808bits

Octopus Authentication Server Cryptographic Module

FIPS 140-2 certificate #4175 · Secret Double Octopus · data as of 2026-08-28
Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode. No assurance of the minimum strength of generated keys.

Certificate

Certificate number4175
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorSecret Double Octopus · website
Software versions1.0

Module description

The Octopus Authentication Server manages the authentication requests and the connection to the application on the mobile device to get the user approval.

Security level exceptions

  • Roles, Services, and Authentication: Level 2
  • Physical Security: N/A
  • Design Assurance: Level 3
  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AESC1651
CKGvendor affirmed
DRBGC1651
DSAC1651
ECDSAC1651
HMACC1651
KAS-SSCvendor affirmed
RSA
SHSC1651
Triple-DESC1651

Allowed algorithms

RSA (key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength)

Tested configurations

  • Oracle® Linux 7.6 64 bit running on Oracle® X7-2 Server with Intel® Xeon® Silver 4114 with PAA
  • Oracle® Linux 7.6 64 bit running on Oracle® X7-2 Server with Intel® Xeon® Silver 4114 without PAA (single-user mode)

Validation history

DateTypeLab
2022-03-13InitialAcumen Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2022-03-13

Source documents