808bits

CryptoComply 140-3 FIPS Provider

FIPS 140-3 certificate #4781 · SafeLogic Inc. · data as of 2026-09-15

CryptoComply 140-3 FIPS Provider, from SafeLogic Inc., holds FIPS 140-3 certificate #4781 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Replaced by certificate #5040. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: Interim validation. When installed, initialized and configured as specified in Section 11.1 of the Security Policy. No assurance of the minimum strength of generated SSPs (e.g., keys) and random strings. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs

Certificate

Certificate number4781
StandardFIPS 140-3
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorSafeLogic Inc. · website
Software versions3.0.0-FIPS 140-3, 3.0.1-FIPS 140-3

Module description

Quoted from the NIST CMVP entry for this certificate.

CryptoComply 140-3 FIPS Provider is a standards-based “Drop-in Compliance™” cryptographic engine. The module delivers core cryptographic functions to applications such as servers, personal computers, mobile devices, and appliances. The module features robust algorithm support, including CNSA algorithms. The module delivers cryptographic services to host applications through a C language Application Programming Interface (API).

Security level exceptions

  • Physical security: N/A
  • Non-invasive security: N/A

Approved algorithms (80)

AlgorithmCAVP certificates
AES-CBCA4593, A5173
AES-CBC-CS1A4593, A5173
AES-CBC-CS2A4593, A5173
AES-CBC-CS3A4593, A5173
AES-CCMA4593, A5173
AES-CFB1A4593, A5173
AES-CFB128A4593, A5173
AES-CFB8A4593, A5173
AES-CMACA4593, A5173
AES-CTRA4593, A5173
AES-ECBA4593, A5173
AES-GCMA4593, A5173
AES-GMACA4593, A5173
AES-KWA4593, A5173
AES-KWPA4593, A5173
AES-OFBA4593, A5173
AES-XTS Testing Revision 2.0A4593, A5173
Counter DRBGA4593, A5173
DSA KeyGen (FIPS186-4)A4593, A5173
DSA PQGGen (FIPS186-4)A4593, A5173
DSA PQGVer (FIPS186-4)A4593, A5173
DSA SigVer (FIPS186-4)A4593, A5173
ECDSA KeyGen (FIPS186-4)A4593, A5173
ECDSA KeyVer (FIPS186-4)A4593, A5173
ECDSA SigGen (FIPS186-4)A4593
ECDSA SigVer (FIPS186-4)A4593, A5173
EDDSA KeyGenA4593, A5173
EDDSA KeyVerA4593, A5173
EDDSA SigGenA4593, A5173
EDDSA SigVerA4593
Hash DRBGA4593, A5173
HMAC DRBGA4593, A5173
HMAC-SHA-1A4593, A5173
HMAC-SHA2-224A4593, A5173
HMAC-SHA2-256A4593, A5173
HMAC-SHA2-384A4593, A5173
HMAC-SHA2-512A4593, A5173
HMAC-SHA2-512/224A4593, A5173
HMAC-SHA2-512/256A4593, A5173
HMAC-SHA3-224A4593, A5173
HMAC-SHA3-256A4593, A5173
HMAC-SHA3-384A4593, A5173
HMAC-SHA3-512A4593, A5173
KAS-ECC-SSC Sp800-56Ar3A4593, A5173
KAS-FFC-SSC Sp800-56Ar3A4593, A5173
KAS-IFC-SSCA4593, A5173
KDA HKDF SP800-56Cr2A4593, A5173
KDA OneStep SP800-56Cr2A4593, A5173
KDA TwoStep SP800-56Cr2A4593, A5173
KDF ANS 9.42A4593, A5173
KDF ANS 9.63A4593, A5173
KDF KMAC Sp800-108r1A4593, A5173
KDF SP800-108A4593, A5173
KDF SSHA4593, A5173
KMAC-128A4593, A5173
KMAC-256A4593, A5173
KTS-IFCA4593, A5173
PBKDFA4593, A5173
RSA KeyGen (FIPS186-4)A4593, A5173
RSA SigGen (FIPS186-4)A4593, A5173
RSA SigVer (FIPS186-4)A4593, A5173
Safe Primes Key GenerationA4593, A5173
Safe Primes Key VerificationA4593, A5173
SHA-1A4593, A5173
SHA2-224A4593, A5173
SHA2-256A4593, A5173
SHA2-384A4593, A5173
SHA2-512A4593, A5173
SHA2-512/224A4593, A5173
SHA2-512/256A4593, A5173
SHA3-224A4593, A5173
SHA3-256A4593, A5173
SHA3-384A4593, A5173
SHA3-512A4593, A5173
SHAKE-128A4593, A5173
SHAKE-256A4593, A5173
TDES-CBCA4593, A5173
TDES-ECBA4593, A5173
TLS v1.2 KDF RFC7627A4593, A5173
TLS v1.3 KDFA4593, A5173

Allowed algorithms

EC Diffie-Hellman with non-NIST recommended curves (Provides 112, 128, 160, 192, or 256 bits of encryption strength. Per IGs D.F and C.A.; Shared secret computation using non-NIST curves: brainpoolP224r1, brainpoolP256r1, brainpoolP320r1, brainpoolP384r1, brainpoolP512r1, with strengths 112 bits, 128 bits, 160 bits, 192 bits, and 256 bits);ECDSA with non-NIST recommended curves (Provides 112, 128, 160, 192, or 256 bits of encryption strength. Per IG C.A.; Key pair generation, digital signature generation, digital signature verification using non-NIST curves: brainpoolP224r1, brainpoolP256r1, brainpoolP320r1, brainpoolP384r1, brainpoolP512r1, with strengths 112 bits, 128 bits, 160 bits, 192 bits, and 256 bits)

Tested configurations

  • AlmaLinux 9 running on a Dell PowerEdge R830 with an Intel Xeon E5-4667v4 with PAA
  • AlmaLinux 9 running on a Dell PowerEdge R830 with an Intel Xeon E5-4667v4 without PAA
  • Android 13 running on a Google Pixel 7 with a Google Tensor G2
  • Debian 11 running on a Dell PowerEdge R830 with an Intel Xeon E5-4667v4 with PAA
  • Debian 11 running on a Dell PowerEdge R830 with an Intel Xeon E5-4667v4 without PAA
  • FreeBSD 13 running on a Dell PowerEdge R830 with an Intel Xeon E5-4667v4 with PAA
  • FreeBSD 13 running on a Dell PowerEdge R830 with an Intel Xeon E5-4667v4 without PAA
  • iOS 16 running on an iPhone 13 Mini with an Apple A15 Bionic without PAA
  • iPadOS 16 running on an iPad Air (2022) with an Apple M1 without No
  • macOS 13 (Ventura) running on a Mac Mini M2 with an Apple M2
  • Oracle Solaris 11.4 running on a Dell PowerEdge R830 with an Intel Xeon E5-4667v4 with PAA
  • Oracle Solaris 11.4 running on a Dell PowerEdge R830 with an Intel Xeon E5-4667v4 without PAA
  • Red Hat Enterprise Linux 9 running on a Dell PowerEdge R830 with an Intel Xeon E5-4667v4 with PAA
  • Red Hat Enterprise Linux 9 running on a Dell PowerEdge R830 with an Intel Xeon E5-4667v4 without PAA
  • Rocky Linux 9 running on a Dell PowerEdge R830 with an Intel Xeon E5-4667v4 with PAA
  • Rocky Linux 9 running on a Dell PowerEdge R830 with an Intel Xeon E5-4667v4 without PAA
  • SUSE Linux Enterprise Server 15 running on a Dell PowerEdge R830 with an Intel Xeon E5-4667v4 with PAA
  • SUSE Linux Enterprise Server 15 running on a Dell PowerEdge R830 with an Intel Xeon E5-4667v4 without PAA
  • Ubuntu 22.04 running on a Dell PowerEdge R830 with an Intel Xeon E5-4667v4 with PAA
  • Ubuntu 22.04 running on a Dell PowerEdge R830 with an Intel Xeon E5-4667v4 without PAA
  • Windows 10 running on a Dell PowerEdge R830 with an Intel Xeon E5-4667v4 with PAA
  • Windows 10 running on a Dell PowerEdge R830 with an Intel Xeon E5-4667v4 without PAA
  • Windows 11 running on a Dell PowerEdge R830 with an Intel Xeon E5-4667v4 with PAA
  • Windows 11 running on a Dell PowerEdge R830 with an Intel Xeon E5-4667v4 without PAA
  • Windows Server 2019 running on a Dell PowerEdge R830 with an Intel Xeon E5-4667v4 with PAA
  • Windows Server 2019 running on a Dell PowerEdge R830 with an Intel Xeon E5-4667v4 without PAA
  • Windows Server 2022 running on a Dell PowerEdge R830 with an Intel Xeon E5-4667v4 with PAA
  • Windows Server 2022 running on a Dell PowerEdge R830 with an Intel Xeon E5-4667v4 without PAA

Validation history

DateTypeLab
2024-08-27InitialLeidos Accredited Testing & Evaluation (AT&E) Lab

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2024-08-27

Source documents