Module Name
Aruba Virtual and Hardware Mobility Master Appliances with ArubaOS FIPS Firmware
Historical Reason
SP 800-56Arev3 transition - replaced by certificate #4637
Caveat
When operated in FIPS mode. When installed, initialized and configured as specified in Section 9 of the Security Policy
Security Level Exceptions
- Roles, Services, and Authentication: Level 2
- Mitigation of Other Attacks: N/A
Embodiment
Multi-Chip Stand Alone
Description
Aruba's family of Mobility Masters simplify the management of multiple Aruba controllers running ArubaOS. Key features include a centralized dashboard to easily see and manage controllers, configuration hierarchy to customize deployments for various sites, and live firmware and feature upgrades to improve network reliability during active user sessions. The addition of licensing pools simplifies the transfer of licenses between different controllers to quickly address expanded deployment needs.
Tested Configuration(s)
- Aruba Mobility Master 10K - F1 Hardware Appliance (JZ398A) with ArubaOS 8.2.2.5-FIPS with an Intel Xeon Silver with PAA
- Aruba Mobility Master 10K - F1 Hardware Appliance (JZ398A) with ArubaOS 8.5.0.3-FIPS with an Intel Xeon Silver with PAA
- Aruba Mobility Master 10K - F1 Hardware Appliance (JZ398A) with ArubaOS 8.6.0.4-FIPS with an Intel Xeon Silver with PAA
- Aruba Mobility Master 1K - F1 Hardware Appliance (JZ396A) with ArubaOS 8.2.2.5-FIPS with an Intel Xeon Silver with PAA
- Aruba Mobility Master 1K - F1 Hardware Appliance (JZ396A) with ArubaOS 8.5.0.3-FIPS with an Intel Xeon Silver with PAA
- Aruba Mobility Master 1K - F1 Hardware Appliance (JZ396A) with ArubaOS 8.6.0.4-FIPS with an Intel Xeon Silver with PAA
- Aruba Mobility Master 5K - F1 Hardware Appliance (JZ397A) with ArubaOS 8.2.2.5-FIPS with an Intel Xeon Silver with PAA
- Aruba Mobility Master 5K - F1 Hardware Appliance (JZ397A) with ArubaOS 8.5.0.3-FIPS with an Intel Xeon Silver with PAA
- Aruba Mobility Master 5K - F1 Hardware Appliance (JZ397A) with ArubaOS 8.6.0.4-FIPS with an Intel Xeon Silver with PAA
- ArubaOS 8.2.2.5-FIPS on ESXi 6.5 running on an HPE ProLiant ML110 Gen10 with an Intel Xeon Silver with PAA
- ArubaOS 8.2.2.5-FIPS on ESXi 6.5 running on an HPE ProLiant ML110 Gen10 with an Intel Xeon Silver without PAA
- ArubaOS 8.5.0.3-FIPS on ESXi 6.5 running on an HPE ProLiant ML110 Gen10 with an Intel Xeon Silver with PAA
- ArubaOS 8.5.0.3-FIPS on ESXi 6.5 running on an HPE ProLiant ML110 Gen10 with an Intel Xeon Silver without PAA
- ArubaOS 8.6.0.4-FIPS on ESXi 6.5 running on an HPE ProLiant ML110 Gen10 with an Intel Xeon Silver with PAA
- ArubaOS 8.6.0.4-FIPS on ESXi 6.5 running on an HPE ProLiant ML110 Gen10 with an Intel Xeon Silver without PAA
Approved Algorithms
AES |
Certs. #C413 and #C414 |
CVL |
Certs. #C413, #C414, #C1972 and #C1974 |
DRBG |
Cert. #C413 |
ECDSA |
Certs. #C413 and #C414 |
HMAC |
Certs. #C413, #C414, #C1972 and #C1974 |
KTS |
AES Cert. #C413; key establishment methodology provides 128 or 256 bits of encryption strength |
KTS |
AES Cert. #C413 and HMAC Cert. #C413; key establishment methodology provides between 128 and 256 bits of encryption strength |
KTS |
AES Cert. #C414; key establishment methodology provides 128 or 256 bits of encryption strength |
KTS |
AES Cert. #C414 and HMAC Cert. #C414; key establishment methodology provides between 128 and 256 bits of encryption strength |
RSA |
Certs. #C413, #C414 and #C818 |
SHS |
Certs. #C413, #C414, #C818, #C1972 and #C1974 |
Allowed Algorithms
Diffie-Hellman (key agreement; key establishment methodology provides 112 bits of encryption strength); EC Diffie-Hellman (key agreement; key establishment methodology provides 128 or 192 bits of encryption strength); MD5; NDRNG; RSA (key wrapping; key establishment methodology provides 112 bits of encryption strength)
Firmware Versions
ArubaOS 8.2.2.5-FIPS, ArubaOS 8.5.0.3-FIPS and ArubaOS 8.6.0.4-FIPS