808bits

Cisco Common Cryptographic Module (C3M)

FIPS 140-2 certificate #1643 · Cisco Systems, Inc. · data as of 2026-08-28
Historical. RNG SP800-131A Revision 1 Transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: None

Certificate

Certificate number1643
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-chip standalone
VendorCisco Systems, Inc. · website
Software versions0.9.8r.1.1

Module description

The Cisco Common Cryptographic Module (C3M) is a software library that provides cryptographic services to a vast array of Cisco's networking and collaboration products. The module provides FIPS validated cryptographic algorithms for services such as sRTP, SSH, TLS, 802.1x etc. The module does not implement any of the protocols directly. Instead, it provides the cryptographic primitives and functions to allow a developer to implement various protocols.

Approved algorithms

AlgorithmCAVP certificate
AES1759
DSA550
ECDSA234
HMAC1031
RNG937
RSA876
SHS1544
Triple-DES1139

Other algorithms

Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 152 bits of encryption strength; non-compliant less than 112 bits of encryption strength); EC Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength; non-compliant less than 112 bits of encryption strength); RSA (key wrapping; key establishment methodology provides between 112 and 152 bits of encryption strength; non-compliant less than 112 bits of encryption strength)

Tested configurations

  • Android 2.3.3 (single-user mode)
  • FreeBSD 8.2 (32-bit and 64-bit)
  • Linux Kernel 2.6.27.7
  • Mac OS X 10.6 (32-bit and 64-bit)
  • Openwall Linux 3.0 (32-bit)
  • Red Hat Enterprise Linux v5 (32-bit and 64-bit)
  • Windows 7 SP1 (32-bit and 64-bit)
  • Yellow Dog Linux 6.2

Validation history

DateTypeLab
2011-11-29InitialSAIC-VA
2012-02-23Update

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2011-11-29, 2012-02-23

Source documents