808bits

Junos-FIPS 10.4 L2 OS Cryptographic Module

FIPS 140-2 certificate #1813 · Juniper Networks, Inc. · data as of 2026-08-28
Historical. RNG SP800-131A Revision 1 Transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated only on the specific platforms specified on the reverse. The routing engine and chassis configured with tamper evident seals installed as indicated in the Security Policy.

Certificate

Certificate number1813
StandardFIPS 140-2
Statushistorical
Overall level2
Module typeFirmware
EmbodimentMulti-chip embedded
VendorJuniper Networks, Inc. · website
Firmware versions10.4R5

Module description

Juniper Networks M, T and MX series routing platforms are complete routing systems that support a variety of high-speed interfaces for medium/large networks and network applications and numerous routing standards. All platforms are physically self-contained, housing software, firmware, and hardware necessary for routing. The router architecture provides for streamlined forwarding and routing control and the capability to run Internet-scale networks at high speeds. They are powered by the same JUNOS software, which provides both management and control functions as well as all IP routing.

Security level exceptions

  • Design Assurance: Level 3
  • Tested: M120 [1], M320 [2], MX240 [3], MX480 [4], MX960 [5] and T1600 [6]
  • Routing Engines: (RE-A-2000-4096 [1,2] and RE-S-2000-4096 [3,4,5,6])
  • Routing Engine Control Boards: (750-011402 [1] and 750-021524 [3,4,5])
  • Blanking Plate (540-015089 Rev02 [5])
  • Control Boards: (750-009188 [2] and 750-024570 [6])
  • with Tamper Evident Seal Kit: (JNPR-FIPS-TAMPER-LBLS [1,2,3,4,5,6])

Approved algorithms

AlgorithmCAVP certificate
AES1719, 1726, 1727
DSA531
ECDSA225
HMAC994, 1000, 1001, 1002
RNG909
RSA847
SHS1502, 1508, 1509, 1510
Triple-DES1106, 1112, 1113

Other algorithms

MD5; Diffie-Hellman (key agreement; key establishment methodology provides 80 bits of encryption strength; non-compliant); RSA (key wrapping; key establishment methodology provides 80 bits of encryption strength; non-compliant)

Validation history

DateTypeLab
2012-10-11InitialCYGNACOM SOLUTIONS INC

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2012-10-11

Source documents