VMware's ESXboot Cryptographic Module
Caveat: When installed, initialized and configured as specified in Section 11 of the Security Policy
Certificate
| Certificate number | 4442 |
|---|---|
| Standard | FIPS 140-3 |
| Status | active |
| Sunset date | 2028-02-22 |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | VMware, Inc. · website |
| Software versions | 1.0 |
Module description
VMware’s ESXboot Cryptographic Module provides FIPS 140-3 Approved cryptographic services for verifying the integrity of ESXi during the boot process.
Security level exceptions
- Physical security: N/A
- Non-invasive security: N/A
- Mitigation of other attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| HMAC-SHA2-224 | A1357 |
| HMAC-SHA2-256 | A1357 |
| HMAC-SHA2-384 | A1357 |
| HMAC-SHA2-512 | A1357 |
| RSA SigVer (FIPS186-4) | A1357 |
| SHA2-224 | A1357 |
| SHA2-256 | A1357 |
| SHA2-384 | A1357 |
| SHA2-512 | A1357 |
Tested configurations
- UEFI 2.5 running on a Dell PowerEdge R740 with an Intel® Xeon® Gold 6126
- UEFI 2.7 running on a Dell PowerEdge R740 with an Intel® Xeon® Gold 6230R
- UEFI 2.7 running on a Lenovo ThinkSystem HR350A with an Ampere Computing eMAG
Validation history
| Date | Type | Lab |
|---|---|---|
| 2023-02-23 | Initial | Leidos Accredited Testing & Evaluation (AT&E) Lab |
| 2024-04-04 | Update | Leidos Accredited Testing & Evaluation (AT&E) Lab |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2023-02-23