808bits

Aruba 2930M, 3810M and 5400R zl2 Switch Series

FIPS 140-2 certificate #4571 · Aruba, a Hewlett Packard Enterprise Company · data as of 2026-09-13

Aruba 2930M, 3810M and 5400R zl2 Switch Series, from Aruba, a Hewlett Packard Enterprise Company, holds FIPS 140-2 certificate #4571 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode

Certificate

Certificate number4571
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorAruba, a Hewlett Packard Enterprise Company · website
Hardware versionsAruba 2930M Switches (JL319A, JL320A, JL321A, JL322A, JL323A, and JL324A) [1] with Expansion Cards listed in Table 2 of the Security Policy, Aruba 3810M Switches (JL071A, JL072A, JL073A, JL074A, JL075A, and JL076A) [2] with Expansion Cards listed in Table 3 of the Security Policy, Aruba 5400R zl2 Switches (5406R zl2 J9821A and 5412R zl2 J9822A) [3] with Management card and Interface Cards listed in Table 4 of the Security Policy
Firmware versionsWC.16.11 [1] and KB.16.11 [2] or [3]

Module description

Quoted from the NIST CMVP entry for this certificate.

The Aruba 2930M and 3810M Switch Series are designed for customers creating digital workplaces that are optimized for mobile users with an integrated wired and wireless approach. These Layer 3 access switches support 10GbE and 40GbE uplinks, Dual Modular Power Supplies, full PoE+, HPE Smart Rate, ACLs, robust QoS, RIP, OSPF routing, Tunnel Node, PIM, VRRP and IPv6. The Aruba 5400R zl2 Switch Series is an industry-leading mobile campus access chassis solution with HPE Smart Rate multi-gigabit ports.

Security level exceptions

  • Roles, Services, and Authentication: Level 3
  • Design Assurance: Level 2
  • Mitigation of Other Attacks: N/A

Approved algorithms (11)

AlgorithmCAVP certificates
AESA2638
CKGvendor affirmed
CVLA2638
DRBGA2638
ECDSAA2638
HMACA2638
KAS
KAS-SSCA2638
RSAA2638
SHSA2638
Triple-DESA2638

Allowed algorithms

HMAC-MD5; MD5; NDRNG; RSA (key wrapping; key establishment methodology provides 112 or 128 bits of encryption strength)

Tested configurations

  • N/A

Validation history

DateTypeLab
2023-08-31InitialGossamer Security Solutions

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2023-08-31

Source documents