This page was not yet optimized for use on mobile devices.
Cisco Adaptive Security Appliance Cryptographic Module (FPR 3100 Series)
Certificate details
| Certificate ID | #4966 |
|---|---|
| Status | active |
| Validation dates | 14.02.2025 |
| Sunset date | 13-02-2030 |
| Standard | FIPS 140-3 |
| Security level | 2 |
| Type | Hardware |
| Embodiment | Multi-Chip Stand Alone |
| Caveat | When installed, initialized and configured as specified in Section "Life-Cycle Assurance" of the Security Policy. The tamper evident seals and opacity shields installed as indicated in Section "Physical Security" of the Security Policy. |
| Exceptions |
|
| Description | The market-leading Cisco ASA delivering robust user and application policy enforcement, multi-vector attack protection, and secure connectivity services in cost-effective, easy-to-deploy solutions. The ASA provides comprehensive security, performance, and reliability for network environments. |
| Vendor | Cisco Systems, Inc. http://www.cisco.com |
| Lab | Gossamer Security Solutions |
| Algorithms |
|
| References | This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates. |
Security policy
Extracted keywords
Symmetric Algorithms
AES-128, AES-192, AES-256, AES, AES-, CAST, HMACAsymmetric Algorithms
RSA 2048, ECDH, ECDHE, ECDSA, ECC, Diffie-Hellman, DHHash functions
SHA-1Schemes
MAC, Key AgreementProtocols
SSHv2, SSH, TLS v1.2, TLSv1.2, TLS, IKEv2, IKE, IPsec, VPNRandomness
DRBG, RBGElliptic Curves
P-256, P-384, P-521Block cipher modes
CTR, GCMTrusted Execution Environments
PSP, SSCVendor
Cisco Systems, Inc, CiscoSecurity level
Level 2Certification process
out of scope, fails. Any firmware loaded into the module that is not shown on the module certificate, is out of scope of this validation and requires a separate FIPS 140-3 validationStandards
FIPS 140-3, FIPS186-4, FIPS 186-4, FIPS 198-1, FIPS 180-4, FIPS140-3, SP 800-140, SP 800-38A, SP 800-38D, SP 800-90A, SP 800-56A, SP 800-135, SP 800-52, NIST SP 800-90A, PKCS 1, RFC7627, RFC 5288, RFC 7296, ISO/IEC 19790Automated analysis
Automated inference - use with caution
All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.No automatically derived data are available in this section.
Cross-references
No references are available for this certificate.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate was first processed.
{
"_type": "sec_certs.sample.fips.FIPSCertificate",
"cert_id": 4966,
"dgst": "1a5fd4b21080a2de",
"heuristics": {
"_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
"algorithms": {
"_type": "Set",
"elements": [
"SHA2-256C1026",
"Counter DRBGA4446",
"SHA2-224A4446",
"Hash DRBGC1026",
"AES-GCMC1026",
"SHA2-512C1026",
"KDF IKEv2A4446",
"#A4446",
"HMAC-SHA2-384C1026",
"HMAC-SHA2-256C1026",
"KDF SNMPA4446",
"Safe Primes Key GenerationA4446",
"SHA-1C1026",
"KAS-FFC-SSC Sp800-56Ar3A4446",
"ECDSA SigGen (FIPS186-4)A4446",
"RSA SigVer (FIPS186-4)A4446",
"RSA SigGen (FIPS186-4)A4446",
"RSA KeyGen (FIPS186-4)A4446",
"HMAC-SHA2-512C1026",
"KAS-ECC-SSC Sp800-56Ar3A4446",
"ECDSA KeyGen (FIPS186-4)A4446",
"HMAC-SHA-1C1026",
"AES-CBCC1026",
"#C1026",
"TLS v1.2 KDF RFC7627A4446",
"ECDSA SigVer (FIPS186-4)A4446",
"SHA2-384C1026",
"HMAC-SHA2-224A4446",
"KDF SSHA4446"
]
},
"cpe_matches": null,
"direct_transitive_cves": null,
"extracted_versions": {
"_type": "Set",
"elements": [
"3100"
]
},
"indirect_transitive_cves": null,
"module_processed_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": null,
"indirectly_referenced_by": null,
"indirectly_referencing": null
},
"module_prunned_references": {
"_type": "Set",
"elements": []
},
"policy_processed_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": null,
"indirectly_referenced_by": null,
"indirectly_referencing": null
},
"policy_prunned_references": {
"_type": "Set",
"elements": []
},
"related_cves": null,
"verified_cpe_matches": null
},
"pdf_data": {
"_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
"br1_deviations": 0,
"br1_tables": {
"_type": "sec_certs.heuristics.br1.table_parsing.model.br1_tables.BR1Tables",
"approved_algorithms": {
"entries": [
{
"algorithm": "AES-CBC",
"cavpCertName": "A4446",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-GCM",
"cavpCertName": "A4446",
"properties": "Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256",
"reference": "SP 800-38D"
},
{
"algorithm": "Counter DRBG",
"cavpCertName": "A4446",
"properties": "Prediction Resistance - Yes Mode - AES-128, AES-192, AES-256 Derivation Function Enabled - Yes",
"reference": "SP 800-90A Rev. 1"
},
{
"algorithm": "ECDSA KeyGen (FIPS186-4)",
"cavpCertName": "A4446",
"properties": "Curve - P-256, P-384, P-521",
"reference": "FIPS 186-4"
},
{
"algorithm": "ECDSA SigGen (FIPS186-4)",
"cavpCertName": "A4446",
"properties": "Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-224, SHA2-256, SHA2-384, SHA2-512",
"reference": "FIPS 186-4"
},
{
"algorithm": "ECDSA SigVer (FIPS186-4)",
"cavpCertName": "A4446",
"properties": "Curve - P-256, P-384, P-521",
"reference": "FIPS 186-4"
},
{
"algorithm": "HMAC-SHA-1",
"cavpCertName": "A4446",
"properties": "Key Length - Key Length: 256-448 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA2-224",
"cavpCertName": "A4446",
"properties": "Key Length - Key Length: 256-448 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA2-256",
"cavpCertName": "A4446",
"properties": "Key Length - Key Length: 256-448 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA2-384",
"cavpCertName": "A4446",
"properties": "Key Length - Key Length: 256-448 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA2-512",
"cavpCertName": "A4446",
"properties": "Key Length - Key Length: 256-448 Increment 8",
"reference": "FIPS 198-1"
},
{
"algorithm": "KAS-ECC-SSC Sp800-56Ar3",
"cavpCertName": "A4446",
"properties": "Domain Parameter Generation Methods - P- 256, P-384, P-521",
"reference": "SP 800-56A Rev. 3"
},
{
"algorithm": "KAS-FFC-SSC Sp800-56Ar3",
"cavpCertName": "A4446",
"properties": "Domain Parameter Generation Methods - ffdhe2048, ffdhe3072, ffdhe4096, modp-2048, modp-3072, modp-4096",
"reference": "SP 800-56A Rev. 3"
},
{
"algorithm": "KDF IKEv2 (CVL)",
"cavpCertName": "A4446",
"properties": "Diffie-Hellman Shared Secret Length - Diffie- Hellman Shared Secret Length: 2048 Derived Keying Material Length - Derived Keying Material Length: 3072 Hash Algorithm - SHA-1",
"reference": "SP 800-135 Rev. 1"
},
{
"algorithm": "KDF SNMP (CVL)",
"cavpCertName": "A4446",
"properties": "Password Length - Password Length: 256, 64",
"reference": "SP 800-135 Rev. 1"
},
{
"algorithm": "KDF SSH (CVL)",
"cavpCertName": "A4446",
"properties": "Cipher - AES-128, AES-192, AES-256",
"reference": "SP 800-135 Rev. 1"
},
{
"algorithm": "RSA KeyGen (FIPS186-4)",
"cavpCertName": "A4446",
"properties": "Key Generation Mode - B.3.4 Modulo - 2048, 3072, 4096 Hash Algorithm - SHA2-256 Private Key Format - Standard",
"reference": "FIPS 186-4"
},
{
"algorithm": "RSA SigGen (FIPS186-4)",
"cavpCertName": "A4446",
"properties": "Signature Type - ANSI X9.31, PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096",
"reference": "FIPS 186-4"
},
{
"algorithm": "RSA SigVer (FIPS186-4)",
"cavpCertName": "A4446",
"properties": "Signature Type - ANSI X9.31, PKCS 1.5, PKCSPSS Modulo - 1024, 2048, 3072, 4096",
"reference": "FIPS 186-4"
},
{
"algorithm": "Safe Primes Key Generation",
"cavpCertName": "A4446",
"properties": "Safe Prime Groups - modp-2048, modp-3072, modp-4096",
"reference": "SP 800-56A Rev. 3"
},
{
"algorithm": "SHA-1",
"cavpCertName": "A4446",
"properties": "Message Length - Message Length: 0-65536 Increment 8",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2-224",
"cavpCertName": "A4446",
"properties": "Message Length - Message Length: 0-65536 Increment 8",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2-256",
"cavpCertName": "A4446",
"properties": "Message Length - Message Length: 0-65536 Increment 8",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2-384",
"cavpCertName": "A4446",
"properties": "Message Length - Message Length: 0-65536 Increment 8",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2-512",
"cavpCertName": "A4446",
"properties": "Message Length - Message Length: 0-65536 Increment 8",
"reference": "FIPS 180-4"
},
{
"algorithm": "TLS v1.2 KDF RFC7627 (CVL)",
"cavpCertName": "A4446",
"properties": "Hash Algorithm - SHA2-256, SHA2-384, SHA2-512",
"reference": "SP 800-135 Rev. 1"
},
{
"algorithm": "AES-CBC",
"cavpCertName": "C1026",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-GCM",
"cavpCertName": "C1026",
"properties": "Direction - Decrypt, Encrypt IV Generation - External Key Length - 128, 192, 256",
"reference": "SP 800-38D"
},
{
"algorithm": "Hash DRBG",
"cavpCertName": "C1026",
"properties": "Prediction Resistance - No Mode - SHA2-512",
"reference": "SP 800-90A Rev. 1"
},
{
"algorithm": "HMAC-SHA-1",
"cavpCertName": "C1026",
"properties": "-",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA2- 256",
"cavpCertName": "C1026",
"properties": "-",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA2- 384",
"cavpCertName": "C1026",
"properties": "-",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA2- 512",
"cavpCertName": "C1026",
"properties": "-",
"reference": "FIPS 198-1"
},
{
"algorithm": "SHA-1",
"cavpCertName": "C1026",
"properties": "Message Length - Message Length: 0- 51200 Increment 8",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2-256",
"cavpCertName": "C1026",
"properties": "Message Length - Message Length: 0- 51200 Increment 8",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2-384",
"cavpCertName": "C1026",
"properties": "Message Length - Message Length: 0- 102400 Increment 8",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2-512",
"cavpCertName": "C1026",
"properties": "Message Length - Message Length: 0- 102400 Increment 8",
"reference": "FIPS 180-4"
}
],
"found": true,
"section": 2,
"subsection": 5
},
"approved_services": {
"entries": [
{
"description": "Provide Module\u0027s current status (return",
"indicator": "N/A",
"inputs": "Command used to show Module\u0027s Status",
"name": "Show Status",
"outputs": "Module\u0027s Operationa l Status",
"rolesSspAccess": "Crypto Officer User",
"secFunImpl": "None"
},
{
"description": "codes and/or syslog messages)",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "",
"secFunImpl": ""
},
{
"description": "Provide Module\u0027s name and version information",
"indicator": "N/A",
"inputs": "Command to show version",
"name": "Show Version",
"outputs": "Module\u0027s ID and versioning information",
"rolesSspAccess": "Crypto Officer User",
"secFunImpl": "None"
},
{
"description": "Perform Self-Tests (Pre- operational self-test and Conditional Self-Tests)",
"indicator": "N/A",
"inputs": "Command to trigger Self-Test",
"name": "Perform Self-Tests",
"outputs": "Status of the self- tests results",
"rolesSspAccess": "Crypto Officer User Unauthentic ated",
"secFunImpl": "None"
},
{
"description": "Perform Zeroization",
"indicator": "Syslog message",
"inputs": "Command to zeroize the module",
"name": "Perform Zeroization",
"outputs": "Status of the SSPs zeroization",
"rolesSspAccess": "Crypto Officer - DRBG Entropy Input: Z - DRBG Seed: Z - DRBG Internal State V value: Z - DRBG Key: Z - User Password: Z - Crypto Officer Password: Z - RADIUS Secret: Z - TACACS+ Secret: Z - Firmware Load Test Key: Z - SSH DH Private Key: Z - SSH DH Public Key: Z",
"secFunImpl": "None"
},
{
"description": "Descriptio n",
"indicator": "Indicator",
"inputs": "Inputs",
"name": "Name",
"outputs": "Outputs",
"rolesSspAccess": "SSP Access",
"secFunImpl": "Security"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "- SSH Peer DH Public Key: Z - SSH DH Shared Secret: Z - SSH ECDH Private Key: Z - SSH ECDH Public Key: Z - SSH Peer ECDH Public Key: Z - SSH ECDH Shared Secret: Z - SSH RSA Private Key: Z - SSH RSA Public Key: Z - SSH ECDSA Private Key: Z - SSH ECDSA Public Key: Z - SSH Session Encryption Key: Z - SSH Session Authenticatio n Key: Z - TLS DH Private Key: Z - TLS DH Public Key: Z - TLS Peer DH Public",
"secFunImpl": "Functions"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "Key: Z - TLS DH Shared Secret: Z - TLS ECDH Private Key: Z - TLS ECDH Public Key: Z - TLS Peer ECDH Public Key: Z - TLS ECDH Shared Secret: Z - TLS ECDSA Private Key: Z - TLS ECDSA Public Key: Z - TLS RSA Private Key: Z - TLS RSA Public Key: Z - TLS Master Secret: Z - TLS Session Encryption Key: Z - TLS Session Authenticatio n Key: Z - IPSec/IKE DH Private Key: Z - IPSec/IKE DH Public Key: Z - IPSec/IKE Peer DH",
"secFunImpl": ""
},
{
"description": "Descriptio n",
"indicator": "Indicator",
"inputs": "Inputs",
"name": "Name",
"outputs": "Outputs",
"rolesSspAccess": "SSP Access",
"secFunImpl": "Security"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "Public Key: Z - IPSec/IKE DH Shared Secret: Z - IPSec/IKE ECDH Private Key: Z - IPSec/IKE ECDH Public Key: Z - IPSec/IKE Peer ECDH Public Key: Z - IPSec/IKE ECDH Shared Secret: Z - IPSec/IKE ECDSA Private Key: Z - IPSec/IKE ECDSA Public Key: Z - IPSec/IKE RSA Private Key: Z - IPSec/IKE RSA Public Key: Z - IPSec/IKE Pre-shared Secret: Z - SKEYSEED: Z - IPSec/IKE Session Encryption Key: Z - IPSec/IKE Authenticatio n Key: Z - SNMPv3",
"secFunImpl": "Functions"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "Shared Secret: Z - SNMPv3 Encryption Key: Z - SNMPv3 Authenticatio n Key: Z",
"secFunImpl": ""
},
{
"description": "Sets configurati on of the systems",
"indicator": "None",
"inputs": "Command s to configure the network",
"name": "Configure Network",
"outputs": "Status of the completion of network configurati on status",
"rolesSspAccess": "Crypto Officer",
"secFunImpl": "None"
},
{
"description": "CO Role Authenticat ion",
"indicator": "N/A",
"inputs": "CO Authenticat ion Request",
"name": "Crypto Officer Authenticat ion",
"outputs": "Status of the CO authenticat ion",
"rolesSspAccess": "Crypto Officer - Crypto Officer Password: W,Z",
"secFunImpl": "None"
},
{
"description": "User Role Authenticat ion",
"indicator": "N/A",
"inputs": "User role authenticat ion request",
"name": "User Authenticat ion",
"outputs": "Status of the User role authenticat ion",
"rolesSspAccess": "User - User Password: W,Z",
"secFunImpl": "None"
},
{
"description": "Sets the Bypass capability",
"indicator": "None",
"inputs": "CLI Bypass commands",
"name": "Configure Bypass Capability",
"outputs": "Status of the completion of Bypass capability configurati on",
"rolesSspAccess": "Crypto Officer",
"secFunImpl": "None"
},
{
"description": "Configure SSHv2 Function",
"indicator": "Global Indicator and SSHv2 configurat ion success status message",
"inputs": "Command s to configure SSHv2",
"name": "Configure SSHv2 Function",
"outputs": "Status of the completion of the SSHv2 configurati on",
"rolesSspAccess": "Crypto Officer - SSH DH Private Key: W,E - SSH DH Public Key: W,E - SSH Peer DH Public Key: W,E - SSH DH Shared Secret: W,E - SSH ECDH Private Key:",
"secFunImpl": "KAS-FFC (SSHv2) KAS-ECC (SSHv2) KTS (SSHv2 with AES and HMAC) KTS (SSHv2 with AES- GCM) RSA KeyGen (SSHv2,"
},
{
"description": "Descriptio",
"indicator": "Indicator",
"inputs": "Inputs",
"name": "Name",
"outputs": "Outputs",
"rolesSspAccess": "SSP Access",
"secFunImpl": "Security Functions"
},
{
"description": "n",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "W,E - SSH ECDH Public Key: W,E - SSH Peer ECDH Public Key: W,E - SSH ECDH Shared Secret: W,E - SSH RSA Private Key: W,E - SSH RSA Public Key: W,E - SSH ECDSA Private Key: W,E - SSH ECDSA Public Key: W,E - SSH Session Encryption Key: W,E - SSH Session Authenticatio n Key: W,E - DRBG Entropy Input: W,E - DRBG Seed: W,E - DRBG Internal State V value: W,E - DRBG Key: W,E",
"secFunImpl": "TLSv1.2, IKEv2) ECDSA KeyGen (SSHv2, TLSv1.2 and IKEv2) RSA SigGen (SSHv2, TLSv1.2, IKEv2) ECDSA SigGen (SSHv2, TLSv1.2 and IKEv2) RSA SigVer (SSHv2, TLSv1.2, and IKEv2) ECDSA SigVer (SSHv2, TLSv1.2, and IKEv2) Block Cipher (SSHv2) MAC (SSHv2) KAS-ECC- KeyGen (SSHv2) KAS-FFC- KeyGen (SSHv2) DRBG Function SSHv2 Keying Materials Developm ent"
},
{
"description": "Configure HTTPS over",
"indicator": "Global Indicator and HTTPS",
"inputs": "Command s to configure TLSv1.2",
"name": "Configure HTTPS over",
"outputs": "Status of the completion of TLSv1.2",
"rolesSspAccess": "Crypto Officer - TLS DH Private Key:",
"secFunImpl": "KAS-FFC (TLSv1.2) KAS-ECC (TLSv1.2)"
},
{
"description": "TLSv1.2 Function",
"indicator": "over TLSv1.2 configurat ion success status message",
"inputs": "",
"name": "TLSv1.2 Function",
"outputs": "configurati on",
"rolesSspAccess": "W,E - TLS DH Public Key: W,E - TLS Peer DH Public Key: W,E - TLS DH Shared Secret: W,E - TLS ECDH Private Key: W,E - TLS ECDH Public Key: W,E - TLS Peer ECDH Public Key: W,E - TLS ECDH Shared Secret: W,E - TLS ECDSA Private Key: W,E - TLS ECDSA Public Key: W,E - TLS RSA Private Key: W,E - TLS RSA Public Key: W,E - TLS Master Secret: W,E - TLS Session Encryption Key: W,E - TLS Session Authenticatio n Key: W,E - DRBG Entropy",
"secFunImpl": "KTS (TLSv1.2 with AES and HMAC) KTS (TLSv1.2 with AES- GCM) RSA KeyGen (SSHv2, TLSv1.2, IKEv2) ECDSA KeyGen (SSHv2, TLSv1.2 and IKEv2) RSA SigGen (SSHv2, TLSv1.2, IKEv2) ECDSA SigGen (SSHv2, TLSv1.2 and IKEv2) RSA SigVer (SSHv2, TLSv1.2, and IKEv2) ECDSA SigVer (SSHv2, TLSv1.2, and IKEv2) Block Cipher (TLSv1.2) MAC (TLSv1.2) KAS-ECC- KeyGen (TLSv1.2) KAS-FFC- KeyGen"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "Input: W,E - DRBG Seed: W,E - DRBG Internal State V value: W,E - DRBG Key: W,E",
"secFunImpl": "(TLSv1.2) TLS Keying Materials Developm ent DRBG Function"
},
{
"description": "Configure IPSec/IKEv 2 Function",
"indicator": "Global Indicator with IPsec/IKE v2 configurat ion success status message",
"inputs": "Command s to configure IPsec/IKEv 2",
"name": "Configure IPsec/IKEv 2 Function",
"outputs": "Status of the completion of IPsec/IKEv 2 configurati on",
"rolesSspAccess": "Crypto Officer - IPSec/IKE DH Private Key: W,E - IPSec/IKE DH Public Key: W,E - IPSec/IKE Peer DH Public Key: W,E - IPSec/IKE DH Shared Secret: W,E - IPSec/IKE ECDH Private Key: W,E - IPSec/IKE ECDH Public Key: W,E - IPSec/IKE Peer ECDH Public Key: W,E - IPSec/IKE ECDH Shared Secret: W,E - IPSec/IKE ECDSA Private Key: W,E - IPSec/IKE ECDSA Public Key: W,E - IPSec/IKE",
"secFunImpl": "KAS-ECC (IKEv2) KAS-FFC (IKEv2) RSA KeyGen (SSHv2, TLSv1.2, IKEv2) ECDSA KeyGen (SSHv2, TLSv1.2 and IKEv2) RSA SigGen (SSHv2, TLSv1.2, IKEv2) ECDSA SigGen (SSHv2, TLSv1.2 and IKEv2) RSA SigVer (SSHv2, TLSv1.2, and IKEv2) ECDSA SigVer (SSHv2, TLSv1.2, and IKEv2) Block Cipher (IPSec/IKE v2) MAC (IPSec/IKE"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "RSA Private Key: W,E - IPSec/IKE RSA Public Key: W,E - IPSec/IKE Pre-shared Secret: W,E - SKEYSEED: W,E - IPSec/IKE Session Encryption Key: W,E - IPSec/IKE Authenticatio n Key: W,E - DRBG Entropy Input: W,E - DRBG Seed: W,E - DRBG Internal State V value: W,E - DRBG Key: W,E",
"secFunImpl": "v2) KAS-ECC- KeyGen (IKEv2) KAS-FFC- KeyGen (IKEv2) IKEv2 Keying Materials Developm ent DRBG Function"
},
{
"description": "Execute SSHv2 Function",
"indicator": "Global Indicator and successfu l SSHv2 log message",
"inputs": "Initiate SSHv2 tunnel establishm ent",
"name": "Run SSHv2 Function",
"outputs": "Status of SSHv2 tunnel establishm ent",
"rolesSspAccess": "Crypto Officer - SSH DH Private Key: W,E - SSH DH Public Key: W,E - SSH Peer DH Public Key: W,E - SSH DH Shared Secret: W,E - SSH ECDH Private Key: W,E - SSH ECDH Public Key: W,E",
"secFunImpl": "KAS-FFC (SSHv2) KAS-ECC (SSHv2) KTS (SSHv2 with AES and HMAC) KTS (SSHv2 with AES- GCM) RSA KeyGen (SSHv2, TLSv1.2, IKEv2) ECDSA KeyGen"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "- SSH Peer ECDH Public Key: W,E - SSH ECDH Shared Secret: W,E - SSH RSA Private Key: W,E - SSH RSA Public Key: W,E - SSH ECDSA Private Key: W,E - SSH ECDSA Public Key: W,E - SSH Session Encryption Key: W,E - SSH Session Authenticatio n Key: W,E - DRBG Entropy Input: W,E - DRBG Seed: W,E - DRBG Internal State V value: W,E - DRBG Key: W,E User - SSH DH Private Key: W,E - SSH DH Public Key: W,E - SSH Peer DH Public",
"secFunImpl": "(SSHv2, TLSv1.2 and IKEv2) RSA SigGen (SSHv2, TLSv1.2, IKEv2) ECDSA SigGen (SSHv2, TLSv1.2 and IKEv2) RSA SigVer (SSHv2, TLSv1.2, and IKEv2) ECDSA SigVer (SSHv2, TLSv1.2, and IKEv2) Block Cipher (SSHv2) MAC (SSHv2) KAS-ECC- KeyGen (SSHv2) KAS-FFC- KeyGen (SSHv2) DRBG Function SSHv2 Keying Materials Developm ent"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "Key: W,E - SSH DH Shared Secret: W,E - SSH ECDH Private Key: W,E - SSH ECDH Public Key: W,E - SSH Peer ECDH Public Key: W,E - SSH ECDH Shared Secret: W,E - SSH RSA Private Key: W,E - SSH RSA Public Key: W,E - SSH ECDSA Private Key: W,E - SSH ECDSA Public Key: W,E - SSH Session Encryption Key: W,E - SSH Session Authenticatio n Key: W,E - DRBG Entropy Input: W,E - DRBG Seed: W,E - DRBG Internal State V value: W,E",
"secFunImpl": ""
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "- DRBG Key: W,E",
"secFunImpl": ""
},
{
"description": "Execute HTTPS over TLSv1.2 function",
"indicator": "Global Indicator and successfu l HTTPS over TLSv1.2 log message",
"inputs": "Initiate TLSv1.2 tunnel establishm ent request",
"name": "Run HTTPS over TLSv1.2 Function",
"outputs": "Status of TLSv1.2 tunnel establishm ent",
"rolesSspAccess": "Crypto Officer - TLS DH Private Key: W,E - TLS DH Public Key: W,E - TLS Peer DH Public Key: W,E - TLS DH Shared Secret: W,E - TLS ECDH Private Key: W,E - TLS ECDH Public Key: W,E - TLS Peer ECDH Public Key: W,E - TLS ECDH Shared Secret: W,E - TLS ECDSA Private Key: W,E - TLS ECDSA Public Key: W,E - TLS RSA Private Key: W,E - TLS RSA Public Key: W,E - TLS Master Secret: W,E - TLS Session Encryption Key: W,E",
"secFunImpl": "KAS-FFC (TLSv1.2) KAS-ECC (TLSv1.2) KTS (TLSv1.2 with AES and HMAC) KTS (TLSv1.2 with AES- GCM) RSA KeyGen (SSHv2, TLSv1.2, IKEv2) ECDSA KeyGen (SSHv2, TLSv1.2 and IKEv2) RSA SigGen (SSHv2, TLSv1.2, IKEv2) ECDSA SigGen (SSHv2, TLSv1.2 and IKEv2) RSA SigVer (SSHv2, TLSv1.2, and IKEv2) ECDSA SigVer (SSHv2, TLSv1.2, and IKEv2) Block Cipher (TLSv1.2) MAC"
},
{
"description": "Descriptio",
"indicator": "Indicator",
"inputs": "Inputs",
"name": "Name",
"outputs": "Outputs",
"rolesSspAccess": "SSP Access",
"secFunImpl": "Security Functions"
},
{
"description": "n",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "- TLS Session Authenticatio n Key: W,E - DRBG Entropy Input: W,E - DRBG Seed: W,E - DRBG Internal State V value: W,E - DRBG Key: W,E User - TLS DH Private Key: W,E - TLS DH Public Key: W,E - TLS Peer DH Public Key: W,E - TLS DH Shared Secret: W,E - TLS ECDH Private Key: W,E - TLS ECDH Public Key: W,E - TLS Peer ECDH Public Key: W,E - TLS ECDH Shared Secret: W,E - TLS ECDSA Private Key: W,E - TLS ECDSA Public Key: W,E",
"secFunImpl": "(TLSv1.2) KAS-ECC- KeyGen (SSHv2) KAS-FFC- KeyGen (SSHv2) DRBG Function SSHv2 Keying Materials Developm ent"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "- TLS RSA Private Key: W,E - TLS RSA Public Key: W,E - TLS Master Secret: W,E - TLS Session Encryption Key: W,E - TLS Session Authenticatio n Key: W,E - DRBG Entropy Input: W,E - DRBG Seed: W,E - DRBG Internal State V value: W,E - DRBG Key:",
"secFunImpl": ""
},
{
"description": "Execute IPsec/IKEv 2 Function",
"indicator": "Global Indicator and succesful IPsec/IKE v2 log message",
"inputs": "Initiate IPsec/IKEv 2 tunnel establishm ent request",
"name": "Run IPSec/IKEv 2 Function",
"outputs": "Status of IPSec/IKE v2 tunnel establishm ent",
"rolesSspAccess": "W,E Crypto Officer - IPSec/IKE DH Private Key: W,E - IPSec/IKE DH Public Key: W,E - IPSec/IKE Peer DH Public Key: W,E - IPSec/IKE DH Shared Secret: W,E - IPSec/IKE ECDH Private Key: W,E - IPSec/IKE ECDH Public Key:",
"secFunImpl": "KAS-ECC (IKEv2) KAS-FFC (IKEv2) RSA KeyGen (SSHv2, TLSv1.2, IKEv2) ECDSA KeyGen (SSHv2, TLSv1.2 and IKEv2) RSA SigGen (SSHv2, TLSv1.2, IKEv2) ECDSA SigGen (SSHv2,"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "W,E - IPSec/IKE Peer ECDH Public Key: W,E - IPSec/IKE ECDH Shared Secret: W,E - IPSec/IKE ECDSA Private Key: W,E - IPSec/IKE ECDSA Public Key: W,E - IPSec/IKE RSA Private Key: W,E - IPSec/IKE RSA Public Key: W,E - IPSec/IKE Pre-shared Secret: W,E - SKEYSEED: W,E - IPSec/IKE Session Encryption Key: W,E - IPSec/IKE Authenticatio n Key: W,E - DRBG Entropy Input: W,E - DRBG Seed: W,E - DRBG Internal State V value: W,E - DRBG Key: W,E User - IPSec/IKE",
"secFunImpl": "TLSv1.2 and IKEv2) RSA SigVer (SSHv2, TLSv1.2, and IKEv2) ECDSA SigVer (SSHv2, TLSv1.2, and IKEv2) Block Cipher (IPSec/IKE v2) MAC (IPSec/IKE v2) KAS-ECC- KeyGen (IKEv2) KAS-FFC- KeyGen (IKEv2) IKEv2 Keying Materials Developm ent DRBG Function"
},
{
"description": "Descriptio n",
"indicator": "Indicator",
"inputs": "Inputs",
"name": "Name",
"outputs": "Outputs",
"rolesSspAccess": "SSP Access",
"secFunImpl": "Security"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "DH Private Key: W,E - IPSec/IKE DH Public Key: W,E - IPSec/IKE Peer DH Public Key: W,E - IPSec/IKE DH Shared Secret: W,E - IPSec/IKE ECDH Private Key: W,E - IPSec/IKE ECDH Public Key: W,E - IPSec/IKE Peer ECDH Public Key: W,E - IPSec/IKE ECDH Shared Secret: W,E - IPSec/IKE ECDSA Private Key: W,E - IPSec/IKE ECDSA Public Key: W,E - IPSec/IKE RSA Private Key: W,E - IPSec/IKE RSA Public Key: W,E - IPSec/IKE Pre-shared Secret: W,E - SKEYSEED: W,E - IPSec/IKE",
"secFunImpl": "Functions"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "Session Encryption Key: W,E - IPSec/IKE Authenticatio n Key: W,E - DRBG Entropy Input: W,E - DRBG Seed: W,E - DRBG Internal State V value: W,E - DRBG Key: W,E",
"secFunImpl": ""
},
{
"description": "Configure SNMPv3 Function",
"indicator": "Global Indicator and SNMPv3 configurat ion success status message",
"inputs": "Command s to configure SNMPv3",
"name": "Configure SNMPv3 Function",
"outputs": "Status of the completion of SNMPv3 configurati on",
"rolesSspAccess": "Crypto Officer - SNMPv3 Shared Secret: W,E - SNMPv3 Encryption Key: W,E - SNMPv3 Authenticatio n Key: W,E",
"secFunImpl": "Block Cipher (SNMPv3) MAC (SNMPv3) SNMPv3 Keying Materials Developm ent"
},
{
"description": "Execute SNMPv3 Function",
"indicator": "Global Indicator and successfu l SNMPv3 log message",
"inputs": "Initiate SNMPv3 tunnel establishm ent request",
"name": "Run SNMPv3 Function",
"outputs": "Status of SNMPv3 tunnel establishm ent",
"rolesSspAccess": "Crypto Officer User",
"secFunImpl": "Block Cipher (SNMPv3) MAC (SNMPv3) SNMPv3 Keying Materials Developm ent"
},
{
"description": "Execute the Firmware Load Test",
"indicator": "Global indicator and successfu l Firmware Loading status message",
"inputs": "Command s to load new firmware image",
"name": "Firmware Load Test",
"outputs": "Outcome of the Firmware Load Test",
"rolesSspAccess": "Crypto Officer - Firmware Load Test Key: R",
"secFunImpl": "Firmware Load Test"
}
],
"found": true,
"section": 4,
"subsection": 3
},
"authentication_methods": {
"entries": [
{
"description": "The minimum length is eight (8) characters (94",
"mechanism": "Password Based",
"name": "Password",
"perMinute": "The probability of successfully",
"strength": "The probability that a random"
},
{
"description": "possible characters). The configuration supports at most ten failed attempts to authenticate in a one- minute period.",
"mechanism": "",
"name": "",
"perMinute": "authenticating to the module within one minute is 10/(94^8), which is less than 1/100,000.",
"strength": "attempt will succeed or a false acceptance will occur is 1/(94^8) which is less than 1/1,000,000."
},
{
"description": "The modules support RSA public-key based authentication mechanism using a minimum of RSA 2048 bits, which provides 112 bits of security strength. The probability that a random attempt will succeed is 1/(2^112) which is less than 1/1,000,000. For multiple attacks during a one-minute period, as the module at its highest can support at most 17,000 new sessions per second to authenticate in a one- minute period, the probability of successfully authenticating to the module within a one minute period is 17,000 * 60 = 1,020,000/(2^112), which is less than 1/100,000.",
"mechanism": "RSA SigVer (FIPS186-4) (A4446)",
"name": "RSA- Based Certificate",
"perMinute": "the probability of successfully authenticating to the module within a one minute period is 17,000 * 60 = 1,020,000/(2^112). Please refer to Description section in this table for more details",
"strength": "The probability that a random attempt will succeed is 1/(2^112). Please refer to Description section in this table for more details"
},
{
"description": "The modules support ECDSA public-key based authentication mechanism using a minimum of curve P- 256, which provides 128 bits of security strength. The probability that a random attempt will succeed is 1/(2^128) which is less than 1/1,000,000. For",
"mechanism": "ECDSA SigVer (FIPS186-4) (A4446)",
"name": "ECDSA- Based Certificate",
"perMinute": "the probability of successfully authenticating to the module within a one minute period is 17,000 * 60 = 1,020,000/(2^128). Please refer to Description section in this table for more details",
"strength": "The probability that a random attempt will succeed is 1/(2^128) which is less than 1/1,000,000. Please refer to Description section in this"
},
{
"description": "multiple attacks during a one-minute period, as the module at its highest can support at most 17,000 new sessions per second to authenticate in a one- minute period, the probability of successfully authenticating to the module within a one minute period is 17,000 * 60 = 1,020,000/(2^128), which is less than 1/100,000.",
"mechanism": "",
"name": "",
"perMinute": "",
"strength": "table for more details"
}
],
"found": true,
"section": 4,
"subsection": 1
},
"cond_self_tests": {
"entries": [
{
"algorithmOrTest": "AES-CBC (A4446)",
"condition": "Power Up",
"details": "Encrypt",
"indicator": "Module is in normal state",
"testMethod": "KAT",
"testProps": "256 bits",
"type": "CAST"
},
{
"algorithmOrTest": "AES-CBC (A4446)",
"condition": "Power Up",
"details": "Decrypt",
"indicator": "Module is in normal state",
"testMethod": "KAT",
"testProps": "256 bits",
"type": "CAST"
},
{
"algorithmOrTest": "AES-GCM (A4446)",
"condition": "Power Up",
"details": "Authenticated Encrypt",
"indicator": "Module is in normal state",
"testMethod": "KAT",
"testProps": "256 bits",
"type": "CAST"
},
{
"algorithmOrTest": "AES-GCM (A4446)",
"condition": "Power Up",
"details": "Authenticated Decrypt",
"indicator": "Module is in normal state",
"testMethod": "KAT",
"testProps": "256 bits",
"type": "CAST"
},
{
"algorithmOrTest": "Counter DRBG (A4446)",
"condition": "Power Up",
"details": "Instantiate KAT",
"indicator": "Module is in normal state",
"testMethod": "KAT",
"testProps": "AES-128",
"type": "CAST"
},
{
"algorithmOrTest": "Counter DRBG (A4446)",
"condition": "Power Up",
"details": "Generate KAT",
"indicator": "Module is in normal state",
"testMethod": "KAT",
"testProps": "AES-128",
"type": "CAST"
},
{
"algorithmOrTest": "Counter DRBG (A4446)",
"condition": "Power Up",
"details": "Reseed KAT",
"indicator": "Module is in normal state",
"testMethod": "KAT",
"testProps": "AES-128",
"type": "CAST"
},
{
"algorithmOrTest": "ECDSA SigGen (FIPS186-4) (A4446)",
"condition": "Power Up",
"details": "ECDSA SigGen KAT",
"indicator": "Module is in normal state",
"testMethod": "KAT",
"testProps": "P-256 curve with SHA2- 256",
"type": "CAST"
},
{
"algorithmOrTest": "ECDSA SigVer (FIPS186-4) (A4446)",
"condition": "Power Up",
"details": "ECDSA SigVer KAT",
"indicator": "Module is in normal state",
"testMethod": "KAT",
"testProps": "P-256 curve with SHA2- 256",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC- SHA-1 (A4446)",
"condition": "Power Up",
"details": "HMAC-SHA-1",
"indicator": "Module is in normal state",
"testMethod": "KAT",
"testProps": "SHA-1",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC- SHA2-256 (A4446)",
"condition": "Power Up",
"details": "HMAC-SHA2- 256",
"indicator": "Module is in normal state",
"testMethod": "KAT",
"testProps": "SHA2-256",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC- SHA2-384 (A4446)",
"condition": "Power Up",
"details": "HMAC-SHA2- 384",
"indicator": "Module is in normal state",
"testMethod": "KAT",
"testProps": "SHA2-384",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC- SHA2-512 (A4446)",
"condition": "Power Up",
"details": "HMAC-SHA2- 512",
"indicator": "Module is in normal state",
"testMethod": "KAT",
"testProps": "SHA2-512",
"type": "CAST"
},
{
"algorithmOrTest": "KAS-ECC- SSC Sp800- 56Ar3 (A4446)",
"condition": "Power Up",
"details": "Primitive Z KAT",
"indicator": "Module is in normal state",
"testMethod": "KAT",
"testProps": "P-256 Curve",
"type": "CAST"
},
{
"algorithmOrTest": "KAS-FFC- SSC Sp800- 56Ar3",
"condition": "Power Up",
"details": "Primitive Z KAT",
"indicator": "Module is in normal state",
"testMethod": "KAT",
"testProps": "MODP- 2048",
"type": "CAST"
},
{
"algorithmOrTest": "(A4446) RSA SigGen (FIPS186-4) (A4446)",
"condition": "Power Up",
"details": "RSA SigGen KAT",
"indicator": "Module is in normal state",
"testMethod": "KAT",
"testProps": "2048 bit modulus with SHA2- 256",
"type": "CAST"
},
{
"algorithmOrTest": "RSA SigVer (FIPS186-4) (A4446)",
"condition": "Power Up",
"details": "RSA SigVer KAT",
"indicator": "Module is in normal state",
"testMethod": "KAT",
"testProps": "2048 bit modulus with SHA2- 256",
"type": "CAST"
},
{
"algorithmOrTest": "KDF IKEv2 (A4446)",
"condition": "Power Up",
"details": "N/A",
"indicator": "Module is in normal state",
"testMethod": "KAT",
"testProps": "N/A",
"type": "CAST"
},
{
"algorithmOrTest": "KDF SNMP (A4446)",
"condition": "Power Up",
"details": "N/A",
"indicator": "Module is in normal state",
"testMethod": "KAT",
"testProps": "N/A",
"type": "CAST"
},
{
"algorithmOrTest": "KDF SSH (A4446)",
"condition": "Power Up",
"details": "N/A",
"indicator": "Module is in normal state",
"testMethod": "KAT",
"testProps": "N/A",
"type": "CAST"
},
{
"algorithmOrTest": "TLS v1.2 KDF RFC7627 (A4446)",
"condition": "Power Up",
"details": "N/A",
"indicator": "Module is in normal state",
"testMethod": "KAT",
"testProps": "N/A",
"type": "CAST"
},
{
"algorithmOrTest": "SHA-1 (A4446)",
"condition": "Power Up",
"details": "N/A",
"indicator": "Module is in normal state",
"testMethod": "KAT",
"testProps": "Message Length: 0- 65536 Increment 8",
"type": "CAST"
},
{
"algorithmOrTest": "AES-CBC (C1026)",
"condition": "Power Up",
"details": "Encrypt KAT",
"indicator": "Module is in normal state",
"testMethod": "KAT",
"testProps": "128 bits",
"type": "CAST"
},
{
"algorithmOrTest": "AES-CBC (C1026)",
"condition": "Power Up",
"details": "Decrypt KAT",
"indicator": "Module is in normal state",
"testMethod": "KAT",
"testProps": "128 bits",
"type": "CAST"
},
{
"algorithmOrTest": "AES-GCM (C1026)",
"condition": "Power Up",
"details": "Encrypt KAT",
"indicator": "Module is in normal state",
"testMethod": "KAT",
"testProps": "128 bits",
"type": "CAST"
},
{
"algorithmOrTest": "AES-GCM (C1026)",
"condition": "Power Up",
"details": "Decrypt KAT",
"indicator": "Module is in normal state",
"testMethod": "KAT",
"testProps": "128 bits",
"type": "CAST"
},
{
"algorithmOrTest": "Hash DRBG (C1026)",
"condition": "Power Up",
"details": "Instantiate KAT",
"indicator": "Module is in normal state",
"testMethod": "KAT",
"testProps": "SHA2-512",
"type": "CAST"
},
{
"algorithmOrTest": "Hash DRBG (C1026)",
"condition": "Power Up",
"details": "Generate KAT",
"indicator": "Module is in normal state",
"testMethod": "KAT",
"testProps": "SHA2-512",
"type": "CAST"
},
{
"algorithmOrTest": "Hash DRBG (C1026)",
"condition": "Power Up",
"details": "Reseed KAT",
"indicator": "Module is in normal state",
"testMethod": "KAT",
"testProps": "SHA2-512",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC- SHA-1 (C1026)",
"condition": "Power Up",
"details": "HMAC-SHA-1",
"indicator": "Module is in normal state",
"testMethod": "KAT",
"testProps": "SHA-1",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC- SHA2-256 (C1026)",
"condition": "Power Up",
"details": "HMAC-SHA2- 256",
"indicator": "Module is in normal state",
"testMethod": "KAT",
"testProps": "SHA2-256",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC- SHA2-384 (C1026)",
"condition": "Power Up",
"details": "HMAC-SHA2- 384",
"indicator": "Module is in normal state",
"testMethod": "KAT",
"testProps": "SHA2-384",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC- SHA2-512 (C1026)",
"condition": "Power Up",
"details": "HMAC-SHA2- 512",
"indicator": "Module is in normal state",
"testMethod": "KAT",
"testProps": "SHA2-512",
"type": "CAST"
},
{
"algorithmOrTest": "SHA-1 (C1026)",
"condition": "Power Up",
"details": "SHA-1",
"indicator": "Module is in normal state",
"testMethod": "KAT",
"testProps": "Message Length: 0- 51200 Increment 8",
"type": "CAST"
},
{
"algorithmOrTest": "ECDSA KeyGen (FIPS186-4) (A4446)",
"condition": "Performs all required pair- wise consistency tests on the newly generated key pairs before the first operational use.",
"details": "ECDSA",
"indicator": "Module is in normal state",
"testMethod": "PCT",
"testProps": "Curve P- 256 with SHA2-256",
"type": "PCT"
},
{
"algorithmOrTest": "RSA KeyGen",
"condition": "Performs all required pair- wise",
"details": "RSA",
"indicator": "Module is in normal state",
"testMethod": "PCT",
"testProps": "2048 bit Modulus",
"type": "PCT"
},
{
"algorithmOrTest": "(FIPS186-4) (A4446)",
"condition": "consistency tests on the newly generated key pairs before the first operational use.",
"details": "",
"indicator": "",
"testMethod": "",
"testProps": "",
"type": ""
},
{
"algorithmOrTest": "KAS-ECC- SSC Sp800- 56Ar3 (A4446)",
"condition": "Performs all required pair- wise consistency tests on the newly generated key pairs before the first operational use.",
"details": "N/A",
"indicator": "Module is in normal state",
"testMethod": "PCT",
"testProps": "Curve P- 256 with SHA2-256",
"type": "PCT"
},
{
"algorithmOrTest": "KAS-FFC- SSC Sp800- 56Ar3 (A4446)",
"condition": "Performs all required pair- wise consistency tests on the newly generated key pairs before the first operational use.",
"details": "N/A",
"indicator": "Module is in normal state",
"testMethod": "PCT",
"testProps": "MODP- 2048",
"type": "PCT"
},
{
"algorithmOrTest": "HMAC- SHA2-512 (A4446)",
"condition": "When firmware has been uploaded to the module",
"details": "N/A",
"indicator": "Module is in normal state",
"testMethod": "KAT",
"testProps": "HMAC- SHA2-512",
"type": "SW/FW Load"
},
{
"algorithmOrTest": "Conditional Bypass",
"condition": "Performs conditional bypass test before first operational use of bypass service",
"details": "N/A",
"indicator": "Module is in normal state",
"testMethod": "N/A",
"testProps": "N/A",
"type": "Bypass"
}
],
"found": true,
"section": 10,
"subsection": 2
},
"error_states": {
"entries": [
{
"conditions": "Self-test failure",
"description": "If self-test tests fail, the module is put into an error state",
"indicator": "System Halt",
"name": "Error State",
"recoveryMethod": "Reboot the module"
}
],
"found": true,
"section": 10,
"subsection": 4
},
"mechanisms_actions": {
"entries": [
{
"inspectFreq": "Recommend 30 Days",
"inspectGuidance": "Visible inspection of platform for residual evidence of tampering",
"mechanism": "Tamper labels (9) with Part number: AIR-AP-FIPSKIT="
},
{
"inspectFreq": "Recommend 30 Days",
"inspectGuidance": "Visible inspection of platform for evidence of tampering, removal or access",
"mechanism": "Opacity shield (1) with Part number: FPR3K-FIPS-KIT="
}
],
"found": true,
"section": 7,
"subsection": 1
},
"modes_of_operation": {
"entries": [
{
"description": "The module is always in the approved mode of operation after initial operations are performed.",
"name": "Approved Mode of Operation",
"statusIndicator": "Approved mode indicator: \"FIPS is currently enabled.\"",
"type": "Approved"
}
],
"found": true,
"section": 2,
"subsection": 4
},
"non_approved_allowed_NSC": {
"entries": [],
"found": false,
"section": 2,
"subsection": 5
},
"non_approved_allowed_algos": {
"entries": [],
"found": false,
"section": 2,
"subsection": 5
},
"non_approved_not_allowed": {
"entries": [],
"found": false,
"section": 2,
"subsection": 5
},
"non_approved_services": {
"entries": [],
"found": false,
"section": 4,
"subsection": 4
},
"ports_interfaces": {
"entries": [
{
"data": "Data input into the module for all the services defined in Approved Services Table, including TLSv1.2, SSHv2, SNMPv3 and IPsec/IKEv2 service data.",
"logicalInterface": "Data Input",
"physicalPort": "Ethernet Port, SFP (1G) port, SFP+ (10G) port, and Console Port"
},
{
"data": "Data output from the module for all the services defined in Approved Services Table, including TLSv1.2, SSHv2, SNMPv3 and IPsec/IKEv2 service data.",
"logicalInterface": "Data Output",
"physicalPort": "Ethernet Port, SFP (1G) port, SFP+ (10G) port and Console Port"
},
{
"data": "Control Data input into the module for all the services defined in Approved Services Table, including TLSv1.2, SSHv2, SNMPv3 and IPsec/IKEv2 service data.",
"logicalInterface": "Control Input",
"physicalPort": "Ethernet Port, SFP (1G) port, SFP+ (10G) port, Console Port and RESET"
},
{
"data": "Status Information output from the module.",
"logicalInterface": "Status Output",
"physicalPort": "Ethernet Port, SFP (1G) port, SFP+ (10G) port, Console Port and LEDs"
},
{
"data": "N/A",
"logicalInterface": "Control Output",
"physicalPort": "N/A"
},
{
"data": "Provide the Power Supply to the module.",
"logicalInterface": "Power",
"physicalPort": "Power"
}
],
"found": true,
"section": 3,
"subsection": 1
},
"roles": {
"entries": [
{
"authMethodList": "Password RSA-Based Certificate ECDSA-Based Certificate",
"name": "Crypto Officer",
"operatorType": "CO",
"type": "Identity"
},
{
"authMethodList": "Password RSA-Based Certificate ECDSA-Based Certificate",
"name": "User",
"operatorType": "User",
"type": "Identity"
}
],
"found": true,
"section": 4,
"subsection": 2
},
"security_levels": {
"entries": [
{
"level": "2",
"section": "1",
"title": "General"
},
{
"level": "2",
"section": "2",
"title": "Cryptographic module specification"
},
{
"level": "2",
"section": "3",
"title": "Cryptographic module interfaces"
},
{
"level": "3",
"section": "4",
"title": "Roles, services, and authentication"
},
{
"level": "2",
"section": "5",
"title": "Software/Firmware security"
},
{
"level": "N/A",
"section": "6",
"title": "Operational environment"
},
{
"level": "2",
"section": "7",
"title": "Physical security"
},
{
"level": "N/A",
"section": "8",
"title": "Non-invasive security"
},
{
"level": "2",
"section": "9",
"title": "Sensitive security parameter management"
},
{
"level": "2",
"section": "10",
"title": "Self-tests"
},
{
"level": "2",
"section": "11",
"title": "Life-cycle assurance"
},
{
"level": "N/A",
"section": "12",
"title": "Mitigation of other attacks"
},
{
"level": "2",
"section": "",
"title": "Overall Level"
}
],
"found": true,
"section": 1,
"subsection": 2
},
"self_tests": {
"entries": [
{
"algorithmOrTest": "RSA SigVer (FIPS186-4) (A4446)",
"details": "RSA SigVer",
"indicator": "Module is in normal state",
"testMethod": "KAT",
"testProps": "RSA SigVer 2048 bits with SHA2-512",
"type": "SW/FW Integrity"
},
{
"algorithmOrTest": "Pre-Operational Bypass Test",
"details": "N/A",
"indicator": "Module is in normal state",
"testMethod": "N/A",
"testProps": "N/A",
"type": "Bypass"
}
],
"found": true,
"section": 10,
"subsection": 1
},
"ssp_io_methods": {
"entries": [
{
"dest": "Module",
"distribution": "Automated",
"entry": "Electroni c",
"format": "Encrypte d",
"name": "Password/Secre t Input via TLS encrypted by GCM",
"sfiAlgo": "KTS (TLSv1.2 with AES- GCM)",
"source": "External (Outside of the Module\u0027s Boundary )"
},
{
"dest": "Module",
"distribution": "Automated",
"entry": "Electroni c",
"format": "Encrypte d",
"name": "Password/Secre t Input via TLS encrypted by AES and HMAC",
"sfiAlgo": "KTS (TLSv1.2 with AES and HMAC)",
"source": "External (Outside of the Module\u0027s Boundary )"
},
{
"dest": "Module",
"distribution": "Automated",
"entry": "Electroni c",
"format": "Plaintext",
"name": "Peer Public Key Input",
"sfiAlgo": "",
"source": "External (Outside of the Module\u0027s"
},
{
"dest": "External (Outside of the Module\u0027s Boundary )",
"distribution": "Automated",
"entry": "Electroni c",
"format": "Plaintext",
"name": "Module Public Key Output",
"sfiAlgo": "",
"source": "Module"
},
{
"dest": "Module",
"distribution": "Automated",
"entry": "Electroni c",
"format": "Encrypte d",
"name": "Password/Secre t Input via SSHv2 encrypted by GCM",
"sfiAlgo": "KTS (SSHv2 with AES- GCM)",
"source": "External (Outside of the Module\u0027s Boundary )"
},
{
"dest": "Module",
"distribution": "Automated",
"entry": "Electroni c",
"format": "Encrypte d",
"name": "Password/Secre t Input via SSHv2 encrypted by AES and HMAC",
"sfiAlgo": "KTS (SSHv2 with AES and HMAC)",
"source": "External (Outside of the Module\u0027s Boundary )"
}
],
"found": true,
"section": 9,
"subsection": 2
},
"ssp_zeroization_methods": {
"entries": [
{
"description": "CO issues zeroization service",
"method": "Zeroization Command",
"operatorId": "\u0027configure factory-default\u0027",
"rationale": "the zeroization command will erase all SSPs stored in the DRAM or in the Flash of the module."
}
],
"found": true,
"section": 9,
"subsection": 3
},
"storage_areas": {
"entries": [
{
"description": "Volatile Memory",
"name": "DRAM",
"persistance": "Dynamic"
},
{
"description": "Non-Volatile Memory",
"name": "Flash",
"persistance": "Static"
}
],
"found": true,
"section": 9,
"subsection": 1
},
"tested_module_id_hw": {
"entries": [
{
"features": "",
"fwVersion": "9.20",
"hwVersion": "FPR-3105",
"modelPartNum": "FRP 3105",
"processors": "AMD EPYC 7272 (Zen2) \u0026 NITROX-V, Marvell Semiconductor, NITROX"
},
{
"features": "",
"fwVersion": "9.20",
"hwVersion": "FPR-3110",
"modelPartNum": "FRP 3110",
"processors": "AMD EPYC 7272 (Zen2) \u0026 NITROX-V, Marvell Semiconductor, NITROX"
},
{
"features": "",
"fwVersion": "9.20",
"hwVersion": "FPR-3120",
"modelPartNum": "FRP 3120",
"processors": "AMD EPYC 7282 (Zen2) \u0026 NITROX-V, Marvell Semiconductor, NITROX"
},
{
"features": "",
"fwVersion": "9.20",
"hwVersion": "FPR-3130",
"modelPartNum": "FRP 3130",
"processors": "AMD EPYC 7352 (Zen2) \u0026 NITROX-V, Marvell Semiconductor, NITROX"
},
{
"features": "",
"fwVersion": "9.20",
"hwVersion": "FPR-3140",
"modelPartNum": "FRP 3140",
"processors": "AMD EPYC 7452 (Zen2) \u0026 NITROX-V, Marvell Semiconductor, NITROX"
}
],
"found": true,
"section": 2,
"subsection": 2
},
"tested_module_id_hw_hy": {
"entries": [],
"found": false,
"section": 2,
"subsection": 2
},
"tested_module_id_sw_fw_hy": {
"entries": [],
"found": false,
"section": 2,
"subsection": 2
},
"tested_op_env_sw_fw_hy": {
"entries": [],
"found": false,
"section": 2,
"subsection": 2
},
"vendor_affirmed_algos": {
"entries": [
{
"algoPropList": "Key Type:Asymmetric",
"implName": "CiscoSSL FOM Cryptographic Implementation",
"name": "CKG",
"reference": "The cryptographic module performs Cryptographic Key Generation (CKG) for asymmetric keys as per sections 4 and 5 in SP800-133rev2 (vendor affirmed) and FIPS"
},
{
"algoPropList": "",
"implName": "",
"name": "",
"reference": "140-3 IG D.H. A seed (i.e., the random value) used in asymmetric key generation is a direct output from SP800-90Arev1 CTR_DRBG (A4446) or HMAC_DRBG (C1026)"
}
],
"found": true,
"section": 2,
"subsection": 5
},
"vendor_affirmed_op_env_sw_fw_hy": {
"entries": [],
"found": false,
"section": 2,
"subsection": 2
}
},
"is_br1_format": true,
"keywords": {
"asymmetric_crypto": {
"ECC": {
"ECC": {
"ECC": 5
},
"ECDH": {
"ECDH": 103,
"ECDHE": 1
},
"ECDSA": {
"ECDSA": 96
}
},
"FF": {
"DH": {
"DH": 100,
"Diffie-Hellman": 1
}
},
"RSA": {
"RSA 2048": 2
}
},
"certification_process": {
"OutOfScope": {
"fails. Any firmware loaded into the module that is not shown on the module certificate, is out of scope of this validation and requires a separate FIPS 140-3 validation": 1,
"out of scope": 1
}
},
"cipher_mode": {
"CTR": {
"CTR": 1
},
"GCM": {
"GCM": 22
}
},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {},
"crypto_protocol": {
"IKE": {
"IKE": 5,
"IKEv2": 120
},
"IPsec": {
"IPsec": 2
},
"SSH": {
"SSH": 138,
"SSHv2": 154
},
"TLS": {
"TLS": {
"TLS": 153,
"TLS v1.2": 8,
"TLSv1.2": 133
}
},
"VPN": {
"VPN": 2
}
},
"crypto_scheme": {
"KA": {
"Key Agreement": 6
},
"MAC": {
"MAC": 21
}
},
"device_model": {},
"ecc_curve": {
"NIST": {
"P-256": 34,
"P-384": 8,
"P-521": 12
}
},
"eval_facility": {},
"fips_cert_id": {
"Cert": {
"#1": 3,
"#2": 3,
"#3": 3,
"#9": 1
}
},
"fips_certlike": {
"Certlike": {
"AES-128": 5,
"AES-192": 2,
"AES-256": 2,
"DRBG 384": 1,
"HMAC- SHA-1": 2,
"HMAC-SHA-1": 24,
"PKCS 1": 4,
"RSA 2048": 2,
"SHA-1": 18,
"SHA2- 256": 4,
"SHA2-224": 3,
"SHA2-256": 14,
"SHA2-384": 10,
"SHA2-512": 18,
"SHA3- 256": 1
}
},
"fips_security_level": {
"Level": {
"Level 2": 2
}
},
"hash_function": {
"SHA": {
"SHA1": {
"SHA-1": 18
}
}
},
"ic_data_group": {},
"javacard_api_const": {},
"javacard_packages": {},
"javacard_version": {},
"os_name": {},
"pq_crypto": {},
"randomness": {
"PRNG": {
"DRBG": 113
},
"RNG": {
"RBG": 2
}
},
"side_channel_analysis": {},
"standard_id": {
"FIPS": {
"FIPS 140-3": 6,
"FIPS 180-4": 9,
"FIPS 186-4": 7,
"FIPS 198-1": 9,
"FIPS140-3": 6,
"FIPS186-4": 28
},
"ISO": {
"ISO/IEC 19790": 2
},
"NIST": {
"NIST SP 800-90A": 1,
"SP 800-135": 4,
"SP 800-140": 1,
"SP 800-38A": 2,
"SP 800-38D": 2,
"SP 800-52": 1,
"SP 800-56A": 3,
"SP 800-90A": 2
},
"PKCS": {
"PKCS 1": 2
},
"RFC": {
"RFC 5288": 1,
"RFC 7296": 1,
"RFC7627": 7
}
},
"symmetric_crypto": {
"AES_competition": {
"AES": {
"AES": 25,
"AES-": 6,
"AES-128": 5,
"AES-192": 2,
"AES-256": 2
},
"CAST": {
"CAST": 68
}
},
"constructions": {
"MAC": {
"HMAC": 22
}
}
},
"tee_name": {
"AMD": {
"PSP": 18
},
"IBM": {
"SSC": 4
}
},
"tls_cipher_suite": {},
"vendor": {
"Cisco": {
"Cisco": 4,
"Cisco Systems, Inc": 72
}
},
"vulnerability": {}
},
"module_algorithms": {
"_type": "Set",
"elements": [
"SHA2-256C1026",
"Counter DRBGA4446",
"SHA2-224A4446",
"Hash DRBGC1026",
"AES-GCMC1026",
"SHA2-512C1026",
"KDF IKEv2A4446",
"HMAC-SHA2-384C1026",
"HMAC-SHA2-256C1026",
"KDF SNMPA4446",
"Safe Primes Key GenerationA4446",
"SHA-1C1026",
"KAS-FFC-SSC Sp800-56Ar3A4446",
"ECDSA SigGen (FIPS186-4)A4446",
"RSA SigVer (FIPS186-4)A4446",
"RSA SigGen (FIPS186-4)A4446",
"RSA KeyGen (FIPS186-4)A4446",
"HMAC-SHA2-512C1026",
"KAS-ECC-SSC Sp800-56Ar3A4446",
"ECDSA KeyGen (FIPS186-4)A4446",
"HMAC-SHA-1C1026",
"AES-CBCC1026",
"TLS v1.2 KDF RFC7627A4446",
"ECDSA SigVer (FIPS186-4)A4446",
"SHA2-384C1026",
"HMAC-SHA2-224A4446",
"KDF SSHA4446"
]
},
"policy_algorithms": {
"_type": "Set",
"elements": [
"#A4446",
"#C1026"
]
},
"policy_metadata": {
"/Author": "Hawes, David J. (Fed)",
"/Comments": "",
"/Company": "",
"/CreationDate": "D:20250214102422-05\u002700\u0027",
"/Creator": "Acrobat PDFMaker 24 for Word",
"/Keywords": "",
"/ModDate": "D:20250214102553-05\u002700\u0027",
"/Producer": "Adobe PDF Library 24.5.96",
"/SourceModified": "",
"/Subject": "",
"/Title": "",
"pdf_file_size_bytes": 1294036,
"pdf_hyperlinks": {
"_type": "Set",
"elements": []
},
"pdf_is_encrypted": false,
"pdf_number_of_pages": 67
}
},
"state": {
"_type": "sec_certs.sample.fips.InternalState",
"module": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": null,
"source_hash": null,
"txt_hash": null
},
"policy": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": "5076d0db9e559970d1ef35bd3e7fa4dbb733356d06e637b8b1dc051666a7ace9",
"source_hash": "a6a68e12cb7839a29c936100efea3681af03d1633113fd717e537ec4293469da",
"txt_hash": "f5a2773ad67314d4d1972688ac151bd961011cbbb72e25335b2e2cd6bbae4f96"
}
},
"web_data": {
"_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
"caveat": "When installed, initialized and configured as specified in Section \"Life-Cycle Assurance\" of the Security Policy. The tamper evident seals and opacity shields installed as indicated in Section \"Physical Security\" of the Security Policy.",
"certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/February 2025_030325_1258.pdf",
"date_sunset": "2030-02-13",
"description": "The market-leading Cisco ASA delivering robust user and application policy enforcement, multi-vector attack protection, and secure connectivity services in cost-effective, easy-to-deploy solutions. The ASA provides comprehensive security, performance, and reliability for network environments.",
"embodiment": "Multi-Chip Stand Alone",
"exceptions": [
"Roles, services, and authentication: Level 3",
"Operational environment: N/A",
"Non-invasive security: N/A",
"Mitigation of other attacks: N/A"
],
"fw_versions": null,
"historical_reason": null,
"hw_versions": null,
"level": 2,
"mentioned_certs": {},
"module_name": "Cisco Adaptive Security Appliance Cryptographic Module (FPR 3100 Series)",
"module_type": "Hardware",
"revoked_link": null,
"revoked_reason": null,
"standard": "FIPS 140-3",
"status": "active",
"sw_versions": null,
"tested_conf": null,
"validation_history": [
{
"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
"date": "2025-02-14",
"lab": "Gossamer Security Solutions",
"validation_type": "Initial"
}
],
"vendor": "Cisco Systems, Inc.",
"vendor_url": "http://www.cisco.com"
}
}