
The above hardware algorithm certificates were tested on Broadcom XLP series processors by Broadcom
Corporation. Aruba Networks purchased the processors and put them in the Aruba modules to support
bulk cryptographic operations. Please be aware that there is no partnership between Aruba Networks and
Broadcom Corporation.
The firmware supports the following cryptographic implementations.
•
ArubaOS OpenSSL library implements the following FIPS-approved algorithms:
o
AES (Cert. #2900)
o
SP800-135rev1 KDF CVL (Cert. #326)
o
DRBG (Cert. #528)
o
ECDSA (Cert. #524)
o
HMAC (Cert. #1835)
o
KBKDF (Cert. #32)
o
RSA (Cert. #1528)
o
SHS (Cert. #2440)
o
Triple-DES (Cert. #1726)
•
ArubaOS Crypto library implements the following FIPS Approved Algorithms:
o
AES (Cert. #2884)
o
SP800-135rev1 KDF CVL (Cert. #314)
1
o
ECDSA (Cert. #519)
o
HMAC (Cert. #1818)
o
RSA (Cert. #1518)
o
SHS (Cert. #2425)
o
Triple-DES (Cert. #1720)
•
ArubaOS UBOOT Bootloader library implements the following FIPS-approved algorithms:
o
RSA (Cert. #1517)
o
SHS (Cert. #2424)
Non-FIPS Approved but Allowed Cryptographic Algorithms
•
Diffie-Hellman (key agreement; key establishment methodology provides 112 bits of encryption
strength)
•
EC Diffie-Hellman (key agreement; key establishment methodology provides 128 or 192 bits of
encryption strength)
•
RSA (key wrapping; key establishment methodology provides 112 bits of encryption strength)
•
NDRNG
Note: RSA key wrapping is used in TLS protocol implementation.
Non-FIPS Approved Cryptographic Algorithms
1
Only the IKEv2 KDF is active on this algorithm implementation
20
|
Aruba 7XXX Series Controllers FIPS 140-2 Level 2 Security Policy