SSL Visibility Appliance
SSL Visibility Appliance, from Symantec Corporation, holds FIPS 140-2 certificate #2821 at overall level 2. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.
Certificate
| Certificate number | 2821 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 2 |
| Module type | Hardware |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Symantec Corporation · website |
| Hardware versions | SV3800 [1], SV3800B [2] and SV3800B-20 [3]; 090-03064 [1], 080-03563 [1], 080-03679 [1], 090-03550 [2], 080-03782 [2], 080-03787 [2], 090-03551 [3], 080-03783 [3], and 080-03788 [3] with FIPS Kit: FIPS-LABELS-SV |
| Firmware versions | 3.8.2F build 227, 3.8.4FC, 3.10 build 40 |
Module description
Quoted from the NIST CMVP entry for this certificate.
The SSL Visibility Appliance is designed to detect SSL traffic and then under policy control to "inspect" the traffic. Inspection involves decrypting and re-encrypting the traffic to gain access to the clear text then passing this data to one or more associated security appliance(s) that need to see decrypted traffic.
Security level exceptions
- Design Assurance: Level 3
- Mitigation of Other Attacks: N/A
Approved algorithms (9)
| Algorithm | CAVP certificates |
|---|---|
| AES | 3195, 3496, 4106 |
| CVL | 429, 562, 919 |
| DRBG | 669, 866, 1233 |
| ECDSA | 584, 711, 931 |
| HMAC | 2013, 2230, 2682 |
| PBKDF | vendor affirmed |
| RSA | 1238, 1625, 1794, 2222 |
| SHS | 2052, 2642, 2885, 3378 |
| Triple-DES | 1821, 1968, 2244 |
Other algorithms
Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength; non-compliant less than 112 bits of encryption strength); EC Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength; non-compliant less than 112 bits of encryption strength); NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 256 bits of encryption strength; non-compliant less than 112 bits of encryption strength); Camelia; ChaCha20-Poly1305; DES; HMAC-MD5; MD5; RC4
Tested configurations
- N/A
Validation history
| Date | Type | Lab |
|---|---|---|
| 2017-01-25 | Initial | CGI Information Systems & Management Consultants Inc |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2017-01-25