Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Cryptographic Module Validation Program CMVP

Certificate #4747

Details

Module Name
Cisco FIPS Object Module
Standard
FIPS 140-3
Status
Active
Sunset Date
7/31/2029
Overall Level
1
Caveat
No assurance of the minimum strength of generated SSPs (e.g., keys).
Security Level Exceptions
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A
Module Type
Firmware-hybrid
Embodiment
Multi-Chip Stand Alone
Description
The Cisco FIPS Object Module (FOM) is a firmware hybrid library that provides cryptographic services to a vast array of Cisco's networking and collaboration products. The module provides FIPS 140 validated cryptographic algorithms for services such as IPSEC, SRTP, SSH, TLS, 802.1x, etc. The module does not directly implement any of these protocols, instead, it provides the cryptographic primitives and functions to allow a developer to implement the various protocols.
Tested Configuration(s)
  • Linux 4.4 running on Cisco Catalyst 9300 with Intel Xeon D-1526 (Broadwell) with PAA
  • Linux 4.5 running on Cisco Unified Computing System (UCS) with Intel Xeon Gold 6244 (Cascade Lake) with PAA
  • Linux 5.4 running on ISR 4321 with Intel Atom C2558 (Silvermont) with PAA
Approved Algorithms
AES-CBC
AES-CCM
AES-CFB1
AES-CFB128
AES-CFB8
AES-CMAC
AES-CTR
AES-ECB
AES-GCM
AES-GMAC
AES-KW
AES-KWP
AES-OFB
AES-XTS Testing Revision 2.0
Counter DRBG
DSA KeyGen (FIPS186-4)
DSA PQGGen (FIPS186-4)
DSA PQGVer (FIPS186-4)
DSA SigGen (FIPS186-4)
DSA SigVer (FIPS186-4)
ECDSA KeyGen (FIPS186-4)
ECDSA KeyVer (FIPS186-4)
ECDSA SigGen (FIPS186-4)
ECDSA SigVer (FIPS186-4)
Hash DRBG
HMAC DRBG
HMAC-SHA-1
HMAC-SHA2-224
HMAC-SHA2-256
HMAC-SHA2-384
HMAC-SHA2-512
HMAC-SHA2-512/224
HMAC-SHA2-512/256
HMAC-SHA3-224
HMAC-SHA3-256
HMAC-SHA3-384
HMAC-SHA3-512
KAS-ECC CDH-Component SP800-56Ar3
KAS-ECC-SSC Sp800-56Ar3
KAS-FFC-SSC Sp800-56Ar3
KAS-IFC-SSC
KDA HKDF Sp800-56Cr1
KDA OneStep Sp800-56Cr1
KDF IKEv2
KDF SNMP
KDF SP800-108
KDF SRTP
KDF SSH
KTS-IFC
PBKDF
RSA KeyGen (FIPS186-4)
RSA SigGen (FIPS186-4)
RSA SigVer (FIPS186-4)
Safe Primes Key Generation
Safe Primes Key Verification
SHA-1
SHA2-224
SHA2-256
SHA2-384
SHA2-512
SHA2-512/224
SHA2-512/256
SHA3-224
SHA3-256
SHA3-384
SHA3-512
SHAKE-128
SHAKE-256
TDES-CBC
TDES-CFB1
TDES-CFB64
TDES-CFB8
TDES-CMAC
TDES-CTR
TDES-ECB
TDES-OFB
TLS v1.2 KDF RFC7627
TLS v1.3 KDF
Firmware Versions
7.3a

Vendor

Cisco Systems, Inc.
170 West Tasman Dr.
San Jose, California 95314
USA

Global Certification Team
[email protected]
Phone: 800-553-6387

Validation History

Date Type Lab
8/1/2024 Initial Acumen Security