This page was not yet optimized for use on mobile devices.
Cryptographic Primitives Library
Certificate details
| Certificate ID | #4825 |
|---|---|
| Status | active |
| Validation dates | 07.10.2024 |
| Sunset date | 21-09-2026 |
| Standard | FIPS 140-2 |
| Security level | 1 |
| Type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Caveat | When operated in FIPS mode with modules Kernel Mode Cryptographic Primitives Library validated to FIPS 140-2 under Cert. #4766 operating in FIPS mode and Code Integrity validated to FIPS 140-2 under Cert. #4511 operating in FIPS mode or Secure Kernel Code Integrity validated to FIPS 140-2 under Cert. #4512 operating in FIPS mode |
| Exceptions |
|
| Description | The Cryptographic Primitives Library (bcryptprimitives.dll and ncryptsslp.dll) provides cryptographic services to Windows components and applications. It includes cryptographic algorithms in an easy-to-use cryptographic module via the Cryptography Next Generation (CNG) API. It can be dynamically linked into applications for the use of general-purpose FIPS 140-2 validated cryptography. |
| Tested configurations |
|
| Vendor | Microsoft Corporation |
| References | This certificate's webpage directly references 3 certificates, transitively this expands into 7 certificates. |
Security policy
Extracted keywords
Symmetric Algorithms
AES, AES-128, AES-192, AES-256, AES-, RC2, RC4, DES, Triple-DES, HMAC, HMAC-SHA-384, HMAC-SHA-512, HMAC-SHA-256, CMACAsymmetric Algorithms
ECDH, ECDSA, ECC, Diffie-Hellman, DH, DSAHash functions
SHA-1, SHA1, SHA-256, SHA-384, SHA-512, SHA-2, SHA2, MD4, MD5, PBKDF, PBKDF2Schemes
Key AgreementProtocols
SSL, TLS, TLS 1.2, TLSv1.0, IKEv1, IKEv2, IKE, IPsecRandomness
DRBG, RNGElliptic Curves
P-384, P-521, P-256, brainpoolP160r1, brainpoolP192r1, brainpoolP192t1, brainpoolP224r1, brainpoolP224t1, brainpoolP256r1, brainpoolP256t1, brainpoolP320r1, brainpoolP320t1, brainpoolP384r1, brainpoolP384t1, brainpoolP512r1, brainpoolP512t1Block cipher modes
ECB, CBC, CTR, GCM, CCM, XTSTrusted Execution Environments
SSCVendor
Microsoft Corporation, MicrosoftSecurity level
Level 1Standards
FIPS 140, FIPS 140-2, FIPS 180-4, FIPS PUB 198-1, FIPS 197, FIPS 186-4, FIPS 186-2, NIST SP 800-132, NIST SP 800-38F, NIST SP 800-38B, SP 800-38C, NIST SP 800-38D, NIST SP 800-38E, NIST SP 800-56A, NIST SP 800-56B, NIST SP 800-90A, NIST SP 800-108, NIST SP 800-135, SP 800-131A, SP 800-135, NIST SP 800-133, NIST SP 800-90B, SP 800-90A, NIST SP 800-131A, SP 800-38F, SP 800-56B, SP 800-56A, SP 800-108, SP 800-132, SP 800-90B, PKCS#1, RFC 2898Cross-references
OutgoingAutomated analysis
Automated inference - use with caution
All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.No automatically derived data are available in this section.
Cross-references
Loading...
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate was first processed.
{
"_type": "sec_certs.sample.fips.FIPSCertificate",
"cert_id": 4825,
"dgst": "90b303a74db7b556",
"heuristics": {
"_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
"algorithms": {
"_type": "Set",
"elements": [
"Triple-DES#A2066",
"KAS#A2025",
"CVL#A2066",
"ECDSA#A2004",
"KAS-SSC#A2019",
"AES#A2069",
"DSA#A2066",
"SHS#A2025",
"KBKDF#A2031",
"DRBG#A2066",
"HMAC#A2066",
"Triple-DES#A2025",
"AES#A2004",
"KTS#A2023",
"KBKDF#A2069",
"SHS#A2066",
"AES#A2025",
"DSA#A2019",
"Triple-DES#A2004",
"CVL#A2019",
"AES#A2066",
"ECDSA#A2066",
"AES#A2019",
"ECDSA#A2025",
"DRBG#A2025",
"HMAC#A2025",
"KTS#A2001",
"HMAC#A2004",
"HMAC#A2019",
"KAS#A2019",
"CVL#A2004",
"DSA#A2025",
"KAS-SSC#A2066",
"AES#A2001",
"KTS#A2069",
"KAS#A2004",
"KAS-SSC#A2025",
"PBKDF#A2019",
"RSA#A2066",
"RSA#A2019",
"SHS#A2004",
"DRBG#A2004",
"AES#A2031",
"PBKDF#A2025",
"DRBG#A2019",
"SHS#A2019",
"ECDSA#A2019",
"KBKDF#A2023",
"Triple-DES#A2019",
"CVL#A2025",
"DSA#A2004",
"KAS-SSC#A2004",
"RSA#A2025",
"KTS#A2031",
"AES#A2023",
"PBKDF#A2066",
"KBKDF#A2001",
"RSA#A2004",
"KAS#A2066",
"PBKDF#A2004"
]
},
"cpe_matches": null,
"direct_transitive_cves": null,
"extracted_versions": {
"_type": "Set",
"elements": [
"-"
]
},
"indirect_transitive_cves": null,
"module_processed_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": {
"_type": "Set",
"elements": [
"4766",
"4511",
"4512"
]
},
"indirectly_referenced_by": null,
"indirectly_referencing": {
"_type": "Set",
"elements": [
"4457",
"4766",
"3923",
"4348",
"4511",
"4512",
"4339"
]
}
},
"module_prunned_references": {
"_type": "Set",
"elements": [
"4766",
"4511",
"4512"
]
},
"policy_processed_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": {
"_type": "Set",
"elements": [
"4766",
"4511",
"4512"
]
},
"indirectly_referenced_by": null,
"indirectly_referencing": {
"_type": "Set",
"elements": [
"4457",
"4766",
"3923",
"4348",
"4511",
"4512",
"4339"
]
}
},
"policy_prunned_references": {
"_type": "Set",
"elements": [
"4766",
"4511",
"4512"
]
},
"related_cves": null,
"verified_cpe_matches": null
},
"pdf_data": {
"_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
"keywords": {
"asymmetric_crypto": {
"ECC": {
"ECC": {
"ECC": 2
},
"ECDH": {
"ECDH": 6
},
"ECDSA": {
"ECDSA": 20
}
},
"FF": {
"DH": {
"DH": 6,
"Diffie-Hellman": 7
},
"DSA": {
"DSA": 26
}
}
},
"certification_process": {},
"cipher_mode": {
"CBC": {
"CBC": 8
},
"CCM": {
"CCM": 6
},
"CTR": {
"CTR": 5
},
"ECB": {
"ECB": 9
},
"GCM": {
"GCM": 7
},
"XTS": {
"XTS": 2
}
},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {},
"crypto_protocol": {
"IKE": {
"IKE": 1,
"IKEv1": 6,
"IKEv2": 4
},
"IPsec": {
"IPsec": 1
},
"TLS": {
"SSL": {
"SSL": 3
},
"TLS": {
"TLS": 12,
"TLS 1.2": 3,
"TLSv1.0": 2
}
}
},
"crypto_scheme": {
"KA": {
"Key Agreement": 7
}
},
"device_model": {},
"ecc_curve": {
"Brainpool": {
"brainpoolP160r1": 2,
"brainpoolP192r1": 2,
"brainpoolP192t1": 2,
"brainpoolP224r1": 2,
"brainpoolP224t1": 2,
"brainpoolP256r1": 2,
"brainpoolP256t1": 2,
"brainpoolP320r1": 2,
"brainpoolP320t1": 2,
"brainpoolP384r1": 2,
"brainpoolP384t1": 2,
"brainpoolP512r1": 2,
"brainpoolP512t1": 2
},
"NIST": {
"P-256": 20,
"P-384": 22,
"P-521": 20
}
},
"eval_facility": {},
"fips_cert_id": {
"Cert": {
"#4511": 1,
"#4512": 1,
"#4766": 1
}
},
"fips_certlike": {
"Certlike": {
"AES- 192": 1,
"AES- 256": 4,
"AES-128": 14,
"AES-192": 8,
"AES-256": 11,
"HMAC-SHA- 256": 2,
"HMAC-SHA- 384": 2,
"HMAC-SHA-12": 2,
"HMAC-SHA-17": 2,
"HMAC-SHA-256": 2,
"HMAC-SHA-384": 2,
"HMAC-SHA-512": 4,
"HMAC-SHA1": 4,
"HMAC-SHA256": 2,
"HMAC-SHA384": 2,
"HMAC-SHA512": 2,
"PKCS#1": 10,
"PKCS1-v1_5": 1,
"RSA PKCS#1": 10,
"SHA- 256": 2,
"SHA- 384": 1,
"SHA- 512": 1,
"SHA-1": 20,
"SHA-115": 1,
"SHA-14": 1,
"SHA-19": 1,
"SHA-2": 2,
"SHA-256": 33,
"SHA-384": 14,
"SHA-512": 16,
"SHA1": 4,
"SHA2": 1,
"SHA2- 256": 1,
"SHA2- 384": 1,
"SHA2-256": 5,
"SHA2-384": 3,
"SHA2-512": 6
}
},
"fips_security_level": {
"Level": {
"Level 1": 1
}
},
"hash_function": {
"MD": {
"MD4": {
"MD4": 2
},
"MD5": {
"MD5": 2
}
},
"PBKDF": {
"PBKDF": 8,
"PBKDF2": 1
},
"SHA": {
"SHA1": {
"SHA-1": 20,
"SHA1": 4
},
"SHA2": {
"SHA-2": 2,
"SHA-256": 33,
"SHA-384": 14,
"SHA-512": 16,
"SHA2": 1
}
}
},
"ic_data_group": {},
"javacard_api_const": {},
"javacard_packages": {},
"javacard_version": {},
"os_name": {},
"pq_crypto": {},
"randomness": {
"PRNG": {
"DRBG": 24
},
"RNG": {
"RNG": 1
}
},
"side_channel_analysis": {},
"standard_id": {
"FIPS": {
"FIPS 140": 4,
"FIPS 140-2": 12,
"FIPS 180-4": 12,
"FIPS 186-2": 2,
"FIPS 186-4": 21,
"FIPS 197": 2,
"FIPS PUB 198-1": 2
},
"NIST": {
"NIST SP 800-108": 2,
"NIST SP 800-131A": 2,
"NIST SP 800-132": 6,
"NIST SP 800-133": 2,
"NIST SP 800-135": 2,
"NIST SP 800-38B": 2,
"NIST SP 800-38D": 2,
"NIST SP 800-38E": 2,
"NIST SP 800-38F": 5,
"NIST SP 800-56A": 5,
"NIST SP 800-56B": 2,
"NIST SP 800-90A": 3,
"NIST SP 800-90B": 4,
"SP 800-108": 2,
"SP 800-131A": 3,
"SP 800-132": 4,
"SP 800-135": 2,
"SP 800-38C": 1,
"SP 800-38F": 1,
"SP 800-56A": 3,
"SP 800-56B": 1,
"SP 800-90A": 3,
"SP 800-90B": 1
},
"PKCS": {
"PKCS#1": 10
},
"RFC": {
"RFC 2898": 1
}
},
"symmetric_crypto": {
"AES_competition": {
"AES": {
"AES": 26,
"AES-": 5,
"AES-128": 14,
"AES-192": 8,
"AES-256": 11
},
"RC": {
"RC2": 6,
"RC4": 6
}
},
"DES": {
"3DES": {
"Triple-DES": 13
},
"DES": {
"DES": 9
}
},
"constructions": {
"MAC": {
"CMAC": 7,
"HMAC": 26,
"HMAC-SHA-256": 1,
"HMAC-SHA-384": 1,
"HMAC-SHA-512": 2
}
}
},
"tee_name": {
"IBM": {
"SSC": 1
}
},
"tls_cipher_suite": {},
"vendor": {
"Microsoft": {
"Microsoft": 36,
"Microsoft Corporation": 56
}
},
"vulnerability": {}
},
"policy_metadata": {
"/Author": "Robert Durff",
"/CreationDate": "D:20240823113711-07\u002700\u0027",
"/Creator": "Microsoft\u00ae Word for Microsoft 365",
"/ModDate": "D:20240823113711-07\u002700\u0027",
"/Producer": "Microsoft\u00ae Word for Microsoft 365",
"pdf_file_size_bytes": 1016835,
"pdf_hyperlinks": {
"_type": "Set",
"elements": [
"https://docs.microsoft.com/en-us/windows/win32/seccng/cng-portal",
"https://docs.microsoft.com/en-us/windows/win32/api/wincrypt/nf-wincrypt-cryptderivekey",
"https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/4766",
"http://www.gbstandards.org/GB_standards/GB_standard.asp?id=900",
"http://www.openmobilealliance.org/tech/affiliates/wap/wap-261-wtls-20010406-a.pdf",
"https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=14675",
"https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/4511",
"http://www.commoncriteriaportal.org/files/epfiles/Windows%2010%20AU%20and%20Server%202016%20GP%20OS%20Security%20Target%20-%20Public.pdf",
"https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-cryptography#cryptography-allowfipsalgorithmpolicy",
"https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=14522",
"https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/4512",
"https://docs.microsoft.com/en-us/windows/security/threat-protection/fips-140-validation",
"https://www.microsoft.com/en-us/research/wp-content/uploads/2016/02/curvegen.pdf",
"https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=15140",
"http://www.ecc-brainpool.org/download/Domain-parameters.pdf",
"https://global.ihs.com/doc_detail.cfm?\u0026item_s_key=00325725\u0026item_key_date=941231\u0026input_doc_number=ANSI%20X9%2E62\u0026input_doc_title",
"https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=14498",
"https://docs.microsoft.com/en-us/windows/win32/seccng/cng-algorithm-identifiers",
"https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=14504",
"http://csrc.nist.gov/groups/ST/toolkit/documents/dss/NISTReCur.pdf",
"https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=14291",
"http://www.secg.org/sec2-v2.pdf",
"https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=14495",
"https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=14501",
"http://creativecommons.org/licenses/by-nd-nc/1.0/",
"https://www.microsoft.com/en-us/howtotell/default.aspx",
"https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=14507",
"https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=14492",
"https://www.microsoft.com/en-us/windows",
"https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?product=14525",
"https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?validation=34747"
]
},
"pdf_is_encrypted": false,
"pdf_number_of_pages": 53
}
},
"state": {
"_type": "sec_certs.sample.fips.InternalState",
"module": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": null,
"source_hash": null,
"txt_hash": null
},
"policy": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": null,
"source_hash": "46ae9c9274fbf87ecf79875b6aa20b8032a7266ee4f0e0b11ea69db26af35577",
"txt_hash": "64d7f0ec1f6bc7654f304fbd8ddecc2ad45c337c738ca11206ed010212d32b6e"
}
},
"web_data": {
"_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
"caveat": "When operated in FIPS mode with modules Kernel Mode Cryptographic Primitives Library validated to FIPS 140-2 under Cert. #4766 operating in FIPS mode and Code Integrity validated to FIPS 140-2 under Cert. #4511 operating in FIPS mode or Secure Kernel Code Integrity validated to FIPS 140-2 under Cert. #4512 operating in FIPS mode",
"certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/October 2024_041124_0733 (1).pdf",
"date_sunset": "2026-09-21",
"description": "The Cryptographic Primitives Library (bcryptprimitives.dll and ncryptsslp.dll) provides cryptographic services to Windows components and applications. It includes cryptographic algorithms in an easy-to-use cryptographic module via the Cryptography Next Generation (CNG) API. It can be dynamically linked into applications for the use of general-purpose FIPS 140-2 validated cryptography.",
"embodiment": "Multi-Chip Stand Alone",
"exceptions": [
"Physical Security: N/A",
"Design Assurance: Level 2"
],
"fw_versions": null,
"historical_reason": null,
"hw_versions": null,
"level": 1,
"mentioned_certs": {
"4511": 1,
"4512": 1,
"4766": 1
},
"module_name": "Cryptographic Primitives Library",
"module_type": "Software",
"revoked_link": null,
"revoked_reason": null,
"standard": "FIPS 140-2",
"status": "active",
"sw_versions": "10.0.19042, 10.0.19043, 10.0.20348 and 10.0.22000",
"tested_conf": [
"Azure Host OS 2021 (64-bit) running on a Dell PowerEdge R840 with an Intel Xeon Platinum 8260 with PAA",
"Azure Stack HCI version 21H2 (64-bit) running on an HPE ProLiant DL380 with an Intel Xeon Platinum 8276L with PAA",
"Windows 10 version 20H2 Enterprise (64-bit) running on a Dell Latitude 7420 with an Intel i7-1185G7 with PAA",
"Windows 10 version 20H2 Enterprise (64-bit) running on a Dell Latitude 9520 with an Intel i7-1185G7 with PAA",
"Windows 10 version 20H2 Pro (64-bit) running on a Dell Latitude 3520 with an Intel i3-1115G4 with PAA",
"Windows 10 version 20H2 Pro (64-bit) running on a Microsoft Surface Laptop 4 with an Intel i5-1145G7 with PAA",
"Windows 10 version 20H2 Pro (64-bit) running on an HP EliteBook x360 830 G8 with an Intel i7-1165G7 with PAA",
"Windows 10 version 21H1 Pro (64-bit) running on a HP EliteBook x360 830 G8 with an Intel i7-1165G7 with PAA",
"Windows 10 version 21H1 Pro (64-bit) running on a Microsoft Surface Laptop 4 with an Intel i5-1145G7 with PAA",
"Windows 11 (64-bit) running on a Microsoft Surface Laptop 4 with an Intel i5-1145G7 with PAA",
"Windows Server 2022 Core (64-bit) on Microsoft Windows Server 2019 Hyper-V running on a Dell PowerEdge R630 with an Intel Xeon E5-2660 with PAA",
"Windows Server 2022 Core Datacenter (64-bit) on Microsoft Windows Server 2019 Hyper-V running on a Dell PowerEdge R630 with an Intel Xeon E5-2660 with PAA",
"Windows Server 2022 Core Datacenter (64-bit) running on an HPE ProLiant E910 with an Intel Xeon Gold 6248 without PAA",
"Windows Server 20H2 Core (64-bit) on Microsoft Windows Server 2019 Hyper-V running on a Dell PowerEdge R630 with an Intel Xeon E5-2660 with PAA",
"Windows Server 20H2 Core Datacenter (64-bit) on Microsoft Windows Server 2019 Hyper-V running on a Dell PowerEdge R630 with an Intel Xeon E5-2660 with PAA",
"Windows Server Azure Edition (64-bit) running on a Dell PowerEdge R840 with an Intel Xeon Platinum 8260 with PAA (single-user mode)"
],
"validation_history": [
{
"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
"date": "2024-10-07",
"lab": "Leidos Accredited Testing \u0026 Evaluation (AT\u0026E) Lab",
"validation_type": "Initial"
}
],
"vendor": "Microsoft Corporation",
"vendor_url": "http://www.microsoft.com"
}
}