Edge SWG
Edge SWG, from Symantec, A Division of Broadcom, holds FIPS 140-3 certificate #4873 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.
Caveat: Interim Validation. When operated in approved mode and when installed, initialized and configured as specified in Section 11.1.1 of the Security Policy. The protocols TLS v1.0 and v1.1 shall not be used when operated in approved mode.
Certificate
| Certificate number | 4873 |
|---|---|
| Standard | FIPS 140-3 |
| Status | historical |
| Overall level | 1 |
| Module type | Software-hybrid |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Symantec, A Division of Broadcom · website |
| Software versions | 7.4 |
| Hardware versions | Intel Xeon Silver 4210, Intel Xeon Silver 4216 |
| Entropy | ENT (P) |
Module description
Quoted from the NIST CMVP entry for this certificate.
The Edge SWG appliances from Symantec provide companies the ability to deploy a scalable proxy-based security solution to protect their organization against advanced threats. The Edge SWG acts as gateway between web users and the Internet: a single point where all web traffic can be monitored and corporate policies for web use can be enforced.
Security level exceptions
- Roles, services, and authentication: Level 2
- Non-invasive security: N/A
- Mitigation of other attacks: N/A
Approved algorithms (25)
| Algorithm | CAVP certificates |
|---|---|
| AES-CBC | A2936 |
| AES-CTR | A2936 |
| AES-GCM | A2936 |
| Counter DRBG | A2936 |
| HMAC-SHA-1 | A2936, A3192 |
| HMAC-SHA2-224 | A2936 |
| HMAC-SHA2-256 | A2936 |
| HMAC-SHA2-384 | A2936 |
| HMAC-SHA2-512 | A2936 |
| KAS-FFC-SSC Sp800-56Ar3 | A2936 |
| KDF SNMP | A2936 |
| KDF SSH | A2936 |
| KDF TLS | A2936 |
| PBKDF | A2936 |
| RSA KeyGen (FIPS186-4) | A2936 |
| RSA SigGen (FIPS186-4) | A2936 |
| RSA SigVer (FIPS186-4) | A2936, A3192 |
| Safe Primes Key Generation | A2936 |
| Safe Primes Key Verification | A2936 |
| SHA-1 | A2936, A3192 |
| SHA2-224 | A2936 |
| SHA2-256 | A2936, A3192 |
| SHA2-384 | A2936 |
| SHA2-512 | A2936 |
| TLS v1.3 KDF | A2936 |
Tested configurations
- SGOS v7.4 with KVM v2.3 running on Symantec SSP-S410 with Intel Xeon Silver 4210 with PAA
- SGOS v7.4 with VMware ESXi v6.5 running on Dell PowerEdge R440 with Intel Xeon Silver 4216 with PAA
Validation history
| Date | Type | Lab |
|---|---|---|
| 2024-11-11 | Initial | Acumen Security |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2024-11-11