808bits

Aruba RAP-108 and RAP-109 Wireless Access Points

FIPS 140-2 certificate #3023 · Aruba, a Hewlett Packard Enterprise company · data as of 2026-09-13

Aruba RAP-108 and RAP-109 Wireless Access Points, from Aruba, a Hewlett Packard Enterprise company, holds FIPS 140-2 certificate #3023 at overall level 2. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. SP 800-56Arev3 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode with tamper evident labels installed as indicated in the Security Policy

Certificate

Certificate number3023
StandardFIPS 140-2
Statushistorical
Overall level2
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorAruba, a Hewlett Packard Enterprise company · website
Hardware versions[RAP-108-F1 (HPE SKU JW268A), RAP-108-USF1 (HPE SKU JW269A), RAP-109-F1 (HPE SKU JW274A) and RAP-109-USF1 (HPE SKU JW275A)] with FIPS kit 4011570-01
Firmware versionsArubaOS 6.5.1-FIPS

Module description

Quoted from the NIST CMVP entry for this certificate.

Aruba's 802.11n wired and wireless access points offer the highest performance for mobile devices. In FIPS 140-2 mode, Aruba APs in conjunction with a Mobility Controller support the IEEE 802.11i/WPA2 client standard along with optional Suite B cryptography. Aruba APs also support wireless intrusion detection/prevention services and wireless mesh topologies.

Security level exceptions

  • Mitigation of Other Attacks: N/A

Approved algorithms (10)

AlgorithmCAVP certificates
AES2450, 2677, 2680, 2689
CVL150, 232, 251
DRBG433
ECDSA466, 469
HMAC1663, 1666
KBKDF16
KTS
RSA1376, 1379, 2417
SHS2246, 2249, 3654
Triple-DES1605, 1607

Allowed algorithms

Diffie-Hellman (key agreement; key establishment methodology provides 112 bits of encryption strength); EC Diffie-Hellman (key agreement; key establishment methodology provides 128 or 192 bits of encryption strength); NDRNG

Tested configurations

  • N/A

Validation history

DateTypeLab
2017-09-22InitialLeidos Accredited Testing & Evaluation (AT&E) Lab

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2017-09-22

Source documents