Firepower Management Center Virtual VMware Cryptographic Module
Firepower Management Center Virtual VMware Cryptographic Module, from Cisco Systems, Inc., holds FIPS 140-3 certificate #4710 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.
Caveat: Interim Validation. When installed, initialized and configured as specified in section "Secure Operation" of the Security Policy and operated in approved mode. No assurance of the minimum strength of generated SSPs (e.g., keys)
Certificate
| Certificate number | 4710 |
|---|---|
| Standard | FIPS 140-3 |
| Status | historical |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Cisco Systems, Inc. · website |
| Software versions | 7.0.5 |
Module description
Quoted from the NIST CMVP entry for this certificate.
Cisco FMCv Module provides complete and unified management over firewalls, application control, intrusion prevention, URL filtering, and advanced malware protection. Delivering in-depth analysis, streamlined security management across the network and cloud, and accelerated incident investigation and response, working across Cisco and third-party technologies.
Security level exceptions
- Physical security: N/A
- Non-invasive security: N/A
- Mitigation of other attacks: N/A
Approved algorithms (21)
| Algorithm | CAVP certificates |
|---|---|
| AES-CBC | A2952, A3376 |
| AES-GCM | A2952, A3376 |
| Counter DRBG | A2952, A3376 |
| ECDSA KeyGen (FIPS186-4) | A2952, A3376 |
| ECDSA KeyVer (FIPS186-4) | A2952, A3376 |
| ECDSA SigGen (FIPS186-4) | A2952, A3376 |
| ECDSA SigVer (FIPS186-4) | A2952, A3376 |
| HMAC-SHA-1 | A2952, A3376 |
| HMAC-SHA2-256 | A2952, A3376 |
| HMAC-SHA2-384 | A2952, A3376 |
| HMAC-SHA2-512 | A2952, A3376 |
| KDF SSH | A2952, A3376 |
| RSA KeyGen (FIPS186-4) | A2952, A3376 |
| RSA SigGen (FIPS186-4) | A2952, A3376 |
| RSA SigVer (FIPS186-4) | A2952, A3376 |
| Safe Primes Key Generation | A2952, A3376 |
| SHA-1 | A2952, A3376 |
| SHA2-256 | A2952, A3376 |
| SHA2-384 | A2952, A3376 |
| SHA2-512 | A2952, A3376 |
| TLS v1.2 KDF RFC7627 | A2952, A3376 |
Tested configurations
- Linux 4 (FX-OS) on VMware ESXi 6.7 running on UCS C220 M5 SFF Server with Intel Xeon Gold 6128 (Skylake) with PAA
- Linux 4 (FX-OS) on VMware ESXi 6.7 running on UCS C220 M5 SFF Server with Intel Xeon Gold 6128 (Skylake) without PAA
- Linux 4 (FX-OS) on VMware ESXi 7.0 running on UCS C220 M5 SFF Server with Intel Xeon Gold 6128 (Skylake) with PAA
- Linux 4 (FX-OS) on VMware ESXi 7.0 running on UCS C220 M5 SFF Server with Intel Xeon Gold 6128 (Skylake) without PAA
Validation history
| Date | Type | Lab |
|---|---|---|
| 2024-06-17 | Initial | Gossamer Security Solutions |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2024-06-17