Aruba 2920 Switch Series

Certificate #2990

Webpage information

Status historical
Historical reason SP 800-56Arev3 transition
Validation dates 10.08.2017
Standard FIPS 140-2
Security level 1
Type Hardware
Embodiment Multi-Chip Stand Alone
Caveat When operated in FIPS mode. When installed, initialized and configured as specified in the Security Policy Section 11
Exceptions
  • Roles, Services, and Authentication: Level 3
  • Design Assurance: Level 2
  • Mitigation of Other Attacks: N/A
Description The Aruba 2920 Switch series is a scalable Basic Layer 3 switch series that delivers modular stacking, static & RIP routing, IPv6, ACLs, and sFlow for a better mobile-first campus network experience. With a powerful ProVision ASIC, the 2920 provides security, scalability, and ease of use for the enterprise campus, SMB, and branch office networks.
Version (Hardware) J9726A and J9729A
Version (Firmware) WB.16.02.0015
Vendor Aruba a Hewlett Packard Enterprise company
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Symmetric Algorithms
AES, AES-256, AES-128, RC4, DES, Triple-DES, HMAC
Asymmetric Algorithms
RSA 2048, RSA-2048, ECDSA, Diffie-Hellman, DSA
Hash functions
SHA-1, SHA1, SHA-224, SHA-384, SHA-512, SHA-256, SHA256, SHA512, MD5
Schemes
Key Agreement, Key agreement
Protocols
SSHv2, SSH, SSL, TLS
Randomness
DRBG, RNG
Elliptic Curves
secp256r1, secp384r1, secp521r1, secp224r1
Block cipher modes
ECB, CBC, CTR

Security level
Level 1

Standards
FIPS 140-2, FIPS PUB 140-2, FIPS 197, FIPS 198-1, FIPS 180-4, FIPS 186-4, FIPS 46-3, SP 800-38A, SP 800-38D, SP 800-90A, SP 800-135, SP 800-67, PKCS1

File metadata

Title Aruba 2920 Switch Security Policy
Author [email protected]
Creation date D:20170801130815-07'00'
Modification date D:20170801130815-07'00'
Pages 40
Creator Microsoft® Word 2013
Producer Microsoft® Word 2013

Heuristics

No heuristics are available for this certificate.

References

No references are available for this certificate.

Updates Feed

  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 2990,
  "dgst": "8c19996aa890257d",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "CVL#1019",
        "RSA#2326",
        "Triple-DES#2326",
        "HMAC#2841",
        "DRBG#1366",
        "SHS#3544",
        "AES#4305",
        "DSA#1145"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "16.02.0015"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECDSA": {
            "ECDSA": 2
          }
        },
        "FF": {
          "DH": {
            "Diffie-Hellman": 7
          },
          "DSA": {
            "DSA": 4
          }
        },
        "RSA": {
          "RSA 2048": 5,
          "RSA-2048": 1
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 3
        },
        "CTR": {
          "CTR": 2
        },
        "ECB": {
          "ECB": 2
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "SSH": {
          "SSH": 29,
          "SSHv2": 15
        },
        "TLS": {
          "SSL": {
            "SSL": 2
          },
          "TLS": {
            "TLS": 29
          }
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 1,
          "Key agreement": 3
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "secp224r1": 2,
          "secp256r1": 2,
          "secp384r1": 2,
          "secp521r1": 2
        }
      },
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "#1019": 1,
          "#1145": 1,
          "#1366": 1,
          "#2326": 2,
          "#2841": 1,
          "#3544": 1,
          "#4305": 1
        }
      },
      "fips_certlike": {
        "Certlike": {
          "#1366 DRBG": 1,
          "#2326 RSA": 1,
          "AES #4305": 1,
          "AES-128": 1,
          "AES-256": 1,
          "AES-CBC 128": 1,
          "CVL #1019": 1,
          "DRBG #1366": 1,
          "DSA #1145": 1,
          "DSA 1024": 1,
          "DSA-1024": 1,
          "DSA-2048": 1,
          "HMAC #2841": 2,
          "HMAC SHA-1 160": 1,
          "HMAC SHA-224": 1,
          "HMAC SHA-256": 1,
          "HMAC SHA-384": 1,
          "HMAC SHA-512": 1,
          "HMAC-SHA1": 2,
          "HMAC-SHA1 160": 2,
          "PKCS1": 4,
          "RSA #2326": 1,
          "RSA 2048": 5,
          "SHA- 256": 1,
          "SHA-1": 4,
          "SHA-1 160": 1,
          "SHA-224": 3,
          "SHA-256": 6,
          "SHA-384": 3,
          "SHA-512": 4,
          "SHA1": 2,
          "SHA256": 1,
          "SHA512": 1,
          "SHS #3544": 1
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 6
        }
      },
      "hash_function": {
        "MD": {
          "MD5": {
            "MD5": 5
          }
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 5,
            "SHA1": 2
          },
          "SHA2": {
            "SHA-224": 3,
            "SHA-256": 6,
            "SHA-384": 3,
            "SHA-512": 4,
            "SHA256": 1,
            "SHA512": 1
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 20
        },
        "RNG": {
          "RNG": 2
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-2": 11,
          "FIPS 180-4": 1,
          "FIPS 186-4": 3,
          "FIPS 197": 1,
          "FIPS 198-1": 1,
          "FIPS 46-3": 1,
          "FIPS PUB 140-2": 2
        },
        "NIST": {
          "SP 800-135": 1,
          "SP 800-38A": 1,
          "SP 800-38D": 1,
          "SP 800-67": 1,
          "SP 800-90A": 2
        },
        "PKCS": {
          "PKCS1": 2
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 2,
            "AES-128": 1,
            "AES-256": 1
          },
          "RC": {
            "RC4": 1
          }
        },
        "DES": {
          "3DES": {
            "Triple-DES": 5
          },
          "DES": {
            "DES": 5
          }
        },
        "constructions": {
          "MAC": {
            "HMAC": 8
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "[email protected]",
      "/CreationDate": "D:20170801130815-07\u002700\u0027",
      "/Creator": "Microsoft\u00ae Word 2013",
      "/ModDate": "D:20170801130815-07\u002700\u0027",
      "/Producer": "Microsoft\u00ae Word 2013",
      "/Title": "Aruba 2920 Switch Security Policy",
      "pdf_file_size_bytes": 1090830,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "http://csrc.nist.gov/groups/STM/cavp/documents/dss/rsanewval.html#2326",
          "file:///C:/Users/sweingart/AppData/Local/Microsoft/Windows/Temporary%20Internet%20Files/Content.Outlook/V3LN0ZO3/www.hpe.com",
          "http://csrc.nist.gov/groups/STM/cavp/documents/mac/hmacval.html#2841",
          "http://csrc.nist.gov/groups/STM/cavp/documents/shs/shaval.html#3544",
          "http://csrc.nist.gov/groups/STM/cmvp/documents/140-1/140val-all.htm",
          "http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html#4305",
          "http://csrc.nist.gov/groups/STM/cavp/documents/des/tripledesnewval.html#2326",
          "http://www.hpe.com./",
          "https://www.hpe.com/us/en/networking/switches.html",
          "http://csrc.nist.gov/groups/STM/cmvp",
          "http://csrc.nist.gov/groups/STM/cavp/documents/components/componentnewval.html#1019",
          "http://www.google.com/aclk?sa=l\u0026ai=DChcSEwiSye3Kr9zSAhXXe70KHYKLAzUYABAKGgJ0aA\u0026sig=AOD64_0yE4mx_nIXq1SUH4GcQSkf91l31w\u0026ctype=5\u0026rct=j\u0026q=\u0026ved=0ahUKEwiz5ufKr9zSAhUH72MKHVnRB_4QwjwIKA\u0026adurl=",
          "https://www.hpe.com/us/en/networking.html%23.UcMNEpzzlX0",
          "http://csrc.nist.gov/groups/STM/cavp/documents/dss/dsanewval.html#1145",
          "http://csrc.nist.gov/groups/STM/cavp/documents/drbg/drbgnewval.html#1366"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 40
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
    "module_download_ok": true,
    "module_extract_ok": true,
    "policy_convert_ok": true,
    "policy_download_ok": true,
    "policy_extract_ok": true,
    "policy_json_hash": null,
    "policy_pdf_hash": "da9d214eee95b3ec8d05fb55744eb5d26b8d4113c5a49f4d5ee737533dfef1fc",
    "policy_txt_hash": "4f35f518e7a818afe260a27c1d89d1d7de66ad40db84caa03132020626ccbd2c"
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in FIPS mode. When installed, initialized and configured as specified in the Security Policy Section 11",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/AugConsolidatedCert.pdf",
    "date_sunset": null,
    "description": "The Aruba 2920 Switch series is a scalable Basic Layer 3 switch series that delivers modular stacking, static \u0026 RIP routing, IPv6, ACLs, and sFlow for a better mobile-first campus network experience. With a powerful ProVision ASIC, the 2920 provides security, scalability, and ease of use for the enterprise campus, SMB, and branch office networks.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Roles, Services, and Authentication: Level 3",
      "Design Assurance: Level 2",
      "Mitigation of Other Attacks: N/A"
    ],
    "fw_versions": "WB.16.02.0015",
    "historical_reason": "SP 800-56Arev3 transition",
    "hw_versions": "J9726A and J9729A",
    "level": 1,
    "mentioned_certs": {},
    "module_name": "Aruba 2920 Switch Series",
    "module_type": "Hardware",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-2",
    "status": "historical",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2017-08-10",
        "lab": "CYGNACOM SOLUTIONS INC",
        "validation_type": "Initial"
      }
    ],
    "vendor": "Aruba a Hewlett Packard Enterprise company",
    "vendor_url": "http://www.arubanetworks.com"
  }
}