AT-SBx908 Gen2, AT-x950, AT-x550, AT-x530 Secure Management Module

Certificate #3885

Webpage information

Status active
Validation dates 06.04.2021 , 23.08.2022 , 24.04.2023
Sunset date 05-04-2026
Standard FIPS 140-2
Security level 2
Type Hardware
Embodiment Multi-Chip Stand Alone
Caveat When operated in FIPS mode and installed, initialized, and configured as specified in Section 8 of the Security Policy and tamper-evident seals installed as indicated in the Section 5
Exceptions
  • Mitigation of Other Attacks: N/A
Description The AlliedWare Plus OpenSSL FIPS Object Module is a software library which provides cryptographic support for securing the communication and management of the device. The products certified cover AT-x530, AT-x530L, AT-x550, ATx950 and SwitchBlade x908 Generation 2 models.
Version (Hardware) AT-SBx908 Gen2, 990-007222-F00 with [1], [2], [3], [4] [Tamper Label Kit: 066-000080 x 10, 056-000658 x 1] [A], AT-SBx908 Gen2, 990-008144-F00 with [1], [2], [3], [4] [Tamper Label Kit: 066-000080 x 10, 056-000658 x 1] [E], AT-x950-28XTQm, 990-007221-F00 with [2], [5], [Tamper Label Kit: 066-000080 x 4, 056-000658 x 1] [B], AT-x950-28XTQm, 990-008145-F00 with [2], [5], [Tamper Label Kit: 066-000080 x 4, 056-000658 x 1] [F], AT-x950-28XSQ, 990-007712-F00 with [3], [5], [Tamper Label Kit: 066-000080 x 4, 056-000658 x 1] [B], AT-x950-28XSQ, 990-008147-F00 with [3], [5], [Tamper Label Kit: 066-000080 x 4, 056-000658 x 1] [F], AT-x550-18XTQ, 990-007217-F90, [Tamper Label Kit: 066-000080 x 1, 056-000658 x 1] [C], AT-x550-18XSQ, 990-007218-F90, [Tamper Label Kit: 066-000080 x 1, 056-000658 x 1] [C], AT-x550-18XSQ, 990-007724-F90, [Tamper Label Kit: 066-000080 x 1, 056-000658 x 1] [C], AT-x550-18XSPQm, 990-007219-F90, [Tamper Label Kit: 066-000080 x 1, 056-000658 x 1] [C], AT-x530-52GTXm, 990-007725-F90, [Tamper Label Kit: 066-000080 x 1, 056-000658 x 1] [D], AT-x530-52GPXm, 990-007726-F90, [Tamper Label Kit: 066-000080 x 1, 056-000658 x 1] [D], AT-x530-28GTXm, 990-007220-F90, [Tamper Label Kit: 066-000080 x 1, 056-000658 x 1] [D], AT-x530-28GPXm, 990-007727-F90, [Tamper Label Kit: 066-000080 x 1, 056-000658 x 1] [D], AT-x530L-52GTX, 990-007728-F90, [Tamper Label Kit: 066-000080 x 1, 056-000658 x 1] [D], AT-x530L-52GPX, 990-007729-F90, [Tamper Label Kit: 066-000080 x 1, 056-000658 x 1] [D], AT-x530L-28GTX, 990-007730-F90, [Tamper Label Kit: 066-000080 x 1, 056-000658 x 1] [D] and AT-x530L-28GPX, 990-007731-F90, [Tamper Label Kit: 066-000080 x 1, 056-000658 x 1] [D]; XEM2 Modules [1] 990-005492-00, 990-005490-00, 990-005493-00, 990-006024-00, 990-005491-00, XEM2 Module [2] 990-006242-00 and XEM2 Module [3] 990-006018-00; Power Supply Unit [4] 990-004783-10 and Power Supply Unit [5] 990-006195-10
Version (Firmware) 5.4.9.APCERT-2.3; Bootloader Versions bl-6.2.7-SBx908NG-39A8-D2D8.bin [A], bl-6.2.20-x950-1D0D-2BC3.bin [B], bl-6.2.21-x550-2FC1-A0F1.bin [C], bl-7.0.3-x530-noecc-B495-8AEE.kwb [D] , bl-6.2.30-SBx908NG-FD3D-FFB4 [E], bl-6.2.30-x950-B983-3904 [F]
Vendor Allied Telesis
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Symmetric Algorithms
AES, AES-256, RC4, DES, TDEA, Blowfish, HMAC, HMAC-SHA-256, CMAC
Asymmetric Algorithms
RSA-2048, RSA 2048, ECDH, ECDSA, ECC
Hash functions
SHA-1, SHA-256, SHA-384, SHA-512, SHA256, MD5
Schemes
Key Exchange, Key Agreement
Protocols
SSH, SSHv2, TLS 1.2, TLS, TLSv1.2, TLS v1.2
Randomness
DRBG, RNG
Elliptic Curves
P-256, P-384, P-521, P-192, P-224, K-233, K-409, B-283, B-409, K-163, B-163, B-233, K-283, K-571, B-571
Block cipher modes
CBC, CTR, CFB, GCM, CCM, XTS
TLS cipher suites
TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256, TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256, TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384, TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384, TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256, TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

Standards
FIPS 140-2, FIPS140-2, FIPS PUB 140-2, SP 800-135, SP 800-56A, RFC5246, RFC 5246, RFC 8332

File metadata

Subject FIPS 140-2 Security Policy Template
Author Timothy Myers
Creation date D:20230403140622-07'00'
Modification date D:20230403140753-07'00'
Pages 63
Creator Acrobat PDFMaker 23 for Word
Producer Adobe PDF Library 23.1.125

Heuristics

No heuristics are available for this certificate.

References

No references are available for this certificate.

Updates Feed

  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 3885,
  "dgst": "8f1d857513c617aa",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "DRBG#C1547",
        "AES#C1547",
        "CVL#C1547",
        "HMAC#C1547",
        "RSA#C1547",
        "SHS#C1547",
        "ECDSA#C1547",
        "KTS#C1547"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "6.2.30",
        "5.4.9",
        "6.2.21",
        "2.3",
        "7.0.3",
        "6.2.20",
        "6.2.7"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 2
          },
          "ECDH": {
            "ECDH": 5
          },
          "ECDSA": {
            "ECDSA": 15
          }
        },
        "RSA": {
          "RSA 2048": 2,
          "RSA-2048": 1
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 2
        },
        "CCM": {
          "CCM": 1
        },
        "CFB": {
          "CFB": 2
        },
        "CTR": {
          "CTR": 2
        },
        "GCM": {
          "GCM": 3
        },
        "XTS": {
          "XTS": 1
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "SSH": {
          "SSH": 19,
          "SSHv2": 15
        },
        "TLS": {
          "TLS": {
            "TLS": 25,
            "TLS 1.2": 2,
            "TLS v1.2": 2,
            "TLSv1.2": 2
          }
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 2
        },
        "KEX": {
          "Key Exchange": 2
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "B-163": 1,
          "B-233": 1,
          "B-283": 2,
          "B-409": 2,
          "B-571": 1,
          "K-163": 1,
          "K-233": 3,
          "K-283": 1,
          "K-409": 2,
          "K-571": 1,
          "P-192": 2,
          "P-224": 2,
          "P-256": 22,
          "P-384": 14,
          "P-521": 12
        }
      },
      "eval_facility": {},
      "fips_cert_id": {},
      "fips_certlike": {
        "Certlike": {
          "AES [197": 1,
          "AES-256": 2,
          "DES 5": 1,
          "HMAC [198": 1,
          "HMAC-SHA-1": 8,
          "HMAC-SHA-256": 6,
          "HMAC-SHA1": 2,
          "HMAC-SHA256": 2,
          "RSA 2048": 2,
          "SHA (1": 24,
          "SHA (224": 14,
          "SHA (256": 6,
          "SHA-1": 3,
          "SHA-256": 9,
          "SHA-384": 1,
          "SHA-512": 3,
          "SHA256": 1,
          "SHS [180": 1
        }
      },
      "fips_security_level": {},
      "hash_function": {
        "MD": {
          "MD5": {
            "MD5": 2
          }
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 3
          },
          "SHA2": {
            "SHA-256": 9,
            "SHA-384": 1,
            "SHA-512": 3,
            "SHA256": 1
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 8
        },
        "RNG": {
          "RNG": 2
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-2": 135,
          "FIPS PUB 140-2": 1,
          "FIPS140-2": 1
        },
        "NIST": {
          "SP 800-135": 2,
          "SP 800-56A": 1
        },
        "RFC": {
          "RFC 5246": 2,
          "RFC 8332": 1,
          "RFC5246": 1
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 5,
            "AES-256": 2
          },
          "RC": {
            "RC4": 1
          }
        },
        "DES": {
          "3DES": {
            "TDEA": 1
          },
          "DES": {
            "DES": 1
          }
        },
        "constructions": {
          "MAC": {
            "CMAC": 2,
            "HMAC": 4,
            "HMAC-SHA-256": 3
          }
        },
        "miscellaneous": {
          "Blowfish": {
            "Blowfish": 1
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {
        "TLS": {
          "TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256": 1,
          "TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256": 1,
          "TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384": 1,
          "TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384": 1,
          "TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256": 1,
          "TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256": 1,
          "TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384": 1,
          "TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384": 1
        }
      },
      "vendor": {},
      "vulnerability": {}
    },
    "policy_metadata": {
      "/AppVersion": "16.0000",
      "/Author": "Timothy Myers",
      "/Comments": "",
      "/Company": "Microsoft",
      "/CreationDate": "D:20230403140622-07\u002700\u0027",
      "/Creator": "Acrobat PDFMaker 23 for Word",
      "/DocSecurity": "0",
      "/HyperlinksChanged": "0",
      "/LinksUpToDate": "0",
      "/ModDate": "D:20230403140753-07\u002700\u0027",
      "/Producer": "Adobe PDF Library 23.1.125",
      "/ScaleCrop": "0",
      "/ShareDoc": "0",
      "/SourceModified": "D:20230403210545",
      "/Subject": "FIPS 140-2 Security Policy Template",
      "/Title": "",
      "pdf_file_size_bytes": 7418597,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "https://www.alliedtelesis.com/",
          "https://www.alliedtelesis.com/documents/getting-started-alliedware-plus-feature-overview-and-configuration-guide",
          "https://www.alliedtelesis.com/documents/installation-guide-x530l-series-stand-alone-switches",
          "https://www.alliedtelesis.com/documents/documentation-for-sec-cert"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 63
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
    "module_download_ok": true,
    "module_extract_ok": true,
    "policy_convert_ok": true,
    "policy_download_ok": true,
    "policy_extract_ok": true,
    "policy_json_hash": null,
    "policy_pdf_hash": "c87989f24b06020ac86a6c8d73a585e5a4ceb48c011aa1c6e5abf736823028c9",
    "policy_txt_hash": "878582edbcbed01b0957bdac49df0feb5cceb9bed2060907950fbd5aa8b6f006"
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in FIPS mode and installed, initialized, and configured as specified in Section 8 of the Security Policy and tamper-evident seals installed as indicated in the Section 5",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/April 2021_030521_0757_signed.pdf",
    "date_sunset": "2026-04-05",
    "description": "The AlliedWare Plus OpenSSL FIPS Object Module is a software library which provides cryptographic support for securing the communication and management of the device. The products certified cover AT-x530, AT-x530L, AT-x550, ATx950 and SwitchBlade x908 Generation 2 models.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Mitigation of Other Attacks: N/A"
    ],
    "fw_versions": "5.4.9.APCERT-2.3; Bootloader Versions bl-6.2.7-SBx908NG-39A8-D2D8.bin [A], bl-6.2.20-x950-1D0D-2BC3.bin [B], bl-6.2.21-x550-2FC1-A0F1.bin [C], bl-7.0.3-x530-noecc-B495-8AEE.kwb [D] , bl-6.2.30-SBx908NG-FD3D-FFB4 [E], bl-6.2.30-x950-B983-3904 [F]",
    "historical_reason": null,
    "hw_versions": "AT-SBx908 Gen2, 990-007222-F00 with [1], [2], [3], [4] [Tamper Label Kit: 066-000080 x 10, 056-000658 x 1] [A], AT-SBx908 Gen2, 990-008144-F00 with [1], [2], [3], [4] [Tamper Label Kit: 066-000080 x 10, 056-000658 x 1] [E], AT-x950-28XTQm, 990-007221-F00 with [2], [5], [Tamper Label Kit: 066-000080 x 4, 056-000658 x 1] [B], AT-x950-28XTQm, 990-008145-F00 with [2], [5], [Tamper Label Kit: 066-000080 x 4, 056-000658 x 1] [F], AT-x950-28XSQ, 990-007712-F00 with [3], [5], [Tamper Label Kit: 066-000080 x 4, 056-000658 x 1] [B], AT-x950-28XSQ, 990-008147-F00 with [3], [5], [Tamper Label Kit: 066-000080 x 4, 056-000658 x 1] [F], AT-x550-18XTQ, 990-007217-F90, [Tamper Label Kit: 066-000080 x 1, 056-000658 x 1] [C], AT-x550-18XSQ, 990-007218-F90, [Tamper Label Kit: 066-000080 x 1, 056-000658 x 1] [C], AT-x550-18XSQ, 990-007724-F90, [Tamper Label Kit: 066-000080 x 1, 056-000658 x 1] [C], AT-x550-18XSPQm, 990-007219-F90, [Tamper Label Kit: 066-000080 x 1, 056-000658 x 1] [C], AT-x530-52GTXm, 990-007725-F90, [Tamper Label Kit: 066-000080 x 1, 056-000658 x 1] [D], AT-x530-52GPXm, 990-007726-F90, [Tamper Label Kit: 066-000080 x 1, 056-000658 x 1] [D], AT-x530-28GTXm, 990-007220-F90, [Tamper Label Kit: 066-000080 x 1, 056-000658 x 1] [D], AT-x530-28GPXm, 990-007727-F90, [Tamper Label Kit: 066-000080 x 1, 056-000658 x 1] [D], AT-x530L-52GTX, 990-007728-F90, [Tamper Label Kit: 066-000080 x 1, 056-000658 x 1] [D], AT-x530L-52GPX, 990-007729-F90, [Tamper Label Kit: 066-000080 x 1, 056-000658 x 1] [D], AT-x530L-28GTX, 990-007730-F90, [Tamper Label Kit: 066-000080 x 1, 056-000658 x 1] [D] and AT-x530L-28GPX, 990-007731-F90, [Tamper Label Kit: 066-000080 x 1, 056-000658 x 1] [D]; XEM2 Modules [1] 990-005492-00, 990-005490-00, 990-005493-00, 990-006024-00, 990-005491-00, XEM2 Module [2] 990-006242-00 and XEM2 Module [3] 990-006018-00; Power Supply Unit [4] 990-004783-10 and Power Supply Unit [5] 990-006195-10",
    "level": 2,
    "mentioned_certs": {},
    "module_name": "AT-SBx908 Gen2, AT-x950, AT-x550, AT-x530 Secure Management Module",
    "module_type": "Hardware",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-2",
    "status": "active",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2021-04-06",
        "lab": "UL Verification Services, Inc.",
        "validation_type": "Initial"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2022-08-23",
        "lab": "UL Verification Services, Inc.",
        "validation_type": "Update"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2023-04-24",
        "lab": "UL Verification Services, Inc.",
        "validation_type": "Update"
      }
    ],
    "vendor": "Allied Telesis",
    "vendor_url": "http://www.alliedtelesis.com"
  }
}