VMware's BoringCrypto Module
Caveat: When installed, initialized and configured as specified in Section 3.1 of the Security Policy and operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy
Certificate
| Certificate number | 3846 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | VMware, Inc. · website |
| Software versions | 1.0 |
Module description
VMware’s BoringCrypto Module is a versatile software library that implements FIPS 140-2 Approved cryptographic services for VMware products and platforms.
Security level exceptions
- Physical Security: N/A
- Mitigation of Other Attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | C2129 |
| CVL | C2129 |
| DRBG | C2129 |
| ECDSA | C2129 |
| HMAC | C2129 |
| KTS | |
| RSA | C2129 |
| SHS | C2129 |
| Triple-DES | C2129 |
Allowed algorithms
NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 256 bits of encryption strength)
Tested configurations
- Amazon Linux 2 on ESXi 7.0 running on Dell PowerEdge R740 with Intel® Xeon Gold 6126 with PAA
- Amazon Linux 2 on ESXi 7.0 running on Dell PowerEdge R740 with Intel® Xeon Gold 6126 without PAA
- Photon OS 2.0 on ESXi 7.0 running on Dell PowerEdge R740 with Intel® Xeon Gold 6126 with PAA
- Photon OS 2.0 on ESXi 7.0 running on Dell PowerEdge R740 with Intel® Xeon Gold 6126 without PAA
- Photon OS 3.0 on ESXi 6.7 running on Dell PowerEdge R740 with Intel® Xeon Gold 6126 with PAA
- Photon OS 3.0 on ESXi 6.7 running on Dell PowerEdge R740 with Intel® Xeon Gold 6126 without PAA
- Photon OS 3.0 on ESXi 7.0 running on Dell PowerEdge R740 with Intel® Xeon Gold 6126 with PAA
- Photon OS 3.0 on ESXi 7.0 running on Dell PowerEdge R740 with Intel® Xeon Gold 6126 without PAA
- Red Hat Enterprise Linux 7.7 on ESXi 7.0 running on Dell PowerEdge R740 with Intel® Xeon Gold 6126 with PAA
- Red Hat Enterprise Linux 7.7 on ESXi 7.0 running on Dell PowerEdge R740 with Intel® Xeon Gold 6126 without PAA
- Ubuntu 16.04 on ESXi 7.0 running on Dell PowerEdge R740 with Intel® Xeon Gold 6126 with PAA
- Ubuntu 16.04 on ESXi 7.0 running on Dell PowerEdge R740 with Intel® Xeon Gold 6126 without PAA
- Ubuntu 18.04 on ESXi 7.0 running on Dell PowerEdge R740 with Intel® Xeon Gold 6126 with PAA
- Ubuntu 18.04 on ESXi 7.0 running on Dell PowerEdge R740 with Intel® Xeon Gold 6126 without PAA
- Ubuntu 20.04 on ESXi 7.0 running on Dell PowerEdge R740 with Intel® Xeon Gold 6126 with PAA
- Ubuntu 20.04 on ESXi 7.0 running on Dell PowerEdge R740 with Intel® Xeon Gold 6126 without PAA
- Ubuntu 20.04 running on Dell Latitude E7450 with Intel® Core i5 with PAA
- Ubuntu 20.04 running on Dell Latitude E7450 with Intel® Core i5 without PAA (single-user mode)
- Within ESXi 7.0 (as a host) running on Dell PowerEdge R740 with Intel® Xeon Gold 6126 with PAA
- Within ESXi 7.0 (as a host) running on Dell PowerEdge R740 with Intel® Xeon Gold 6126 without PAA
Validation history
| Date | Type | Lab |
|---|---|---|
| 2021-03-13 | Initial | Acumen Security |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2021-03-13