Brocade® MLXe® Series Ethernet Routers, Brocade® NetIron® CER 2000 Series Ethernet Routers and Brocade NetIron® CES 2000 Series Ethernet Switches

Certificate #2864

Webpage information

Status historical
Historical reason Moved to historical list due to sunsetting
Validation dates 21.03.2017
Standard FIPS 140-2
Security level 2
Type Hardware
Embodiment Multi-Chip Stand Alone
Caveat When operated in FIPS mode with the tamper evident labels installed and configured as specified in Section 14 of the Security Policy
Exceptions
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A
Description The Brocade NetIron CER 2000 Series is a family of compact routers that are purpose-built for high performance Ethernet edge routing and MPLS applications.The Brocade NetIron CES 2000 Series of switches provides IP routing and advanced Carrier Ethernet capabilities in a compact form factor. Brocade MLXe Series routers feature industry-leading Gigabit Ethernet ports with wire-speed density; advanced Layer 2 switching; rich IPv4, IPv6, Multi-VRF, MPLS, L2/L3 Virtual Private Networks (VPN),IKEv2/IPsec and PHY based MACsec capabilities without compromising performance.
Version (Hardware) {[BR-MLXE-8-MR2-M-AC (80-1007225-01), BR-MLXE-16-MR2-M-AC (80-1006827-02), BR-MLXE-32-MR2-M-AC (80-1007253-04), BR-MLXE-4-MR2-X-AC (80-1006874-03), BR-MLXE-32-MR2-X-AC (80-1007255-04), with Components (80-1005643-01, 80-1005644-03, 80-1005641-02, 80-1005642-03, 80-1007878-02, 80-1007911-02, 80-1008426-01, 80-1008427-02, 80-1007879-02, 80-1003891-02, 80-1002983-01, 80-1008686-01, 80-1003971-01, 80-1003969-02, 80-1004114-01, 80-1004113-01, 80-1004112-01, 80-1004469-01, 80-1004760-02, 80-1006511-02, 80-1004757-02, 80-1003009-01, 80-1003052-01, 80-1003053-01)], [BR-CER-2024C-4X-RT-AC (80-1006530-01), BR-CER-2024F-4X-RT-AC (80-1006529-01), with Components (80-1003868-01, 80-1004848-01)], [BR-CES-2024C-4X-AC (80-1000077-01), BR-CES-2024F-4X-AC (80-1000037-01), with Component (80-1003868-01)]} with FIPS Kit XBR-000195
Version (Firmware) Multi-Service IronWare R05.9.00aa
Vendor Brocade Communications Systems, Inc.
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Symmetric Algorithms
AES, AES-128, DES, Triple-DES, TDEA, HMAC, HMAC-SHA-256, HMAC-SHA-224, HMAC-SHA-512, HMAC-SHA-384, CMAC
Asymmetric Algorithms
RSA 2048, ECDH, ECDSA, ECC, Diffie-Hellman, DH, DSA
Hash functions
SHA1, SHA-1, SHA-224, SHA-512, SHA-256, SHA-384, MD5
Schemes
MAC, KEX, Key Exchange, Key Agreement, Key agreement
Protocols
SSHv2, SSH, SSL 3.0, TLS, TLS v1.2, TLSv1.2, TLS v1.0, IKEv2, IKE, IPsec, VPN
Randomness
DRBG
Elliptic Curves
P-256, P-384, curve P-256
Block cipher modes
ECB, CBC, CTR, GCM
TLS cipher suites
TLS_RSA_WITH_AES_128_CBC_SHA, TLS_RSA_WITH_AES_256_CBC_SHA, TLS_RSA_WITH_AES_128_CBC_SHA256, TLS_RSA_WITH_AES_256_CBC_SHA256, TLS_DHE_RSA_WITH_AES_128_CBC_SHA, TLS_DHE_RSA_WITH_AES_256_CBC_SHA, TLS_DHE_RSA_WITH_AES_128_CBC_SHA256, TLS_DHE_RSA_WITH_AES_256_CBC_SHA256

Vendor
Broadcom

Security level
level 2, level 3, Level 2

Standards
FIPS 140-2, FIPS 186-4, RFC-5905

File metadata

Author Gauri Gokhale
Creation date D:20170315100528-07'00'
Modification date D:20170315100706-07'00'
Pages 137
Creator Acrobat PDFMaker 11 for Word
Producer Adobe PDF Library 11.0

Heuristics

No heuristics are available for this certificate.

References

No references are available for this certificate.

Updates Feed

  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 2864,
  "dgst": "cf5df26713138318",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "AES#2717",
        "AES#2154",
        "HMAC#1694",
        "CVL#175",
        "CVL#393",
        "RSA#1413",
        "ECDSA#809",
        "CVL#394",
        "CVL#403",
        "AES#3143",
        "DRBG#452",
        "ECDSA#761",
        "AES#1648",
        "HMAC#1696",
        "SHS#934",
        "RSA#1411",
        "CVL#1029",
        "AES#3144",
        "CVL#173",
        "DRBG#684",
        "SHS#2282",
        "AES#3478",
        "KBKDF#35",
        "CVL#712",
        "KTS#2717",
        "AES#2715",
        "AES#2946",
        "DRBG#454",
        "KTS#1696",
        "SHS#2280",
        "HMAC#2848",
        "CVL#404",
        "CVL#713"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "05.9.00"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 2
          },
          "ECDH": {
            "ECDH": 28
          },
          "ECDSA": {
            "ECDSA": 26
          }
        },
        "FF": {
          "DH": {
            "DH": 48,
            "Diffie-Hellman": 3
          },
          "DSA": {
            "DSA": 1
          }
        },
        "RSA": {
          "RSA 2048": 17
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 11
        },
        "CTR": {
          "CTR": 7
        },
        "ECB": {
          "ECB": 9
        },
        "GCM": {
          "GCM": 11
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "IKE": {
          "IKE": 3,
          "IKEv2": 77
        },
        "IPsec": {
          "IPsec": 23
        },
        "SSH": {
          "SSH": 5,
          "SSHv2": 124
        },
        "TLS": {
          "SSL": {
            "SSL 3.0": 2
          },
          "TLS": {
            "TLS": 72,
            "TLS v1.0": 1,
            "TLS v1.2": 25,
            "TLSv1.2": 1
          }
        },
        "VPN": {
          "VPN": 1
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 7,
          "Key agreement": 1
        },
        "KEX": {
          "KEX": 2,
          "Key Exchange": 1
        },
        "MAC": {
          "MAC": 1
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-256": 41,
          "P-384": 34,
          "curve P-256": 1
        }
      },
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "#1029": 1,
          "#1411": 1,
          "#1413": 1,
          "#1648": 3,
          "#1694": 1,
          "#1696": 1,
          "#173": 1,
          "#175": 2,
          "#2154": 6,
          "#2280": 1,
          "#2282": 1,
          "#2715": 1,
          "#2717": 1,
          "#2848": 1,
          "#2946": 1,
          "#3143": 1,
          "#3144": 1,
          "#3478": 1,
          "#35": 1,
          "#393": 1,
          "#394": 1,
          "#403": 1,
          "#404": 1,
          "#452": 1,
          "#454": 1,
          "#684": 1,
          "#712": 2,
          "#713": 2,
          "#761": 1,
          "#809": 1,
          "#934": 1
        }
      },
      "fips_certlike": {
        "Certlike": {
          "AES Cert #1648": 2,
          "AES Cert #2154": 4,
          "AES-128": 6,
          "DES 56": 1,
          "DRBG 14": 1,
          "DRBG 18": 1,
          "HMAC- SHA-1, 160": 1,
          "HMAC-SHA- 256": 2,
          "HMAC-SHA-1": 76,
          "HMAC-SHA-1, 160": 2,
          "HMAC-SHA-1, 256": 2,
          "HMAC-SHA-1-96": 4,
          "HMAC-SHA-224": 2,
          "HMAC-SHA-256": 8,
          "HMAC-SHA-256 #1694": 2,
          "HMAC-SHA-256 #1696": 2,
          "HMAC-SHA-384": 2,
          "HMAC-SHA-384 #2848": 2,
          "HMAC-SHA-512": 2,
          "RSA 2048": 17,
          "SHA-1": 8,
          "SHA-1, 160": 1,
          "SHA-1, 224": 4,
          "SHA-1, 256": 1,
          "SHA-224": 8,
          "SHA-256": 12,
          "SHA-384": 3,
          "SHA-512": 4,
          "SHA1": 5
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 2": 2,
          "level 2": 1,
          "level 3": 1
        }
      },
      "hash_function": {
        "MD": {
          "MD5": {
            "MD5": 10
          }
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 14,
            "SHA1": 5
          },
          "SHA2": {
            "SHA-224": 8,
            "SHA-256": 12,
            "SHA-384": 3,
            "SHA-512": 4
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 65
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-2": 42,
          "FIPS 186-4": 13
        },
        "RFC": {
          "RFC-5905": 1
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 69,
            "AES-128": 6
          }
        },
        "DES": {
          "3DES": {
            "TDEA": 1,
            "Triple-DES": 5
          },
          "DES": {
            "DES": 5
          }
        },
        "constructions": {
          "MAC": {
            "CMAC": 3,
            "HMAC": 8,
            "HMAC-SHA-224": 1,
            "HMAC-SHA-256": 6,
            "HMAC-SHA-384": 2,
            "HMAC-SHA-512": 1
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {
        "TLS": {
          "TLS_DHE_RSA_WITH_AES_128_CBC_SHA": 1,
          "TLS_DHE_RSA_WITH_AES_128_CBC_SHA256": 1,
          "TLS_DHE_RSA_WITH_AES_256_CBC_SHA": 1,
          "TLS_DHE_RSA_WITH_AES_256_CBC_SHA256": 1,
          "TLS_RSA_WITH_AES_128_CBC_SHA": 1,
          "TLS_RSA_WITH_AES_128_CBC_SHA256": 1,
          "TLS_RSA_WITH_AES_256_CBC_SHA": 1,
          "TLS_RSA_WITH_AES_256_CBC_SHA256": 1
        }
      },
      "vendor": {
        "Broadcom": {
          "Broadcom": 5
        }
      },
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "Gauri Gokhale",
      "/Comments": "",
      "/Company": "Brocade Communications Systems, Inc.",
      "/ContentTypeId": "0x010100587F7AB216E8E54BB1E11AF6F44031A9",
      "/CreationDate": "D:20170315100528-07\u002700\u0027",
      "/Creator": "Acrobat PDFMaker 11 for Word",
      "/Keywords": "",
      "/ModDate": "D:20170315100706-07\u002700\u0027",
      "/Producer": "Adobe PDF Library 11.0",
      "/SourceModified": "D:20170315170245",
      "/Subject": "",
      "/Title": "",
      "pdf_file_size_bytes": 3211105,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "http://csrc.nist.gov/groups/STM/cmvp/",
          "http://csrc.nist.gov/groups/STM/cavp/validation.html",
          "http://csrc.nist.gov/groups/STM/cmvp/)"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 137
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
    "module_download_ok": true,
    "module_extract_ok": true,
    "policy_convert_ok": true,
    "policy_download_ok": true,
    "policy_extract_ok": true,
    "policy_json_hash": null,
    "policy_pdf_hash": "7ed608fbac4b4eb95869109c6df8651d98fe89a8148e36146d9b9386e46484c1",
    "policy_txt_hash": "de3ac6085cd8bb11e7a46ed08e54a6de7e340164943a617d1cefa4f0ec24b8f9"
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in FIPS mode with the tamper evident labels installed and configured as specified in Section 14 of the Security Policy",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/FIPS140ConsolidatedCertMar2017.pdf",
    "date_sunset": null,
    "description": "The Brocade NetIron CER 2000 Series is a family of compact routers that are purpose-built for high performance Ethernet edge routing and MPLS applications.The Brocade NetIron CES 2000 Series of switches provides IP routing and advanced Carrier Ethernet capabilities in a compact form factor. Brocade MLXe Series routers feature industry-leading Gigabit Ethernet ports with wire-speed density; advanced Layer 2 switching; rich IPv4, IPv6, Multi-VRF, MPLS, L2/L3 Virtual Private Networks (VPN),IKEv2/IPsec and PHY based MACsec capabilities without compromising performance.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Design Assurance: Level 3",
      "Mitigation of Other Attacks: N/A"
    ],
    "fw_versions": "Multi-Service IronWare R05.9.00aa",
    "historical_reason": "Moved to historical list due to sunsetting",
    "hw_versions": "{[BR-MLXE-8-MR2-M-AC (80-1007225-01), BR-MLXE-16-MR2-M-AC (80-1006827-02), BR-MLXE-32-MR2-M-AC (80-1007253-04), BR-MLXE-4-MR2-X-AC (80-1006874-03), BR-MLXE-32-MR2-X-AC (80-1007255-04), with Components (80-1005643-01, 80-1005644-03, 80-1005641-02, 80-1005642-03, 80-1007878-02, 80-1007911-02, 80-1008426-01, 80-1008427-02, 80-1007879-02, 80-1003891-02, 80-1002983-01, 80-1008686-01, 80-1003971-01, 80-1003969-02, 80-1004114-01, 80-1004113-01, 80-1004112-01, 80-1004469-01, 80-1004760-02, 80-1006511-02, 80-1004757-02, 80-1003009-01, 80-1003052-01, 80-1003053-01)], [BR-CER-2024C-4X-RT-AC (80-1006530-01), BR-CER-2024F-4X-RT-AC (80-1006529-01), with Components (80-1003868-01, 80-1004848-01)], [BR-CES-2024C-4X-AC (80-1000077-01), BR-CES-2024F-4X-AC (80-1000037-01), with Component (80-1003868-01)]} with FIPS Kit XBR-000195",
    "level": 2,
    "mentioned_certs": {},
    "module_name": "Brocade\u00ae MLXe\u00ae Series Ethernet Routers, Brocade\u00ae NetIron\u00ae CER 2000 Series Ethernet Routers and Brocade NetIron\u00ae CES 2000 Series Ethernet Switches",
    "module_type": "Hardware",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-2",
    "status": "historical",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2017-03-21",
        "lab": "AEGISOLVE, Inc.",
        "validation_type": "Initial"
      }
    ],
    "vendor": "Brocade Communications Systems, Inc.",
    "vendor_url": "http://www.brocade.com"
  }
}