FIPS status of RSA Cloud Access Service components
5 hours ago
Originally Published: 2020-12-01
Article Number
000055602
Applies To
RSA Product Set: RSA ID Plus
RSA Product/Service Type: Cloud Authentication Service, Identity Router, Authenticator app
Issue

Is the RSA ID Plus Cloud Authentication Service FIPS 140 compliant and validated?

Resolution

The table below lists the cryptographic modules that are used by various RSA components, with links to the related FIPS 140 certificates.
As part of its general release process, RSA is upgrading to FIPS 140-3 certified modules if/when available.
For further information on FIPS 140-2 vs FIPS 140-3, see FIPS 140-3 Transition Effort | CSRC (nist.gov)

Vendor

Crypto Module Name

NIST Certificate

RSA Component

Legion of the Bouncy Castle Inc.

BC-FJA (Bouncy Castle FIPS Java API)

#4943

Cloud Authentication Service
Identity Router

Authenticator App for Android, V4.7 and above.

DELL, BSAFE

Crypto-J 6.2.5

#4645 / #4646

Cloud Authentication Service
Identity Router
Authentication Manager (< V8.9)
Authenticator App for Android < V4.7

Crypto-J 7

#4892

Authentication Manager 8.9 and above

Apple

Apple CoreCrypto User Module for iOS X

Multiple Certificates

(Different certificates for different OS versions)

Authenticator App  for iOS 

Apple Corecrypto Module for MacOX S

Multiple Certificates

(Different certificates for different OS versions)

Authenticator App for macOS

Microsoft

Cryptographic Primitives Library

#3197

Authenticator App for Windows

SafeLogic

CryptoComply 140-3 FIPS Provider

#5040

Authenticator App for iOS, V4.7 and above.