808bits

Cisco 5508 Wireless LAN Controller

FIPS 140-2 certificate #1829 · Cisco Systems, Inc. · data as of 2026-09-08

Cisco 5508 Wireless LAN Controller, from Cisco Systems, Inc., holds FIPS 140-2 certificate #1829 at overall level 2. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. RNG SP800-131A Revision 1 Transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode and with the tamper evident seals and security devices installed as indicated in the Security Policy

Certificate

Certificate number1829
StandardFIPS 140-2
Statushistorical
Overall level2
Module typeHardware
EmbodimentMulti-chip standalone
VendorCisco Systems, Inc. · website
Hardware versionsCT5508 Revision Number B0; FIPS Kit AIR-CT5508FIPSKIT=; Opacity Baffle Version A0
Firmware versions7.0.230.0, 7.2.103.0, 7.2.115.1 or 7.2.115.2

Module description

Quoted from the NIST CMVP entry for this certificate.

The Cisco 5508 Series WLAN Controllers deliver centralized control and high capacity for small, medium and large-scale Enterprise wireless LAN networks. In FIPS 140-2 mode of operation, the Cisco WLAN Controllers support the IEEE 802.11i & 802.1x standards, IETF CAPWAP standard and support a Secure Wireless Architecture with WiFi Alliance certified WPA-2 security. The Cisco WLAN Controllers support voice, video and data services along with Cisco Clean Air technology, IPv6 mobility, intrusion protection and intelligent radio resource management.

Security level exceptions

  • Design Assurance: Level 3

Approved algorithms (6)

AlgorithmCAVP certificates
AES1346, 1347, 1348
HMAC785, 786, 787
RNG741, 742
RSA653, 654
SHS1228, 1229, 1230
Triple-DES935

Other algorithms

RSA (key wrapping; key establishment methodology provides 96 bits of encryption strength; non-compliant); AES (Cert. #1346, key wrapping; key establishment methodology provides 128 bits of encryption strength); Diffie-Hellman (key agreement; key establishment methodology provides 112 bits of encryption strength); RC4; MD5; HMAC MD5; AES-CTR (non-compliant); CCKM

Validation history

DateTypeLab
2012-11-05InitialUL Verification Services, Inc.
2013-05-16UpdateUL Verification Services, Inc.
2013-07-12UpdateUL Verification Services, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2012-11-05, 2013-05-16, 2013-07-12

Source documents