FIPS 140 certificate tracker

Every NIST FIPS 140 certificate, plus the modules-in-process queue NIST publishes only as a page.

我該用這個嗎

品質與安全性

A
說明品質
100%
結構描述完整度
82%
命名品質
80%
汙染風險
100%
權限相符程度
100%
協定合規性
100%

根據工具定義與協定合規性的自動化分析。

上下文成本

~1,056Token(工具定義)
~1008 B典型回應大小
中等的注意力影響(128k 上下文的 0.83%)

這是每次將伺服器的工具載入模型上下文時所消耗的約略 token 數量。數量越高,可用於其他工作的注意力就越少。

安裝

一鍵安裝

將以下內容加入你的 `claude_desktop_config.json` 檔案:

{
  "mcpServers": {
    "fips-cmvp": {
      "url": "https://fips.808bits.com/mcp"
    }
  }
}

遠端端點

https://fips.808bits.com/mcpstreamable-http

它能做什麼

工具清單

工具(6)

🟢 唯讀🟡 寫入🔴 刪除⚪ 未知
⚪fips_cert(number)

Look up one FIPS 140 cryptographic module validation by certificate number. Returns status (active, historical or revoked), overall level, sunset date, validation history, approved algorithms and tested configurations.

輸入結構描述

{
  "type": "object",
  "properties": {
    "number": {
      "type": "integer",
      "exclusiveMinimum": 0,
      "maximum": 9007199254740991
    }
  },
  "required": [
    "number"
  ],
  "$schema": "https://json-schema.org/draft/2020-12/schema"
}
🟢fips_search(query, status, standard, level, limit)

Search FIPS 140 validations by module name or vendor. Use this to answer whether a given product or vendor holds a current validation, and at what level. Results are ordered by status, then how well they match, then newest first, so the current validations lead.

輸入結構描述

{
  "type": "object",
  "properties": {
    "query": {
      "type": "string",
      "minLength": 2,
      "description": "Module name or vendor. Several words all have to match, in any order and across either field, so \"openssl provider\" works."
    },
    "status": {
      "type": "string",
      "enum": [
        "active",
        "historical",
        "revoked"
      ]
    },
    "standard": {
      "type": "string",
      "enum": [
        "140-1",
        "140-2",
        "140-3"
      ]
    },
    "level": {
      "type": "integer",
      "minimum": 1,
      "maximum": 4
    },
    "limit": {
      "default": 20,
      "type": "integer",
      "minimum": 1,
      "maximum": 50
    }
  },
  "required": [
    "query"
  ],
  "$schema": "https://json-schema.org/draft/2020-12/schema"
}
🟢fips_in_process(query, phase, limit)

Search NIST's Modules in Process queue: submissions awaiting FIPS 140-3 validation, with the review phase each one is sitting in. Use this when a vendor claims a validation is 'coming' and you need to know whether it has actually been submitted, and how far along it is.

輸入結構描述

{
  "type": "object",
  "properties": {
    "query": {
      "description": "Substring of the module name or vendor",
      "type": "string",
      "minLength": 2
    },
    "phase": {
      "description": "e.g. Review, Finalization, Coordination",
      "type": "string"
    },
    "limit": {
      "default": 50,
      "type": "integer",
      "minimum": 1,
      "maximum": 200
    }
  },
  "$schema": "https://json-schema.org/draft/2020-12/schema"
}
⚪fips_vendor(vendor, limit)

Everything one company holds, grouped across the spelling variants NIST filed it under. Cisco alone appears as three different strings. Returns a breakdown by status and standard plus the certificates themselves. Note this groups spellings of one registration, not corporate families: the nShield line sits under nCipher, Thales and Entrust separately, because the product changed owner. Groups large enough to have their own page on the tracker carry a tracker_url alongside the per-certificate ones.

輸入結構描述

{
  "type": "object",
  "properties": {
    "vendor": {
      "type": "string",
      "minLength": 2,
      "description": "Vendor name or part of one"
    },
    "limit": {
      "default": 100,
      "type": "integer",
      "minimum": 1,
      "maximum": 500
    }
  },
  "required": [
    "vendor"
  ],
  "$schema": "https://json-schema.org/draft/2020-12/schema"
}
🟢fips_cve(cve, vendor, min_cvss, limit)

Which FIPS-validated modules are associated with a given CVE, or which CVEs are associated with a vendor's modules. Answers 'we have a validated module, is it caught up in this advisory'. The association is name-based against the product CPE, so read it as a pointer to check rather than a finding. An empty result means nothing matched by name, not that the module is unaffected: only 4 of the 712 active certificates carry any association at all, and historical ones are never scanned.

輸入結構描述

{
  "type": "object",
  "properties": {
    "cve": {
      "description": "CVE id, e.g. CVE-2023-4807",
      "type": "string"
    },
    "vendor": {
      "description": "Vendor name or part of one",
      "type": "string"
    },
    "min_cvss": {
      "type": "number",
      "minimum": 0,
      "maximum": 10
    },
    "limit": {
      "default": 50,
      "type": "integer",
      "minimum": 1,
      "maximum": 200
    }
  },
  "$schema": "https://json-schema.org/draft/2020-12/schema"
}
🟢fips_sunset(before, standard, vendor, limit)

List active FIPS validations by sunset date, the day each moves to NIST's historical list and stops being valid for new procurement. Answers 'what expires before date X' and 'which vendors are about to have nothing valid'. A certificate listed here may already have a 140-3 successor: check fips_search for the same module name before reporting a gap.

輸入結構描述

{
  "type": "object",
  "properties": {
    "before": {
      "description": "ISO date, exclusive: before=2026-09-21 excludes the 21st itself",
      "type": "string"
    },
    "standard": {
      "type": "string",
      "enum": [
        "140-1",
        "140-2",
        "140-3"
      ]
    },
    "vendor": {
      "type": "string"
    },
    "limit": {
      "default": 50,
      "type": "integer",
      "minimum": 1,
      "maximum": 200
    }
  },
  "$schema": "https://json-schema.org/draft/2020-12/schema"
}

建議的提示詞

find_specific
Find [specific item] using FIPS 140 certificate tracker
預期的工具: fips_search
search_research
Search for information about [topic] using FIPS 140 certificate tracker
預期的工具: fips_search
search_then_create
Search for [item] and create a new [related item] using FIPS 140 certificate tracker
預期的工具: fips_searchfips_sunset

社群

為此伺服器評分

證據

近期觀測

已驗證未記錄版本6 個工具
已驗證未記錄版本6 個工具