Module Name
Cisco Firepower Threat Defense on ASA Cryptographic Module
Validation Dates
10/26/2018
Caveat
When operated in FIPS mode. When installed with the tamper evident seals and opacity shields, initialized and configured as specified in Section 3 of the Security Policy
Security Level Exceptions
- Roles, Services, and Authentication: Level 3
- Mitigation of Other Attacks: N/A
Embodiment
Multi-Chip Stand Alone
Description
Cisco Firepower Threat Defense (FTD) is a unified software image, which includes the Cisco ASA features and FirePOWER Services. This unified software is capable of offering the functions of ASA and FirePOWER deployed on Cisco Firepower 4100 Series and the Firepower 9300 appliances as well the FTD can be also be deployed on Cisco Firepower Threat Defense (FTD) ASA 5506-X, ASA 5506H-X, ASA 5506W-X, ASA 5508-X, ASA 5512-X, ASA 5515-X, ASA 5516-X, ASA 5525-X, ASA 5545-X, and ASA 5555-X.
FIPS Algorithms
AES |
Certs. #2050, #2444, #2472, #3301 and #4905 |
CKG |
vendor affirmed |
CVL |
Cert. #1521 |
DRBG |
Certs. #332, #336, #819 and #1735 |
ECDSA |
Cert. #1254 |
HMAC |
Certs. #1247, #1514, #2095 and #3272 |
RSA |
Cert. #2678 |
SHS |
Certs. #1794, #2091, #2737 and #4012 |
Triple-DES |
Certs. #1321, #1513, #1881 and #2559 |
Allowed Algorithms
Diffie-Hellman (CVL Cert. #1521, key agreement; key establishment methodology provides between 112 and 150 bits of encryption strength); EC Diffie-Hellman (CVL Cert. #1521, key agreement; key establishment methodology provides between 128 and 256 bits of encryption strength); NDRNG; RSA (key wrapping; key establishment methodology provides 112 bits of encryption strength)
Hardware Versions
ASA 5506-X[1][2], ASA 5506H-X[1][2], ASA 5506W-X[1][2], ASA 5508-X[1][3], ASA 5516-X[1][4], ASA 5525-X[1], ASA 5545-X[1] and ASA 5555-X[1] with [AIR-AP-FIPSKIT=][1], [ASA5506-FIPS-KIT=][2], [ASA5508-FIPS-KIT=][3] and [ASA5516-FIPS-KIT=][4]