808bits

Zebra BoringSSL Cryptographic Module

FIPS 140-2 certificate #3866 · Zebra Technologies Corporation · data as of 2026-09-08

Zebra BoringSSL Cryptographic Module, from Zebra Technologies Corporation, holds FIPS 140-2 certificate #3866 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When installed, initialized and configured as specified in Section 12.1 of the Security Policy and operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy

Certificate

Certificate number3866
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorZebra Technologies Corporation · website
Software versions1.0

Module description

Quoted from the NIST CMVP entry for this certificate.

A software library that contains cryptographic functionality to serve BoringSSL and other user-space applications.

Security level exceptions

  • Physical Security: N/A
  • Mitigation of Other Attacks: N/A

Approved algorithms (12)

AlgorithmCAVP certificates
key establishment methodology provides between 128 and 256 bits of encryption strength
AESC1748, A1395
CKGvendor affirmed
CVLC1748, A1395
DRBGC1748, A1395
ECDSAC1748, A1395
HMACC1748, A1395
KAS-SSCvendor affirmed
KTS
RSAC1748, A1395
SHSC1748, A1395
Triple-DESC1748, A1395

Allowed algorithms

MD5; NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 256 bits of encryption strength)

Tested configurations

  • Android 10 running on TC57 with Qualcomm SDM660 with PAA
  • Android 10 running on TC57 with Qualcomm SDM660 without PAA
  • Android 11 running on ET40 with Qualcomm SM6375 with PAA
  • Android 11 running on ET40 with Qualcomm SM6375 without PAA
  • Android 11 running on TC57 with Qualcomm SDM660 with PAA
  • Android 11 running on TC57 with Qualcomm SDM660 without PAA
  • Android 13 running on ET40 with Qualcomm SM6375 with PAA
  • Android 13 running on ET40 with Qualcomm SM6375 without PAA (single-user mode)
  • Android 13 running on TC57 with Qualcomm SDM660 with PAA
  • Android 13 running on TC57 with Qualcomm SDM660 without PAA
  • Android 13 running on TC58 with Qualcomm QCM6490 with PAA
  • Android 13 running on TC58 with Qualcomm QCM6490 without PAA

Validation history

DateTypeLab
2021-03-25InitialAcumen Security
2021-09-14UpdateAcumen Security
2024-03-18UpdateAcumen Security
2024-09-17UpdateAcumen Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2021-03-25, 2021-09-14, 2024-03-18, 2024-09-17

Source documents