808bits

ExtraHop Cryptographic Module

FIPS 140-3 certificate #4561 · ExtraHop Networks, Inc. · data as of 2026-08-28
Revoked. Non-conformance to the FIPS 140-3 standard identified.
Caveat: When operated in approved mode. No assurance of the minimum strength of generated keys

Certificate

Certificate number4561
StandardFIPS 140-3
Statusrevoked
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorExtraHop Networks, Inc. · website
Software versions1.0

Module description

The ExtraHop Cryptographic Module 1.0 is a cryptographic library embedded in the ExtraHop Reveal(x) 360 application software. The ExtraHop Cryptographic Module 1.0 offers symmetric encryption/decryption, digital signature generation/verification, hashing, cryptographic key generation, random number generation, message authentication, and key establishment functions to secure data-at-rest/data-in-flight and to support secure communications protocols (including SSH and TLS 1.2/1.3).

Security level exceptions

  • Physical security: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES-CBCA2293
AES-CCMA2293
AES-CFB1A2293
AES-CFB128A2293
AES-CFB8A2293
AES-CMACA2293
AES-CTRA2293
AES-ECBA2293
AES-GCMA2293
AES-GMACA2293
AES-KWA2293
AES-KWPA2293
AES-OFBA2293
AES-XTSA2293
Counter DRBGA2293
DSA KeyGen (FIPS186-4)A2293
DSA PQGGen (FIPS186-4)A2293
DSA PQGVer (FIPS186-4)A2293
DSA SigVer (FIPS186-4)A2293
ECDSA KeyGen (FIPS186-4)A2293
ECDSA KeyVer (FIPS186-4)A2293
ECDSA SigVer (FIPS186-4)A2293
HMAC-SHA-1A2293
HMAC-SHA2-224A2293
HMAC-SHA2-256A2293
HMAC-SHA2-384A2293
HMAC-SHA2-512A2293
HMAC-SHA3-224A2293
HMAC-SHA3-256A2293
HMAC-SHA3-384A2293
HMAC-SHA3-512A2293
KAS-ECC-SSC Sp800-56Ar3A2293
KAS-FFC-SSC Sp800-56Ar3A2293
KDA HKDF SP800-56Cr2A2293
KDF SSHA2293
KDF TLSA2293
PBKDFA2293
RSA KeyGen (FIPS186-4)A2293
RSA SigGen (FIPS186-4)A2293
RSA SigVer (FIPS186-4)A2293
SHA-1A2293
SHA2-224A2293
SHA2-256A2293
SHA2-384A2293
SHA2-512A2293
SHA3-224A2293
SHA3-256A2293
SHA3-384A2293
SHA3-512A2293
SHAKE-128A2293
SHAKE-256A2293
TDES-CBCA2293
TDES-CFB1A2293
TDES-CFB64A2293
TDES-CFB8A2293
TDES-CMACA2293
TDES-ECBA2293
TDES-OFBA2293
TLS v1.2 KDF RFC7627A2293
TLS v1.3 KDFA2294

Allowed algorithms

AES (Cert. #A2293) (Key establishment methodology provides between 112 and 256 bits of encryption strength.; Key unwrapping (using any approved mode));RSA (Cert. #A2293) (Key establishment methodology provides between 112 and 256 bits of encryption strength.; Key transport );SHA-1 (Cert. #A2293) (-; Digital signature generation in TLS );Triple-DES (Cert. #A2293) (Key establishment methodology provides 112 bits of encryption strength.; Key unwrapping (using any approved mode with two-key or three-key))

Tested configurations

  • ExtraHop OS 8.6 on VMware ESXi 6.7 running on Dell PowerEdge R640-XL with Intel Xeon Silver 4110 with PAA
  • ExtraHop OS 8.6 on VMware ESXi 6.7 running on Dell PowerEdge R640-XL with Intel Xeon Silver 4110 without PAA
  • ExtraHop OS 8.6 on VMware ESXi 7.0 running on Dell PowerEdge R740 with Intel Xeon Silver 4110 with PAA
  • ExtraHop OS 8.6 on VMware ESXi 7.0 running on Dell PowerEdge R740 with Intel Xeon Silver 4110 without PAA
  • ExtraHop OS 8.6 running on EDA 8200 appliance with Intel Xeon Silver 4110 with PAA
  • ExtraHop OS 8.6 running on EDA 8200 appliance with Intel Xeon Silver 4110 without PAA

Validation history

DateTypeLab
2023-08-28InitialLightship Security, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status revoked
  • Validation dates on record: 2023-08-28

Source documents