Ruckus FastIron ICX ™ 7550/7650/7850 Series Switch/Router

Certificate details

Certificate ID #4836
Status active
Validation dates 11.10.2024
Sunset date 10-10-2029
Standard FIPS 140-3
Security level 1
Type Hardware
Embodiment Multi-Chip Stand Alone
Caveat When installed, initialized and configured as specified in section "Secure Operation" of the Security Policy and operated in approved mode
Exceptions
  • Roles, services, and authentication: Level 2
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A
Description The ICX® family of fixed form-factor switches works together to deliver a complete, scalable, and high-performance network solution that supports today’s demanding video, Unified Communications (UC), VDI, and mobile applications. They leverage the innovative Campus Fabric technology, which provides simplified network deployment and management, scale-out networking, and investment protection with the industry’s lowest total cost of ownership.
Version (Hardware) ICX7550-24-E2[1][2], ICX7550-48-E2[1][2], ICX7550-24P-E2[1][2], ICX7550-48P-E2[1][2], ICX7550-24ZP-E2[1][2][3], ICX7550-24F-E2[1] [2][3], ICX7550-48F-E2[1][2][3], ICX7650-48F-E2[1][2][3], ICX7650-48P-E2[1][2][3], ICX7650-48ZP-E[1][2][3] with {ICX7650/7550-2X40GQ[1], ICX7650/7550-4X10GF[2], ICX7650/7550-1X100GQ[3]}, ICX7850-32Q-E2, ICX7850-48F-E2, ICX7850-48FS, ICX7850-48C-E2 and ICX7850-32Q-E2
Version (Firmware) IronWare OS 09.0.10
Vendor Ruckus Wireless LLC http://www.commscope.com
Lab Gossamer Security Solutions
Algorithms
  • AES-CBCA2345
  • AES-CFB128A2345
  • AES-CMACA2345
  • AES-CTRA2345
  • AES-ECBAES 4550
  • AES-GCMAES 4550
  • AES-KWA2345
  • AES-KWPA2345
  • Counter DRBGA2345
  • ECDSA KeyGen (FIPS186-4)A2345
  • ECDSA SigGen (FIPS186-4)A2345
  • ECDSA SigVer (FIPS186-4)A2345
  • HMAC-SHA-1A2345
  • HMAC-SHA2-256A2345
  • HMAC-SHA2-384A2345
  • KAS-ECC-SSC Sp800-56Ar3A2345
  • KAS-FFC-SSC Sp800-56Ar3A2345
  • KDF SNMPA2345
  • KDF SP800-108A2345
  • KDF SSHA2345
  • KDF TLSA2345
  • RSA KeyGen (FIPS186-4)A2345
  • RSA SigGen (FIPS186-4)A2345
  • RSA SigVer (FIPS186-4)A2345
  • Safe Primes Key GenerationA2345
  • SHA-1A2345
  • SHA2-256A2345
  • SHA2-384A2345
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Extracted keywords

Symmetric Algorithms
AES, AES-256, AES-, CAST, DES, TDEA, HMAC
Asymmetric Algorithms
RSA 2048, ECDH, ECDSA, ECC, DH, Diffie-Hellman, DSA
Hash functions
SHA-1
Schemes
Key Agreement
Protocols
SSH, SSHv2, SSL, TLS, TLSv1.2
Randomness
DRBG, RNG, RBG
Elliptic Curves
P-256, P-384, P-521
Block cipher modes
ECB, GCM

Trusted Execution Environments
SSC

Security level
Level 1, level 1

Cross-references

Outgoing
  • 137 - historical - BlackBerry 850/857and BlackBerry 950/957Cryptographic Kernel

Automated analysis

Automated inference - use with caution

All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.

No automatically derived data are available in this section.

Cross-references

Loading...

Processing updates

Feed
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 4836,
  "dgst": "4a01d23dba2dee61",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "KDF SNMPA2345",
        "#A2345",
        "AES-KWPA2345",
        "RSA SigVer (FIPS186-4)A2345",
        "RSA KeyGen (FIPS186-4)A2345",
        "AES-ECBAES 4550",
        "KDF SP800-108A2345",
        "AES-CBCA2345",
        "SHA-1A2345",
        "KAS-FFC-SSC Sp800-56Ar3A2345",
        "AES-KWA2345",
        "AES-CMACA2345",
        "SHA2-256A2345",
        "ECDSA SigGen (FIPS186-4)A2345",
        "ECDSA SigVer (FIPS186-4)A2345",
        "KDF TLSA2345",
        "HMAC-SHA2-384A2345",
        "KAS-ECC-SSC Sp800-56Ar3A2345",
        "HMAC-SHA-1A2345",
        "AES-CFB128A2345",
        "RSA SigGen (FIPS186-4)A2345",
        "AES-GCMAES 4550",
        "ECDSA KeyGen (FIPS186-4)A2345",
        "AES-CTRA2345",
        "KDF SSHA2345",
        "Counter DRBGA2345",
        "HMAC-SHA2-256A2345",
        "Safe Primes Key GenerationA2345",
        "SHA2-384A2345",
        "#4550"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "09.0.10"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": {
        "_type": "Set",
        "elements": [
          "137"
        ]
      },
      "indirectly_referenced_by": null,
      "indirectly_referencing": {
        "_type": "Set",
        "elements": [
          "137"
        ]
      }
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": [
        "137"
      ]
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 8
          },
          "ECDH": {
            "ECDH": 22
          },
          "ECDSA": {
            "ECDSA": 46
          }
        },
        "FF": {
          "DH": {
            "DH": 22,
            "Diffie-Hellman": 12
          },
          "DSA": {
            "DSA": 1
          }
        },
        "RSA": {
          "RSA 2048": 4
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "ECB": {
          "ECB": 1
        },
        "GCM": {
          "GCM": 5
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "SSH": {
          "SSH": 80,
          "SSHv2": 21
        },
        "TLS": {
          "SSL": {
            "SSL": 10
          },
          "TLS": {
            "TLS": 89,
            "TLSv1.2": 1
          }
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 2
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-256": 34,
          "P-384": 16,
          "P-521": 10
        }
      },
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "#1": 1,
          "#137": 1,
          "#4550": 5
        }
      },
      "fips_certlike": {
        "Certlike": {
          "#4550 AES": 2,
          "AES #4550": 2,
          "AES Cert. #4550": 2,
          "AES-256": 1,
          "AES-CBC 128": 2,
          "AES-CBC 128 and 256": 1,
          "AES-CMAC 128": 3,
          "AES-CTR 128 and 256": 1,
          "AES-GCM 128": 5,
          "AES-GCM 128 and 256": 1,
          "HMAC-SHA- 1": 12,
          "HMAC-SHA-1": 8,
          "PKCS 1": 4,
          "RSA 2048": 4,
          "SHA-1": 3,
          "SHA2-256": 14,
          "SHA2-384": 6,
          "SHA2256": 1
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 3,
          "level 1": 1
        }
      },
      "hash_function": {
        "SHA": {
          "SHA1": {
            "SHA-1": 3
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 51
        },
        "RNG": {
          "RBG": 1,
          "RNG": 1
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-3": 18,
          "FIPS 186-4": 8,
          "FIPS140-3": 2,
          "FIPS180-4": 3,
          "FIPS186-4": 6,
          "FIPS197": 8,
          "FIPS198-1": 3
        },
        "ISO": {
          "ISO/IEC 24759": 2
        },
        "NIST": {
          "SP 800-38D": 2,
          "SP 800-52": 1
        },
        "PKCS": {
          "PKCS 1": 2
        },
        "RFC": {
          "RFC 5288": 1,
          "RFC2104": 1
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 23,
            "AES-": 2,
            "AES-256": 1
          },
          "CAST": {
            "CAST": 1
          }
        },
        "DES": {
          "3DES": {
            "TDEA": 1
          },
          "DES": {
            "DES": 2
          }
        },
        "constructions": {
          "MAC": {
            "HMAC": 8
          }
        }
      },
      "tee_name": {
        "IBM": {
          "SSC": 8
        }
      },
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "module_algorithms": {
      "_type": "Set",
      "elements": [
        "KDF SNMPA2345",
        "AES-KWPA2345",
        "RSA SigVer (FIPS186-4)A2345",
        "RSA KeyGen (FIPS186-4)A2345",
        "AES-ECBAES 4550",
        "KDF SP800-108A2345",
        "AES-CBCA2345",
        "SHA-1A2345",
        "KAS-FFC-SSC Sp800-56Ar3A2345",
        "AES-KWA2345",
        "AES-CMACA2345",
        "SHA2-256A2345",
        "ECDSA SigGen (FIPS186-4)A2345",
        "ECDSA SigVer (FIPS186-4)A2345",
        "KDF TLSA2345",
        "HMAC-SHA2-384A2345",
        "KAS-ECC-SSC Sp800-56Ar3A2345",
        "HMAC-SHA-1A2345",
        "AES-CFB128A2345",
        "RSA SigGen (FIPS186-4)A2345",
        "AES-GCMAES 4550",
        "ECDSA KeyGen (FIPS186-4)A2345",
        "AES-CTRA2345",
        "KDF SSHA2345",
        "Counter DRBGA2345",
        "HMAC-SHA2-256A2345",
        "Safe Primes Key GenerationA2345",
        "SHA2-384A2345"
      ]
    },
    "policy_algorithms": {
      "_type": "Set",
      "elements": [
        "#4550",
        "#A2345"
      ]
    },
    "policy_metadata": {
      "/Author": "Kim Schaffer",
      "/CreationDate": "D:20241008130109-04\u002700\u0027",
      "/Creator": "Microsoft\u00ae Word 2016",
      "/Keywords": "\"Cryptographic Module Validation Program; CMVP; FIPS 140 testing; FIPS 140; ISO/IEC 19790; ISO/IEC 24759; testing requirement; vendor evidence; vendor documentation; security policy\"",
      "/ModDate": "D:20241008130109-04\u002700\u0027",
      "/Producer": "Microsoft\u00ae Word 2016",
      "/Subject": "NIST Special Publication (SP) 800-140B is to be used in conjunction with ISO/IEC 19790 Annex B and ISO/IEC 24759 section 6.14. The special publication modifies only those requirements identified in this document. SP 800-140B also specifies the content of",
      "/Title": "CMVP Security Policy Requirements: CMVP Validation Authority Updates to ISO/IEC 24759 and ISO/IEC 19790 Annex B",
      "pdf_file_size_bytes": 1123133,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "http://www.commscope.com/",
          "https://csrc.nist.gov/projects/cryptographic-module-validation-program"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 33
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.InternalState",
    "module": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "policy": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": "0c69ca29ecd2f292681a814b84398c35d76cdb2441fa9565657cddf860bfed29",
      "source_hash": "d7e55d06abd9b7c69174f00860a0c8c7eef1c5118165da52a1b8ec79e06783a6",
      "txt_hash": "07c8bb7db73726df022c35fc410cd6baac15a28e8dc5bcd4e12989efe9a9ff7a"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When installed, initialized and configured as specified in section \"Secure Operation\" of the Security Policy and operated in approved mode",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/October 2024_041124_0733 (1).pdf",
    "date_sunset": "2029-10-10",
    "description": "The ICX\u00ae family of fixed form-factor switches works together to deliver a complete, scalable, and high-performance network solution that supports today\u2019s demanding video, Unified Communications (UC), VDI, and mobile applications. They leverage the innovative Campus Fabric technology, which provides simplified network deployment and management, scale-out networking, and investment protection with the industry\u2019s lowest total cost of ownership.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Roles, services, and authentication: Level 2",
      "Non-invasive security: N/A",
      "Mitigation of other attacks: N/A"
    ],
    "fw_versions": "IronWare OS 09.0.10",
    "historical_reason": null,
    "hw_versions": "ICX7550-24-E2[1][2], ICX7550-48-E2[1][2], ICX7550-24P-E2[1][2], ICX7550-48P-E2[1][2], ICX7550-24ZP-E2[1][2][3], ICX7550-24F-E2[1] [2][3], ICX7550-48F-E2[1][2][3], ICX7650-48F-E2[1][2][3], ICX7650-48P-E2[1][2][3], ICX7650-48ZP-E[1][2][3] with {ICX7650/7550-2X40GQ[1], ICX7650/7550-4X10GF[2], ICX7650/7550-1X100GQ[3]}, ICX7850-32Q-E2, ICX7850-48F-E2, ICX7850-48FS, ICX7850-48C-E2 and ICX7850-32Q-E2",
    "level": 1,
    "mentioned_certs": {},
    "module_name": "Ruckus FastIron ICX \u2122 7550/7650/7850 Series Switch/Router",
    "module_type": "Hardware",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-3",
    "status": "active",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2024-10-11",
        "lab": "Gossamer Security Solutions",
        "validation_type": "Initial"
      }
    ],
    "vendor": "Ruckus Wireless LLC",
    "vendor_url": "http://www.commscope.com"
  }
}