{"_type": "sec_certs.sample.fips.FIPSCertificate", "dgst": "c54bea44135df61e", "cert_id": 5450, "web_data": {"_type": "sec_certs.sample.fips.FIPSCertificate.WebData", "module_name": "Luna T7", "validation_history": [{"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry", "date": "2026-07-29", "validation_type": "Initial", "lab": "Lightship Security, Inc."}], "vendor_url": "http://www.thalestct.com", "vendor": "Thales Trusted Cyber Technologies", "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/July 2026_040826_0807.pdf", "module_type": "Hardware", "standard": "FIPS 140-3", "status": "active", "level": 3, "caveat": "When installed, initialized and configured as specified in Section 11.1.2 of the Security Policy", "exceptions": ["Operational environment: N/A", "Non-invasive security: N/A"], "embodiment": "MultiChipEmbed", "description": "The Luna T7 Cryptographic Module from Thales Trusted Cyber Technologies (TCT) is a tamper-resistant Hardware Security Module (HSM) implemented in a multi-chip embedded hardware module for FIPS 140-3 validated key security, typically used in enterprise-class tamper-resistant server appliances. Thales TCT's Luna HSMs are developed, manufactured, sold, and supported in the United States.", "tested_conf": null, "hw_versions": null, "fw_versions": null, "sw_versions": null, "mentioned_certs": {}, "historical_reason": null, "date_sunset": "2031-07-28", "revoked_reason": null, "revoked_link": null}, "pdf_data": {"_type": "sec_certs.sample.fips.FIPSCertificate.PdfData", "keywords": {"fips_cert_id": {"Cert": {"#11": 1, "#1": 1}}, "fips_security_level": {"Level": {"Level 1": 1, "Level 3": 1, "level 3": 1}}, "fips_certlike": {"Certlike": {"HMAC-SHA-1": 14, "HMAC-SHA-2": 8, "HMAC-SHA-3": 8, "SHA-1": 16, "SHA2-224": 19, "SHA2-256": 32, "SHA2-384": 17, "SHA2-512": 18, "SHA3-224": 13, "SHA3-256": 12, "SHA3-384": 10, "SHA3-512": 10, "SHA3- 512": 2, "SHA 1": 2, "SHA-2": 4, "SHA2-348": 2, "SHA-3": 4, "SHA3-348": 2, "PKCS #11": 2, "PKCS 1": 4, "PKCS #1": 2, "DRBG, 640": 1, "DRBG 2048": 1}}, "vendor": {"NXP": {"NXP": 7}, "STMicroelectronics": {"STM": 10}, "Thales": {"Thales": 19}}, "eval_facility": {}, "symmetric_crypto": {"AES_competition": {"CAST": {"CAST": 157}}, "constructions": {"MAC": {"HMAC": 2, "CMAC": 4}}}, "asymmetric_crypto": {"RSA": {"RSA-OAEP": 2}, "ECC": {"ECDSA": {"ECDSA": 92}, "ECC": {"ECC": 1}}, "FF": {"DH": {"DH": 1}, "DSA": {"DSA": 80}}}, "pq_crypto": {"FIPS": {"ML-DSA": 44, "ML-KEM": 27}, "LMS": {"LMS": 86}, "PQC": {"PQC": 1}}, "hash_function": {"SHA": {"SHA1": {"SHA-1": 16}, "SHA2": {"SHA-2": 4}, "SHA3": {"SHA3-224": 13, "SHA3-256": 12, "SHA3-384": 10, "SHA3-512": 10, "SHA-3": 4, "SHA3-348": 2}}, "PBKDF": {"PBKDF": 15}}, "crypto_scheme": {"MAC": {"MAC": 13}, "KEM": {"KEM": 62}, "KA": {"Key Agreement": 4}}, "crypto_protocol": {"SSH": {"SSH": 6}}, "randomness": {"PRNG": {"DRBG": 48}, "RNG": {"RNG": 1, "RBG": 4}}, "cipher_mode": {"XTS": {"XTS": 2}}, "ecc_curve": {"NIST": {"P-224": 20, "P-256": 28, "P-384": 32, "P-521": 20, "P-192": 4, "B-233": 2, "B-283": 2, "B-409": 2, "B-571": 2, "K-233": 2, "K-283": 2, "K-409": 2, "K-571": 2}}, "crypto_engine": {}, "tls_cipher_suite": {}, "crypto_library": {}, "vulnerability": {}, "side_channel_analysis": {"SCA": {"Timing attacks": 1}}, "device_model": {}, "tee_name": {"AMD": {"PSP": 17}, "IBM": {"SSC": 2}}, "os_name": {}, "cplc_data": {}, "ic_data_group": {}, "standard_id": {"FIPS": {"FIPS 140-3": 6, "FIPS186-4": 9, "FIPS 186-4": 6, "FIPS186-5": 18, "FIPS 186-5": 12, "FIPS 198-1": 18, "FIPS 204": 6, "FIPS 203": 4, "FIPS 180-4": 10, "FIPS 202": 10, "FIPS 198": 1}, "NIST": {"SP 800-38A": 13, "SP 800-38B": 2, "SP 800-56A": 4, "SP 800-56C": 2, "SP 800-108": 2, "SP 800-56B": 2, "SP 800-208": 6, "SP 800-132": 2, "SP 800-67": 2, "SP 800-38D": 2, "SP 800-38F": 3, "SP 800-38E": 1, "SP 800-90A": 1}, "PKCS": {"PKCS #11": 1, "PKCS 1": 2, "PKCS #1": 1}, "ISO": {"ISO/IEC 19790:2012": 1}}, "javacard_version": {}, "javacard_api_const": {}, "javacard_packages": {}, "certification_process": {}}, "policy_metadata": {"pdf_file_size_bytes": 1212574, "pdf_is_encrypted": false, "pdf_number_of_pages": 89, "/CreationDate": "D:20260727124753-04'00'", "/Creator": "Microsoft\u00ae Word for Microsoft 365", "/MSIP_Label_4dd2c6e0-f1e3-4cf2-bd0b-256ab4cff3af_ActionId": "b4811f90-60cd-4d2c-8842-4fd66d16aa5a", "/MSIP_Label_4dd2c6e0-f1e3-4cf2-bd0b-256ab4cff3af_ContentBits": "1", "/MSIP_Label_4dd2c6e0-f1e3-4cf2-bd0b-256ab4cff3af_Enabled": "true", "/MSIP_Label_4dd2c6e0-f1e3-4cf2-bd0b-256ab4cff3af_Method": "Privileged", "/MSIP_Label_4dd2c6e0-f1e3-4cf2-bd0b-256ab4cff3af_Name": "UNCLASSIFIED", "/MSIP_Label_4dd2c6e0-f1e3-4cf2-bd0b-256ab4cff3af_SetDate": "2026-07-27T16:39:08Z", "/MSIP_Label_4dd2c6e0-f1e3-4cf2-bd0b-256ab4cff3af_SiteId": "da9cbe40-ec1e-4997-afb3-17d87574571a", "/MSIP_Label_4dd2c6e0-f1e3-4cf2-bd0b-256ab4cff3af_Tag": "10, 0, 1, 1", "/ModDate": "D:20260727124753-04'00'", "/Producer": "Microsoft\u00ae Word for Microsoft 365", "pdf_hyperlinks": {"_type": "Set", "elements": ["https://www.thalestct.com/resources/ciphertrust-manager-k570-product-brief/", "https://support.thalestct.com/", "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?validation=40490", "https://www.thalestct.com/luna-network-hsm", "https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program/details?validation=40489", "https://www.thalestct.com/luna-PCIe-hsm"]}}}, "heuristics": {"_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics", "algorithms": {"_type": "Set", "elements": ["KTS-IFCA7880", "AES-CFB128A7880", "TDES-CBCA7880", "HMAC-SHA3-512A7880", "ML-DSA KeyGenA7880", "SHA3-384A7880", "SHA2-256A7880", "ML-KEM EncapDecapA7880", "AES-CBCA7880", "AES-XTS Testing Revision 2.0A7880", "LMS SigGenA7880", "ML-KEM KeyGenA7880", "HMAC-SHA2-384A7880", "AES-CTRA7880", "SHAKE-128A7879", "SHA3-224A7880", "ECDSA SigVer (FIPS186-4)A7880", "HMAC-SHA2-224A7880", "ML-DSA SigGenA7880", "RSA SigGen (FIPS186-5)A7880", "DSA SigVer (FIPS186-4)A7880", "LMS KeyGenA7880", "AES-GMACA7880", "AES-OFBA7880", "AES-KWPA7880", "ECDSA SigGen (FIPS186-5)A7880", "HMAC-SHA3-384A7880", "KAS-IFC-SSCA7880", "LMS SigVerA7880", "RSA KeyGen (FIPS186-5)A7880", "AES-ECBA7880", "SHA2-384A7880", "HMAC-SHA2-256A7880", "RSA SigVer (FIPS186-5)A7880", "HMAC-SHA3-256A7880", "SHA3-512A7880", "ML-DSA SigVerA7880", "ECDSA SigVer (FIPS186-5)A7880", "KDA TwoStep SP800-56Cr2A7880", "AES-KWA7880", "HMAC-SHA2-512A7880", "Hash DRBGA7880", "SHA3-256A7880", "KDF SP800-108A7880", "SHA2-224A7880", "PBKDFA7880", "HMAC-SHA3-224A7880", "SHA2-512A7880", "ECDSA KeyGen (FIPS186-5)A7880", "SHAKE-256A7879", "KAS-ECC-SSC Sp800-56Ar3A7880", "AES-GCMA7880", "HMAC-SHA-1A7880", "RSA SigVer (FIPS186-4)A7880", "AES-CMACA7880", "AES-CFB8A7880", "SHA-1A7880"]}, "extracted_versions": {"_type": "Set", "elements": ["-"]}, "cpe_matches": null, "verified_cpe_matches": null, "related_cves": null, "policy_prunned_references": {"_type": "Set", "elements": []}, "module_prunned_references": {"_type": "Set", "elements": []}, "policy_processed_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": null, "indirectly_referenced_by": null, "directly_referencing": null, "indirectly_referencing": null}, "module_processed_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": null, "indirectly_referenced_by": null, "directly_referencing": null, "indirectly_referencing": null}, "direct_transitive_cves": null, "indirect_transitive_cves": null}, "state": {"_type": "sec_certs.sample.fips.InternalState", "module": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": null, "txt_hash": null, "json_hash": null}, "policy": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": "f0eb4ff7a8e2879e310cbc2ca252671055dcf69d49b1a5fdebd9264bbd671e81", "txt_hash": "8a6cbee86853b83dd4b92e45b645aebde6ea6f9679d27e989596a578a64ab738", "json_hash": null}}}