Computer Security Resource Center

Computer Security Resource Center

Computer Security
Resource Center

Cryptographic Module Validation Program

Certificate #3318

Details

Module Name
BoringCrypto
Standard
FIPS 140-2
Status
Active
Sunset Date
11/1/2023
Validation Dates
11/2/2018
Overall Level
1
Caveat
When installed, initialized and configured as specified in Section 12.1 of the Security Policy and operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy
Security Level Exceptions
  • Physical Security: N/A
  • Mitigation of Other Attacks: N/A
Module Type
Software
Embodiment
Multi-Chip Stand Alone
Description
A software library that contains cryptographic functionality to serve BoringSSL and other user-space applications.
Tested Configuration(s)
  • and Ubuntu Linux 18.04 running on POWER9 with PAA (clang Compiler Version 6.0.1) (single-user mode)
  • Debian Linux 4.9.0 running on Intel Xeon E5-2680 with PAA (clang Compiler Version 6.0.1)
  • Debian Linux 4.9.0 running on Intel Xeon E5-2680 without PAA (clang Compiler Version 6.0.1)
  • Ubuntu Linux 18.04 running on POWER9 without PAA (clang Compiler Version 6.0.1)
FIPS Algorithms
AES Cert. #5612
CKG vendor affirmed
CVL Certs. #2033, #2034 and #2035
DRBG Cert. #2253
ECDSA Cert. #1520
HMAC Cert. #3743
KTS AES Cert. #5612; key establishment methodology provides between 128 and 256 bits of encryption strength
RSA Cert. #3020
SHS Cert. #4509
Triple-DES Cert. #2825
Allowed Algorithms
EC Diffie-Hellman (CVL Certs. #2033 and #2034; key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength); MD5; NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 256 bits of encryption strength)
Software Versions
66005f41fbc3529ffe8d007708756720529da20d

Vendor

Google, Inc.
1600 Amphitheatre Parkway
Mountain View, CA 94043
USA

Adam Langley
security@chromium.org

Lab

ACUMEN SECURITY, LLC
NVLAP Code: 201029-0