808bits

BoringCrypto

FIPS 140-3 certificate #4953 · Google, LLC. · data as of 2026-08-28
Historical. Replaced by certificate #5296. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: Interim validation. When operated in approved mode. No assurance of the minimum strength of generated SSPs (e.g., keys)

Certificate

Certificate number4953
StandardFIPS 140-3
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorGoogle, LLC. · website
Software versions2023042800

Module description

A software library that contains cryptographic functionality to serve BoringSSL and other user-space applications.

Security level exceptions

  • Physical security: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES-CBCA4687
AES-CCMA4687
AES-CTRA4687
AES-ECBA4687
AES-GCMA4687
AES-GMACA4687
AES-KWA4687
AES-KWPA4687
Counter DRBGA4687
ECDSA KeyGen (FIPS186-4)A4687
ECDSA KeyVer (FIPS186-4)A4687
ECDSA SigGen (FIPS186-4)A4687
ECDSA SigVer (FIPS186-4)A4687
HMAC-SHA-1A4687
HMAC-SHA2-224A4687
HMAC-SHA2-256A4687
HMAC-SHA2-384A4687
HMAC-SHA2-512A4687
HMAC-SHA2-512/256A4687
KAS-ECC-SSC Sp800-56Ar3A4687
KAS-FFC-SSC Sp800-56Ar3A4687
KDA HKDF Sp800-56Cr1A4687
RSA KeyGen (FIPS186-4)A4687
RSA SigGen (FIPS186-4)A4687
RSA SigVer (FIPS186-4)A4687
SHA-1A4687
SHA2-224A4687
SHA2-256A4687
SHA2-384A4687
SHA2-512A4687
SHA2-512/256A4687
TLS v1.2 KDF RFC7627A4687
TLS v1.3 KDFA4687

Tested configurations

  • Android 14 running on a Google Pixel 5a with a Qualcomm Snapdragon 765 with PAA
  • Android 14 running on a Google Pixel 5a with a Qualcomm Snapdragon 765 without PAA
  • Android 14 running on a Google Pixel 6 with a Google Tensor with PAA
  • Android 14 running on a Google Pixel 6 with a Google Tensor without PAA
  • Android 14 running on a Google Pixel 7 with a Google Tensor G2 with PAA
  • Android 14 running on a Google Pixel 7 with a Google Tensor G2 without PAA
  • Android 14 running on a Google Pixel 8 with a Google Tensor G3 with PAA
  • Android 14 running on a Google Pixel 8 with a Google Tensor G3 without PAA
  • Debian Linux 6.4.4 running on an n2d with an AMD EPYC 7B12 with PAA
  • Debian Linux 6.4.4 running on an n2d with an AMD EPYC 7B12 without PAA
  • Google Prodimage with Linux 5.10.0 running on a Tau t2a with an Ampere Altra with PAA
  • Google Prodimage with Linux 5.10.0 running on a Tau t2a with an Ampere Altra without PAA
  • Google Prodimage with Linux 5.15.110 running on an IN762 with an IN762 with PAA
  • Google Prodimage with Linux 5.15.110 running on an IN762 with an IN762 without PAA
  • Ubuntu 23.04 running on a Gigabyte GA-Z170X-UD5 with an Intel Core i7-6700K with PAA
  • Ubuntu 23.04 running on a Gigabyte GA-Z170X-UD5 with an Intel Core i7-6700K without PAA

Validation history

DateTypeLab
2025-01-27InitialDEKRA Cybersecurity Certification Laboratory

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2025-01-27

Source documents