808bits

Cisco Systems Libreswan Cryptographic Module

FIPS 140-2 certificate #3534 · Cisco Systems, Inc. · data as of 2026-08-28
Historical. Moved to historical list due to dependency on certificate #2984. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode with module Cisco Systems NSS Module validated to FIPS 140-2 under Cert. #3554 operating in FIPS mode and Cisco FIPS Object Module validated to FIPS 140-2 under Cert. #2984 in FIPS mode.

Certificate

Certificate number3534
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorCisco Systems, Inc. · website
Software versions3.20 and 3.25

Module description

The Cisco Systems Libreswan Cryptographic Module is a software library implementing the cryptographic algorithms. The module provides key derivation for the IKEv1 and IKEv2 protocols.

Security level exceptions

  • Physical Security: N/A
  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
CVLC84
HMACC8, C503
SHSC8, C503

Tested configurations

  • CentOS Linux 7.4 running on Cisco UCS M4 with Intel Xeon E5-2600
  • CentOS Linux 7.4 running on Cisco UCS M5 with Intel Xeon Bronze

Validation history

DateTypeLab
2019-11-02InitialAcumen Security
2020-12-09UpdateAcumen Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2019-11-02, 2020-12-09

Source documents