808bits

Microsoft BoringCrypto Module

FIPS 140-2 certificate #4253 · Microsoft Corporation · data as of 2026-08-28
Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When installed, initialized and configured as specified in Section 12.1 of the Security Policy and operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy

Certificate

Certificate number4253
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorMicrosoft Corporation · website
Software versions7f02881e96e51f1873afcf384d02f782b48967ca

Module description

Software library for the Microsoft Surface 2 Duo that contains cryptographic functionality to serve BoringSSL and other user-space applications

Security level exceptions

  • Physical Security: N/A
  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AESA2316
CVLA2316
DRBGA2316
ECDSAA2316
HMACA2316
KAS-SSCvendor affirmed
KTS
RSAA2316
SHSA2316
Triple-DESA2316

Allowed algorithms

MD5; NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 256 bits of encryption strength)

Tested configurations

  • Android 11 running on Microsoft Surface Duo 2 with Qualcomm Snapdragon 888 with PAA with PAA
  • Android 11 running on Microsoft Surface Duo 2 with Qualcomm Snapdragon 888 without PAA (single-user mode)

Validation history

DateTypeLab
2022-06-23InitialGossamer Security Solutions

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2022-06-23

Source documents