BoringCrypto
Caveat: When operated in approved mode. No assurance of the minimum strength of generated SSPs (e.g., keys). No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.
Certificate
| Certificate number | 5296 |
|---|---|
| Standard | FIPS 140-3 |
| Status | active |
| Sunset date | 2030-01-26 |
| Overall level | 1 |
| Module type | Software |
| Embodiment | MultiChipStand |
| Vendor | Google, LLC · website |
Module description
A software library that contains cryptographic functionality to serve BoringSSL and other user-space applications.
Security level exceptions
- Physical security: N/A
- Non-invasive security: N/A
- Mitigation of other attacks: N/A
Validation history
| Date | Type | Lab |
|---|---|---|
| 2026-06-02 | Initial | DEKRA Cybersecurity Certification Laboratory |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2026-06-02