Device Cryptographic Module

Certificate details

Certificate ID #5056
Status active
Validation dates 02.09.2025
Sunset date 01-09-2030
Standard FIPS 140-3
Security level 2
Type Hardware
Embodiment Multi-Chip Stand Alone
Caveat When operated in approved mode; When tamper evident labels contained in F5-ADD-BIG-FIPS140 kit and installed as indicated in the Security Policy section 7; No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs
Exceptions
  • Operational environment: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A
Description F5 Device Cryptographic Module, Application Delivery Controller and Firewall software running on F5 BIG-IP.
Vendor F5, Inc. f5.com
Lab atsec information security corporation
Algorithms
  • AES-CBCA3698
  • AES-CCMA3698
  • AES-CTRA3697
  • AES-GCMA3698
  • Counter DRBGA3698
  • ECDSA KeyGen (FIPS186-4)A3698
  • ECDSA KeyVer (FIPS186-4)A3698
  • ECDSA SigGen (FIPS186-4)A3698
  • ECDSA SigVer (FIPS186-4)A3698
  • HMAC-SHA-1A3698
  • HMAC-SHA2-256A3698
  • HMAC-SHA2-384A3698
  • KAS-ECC-SSC Sp800-56Ar3A3698
  • KAS-FFC-SSC Sp800-56Ar3A3698
  • KDF SSHA3697
  • RSA KeyGen (FIPS186-4)A3697
  • RSA SigGen (FIPS186-4)A3698
  • RSA SigVer (FIPS186-4)A3698
  • Safe Primes Key GenerationA3698
  • Safe Primes Key VerificationA3698
  • SHA-1A3698
  • SHA2-256A3698
  • SHA2-384A3698
  • SHA2-512A3698
  • TLS v1.2 KDF RFC7627A3698
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy

Extracted keywords

Symmetric Algorithms
AES-256, AES-128, AES-192, AES, CAST, DES, Triple-DES, TDES, TDEA, Camellia, SEED, HMAC, HMAC-SHA-384, CMAC
Asymmetric Algorithms
ECDH, ECDSA, EdDSA, ECC, Diffie-Hellman, DH, DSA
Hash functions
SHA-1, SHA-256, SHA-3
Schemes
MAC, Key Exchange, Key agreement, Key Agreement
Protocols
SSH, SSHv2, SSL, TLS v1.2, TLS, TLS 1.2, IKEv2, IPsec
Randomness
DRBG, RNG, RBG
Elliptic Curves
P-256, P-384, Ed25519
Block cipher modes
ECB, CBC, CTR, CFB, OFB, GCM, CCM, XTS

Trusted Execution Environments
PSP, SSC

Security level
Level 2

Automated analysis

Automated inference - use with caution

All attributes shown in this section (e.g., links between certificates, products, vendors, and known CVEs) are generated by automated heuristics and have not been reviewed by humans. These methods can produce false positives or false negatives and should not be treated as definitive without independent verification. This applies equally to the Cross-references section below. If you want to know more about how this data is computed and how reliable it is, see our documentation on automated analysis. If you believe any information here is inaccurate or harmful, please submit feedback.

No automatically derived data are available in this section.

Cross-references

No references are available for this certificate.

Processing updates

Feed
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate data changed.
  • The certificate was first processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 5056,
  "dgst": "fcf40aad4b47bd25",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "SHA2-256A3698",
        "AES-CTRA3697",
        "AES-CBCA3698",
        "HMAC-SHA2-384A3698",
        "ECDSA KeyVer (FIPS186-4)A3698",
        "HMAC-SHA-1A3698",
        "#A3698",
        "#A3697",
        "RSA SigVer (FIPS186-4)A3698",
        "RSA KeyGen (FIPS186-4)A3697",
        "AES-GCMA3698",
        "KDF SSHA3697",
        "SHA2-384A3698",
        "RSA SigGen (FIPS186-4)A3698",
        "ECDSA SigGen (FIPS186-4)A3698",
        "HMAC-SHA2-256A3698",
        "Counter DRBGA3698",
        "ECDSA SigVer (FIPS186-4)A3698",
        "KAS-ECC-SSC Sp800-56Ar3A3698",
        "Safe Primes Key GenerationA3698",
        "KAS-FFC-SSC Sp800-56Ar3A3698",
        "AES-CCMA3698",
        "SHA2-512A3698",
        "Safe Primes Key VerificationA3698",
        "SHA-1A3698",
        "TLS v1.2 KDF RFC7627A3698",
        "ECDSA KeyGen (FIPS186-4)A3698"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "-"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "br1_deviations": 0,
    "br1_tables": {
      "_type": "sec_certs.heuristics.br1.table_parsing.model.br1_tables.BR1Tables",
      "approved_algorithms": {
        "entries": [
          {
            "algorithm": "AES-CBC",
            "cavpCertName": "A3697",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CBC",
            "cavpCertName": "A3698",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-CCM",
            "cavpCertName": "A3697",
            "properties": "Key Length - 128, 192, 256",
            "reference": "SP 800-38C"
          },
          {
            "algorithm": "AES-CCM",
            "cavpCertName": "A3698",
            "properties": "Key Length - 128, 256",
            "reference": "SP 800-38C"
          },
          {
            "algorithm": "AES-CTR",
            "cavpCertName": "A3697",
            "properties": "Direction - Decrypt, Encrypt Key Length - 128, 192, 256",
            "reference": "SP 800-38A"
          },
          {
            "algorithm": "AES-GCM",
            "cavpCertName": "A3697",
            "properties": "Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 192, 256",
            "reference": "SP 800-38D"
          },
          {
            "algorithm": "AES-GCM",
            "cavpCertName": "A3698",
            "properties": "Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 256",
            "reference": "SP 800-38D"
          },
          {
            "algorithm": "Counter DRBG",
            "cavpCertName": "A3697",
            "properties": "Prediction Resistance - No, Yes Mode - AES-256 Derivation Function Enabled - No, Yes",
            "reference": "SP 800-90A Rev. 1"
          },
          {
            "algorithm": "Counter DRBG",
            "cavpCertName": "A3698",
            "properties": "Prediction Resistance - No Mode - AES-256 Derivation Function Enabled - Yes",
            "reference": "SP 800-90A Rev. 1"
          },
          {
            "algorithm": "ECDSA KeyGen (FIPS186-4)",
            "cavpCertName": "A3697",
            "properties": "Curve - P-256, P-384 Secret Generation Mode - Testing Candidates",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA KeyGen (FIPS186-4)",
            "cavpCertName": "A3698",
            "properties": "Curve - P-256, P-384 Secret Generation Mode - Testing Candidates",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA KeyVer (FIPS186-4)",
            "cavpCertName": "A3697",
            "properties": "Curve - P-256, P-384",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA KeyVer (FIPS186-4)",
            "cavpCertName": "A3698",
            "properties": "Curve - P-256, P-384",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA SigGen (FIPS186-4)",
            "cavpCertName": "A3697",
            "properties": "Component - No Curve - P-256, P-384 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA SigGen (FIPS186-4)",
            "cavpCertName": "A3698",
            "properties": "Component - No Curve - P-256, P-384 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA SigVer (FIPS186-4)",
            "cavpCertName": "A3697",
            "properties": "Component - No Curve - P-256, P-384 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "ECDSA SigVer (FIPS186-4)",
            "cavpCertName": "A3698",
            "properties": "Component - No Curve - P-256, P-384",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "",
            "cavpCertName": "",
            "properties": "Hash Algorithm - SHA2-256, SHA2-384, SHA2-512",
            "reference": ""
          },
          {
            "algorithm": "HMAC-SHA-1",
            "cavpCertName": "A3697",
            "properties": "Key Length - Key Length: 8, 16, 64, 128, 1024",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA-1",
            "cavpCertName": "A3698",
            "properties": "Key Length - Key Length: 8, 16, 64, 128, 1024",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-256",
            "cavpCertName": "A3697",
            "properties": "Key Length - Key Length: 8, 16, 64, 128, 1024",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-256",
            "cavpCertName": "A3698",
            "properties": "Key Length - Key Length: 8, 16, 64, 128, 1024",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-384",
            "cavpCertName": "A3697",
            "properties": "Key Length - Key Length: 8, 16, 64, 128, 1024",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "HMAC-SHA2-384",
            "cavpCertName": "A3698",
            "properties": "Key Length - Key Length: 8, 16, 64, 128, 1024",
            "reference": "FIPS 198-1"
          },
          {
            "algorithm": "KAS-ECC-SSC Sp800-56Ar3",
            "cavpCertName": "A3697",
            "properties": "Domain Parameter Generation Methods - P-256, P-384 Scheme - ephemeralUnified - KAS Role - initiator, responder",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "KAS-ECC-SSC Sp800-56Ar3",
            "cavpCertName": "A3698",
            "properties": "Domain Parameter Generation Methods - P-256, P-384 Scheme - ephemeralUnified - KAS Role - initiator, responder",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "KAS-FFC-SSC Sp800-56Ar3",
            "cavpCertName": "A3697",
            "properties": "Domain Parameter Generation Methods - ffdhe2048, ffdhe3072, ffdhe4096 Scheme - dhEphem - KAS Role - initiator, responder",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "KAS-FFC-SSC Sp800-56Ar3",
            "cavpCertName": "A3698",
            "properties": "Domain Parameter Generation Methods - ffdhe2048, ffdhe3072, ffdhe4096 Scheme - dhEphem - KAS Role - initiator, responder",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "KDF SSH (CVL)",
            "cavpCertName": "A3697",
            "properties": "Cipher - AES-128, AES-256 Hash Algorithm - SHA2-256, SHA2-384",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "RSA KeyGen (FIPS186-4)",
            "cavpCertName": "A3697",
            "properties": "Key Generation Mode - B.3.3 Modulo - 2048, 4096 Primality Tests - Table C.2 Private Key Format - Standard",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "RSA SigGen (FIPS186-4)",
            "cavpCertName": "A3697",
            "properties": "Signature Type - PKCS 1.5 Modulo - 2048, 3072, 4096",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "RSA SigGen (FIPS186-4)",
            "cavpCertName": "A3698",
            "properties": "Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "RSA SigVer (FIPS186-4)",
            "cavpCertName": "A3697",
            "properties": "Signature Type - PKCS 1.5 Modulo - 2048, 3072, 4096",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "RSA SigVer (FIPS186-4)",
            "cavpCertName": "A3698",
            "properties": "Signature Type - PKCS 1.5, PKCSPSS Modulo - 2048, 3072, 4096",
            "reference": "FIPS 186-4"
          },
          {
            "algorithm": "Safe Primes Key Generation",
            "cavpCertName": "A3697",
            "properties": "Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "Safe Primes Key Generation",
            "cavpCertName": "A3698",
            "properties": "Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "Safe Primes Key Verification",
            "cavpCertName": "A3697",
            "properties": "Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "Safe Primes Key Verification",
            "cavpCertName": "A3698",
            "properties": "Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096",
            "reference": "SP 800-56A Rev. 3"
          },
          {
            "algorithm": "SHA-1",
            "cavpCertName": "A3697",
            "properties": "Message Length - Message Length: 0- 65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA-1",
            "cavpCertName": "A3698",
            "properties": "Message Length - Message Length: 0- 65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-256",
            "cavpCertName": "A3697",
            "properties": "Message Length - Message Length: 0- 65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-256",
            "cavpCertName": "A3698",
            "properties": "Message Length - Message Length: 0- 65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-384",
            "cavpCertName": "A3697",
            "properties": "Message Length - Message Length: 0- 65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "SHA2-384",
            "cavpCertName": "A3698",
            "properties": "Message Length - Message Length: 0- 65536 Increment 8",
            "reference": "FIPS 180-4"
          },
          {
            "algorithm": "TLS v1.2 KDF RFC7627 (CVL)",
            "cavpCertName": "A3697",
            "properties": "Hash Algorithm - SHA2-256, SHA2-384",
            "reference": "SP 800-135 Rev. 1"
          },
          {
            "algorithm": "TLS v1.2 KDF RFC7627 (CVL)",
            "cavpCertName": "A3698",
            "properties": "Hash Algorithm - SHA2-256, SHA2-384",
            "reference": "SP 800-135 Rev. 1"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "approved_services": {
        "entries": [
          {
            "description": "Display list of all User accounts",
            "indicator": "None",
            "inputs": "None",
            "name": "List users",
            "outputs": "List of user accounts",
            "rolesSspAccess": "Administr ator User Manager Resource Manager Auditor",
            "secFunImpl": "None"
          },
          {
            "description": "Create additional User",
            "indicator": "None",
            "inputs": "Username / password",
            "name": "Create additiona l User",
            "outputs": "Confirmati on of account creation",
            "rolesSspAccess": "Administr ator - Password : W User Manager - Password : W",
            "secFunImpl": "None"
          },
          {
            "description": "Modify existing Users",
            "indicator": "None",
            "inputs": "Username",
            "name": "Modify existing Users",
            "outputs": "Confirmati on of account modificati on",
            "rolesSspAccess": "Administr ator User Manager",
            "secFunImpl": "None"
          },
          {
            "description": "Delete User",
            "indicator": "None",
            "inputs": "Username",
            "name": "Delete User",
            "outputs": "Confirmati on of deletion",
            "rolesSspAccess": "Administr ator User Manager",
            "secFunImpl": "None"
          },
          {
            "description": "Remove lock from user who has exceeded login attempts",
            "indicator": "None",
            "inputs": "Username",
            "name": "Unlock User",
            "outputs": "Confirmati on of unlock",
            "rolesSspAccess": "Administr ator User Manager",
            "secFunImpl": "None"
          },
          {
            "description": "Update own password",
            "indicator": "None",
            "inputs": "Own password",
            "name": "Update own password",
            "outputs": "Confirmati on of update of password",
            "rolesSspAccess": "Administr ator - Password : W Auditor - Password : W Certificat e Manager - Password : W Manager - Password : W iRule Manager - Password : W Operator - Password : W Resource Manager - Password : W User Manager - Password : W",
            "secFunImpl": "None"
          },
          {
            "description": "Update others password",
            "indicator": "None",
            "inputs": "Username / password",
            "name": "Update others password",
            "outputs": "Confirmati on of update",
            "rolesSspAccess": "Administr ator - Password : W User Manager - Password : W",
            "secFunImpl": "None"
          },
          {
            "description": "Set password policy features",
            "indicator": "None",
            "inputs": "New password policy",
            "name": "Configur e Password Policy",
            "outputs": "Confirmati on of configurati on change",
            "rolesSspAccess": "Administr ator",
            "secFunImpl": "None"
          },
          {
            "description": "Self-signed certificate creation",
            "indicator": "Service Indicat or: Approv ed",
            "inputs": "Certificate identificatio n information",
            "name": "Create TLS Certificat e",
            "outputs": "Confirmati on of certificate creation",
            "rolesSspAccess": "Administr ator - TLS RSA private key: E - TLS ECDSA private key: E Certificat e Manager - TLS RSA private key: E - TLS ECDSA private key: E Resource Manager - TLS RSA private key: E - TLS ECDSA private",
            "secFunImpl": "Signature generation"
          },
          {
            "description": "Used for the SSL Certificate key file",
            "indicator": "Service Indicat or: Approv ed",
            "inputs": "Key identificatio n information",
            "name": "Create TLS Key",
            "outputs": "Confirmati on of key creation",
            "rolesSspAccess": "key: E Administr ator - TLS RSA private key: G - TLS RSA public key: G - TLS ECDSA private key: G - TLS ECDSA public key: G - DRBG seed : E",
            "secFunImpl": "Key pair generation Random Number Generation in Control Plane Random Number Generation in Data Plane"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "- DRBG internal state (V and key values) : E,W - Entropy input: E Resource Manager - TLS RSA private key: G - TLS RSA public key: G - TLS ECDSA private key: G - TLS ECDSA public key: G - DRBG seed : E - DRBG internal state (V and key values) : E,W - Entropy input: E Certificat e Manager - TLS RSA private key: G - TLS RSA public key: G - TLS ECDSA private key: G - TLS ECDSA public key: G",
            "secFunImpl": ""
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "- DRBG seed : E - DRBG internal state (V and key values) : E,W - Entropy input: E",
            "secFunImpl": ""
          },
          {
            "description": "Self-signed certificate / key deletion",
            "indicator": "None",
            "inputs": "Key identificatio n information",
            "name": "Delete TLS Certificat e /Key",
            "outputs": "Confirmati on of key / certificate deletion",
            "rolesSspAccess": "Administr ator - TLS RSA private key: Z - TLS RSA public key: Z - TLS ECDSA private key: Z - TLS ECDSA public key: Z Resource Manager - TLS RSA private key: Z - TLS RSA public key: Z - TLS ECDSA private key: Z - TLS ECDSA public key: Z Certificat e Manager - TLS RSA private key: Z - TLS RSA",
            "secFunImpl": "None"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "key: Z - TLS ECDSA private key: Z - TLS ECDSA public key: Z",
            "secFunImpl": ""
          },
          {
            "description": "Display / log expiration data of installed certificates",
            "indicator": "None",
            "inputs": "List of certificates to display",
            "name": "List Certificat e",
            "outputs": "Certificate expiration informatio n",
            "rolesSspAccess": "Administr ator Auditor Certificat e Manager Resource Manager",
            "secFunImpl": "None"
          },
          {
            "description": "List private key information (Name, size)",
            "indicator": "None",
            "inputs": "List of private keys to display",
            "name": "List Private Keys",
            "outputs": "TLS private key informatio n",
            "rolesSspAccess": "Administr ator Auditor Certificat e Manager Resource Manager",
            "secFunImpl": "None"
          },
          {
            "description": "SSH session Key authenticat ion, Key Exchange",
            "indicator": "SSH connect ion success ful",
            "inputs": "User / address / password / algorithms / key sizes / key derivation",
            "name": "Establish SSH session",
            "outputs": "Confirmati on of SSH session authentica tion, Confirmati on of SSH session key exchange",
            "rolesSspAccess": "Administr ator - SSH ECDSA public key: E - Password : W,E - SSH EC Diffie- Hellman public key: G,R,W,E - SSH EC Diffie- Hellman private key: G,R,W,E - SSH shared secret: G - SSH",
            "secFunImpl": "Signature generation Signature verification SSH Handshake"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "derived session key : E Auditor - SSH ECDSA public key: E - Password : W,E - SSH EC Diffie- Hellman public key: G,R,W,E - SSH EC Diffie- Hellman private key: G,R,W,E - SSH shared secret: G - SSH derived session key : E Certificat e Manager - SSH ECDSA public key: E - Password : W,E - SSH EC Diffie- Hellman public key: G,R,W,E - SSH EC Diffie- Hellman private key:",
            "secFunImpl": ""
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "G,R,W,E - SSH shared secret: G - SSH derived session key : E Manager - SSH ECDSA public key: E - Password : W,E - SSH EC Diffie- Hellman public key: G,R,W,E - SSH EC Diffie- Hellman private key: G,R,W,E - SSH shared secret: G - SSH derived session key : E iRule Manager - SSH ECDSA public key: E - Password : W,E - SSH EC Diffie- Hellman public key: G,R,W,E - SSH EC",
            "secFunImpl": ""
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "Diffie- Hellman private key: G,R,W,E - SSH shared secret: G - SSH derived session key : E Operator - SSH ECDSA public key: E - Password : W,E - SSH EC Diffie- Hellman public key: G,R,W,E - SSH EC Diffie- Hellman private key: G,R,W,E - SSH shared secret: G - SSH derived session key : E Resource Manager - SSH ECDSA public key: E - Password : W,E - SSH EC Diffie- Hellman",
            "secFunImpl": ""
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "public key: G,R,W,E - SSH EC Diffie- Hellman private key: G,R,W,E - SSH shared secret: G - SSH derived session key : E User Manager - SSH ECDSA public key: E - Password : W,E - SSH EC Diffie- Hellman public key: G,R,W,E - SSH EC Diffie- Hellman private key: G,R,W,E - SSH shared secret: G - SSH derived session key : E",
            "secFunImpl": ""
          },
          {
            "description": "SSH data encryption, decryption, integrity",
            "indicator": "SSH connect ion success ful",
            "inputs": "SSH Derived Session key",
            "name": "Maintain SSH Session",
            "outputs": "SSH session informatio n",
            "rolesSspAccess": "Administr ator - SSH derived session key : E",
            "secFunImpl": "Key Wrapping/Unwr apping with encryption and authentication in SSH"
          },
          {
            "description": "Descriptio n",
            "indicator": "Indicat or",
            "inputs": "Inputs",
            "name": "Name",
            "outputs": "Outputs",
            "rolesSspAccess": "SSP",
            "secFunImpl": "Security Functions"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "Access Auditor - SSH derived session key : E Certificat e Manager - SSH derived session key : E Manager - SSH derived session key : E iRule Manager - SSH derived session key : E Operator - SSH derived session key : E Resource Manager - SSH derived session key : E User Manager - SSH derived session",
            "secFunImpl": ""
          },
          {
            "description": "TLS session signature generation and verification , key exchange",
            "indicator": "Service Indicat or: Approv ed",
            "inputs": "Address / algorithms/ keys",
            "name": "Establish TLS Session",
            "outputs": "Confirmati on of digital signature verificatio n of TLS session, Confirmati on of establishm",
            "rolesSspAccess": "key : E Administr ator - TLS RSA public key: R - TLS ECDSA public key: R - TLS EC",
            "secFunImpl": "Signature verification Message digest TLS Handshake (ECC) TLS Handshake (FFC)"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "ent of TLS session",
            "rolesSspAccess": "Diffie- Hellman private key: E - TLS EC Diffie- Hellman public key: W - TLS Diffie- Hellman private key: E - TLS Diffie- Hellman public key: W - TLS pre- primary secret : E,G - TLS derived session key : G - TLS primary secret: G Auditor - TLS RSA public key: R - TLS ECDSA public key: R - TLS EC Diffie- Hellman private key: E - TLS EC Diffie- Hellman public key: W - TLS Diffie- Hellman",
            "secFunImpl": ""
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "private key: E - TLS Diffie- Hellman public key: W - TLS pre- primary secret : E,G - TLS derived session key : G - TLS primary secret: G Certificat e Manager - TLS RSA public key: R - TLS ECDSA public key: R - TLS EC Diffie- Hellman private key: E - TLS EC Diffie- Hellman public key: W - TLS Diffie- Hellman private key: E - TLS Diffie- Hellman public key: W - TLS pre- primary",
            "secFunImpl": ""
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "E,G - TLS derived session key : G - TLS primary secret: G Manager - TLS RSA public key: R - TLS ECDSA public key: R - TLS EC Diffie- Hellman private key: E - TLS EC Diffie- Hellman public key: W - TLS Diffie- Hellman private key: E - TLS Diffie- Hellman public key: W - TLS pre- primary secret : E,G - TLS derived session key : G - TLS primary secret: G iRule Manager - TLS RSA public",
            "secFunImpl": ""
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "key: R - TLS ECDSA public key: R - TLS EC Diffie- Hellman private key: E - TLS EC Diffie- Hellman public key: W - TLS Diffie- Hellman private key: E - TLS Diffie- Hellman public key: W - TLS pre- primary secret : E,G - TLS derived session key : G - TLS primary secret: G Operator - TLS RSA public key: R - TLS ECDSA public key: R - TLS EC Diffie- Hellman private key: E - TLS EC Diffie-",
            "secFunImpl": ""
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "Hellman public key: W - TLS Diffie- Hellman private key: E - TLS Diffie- Hellman public key: W - TLS pre- primary secret : E,G - TLS derived session key : G - TLS primary secret: G Resource Manager - TLS RSA public key: R - TLS ECDSA public key: R - TLS EC Diffie- Hellman private key: E - TLS EC Diffie- Hellman public key: W - TLS Diffie- Hellman private key: E - TLS Diffie- Hellman",
            "secFunImpl": ""
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "public key: W - TLS pre- primary secret : E,G - TLS derived session key : G - TLS primary secret: G User Manager - TLS RSA public key: R - TLS ECDSA public key: R - TLS EC Diffie- Hellman private key: E - TLS EC Diffie- Hellman public key: W - TLS Diffie- Hellman private key: E - TLS Diffie- Hellman public key: W - TLS pre- primary secret : E,G - TLS derived session key : G - TLS",
            "secFunImpl": ""
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "primary secret: G",
            "secFunImpl": ""
          },
          {
            "description": "TLS data encryption, authenticat ion",
            "indicator": "Service Indicat or: Approv ed",
            "inputs": "TLS Derived Session key",
            "name": "Maintain TLS Session",
            "outputs": "TLS session informatio n",
            "rolesSspAccess": "Administr ator - TLS derived session key : E Auditor - TLS derived session key : E Certificat e Manager - TLS derived session key : E Manager - TLS derived session key : E iRule Manager - TLS derived session key : E Operator - TLS derived session key : E Resource Manager - TLS derived session key : E User Manager - TLS derived session key : E",
            "secFunImpl": "Key Wrapping/Unwr apping with authenticated encryption Key Wrapping/Unwr apping with encryption and authentication in TLS"
          },
          {
            "description": "Utility service delete ssh keys",
            "indicator": "None",
            "inputs": "SSH key to delete",
            "name": "Delete ssh- keyswap",
            "outputs": "Confirmati on of SSH key deletion",
            "rolesSspAccess": "Administr ator - SSH ECDSA private key: Z - SSH ECDSA public key: Z Resource Manager - SSH ECDSA private key: Z - SSH ECDSA public key: Z",
            "secFunImpl": "None"
          },
          {
            "description": "Restart the cryptograp hic module",
            "indicator": "Module reboots",
            "inputs": "None",
            "name": "Reboot System",
            "outputs": "Confirmati on of system reboot",
            "rolesSspAccess": "Administr ator - TLS primary secret: Z - TLS derived session",
            "secFunImpl": "None"
          },
          {
            "description": "Full system zeroization",
            "indicator": "Module end of life",
            "inputs": "Selection option",
            "name": "Secure Erase",
            "outputs": "Confirmati on of full system zeroization",
            "rolesSspAccess": "key : Z Administr ator - TLS RSA private key: Z - TLS RSA public key: Z - TLS ECDSA private key: Z - TLS ECDSA public key: Z - SSH ECDSA public key: Z - SSH",
            "secFunImpl": "None"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "ECDSA private key: Z - Password : Z",
            "secFunImpl": ""
          },
          {
            "description": "Return the HW and FW versions and the module\u0027s name",
            "indicator": "N/A",
            "inputs": "N/A",
            "name": "Show version",
            "outputs": "Module name and version",
            "rolesSspAccess": "Administr ator Auditor Certificat e Manager Manager iRule Manager Operator Resource Manager User Manager",
            "secFunImpl": "None"
          },
          {
            "description": "Return the module status",
            "indicator": "N/A",
            "inputs": "N/A",
            "name": "Show Status",
            "outputs": "Module status",
            "rolesSspAccess": "Administr ator Auditor Certificat e Manager Manager iRule Manager Operator Resource Manager User",
            "secFunImpl": "None"
          },
          {
            "description": "Closing TLS / SSH session",
            "indicator": "N/A",
            "inputs": "N/A",
            "name": "Close TLS / SSH session",
            "outputs": "Confirmati on of TLS/SSH session closure",
            "rolesSspAccess": "Manager Administr ator - TLS EC Diffie- Hellman private key: Z - TLS EC Diffie- Hellman public key: Z - TLS pre- primary secret : Z - TLS",
            "secFunImpl": "None"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "primary secret: Z - TLS derived session key : Z - SSH shared secret: Z - SSH derived session key : Z - SSH EC Diffie- Hellman private key: Z - SSH EC Diffie- Hellman public key: Z - TLS Diffie- Hellman public key: Z - TLS Diffie- Hellman private key: Z Auditor - TLS EC Diffie- Hellman private key: Z - TLS EC Diffie- Hellman public key: Z - TLS pre- primary secret : Z - TLS primary secret: Z - TLS",
            "secFunImpl": ""
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "derived session key : Z - SSH shared secret: Z - SSH derived session key : Z - SSH EC Diffie- Hellman private key: Z - SSH EC Diffie- Hellman public key: Z - TLS Diffie- Hellman public key: Z - TLS Diffie- Hellman private key: Z Certificat e Manager - TLS EC Diffie- Hellman private key: Z - TLS EC Diffie- Hellman public key: Z - TLS pre- primary secret : Z - TLS primary secret: Z - TLS derived",
            "secFunImpl": ""
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "session key : Z - SSH shared secret: Z - SSH derived session key : Z - SSH EC Diffie- Hellman private key: Z - SSH EC Diffie- Hellman public key: Z - TLS Diffie- Hellman public key: Z - TLS Diffie- Hellman private key: Z Manager - TLS EC Diffie- Hellman public key: Z - TLS EC Diffie- Hellman private key: Z - TLS pre- primary secret : Z - TLS primary secret: Z - TLS derived session key : Z - SSH",
            "secFunImpl": ""
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "shared secret: Z - SSH derived session key : Z - SSH EC Diffie- Hellman private key: Z - SSH EC Diffie- Hellman public key: Z - TLS Diffie- Hellman public key: Z - TLS Diffie- Hellman private key: Z iRule Manager - TLS EC Diffie- Hellman public key: Z - TLS EC Diffie- Hellman private key: Z - TLS pre- primary secret : Z - TLS primary secret: Z - TLS derived session key : Z - SSH shared secret: Z",
            "secFunImpl": ""
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "- SSH derived session key : Z - SSH EC Diffie- Hellman private key: Z - SSH EC Diffie- Hellman public key: Z - TLS Diffie- Hellman public key: Z - TLS Diffie- Hellman private key: Z Operator - TLS EC Diffie- Hellman private key: Z - TLS EC Diffie- Hellman public key: Z - TLS pre- primary secret : Z - TLS primary secret: Z - TLS derived session key : Z - SSH shared secret: Z - SSH derived session",
            "secFunImpl": ""
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "key : Z - SSH EC Diffie- Hellman private key: Z - SSH EC Diffie- Hellman public key: Z - TLS Diffie- Hellman public key: Z - TLS Diffie- Hellman private key: Z Resource Manager - TLS EC Diffie- Hellman public key: Z - TLS EC Diffie- Hellman private key: Z - TLS pre- primary secret : Z - TLS primary secret: Z - TLS derived session key : Z - SSH shared secret: Z - SSH derived session key : Z - SSH EC",
            "secFunImpl": ""
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "Diffie- Hellman private key: Z - SSH EC Diffie- Hellman public key: Z - TLS Diffie- Hellman public key: Z - TLS Diffie- Hellman private key: Z User Manager - TLS EC Diffie- Hellman private key: Z - TLS EC Diffie- Hellman public key: Z - TLS pre- primary secret : Z - TLS primary secret: Z - TLS derived session key : Z - SSH derived session key : Z - SSH EC Diffie- Hellman private key: Z - SSH EC",
            "secFunImpl": ""
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "Diffie- Hellman public key: Z - TLS Diffie- Hellman public key: Z - TLS Diffie- Hellman private key: Z",
            "secFunImpl": ""
          },
          {
            "description": "Execute integrity test. Execute the CASTs",
            "indicator": "Integrit y test, CASTs from section 10",
            "inputs": "N/A",
            "name": "Self-tests",
            "outputs": "Pass or fail",
            "rolesSspAccess": "Administr ator Auditor Certificat e Manager Manager iRule Manager Operator Resource Manager User Manager",
            "secFunImpl": "Key pair generation Key pair verification Signature generation Signature verification Random Number Generation in Control Plane Random Number Generation in Data Plane"
          },
          {
            "description": "Return license indication",
            "indicator": "N/A",
            "inputs": "N/A",
            "name": "Show license",
            "outputs": "FIPS license informatio n",
            "rolesSspAccess": "Administr ator Auditor Certificat e Manager Manager iRule Manager Operator Resource Manager User Manager",
            "secFunImpl": "None"
          },
          {
            "description": "Import TLS Certificate",
            "indicator": "None",
            "inputs": "Certificate to import",
            "name": "Import TLS Certificat e",
            "outputs": "Confirmati on of import of certificate",
            "rolesSspAccess": "Administr ator - TLS RSA public key: W - TLS",
            "secFunImpl": "None"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "ECDSA public key: W Certificat e Manager - TLS RSA public key: W - TLS ECDSA public key: W",
            "secFunImpl": ""
          },
          {
            "description": "Export Certificate File",
            "indicator": "None",
            "inputs": "Certificate to export",
            "name": "Export Certificat e File",
            "outputs": "Exported Certificate file",
            "rolesSspAccess": "Administr ator - TLS ECDSA public key: R - TLS RSA public key: R Certificat e Manager - TLS RSA public key: R - TLS ECDSA public key: R",
            "secFunImpl": "None"
          },
          {
            "description": "Utility service create ssh keys",
            "indicator": "Service Indicat or: Approv ed",
            "inputs": "SSH key to create",
            "name": "Create ssh- keyswap",
            "outputs": "Confirmati on of SSH key creation",
            "rolesSspAccess": "Administr ator - SSH ECDSA private key: G - SSH ECDSA public key: G Resource Manager - SSH ECDSA private key: G - SSH ECDSA",
            "secFunImpl": "Key pair generation"
          },
          {
            "description": "",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "public key: G",
            "secFunImpl": ""
          },
          {
            "description": "Set policy rules, and address lists for use by firewall rules",
            "indicator": "None",
            "inputs": "Policy rules, address lists",
            "name": "Configur e Firewall",
            "outputs": "Confirmati on of policy configurati on",
            "rolesSspAccess": "Administr ator",
            "secFunImpl": "None"
          },
          {
            "description": "Display the current system- wide state of firewall rules",
            "indicator": "None",
            "inputs": "N/A",
            "name": "Show firewall state",
            "outputs": "Display the current system wide state of the firewall rules.",
            "rolesSspAccess": "Administr ator Manager",
            "secFunImpl": "None"
          },
          {
            "description": "Shows statistics of firewall rules on the BIG-IP system",
            "indicator": "None",
            "inputs": "N/A",
            "name": "Shows statistics",
            "outputs": "List of statistics of firewall rules",
            "rolesSspAccess": "Administr ator Manager",
            "secFunImpl": "None"
          },
          {
            "description": "Display logs/files of configurati on changes",
            "indicator": "None",
            "inputs": "N/A",
            "name": "View System Audit Log",
            "outputs": "Display of system audit logs",
            "rolesSspAccess": "Administr ator Auditor Resource Manager",
            "secFunImpl": "None"
          },
          {
            "description": "Export Analytics Logs System",
            "indicator": "None",
            "inputs": "N/A",
            "name": "Export Analytics Logs System",
            "outputs": "Display System Analytics Logs",
            "rolesSspAccess": "Administr ator Auditor",
            "secFunImpl": "None"
          },
          {
            "description": "Enable/ Disable Audit",
            "indicator": "None",
            "inputs": "N/A",
            "name": "Enable/ Disable Audit",
            "outputs": "Confirmati on of enabling or disabling of audit",
            "rolesSspAccess": "Administr ator Resource Manager",
            "secFunImpl": "None"
          },
          {
            "description": "Enable Quiet boot, Manage boot locations",
            "indicator": "None",
            "inputs": "Boot options",
            "name": "Configur e Boot Options",
            "outputs": "Confirmati on of configurati on of boot options",
            "rolesSspAccess": "Administr ator Resource Manager",
            "secFunImpl": "None"
          },
          {
            "description": "Enable / Disable SSH access, Configure",
            "indicator": "None",
            "inputs": "SSH access / IP address list",
            "name": "Configur e SSH access options",
            "outputs": "Confirmati on of configurati on of SSH access options",
            "rolesSspAccess": "Administr ator Resource Manager",
            "secFunImpl": "None"
          },
          {
            "description": "IP address allow list",
            "indicator": "",
            "inputs": "",
            "name": "",
            "outputs": "",
            "rolesSspAccess": "",
            "secFunImpl": ""
          },
          {
            "description": "Update ssh/ authorized_ keys file for user authenticat ion",
            "indicator": "None",
            "inputs": "ssh/ authorized_ keys file",
            "name": "Configur e SSH user configura tion",
            "outputs": "Confirmati on of configurati on of SSH user configurati on",
            "rolesSspAccess": "Administr ator - SSH ECDSA public key: W",
            "secFunImpl": "None"
          },
          {
            "description": "Configure Firewall Users",
            "indicator": "None",
            "inputs": "Firewall user and configurati on information",
            "name": "Configur e Firewall Users",
            "outputs": "Confirmati on of configurati on",
            "rolesSspAccess": "Administr ator",
            "secFunImpl": "None"
          },
          {
            "description": "Enable / Disable nodes and pool members",
            "indicator": "None",
            "inputs": "Which nodes and pool members to modify",
            "name": "Modify nodes and pool members",
            "outputs": "Confirmati on of modificati on of nodes and pool members",
            "rolesSspAccess": "Administr ator",
            "secFunImpl": "None"
          },
          {
            "description": "Create, modify, view, delete nodes",
            "indicator": "None",
            "inputs": "List of nodes to create / modify / view / delete",
            "name": "Configur e nodes",
            "outputs": "Confirmati on of creation / modificati on / display / deletion of nodes",
            "rolesSspAccess": "Administr ator Manager Resource Manager",
            "secFunImpl": "None"
          },
          {
            "description": "Create, modify, view, delete, iRules",
            "indicator": "None",
            "inputs": "List of iRules to create / modify/ view/ delete",
            "name": "Configur e iRules",
            "outputs": "Confirmati on of creation / modificati on / display / deletion of iRules",
            "rolesSspAccess": "Administr ator Manager Resource Manager",
            "secFunImpl": "None"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 3
      },
      "authentication_methods": {
        "entries": [
          {
            "description": "The password must consist of a minimum of 8 characters with at least one from each of the three-character classes. Character classes are defined as: digits (0-9), ASCII lowercase letters (a-z), ASCII uppercase letters (A-Z). - Assuming a worst-case scenario where the password contains six digits, one ASCII lowercase letter and one ASCII uppercase letter. The probability of guessing every character successfully is (1/10)^6 * (1/26)^1 * (1/26)^1 = 1/676,000,000. Note: this is less than 1/1,000,000. - - The maximum number of login attempts is limited to 3 after which the account is locked. This means that, in the worst case, an attacker has the probability of guessing the password in one minute as 3/676,000,000. Note: This is less than 1/100,000.",
            "mechanism": "Password",
            "name": "Role-based authentication with Password (CLI or Web interface)",
            "perMinute": "3/676,000,000",
            "strength": "1/676,000,000"
          },
          {
            "description": "The ECDSA using P-256 or P-384 curves for key based authentication yields a minimum security-strength of 128 bits . The chance of a random authentication attempt falsely succeeding is at most 1/(2^128) that is",
            "mechanism": "ECDSA SigVer (FIPS186-4) (A3697)",
            "name": "Role-based authentication with SSH ECDSA key-pair (CLI only)",
            "perMinute": "3/676,000,000",
            "strength": "1/(2^128)"
          },
          {
            "description": "less than 1/1,000,000. - - The maximum number of login attempts is limited to 3 after which the account switch to password authentication. Then the attacker probability of succeeding to establish the connection depends on the probability of guessing the password and it is, as above, 3/676,000,000 less than 1/100,000.",
            "mechanism": "",
            "name": "",
            "perMinute": "",
            "strength": ""
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 1
      },
      "cond_self_tests": {
        "entries": [
          {
            "algorithmOrTest": "Counter DRBG (A3697)",
            "condition": "Test runs at power on",
            "details": "SP 800- 90ARev1 section 11.3 health tests",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "AES-256 in CTR mode, with and without derivation function, prediction resistance disabled",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-CBC (A3698)",
            "condition": "Test runs at power on",
            "details": "Encryption / decryption",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "128-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A3698)",
            "condition": "Test runs at power on",
            "details": "Encryption / decryption",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "128-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigGen (FIPS186-4) (A3698)",
            "condition": "Test runs at power on",
            "details": "Signature generation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "2048 bit key and SHA2- 256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186-4) (A3698)",
            "condition": "Test runs at power on",
            "details": "Signature verification",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "2048 bit key and SHA2- 256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA KeyGen (FIPS186-4) (A3697)",
            "condition": "Key generation",
            "details": "Calculation and verification of a digital signature",
            "indicator": "Asymmetric algorithm is performed",
            "testMethod": "PCT",
            "testProps": "Requested modulus size, SHA2- 256",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "ECDSA SigGen (FIPS186-4) (A3698)",
            "condition": "Test runs at power on",
            "details": "Signature generation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "P-256 and SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA KeyGen (FIPS186-4) (A3698)",
            "condition": "Key generation",
            "details": "Calculation and verification of a digital signature",
            "indicator": "Asymmetric algorithm is performed",
            "testMethod": "PCT",
            "testProps": "Requested curve size, SHA2-256",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "KAS-ECC- SSC Sp800- 56Ar3 (A3698)",
            "condition": "Test runs at power on",
            "details": "Shared secret computation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "P-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA-1 (A3697)",
            "condition": "Test runs at power on",
            "details": "MAC",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "HMAC-SHA- 1",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA2- 256 (A3698)",
            "condition": "Test runs at power on",
            "details": "MAC",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "HMAC- SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "TLS v1.2 KDF RFC7627 (A3698)",
            "condition": "Test runs at power on",
            "details": "Key derivation used in the TLS protocol",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KDF SSH (A3697)",
            "condition": "Test runs at power on",
            "details": "Key derivation used in the SSH protocol",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA2- 384 (A3697)",
            "condition": "Test runs at power on",
            "details": "MAC",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "HMAC-SHA- 384",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-GCM (A3697)",
            "condition": "Test runs at power on",
            "details": "Encryption / decryption",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "128-bit key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigGen (FIPS186-4) (A3697)",
            "condition": "Test runs at power on",
            "details": "Signature generation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "2048 bit key and SHA2- 256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "RSA SigVer (FIPS186-4) (A3697)",
            "condition": "Test runs at power on",
            "details": "Signature verification",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "2048 bit key and SHA2- 256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS-ECC- SSC Sp800- 56Ar3 (A3697)",
            "condition": "Test runs at power on",
            "details": "Shared secret computation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "P-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigVer (FIPS186-4) (A3698)",
            "condition": "Test runs at power on",
            "details": "Signature verification",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "P-256 and SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "Safe Primes Key Generation (A3698)",
            "condition": "Key generation",
            "details": "Calculation and verification of shared secret",
            "indicator": "Asymmetric algorithm is performed",
            "testMethod": "PCT",
            "testProps": "Requested curve size",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "KAS-FFC-SSC Sp800-56Ar3 (A3698)",
            "condition": "Test runs at power on",
            "details": "Shared secret computation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "ffdhe2048",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA2- 384 (A3698)",
            "condition": "Test runs at power on",
            "details": "MAC",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "HMAC-SHA- 384",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "Safe Primes Key Generation (A3697)",
            "condition": "Key generation",
            "details": "Calculation and verification of shared secret",
            "indicator": "Asymmetric algorithm is performed",
            "testMethod": "PCT",
            "testProps": "Requested curve size",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "ECDSA KeyGen",
            "condition": "Key generation",
            "details": "Calculation and verification",
            "indicator": "Asymmetric algorithm is performed",
            "testMethod": "PCT",
            "testProps": "Requested curve size, SHA2-256",
            "type": "PCT"
          },
          {
            "algorithmOrTest": "(FIPS186-4) (A3697)",
            "condition": "",
            "details": "of a digital signature",
            "indicator": "",
            "testMethod": "",
            "testProps": "",
            "type": ""
          },
          {
            "algorithmOrTest": "ECDSA SigGen (FIPS186-4) (A3697)",
            "condition": "Test runs at power on",
            "details": "Signature generation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "P-256 and SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ECDSA SigVer (FIPS186-4) (A3697)",
            "condition": "Test runs at power on",
            "details": "Signature verification",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "P-256 and SHA2-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "KAS-FFC-SSC Sp800-56Ar3 (A3697)",
            "condition": "Test runs at power on",
            "details": "Shared secret computation",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "ffdhe2048",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA2- 256 (A3697)",
            "condition": "Test runs at power on",
            "details": "MAC",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "HMAC-SHA- 256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "TLS v1.2 KDF RFC7627 (A3697)",
            "condition": "Test runs at power on",
            "details": "Key derivation used in the TLS protocol",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "SHA-256",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "HMAC-SHA-1 (A3698)",
            "condition": "Test runs at power on",
            "details": "MAC",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "HMAC-SHA- 1",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "AES-CBC (A3697)",
            "condition": "Test runs at power on",
            "details": "Encryption/ decryption",
            "indicator": "Module becomes operational",
            "testMethod": "KAT",
            "testProps": "128-bits key",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ESV - Repetition Count Test (Startup)",
            "condition": "Performed upon startup",
            "details": "SP 800-90B Heath test",
            "indicator": "Module is operational",
            "testMethod": "RCT",
            "testProps": "Startup test with 1024 samples; Cutoff value = 90",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ESV - Repetition Count Test (Continuous)",
            "condition": "Continuous test performed for Entropy Source while the module is operating",
            "details": "SP 800-90B Heath test",
            "indicator": "Module is operational",
            "testMethod": "RCT",
            "testProps": "Cutoff value = 90",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ESV - Adaptive Proportional Test (Startup)",
            "condition": "Performed upon startup",
            "details": "SP 800-90B Heath test",
            "indicator": "Module is operational",
            "testMethod": "APT",
            "testProps": "Startup test with 1024 samples; Cutoff value = 459",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "ESV - Adaptive Proportional",
            "condition": "Performed upon startup",
            "details": "SP 800-90B Heath test",
            "indicator": "Module is operational",
            "testMethod": "APT",
            "testProps": "Cutoff value = 459",
            "type": "CAST"
          },
          {
            "algorithmOrTest": "Test (Continuous)",
            "condition": "",
            "details": "",
            "indicator": "",
            "testMethod": "",
            "testProps": "",
            "type": ""
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 2
      },
      "error_states": {
        "entries": [
          {
            "conditions": "Integrity test failure Failure of any of the CASTs Failure of any of the PCTs Failure of the APT, RCT at restart (power- on)",
            "description": "Module is no longer operational. The data output is inhibited.",
            "indicator": "For Integrity test failure, CASTs and health tests the module will not load. For PCTs failure the module transitions to error state.",
            "name": "Halt Error",
            "recoveryMethod": "The module must be re- loaded"
          },
          {
            "conditions": "Failure of the APT, RCT at runtime",
            "description": "Module is no longer operational.",
            "indicator": "The module reboot in a loop",
            "name": "Health Test Error",
            "recoveryMethod": "The module must be re- loaded"
          },
          {
            "conditions": "",
            "description": "The data output is inhibited.",
            "indicator": "",
            "name": "",
            "recoveryMethod": ""
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 4
      },
      "mechanisms_actions": {
        "entries": [
          {
            "inspectFreq": "N/A",
            "inspectGuidance": "N/A",
            "mechanism": "Production grade enclosure (SL1)"
          },
          {
            "inspectFreq": "N/A",
            "inspectGuidance": "N/A",
            "mechanism": "Opaque enclosure (SL2)"
          },
          {
            "inspectFreq": "Once per month",
            "inspectGuidance": "The Crypto Officer/ Administrator is responsible for inspecting the quality of the tamper labels on a regular basis to confirm that the module has not been tampered with. The Crypto Officer/ Administrator checks the quality of the tamper evident labels for any sign of removal, replacement, tearing, etc. If any label is found to be damaged or missing, a kit providing 25 tamper labels is available for purchase.",
            "mechanism": "Tamper Evident Labels (SL2)"
          }
        ],
        "found": true,
        "section": 7,
        "subsection": 1
      },
      "modes_of_operation": {
        "entries": [
          {
            "description": "Automatically entered whenever an approved service is requested",
            "name": "Approved mode",
            "statusIndicator": "Equivalent to the indicator of the requested service as defined in section 4.3",
            "type": "Approved"
          },
          {
            "description": "Only non-approved security functions can be used",
            "name": "Non- Approved mode",
            "statusIndicator": "Equivalent to the indicator of the requested service as defined in section 4.3",
            "type": "Non- Approved"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 4
      },
      "non_approved_allowed_NSC": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_allowed_algos": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 5
      },
      "non_approved_not_allowed": {
        "entries": [
          {
            "name": "HMAC-SHA2-224, HMAC-SHA2-512",
            "use": "Message authentication TLS"
          },
          {
            "name": "Triple-DES, Camellia, SEED",
            "use": "Symmetric encryption and decryption TLS"
          },
          {
            "name": "HMAC-SHA2-256, HMAC-SHA2-512, AES-GCM",
            "use": "Message authentication in IPsec/ IKEv2 protocol"
          },
          {
            "name": "PKCS #1 v1.5 scheme with modulus other than 2048, 3072 or 4096 bits, for all SHA sizes",
            "use": "RSA signature generation and verification"
          },
          {
            "name": "PKCS #1 v1.5 and PSS schema with modulus size 2048, 3072, 4096 bits with SHA-1, SHA2-224, SHA2-512; ANS X9.31",
            "use": "RSA signature generation"
          },
          {
            "name": "PKCS #1 v1.5 and PSS schema with modulus size 2048, 3072, 4096 bits with SHA2-224, SHA2-512",
            "use": "RSA signature verification"
          },
          {
            "name": "ECDSA with curves P-256, P-384 with SHA-1, SHA2- 224, SHA2-512; ECDSA using curves other than P- 256 and P-384, all SHA sizes",
            "use": "ECDSA signature generation"
          },
          {
            "name": "ECDSA with curves P-256, P-384 with SHA2-224, SHA2-512; ECDSA using curves other than P-256 and P-384, all SHA sizes",
            "use": "ECDSA signature verification"
          },
          {
            "name": "RSA with modulus sizes up to 16384 bits",
            "use": "RSA encrypt / decrypt"
          },
          {
            "name": "DSA with all key and SHA sizes",
            "use": "DSA domain parameter generation, domain parameter verification, key pair generation, signature generation and verification"
          },
          {
            "name": "Diffie-Hellman using MODP1024, MODP2048 groups",
            "use": "Shared secret computation in IPsec/IKE protocol"
          },
          {
            "name": "MD5/ SHA-1/ SHA2-224 / SHA2-512",
            "use": "Key Derivation function in the context of TLS KDF"
          },
          {
            "name": "EdDSA with Ed25519",
            "use": "EdDSA digital signature"
          },
          {
            "name": "SHA-1, AES-ECB, RSA- signature verification",
            "use": "SNMP"
          },
          {
            "name": "TLS ciphersuites implemented by f5-rest-node",
            "use": "TLS used in SSL Orchestrator (SSLO)"
          },
          {
            "name": "RSA keypair with 2048, 3072 and 4096 (REST API)",
            "use": "iControl representation state transfer (REST) access"
          },
          {
            "name": "EC Diffie-Hellman Ephemeral Unified with curves other than P-256, P-384. EC Diffie-Hellman using onePassDH / StaticUnified schemes. Diffie-Hellman using groups other than ffdhe2048, ffdhe3072, ffdhe4096",
            "use": "Shared secret computation"
          },
          {
            "name": "Triple-DES, AES-GCM-128, AES-192, AES-256",
            "use": "Symmetric encryption and decryption in IPsec /IKEv2"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "non_approved_services": {
        "entries": [
          {
            "alg_accessed": "HMAC-SHA2-224, HMAC-SHA2-512 Triple-DES, Camellia, SEED DSA with all key and SHA sizes",
            "description": "Data encryption, Data authentication",
            "name": "Maintain TLS session",
            "role": "CO / User"
          },
          {
            "alg_accessed": "TLS ciphersuites implemented by f5- rest-node",
            "description": "Management of the module protected by iApplx authentication",
            "name": "SSLO Configuration and usage",
            "role": "CO / User"
          },
          {
            "alg_accessed": "RSA keypair with 2048, 3072 and 4096 (REST API)",
            "description": "Access to the system through REST API",
            "name": "iControl REST access",
            "role": "CO / User"
          },
          {
            "alg_accessed": "HMAC-SHA2-256, HMAC-SHA2-512, AES-GCM Diffie-Hellman using MODP1024, MODP2048 groups Triple-DES, AES-GCM-128, AES-192, AES-256",
            "description": "Protocol configuration",
            "name": "IPsec /IKEv2",
            "role": "CO / User"
          },
          {
            "alg_accessed": "SHA-1, AES-ECB, RSA- signature verification",
            "description": "Protocol configuration",
            "name": "Simple network management protocol (SNMP)",
            "role": "CO / User"
          },
          {
            "alg_accessed": "PKCS #1 v1.5 scheme with modulus other than 2048, 3072 or 4096 bits, for all SHA sizes PKCS #1 v1.5 and PSS schema with modulus size 2048, 3072, 4096 bits with SHA-1, SHA2-224, SHA2-512; ANS X9.31 PKCS #1 v1.5 and PSS schema with modulus size 2048, 3072, 4096 bits with SHA2-224, SHA2-512 ECDSA with curves P-256, P-384 with SHA-1, SHA2-224, SHA2-512; ECDSA using curves other than P-256 and P- 384, all SHA sizes ECDSA with curves P-256, P-384 with SHA2-224, SHA2-512; ECDSA using curves other than P-256 and P-384, all SHA sizes RSA with modulus sizes up to 16384 bits MD5/ SHA-1/ SHA2-224 / SHA2-512 EdDSA with Ed25519 EC Diffie-Hellman Ephemeral Unified with curves other than P-256, P-384. EC Diffie-Hellman using onePassDH / StaticUnified schemes. Diffie-Hellman using groups other than ffdhe2048, ffdhe3072, ffdhe4096",
            "description": "Signature generation and verification, Key Exchange",
            "name": "Establish TLS session",
            "role": "CO / User"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 4
      },
      "ports_interfaces": {
        "entries": [
          {
            "data": "TLS/SSH protocol input messages; Configuration commands for interface management",
            "logicalInterface": "Data Input",
            "physicalPort": "Network Interface (SFP, SFP+, and QSFP+ ports (Ethernet and/or Fiber Optic) which allow transfer speeds from 1Gbps up to 100Gbps"
          },
          {
            "data": "TLS/SSH protocol output messages; Status logs",
            "logicalInterface": "Data Output",
            "physicalPort": "Network Interface (SFP, SFP+, and QSFP+ ports)"
          },
          {
            "data": "API which control system state (e.g. reset system, power-off system)",
            "logicalInterface": "Control Input",
            "physicalPort": "Network Interface (SFP, SFP+, and QSFP+ ports)"
          },
          {
            "data": "API which provides system status information",
            "logicalInterface": "Status Output",
            "physicalPort": "Network Interface (SFP, SFP+, and QSFP+ ports); Display Interface (LEDs, and/or output to STDOUT"
          },
          {
            "data": "Power Supply (PSU)",
            "logicalInterface": "Power",
            "physicalPort": "Power Interface"
          }
        ],
        "found": true,
        "section": 3,
        "subsection": 1
      },
      "roles": {
        "entries": [
          {
            "authMethodList": "Role-based authentication with Password (CLI or Web interface) Role-based authentication with SSH ECDSA key-pair (CLI only)",
            "name": "Administrator",
            "operatorType": "CO",
            "type": "Role"
          },
          {
            "authMethodList": "Role-based authentication with Password (CLI or Web interface) Role-based authentication with SSH ECDSA key-pair (CLI only)",
            "name": "Auditor",
            "operatorType": "User",
            "type": "Role"
          },
          {
            "authMethodList": "Role-based authentication with Password (CLI or Web interface) Role-based authentication with SSH ECDSA key-pair (CLI only)",
            "name": "Certificate Manager",
            "operatorType": "User",
            "type": "Role"
          },
          {
            "authMethodList": "Role-based authentication with Password (CLI or Web interface) Role-based authentication with SSH ECDSA key-pair (CLI only)",
            "name": "Manager",
            "operatorType": "User",
            "type": "Role"
          },
          {
            "authMethodList": "Role-based authentication with Password (CLI or Web interface) Role-based authentication with SSH ECDSA key-pair (CLI only)",
            "name": "iRule Manager",
            "operatorType": "User",
            "type": "Role"
          },
          {
            "authMethodList": "Role-based authentication with Password (CLI or Web interface) Role-based authentication with SSH ECDSA key-pair (CLI only)",
            "name": "Operator",
            "operatorType": "User",
            "type": "Role"
          },
          {
            "authMethodList": "Role-based authentication with Password (CLI or Web interface) Role-based authentication with SSH ECDSA key-pair (CLI only)",
            "name": "Resource Manager",
            "operatorType": "User",
            "type": "Role"
          },
          {
            "authMethodList": "Role-based authentication with Password (CLI or Web interface) Role-based authentication with SSH ECDSA key-pair (CLI only)",
            "name": "User Manager",
            "operatorType": "User",
            "type": "Role"
          }
        ],
        "found": true,
        "section": 4,
        "subsection": 2
      },
      "security_levels": {
        "entries": [
          {
            "level": "2",
            "section": "1",
            "title": "General"
          },
          {
            "level": "2",
            "section": "2",
            "title": "Cryptographic module specification"
          },
          {
            "level": "2",
            "section": "3",
            "title": "Cryptographic module interfaces"
          },
          {
            "level": "2",
            "section": "4",
            "title": "Roles, services, and authentication"
          },
          {
            "level": "2",
            "section": "5",
            "title": "Software/Firmware security"
          },
          {
            "level": "N/A",
            "section": "6",
            "title": "Operational environment"
          },
          {
            "level": "2",
            "section": "7",
            "title": "Physical security"
          },
          {
            "level": "N/A",
            "section": "8",
            "title": "Non-invasive security"
          },
          {
            "level": "2",
            "section": "9",
            "title": "Sensitive security parameter management"
          },
          {
            "level": "2",
            "section": "10",
            "title": "Self-tests"
          },
          {
            "level": "2",
            "section": "11",
            "title": "Life-cycle assurance"
          },
          {
            "level": "N/A",
            "section": "12",
            "title": "Mitigation of other attacks"
          },
          {
            "level": "2",
            "section": "",
            "title": "Overall Level"
          }
        ],
        "found": true,
        "section": 1,
        "subsection": 2
      },
      "self_tests": {
        "entries": [
          {
            "algorithmOrTest": "HMAC- SHA2-384 (A3698)",
            "details": "Integrity of the module is verified by comparing the HMAC-SHA2-384 value calculated at runtime with the HMAC-SHA2-384 value stored in the module that was computed at build time",
            "indicator": "Module becomes operational",
            "testMethod": "Message Authentication",
            "testProps": "HMAC key: 384-bits",
            "type": "SW/FW Integrity"
          },
          {
            "algorithmOrTest": "HMAC- SHA2-384 (A3697)",
            "details": "Integrity of the module is verified by comparing the HMAC-SHA2-384 value calculated at runtime with the HMAC-SHA2-384 value stored in the module that was computed at build time",
            "indicator": "Module becomes operational",
            "testMethod": "Message Authentication",
            "testProps": "HMAC key: 384-bits",
            "type": "SW/FW Integrity"
          }
        ],
        "found": true,
        "section": 10,
        "subsection": 1
      },
      "ssp_io_methods": {
        "entries": [
          {
            "dest": "Module",
            "distribution": "Automated",
            "entry": "Electronic",
            "format": "Encrypted",
            "name": "SSPs input during TLS/SSH sessions",
            "sfiAlgo": "",
            "source": "User"
          },
          {
            "dest": "User",
            "distribution": "Automated",
            "entry": "Electronic",
            "format": "Plaintext",
            "name": "Public key output during protocol handshake",
            "sfiAlgo": "",
            "source": "Module"
          },
          {
            "dest": "Module",
            "distribution": "Automated",
            "entry": "Electronic",
            "format": "Plaintext",
            "name": "Public key input during protocol handshake",
            "sfiAlgo": "",
            "source": "User"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 2
      },
      "ssp_zeroization_methods": {
        "entries": [
          {
            "description": "Single pass zeroization erasing the HDD or SSD contents and the module itself",
            "method": "Secure Erase",
            "operatorId": "The Crypto Officer/ Administrator is calling the Secure Erase service which can only be triggered during reboot of the test platform",
            "rationale": "All SSPs present in the module are erased including the one in the non- volatile memory"
          },
          {
            "description": "Clear the SSPs present in RAM memory",
            "method": "Reboot System",
            "operatorId": "The Crypto Officer/Administrator is calling Reboot System service",
            "rationale": "Volatile memory used by the module is overwritten within nanoseconds when the system is reboot."
          },
          {
            "description": "Destruction of the selected SSH ECDSA authentication key",
            "method": "Delete SSH keyswap",
            "operatorId": "The Administrator or Resource Manager are calling the Delete SSH keyswap service",
            "rationale": "Zeroization service overwrites the memory occupied by keys with \"zeros\" or pre-defined values."
          },
          {
            "description": "Zeroization of all session specific keys",
            "method": "Closing TLS/SSH Connection",
            "operatorId": "Closing TLS/SSH Connection",
            "rationale": "SSP values generated during key generation services are zeroized by the module"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 3
      },
      "storage_areas": {
        "entries": [
          {
            "description": "The keys are stored in plaintext form are only accessible to the authenticated operator, to which the SSPs are associated",
            "name": "RAM",
            "persistance": "Dynamic"
          },
          {
            "description": "The keys stored in plaintext and the password will remain on the system across power cycle and are only accessible to the authenticated operator to which the SSPs are associated",
            "name": "SSD/ HDD",
            "persistance": "Static"
          }
        ],
        "found": true,
        "section": 9,
        "subsection": 1
      },
      "tested_module_id_hw": {
        "entries": [
          {
            "features": "1 x USB port; 8 x 1GbE; 4 x 10GbE network ports; 1 x Console port; 1 x 1GbE management port",
            "fwVersion": "17.1.01",
            "hwVersion": "i4600",
            "modelPartNum": "i4600 BIG- IP iseries",
            "processors": "Intel\u00ae Xeon\u00ae D-1518, Broadwell"
          },
          {
            "features": "1 x USB port; 8 x 1GbE; 4 x 10GbE network ports; 1 x Console port; 1 x 1GbE management port",
            "fwVersion": "17.1.01",
            "hwVersion": "i4800",
            "modelPartNum": "i4800 BIG- IP iseries",
            "processors": "Intel\u00ae Xeon\u00ae D-1518, Broadwell"
          },
          {
            "features": "1 x USB port; 8 x 10GbE; 4 x 40GbE network ports; 1 x Console port; 1 x 1GbE management port",
            "fwVersion": "17.1.01",
            "hwVersion": "i5600",
            "modelPartNum": "i5600 BIG- IP iseries",
            "processors": "Intel\u00ae Xeon\u00ae E5-1630v4, Broadwell"
          },
          {
            "features": "1 x USB port; 8 x 10GbE; 4 x 40GbE network ports; 1 x Console port; 1 x 1GbE management port",
            "fwVersion": "17.1.01",
            "hwVersion": "i5800",
            "modelPartNum": "i5800 BIG- IP iseries",
            "processors": "Intel\u00ae Xeon\u00ae E5-1630v4, Broadwell"
          },
          {
            "features": "1 x USB port; 8 x 10GbE; 4 x 40GbE network ports; 1 x Console port; 1 x 1GbE management port",
            "fwVersion": "17.1.01",
            "hwVersion": "i5820-DF",
            "modelPartNum": "i5820-DF BIG-IP iseries",
            "processors": "Intel\u00ae Xeon\u00ae E5-1630v4, Broadwell"
          },
          {
            "features": "1 x USB port; 8 x 10GbE and 4 x 40GbE network ports; 1 x Console port; 1 x 10/100/1000- BaseT management port",
            "fwVersion": "17.1.01",
            "hwVersion": "i7600",
            "modelPartNum": "i7600 BIG- IP iseries",
            "processors": "Intel\u00ae Xeon\u00ae E5-1650v4, Broadwel"
          },
          {
            "features": "1 x USB port; 8 x 10GbE and 4 x 40GbE network ports; 1 x Console port; 1 x 10/100/1000- BaseT management port",
            "fwVersion": "17.1.01",
            "hwVersion": "i7800",
            "modelPartNum": "i7800 BIG- IP iseries",
            "processors": "Intel\u00ae Xeon\u00ae E5-1650v4, Broadwel"
          },
          {
            "features": "1 x USB port; 8 x 10GbE and 4 x 40GbE network ports; 1 x Console port; 1 x 10/100/1000- BaseT management port",
            "fwVersion": "17.1.01",
            "hwVersion": "i7820-DF",
            "modelPartNum": "i7820-DF BIG-IP iseries",
            "processors": "Intel\u00ae Xeon\u00ae E5-1650v4, Broadwel"
          },
          {
            "features": "1 x USB port; 8 x 10GbE; 6 x 40GbE network ports; 1 x Console port; 1 x 1GbE management port",
            "fwVersion": "17.1.01",
            "hwVersion": "i10600",
            "modelPartNum": "i10600 BIG-IP iseries",
            "processors": "Intel\u00ae Xeon\u00ae E5-1660v4, Broadwell"
          },
          {
            "features": "1 x USB port; 8 x 10GbE; 6 x 40GbE network ports; 1 x Console port; 1 x 1GbE management port",
            "fwVersion": "17.1.01",
            "hwVersion": "i10800",
            "modelPartNum": "i10800 BIG-IP iseries",
            "processors": "Intel\u00ae Xeon\u00ae E5-1660v4, Broadwell"
          },
          {
            "features": "1 x USB port; 8 x 10GbE; 6 x 40GbE network ports; 1 x Console port; 1 x 1GbE (10/100/1000 capable) management port",
            "fwVersion": "17.1.01",
            "hwVersion": "i11600-DS",
            "modelPartNum": "i11600-DS BIG-IP iseries",
            "processors": "Intel\u00ae Xeon\u00ae E5-2695v4, Broadwell"
          },
          {
            "features": "1 x USB port; 8 x 10GbE; 6 x 40GbE network ports; 1 x Console port; 1 x 1GbE (10/100/1000 capable) management port",
            "fwVersion": "17.1.01",
            "hwVersion": "i11800-DS",
            "modelPartNum": "i11800-DS BIG-IP iseries",
            "processors": "Intel\u00ae Xeon\u00ae E5-2695v4, Broadwell"
          },
          {
            "features": "1 x USB port; 8 x 40GbE; 4 x 100GbE network ports; 1 x Console port; 1 x 1GbE management port",
            "fwVersion": "17.1.01",
            "hwVersion": "BIG-IP iseries i15600",
            "modelPartNum": "i15600 BIG-IP iseries",
            "processors": "Intel\u00ae Xeon\u00ae E5-2680v4, Broadwell"
          },
          {
            "features": "1 x USB port; 8 x 40GbE; 4 x 100GbE network ports; 1 x",
            "fwVersion": "17.1.01",
            "hwVersion": "i15800",
            "modelPartNum": "i15800 BIG-IP iseries",
            "processors": "Intel\u00ae Xeon\u00ae E5-2680v4, Broadwell"
          },
          {
            "features": "Console port; 1 x 1GbE management port",
            "fwVersion": "",
            "hwVersion": "",
            "modelPartNum": "",
            "processors": ""
          },
          {
            "features": "1 x USB port; 8 x 40GbE; 4 x 100GbE network ports; 1 x Console port; 1 x 1GbE management port",
            "fwVersion": "17.1.01",
            "hwVersion": "i15820-DF",
            "modelPartNum": "i15820-DF BIG-IP iseries",
            "processors": "Intel\u00ae Xeon\u00ae E5-2680v4, Broadwell"
          },
          {
            "features": "2 x USB port; 4 x 40 GbE network ports; 1 x Console port; 1 x GbE management port",
            "fwVersion": "17.1.01",
            "hwVersion": "VIPRION C2400",
            "modelPartNum": "B2250",
            "processors": "Intel\u00ae Xeon\u00ae E5-2658v2, Ivy Bridge"
          },
          {
            "features": "1 x USB port; 6 x 40 GbE; 2 x 100 GbE network ports; 1 x Console port; 1 x GbE (10/100/1000 Ethernet) management port",
            "fwVersion": "17.1.01",
            "hwVersion": "VIPRION C4480",
            "modelPartNum": "B4450",
            "processors": "Intel\u00ae Xeon\u00ae E5-2658v3, Haswell"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 2
      },
      "tested_module_id_hw_hy": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "tested_module_id_sw_fw_hy": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "tested_op_env_sw_fw_hy": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      },
      "vendor_affirmed_algos": {
        "entries": [
          {
            "algoPropList": "Key Type:Asymmetric",
            "implName": "N/A",
            "name": "Cryptographic Key Generation (CKG)",
            "reference": "Random bit strings required for generating the cryptographic keys is compliant with [SP 800- 133Rev2] section 4 example 1"
          }
        ],
        "found": true,
        "section": 2,
        "subsection": 5
      },
      "vendor_affirmed_op_env_sw_fw_hy": {
        "entries": [],
        "found": false,
        "section": 2,
        "subsection": 2
      }
    },
    "is_br1_format": true,
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 10
          },
          "ECDH": {
            "ECDH": 3
          },
          "ECDSA": {
            "ECDSA": 112
          },
          "EdDSA": {
            "EdDSA": 3
          }
        },
        "FF": {
          "DH": {
            "DH": 3,
            "Diffie-Hellman": 17
          },
          "DSA": {
            "DSA": 4
          }
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 1
        },
        "CCM": {
          "CCM": 2
        },
        "CFB": {
          "CFB": 1
        },
        "CTR": {
          "CTR": 2
        },
        "ECB": {
          "ECB": 1
        },
        "GCM": {
          "GCM": 3
        },
        "OFB": {
          "OFB": 1
        },
        "XTS": {
          "XTS": 2
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "IKE": {
          "IKEv2": 1
        },
        "IPsec": {
          "IPsec": 2
        },
        "SSH": {
          "SSH": 168,
          "SSHv2": 2
        },
        "TLS": {
          "SSL": {
            "SSL": 2
          },
          "TLS": {
            "TLS": 277,
            "TLS 1.2": 4,
            "TLS v1.2": 8
          }
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 2,
          "Key agreement": 3
        },
        "KEX": {
          "Key Exchange": 2
        },
        "MAC": {
          "MAC": 7
        }
      },
      "device_model": {},
      "ecc_curve": {
        "Edwards": {
          "Ed25519": 2
        },
        "NIST": {
          "P-256": 70,
          "P-384": 42
        }
      },
      "eval_facility": {
        "atsec": {
          "atsec": 2
        }
      },
      "fips_cert_id": {
        "Cert": {
          "#1": 6
        }
      },
      "fips_certlike": {
        "Certlike": {
          "- PKCS 1": 4,
          "AES-128": 1,
          "AES-192": 2,
          "AES-256": 7,
          "DRBG 384": 1,
          "HMAC-SHA- 1": 4,
          "HMAC-SHA- 256": 2,
          "HMAC-SHA- 384": 4,
          "HMAC-SHA-1": 12,
          "HMAC-SHA-384": 2,
          "PKCS #1": 12,
          "PKCS 1": 4,
          "PKCS#1": 2,
          "SHA-1": 9,
          "SHA-256": 3,
          "SHA-3": 2,
          "SHA2- 224": 1,
          "SHA2- 256": 5,
          "SHA2-224": 9,
          "SHA2-256": 17,
          "SHA2-382": 1,
          "SHA2-384": 11,
          "SHA2-512": 14
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 2": 3
        }
      },
      "hash_function": {
        "SHA": {
          "SHA1": {
            "SHA-1": 9
          },
          "SHA2": {
            "SHA-256": 3
          },
          "SHA3": {
            "SHA-3": 2
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {},
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 28
        },
        "RNG": {
          "RBG": 2,
          "RNG": 2
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140-3": 96,
          "FIPS 1403": 1,
          "FIPS 180-4": 6,
          "FIPS 186-4": 16,
          "FIPS 186-5": 4,
          "FIPS 197": 4,
          "FIPS 198-1": 6,
          "FIPS PUB 140-3": 2,
          "FIPS140-3": 1,
          "FIPS180-4": 1,
          "FIPS186-4": 44,
          "FIPS186-5": 2,
          "FIPS197": 1,
          "FIPS198-1": 1,
          "FIPS202": 1
        },
        "NIST": {
          "SP 800-132": 1,
          "SP 800-135": 7,
          "SP 800-140F": 1,
          "SP 800-38A": 4,
          "SP 800-38B": 1,
          "SP 800-38C": 3,
          "SP 800-38D": 3,
          "SP 800-38E": 1,
          "SP 800-38F": 4,
          "SP 800-38G": 1,
          "SP 800-56A": 8,
          "SP 800-57": 1,
          "SP 800-67": 1,
          "SP 800-90A": 2,
          "SP 800-90B": 6
        },
        "PKCS": {
          "PKCS #1": 6,
          "PKCS 1": 4,
          "PKCS#1": 1
        },
        "RFC": {
          "RFC 4253": 1,
          "RFC 5288": 1,
          "RFC 6668": 1,
          "RFC3394": 1,
          "RFC5288": 1,
          "RFC5649": 1,
          "RFC7627": 6
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 12,
            "AES-128": 1,
            "AES-192": 2,
            "AES-256": 7
          },
          "CAST": {
            "CAST": 60
          }
        },
        "DES": {
          "3DES": {
            "TDEA": 1,
            "TDES": 1,
            "Triple-DES": 4
          },
          "DES": {
            "DES": 1
          }
        },
        "constructions": {
          "MAC": {
            "CMAC": 2,
            "HMAC": 10,
            "HMAC-SHA-384": 1
          }
        },
        "miscellaneous": {
          "Camellia": {
            "Camellia": 2
          },
          "SEED": {
            "SEED": 2
          }
        }
      },
      "tee_name": {
        "AMD": {
          "PSP": 6
        },
        "IBM": {
          "SSC": 2
        }
      },
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "module_algorithms": {
      "_type": "Set",
      "elements": [
        "SHA2-256A3698",
        "AES-CTRA3697",
        "AES-CBCA3698",
        "HMAC-SHA2-384A3698",
        "ECDSA KeyVer (FIPS186-4)A3698",
        "HMAC-SHA-1A3698",
        "RSA SigVer (FIPS186-4)A3698",
        "RSA KeyGen (FIPS186-4)A3697",
        "AES-GCMA3698",
        "KDF SSHA3697",
        "SHA2-384A3698",
        "RSA SigGen (FIPS186-4)A3698",
        "ECDSA SigGen (FIPS186-4)A3698",
        "HMAC-SHA2-256A3698",
        "Counter DRBGA3698",
        "ECDSA SigVer (FIPS186-4)A3698",
        "KAS-ECC-SSC Sp800-56Ar3A3698",
        "Safe Primes Key GenerationA3698",
        "KAS-FFC-SSC Sp800-56Ar3A3698",
        "AES-CCMA3698",
        "SHA2-512A3698",
        "Safe Primes Key VerificationA3698",
        "SHA-1A3698",
        "TLS v1.2 KDF RFC7627A3698",
        "ECDSA KeyGen (FIPS186-4)A3698"
      ]
    },
    "policy_algorithms": {
      "_type": "Set",
      "elements": [
        "#A3697",
        "#A3698"
      ]
    },
    "policy_metadata": {
      "/Author": "",
      "/Comments": "",
      "/Company": "",
      "/CreationDate": "D:20250829072526-04\u002700\u0027",
      "/Creator": "Acrobat PDFMaker 25 for Word",
      "/Keywords": "",
      "/ModDate": "D:20250829072705-04\u002700\u0027",
      "/Producer": "Adobe PDF Library 25.1.51",
      "/SourceModified": "",
      "/Subject": "",
      "/Title": "",
      "pdf_file_size_bytes": 1142421,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": [
          "http://csrc.nist.gov/publications/nistpubs/800-38E/nist-sp-800-38E.pdf",
          "http://csrc.nist.gov/publications/fips/fips198-1/FIPS-198-1_final.pdf",
          "http://csrc.nist.gov/publications/nistpubs/800-67-Rev1/SP-800-67-Rev1.pdf",
          "http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.186-4.pdf",
          "http://csrc.nist.gov/publications/fips/fips197/fips-197.pdf",
          "http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-38c.pdf",
          "http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38G.pdf",
          "https://csrc.nist.gov/Projects/cryptographic-module-validation-program/fips-140-3-ig-announcements",
          "http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-57pt1r4.pdf",
          "http://www.ietf.org/rfc/rfc5649.txt",
          "http://csrc.nist.gov/publications/nistpubs/800-38B/SP_800-38B.pdf",
          "http://csrc.nist.gov/publications/nistpubs/800-38D/SP-800-38D.pdf",
          "http://www.ietf.org/rfc/rfc3394.txt",
          "http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-38F.pdf",
          "http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.202.pdf",
          "http://csrc.nist.gov/publications/nistpubs/800-38a/sp800-38a.pdf",
          "http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.180-4.pdf",
          "https://support.f5.com/csp/article/K7752",
          "http://www.ietf.org/rfc/rfc3447.txt",
          "http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-135r1.pdf"
        ]
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 90
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.InternalState",
    "module": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": null,
      "source_hash": null,
      "txt_hash": null
    },
    "policy": {
      "_type": "sec_certs.sample.document_state.DocumentState",
      "convert_ok": true,
      "download_ok": true,
      "extract_ok": true,
      "json_hash": "1d448bd2468a945294810b2133e94630c68e280d19206e471b51a49ee85f9922",
      "source_hash": "8c1b3875d8208c15c053a8661ee5f3ebcd26e9599f9e2a436ee8b7aaa8ae3369",
      "txt_hash": "8f0e331c56a304035f3898192f08d342f9b9db03efbf5551488f27dd293f0abe"
    }
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "When operated in approved mode; When tamper evident labels contained in F5-ADD-BIG-FIPS140 kit and installed as indicated in the Security Policy section 7; No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs",
    "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/November 2025_181225_1202.pdf",
    "date_sunset": "2030-09-01",
    "description": "F5 Device Cryptographic Module, Application Delivery Controller and Firewall software running on F5 BIG-IP.",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Operational environment: N/A",
      "Non-invasive security: N/A",
      "Mitigation of other attacks: N/A"
    ],
    "fw_versions": null,
    "historical_reason": null,
    "hw_versions": null,
    "level": 2,
    "mentioned_certs": {},
    "module_name": "Device Cryptographic Module",
    "module_type": "Hardware",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-3",
    "status": "active",
    "sw_versions": null,
    "tested_conf": null,
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2025-09-02",
        "lab": "atsec information security corporation",
        "validation_type": "Initial"
      }
    ],
    "vendor": "F5, Inc.",
    "vendor_url": "f5.com"
  }
}