nShield 5s Hardware Security Module

Certificate #5329

Webpage information

Status active
Validation dates 15.06.2026 , 22.06.2026 , 29.06.2026
Sunset date 18-08-2029
Standard FIPS 140-3
Security level 3
Type Hardware
Embodiment MultiChipEmbed
Caveat When installed, initialized and configured as specified in Section 11.3 of the Security Policy
Exceptions
  • Operational environment: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A
Vendor Entrust Corporation
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Symmetric Algorithms
AES-128, AES, AES256, AES-, CAST, HMAC, CMAC
Asymmetric Algorithms
RSA-OAEP, ECDH, ECDSA, ECC, DSA
Hash functions
SHA-1, SHA256, SHA-256, SHA2, SHA3-224, SHA3-256, SHA3-384, SHA3-512, SHA-3
Schemes
MAC, Key Agreement, Key agreement, KA
Protocols
SSH, SSHv2
Randomness
DRBG, RBG
Elliptic Curves
P-224, P-256, P-384, P-521, P-192, curve P-521, B-233, B-283, B-409, B-571, K-233, K-283, K-409, B-163, K-163, K-571
Block cipher modes
ECB, CTR, GCM

Trusted Execution Environments
PSP
Vendor
NXP

Security level
Level 3, Level 1, level 3

File metadata

Title FIPS 140-3 Non-Proprietary Security Policy
Author Zsuzsa Nagy
Creation date D:20260629144939-04'00'
Modification date D:20260629145459-04'00'
Pages 73
Creator Acrobat PDFMaker 26 for Word
Producer Adobe PDF Library 26.1.158

Heuristics

No heuristics are available for this certificate.

References

No references are available for this certificate.

Updates Feed

  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 5329,
  "dgst": "7385cae611099e13",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": []
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "-"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 4
          },
          "ECDH": {
            "ECDH": 3
          },
          "ECDSA": {
            "ECDSA": 59
          }
        },
        "FF": {
          "DSA": {
            "DSA": 20
          }
        },
        "RSA": {
          "RSA-OAEP": 1
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CTR": {
          "CTR": 1
        },
        "ECB": {
          "ECB": 1
        },
        "GCM": {
          "GCM": 3
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "SSH": {
          "SSH": 249,
          "SSHv2": 1
        }
      },
      "crypto_scheme": {
        "KA": {
          "KA": 2,
          "Key Agreement": 3,
          "Key agreement": 4
        },
        "MAC": {
          "MAC": 35
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "B-163": 2,
          "B-233": 7,
          "B-283": 5,
          "B-409": 4,
          "B-571": 5,
          "K-163": 2,
          "K-233": 5,
          "K-283": 3,
          "K-409": 5,
          "K-571": 3,
          "P-192": 6,
          "P-224": 16,
          "P-256": 44,
          "P-384": 10,
          "P-521": 27,
          "curve P-521": 1
        }
      },
      "eval_facility": {},
      "fips_cert_id": {},
      "fips_certlike": {
        "Certlike": {
          "- PKCS 1": 4,
          "AES- CTR 128": 1,
          "AES- GCM 128": 1,
          "AES-128": 1,
          "AES-CMAC 128": 1,
          "AES256": 1,
          "DRBG-1": 16,
          "DRBG-2": 14,
          "DSA 2048": 1,
          "HMAC- SHA256": 1,
          "HMAC-SHA- 1": 2,
          "PKCS 1": 4,
          "SHA-1": 8,
          "SHA-256": 1,
          "SHA-3": 2,
          "SHA2": 1,
          "SHA2- 224": 1,
          "SHA2- 256": 1,
          "SHA2- 384": 1,
          "SHA2- 512": 2,
          "SHA2-224": 15,
          "SHA2-256": 23,
          "SHA2-384": 7,
          "SHA2-512": 10,
          "SHA256": 1,
          "SHA3-224": 5,
          "SHA3-256": 6,
          "SHA3-384": 6,
          "SHA3-512": 6
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 1,
          "Level 3": 2,
          "level 3": 3
        }
      },
      "hash_function": {
        "SHA": {
          "SHA1": {
            "SHA-1": 8
          },
          "SHA2": {
            "SHA-256": 1,
            "SHA2": 1,
            "SHA256": 1
          },
          "SHA3": {
            "SHA-3": 2,
            "SHA3-224": 5,
            "SHA3-256": 6,
            "SHA3-384": 6,
            "SHA3-512": 6
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 14
        },
        "RNG": {
          "RBG": 32
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-3": 6,
          "FIPS 180-4": 9,
          "FIPS 186-4": 19,
          "FIPS 198-1": 10,
          "FIPS 202": 4,
          "FIPS186-4": 34
        },
        "ISO": {
          "ISO/IEC 19790": 2
        },
        "NIST": {
          "SP 800-133": 1,
          "SP 800-38F": 2,
          "SP 800-90B": 3
        },
        "PKCS": {
          "PKCS 1": 4
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 10,
            "AES-": 4,
            "AES-128": 1,
            "AES256": 1
          },
          "CAST": {
            "CAST": 51
          }
        },
        "constructions": {
          "MAC": {
            "CMAC": 2,
            "HMAC": 7
          }
        }
      },
      "tee_name": {
        "AMD": {
          "PSP": 12
        }
      },
      "tls_cipher_suite": {},
      "vendor": {
        "NXP": {
          "NXP": 2
        }
      },
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "Zsuzsa Nagy",
      "/Comments": "",
      "/Company": "Entrust",
      "/ContentTypeId": "0x01010044788752DEE24048B316A411A5F1F9B2",
      "/CreationDate": "D:20260629144939-04\u002700\u0027",
      "/Creator": "Acrobat PDFMaker 26 for Word",
      "/Keywords": "",
      "/MediaServiceImageTags": "",
      "/ModDate": "D:20260629145459-04\u002700\u0027",
      "/Producer": "Adobe PDF Library 26.1.158",
      "/SourceModified": "",
      "/Subject": "",
      "/Title": "FIPS 140-3 Non-Proprietary Security Policy",
      "/_dlc_DocIdItemGuid": "31c10961-758d-48a7-add4-dd4da01ceb50",
      "pdf_file_size_bytes": 928169,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": []
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 73
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.InternalState",
    "module": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "policy": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": "e983cd3b2ea0168e660948f48404c6abc0464fdcef4b32a4a441cafba272f863",
      "txt_hash": "da461586711dbc4b8df8af2ccebb3f12e8b915e19fe43bc8bfb8494e2d9ce12e"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When installed, initialized and configured as specified in Section 11.3 of the Security Policy",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/June 2026_080726_0648.pdf",
    "date_sunset": "2029-08-18",
    "description": null,
    "embodiment": "MultiChipEmbed",
    "exceptions": [
      "Operational environment: N/A",
      "Non-invasive security: N/A",
      "Mitigation of other attacks: N/A"
    ],
    "fw_versions": null,
    "historical_reason": null,
    "hw_versions": null,
    "level": 3,
    "mentioned_certs": {},
    "module_name": "nShield 5s Hardware Security Module",
    "module_type": "Hardware",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-3",
    "status": "active",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2026-06-15",
        "lab": "Lightship Security, Inc.",
        "validation_type": "Initial"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2026-06-22",
        "lab": "Lightship Security, Inc.",
        "validation_type": "Update"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2026-06-29",
        "lab": "Lightship Security, Inc.",
        "validation_type": "Update"
      }
    ],
    "vendor": "Entrust Corporation",
    "vendor_url": "http://www.entrust.com"
  }
}