808bits

Aruba IAP-303H, IAP-304, IAP-305, IAP-314, IAP-315, IAP-324, IAP-325, IAP-334, and IAP-335 Wireless Access Points with Aruba Instant Firmware

FIPS 140-2 certificate #3899 · Aruba, a Hewlett Packard Enterprise company · data as of 2026-08-28
Historical. SP 800-56Arev3 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode. When installed, initialized and configured as specified in Section 13 of the Security Policy. The tamper evident labels installed as indicated in the security policy. The module generates cryptographic keys whose strengths are modified by available entropy

Certificate

Certificate number3899
StandardFIPS 140-2
Statushistorical
Overall level2
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorAruba, a Hewlett Packard Enterprise company · website
Hardware versions[IAP-303H-US TAA (HPE SKU JY681A), IAP-304-US TAA (HPE SKU JX944A), IAP-305-US TAA (HPE SKU JX950A), IAP-314-US TAA (HPE SKU JW808A), IAP-315-US TAA (HPE SKU JW814A), IAP-324-US TAA (HPE SKU JW322A), IAP-325-US TAA (HPE SKU JW328A), IAP-334-US TAA (HPE SKU JW820A), IAP-335-US TAA (HPE SKU JW826A)] with FIPS Kit 4011570-01 (HPE SKU JY894A)
Firmware versionsArubaInstant 8.5.0.12

Module description

Aruba's Wi-Fi Instant Access Points operate at gigabit speeds, offering extreme performance for mobile devices. In FIPS 140-2 mode, Aruba IAPs support the IEEE 802.11i/WPA2 client standard. Aruba APs also support wireless intrusion detection/prevention services and wireless mesh topologies. The built-in GUI provides access to live monitoring and traffic visibility, while network configuration provides full customization of SSIDs, roles, guest access, and more.

Approved algorithms

AlgorithmCAVP certificate
AES5412, C564, C565
CVLC564, C565
DRBGC565
HMACC564, C565
KBKDFC565
KTS
KTS
RSAC563, C564, C565
SHSC563, C564, C565

Allowed algorithms

Diffie-Hellman (key agreement; key establishment methodology provides 112 bits of encryption strength); EC Diffie-Hellman (key agreement; key establishment methodology provides 128 or 192 bits of encryption strength); NDRNG; RSA (key wrapping; key establishment methodology provides 112 bits of encryption strength)

Tested configurations

  • N/A

Validation history

DateTypeLab
2021-04-19InitialLeidos Accredited Testing & Evaluation (AT&E) Lab

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2021-04-19

Source documents