Cisco Systems Libreswan Cryptographic Module
Caveat: When operated in FIPS mode with module Cisco Systems NSS Module validated to FIPS 140-2 under Cert. #3554 operating in FIPS mode and Cisco FIPS Object Module validated to FIPS 140-2 under Cert. #2984 in FIPS mode.
Certificate
| Certificate number | 3534 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Cisco Systems, Inc. · website |
| Software versions | 3.20 and 3.25 |
Module description
The Cisco Systems Libreswan Cryptographic Module is a software library implementing the cryptographic algorithms. The module provides key derivation for the IKEv1 and IKEv2 protocols.
Security level exceptions
- Physical Security: N/A
- Mitigation of Other Attacks: N/A
Approved algorithms
Tested configurations
- CentOS Linux 7.4 running on Cisco UCS M4 with Intel Xeon E5-2600
- CentOS Linux 7.4 running on Cisco UCS M5 with Intel Xeon Bronze
Validation history
| Date | Type | Lab |
|---|---|---|
| 2019-11-02 | Initial | Acumen Security |
| 2020-12-09 | Update | Acumen Security |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2019-11-02, 2020-12-09