808bits

RapidIdentity FIPS Cryptographic Module

FIPS 140-2 certificate #4669 · Identity Automation · data as of 2026-08-28
Active. Sunset date 2026-09-21, 23 days away. This is the FIPS 140-2 sunset: after it, agencies may keep the module only in existing systems.
Caveat: When operated in FIPS mode. No assurance of the minimum strength of generated keys.

Certificate

Certificate number4669
StandardFIPS 140-2
Statusactive
Sunset date2026-09-21
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorIdentity Automation · website
Software versions2.0

Module description

The RapidIdentity FIPS Cryptographic Module is a cryptographic engine for Windows, iOS, and Android. The module delivers core cryptographic functions to Identity Automation’s RapidIdentity MFA Server and MFA Mobile app which provide a variety of authentication methods. The RapidIdentity FIPS Cryptographic Module leverages industry leading, FIPS approved cryptographic algorithms provided by the Bouncy Castle FIPS .NET APIs.

Security level exceptions

  • Physical Security: N/A

Approved algorithms

AlgorithmCAVP certificate
AESA2698
CKGvendor affirmed
CVLA2698
DRBGA2698
DSAA2698
ECDSAA2698
HMACA2698
KASA2698
KAS
KAS
KAS-SSCA2698
KDAA2698
KMAC
KTS
KTS
KTS-RSA
PBKDFA2698
RSAA2698
SHA-3A2698
SHSA2698
Triple- DES

Allowed algorithms

RSA (key wrapping; key establishment methodology provides 112 or 128 bits of encryption strength)

Tested configurations

  • Android 11 with Xamarin.Android 11.1.0.26 running on Realme RMX3461 with Qualcomm Snapdragon 778G SM7325
  • iOS 15.5 with Xamarin.iOS 15.2.0.17 running on Apple iPhone 7 with Apple A10 Fusion
  • Windows Server 2016 with .NET Framework 4.6 running on Dell Latitude 3410 with Intel(R) Core(TM) i5-10210U (single-user mode)

Validation history

DateTypeLab
2023-12-08InitialAcumen Security
2024-04-24UpdateAcumen Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2023-12-08, 2024-04-24

Known CVEs in this module family (heuristic match)

Name-based association with the module's product family, not a statement about the validated boundary. See methodology.

CVECVSSSeverity
CVE-2024-455895.9MEDIUM

Source documents