMWare ESXi 6.5.0 running on Dell Precision Tower 7910 with Intel® Xenon® CPU E5-2620 v3 @ 2.4GHz without PAA
Validation history
| Date | Type | Lab |
|---|---|---|
| 2020-10-21 | Initial | AEGISOLVE, Inc. |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2020-10-21