808bits

Commvault Crypto Library

FIPS 140-3 certificate #4989 · Commvault Systems, Inc. · data as of 2026-08-28
Active. Sunset date 2027-03-17, 200 days away.
Caveat: Interim Validation. When operated in approved mode. No assurance of the minimum strength of generated SSPs (e.g., keys)

Certificate

Certificate number4989
StandardFIPS 140-3
Statusactive
Sunset date2027-03-17
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorCommvault Systems, Inc. · website
Software versions3.0

Module description

Commvault Crypto Library (CVCL) is a cryptographic software module used in various products by Commvault Systems, Inc. The module provides a collection of Approved and Non-Approved cryptographic services for key generation, symmetric and asymmetric encryption, hash, HMAC and signature generation/verification.

Security level exceptions

  • Physical security: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES-CBC-CS2A2412
AES-ECBA2412
Counter DRBGA2412
HMAC-SHA-1A2412
HMAC-SHA2-256A2412
HMAC-SHA2-512A2412
RSA KeyGen (FIPS186-4)A2412
RSA SigGen (FIPS186-4)A2412
RSA SigVer (FIPS186-2)A2412
RSA SigVer (FIPS186-4)A2412
SHA-1A2412
SHA2-256A2412
SHA2-512A2412

Tested configurations

  • Microsoft Windows Server 2019 on Fujitsu RX2530 M5 with Intel Xeon R Silver 4208 with AES-NI, Microsoft Windows Server 2019 on Fujitsu RX2530 M5 with Intel Xeon R Silver 4208 without AES-NI, Red Hat Enterprise Linux 8.4 on Fujitsu RX2530 M5 with Intel Xeon R Silver 4208 with AES-NI, Red Hat Enterprise Linux 8.4 on Fujitsu RX2530 M5 with Intel Xeon R Silver 4208 without AES-NI

Validation history

DateTypeLab
2025-03-18InitialAcumen Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2025-03-18

Source documents