808bits

NetApp Cryptographic Security Module

FIPS 140-2 certificate #2648 · NetApp, Inc. · data as of 2026-08-28
Historical. SP 800-56Arev3 transition - replaced by certificate #4297. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode. No assurance of the minimum strength of generated keys.

Certificate

Certificate number2648
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorNetApp, Inc. · website
Software versions1.0

Module description

The NetApp Cryptographic Security Module is a software library that provides cryptographic services to a vast array of NetApp's storage and networking products.

Security level exceptions

  • Physical Security: N/A
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES3593, A950
CKGvendor affirmed
CVL615, A950
DRBG928, A950
DSA998, A950
ECDSA732, A950
HMAC2290, A950
RSA1847, A950
SHS2955, A950
Triple-DES2000, A950

Other algorithms

Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 219 bits of encryption strength); EC Diffie-Hellman (CVL Certs. #615 and #A950, key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength); RSA (key wrapping; key establishment methodology provides between 112 and 150 bits of encryption strength)

Tested configurations

  • Debian Linux 8 running on Fujitsu RX200S5 Server with Intel Xeon E5-2609V4 (Broadwell) with PAA
  • Debian Linux 8 running on Fujitsu RX300-S6 Server with Intel Xeon E5645 (Westmere EP) without PAA
  • FreeBSD 9.1 running on Fujitsu RX200S5 Server with Intel Xeon E5-2609V4 (Broadwell) with PAA
  • FreeBSD 9.1 running on Fujitsu RX300-S6 Server with Intel Xeon E5645 (Westmere EP) without PAA
  • ONTAP 9.7P6 running on FAS2650 with Intel Xeon D-1528 with PAA
  • ONTAP 9.7P6 running on FAS2650 with Intel Xeon D-1528 without PAA
  • ONTAP 9.7P6 running on NetApp AFF A800 with Intel Xeon Platinum 8160 with PAA
  • ONTAP 9.7P6 running on NetApp AFF A800 with Intel Xeon Platinum 8160 without PAA
  • ONTAP 9.7P6 running on NetApp FAS8300 with Intel Xeon Silver 4210 with PAA
  • ONTAP 9.7P6 running on NetApp FAS8300 with Intel Xeon Silver 4210 without PAA
  • ONTAP 9.7P6 running on NetApp FAS9000 with Intel Xeon E5-2697 with PAA
  • ONTAP 9.7P6 running on NetApp FAS9000 with Intel Xeon E5-2697 without PAA (single-user mode)
  • Scientific Linux 6.1 running on Fujitsu RX200S5 Server with Intel Xeon E5-2609V4 (Broadwell) with PAA
  • Scientific Linux 6.1 running on Fujitsu RX300-S6 Server with Intel Xeon E5645 (Westmere EP) without PAA
  • SUSE Linux 11 running on Fujitsu RX200S5 Server with Intel Xeon E5-2609V4 (Broadwell) with PAA
  • SUSE Linux 11 running on Fujitsu RX300-S6 Server with Intel Xeon E5645 (Westmere EP) without PAA

Validation history

DateTypeLab
2016-05-27InitialAcumen Security
2016-06-10UpdateAcumen Security
2019-10-29UpdateAcumen Security
2021-02-10UpdateAcumen Security
2021-07-20UpdateAcumen Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2016-05-27, 2016-06-10, 2019-10-29, 2021-02-10, 2021-07-20

Source documents