Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Cryptographic Module Validation Program CMVP

Certificate #4945

Details

Module Name
BIG-IP Tenant Cryptographic Module
Standard
FIPS 140-3
Status
Active
Sunset Date
1/16/2027
Overall Level
2
Caveat
Interim validation. When operated in approved mode. When installed, initialized, and configured as specified in Section 11 of the Security Policy. The tamper evident labels contained in F5-ADD-BIG-FIPS140 kit and panel fillers installed as indicated in the Security Policy section 7.
Security Level Exceptions
  • Operational environment: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A
  • Documentation requirements: N/A
  • Cryptographic module security policy: N/A
Module Type
Firmware
Embodiment
Multi-Chip Stand Alone
Description
BIG-IP Tenant Cryptographic Module, Application Delivery Controller and Firewall software running on running on F5 hardware and the underlying platform layer.
Tested Configuration(s)
  • BIG-IP 17.1.0.1 Tenant Cryptographic Module on F5OS-A 1.5.1 running on r10900 with Intel® Xeon® Gold 6312U Ice Lake
  • BIG-IP 17.1.0.1 Tenant Cryptographic Module on F5OS-A 1.5.1 running on r10920-DF with Intel® Xeon® Gold 6312U Ice Lake
  • BIG-IP 17.1.0.1 Tenant Cryptographic Module on F5OS-A 1.5.1 running on r4800 with Intel® Atom® P5342 Snow Ridge
  • BIG-IP 17.1.0.1 Tenant Cryptographic Module on F5OS-A 1.5.1 running on r5900 with Intel® Xeon® 4314 Silver Ice Lake
  • BIG-IP 17.1.0.1 Tenant Cryptographic Module on F5OS-A 1.5.1 running on r5920-DF with Intel® Xeon® 4314 Silver Ice Lake
  • BIG-IP 17.1.0.1 Tenant Cryptographic Module on F5OS-A 1.7.0 running on r12900-DS with Intel® Xeon® Platinum 8351N Ice Lake
  • BIG-IP 17.1.0.1 Tenant Cryptographic Module on F5OS-C 1.6.0 running on VELOS CX410 BX110 with Intel® Xeon® D-2177NT Skylake
Approved Algorithms
AES-CBC
AES-CBC
AES-CCM
AES-CCM
AES-CTR
AES-ECB
AES-GCM
AES-GCM
AES-GMAC
AES-GMAC
Counter DRBG
Counter DRBG
ECDSA KeyGen (FIPS186-4)
ECDSA KeyGen (FIPS186-4)
ECDSA KeyVer (FIPS186-4)
ECDSA KeyVer (FIPS186-4)
ECDSA SigGen (FIPS186-4)
ECDSA SigGen (FIPS186-4)
ECDSA SigVer (FIPS186-4)
ECDSA SigVer (FIPS186-4)
HMAC-SHA-1
HMAC-SHA-1
HMAC-SHA2-256
HMAC-SHA2-256
HMAC-SHA2-384
HMAC-SHA2-384
HMAC-SHA2-512
HMAC-SHA2-512
KAS-ECC-SSC Sp800-56Ar3
KAS-ECC-SSC Sp800-56Ar3
KAS-FFC-SSC Sp800-56Ar3
KAS-FFC-SSC Sp800-56Ar3
KDF SSH
RSA KeyGen (FIPS186-4)
RSA SigGen (FIPS186-4)
RSA SigGen (FIPS186-4)
RSA SigVer (FIPS186-4)
RSA SigVer (FIPS186-4)
Safe Primes Key Generation
Safe Primes Key Generation
Safe Primes Key Verification
Safe Primes Key Verification
SHA-1
SHA-1
SHA2-256
SHA2-256
SHA2-384
SHA2-384
SHA2-512
SHA2-512
TLS v1.2 KDF RFC7627
TLS v1.2 KDF RFC7627
Firmware Versions
17.1.0.1

Vendor

F5, Inc.
801 Fifth Ave
Seattle, WA 98104
USA

Maryrita Steinhour
fipsbigip17@f5.com
Phone: 206-272-735

Related Files

Validation History

Date Type Lab
1/17/2025 Initial ATSEC INFORMATION SECURITY CORP