FortiManager 5.2

Certificate #2515

Webpage information

Status historical
Historical reason Moved to historical list due to sunsetting
Validation dates 29.12.2015
Standard FIPS 140-2
Security level 1
Type Firmware
Embodiment Multi-Chip Stand Alone
Caveat When operated in FIPS mode and configured according to the Entropy Token Section of the Security Policy. The module generates cryptographic keys whose strengths are modified by available entropy. There is no assurance of the minimum strength of generated keys
Exceptions
  • Cryptographic Module Ports and Interfaces: Level 3
  • Roles, Services, and Authentication: Level 3
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A
Description The FortiManager OS is a firmware operating system that runs exclusively on Fortinet's FortiManager product family. FortiManager units are PC-based, purpose built appliances.
Version (Firmware) v5.2.4-build0738 150923 (GA)
Tested configurations
  • FortiManager-4000D with the Fortinet entropy token (part number FTR-ENT-1 )
Vendor Fortinet, Inc.
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Symmetric Algorithms
AES, DES, Triple-DES, HMAC
Asymmetric Algorithms
Diffie-Hellman
Hash functions
SHA-1, SHA1, SHA-256, SHA256, SHA512, MD5
Schemes
Key agreement
Protocols
SSH, TLS, VPN
Randomness
DRBG
Block cipher modes
CBC, CTR

Security level
Level 1

Standards
FIPS 140-2, FIPS 140, NIST SP 800-90A, PKCS1

File metadata

Title FortiProduct Administration Guide version 4.0.0
Subject FortiProduct
Author Fortinet Technical Documentation
Creation date D:20151223115626Z
Modification date D:20151223120413-05'00'
Pages 16
Creator FrameMaker 9.0
Producer Acrobat Distiller 10.1.16 (Windows)

Heuristics

No heuristics are available for this certificate.

References

No references are available for this certificate.

Updates Feed

  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 2515,
  "dgst": "81e3115919b4a97b",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "HMAC#2291",
        "AES#3594",
        "Triple-DES#2001",
        "RSA#1848",
        "CVL#616",
        "SHS#2956",
        "DRBG#929"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "5.2",
        "5.2.4"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "FF": {
          "DH": {
            "Diffie-Hellman": 8
          }
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 6
        },
        "CTR": {
          "CTR": 1
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "SSH": {
          "SSH": 17
        },
        "TLS": {
          "TLS": {
            "TLS": 4
          }
        },
        "VPN": {
          "VPN": 1
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key agreement": 1
        }
      },
      "device_model": {},
      "ecc_curve": {},
      "eval_facility": {},
      "fips_cert_id": {},
      "fips_certlike": {
        "Certlike": {
          "AES 128": 1,
          "AES 256": 1,
          "HMAC SHA-1": 6,
          "HMAC SHA-1 2291": 1,
          "HMAC SHA-256": 7,
          "PKCS1": 1,
          "RSA PKCS1": 1,
          "SHA-1": 10,
          "SHA-1 2291": 1,
          "SHA-1 2956": 1,
          "SHA-256": 9,
          "SHA1": 1,
          "SHA256": 1,
          "SHA512": 1
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 3
        }
      },
      "hash_function": {
        "MD": {
          "MD5": {
            "MD5": 2
          }
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 12,
            "SHA1": 1
          },
          "SHA2": {
            "SHA-256": 10,
            "SHA256": 1,
            "SHA512": 1
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 22
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140": 1,
          "FIPS 140-2": 32
        },
        "NIST": {
          "NIST SP 800-90A": 1
        },
        "PKCS": {
          "PKCS1": 1
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 11
          }
        },
        "DES": {
          "3DES": {
            "Triple-DES": 3
          },
          "DES": {
            "DES": 4
          }
        },
        "constructions": {
          "MAC": {
            "HMAC": 16
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "Fortinet Technical Documentation",
      "/Copyright": "2009",
      "/CreationDate": "D:20151223115626Z",
      "/Creator": "FrameMaker 9.0",
      "/ModDate": "D:20151223120413-05\u002700\u0027",
      "/Producer": "Acrobat Distiller 10.1.16 (Windows)",
      "/Subject": "FortiProduct",
      "/Title": "FortiProduct Administration Guide version 4.0.0",
      "pdf_file_size_bytes": 620839,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "http://docs.fortinet.com/",
          "http://docs.fortinet.com/surveyredirect.html",
          "https://fortinetdoc.polldaddy.com/s/report-issue"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 16
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
    "module_download_ok": true,
    "module_extract_ok": true,
    "policy_convert_ok": true,
    "policy_download_ok": true,
    "policy_extract_ok": true,
    "policy_json_hash": null,
    "policy_pdf_hash": "613de4b4e89e20acc4e2bc9019100ca8e28ad695db865a88006961dfb09be248",
    "policy_txt_hash": "6edd39d1c7e237fd60d0ed936393d9d121c36c6936488b016a592e550cb2f56d"
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in FIPS mode and configured according to the Entropy Token Section of the Security Policy. The module generates cryptographic keys whose strengths are modified by available entropy. There is no assurance of the minimum strength of generated keys",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/FIPS140ConsolidatedCertDec2015.pdf",
    "date_sunset": null,
    "description": "The FortiManager OS is a firmware operating system that runs exclusively on Fortinet\u0027s FortiManager product family. FortiManager units are PC-based, purpose built appliances.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Cryptographic Module Ports and Interfaces: Level 3",
      "Roles, Services, and Authentication: Level 3",
      "Design Assurance: Level 3",
      "Mitigation of Other Attacks: N/A"
    ],
    "fw_versions": "v5.2.4-build0738 150923 (GA)",
    "historical_reason": "Moved to historical list due to sunsetting",
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {},
    "module_name": "FortiManager 5.2",
    "module_type": "Firmware",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-2",
    "status": "historical",
    "sw_versions": null,
    "tested_conf": [
      "FortiManager-4000D with the Fortinet entropy token (part number FTR-ENT-1 )"
    ],
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2015-12-29",
        "lab": "CGI Information Systems \u0026 Management Consultants Inc",
        "validation_type": "Initial"
      }
    ],
    "vendor": "Fortinet, Inc.",
    "vendor_url": "http://www.fortinet.com"
  }
}