808bits

CorSSL

FIPS 140-3 certificate #4897 · Corsec Security, Inc. · data as of 2026-08-28
Active. Sunset date 2026-11-20, 83 days away.
Caveat: Interim validation. When operated in approved mode. When installed, initialized and configured as specified in Section 11 of the Security Policy. No assurance of the minimum strength of generated SSPs (e.g., keys)

Certificate

Certificate number4897
StandardFIPS 140-3
Statusactive
Sunset date2026-11-20
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorCorsec Security, Inc. · website
Software versions1.1.1s.005

Module description

CorSSL offers symmetric encryption/decryption, digital signature generation/verification, hashing, cryptographic key generation, random number generation, message authentication, and key establishment functions to secure data. The libcrypto library provides the main cryptographic functionality for the module.

Security level exceptions

  • Physical security: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES-CBCA3254
AES-CCMA3254
AES-CFB1A3254
AES-CFB128A3254
AES-CFB8A3254
AES-CMACA3254
AES-CTRA3254
AES-ECBA3254
AES-GCMA3254
AES-GMACA3254
AES-KWA3254
AES-KWPA3254
AES-OFBA3254
AES-XTS Testing Revision 2.0A3254
Counter DRBGA3254
DSA KeyGen (FIPS186-4)A3254
DSA PQGGen (FIPS186-4)A3254
DSA PQGVer (FIPS186-4)A3254
DSA SigGen (FIPS186-4)A3254
DSA SigVer (FIPS186-4)A3254
ECDSA KeyGen (FIPS186-4)A3254
ECDSA KeyVer (FIPS186-4)A3254
ECDSA SigGen (FIPS186-4)A3254
ECDSA SigVer (FIPS186-4)A3254
HMAC-SHA-1A3254
HMAC-SHA2-224A3254
HMAC-SHA2-256A3254
HMAC-SHA2-384A3254
HMAC-SHA2-512A3254
HMAC-SHA3-224A3254
HMAC-SHA3-256A3254
HMAC-SHA3-384A3254
HMAC-SHA3-512A3254
KAS-ECC-SSC Sp800-56Ar3A3254
KAS-FFC-SSC Sp800-56Ar3A3254
PBKDFA3254
RSA KeyGen (FIPS186-4)A3254
RSA SigGen (FIPS186-4)A3254
RSA SigGen (FIPS186-4)A3254
RSA SigGen (FIPS186-4)A3254
RSA SigVer (FIPS186-4)A3254
RSA SigVer (FIPS186-4)A3254
RSA SigVer (FIPS186-4)A3254
SHA-1A3254
SHA2-224A3254
SHA2-256A3254
SHA2-384A3254
SHA2-512A3254
SHA3-224A3254
SHA3-256A3254
SHA3-384A3254
SHA3-512A3254
SHAKE-128A3254
SHAKE-256A3254
TDES-CBCA3254
TDES-CFB1A3254
TDES-CFB64A3254
TDES-CFB8A3254
TDES-CMACA3254
TDES-ECBA3254
TDES-OFBA3254
TLS v1.2 KDF RFC7627A3254
TLS v1.3 KDFA3253

Allowed algorithms

AES (Cert. #A3254, Key Unwrapping. Per IG D.G.; Symmetric Key Unwrapping (using any approved mode));Triple-DES (Cert. #A3254, Key Unwrapping. Per IG D.G.; Symmetric Key Unwrapping (using any approved mode with two-key or three-key))

Tested configurations

  • Debian 9 running on a Dell PowerEdge R440 with an Intel(R) Xeon(R) Silver 4214R with PAA
  • Debian 9 running on a Dell PowerEdge R440 with an Intel(R) Xeon(R) Silver 4214R without PAA

Validation history

DateTypeLab
2024-11-21InitialLeidos Accredited Testing & Evaluation (AT&E) Lab

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2024-11-21

Source documents