FIPS 140 validated modules in Windows Server 2022

The following tables list the completed FIPS 140 validations of cryptographic modules used in Windows Server 2022, organized by major release of the operating system. The linked Security Policy document for each module provides details on the module capabilities and the policies the operator must follow to use the module in its FIPS approved mode of operation. For information on using the overall operating system in its FIPS approved mode, see Use Windows in a FIPS approved mode of operation. For details on the FIPS approved algorithms used by each module, see its linked Security Policy document or module certificate.

Windows Server 2022

Build: 10.0.20348.1668. Validated Editions: Standard and Datacenter.

Cryptographic Module (linked to Security Policy document) CMVP Certificate # Validated Algorithms
Boot Manager #5404 FIPS Approved: AES-CBC, AES-CCM, AES-XTS Testing Revision 2.0, Counter DRBG, HMAC-SHA2-256, PBKDF, RSA SigVer (FIPS186-4), SHA-1, SHA2-256, SHA2-384, SHA2-512
Windows OS Loader #5405 FIPS Approved: AES-CBC, AES-CCM, AES-GCM, AES-XTS Testing Revision 2.0, Counter DRBG, RSA SigVer (FIPS186-4), SHA-1, SHA2-256, SHA2-384, SHA2-512
Code Integrity #5406 FIPS Approved: RSA SigVer (FIPS186-4), SHA-1, SHA2-256, SHA2-384, SHA2-512
Secure Kernel Code Integrity #5407 FIPS Approved: RSA SigVer (FIPS186-4), SHA-1, SHA2-256, SHA2-384, SHA2-512
Kernel Mode Cryptographic Primitives Library #5408 FIPS Approved: AES-CBC, AES-CCM, AES-CFB128, AES-CFB8, AES-CMAC, AES-CTR, AES-ECB, AES-GCM, AES-GMAC, AES-KW, AES-XTS Testing Revision 2.0, Counter DRBG, ECDSA KeyGen (FIPS186-4), ECDSA KeyVer (FIPS186-4), ECDSA SigGen (FIPS186-4), ECDSA SigVer (FIPS186-4), HMAC-SHA-1, HMAC-SHA2-256, HMAC-SHA2-384, HMAC-SHA2-512, KAS-ECC Sp800-56Ar3, KAS-ECC-SSC Sp800-56Ar3, KAS-FFC Sp800-56Ar3, KAS-FFC-SSC Sp800-56Ar3, KDA HKDF SP800-56Cr2, KDF IKEv1, KDF IKEv2, KDF SP800-108, KDF TLS, PBKDF, RSA Decryption Primitive, RSA KeyGen (FIPS186-4), RSA SigGen (FIPS186-4), RSA Signature Primitive, RSA SigVer (FIPS186-4), Safe Primes Key Generation, SHA-1, SHA2-256, SHA2-384, SHA2-512, TLS v1.2 KDF RFC7627
BitLocker Dump Filter #5409 FIPS Approved: AES-CBC, AES-XTS Testing Revision 2.0, RSA SigVer (FIPS186-4), SHA2-256
Cryptographic Primitives Library #5410 FIPS Approved: AES-CBC, AES-CCM, AES-CFB128, AES-CFB8, AES-CMAC, AES-CTR, AES-ECB, AES-GCM, AES-GMAC, AES-KW, AES-XTS Testing Revision 2.0, Counter DRBG, DSA KeyGen (FIPS186-4), DSA PQGGen (FIPS186-4), DSA PQGVer (FIPS186-4), ECDSA KeyGen (FIPS186-4), ECDSA KeyVer (FIPS186-4), ECDSA SigGen (FIPS186-4), ECDSA SigVer (FIPS186-4), HMAC-SHA-1, HMAC-SHA2-256, HMAC-SHA2-384, HMAC-SHA2-512, KAS-ECC Sp800-56Ar3, KAS-ECC-SSC Sp800-56Ar3, KAS-FFC Sp800-56Ar3, KAS-FFC-SSC Sp800-56Ar3, KDA HKDF SP800-56Cr2, KDF IKEv1, KDF IKEv2, KDF SP800-108, KDF TLS, PBKDF, RSA Decryption Primitive, RSA KeyGen (FIPS186-4), RSA SigGen (FIPS186-4), RSA Signature Primitive, RSA SigVer (FIPS186-4), Safe Primes Key Generation, SHA-1, SHA2-256, SHA2-384, SHA2-512, TLS v1.2 KDF RFC7627

Build: 10.0.20348. Validated Editions: Standard, Datacenter, and Datacenter: Azure.

Cryptographic Module (linked to Security Policy document) CMVP Certificate # Validated Algorithms
Cryptographic Primitives Library #4825 FIPS Approved: AES, CKG, CVL, DRBG, DSA, ECDSA, ENT (P), HMAC, KAS, KAS-SSC, KBKDF, KTS, PBKDF, RSA, SHS, and Triple-DES
Kernel Mode Cryptographic Primitives Library #4766 FIPS Approved: AES, CKG, CVL, DRBG, DSA, ECDSA, ENT (P), HMAC, KAS, KAS-SSC, KBKDF, KTS, PBKDF, RSA, SHS, and Triple-DES