808bits

iLO 3 Cryptographic Module

FIPS 140-2 certificate #2173 · Hewlett-Packard Development Company, L.P. · data as of 2026-09-03

iLO 3 Cryptographic Module, from Hewlett-Packard Development Company, L.P., holds FIPS 140-2 certificate #2173 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When installed, initialized and configured as specified in the Security Policy Section 3 and operated in FIPS mode

Certificate

Certificate number2173
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeHardware
EmbodimentMulti-chip embedded
VendorHewlett-Packard Development Company, L.P. · website
Hardware versionsGLP: 531510-003 [1] and GXE: 438893-503 [2]; Flash Memory: (41050DL00-233-G [1,2]); NVRAM: (420102C00-244-G [1,2]); DDR3 SDRAM: (42020BJ00-216-G [1]); DDR2 SDRAM: (459715-002 [2])
Firmware versions1.50

Module description

Quoted from the NIST CMVP entry for this certificate.

HP Integrated Lights-Out (iLO) management built into BladeSystem blade servers and storage blades is an autonomous management subsystem embedded directly on the server. iLO monitors each server’s overall "health", reports issues, and provides a means for setup and managing of power and thermal settings.

Security level exceptions

  • Mitigation of Other Attacks: N/A

Approved algorithms (6)

AlgorithmCAVP certificates
AES2294, 2295, 2296, 2297, 2298
DSA720
HMAC1410
RSA1182, 1183
SHS1977, 1978, 1979
Triple-DES1443, 1444, 1445

Other algorithms

RC2; RC4; HMAC-MD5; DES; MD5; RSA (non-compliant); DSA (non-compliant); RNG (non-compliant); Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 128 bits of encryption strength; non-compliant less than 112-bits of encryption strength); TLSv1.0 KDF; TLSv1.1 KDF

Validation history

DateTypeLab
2014-06-17InitialCGI Information Systems & Management Consultants Inc

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2014-06-17

Source documents