808bits

Cisco FIPS Object Module

FIPS 140-3 certificate #4747 · Cisco Systems, Inc. · data as of 2026-08-28
Active. Sunset date 2029-07-31, 1067 days away.
Caveat: No assurance of the minimum strength of generated SSPs (e.g., keys).

Certificate

Certificate number4747
StandardFIPS 140-3
Statusactive
Sunset date2029-07-31
Overall level1
Module typeFirmware-hybrid
EmbodimentMulti-Chip Stand Alone
VendorCisco Systems, Inc. · website
Firmware versions7.3a

Module description

The Cisco FIPS Object Module (FOM) is a firmware hybrid library that provides cryptographic services to a vast array of Cisco's networking and collaboration products. The module provides FIPS 140 validated cryptographic algorithms for services such as IPSEC, SRTP, SSH, TLS, 802.1x, etc. The module does not directly implement any of these protocols, instead, it provides the cryptographic primitives and functions to allow a developer to implement the various protocols.

Security level exceptions

  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES-CBCA4446
AES-CCMA4446
AES-CFB1A4446
AES-CFB128A4446
AES-CFB8A4446
AES-CMACA4446
AES-CTRA4446
AES-ECBA4446
AES-GCMA4446
AES-GMACA4446
AES-KWA4446
AES-KWPA4446
AES-OFBA4446
AES-XTS Testing Revision 2.0A4446
Counter DRBGA4446
DSA KeyGen (FIPS186-4)A4446
DSA PQGGen (FIPS186-4)A4446
DSA PQGVer (FIPS186-4)A4446
DSA SigGen (FIPS186-4)A4446
DSA SigVer (FIPS186-4)A4446
ECDSA KeyGen (FIPS186-4)A4446
ECDSA KeyVer (FIPS186-4)A4446
ECDSA SigGen (FIPS186-4)A4446
ECDSA SigVer (FIPS186-4)A4446
Hash DRBGA4446
HMAC DRBGA4446
HMAC-SHA-1A4446
HMAC-SHA2-224A4446
HMAC-SHA2-256A4446
HMAC-SHA2-384A4446
HMAC-SHA2-512A4446
HMAC-SHA2-512/224A4446
HMAC-SHA2-512/256A4446
HMAC-SHA3-224A4446
HMAC-SHA3-256A4446
HMAC-SHA3-384A4446
HMAC-SHA3-512A4446
KAS-ECC CDH-Component SP800-56Ar3A4446
KAS-ECC-SSC Sp800-56Ar3A4446
KAS-FFC-SSC Sp800-56Ar3A4446
KAS-IFC-SSCA4446
KDA HKDF Sp800-56Cr1A4446
KDA OneStep Sp800-56Cr1A4446
KDF IKEv2A4446
KDF SNMPA4446
KDF SP800-108A4446
KDF SRTPA4446
KDF SSHA4446
KTS-IFCA4446
PBKDFA4446
RSA KeyGen (FIPS186-4)A4446
RSA SigGen (FIPS186-4)A4446
RSA SigVer (FIPS186-4)A4446
Safe Primes Key GenerationA4446
Safe Primes Key VerificationA4446
SHA-1A4446
SHA2-224A4446
SHA2-256A4446
SHA2-384A4446
SHA2-512A4446
SHA2-512/224A4446
SHA2-512/256A4446
SHA3-224A4446
SHA3-256A4446
SHA3-384A4446
SHA3-512A4446
SHAKE-128A4446
SHAKE-256A4446
TDES-CBCA4446
TDES-CFB1A4446
TDES-CFB64A4446
TDES-CFB8A4446
TDES-CMACA4446
TDES-CTRA4446
TDES-ECBA4446
TDES-OFBA4446
TLS v1.2 KDF RFC7627A4446
TLS v1.3 KDFA4446

Tested configurations

  • Linux 4.4 running on Cisco Catalyst 9300 with Intel Xeon D-1526 (Broadwell) with PAA
  • Linux 4.5 running on Cisco Unified Computing System (UCS) with Intel Xeon Gold 6244 (Cascade Lake) with PAA
  • Linux 5.4 running on ISR 4321 with Intel Atom C2558 (Silvermont) with PAA

Validation history

DateTypeLab
2024-08-01InitialAcumen Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2024-08-01

Source documents