Okta Cryptographic Module for Java
Caveat: When installed, initialized and configured as specified in the Security Policy Section 3 and operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy.
Certificate
| Certificate number | 4370 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Okta, Inc. · website |
| Software versions | 3.0.2.1 |
Module description
The Okta Cryptographic Module for Java manages functions for secure key management, data integrity, data at rest encryption, and secure communications for the Okta Multifactor Authentication solution.
Security level exceptions
- Physical Security: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | A2720 |
| CKG | vendor affirmed |
| CVL | A2720 |
| DRBG | A2720 |
| DSA | A2720 |
| ECDSA | A2720 |
| HMAC | A2720 |
| KAS-SSC | vendor affirmed |
| KBKDF | A2720 |
| KTS | |
| KTS | vendor affirmed |
| KTS | |
| PBKDF | vendor affirmed |
| RSA | A2720 |
| SHA-3 | A2720 |
| SHA-3-Customized | vendor affirmed |
| SHS | A2720 |
| Triple-DES | A2720 |
Allowed algorithms
NDRNG; MD5; RSA (key wrapping; key establishment methodology provides between 150 and 256 bits of encryption strength)
Tested configurations
- VMware Photon OS 2.0 with JDK 11 on Vmware ESXi 6.7 running on Dell PowerEdge R830 with Intel Xeon E5 (single-user mode)
Validation history
| Date | Type | Lab |
|---|---|---|
| 2022-11-16 | Initial | AEGISOLVE, Inc. |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2022-11-16