808bits

F-Secure® Cryptographic Library

FIPS 140-2 certificate #494 · F-Secure Corporation · data as of 2026-09-03

F-Secure® Cryptographic Library, from F-Secure Corporation, holds FIPS 140-2 certificate #494 at overall level 2. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. RNG SP800-131A Revision 1 Transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode

Certificate

Certificate number494
StandardFIPS 140-2
Statushistorical
Overall level2
Module typeSoftware
EmbodimentMulti-chip standalone
VendorF-Secure Corporation · website
Software versions2.2.5, 2.2.7 and 2.2.12 (Windows) and 1.1.8, 1.1.9 and 1.1.15 (Solaris)

Module description

Quoted from the NIST CMVP entry for this certificate.

The F-Secure® Cryptographic Library™ is a family of software modules for a number of Windows and Unix platforms. The modules provide an assortment of cryptographic services accessible for clients through a C/C++ Application Programming Interface. The Windows and Solaris versions are designed and implemented to meet the Level 2 requirements of FIPS publication 140-2 when running on an appropriate hardware under Windows 2000, Solaris 8 and Trusted Solaris 8 operating systems.

Approved algorithms (7)

AlgorithmCAVP certificates
AES145, 148
DSA107, 109
HMAC-SHA-1 and HMAC-SHA-256vendor affirmed
RNG2, 4
RSA190, 192
SHS234, 237
Triple-DES255, 257

Other algorithms

DES (Certs. #257 and #259); DES (CTR); Blowfish; CAST-128; MD5; HMAC-MD5; Diffie-Hellman (key agreement)); RC2

Tested configurations

  • Windows 2000 Professional with Service Pack 3 and Q326886 Hotfix EAL 4 on Dell Optiplex GX 400 Personal Computer System, Trusted Solaris 8 7/03 EAL 4 on SunBlade 100

Validation history

DateTypeLab
2004-12-22InitialSAIC-VA
2005-02-03Update
2006-12-20Update

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2004-12-22, 2005-02-03, 2006-12-20

Source documents