McAfee Firewall Enterprise 1100E, 2150E and 4150E

Certificate #2154

Webpage information

Status historical
Historical reason RNG SP800-131A Revision 1 Transition
Validation dates 14.05.2014
Standard FIPS 140-2
Security level 2
Type Hardware
Embodiment Multi-Chip Stand Alone
Caveat When operated in FIPS mode and when installed, initialized and configured as specified in the Security Policy Section 3.1. The module generates cryptographic keys whose strengths are modified by available entropy.
Exceptions
  • Mitigation of Other Attacks: N/A
Description McAfee Firewall Enterprise solutions provide unmatched protection for the enterprise in the most mission-critical and sensitive environments. McAfee Firewall Enterprise appliances are created to meet the specific needs of organizations of all types and enable those organizations to reduce costs and mitigate the evolving risks that threaten today's networks and applications.
Version (Hardware) NSA-1100-FWEX-E, NSA-2150-FWEX-E, NSA-4150-FWEX-E with FRU-686-0089-00
Version (Firmware) 8.3.1
Vendor McAfee, Inc.
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Symmetric Algorithms
AES, AES-128, AES-, AES-256, CAST, DES, Triple-DES, HMAC
Asymmetric Algorithms
Diffie-Hellman, DH, DSA
Hash functions
SHA-1, SHA-256, SHA-384, SHA-512
Schemes
MAC, Key Exchange, Key Agreement
Protocols
SSH, SSL, TLS, TLS 1.0, DTLS, IKE, IPsec, VPN
Randomness
PRNG, RNG
Block cipher modes
ECB, CBC, CFB, OFB

Security level
Level 2, Level 1

Standards
FIPS 140-2, PKCS #1

File metadata

Title Security Policy
Subject McAfee Firewall Enterprise 1100E, 2150E, and 4150E
Author Darryl H. Johnson
Creation date D:20140411164327-04'00'
Modification date D:20140514070803-04'00'
Pages 41
Creator Microsoft® Office Word 2007
Producer Microsoft® Office Word 2007

Heuristics

No heuristics are available for this certificate.

References

No references are available for this certificate.

Updates Feed

  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 2154,
  "dgst": "9e3b6232cb7bd60e",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "SHS#1988",
        "HMAC#1420",
        "Triple-DES#1185",
        "RSA#1189",
        "AES#2303",
        "RNG#964",
        "RNG#1148",
        "SHS#1612",
        "RNG#1146",
        "SHS#1990",
        "AES#2305",
        "DSA#722",
        "HMAC#1418",
        "DSA#724",
        "Triple-DES#1451",
        "HMAC#1086",
        "AES#1833",
        "Triple-DES#1453",
        "RSA#1187"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "8.3.1"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "FF": {
          "DH": {
            "DH": 3,
            "Diffie-Hellman": 4
          },
          "DSA": {
            "DSA": 11
          }
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 5
        },
        "CFB": {
          "CFB": 2
        },
        "ECB": {
          "ECB": 4
        },
        "OFB": {
          "OFB": 3
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "IKE": {
          "IKE": 16
        },
        "IPsec": {
          "IPsec": 17
        },
        "SSH": {
          "SSH": 15
        },
        "TLS": {
          "DTLS": {
            "DTLS": 10
          },
          "SSL": {
            "SSL": 11
          },
          "TLS": {
            "TLS": 63,
            "TLS 1.0": 1
          }
        },
        "VPN": {
          "VPN": 7
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 24
        },
        "KEX": {
          "Key Exchange": 2
        },
        "MAC": {
          "MAC": 1
        }
      },
      "device_model": {},
      "ecc_curve": {},
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "#1": 9,
          "#2": 4,
          "#3": 2,
          "#4": 2
        }
      },
      "fips_certlike": {
        "Certlike": {
          "AES- 256": 7,
          "AES-128": 7,
          "AES-256": 3,
          "DES18": 1,
          "HMAC SHA-1": 4,
          "HMAC SHA-256": 1,
          "HMAC-SHA1": 2,
          "HMAC15": 2,
          "PKCS #1": 3,
          "RSA PKCS #1": 3,
          "RSA12": 1,
          "SHA-1": 8,
          "SHA-256": 5,
          "SHA-384": 4,
          "SHA-512": 2,
          "SHA-512 1418": 1,
          "SHA-512 1988": 1
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 1,
          "Level 2": 5
        }
      },
      "hash_function": {
        "SHA": {
          "SHA1": {
            "SHA-1": 8
          },
          "SHA2": {
            "SHA-256": 5,
            "SHA-384": 4,
            "SHA-512": 4
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "PRNG": 15
        },
        "RNG": {
          "RNG": 4
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-2": 20
        },
        "PKCS": {
          "PKCS #1": 3
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 7,
            "AES-": 7,
            "AES-128": 7,
            "AES-256": 3
          },
          "CAST": {
            "CAST": 1
          }
        },
        "DES": {
          "3DES": {
            "Triple-DES": 8
          },
          "DES": {
            "DES": 5
          }
        },
        "constructions": {
          "MAC": {
            "HMAC": 8
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "Darryl H. Johnson",
      "/CreationDate": "D:20140411164327-04\u002700\u0027",
      "/Creator": "Microsoft\u00ae Office Word 2007",
      "/ModDate": "D:20140514070803-04\u002700\u0027",
      "/Producer": "Microsoft\u00ae Office Word 2007",
      "/Subject": "McAfee Firewall Enterprise 1100E, 2150E, and 4150E",
      "/Title": "Security Policy",
      "pdf_file_size_bytes": 1588953,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "http://mysupport.mcafee.com/",
          "mailto:[email protected]",
          "http://csrc.nist.gov/groups/STM/cmvp/documents/140-1/140val-all.htm",
          "http://www.corsec.com/",
          "http://csrc.nist.gov/groups/STM/cmvp",
          "http://www.mcafee.com/",
          "mailto:[email protected]"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 41
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
    "module_download_ok": true,
    "module_extract_ok": true,
    "policy_convert_ok": true,
    "policy_download_ok": true,
    "policy_extract_ok": true,
    "policy_json_hash": null,
    "policy_pdf_hash": "624e11f17d3d4a74deedd983b5db5ffb53dc50e2ac7d739b9268af201d94997c",
    "policy_txt_hash": "1437abb9807ca061008ffbccd3b3a521f8b6359699dfdc3b3bcbfb8a59fca2d0"
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in FIPS mode and when installed, initialized and configured as specified in the Security Policy Section 3.1. The module generates cryptographic keys whose strengths are modified by available entropy.",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/FIPS140ConsolidatedCertList0041.pdf",
    "date_sunset": null,
    "description": "McAfee Firewall Enterprise solutions provide unmatched protection for the enterprise in the most mission-critical and sensitive environments. McAfee Firewall Enterprise appliances are created to meet the specific needs of organizations of all types and enable those organizations to reduce costs and mitigate the evolving risks that threaten today\u0027s networks and applications.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Mitigation of Other Attacks: N/A"
    ],
    "fw_versions": "8.3.1",
    "historical_reason": "RNG SP800-131A Revision 1 Transition",
    "hw_versions": "NSA-1100-FWEX-E, NSA-2150-FWEX-E, NSA-4150-FWEX-E with FRU-686-0089-00",
    "level": 2,
    "mentioned_certs": {},
    "module_name": "McAfee Firewall Enterprise 1100E, 2150E and 4150E",
    "module_type": "Hardware",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-2",
    "status": "historical",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2014-05-14",
        "lab": "EWA - Canada",
        "validation_type": "Initial"
      }
    ],
    "vendor": "McAfee, Inc.",
    "vendor_url": "http://www.mcafee.com"
  }
}