808bits

Windows Server 2003 Enhanced Cryptographic Provider (RSAENH)

FIPS 140-2 certificate #382 · Microsoft Corporation · data as of 2026-08-28
Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode

Certificate

Certificate number382
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-chip standalone
VendorMicrosoft Corporation · website
Software versions5.2.3790.0 and 5.2.3790.1830 [Service Pack 1]

Module description

The Microsoft Enhanced Cryptographic Provider is a FIPS 140-2 compliant, software-based, cryptographic module. RSAENH encapsulates several different cryptographic algorithms (including SHA-1, DES, 3DES, AES, RSA, SHA-1-based HMAC) in a cryptographic module accessible via the Microsoft CryptoAPI.

Approved algorithms

AlgorithmCAVP certificate
AES80, 290
HMAC176, 99
RSAvendor affirmed
SHS176, 364
Triple-DES192, 365

Other algorithms

DES (Cert. #226[1]); SHA-256[1]; SHA-384[1]; SHA-512[1]; RC2; RC4; MD2; MD4; MD5

Tested configurations

  • Windows Server 2003[1] and Windows Server 2003 Service Pack 1[2] (single-user mode)

Validation history

DateTypeLab
2004-02-17InitialSAIC-VA
2005-10-07Update
2005-10-25Update
2007-10-15Update

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2004-02-17, 2005-10-07, 2005-10-25, 2007-10-15

Source documents