808bits

Thales Luna G7 Cryptographic Module

FIPS 140-3 certificate #4962 · Thales · data as of 2026-08-28
Active. Sunset date 2027-02-06, 161 days away.
Caveat: Interim validation. When operated in approved mode. When installed, initialized and configured as specified in Section 11.2 of the Security Policy

Certificate

Certificate number4962
StandardFIPS 140-3
Statusactive
Sunset date2027-02-06
Overall level3
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorThales · website
Hardware versions808-000080-001, 808-000080-002, 808-000064-005, 808-000064-006
Firmware versions7.7.3 with bootloader versions 1.3.0, 1.5.0 and 1.6.0
EntropyENT (P)

Module description

The Thales Luna G7 Cryptographic Module is a standalone hardware security module in the form of a USB device. The cryptographic module is contained in its own secure enclosure, which provides physical resistance.

Security level exceptions

  • Operational environment: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES-CBCC2020
AES-CFB128C2020
AES-CFB8C2020
AES-CMACC2020
AES-CTRC2020
AES-ECBC2020
AES-GCMC2020
AES-KWC2020
AES-KWPC2020
AES-OFBC2020
DSA KeyGen (FIPS186-4)C2020
DSA PQGGen (FIPS186-4)C2020
DSA SigGen (FIPS186-4)C2020
DSA SigVer (FIPS186-4)C2020
ECDSA KeyGen (FIPS186-4)C2020
ECDSA SigGen (FIPS186-4)A2125
ECDSA SigGen (FIPS186-4)C2020
ECDSA SigVer (FIPS186-4)A2125
ECDSA SigVer (FIPS186-4)C2020
Hash DRBGA2125
HMAC-SHA-1C2020
HMAC-SHA2-224C2020
HMAC-SHA2-256C2020
HMAC-SHA2-384C2020
HMAC-SHA2-512C2020
HMAC-SHA3-224C2020
HMAC-SHA3-256C2020
HMAC-SHA3-384C2020
HMAC-SHA3-512C2020
KAS-ECC Sp800-56Ar3A2125
KAS-ECC-SSC Sp800-56Ar3A2125
KAS-FFC-SSC Sp800-56Ar3A2125
KAS-IFCA2125
KDA OneStep Sp800-56Cr1A2125
KDA OneStep SP800-56Cr2A2125
KDF ANS 9.42A2125
KDF ANS 9.63A2125
KDF SP800-108C2020
KTS-IFCA2125
PBKDFA2125
RSA KeyGen (FIPS186-4)A674
RSA KeyGen (FIPS186-4)C2020
RSA SigGen (FIPS186-4)A674
RSA SigGen (FIPS186-4)C2020
RSA SigVer (FIPS186-4)A674
RSA SigVer (FIPS186-4)C2020
RSA SigVer (FIPS186-5)A6549
SHA-1C2020
SHA2-224C2020
SHA2-256C2020
SHA2-384C2020
SHA2-384C2022
SHA2-512C2020
SHA3-224C2020
SHA3-256C2020
SHA3-384C2020
SHA3-512C2020
SHAKE-128C2020
SHAKE-256C2020
TDES-CBCC2020
TDES-CFB64C2020
TDES-CFB8C2020
TDES-CMACC2020
TDES-CTRC2020
TDES-ECBC2020
TDES-OFBC2020

Allowed algorithms

KAS-ECC-SSC Cert #A2125 (ephemeralUnified, fullUnified, onePassDH When using Non-NIST curves and allowances from FIPS 140-3 IG C.A, Use of Non-approved elliptic curves.; Derive key from existing partition secret or private key object);KTS (AES Cert. #C2020) (Key unwrapping: key establishment methodology provides between 128 and 256 bits of encryption strength. Uses allowances in FIPS 140-3 IG D.G, Key transport methods, for key unwrapping using un-authenticated modes of encryption listed on Cert #C2020 without use of an additional approved hash function.; Clone SMK between partitions, Import secret or private key using key wrapping. Legacy Unwrapping);KTS (Triple-DES Cert #C2020) (Key unwrapping: key establishment methodology provides 112 bits of encryption strength. Uses allowances in FIPS 140-3 IG D.G, Key transport methods, for key unwrapping using un-authenticated modes of encryption listed on Cert #C2020 without use of an additional approved hash function.; Import secret or private key using key wrapping. Legacy Unwrapping)

Tested configurations

  • N/A

Validation history

DateTypeLab
2025-02-07InitialLeidos Accredited Testing & Evaluation (AT&E) Lab

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2025-02-07

Source documents