Zebra BoringSSL Cryptographic Module
Zebra BoringSSL Cryptographic Module, from Zebra Technologies Corporation, holds FIPS 140-2 certificate #3866 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.
Caveat: When installed, initialized and configured as specified in Section 12.1 of the Security Policy and operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy
Certificate
| Certificate number | 3866 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Zebra Technologies Corporation · website |
| Software versions | 1.0 |
Module description
Quoted from the NIST CMVP entry for this certificate.
A software library that contains cryptographic functionality to serve BoringSSL and other user-space applications.
Security level exceptions
- Physical Security: N/A
- Mitigation of Other Attacks: N/A
Approved algorithms (12)
| Algorithm | CAVP certificates |
|---|---|
| key establishment methodology provides between 128 and 256 bits of encryption strength | |
| AES | C1748, A1395 |
| CKG | vendor affirmed |
| CVL | C1748, A1395 |
| DRBG | C1748, A1395 |
| ECDSA | C1748, A1395 |
| HMAC | C1748, A1395 |
| KAS-SSC | vendor affirmed |
| KTS | |
| RSA | C1748, A1395 |
| SHS | C1748, A1395 |
| Triple-DES | C1748, A1395 |
Allowed algorithms
MD5; NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 256 bits of encryption strength)
Tested configurations
- Android 10 running on TC57 with Qualcomm SDM660 with PAA
- Android 10 running on TC57 with Qualcomm SDM660 without PAA
- Android 11 running on ET40 with Qualcomm SM6375 with PAA
- Android 11 running on ET40 with Qualcomm SM6375 without PAA
- Android 11 running on TC57 with Qualcomm SDM660 with PAA
- Android 11 running on TC57 with Qualcomm SDM660 without PAA
- Android 13 running on ET40 with Qualcomm SM6375 with PAA
- Android 13 running on ET40 with Qualcomm SM6375 without PAA (single-user mode)
- Android 13 running on TC57 with Qualcomm SDM660 with PAA
- Android 13 running on TC57 with Qualcomm SDM660 without PAA
- Android 13 running on TC58 with Qualcomm QCM6490 with PAA
- Android 13 running on TC58 with Qualcomm QCM6490 without PAA
Validation history
| Date | Type | Lab |
|---|---|---|
| 2021-03-25 | Initial | Acumen Security |
| 2021-09-14 | Update | Acumen Security |
| 2024-03-18 | Update | Acumen Security |
| 2024-09-17 | Update | Acumen Security |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2021-03-25, 2021-09-14, 2024-03-18, 2024-09-17