808bits

HP BladeSystem Onboard Administrator Firmware

FIPS 140-2 certificate #2174 · Hewlett-Packard Development Company, L.P. · data as of 2026-09-08

HP BladeSystem Onboard Administrator Firmware, from Hewlett-Packard Development Company, L.P., holds FIPS 140-2 certificate #2174 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. RNG SP800-131A Revision 1 Transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When installed, initialized and configured as indicated in the Security Policy in Section 3 and operated in FIPS mode.

Certificate

Certificate number2174
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeFirmware
EmbodimentMulti-chip standalone
VendorHewlett-Packard Development Company, L.P. · website
Firmware versions3.71

Module description

Quoted from the NIST CMVP entry for this certificate.

The module provides administrative control of HP BladeSystem c-Class enclosures. The cryptographic functions of the module provide security for administrative access via HTTPS and SSH, and to administrative commands for the BladeSystem enclosure.

Security level exceptions

  • Mitigation of Other Attacks: N/A
  • Tested: BladeSystem c7000 DDR2 Onboard Administrator with KVM option enclosure
  • BladeSystem c3000 Tray with Embedded DDR2 Onboard Administrator enclosure
  • BladeSystem c3000 Dual DDR2 Onboard Administrator enclosure

Approved algorithms (6)

AlgorithmCAVP certificates
AES2289
HMAC1406
RNG1140
RSA1178
SHS1972, 1973
Triple-DES1439

Other algorithms

NDRNG; DSA; RC4; HMAC-SHA1-96; Diffie-Hellman (key agreement; key establishment methodology provides 112 bits of encryption strength; non-compliant less than 112 bits of encryption strength); MD5; RSA (key wrapping; key establishment methodology provides 112 bits of encryption strength; non-compliant less than 112 bits of encryption strength)

Validation history

DateTypeLab
2014-06-17InitialCGI Information Systems & Management Consultants Inc

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2014-06-17

Source documents