808bits

VMware's BoringCrypto Module

FIPS 140-2 certificate #3846 · VMware, Inc. · data as of 2026-08-28
Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When installed, initialized and configured as specified in Section 3.1 of the Security Policy and operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy

Certificate

Certificate number3846
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorVMware, Inc. · website
Software versions1.0

Module description

VMware’s BoringCrypto Module is a versatile software library that implements FIPS 140-2 Approved cryptographic services for VMware products and platforms.

Security level exceptions

  • Physical Security: N/A
  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AESC2129
CVLC2129
DRBGC2129
ECDSAC2129
HMACC2129
KTS
RSAC2129
SHSC2129
Triple-DESC2129

Allowed algorithms

NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 256 bits of encryption strength)

Tested configurations

  • Amazon Linux 2 on ESXi 7.0 running on Dell PowerEdge R740 with Intel® Xeon Gold 6126 with PAA
  • Amazon Linux 2 on ESXi 7.0 running on Dell PowerEdge R740 with Intel® Xeon Gold 6126 without PAA
  • Photon OS 2.0 on ESXi 7.0 running on Dell PowerEdge R740 with Intel® Xeon Gold 6126 with PAA
  • Photon OS 2.0 on ESXi 7.0 running on Dell PowerEdge R740 with Intel® Xeon Gold 6126 without PAA
  • Photon OS 3.0 on ESXi 6.7 running on Dell PowerEdge R740 with Intel® Xeon Gold 6126 with PAA
  • Photon OS 3.0 on ESXi 6.7 running on Dell PowerEdge R740 with Intel® Xeon Gold 6126 without PAA
  • Photon OS 3.0 on ESXi 7.0 running on Dell PowerEdge R740 with Intel® Xeon Gold 6126 with PAA
  • Photon OS 3.0 on ESXi 7.0 running on Dell PowerEdge R740 with Intel® Xeon Gold 6126 without PAA
  • Red Hat Enterprise Linux 7.7 on ESXi 7.0 running on Dell PowerEdge R740 with Intel® Xeon Gold 6126 with PAA
  • Red Hat Enterprise Linux 7.7 on ESXi 7.0 running on Dell PowerEdge R740 with Intel® Xeon Gold 6126 without PAA
  • Ubuntu 16.04 on ESXi 7.0 running on Dell PowerEdge R740 with Intel® Xeon Gold 6126 with PAA
  • Ubuntu 16.04 on ESXi 7.0 running on Dell PowerEdge R740 with Intel® Xeon Gold 6126 without PAA
  • Ubuntu 18.04 on ESXi 7.0 running on Dell PowerEdge R740 with Intel® Xeon Gold 6126 with PAA
  • Ubuntu 18.04 on ESXi 7.0 running on Dell PowerEdge R740 with Intel® Xeon Gold 6126 without PAA
  • Ubuntu 20.04 on ESXi 7.0 running on Dell PowerEdge R740 with Intel® Xeon Gold 6126 with PAA
  • Ubuntu 20.04 on ESXi 7.0 running on Dell PowerEdge R740 with Intel® Xeon Gold 6126 without PAA
  • Ubuntu 20.04 running on Dell Latitude E7450 with Intel® Core i5 with PAA
  • Ubuntu 20.04 running on Dell Latitude E7450 with Intel® Core i5 without PAA (single-user mode)
  • Within ESXi 7.0 (as a host) running on Dell PowerEdge R740 with Intel® Xeon Gold 6126 with PAA
  • Within ESXi 7.0 (as a host) running on Dell PowerEdge R740 with Intel® Xeon Gold 6126 without PAA

Validation history

DateTypeLab
2021-03-13InitialAcumen Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2021-03-13

Source documents