808bits

EOS MACsec Bravo Hybrid Module

FIPS 140-2 certificate #3420 · Arista Networks Inc. · data as of 2026-08-28
Historical. SP 800-56Arev3 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode and installed, initialized and configured as specified in Section 8.1 of the Security Policy

Certificate

Certificate number3420
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeFirmware-Hybrid
EmbodimentMulti-Chip Stand Alone
VendorArista Networks Inc.
Hardware versionsP/Ns Credo MACsec chip CMX42550 and Renesas Security chip R5H30211 or N313X; Chassis: DCS-7508N, Version 06.00; DCS-7512N, Version 00.06; DCS-7516N, Version 10.00; Supervisor: DCS-7500E-SUP, Version 01.02; DCS-7500-SUP2, Version 03.03; DCS-7516-SUP2, Version 10.00; Linecard: DCS-7500R2M-36CQ-LC, Version 21.01; Fixed Hardware: DCS-7280SRAM-48C6, Version 21.00; DCS-7280SRM-40CX2, Version 21.00; DCS-7280CR2M-30, Version 20.01
Firmware versions1.0

Module description

Arista’s crypto library is a comprehensive suite of FIPS Approved algorithms. Many key sizes and modes have been implemented to allow flexibility and efficiency.

Security level exceptions

  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES4471, 5482
CKGvendor affirmed
CVL1933, 1934, 1935
DRBG2158
ECDSA1469
HMAC3636
KAS183
KBKDF235
KTS
RSA2944
SHS4399

Allowed algorithms

Diffie-Hellman (CVL Cert. #1933, key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength); EC Diffie-Hellman (CVL Cert. #1933, key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength); MD5; NDRNG; RSA (CVL Cert. #1934, key wrapping; key establishment methodology provides between 112 and 128 bits of encryption strength)

Tested configurations

  • Arista Networks DCS-7280CR2M-30 with Credo MACsec chip CMX42550 and EOSv4 Firmware Version 1.0 (single-user mode)
  • Arista Networks DCS-7280SRAM-48C6 with Credo MACsec chip CMX42550 and EOSv4 Firmware Version 1.0
  • Arista Networks DCS-7280SRM-40CX2 with Credo MACsec chip CMX42550 and EOSv4 Firmware Version 1.0
  • Arista Networks DCS-7500E-SUP 01.02 with EOSv4 Firmware Version 1.0
  • Arista Networks DCS-7500R2M-36CQ-LC 21.01 with Credo MACsec chip CMX42550
  • Arista Networks DCS-7500-SUP2 03.03 with EOSv4 Firmware Version 1.0
  • Arista Networks DCS-7508N Chassis 06.00
  • Arista Networks DCS-7512N Chassis 00.06
  • Arista Networks DCS-7516N Chassis 10.00
  • Arista Networks DCS-7516-SUP2 10.00 with EOSv4 Firmware Version 1.0

Validation history

DateTypeLab
2019-03-27InitialUL Verification Services, Inc.
2019-04-09UpdateUL Verification Services, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2019-03-27, 2019-04-09

Source documents