
Table 6 CSPs/Keys Used in the module
12
RADIUS server
shared secret
8-128 characters
shared secret
Entered by CO role.
Used for RADIUS
server authentication
Stored in SDRAM
memory (plaintext).
Zeroized by using
command ‘write erase
all’ or by overwriting
with a new secret
13
Enable secret
8-64 characters
password
Entered by CO role.
Used for CO role
authentication
Stored in SDRAM
memory (plaintext).
Zeroized by using
command ‘write erase
all’ or by overwriting
with a new secret
14
User Passwords
8-64 characters
password
Entered by CO role.
Used for User role
authentication.
Stored in SDRAM
memory (plaintext).
Zeroized by using
command ‘write erase
all’ or by overwriting
with a new secret
15
RSA Private Key
RSA 2048 bit private
key
This key is generated by
calling FIPS approved
DRBG (cert #528) in the
module. Used for
IKEv1, IKEv2, TLS,
OCSP (signing OCSP
messages) and EAP-
TLS peers
authentication.
Stored in Flash
memory (plaintext)
encrypted with KEK.
Zeroized by using
command ‘write erase
all’
16
RSA public key
RSA 2048 bits public
key
This key is generated by
calling FIPS approved
DRBG (cert #528) in the
module. Used for
IKEv1, IKEv2, TLS,
OCSP (verifying OCSP
messages) and EAP-
TLS peers
authentication.
Stored in Flash
memory (plaintext)
encrypted with KEK.
Zeroized by using
command ‘write erase
all’
17
ECDSA Private Key
ECDSA suite B P-256
and P-384 curves
This key is generated by
calling FIPS approved
DRBG (cert #528) in the
module. Used for
IKEv1, IKEv2, TLS and
EAP-TLS peers
authentication.
Stored in Flash
memory (plaintext)
encrypted with KEK.
Zeroized by using
command ‘write erase
all’
24
|
Aruba 7XXX Series Controllers FIPS 140-2 Level 2 Security Policy