CorSSL
CorSSL, from Corsec Security, Inc., holds FIPS 140-3 certificate #4897 at overall level 1. The validation is active, with a sunset date of 2026-11-20. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.
Caveat: Interim validation. When operated in approved mode. When installed, initialized and configured as specified in Section 11 of the Security Policy. No assurance of the minimum strength of generated SSPs (e.g., keys)
Certificate
| Certificate number | 4897 |
|---|---|
| Standard | FIPS 140-3 |
| Status | active |
| Sunset date | 2026-11-20 |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Corsec Security, Inc. · website |
| Software versions | 1.1.1s.005 |
Module description
Quoted from the NIST CMVP entry for this certificate.
CorSSL offers symmetric encryption/decryption, digital signature generation/verification, hashing, cryptographic key generation, random number generation, message authentication, and key establishment functions to secure data. The libcrypto library provides the main cryptographic functionality for the module.
Security level exceptions
- Physical security: N/A
- Non-invasive security: N/A
- Mitigation of other attacks: N/A
Approved algorithms (59)
| Algorithm | CAVP certificates |
|---|---|
| AES-CBC | A3254 |
| AES-CCM | A3254 |
| AES-CFB1 | A3254 |
| AES-CFB128 | A3254 |
| AES-CFB8 | A3254 |
| AES-CMAC | A3254 |
| AES-CTR | A3254 |
| AES-ECB | A3254 |
| AES-GCM | A3254 |
| AES-GMAC | A3254 |
| AES-KW | A3254 |
| AES-KWP | A3254 |
| AES-OFB | A3254 |
| AES-XTS Testing Revision 2.0 | A3254 |
| Counter DRBG | A3254 |
| DSA KeyGen (FIPS186-4) | A3254 |
| DSA PQGGen (FIPS186-4) | A3254 |
| DSA PQGVer (FIPS186-4) | A3254 |
| DSA SigGen (FIPS186-4) | A3254 |
| DSA SigVer (FIPS186-4) | A3254 |
| ECDSA KeyGen (FIPS186-4) | A3254 |
| ECDSA KeyVer (FIPS186-4) | A3254 |
| ECDSA SigGen (FIPS186-4) | A3254 |
| ECDSA SigVer (FIPS186-4) | A3254 |
| HMAC-SHA-1 | A3254 |
| HMAC-SHA2-224 | A3254 |
| HMAC-SHA2-256 | A3254 |
| HMAC-SHA2-384 | A3254 |
| HMAC-SHA2-512 | A3254 |
| HMAC-SHA3-224 | A3254 |
| HMAC-SHA3-256 | A3254 |
| HMAC-SHA3-384 | A3254 |
| HMAC-SHA3-512 | A3254 |
| KAS-ECC-SSC Sp800-56Ar3 | A3254 |
| KAS-FFC-SSC Sp800-56Ar3 | A3254 |
| PBKDF | A3254 |
| RSA KeyGen (FIPS186-4) | A3254 |
| RSA SigGen (FIPS186-4) | A3254 |
| RSA SigVer (FIPS186-4) | A3254 |
| SHA-1 | A3254 |
| SHA2-224 | A3254 |
| SHA2-256 | A3254 |
| SHA2-384 | A3254 |
| SHA2-512 | A3254 |
| SHA3-224 | A3254 |
| SHA3-256 | A3254 |
| SHA3-384 | A3254 |
| SHA3-512 | A3254 |
| SHAKE-128 | A3254 |
| SHAKE-256 | A3254 |
| TDES-CBC | A3254 |
| TDES-CFB1 | A3254 |
| TDES-CFB64 | A3254 |
| TDES-CFB8 | A3254 |
| TDES-CMAC | A3254 |
| TDES-ECB | A3254 |
| TDES-OFB | A3254 |
| TLS v1.2 KDF RFC7627 | A3254 |
| TLS v1.3 KDF | A3253 |
Allowed algorithms
AES (Cert. #A3254, Key Unwrapping. Per IG D.G.; Symmetric Key Unwrapping (using any approved mode));Triple-DES (Cert. #A3254, Key Unwrapping. Per IG D.G.; Symmetric Key Unwrapping (using any approved mode with two-key or three-key))
Tested configurations
- Debian 9 running on a Dell PowerEdge R440 with an Intel(R) Xeon(R) Silver 4214R with PAA
- Debian 9 running on a Dell PowerEdge R440 with an Intel(R) Xeon(R) Silver 4214R without PAA
Validation history
| Date | Type | Lab |
|---|---|---|
| 2024-11-21 | Initial | Leidos Accredited Testing & Evaluation (AT&E) Lab |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2024-11-21