Kernel Mode Cryptographic Primitives Library
Caveat: When operated in approved mode. When installed, initialized and configured as specified in Section 11.1 of the Security Policy. When operated in approved mode with module Windows OS Loader validated to FIPS 140-3 under Cert. #5405 operating in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs. No assurance of FIPS 140-3 requirements met for the components of the RBG construct that are external to the module boundary (e.g., DRBG, ESV) except for SP 800-90C compliance and security strength of the provided random bits
This caveat mentions binding. A bound module inherits the earliest sunset of the modules it binds to, so the sunset date above can be optimistic.
Certificate
| Certificate number | 5408 |
|---|---|
| Standard | FIPS 140-3 |
| Status | active |
| Sunset date | 2031-08-30 |
| Overall level | 1 |
| Module type | Software-hybrid |
| Embodiment | MultiChipStand |
| Vendor | Microsoft Corporation · website |
Module description
The Kernel Mode Cryptographic Primitives Library is a kernel-mode cryptographic module that provides cryptographic services through the Microsoft CNG (Cryptography, Next Generation) API to Windows kernel components. The module also provides cryptographic provider registration and configuration services to both user and kernel mode components.
Security level exceptions
- Non-invasive security: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES-CBC | A4008 |
| AES-CBC | A4009 |
| AES-CCM | A4008 |
| AES-CCM | A4009 |
| AES-CFB128 | A4008 |
| AES-CFB128 | A4009 |
| AES-CFB8 | A4008 |
| AES-CFB8 | A4009 |
| AES-CMAC | A4008 |
| AES-CMAC | A4009 |
| AES-CTR | A4008 |
| AES-CTR | A4009 |
| AES-ECB | A4008 |
| AES-ECB | A4009 |
| AES-GCM | A4008 |
| AES-GCM | A4009 |
| AES-GMAC | A4008 |
| AES-GMAC | A4009 |
| AES-KW | A3763 |
| AES-KW | A3764 |
| AES-XTS Testing Revision 2.0 | A4008 |
| AES-XTS Testing Revision 2.0 | A4009 |
| Counter DRBG | A4008 |
| Counter DRBG | A4009 |
| ECDSA KeyGen (FIPS186-4) | A4008 |
| ECDSA KeyGen (FIPS186-4) | A4009 |
| ECDSA KeyVer (FIPS186-4) | A4008 |
| ECDSA KeyVer (FIPS186-4) | A4009 |
| ECDSA SigGen (FIPS186-4) | A4008 |
| ECDSA SigGen (FIPS186-4) | A4009 |
| ECDSA SigVer (FIPS186-4) | A4008 |
| ECDSA SigVer (FIPS186-4) | A4009 |
| HMAC-SHA-1 | A4008 |
| HMAC-SHA-1 | A4009 |
| HMAC-SHA2-256 | A4008 |
| HMAC-SHA2-256 | A4009 |
| HMAC-SHA2-384 | A4008 |
| HMAC-SHA2-384 | A4009 |
| HMAC-SHA2-512 | A4008 |
| HMAC-SHA2-512 | A4009 |
| KAS-ECC Sp800-56Ar3 | A4008 |
| KAS-ECC Sp800-56Ar3 | A4009 |
| KAS-ECC-SSC Sp800-56Ar3 | A4008 |
| KAS-ECC-SSC Sp800-56Ar3 | A4009 |
| KAS-FFC Sp800-56Ar3 | A4008 |
| KAS-FFC Sp800-56Ar3 | A4009 |
| KAS-FFC-SSC Sp800-56Ar3 | A4008 |
| KAS-FFC-SSC Sp800-56Ar3 | A4009 |
| KDA HKDF SP800-56Cr2 | A4008 |
| KDA HKDF SP800-56Cr2 | A4009 |
| KDF IKEv1 | A4008 |
| KDF IKEv1 | A4009 |
| KDF IKEv2 | A4008 |
| KDF IKEv2 | A4009 |
| KDF SP800-108 | A3763 |
| KDF SP800-108 | A3764 |
| KDF TLS | A4008 |
| KDF TLS | A4009 |
| PBKDF | A4008 |
| PBKDF | A4009 |
| RSA Decryption Primitive | A4008 |
| RSA Decryption Primitive | A4009 |
| RSA KeyGen (FIPS186-4) | A4008 |
| RSA KeyGen (FIPS186-4) | A4009 |
| RSA SigGen (FIPS186-4) | A4008 |
| RSA SigGen (FIPS186-4) | A4009 |
| RSA Signature Primitive | A4008 |
| RSA Signature Primitive | A4009 |
| RSA SigVer (FIPS186-4) | A3767 |
| RSA SigVer (FIPS186-4) | A3768 |
| RSA SigVer (FIPS186-4) | A4008 |
| RSA SigVer (FIPS186-4) | A4009 |
| Safe Primes Key Generation | A4008 |
| Safe Primes Key Generation | A4009 |
| SHA-1 | A4008 |
| SHA-1 | A4009 |
| SHA2-256 | A4008 |
| SHA2-256 | A4009 |
| SHA2-384 | A4008 |
| SHA2-384 | A4009 |
| SHA2-512 | A4008 |
| SHA2-512 | A4009 |
| TLS v1.2 KDF RFC7627 | A4008 |
| TLS v1.2 KDF RFC7627 | A4009 |
Validation history
| Date | Type | Lab |
|---|---|---|
| 2026-08-31 | Initial | Leidos Accredited Testing & Evaluation (AT&E) Lab |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-09-01: first observed by this tracker, status active
- Validation dates on record: 2026-08-31