Applicability of FIPS 140-2 Historical Certificate #4028 to ESXi 8.0 Deployments
search cancel

Applicability of FIPS 140-2 Historical Certificate #4028 to ESXi 8.0 Deployments

book

Article ID: 438504

calendar_today

Updated On:

Products

VMware vSphere ESXi

Issue/Introduction

Public Cryptographic Module Validation Program (CMVP) records show that ESXi 8.0 environments have been associated with VMware cryptographic modules in both Historical and Active statuses. This includes Historical Certificate #4028 (VMware’s BoringCrypto Module) as well as active certificates (such as #4815, #4442, and #4861)

Because CMVP status applies to the underlying cryptographic modules and not directly to specific ESXi patch build numbers, users often require vendor confirmation to determine if Historical Cert #4028 is applicable to deployed ESXi 8.0.3 builds (such as builds 24674464 and 24859861).

Environment

VMware ESXi 8.0 

Resolution

Based on official VMware specifications, Certificate #4028 is NOT applicable to or used by ESXi 8.0 environments.

According to the  vSphere 8.0 TechDocs regarding FIPS Modules, Cert #4028 is not included in the set of FIPS 140-2 validated cryptographic modules utilized by ESXi. The active modules utilized by ESXi 8.0 instead include newer validated modules, such as VMware's ESXboot Cryptographic Module (Cert #4442) and VMware's Boring Crypto Module v6.0 (Cert #4694), among others.

Additional Context on Certificate #4028
As per the NIST CMVP Database, Certificate #4028 (VMware's BoringCrypto Module v3.0) has officially been moved to the Historical list due to sunsetting, which is standard procedure during cryptographic algorithm transitions.