808bits

Thales Luna Backup HSM Cryptographic Module

FIPS 140-2 certificate #4195 · Thales · data as of 2026-08-28
Active. Sunset date 2026-09-21, 23 days away. This is the FIPS 140-2 sunset: after it, agencies may keep the module only in existing systems.
Caveat: When operated in FIPS mode.

Certificate

Certificate number4195
StandardFIPS 140-2
Statusactive
Sunset date2026-09-21
Overall level3
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorThales · website
Hardware versions808-000064-005, 808-000064-006
Firmware versions7.7.1 and bootloader version 1.3.0 or 1.5.0

Module description

The Thales Luna Backup HSM Cryptographic Module is a multi-chip standalone hardware cryptographic module in the small form factor device that connects to a computer workstation or server via USB. The cryptographic module is contained in its own enclosure that provides physical resistance to tampering.

Security level exceptions

  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AESC2020
CKGvendor affirmed
CVLC2020, C2021
DRBGC2020
ECDSAC2020
HMACC2020
KASA2125
KAS-RSAA2125
KBKDFC2020
KDAA2125
KTS
KTS-RSA
PBKDFA2125
RSAA674, A675, C2020, C2021, C2022
SHSC2020, C2022

Allowed algorithms

AES (Cert. #C2020, key unwrapping; key establishment methodology provides 256 bits of encryption strength); NDRNG; RSA (CVL Certs. #C2020 and #C2021, key unwrapping; key establishment methodology provides between 112 and 150 bits of encryption strength)

Tested configurations

  • N/A

Validation history

DateTypeLab
2022-04-14InitialEWA - Canada

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2022-04-14

Source documents