808bits

TCB Launcher

FIPS 140-2 certificate #4457 · Microsoft Corporation · data as of 2026-08-28
Active. Sunset date 2026-09-21, 23 days away. This is the FIPS 140-2 sunset: after it, agencies may keep the module only in existing systems.
Caveat: When operated in FIPS mode with modules Windows OS Loader validated to FIPS 140-2 under Cert. #4339 operating in FIPS mode or Windows Resume validated to FIPS 140-2 under Cert. #4348 operating in FIPS mode

Certificate

Certificate number4457
StandardFIPS 140-2
Statusactive
Sunset date2026-09-21
Overall level1
Module typeSoftware-Hybrid
EmbodimentMulti-Chip Stand Alone
VendorMicrosoft Corporation · website
Software versions10.0.18363[1] and 10.0.19041[2]
Hardware versionsIntel Core i5-8365U[2] and Intel Core i7-8665U[1]

Module description

The TCB Launcher Module, which consists of the binary TCBLAUNCH.EXE, is the module that launches the Hypervisor and Secure Kernel and other binary image files needed to launch those two components.

Security level exceptions

  • Design Assurance: Level 2

Approved algorithms

AlgorithmCAVP certificate
AESC1363, C1897
CKGvendor affirmed
DRBGC1363, C1897
RSAC1367, C1947
SHSC1363, C1897

Allowed algorithms

NDRNG

Tested configurations

  • Windows 10 Enterprise May 2020 Update (x64) running on a Panasonic Toughbook FZ 55 with an Intel Core i5-8365U with PAA [2]
  • Windows 10 Enterprise November 2019 Update (x64) running on a Dell Latitude 5300 2-in-1 with an Intel Core i7-8665U with PAA [1] (single-user mode)

Validation history

DateTypeLab
2023-03-22InitialLeidos Accredited Testing & Evaluation (AT&E) Lab

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2023-03-22

Source documents