Thales CipherTrust Manager Core Security Module
Certificate
| Certificate number | 4430 |
|---|---|
| Standard | FIPS 140-2 |
| Status | active |
| Sunset date | 2026-09-21 |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Thales |
| Software versions | 1.0.3 |
Module description
The module provides secure key generation and protection for symmetric keys and asymmetric key pairs along with support for a broad range of other cryptographic services. Access to services offered by Thales CipherTrust Manager Core Security Module is exclusively through a number of Application Programming Interfaces (API) offered by the Thales CipherTrust Manager Core Security Module. These API can be accessed by other applications running internal to the physical boundary of the module or, in some instances, can be accessed by remote client over dedicated TLS tunnels.
Security level exceptions
- Physical Security: N/A
- Design Assurance: Level 3
- Mitigation of Other Attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | A1778, A1779, A2634, A2635 |
| CKG | vendor affirmed |
| CVL | A1779 |
| DRBG | A1779 |
| ECDSA | A1779, A2634 |
| ENT | |
| HMAC | A1779, A2634 |
| KAS-SSC | A1779, A2634 |
| KDA | A1779 |
| KTS | |
| KTS | |
| KTS | |
| KTS-RSA | |
| PBKDF | A1779 |
| RSA | A1779 |
| SHA-3 | A1779 |
| SHS | A1779, A2634 |
| Triple-DES | A1779, A2634 |
Allowed algorithms
RSA (Key wrapping; key establishment methodology provides between 112 and 150 bits of encryption strength)
Tested configurations
- Ubuntu 18.04 on VMware ESXi 6.5 running on a HPE P11782-001 platform with Intel Xeon Gold 6252 with PAA
- Ubuntu 18.04 on VMware ESXi 6.5 running on a HPE P11782-001 platform with Intel Xeon Gold 6252 without PAA
- Ubuntu 18.04 running on a AIC Antlia BMB-UPS0000B (K470) platform with Intel Xeon E3 1275 v6 with PAA
- Ubuntu 18.04 running on a AIC Antlia BMB-UPS0000B (K470) platform with Intel Xeon E3 1275 v6 without PAA
- Ubuntu 18.04 running on a AIC Antlia BMB-UPS0000B (K570) platform with Intel Xeon E3 1275 v6 with PAA
- Ubuntu 18.04 running on a AIC Antlia BMB-UPS0000B (K570) platform with Intel Xeon E3 1275 v6 without PAA
Validation history
| Date | Type | Lab |
|---|---|---|
| 2023-01-27 | Initial | Acumen Security |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2023-01-27