Juniper Networks vSRX 3.0 Virtual Firewall

Certificate #3677

Webpage information

Status historical
Historical reason Moved to historical list due to sunsetting
Validation dates 07.07.2020
Standard FIPS 140-2
Security level 1
Type Software
Embodiment Multi-Chip Stand Alone
Caveat When operated in FIPS mode
Exceptions
  • Roles, Services, and Authentication: Level 3
  • Physical Security: N/A
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A
Description The vSRX Virtual Firewall delivers a complete virtual firewall solution, including advanced security, robust networking, and automated virtual machine life cycle management capabilities for service providers and enterprises. vSRX empowers security professionals to deploy and scale firewall protection in highly dynamic environments.
Tested configurations
  • and Junos OS 19.2R1 on VMware ESXi 6.5 running on a PacStar 451 Server with Intel Corei5
  • Junos OS 19.2R1 on VMware ESXi 6.5 running on a HP ProLiant DL380 Gen9 Server with Intel Xeon E5
  • Junos OS 19.2R1 on VMware ESXi 6.5 running on a PacStar 451 Server with Intel Xeon D
Vendor Juniper Networks, Inc.
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Symmetric Algorithms
AES, CAST, DES, Triple-DES, TDES, TDEA, Blowfish, HMAC, HMAC-SHA-256, HMAC-SHA-512
Asymmetric Algorithms
RSA 4096, RSA 2048, ECDH, ECDSA, Diffie-Hellman, DH, DSA
Hash functions
SHA-1, SHA1, SHA-256, SHA-512, MD5
Schemes
Key Exchange, Key Agreement, AEAD
Protocols
SSH, SSHv2, IKE, IKEv2, IKEv1, IPsec
Randomness
DRBG, RNG
Libraries
OpenSSL
Elliptic Curves
P-256, P-384, P-521
Block cipher modes
CBC, CTR, GCM

Security level
Level 1, level 2

Standards
FIPS 140-2, FIPS140-2, FIPS PUB 140-2, SP 800-38D, SP 800-67, SP 800-135, SP 800-90A, RFC 2409, RFC7296, RFC5282, RFC4106, RFC 4253, RFC 4251, RFC 7296, RFC 6071, X.509

File metadata

Subject FIPS 140-2 Security Policy Template
Author Jennifer Brady
Creation date D:20200625095513-04'00'
Modification date D:20200625095513-04'00'
Pages 27
Creator Microsoft® Word for Microsoft 365
Producer Microsoft® Word for Microsoft 365

Heuristics

No heuristics are available for this certificate.

References

No references are available for this certificate.

Updates Feed

  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 3677,
  "dgst": "2ca9f63bb06128cd",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "RSA#C937",
        "DRBG#C939",
        "SHS#C939",
        "SHS#C934",
        "CVL#C935",
        "KTS#C939",
        "SHS#C936",
        "HMAC#C932",
        "SHS#C937",
        "ECDSA#C939",
        "Triple-DES#C939",
        "ECDSA#C937",
        "HMAC#C937",
        "AES#C939",
        "HMAC#C939",
        "HMAC#C934",
        "HMAC#C936",
        "SHS#C932",
        "KTS#C937",
        "AES#C937",
        "RSA#C939",
        "Triple-DES#C936",
        "DRBG#C932",
        "CVL#C939",
        "Triple-DES#C937",
        "DRBG#C937",
        "AES#C936"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "3.0"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECDH": {
            "ECDH": 17
          },
          "ECDSA": {
            "ECDSA": 26
          }
        },
        "FF": {
          "DH": {
            "DH": 7,
            "Diffie-Hellman": 23
          },
          "DSA": {
            "DSA": 3
          }
        },
        "RSA": {
          "RSA 2048": 14,
          "RSA 4096": 8
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 13
        },
        "CTR": {
          "CTR": 2
        },
        "GCM": {
          "GCM": 11
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {
        "OpenSSL": {
          "OpenSSL": 3
        }
      },
      "crypto_protocol": {
        "IKE": {
          "IKE": 21,
          "IKEv1": 6,
          "IKEv2": 7
        },
        "IPsec": {
          "IPsec": 18
        },
        "SSH": {
          "SSH": 38,
          "SSHv2": 3
        }
      },
      "crypto_scheme": {
        "AEAD": {
          "AEAD": 3
        },
        "KA": {
          "Key Agreement": 1
        },
        "KEX": {
          "Key Exchange": 2
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-256": 54,
          "P-384": 40,
          "P-521": 12
        }
      },
      "eval_facility": {},
      "fips_cert_id": {},
      "fips_certlike": {
        "Certlike": {
          "# C937": 4,
          "# C939": 4,
          "AES CBC 128/192/256": 5,
          "AES GCM10": 1,
          "DRBG 2": 1,
          "HMAC SHA-1": 1,
          "HMAC SHA-256": 4,
          "HMAC-SHA- 1": 1,
          "HMAC-SHA- 1-96": 2,
          "HMAC-SHA- 256": 1,
          "HMAC-SHA- 512": 1,
          "HMAC-SHA-1": 4,
          "HMAC-SHA-256": 8,
          "HMAC-SHA-512": 2,
          "RSA 2048": 14,
          "RSA 4096": 8,
          "SHA 1, 256": 1,
          "SHA 256": 10,
          "SHA 384": 4,
          "SHA 512": 2,
          "SHA-1": 9,
          "SHA-256": 18,
          "SHA-384": 1,
          "SHA-512": 3,
          "SHA1": 1
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 4,
          "level 2": 2
        }
      },
      "hash_function": {
        "MD": {
          "MD5": {
            "MD5": 2
          }
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 9,
            "SHA1": 1
          },
          "SHA2": {
            "SHA-256": 22,
            "SHA-512": 3
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 14
        },
        "RNG": {
          "RNG": 2
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-2": 7,
          "FIPS PUB 140-2": 1,
          "FIPS140-2": 1
        },
        "NIST": {
          "SP 800-135": 3,
          "SP 800-38D": 2,
          "SP 800-67": 3,
          "SP 800-90A": 7
        },
        "RFC": {
          "RFC 2409": 2,
          "RFC 4251": 1,
          "RFC 4253": 1,
          "RFC 6071": 1,
          "RFC 7296": 1,
          "RFC4106": 2,
          "RFC5282": 1,
          "RFC7296": 1
        },
        "X509": {
          "X.509": 2
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 27
          },
          "CAST": {
            "CAST": 1
          }
        },
        "DES": {
          "3DES": {
            "TDEA": 1,
            "TDES": 3,
            "Triple-DES": 20
          },
          "DES": {
            "DES": 1
          }
        },
        "constructions": {
          "MAC": {
            "HMAC": 25,
            "HMAC-SHA-256": 4,
            "HMAC-SHA-512": 1
          }
        },
        "miscellaneous": {
          "Blowfish": {
            "Blowfish": 1
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "Jennifer Brady",
      "/CreationDate": "D:20200625095513-04\u002700\u0027",
      "/Creator": "Microsoft\u00ae Word for Microsoft 365",
      "/ModDate": "D:20200625095513-04\u002700\u0027",
      "/Producer": "Microsoft\u00ae Word for Microsoft 365",
      "/Subject": "FIPS 140-2 Security Policy Template",
      "pdf_file_size_bytes": 676538,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "http://www.juniper.net/assets/us/en/local/pdf/datasheets/1000489-en.pdf",
          "https://www.juniper.net/documentation/en_US/vsrx/information-products/pathway-pages/security-vsrx-vmware-guide-pwp.pdf",
          "http://www.juniper.net/support/downloads/?p=vsrx#sw"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 27
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
    "module_download_ok": true,
    "module_extract_ok": true,
    "policy_convert_ok": true,
    "policy_download_ok": true,
    "policy_extract_ok": true,
    "policy_json_hash": null,
    "policy_pdf_hash": "cce72ccd04cbb3e872683a90fd0928df966723567acd8d3cff00679024bef6dc",
    "policy_txt_hash": "81954c5dc719b416a42e280a72969293516f211254755c97a033ce69d94feb2d"
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in FIPS mode",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/July 2020_030820_0656_signed.pdf",
    "date_sunset": null,
    "description": "The vSRX Virtual Firewall delivers a complete virtual firewall solution, including advanced security, robust networking, and automated virtual machine life cycle management capabilities for service providers and enterprises. vSRX empowers security professionals to deploy and scale firewall protection in highly dynamic environments.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Roles, Services, and Authentication: Level 3",
      "Physical Security: N/A",
      "Design Assurance: Level 3",
      "Mitigation of Other Attacks: N/A"
    ],
    "fw_versions": null,
    "historical_reason": "Moved to historical list due to sunsetting",
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {},
    "module_name": "Juniper Networks vSRX 3.0 Virtual Firewall",
    "module_type": "Software",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-2",
    "status": "historical",
    "sw_versions": "Junos OS 19.2R1",
    "tested_conf": [
      "and Junos OS 19.2R1 on VMware ESXi 6.5 running on a PacStar 451 Server with Intel Corei5",
      "Junos OS 19.2R1 on VMware ESXi 6.5 running on a HP ProLiant DL380 Gen9 Server with Intel Xeon E5",
      "Junos OS 19.2R1 on VMware ESXi 6.5 running on a PacStar 451 Server with Intel Xeon D"
    ],
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2020-07-07",
        "lab": "Acumen Security",
        "validation_type": "Initial"
      }
    ],
    "vendor": "Juniper Networks, Inc.",
    "vendor_url": "http://www.juniper.net/"
  }
}