Aruba 3000 [1] and 6000/M3 Revision B2 [2] Controllers with ArubaOS FIPS Firmware

Certificate #1840

Webpage information

Status historical
Historical reason RNG SP800-131A Revision 1 Transition
Validation dates 11.02.2013 , 08.03.2013 , 26.07.2013 , 23.01.2014
Standard FIPS 140-2
Security level 2
Type Hardware
Embodiment Multi-Chip Stand Alone
Caveat When operated in FIPS mode with tamper evident labels installed as indicated in the Security Policy clause "Installing the Controller" and the 6000/M3 configured as specified in Security Policy clause "Minimum Configuration for the Aruba 6000-400"
Description Aruba's family of Mobility Controllers are network infrastructure devices providing secure, scalable solutions for enterprise Wi-Fi, network security policy enforcement, VPN services, and wireless intrusion detection and prevention. Mobility controllers serve as central points of authentication, encryption, access control, and network coordination for all mobile network services
Version (Hardware) [3200-F1 Revision B2, 3400-F1 Revision B2, 3600-F1 Revision B2, 3200-USF1 Revision B2, 3400-USF1 Revision B2, 3600-USF1 Revision B2] [1] and [(6000-400-F1 or 6000-400-USF1) with (M3mk1-S-F1 Revision B2, LC-2G-1, LC-2G24F-1, LC-2G24FP-1, HW-FT, HW-PSU-200 or HW-PSU-400] [2] with FIPS kit 4010061-01
Version (Firmware) ArubaOS_MMC_6.1.2.3-FIPS or ArubaOS_MMC_6.1.4.1-FIPS or ArubaOS_MMC_6.1.4.5-FIPS or ArubaOS_MMC_6.1.4.7-FIPS
Vendor Aruba Networks, Inc.
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Symmetric Algorithms
AES, AES-, AES-128, AES256, RC4, DES, Triple-DES, 3DES, HMAC, HMAC-SHA-256
Asymmetric Algorithms
ECDSA, Diffie-Hellman
Hash functions
SHA-1, SHA1, SHA-256, SHA256, SHA384, SHA512, MD5
Schemes
MAC, Key Exchange, Key agreement, Key Agreement
Protocols
SSHv2, SSH, SSL, TLS, IKEv1, IKEv2, IPsec, VPN
Randomness
RNG
Libraries
OpenSSL
Elliptic Curves
P-256, P-384
Block cipher modes
CBC, CTR, GCM, CCM

Vendor
Cisco

Security level
Level 2, Level 1

Standards
FIPS 140-2, FIPS 186-2, FIPS 140, PKCS#1

File metadata

Title Microsoft Word - 3000-6000-M3 Security Policy__B2 6.1.4.7 12-23-2013.docx
Author wangzhi
Creation date D:20131230112945-05'00'
Modification date D:20131230112945-05'00'
Pages 38
Creator PScript5.dll Version 5.2.2
Producer Acrobat Distiller 11.0 (Windows)

References

Incoming
  • 3326 - historical - Self-Defending Key Management Serviceā„¢

Heuristics

No heuristics are available for this certificate.

References

Loading...

Updates Feed

  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 1840,
  "dgst": "f23173a6a69eac18",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "HMAC#1098",
        "AES#1854",
        "SHS#1627",
        "HMAC#416",
        "SHS#1629",
        "ECDSA#257",
        "Triple-DES#1198",
        "ECDSA#258",
        "RSA#933",
        "SHS#768",
        "RSA#937",
        "AES#465",
        "RNG#972",
        "AES#1850",
        "SHS#1631",
        "Triple-DES#482",
        "RSA#935",
        "Triple-DES#1201",
        "RNG#969",
        "HMAC#1101"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "6.1.2.3",
        "6.1.4.1",
        "6.1.4.5",
        "6.1.4.7"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": {
        "_type": "Set",
        "elements": [
          "3326"
        ]
      },
      "directly_referencing": null,
      "indirectly_referenced_by": {
        "_type": "Set",
        "elements": [
          "3326"
        ]
      },
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECDSA": {
            "ECDSA": 16
          }
        },
        "FF": {
          "DH": {
            "Diffie-Hellman": 17
          }
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 2
        },
        "CCM": {
          "CCM": 1
        },
        "CTR": {
          "CTR": 1
        },
        "GCM": {
          "GCM": 2
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {
        "OpenSSL": {
          "OpenSSL": 5
        }
      },
      "crypto_protocol": {
        "IKE": {
          "IKEv1": 1,
          "IKEv2": 1
        },
        "IPsec": {
          "IPsec": 4
        },
        "SSH": {
          "SSH": 22,
          "SSHv2": 1
        },
        "TLS": {
          "SSL": {
            "SSL": 1
          },
          "TLS": {
            "TLS": 20
          }
        },
        "VPN": {
          "VPN": 6
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 3,
          "Key agreement": 7
        },
        "KEX": {
          "Key Exchange": 1
        },
        "MAC": {
          "MAC": 1
        }
      },
      "device_model": {},
      "ecc_curve": {
        "NIST": {
          "P-256": 4,
          "P-384": 6
        }
      },
      "eval_facility": {},
      "fips_cert_id": {
        "Cert": {
          "#1098": 1,
          "#1101": 1,
          "#1198": 1,
          "#1201": 1,
          "#1627": 1,
          "#1629": 1,
          "#1631": 1,
          "#1850": 1,
          "#1854": 1,
          "#257": 1,
          "#258": 1,
          "#416": 1,
          "#465": 1,
          "#482": 1,
          "#768": 1,
          "#933": 1,
          "#935": 1,
          "#937": 1,
          "#969": 1,
          "#972": 1
        }
      },
      "fips_certlike": {
        "Certlike": {
          "AES (Cert. #1850": 1,
          "AES (Cert. #1854": 1,
          "AES (Cert. #465": 1,
          "AES 128, 192": 1,
          "AES key (256": 1,
          "AES-128": 3,
          "AES256": 3,
          "HMAC (Cert. #1098": 1,
          "HMAC (Cert. #1101": 1,
          "HMAC (Cert.#416": 1,
          "HMAC SHA-1": 2,
          "HMAC- SHA-1": 1,
          "HMAC- SHA1": 1,
          "HMAC-SHA-1": 2,
          "HMAC-SHA-256": 2,
          "HMAC-SHA1": 16,
          "HMAC-SHA256": 6,
          "HMAC-SHA384": 4,
          "HMAC-SHA512": 2,
          "PKCS#1": 2,
          "RSA PKCS#1": 2,
          "SHA-1": 10,
          "SHA-256": 1,
          "SHA1": 3,
          "SHA256": 2,
          "SHA384": 2,
          "SHA512": 1,
          "SHS (Cert. #1627": 1,
          "SHS (Cert. #1629": 1,
          "SHS (Cert. #1631": 1,
          "SHS (Cert. #768": 1
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 1,
          "Level 2": 47
        }
      },
      "hash_function": {
        "MD": {
          "MD5": {
            "MD5": 2
          }
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 10,
            "SHA1": 3
          },
          "SHA2": {
            "SHA-256": 1,
            "SHA256": 2,
            "SHA384": 2,
            "SHA512": 1
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "RNG": {
          "RNG": 21
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140": 1,
          "FIPS 140-2": 25,
          "FIPS 186-2": 1
        },
        "PKCS": {
          "PKCS#1": 2
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 11,
            "AES-": 2,
            "AES-128": 3,
            "AES256": 3
          },
          "RC": {
            "RC4": 1
          }
        },
        "DES": {
          "3DES": {
            "3DES": 3,
            "Triple-DES": 10
          },
          "DES": {
            "DES": 6
          }
        },
        "constructions": {
          "MAC": {
            "HMAC": 8,
            "HMAC-SHA-256": 1
          }
        }
      },
      "tee_name": {},
      "tls_cipher_suite": {},
      "vendor": {
        "Cisco": {
          "Cisco": 1
        }
      },
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "wangzhi",
      "/CreationDate": "D:20131230112945-05\u002700\u0027",
      "/Creator": "PScript5.dll Version 5.2.2",
      "/ModDate": "D:20131230112945-05\u002700\u0027",
      "/Producer": "Acrobat Distiller 11.0 (Windows)",
      "/Title": "Microsoft Word - 3000-6000-M3 Security Policy__B2 6.1.4.7 12-23-2013.docx",
      "pdf_file_size_bytes": 470632,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": []
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 38
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
    "module_download_ok": true,
    "module_extract_ok": true,
    "policy_convert_ok": true,
    "policy_download_ok": true,
    "policy_extract_ok": true,
    "policy_json_hash": null,
    "policy_pdf_hash": "b845a03086846fcaeede0b7bbb9de0da041f16818c1f0bcc1af7dcaef207d539",
    "policy_txt_hash": "93136fb6c871cec15a80996357949c460f6a4fd7fbf19aaf10edc765c84774ec"
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in FIPS mode with tamper evident labels installed as indicated in the Security Policy clause \"Installing the Controller\" and the 6000/M3 configured as specified in Security Policy clause \"Minimum Configuration for the Aruba 6000-400\"",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/FIPS140ConsolidatedCertList0026.pdf",
    "date_sunset": null,
    "description": "Aruba\u0027s family of Mobility Controllers are network infrastructure devices providing secure, scalable solutions for enterprise Wi-Fi, network security policy enforcement, VPN services, and wireless intrusion detection and prevention. Mobility controllers serve as central points of authentication, encryption, access control, and network coordination for all mobile network services",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": null,
    "fw_versions": "ArubaOS_MMC_6.1.2.3-FIPS or ArubaOS_MMC_6.1.4.1-FIPS or ArubaOS_MMC_6.1.4.5-FIPS or ArubaOS_MMC_6.1.4.7-FIPS",
    "historical_reason": "RNG SP800-131A Revision 1 Transition",
    "hw_versions": "[3200-F1 Revision B2, 3400-F1 Revision B2, 3600-F1 Revision B2, 3200-USF1 Revision B2, 3400-USF1 Revision B2, 3600-USF1 Revision B2] [1] and [(6000-400-F1 or 6000-400-USF1) with (M3mk1-S-F1 Revision B2, LC-2G-1, LC-2G24F-1, LC-2G24FP-1, HW-FT, HW-PSU-200 or HW-PSU-400] [2] with FIPS kit 4010061-01",
    "level": 2,
    "mentioned_certs": {},
    "module_name": "Aruba 3000 [1] and 6000/M3 Revision B2 [2] Controllers with ArubaOS FIPS Firmware",
    "module_type": "Hardware",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-2",
    "status": "historical",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2013-02-11",
        "lab": "SAIC-VA",
        "validation_type": "Initial"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2013-03-08",
        "lab": "Leidos Accredited Testing \u0026 Evaluation (AT\u0026E) Lab",
        "validation_type": "Update"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2013-07-26",
        "lab": "Leidos Accredited Testing \u0026 Evaluation (AT\u0026E) Lab",
        "validation_type": "Update"
      },
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2014-01-23",
        "lab": "Leidos Accredited Testing \u0026 Evaluation (AT\u0026E) Lab",
        "validation_type": "Update"
      }
    ],
    "vendor": "Aruba Networks, Inc.",
    "vendor_url": "http://www.arubanetworks.com"
  }
}