808bits

Juniper Networks SRX5400, SRX5600, and SRX5800 Services Gateways

FIPS 140-2 certificate #2926 · Juniper Networks, Inc. · data as of 2026-09-03

Juniper Networks SRX5400, SRX5600, and SRX5800 Services Gateways, from Juniper Networks, Inc., holds FIPS 140-2 certificate #2926 at overall level 2. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode and with the tamper-evident seals installed as indicated in the Security Policy

Certificate

Certificate number2926
StandardFIPS 140-2
Statushistorical
Overall level2
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorJuniper Networks, Inc. · website
Hardware versionsSRX5400, SRX5600, and SRX5800 with components identified in Security Policy Table 1
Firmware versionsJUNOS-FIPS 12.3X48-D30

Module description

Quoted from the NIST CMVP entry for this certificate.

Juniper Networks SRX Series Services Gateways provide the essential capabilities necessary to connect, secure, and manage enterprise and service provider networks, from the smallest sites to the largest headquarters and data centers.

Security level exceptions

  • Roles, Services, and Authentication: Level 3
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A

Approved algorithms (10)

AlgorithmCAVP certificates
AES4054, 4055, 4056, 4070, 4329
CVL880, 926
DRBG1216, 1399, 1401
DSA1096, 1103, 1104
ECDSA909, 916, 917
HMAC2646, 2647, 2648, 2657, 2867
KTS
RSA2087, 2201, 2202
SHS3341, 3342, 3343, 3353, 3571
Triple-DES2221, 2222, 2223, 2224

Other algorithms

Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 192 bits of encryption strength); EC Diffie-Hellman (key agreement; key establishment methodology provides 128 or 192 bits of encryption strength); NDRNG; ARCFOUR; Blowfish; CAST; HMAC-MD5; HMAC-RIPEMD160; UMAC

Tested configurations

  • N/A

Validation history

DateTypeLab
2017-06-19InitialUL Verification Services, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2017-06-19

Source documents