808bits

FortiAnalyzer 6.2

FIPS 140-2 certificate #4361 · Fortinet, Inc. · data as of 2026-08-28
Active. Sunset date 2026-09-21, 23 days away. This is the FIPS 140-2 sunset: after it, agencies may keep the module only in existing systems.
Caveat: When operated in FIPS mode and installed, initialized and configured as specified in the FIPS 140-2 Compliant Operation Section of the Security Policy with the entropy token installed as indicated in the Security Policy. Authentication at level 3 is only applicable when identity-based authentication is enforced for the User role. No assurance of the minimum strength of generated keys

Certificate

Certificate number4361
StandardFIPS 140-2
Statusactive
Sunset date2026-09-21
Overall level1
Module typeFirmware
EmbodimentMulti-Chip Stand Alone
VendorFortinet, Inc. · website
Firmware versionsFortiAnalyzer v6.2, build9599

Module description

The FortiAnalyzer family of logging, analyzing, and reporting appliances securely aggregate log data from Fortinet devices and other syslog-compatible devices. Using a comprehensive suite of customizable reports, users can filter and review records, including traffic, event, virus, attack, Web content, and email data.

Security level exceptions

  • Roles, Services, and Authentication: Level 3
  • Design Assurance: Level 2
  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AESA1062, C1908, C2013
CVLC2013
DRBGC1985
ECDSAA1062
HMACC2013
KAS
KAS-SSCA1062
KTS
KTS
RSAA1062, C2013
SHSC2013

Tested configurations

  • FortiAnalyzer-3500G with Intel® Xeon® Gold 5118 processor

Validation history

DateTypeLab
2022-11-09InitialLightship Security, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2022-11-09

Known CVEs in this module family (heuristic match)

Name-based association with the module's product family, not a statement about the validated boundary. See methodology.

Source documents