
ECDSA-based authentication
IKEv1, IKEv2 and TLS
User
ECDSA signing and verification is used to authenticate to the module
during IKEv1/IKEv2. Both P-256 and P-384 curves are supported.
ECDSA P-256 provides 128 bits of equivalent security, and P-384
provides 192 bits of equivalent security. Assuming the low end of
that range, the associated probability of a successful random attempt
during a one-minute period is 1 in 2^128, which is less than 1 in
100,000 required by FIPS 140-2.
Unauthenticated Services
The Aruba Controller can perform VLAN, bridging, firewall, routing, and forwarding functionality without
authentication. These services do not involve any cryptographic processing.
Additional unauthenticated services include performance of the power-on self-test and system status
indication via LEDs.
Non-Approved Services
The following non-approved services are available in non-FIPS mode.
•
IPSec/IKE with Diffie-Hellman 768-bit/1024-bit moduli, DES, HMAC-MD5 and MD5
•
SSHv1 using RC4
Please note that all CSPs will be zeroized automatically when switching from FIPS mode to non-FIPS
mode, or from non-FIPS mode to FIPS mode.
Cryptographic Key Management
Implemented Algorithms
The firmware in each module contains the following cryptographic algorithm implementations/crypto
libraries to implement the different FIPS approved cryptographic algorithms that will be used for the
corresponding security services supported by the module in FIPS mode:
•
ArubaOS OpenSSL library algorithm implementation
•
ArubaOS Crypto library algorithm implementation
•
ArubaOS UBootloader library algorithm implementation
•
Aruba Hardware Crypto Accelerator algorithm implementation
Below are the detailed lists for the FIPS approved algorithms and the associated certificate implemented
by each algorithm implementation.
•
Aruba Hardware Crypto Accelerator algorithm implementation:
o
AES (Certs. #2477 and #3014)
o
Triple-DES (Certs. #1516 and #1770)
o
SHS (Certs. #2096 and #2522)
o
HMAC (Certs. #1520 and #1906)
o
RSA (Certs. #1266 and #1573)
Aruba 7XXX Series Controllers FIPS 140-2 Level 2 Security Policy
|19