Module Name
Cisco Adaptive Security Appliances Cryptographic Module
Validation Dates
08/01/2017
Caveat
When operated in FIPS mode and with the tamper evident seals and opacity shields installed as indicated in the Security Policy. This module contains the embedded module Cisco Firepower Cryptographic Module validated to FIPS 140-2 under Cert. #2960 operating in FIPS mode
Security Level Exceptions
- Roles, Services, and Authentication: Level 3
- Mitigation of Other Attacks: N/A
Embodiment
Multi-Chip Stand Alone
Description
Enterprise-class firewall capabilities for the ASA devices in an array of form factors - standalone appliances tailor-made for small and midsize businesses, midsize appliances for businesses improving security . This solution offers the combination of the industry's most deployed stateful firewall with a comprehensive range of next-generation network security services.
FIPS Algorithms
AES |
Certs. #2050, #2444, #2472, #3301, #4249 and #4266 |
CVL |
Certs. #1002 and #1008 |
DRBG |
Certs. #332, #336, #819, #1328 and #1337 |
ECDSA |
Certs. #989 and #995 |
HMAC |
Certs. #1247, #1514, #2095, #2787 and #2811 |
RSA |
Certs. #2297 and #2298 |
SHS |
Certs. #1794, #2091, #2737, #3486 and #3512 |
Triple-DES |
Certs. #1321, #1513, #1881, #2304 and #2307 |
Allowed Algorithms
Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 150 bits of encryption strength); EC Diffie-Hellman (key agreement; key establishment methodology provides between 128 and 256 bits of encryption strength); HMAC MD5; MD5; NDRNG; RSA (key wrapping; key establishment methodology provides 112 bits of encryption strength)
Hardware Versions
ASA 5506-X[1], ASA 5506H-X[1], ASA 5506W-X[1], ASA 5508-X[2][3], ASA 5512-X[2], ASA 5515-X[5], ASA 5516-X[2][4], ASA 5525-X[5], ASA 5545-X[5], ASA 5555-X[5] with [ASA5506-FIPS-KIT=][1], [ASA5500X-FIPS-KIT=][2], [ASA5508-FIPS-KIT=][3], [ASA5516-FIPS-KIT=][4] or [CISCO-FIPS-KIT=][5]