808bits

FortiWeb 5.6

FIPS 140-2 certificate #3103 · Fortinet, Inc. · data as of 2026-08-28
Historical. SP 800-56Arev3 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode and configured according to the Entropy Token Section of the Security Policy. There is no assurance of the minimum strength of generated keys

Certificate

Certificate number3103
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeFirmware
EmbodimentMulti-Chip Stand Alone
VendorFortinet, Inc. · website
Firmware versionsv5.6.0, build 6180,170928

Module description

The FortiWeb OS is a firmware operating system that runs exclusively on Fortinet's FortiWeb product family. FortiWeb units are PC-based, purpose built appliances.

Security level exceptions

  • Cryptographic Module Ports and Interfaces: Level 3
  • Roles, Services, and Authentication: Level 3
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES4461
CKGvendor affirmed
CVL1169
DRBG1434
HMAC2960
KTS
RSA2437
SHS3673

Allowed algorithms

Diffie-Hellman (CVL Cert. #1169, key agreement; key establishment methodology provides 112 bits of encryption strength); MD5; RSA (CVL Cert. #1169, key wrapping; key establishment methodology provides 112 or 128 bits of encryption strength)

Tested configurations

  • FortiWeb-4000E with the Fortinet entropy token (part number FTR-ENT-1 )

Validation history

DateTypeLab
2018-01-05InitialCGI Information Systems & Management Consultants Inc

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2018-01-05

Source documents