808bits

Arista Crypto Module v3.0 [Software, Software IPsec]

FIPS 140-3 certificate #4790 · Arista Networks, Inc. · data as of 2026-08-28
Historical. Replaced by certificate #5402. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: Interim validation. When operated in approved mode. No assurance of the minimum strength of generated SSPs (e.g., keys)

Certificate

Certificate number4790
StandardFIPS 140-3
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorArista Networks, Inc. · website
Software versions3.0

Module description

Arista's crypto library is a comprehensive suite of FIPS Approved algorithms. Many key sizes and modes have been implemented to allow flexibility and efficiency. This validation is for the library contained within the CloudEOS Router products and all its related SKUs, which includes SS-CLOUDEOS-VR-CV-100M-B-1M, SS-CLOUDEOS-VR-CVS-100M-B-1M, SS-CLOUDEOS-VR-CV-1G-B-1M, SS-CLOUDEOS-VR-CVS-1G-B-1M, SS-CLOUDEOS-VR-CV-10G-B-1M, SS-CLOUDEOS-VR-CVS-10G-B-1M, SS-CVPATH-CloudEOS-100M-E-CVS-B-1M, SS-CVPATH-CloudEOS-1G-E-CVS-B-1M, SS-CVPATH-CloudEOS-10G-E-CVS-B-1M and any other future SKUs which use the validated library for the CloudEOS Router product.

Security level exceptions

  • Roles, services, and authentication: Level 2
  • Physical security: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES-CBCA3592
AES-CCMA3592
AES-CFB1A3592
AES-CFB128A3592
AES-CFB8A3592
AES-CMACA3592
AES-CTRA3592
AES-ECBA3592
AES-GCMA3592
AES-XTS Testing Revision 2.0A3592
Counter DRBGA3592
ECDSA KeyGen (FIPS186-4)A3592
ECDSA KeyVer (FIPS186-4)A3592
ECDSA SigGen (FIPS186-4)A3592
ECDSA SigVer (FIPS186-4)A3592
Hash DRBGA3592
HMAC DRBGA3592
HMAC-SHA-1A3592
HMAC-SHA2-224A3592
HMAC-SHA2-256A3592
HMAC-SHA2-384A3592
HMAC-SHA2-512A3592
KAS-ECC-SSC Sp800-56Ar3A3592
KAS-FFC-SSC Sp800-56Ar3A3592
KDF IKEv1A3592
KDF IKEv2A3592
KDF SP800-108A3592
KDF SSHA3592
KDF TLSA3592
KTS-IFCA3592
RSA KeyGen (FIPS186-4)A3592
RSA SigGen (FIPS186-4)A3592
RSA SigVer (FIPS186-4)A3592
SHA-1A3592
SHA2-224A3592
SHA2-256A3592
SHA2-384A3592
SHA2-512A3592
TLS v1.2 KDF RFC7627A3592

Tested configurations

  • CloudEOS version 4.29 on QEMU version 2.0.0 on Linux 3.10.0-1160.el7.x86_64 running on a Supermicro SYS-1029U-TR-CTO with an Intel Xeon Gold 6240R with PAA
  • CloudEOS version 4.29 on QEMU version 2.0.0 on Linux 3.10.0-1160.el7.x86_64 running on a Supermicro SYS-1029U-TR-CTO with an Intel Xeon Gold 6240R without PAA

Validation history

DateTypeLab
2024-09-06InitialDEKRA Cybersecurity Certification Laboratory

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2024-09-06

Source documents