Arista EOS Crypto Module
Caveat: When operated in FIPS mode
Certificate
| Certificate number | 4019 |
|---|---|
| Standard | FIPS 140-2 |
| Status | active |
| Sunset date | 2026-08-29 |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Arista Networks, Inc. · website |
| Software versions | v2.0 |
Module description
Arista’s crypto library is a comprehensive suite of FIPS Approved algorithms. Many key sizes and modes have been implemented to allow flexibility and efficiency.
Security level exceptions
- Physical Security: N/A
- Mitigation of Other Attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | C1859 |
| CVL | C1859 |
| DRBG | C1859 |
| DSA | C1859 |
| ECDSA | C1859 |
| HMAC | C1859 |
| RSA | C1859 |
| SHS | C1859 |
| Triple-DES | C1859 |
Allowed algorithms
MD5; NDRNG; RSA (key wrapping; key establishment methodology provides 112 or 128 bits of encryption strength)
Tested configurations
- EOSv4 on Arista CCS-720XP-24Y6 with AMD G-Series GX-224 (Crowned Eagle)
- EOSv4 on Arista CCS-720XP-24ZY4 with AMD G-Series GX-224 (Crowned Eagle)
- EOSv4 on Arista CCS-720XP-48Y6 with AMD G-Series GX-224 (Crowned Eagle)
- EOSv4 on Arista CCS-720XP-48ZC2 with AMD G-Series GX-224 (Crowned Eagle)
- EOSv4 on Arista CCS-720XP-96ZC2 with AMD R-Series RX-216 (Merlin Falcon)
- EOSv4 on Arista CCS-750-Sup25 with Intel Xeon D-1527 (Broadwell) (single-user mode)
Validation history
| Date | Type | Lab |
|---|---|---|
| 2021-08-30 | Initial | CYGNACOM SOLUTIONS INC |
| 2021-11-01 | Update | CYGNACOM SOLUTIONS INC |
| 2023-01-17 | Update | DEKRA Cybersecurity Certification Laboratory |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2021-08-30, 2021-11-01, 2023-01-17