IOS Common Cryptographic Module (IC2M)
Certificate
| Certificate number | 1940 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 1 |
| Module type | Firmware |
| Embodiment | Multi-chip standalone |
| Vendor | Cisco Systems, Inc. · website |
| Firmware versions | Rel 1(1.0.0), Rel 1(1.0.1) and Rel 1(1.0.2) |
Module description
The IC2M module provides the FIPS validated cryptographic algorithms for services requiring those algorithms. The module does not implement any protocols directly. Instead, it provides the cryptographic primitives and functions to allow IOS to implement those various protocols.
Security level exceptions
- Tested: Cisco Catalyst 2960 with IOS 15.0SE
- Cisco 3925 ISR with IOS 15.2
- Cisco 2811 ISR with IOS 15.2
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | 2134, 2136 |
| CVL | 30 |
| DRBG | 237 |
| ECDSA | 322 |
| HMAC | 1304 |
| RSA | 1100 |
| SHS | 1858, 1859 |
| Triple-DES | 1358, 1359, 1360 |
Other algorithms
DES; HMAC-MD5; MD2; MD5; RC2; RC4; SEAL; Diffie-Hellman (key agreement; key establishment methodology provides 112 bits of encryption strength; non-compliant less than 112 bits of encryption strength); EC Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength; non-compliant less than 112 bits of encryption strength); RSA (key wrapping; key establishment methodology provides 112 bits of encryption strength; non-compliant less than 112 bits of encryption strength)
Validation history
| Date | Type | Lab |
|---|---|---|
| 2013-04-30 | Initial | Leidos Accredited Testing & Evaluation (AT&E) Lab |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2013-04-30