FIPS status of RSA Cloud Access Service components
a month ago
Originally Published: 2020-12-01
Article Number
000055602
Applies To
RSA Product Set: RSA ID Plus
RSA Product/Service Type: Cloud Authentication Service, Identity Router, Authenticator app
Issue
Is the RSA ID Plus Cloud Authentication Service FIPS 140-2/140-3 compliant and validated?
Resolution

The table below lists the cryptographic modules that are used by various RSA components, with links to the related FIPS certificates.
As part of its general release process, RSA will look to upgrade to FIPS 140-3 certified modules if/when available.
For further information on FIPS 140-2 vs FIPS 140-3, see FIPS 140-3 Transition Effort | CSRC (nist.gov)

Vendor

Crypto Module Name

NIST Certificate

RSA Component

Legion of the Bouncy Castle Inc.

bc-fips 1.0.2.3

#4616 #3514

Cloud Authentication Service
Identity Router

DELL, BSAFE

Crypto-J 6.2.5

#4645 / #4646

Cloud Authentication Service
Identity Router
Authentication Manager (< V8.9)
Authenticator App (Android)

Crypto-J 7

#4892

Authentication Manager 8.9 and above

Apple

Apple CoreCrypto User Module for iOS X

Multiple Certificates

(Different certificates for different OS versions)

Authenticator App (iOS)

Apple Corecrypto Module for MacOX S

Multiple Certificates

(Different certificates for different OS versions)

Authenticator App (MacOS)

Microsoft

Cryptographic Primitives Library

#3197

Authenticator App (Windows)