808bits

Cisco FIPS Object Module

FIPS 140-2 certificate #2034 · Cisco Systems, Inc. · data as of 2026-08-28
Historical. RNG SP800-131A Revision 1 Transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode

Certificate

Certificate number2034
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-chip standalone
VendorCisco Systems, Inc. · website
Software versions3.0 and 3.1

Module description

The Cisco FIPS Object Module (FOM) is a software library that provides cryptographic services to a vast array of Cisco's networking and collaboration products. The module provides FIPS 140 validated cryptographic algorithms for services such as IPSEC, SRTP, SSH, TLS, 802.1x, etc. The module does not directly implement any of these protocols, instead it provides the cryptographic primitives and functions to allow a developer to implement the various protocols.

Security level exceptions

  • Design Assurance: Level 3

Approved algorithms

AlgorithmCAVP certificate
AES2255, 2558
CVL40, 95
DRBG275, 385
DSA703, 783
ECDSA362, 440
HMAC1382, 1578
RNG1125, 1215
RSA1156, 1310
SHS1942, 2157
Triple-DES1410, 1548

Other algorithms

Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 219 bits of encryption strength; non-compliant less than 112 bits of encryption strength); EC Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength; non-compliant less than 112 bits of encryption strength); RSA (key wrapping; key establishment methodology provides between 112 and 152 bits of encryption strength; non-compliant less than 112 bits of encryption strength)

Tested configurations

  • Android 4.0 running on Samsung Galaxy S II without PAA
  • Android 4.0 running on Samsung SGH-T989 without PAA
  • Apple iOS 5.1 running on Apple iPad (MC705LL) without PAA
  • Free BSD 9.0 running Cisco UCS C200 M2 without PAA
  • Linux 2.6 running on Cisco UCS C210 M2 with PAA
  • Linux 2.6 running on a Cisco ASR1K without PAA (single-user mode)
  • Linux 2.6 running on Cavium CN5200-EVP-MB4-Y without PAA
  • Linux 2.6 running on Cisco ASR1K without PAA
  • Mac OS X 10.7 running on Apple Mac Mini 5,2 with PAA
  • Microsoft Windows 7 (32-bit) running on HP Pro 3130 Microtower with PAA

Validation history

DateTypeLab
2013-11-13InitialLeidos Accredited Testing & Evaluation (AT&E) Lab

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2013-11-13

Source documents