808bits

Riverbed Cryptographic Module v1.1

FIPS 140-2 certificate #4094 · Riverbed · data as of 2026-09-13

Riverbed Cryptographic Module v1.1, from Riverbed, holds FIPS 140-2 certificate #4094 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode. No assurance of the minimum strength of generated keys.

Certificate

Certificate number4094
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorRiverbed · website
Software versions1.1

Module description

Quoted from the NIST CMVP entry for this certificate.

The Riverbed Cryptographic Module is a general purpose cryptographic library incorporated into SteelHead family products for the protection of sensitive information.

Security level exceptions

  • Roles, Services, and Authentication: Level 2
  • Physical Security: N/A
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A

Approved algorithms (10)

AlgorithmCAVP certificates
AESC1318, A2089
CKGvendor affirmed
DRBGC1318
DSAC1318, A2089
ECDSAC1318, A2089
HMACC1318, A2089
KAS-SSCvendor affirmed
RSAC1318, A2089
SHSC1318, A2089
Triple-DESC1318, A2089

Allowed algorithms

RSA (key wrapping; key establishment methodology provides between 112 and 256 bits of encryption strength)

Tested configurations

  • CentOS 7 running on HPE ProLiant DL60 Gen9 with Intel Xeon E5-2609 with PAA
  • CentOS 7 running on HPE ProLiant DL60 Gen9 with Intel Xeon E5-2609 without PAA
  • Scientific Linux 6 running on SteelHead CXA580 with Intel Xeon D-1513N (x86-64) with PAA
  • Scientific Linux 6 running on SteelHead CXA580 with Intel Xeon D-1513N (x86-64) without PAA (single-user mode).

Validation history

DateTypeLab
2021-12-06InitialAcumen Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2021-12-06

Source documents