PGP Software Development Kit (SDK): FIPS Validation

The PGP® Software Development Kit (SDK), which is the core cryptographic technology underlying PGP Universal™ Server and other PGP® products, has been validated to the National Institute of Standards and Technology's (NIST's) Federal Information Processing Standard 140-2. FIPS 140-2 validation provides independent assurance that the standard cryptographic algorithms used within the PGP SDK and other security-critical functions throughout the PGP SDK, such as key handling, are implemented correctly.

PGP Corporation has a long history of FIPS validating its core cryptographic implementations, which are part of the PGP SDK.

PGP® Whole Disk Encryption, PGP® NetShare, PGP® Desktop, PGP Universal™, and PGP® Command Line contain the PGP SDK.

The PGP SDK 3.12 is validated, and includes PGP® Desktop 9.9.1 , PGP® Universal Server™ 2.9.1.

PGP Desktop
PGP Command Line
PGP Universal
PGP SDK
NIST Cert#
Validation
Date
9.9.1 (PGP Desktop only)
2.9.1
3.12
03/11/09
9.9.0
2.9.0
3.11.0
10/17/08
9.8.3
2.8.3
3.10.3
10/17/08
9.6.1
2.6.1
3.8.1
10/22/07
9.5.1
2.5.1
3.7.1
05/02/07
9.0.3
2.0.3
3.5.3
03/03/06
8.0.3
 
3.0.3
03/18/04
N/A
 
1.5.0
08/26/99

For more information on FIPS validation, see the NIST's Cryptographic Module Validation Program.

"Having the PGP SDK available for 3rd party use is another great step forward for the security market."

- Bruce Schneier, Cryptographer

White Papers More
Customers More

"PGP Corporation is the only commercial encryption vendor that publishes its source code, which has been under scrutiny by the world's cryptography experts for years. Even though we didn't read every line of code, this practice convinced us that its products were safe to use."

Keld Viftrup Møller, Security Designer, H. Lundbeck A/S

Related Links