808bits

Citrix ADC MPX

FIPS 140-2 certificate #4043 · Citrix Systems, Inc. · data as of 2026-09-08

Citrix ADC MPX, from Citrix Systems, Inc., holds FIPS 140-2 certificate #4043 at overall level 2. The validation is active, with a sunset date of 2026-09-21. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Active. Sunset date 2026-09-21, 11 days away. This is the FIPS 140-2 sunset: after it, agencies may keep the module only in existing systems.
Caveat: When installed, initialized and configured as specified in Section [3.1.4] of the Security Policy. The module generates cryptographic keys whose strengths are modified by available entropy

Certificate

Certificate number4043
StandardFIPS 140-2
Statusactive
Sunset date2026-09-21
Overall level2
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorCitrix Systems, Inc. · website
Hardware versions8905 FIPS, 8910 FIPS, 8920 FIPS, 15020-50G FIPS, 15030-50G FIPS, 15040-50G FIPS, 15060-50G FIPS, 15080-50G FIPS, 15100-50G FIPS, 15120-50G FIPS
Firmware versions12.1.55.180

Module description

Quoted from the NIST CMVP entry for this certificate.

The MPX product line optimizes delivery of applications over the Internet and private networks. MPX is an application delivery controller (ADC) that performs application-specific traffic analysis to intelligently distribute, optimize, and secure L4-L7 network traffic for web-applications. All these capabilities are combined into a single, integrated appliance for increased productivity, with lower overall total cost of ownership.

Security level exceptions

  • Roles, Services, and Authentication: Level 3

Approved algorithms (11)

AlgorithmCAVP certificates
AESC1565, C1920, C1922
CKGvendor affirmed
CVLC1561, C1562, C1563, C1565, C1920, C1921, C1922
DRBGC1920, C1922
ECDSAC1565, C1920, C1922
HMACC1565, C1920, C1922
KAS-SSCvendor affirmed
PBKDFvendor affirmed
RSAA393, A607, C1565, C1920, C1922
SHSC1565, C1920, C1922
Triple-DESC1920

Allowed algorithms

MD5; NDRNG; RSA (key wrapping; key establishment methodology provides 112 or 128 bits of encryption strength)

Tested configurations

  • N/A

Validation history

DateTypeLab
2021-10-16InitialLightship Security, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2021-10-16

Source documents