HyTrust KeyControl Cryptographic Module
HyTrust KeyControl Cryptographic Module, from HyTrust, Inc., holds FIPS 140-2 certificate #4191 at overall level 1. The validation is active, with a sunset date of 2026-09-21. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.
Caveat: None
Certificate
| Certificate number | 4191 |
|---|---|
| Standard | FIPS 140-2 |
| Status | active |
| Sunset date | 2026-09-21 |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | HyTrust, Inc. · website |
| Software versions | 1.1 |
Module description
Quoted from the NIST CMVP entry for this certificate.
HyTrust KeyControl enables enterprises to easily manage all their encryption keys at scale, how often they rotate them, and how they are shared securely. HyTrust KeyControl capabilities include VMware certified Key Management Server (KMS), KMIP support, Enterprise scalability and performance, Multi-cloud support (AWS, Azure, GCP) and HSM Support.
Security level exceptions
- Physical Security: N/A
- Design Assurance: Level 3
- Mitigation of Other Attacks: N/A
Approved algorithms (7)
| Algorithm | CAVP certificates |
|---|---|
| AES | A762, C2100, C2101, C2104, C2105 |
| CVL | C2104, C2105 |
| DRBG | A762 |
| HMAC | C2102, C2103, C2104, C2105 |
| PBKDF | A762 |
| RSA | A762 |
| SHS | C2102, C2103, C2104, C2105 |
Allowed algorithms
NDRNG; RSA (CVL Certs. #C2104 and #C2105, key wrapping)
Tested configurations
- Centos 7.7 on Vmware vSphere Hypervisor (ESXi) 6.7.0u3 running on running on Dell PowerEdge R220 with Intel® Xeon® CPU E3-1241v3 @ 3.50GHz (single-user mode)
Validation history
| Date | Type | Lab |
|---|---|---|
| 2022-04-04 | Initial | AEGISOLVE, Inc. |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2022-04-04