McAfee Firewall Enterprise Virtual Appliance for VMware

Certificate #2238

Webpage information

Status historical
Historical reason RNG SP800-131A Revision 1 Transition
Validation dates 08.09.2014
Standard FIPS 140-2
Security level 1
Type Software
Embodiment Multi-Chip Stand Alone
Caveat When operated in FIPS mode and when installed, initialized and configured as specified in the Security Policy Section Secure Operation. The module generates cryptographic keys whose strengths are modified by available entropy
Exceptions
  • Cryptographic Module Specification: Level 3
  • Roles, Services, and Authentication: Level 2
  • Physical Security: N/A
  • Design Assurance: Level 2
  • Mitigation of Other Attacks: N/A
Description McAfee Firewall Enterprise solutions provide unmatched protection for the enterprise in the most mission-critical and sensitive environments. McAfee's Firewall Enterprise appliances are created to meet the specific needs of organizations of all types and enable those organizations to reduce costs and mitigate the evolving risks that threaten today's networks and applications.
Tested configurations
  • McAfee SecureOS v8.3 on VMware ESXi 5.0 running on a McAfee S7032 (single-user mode)
Vendor McAfee, Inc.
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Symmetric Algorithms
AES, AES-128, AES-, AES-256, DES, Triple-DES, HMAC
Asymmetric Algorithms
ECDSA, Diffie-Hellman, DH, DSA
Hash functions
SHA-1, SHA-256, SHA-384, SHA-512
Schemes
MAC, Key Exchange, Key Agreement
Protocols
SSH, SSL, TLS, TLS 1.0, DTLS, IKE, IPsec, VPN
Randomness
PRNG, DRBG, RNG
Block cipher modes
ECB, CBC, CTR, CFB, OFB

Security level
Level 1

Standards
FIPS 140-2, SP 800-90, PKCS14, PKCS #1

File metadata

Title Security Policy
Subject McAfee Firewall Enterprise Virtual Appliance for VMware
Author Darryl H. Johnson
Creation date D:20140717101608-04'00'
Modification date D:20140908085818-04'00'
Pages 33
Creator Microsoft® Office Word 2007
Producer Microsoft® Office Word 2007

References

Outgoing
  • 168 - historical - LUNA® RA Secure Key Issuance HSM token
  • 2711 - historical - Red Hat Enterprise Linux NSS Cryptographic Module v4.0
  • 1628 - historical - XM Crypto Module
  • 964 - historical - Motorola Gold Elite Gateway Secure Card Crypto Engine (MGEG SCCE)
  • 1086 - historical - Lenel OnGuard Communication Server
  • 171 - historical - nForce 150 SCSI and nForce 400 SCSI
  • 1185 - historical - FIPSCOM Cryptographic Module
  • 448 - historical - SafGuard 200 HSM
  • 1833 - historical - Fusion 802.1x Authentication Supplicant
  • 1612 - historical - Mocana Cryptographic Loadable Kernel Module

Heuristics

No heuristics are available for this certificate.

References

Loading...

Updates Feed

  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 2238,
  "dgst": "7a98c22ae38c33c9",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "Triple-DES#1631",
        "RNG#1032",
        "ECDSA#475",
        "RSA#1408",
        "CVL#172",
        "HMAC#1691",
        "SHS#2277",
        "AES#1963",
        "HMAC#1184",
        "AES#2714",
        "DRBG#451",
        "SHS#2279",
        "CVL#170",
        "DSA#829",
        "AES#2712",
        "RSA#1410",
        "Triple-DES#1275",
        "Triple-DES#1629",
        "HMAC#1693",
        "SHS#1722",
        "ECDSA#473",
        "DRBG#449",
        "DSA#831"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "-"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": {
        "_type": "Set",
        "elements": [
          "1612",
          "1833",
          "1185",
          "1628",
          "171",
          "168",
          "964",
          "1086",
          "448",
          "2711"
        ]
      },
      "indirectly_referenced_by": null,
      "indirectly_referencing": {
        "_type": "Set",
        "elements": [
          "1612",
          "1833",
          "1185",
          "1628",
          "88",
          "171",
          "168",
          "315",
          "964",
          "149",
          "1086",
          "382",
          "448",
          "484",
          "2711"
        ]
      }
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": [
        "1612",
        "1833",
        "1185",
        "1628",
        "171",
        "168",
        "964",
        "1086",
        "448",
        "2711"
      ]
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECDSA": {
            "ECDSA": 4
          }
        },
        "FF": {
          "DH": {
            "DH": 3,
            "Diffie-Hellman": 4
          },
          "DSA": {
            "DSA": 19
          }
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 5
        },
        "CFB": {
          "CFB": 2
        },
        "CTR": {
          "CTR": 2
        },
        "ECB": {
          "ECB": 4
        },
        "OFB": {
          "OFB": 3
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "IKE": {
          "IKE": 17
        },
        "IPsec": {
          "IPsec": 16
        },
        "SSH": {
          "SSH": 15
        },
        "TLS": {
          "DTLS": {
            "DTLS": 10
          },
          "SSL": {
            "SSL": 11
          },
          "TLS": {
            "TLS": 64,
            "TLS 1.0": 1
          }
        },
        "VPN": {
          "VPN": 7
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 24
        },
        "KEX": {
          "Key Exchange": 3
        },
        "MAC": {
          "MAC": 1
        }
      },
      "device_model": {},
      "ecc_curve": {},
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "#1": 4,
          "#1086": 1,
          "#1185": 1,
          "#1408": 3,
          "#1612": 1,
          "#1628": 1,
          "#168": 3,
          "#1690": 1,
          "#171": 1,
          "#1833": 1,
          "#2276": 1,
          "#2711": 1,
          "#448": 1,
          "#473": 1,
          "#829": 5,
          "#964": 1
        }
      },
      "fips_certlike": {
        "Certlike": {
          "AES- 256": 7,
          "AES-128": 7,
          "AES-256": 3,
          "CVL24": 1,
          "DES23": 1,
          "DRBG20": 1,
          "DSA 17": 1,
          "DSA15": 1,
          "HMAC SHA-1": 4,
          "HMAC SHA-256": 1,
          "HMAC-SHA1": 2,
          "HMAC18": 2,
          "PKCS #1": 3,
          "PKCS14": 2,
          "RSA PKCS #1": 3,
          "RSA13": 1,
          "SHA-1": 10,
          "SHA-256": 5,
          "SHA-384": 4,
          "SHA-512": 2,
          "SHA-512 #1690": 1,
          "SHA-512 #2276": 1
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 5
        }
      },
      "hash_function": {
        "SHA": {
          "SHA1": {
            "SHA-1": 10
          },
          "SHA2": {
            "SHA-256": 5,
            "SHA-384": 4,
            "SHA-512": 4
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 4,
          "PRNG": 16
        },
        "RNG": {
          "RNG": 5
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-2": 17
        },
        "NIST": {
          "SP 800-90": 1
        },
        "PKCS": {
          "PKCS #1": 3,
          "PKCS14": 1
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 7,
            "AES-": 7,
            "AES-128": 7,
            "AES-256": 3
          }
        },
        "DES": {
          "3DES": {
            "Triple-DES": 8
          },
          "DES": {
            "DES": 5
          }
        },
        "constructions": {
          "MAC": {
            "HMAC": 8
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "Darryl H. Johnson",
      "/CreationDate": "D:20140717101608-04\u002700\u0027",
      "/Creator": "Microsoft\u00ae Office Word 2007",
      "/ModDate": "D:20140908085818-04\u002700\u0027",
      "/Producer": "Microsoft\u00ae Office Word 2007",
      "/Subject": "McAfee Firewall Enterprise Virtual Appliance for VMware",
      "/Title": "Security Policy",
      "pdf_file_size_bytes": 975634,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "http://mysupport.mcafee.com/",
          "http://csrc.nist.gov/groups/STM/cmvp/documents/140-1/140val-all.htm",
          "http://www.corsec.com/",
          "http://csrc.nist.gov/groups/STM/cmvp",
          "http://www.mcafee.com/us/downloads",
          "http://www.mcafee.com/",
          "mailto:[email protected]"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 33
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
    "module_download_ok": true,
    "module_extract_ok": true,
    "policy_convert_ok": true,
    "policy_download_ok": true,
    "policy_extract_ok": true,
    "policy_json_hash": null,
    "policy_pdf_hash": "020aeb32214a854e956909d1e3136349b5a1e585f2d2bf3916e8a92882f18429",
    "policy_txt_hash": "0ba744620b72674e2e85b8fdca51c50cd6cb68f75cfd9534a330e8a6aa3216b9"
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in FIPS mode and when installed, initialized and configured as specified in the Security Policy Section Secure Operation. The module generates cryptographic keys whose strengths are modified by available entropy",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/FIPS140ConsolidatedCertList0045.pdf",
    "date_sunset": null,
    "description": "McAfee Firewall Enterprise solutions provide unmatched protection for the enterprise in the most mission-critical and sensitive environments. McAfee\u0027s Firewall Enterprise appliances are created to meet the specific needs of organizations of all types and enable those organizations to reduce costs and mitigate the evolving risks that threaten today\u0027s networks and applications.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Cryptographic Module Specification: Level 3",
      "Roles, Services, and Authentication: Level 2",
      "Physical Security: N/A",
      "Design Assurance: Level 2",
      "Mitigation of Other Attacks: N/A"
    ],
    "fw_versions": null,
    "historical_reason": "RNG SP800-131A Revision 1 Transition",
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {},
    "module_name": "McAfee Firewall Enterprise Virtual Appliance for VMware",
    "module_type": "Software",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-2",
    "status": "historical",
    "sw_versions": "8.3.2 with patch number 8.3.2E14",
    "tested_conf": [
      "McAfee SecureOS v8.3 on VMware ESXi 5.0 running on a McAfee S7032 (single-user mode)"
    ],
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2014-09-08",
        "lab": "EWA - Canada",
        "validation_type": "Initial"
      }
    ],
    "vendor": "McAfee, Inc.",
    "vendor_url": "http://www.mcafee.com"
  }
}