F5OS-A Cryptographic Module

Certificate #4883

Webpage information ?

Status active
Validation dates 18.11.2024
Sunset date 17-11-2026
Standard FIPS 140-3
Security level 2
Type Firmware
Embodiment Multi-Chip Stand Alone
Caveat Interim Validation. When operated in approved mode. When installed, initialized and configured as specified in Section 11 of the Security Policy. The tamper evident seals with F5-ADD-BIG-FIPS140 kit installed as indicated in the Security Policy.
Exceptions
  • Operational environment: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A
  • Documentation requirements: N/A
  • Cryptographic module security policy: N/A
Description F5OS-A Cryptographic Module Platform layer services for F5 appliance platforms
Version (Firmware) 1.5.1
Tested configurations
  • F5OS-A 1.5.1 on r10900 with Intel® Xeon® Gold 6312U Ice Lake-SP with PAA
  • F5OS-A 1.5.1 on r10900 with Intel® Xeon® Gold 6312U Ice Lake-SP without PAA
  • F5OS-A 1.5.1 on r10920-DF with Intel® Xeon® Gold 6312U Ice Lake-SP with PAA
  • F5OS-A 1.5.1 on r10920-DF with Intel® Xeon® Gold 6312U Ice Lake-SP without PAA
  • F5OS-A 1.5.1 on r4800 with Intel® Atom® P5342 Snow Ridge NS with PAA
  • F5OS-A 1.5.1 on r4800 with Intel® Atom® P5342 Snow Ridge NS without PAA
  • F5OS-A 1.5.1 on r5900 with Intel® Xeon® Silver 4314 Ice Lake-SP with PAA
  • F5OS-A 1.5.1 on r5900 with Intel® Xeon® Silver 4314 Ice Lake-SP without PAA
  • F5OS-A 1.5.1 on r5920-DF with Intel® Xeon® Silver 4314 Ice Lake-SP with PAA
  • F5OS-A 1.5.1 on r5920-DF with Intel® Xeon® Silver 4314 Ice Lake-SP without PAA
Vendor F5, Inc.
References

This certificate's webpage directly references 0 certificates, transitively this expands into 0 certificates.

Security policy ?

Symmetric Algorithms
AES, AES-128, AES-256, CAST, RC4, DES, Triple-DES, SM4, HMAC, HMAC-SHA-384, CMAC
Asymmetric Algorithms
ECDH, ECDSA, EdDSA, ECC, Diffie-Hellman, DSA
Hash functions
SHA-1, SHA3, SHA3-256, MD5
Schemes
MAC, Key exchange, Key Exchange, Key Agreement
Protocols
SSH, SSL, TLS, TLS v1.2, TLS1.2, IKEv1, IKEv2, IKE
Randomness
DRBG, RNG
Elliptic Curves
P-256, P-384, Ed25519
Block cipher modes
ECB, CBC, CTR, CFB, OFB, GCM, CCM, XTS

JavaCard API constants
SM2
Trusted Execution Environments
SSC

Security level
Level 2, Level 1

Standards
FIPS 140-3, FIPS PUB 140-3, FIPS 197, FIPS 186-4, FIPS180-4, FIPS 198-1, FIPS140-3, FIPS140, FIPS186-4, FIPS 140, FIPS197, FIPS198-1, NIST SP 800-140B, SP 800-135, SP 800-38F, PKCS#1, PKCS #1, RFC 7627, RFC 5288, RFC 2313, ISO/IEC 24759

File metadata

Title 140-3-SecurityPolicy_F5OS-A
Author Marylene Palard
Creation date D:20241105042613Z00'00'
Modification date D:20241105042613Z00'00'
Pages 43
Creator Word
Producer macOS Version 14.6 (Build 23G80) Quartz PDFContext

Heuristics ?

No heuristics are available for this certificate.

References ?

No references are available for this certificate.

Updates ?

  • 18.11.2024 The certificate was first processed.
    New certificate

    A new FIPS 140 certificate with the product name was processed.

Raw data

{
  "_type": "sec_certs.sample.fips.FIPSCertificate",
  "cert_id": 4883,
  "dgst": "c7d0562cd4f65e47",
  "heuristics": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics",
    "algorithms": {
      "_type": "Set",
      "elements": [
        "Counter DRBGA5260",
        "SHA-1A5260",
        "KAS-ECC-SSC Sp800-56Ar3A5260",
        "ECDSA KeyGen (FIPS186-4)A5260",
        "AES-CBCA5260",
        "AES-CTRA5260",
        "TLS v1.2 KDF RFC7627A5260",
        "HMAC-SHA2-256A5260",
        "HMAC-SHA2-384A5260",
        "AES-GCMA5260",
        "ECDSA KeyVer (FIPS186-4)A5260",
        "RSA KeyGen (FIPS186-4)A5260",
        "ECDSA SigGen (FIPS186-4)A5260",
        "AES-ECBA5260",
        "AES-GMACA5260",
        "ECDSA SigVer (FIPS186-4)A5260",
        "HMAC-SHA-1A5260",
        "SHA2-256A5260",
        "KDF SSHA5260",
        "RSA SigGen (FIPS186-4)A5260",
        "SHA2-384A5260",
        "RSA SigVer (FIPS186-4)A5260"
      ]
    },
    "cpe_matches": null,
    "direct_transitive_cves": null,
    "extracted_versions": {
      "_type": "Set",
      "elements": [
        "1.5.1"
      ]
    },
    "indirect_transitive_cves": null,
    "module_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "module_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "policy_processed_references": {
      "_type": "sec_certs.sample.certificate.References",
      "directly_referenced_by": null,
      "directly_referencing": null,
      "indirectly_referenced_by": null,
      "indirectly_referencing": null
    },
    "policy_prunned_references": {
      "_type": "Set",
      "elements": []
    },
    "related_cves": null,
    "verified_cpe_matches": null
  },
  "pdf_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.PdfData",
    "keywords": {
      "asymmetric_crypto": {
        "ECC": {
          "ECC": {
            "ECC": 2
          },
          "ECDH": {
            "ECDH": 1
          },
          "ECDSA": {
            "ECDSA": 50
          },
          "EdDSA": {
            "EdDSA": 2
          }
        },
        "FF": {
          "DH": {
            "Diffie-Hellman": 32
          },
          "DSA": {
            "DSA": 4
          }
        }
      },
      "certification_process": {},
      "cipher_mode": {
        "CBC": {
          "CBC": 2
        },
        "CCM": {
          "CCM": 3
        },
        "CFB": {
          "CFB": 2
        },
        "CTR": {
          "CTR": 3
        },
        "ECB": {
          "ECB": 3
        },
        "GCM": {
          "GCM": 9
        },
        "OFB": {
          "OFB": 2
        },
        "XTS": {
          "XTS": 2
        }
      },
      "cplc_data": {},
      "crypto_engine": {},
      "crypto_library": {},
      "crypto_protocol": {
        "IKE": {
          "IKE": 2,
          "IKEv1": 2,
          "IKEv2": 2
        },
        "SSH": {
          "SSH": 101
        },
        "TLS": {
          "SSL": {
            "SSL": 1
          },
          "TLS": {
            "TLS": 102,
            "TLS v1.2": 1,
            "TLS1.2": 1
          }
        }
      },
      "crypto_scheme": {
        "KA": {
          "Key Agreement": 4
        },
        "KEX": {
          "Key Exchange": 1,
          "Key exchange": 3
        },
        "MAC": {
          "MAC": 4
        }
      },
      "device_model": {},
      "ecc_curve": {
        "Edwards": {
          "Ed25519": 1
        },
        "NIST": {
          "P-256": 36,
          "P-384": 30
        }
      },
      "eval_facility": {
        "atsec": {
          "atsec": 44
        }
      },
      "fips_cert_id": {
        "Cert": {
          "#1": 1
        }
      },
      "fips_certlike": {
        "Certlike": {
          "AES 256": 2,
          "AES-128": 1,
          "AES-256": 2,
          "HMAC-SHA- 384": 2,
          "HMAC-SHA-1": 10,
          "HMAC-SHA-384": 6,
          "PKCS #1": 2,
          "PKCS#1": 6,
          "RSA PKCS#1": 2,
          "SHA-1": 8,
          "SHA2- 224": 1,
          "SHA2- 256": 2,
          "SHA2-224": 6,
          "SHA2-256": 10,
          "SHA2-384": 9,
          "SHA2-512": 7,
          "SHA3": 4,
          "SHA3-256": 1
        }
      },
      "fips_security_level": {
        "Level": {
          "Level 1": 1,
          "Level 2": 3
        }
      },
      "hash_function": {
        "MD": {
          "MD5": {
            "MD5": 4
          }
        },
        "SHA": {
          "SHA1": {
            "SHA-1": 8
          },
          "SHA3": {
            "SHA3": 4,
            "SHA3-256": 1
          }
        }
      },
      "ic_data_group": {},
      "javacard_api_const": {
        "curves": {
          "SM2": 2
        }
      },
      "javacard_packages": {},
      "javacard_version": {},
      "os_name": {},
      "pq_crypto": {},
      "randomness": {
        "PRNG": {
          "DRBG": 37
        },
        "RNG": {
          "RNG": 2
        }
      },
      "side_channel_analysis": {},
      "standard_id": {
        "FIPS": {
          "FIPS 140": 1,
          "FIPS 140-3": 54,
          "FIPS 186-4": 11,
          "FIPS 197": 3,
          "FIPS 198-1": 1,
          "FIPS PUB 140-3": 2,
          "FIPS140": 1,
          "FIPS140-3": 2,
          "FIPS180-4": 2,
          "FIPS186-4": 2,
          "FIPS197": 1,
          "FIPS198-1": 1
        },
        "ISO": {
          "ISO/IEC 24759": 2
        },
        "NIST": {
          "NIST SP 800-140B": 1,
          "SP 800-135": 10,
          "SP 800-38F": 3
        },
        "PKCS": {
          "PKCS #1": 1,
          "PKCS#1": 4
        },
        "RFC": {
          "RFC 2313": 1,
          "RFC 5288": 2,
          "RFC 7627": 2
        }
      },
      "symmetric_crypto": {
        "AES_competition": {
          "AES": {
            "AES": 37,
            "AES-128": 1,
            "AES-256": 2
          },
          "CAST": {
            "CAST": 15
          },
          "RC": {
            "RC4": 2
          }
        },
        "DES": {
          "3DES": {
            "Triple-DES": 5
          },
          "DES": {
            "DES": 3
          }
        },
        "constructions": {
          "MAC": {
            "CMAC": 2,
            "HMAC": 24,
            "HMAC-SHA-384": 3
          }
        },
        "miscellaneous": {
          "SM4": {
            "SM4": 2
          }
        }
      },
      "tee_name": {
        "IBM": {
          "SSC": 4
        }
      },
      "tls_cipher_suite": {},
      "vendor": {},
      "vulnerability": {}
    },
    "policy_metadata": {
      "/Author": "Marylene Palard",
      "/CreationDate": "D:20241105042613Z00\u002700\u0027",
      "/Creator": "Word",
      "/ModDate": "D:20241105042613Z00\u002700\u0027",
      "/Producer": "macOS Version 14.6 (Build 23G80) Quartz PDFContext",
      "/Title": "140-3-SecurityPolicy_F5OS-A",
      "pdf_file_size_bytes": 2483874,
      "pdf_hyperlinks": {
        "_type": "Set",
        "elements": []
      },
      "pdf_is_encrypted": false,
      "pdf_number_of_pages": 43
    }
  },
  "state": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.InternalState",
    "module_download_ok": true,
    "module_extract_ok": true,
    "policy_convert_garbage": false,
    "policy_convert_ok": true,
    "policy_download_ok": true,
    "policy_extract_ok": true,
    "policy_pdf_hash": "85bc7f90ec9282c3ef822fd0cfdd03d84f0243ec105afc72cfa8f32da3019999",
    "policy_txt_hash": "88aa9e0569c2215feb4bc7d004a3926ae53b9586151ff8960cbfb41f66307be9"
  },
  "web_data": {
    "_type": "sec_certs.sample.fips.FIPSCertificate.WebData",
    "caveat": "Interim Validation. When operated in approved mode. When installed, initialized and configured as specified in Section 11 of the Security Policy. The tamper evident seals with F5-ADD-BIG-FIPS140 kit installed as indicated in the Security Policy.",
    "certificate_pdf_url": null,
    "date_sunset": "2026-11-17",
    "description": "F5OS-A Cryptographic Module Platform layer services for F5 appliance platforms",
    "embodiment": "Multi-Chip Stand Alone",
    "exceptions": [
      "Operational environment: N/A",
      "Non-invasive security: N/A",
      "Mitigation of other attacks: N/A",
      "Documentation requirements: N/A",
      "Cryptographic module security policy: N/A"
    ],
    "fw_versions": "1.5.1",
    "historical_reason": null,
    "hw_versions": null,
    "level": 2,
    "mentioned_certs": {},
    "module_name": "F5OS-A Cryptographic Module",
    "module_type": "Firmware",
    "revoked_link": null,
    "revoked_reason": null,
    "standard": "FIPS 140-3",
    "status": "active",
    "sw_versions": null,
    "tested_conf": [
      "F5OS-A 1.5.1 on r10900 with Intel\u00ae Xeon\u00ae Gold 6312U Ice Lake-SP with PAA",
      "F5OS-A 1.5.1 on r10900 with Intel\u00ae Xeon\u00ae Gold 6312U Ice Lake-SP without PAA",
      "F5OS-A 1.5.1 on r10920-DF with Intel\u00ae Xeon\u00ae Gold 6312U Ice Lake-SP with PAA",
      "F5OS-A 1.5.1 on r10920-DF with Intel\u00ae Xeon\u00ae Gold 6312U Ice Lake-SP without PAA",
      "F5OS-A 1.5.1 on r4800 with Intel\u00ae Atom\u00ae P5342 Snow Ridge NS with PAA",
      "F5OS-A 1.5.1 on r4800 with Intel\u00ae Atom\u00ae P5342 Snow Ridge NS without PAA",
      "F5OS-A 1.5.1 on r5900  with Intel\u00ae  Xeon\u00ae Silver 4314 Ice Lake-SP with PAA",
      "F5OS-A 1.5.1 on r5900  with Intel\u00ae  Xeon\u00ae Silver 4314 Ice Lake-SP without PAA",
      "F5OS-A 1.5.1 on r5920-DF with Intel\u00ae  Xeon\u00ae Silver 4314 Ice Lake-SP with PAA",
      "F5OS-A 1.5.1 on r5920-DF with Intel\u00ae  Xeon\u00ae Silver 4314 Ice Lake-SP without PAA"
    ],
    "validation_history": [
      {
        "_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry",
        "date": "2024-11-18",
        "lab": "ATSEC INFORMATION SECURITY CORP",
        "validation_type": "Initial"
      }
    ],
    "vendor": "F5, Inc.",
    "vendor_url": "f5.com"
  }
}