808bits

AP-514, AP-515, AP-534, AP-535, AP-584, AP-585, AP-587, AP-635 and AP-655 Access Points

FIPS 140-3 certificate #4916 · Aruba, a Hewlett Packard Enterprise company · data as of 2026-08-28
Active. Sunset date 2026-12-11, 104 days away.
Caveat: Interim validation. When operated in the approved mode, with tamper evident labels installed as indicated in the Security Policy

Certificate

Certificate number4916
StandardFIPS 140-3
Statusactive
Sunset date2026-12-11
Overall level2
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorAruba, a Hewlett Packard Enterprise company · website
Hardware versionsAP-514-USF1 (HPE SKU Q9H68A), AP-515-USF1 (HPE SKU Q9H73A), AP-534-USF1 (HPE SKU JZ342A), AP-535-USF1 (HPE SKU JZ347A), AP-584-US TAA (HPE SKU R7T14A), AP-584-RW TAA (HPE SKU R7T15A), AP-585-US TAA (HPE SKU R7T19A), AP-585-RW TAA (HPE SKU R7T20A), AP-587-US TAA (HPE SKU R7T24A), AP-587-RW TAA (HPE SKU R7T25A), AP-635-RW TAA (HPE SKU R7J32A), AP-635-US TAA (HPE SKU R7J33A), AP-655-RW TAA (HPE SKU R7J43A), AP-655-US TAA (HPE SKU R7J44A) with FIPS Kit 4011570-01 (HPE SKU JY894A)
Firmware versionsArubaOS 8.10.0.5-FIPS

Module description

Aruba's 802.11 Wi-Fi access points operate at gigabit speeds, offering extreme performance for mobile devices. In FIPS 140-3 mode, Aruba APs in conjunction with a Mobility Controller support the WPA2/WPA3 client standard along with optional Suite B cryptography. Aruba APs also support wireless intrusion detection/prevention services and wireless mesh topologies.

Security level exceptions

  • Operational environment: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES-CBCA2689
AES-CBCA2690
AES-CCMA2690
AES-CTRA2690
AES-ECBA2690
AES-GCMA2689
AES-GCMA2690
Counter DRBGA2690
DSA KeyGen (FIPS186-4)A2689
DSA KeyGen (FIPS186-4)A2690
DSA PQGGen (FIPS186-4)A2689
DSA PQGGen (FIPS186-4)A2690
ECDSA KeyGen (FIPS186-4)A2689
ECDSA KeyGen (FIPS186-4)A2690
ECDSA KeyVer (FIPS186-4)A2689
ECDSA KeyVer (FIPS186-4)A2690
ECDSA SigGen (FIPS186-4)A2689
ECDSA SigGen (FIPS186-4)A2690
ECDSA SigVer (FIPS186-4)A2689
ECDSA SigVer (FIPS186-4)A2690
HMAC-SHA-1A2689
HMAC-SHA-1A2690
HMAC-SHA2-256A2689
HMAC-SHA2-256A2690
HMAC-SHA2-384A2689
HMAC-SHA2-384A2690
KAS-ECC-SSC Sp800-56Ar3A2689
KAS-ECC-SSC Sp800-56Ar3A2690
KAS-FFC-SSC Sp800-56Ar3A2689
KAS-FFC-SSC Sp800-56Ar3A2690
KDA TwoStep Sp800-56Cr1A2690
KDF IKEv1A2690
KDF IKEv2A2689
KDF SP800-108A2690
RSA KeyGen (FIPS186-4)A2689
RSA KeyGen (FIPS186-4)A2690
RSA SigGen (FIPS186-4)A2689
RSA SigGen (FIPS186-4)A2690
RSA Signature PrimitiveA2689
RSA Signature PrimitiveA2690
RSA SigVer (FIPS186-2)A2689
RSA SigVer (FIPS186-2)A2690
RSA SigVer (FIPS186-4)A2688
RSA SigVer (FIPS186-4)A2689
RSA SigVer (FIPS186-4)A2690
Safe Primes Key GenerationA2689
Safe Primes Key GenerationA2690
Safe Primes Key VerificationA2689
Safe Primes Key VerificationA2690
SHA-1A2689
SHA-1A2690
SHA2-256A2688
SHA2-256A2689
SHA2-256A2690
SHA2-384A2689
SHA2-384A2690
SHA2-512A2689
SHA2-512A2690
SHA3-256A2738

Tested configurations

  • N/A

Validation history

DateTypeLab
2024-12-12InitialLightship Security, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2024-12-12

Source documents