808bits

IBM LTO Generation 6 Encrypting Tape Drive

FIPS 140-2 certificate #2169 · IBM® Corporation · data as of 2026-08-28
Historical. Moved to historical list in accordance with SP800-131A Revision 1 Transition (AES/TDES key wrapping). Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode

Certificate

Certificate number2169
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeHardware
EmbodimentMulti-chip standalone
VendorIBM® Corporation · website
Hardware versions00V7133 EC Level M12977 [1], 00V7137 EC Level M12977 [2], 00V7135 EC Level M12977 [3] and 00V7139 EC Level M12977 [4]
Firmware versionsLTO6_DA86.fcp_fh_f.fmrz [1], LTO6_DA86.fcp_hh_f.fmrz [2], LTO6_DA86.sas_fh_f.fmrz [3] and LTO6_DA86.sas_hh_f.fmrz [4]

Module description

The IBM LTO Generation 6 Encrypting Tape Drive provides AES-GCM encryption of customer data recorded to tape. Both encryption and compression are implemented in the hardware for optimum performance. Four different host interface types of the LTO Generation 6 "brick" unit are FIPS certified as a multi-chip, standalone cryptographic module. In customer operation the "brick" unit may be embedded in bridge box or in a canister package for operation in a library.

Security level exceptions

  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES2692, 2693, 2694
DRBG440
RSA1392
SHS2261

Other algorithms

AES (Cert. #2694, key wrapping); RSA (key wrapping; key establishment methodology provides 112 bits of encryption strength)

Validation history

DateTypeLab
2014-06-11InitialLeidos Accredited Testing & Evaluation (AT&E) Lab

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2014-06-11

Source documents