Edge SWG

Certificate #5383

Webpage information

Status active
Validation dates 08.07.2026
Sunset date 10-11-2029
Standard FIPS 140-3
Security level 1
Type Software-Hybrid
Embodiment MultiChipStand
Caveat When operated in approved mode and when installed, initialized and configured as specified in Section 11.1 of the Security Policy. The protocols TLS v1.0 and v1.1 shall not be used when operated in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.
Exceptions
  • Roles, services, and authentication: Level 2
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A
Description The Edge SWG appliances from Symantec provide companies the ability to deploy a scalable proxy-based security solution to protect their organization against advanced threats. The Edge SWG acts as gateway between web users and the Internet: a single point where all web traffic can be monitored and corporate policies for web use can be enforced.
Vendor Symantec, A Division of Broadcom
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Symmetric Algorithms
AES-128, AES-192, AES-256, AES, CAST, HMAC
Asymmetric Algorithms
RSA 2048, ECDH, DHE, Diffie-Hellman, DH
Hash functions
SHA-1, MD5, PBKDF
Schemes
MAC, Key Agreement
Protocols
SSH, SSHv2, SSL, TLS, TLS v1.3, TLS 1.2, TLS 1.3
Randomness
DRBG, RBG
Block cipher modes
CBC, GCM

Trusted Execution Environments
PSP, SSC
Vendor
Broadcom, Microsoft

Security level
Level 1
Certification process
out of scope, Dell PowerEdge R440 and S410 Server) and out of scope of this validation, and physical indicators are those of the host system (Dell PowerEdge R440 and S410 Server) and out of scope of this validation. The hypervisor provides virtualized ports and interfaces for the module

File metadata

Author Sowndar Raja Rao Gillan Gopi Intertek
Creation date D:20260616145100-04'00'
Modification date D:20260616145100-04'00'
Pages 45
Creator Microsoft® Word for Microsoft 365
Producer Microsoft® Word for Microsoft 365

Heuristics

No heuristics are available for this certificate.

References

No references are available for this certificate.

Updates Feed

  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 5383,
  "dgst": "08b25a1fb4a58b22",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": []
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "-"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECDH": {
            "ECDH": 1
          }
        },
        "FF": {
          "DH": {
            "DH": 15,
            "DHE": 1,
            "Diffie-Hellman": 1
          }
        },
        "RSA": {
          "RSA 2048": 1
        }
      },
      "certification_process": {
        "OutOfScope": {
          "Dell PowerEdge R440 and S410 Server) and out of scope of this validation": 1,
          "and physical indicators are those of the host system (Dell PowerEdge R440 and S410 Server) and out of scope of this validation. The hypervisor provides virtualized ports and interfaces for the module": 1,
          "out of scope": 1
        }
      },
      "cipher_mode": {
        "CBC": {
          "CBC": 1
        },
        "GCM": {
          "GCM": 2
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "SSH": {
          "SSH": 44,
          "SSHv2": 2
        },
        "TLS": {
          "SSL": {
            "SSL": 1
          },
          "TLS": {
            "TLS": 27,
            "TLS 1.2": 1,
            "TLS 1.3": 3,
            "TLS v1.3": 5
          }
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 1
        },
        "MAC": {
          "MAC": 9
        }
      },
      "device_model": {},
      "ecc_curve": {},
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "#1": 1
        }
      },
      "fips_certlike": {
        "Certlike": {
          "- PKCS 1": 1,
          "AES-128": 3,
          "AES-192": 2,
          "AES-256": 3,
          "HMAC-SHA- 1": 4,
          "HMAC-SHA-1": 10,
          "HMAC-SHA1": 4,
          "PKCS 1": 5,
          "PKCS7": 4,
          "RSA 2048": 1,
          "SHA-1": 9,
          "SHA2-224": 5,
          "SHA2-256": 15,
          "SHA2-384": 6,
          "SHA2-512": 8
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 5
        }
      },
      "hash_function": {
        "MD": {
          "MD5": {
            "MD5": 3
          }
        },
        "PBKDF": {
          "PBKDF": 6
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 9
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 48
        },
        "RNG": {
          "RBG": 2
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-3": 8,
          "FIPS 180-4": 7,
          "FIPS 186-4": 4,
          "FIPS 198-1": 6,
          "FIPS186-4": 19
        },
        "PKCS": {
          "PKCS 1": 3,
          "PKCS7": 2
        },
        "RFC": {
          "RFC4252": 1,
          "RFC5288": 1,
          "RFC8446": 2
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 2,
            "AES-128": 3,
            "AES-192": 2,
            "AES-256": 3
          },
          "CAST": {
            "CAST": 34
          }
        },
        "constructions": {
          "MAC": {
            "HMAC": 2
          }
        }
      },
      "tee_name": {
        "AMD": {
          "PSP": 4
        },
        "IBM": {
          "SSC": 2
        }
      },
      "tls_cipher_suite": {},
      "vendor": {
        "Broadcom": {
          "Broadcom": 48
        },
        "Microsoft": {
          "Microsoft": 4
        }
      },
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "Sowndar Raja Rao Gillan Gopi  Intertek",
      "/CreationDate": "D:20260616145100-04\u002700\u0027",
      "/Creator": "Microsoft\u00ae Word for Microsoft 365",
      "/ModDate": "D:20260616145100-04\u002700\u0027",
      "/Producer": "Microsoft\u00ae Word for Microsoft 365",
      "pdf_file_size_bytes": 818045,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "https://techdocs.broadcom.com/us/en/symantec-security-software/web-and-network-security/edge-swg/7-4/deploy-edge-swg-va/Gen2_Overview/Gen2_create_the_swg_va/Gen2_download_the_virtual_appliance_package.html",
          "https://support.broadcom.com/security/download-center"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 45
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.InternalState",
    "module": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "policy": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": "426b7dced1b98b0d9336797e69644726ac37215a8f9028297b0d967115161869",
      "txt_hash": "56ae85735b94e9b369e4299a9be031785b5935489f5831401ed761f5081478e0"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in approved mode and when installed, initialized and configured as specified in Section 11.1 of the Security Policy. The protocols TLS v1.0 and v1.1 shall not be used when operated in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/July 2026_040826_0807.pdf",
    "date_sunset": "2029-11-10",
    "description": "The Edge SWG appliances from Symantec provide companies the ability to deploy a scalable proxy-based security solution to protect their organization against advanced threats. The Edge SWG acts as gateway between web users and the Internet: a single point where all web traffic can be monitored and corporate policies for web use can be enforced.",
    "embodiment": "MultiChipStand",
    "exceptions": [
      "Roles, services, and authentication: Level 2",
      "Non-invasive security: N/A",
      "Mitigation of other attacks: N/A"
    ],
    "fw_versions": null,
    "historical_reason": null,
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {},
    "module_name": "Edge SWG",
    "module_type": "Software-Hybrid",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-3",
    "status": "active",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2026-07-08",
        "lab": "Acumen Security",
        "validation_type": "Initial"
      }
    ],
    "vendor": "Symantec, A Division of Broadcom",
    "vendor_url": "http://www.broadcom.com"
  }
}