Windows Server 2003 Enhanced Cryptographic Provider (RSAENH)
Windows Server 2003 Enhanced Cryptographic Provider (RSAENH), from Microsoft Corporation, holds FIPS 140-2 certificate #382 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.
Caveat: When operated in FIPS mode
Certificate
| Certificate number | 382 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-chip standalone |
| Vendor | Microsoft Corporation · website |
| Software versions | 5.2.3790.0 and 5.2.3790.1830 [Service Pack 1] |
Module description
Quoted from the NIST CMVP entry for this certificate.
The Microsoft Enhanced Cryptographic Provider is a FIPS 140-2 compliant, software-based, cryptographic module. RSAENH encapsulates several different cryptographic algorithms (including SHA-1, DES, 3DES, AES, RSA, SHA-1-based HMAC) in a cryptographic module accessible via the Microsoft CryptoAPI.
Approved algorithms (5)
Other algorithms
DES (Cert. #226[1]); SHA-256[1]; SHA-384[1]; SHA-512[1]; RC2; RC4; MD2; MD4; MD5
Tested configurations
- Windows Server 2003[1] and Windows Server 2003 Service Pack 1[2] (single-user mode)
Validation history
| Date | Type | Lab |
|---|---|---|
| 2004-02-17 | Initial | SAIC-VA |
| 2005-10-07 | Update | |
| 2005-10-25 | Update | |
| 2007-10-15 | Update |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2004-02-17, 2005-10-07, 2005-10-25, 2007-10-15