Microsoft Kernel Mode Security Support Provider Interface (ksecdd.sys)
Caveat: When operated in FIPS mode with Code Integrity (ci.dll) validated to FIPS 140-2 under Cert. #890 operating in FIPS mode
Certificate
| Certificate number | 891 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-chip standalone |
| Vendor | Microsoft Corporation · website |
| Software versions | 6.0.6000.16386, 6.0.6000.16870 and 6.0.6000.21067 |
Module description
KSECDD.SYS runs as a kernel mode export driver, and provides cryptographic services, through their documented interfaces, to Windows Vista kernel components. It supports several cryptographic algorithms accessible via a FIPS function table request irp (I/O request packet).
Approved algorithms
Other algorithms
DES; Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 150 bits of encryption strength; non-compliant less than 112 bits of encryption strength); EC Diffie-Hellman (key agreement; key establishment methodology provides 128 to 256 bits of encryption strength); MD2; MD4; MD5; RC2; RC4; HMAC MD5
Tested configurations
- Microsoft Windows Vista Ultimate Edition (x64 version) (single-user mode)
- Microsoft Windows Vista Ultimate Edition (x86 Version)
Validation history
| Date | Type | Lab |
|---|---|---|
| 2008-01-10 | Initial | SAIC-VA |
| 2009-10-16 | Update |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2008-01-10, 2009-10-16