808bits

Aruba 3000 and 6000/M3 Mobility Controllers with ArubaOS FIPS Firmware

FIPS 140-2 certificate #2224 · Hewlett Packard®, Enterprise · data as of 2026-09-03

Aruba 3000 and 6000/M3 Mobility Controllers with ArubaOS FIPS Firmware, from Hewlett Packard®, Enterprise, holds FIPS 140-2 certificate #2224 at overall level 2. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. 186-2 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode with tamper evident labels installed as indicated in the Security Policy clause "Installing the Controller" and the 6000/M3 configured as specified in Security Policy clause "Minimum Configuration for the Aruba 6000-400"

Certificate

Certificate number2224
StandardFIPS 140-2
Statushistorical
Overall level2
Module typeHardware
EmbodimentMulti-chip standalone
VendorHewlett Packard®, Enterprise · website
Hardware versionsAruba 3200-F1, Aruba 3200-USF1, Aruba 3400-F1, Aruba 3400-USF1, Aruba 3600-F1, Aruba 3600-USF1 and [(Aruba 6000-400-F1 or Aruba 6000-400-USF1) with M3mk1-S-F1, HW-PSU-200 or HW-PSU-400, LC-2G-1, LC-2G24F-1 or LC-2G24FP-1] with FIPS kit 4011570-01
Firmware versionsArubaOS 6.4.4-FIPS

Module description

Quoted from the NIST CMVP entry for this certificate.

Aruba's family of Mobility Controllers are network infrastructure devices providing secure, scalable solutions for enterprise Wi-Fi, network security policy enforcement, VPN services, and wireless intrusion detection and prevention. Mobility controllers serve as central points of authentication, encryption, access control, and network coordination for all mobile network services.

Security level exceptions

  • Mitigation of Other Attacks: N/A

Approved algorithms (9)

AlgorithmCAVP certificates
AES762, 2677, 2680
CVL150, 152
DRBG433
ECDSA466, 469
HMAC417, 1663, 1666
KBKDF16
RSA1376, 1379, 1380
SHS769, 2246, 2249, 2250
Triple-DES667, 1605, 1607

Other algorithms

DES; Diffie-Hellman (key agreement; key establishment methodology provides 112 bits of encryption strength; non-compliant less than 112 bits of encryption strength); EC Diffie-Hellman (key agreement; key establishment methodology provides 128 or 192 bits of encryption strength); HMAC-MD5; MD5; NDRNG; RC4; RSA (key wrapping; key establishment methodology provides 112 bits of encryption strength; non-compliant less than 112 bits of encryption strength)

Validation history

DateTypeLab
2014-08-12InitialLeidos Accredited Testing & Evaluation (AT&E) Lab
2015-03-20UpdateLeidos Accredited Testing & Evaluation (AT&E) Lab
2016-01-20UpdateLeidos Accredited Testing & Evaluation (AT&E) Lab

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2014-08-12, 2015-03-20, 2016-01-20

Source documents