808bits

Dynatrace Cryptographic Module

FIPS 140-3 certificate #4988 · Dynatrace LLC · data as of 2026-08-28
Active. Sunset date 2030-03-16, 1295 days away.
Caveat: When operated in approved mode. When installed, initialized and configured as specified in Section 11 of the Security Policy. No assurance of the minimum strength of generated SSPs (e.g., keys)

Certificate

Certificate number4988
StandardFIPS 140-3
Statusactive
Sunset date2030-03-16
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorDynatrace LLC · website
Software versions1.1

Module description

The Dynatrace Cryptographic Module is a cryptographic library embedded in the Dynatrace OneAgent application software. The Dynatrace Cryptographic Module supplies the cryptographic functionality for encryption and decryption, digital signature functions, hashing, message authentication, key establishment, and random number generation in support of general data protection functionality and secure communications protocols, including TLS 1.2/1.3.

Security level exceptions

  • Physical security: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES-CBCA3358
AES-CCMA3358
AES-CFB1A3358
AES-CFB128A3358
AES-CFB8A3358
AES-CMACA3358
AES-CTRA3358
AES-ECBA3358
AES-GCMA3358
AES-GMACA3358
AES-KWA3358
AES-KWPA3358
AES-OFBA3358
Counter DRBGA3358
DSA KeyGen (FIPS186-4)A3358
DSA PQGGen (FIPS186-4)A3358
DSA PQGVer (FIPS186-4)A3358
DSA SigGen (FIPS186-4)A3358
DSA SigVer (FIPS186-4)A3358
ECDSA KeyGen (FIPS186-4)A3358
ECDSA KeyVer (FIPS186-4)A3358
ECDSA SigGen (FIPS186-4)A3358
ECDSA SigVer (FIPS186-4)A3358
HMAC-SHA-1A3358
HMAC-SHA2-224A3358
HMAC-SHA2-256A3358
HMAC-SHA2-384A3358
HMAC-SHA2-512A3358
KAS-ECC-SSC Sp800-56Ar3A3358
KAS-FFC-SSC Sp800-56Ar3A3358
KDF TLSA3358
RSA KeyGen (FIPS186-4)A3358
RSA SigGen (FIPS186-4)A3358
RSA SigGen (FIPS186-4)A3358
RSA SigGen (FIPS186-4)A3358
RSA SigVer (FIPS186-4)A3358
RSA SigVer (FIPS186-4)A3358
RSA SigVer (FIPS186-4)A3358
SHA-1A3358
SHA2-224A3358
SHA2-256A3358
SHA2-384A3358
SHA2-512A3358
TLS v1.3 KDFA3359

Allowed algorithms

AES (Cert. #A3358, Key Unwrapping (allowed per FIPS 140-3 IG D.G); Symmetric key unwrapping (using any Approved unauthenticated mode) For legacy use only.)

Tested configurations

  • Red Hat Enterprise Linux 8.2 running on a Dell PowerEdge R440 with an Intel(R) Xeon(R) Silver 4214R with PAA
  • Red Hat Enterprise Linux 8.2 running on a Dell PowerEdge R440 with an Intel(R) Xeon(R) Silver 4214R without PAA

Validation history

DateTypeLab
2025-03-17InitialLeidos Accredited Testing & Evaluation (AT&E) Lab

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2025-03-17

Source documents