808bits

Cisco FIPS Object Module

FIPS 140-2 certificate #3341 · Cisco Systems, Inc. · data as of 2026-08-28
Historical. SP 800-56Arev3 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When installed, initialized and configured as specified in the Security Policy Section 4.2 and operated in FIPS mode. No assurance of the minimum strength of generated keys

Certificate

Certificate number3341
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorCisco Systems, Inc. · website
Software versions7.0; 7.0a

Module description

The Cisco FIPS Object Module (FOM) is a software library that provides cryptographic services to a vast array of Cisco's networking and collaboration products. The module provides FIPS 140 validated cryptographic algorithms for services such as IPSEC, SRTP, SSH, TLS, 802.1x, etc. The module does not directly implement any of these protocols, instead it provides the cryptographic primitives and functions to allow a developer to implement the various protocols.

Security level exceptions

  • Physical Security: N/A
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES5310
CKGvendor affirmed
CVL1779, 1780
DRBG2048
DSA1374
ECDSA1395
HMAC3513
KBKDF186
KTS
RSA2845
SHS4267
Triple-DES2685

Allowed algorithms

Diffie-Hellman (CVL Cert. #1779 with CVL Cert. #1780, key agreement; key establishment methodology provides between 112 and 219 bits of encryption strength); EC Diffie-Hellman (CVL Cert. #1779 with CVL Cert. #1780, key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength); MD5; RSA (key wrapping; key establishment methodology provides between 112 and 132 bits of encryption strength)

Tested configurations

  • Android 7.1 running on Google Nexus 5x with ARMv8 without PAA
  • iOS 11.2 running on Apple iPhone 8 with ARMv8 without PAA
  • macOS 10.12 on a MacBook Pro with Intel Core i7 with PAA
  • macOS 10.12 on a MacBook Pro with Intel Core i7 without PAA
  • SUSE Linux Enterprise 11 on Vmware ESXi 6.0 running on Cisco UCSC-C220-M5SX with Intel Xeon Bronze without PAA
  • SUSE Linux Enterprise 11 running on Cisco UCSC-C220-M5SX with Intel Xeon Bronze with PAA
  • Wind River Linux 4 running on a Advantech NCP-3110 with Cavium Octeon II 68XX without PAA
  • Wind River Linux 5 running on a Cisco N3K-C3172PQ-10GE with Intel Pentium without PAA (single-user mode)
  • Windows 10 on a Lenovo ThinkCentre M900 with Intel Core i5 with PAA
  • Windows 10 on a Lenovo ThinkCentre M900 with Intel Core i5 without PAA

Validation history

DateTypeLab
2018-12-17InitialAcumen Security
2019-05-09UpdateAcumen Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2018-12-17, 2019-05-09

Source documents