CyberArk Cryptographic Module for Java
Caveat: When operated in approved mode. No assurance of the minimum strength of generated SSPs (e.g., keys).
Certificate
| Certificate number | 5122 |
|---|---|
| Standard | FIPS 140-3 |
| Status | active |
| Sunset date | 2029-07-28 |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | CyberArk Software Ltd. · website |
| Software versions | 4.0.0 |
Module description
CyberArk Cryptographic Module for Java is a comprehensive cryptographic library designed to provide robust security solutions for Java and Android applications. It offers a wide range of cryptographic functions and features, including encryption, decryption, hashing, digital signatures, and key management. With CyberArk Cryptographic Module for Java, developers can easily integrate strong cryptographic capabilities into their Java applications to ensure data confidentiality, integrity, and authenticity.
Security level exceptions
- Physical security: N/A
- Non-invasive security: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES-CBC | A6047 |
| AES-CBC-CS1 | A6047 |
| AES-CBC-CS2 | A6047 |
| AES-CBC-CS3 | A6047 |
| AES-CCM | A6047 |
| AES-CFB128 | A6047 |
| AES-CFB8 | A6047 |
| AES-CMAC | A6047 |
| AES-CTR | A6047 |
| AES-ECB | A6047 |
| AES-FF1 | A6047 |
| AES-GCM | A6047 |
| AES-GMAC | A6047 |
| AES-KW | A6047 |
| AES-KWP | A6047 |
| AES-OFB | A6047 |
| Counter DRBG | A6047 |
| cSHAKE-128 | A6047 |
| cSHAKE-256 | A6047 |
| DSA KeyGen (FIPS186-4) | A6047 |
| DSA PQGGen (FIPS186-4) | A6047 |
| DSA PQGVer (FIPS186-4) | A6047 |
| DSA SigGen (FIPS186-4) | A6047 |
| DSA SigVer (FIPS186-4) | A6047 |
| ECDSA KeyGen (FIPS186-4) | A6047 |
| ECDSA KeyVer (FIPS186-4) | A6047 |
| ECDSA SigGen (FIPS186-4) | A6047 |
| ECDSA SigVer (FIPS186-4) | A6047 |
| Hash DRBG | A6047 |
| HMAC DRBG | A6047 |
| HMAC-SHA-1 | A6047 |
| HMAC-SHA2-224 | A6047 |
| HMAC-SHA2-256 | A6047 |
| HMAC-SHA2-384 | A6047 |
| HMAC-SHA2-512 | A6047 |
| HMAC-SHA2-512/224 | A6047 |
| HMAC-SHA2-512/256 | A6047 |
| HMAC-SHA3-224 | A6047 |
| HMAC-SHA3-256 | A6047 |
| HMAC-SHA3-384 | A6047 |
| HMAC-SHA3-512 | A6047 |
| KAS-ECC Sp800-56Ar3 | A6047 |
| KAS-FFC Sp800-56Ar3 | A6047 |
| KAS-IFC | A6047 |
| KDA HKDF SP800-56Cr2 | A6047 |
| KDA OneStep SP800-56Cr2 | A6047 |
| KDA TwoStep SP800-56Cr2 | A6047 |
| KDF ANS 9.63 | A6047 |
| KDF IKEv2 | A6047 |
| KDF SNMP | A6047 |
| KDF SP800-108 | A6047 |
| KDF SRTP | A6047 |
| KDF SSH | A6047 |
| KDF TLS | A6047 |
| KMAC-128 | A6047 |
| KMAC-256 | A6047 |
| KTS-IFC | A6047 |
| ParallelHash-128 | A6047 |
| ParallelHash-256 | A6047 |
| PBKDF | A6047 |
| RSA Decryption Primitive | A6047 |
| RSA KeyGen (FIPS186-4) | A6047 |
| RSA SigGen (FIPS186-4) | A6047 |
| RSA Signature Primitive | A6047 |
| RSA SigVer (FIPS186-2) | A6047 |
| RSA SigVer (FIPS186-4) | A6047 |
| Safe Primes Key Generation | A6047 |
| Safe Primes Key Verification | A6047 |
| SHA-1 | A6047 |
| SHA2-224 | A6047 |
| SHA2-256 | A6047 |
| SHA2-384 | A6047 |
| SHA2-512 | A6047 |
| SHA2-512/224 | A6047 |
| SHA2-512/256 | A6047 |
| SHA3-224 | A6047 |
| SHA3-256 | A6047 |
| SHA3-384 | A6047 |
| SHA3-512 | A6047 |
| SHAKE-128 | A6047 |
| SHAKE-256 | A6047 |
| TupleHash-128 | A6047 |
| TupleHash-256 | A6047 |
Tested configurations
- OpenJDK Runtime Environment v11 on VMware Photon OS 5.0 on VMware ESXi 8.0 running on Dell PowerEdge R830 with Intel Xeon E5 without PAA
- OpenJDK Runtime Environment v17 on VMware Photon OS 5.0 on VMware ESXi 8.0 running on Dell PowerEdge R830 with Intel Xeon E5 without PAA
- OpenJDK Runtime Environment v21 on VMware Photon OS 5.0 on VMware ESXi 8.0 running on Dell PowerEdge R830 with Intel Xeon E5 without PAA
- OpenJDK Runtime Environment v8 on VMware Photon OS 5.0 on VMware ESXi 8.0 running on Dell PowerEdge R830 with Intel Xeon E5 without PAA
Validation history
| Date | Type | Lab |
|---|---|---|
| 2026-01-13 | Initial | DEKRA Cybersecurity Certification Laboratory |
| 2026-03-03 | Update | DEKRA Cybersecurity Certification Laboratory |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2026-01-13