Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Cryptographic Module Validation Program CMVP

Certificate #4257

Details

Module Name
Gloo BoringCrypto
Standard
FIPS 140-2
Status
Active
Sunset Date
7/12/2025
Overall Level
1
Caveat
When installed, initialized and configured as specified in Section 12.1 of the Security Policy and operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy
Security Level Exceptions
  • Physical Security: N/A
  • Mitigation of Other Attacks: N/A
Module Type
Software
Embodiment
Multi-Chip Stand Alone
Description
BoringCrypto
Tested Configuration(s)
  • Debian Linux 4.19.37 (Rodete) running on HPE Z620 with Intel Xeon E5-2680 with PAA
  • Debian Linux 4.19.37 (Rodete) running on HPE Z620 with Intel Xeon E5-2680 without PAA
  • Ubuntu Linux 18.04 running on Google Arcadia-Rome with AMD Rome with PAA
  • Ubuntu Linux 18.04 running on Google Arcadia-Rome with AMD Rome without PAA
  • Ubuntu Linux 18.04 running on Zaius P9 with POWER9 with PAA
  • Ubuntu Linux 18.04 running on Zaius P9 with POWER9 without PAA (single-user mode)
Approved Algorithms
AES Cert. #C1063
CKG vendor affirmed
CVL Certs. #C1063
DRBG Cert. #C1063
ECDSA Cert. #C1063
HMAC Cert. #C1063
KAS-SSC vendor affirmed
KTS AES Cert. #C1063; key establishment methodology provides between 128 and 256 bits of encryption strength
RSA Cert. #C1063
SHS Cert. #C1063
Triple-DES Cert. #C1063
Allowed Algorithms
NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 256 bits of encryption strength)
Software Versions
1701

Vendor

Solo.io
222 Third St
Cambridge, MA 02142
USA

Chris Gaun
chris.gaun@solo.io
Phone: 617-221-3102

Validation History

Date Type Lab
6/24/2022 Initial ACUMEN SECURITY, LLC
9/12/2022 Update ACUMEN SECURITY, LLC