U.S. flag   An unofficial archive of your favorite United States government website
This is an archive
(replace .gov by .rip)

Cryptographic Module Validation Program CMVP

Certificate #3193

Details

Module Name
FortiGate-100E[1], FortiGate-201E[2], FortiGate-300D[3], FortiGate-600D[4], FortiGate-800D[5]
Standard
FIPS 140-2
Status
Active
Sunset Date
6/11/2023
Validation Dates
06/12/2018
Overall Level
2
Caveat
When operated in FIPS mode with the tamper evident seals installed as indicated in the Security Policy and configured according to the Entropy Token Section of the Security Policy. There is no assurance of the minimum strength of generated keys
Security Level Exceptions
  • Cryptographic Module Ports and Interfaces: Level 3
  • Roles, Services, and Authentication: Level 3
  • Design Assurance: Level 3
Module Type
Hardware
Embodiment
Multi-Chip Stand Alone
Description
The FortiOS is a firmware based operating system that runs exclusively on Fortinet's FortiGate/FortiWiFi product family. The FortiOS provides integrated firewall, VPN, antivirus, antispam, intrusion prevention, content filtering and traffic shaping and HA capabilities.
Tested Configuration(s)
  • N/A
FIPS Algorithms
AES Certs. #4602, #4604, #4607 and #4628
CKG vendor affirmed
CVL Certs. #1272, #1287, #1288 and #1329
DRBG Cert. #1543
ECDSA Certs. #1129, #1130 and #1137
HMAC Certs. #3050, #3052, #3053 and #3063
KTS AES Cert. #4628 and HMAC Cert. #3063; key establishment methodology provides 128 or 256 bits of encryption strength
RSA Certs. #2510, #2512 and #2526
SHS Certs. #3777, #3779, #3781 and #3792
Allowed Algorithms
Diffie-Hellman (CVL Certs. #1272 and #1287, key agreement; key establishment methodology provides between 112 and 201 bits of encryption strength); EC Diffie-Hellman (CVL Certs. #1272 and #1287, key agreement; key establishment methodology provides between 128 and 256 bits of encryption strength); RSA (CVL Certs. #1272 and #1287, key wrapping; key establishment methodology provides 112 or 128 bits of encryption strength)
Hardware Versions
C1AE25 [1], C1AE64 [2], C1AB49 [3], C1AE11 [4] and C1AC58 [5] with Tamper Evident Seal Kit: FIPS-SEAL-RED
Firmware Versions
FortiOS 5.4, b3141, 170602 [1], FortiOS 5.4, b3144, 170602 [2], FortiOS 5.4, b9791, 170802 [3,4,5]

Vendor

Fortinet, Inc.
1826 Robertson Road
Ottawa, ON K2H 5Z6
Canada

Alan Kaye
akaye@fortinet.com
Phone: 613-225-9381 x87416
Fax: 613-225-2951

Lab

CGI ITSETF
NVLAP Code: 200928-0