U.S. flag   An unofficial archive of your favorite United States government website
This is an archive
(replace .gov by .rip)

Cryptographic Module Validation Program CMVP

Certificate #3823

Details

Module Name
Cisco ASA and ISA Firepower Threat Defense Cryptographic Modules
Standard
FIPS 140-2
Status
Active
Sunset Date
2/22/2026
Validation Dates
02/23/2021
Overall Level
2
Caveat
When operated in FIPS mode. When installed with the tamper evident seals and opacity shields, initialized and configured as specified in Section 3 of the Security Policy
Security Level Exceptions
  • Roles, Services, and Authentication: Level 3
  • Mitigation of Other Attacks: N/A
Module Type
Hardware
Embodiment
Multi-Chip Stand Alone
Description
Cisco Firepower Threat Defense (FTD) is a unified software image, which includes the Cisco ASA features and FirePOWER Services. This unified software is capable of offering the functions of ASA and FirePOWER deployed on Cisco Firepower 4100 Series and the Firepower 9300 appliances as well the FTD can be also be deployed on Cisco Firepower Threat Defense (FTD) ASA 5508-X, ASA 5516-X, ISA 3000-4C and ISA 3000-2C2F.
Tested Configuration(s)
  • N/A
FIPS Algorithms
AES Certs. #3301 and #4905
CVL Cert. #1521
DRBG Certs. #819 and #1735
ECDSA Cert. #1254
HMAC Certs. #2095 and #3272
RSA Cert. #2678
SHS Certs. #2737 and #4012
Triple-DES Certs. #1881 and #2559
Allowed Algorithms
Diffie-Hellman (CVL Cert. #1521, key agreement; key establishment methodology provides between 112 and 150 bits of encryption strength); EC Diffie-Hellman (CVL Cert. #1521, key agreement; key establishment methodology provides between 128 and 256 bits of encryption strength); NDRNG; RSA (key wrapping; key establishment methodology provides 112 bits of encryption strength)
Hardware Versions
ASA 5508-X[1][2], ASA 5516-X[1][3], ISA 3000-4C[1] and ISA 3000-2C2F[1] with [AIR-AP-FIPSKIT=][1], [ASA5508-FIPS-KIT=][2] and [ASA5516-FIPS-KIT=][3]
Firmware Versions
6.4

Vendor

Cisco Systems, Inc.
170 West Tasman Drive
San Jose, CA 95134
USA

Global Certification Team
certteam@cisco.com

Lab

GOSSAMER SECURITY SOLUTIONS INC
NVLAP Code: 200997-0