EZPES Centralized Security Module (CSM)
Caveat: When operated in FIPS mode
Certificate
| Certificate number | 4433 |
|---|---|
| Standard | FIPS 140-2 |
| Status | active |
| Sunset date | 2026-09-21 |
| Overall level | 3 |
| Module type | Hardware |
| Embodiment | Multi-Chip Embedded |
| Vendor | EasyPost · website |
| Hardware versions | CryptoServer CSe-Series 4.00.5.1 |
| Firmware versions | CryptoServer CSe-Series 4.32.0.5; App version: 3.0.0.0 |
Module description
The EasyPost Centralized Security Module (CSM) acts as the core security module of a United States Postal Service (USPS) Intelligent Mail Indicia Performance Criteria (IMI PC) conformant online postage evidencing system (PES). Its primary purpose is to perform secure postal financial transactions.
Security level exceptions
- Physical Security: Level 4
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | C1122, C1137, C1138, C1140, C1246 |
| CKG | vendor affirmed |
| CVL | A1016, C1141, C1165 |
| DRBG | A1068 |
| DSA | C1195 |
| ECDSA | A2367, C1196 |
| ENT | |
| HMAC | C1142 |
| KAS | |
| KAS-SSC | A2227, A2368, A2369 |
| KBKDF | C1164 |
| KDA | A1016, A2417 |
| KTS | |
| KTS | |
| KTS-RSA | |
| RSA | C1197 |
| SHA-3 | C1125 |
| SHS | A1067, C1124, C1126 |
| Triple-DES | C1128 |
Tested configurations
- N/A
Validation history
| Date | Type | Lab |
|---|---|---|
| 2023-02-09 | Initial | Penumbra Security, Inc. |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2023-02-09