808bits

Cryptographic Module for SecureOS®

FIPS 140-2 certificate #638 · Secure Computing Corporation (Wholly owned subsidiary of McAfee, Inc.) · data as of 2026-09-08

Cryptographic Module for SecureOS®, from Secure Computing Corporation (Wholly owned subsidiary of McAfee, Inc.), holds FIPS 140-2 certificate #638 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. RNG SP800-131A Revision 1 Transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode

Certificate

Certificate number638
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-chip standalone
VendorSecure Computing Corporation (Wholly owned subsidiary of McAfee, Inc.) · website
Software versions9.7

Module description

Quoted from the NIST CMVP entry for this certificate.

The Cryptographic Module for SecureOS® is software providing cryptographic services for applications on versions of Sidewinder G2® Security Appliance™ and Sidewinder G2 Enterprise Manager™. Sidewinder G2 is a line of comprehensive unified threat management (UTM) security appliances consolidating a variety of Internet security functions including Application Defenses™ firewall, anti-virus, anti-spam, traffic anomaly detection, IDS/IPS, and more. It is Common Criteria EAL4+ certified as compliant with the US DoD Application-level Firewall Protection Profile for Medium Robustness.

Approved algorithms (7)

AlgorithmCAVP certificates
AES295
DSA141
HMAC106
RNG120
RSA85
SHS368
Triple-DES368

Other algorithms

Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength; non-compliant less than 112 bits of encryption strength); MD5; DES; RSA (key wrapping; key establishment methodology provides between 112 and 150 bits of encryption strength; non-compliant less than 112 bits of encryption strength)

Tested configurations

  • SecureOS® V6.1 by Secure Computing Corporation

Validation history

DateTypeLab
2006-03-22InitialDOMUS

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2006-03-22

Source documents