808bits

FortiAnalyzer 4.0 MR3

FIPS 140-2 certificate #2105 · Fortinet, Inc. · data as of 2026-08-28
Historical. RNG SP800-131A Revision 1 Transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy

Certificate

Certificate number2105
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeFirmware
EmbodimentMulti-chip standalone
VendorFortinet, Inc. · website
Firmware versionsv4.0, build3059, 130918

Module description

The FortiAnalyzer family of logging, analyzing, and reporting appliances securely aggregate log data from Fortinet devices and other syslog-compatible devices. Using a comprehensive suite of customizable reports, users can filter and review records, including traffic, event, virus, attack, Web content, and email data.

Security level exceptions

  • Roles, Services, and Authentication: Level 3
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A
  • Tested: FortiAnalyzer 4000-B with FortiAnalyzer v4.0, build3059, 130918

Approved algorithms

AlgorithmCAVP certificate
AES2681
HMAC1667, 1668
RNG1251
RSA1030
SHS2251, 2252
Triple-DES1608, 1609

Other algorithms

Diffie-Hellman (non-compliant); RSA (key wrapping; key establishment methodology provides 112 bits of encryption strength; non-compliant less than 112 bits of encryption strength); DES; MD5; HMAC-MD5

Validation history

DateTypeLab
2014-03-19InitialEWA - Canada

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2014-03-19

Source documents