nShield 5s Hardware Security Module
Certificate
| Certificate number | 4745 |
|---|---|
| Standard | FIPS 140-3 |
| Status | active |
| Sunset date | 2029-07-30 |
| Overall level | 3 |
| Module type | Hardware |
| Embodiment | Multi-Chip Embedded |
| Vendor | Entrust · website |
| Hardware versions | PCA10005-01 revision 03 and 04 |
| Firmware versions | primary-version 13.2.4; recovery-version 13.2.4; uboot-version 1.1.0 and uboot-version 1.4.1 |
Module description
The nShield 5s PCIe Hardware Security Module (HSM) is a multi-chip embedded hardware Cryptographic Module as defined in FIPS 140-3, which comes in a PCI express board form factor protected by a tamper resistant enclosure, and performs encryption, digital signing, and key management on behalf of an extensive range of commercial and custom-built applications including public key infrastructures (PKIs), identity management systems, application-level encryption and tokenization, SSL/TLS, and code signing.
Security level exceptions
- Operational environment: N/A
- Non-invasive security: N/A
- Mitigation of other attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES-CBC | A2513 |
| AES-CMAC | A2513 |
| AES-CTR | A2512 |
| AES-ECB | A2512 |
| AES-ECB | A2513 |
| AES-GCM | A2512 |
| AES-GCM | A2513 |
| AES-KW | A2513 |
| AES-KWP | A2513 |
| DSA KeyGen (FIPS186-4) | A2513 |
| DSA PQGGen (FIPS186-4) | A2513 |
| DSA PQGVer (FIPS186-4) | A2513 |
| DSA SigGen (FIPS186-4) | A2513 |
| DSA SigVer (FIPS186-4) | A2513 |
| ECDSA KeyGen (FIPS186-4) | A2513 |
| ECDSA KeyVer (FIPS186-4) | A2513 |
| ECDSA SigGen (FIPS186-4) | A2512 |
| ECDSA SigGen (FIPS186-4) | A2513 |
| ECDSA SigVer (FIPS186-4) | A2512 |
| ECDSA SigVer (FIPS186-4) | A2513 |
| Hash DRBG | A2513 |
| HMAC-SHA-1 | A2513 |
| HMAC-SHA2-224 | A2513 |
| HMAC-SHA2-256 | A2512 |
| HMAC-SHA2-256 | A2513 |
| HMAC-SHA2-384 | A2513 |
| HMAC-SHA2-512 | A2513 |
| KAS-ECC Sp800-56Ar3 | A2513 |
| KAS-ECC Sp800-56Ar3 | A2513 |
| KAS-ECC-SSC Sp800-56Ar3 | A2512 |
| KAS-FFC Sp800-56Ar3 | A2513 |
| KAS-FFC Sp800-56Ar3 | A2513 |
| KDF SP800-108 | A2513 |
| KDF SSH | A2512 |
| KTS-IFC | A2513 |
| RSA KeyGen (FIPS186-4) | A2513 |
| RSA SigGen (FIPS186-4) | A2513 |
| RSA SigVer (FIPS186-4) | A2404 |
| RSA SigVer (FIPS186-4) | A2513 |
| RSA SigVer (FIPS186-4) | A6385 |
| Safe Primes Key Generation | A2513 |
| Safe Primes Key Verification | A2513 |
| SHA-1 | A2513 |
| SHA2-224 | A2513 |
| SHA2-256 | A2404 |
| SHA2-256 | A2512 |
| SHA2-256 | A2513 |
| SHA2-256 | A6385 |
| SHA2-384 | A2513 |
| SHA2-512 | A2512 |
| SHA2-512 | A2513 |
| SHA3-224 | A2513 |
| SHA3-256 | A2513 |
| SHA3-384 | A2513 |
| SHA3-512 | A2513 |
Allowed algorithms
ECDSA (Cert. #A2513) (when used with non-approved Brainpool elliptic curves P224r1/P224t1, P256r1/P256t1, P320r1/P320t1, P384r1/P384t1 and P512r1/P512t1; Key generation Signature generation and verification);KAS-ECC (Cert. #A2513) (when used with non-approved Brainpool elliptic curves P224r1/P224t1, P256r1/P256t1, P320r1/P320t1, P384r1/P384t1 and P512r1/P512t1; Key establishment)
Tested configurations
- n/a
Validation history
| Date | Type | Lab |
|---|---|---|
| 2024-07-31 | Initial | Lightship Security, Inc. |
| 2025-04-01 | Update | Lightship Security, Inc. |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2024-07-31