
Aruba AP-5XX Wireless Access Points with ArubaOS FIPS Firmware FIPS 140-2 Level 2 Security Policy |29
Table 8 - Estimated Strength of Authentication Mechanisms
Therefore the associated probability of a successful random attempt
during a one-minute period is 60,000/2^128, which is less than 1 in
100,000 required by FIPS 140-2.
7.4
Unauthenticated Services
The module provides the following unauthenticated services, which are available regardless of role.
System status – module LEDs
Reboot module by removing/replacing power
Self-test and initialization at power-on.
7.5
Services Available in Non-FIPS Mode
The following services are available in Non-FIPS mode:
All of the services that are available in FIPS mode are also available in non-FIPS mode.
If not operating in the Approved mode as per the procedures in sections 13.1,
Crypto Officer Management
,
13.4,
Setting Up Your Wireless Access Point
and 13.5,
Enabling FIPS Mode on the Staging Controller
, then
non-Approved algorithms and/or sizes are available.
Upgrading the firmware via the console port.
Debugging via the console port.
IPSec/IKE using Triple-DES.
Creation/use of secure mesh channel
3
Generation and use of 802.11i cryptographic keys
Use of 802.11i Pre-Shared Secret for establishment of IEEE 802.11i keys
For additional non-security-relevant services offered by the module, please refer to the
ArubaOS User Guide
listed
in section 13.7.
3
This service is only applicable in the Mesh Portal mode and Mesh Point mode. It is not applicable in Control Plane Security
(CPSec) Protected AP FIPS mode and Remote AP mode.