U.S. flag   An unofficial archive of your favorite United States government website
This is an archive
(replace .gov by .rip)

Cryptographic Module Validation Program CMVP

Certificate #3286

Details

Module Name
Cisco Adaptive Security Appliances Cryptographic Module
Standard
FIPS 140-2
Status
Active
Sunset Date
9/16/2023
Validation Dates
09/17/2018
Overall Level
2
Caveat
When operated in FIPS mode and with the tamper evident seals and opacity shields installed as indicated in the Security Policy. This module contains the embedded module Cisco Firepower Cryptographic Module validated to FIPS 140-2 under Cert. #3261 operating in FIPS mode
Security Level Exceptions
  • Roles, Services, and Authentication: Level 3
  • Mitigation of Other Attacks: N/A
Module Type
Hardware
Embodiment
Multi-Chip Stand Alone
Description
Enterprise-class firewall capabilities for the ASA devices in an array of form factors - standalone appliances tailor-made for small and midsize businesses, midsize appliances for businesses improving security . This solution offers the combination of the industry's most deployed stateful firewall with a comprehensive range of next-generation network security services.
Tested Configuration(s)
  • N/A
FIPS Algorithms
AES Certs. #2050, #2444, #2472, #3301, #4266 and #4905
CKG vendor affirmed
CVL Certs. #1008 and #1521
DRBG Certs. #332, #336, #819, #1337 and #1735
ECDSA Cert. #1254
HMAC Certs. #1247, #1514, #2095, #2811 and #3272
RSA Certs. #2297 and #2678
SHS Certs. #1794, #2091, #2737, #3512 and #4012
Triple-DES Certs. #1321, #1513, #1881, #2307 and #2559
Allowed Algorithms
Diffie-Hellman (CVL Cert. #1521, key agreement; key establishment methodology provides between 112 and 150 bits of encryption strength); Diffie-Hellman (CVL Cert. #1008, key agreement; key establishment methodology provides between 112 and 150 bits of encryption strength); EC Diffie-Hellman (CVL Cert. #1008, key agreement; key establishment methodology provides between 128 and 256 bits of encryption strength); NDRNG; RSA (key wrapping; key establishment methodology provides 112 bits of encryption strength)
Hardware Versions
[ASA 5506-X, ASA 5506H-X, ASA 5506W-X] with [1][2], ASA 5508-X with [1][3], ASA 5516-X with [1][4], and [ASA 5525-X, ASA 5545-X, ASA 5555-X] with [1]; FIPS Kit: [AIR-AP-FIPSKIT=][1], [ASA5506-FIPS-KIT=][2], [ASA5508-FIPS-KIT=][3] or [ASA5516-FIPS-KIT=][4]
Firmware Versions
9.8

Vendor

Cisco Systems, Inc.
170 W Tasman Drive
San Jose, CA 95134
USA

Global Certification Team
certteam@cisco.com

Lab

GOSSAMER SECURITY SOLUTIONS INC
NVLAP Code: 200997-0