CGX Cryptographic Module
CGX Cryptographic Module, from SafeNet, Inc., holds FIPS 140-2 certificate #644 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.
Caveat: When operated in FIPS mode
Certificate
| Certificate number | 644 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-chip standalone |
| Vendor | SafeNet, Inc. · website |
| Software versions | 3.21.1 |
Module description
Quoted from the NIST CMVP entry for this certificate.
Based on SafeNet's 20 years of security expertise and the most widely deployed VPN software in the industry, the CGX Cryptographic Library provides a high-level software interface to SafeNet SafeXcel™ VPN acceleration chips, cards, and EmbeddedIP™ intellectual property. The CGX library can be used as an API to hardware accelerators or for compiling software implementations of the latest industry standard algorithms.
Security level exceptions
- EMI/EMC: Level 3
- Design Assurance: Level 3
Approved algorithms (5)
Other algorithms
DES; MD5; MD2; RSA (non-compliant); RC5; RIPEMD-128; RIPEMD-160; Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 150 bits of encryption strength; non-compliant less than 80-bits of encryption strength)
Tested configurations
- Linux 2.4.18-3 and Solaris 8.2/02
Validation history
| Date | Type | Lab |
|---|---|---|
| 2006-04-03 | Initial | COACT INC CAFE LAB |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2006-04-03