808bits

FortiAnalyzer

FIPS 140-2 certificate #1406 · Fortinet, Inc. · data as of 2026-08-28
Historical. RNG SP800-131A Revision 1 Transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode

Certificate

Certificate number1406
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeFirmware
EmbodimentMulti-chip standalone
VendorFortinet, Inc. · website
Firmware versionsv4.0.0,build6087,091105

Module description

The FortiAnalyzer family of logging, analyzing, and reporting appliances securely aggregate log data from Fortinet devices and other syslog-compatible devices. Using a comprehensive suite of customizable reports, users can filter and review records, including traffic, event, virus, attack, Web content, and email data.

Security level exceptions

  • Roles, Services, and Authentication: Level 3
  • EMI/EMC: Level 3
  • Design Assurance: Level 3
  • Tested: FortiAnalyzer-1000B with the FortiAnalyzer 4.0.0 operating system

Approved algorithms

AlgorithmCAVP certificate
AES1206, 1213
HMAC701, 707
RNG667
RSA584
SHS1109, 1117
Triple-DES870, 874

Other algorithms

Diffie-Hellman (key agreement; key establishment method provides between 80 and 96 bits of encryption strength; non-compliant); RSA (key wrapping; key establishment methodology provides 112 bits of encryption strength; non-compliant less than 112 bits of encryption strength); DES; MD5; HMAC-MD5

Validation history

DateTypeLab
2010-09-15InitialEWA - Canada

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2010-09-15

Source documents