Cisco Adaptive Security Appliance Cryptographic Module (FPR 4200 Series)

Certificate details

Certificate ID #5067
Status active
Validation dates 22.09.2025
Sunset date 21-09-2030
Standard FIPS 140-3
Security level 2
Type Hardware
Embodiment Multi-Chip Stand Alone
Caveat When installed, initialized and configured as specified in Section Life-Cycle Assurance of the Security Policy. The tamper evident seals installed as indicated in the Security Policy
Exceptions
  • Roles, services, and authentication: Level 3
  • Operational environment: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A
Description Next generation security services on Cisco Firepower 4200 Series, capable of running multiple (firewall (NGFW), traffic management) security services simultaneously.
Vendor Cisco Systems, Inc. http://www.cisco.com
Lab Gossamer Security Solutions
Algorithms
  • AES-CBCC1026
  • AES-GCMC1026
  • Counter DRBGA4446
  • ECDSA KeyGen (FIPS186-4)A4446
  • ECDSA SigGen (FIPS186-4)A4446
  • ECDSA SigVer (FIPS186-4)A4446
  • Hash DRBGC1026
  • HMAC-SHA-1C1026
  • HMAC-SHA2-224A4446
  • HMAC-SHA2-256C1026
  • HMAC-SHA2-384C1026
  • HMAC-SHA2-512C1026
  • KAS-ECC-SSC Sp800-56Ar3A4446
  • KAS-FFC-SSC Sp800-56Ar3A4446
  • KDF IKEv2A4446
  • KDF SNMPA4446
  • KDF SSHA4446
  • RSA KeyGen (FIPS186-4)A4446
  • RSA SigGen (FIPS186-4)A4446
  • RSA SigVer (FIPS186-4)A4446
  • Safe Primes Key GenerationA4446
  • SHA-1C1026
  • SHA2-224A4446
  • SHA2-256C1026
  • SHA2-384C1026
  • SHA2-512C1026
  • TLS v1.2 KDF RFC7627A4446
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Extracted keywords

Symmetric Algorithms
AES-128, AES-192, AES-256, AES, AES-, CAST, HMAC
Asymmetric Algorithms
RSA 2048, ECDH, ECDHE, ECDSA, ECC, Diffie-Hellman, DH, DSA
Hash functions
SHA-1, SHA2
Schemes
MAC
Protocols
SSHv2, SSH, TLS v1.2, TLSv1.2, TLS, IKEv2, IKE, IPsec, VPN
Randomness
DRBG, RBG
Elliptic Curves
P-256, P-384, P-521
Block cipher modes
CTR, GCM

Trusted Execution Environments
PSP, SSC
Vendor
Cisco Systems, Inc, Cisco

Security level
Level 2
Certification process
out of scope, fails. Any firmware loaded into the module that is not shown on the module certificate, is out of scope of this validation and requires a separate FIPS 140-3 validation

Automated analysis

Automated inference - use with caution

All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.

No automatically derived data are available in this section.

Cross-references

No references are available for this certificate.

Processing updates

Feed
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 5067,
  "dgst": "197a2971491b3b3a",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "SHA2-256C1026",
        "Counter DRBGA4446",
        "SHA2-224A4446",
        "Hash DRBGC1026",
        "AES-GCMC1026",
        "SHA2-512C1026",
        "KDF IKEv2A4446",
        "#A4446",
        "HMAC-SHA2-384C1026",
        "HMAC-SHA2-256C1026",
        "KDF SNMPA4446",
        "Safe Primes Key GenerationA4446",
        "SHA-1C1026",
        "KAS-FFC-SSC Sp800-56Ar3A4446",
        "ECDSA SigGen (FIPS186-4)A4446",
        "RSA SigVer (FIPS186-4)A4446",
        "RSA SigGen (FIPS186-4)A4446",
        "RSA KeyGen (FIPS186-4)A4446",
        "HMAC-SHA2-512C1026",
        "KAS-ECC-SSC Sp800-56Ar3A4446",
        "ECDSA KeyGen (FIPS186-4)A4446",
        "HMAC-SHA-1C1026",
        "AES-CBCC1026",
        "#C1026",
        "TLS v1.2 KDF RFC7627A4446",
        "ECDSA SigVer (FIPS186-4)A4446",
        "SHA2-384C1026",
        "HMAC-SHA2-224A4446",
        "KDF SSHA4446"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "4200"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "br1_deviations": 0,
    "br1_tables": {
      "_type": "sec_certs.heuristics.br1.table_parsing.model.br1_tables.BR1Tables",
      "approved_algorithms": {
        "entries": [
          {
            "algorithm": "AES-CBC",
            "cavpCertName": "A4446",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-GCM",
            "cavpCertName": "A4446",
            "properties": "Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256",
            "reference": "SP 800-38D"
          },
          {
            "algorithm": "Counter DRBG",
            "cavpCertName": "A4446",
            "properties": "Prediction Resistance - Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - Yes",
            "reference": "SP 800-90A Rev. 1"
          },
          {
            "algorithm": "ECDSA KeyGen (FIPS186-4)",
            "cavpCertName": "A4446",
            "properties": "Curve - P-256, P-384, P-521 Secret Generation Mode - Testing Candidates",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA SigGen (FIPS186-4)",
            "cavpCertName": "A4446",
            "properties": "Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2- 384, SHA2-512",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA SigVer (FIPS186-4)",
            "cavpCertName": "A4446",
            "properties": "Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2- 384, SHA2-512",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "HMAC-SHA-1",
            "cavpCertName": "A4446",
            "properties": "Key Length - Key Length: 256-448 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2- 224",
            "cavpCertName": "A4446",
            "properties": "Key Length - Key Length: 256-448 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2- 256",
            "cavpCertName": "A4446",
            "properties": "Key Length - Key Length: 256-448 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2- 384",
            "cavpCertName": "A4446",
            "properties": "Key Length - Key Length: 256-448 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2- 512",
            "cavpCertName": "A4446",
            "properties": "Key Length - Key Length: 256-448 Increment 8",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "KAS-ECC-SSC Sp800-56Ar3",
            "cavpCertName": "A4446",
            "properties": "Domain Parameter Generation Methods - P- 256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responder",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "KAS-FFC-SSC Sp800-56Ar3",
            "cavpCertName": "A4446",
            "properties": "Domain Parameter Generation Methods - ffdhe2048, ffdhe3072, ffdhe4096, modp-2048, modp-3072, modp-4096 Scheme - dhEphem - KAS Role - initiator, responder",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "KDF IKEv2 (CVL)",
            "cavpCertName": "A4446",
            "properties": "Diffie-Hellman Shared Secret Length - Diffie- Hellman Shared Secret Length: 2048 Derived Keying Material Length - Derived Keying Material Length: 3072 Hash Algorithm - SHA-1",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "KDF SNMP (CVL)",
            "cavpCertName": "A4446",
            "properties": "Password Length - Password Length: 256, 64",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "KDF SSH (CVL)",
            "cavpCertName": "A4446",
            "properties": "Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-256",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "RSA KeyGen (FIPS186-4)",
            "cavpCertName": "A4446",
            "properties": "Key Generation Mode - B.3.4 Modulo - 2048, 3072 Hash Algorithm - SHA2-256 Private Key Format - Standard",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "RSA SigGen (FIPS186-4)",
            "cavpCertName": "A4446",
            "properties": "Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "RSA SigVer (FIPS186-4)",
            "cavpCertName": "A4446",
            "properties": "Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "Safe Primes Key Generation",
            "cavpCertName": "A4446",
            "properties": "Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, modp-2048, modp-3072, modp- 4096",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "SHA-1",
            "cavpCertName": "A4446",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-224",
            "cavpCertName": "A4446",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-256",
            "cavpCertName": "A4446",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-384",
            "cavpCertName": "A4446",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512",
            "cavpCertName": "A4446",
            "properties": "Message Length - Message Length: 0-65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "TLS v1.2 KDF RFC7627 (CVL)",
            "cavpCertName": "A4446",
            "properties": "Hash Algorithm - SHA2-256, SHA2-384, SHA2- 512",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "AES-CBC",
            "cavpCertName": "C1026",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-GCM",
            "cavpCertName": "C1026",
            "properties": "Direction - Decrypt, Encrypt IV Generation - External Key Length - 128, 192, 256",
            "reference": "SP 800-38D"
          },
          {
            "algorithm": "Hash DRBG",
            "cavpCertName": "C1026",
            "properties": "Prediction Resistance - No Mode - SHA2-512",
            "reference": "SP 800-90A Rev. 1"
          },
          {
            "algorithm": "HMAC-SHA-1",
            "cavpCertName": "C1026",
            "properties": "-",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2- 256",
            "cavpCertName": "C1026",
            "properties": "-",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2- 384",
            "cavpCertName": "C1026",
            "properties": "-",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2- 512",
            "cavpCertName": "C1026",
            "properties": "-",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "SHA-1",
            "cavpCertName": "C1026",
            "properties": "Message Length - Message Length: 0- 51200 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-256",
            "cavpCertName": "C1026",
            "properties": "Message Length - Message Length: 0- 51200 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-384",
            "cavpCertName": "C1026",
            "properties": "Message Length - Message Length: 0- 102400 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-512",
            "cavpCertName": "C1026",
            "properties": "Message Length - Message Length: 0- 102400 Increment 8",
            "reference": "FIPS 180-4"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "approved_services": {
        "entries": [
          {
            "description": "Provide Module\u0027s current status (return codes and/or syslog messages)",
            "indicator": "Global Indicator or syslog message",
            "inputs": "Command used to show Module\u0027s Status",
            "name": "Show Status",
            "outputs": "Module\u0027s Operationa l Status",
            "rolesSspAccess": "Crypto Officer User",
            "secFunImpl": "None"
          },
          {
            "description": "Provide Module\u0027s name and version information",
            "indicator": "Console message",
            "inputs": "Command to show version",
            "name": "Show Version",
            "outputs": "Module\u0027s ID and versioning information",
            "rolesSspAccess": "Crypto Officer User",
            "secFunImpl": "None"
          },
          {
            "description": "Perform Self-Tests (Pre- operational self-test and Conditional Self-Tests)",
            "indicator": "Global Indicator or syslog message",
            "inputs": "Command to trigger Self-Test",
            "name": "Perform Self-Tests",
            "outputs": "Status of the self- tests results",
            "rolesSspAccess": "Crypto Officer User Unauthentic ated",
            "secFunImpl": "None"
          },
          {
            "description": "Perform Zeroization",
            "indicator": "Syslog message",
            "inputs": "Command to zeroize the module",
            "name": "Perform Zeroization",
            "outputs": "Status of the SSPs zeroization",
            "rolesSspAccess": "Crypto Officer - DRBG Entropy",
            "secFunImpl": "None"
          },
          {
            "description": "Descriptio n",
            "indicator": "Indicator",
            "inputs": "Inputs",
            "name": "Name",
            "outputs": "Outputs",
            "rolesSspAccess": "SSP Access",
            "secFunImpl": "Security"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "Input: Z - DRBG Seed: Z - DRBG Internal State (V, Key): Z - DRBG Internal State (V, C): Z - User Password: Z - Crypto Officer Password: Z - RADIUS Secret: Z - TACACS+ Secret: Z - Firmware Load Test Key: Z - SSH DH Private Key: Z - SSH DH Public Key: Z - SSH Peer DH Public Key: Z - SSH DH Shared Secret: Z - SSH ECDH Private Key: Z - SSH ECDH Public Key: Z - SSH Peer ECDH Public Key: Z - SSH ECDH Shared Secret: Z - SSH RSA",
            "secFunImpl": "Functions"
          },
          {
            "description": "Descriptio n",
            "indicator": "Indicator",
            "inputs": "Inputs",
            "name": "Name",
            "outputs": "Outputs",
            "rolesSspAccess": "SSP Access",
            "secFunImpl": "Security"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "Private Key: Z - SSH RSA Public Key: Z - SSH ECDSA Private Key: Z - SSH ECDSA Public Key: Z - SSH Session Encryption Key: Z - SSH Session Authenticatio n Key: Z - TLS DH Private Key: Z - TLS DH Public Key: Z - TLS Peer DH Public Key: Z - TLS DH Shared Secret: Z - TLS ECDH Private Key: Z - TLS ECDH Public Key: Z - TLS Peer ECDH Public Key: Z - TLS ECDH Shared Secret: Z - TLS ECDSA Private Key:",
            "secFunImpl": "Functions"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "Z - TLS ECDSA Public Key: Z - TLS RSA Private Key: Z - TLS RSA Public Key: Z - TLS Master Secret: Z - TLS Session Encryption Key: Z - TLS Session Authenticatio n Key: Z - IPSec/IKE DH Private Key: Z - IPSec/IKE DH Public Key: Z - IPSec/IKE Peer DH Public Key: Z - IPSec/IKE DH Shared Secret: Z - IPSec/IKE ECDH Private Key: Z - IPSec/IKE ECDH Public Key: Z - IPSec/IKE Peer ECDH Public Key: Z - IPSec/IKE ECDH Shared",
            "secFunImpl": ""
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "Secret: Z - IPSec/IKE ECDSA Private Key: Z - IPSec/IKE ECDSA Public Key: Z - IPSec/IKE RSA Private Key: Z - IPSec/IKE RSA Public Key: Z - IPSec/IKE Pre-shared Secret: Z - SKEYSEED: Z - IPSec/IKE Session Encryption Key: Z - IPSec/IKE Authenticatio n Key: Z - SNMPv3 Shared Secret: Z - SNMPv3 Encryption Key: Z - SNMPv3 Authenticatio n Key: Z",
            "secFunImpl": ""
          },
          {
            "description": "Sets configurati on of the systems",
            "indicator": "None",
            "inputs": "Command s to configure the network",
            "name": "Configure Network",
            "outputs": "Status of the completion of network configurati on status",
            "rolesSspAccess": "Crypto Officer",
            "secFunImpl": "None"
          },
          {
            "description": "CO Role Authenticat ion",
            "indicator": "N/A",
            "inputs": "CO Authenticat ion Request",
            "name": "Crypto Officer Authenticat ion",
            "outputs": "Status of the CO authenticat ion",
            "rolesSspAccess": "Crypto Officer - Crypto Officer Password: W,Z",
            "secFunImpl": "None"
          },
          {
            "description": "User Role Authenticat ion",
            "indicator": "N/A",
            "inputs": "User role authenticat ion request",
            "name": "User Authenticat ion",
            "outputs": "Status of the User role authenticat ion",
            "rolesSspAccess": "User - User Password: W,Z",
            "secFunImpl": "None"
          },
          {
            "description": "Sets the Bypass capability",
            "indicator": "None",
            "inputs": "CLI Bypass commands",
            "name": "Configure Bypass Capability",
            "outputs": "Status of the completion of Bypass capability configurati on",
            "rolesSspAccess": "Crypto Officer",
            "secFunImpl": "None"
          },
          {
            "description": "Configure SSHv2 Function",
            "indicator": "Global Indicator and SSHv2 configurat ion success status message",
            "inputs": "Command s to configure SSHv2",
            "name": "Configure SSHv2 Function",
            "outputs": "Status of the completion of the SSHv2 configurati on",
            "rolesSspAccess": "Crypto Officer - SSH DH Private Key: G,W,E - SSH DH Public Key: G,R,W - SSH Peer DH Public Key: W,E - SSH DH Shared Secret: G,W,E - SSH ECDH Private Key: G,W,E - SSH ECDH Public Key: G,R,W - SSH Peer ECDH Public Key: W,E - SSH ECDH Shared Secret: G,W,E - SSH RSA Private Key: G,W,E - SSH RSA Public Key: G,R,W - SSH ECDSA",
            "secFunImpl": "KAS-ECC- KeyGen (SSHv2) KAS-FFC- KeyGen (SSHv2) KAS-ECC (SSHv2) KAS-FFC (SSHv2) KTS (SSHv2 with AES and HMAC) KTS (SSHv2 with AES- GCM) RSA KeyGen (SSHv2, TLSv1.2, IKEv2) ECDSA KeyGen (SSHv2, TLSv1.2 and IKEv2) RSA SigGen (SSHv2, TLSv1.2, IKEv2) ECDSA SigGen (SSHv2,"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "Private Key: G,W,E - SSH ECDSA Public Key: G,R,W - SSH Session Encryption Key: G,W,E - SSH Session Authenticatio n Key: G,W,E - DRBG Entropy Input: G,W,E - DRBG Seed: G,W,E - DRBG Internal State (V, Key): G,W,E - DRBG Internal State (V, C): G,W,E - RADIUS Secret: W - TACACS+",
            "secFunImpl": "TLSv1.2 and IKEv2) RSA SigVer (SSHv2, TLSv1.2, and IKEv2) ECDSA SigVer (SSHv2, TLSv1.2, and IKEv2) Block Cipher (SSHv2) MAC (SSHv2)"
          },
          {
            "description": "Configure HTTPS over TLSv1.2 Function",
            "indicator": "Global Indicator and HTTPS over TLSv1.2 configurat ion success status message",
            "inputs": "Command s to configure TLSv1.2",
            "name": "Configure HTTPS over TLSv1.2 Function",
            "outputs": "Status of the completion of TLSv1.2 configurati on",
            "rolesSspAccess": "Secret: W Crypto Officer - TLS DH Private Key: G,W,E - TLS DH Public Key: G,R,W - TLS Peer DH Public Key: W,E - TLS DH Shared Secret: G,W,E - TLS ECDH",
            "secFunImpl": "KAS-ECC- KeyGen (TLSv1.2) KAS-FFC- KeyGen (TLSv1.2) KAS-ECC (TLSv1.2) KAS-FFC (TLSv1.2) KTS (TLSv1.2 with AES and HMAC) KTS"
          },
          {
            "description": "Descriptio n",
            "indicator": "Indicator",
            "inputs": "Inputs",
            "name": "Name",
            "outputs": "Outputs",
            "rolesSspAccess": "SSP Access",
            "secFunImpl": "Security"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "Private Key: G,W,E - TLS ECDH Public Key: G,R,W - TLS Peer ECDH Public Key: W,E - TLS ECDH Shared Secret: G,W,E - TLS ECDSA Private Key: G,W,E - TLS ECDSA Public Key: G,R,W - TLS RSA Private Key: G,W,E - TLS RSA Public Key: G,R,W - TLS Master Secret: G,W,E - TLS Session Encryption Key: G,W,E - TLS Session Authenticatio n Key: G,W,E - DRBG Entropy Input: G,W,E - DRBG Seed: G,W,E - DRBG Internal State (V, Key): G,W,E",
            "secFunImpl": "Functions (TLSv1.2 with AES- GCM) RSA KeyGen (SSHv2, TLSv1.2, IKEv2) ECDSA KeyGen (SSHv2, TLSv1.2 and IKEv2) RSA SigGen (SSHv2, TLSv1.2, IKEv2) ECDSA SigGen (SSHv2, TLSv1.2 and IKEv2) RSA SigVer (SSHv2, TLSv1.2, and IKEv2) ECDSA SigVer (SSHv2, TLSv1.2, and IKEv2) Block Cipher (TLSv1.2) MAC (TLSv1.2)"
          },
          {
            "description": "Configure IPSec/IKEv 2 Function",
            "indicator": "Global Indicator with IPsec/IKE v2 configurat ion success status message",
            "inputs": "Command s to configure IPsec/IKEv 2",
            "name": "Configure IPsec/IKEv 2 Function",
            "outputs": "Status of the completion of IPsec/IKEv 2 configurati on",
            "rolesSspAccess": "G,W,E Crypto Officer - IPSec/IKE DH Private Key: G,W,E - IPSec/IKE DH Public Key: G,R,W - IPSec/IKE Peer DH Public Key: W,E - IPSec/IKE DH Shared Secret: G,W,E - IPSec/IKE ECDH Private Key: G,W,E - IPSec/IKE ECDH Public Key: G,R,W - IPSec/IKE Peer ECDH Public Key: W,E - IPSec/IKE ECDH Shared Secret: G,W,E - IPSec/IKE ECDSA Private Key: G,W,E - IPSec/IKE ECDSA Public Key: G,R,W - IPSec/IKE RSA Private Key: G,W,E - IPSec/IKE",
            "secFunImpl": "KAS-ECC- KeyGen (IKEv2) KAS-FFC- KeyGen (IKEv2) KAS-ECC (IKEv2) KAS-FFC (IKEv2) RSA KeyGen (SSHv2, TLSv1.2, IKEv2) ECDSA KeyGen (SSHv2, TLSv1.2 and IKEv2) RSA SigGen (SSHv2, TLSv1.2, IKEv2) ECDSA SigGen (SSHv2, TLSv1.2 and IKEv2) RSA SigVer (SSHv2, TLSv1.2, and IKEv2) ECDSA SigVer (SSHv2, TLSv1.2, and IKEv2) Block Cipher (IPSec/IKE ) MAC"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "RSA Public Key: G,R,W - IPSec/IKE Pre-shared Secret: G,W,E - SKEYSEED: G,W,E - IPSec/IKE Session Encryption Key: G,W,E - IPSec/IKE Authenticatio n Key: G,W,E - DRBG Entropy Input: G,W,E - DRBG Seed: G,W,E - DRBG Internal State (V, Key): G,W,E - DRBG Internal State (V, C):",
            "secFunImpl": "(IPSec/IKE v2)"
          },
          {
            "description": "Configure SNMPv3 Function",
            "indicator": "Global Indicator and SNMPv3 configurat ion success status message",
            "inputs": "Command s to configure SNMPv3",
            "name": "Configure SNMPv3 Function",
            "outputs": "Status of the completion of SNMPv3 configurati on",
            "rolesSspAccess": "Crypto Officer - SNMPv3 Shared Secret: W,E - SNMPv3 Encryption Key: G,W,E - SNMPv3 Authenticatio n Key: G,W,E",
            "secFunImpl": "Block Cipher (SNMPv3) MAC (SNMPv3)"
          },
          {
            "description": "Execute SSHv2 Function",
            "indicator": "Global Indicator and successfu l SSHv2",
            "inputs": "Initiate SSHv2 tunnel establishm ent",
            "name": "Run SSHv2 Function",
            "outputs": "Status of SSHv2 tunnel establishm ent",
            "rolesSspAccess": "Crypto Officer - SSH DH Private Key: G,W,E - SSH DH",
            "secFunImpl": "KAS-ECC- KeyGen (SSHv2) KAS-FFC- KeyGen (SSHv2)"
          },
          {
            "description": "Descriptio",
            "indicator": "Indicator",
            "inputs": "Inputs",
            "name": "Name",
            "outputs": "Outputs",
            "rolesSspAccess": "SSP Access",
            "secFunImpl": "Security Functions"
          },
          {
            "description": "n",
            "indicator": "log message",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "Public Key: G,R,W - SSH Peer DH Public Key: W,E - SSH DH Shared Secret: G,W,E - SSH ECDH Private Key: G,W,E - SSH ECDH Public Key: G,R,W - SSH Peer ECDH Public Key: W,E - SSH ECDH Shared Secret: G,W,E - SSH RSA Private Key: G,W,E - SSH RSA Public Key: G,R,W - SSH ECDSA Private Key: G,W,E - SSH ECDSA Public Key: G,R,W - SSH Session Encryption Key: G,W,E - SSH Session Authenticatio n Key: G,W,E - DRBG Entropy Input: G,W,E",
            "secFunImpl": "KAS-ECC (SSHv2) KAS-FFC (SSHv2) KTS (SSHv2 with AES and HMAC) KTS (SSHv2 with AES- GCM) RSA KeyGen (SSHv2, TLSv1.2, IKEv2) ECDSA KeyGen (SSHv2, TLSv1.2 and IKEv2) RSA SigGen (SSHv2, TLSv1.2, IKEv2) ECDSA SigGen (SSHv2, TLSv1.2 and IKEv2) RSA SigVer (SSHv2, TLSv1.2, and IKEv2) ECDSA SigVer (SSHv2, TLSv1.2, and IKEv2) Block Cipher (SSHv2) MAC (SSHv2)"
          },
          {
            "description": "Descriptio n",
            "indicator": "Indicator",
            "inputs": "Inputs",
            "name": "Name",
            "outputs": "Outputs",
            "rolesSspAccess": "SSP Access",
            "secFunImpl": "Security"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "- DRBG Seed: G,W,E - DRBG Internal State (V, Key): G,W,E - DRBG Internal State (V, C): G,W,E - RADIUS Secret: W,E - TACACS+ Secret: R,E User - SSH DH Private Key: G,W,E - SSH DH Public Key: G,R,W - SSH Peer DH Public Key: W,E - SSH DH Shared Secret: G,W,E - SSH ECDH Private Key: G,W,E - SSH ECDH Public Key: G,R,W - SSH Peer ECDH Public Key: W,E - SSH ECDH Shared Secret: G,W,E - SSH RSA Private Key: E - SSH RSA Public Key: R",
            "secFunImpl": "Functions"
          },
          {
            "description": "Descriptio n",
            "indicator": "Indicator",
            "inputs": "Inputs",
            "name": "Name",
            "outputs": "Outputs",
            "rolesSspAccess": "SSP Access",
            "secFunImpl": "Security"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "- SSH ECDSA Private Key: E - SSH ECDSA Public Key: R - SSH Session Encryption Key: G,W,E - SSH Session Authenticatio n Key: G,W,E - DRBG Entropy Input: G,W,E - DRBG Seed: G,W,E - DRBG Internal State (V, Key): G,W,E - DRBG Internal State (V, C): G,W,E - RADIUS Secret: E - TACACS+",
            "secFunImpl": "Functions"
          },
          {
            "description": "Execute HTTPS over TLSv1.2 function",
            "indicator": "Global Indicator and successfu l HTTPS over TLSv1.2 log message",
            "inputs": "Initiate TLSv1.2 tunnel establishm ent request",
            "name": "Run HTTPS over TLSv1.2 Function",
            "outputs": "Status of TLSv1.2 tunnel establishm ent",
            "rolesSspAccess": "Secret: R,E Crypto Officer - TLS DH Private Key: G,W,E - TLS DH Public Key: G,R,W - TLS Peer DH Public Key: W,E - TLS DH Shared Secret:",
            "secFunImpl": "KAS-ECC- KeyGen (TLSv1.2) KAS-FFC- KeyGen (TLSv1.2) KAS-ECC (TLSv1.2) KAS-FFC (TLSv1.2) KTS (TLSv1.2 with AES and"
          },
          {
            "description": "Descriptio n",
            "indicator": "Indicator",
            "inputs": "Inputs",
            "name": "Name",
            "outputs": "Outputs",
            "rolesSspAccess": "SSP Access",
            "secFunImpl": "Security"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "G,W,E - TLS ECDH Private Key: G,W,E - TLS ECDH Public Key: G,R,W - TLS Peer ECDH Public Key: W,E - TLS ECDH Shared Secret: G,W,E - TLS ECDSA Private Key: G,W,E - TLS ECDSA Public Key: G,R,W - TLS RSA Private Key: G,W,E - TLS RSA Public Key: G,R,W - TLS Master Secret: G,W,E - TLS Session Encryption Key: G,W,E - TLS Session Authenticatio n Key: G,W,E - DRBG Entropy Input: G,W,E - DRBG Seed: G,W,E - DRBG Internal",
            "secFunImpl": "Functions HMAC) KTS (TLSv1.2 with AES- GCM) RSA KeyGen (SSHv2, TLSv1.2, IKEv2) ECDSA KeyGen (SSHv2, TLSv1.2 and IKEv2) RSA SigGen (SSHv2, TLSv1.2, IKEv2) ECDSA SigGen (SSHv2, TLSv1.2 and IKEv2) RSA SigVer (SSHv2, TLSv1.2, and IKEv2) ECDSA SigVer (SSHv2, TLSv1.2, and IKEv2) Block Cipher (TLSv1.2) MAC (TLSv1.2)"
          },
          {
            "description": "Descriptio n",
            "indicator": "Indicator",
            "inputs": "Inputs",
            "name": "Name",
            "outputs": "Outputs",
            "rolesSspAccess": "SSP Access",
            "secFunImpl": "Security"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "State (V, Key): G,W,E - DRBG Internal State (V, C): G,W,E User - TLS DH Private Key: G,W,E - TLS DH Public Key: G,R,W - TLS Peer DH Public Key: W,E - TLS DH Shared Secret: G,W,E - TLS ECDH Private Key: G,W,E - TLS ECDH Public Key: G,R,W - TLS Peer ECDH Public Key: W,E - TLS ECDH Shared Secret: G,W,E - TLS ECDSA Private Key: E - TLS ECDSA Public Key: R - TLS RSA Private Key: E - TLS RSA Public Key: R - TLS Master",
            "secFunImpl": "Functions"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "Secret: G,W,E - TLS Session Encryption Key: G,W,E - TLS Session Authenticatio n Key: G,W,E - DRBG Entropy Input: G,W,E - DRBG Seed: G,W,E - DRBG Internal State (V, Key): G,W,E - DRBG Internal State (V, C):",
            "secFunImpl": ""
          },
          {
            "description": "Execute IPsec/IKEv 2 Function",
            "indicator": "Global Indicator and succesful IPsec/IKE v2 log message",
            "inputs": "Initiate IPsec/IKEv 2 tunnel establishm ent request",
            "name": "Run IPSec/IKEv 2 Function",
            "outputs": "Status of IPSec/IKE v2 tunnel establishm ent",
            "rolesSspAccess": "G,W,E Crypto Officer - IPSec/IKE DH Private Key: G,W,E - IPSec/IKE DH Public Key: G,R,W - IPSec/IKE Peer DH Public Key: W,E - IPSec/IKE DH Shared Secret: G,W,E - IPSec/IKE ECDH Private Key: G,W,E - IPSec/IKE ECDH Public Key: G,R,W",
            "secFunImpl": "KAS-ECC- KeyGen (IKEv2) KAS-FFC- KeyGen (IKEv2) KAS-ECC (IKEv2) KAS-FFC (IKEv2) RSA KeyGen (SSHv2, TLSv1.2, IKEv2) ECDSA KeyGen (SSHv2, TLSv1.2 and IKEv2) RSA SigGen (SSHv2, TLSv1.2,"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "- IPSec/IKE Peer ECDH Public Key: W,E - IPSec/IKE ECDH Shared Secret: G,W,E - IPSec/IKE ECDSA Private Key: G,W,E - IPSec/IKE ECDSA Public Key: G,R,W - IPSec/IKE RSA Private Key: G,W,E - IPSec/IKE RSA Public Key: G,R,W - IPSec/IKE Pre-shared Secret: G,W,E - SKEYSEED: G,W,E - IPSec/IKE Session Encryption Key: G,W,E - IPSec/IKE Authenticatio n Key: G,W,E - DRBG Entropy Input: G,W,E - DRBG Seed: G,W,E - DRBG Internal State (V, Key): G,W,E - DRBG",
            "secFunImpl": "IKEv2) ECDSA SigGen (SSHv2, TLSv1.2 and IKEv2) RSA SigVer (SSHv2, TLSv1.2, and IKEv2) ECDSA SigVer (SSHv2, TLSv1.2, and IKEv2) Block Cipher (IPSec/IKE ) MAC (IPSec/IKE v2)"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "Internal State (V, C): G,W,E User - IPSec/IKE DH Private Key: G,W,E - IPSec/IKE DH Public Key: G,R,W - IPSec/IKE Peer DH Public Key: W,E - IPSec/IKE DH Shared Secret: G,W,E - IPSec/IKE ECDH Private Key: G,W,E - IPSec/IKE ECDH Public Key: G,R,W - IPSec/IKE Peer ECDH Public Key: W,E - IPSec/IKE ECDH Shared Secret: G,W,E - IPSec/IKE ECDSA Private Key: E - IPSec/IKE ECDSA Public Key: R - IPSec/IKE RSA Private Key: E - IPSec/IKE RSA Public Key: R",
            "secFunImpl": ""
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "- IPSec/IKE Pre-shared Secret: G,W,E - SKEYSEED: G,W,E - IPSec/IKE Session Encryption Key: G,W,E - IPSec/IKE Authenticatio n Key: G,W,E - DRBG Entropy Input: G,W,E - DRBG Seed: G,W,E - DRBG Internal State (V, Key): G,W,E - DRBG Internal State (V, C): G,W,E",
            "secFunImpl": ""
          },
          {
            "description": "Execute SNMPv3 Function",
            "indicator": "Global Indicator and successfu l SNMPv3 log message",
            "inputs": "Initiate SNMPv3 tunnel establishm ent request",
            "name": "Run SNMPv3 Function",
            "outputs": "Status of SNMPv3 tunnel establishm ent",
            "rolesSspAccess": "Crypto Officer - SNMPv3 Shared Secret: W,E - SNMPv3 Encryption Key: G,W,E - SNMPv3 Authenticatio n Key: G,W,E User - SNMPv3 Shared Secret: W,E - SNMPv3 Encryption Key: G,W,E - SNMPv3",
            "secFunImpl": "Block Cipher (SNMPv3) MAC (SNMPv3)"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "Authenticatio n Key: G,W,E",
            "secFunImpl": ""
          },
          {
            "description": "Execute the Firmware Load Test",
            "indicator": "Global indicator and successfu l Firmware Loading status message",
            "inputs": "Command s to load new firmware image",
            "name": "Firmware Load Test",
            "outputs": "Outcome of the Firmware Load Test",
            "rolesSspAccess": "Crypto Officer - Firmware Load Test Key: R",
            "secFunImpl": "Firmware Load Test"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 3
      },
      "authentication_methods": {
        "entries": [
          {
            "description": "The minimum length is eight (8) characters (94 possible characters). The configuration supports at most ten failed attempts to authenticate in a one- minute period.",
            "mechanism": "Password Based",
            "name": "Password",
            "perMinute": "The probability of successfully authenticating to the module within one minute is 10/(94^8), which is less than 1/100,000.",
            "strength": "The probability that a random attempt will succeed or a false acceptance will occur is 1/(94^8) which is less than 1/1,000,000."
          },
          {
            "description": "The modules support RSA public-key based authentication mechanism using a minimum of RSA 2048 bits, which provides 112 bits of security strength. The probability that a random attempt will succeed is 1/(2^112) which is less than",
            "mechanism": "RSA SigVer (FIPS186-4) (A4446)",
            "name": "RSA- Based Certificate",
            "perMinute": "the probability of successfully authenticating to the module within a one minute period is 17,000 * 60 = 1,020,000/(2^112). Please refer to Description section in this table for more details",
            "strength": "The probability that a random attempt will succeed is 1/(2^112). Please refer to Description section in this table for more details"
          },
          {
            "description": "1/1,000,000. For multiple attacks during a one-minute period, as the module at its highest can support at most 17,000 new sessions per second to authenticate in a one- minute period, the probability of successfully authenticating to the module within a one minute period is 17,000 * 60 = 1,020,000/(2^112), which is less than 1/100,000.",
            "mechanism": "",
            "name": "",
            "perMinute": "",
            "strength": ""
          },
          {
            "description": "The modules support ECDSA public-key based authentication mechanism using a minimum of curve P- 256, which provides 128 bits of security strength. The probability that a random attempt will succeed is 1/(2^128) which is less than 1/1,000,000. For multiple attacks during a one-minute period, as the module at its highest can support at most 17,000 new sessions per second to authenticate in a one- minute period, the probability of successfully authenticating to the module within a one minute period is 17,000 * 60 = 1,020,000/(2^128), which is less than 1/100,000.",
            "mechanism": "ECDSA SigVer (FIPS186-4) (A4446)",
            "name": "ECDSA- Based Certificate",
            "perMinute": "the probability of successfully authenticating to the module within a one minute period is 17,000 * 60 = 1,020,000/(2^128). Please refer to Description section in this table for more details",
            "strength": "The probability that a random attempt will succeed is 1/(2^128) which is less than 1/1,000,000. Please refer to Description section in this table for more details"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 1
      },
      "cond_self_tests": {
        "entries": [
          {
            "algorithmOrTest": "AES-CBC Encrypt KAT (A4446)",
            "condition": "Power Up",
            "details": "Encrypt",
            "indicator": "Module is in normal state",
            "testMethod": "KAT",
            "testProps": "256 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-CBC Decrypt KAT (A4446)",
            "condition": "Power Up",
            "details": "Decrypt",
            "indicator": "Module is in normal state",
            "testMethod": "KAT",
            "testProps": "256 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM Authenticated Encrypt KAT (A4446)",
            "condition": "Power Up",
            "details": "Authenticated Encrypt",
            "indicator": "Module is in normal state",
            "testMethod": "KAT",
            "testProps": "256 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM Authenticated Decrypt KAT (A4446)",
            "condition": "Power Up",
            "details": "Authenticated Decrypt",
            "indicator": "Module is in normal state",
            "testMethod": "KAT",
            "testProps": "256 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "Counter DRBG Instantiate KAT (A4446)",
            "condition": "Power Up",
            "details": "Instantiate KAT",
            "indicator": "Module is in normal state",
            "testMethod": "KAT",
            "testProps": "AES-128",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "Counter DRBG Generate KAT (A4446)",
            "condition": "Power Up",
            "details": "Generate KAT",
            "indicator": "Module is in normal state",
            "testMethod": "KAT",
            "testProps": "AES-128",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "Counter DRBG Reseed KAT (A4446)",
            "condition": "Power Up",
            "details": "Reseed KAT",
            "indicator": "Module is in normal state",
            "testMethod": "KAT",
            "testProps": "AES-128",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigGen (FIPS186-4) KAT (A4446)",
            "condition": "Power Up",
            "details": "ECDSA SigGen KAT",
            "indicator": "Module is in normal state",
            "testMethod": "KAT",
            "testProps": "P-256 curve with SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigVer (FIPS186-4) KAT (A4446)",
            "condition": "Power Up",
            "details": "ECDSA SigVer KAT",
            "indicator": "Module is in normal state",
            "testMethod": "KAT",
            "testProps": "P-256 curve with SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA-1 KAT (A4446)",
            "condition": "Power Up",
            "details": "HMAC-SHA-1",
            "indicator": "Module is in normal state",
            "testMethod": "KAT",
            "testProps": "SHA-1",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA2- 256 KAT (A4446)",
            "condition": "Power Up",
            "details": "HMAC-SHA2- 256",
            "indicator": "Module is in normal state",
            "testMethod": "KAT",
            "testProps": "SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA2- 384 KAT (A4446)",
            "condition": "Power Up",
            "details": "HMAC-SHA2- 384",
            "indicator": "Module is in normal state",
            "testMethod": "KAT",
            "testProps": "SHA2-384",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA2- 512 KAT (A4446)",
            "condition": "Power Up",
            "details": "HMAC-SHA2- 512",
            "indicator": "Module is in normal state",
            "testMethod": "KAT",
            "testProps": "SHA2-512",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS-ECC- SSC Sp800- 56Ar3 KAT (A4446)",
            "condition": "Power Up",
            "details": "Primitive Z KAT",
            "indicator": "Module is in normal state",
            "testMethod": "KAT",
            "testProps": "P-256 Curve",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS-FFC- SSC Sp800- 56Ar3 KAT (A4446)",
            "condition": "Power Up",
            "details": "Primitive Z KAT",
            "indicator": "Module is in normal state",
            "testMethod": "KAT",
            "testProps": "MODP- 2048",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigGen (FIPS186-4) KAT (A4446)",
            "condition": "Power Up",
            "details": "RSA SigGen KAT",
            "indicator": "Module is in normal state",
            "testMethod": "KAT",
            "testProps": "2048 bit modulus with SHA2- 256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186-4) KAT (A4446)",
            "condition": "Power Up",
            "details": "RSA SigVer KAT",
            "indicator": "Module is in normal state",
            "testMethod": "KAT",
            "testProps": "2048 bit modulus with SHA2- 256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF IKEv2 KAT (A4446)",
            "condition": "Power Up",
            "details": "N/A",
            "indicator": "Module is in normal state",
            "testMethod": "KAT",
            "testProps": "N/A",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF SNMP KAT (A4446)",
            "condition": "Power Up",
            "details": "N/A",
            "indicator": "Module is in normal state",
            "testMethod": "KAT",
            "testProps": "N/A",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF SSH KAT (A4446)",
            "condition": "Power Up",
            "details": "N/A",
            "indicator": "Module is in normal state",
            "testMethod": "KAT",
            "testProps": "N/A",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "TLS v1.2 KDF RFC7627 KAT (A4446)",
            "condition": "Power Up",
            "details": "N/A",
            "indicator": "Module is in normal state",
            "testMethod": "KAT",
            "testProps": "N/A",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA-1 KAT (A4446)",
            "condition": "Power Up",
            "details": "N/A",
            "indicator": "Module is in normal state",
            "testMethod": "KAT",
            "testProps": "N/A",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-CBC Encrypt KAT (C1026)",
            "condition": "Power Up",
            "details": "Encrypt KAT",
            "indicator": "Module is in normal state",
            "testMethod": "KAT",
            "testProps": "128 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-CBC Decrypt KAT (C1026)",
            "condition": "Power Up",
            "details": "Decrypt KAT",
            "indicator": "Module is in normal state",
            "testMethod": "KAT",
            "testProps": "128 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM Authenticated Encrypt KAT (C1026)",
            "condition": "Power Up",
            "details": "Encrypt KAT",
            "indicator": "Module is in normal state",
            "testMethod": "KAT",
            "testProps": "128 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM Authenticated Decrypt KAT (C1026)",
            "condition": "Power Up",
            "details": "Decrypt KAT",
            "indicator": "Module is in normal state",
            "testMethod": "KAT",
            "testProps": "128 bits",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "Hash DRBG Instantiate KAT (C1026)",
            "condition": "Power Up",
            "details": "Instantiate KAT",
            "indicator": "Module is in normal state",
            "testMethod": "KAT",
            "testProps": "SHA2-512",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "Hash DRBG Generate KAT (C1026)",
            "condition": "Power Up",
            "details": "Generate KAT",
            "indicator": "Module is in normal state",
            "testMethod": "KAT",
            "testProps": "SHA2-512",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "Hash DRBG Reseed KAT (C1026)",
            "condition": "Power Up",
            "details": "Reseed KAT",
            "indicator": "Module is in normal state",
            "testMethod": "KAT",
            "testProps": "SHA2-512",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA-1 KAT (C1026)",
            "condition": "Power Up",
            "details": "HMAC-SHA-1",
            "indicator": "Module is in normal state",
            "testMethod": "KAT",
            "testProps": "SHA-1",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA2- 256 KAT (C1026)",
            "condition": "Power Up",
            "details": "HMAC-SHA2- 256",
            "indicator": "Module is in normal state",
            "testMethod": "KAT",
            "testProps": "SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA2- 384 KAT (C1026)",
            "condition": "Power Up",
            "details": "HMAC-SHA2- 384",
            "indicator": "Module is in normal state",
            "testMethod": "KAT",
            "testProps": "SHA2-384",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA2- 512 KAT (C1026)",
            "condition": "Power Up",
            "details": "HMAC-SHA2- 512",
            "indicator": "Module is in normal state",
            "testMethod": "KAT",
            "testProps": "SHA2-512",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "SHA-1 KAT (C1026)",
            "condition": "Power Up",
            "details": "N/A",
            "indicator": "Module is in normal state",
            "testMethod": "KAT",
            "testProps": "N/A",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA KeyGen (FIPS186-4) PCT (A4446)",
            "condition": "Performs all required pair-wise consistency tests on the newly generated key pairs before the first operational use.",
            "details": "ECDSA",
            "indicator": "Module is in normal state",
            "testMethod": "PCT",
            "testProps": "Curve P- 256 with SHA2-256",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "RSA KeyGen (FIPS186-4) PCT (A4446)",
            "condition": "Performs all required pair-wise consistency",
            "details": "RSA",
            "indicator": "Module is in normal state",
            "testMethod": "PCT",
            "testProps": "2048 bit Modulus",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "",
            "condition": "tests on the newly generated key pairs before the first operational use.",
            "details": "",
            "indicator": "",
            "testMethod": "",
            "testProps": "",
            "type": ""
          },
          {
            "algorithmOrTest": "KAS-ECC- SSC Sp800- 56Ar3 PCT (A4446)",
            "condition": "Performs all required pair-wise consistency tests on the newly generated key pairs before the first operational use.",
            "details": "N/A",
            "indicator": "Module is in normal state",
            "testMethod": "PCT",
            "testProps": "Curve P- 256 with SHA2-256",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "KAS-FFC- SSC Sp800- 56Ar3 PCT (A4446)",
            "condition": "Performs all required pair-wise consistency tests on the newly generated key pairs before the first operational use.",
            "details": "N/A",
            "indicator": "Module is in normal state",
            "testMethod": "PCT",
            "testProps": "MODP- 2048",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "Firmware Load Test",
            "condition": "When firmware has been uploaded to the module",
            "details": "N/A",
            "indicator": "Module is in normal state",
            "testMethod": "KAT",
            "testProps": "HMAC- SHA2-512",
            "type": "SW/FW Load"
          },
          {
            "algorithmOrTest": "Conditional Bypass",
            "condition": "Performs conditional bypass test before first operational use of bypass service",
            "details": "N/A",
            "indicator": "Module is in normal state",
            "testMethod": "N/A",
            "testProps": "N/A",
            "type": "Bypass"
          },
          {
            "algorithmOrTest": "Entropy 90B Start-up Repetition",
            "condition": "Power Up",
            "details": "Designed to quickly detect catastrophic",
            "indicator": "Module is in normal state",
            "testMethod": "RCT",
            "testProps": "Repetition Count Test",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "Count Test (RCT)",
            "condition": "",
            "details": "failures that cause the noise source to become \"stuck\" on a single output value for a long period of time",
            "indicator": "",
            "testMethod": "",
            "testProps": "",
            "type": ""
          },
          {
            "algorithmOrTest": "Entropy 90B Start-up Adaptive Proportion Test (APT)",
            "condition": "Power Up",
            "details": "Designed to detect a large loss of entropy that might occur as a result of some physical failure or environmental change affecting the noise source",
            "indicator": "Module is in normal state",
            "testMethod": "APT",
            "testProps": "Adaptive Proportion Test",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "Entropy 90B Continuous Repetition Count Test (RCT)",
            "condition": "Entropy data is generated from the Entropy Source - Continuous",
            "details": "Designed to quickly detect catastrophic failures that cause the noise source to become \"stuck\" on a single output value for a long period of time",
            "indicator": "Module is in normal state",
            "testMethod": "RCT",
            "testProps": "Repetition Count Test",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "Entropy 90B Continuous Adaptive Proportion Test (APT)",
            "condition": "Entropy data is generated from the Entropy Source - Continuous",
            "details": "Designed to detect a large loss of entropy that might occur as a result of some physical failure or environmental change affecting the noise source",
            "indicator": "Module is in normal state",
            "testMethod": "APT",
            "testProps": "Adaptive Proportion Test",
            "type": "CAST"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 2
      },
      "error_states": {
        "entries": [
          {
            "conditions": "Self-test failure",
            "description": "If self-test tests fail, the module is put into an error state",
            "indicator": "System Halt",
            "name": "Error State",
            "recoveryMethod": "Reboot the module"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 4
      },
      "mechanisms_actions": {
        "entries": [
          {
            "inspectFreq": "Recommend 30 Days",
            "inspectGuidance": "Visible inspection of platform for residual evidence of tampering",
            "mechanism": "Tamper labels (10) with Part number: AIR-AP-FIPSKIT="
          },
          {
            "inspectFreq": "Recommend 30 Days",
            "inspectGuidance": "Visible inspection of platform for evidence of tampering, removal or access",
            "mechanism": "Opacity shield (1) with Part number: FPR4200-FIPS-KIT"
          },
          {
            "inspectFreq": "N/A",
            "inspectGuidance": "N/A",
            "mechanism": "Production grade components"
          }
        ],
        "found": true,
        "section": 7,
        "subsection": 1
      },
      "modes_of_operation": {
        "entries": [
          {
            "description": "The module is always in the approved mode of operation after initial operations are performed.",
            "name": "Approved Mode of Operation",
            "statusIndicator": "Approved mode indicator: \"FIPS is currently enabled.\"",
            "type": "Approved"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 4
      },
      "non_approved_allowed_NSC": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_allowed_algos": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_not_allowed": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_services": {
        "entries": [],
        "found": false,
        "section": 4,
        "subsection": 4
      },
      "ports_interfaces": {
        "entries": [
          {
            "data": "Data input into the module for all the services defined in Approved Services Table, including TLSv1.2, SSHv2, SNMPv3 and IPsec/IKEv2 service data.",
            "logicalInterface": "Data Input",
            "physicalPort": "Ethernet Port, SFP28 (1/10/25G) port, and Console Port"
          },
          {
            "data": "Data output from the module for all the services defined in Approved Services Table, including TLSv1.2, SSHv2, SNMPv3 and IPsec/IKEv2 service data.",
            "logicalInterface": "Data Output",
            "physicalPort": "Ethernet Port, SFP28 (1/10/25G) port, and Console Port"
          },
          {
            "data": "Control Data input into the module for all the services defined in Approved Services Table, including TLSv1.2, SSHv2, SNMPv3 and IPsec/IKEv2 service data.",
            "logicalInterface": "Control Input",
            "physicalPort": "Ethernet Port, SFP28 (1/10/25G) port, Console Port and RESET"
          },
          {
            "data": "Status Information output from the module.",
            "logicalInterface": "Status Output",
            "physicalPort": "Ethernet Port, SFP28 (1/10/25G) port, Console Port and LEDs"
          },
          {
            "data": "N/A",
            "logicalInterface": "Control Output",
            "physicalPort": "N/A"
          },
          {
            "data": "Provide the Power Supply to the module.",
            "logicalInterface": "Power",
            "physicalPort": "Power"
          }
        ],
        "found": true,
        "section": 3,
        "subsection": 1
      },
      "roles": {
        "entries": [
          {
            "authMethodList": "Password RSA-Based Certificate ECDSA-Based Certificate",
            "name": "Crypto Officer",
            "operatorType": "CO",
            "type": "Identity"
          },
          {
            "authMethodList": "Password RSA-Based Certificate ECDSA-Based Certificate",
            "name": "User",
            "operatorType": "User",
            "type": "Identity"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 2
      },
      "security_levels": {
        "entries": [
          {
            "level": "2",
            "section": "1",
            "title": "General"
          },
          {
            "level": "2",
            "section": "2",
            "title": "Cryptographic module specification"
          },
          {
            "level": "2",
            "section": "3",
            "title": "Cryptographic module interfaces"
          },
          {
            "level": "3",
            "section": "4",
            "title": "Roles, services, and authentication"
          },
          {
            "level": "2",
            "section": "5",
            "title": "Software/Firmware security"
          },
          {
            "level": "N/A",
            "section": "6",
            "title": "Operational environment"
          },
          {
            "level": "2",
            "section": "7",
            "title": "Physical security"
          },
          {
            "level": "N/A",
            "section": "8",
            "title": "Non-invasive security"
          },
          {
            "level": "2",
            "section": "9",
            "title": "Sensitive security parameter management"
          },
          {
            "level": "2",
            "section": "10",
            "title": "Self-tests"
          },
          {
            "level": "2",
            "section": "11",
            "title": "Life-cycle assurance"
          },
          {
            "level": "N/A",
            "section": "12",
            "title": "Mitigation of other attacks"
          },
          {
            "level": "2",
            "section": "",
            "title": "Overall Level"
          }
        ],
        "found": true,
        "section": 1,
        "subsection": 2
      },
      "self_tests": {
        "entries": [
          {
            "algorithmOrTest": "RSA SigVer (FIPS186-4) (A4446)",
            "details": "RSA SigVer",
            "indicator": "Module is in normal state",
            "testMethod": "KAT",
            "testProps": "RSA SigVer 2048 bits with SHA2-512",
            "type": "SW/FW Integrity"
          },
          {
            "algorithmOrTest": "Pre-Operational Bypass Test",
            "details": "N/A",
            "indicator": "Module is in normal state",
            "testMethod": "N/A",
            "testProps": "N/A",
            "type": "Bypass"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 1
      },
      "ssp_io_methods": {
        "entries": [
          {
            "dest": "Module",
            "distribution": "Automated",
            "entry": "Electroni c",
            "format": "Plaintext",
            "name": "Peer Public Key Input",
            "sfiAlgo": "",
            "source": "External (Outside of the Module\u0027s Boundary )"
          },
          {
            "dest": "External (Outside of the Module\u0027s Boundary )",
            "distribution": "Automated",
            "entry": "Electroni c",
            "format": "Plaintext",
            "name": "Module Public Key Output",
            "sfiAlgo": "",
            "source": "Module"
          },
          {
            "dest": "Module",
            "distribution": "Automated",
            "entry": "Electroni c",
            "format": "Encrypte d",
            "name": "Password/Secre t Input via SSHv2 encrypted by GCM",
            "sfiAlgo": "KTS (SSHv2 with AES- GCM)",
            "source": "External (Outside of the Module\u0027s Boundary )"
          },
          {
            "dest": "Module",
            "distribution": "Automated",
            "entry": "Electroni c",
            "format": "Encrypte d",
            "name": "Password/Secre t Input via SSHv2 encrypted by AES and HMAC",
            "sfiAlgo": "KTS (SSHv2 with AES and HMAC)",
            "source": "External (Outside of the Module\u0027s Boundary )"
          },
          {
            "dest": "Module",
            "distribution": "Automated",
            "entry": "Electroni c",
            "format": "Encrypte d",
            "name": "Password/Secre t Input via TLS encrypted by GCM",
            "sfiAlgo": "KTS (TLSv1.2 with AES- GCM)",
            "source": "External (Outside of the Module\u0027s Boundary )"
          },
          {
            "dest": "Module",
            "distribution": "Automated",
            "entry": "Electroni c",
            "format": "Encrypte d",
            "name": "Password/Secre t Input via TLS encrypted by AES and HMAC",
            "sfiAlgo": "KTS (TLSv1.2 with AES and HMAC)",
            "source": "External (Outside of the Module\u0027s Boundary )"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 2
      },
      "ssp_zeroization_methods": {
        "entries": [
          {
            "description": "CO issues zeroization service",
            "method": "Zeroization Command",
            "operatorId": "\u0027configure factory- default\u0027",
            "rationale": "the zeroization command will erase all SSPs stored in the DRAM or in the Flash of the module."
          },
          {
            "description": "Zeroization upon session termination",
            "method": "Session termination",
            "operatorId": "Terminate session",
            "rationale": "Session termination will automatically zeroize all session based temporary SSPs"
          },
          {
            "description": "Zeroization upon rebooting the module",
            "method": "Reboot",
            "operatorId": "Reboot",
            "rationale": "Reboot to zeroize all temporary SSPs stored in Module\u0027s DRAM"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 3
      },
      "storage_areas": {
        "entries": [
          {
            "description": "Volatile Memory",
            "name": "DRAM",
            "persistance": "Dynamic"
          },
          {
            "description": "Non-Volatile Memory",
            "name": "Flash",
            "persistance": "Static"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 1
      },
      "tested_module_id_hw": {
        "entries": [
          {
            "features": "",
            "fwVersion": "9.20",
            "hwVersion": "FPR-4215",
            "modelPartNum": "FRP 4215",
            "processors": "AMD EPYC 7543 (Zen 3), Marvell Cavium Nitrox V CNN5560-900BG676-C45-G"
          },
          {
            "features": "",
            "fwVersion": "9.20",
            "hwVersion": "FPR-4225",
            "modelPartNum": "FRP 4225",
            "processors": "AMD EPYC 7763 (Zen 3), Marvell Cavium Nitrox V CNN5560-900BG676-C45-G"
          },
          {
            "features": "",
            "fwVersion": "9.20",
            "hwVersion": "FPR-4245",
            "modelPartNum": "FRP 4245",
            "processors": "AMD EPYC 7763 (Zen 3), Marvell Cavium Nitrox V CNN5560-900BG676-C45-G"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 2
      },
      "tested_module_id_hw_hy": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "tested_module_id_sw_fw_hy": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "tested_op_env_sw_fw_hy": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "vendor_affirmed_algos": {
        "entries": [
          {
            "algoPropList": "Key Type:Asymmetric",
            "implName": "N/A",
            "name": "CKG",
            "reference": "SP 800-133r2 Section 4, Method 1"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "vendor_affirmed_op_env_sw_fw_hy": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      }
    },
    "is_br1_format": true,
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 3
          },
          "ECDH": {
            "ECDH": 103,
            "ECDHE": 1
          },
          "ECDSA": {
            "ECDSA": 93
          }
        },
        "FF": {
          "DH": {
            "DH": 100,
            "Diffie-Hellman": 1
          },
          "DSA": {
            "DSA": 3
          }
        },
        "RSA": {
          "RSA 2048": 3
        }
      },
      "certification_process": {
        "OutOfScope": {
          "fails. Any firmware loaded into the module that is not shown on the module certificate, is out of scope of this validation and requires a separate FIPS 140-3 validation": 1,
          "out of scope": 1
        }
      },
      "cipher_mode": {
        "CTR": {
          "CTR": 1
        },
        "GCM": {
          "GCM": 24
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "IKE": {
          "IKE": 3,
          "IKEv2": 92
        },
        "IPsec": {
          "IPsec": 2
        },
        "SSH": {
          "SSH": 136,
          "SSHv2": 127
        },
        "TLS": {
          "TLS": {
            "TLS": 151,
            "TLS v1.2": 9,
            "TLSv1.2": 119
          }
        },
        "VPN": {
          "VPN": 6
        }
      },
      "crypto_scheme": {
        "MAC": {
          "MAC": 21
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-256": 34,
          "P-384": 8,
          "P-521": 12
        }
      },
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "#1": 3,
          "#2": 3,
          "#3": 3,
          "#7": 1
        }
      },
      "fips_certlike": {
        "Certlike": {
          "- PKCS 1": 2,
          "AES-128": 5,
          "AES-128/192/256": 1,
          "AES-192": 2,
          "AES-256": 2,
          "DRBG 384": 1,
          "HMAC-SHA-1": 16,
          "PKCS 1": 2,
          "RSA 2048": 3,
          "SHA-1": 12,
          "SHA2": 1,
          "SHA2- 256": 2,
          "SHA2- 384": 2,
          "SHA2- 512": 1,
          "SHA2-224": 3,
          "SHA2-256": 13,
          "SHA2-384": 5,
          "SHA2-512": 14,
          "SHA3- 256": 1
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 2": 2
        }
      },
      "hash_function": {
        "SHA": {
          "SHA1": {
            "SHA-1": 12
          },
          "SHA2": {
            "SHA2": 1
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 89
        },
        "RNG": {
          "RBG": 2
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-3": 6,
          "FIPS 180-4": 9,
          "FIPS 186-4": 8,
          "FIPS 198-1": 9,
          "FIPS186-4": 34
        },
        "ISO": {
          "ISO/IEC 19790": 2
        },
        "NIST": {
          "SP 800-135": 4,
          "SP 800-140": 1,
          "SP 800-38A": 2,
          "SP 800-38D": 2,
          "SP 800-52": 1,
          "SP 800-56A": 3,
          "SP 800-90A": 2
        },
        "PKCS": {
          "PKCS 1": 2
        },
        "RFC": {
          "RFC 3526": 2,
          "RFC 4419": 2,
          "RFC 5288": 1,
          "RFC 7296": 1,
          "RFC 7919": 2,
          "RFC7627": 6
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 27,
            "AES-": 6,
            "AES-128": 5,
            "AES-192": 2,
            "AES-256": 2
          },
          "CAST": {
            "CAST": 76
          }
        },
        "constructions": {
          "MAC": {
            "HMAC": 25
          }
        }
      },
      "tee_name": {
        "AMD": {
          "PSP": 18
        },
        "IBM": {
          "SSC": 22
        }
      },
      "tls_cipher_suite": {},
      "vendor": {
        "Cisco": {
          "Cisco": 7,
          "Cisco Systems, Inc": 80
        }
      },
      "vulnerability": {}
    },
    "module_algorithms": {
      "_type": "Set",
      "elements": [
        "SHA2-256C1026",
        "Counter DRBGA4446",
        "SHA2-224A4446",
        "Hash DRBGC1026",
        "AES-GCMC1026",
        "SHA2-512C1026",
        "KDF IKEv2A4446",
        "HMAC-SHA2-384C1026",
        "HMAC-SHA2-256C1026",
        "KDF SNMPA4446",
        "Safe Primes Key GenerationA4446",
        "SHA-1C1026",
        "KAS-FFC-SSC Sp800-56Ar3A4446",
        "ECDSA SigGen (FIPS186-4)A4446",
        "RSA SigVer (FIPS186-4)A4446",
        "RSA SigGen (FIPS186-4)A4446",
        "RSA KeyGen (FIPS186-4)A4446",
        "HMAC-SHA2-512C1026",
        "KAS-ECC-SSC Sp800-56Ar3A4446",
        "ECDSA KeyGen (FIPS186-4)A4446",
        "HMAC-SHA-1C1026",
        "AES-CBCC1026",
        "TLS v1.2 KDF RFC7627A4446",
        "ECDSA SigVer (FIPS186-4)A4446",
        "SHA2-384C1026",
        "HMAC-SHA2-224A4446",
        "KDF SSHA4446"
      ]
    },
    "policy_algorithms": {
      "_type": "Set",
      "elements": [
        "#A4446",
        "#C1026"
      ]
    },
    "policy_metadata": {
      "/Author": "Hawes, David J. (Fed)",
      "/ClassificationContentMarkingFooterFontProps": "#000000,8,Calibri",
      "/ClassificationContentMarkingFooterShapeIds": "76b99bd2,3faae116,5e41b8de",
      "/ClassificationContentMarkingFooterText": "Cisco Confidential",
      "/Comments": "",
      "/Company": "",
      "/CreationDate": "D:20250922090837-04\u002700\u0027",
      "/Creator": "Acrobat PDFMaker 25 for Word",
      "/Keywords": "",
      "/MSIP_Label_c8f49a32-fde3-48a5-9266-b5b0972a22dc_ActionId": "8e222a41-a2fa-4afa-aea3-427b99154667",
      "/MSIP_Label_c8f49a32-fde3-48a5-9266-b5b0972a22dc_ContentBits": "2",
      "/MSIP_Label_c8f49a32-fde3-48a5-9266-b5b0972a22dc_Enabled": "true",
      "/MSIP_Label_c8f49a32-fde3-48a5-9266-b5b0972a22dc_Method": "Standard",
      "/MSIP_Label_c8f49a32-fde3-48a5-9266-b5b0972a22dc_Name": "Cisco Confidential",
      "/MSIP_Label_c8f49a32-fde3-48a5-9266-b5b0972a22dc_SetDate": "2024-05-08T11:43:39Z",
      "/MSIP_Label_c8f49a32-fde3-48a5-9266-b5b0972a22dc_SiteId": "5ae1af62-9505-4097-a69a-c1553ef7840e",
      "/ModDate": "D:20250922091052-04\u002700\u0027",
      "/Producer": "Adobe PDF Library 25.1.51",
      "/SourceModified": "",
      "/Subject": "",
      "/Title": "",
      "pdf_file_size_bytes": 1294490,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "https://www.cisco.com/c/en/us/products/collateral/security/firewalls/secure-firewall-4200-ds.html",
          "https://www.cisco.com/c/en/us/td/docs/security/asa/asa923/asdm723/general/asdm-723-general-config.html",
          "https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/threat-defense/use-case/multi-instance-sec-fw/multi-instance-sec-fw.html",
          "https://www.cisco.com/c/en/us/td/docs/security/asa/special/cluster-sec-fw/secure-firewall-cluster.html"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 75
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.InternalState",
    "module": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "policy": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": "866d627e4d6a51f06013ad8cfe543c4e17c23f9fce3f01d66188f28d52b1cb86",
      "source_hash": "c469f57e1b34c3a59699c90748b165299201fe9b8b66ed52251b21e804407c88",
      "txt_hash": "2bee5b46d6a4508306511a840ac417bfb81e2ef6d4567f6b0fa65f9cc7748421"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When installed, initialized and configured as specified in Section Life-Cycle Assurance of the Security Policy. The tamper evident seals installed as indicated in the Security Policy",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/November 2025_181225_1202.pdf",
    "date_sunset": "2030-09-21",
    "description": "Next generation security services on Cisco Firepower 4200 Series, capable of running multiple (firewall (NGFW), traffic management) security services simultaneously.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Roles, services, and authentication: Level 3",
      "Operational environment: N/A",
      "Non-invasive security: N/A",
      "Mitigation of other attacks: N/A"
    ],
    "fw_versions": null,
    "historical_reason": null,
    "hw_versions": null,
    "level": 2,
    "mentioned_certs": {},
    "module_name": "Cisco Adaptive Security Appliance Cryptographic Module (FPR 4200 Series)",
    "module_type": "Hardware",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-3",
    "status": "active",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2025-09-22",
        "lab": "Gossamer Security Solutions",
        "validation_type": "Initial"
      }
    ],
    "vendor": "Cisco Systems, Inc.",
    "vendor_url": "http://www.cisco.com"
  }
}