Brocade Fabric OS FIPS Cryptographic Module

Certificate details

Certificate ID #4849
Status active
Validation dates 23.10.2024
Sunset date 22-10-2029
Standard FIPS 140-3
Security level 1
Type Firmware
Embodiment Multi-Chip Stand Alone
Caveat When operated in approved mode
Exceptions
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A
Description The Brocade Fabric OS FIPS Cryptographic Module underpins Brocade’s Fabric Operating System equipment. The Brocade Fabric OS is the software foundation for Brocade’s purpose-built network infrastructure for mission-critical storage.
Version (Firmware) 9.1.1
Tested configurations
  • Fabric OS 9.1.1 running on Brocade G630 Switch with NXP Semiconductors T1042 (e5500 core)
  • Fabric OS 9.1.1 running on Brocade G730 Switch with Intel(R) Atom(TM) CPU C3338R (2 cores) with PAA
  • Fabric OS 9.1.1 running on Brocade G730 Switch with Intel(R) Atom(TM) CPU C3338R (2 cores) without PAA
  • Fabric OS 9.1.1 running on Brocade X7-8 Director with NXP Semiconductors P4080 (e500mc core)
Vendor Brocade Communications Systems LLC http://www.broadcom.com
Lab Gossamer Security Solutions
Algorithms
  • AES-CBCA2604
  • AES-CCMA2604
  • AES-CMACA2604
  • AES-CTRA2604
  • AES-ECBA2604
  • Counter DRBGA2604
  • ECDSA KeyGen (FIPS186-4)A2604
  • ECDSA KeyVer (FIPS186-4)A2604
  • ECDSA SigGen (FIPS186-4)A2604
  • ECDSA SigVer (FIPS186-4)A2604
  • HMAC-SHA-1A2604
  • HMAC-SHA2-256A2604
  • HMAC-SHA2-384A2604
  • HMAC-SHA2-512A2604
  • HMAC-SHA3-224A2604
  • HMAC-SHA3-256A2604
  • HMAC-SHA3-384A2604
  • HMAC-SHA3-512A2604
  • KAS-ECC-SSC Sp800-56Ar3A2604
  • KAS-FFC-SSC Sp800-56Ar3A2604
  • RSA KeyGen (FIPS186-4)A2604
  • RSA SigGen (FIPS186-4)A2604
  • RSA SigVer (FIPS186-4)A2604
  • Safe Primes Key GenerationA2604
  • Safe Primes Key VerificationA2604
  • SHA-1A2604
  • SHA2-224A2604
  • SHA2-256A2604
  • SHA2-384A2604
  • SHA2-512A2604
  • SHA3-224A2604
  • SHA3-256A2604
  • SHA3-384A2604
  • SHA3-512A2604
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Extracted keywords

Symmetric Algorithms
AES, AES-, CAST, RC4, Triple-DES, Camellia, SEED, HMAC, CMAC
Asymmetric Algorithms
ECDH, ECDSA, DH, Diffie-Hellman, DSA
Hash functions
SHA-1, SHA-3, SHA3-224, SHA3-256, SHA3-384, SHA3-512, MD5
Schemes
MAC, Key agreement
Randomness
DRBG, RBG
Elliptic Curves
P-256, P-384, P-521, Curve P-256
Block cipher modes
ECB, CBC, CTR

Vendor
NXP Semiconductors

Security level
Level 1, level 1

Automated analysis

Automated inference - use with caution

All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.

No automatically derived data are available in this section.

Cross-references

No references are available for this certificate.

Processing updates

Feed
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 4849,
  "dgst": "b6e3ae7742d8a778",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "AES-CTRA2604",
        "AES-ECBA2604",
        "SHA2-256A2604",
        "SHA3-512A2604",
        "SHA2-384A2604",
        "Counter DRBGA2604",
        "HMAC-SHA3-384A2604",
        "ECDSA SigVer (FIPS186-4)A2604",
        "ECDSA SigGen (FIPS186-4)A2604",
        "SHA3-384A2604",
        "HMAC-SHA2-384A2604",
        "KAS-FFC-SSC Sp800-56Ar3A2604",
        "RSA SigGen (FIPS186-4)A2604",
        "AES-CMACA2604",
        "#A2604",
        "HMAC-SHA3-224A2604",
        "Safe Primes Key GenerationA2604",
        "HMAC-SHA3-512A2604",
        "SHA2-512A2604",
        "RSA SigVer (FIPS186-4)A2604",
        "KAS-ECC-SSC Sp800-56Ar3A2604",
        "SHA-1A2604",
        "AES-CBCA2604",
        "HMAC-SHA-1A2604",
        "ECDSA KeyGen (FIPS186-4)A2604",
        "HMAC-SHA2-256A2604",
        "SHA3-224A2604",
        "HMAC-SHA3-256A2604",
        "ECDSA KeyVer (FIPS186-4)A2604",
        "SHA3-256A2604",
        "AES-CCMA2604",
        "HMAC-SHA2-512A2604",
        "RSA KeyGen (FIPS186-4)A2604",
        "SHA2-224A2604",
        "Safe Primes Key VerificationA2604"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "9.1.1"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "br1_deviations": 33,
    "br1_tables": null,
    "is_br1_format": false,
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECDH": {
            "ECDH": 11
          },
          "ECDSA": {
            "ECDSA": 30
          }
        },
        "FF": {
          "DH": {
            "DH": 11,
            "Diffie-Hellman": 4
          },
          "DSA": {
            "DSA": 4
          }
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 1
        },
        "CTR": {
          "CTR": 1
        },
        "ECB": {
          "ECB": 1
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {},
      "crypto_scheme": {
        "KA": {
          "Key agreement": 3
        },
        "MAC": {
          "MAC": 3
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "Curve P-256": 2,
          "P-256": 22,
          "P-384": 10,
          "P-521": 2
        }
      },
      "eval_facility": {},
      "fips_cert_id": {},
      "fips_certlike": {
        "Certlike": {
          "AES- 256": 1,
          "AES-CMAC 128": 1,
          "HMAC-SHA-1": 16,
          "HMAC-SHA1": 1,
          "HMAC-SHA1 112": 1,
          "SHA-1": 4,
          "SHA-3": 5,
          "SHA2-224": 1,
          "SHA2-256": 7,
          "SHA2-384": 2,
          "SHA2-512": 3,
          "SHA3-224": 2,
          "SHA3-256": 5,
          "SHA3-384": 2,
          "SHA3-512": 3
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 5,
          "level 1": 3
        }
      },
      "hash_function": {
        "MD": {
          "MD5": {
            "MD5": 2
          }
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 4
          },
          "SHA3": {
            "SHA-3": 5,
            "SHA3-224": 2,
            "SHA3-256": 5,
            "SHA3-384": 2,
            "SHA3-512": 3
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 33
        },
        "RNG": {
          "RBG": 1
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-3": 13,
          "FIPS 1403": 1,
          "FIPS 186-4": 2,
          "FIPS 197": 3,
          "FIPS180-4": 5,
          "FIPS186-4": 9,
          "FIPS198-1": 8,
          "FIPS202": 4
        },
        "ISO": {
          "ISO/IEC 24759:2017": 1
        },
        "NIST": {
          "SP 800-90B": 1
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 5,
            "AES-": 1
          },
          "CAST": {
            "CAST": 1
          },
          "RC": {
            "RC4": 2
          }
        },
        "DES": {
          "3DES": {
            "Triple-DES": 2
          }
        },
        "constructions": {
          "MAC": {
            "CMAC": 2,
            "HMAC": 12
          }
        },
        "miscellaneous": {
          "Camellia": {
            "Camellia": 2
          },
          "SEED": {
            "SEED": 2
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {
        "NXP": {
          "NXP Semiconductors": 2
        }
      },
      "vulnerability": {}
    },
    "module_algorithms": {
      "_type": "Set",
      "elements": [
        "AES-CTRA2604",
        "AES-ECBA2604",
        "SHA2-256A2604",
        "SHA3-512A2604",
        "SHA2-384A2604",
        "Counter DRBGA2604",
        "HMAC-SHA3-384A2604",
        "ECDSA SigVer (FIPS186-4)A2604",
        "ECDSA SigGen (FIPS186-4)A2604",
        "SHA3-384A2604",
        "HMAC-SHA2-384A2604",
        "KAS-FFC-SSC Sp800-56Ar3A2604",
        "RSA SigGen (FIPS186-4)A2604",
        "AES-CMACA2604",
        "HMAC-SHA3-224A2604",
        "Safe Primes Key GenerationA2604",
        "HMAC-SHA3-512A2604",
        "SHA2-512A2604",
        "RSA SigVer (FIPS186-4)A2604",
        "KAS-ECC-SSC Sp800-56Ar3A2604",
        "SHA-1A2604",
        "AES-CBCA2604",
        "HMAC-SHA-1A2604",
        "ECDSA KeyGen (FIPS186-4)A2604",
        "HMAC-SHA2-256A2604",
        "SHA3-224A2604",
        "HMAC-SHA3-256A2604",
        "ECDSA KeyVer (FIPS186-4)A2604",
        "SHA3-256A2604",
        "AES-CCMA2604",
        "HMAC-SHA2-512A2604",
        "RSA KeyGen (FIPS186-4)A2604",
        "SHA2-224A2604",
        "Safe Primes Key VerificationA2604"
      ]
    },
    "policy_algorithms": {
      "_type": "Set",
      "elements": [
        "#A2604"
      ]
    },
    "policy_metadata": {
      "/Author": "Hamid Sobouti",
      "/CreationDate": "D:20241021163842-04\u002700\u0027",
      "/Creator": "Microsoft\u00ae Word 2016",
      "/ModDate": "D:20241021163842-04\u002700\u0027",
      "/Producer": "Microsoft\u00ae Word 2016",
      "/Subject": "FIPS 140-3 Security Policy",
      "/Title": "Gossamer FIPS 140-3 Cryptographic Module Security Policy",
      "pdf_file_size_bytes": 489860,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": []
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 28
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.InternalState",
    "module": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "policy": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": "7b8ce89cb92ea14857737ccbcf5156a95afd527455b4eab1ad2c5dfc87416cdd",
      "source_hash": "ba96ac0e47259703d940d2d9a56c7c1a3ccf80f4039c68ee54b1994a22344b37",
      "txt_hash": "ed65568ef42e1621287a52e749101410e931ddda72b009ee7c17aeafd107bd7d"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in approved mode",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/October 2024_041124_0733 (1).pdf",
    "date_sunset": "2029-10-22",
    "description": "The Brocade Fabric OS FIPS Cryptographic Module underpins Brocade\u2019s Fabric Operating System equipment. The Brocade Fabric OS is the software foundation for Brocade\u2019s purpose-built network infrastructure for mission-critical storage.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Non-invasive security: N/A",
      "Mitigation of other attacks: N/A"
    ],
    "fw_versions": "9.1.1",
    "historical_reason": null,
    "hw_versions": null,
    "level": 1,
    "mentioned_certs": {},
    "module_name": "Brocade Fabric OS FIPS Cryptographic Module",
    "module_type": "Firmware",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-3",
    "status": "active",
    "sw_versions": null,
    "tested_conf": [
      "Fabric OS 9.1.1 running on Brocade G630 Switch with NXP Semiconductors T1042 (e5500 core)",
      "Fabric OS 9.1.1 running on Brocade G730 Switch with Intel(R) Atom(TM) CPU C3338R (2 cores) with PAA",
      "Fabric OS 9.1.1 running on Brocade G730 Switch with Intel(R) Atom(TM) CPU C3338R (2 cores) without PAA",
      "Fabric OS 9.1.1 running on Brocade X7-8 Director with NXP Semiconductors P4080 (e500mc core)"
    ],
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2024-10-23",
        "lab": "Gossamer Security Solutions",
        "validation_type": "Initial"
      }
    ],
    "vendor": "Brocade Communications Systems LLC",
    "vendor_url": "http://www.broadcom.com"
  }
}