808bits

Cisco FIPS Object Module

FIPS 140-2 certificate #2505 · Cisco Systems, Inc. · data as of 2026-08-28
Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When installed, initialized and configured as specified in the Security Policy Section 4.2 and operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy.

Certificate

Certificate number2505
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorCisco Systems, Inc. · website
Software versions6.0

Module description

The Cisco FIPS Object Module (FOM) is a software library that provides cryptographic services to a vast array of Cisco's networking and collaboration products. The module provides FIPS 140 validated cryptographic algorithms for services such as IPSEC, SRTP, SSH, TLS, 802.1x, etc. The module does not directly implement any of these protocols, instead it provides the cryptographic primitives and functions to allow a developer to implement the various protocols.

Security level exceptions

  • Physical Security: N/A
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES3404, 3405
CVL504, 505, 506, 507
DRBG817, 818
DSA961, 962
ECDSA678, 679
HMAC2172, 2173
KBKDF52, 53
RSA1743, 1744
SHS2817, 2818
Triple-DES1926, 1927

Other algorithms

Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 219 bits of encryption strength; non-compliant less than 112 bits of encryption strength); EC Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength; non-compliant less than 112 bits of encryption strength); RSA (key wrapping; key establishment methodology provides between 112 and 150 bits of encryption strength; non-compliant less than 112 bits of encryption strength)

Tested configurations

  • Android v4.4 running on a Qualcomm Snapdragon Pro APQ8064 ARMv7 on a Google Nexus 4
  • FreeBSD 9.2 running on an Intel Xeon on a Cisco UCS C200 M2 (single-user mode)
  • Linux 2.6 running on an Intel Xeon on a Cisco UCS C22 M3
  • Linux 2.6 running on an Octeon Evaluation Board CN5645 on a Cisco WLC 5508 with Octeon
  • Linux 2.6 running on an Octeon Evaluation Board CN5645 on a Cisco WLC 5508 without Octeon
  • Windows 8.1 running on an Intel Core i7 on a Gateway FX6860 with PAA
  • Windows 8.1 running on an Intel Core i7 on a Gateway FX6860 without PAA

Validation history

DateTypeLab
2015-12-21InitialCGI Information Systems & Management Consultants Inc

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2015-12-21

Source documents