808bits

HPE LTO-7 and LTO-8 Encrypting Tape Drive

FIPS 140-2 certificate #3282 · Hewlett Packard Enterprise · data as of 2026-09-12

HPE LTO-7 and LTO-8 Encrypting Tape Drive, from Hewlett Packard Enterprise, holds FIPS 140-2 certificate #3282 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode. No assurance of the minimum strength of generated keys

Certificate

Certificate number3282
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorHewlett Packard Enterprise · website
Hardware versionsAQ308A#103 [1], AQ303A#103 [2], AQ338A#103 [3], AQ333A#103 [4]
Firmware versionsLTO_15000_FC_G986_MSL_S.frm [1], LTO_15000_SAS_G986_MSL_S.frm [2], LTO_30750_FC_J4DB_MSL_S.frm [3], LTO_30750_SAS_J4DB_MSL_S.frm [4]

Module description

Quoted from the NIST CMVP entry for this certificate.

The HPE LTO-7 and LTO-8 Ultrium tape drives represent Hewlett Packard Enterprise's seventh and eight generations of LTO tape drive technology, capable of storing up to 15TB (LTO-7 compressed 2.5:1) and 30TB (LTO-8 compressed 2.5:1) per cartridge while providing AES 256-bit hardware data encryption to protect the most sensitive data and prevent unauthorized access of tape cartridges. Capable of data transfer rates up to 300 MB/sec (native), its Speed Matching feature further optimizes performance by matching the speed of the host to keep drives streaming and increase the reliability of the drive and media. The HPE LTO-7 and LTO-8 Ultrium tape drives are available as standalone internal and desktop devices or for integration into HPE MSL autoloaders and tape libraries.

Security level exceptions

  • Mitigation of Other Attacks: N/A

Approved algorithms (6)

AlgorithmCAVP certificates
AES3357, 3358, 4810
CKGvendor affirmed
DRBG1672
KTS
RSA2634
SHS3954

Allowed algorithms

NDRNG; RSA (key wrapping; key establishment methodology provides 112 bits of encryption strength)

Tested configurations

  • N/A

Validation history

DateTypeLab
2018-09-12InitialLeidos Accredited Testing & Evaluation (AT&E) Lab
2019-04-08UpdateLeidos Accredited Testing & Evaluation (AT&E) Lab

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2018-09-12, 2019-04-08

Source documents