Thales CipherTrust Manager Core Security Module
Thales CipherTrust Manager Core Security Module, from Thales, holds FIPS 140-2 certificate #4430 at overall level 1. The validation is active, with a sunset date of 2026-09-21. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.
Caveat: When installed, initialized and configured as specified in Section 10 of the Security Policy. When operated in FIPS mode. No assurance of the minimum strength of generated keys.
Certificate
| Certificate number | 4430 |
|---|---|
| Standard | FIPS 140-2 |
| Status | active |
| Sunset date | 2026-09-21 |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Thales |
| Software versions | 1.0.3 |
Module description
Quoted from the NIST CMVP entry for this certificate.
The module provides secure key generation and protection for symmetric keys and asymmetric key pairs along with support for a broad range of other cryptographic services. Access to services offered by Thales CipherTrust Manager Core Security Module is exclusively through a number of Application Programming Interfaces (API) offered by the Thales CipherTrust Manager Core Security Module. These API can be accessed by other applications running internal to the physical boundary of the module or, in some instances, can be accessed by remote client over dedicated TLS tunnels.
Security level exceptions
- Physical Security: N/A
- Design Assurance: Level 3
- Mitigation of Other Attacks: N/A
Approved algorithms (16)
| Algorithm | CAVP certificates |
|---|---|
| AES | A1778, A1779, A2634, A2635 |
| CKG | vendor affirmed |
| CVL | A1779 |
| DRBG | A1779 |
| ECDSA | A1779, A2634 |
| ENT | |
| HMAC | A1779, A2634 |
| KAS-SSC | A1779, A2634 |
| KDA | A1779 |
| KTS | |
| KTS-RSA | |
| PBKDF | A1779 |
| RSA | A1779 |
| SHA-3 | A1779 |
| SHS | A1779, A2634 |
| Triple-DES | A1779, A2634 |
Allowed algorithms
RSA (Key wrapping; key establishment methodology provides between 112 and 150 bits of encryption strength)
Tested configurations
- Ubuntu 18.04 on VMware ESXi 6.5 running on a HPE P11782-001 platform with Intel Xeon Gold 6252 with PAA
- Ubuntu 18.04 on VMware ESXi 6.5 running on a HPE P11782-001 platform with Intel Xeon Gold 6252 without PAA
- Ubuntu 18.04 running on a AIC Antlia BMB-UPS0000B (K470) platform with Intel Xeon E3 1275 v6 with PAA
- Ubuntu 18.04 running on a AIC Antlia BMB-UPS0000B (K470) platform with Intel Xeon E3 1275 v6 without PAA
- Ubuntu 18.04 running on a AIC Antlia BMB-UPS0000B (K570) platform with Intel Xeon E3 1275 v6 with PAA
- Ubuntu 18.04 running on a AIC Antlia BMB-UPS0000B (K570) platform with Intel Xeon E3 1275 v6 without PAA
Validation history
| Date | Type | Lab |
|---|---|---|
| 2023-01-27 | Initial | Acumen Security |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2023-01-27