808bits

Boot Manager

FIPS 140-3 certificate #5404 · Microsoft Corporation · data as of 2026-09-01
Active. Sunset date 2031-08-30, 1823 days away.
Caveat: When installed, initialized and configured as specified in Section 11 of the Security Policy. When operated in approved mode with module Kernel Mode Cryptographic Primitives Library (cng.sys) validated to FIPS 140-3 under Cert. #5408 operating in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs

Certificate

Certificate number5404
StandardFIPS 140-3
Statusactive
Sunset date2031-08-30
Overall level1
Module typeSoftware-hybrid
EmbodimentMultiChipStand
VendorMicrosoft Corporation · website

Module description

The Windows Boot Manager module is a multi-chip standalone software-hybrid cryptographic module. Boot Manager is the first Windows OS component to load when the computer powers up. When Secure Boot is enabled, the integrity of Boot Manager is validated before loading by the computer’s UEFI firmware. Along with other startup and initialization tasks, Boot Manager loads and cryptographically validates the integrity of Winload.efi (the Windows OS Loader), the next module in the startup sequence. The Boot Manager, which includes parts of BitLocker disk encryption, collects authorization factors, known as “protectors”, by reading data or interacting with the user. BitLocker uses these protectors to encrypt entire disk volumes.

Security level exceptions

  • Non-invasive security: N/A

Approved algorithms

AlgorithmCAVP certificate
AES-CBCA4008
AES-CBCA4009
AES-CCMA3748
AES-CCMA3749
AES-XTS Testing Revision 2.0A4008
AES-XTS Testing Revision 2.0A4009
Counter DRBGA4008
Counter DRBGA4009
HMAC-SHA2-256A4008
HMAC-SHA2-256A4009
PBKDFA4008
PBKDFA4009
RSA SigVer (FIPS186-4)A3767
RSA SigVer (FIPS186-4)A3768
SHA-1A4008
SHA-1A4009
SHA2-256A4008
SHA2-256A4009
SHA2-384A4008
SHA2-384A4009
SHA2-512A4008
SHA2-512A4009

Validation history

DateTypeLab
2026-08-31InitialLeidos Accredited Testing & Evaluation (AT&E) Lab

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-09-01: first observed by this tracker, status active
  • Validation dates on record: 2026-08-31

Source documents