VMware’s VPN Crypto Module
Caveat: Interim validation
Certificate
| Certificate number | 4881 |
|---|---|
| Standard | FIPS 140-3 |
| Status | active |
| Sunset date | 2026-11-14 |
| Overall level | 1 |
| Module type | Firmware |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Broadcom Inc. · website |
| Firmware versions | 21.11 |
Module description
VMware's VPN Crypto Module is a firmware cryptographic module whose purpose is to provide FIPS 140-3 validated cryptographic functions to various applications utilizing VPN capabilities.
Security level exceptions
- Non-invasive security: N/A
- Mitigation of other attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES-CBC | A4384 |
| AES-CCM | A4384 |
| AES-CMAC | A4384 |
| AES-GCM | A4384 |
| AES-GMAC | A4384 |
| HMAC-SHA-1 | A4384 |
| HMAC-SHA2-224 | A4384 |
| HMAC-SHA2-256 | A4384 |
| HMAC-SHA2-256 | A4385 |
| HMAC-SHA2-384 | A4384 |
| HMAC-SHA2-512 | A4384 |
| SHA-1 | A4384 |
| SHA2-224 | A4384 |
| SHA2-256 | A4384 |
| SHA2-256 | A4385 |
| SHA2-384 | A4384 |
| SHA2-512 | A4384 |
Tested configurations
- Ubuntu 20.04 on ESXi 8.0 running on Dell PowerEdge R650 with Intel(R) Xeon(R) Gold 6330 with PAA
- Ubuntu 20.04 on ESXi 8.0 running on Dell PowerEdge R650 with Intel(R) Xeon(R) Gold 6330 without PAA
Validation history
| Date | Type | Lab |
|---|---|---|
| 2024-11-15 | Initial | Lightship Security, Inc. |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2024-11-15