808bits

nShield 5s Hardware Security Module

FIPS 140-3 certificate #4765 · Entrust · data as of 2026-08-28
Historical. Replaced by certificate #5329. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: Interim validation. When installed, initialized and configured as specified in Section 11.3 of the Security Policy

Certificate

Certificate number4765
StandardFIPS 140-3
Statushistorical
Overall level3
Module typeHardware
EmbodimentMulti-Chip Embedded
VendorEntrust · website
Hardware versionsPCA10005-01 revision 03 and 04
Firmware versionsprimary-version 13.4.5; recovery-version 13.2.4; uboot-version 1.1.0 and uboot-version 1.4.1

Module description

The nShield 5s Hardware Security Module is a multi-chip embedded hardware Cryptographic Module as defined in FIPS 140-3, which comes in a PCI express board form factor protected by a tamper resistant enclosure, and performs encryption, digital signing, and key management on behalf of an extensive range of commercial and custom-built applications including public key infrastructures (PKIs), identity management systems, application-level encryption and tokenization, SSL/TLS, and code signing.

Security level exceptions

  • Operational environment: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES-CBCA3707
AES-CMACA3707
AES-CTRA3706
AES-ECBA3706
AES-ECBA3707
AES-GCMA3706
AES-GCMA3707
AES-KWA3707
AES-KWPA3707
DSA KeyGen (FIPS186-4)A3707
DSA PQGGen (FIPS186-4)A3707
DSA PQGVer (FIPS186-4)A3707
DSA SigGen (FIPS186-4)A3707
DSA SigVer (FIPS186-4)A3707
ECDSA KeyGen (FIPS186-4)A3707
ECDSA KeyVer (FIPS186-4)A3707
ECDSA SigGen (FIPS186-4)A3706
ECDSA SigGen (FIPS186-4)A3707
ECDSA SigVer (FIPS186-4)A3706
ECDSA SigVer (FIPS186-4)A3707
Hash DRBGA3707
HMAC-SHA-1A3707
HMAC-SHA2-224A3707
HMAC-SHA2-256A3706
HMAC-SHA2-256A3707
HMAC-SHA2-384A3707
HMAC-SHA2-512A3707
HMAC-SHA3-224A3707
HMAC-SHA3-256A3707
HMAC-SHA3-384A3707
HMAC-SHA3-512A3707
KAS-ECC Sp800-56Ar3A3707
KAS-ECC-SSC Sp800-56Ar3A3706
KAS-FFC Sp800-56Ar3A3707
KDF SP800-108A3707
KDF SSHA3706
KMAC-128A3707
KMAC-256A3707
KTS-IFCA3707
RSA KeyGen (FIPS186-4)A3707
RSA SigGen (FIPS186-4)A3707
RSA SigVer (FIPS186-4)A2404
RSA SigVer (FIPS186-4)A3707
RSA SigVer (FIPS186-4)A6385
Safe Primes Key GenerationA3707
Safe Primes Key VerificationA3707
SHA-1A3707
SHA2-224A3707
SHA2-256A2404
SHA2-256A3706
SHA2-256A3707
SHA2-256A6385
SHA2-384A3707
SHA2-512A3706
SHA2-512A3707
SHA3-224A3707
SHA3-256A3707
SHA3-384A3707
SHA3-512A3707

Allowed algorithms

ECDSA (Cert. #A3707) (When used with non-approved Brainpool elliptic curves P224r1/P224t1, P256r1/P256t1, P320r1/P320t1, P384r1/P384t1, and P512r1/P512t1; Key generation Signature generation and verification);KAS-ECC (Cert. #A3707) (When used with non-approved Brainpool elliptic curves P224r1/P224t1, P256r1/P256t1, P320r1/P320t1, P384r1/P384t1, and P512r1/P512t1; Key establishment)

Tested configurations

  • n/a

Validation history

DateTypeLab
2024-08-19InitialLightship Security, Inc.
2025-04-01UpdateLightship Security, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2024-08-19

Source documents