LUNA® RA Secure Key Issuance HSM token

Certificate #168

Webpage information ?

Status historical
Historical reason Validation Sunsetting Policy - FIPS 140-1 Certificate
Validation dates 25.09.2001 , 18.10.2004
Standard FIPS 140-1
Security level 2
Type Hardware
Embodiment Multi-Chip Stand Alone
Caveat When operated in FIPS mode
Exceptions
  • Software Security: Level 3
  • Self Tests: Level 3
Description The Chrysalis-ITS® LUNA RA Secure Issuance HSM token is a hardware-based, multiple-chip standalone module which is a delta production of the Chrysalis-ITS® LUNA 2 token (certificate #56, dated 08/08/1999). Like the LUNA 2, the LUNA RA is in the form of a PC card “token” based on the PCMCIA standard. The LUNA RA token offers secure key distribution, fast key generation and secure key backup functionality to increase security and reduce operational overhead. The Luna RA token is integral to the secure issuance of keys to smart cards, cable modems, mobile phones and other PKI-enabled devices.
Version (Hardware) v 1 and 2
Version (Firmware) v3.9
Vendor SafeNet, Inc.
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Document information ?

Security policy

Symmetric Algorithms
CAST, CAST5, RC4, RC2, RC5, DES
Asymmetric Algorithms
RSA-1024, RSA-2048, RSA-4096, DSA
Hash functions
SHA-1, MD5
Schemes
MAC
Protocols
SSL
Block cipher modes
CCM

Security level
Level 7, level 2, Level 2
Side-channel analysis
timing attacks

Standards
FIPS 140-1, PKCS#11

File metadata

Title: Luna RA Security Policies
Subject: Luna RA
Author: Bob Woodard, Terry Fletcher
Creation date: D:20010913115419
Modification date: D:20010913115548-04'00'
Pages: 15
Creator: Microsoft Word 9.0
Producer: Acrobat Distiller 4.05 for Windows

References

Heuristics ?

No heuristics are available for this certificate.

References ?

No references are available for this certificate.

Updates ?

  • 09.02.2023 The certificate data changed.
    Certificate changed

    The cert_id was updated.

    • The new value is 168.

    The web extraction data was updated.

    • The following values were inserted: {'validation_history': [{'_type': 'sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry', 'date': '2001-09-25', 'validation_type': 'Initial', 'lab': 'DOMUS'}, {'_type': 'sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry', 'date': '2004-10-18', 'validation_type': 'Update', 'lab': ''}], 'vendor_url': 'http://www.safenet-inc.com', 'certificate_pdf_url': 'https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/140crt168.pdf', 'hw_versions': 'v 1 and 2', 'fw_versions': 'v3.9'}.
    • The standard property was set to FIPS 140-1.
    • The status property was set to historical.
    • The level property was set to 2.
    • The embodiment property was set to Multi-Chip Stand Alone.
    • The following properties were deleted: ['date_validation', 'algorithms', 'vendor_www', 'lab', 'lab_nvlap', 'security_policy_www', 'certificate_www', 'hw_version', 'fw_version', 'product_url'].

    The PDF extraction data was updated.

    • The following values were inserted: {'policy_metadata': {'pdf_file_size_bytes': 293333, 'pdf_is_encrypted': False, 'pdf_number_of_pages': 15, '/Producer': 'Acrobat Distiller 4.05 for Windows', '/Creator': 'Microsoft Word 9.0', '/ModDate': "D:20010913115548-04'00'", '/Author': 'Bob Woodard, Terry Fletcher', '/Subject': 'Luna RA', '/Title': 'Luna RA Security Policies', '/CreationDate': 'D:20010913115419', 'pdf_hyperlinks': {'_type': 'Set', 'elements': []}}}.
    • The following properties were deleted: ['cert_id', 'algorithms', 'clean_cert_ids', 'st_metadata'].

    The computed heuristics were updated.

    • The following values were inserted: {'policy_prunned_references': {'_type': 'Set', 'elements': ['484']}, 'module_prunned_references': {'_type': 'Set', 'elements': []}, 'policy_processed_references': {'_type': 'sec_certs.sample.certificate.References', 'directly_referenced_by': {'_type': 'Set', 'elements': ['720', '2238']}, 'indirectly_referenced_by': {'_type': 'Set', 'elements': ['720', '2238']}, 'directly_referencing': {'_type': 'Set', 'elements': ['484']}, 'indirectly_referencing': {'_type': 'Set', 'elements': ['484', '88']}}, 'module_processed_references': {'_type': 'sec_certs.sample.certificate.References', 'directly_referenced_by': None, 'indirectly_referenced_by': None, 'directly_referencing': None, 'indirectly_referencing': None}, 'direct_transitive_cves': None, 'indirect_transitive_cves': None}.
    • The algorithms property was set to {'_type': 'Set', 'elements': ['Triple-DES#74', 'Triple-DES MAC; DSA/SHA-1#13']}.
    • The following properties were deleted: ['keywords', 'unmatched_algs', 'clean_cert_ids', 'st_references', 'web_references'].

    The state was updated.

    • The following values were inserted: {'module_download_ok': True, 'policy_download_ok': True, 'policy_convert_garbage': False, 'policy_convert_ok': True, 'module_extract_ok': True, 'policy_extract_ok': True, 'policy_pdf_hash': 'ad3507be1d9842bdeb2d37a7d989d1e2db2bad24fc6c66e61ce66909e7e43e8c', 'policy_txt_hash': '4cd7e65f997f2808b9d005b56c58c6297ad5bd599c01caef3ab17c50aa7f68ee'}.
    • The following properties were deleted: ['sp_path', 'html_path', 'tables_done', 'file_status', 'txt_state'].
  • 19.12.2022 The certificate data changed.
    Certificate changed

    The computed heuristics were updated.

    • The st_references property was updated, with the {'indirectly_referenced_by': {'__add__': {'_type': 'Set', 'elements': ['3453']}}} data.
  • 18.12.2022 The certificate data changed.
    Certificate changed

    The computed heuristics were updated.

    • The st_references property was updated, with the {'indirectly_referenced_by': {'__discard__': {'_type': 'Set', 'elements': ['3453']}}} data.
  • 07.12.2022 The certificate data changed.
    Certificate changed

    The computed heuristics were updated.

    • The st_references property was updated, with the {'directly_referenced_by': {'_type': 'Set', 'elements': ['720', '719']}, 'indirectly_referenced_by': {'_type': 'Set', 'elements': ['2227', '2344', '2937', '1599', '3023', '2917', '3409', '2271', '1376', '1068', '1067', '2224', '2339', '2589', '2136', '1073', '3373', '3024', '2334', '1294', '2514', '3378', '2794', '2876', '3981', '3171', '2981', '1670', '1066', '3320', '1885', '2512', '2199', '1978', '2406', '1928', '1580', '2347', '2228', '719', '3149', '2226', '2230', '3026', '2182', '2078', '2111', '2345', '2173', '720', '2729', '1614', '3351', '2335', '3453', '2221', '2936', '2346', '3948', '1505', '2321', '1922', '2895']}} data.
  • 05.11.2022 The certificate data changed.
    Certificate changed

    The web extraction data was updated.

    • The algorithms property was updated, with the {'_type': 'Set', 'elements': [{'_type': 'sec_certs.sample.fips_algorithm.FIPSAlgorithm', 'cert_id': '#74', 'algorithm_type': 'Triple-DES', 'vendor': None, 'implementation': None, 'date': None}, {'_type': 'sec_certs.sample.fips_algorithm.FIPSAlgorithm', 'cert_id': '#13', 'algorithm_type': 'Triple-DES MAC; DSA/SHA-1', 'vendor': None, 'implementation': None, 'date': None}]} values discarded.

    The computed heuristics were updated.

    • The algorithms property was updated, with the {'_type': 'Set', 'elements': [{'_type': 'sec_certs.sample.fips_algorithm.FIPSAlgorithm', 'cert_id': '#74', 'algorithm_type': 'Triple-DES', 'vendor': None, 'implementation': None, 'date': None}, {'_type': 'sec_certs.sample.fips_algorithm.FIPSAlgorithm', 'cert_id': '#13', 'algorithm_type': 'Triple-DES MAC; DSA/SHA-1', 'vendor': None, 'implementation': None, 'date': None}]} values discarded.
  • 01.11.2022 The certificate data changed.
    Certificate changed

    The computed heuristics were updated.

    • The st_references property was updated, with the {'directly_referenced_by': None, 'indirectly_referenced_by': None} data.
  • 29.10.2022 The certificate data changed.
    Certificate changed

    The computed heuristics were updated.

    • The st_references property was updated, with the {'directly_referenced_by': {'_type': 'Set', 'elements': ['720']}, 'indirectly_referenced_by': {'_type': 'Set', 'elements': ['720']}} data.
  • 28.10.2022 The certificate data changed.
    Certificate changed

    The computed heuristics were updated.

    • The st_references property was updated, with the {'directly_referenced_by': None, 'indirectly_referenced_by': None} data.
  • 25.10.2022 The certificate data changed.
    Certificate changed

    The PDF extraction data was updated.

    • The keywords property was updated, with the {'fips_cert_id': {'__update__': {'Cert': {'__delete__': ['#11']}}}, 'fips_certlike': {'__update__': {'Certlike': {'__update__': {'SHA-1': 2, 'PKCS#11': 6}, '__delete__': ['SHA1', 'RSA 1', 'DES-CBC1']}}}, 'symmetric_crypto': {'__update__': {'AES_competition': {'__update__': {'CAST': {'__update__': {'CAST': 1, 'CAST5': 1}, '__delete__': ['CAST-']}, 'RC': {'__update__': {'RC2': 1, 'RC5': 1}}}}, 'DES': {'__update__': {'DES': {'__update__': {'DES': 6}}}, '__delete__': ['3DES']}}, '__delete__': ['miscellaneous', 'constructions']}, 'asymmetric_crypto': {'__update__': {'FF': {'__update__': {'DSA': {'__update__': {'DSA': 1}}}, '__delete__': ['DH']}}}, 'hash_function': {'__update__': {'SHA': {'__update__': {'SHA1': {'__update__': {'SHA-1': 2}, '__delete__': ['SHA1']}}}, 'MD': {'__update__': {'MD5': {'__update__': {'MD5': 3}}}}}}, 'crypto_scheme': {'__update__': {'MAC': {'__update__': {'MAC': 1}}}}, 'crypto_protocol': {'__update__': {'TLS': {'__update__': {'SSL': {'__update__': {'SSL': 1}}}}}}, 'cipher_mode': {'__update__': {'CCM': {'__update__': {'CCM': 6}}}, '__delete__': ['ECB', 'CBC', 'XTR', 'XTS']}, 'tee_name': {}, 'standard_id': {'__update__': {'PKCS': {'__update__': {'PKCS#11': 3}}}}} data.

    The computed heuristics were updated.

    • The st_references property was updated, with the {'directly_referenced_by': {'_type': 'Set', 'elements': ['720']}, 'indirectly_referenced_by': {'_type': 'Set', 'elements': ['720']}} data.

    The state was updated.

    • The tables_done property was set to True.
  • 17.07.2022 The certificate data changed.
    Certificate changed

    The _type was updated.

    • The new value is sec_certs.sample.fips.FIPSCertificate.

    The computed heuristics were updated.

    • The following values were inserted: {'clean_cert_ids': {}}.
    • The _type property was set to sec_certs.sample.fips.FIPSCertificate.Heuristics.
    • The keywords property was set to {}.
    • The algorithms property was set to {'_type': 'Set', 'elements': [{'_type': 'sec_certs.sample.fips_algorithm.FIPSAlgorithm', 'cert_id': '#74', 'algorithm_type': 'Triple-DES', 'vendor': None, 'implementation': None, 'date': None}, {'_type': 'sec_certs.sample.fips_algorithm.FIPSAlgorithm', 'cert_id': '#56', 'algorithm_type': None, 'vendor': None, 'implementation': None, 'date': None}, {'_type': 'sec_certs.sample.fips_algorithm.FIPSAlgorithm', 'cert_id': '#13', 'algorithm_type': 'Triple-DES MAC; DSA/SHA-1', 'vendor': None, 'implementation': None, 'date': None}]}.
    • The st_references property was updated, with the {'_type': 'sec_certs.sample.certificate.References'} data.
    • The web_references property was updated, with the {'_type': 'sec_certs.sample.certificate.References'} data.

    The state was updated.

    • The _type property was set to sec_certs.sample.fips.FIPSCertificate.InternalState.
    • The following properties were deleted: ['fragment_path'].
  • 14.06.2022 The certificate data changed.
    Certificate changed

    The pdf_scan was updated.

    • The keywords property was updated, with the {'rules_cert_id': {}, 'rules_standard_id': {'__update__': {'FIPS ?(?:PUB )?[0-9]+-[0-9]+?': {'__update__': {'FIPS 140-1': {'__update__': {'count': 1}}}}, 'PKCS[ #]*[1-9]+': {'__update__': {'PKCS#11': {'__update__': {'count': 1}}}}}}, 'rules_security_assurance_components': {'__update__': {'ATE(?:_[A-Z]{3,4}){1,2}(?:\\.[0-9]|\\.[0-9]\\.[0-9]|)': {'__update__': {'ATE_KEY': {'__update__': {'count': 1}}}, '__delete__': ['ATE_OBJ', 'ATE_USER', 'ATE_KEY_PAIR']}}}, 'rules_block_cipher_modes': {'__insert__': {'CCM': {'CCM': {'count': 1}}, 'XTS': {'XTS': {'count': 1}}}, '__update__': {'ECB': {'__update__': {'ECB': {'__update__': {'count': 1}}}}}}} data.

    The computed heuristics were updated.

    • The keywords property was updated, with the {'rules_cert_id': {}, 'rules_standard_id': {'__update__': {'FIPS ?(?:PUB )?[0-9]+-[0-9]+?': {'__update__': {'FIPS 140-1': {'__update__': {'count': 1}}}}, 'PKCS[ #]*[1-9]+': {'__update__': {'PKCS#11': {'__update__': {'count': 1}}}}}}, 'rules_security_assurance_components': {'__update__': {'ATE(?:_[A-Z]{3,4}){1,2}(?:\\.[0-9]|\\.[0-9]\\.[0-9]|)': {'__update__': {'ATE_KEY': {'__update__': {'count': 1}}}, '__delete__': ['ATE_OBJ', 'ATE_USER', 'ATE_KEY_PAIR']}}}, 'rules_block_cipher_modes': {'__insert__': {'CCM': {'CCM': {'count': 1}}, 'XTS': {'XTS': {'count': 1}}}, '__update__': {'ECB': {'__update__': {'ECB': {'__update__': {'count': 1}}}}}}} data.
  • 08.03.2022 The certificate data changed.
    Certificate changed

    The web_scan was updated.

    • The following properties were deleted: ['connections'].

    The pdf_scan was updated.

    • The following properties were deleted: ['connections'].

    The computed heuristics were updated.

    • The following values were inserted: {'st_references': {'_type': 'References', 'directly_referenced_by': None, 'indirectly_referenced_by': None, 'directly_referencing': None, 'indirectly_referencing': None}, 'web_references': {'_type': 'References', 'directly_referenced_by': None, 'indirectly_referenced_by': None, 'directly_referencing': None, 'indirectly_referencing': None}}.
    • The following properties were deleted: ['connections', 'directly_affected_by', 'indirectly_affected_by', 'directly_affecting', 'indirectly_affecting'].
  • 18.02.2022 The certificate data changed.
    Certificate changed

    The computed heuristics were updated.

    • The extracted_versions property was set to {'_type': 'Set', 'elements': ['3.9']}.
  • 02.02.2022 The certificate data changed.
    Certificate changed

    The web_scan was updated.

    • The module_type property was set to Hardware.
  • 30.01.2022 The certificate was first processed.
    New certificate

    A new FIPS 140 certificate with the product name was processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 168,
  "dgst": "80c3cd40fa35f908",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "Triple-DES#74",
        "Triple-DES MAC; DSA/SHA-1#13"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "3.9"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": {
        "_type": "Set",
        "elements": [
          "720",
          "2238"
        ]
      },
      "directly_referencing": {
        "_type": "Set",
        "elements": [
          "484"
        ]
      },
      "indirectly_referenced_by": {
        "_type": "Set",
        "elements": [
          "720",
          "2238"
        ]
      },
      "indirectly_referencing": {
        "_type": "Set",
        "elements": [
          "484",
          "88"
        ]
      }
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": [
        "484"
      ]
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "FF": {
          "DSA": {
            "DSA": 1
          }
        },
        "RSA": {
          "RSA-1024": 4,
          "RSA-2048": 4,
          "RSA-4096": 4
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CCM": {
          "CCM": 6
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "TLS": {
          "SSL": {
            "SSL": 1
          }
        }
      },
      "crypto_scheme": {
        "MAC": {
          "MAC": 1
        }
      },
      "device_model": {},
      "ecc_curve": {},
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "#484": 1
        }
      },
      "fips_certlike": {
        "Certlike": {
          "DSA-1024": 1,
          "HMAC-SHA1": 2,
          "PKCS#11": 6,
          "SHA-1": 2
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 2": 1,
          "Level 7": 15,
          "level 2": 2
        }
      },
      "hash_function": {
        "MD": {
          "MD5": {
            "MD5": 3
          }
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 2
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {},
      "side_channel_analysis": {
        "SCA": {
          "timing attacks": 2
        }
      },
      "standard_id": {
        "FIPS": {
          "FIPS 140-1": 2
        },
        "PKCS": {
          "PKCS#11": 3
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "CAST": {
            "CAST": 1,
            "CAST5": 1
          },
          "RC": {
            "RC2": 1,
            "RC4": 2,
            "RC5": 1
          }
        },
        "DES": {
          "DES": {
            "DES": 6
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "Bob Woodard, Terry Fletcher",
      "/CreationDate": "D:20010913115419",
      "/Creator": "Microsoft Word 9.0",
      "/ModDate": "D:20010913115548-04\u002700\u0027",
      "/Producer": "Acrobat Distiller 4.05 for Windows",
      "/Subject": "Luna RA",
      "/Title": "Luna RA Security Policies",
      "pdf_file_size_bytes": 293333,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": []
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 15
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
    "module_download_ok": true,
    "module_extract_ok": true,
    "policy_convert_garbage": false,
    "policy_convert_ok": true,
    "policy_download_ok": true,
    "policy_extract_ok": true,
    "policy_pdf_hash": "ad3507be1d9842bdeb2d37a7d989d1e2db2bad24fc6c66e61ce66909e7e43e8c",
    "policy_txt_hash": "4cd7e65f997f2808b9d005b56c58c6297ad5bd599c01caef3ab17c50aa7f68ee"
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in FIPS mode",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/140crt168.pdf",
    "date_sunset": null,
    "description": "The Chrysalis-ITS\u00ae LUNA RA Secure Issuance HSM token is a hardware-based, multiple-chip standalone module which is a delta production of the Chrysalis-ITS\u00ae LUNA 2 token (certificate #56, dated 08/08/1999). Like the LUNA 2, the LUNA RA is in the form of a PC card \u201ctoken\u201d based on the PCMCIA standard. The LUNA RA token offers secure key distribution, fast key generation and secure key backup functionality to increase security and reduce operational overhead. The Luna RA token is integral to the secure issuance of keys to smart cards, cable modems, mobile phones and other PKI-enabled devices.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Software Security: Level 3",
      "Self Tests: Level 3"
    ],
    "fw_versions": "v3.9",
    "historical_reason": "Validation Sunsetting Policy - FIPS 140-1 Certificate",
    "hw_versions": "v 1 and 2",
    "level": 2,
    "mentioned_certs": {},
    "module_name": "LUNA\u00ae RA Secure Key Issuance HSM token",
    "module_type": "Hardware",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-1",
    "status": "historical",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2001-09-25",
        "lab": "DOMUS",
        "validation_type": "Initial"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2004-10-18",
        "lab": "",
        "validation_type": "Update"
      }
    ],
    "vendor": "SafeNet, Inc.",
    "vendor_url": "http://www.safenet-inc.com"
  }
}