808bits

Huawei AC6605 Wireless Access Controller

FIPS 140-2 certificate #2925 · Huawei Technologies Co., Ltd. · data as of 2026-09-15

Huawei AC6605 Wireless Access Controller, from Huawei Technologies Co., Ltd., holds FIPS 140-2 certificate #2925 at overall level 2. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode and with the tamper-evident seals and external baffles installed as indicated in the Security Policy. The protocols IKEv1, SNMP and TLS shall not be used when operated in FIPS mode.

Certificate

Certificate number2925
StandardFIPS 140-2
Statushistorical
Overall level2
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorHuawei Technologies Co., Ltd. · website
Hardware versionsP/Ns AC6605-26, 99089JEB [Baffles] and 4057-113016 [Tamper-Evident Seals]
Firmware versionsV200R007C10SPC100

Module description

Quoted from the NIST CMVP entry for this certificate.

The Huawei Access Controller (AC) are multi-chip standalone cryptographic modules enclosed in hard, commercial grade metal cases. The cryptographic boundary for these modules is the enclosure. The primary purpose of these modules is to handle the configuration of wireless access-points. The modules provide network interfaces for data input and output.

Security level exceptions

  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A

Approved algorithms (8)

AlgorithmCAVP certificates
AES4408
CKGvendor affirmed
CVL1114
DRBG1421
ECDSA1060
HMAC2930
SHS3634
Triple-DES2375

Other algorithms

Diffe-Hellman (key agreement; key establishment methodology provides 112 bits of encryption strength; non-compliant less than 112 bits of encryption strength); HMAC-SHA-1-96 (HMAC Cert. #2930); NDRNG; AES (non-compliant); Blowfish; DES; HMAC-MD5; IKEv1 KDF (non-compliant); MD5; PBKDF2 (non-compliant); RC4; RSA (non-compliant); SM1; SM3; SM4; SNMP KDF (non-compliant); TLS KDF (non-compliant)

Tested configurations

  • N/A

Validation history

DateTypeLab
2017-06-19InitialUL Verification Services, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2017-06-19

Source documents