This page was not yet optimized for use on mobile devices.
Juniper Networks QFX10002, QFX10008 and QFX10016
Certificate details
| Certificate ID | #4882 |
|---|---|
| Status | active |
| Validation dates | 18.11.2024 |
| Sunset date | 17-11-2026 |
| Standard | FIPS 140-3 |
| Security level | 1 |
| Type | Hardware |
| Embodiment | Multi-Chip Stand Alone |
| Caveat | Interim validation. When operated in Approved mode. When installed, initialized and configured as specified in Section 11 of the Security Policy. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs. |
| Exceptions |
|
| Description | Juniper Networks QFX10002, QFX10008, QFX10016 are QFX Series switches. The cryptographic module provides for an encrypted connection, using SSH, between the management station and the QFX switch. |
| Vendor | Juniper Networks, Inc. http://www.juniper.net |
| Lab | Acumen Security |
| Algorithms |
|
| References | This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates. |
Security policy
Extracted keywords
Symmetric Algorithms
AES-128, AES-192, AES-256, AES, AES-, CAST, TDES, Blowfish, HMACAsymmetric Algorithms
RSA 2048, ECDH, ECDSA, Diffie-Hellman, DH, DSAHash functions
SHA-1, RIPEMD160Schemes
MAC, Key AgreementProtocols
SSH, SSHv2Randomness
DRBG, RBGLibraries
OpenSSLElliptic Curves
P-256, P-384, P-521, prime256v1Block cipher modes
CBC, CTRTrusted Execution Environments
PSP, SSCSecurity level
Level 1, Level 3, level 1Standards
FIPS 140-3, FIPS 198-1, FIPS 180-4, FIPS186-4, FIPS 186-4, FIPS186, SP 800-90A, SP 800-38A, SP 800-56A, SP 800-135, NIST SP 800-90B, PKCS 1, X.509Automated analysis
Automated inference - use with caution
All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.Cross-references
No references are available for this certificate.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate data changed.
-
The certificate was first processed.
{
"_type": "sec_certs.sample.fips.FIPSCertificate",
"cert_id": 4882,
"dgst": "4046c1be5d83b630",
"heuristics": {
"_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
"algorithms": {
"_type": "Set",
"elements": [
"HMAC-SHA2-256A3349",
"ECDSA SigGen (FIPS186-4)A3349",
"#A3337",
"AES-CBCA3349",
"#A3349",
"Safe Primes Key GenerationA3349",
"RSA KeyGen (FIPS186-4)A3349",
"KDF SSHA3349",
"RSA SigGen (FIPS186-4)A3349",
"#A3348",
"KAS-FFC-SSC Sp800-56Ar3A3349",
"ECDSA KeyGen (FIPS186-4)A3349",
"AES-CTRA3349",
"SHA-1A3349",
"ECDSA SigVer (FIPS186-4)A3349",
"SHA2-512A3349",
"AES-ECBA3349",
"RSA SigVer (FIPS186-4)A3349",
"ECDSA KeyVer (FIPS186-4)A3349",
"KAS-ECC-SSC Sp800-56Ar3A3349",
"HMAC-SHA2-512A3349",
"SHA2-256A3349",
"HMAC DRBGA3349",
"Safe Primes Key VerificationA3349",
"HMAC-SHA-1A3349"
]
},
"cpe_matches": {
"_type": "Set",
"elements": [
"cpe:2.3:h:juniper:qfx10002:-:*:*:*:*:*:*:*",
"cpe:2.3:h:juniper:qfx10008:-:*:*:*:*:*:*:*",
"cpe:2.3:h:juniper:qfx10016:-:*:*:*:*:*:*:*"
]
},
"direct_transitive_cves": null,
"extracted_versions": {
"_type": "Set",
"elements": [
"-"
]
},
"indirect_transitive_cves": null,
"module_processed_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": null,
"indirectly_referenced_by": null,
"indirectly_referencing": null
},
"module_prunned_references": {
"_type": "Set",
"elements": []
},
"policy_processed_references": {
"_type": "sec_certs.sample.certificate.References",
"directly_referenced_by": null,
"directly_referencing": null,
"indirectly_referenced_by": null,
"indirectly_referencing": null
},
"policy_prunned_references": {
"_type": "Set",
"elements": []
},
"related_cves": null,
"verified_cpe_matches": null
},
"pdf_data": {
"_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
"br1_deviations": 0,
"br1_tables": {
"_type": "sec_certs.heuristics.br1.table_parsing.model.br1_tables.BR1Tables",
"approved_algorithms": {
"entries": [
{
"algorithm": "HMAC DRBG",
"cavpCertName": "A3337",
"properties": "Prediction Resistance - Yes Mode - SHA2-256",
"reference": "SP 800-90A Rev. 1"
},
{
"algorithm": "HMAC-SHA2- 256",
"cavpCertName": "A3337",
"properties": "Key Length - Key Length: 256",
"reference": "FIPS 198-1"
},
{
"algorithm": "SHA2-256",
"cavpCertName": "A3337",
"properties": "Message Length - Message Length: 0- 65536 Increment 8",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2-512",
"cavpCertName": "A3348",
"properties": "Message Length - Message Length: 0-65536 Increment 8",
"reference": "FIPS 180-4"
},
{
"algorithm": "AES-CBC",
"cavpCertName": "A3349",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-CTR",
"cavpCertName": "A3349",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "AES-ECB",
"cavpCertName": "A3349",
"properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
"reference": "SP 800-38A"
},
{
"algorithm": "ECDSA KeyGen (FIPS186-4)",
"cavpCertName": "A3349",
"properties": "Curve - P-256, P-384, P-521 Secret Generation Mode - Testing Candidates",
"reference": "FIPS 186-4"
},
{
"algorithm": "ECDSA KeyVer (FIPS186-4)",
"cavpCertName": "A3349",
"properties": "Curve - P-256, P-384, P-521",
"reference": "FIPS 186-4"
},
{
"algorithm": "ECDSA SigGen (FIPS186-4)",
"cavpCertName": "A3349",
"properties": "Component - No Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512",
"reference": "FIPS 186-4"
},
{
"algorithm": "ECDSA SigVer (FIPS186-4)",
"cavpCertName": "A3349",
"properties": "Component - No Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512",
"reference": "FIPS 186-4"
},
{
"algorithm": "HMAC DRBG",
"cavpCertName": "A3349",
"properties": "Prediction Resistance - Yes Mode - SHA2-256",
"reference": "SP 800-90A Rev. 1"
},
{
"algorithm": "HMAC-SHA-1",
"cavpCertName": "A3349",
"properties": "Key Length - Key Length: 160",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA2-256",
"cavpCertName": "A3349",
"properties": "Key Length - Key Length: 256",
"reference": "FIPS 198-1"
},
{
"algorithm": "HMAC-SHA2-512",
"cavpCertName": "A3349",
"properties": "Key Length - Key Length: 512",
"reference": "FIPS 198-1"
},
{
"algorithm": "KAS-ECC-SSC Sp800-56Ar3",
"cavpCertName": "A3349",
"properties": "Domain Parameter Generation Methods - P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responder",
"reference": "SP 800-56A Rev. 3"
},
{
"algorithm": "KAS-FFC-SSC Sp800-56Ar3",
"cavpCertName": "A3349",
"properties": "Domain Parameter Generation Methods - FC, MODP-2048 Scheme - dhEphem - KAS Role - initiator",
"reference": "SP 800-56A Rev. 3"
},
{
"algorithm": "KDF SSH (CVL)",
"cavpCertName": "A3349",
"properties": "Cipher - AES-128, AES-192, AES-256, TDES Hash Algorithm - SHA-1, SHA2-256, SHA2-384, SHA2-512",
"reference": "SP 800-135 Rev. 1"
},
{
"algorithm": "RSA KeyGen (FIPS186-4)",
"cavpCertName": "A3349",
"properties": "Key Generation Mode - B.3.3 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Private Key Format - Standard",
"reference": "FIPS 186-4"
},
{
"algorithm": "RSA SigGen (FIPS186-4)",
"cavpCertName": "A3349",
"properties": "Signature Type - PKCS 1.5 Modulo - 2048, 3072, 4096",
"reference": "FIPS 186-4"
},
{
"algorithm": "RSA SigVer (FIPS186-4)",
"cavpCertName": "A3349",
"properties": "Signature Type - PKCS 1.5 Modulo - 2048, 3072, 4096",
"reference": "FIPS 186-4"
},
{
"algorithm": "SHA-1",
"cavpCertName": "A3349",
"properties": "Message Length - Message Length: 0- 65536 Increment 8",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2-256",
"cavpCertName": "A3349",
"properties": "Message Length - Message Length: 0- 65536 Increment 8",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2-512",
"cavpCertName": "A3349",
"properties": "Message Length - Message Length: 0- 65536 Increment 8",
"reference": "FIPS 180-4"
},
{
"algorithm": "SHA2-512",
"cavpCertName": "A3337",
"properties": "Message Length - Message Length: 0- 65536 Increment 8",
"reference": "FIPS 180-4"
},
{
"algorithm": "Safe Primes Key Generation",
"cavpCertName": "A3349",
"properties": "Safe Prime Groups - MODP-2048",
"reference": "SP 800-56A Rev. 3"
},
{
"algorithm": "Safe Primes Key Verification",
"cavpCertName": "A3349",
"properties": "Safe Prime Groups - MODP-2048",
"reference": "SP 800-56A Rev. 3"
}
],
"found": true,
"section": 2,
"subsection": 5
},
"approved_services": {
"entries": [
{
"description": "Security relevant configuratio n (SSH, authenticati on data)",
"indicator": "Global Approved Mode indicator \u0027fips\u0027 at the CLI combined with successf ul completio n of each service",
"inputs": "Commands (SSH configuration: set system services ssh root-login allow)",
"name": "Configure security (security relevant)",
"outputs": "Traffic",
"rolesSspAccess": "Root - SSH Private Host Key: G - User Password: W,E - CO Password: W,E - HMAC_DRBG V value: E - HMAC_DRBG Key value: E - HMAC_DRBG entropy input: E - HMAC_DRBG seed: E - SSH Public Host Key: G - User Authentication Public Keys: W - CO Authentication Public Keys: W Super-user - SSH Private Host Key: G - User Password: W,E - CO Password: W,E - HMAC_DRBG V value: E -",
"secFunImpl": "DRBG DRBG2 Passwor d Hash CKG"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "HMAC_DRBG Key value: E - HMAC_DRBG entropy input: E - HMAC_DRBG seed: E - HMAC_DRBG Key value: E - SSH Public Host Key: G - CO Authentication Public Keys: W - User Authentication Public Keys: W",
"secFunImpl": ""
},
{
"description": "Non- security relevant configuratio n",
"indicator": "Global Approved Mode indicator \u0027fips\u0027 at the CLI combined with successf ul completio n of each service",
"inputs": "Commands (miscellaneous commands e.g., for IP address configuration, routing protocols, etc.)",
"name": "Configure (non- security relevant)",
"outputs": "Traffic",
"rolesSspAccess": "Super-user - CO Password: E Root - CO Password: E",
"secFunImpl": "Passwor d Hash"
},
{
"description": "Query the module status",
"indicator": "Global Approved Mode indicator \u0027fips\u0027 at the CLI combined with successf ul completio n of each service",
"inputs": "Command (show)",
"name": "Show status",
"outputs": "CLI output",
"rolesSspAccess": "Super-user - CO Password: E Root - CO Password: E Operator - User Password: E Read-only - User Password: E Unauthorised",
"secFunImpl": "Passwor d Hash"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "- User Password: E",
"secFunImpl": ""
},
{
"description": "LEDs on the module provide physical status output",
"indicator": "LED(s) on the chassis turned on",
"inputs": "N/A",
"name": "Show status (LED)",
"outputs": "LED",
"rolesSspAccess": "Super-user Operator Read-only Unauthorised Root Unauthenticat ed",
"secFunImpl": "None"
},
{
"description": "Query the module\u0027s versioning information",
"indicator": "Global Approved Mode indicator \u0027fips\u0027 at the CLI combined with successf ul completio n of each service",
"inputs": "Command (show version)",
"name": "Show module\u0027s versioning informatio n",
"outputs": "CLI output",
"rolesSspAccess": "Super-user - CO Password: E Operator - User Password: E Read-only - User Password: E Unauthorised - User Password: E Root - CO Password: E",
"secFunImpl": "Passwor d Hash"
},
{
"description": "Destroy all SSPs",
"indicator": "Global Approved Mode indicator \u0027fips\u0027 at the CLI combined with successf ul completio n of each service",
"inputs": "Command (request vmhost zeroise no-forwarding)",
"name": "Zeroise (Perform zeroisatio n)",
"outputs": "N/A",
"rolesSspAccess": "Super-user - SSH Private Host Key: Z - SSH ECDH Private Key: Z - SSH DH Private Key: Z - SSH Session Key: Z - User Password: Z - CO Password: E,Z - HMAC_DRBG V value: Z - HMAC_DRBG Key value: Z - HMAC_DRBG entropy input: Z",
"secFunImpl": "Passwor d Hash"
},
{
"description": "Description",
"indicator": "Indicator",
"inputs": "Inputs",
"name": "Name",
"outputs": "Output s",
"rolesSspAccess": "SSP Access",
"secFunImpl": "Security Function"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "- HMAC_DRBG seed: Z - ECDH Shared Secret: Z - DH Shared Secret: Z - HMAC Key: Z - SSH Public Host Key: Z - User Authentication Public Keys: Z - CO Authentication Public Keys: Z - JuniperRootC A: Z - PackageCA: Z - SSH ECDH Public Key: Z - SSH DH Public Key: Z - SSH ECDH Client Public Key: Z - SSH DH Client Public Key: Z Root - SSH Private Host Key: Z - SSH ECDH Private Key: Z - SSH DH Private Key: Z - SSH Session Key: Z - User Password: Z - CO Password: E,Z - HMAC_DRBG",
"secFunImpl": "s"
},
{
"description": "Description",
"indicator": "Indicator",
"inputs": "Inputs",
"name": "Name",
"outputs": "Output s",
"rolesSspAccess": "SSP Access",
"secFunImpl": "Security Function"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "V value: Z - HMAC_DRBG Key value: Z - HMAC_DRBG entropy input: Z - HMAC_DRBG seed: Z - ECDH Shared Secret: Z - DH Shared Secret: Z - HMAC Key: Z - SSH Public Host Key: Z - User Authentication Public Keys: Z - CO Authentication Public Keys: Z - JuniperRootC A: Z - PackageCA: Z - SSH ECDH Public Key: Z - SSH DH Public Key: Z - SSH ECDH Client Public Key: Z - SSH DH Client Public Key: Z",
"secFunImpl": "s"
},
{
"description": "Initiate SSH connection for SSH monitoring and control (CLI)",
"indicator": "Global Approved Mode indicator \u0027fips\u0027 at the CLI combined",
"inputs": "Authentication data (Username and password/publi c-key based authentication)",
"name": "Perform approved security functions (SSH connectio n)",
"outputs": "SSH session",
"rolesSspAccess": "Super-user - SSH Private Host Key: E - SSH ECDH Private Key: G,E,Z - SSH DH",
"secFunImpl": "KAS1 KAS2 KTS1 ECDSA SigVer2 DRBG DRBG2"
},
{
"description": "",
"indicator": "with successf ul completio n of each service",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "Private Key: G,E,Z - SSH Session Key: G,E,Z - HMAC_DRBG V value: E - HMAC_DRBG Key value: E - HMAC_DRBG entropy input: E - HMAC_DRBG seed: E - ECDH Shared Secret: G,E,Z - DH Shared Secret: G,E,Z - HMAC Key: G,E,Z - SSH Public Host Key: E - SSH DH Public Key: G,E,Z - SSH ECDH Public Key: G,E,Z - CO Password: E - CO Authentication Public Keys: E - SSH ECDH Client Public Key: W,E,Z - SSH DH Client Public Key: W,E,Z Root - SSH Private Host Key: E - SSH ECDH Private Key:",
"secFunImpl": "Entropy Souce ECDSA KeyGen ECDSA KeyGen2 ECDSA KeyVer ECDSA SigGen RSA KeyGen RSA SigGen RSA SigVer Passwor d Hash CKG"
},
{
"description": "Description",
"indicator": "Indicator",
"inputs": "Inputs",
"name": "Name",
"outputs": "Output s",
"rolesSspAccess": "SSP Access",
"secFunImpl": "Security Function"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "G,E,Z - SSH DH Private Key: G,E,Z - SSH Session Key: G,E,Z - HMAC_DRBG V value: E - HMAC_DRBG Key value: E - HMAC_DRBG entropy input: E - HMAC_DRBG seed: E - ECDH Shared Secret: G,E,Z - DH Shared Secret: G,E,Z - HMAC Key: G,E,Z - SSH Public Host Key: E - SSH ECDH Public Key: G,E,Z - SSH DH Public Key: G,E,Z - CO Password: E - CO Authentication Public Keys: E - SSH ECDH Client Public Key: G,E,Z - SSH DH Client Public Key: G,E,Z Operator - SSH Private Host Key: E",
"secFunImpl": "s"
},
{
"description": "Description",
"indicator": "Indicator",
"inputs": "Inputs",
"name": "Name",
"outputs": "Output s",
"rolesSspAccess": "SSP Access",
"secFunImpl": "Security Function"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "- SSH ECDH Private Key: G,E,Z - SSH DH Private Key: G,E,Z - SSH Session Key: G,E,Z - HMAC_DRBG V value: E - HMAC_DRBG entropy input: E - HMAC_DRBG seed: E - ECDH Shared Secret: G,E,Z - DH Shared Secret: G,E,Z - HMAC Key: G,E,Z - SSH Public Host Key: E - SSH ECDH Public Key: G,E,Z - SSH DH Public Key: G,E,Z - User Password: E - User Authentication Public Keys: E - SSH ECDH Client Public Key: G,E,Z - SSH DH Client Public Key: G,E,Z - HMAC_DRBG Key value: E Read-only",
"secFunImpl": "s"
},
{
"description": "Description",
"indicator": "Indicator",
"inputs": "Inputs",
"name": "Name",
"outputs": "Output s",
"rolesSspAccess": "SSP Access",
"secFunImpl": "Security Function"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "- SSH Private Host Key: E - SSH ECDH Private Key: G,E,Z - SSH DH Private Key: G,E,Z - SSH Session Key: G,E,Z - HMAC_DRBG V value: E - HMAC_DRBG Key value: E - HMAC_DRBG entropy input: E - HMAC_DRBG seed: E - ECDH Shared Secret: G,E,Z - DH Shared Secret: G,E,Z - HMAC Key: G,E,Z - SSH Public Host Key: E - SSH ECDH Public Key: G,E,Z - SSH DH Public Key: G,E,Z - User Password: E - User Authentication Public Keys: E - SSH ECDH Client Public Key: G,E,Z - SSH DH Client Public",
"secFunImpl": "s"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "Key: G,E,Z Unauthorised - SSH Private Host Key: E - SSH ECDH Private Key: G,E,Z - SSH DH Private Key: G,E,Z - SSH Session Key: G,E,Z - HMAC_DRBG V value: E - HMAC_DRBG entropy input: E - HMAC_DRBG seed: E - ECDH Shared Secret: G,E,Z - DH Shared Secret: G,E,Z - HMAC Key: G,E,Z - SSH Public Host Key: E - SSH ECDH Public Key: G,E,Z - SSH DH Public Key: G,E,Z - User Password: E - User Authentication Public Keys: E - SSH ECDH Client Public Key: G,E,Z - SSH DH Client Public Key: G,E,Z",
"secFunImpl": ""
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "- HMAC_DRBG Key value: E",
"secFunImpl": ""
},
{
"description": "Console monitoring and control (CLI)",
"indicator": "Global Approved Mode indicator \u0027fips\u0027 at the CLI combined with successf ul completio n of each service",
"inputs": "Username, password (set system login user \u003cusername\u003e class \u003ccrypto- officer/user class\u003e operator authentication plaintext- password)",
"name": "Console Access",
"outputs": "N/A",
"rolesSspAccess": "Super-user - CO Password: E Operator - CO Password: E Read-only - User Password: E Unauthorised - User Password: E Root - CO Password: E",
"secFunImpl": "Passwor d Hash"
},
{
"description": "Software initiated reset, performs self-tests on demand via SSH",
"indicator": "Global Approved Mode indicator \u0027fips\u0027 at the CLI combined with successf ul completio n of each service",
"inputs": "Control input/reset signal (request vmhost reboot)",
"name": "Perform self-tests (remote reset)",
"outputs": "N/A",
"rolesSspAccess": "Super-user - SSH ECDH Private Key: G,E,Z - SSH DH Private Key: G,E,Z - SSH Session Key: G,E,Z - HMAC_DRBG Key value: G,E,Z - HMAC_DRBG V value: G,E,Z - HMAC_DRBG entropy input: G,E,Z - HMAC_DRBG seed: G,E,Z - ECDH Shared Secret: G,E,Z - DH Shared Secret: G,E,Z - HMAC Key: G,E,Z",
"secFunImpl": "KAS1 KAS2 KTS1 DRBG DRBG2 Entropy Souce ECDSA KeyGen ECDSA KeyGen2 ECDSA KeyVer ECDSA SigGen RSA KeyGen RSA SigGen Passwor d Hash CKG CASTs on boot"
},
{
"description": "Description",
"indicator": "Indicator",
"inputs": "Inputs",
"name": "Name",
"outputs": "Output s",
"rolesSspAccess": "SSP Access",
"secFunImpl": "Security Function"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "- SSH ECDH Public Key: G,E,Z - SSH DH Public Key: G,E,Z - CO Password: E - Firmware Integrity Key: E - SSH Private Host Key: E - SSH Public Host Key: E - SSH ECDH Client Public Key: W,E,Z - SSH DH Client Public Key: W,E,Z - SSH Private Host Key: E - SSH Public Host Key: E - User Authentication Public Keys: E - CO Authentication Public Keys: E Root - SSH ECDH Private Key: G,E,Z - SSH DH Private Key: G,E,Z - SSH Session Key: G,E,Z - HMAC_DRBG Key value: G,E,Z - HMAC_DRBG V value: G,E,Z -",
"secFunImpl": "s"
},
{
"description": "Description",
"indicator": "Indicator",
"inputs": "Inputs",
"name": "Name",
"outputs": "Output s",
"rolesSspAccess": "SSP Access",
"secFunImpl": "Security Function"
},
{
"description": "",
"indicator": "",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "HMAC_DRBG entropy input: G,E,Z - HMAC_DRBG seed: G,E,Z - ECDH Shared Secret: G,E,Z - DH Shared Secret: G,E,Z - HMAC Key: G,E,Z - SSH ECDH Public Key: G,E,Z - SSH DH Public Key: G,E,Z - CO Password: E - Firmware Integrity Key: E - SSH Private Host Key: E - SSH Public Host Key: E - SSH ECDH Client Public Key: W,E,Z - SSH DH Client Public Key: W,E,Z - SSH Private Host Key: E - SSH Public Host Key: E - User Authentication Public Keys: E - CO Authentication Public Keys: E",
"secFunImpl": "s"
},
{
"description": "Hardware reset or power cycle",
"indicator": "Global Approved Mode indicator",
"inputs": "Control input/reset signal",
"name": "Perform self-tests (local reset)",
"outputs": "N/A",
"rolesSspAccess": "Super-user - Firmware Integrity Key: E",
"secFunImpl": "CASTs on boot"
},
{
"description": "",
"indicator": "\u0027fips\u0027 at the CLI combined with successf ul completio n of each service",
"inputs": "",
"name": "",
"outputs": "",
"rolesSspAccess": "Root - Firmware Integrity Key: E Operator - Firmware Integrity Key: E Read-only - Firmware Integrity Key: E Unauthorised - Firmware Integrity Key: E Unauthenticat ed - Firmware Integrity Key: E",
"secFunImpl": ""
},
{
"description": "Verification and loading of a validated firmware image into the router/switc h",
"indicator": "Global Approved Mode indicator \u0027fips\u0027 at the CLI combined with successf ul completio n of each service",
"inputs": "Image, commands",
"name": "Load Image",
"outputs": "N/A",
"rolesSspAccess": "Super-user - CO Password: E - Firmware Integrity Key: E - JuniperRootC A: E - PackageCA: E Root - CO Password: E - Firmware Integrity Key: E - JuniperRootC A: E - PackageCA: E",
"secFunImpl": "ECDSA SigVer Passwor d Hash"
}
],
"found": true,
"section": 4,
"subsection": 3
},
"authentication_methods": {
"entries": [
{
"description": "\u2022 The module enforces 10- character passwords (at minimum) chosen from the 96 human readable ASCII characters; The maximum password length is 20- characters; Thus, the probability of a successful random attempt is 1/(96^10), which is less than 1/1,000,000 (million); \u2022 The module enforces a timed access mechanism as follows: For the first two failed attempts (assuming 0 time to process), no timed access is enforced; Upon the third attempt, the module enforces a 5-second delay; Each failed attempt thereafter results in an additional 5-second delay above the previous (e.g., 4th failed attempt = 10-second delay, 5th failed attempt = 15-second delay, 6th failed attempt = 20- second delay, 7th failed attempt = 25-second delay); This leads to a maximum of 7 possible attempts in a one-minute period for each getty; The best approach for the attacker would be to disconnect after 4 failed attempts and wait for a new getty to be spawned; This would allow the attacker to perform roughly 9.6 attempts per minute (576 attempts per hour/60 mins); this would be rounded down to 9 per minute, because there is no such thing as 0.6 attempts; The probability of a success with multiple consecutive attempts in",
"mechanism": "SHA2-512 (A3348)",
"name": "Username and password over the console and SSH",
"perMinute": "9/(96^10)",
"strength": "1/(96^10)"
},
{
"description": "a one-minute period is 9/(96^10), which is less than 1/100,000",
"mechanism": "",
"name": "",
"perMinute": "",
"strength": ""
},
{
"description": "\u2022 The module supports ECDSA (P-256, P-384, and P-521), which has a minimum equivalent computational resistance to attack of either 2^128, 2^192 or 2^256 depending on the curve; Thus, the probability of a successful random attempt is 1/(2^128), which is less than 1/1,000,000 (million) \u2022 Configurable SSH connection establishment rate limits the number of connection attempts, and thus failed authentication attempts in a one-minute period to a maximum of 15,000 attempts; The probability of a success with multiple consecutive attempts in a one- minute period is 15,000/(2^128), which is less than 1/100,000",
"mechanism": "ECDSA SigVer (FIPS186-4) (A3349)",
"name": "Username and ECDSA public key over SSH",
"perMinute": "15,000/(2^128)",
"strength": "1/(2^128)"
},
{
"description": "\u2022 The module supports RSA (2048, 3072, 4096 bits), which has a minimum equivalent computational resistance to attack of 2^112 (2048 bits); Thus, the probability of a successful random attempt is 1/ (2^112), which is less than 1/1,000,000 (million) \u2022 Configurable SSH connection establishment rate limits the number of connection attempts, and thus failed authentication attempts in a one- minute period to a maximum of 15,000 attempts; The probability of a success with multiple consecutive attempts in a one- minute period is 15,000/(2^112), which is less than 1/100,000",
"mechanism": "RSA SigVer (FIPS186-4) (A3349)",
"name": "Username and RSA public key over SSH",
"perMinute": "15,000/(2^112)",
"strength": "1/ (2^112)"
}
],
"found": true,
"section": 4,
"subsection": 1
},
"cond_self_tests": {
"entries": [
{
"algorithmOrTest": "HMAC DRBG (A3337)",
"condition": "During boot",
"details": "N/A",
"indicator": "NIST 800-90 HMAC DRBG Known Answer Test : Passed",
"testMethod": "KAT",
"testProps": "Prediction Resistance: Yes Supports Reseed Capabilities: Mode: SHA2- 256 Entropy Input: 256 Nonce: 128 Personalizati on String Length: 0- 256 Increment 8 Additional",
"type": "CAST"
},
{
"algorithmOrTest": "",
"condition": "",
"details": "",
"indicator": "",
"testMethod": "",
"testProps": "Input: 8-256 Increment 8 Returned Bits: 1024",
"type": ""
},
{
"algorithmOrTest": "HMAC- SHA2- 256 (A3337)",
"condition": "During boot",
"details": "N/A",
"indicator": "HMAC- SHA2- 256 Known Answer Test : Passed",
"testMethod": "KAT",
"testProps": "Key Length: 256 bits",
"type": "CAST"
},
{
"algorithmOrTest": "AES- CBC (A3349)",
"condition": "During boot",
"details": "Encrypt",
"indicator": "AES-CBC Known Answer Test : Passed",
"testMethod": "KAT",
"testProps": "Key Length: 128 bits",
"type": "CAST"
},
{
"algorithmOrTest": "AES- CBC (A3349)",
"condition": "During boot",
"details": "Encrypt",
"indicator": "AES-CBC Known Answer Test : Passed",
"testMethod": "KAT",
"testProps": "Key Length: 192 bits",
"type": "CAST"
},
{
"algorithmOrTest": "AES- CBC (A3349)",
"condition": "During boot",
"details": "Encrypt",
"indicator": "AES-CBC Known Answer Test : Passed",
"testMethod": "KAT",
"testProps": "Key Length: 256 bits",
"type": "CAST"
},
{
"algorithmOrTest": "AES- CBC (A3349)",
"condition": "During boot",
"details": "Decrypt",
"indicator": "AES-CBC Known Answer Test : Passed",
"testMethod": "KAT",
"testProps": "Key Length: 128 bits",
"type": "CAST"
},
{
"algorithmOrTest": "AES- CBC (A3349)",
"condition": "During boot",
"details": "Decrypt",
"indicator": "AES-CBC Known Answer Test : Passed",
"testMethod": "KAT",
"testProps": "Key Length: 192 bits",
"type": "CAST"
},
{
"algorithmOrTest": "AES- CBC (A3349)",
"condition": "During boot",
"details": "Decrypt",
"indicator": "AES-CBC Known Answer Test : Passed",
"testMethod": "KAT",
"testProps": "Key Length: 256 bits",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC DRBG (A3349)",
"condition": "During boot",
"details": "N/A",
"indicator": "NIST 800-90 HMAC DRBG Known Answer",
"testMethod": "KAT",
"testProps": "Mode: SHA2- 256, Entropy Input: 256 , Nonce: 128, Personalizati on String",
"type": "CAST"
},
{
"algorithmOrTest": "",
"condition": "",
"details": "",
"indicator": "Test : Passed",
"testMethod": "",
"testProps": "Length: 0- 256 , Increment 8 , Additional Input: 8-256 Increment 8 , Returned Bits: 1024",
"type": ""
},
{
"algorithmOrTest": "HMAC- SHA-1 (A3349)",
"condition": "During boot",
"details": "N/A",
"indicator": "HMAC- SHA-1 Known Answer Test : Passed",
"testMethod": "KAT",
"testProps": "Key Length: 160 bits",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC- SHA2- 256 (A3349)",
"condition": "During boot",
"details": "N/A",
"indicator": "HMAC- SHA2- 256 Known Answer Test : Passed",
"testMethod": "KAT",
"testProps": "Key Length: 256 bits",
"type": "CAST"
},
{
"algorithmOrTest": "HMAC- SHA2- 512 (A3349)",
"condition": "During boot",
"details": "N/A",
"indicator": "HMAC- SHA2- 512 Known Answer Test : Passed",
"testMethod": "KAT",
"testProps": "Key Length: 512 bits",
"type": "CAST"
},
{
"algorithmOrTest": "KAS- ECC- SSC Sp800- 56Ar3 (A3349)",
"condition": "During boot",
"details": "N/A",
"indicator": "KAS- ECC- EPHEM- UNIFIED- NOKC Known Answer Test: Passed",
"testMethod": "KAT",
"testProps": "Domain Parameter Generation Methods: P- 256",
"type": "CAST"
},
{
"algorithmOrTest": "KAS- ECC- SSC Sp800- 56Ar3 (A3349)",
"condition": "During boot",
"details": "N/A",
"indicator": "KAS- ECC- EPHEM- UNIFIED- NOKC Known Answer Test: Passed",
"testMethod": "KAT",
"testProps": "Domain Parameter Generation Methods: P- 384",
"type": "CAST"
},
{
"algorithmOrTest": "KAS- FFC- SSC Sp800- 56Ar3 (A3349)",
"condition": "During boot",
"details": "N/A",
"indicator": "KAS- FFC- EPHEM- NOKC Known Answer Test: Passed",
"testMethod": "KAT",
"testProps": "Domain Parameter Generation Methods: MODP-2048",
"type": "CAST"
},
{
"algorithmOrTest": "KDF SSH (A3349)",
"condition": "During boot",
"details": "N/A",
"indicator": "KDF- SSH- SHA2- 256 Known Answer Test: Passed",
"testMethod": "KAT",
"testProps": "Cipher: AES- 128, AES- 192, AES- 256 ; Hash Algorithm: SHA-1, SHA2-256, SHA2-384, SHA2-512",
"type": "CAST"
},
{
"algorithmOrTest": "RSA SigGen (FIPS186 -4) (A3349)",
"condition": "During boot",
"details": "Sign",
"indicator": "RSA- SIGN Known Answer Test: Passed",
"testMethod": "KAT",
"testProps": "Modulus 2048 bits SHA2-256",
"type": "CAST"
},
{
"algorithmOrTest": "RSA SigVer (FIPS186 -4) (A3349)",
"condition": "During boot",
"details": "Verify",
"indicator": "RSA- VERIFY Known Answer Test: Passed",
"testMethod": "KAT",
"testProps": "Modulus 2048 bits SHA2-256",
"type": "CAST"
},
{
"algorithmOrTest": "ECDSA SigGen (FIPS186 -4) (A3349)",
"condition": "During boot",
"details": "Sign",
"indicator": "ECDSA- SIGN Known Answer Test: Passed",
"testMethod": "KAT",
"testProps": "Curve: P-256 Hash Algorithm: SHA2-256",
"type": "CAST"
},
{
"algorithmOrTest": "ECDSA SigVer (FIPS186 -4) (A3349)",
"condition": "During boot",
"details": "Verify",
"indicator": "ECDSA- VERIFY Known Answer Test: Passed",
"testMethod": "KAT",
"testProps": "Curve: P-256 Hash Algorithm: SHA2-256",
"type": "CAST"
},
{
"algorithmOrTest": "SHA2- 512 (A3348)",
"condition": "During boot",
"details": "N/A",
"indicator": "SHA-2- 512 Known Answer Test: Passed",
"testMethod": "KAT",
"testProps": "SHA2-512",
"type": "CAST"
},
{
"algorithmOrTest": "Entropy test",
"condition": "During boot and continually",
"details": "Cutoff value C = 21",
"indicator": "pass",
"testMethod": "RCT",
"testProps": "NIST SP 800-90B Repetitive Count Test",
"type": "CAST"
},
{
"algorithmOrTest": "Entropy test",
"condition": "During boot and continually",
"details": "W = 512; Cutoff value C = 311",
"indicator": "pass",
"testMethod": "APT",
"testProps": "NIST SP 800-90B Adapative Proportion Test",
"type": "CAST"
},
{
"algorithmOrTest": "ECDSA KeyGen (FIPS186 -4) (A3349)",
"condition": "On key generation",
"details": "Key pair generated for signature generation/verificati on in the context of SSHv2 protocol",
"indicator": "0",
"testMethod": "PCT",
"testProps": "Curve: P-256 Hash Algorithm: SHA2-256",
"type": "PCT"
},
{
"algorithmOrTest": "ECDSA KeyGen (FIPS186 -4) (A3349)",
"condition": "On key generation",
"details": "Key pair generated for SSP agreement in the context of SSHv2 protocol",
"indicator": "0",
"testMethod": "PCT",
"testProps": "Curve: P-256 Hash Algorithm: SHA2-256",
"type": "PCT"
},
{
"algorithmOrTest": "KAS- FFC- SSC Sp800- 56Ar3 (A3349)",
"condition": "On key generation",
"details": "Key pair generated for SSP agreement in the context of SSHv2 protocol",
"indicator": "0",
"testMethod": "PCT",
"testProps": "Capabilities: Domain Parameter: MODP2048",
"type": "PCT"
},
{
"algorithmOrTest": "RSA KeyGen (FIPS186 -4) (A3349)",
"condition": "On key generation",
"details": "Key pair generated for signature generation/verificati on in the context of SSHv2 protocol",
"indicator": "0",
"testMethod": "PCT",
"testProps": "Modulus: 2048 Hash SHA2-256",
"type": "PCT"
},
{
"algorithmOrTest": "ECDSA SigVer (FIPS186 -4) (A3349)",
"condition": "On loading of firmware from an external source",
"details": "Verify",
"indicator": "Host OS upgrade staged. Reboot the system to complete installatio n!",
"testMethod": "KAT",
"testProps": "Curve: P-256 Hash Algorithm: SHA2-256",
"type": "SW/F W Load"
},
{
"algorithmOrTest": "Manual entry test (duplicat e entries)",
"condition": "On configurati on of operator passwords",
"details": "N/A",
"indicator": "Comman d prompt with \"fips\" string provided post completio",
"testMethod": "Duplicat e entry test",
"testProps": "Duplicate entry test required for entry of operator passwords via direct connection to",
"type": "Manua l Entry"
},
{
"algorithmOrTest": "",
"condition": "",
"details": "",
"indicator": "n of the test",
"testMethod": "",
"testProps": "the module\u0027s console (serial) interface",
"type": ""
}
],
"found": true,
"section": 10,
"subsection": 2
},
"error_states": {
"entries": [
{
"conditions": "If the pre- operational firmware integrity test or if any of the CASTs fail",
"description": "If the pre-operation firmware integrity test, if any of the CASTs or pair- wise consistency tests fail, then the module returns an error indicator, inhibits all data output and enters the hard error state",
"indicator": "\"FIPS error: self- test failure\" for firmware integrity failure, \"FIPS error 1: \u003cname of the algorithm\u003e Known Answer Test: Failed\" for CAST failure and -1 for pair-wise consistency test failure",
"name": "Hard Error state",
"recoveryMethod": "N/A"
},
{
"conditions": "If the firmware load test fails If the APT or RCT test fails",
"description": "\u2022In case of a firmware load test failure, the module rejects the firmware, returns an error indicator and enters the soft error state \u2022In the event of an APT or RCT health test failure, output from the entropy source is inhibited, all entropy accumulated in the conditioning context is discarded and the start- up health-tests are performed again",
"indicator": "\"Validation Error\" for the firmware load test failure; entropy data discarded in case of APT/RCT failure",
"name": "Soft Error state",
"recoveryMethod": "N/A for firmware load test failure; In case of APT and/or RCT failures, new data continues to be tested by the health tests, and once both health tests indicate a \u0027pass\u0027, the entropy source again outputs data"
}
],
"found": true,
"section": 10,
"subsection": 4
},
"mechanisms_actions": {
"entries": [],
"found": false,
"section": 7,
"subsection": 1
},
"modes_of_operation": {
"entries": [
{
"description": "\u2022 The operator can verify that the cryptographic module is in the Approved mode by observing the console prompt and running the \u0027show version\u0027 command; \u2022 When operating in the Approved mode, the prompt will read \u0027\u003coperator\u003e:fips#\u0027 (e.g. root:fips#); \u2022 The \u0027show version\u0027 command will allow the Crypto Officer to verify that the validated firmware version is running on the module; \u2022 The Crypto Officer can also use the \u0027show system fips chassis level\u0027 command (returns \u0027level 1\u0027) to determine if the module is operating in the Approved mode; \u2022 The Approved mode is entered when the module is configured for it and successfully passes all self-tests (both pre-operational and conditional cryptographic algorithm self-tests (CASTs))",
"name": "Approved mode",
"statusIndicator": "global indicator (string \u0027fips\u0027 included in the command prompt)",
"type": "Approved"
},
{
"description": "\u2022 The cryptographic module supports a non- Approved mode of operation; \u2022 When operated in the non-Approved mode of operation, the module supports non-Approved algorithms as well as the algorithms supported in the Approved mode of operation",
"name": "Non- Approved mode",
"statusIndicator": "global indicator (implicit indicator based on exclusion of string \u0027fips\u0027 from the command prompt)",
"type": "Non- Approved"
}
],
"found": true,
"section": 2,
"subsection": 4
},
"non_approved_allowed_NSC": {
"entries": [
{
"caveat": "no security claimed",
"name": "SHA2-256 (JUNOS 22.3R1 QFX10K-LibMD Implementation)",
"use": "Used to store operator passwords in hashed form, per IG 2.4.A: Use of a non-approved cryptographic algorithm to \u0027obfuscate\u0027 a CSP"
},
{
"caveat": "no security claimed",
"name": "SHA-1 (JUNOS 22.3R1 QFX10K-Kernel)",
"use": "Used for an extraneous check in the Kernel, per IG 2.4.A: Use of an approved, non-approved or proprietary algorithm for a purpose that is not security relevant"
}
],
"found": true,
"section": 2,
"subsection": 5
},
"non_approved_allowed_algos": {
"entries": [],
"found": false,
"section": 2,
"subsection": 5
},
"non_approved_not_allowed": {
"entries": [
{
"name": "RSA with key size less than 2048",
"use": "SSH"
},
{
"name": "ECDSA with ed25519 curve",
"use": "SSH"
},
{
"name": "EC Diffie-Hellman with ed25519 curve",
"use": "SSH"
},
{
"name": "ARCFOUR",
"use": "SSH"
},
{
"name": "Blowfish",
"use": "SSH"
},
{
"name": "CAST",
"use": "SSH"
},
{
"name": "DSA (SignGen, SigVer, non-compliant)",
"use": "SSH"
},
{
"name": "HMAC-MD5",
"use": "SSH"
},
{
"name": "HMAC-RIPEMD160",
"use": "SSH"
},
{
"name": "UMAC",
"use": "SSH"
}
],
"found": true,
"section": 2,
"subsection": 5
},
"non_approved_services": {
"entries": [
{
"alg_accessed": "RSA with key size less than 2048 ECDSA with ed25519 curve EC Diffie- Hellman with ed25519 curve ARCFOUR Blowfish CAST DSA (SignGen, SigVer, non- compliant) HMAC-MD5 HMAC- RIPEMD160 UMAC",
"description": "Security relevant configuration",
"name": "Configure security (security relevant)",
"role": "Root, Super-user"
},
{
"alg_accessed": "None",
"description": "Non-security relevant configuration",
"name": "Configure (non- security relevant)",
"role": "Root, Super-user"
},
{
"alg_accessed": "None",
"description": "Query the module status",
"name": "Show status",
"role": "Root, Super-user, Operator, Read-Only, Unauthorized"
},
{
"alg_accessed": "None",
"description": "LEDs on the module provide physical status output",
"name": "Show status (LED)",
"role": "Root, Super-user, Operator, Read-Only, Unauthorized, Unauthenticated"
},
{
"alg_accessed": "None",
"description": "Query the module\u0027s versioning information",
"name": "Show module\u0027s versioning information",
"role": "Root, Super-user, Operator, Read-Only, Unauthorized"
},
{
"alg_accessed": "None",
"description": "Destroy all SSPs",
"name": "Zeroise (Perform zeroisation)",
"role": "Root, Super-user"
},
{
"alg_accessed": "RSA with key size less than 2048 ECDSA with ed25519 curve EC Diffie- Hellman with ed25519 curve ARCFOUR Blowfish CAST DSA (SignGen, SigVer, non- compliant) HMAC-MD5",
"description": "Initiate SSH connection for SSH monitoring and control (CLI)",
"name": "Perform approved security functions (SSH connection)",
"role": "Root, Super-user, Operator, Read-Only, Unauthorized"
},
{
"alg_accessed": "HMAC- RIPEMD160 UMAC",
"description": "",
"name": "",
"role": ""
},
{
"alg_accessed": "None",
"description": "Console monitoring and control (CLI)",
"name": "Console Access",
"role": "Root, Super-user, Operator, Read-Only, Unauthorized"
},
{
"alg_accessed": "None",
"description": "Software initiated reset, performs self-tests on demand",
"name": "Perform self-tests (remote reset)",
"role": "Root, Super-user, Operator, Read-Only, Unauthorized"
},
{
"alg_accessed": "None",
"description": "Hardware reset or power cycle",
"name": "Perform self-tests (local reset)",
"role": "Root, Super-user, Operator, Read-Only, Unauthorized, Unauthenticated"
},
{
"alg_accessed": "None",
"description": "Verification and loading of a validated firmware image into the router/switch",
"name": "Load Image",
"role": "Root, Super-user"
}
],
"found": true,
"section": 4,
"subsection": 4
},
"ports_interfaces": {
"entries": [
{
"data": "LAN Communications (QFX10002-36Q(40: 2 MGMT, 36 QSFP+, 1 ETH), QFX10002-72Q(80: 2 MGMT, 72 QSFP+, 1 ETH), QFX10002-60C (63: 2 MGMT, 60 QSFP+, 1 ETH), QFX10008(12: 4 MGMT, 8 SFP+), QFX10016(12: 4 MGMT, 8 SFP+))",
"logicalInterface": "Data Input Data Output Control Input Status Output",
"physicalPort": "Ethernet"
},
{
"data": "Serial Console Port (QFX10002(1), QFX10008(2), QFX10016(2))",
"logicalInterface": "Control Input Status Output",
"physicalPort": "Serial"
},
{
"data": "Load Junos OS image/configuration (QFX10002(1), QFX10008(2), QFX10016(2))",
"logicalInterface": "Data Input Control Input",
"physicalPort": "USB"
},
{
"data": "Power connector (QFX10002-36Q(4), QFX10002-72Q(4), QFX10002-60C(4), QFX10008(6), QFX10016(10))",
"logicalInterface": "Power",
"physicalPort": "Power"
},
{
"data": "Status indicator lighting (QFX10002(4) QFX10008(13) QFX10016(13))",
"logicalInterface": "Status Output",
"physicalPort": "LED"
},
{
"data": "Reset (QFX10002(1) QFX10008(2) QFX10016(2))",
"logicalInterface": "Control Input",
"physicalPort": "Reset"
},
{
"data": "PTP Connectors (QFX10002(2) QFX10008(8) QFX10016(8))",
"logicalInterface": "Control Input Status Output",
"physicalPort": "SMB"
},
{
"data": "Line card interface (QFX10008(8) QFX10016(16))",
"logicalInterface": "Data Input Data Output Control Input Status Output",
"physicalPort": "Backplane Line Card Interface"
}
],
"found": true,
"section": 3,
"subsection": 1
},
"roles": {
"entries": [
{
"authMethodList": "Username and password over the console and SSH Username and ECDSA public key over SSH Username and RSA public key over SSH",
"name": "Super-user",
"operatorType": "Crypto Officer (CO)",
"type": "Identity"
},
{
"authMethodList": "Username and password over the console and SSH Username and ECDSA public key over SSH Username and RSA public key over SSH",
"name": "Operator",
"operatorType": "User",
"type": "Identity"
},
{
"authMethodList": "Username and password over the console and SSH Username and ECDSA public key over SSH Username and RSA public key over SSH",
"name": "Read-only",
"operatorType": "User",
"type": "Identity"
},
{
"authMethodList": "Username and password over the console and SSH Username and ECDSA public key over SSH Username and RSA public key over SSH",
"name": "Root",
"operatorType": "Crypto Officer (CO)",
"type": "Identity"
},
{
"authMethodList": "Username and password over the console and SSH Username and ECDSA public key over SSH Username and RSA public key over SSH",
"name": "Unauthorised",
"operatorType": "User",
"type": "Identity"
}
],
"found": true,
"section": 4,
"subsection": 2
},
"security_levels": {
"entries": [
{
"level": "1",
"section": "1",
"title": "General"
},
{
"level": "1",
"section": "2",
"title": "Cryptographic module specification"
},
{
"level": "1",
"section": "3",
"title": "Cryptographic module interfaces"
},
{
"level": "3",
"section": "4",
"title": "Roles, services, and authentication"
},
{
"level": "1",
"section": "5",
"title": "Software/Firmware security"
},
{
"level": "1",
"section": "6",
"title": "Operational environment"
},
{
"level": "1",
"section": "7",
"title": "Physical security"
},
{
"level": "N/A",
"section": "8",
"title": "Non-invasive security"
},
{
"level": "1",
"section": "9",
"title": "Sensitive security parameter management"
},
{
"level": "1",
"section": "10",
"title": "Self-tests"
},
{
"level": "1",
"section": "11",
"title": "Life-cycle assurance"
},
{
"level": "N/A",
"section": "12",
"title": "Mitigation of other attacks"
},
{
"level": "1",
"section": "",
"title": "Overall Level"
}
],
"found": true,
"section": 1,
"subsection": 2
},
"self_tests": {
"entries": [
{
"algorithmOrTest": "Firmware Integrity Test",
"details": "Verify",
"indicator": "FIPS Self-tests Passed",
"testMethod": "KAT",
"testProps": "Using ECDSA P-256 with SHA2-256",
"type": "SW/FW Integrity"
}
],
"found": true,
"section": 10,
"subsection": 1
},
"ssp_io_methods": {
"entries": [
{
"dest": "NVRAM",
"distribution": "Automated",
"entry": "Electronic",
"format": "Encrypted",
"name": "Entered over SSH - NVRAM",
"sfiAlgo": "KTS1",
"source": "External endpoint"
},
{
"dest": "NVRAM",
"distribution": "N/A",
"entry": "N/A",
"format": "Plaintext",
"name": "Loaded at manufacture",
"sfiAlgo": "",
"source": "External endpoint"
},
{
"dest": "NVRAM",
"distribution": "Manual",
"entry": "Direct",
"format": "Plaintext",
"name": "Entered through the CLI via console connection - NVRAM",
"sfiAlgo": "",
"source": "External endpoint"
},
{
"dest": "RAM",
"distribution": "Automated",
"entry": "Electronic",
"format": "Plaintext",
"name": "Input during SSH negotiation",
"sfiAlgo": "",
"source": "External endpoint"
},
{
"dest": "External endpoint",
"distribution": "Automated",
"entry": "Electronic",
"format": "Plaintext",
"name": "Output during SSH negotiation (host key)",
"sfiAlgo": "",
"source": "NVRAM"
},
{
"dest": "External endpoint",
"distribution": "Automated",
"entry": "Electronic",
"format": "Plaintext",
"name": "Output during SSH negotiation (Key Agreement public key)",
"sfiAlgo": "",
"source": "RAM"
}
],
"found": true,
"section": 9,
"subsection": 2
},
"ssp_zeroization_methods": {
"entries": [
{
"description": "Command used to zeroise the module: request vmhost zeroize no-forwarding",
"method": "Zeroisation command",
"operatorId": "Operator initiated",
"rationale": "Used to provide zeroisation as a service"
},
{
"description": "Power cycling the module to zeroise temporary SSPs",
"method": "Power-cycle",
"operatorId": "Operator initiated",
"rationale": "Power cycling the module to zeroise temporary SSPs"
},
{
"description": "Termination of SSH sessions automatically zeroises",
"method": "Session termination",
"operatorId": "Module initiated",
"rationale": "Termination of SSH sessions automatically zeroises"
},
{
"description": "temporary SSPs used as part of the session",
"method": "",
"operatorId": "",
"rationale": "temporary SSPs used as part of the session"
},
{
"description": "PSP not zeroised since it cannot be modified due to being inaccessible in the filesystem",
"method": "Not zeroised",
"operatorId": "N/A",
"rationale": "PSP not zeroised since it cannot be modified due to being inaccessible in the filesystem"
},
{
"description": "EC Diffie-Hellman/Diffie- Hellman shared secrets are zeroised after use in derivation of SSH session key",
"method": "Derivation of SSH session key",
"operatorId": "Module initiated",
"rationale": "EC Diffie-Hellman/Diffie- Hellman shared secrets are zeroised after use in derivation of SSH session key"
}
],
"found": true,
"section": 9,
"subsection": 3
},
"storage_areas": {
"entries": [
{
"description": "Non-Volatile Random Access Memory",
"name": "NVRAM",
"persistance": "Static"
},
{
"description": "Random Access Memory",
"name": "RAM",
"persistance": "Dynamic"
}
],
"found": true,
"section": 9,
"subsection": 1
},
"tested_module_id_hw": {
"entries": [
{
"features": "JPSU-1600W-AC- AFO JPSU-1600W- DC-AFO",
"fwVersion": "Junos OS 22.3R1-S2.3",
"hwVersion": "QFX10002 -36Q",
"modelPartNum": "QFX10002- 36Q",
"processors": "Intel Xeon E3- 1125V2"
},
{
"features": "JPSU-1600W-AC- AFO JPSU-1600W- DC-AFO",
"fwVersion": "Junos OS 22.3R1-S2.3",
"hwVersion": "QFX10002-72Q",
"modelPartNum": "QFX10002- 72Q",
"processors": "Intel Xeon E3- 1125V2"
},
{
"features": "JPSU-1600W-AC- AFO JPSU-1600W- DC-AFO",
"fwVersion": "Junos OS 22.3R1-S2.3",
"hwVersion": "QFX10002-60C",
"modelPartNum": "QFX10002- 60C",
"processors": "Intel Xeon E3- 1125V2"
},
{
"features": "QFX10000-PWR-AC QFX10000-PWR-DC",
"fwVersion": "Junos OS 22.3R1-S2.3",
"hwVersion": "QFX10008 with QFX10000 Control board",
"modelPartNum": "QFX10008",
"processors": "Intel Xeon E3- 1125V2"
},
{
"features": "QFX10000-PWR-AC QFX10000-PWR-DC",
"fwVersion": "Junos OS 22.3R1-S2.3",
"hwVersion": "QFX10016 with QFX10000 Control board",
"modelPartNum": "QFX10016",
"processors": "Intel Xeon E3- 1125V2"
}
],
"found": true,
"section": 2,
"subsection": 2
},
"tested_module_id_hw_hy": {
"entries": [],
"found": false,
"section": 2,
"subsection": 2
},
"tested_module_id_sw_fw_hy": {
"entries": [],
"found": false,
"section": 2,
"subsection": 2
},
"tested_op_env_sw_fw_hy": {
"entries": [],
"found": false,
"section": 2,
"subsection": 2
},
"vendor_affirmed_algos": {
"entries": [
{
"algoPropList": "Key Type:Asymmetric",
"implName": "N/A",
"name": "CKG - Section 4 and 5.1",
"reference": "NIST SP800-133r2 Section 4: Asymmetric seed generation using an unmodified output from an Approved DRBG; Section 5.1: Key Pairs for Digital Signature Schemes"
},
{
"algoPropList": "Key Type:Asymmetric",
"implName": "N/A",
"name": "CKG - Section 4 and 5.2",
"reference": "NIST SP800-133r2 Section 4: Asymmetric seed generation using an unmodified output from an Approved DRBG; Section 5.2: Key Pairs for Key Establishment"
},
{
"algoPropList": "Key Type:Symmetric",
"implName": "N/A",
"name": "CKG - Section 6.2.1",
"reference": "NIST SP800-133r2 Section 6.2.1: Derivation of symmetric keys"
}
],
"found": true,
"section": 2,
"subsection": 5
},
"vendor_affirmed_op_env_sw_fw_hy": {
"entries": [],
"found": false,
"section": 2,
"subsection": 2
}
},
"is_br1_format": true,
"keywords": {
"asymmetric_crypto": {
"ECC": {
"ECDH": {
"ECDH": 46
},
"ECDSA": {
"ECDSA": 79
}
},
"FF": {
"DH": {
"DH": 46,
"Diffie-Hellman": 3
},
"DSA": {
"DSA": 3
}
},
"RSA": {
"RSA 2048": 1
}
},
"certification_process": {},
"cipher_mode": {
"CBC": {
"CBC": 9
},
"CTR": {
"CTR": 2
}
},
"cplc_data": {},
"crypto_engine": {},
"crypto_library": {
"OpenSSL": {
"OpenSSL": 3
}
},
"crypto_protocol": {
"SSH": {
"SSH": 199,
"SSHv2": 9
}
},
"crypto_scheme": {
"KA": {
"Key Agreement": 5
},
"MAC": {
"MAC": 3
}
},
"device_model": {},
"ecc_curve": {
"NIST": {
"P-256": 56,
"P-384": 20,
"P-521": 16,
"prime256v1": 2
}
},
"eval_facility": {},
"fips_cert_id": {},
"fips_certlike": {
"Certlike": {
"- PKCS 1": 2,
"AES CBC 128, 192": 1,
"AES CTR 128": 1,
"AES- 128": 1,
"AES- 192": 1,
"AES- 256": 1,
"AES-128": 1,
"AES-192": 1,
"AES-256": 1,
"DRBG 2": 3,
"DRBG 256": 1,
"DRBG 440": 1,
"DRBG2": 14,
"HMAC 198": 2,
"HMAC- SHA-1": 2,
"HMAC-SHA-1": 10,
"PKCS 1": 2,
"RSA 2048": 1,
"RSA2": 1,
"SHA-1": 7,
"SHA-2- 512": 1,
"SHA2- 256": 7,
"SHA2- 512": 3,
"SHA2-256": 23,
"SHA2-384": 4,
"SHA2-512": 15
}
},
"fips_security_level": {
"Level": {
"Level 1": 4,
"Level 3": 1,
"level 1": 4
}
},
"hash_function": {
"RIPEMD": {
"RIPEMD160": 2
},
"SHA": {
"SHA1": {
"SHA-1": 7
}
}
},
"ic_data_group": {},
"javacard_api_const": {},
"javacard_packages": {},
"javacard_version": {},
"os_name": {},
"pq_crypto": {},
"randomness": {
"PRNG": {
"DRBG": 31
},
"RNG": {
"RBG": 2
}
},
"side_channel_analysis": {},
"standard_id": {
"FIPS": {
"FIPS 140-3": 13,
"FIPS 180-4": 6,
"FIPS 186-4": 8,
"FIPS 198-1": 4,
"FIPS186": 8,
"FIPS186-4": 30
},
"NIST": {
"NIST SP 800-90B": 2,
"SP 800-135": 1,
"SP 800-38A": 3,
"SP 800-56A": 4,
"SP 800-90A": 2
},
"PKCS": {
"PKCS 1": 2
},
"X509": {
"X.509": 2
}
},
"symmetric_crypto": {
"AES_competition": {
"AES": {
"AES": 6,
"AES-": 9,
"AES-128": 1,
"AES-192": 1,
"AES-256": 1
},
"CAST": {
"CAST": 51
}
},
"DES": {
"3DES": {
"TDES": 1
}
},
"constructions": {
"MAC": {
"HMAC": 25
}
},
"miscellaneous": {
"Blowfish": {
"Blowfish": 3
}
}
},
"tee_name": {
"AMD": {
"PSP": 9
},
"IBM": {
"SSC": 10
}
},
"tls_cipher_suite": {},
"vendor": {},
"vulnerability": {}
},
"module_algorithms": {
"_type": "Set",
"elements": [
"HMAC-SHA2-256A3349",
"ECDSA SigGen (FIPS186-4)A3349",
"AES-CBCA3349",
"Safe Primes Key GenerationA3349",
"RSA KeyGen (FIPS186-4)A3349",
"KDF SSHA3349",
"RSA SigGen (FIPS186-4)A3349",
"KAS-FFC-SSC Sp800-56Ar3A3349",
"ECDSA KeyGen (FIPS186-4)A3349",
"AES-CTRA3349",
"SHA-1A3349",
"ECDSA SigVer (FIPS186-4)A3349",
"SHA2-512A3349",
"AES-ECBA3349",
"RSA SigVer (FIPS186-4)A3349",
"ECDSA KeyVer (FIPS186-4)A3349",
"KAS-ECC-SSC Sp800-56Ar3A3349",
"HMAC-SHA2-512A3349",
"SHA2-256A3349",
"HMAC DRBGA3349",
"Safe Primes Key VerificationA3349",
"HMAC-SHA-1A3349"
]
},
"policy_algorithms": {
"_type": "Set",
"elements": [
"#A3348",
"#A3349",
"#A3337"
]
},
"policy_metadata": {
"/Author": "",
"/Comments": "",
"/Company": "",
"/CreationDate": "D:20241203131910-05\u002700\u0027",
"/Creator": "Acrobat PDFMaker 24 for Word",
"/Keywords": "",
"/ModDate": "D:20241203132025-05\u002700\u0027",
"/Producer": "Adobe PDF Library 24.3.144",
"/SourceModified": "",
"/Subject": "",
"/Title": "",
"pdf_file_size_bytes": 1306515,
"pdf_hyperlinks": {
"_type": "Set",
"elements": [
"https://csrc.nist.gov/projects/cryptographic-module-validation-program",
"http://www.juniper.net/support/downloads/junos.html"
]
},
"pdf_is_encrypted": false,
"pdf_number_of_pages": 60
}
},
"state": {
"_type": "sec_certs.sample.fips.InternalState",
"module": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": null,
"source_hash": null,
"txt_hash": null
},
"policy": {
"_type": "sec_certs.sample.document_state.DocumentState",
"convert_ok": true,
"download_ok": true,
"extract_ok": true,
"json_hash": "a1f517471c9141401bc85724f32f1e5fb62afbf793ac68b84048ff7b3cb31f09",
"source_hash": "1d783b2d58452893938e5c1e26def9668ce7dc11c99dc56b7624acb84ebafd81",
"txt_hash": "2520d4a260dcf947641dce3880db42aa2226902ea6dc8494a054c1225c9a7b58"
}
},
"web_data": {
"_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
"caveat": "Interim validation. When operated in Approved mode. When installed, initialized and configured as specified in Section 11 of the Security Policy. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.",
"certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/November 2024_021224_0125.pdf",
"date_sunset": "2026-11-17",
"description": "Juniper Networks QFX10002, QFX10008, QFX10016 are QFX Series switches. The cryptographic module provides for an encrypted connection, using SSH, between the management station and the QFX switch.",
"embodiment": "Multi-Chip Stand Alone",
"exceptions": [
"Roles, services, and authentication: Level 3",
"Non-invasive security: N/A",
"Mitigation of other attacks: N/A"
],
"fw_versions": null,
"historical_reason": null,
"hw_versions": null,
"level": 1,
"mentioned_certs": {},
"module_name": "Juniper Networks QFX10002, QFX10008 and QFX10016",
"module_type": "Hardware",
"revoked_link": null,
"revoked_reason": null,
"standard": "FIPS 140-3",
"status": "active",
"sw_versions": null,
"tested_conf": null,
"validation_history": [
{
"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
"date": "2024-11-18",
"lab": "Acumen Security",
"validation_type": "Initial"
}
],
"vendor": "Juniper Networks, Inc.",
"vendor_url": "http://www.juniper.net"
}
}