808bits

Aruba AP-120 Series and Dell W-AP120 Series Wireless Access Points

FIPS 140-2 certificate #1820 · Aruba Networks, Inc. · data as of 2026-09-12

Aruba AP-120 Series and Dell W-AP120 Series Wireless Access Points, from Aruba Networks, Inc., holds FIPS 140-2 certificate #1820 at overall level 2. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. RNG SP800-131A Revision 1 Transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode with tamper evident labels installed as indicated in the Security Policy

Certificate

Certificate number1820
StandardFIPS 140-2
Statushistorical
Overall level2
Module typeHardware
EmbodimentMulti-chip standalone
VendorAruba Networks, Inc. · website
Hardware versionsAP-124-F1 [1], AP-125-F1 [1], W-AP124-F1 [2] and W-AP125-F1 [2] with FIPS kit 4010061-01
Firmware versionsArubaOS_6.1.2.3-FIPS [1] and Dell_PCW_6.1.2.3-FIPS [2] or ArubaOS_6.1.4.1-FIPS [1] and Dell_PCW_6.1.4.1-FIPS [2] or ArubaOS_6.1.4.5-FIPS [1] and Dell_PCW_6.1.4.5-FIPS [2] or ArubaOS_6.1.4.7-FIPS [1] and Dell_PCW_6.1.4.7-FIPS [2]

Module description

Quoted from the NIST CMVP entry for this certificate.

Aruba's Wi-Fi access points serve as secure network on-ramps, aggregating wireless user traffic and forwarding it to Aruba's highly secure Mobility Controllers, where per-user role based access controls are applied through an integrated firewall. In FIPS 140-2 Mode, Aruba APs in conjunction with the Mobility Controller support the IEEE 802.11i/WPA2 client standard along with optional Suite B cryptography. Aruba APs also provide wireless intrusion detection/prevention services, support wireless mesh topologies, and have Wi-Fi Alliance certification for IEEE 802.11a/b/g/n.

Approved algorithms (6)

AlgorithmCAVP certificates
AES861, 1850, 1851
HMAC478, 1098, 1099
RNG969, 970
RSA933, 934, 935
SHS856, 1627, 1628, 1629
Triple-DES708, 1198, 1199

Other algorithms

MD5; Diffie-Hellman (key agreement; key establishment methodology provides 80 bits of encryption strength; non-compliant)

Validation history

DateTypeLab
2012-12-05InitialSAIC-VA
2013-01-24Update
2013-11-14Update
2014-01-23UpdateLeidos Accredited Testing & Evaluation (AT&E) Lab

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2012-12-05, 2013-01-24, 2013-11-14, 2014-01-23

Source documents