808bits

Thales CipherTrust Manager Core Security Module

FIPS 140-2 certificate #4430 · Thales · data as of 2026-08-28
Active. Sunset date 2026-09-21, 23 days away. This is the FIPS 140-2 sunset: after it, agencies may keep the module only in existing systems.
Caveat: When installed, initialized and configured as specified in Section 10 of the Security Policy. When operated in FIPS mode. No assurance of the minimum strength of generated keys.

Certificate

Certificate number4430
StandardFIPS 140-2
Statusactive
Sunset date2026-09-21
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorThales
Software versions1.0.3

Module description

The module provides secure key generation and protection for symmetric keys and asymmetric key pairs along with support for a broad range of other cryptographic services. Access to services offered by Thales CipherTrust Manager Core Security Module is exclusively through a number of Application Programming Interfaces (API) offered by the Thales CipherTrust Manager Core Security Module. These API can be accessed by other applications running internal to the physical boundary of the module or, in some instances, can be accessed by remote client over dedicated TLS tunnels.

Security level exceptions

  • Physical Security: N/A
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AESA1778, A1779, A2634, A2635
CKGvendor affirmed
CVLA1779
DRBGA1779
ECDSAA1779, A2634
ENT
HMACA1779, A2634
KAS-SSCA1779, A2634
KDAA1779
KTS
KTS
KTS
KTS-RSA
PBKDFA1779
RSAA1779
SHA-3A1779
SHSA1779, A2634
Triple-DESA1779, A2634

Allowed algorithms

RSA (Key wrapping; key establishment methodology provides between 112 and 150 bits of encryption strength)

Tested configurations

  • Ubuntu 18.04 on VMware ESXi 6.5 running on a HPE P11782-001 platform with Intel Xeon Gold 6252 with PAA
  • Ubuntu 18.04 on VMware ESXi 6.5 running on a HPE P11782-001 platform with Intel Xeon Gold 6252 without PAA
  • Ubuntu 18.04 running on a AIC Antlia BMB-UPS0000B (K470) platform with Intel Xeon E3 1275 v6 with PAA
  • Ubuntu 18.04 running on a AIC Antlia BMB-UPS0000B (K470) platform with Intel Xeon E3 1275 v6 without PAA
  • Ubuntu 18.04 running on a AIC Antlia BMB-UPS0000B (K570) platform with Intel Xeon E3 1275 v6 with PAA
  • Ubuntu 18.04 running on a AIC Antlia BMB-UPS0000B (K570) platform with Intel Xeon E3 1275 v6 without PAA

Validation history

DateTypeLab
2023-01-27InitialAcumen Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2023-01-27

Source documents