Dynatrace Cryptographic Module
Caveat: When operated in approved mode. When installed, initialized and configured as specified in Section 11 of the Security Policy. No assurance of the minimum strength of generated SSPs (e.g., keys)
Certificate
| Certificate number | 4988 |
|---|---|
| Standard | FIPS 140-3 |
| Status | active |
| Sunset date | 2030-03-16 |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Dynatrace LLC · website |
| Software versions | 1.1 |
Module description
The Dynatrace Cryptographic Module is a cryptographic library embedded in the Dynatrace OneAgent application software. The Dynatrace Cryptographic Module supplies the cryptographic functionality for encryption and decryption, digital signature functions, hashing, message authentication, key establishment, and random number generation in support of general data protection functionality and secure communications protocols, including TLS 1.2/1.3.
Security level exceptions
- Physical security: N/A
- Non-invasive security: N/A
- Mitigation of other attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES-CBC | A3358 |
| AES-CCM | A3358 |
| AES-CFB1 | A3358 |
| AES-CFB128 | A3358 |
| AES-CFB8 | A3358 |
| AES-CMAC | A3358 |
| AES-CTR | A3358 |
| AES-ECB | A3358 |
| AES-GCM | A3358 |
| AES-GMAC | A3358 |
| AES-KW | A3358 |
| AES-KWP | A3358 |
| AES-OFB | A3358 |
| Counter DRBG | A3358 |
| DSA KeyGen (FIPS186-4) | A3358 |
| DSA PQGGen (FIPS186-4) | A3358 |
| DSA PQGVer (FIPS186-4) | A3358 |
| DSA SigGen (FIPS186-4) | A3358 |
| DSA SigVer (FIPS186-4) | A3358 |
| ECDSA KeyGen (FIPS186-4) | A3358 |
| ECDSA KeyVer (FIPS186-4) | A3358 |
| ECDSA SigGen (FIPS186-4) | A3358 |
| ECDSA SigVer (FIPS186-4) | A3358 |
| HMAC-SHA-1 | A3358 |
| HMAC-SHA2-224 | A3358 |
| HMAC-SHA2-256 | A3358 |
| HMAC-SHA2-384 | A3358 |
| HMAC-SHA2-512 | A3358 |
| KAS-ECC-SSC Sp800-56Ar3 | A3358 |
| KAS-FFC-SSC Sp800-56Ar3 | A3358 |
| KDF TLS | A3358 |
| RSA KeyGen (FIPS186-4) | A3358 |
| RSA SigGen (FIPS186-4) | A3358 |
| RSA SigGen (FIPS186-4) | A3358 |
| RSA SigGen (FIPS186-4) | A3358 |
| RSA SigVer (FIPS186-4) | A3358 |
| RSA SigVer (FIPS186-4) | A3358 |
| RSA SigVer (FIPS186-4) | A3358 |
| SHA-1 | A3358 |
| SHA2-224 | A3358 |
| SHA2-256 | A3358 |
| SHA2-384 | A3358 |
| SHA2-512 | A3358 |
| TLS v1.3 KDF | A3359 |
Allowed algorithms
AES (Cert. #A3358, Key Unwrapping (allowed per FIPS 140-3 IG D.G); Symmetric key unwrapping (using any Approved unauthenticated mode) For legacy use only.)
Tested configurations
- Red Hat Enterprise Linux 8.2 running on a Dell PowerEdge R440 with an Intel(R) Xeon(R) Silver 4214R with PAA
- Red Hat Enterprise Linux 8.2 running on a Dell PowerEdge R440 with an Intel(R) Xeon(R) Silver 4214R without PAA
Validation history
| Date | Type | Lab |
|---|---|---|
| 2025-03-17 | Initial | Leidos Accredited Testing & Evaluation (AT&E) Lab |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2025-03-17