nShield F2 500+ & nShield F2 1500+ & nShield F2 6000+
Caveat: When operated in FIPS mode and initialized to Overall Level 2 per Security Policy
Certificate
| Certificate number | 4336 |
|---|---|
| Standard | FIPS 140-2 |
| Status | active |
| Sunset date | 2026-09-21 |
| Overall level | 2 |
| Module type | Hardware |
| Embodiment | Multi-Chip Embedded |
| Vendor | Entrust · website |
| Hardware versions | nC3423E-500, nC3423E-1K5 and nC3423E-6K0, Build Standard N |
| Firmware versions | 12.72.0 |
Module description
The nShield modules: nShield F2 500+ & nShield F2 1500+ & nShield F2 6000+ family of secure e-commerce HSMs are multi-tasking hardware modules that are optimized for performing modular arithmetic on very large integers. The nShield modules are FIPS 140-2 level 2 embedded devices. The units are identical in operation and only vary in the processing speed.
Security level exceptions
- Roles, Services, and Authentication: Level 3
- Physical Security: Level 3
- EMI/EMC: Level 3
- Design Assurance: Level 3
- Mitigation of Other Attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | A1931 |
| CKG | vendor affirmed |
| DRBG | A1931 |
| DSA | A1931 |
| ECDSA | A1931 |
| ENT | |
| HMAC | A1931 |
| KAS | A1931 |
| KBKDF | A1931 |
| KTS | |
| KTS-RSA | |
| RSA | A1931 |
| SHS | A1931 |
| Triple-DES | A1931 |
Allowed algorithms
EC Diffie-Hellman (shared secret computation provides between 112 and 256 bits of encryption strength); EC MQV (shared secret computation provides between 112 and 256 bits of encryption strength)
Tested configurations
- N/A
Validation history
| Date | Type | Lab |
|---|---|---|
| 2022-10-16 | Initial | Lightship Security, Inc. |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2022-10-16