808bits

nShield 5s Hardware Security Module

FIPS 140-3 certificate #4745 · Entrust · data as of 2026-08-28
Active. Sunset date 2029-07-30, 1066 days away.
Caveat: When installed, initialized and configured as specified in Section 11.3 of the Security Policy

Certificate

Certificate number4745
StandardFIPS 140-3
Statusactive
Sunset date2029-07-30
Overall level3
Module typeHardware
EmbodimentMulti-Chip Embedded
VendorEntrust · website
Hardware versionsPCA10005-01 revision 03 and 04
Firmware versionsprimary-version 13.2.4; recovery-version 13.2.4; uboot-version 1.1.0 and uboot-version 1.4.1

Module description

The nShield 5s PCIe Hardware Security Module (HSM) is a multi-chip embedded hardware Cryptographic Module as defined in FIPS 140-3, which comes in a PCI express board form factor protected by a tamper resistant enclosure, and performs encryption, digital signing, and key management on behalf of an extensive range of commercial and custom-built applications including public key infrastructures (PKIs), identity management systems, application-level encryption and tokenization, SSL/TLS, and code signing.

Security level exceptions

  • Operational environment: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES-CBCA2513
AES-CMACA2513
AES-CTRA2512
AES-ECBA2512
AES-ECBA2513
AES-GCMA2512
AES-GCMA2513
AES-KWA2513
AES-KWPA2513
DSA KeyGen (FIPS186-4)A2513
DSA PQGGen (FIPS186-4)A2513
DSA PQGVer (FIPS186-4)A2513
DSA SigGen (FIPS186-4)A2513
DSA SigVer (FIPS186-4)A2513
ECDSA KeyGen (FIPS186-4)A2513
ECDSA KeyVer (FIPS186-4)A2513
ECDSA SigGen (FIPS186-4)A2512
ECDSA SigGen (FIPS186-4)A2513
ECDSA SigVer (FIPS186-4)A2512
ECDSA SigVer (FIPS186-4)A2513
Hash DRBGA2513
HMAC-SHA-1A2513
HMAC-SHA2-224A2513
HMAC-SHA2-256A2512
HMAC-SHA2-256A2513
HMAC-SHA2-384A2513
HMAC-SHA2-512A2513
KAS-ECC Sp800-56Ar3A2513
KAS-ECC Sp800-56Ar3A2513
KAS-ECC-SSC Sp800-56Ar3A2512
KAS-FFC Sp800-56Ar3A2513
KAS-FFC Sp800-56Ar3A2513
KDF SP800-108A2513
KDF SSHA2512
KTS-IFCA2513
RSA KeyGen (FIPS186-4)A2513
RSA SigGen (FIPS186-4)A2513
RSA SigVer (FIPS186-4)A2404
RSA SigVer (FIPS186-4)A2513
RSA SigVer (FIPS186-4)A6385
Safe Primes Key GenerationA2513
Safe Primes Key VerificationA2513
SHA-1A2513
SHA2-224A2513
SHA2-256A2404
SHA2-256A2512
SHA2-256A2513
SHA2-256A6385
SHA2-384A2513
SHA2-512A2512
SHA2-512A2513
SHA3-224A2513
SHA3-256A2513
SHA3-384A2513
SHA3-512A2513

Allowed algorithms

ECDSA (Cert. #A2513) (when used with non-approved Brainpool elliptic curves P224r1/P224t1, P256r1/P256t1, P320r1/P320t1, P384r1/P384t1 and P512r1/P512t1; Key generation Signature generation and verification);KAS-ECC (Cert. #A2513) (when used with non-approved Brainpool elliptic curves P224r1/P224t1, P256r1/P256t1, P320r1/P320t1, P384r1/P384t1 and P512r1/P512t1; Key establishment)

Tested configurations

  • n/a

Validation history

DateTypeLab
2024-07-31InitialLightship Security, Inc.
2025-04-01UpdateLightship Security, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2024-07-31

Source documents