McAfee Firewall Enterprise Virtual Appliance for VMware

Certificate details

Certificate ID #2238
Status historical
Historical reason RNG SP800-131A Revision 1 Transition
Validation dates 08.09.2014
Standard FIPS 140-2
Security level 1
Type Software
Embodiment Multi-Chip Stand Alone
Caveat When operated in FIPS mode and when installed, initialized and configured as specified in the Security Policy Section Secure Operation. The module generates cryptographic keys whose strengths are modified by available entropy
Exceptions
  • Cryptographic Module Specification: Level 3
  • Roles, Services, and Authentication: Level 2
  • Physical Security: N/A
  • Design Assurance: Level 2
  • Mitigation of Other Attacks: N/A
Description McAfee Firewall Enterprise solutions provide unmatched protection for the enterprise in the most mission-critical and sensitive environments. McAfee's Firewall Enterprise appliances are created to meet the specific needs of organizations of all types and enable those organizations to reduce costs and mitigate the evolving risks that threaten today's networks and applications.
Tested configurations
  • McAfee SecureOS v8.3 on VMware ESXi 5.0 running on a McAfee S7032 (single-user mode)
Vendor McAfee, Inc. http://www.mcafee.com
Lab EWA - Canada
Algorithms
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Extracted keywords

Symmetric Algorithms
AES, AES-128, AES-, AES-256, DES, Triple-DES, HMAC
Asymmetric Algorithms
ECDSA, Diffie-Hellman, DH, DSA
Hash functions
SHA-1, SHA-256, SHA-384, SHA-512
Schemes
MAC, Key Exchange, Key Agreement
Protocols
SSH, SSL, TLS, TLS 1.0, DTLS, IKE, IPsec, VPN
Randomness
PRNG, DRBG, RNG
Block cipher modes
ECB, CBC, CTR, CFB, OFB

Security level
Level 1

Automated analysis

Automated inference - use with caution

All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.

No automatically derived data are available in this section.

Cross-references

No references are available for this certificate.

Processing updates

Feed
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 2238,
  "dgst": "7a98c22ae38c33c9",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "#448",
        "#829",
        "#2278",
        "#1628",
        "CVL#170",
        "SHS#2277",
        "DSA#831",
        "#1833",
        "#1185",
        "#831",
        "#1410",
        "#1086",
        "DRBG#451",
        "#473",
        "HMAC#1691",
        "#2276",
        "#1408",
        "#2711",
        "#2713",
        "#1692",
        "CVL#172",
        "SHS#1722",
        "#168",
        "#1612",
        "HMAC#1693",
        "ECDSA#475",
        "DRBG#449",
        "AES#2714",
        "#1630",
        "#475",
        "#450",
        "Triple-DES#1275",
        "SHS#2279",
        "DSA#829",
        "Triple-DES#1629",
        "Triple-DES#1631",
        "ECDSA#473",
        "HMAC#1184",
        "RNG#1032",
        "AES#2712",
        "#964",
        "#171",
        "#1690",
        "AES#1963",
        "RSA#1410",
        "RSA#1408"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "-"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "br1_deviations": 44,
    "br1_tables": null,
    "is_br1_format": false,
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECDSA": {
            "ECDSA": 4
          }
        },
        "FF": {
          "DH": {
            "DH": 3,
            "Diffie-Hellman": 3
          },
          "DSA": {
            "DSA": 18
          }
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 5
        },
        "CFB": {
          "CFB": 2
        },
        "CTR": {
          "CTR": 2
        },
        "ECB": {
          "ECB": 4
        },
        "OFB": {
          "OFB": 3
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "IKE": {
          "IKE": 19
        },
        "IPsec": {
          "IPsec": 17
        },
        "SSH": {
          "SSH": 16
        },
        "TLS": {
          "DTLS": {
            "DTLS": 11
          },
          "SSL": {
            "SSL": 11
          },
          "TLS": {
            "TLS": 66,
            "TLS 1.0": 1
          }
        },
        "VPN": {
          "VPN": 8
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 24
        },
        "KEX": {
          "Key Exchange": 3
        },
        "MAC": {
          "MAC": 1
        }
      },
      "device_model": {},
      "ecc_curve": {},
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "#1": 4,
          "#1086": 1,
          "#1185": 1,
          "#1408": 3,
          "#1612": 1,
          "#1628": 1,
          "#168": 3,
          "#1690": 1,
          "#171": 1,
          "#1833": 1,
          "#2276": 1,
          "#2711": 1,
          "#448": 1,
          "#473": 1,
          "#829": 5,
          "#964": 1
        }
      },
      "fips_certlike": {
        "Certlike": {
          "AES- 256": 7,
          "AES-128": 7,
          "AES-256": 3,
          "CVL 24": 1,
          "DES 23": 1,
          "DRBG 20": 1,
          "DSA 15": 1,
          "HMAC 18": 2,
          "HMAC SHA-1": 4,
          "HMAC SHA-256": 1,
          "HMAC-SHA1": 2,
          "PKCS #1": 3,
          "PKCS 14": 2,
          "RSA 13": 1,
          "RSA PKCS #1": 3,
          "SHA 17": 1,
          "SHA-1": 10,
          "SHA-256": 5,
          "SHA-384": 4,
          "SHA-512": 2,
          "SHA-512 #1690": 1,
          "SHA-512 #2276": 1
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 4
        }
      },
      "hash_function": {
        "SHA": {
          "SHA1": {
            "SHA-1": 10
          },
          "SHA2": {
            "SHA-256": 5,
            "SHA-384": 4,
            "SHA-512": 4
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 4,
          "PRNG": 16
        },
        "RNG": {
          "RNG": 5
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-2": 19,
          "FIPS 1402": 1
        },
        "NIST": {
          "SP 800-90": 1
        },
        "PKCS": {
          "PKCS #1": 3,
          "PKCS 14": 1
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 7,
            "AES-": 7,
            "AES-128": 7,
            "AES-256": 3
          }
        },
        "DES": {
          "3DES": {
            "Triple-DES": 8
          },
          "DES": {
            "DES": 4
          }
        },
        "constructions": {
          "MAC": {
            "HMAC": 8
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "module_algorithms": {
      "_type": "Set",
      "elements": [
        "CVL#170",
        "SHS#2277",
        "DSA#831",
        "DRBG#451",
        "HMAC#1691",
        "CVL#172",
        "SHS#1722",
        "HMAC#1693",
        "ECDSA#475",
        "DRBG#449",
        "AES#2714",
        "Triple-DES#1275",
        "SHS#2279",
        "DSA#829",
        "Triple-DES#1629",
        "Triple-DES#1631",
        "ECDSA#473",
        "HMAC#1184",
        "RNG#1032",
        "AES#2712",
        "AES#1963",
        "RSA#1410",
        "RSA#1408"
      ]
    },
    "policy_algorithms": {
      "_type": "Set",
      "elements": [
        "#448",
        "#829",
        "#2278",
        "#1628",
        "#1833",
        "#1185",
        "#831",
        "#1410",
        "#1086",
        "#473",
        "#2276",
        "#1408",
        "#2711",
        "#2713",
        "#1692",
        "#168",
        "#1612",
        "#1630",
        "#475",
        "#450",
        "#964",
        "#171",
        "#1690"
      ]
    },
    "policy_metadata": {
      "/Author": "Darryl H. Johnson",
      "/CreationDate": "D:20140717101608-04\u002700\u0027",
      "/Creator": "Microsoft\u00ae Office Word 2007",
      "/ModDate": "D:20140908085818-04\u002700\u0027",
      "/Producer": "Microsoft\u00ae Office Word 2007",
      "/Subject": "McAfee Firewall Enterprise Virtual Appliance for VMware",
      "/Title": "Security Policy",
      "pdf_file_size_bytes": 975634,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "http://csrc.nist.gov/groups/STM/cmvp/documents/140-1/140val-all.htm",
          "http://www.mcafee.com/",
          "http://www.mcafee.com/us/downloads",
          "http://csrc.nist.gov/groups/STM/cmvp",
          "http://www.corsec.com/",
          "mailto:[email protected]",
          "http://mysupport.mcafee.com/"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 33
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.InternalState",
    "module": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "policy": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": "b3a99e9cc67ae46c796e6c72d581ef6673ee0d492b65f42742535313442c8156",
      "source_hash": "020aeb32214a854e956909d1e3136349b5a1e585f2d2bf3916e8a92882f18429",
      "txt_hash": "770f117c3e0f2825b6a7df819f9e4f5321fdb4d2e4cc758bb81de6e2d85d9743"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in FIPS mode and when installed, initialized and configured as specified in the Security Policy Section Secure Operation. The module generates cryptographic keys whose strengths are modified by available entropy",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/FIPS140ConsolidatedCertList0045.pdf",
    "date_sunset": null,
    "description": "McAfee Firewall Enterprise solutions provide unmatched protection for the enterprise in the most mission-critical and sensitive environments. McAfee\u0027s Firewall Enterprise appliances are created to meet the specific needs of organizations of all types and enable those organizations to reduce costs and mitigate the evolving risks that threaten today\u0027s networks and applications.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Cryptographic Module Specification: Level 3",
      "Roles, Services, and Authentication: Level 2",
      "Physical Security: N/A",
      "Design Assurance: Level 2",
      "Mitigation of Other Attacks: N/A"
    ],
    "fw_versions": null,
    "historical_reason": "RNG SP800-131A Revision 1 Transition",
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {},
    "module_name": "McAfee Firewall Enterprise Virtual Appliance for VMware",
    "module_type": "Software",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-2",
    "status": "historical",
    "sw_versions": "8.3.2 with patch number 8.3.2E14",
    "tested_conf": [
      "McAfee SecureOS v8.3 on VMware ESXi 5.0 running on a McAfee S7032 (single-user mode)"
    ],
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2014-09-08",
        "lab": "EWA - Canada",
        "validation_type": "Initial"
      }
    ],
    "vendor": "McAfee, Inc.",
    "vendor_url": "http://www.mcafee.com"
  }
}