Adaptive Security Appliance Virtual Cryptographic Module
Caveat: Interim Validation. When installed, initialized and configured as specified in section "Secure Operation" of the Security Policy and operated in approved mode. No assurance of the minimum strength of generated SSPs (e.g., keys)
Certificate
| Certificate number | 4712 |
|---|---|
| Standard | FIPS 140-3 |
| Status | historical |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Cisco Systems, Inc. · website |
| Software versions | 9.16.4 |
Module description
Virtual Adaptive Security Appliances offers the combination of the industry's most deployed stateful firewall with a comprehensive range of next-generation network security services, intrusion prevention system (IPS), content security and secure unified communications. Delivering robust user and application policy enforcement, multi-vector attack protection, and secure connectivity services in cost-effective, easy-to-deploy solutions.
Security level exceptions
- Physical security: N/A
- Non-invasive security: N/A
- Mitigation of other attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES-CBC | A2952 |
| AES-CBC | A3376 |
| AES-GCM | A2952 |
| AES-GCM | A3376 |
| Counter DRBG | A2952 |
| Counter DRBG | A3376 |
| ECDSA KeyGen (FIPS186-4) | A2952 |
| ECDSA KeyGen (FIPS186-4) | A3376 |
| ECDSA KeyVer (FIPS186-4) | A2952 |
| ECDSA KeyVer (FIPS186-4) | A3376 |
| ECDSA SigGen (FIPS186-4) | A2952 |
| ECDSA SigGen (FIPS186-4) | A3376 |
| ECDSA SigVer (FIPS186-4) | A2952 |
| ECDSA SigVer (FIPS186-4) | A3376 |
| HMAC-SHA-1 | A2952 |
| HMAC-SHA-1 | A3376 |
| HMAC-SHA2-256 | A2952 |
| HMAC-SHA2-256 | A3376 |
| HMAC-SHA2-384 | A2952 |
| HMAC-SHA2-384 | A3376 |
| HMAC-SHA2-512 | A2952 |
| HMAC-SHA2-512 | A3376 |
| KAS-ECC-SSC Sp800-56Ar3 | A2952 |
| KAS-ECC-SSC Sp800-56Ar3 | A3376 |
| KAS-FFC-SSC Sp800-56Ar3 | A2952 |
| KAS-FFC-SSC Sp800-56Ar3 | A3376 |
| KDF IKEv2 | A2952 |
| KDF IKEv2 | A3376 |
| KDF SSH | A2952 |
| KDF SSH | A3376 |
| RSA KeyGen (FIPS186-4) | A2952 |
| RSA KeyGen (FIPS186-4) | A3376 |
| RSA SigGen (FIPS186-4) | A2952 |
| RSA SigGen (FIPS186-4) | A3376 |
| RSA SigVer (FIPS186-4) | A2952 |
| RSA SigVer (FIPS186-4) | A3376 |
| Safe Primes Key Generation | A2952 |
| Safe Primes Key Generation | A3376 |
| SHA-1 | A2952 |
| SHA-1 | A3376 |
| SHA2-256 | A2952 |
| SHA2-256 | A3376 |
| SHA2-384 | A2952 |
| SHA2-384 | A3376 |
| SHA2-512 | A2952 |
| SHA2-512 | A3376 |
| TLS v1.2 KDF RFC7627 | A2952 |
| TLS v1.2 KDF RFC7627 | A3376 |
Tested configurations
- Linux 4 (FX-OS) on NFVIS 4.4 running on ENCS 5412 Server with Intel Xeon Processor D-1557 (Broadwell) With PAA
- Linux 4 (FX-OS) on NFVIS 4.4 running on ENCS 5412 Server with Intel Xeon Processor D-1557 (Broadwell) without PAA
- Linux 4 (FX-OS) on VMware ESXi 6.7 running on UCS C220 M5 SFF Server with Intel Xeon Gold 6128 (Skylake) with PAA
- Linux 4 (FX-OS) on VMware ESXi 6.7 running on UCS C220 M5 SFF Server with Intel Xeon Gold 6128 (Skylake) without PAA
- Linux 4 (FX-OS) on VMware ESXi 7.0 running on UCS C220 M5 SFF Server with Intel Xeon Gold 6128 (Skylake) with PAA
- Linux 4 (FX-OS) on VMware ESXi 7.0 running on UCS C220 M5 SFF Server with Intel Xeon Gold 6128 (Skylake) without PAA
Validation history
| Date | Type | Lab |
|---|---|---|
| 2024-06-28 | Initial | Gossamer Security Solutions |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2024-06-28