This page was not yet optimized for use on mobile devices.
FIPS AP43
Certificate #4495
Webpage information ?
Security policy ?
Symmetric Algorithms
AES, HMAC, HMAC-SHA-256, HMAC-SHA-384, HMAC-SHA-512Asymmetric Algorithms
RSA 4096, RSA 2048, ECDH, ECDSA, DH, Diffie-HellmanHash functions
SHA-1, SHA-384, SHA-256, SHA-512, MD5Schemes
Key AgreementProtocols
TLS, TLS 1.2, IKEv2Randomness
DRBGElliptic Curves
P-384, P-256, P-521, Ed25519Block cipher modes
ECB, CTR, GCM, CCMTrusted Execution Environments
SSCSecurity level
Level 2Certification process
out of scope, NOTE: Any firmware loaded into the module with a version not showing in the module certificate is out of scope of this validation and requires a separate FIPS 140-2 validation. 2. SECURITY LEVEL SPECIFICATIONStandards
FIPS 140-2, FIPS 197, FIPS 186-4, FIPS 198-1, FIPS 180-4, SP 800-38A, SP 800-38F, SP 800-90B, SP 800-108, SP 800-38D, SP 800-56A, SP 800-135, SP 800-38C, RFC-2865File metadata
Title | [5CM2] TID-1276 AP43 FIPS Security Policy (MIST_22.12.14_V1.28) (ID 2281) |
---|---|
Author | Santosh Rokade |
Creation date | D:20221215062316Z00'00' |
Modification date | D:20221215062316Z00'00' |
Pages | 41 |
Creator | Word |
Producer | macOS Version 12.6.1 (Build 21G217) Quartz PDFContext |
Heuristics ?
No heuristics are available for this certificate.
References ?
No references are available for this certificate.
Updates ?
-
18.05.2023 The certificate was first processed.
New certificate
A new FIPS 140 certificate with the product name was processed.
Raw data
{
"_type": "sec_certs.sample.fips.FIPSCertificate",
"cert_id": 4495,
"dgst": "3a1e191db60edbc0",
"heuristics": {
"_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
"algorithms": {
"_type": "Set",
"elements": [
"AES#A1758",
"KTS#A1759",
"AES#C1273",
"AES#C1274",
"KAS#A1758",
"HMAC#A1758",
"DRBG#A1759",
"SHS#A1759",
"AES#A1759",
"ECDSA#A1759",
"HMAC#A1759",
"KBKDF#A1759",
"SHS#A1758",
"KAS-SSC#A1758",
"CVL#A1758",
"RSA#A1758",
"ECDSA#A1758"
]
},
"cpe_matches": null,
"direct_transitive_cves": null,
"extracted_versions": {
"_type": "Set",
"elements": [
"0.9.23115"
]
},
"indirect_transitive_cves": null,
"module_processed_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": null,
"indirectly_referenced_by": null,
"indirectly_referencing": null
},
"module_prunned_references": {
"_type": "Set",
"elements": []
},
"policy_processed_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": null,
"indirectly_referenced_by": null,
"indirectly_referencing": null
},
"policy_prunned_references": {
"_type": "Set",
"elements": []
},
"related_cves": null,
"verified_cpe_matches": null
},
"pdf_data": {
"_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
"keywords": {
"asymmetric_crypto": {
"ECC": {
"ECDH": {
"ECDH": 2
},
"ECDSA": {
"ECDSA": 21
}
},
"FF": {
"DH": {
"DH": 2,
"Diffie-Hellman": 1
}
},
"RSA": {
"RSA 2048": 1,
"RSA 4096": 6
}
},
"certification_process": {
"OutOfScope": {
"NOTE: Any firmware loaded into the module with a version not showing in the module certificate is out of scope of this validation and requires a separate FIPS 140-2 validation. 2. SECURITY LEVEL SPECIFICATION": 1,
"out of scope": 1
}
},
"cipher_mode": {
"CCM": {
"CCM": 1
},
"CTR": {
"CTR": 1
},
"ECB": {
"ECB": 3
},
"GCM": {
"GCM": 3
}
},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {},
"crypto_protocol": {
"IKE": {
"IKEv2": 1
},
"TLS": {
"TLS": {
"TLS": 62,
"TLS 1.2": 1
}
}
},
"crypto_scheme": {
"KA": {
"Key Agreement": 2
}
},
"device_model": {},
"ecc_curve": {
"Edwards": {
"Ed25519": 1
},
"NIST": {
"P-256": 22,
"P-384": 42,
"P-521": 4
}
},
"eval_facility": {},
"fips_cert_id": {},
"fips_certlike": {
"Certlike": {
"AES-GCM (128 and 256": 1,
"DRBG KAT 9": 1,
"HMAC-SHA-1": 8,
"HMAC-SHA-1 KAT 11": 2,
"HMAC-SHA-256": 2,
"HMAC-SHA-256 KAT 12": 2,
"HMAC-SHA-256 KAT 13": 2,
"HMAC-SHA-256 KAT 16": 2,
"HMAC-SHA-384 KAT 17": 2,
"HMAC-SHA-512": 2,
"RSA 2048": 1,
"RSA 4096": 6,
"SHA-1": 2,
"SHA-256": 14,
"SHA-384": 12,
"SHA-512": 2,
"SHA2-256": 3,
"SHA2-384": 2
}
},
"fips_security_level": {
"Level": {
"Level 2": 2
}
},
"hash_function": {
"MD": {
"MD5": {
"MD5": 1
}
},
"SHA": {
"SHA1": {
"SHA-1": 2
},
"SHA2": {
"SHA-256": 14,
"SHA-384": 12,
"SHA-512": 2
}
}
},
"ic_data_group": {},
"javacard_api_const": {},
"javacard_packages": {},
"javacard_version": {},
"os_name": {},
"pq_crypto": {},
"randomness": {
"PRNG": {
"DRBG": 23
}
},
"side_channel_analysis": {},
"standard_id": {
"FIPS": {
"FIPS 140-2": 23,
"FIPS 180-4": 2,
"FIPS 186-4": 4,
"FIPS 197": 4,
"FIPS 198-1": 2
},
"NIST": {
"SP 800-108": 1,
"SP 800-135": 1,
"SP 800-38A": 4,
"SP 800-38C": 1,
"SP 800-38D": 2,
"SP 800-38F": 2,
"SP 800-56A": 1,
"SP 800-90B": 1
},
"RFC": {
"RFC-2865": 1
}
},
"symmetric_crypto": {
"AES_competition": {
"AES": {
"AES": 16
}
},
"constructions": {
"MAC": {
"HMAC": 2,
"HMAC-SHA-256": 4,
"HMAC-SHA-384": 1,
"HMAC-SHA-512": 1
}
}
},
"tee_name": {
"IBM": {
"SSC": 1
}
},
"tls_cipher_suite": {},
"vendor": {},
"vulnerability": {}
},
"policy_metadata": {
"/Author": "Santosh Rokade",
"/CreationDate": "D:20221215062316Z00\u002700\u0027",
"/Creator": "Word",
"/ModDate": "D:20221215062316Z00\u002700\u0027",
"/Producer": "macOS Version 12.6.1 (Build 21G217) Quartz PDFContext",
"/Title": "[5CM2] TID-1276 AP43 FIPS Security Policy (MIST_22.12.14_V1.28) (ID 2281)",
"pdf_file_size_bytes": 4813575,
"pdf_hyperlinks": {
"_type": "Set",
"elements": []
},
"pdf_is_encrypted": false,
"pdf_number_of_pages": 41
}
},
"state": {
"_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
"module_download_ok": true,
"module_extract_ok": true,
"policy_convert_garbage": false,
"policy_convert_ok": true,
"policy_download_ok": true,
"policy_extract_ok": true,
"policy_pdf_hash": "8dbad944cb754ad54205e06ead6388a1bc69438fe579e342a63a870d148b8960",
"policy_txt_hash": "2504aaf17592bb176d97bad89bc361692357097671444d6d1613604cdddad155"
},
"web_data": {
"_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
"caveat": "When operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy",
"certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/April 2023_010523_0646.pdf",
"date_sunset": "2026-09-21",
"description": "The AP43 Series is a tri-radio 4x4 802.11ax Access Point with maximum data rates of 2,400 Mbps in the 5GHz band and 1,148 Mbps in the 2.4GHz band. The 3rd radio functions as a network, location, and security sensor, a synthetic test client radio, as well as a spectrum monitor.",
"embodiment": "Multi-Chip Stand Alone",
"exceptions": [
"Mitigation of Other Attacks: N/A"
],
"fw_versions": "fips_apfw-0.9.23115-illyrio-9e5f",
"historical_reason": null,
"hw_versions": "AP43-FIPS-US [REV. AA and AB] and AP43E-FIPS-US [REV. AA and AB]",
"level": 2,
"mentioned_certs": {},
"module_name": "FIPS AP43",
"module_type": "Hardware",
"revoked_link": null,
"revoked_reason": null,
"standard": "FIPS 140-2",
"status": "active",
"sw_versions": null,
"tested_conf": null,
"validation_history": [
{
"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
"date": "2023-04-30",
"lab": "\u00c6GISOLVE",
"validation_type": "Initial"
}
],
"vendor": "Mist Systems",
"vendor_url": "http://www.mist.com"
}
}