Aruba IAP-214, IAP-215, IAP-224, IAP-225, IAP-274, IAP-275, IAP-277, RAP-108 and RAP-109 Wireless Access Points with Aruba Instant Firmware

Certificate #3069

Webpage information

Status historical
Historical reason SP 800-56Arev3 transition
Validation dates 27.11.2017
Standard FIPS 140-2
Security level 2
Type Firmware
Embodiment Multi-Chip Stand Alone
Caveat When operated only on the specific platforms specified on the certificate in FIPS mode with tamper evident labels installed as indicated in the Security Policy. The protocols TLS, SNMP and IKEv2 shall not be used when operated in FIPS mode
Description Aruba's 802.11ac Wi-Fi access points operate at gigabit speeds, offering extreme performance for mobile devices. In FIPS 140-2 mode, Aruba APs in conjunction with a Mobility Controller support the IEEE 802.11i/WPA2 client standard along with optional Suite B cryptography. Aruba APs also support wireless intrusion detection/prevention services and wireless mesh topologies.
Version (Firmware) ArubaInstant 6.5.1.0-4.3.1
Tested configurations
  • IAP-214 (Hardware Versions: IAP-214-USF1 [HPE SKU JW225A], IAP-214-RWF1 [HPE SKU JW224A]), IAP-215 (Hardware Versions: IAP-215-USF1 [HPE SKU JW231A], IAP-215-RWF1 [HPE SKU JW230A]), IAP-224 (Hardware Versions: IAP-224-USF1 [HPE SKU JW237A], IAP-224-RWF1 [HPE SKU JW235A]), IAP-225 (Hardware Versions: IAP-225-USF1 [HPE SKU JW243A], IAP-225-RWF1 [HPE SKU JW241A]), IAP-274 (Hardware Versions: IAP-274-USF1 [HPE SKU JW252A], IAP-274-RWF1 [HPE SKU JW251A]), IAP-275 (Hardware Versions: IAP-275-USF1 [HPE SKU JW257A], IAP-275-RWF1 [HPE SKU JW256A]), IAP-277 (Hardware Versions: IAP-277-USF1 [HPE SKU JW263A], IAP-277-RWF1 [HPE SKU JW262A]), RAP-108 (Hardware Versions: RAP-108-USF1 [HPE SKU JW269A], RAP-108-F1 [HPE SKU JW268A]), RAP-109 (Hardware Versions: RAP-109-USF1 [HPE SKU JW275A], RAP-109-F1 [HPE SKU JW274A])
Vendor Aruba, a Hewlett Packard Enterprise company
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Symmetric Algorithms
AES, RC4, DES, Triple-DES, HMAC, HMAC-SHA-512, HMAC-SHA-256, HMAC-SHA-384
Asymmetric Algorithms
RSA 2048, Diffie-Hellman
Hash functions
SHA1, SHA-1, SHA-384, SHA-512, SHA-256, SHA256, SHA384, SHA512, MD5
Schemes
Key Exchange, Key agreement
Protocols
SSHv2, SSH, TLS, IKE, IKEv2, IPsec, VPN
Randomness
DRBG, RNG
Block cipher modes
ECB, CBC, CTR, OFB, CCM

Vendor
Qualcomm

Security level
Level 2, Level 1

Standards
FIPS 140-2, FIPS 140, FIPS 197, FIPS 198-1, FIPS 186-2, FIPS 186-4, FIPS 180-4, SP 800-38A, SP 800-67, SP 800-108, SP 800-90A, SP 800-38F, PKCS1, PKCS#1, X.509

File metadata

Title Aruba IAP-214, IAP-215, IAP-224, IAP-225, IAP-274, IAP-275, IAP-277, RAP-108 and RAP-109 Wireless Access Points with Aruba Instant Firmware
Author Harsha Nagaraja
Creation date D:20171115093435-05'00'
Modification date D:20171115093435-05'00'
Pages 57
Creator Microsoft® Word 2013
Producer Microsoft® Word 2013

Heuristics

No heuristics are available for this certificate.

References

No references are available for this certificate.

Updates Feed

  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 3069,
  "dgst": "d642822b369cd5e3",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "AES#3944",
        "KBKDF#135",
        "KTS#2569",
        "HMAC#2569",
        "AES#1649",
        "SHS#3254",
        "SHS#3654",
        "RSA#2015",
        "AES#1648",
        "KTS#3944",
        "RSA#2419",
        "RSA#2417",
        "CVL#1210",
        "KBKDF#134",
        "SHS#3657",
        "AES#2450",
        "DRBG#1149"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "6.5.1.0",
        "4.3.1"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "FF": {
          "DH": {
            "Diffie-Hellman": 11
          }
        },
        "RSA": {
          "RSA 2048": 3
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 6
        },
        "CCM": {
          "CCM": 2
        },
        "CTR": {
          "CTR": 6
        },
        "ECB": {
          "ECB": 2
        },
        "OFB": {
          "OFB": 1
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "IKE": {
          "IKE": 1,
          "IKEv2": 1
        },
        "IPsec": {
          "IPsec": 1
        },
        "SSH": {
          "SSH": 11,
          "SSHv2": 11
        },
        "TLS": {
          "TLS": {
            "TLS": 11
          }
        },
        "VPN": {
          "VPN": 5
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key agreement": 1
        },
        "KEX": {
          "Key Exchange": 1
        }
      },
      "device_model": {},
      "ecc_curve": {},
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "#2569": 1,
          "#3944": 1
        }
      },
      "fips_certlike": {
        "Certlike": {
          "AES 128/192/256": 1,
          "AES Cert. #3944": 1,
          "DRBG (256": 1,
          "DRBG (440": 1,
          "DRBG 4": 1,
          "DRBG 5": 1,
          "DRBG 54": 1,
          "HMAC (384": 1,
          "HMAC- SHA-1": 1,
          "HMAC- SHA-256": 1,
          "HMAC- SHA-384": 3,
          "HMAC- SHA1": 3,
          "HMAC-SHA- 128": 2,
          "HMAC-SHA- 256": 6,
          "HMAC-SHA- 512 160": 6,
          "HMAC-SHA-1": 2,
          "HMAC-SHA-256": 2,
          "HMAC-SHA-384": 2,
          "HMAC-SHA-512": 4,
          "HMAC-SHA1": 7,
          "HMAC-SHA1 160": 1,
          "HMAC-SHA256": 2,
          "HMAC-SHA384": 2,
          "HMAC-SHA512": 4,
          "PKCS#1": 2,
          "PKCS1": 8,
          "RSA 2048": 3,
          "RSA PKCS#1": 2,
          "SHA- 256": 12,
          "SHA- 384": 8,
          "SHA-1": 12,
          "SHA-256": 4,
          "SHA-384": 3,
          "SHA-512": 7,
          "SHA1": 6,
          "SHA256": 1,
          "SHA384": 1,
          "SHA512": 1
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 1,
          "Level 2": 14
        }
      },
      "hash_function": {
        "MD": {
          "MD5": {
            "MD5": 1
          }
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 12,
            "SHA1": 6
          },
          "SHA2": {
            "SHA-256": 4,
            "SHA-384": 3,
            "SHA-512": 7,
            "SHA256": 1,
            "SHA384": 1,
            "SHA512": 1
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 17
        },
        "RNG": {
          "RNG": 1
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140": 1,
          "FIPS 140-2": 26,
          "FIPS 180-4": 5,
          "FIPS 186-2": 1,
          "FIPS 186-4": 3,
          "FIPS 197": 5,
          "FIPS 198-1": 4
        },
        "NIST": {
          "SP 800-108": 2,
          "SP 800-38A": 5,
          "SP 800-38F": 1,
          "SP 800-67": 3,
          "SP 800-90A": 2
        },
        "PKCS": {
          "PKCS#1": 2,
          "PKCS1": 4
        },
        "X509": {
          "X.509": 1
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 17
          },
          "RC": {
            "RC4": 1
          }
        },
        "DES": {
          "3DES": {
            "Triple-DES": 11
          },
          "DES": {
            "DES": 1
          }
        },
        "constructions": {
          "MAC": {
            "HMAC": 12,
            "HMAC-SHA-256": 1,
            "HMAC-SHA-384": 1,
            "HMAC-SHA-512": 2
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {
        "Qualcomm": {
          "Qualcomm": 2
        }
      },
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "Harsha Nagaraja",
      "/CreationDate": "D:20171115093435-05\u002700\u0027",
      "/Creator": "Microsoft\u00ae Word 2013",
      "/ModDate": "D:20171115093435-05\u002700\u0027",
      "/Producer": "Microsoft\u00ae Word 2013",
      "/Title": "Aruba IAP-214, IAP-215, IAP-224, IAP-225, IAP-274, IAP-275, IAP-277, RAP-108 and RAP-109 Wireless Access Points with Aruba Instant Firmware",
      "pdf_file_size_bytes": 1424746,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html#1649",
          "http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html#1648",
          "http://csrc.nist.gov/groups/STM/cavp/documents/KBKDF800-108/kbkdfnewval.html#135",
          "http://csrc.nist.gov/groups/STM/cavp/documents/shs/shaval.html#3182",
          "http://csrc.nist.gov/groups/STM/cavp/documents/shs/shaval.html#3654",
          "http://csrc.nist.gov/groups/STM/cavp/documents/des/tripledesnewval.html#2162",
          "http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html#2450",
          "http://csrc.nist.gov/groups/STM/cavp/documents/mac/hmacval.html",
          "http://csrc.nist.gov/groups/STM/cavp/documents/dss/rsanewval.html#2417",
          "https://support.arubanetworks.com/Documentation/tabid/77/DMXModule/512/EntryId/25571/Default.aspx",
          "http://csrc.nist.gov/groups/STM/cavp/documents/mac/hmacval.html#2643",
          "http://csrc.nist.gov/groups/STM/cavp/documents/des/tripledesnewval.html#2128",
          "http://csrc.nist.gov/groups/STM/cavp/documents/dss/rsanewval.html#1970",
          "http://csrc.nist.gov/groups/STM/cavp/documents/drbg/drbgnewval.html#1149",
          "http://csrc.nist.gov/groups/STM/cavp/documents/shs/shaval.html",
          "http://csrc.nist.gov/groups/STM/cavp/documents/dss/rsanewval.html#2015",
          "http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html#4048",
          "http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html#3944",
          "http://csrc.nist.gov/groups/STM/cavp/documents/shs/shaval.html#3657",
          "http://csrc.nist.gov/groups/STM/cavp/documents/KBKDF800-108/kbkdfnewval.html#134",
          "http://csrc.nist.gov/groups/STM/cavp/documents/mac/hmacval.html#2569",
          "http://csrc.nist.gov/groups/STM/cavp/documents/mac/hmacval.html#2507",
          "http://csrc.nist.gov/groups/STM/cavp/documents/components/componentnewval.html#1210",
          "http://csrc.nist.gov/groups/STM/cavp/documents/shs/shaval.html#3337",
          "http://csrc.nist.gov/groups/STM/cavp/documents/aes/aesval.html#3860",
          "http://csrc.nist.gov/groups/STM/cmvp/index.html",
          "http://csrc.nist.gov/groups/STM/cavp/documents/shs/shaval.html#3254",
          "http://csrc.nist.gov/groups/STM/cavp/documents/dss/rsanewval.html#2419",
          "http://csrc.nist.gov/groups/STM/cavp/documents/des/tripledesnewval.html"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 57
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
    "module_download_ok": true,
    "module_extract_ok": true,
    "policy_convert_ok": true,
    "policy_download_ok": true,
    "policy_extract_ok": true,
    "policy_json_hash": null,
    "policy_pdf_hash": "f5a64ba4b534f28bc348f5358ebfed8d08d474d6b802cc8b82fa500a77de0a59",
    "policy_txt_hash": "af7d911beeeafbe8541be1e0dc0900c19b04015900defcc6eee66965a1186cab"
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated only on the specific platforms specified on the certificate in FIPS mode with tamper evident labels installed as indicated in the Security Policy. The protocols TLS, SNMP and IKEv2 shall not be used when operated in FIPS mode",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/FIPS140ConsolidatedCertNov2017.pdf",
    "date_sunset": null,
    "description": "Aruba\u0027s 802.11ac Wi-Fi access points operate at gigabit speeds, offering extreme performance for mobile devices. In FIPS 140-2 mode, Aruba APs in conjunction with a Mobility Controller support the IEEE 802.11i/WPA2 client standard along with optional Suite B cryptography. Aruba APs also support wireless intrusion detection/prevention services and wireless mesh topologies.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": null,
    "fw_versions": "ArubaInstant 6.5.1.0-4.3.1",
    "historical_reason": "SP 800-56Arev3 transition",
    "hw_versions": null,
    "level": 2,
    "mentioned_certs": {},
    "module_name": "Aruba IAP-214, IAP-215, IAP-224, IAP-225, IAP-274, IAP-275, IAP-277, RAP-108 and RAP-109 Wireless Access Points with Aruba Instant Firmware",
    "module_type": "Firmware",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-2",
    "status": "historical",
    "sw_versions": null,
    "tested_conf": [
      "IAP-214 (Hardware Versions: IAP-214-USF1 [HPE SKU JW225A], IAP-214-RWF1 [HPE SKU JW224A]), IAP-215 (Hardware Versions: IAP-215-USF1 [HPE SKU JW231A], IAP-215-RWF1 [HPE SKU JW230A]), IAP-224 (Hardware Versions: IAP-224-USF1 [HPE SKU JW237A], IAP-224-RWF1 [HPE SKU JW235A]), IAP-225 (Hardware Versions: IAP-225-USF1 [HPE SKU JW243A], IAP-225-RWF1 [HPE SKU JW241A]), IAP-274 (Hardware Versions: IAP-274-USF1 [HPE SKU JW252A], IAP-274-RWF1 [HPE SKU JW251A]), IAP-275 (Hardware Versions: IAP-275-USF1 [HPE SKU JW257A], IAP-275-RWF1 [HPE SKU JW256A]), IAP-277 (Hardware Versions: IAP-277-USF1 [HPE SKU JW263A], IAP-277-RWF1 [HPE SKU JW262A]), RAP-108 (Hardware Versions: RAP-108-USF1 [HPE SKU JW269A], RAP-108-F1 [HPE SKU JW268A]), RAP-109 (Hardware Versions: RAP-109-USF1 [HPE SKU JW275A], RAP-109-F1 [HPE SKU JW274A])"
    ],
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2017-11-27",
        "lab": "Leidos Accredited Testing \u0026 Evaluation (AT\u0026E) Lab",
        "validation_type": "Initial"
      }
    ],
    "vendor": "Aruba, a Hewlett Packard Enterprise company",
    "vendor_url": "http://www.arubanetworks.com"
  }
}