{"_type": "sec_certs.sample.fips.FIPSCertificate", "dgst": "8021cc8e4638aad9", "cert_id": 5268, "web_data": {"_type": "sec_certs.sample.fips.FIPSCertificate.WebData", "module_name": "FortiAP Access Points with FortiAP 7.4", "validation_history": [{"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry", "date": "2026-05-15", "validation_type": "Initial", "lab": "Lightship Security, Inc."}], "vendor_url": "http://www.fortinet.com", "vendor": "Fortinet, Inc.", "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/May 2026_030626_0716.pdf", "module_type": "Hardware", "standard": "FIPS 140-3", "status": "active", "level": 2, "caveat": "When installed, initialized and configured as specified in Section 11.1 of the Security Policy.", "exceptions": ["Operational environment: N/A", "Non-invasive security: N/A", "Mitigation of other attacks: N/A"], "embodiment": "MultiChipStand", "description": "The FortiAP Access Points with FortiAP 7.4 are multiple chip, standalone cryptographic hardware modules consisting of production grade components contained in a physically protected enclosure in accordance with FIPS 140-3 Level 2 requirements. The modules contain a firmware operating system that runs exclusively on Fortinet's FortiAP Access Points with FortiAP 7.4 products, and facilitates secure connections within the Security Fabric, enabling seamless integration with various Fortinet products across the network. FortiAP Access Points with FortiAP 7.4 are PC-based, purpose-built appliances.", "tested_conf": null, "hw_versions": null, "fw_versions": null, "sw_versions": null, "mentioned_certs": {}, "historical_reason": null, "date_sunset": "2031-05-14", "revoked_reason": null, "revoked_link": null}, "pdf_data": {"_type": "sec_certs.sample.fips.FIPSCertificate.PdfData", "keywords": {"fips_cert_id": {}, "fips_security_level": {"Level": {"Level 2": 5, "Level 1": 1}}, "fips_certlike": {"Certlike": {"HMAC-SHA-1": 4, "HMAC SHA-1": 1, "HMAC- SHA-1": 1, "SHA2-256": 9, "SHA2-384": 7, "SHA2- 512": 3, "SHA-1": 11, "SHA2-224": 2, "SHA2-512": 3, "SHA3-256": 6, "AES-256": 4, "AES-128": 1, "AES-192": 1, "AES (128": 1, "DRBG 256": 3}}, "vendor": {"Qualcomm": {"Qualcomm": 4}}, "eval_facility": {}, "symmetric_crypto": {"AES_competition": {"AES": {"AES-256": 4, "AES-128": 1, "AES-192": 1, "AES": 8}, "CAST": {"CAST": 34}}, "constructions": {"MAC": {"HMAC": 11}}}, "asymmetric_crypto": {"ECC": {"ECDSA": {"ECDSA": 52}}, "FF": {"DH": {"Diffie-Hellman": 3, "DHE": 1, "DH": 15}}}, "pq_crypto": {}, "hash_function": {"SHA": {"SHA1": {"SHA-1": 11}, "SHA3": {"SHA3-256": 6}}}, "crypto_scheme": {"MAC": {"MAC": 2}, "KEX": {"Key Exchange": 1}, "KA": {"Key agreement": 4, "Key Agreement": 2}}, "crypto_protocol": {"SSH": {"SSH": 41}, "TLS": {"TLS": {"TLS v1.2": 7, "TLS v1.3": 6, "TLS": 12, "TLS 1.2": 1}, "DTLS": {"DTLS": 34}}, "IKE": {"IKEv1": 12, "IKEv2": 11, "IKE": 48}, "IPsec": {"IPsec": 4}}, "randomness": {"PRNG": {"DRBG": 50}, "RNG": {"RBG": 2}}, "cipher_mode": {"GCM": {"GCM": 3}}, "ecc_curve": {"NIST": {"P-256": 18, "P-384": 10, "P-521": 14}}, "crypto_engine": {}, "tls_cipher_suite": {}, "crypto_library": {}, "vulnerability": {}, "side_channel_analysis": {}, "device_model": {}, "tee_name": {"AMD": {"PSP": 12}, "IBM": {"SSC": 2}}, "os_name": {}, "cplc_data": {}, "ic_data_group": {}, "standard_id": {"FIPS": {"FIPS 140-3": 18, "FIPS186-5": 38, "FIPS 186-5": 8, "FIPS 198-1": 4, "FIPS 180-4": 4, "FIPS 202": 1, "FIPS140-3": 2, "FIPS18": 2}, "NIST": {"SP 800-38A": 2, "SP 800-38D": 1, "SP 800-90A": 1, "SP 800-56A": 4, "SP 800-135": 5, "NIST SP 800-131A": 1, "SP 800-186": 1}, "RFC": {"RFC7627": 3, "RFC 8446": 1, "RFC762": 1}, "ISO": {"ISO/IEC 19790:2021": 1}}, "javacard_version": {}, "javacard_api_const": {}, "javacard_packages": {}, "certification_process": {"OutOfScope": {"out of scope": 1, "fap- get-status CLI command. Any firmware version that is not shown on the module certificate is out of scope of this validation and requires a separate FIPS 140-3 validation Mode Change Instructions and": 1}}}, "policy_metadata": {"pdf_file_size_bytes": 1219869, "pdf_is_encrypted": false, "pdf_number_of_pages": 59, "/Author": "Hawes, David J. (Fed)", "/Creator": "Microsoft\u00ae Word for Microsoft 365", "/CreationDate": "D:20260514153024-04'00'", "/ModDate": "D:20260514153024-04'00'", "/Producer": "Microsoft\u00ae Word for Microsoft 365", "pdf_hyperlinks": {"_type": "Set", "elements": ["https://www.fortinet.com/doc/legal/EULA.pdf", "https://training.fortinet.com/", "https://support.fortinet.com/", "https://www.fortinet.com/content/dam/fortinet/assets/data-sheets/fortiap-series.pdf", "https://docs.fortinet.com/document/fortimanager/7.2.4/cli-reference/23811/introduction", "https://fortiguard.com/", "https://blog.fortinet.com/", "https://www.fortinet.com/products", "https://www.fortinet.com/support-and-training/training.html", "https://www.fortinet.com/contact", "https://video.fortinet.com/", "https://csrc.nist.gov/projects/cryptographic-module-validation-program", "https://docs.fortinet.com/", "https://docs.fortinet.com/document/fortimanager/7.2.4/administration-guide/512210/setting-up-fortimanager", "https://wwww.fortiguard.com/"]}}}, "heuristics": {"_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics", "algorithms": {"_type": "Set", "elements": ["KDF IKEv2A6064", "RSA KeyGen (FIPS186-5)A6064", "HMAC-SHA2-256A6064", "KDF SSHA6064", "SHA2-256A6064", "KAS-FFC-SSC Sp800-56Ar3A6064", "SHA2-512A6064", "ECDSA KeyVer (FIPS186-5)A6064", "SHA3-256A4291", "Counter DRBGA6064", "TLS v1.3 KDFA6064", "ECDSA SigVer (FIPS186-5)A6064", "RSA SigVer (FIPS186-5)A6064", "RSA SigGen (FIPS186-5)A6064", "AES-CBCA6064", "HMAC-SHA2-512A6064", "AES-GCMA6064", "AES-CTRA6064", "KAS-ECC-SSC Sp800-56Ar3A6064", "Safe Primes Key GenerationA6064", "SHA-1A6064", "Safe Primes Key VerificationA6064", "ECDSA KeyGen (FIPS186-5)A6064", "HMAC-SHA2-384A6064", "ECDSA SigGen (FIPS186-5)A6064", "HMAC-SHA-1A6064", "SHA2-384A6064", "KDF IKEv1A6064", "TLS v1.2 KDF RFC7627A6064"]}, "extracted_versions": {"_type": "Set", "elements": ["7.4"]}, "cpe_matches": {"_type": "Set", "elements": ["cpe:2.3:a:fortinet:fortiap:7.4.0:*:*:*:*:*:*:*", "cpe:2.3:a:fortinet:fortiap:7.4.1:*:*:*:*:*:*:*", "cpe:2.3:a:fortinet:fortiap:7.4.2:*:*:*:*:*:*:*", "cpe:2.3:a:fortinet:fortiap:7.4.4:*:*:*:*:*:*:*", "cpe:2.3:a:fortinet:fortiap:7.4.8:*:*:*:*:*:*:*", "cpe:2.3:a:fortinet:fortiap:7.4.6:*:*:*:*:*:*:*", "cpe:2.3:a:fortinet:fortiap:7.4.5:*:*:*:*:*:*:*", "cpe:2.3:a:fortinet:fortiap:7.4.10:*:*:*:*:*:*:*", "cpe:2.3:a:fortinet:fortiap:7.4.3:*:*:*:*:*:*:*"]}, "verified_cpe_matches": null, "related_cves": {"_type": "Set", "elements": ["CVE-2024-26012", "CVE-2025-53680", "CVE-2025-53870"]}, "policy_prunned_references": {"_type": "Set", "elements": []}, "module_prunned_references": {"_type": "Set", "elements": []}, "policy_processed_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": null, "indirectly_referenced_by": null, "directly_referencing": null, "indirectly_referencing": null}, "module_processed_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": null, "indirectly_referenced_by": null, "directly_referencing": null, "indirectly_referencing": null}, "direct_transitive_cves": null, "indirect_transitive_cves": null}, "state": {"_type": "sec_certs.sample.fips.InternalState", "module": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": null, "txt_hash": null, "json_hash": null}, "policy": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": "a861b1fb2f53f25f1185e1280929e90beb137fab0bdf23e94c60e1edd2478001", "txt_hash": "ba630382240a91a14d564ef1a1b1b78902dcca4ec65d4425fd1bb1706695f547", "json_hash": null}}}