808bits

ENFORCER R1

FIPS 140-2 certificate #3932 · Private Machines Inc. · data as of 2026-08-28
Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When utilizing a Trusted Path as specified in the security policy

Certificate

Certificate number3932
StandardFIPS 140-2
Statushistorical
Overall level4
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorPrivate Machines Inc. · website
Hardware versions(ENFORCER.R1.A2SDi.1.0.0, ENFORCER.R1.X10SDV.1.0.0, ENFORCER.R1.M11SDV.1.0.0 or ENFORCER.R1.X11SDV.1.0.0) and other excluded components identified in Security Policy Section 1.4
Firmware versionsSecurity Anchor Firmware 1.2.0, Libdrbg 1.0.2, and Libucl 2.5.13

Module description

The ENFORCER R1 provides a physically secure, Level 4 enclosure protecting CSPs and cryptographic data. A physical tamper event on the enclosure immediately zeroizes module CSPs. It provides a KMIP (Key Management Interoperability Protocol) service for key management to external users. It also provides additional services for module management, module configuration, and for building higher-level application scenarios such as integration into cloud and data center environments.

Approved algorithms

AlgorithmCAVP certificate
AES5073, C1028
CKGvendor affirmed
CVL1633, 1634, 1635
DRBGC558
DSA1336
ECDSA1316
HMAC3385
KAS-SSCvendor affirmed
KTS
RSA2751
SHS4131

Allowed algorithms

NDRNG; RSA (CVL Cert. #1635, key wrapping; key establishment methodology provides between 112 and 149 bits of encryption strength)

Tested configurations

  • N/A

Validation history

DateTypeLab
2021-05-24InitialPenumbra Security, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2021-05-24

Source documents