808bits

Cryptographic Module for BIG-IP ®

FIPS 140-3 certificate #4716 · F5, Inc. · data as of 2026-09-15

Cryptographic Module for BIG-IP ®, from F5, Inc., holds FIPS 140-3 certificate #4716 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: Interim validation. When operated in approved mode. When installed, initialized and configured as specified in Section 11.1 of the Security Policy.

Certificate

Certificate number4716
StandardFIPS 140-3
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorF5, Inc. · website
Software versions1.0.2u-fips

Module description

Quoted from the NIST CMVP entry for this certificate.

Cryptographic library offering various cryptographic mechanisms to BIG-IP Virtual Edition.

Security level exceptions

  • Physical security: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Approved algorithms (23)

AlgorithmCAVP certificates
AES-CBCA2711, A2762
AES-CTRA2762
AES-ECBA2711, A2762
AES-GCMA2711, A2762
AES-GMACA2711, A2762
Counter DRBGA2711, A2762
ECDSA KeyGen (FIPS186-4)A2762
ECDSA KeyVer (FIPS186-4)A2762
ECDSA SigGen (FIPS186-4)A2762
ECDSA SigVer (FIPS186-4)A2762
HMAC-SHA-1A2711, A2762
HMAC-SHA2-256A2762
HMAC-SHA2-384A2762
KAS-ECC-SSC Sp800-56Ar3A2762
KAS-FFC-SSC Sp800-56Ar3A2762
RSA KeyGen (FIPS186-4)A2762
RSA SigGen (FIPS186-4)A2762
RSA SigVer (FIPS186-4)A2762
Safe Primes Key GenerationA2762
Safe Primes Key VerificationA2762
SHA-1A2711, A2762
SHA2-256A2762
SHA2-384A2762

Tested configurations

  • BIG-IP 16.1.3.1 on Hyper-V 10.0.20348.1 on Windows Server 2022 running on Dell PowerEdge R450 with an Intel(R) Xeon(R) Silver 4309Y with PAA
  • BIG-IP 16.1.3.1 on Hyper-V 10.0.20348.1 on Windows Server 2022 running on Dell PowerEdge R450 with an Intel(R) Xeon(R) Silver 4309Y without PAA
  • BIG-IP 16.1.3.1 on KVM on Ubuntu 20.04.2 LTS (Focal Fossa) running on Dell PowerEdge M630 with an Intel(R) Xeon(R) E5-2690 v4 Broadwell with PAA
  • BIG-IP 16.1.3.1 on KVM on Ubuntu 20.04.2 LTS (Focal Fossa) running on Dell PowerEdge M630 with an Intel(R) Xeon(R) E5-2690 v4 Broadwell without PAA.
  • BIG-IP 16.1.3.1 on VMware ESXi(TM) 6.5 hypervisor running on Dell PowerEdge M620 with an Intel(R) Xeon(R) E5-2670 Sandy Bridge with PAA
  • BIG-IP 16.1.3.1 on VMware ESXi(TM) 6.5 hypervisor running on Dell PowerEdge M620 with an Intel(R) Xeon(R) E5-2670 Sandy Bridge without PAA

Validation history

DateTypeLab
2024-07-09Initialatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2024-07-09

Source documents