808bits

AP-514, AP-515, AP-534, AP-535, AP-584, AP-585, AP-587, AP-635 and AP-655 Access Points

FIPS 140-3 certificate #4916 · Aruba, a Hewlett Packard Enterprise company · data as of 2026-09-12

AP-514, AP-515, AP-534, AP-535, AP-584, AP-585, AP-587, AP-635 and AP-655 Access Points, from Aruba, a Hewlett Packard Enterprise company, holds FIPS 140-3 certificate #4916 at overall level 2. The validation is active, with a sunset date of 2026-12-11. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Active. Sunset date 2026-12-11, 89 days away.
Caveat: Interim validation. When operated in the approved mode, with tamper evident labels installed as indicated in the Security Policy

Certificate

Certificate number4916
StandardFIPS 140-3
Statusactive
Sunset date2026-12-11
Overall level2
Module typeHardware
EmbodimentMulti-Chip Stand Alone
VendorAruba, a Hewlett Packard Enterprise company · website
Hardware versionsAP-514-USF1 (HPE SKU Q9H68A), AP-515-USF1 (HPE SKU Q9H73A), AP-534-USF1 (HPE SKU JZ342A), AP-535-USF1 (HPE SKU JZ347A), AP-584-US TAA (HPE SKU R7T14A), AP-584-RW TAA (HPE SKU R7T15A), AP-585-US TAA (HPE SKU R7T19A), AP-585-RW TAA (HPE SKU R7T20A), AP-587-US TAA (HPE SKU R7T24A), AP-587-RW TAA (HPE SKU R7T25A), AP-635-RW TAA (HPE SKU R7J32A), AP-635-US TAA (HPE SKU R7J33A), AP-655-RW TAA (HPE SKU R7J43A), AP-655-US TAA (HPE SKU R7J44A) with FIPS Kit 4011570-01 (HPE SKU JY894A)
Firmware versionsArubaOS 8.10.0.5-FIPS

Module description

Quoted from the NIST CMVP entry for this certificate.

Aruba's 802.11 Wi-Fi access points operate at gigabit speeds, offering extreme performance for mobile devices. In FIPS 140-3 mode, Aruba APs in conjunction with a Mobility Controller support the WPA2/WPA3 client standard along with optional Suite B cryptography. Aruba APs also support wireless intrusion detection/prevention services and wireless mesh topologies.

Security level exceptions

  • Operational environment: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Approved algorithms (33)

AlgorithmCAVP certificates
AES-CBCA2689, A2690
AES-CCMA2690
AES-CTRA2690
AES-ECBA2690
AES-GCMA2689, A2690
Counter DRBGA2690
DSA KeyGen (FIPS186-4)A2689, A2690
DSA PQGGen (FIPS186-4)A2689, A2690
ECDSA KeyGen (FIPS186-4)A2689, A2690
ECDSA KeyVer (FIPS186-4)A2689, A2690
ECDSA SigGen (FIPS186-4)A2689, A2690
ECDSA SigVer (FIPS186-4)A2689, A2690
HMAC-SHA-1A2689, A2690
HMAC-SHA2-256A2689, A2690
HMAC-SHA2-384A2689, A2690
KAS-ECC-SSC Sp800-56Ar3A2689, A2690
KAS-FFC-SSC Sp800-56Ar3A2689, A2690
KDA TwoStep Sp800-56Cr1A2690
KDF IKEv1A2690
KDF IKEv2A2689
KDF SP800-108A2690
RSA KeyGen (FIPS186-4)A2689, A2690
RSA SigGen (FIPS186-4)A2689, A2690
RSA Signature PrimitiveA2689, A2690
RSA SigVer (FIPS186-2)A2689, A2690
RSA SigVer (FIPS186-4)A2688, A2689, A2690
Safe Primes Key GenerationA2689, A2690
Safe Primes Key VerificationA2689, A2690
SHA-1A2689, A2690
SHA2-256A2688, A2689, A2690
SHA2-384A2689, A2690
SHA2-512A2689, A2690
SHA3-256A2738

Tested configurations

  • N/A

Validation history

DateTypeLab
2024-12-12InitialLightship Security, Inc.

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2024-12-12

Source documents