Aruba OpenSSL Module
Caveat: Interim validation. When operated in Approved mode.
Certificate
| Certificate number | 4929 |
|---|---|
| Standard | FIPS 140-3 |
| Status | active |
| Sunset date | 2026-12-19 |
| Overall level | 1 |
| Module type | Firmware |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Hewlett Packard Enterprise · website |
| Firmware versions | 1.0 |
Module description
The Aruba OpenSSL Module is an Hewlett Packard Enterprise cryptographic module that provides cryptographic services for the ArubaOS operating system running on the Hewlett Packard Enterprise hardware-based equipment or Hewlett Packard Enterprise virtual appliances.
Security level exceptions
- Non-invasive security: N/A
- Mitigation of other attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES-CBC | A2690 |
| AES-CCM | A2690 |
| AES-CFB128 | A2690 |
| AES-CTR | A2690 |
| AES-CTR | A2690 |
| AES-ECB | A2690 |
| AES-GCM | A2690 |
| AES-KW | A2690 |
| DSA KeyGen (FIPS186-4) | A2690 |
| DSA PQGGen (FIPS186-4) | A2690 |
| ECDSA KeyGen (FIPS186-4) | A2690 |
| ECDSA KeyVer (FIPS186-4) | A2690 |
| ECDSA SigGen (FIPS186-4) | A2690 |
| ECDSA SigVer (FIPS186-4) | A2690 |
| HMAC-SHA-1 | A2690 |
| HMAC-SHA2-256 | A2690 |
| HMAC-SHA2-384 | A2690 |
| HMAC-SHA2-512 | A2690 |
| KAS-ECC-SSC Sp800-56Ar3 | A2690 |
| KAS-FFC-SSC Sp800-56Ar3 | A2690 |
| KDA TwoStep Sp800-56Cr1 | A2690 |
| KDF IKEv1 | A2690 |
| KDF SNMP | A2690 |
| KDF SP800-108 | A2690 |
| KDF SSH | A2690 |
| KDF TLS | A2690 |
| RSA KeyGen (FIPS186-4) | A2690 |
| RSA SigGen (FIPS186-4) | A2690 |
| RSA SigVer (FIPS186-2) | A2690 |
| RSA SigVer (FIPS186-4) | A2690 |
| Safe Primes Key Generation | A2690 |
| Safe Primes Key Verification | A2690 |
| SHA-1 | A2690 |
| SHA2-256 | A2690 |
| SHA2-384 | A2690 |
| SHA2-512 | A2690 |
Tested configurations
- ArubaOS 8.10 on VMWare ESXi 7.0 running on MCR-VA-50 Mobility Conductor Virtual Appliance on HPE Edgeline 20 with Intel Xeon Gold 6212U (Cascade Lake) without PAA
- ArubaOS 8.10 on VMWare ESXi 7.0 running on MC-VA-50 Mobility Controller Virtual Appliance on HPE ProLiant ML110 Gen10 with Intel Xeon E3 1515 (Skylake) without PAA
- ArubaOS 8.10 on VMWare ESXi 7.0 running on MC-VA-50 Mobility Controller Virtual Appliance on Pacstar PS451-1258 Series with Intel Xeon E-2254ML (CoffeeLake) without PAA
- ArubaOS 8.10 running on 7020 Mobility Controller with Broadcom XLP208 (MIPS64) without PAA
- ArubaOS 8.10 running on 7205 Mobility Controller with Broadcom XLP316 (MIPS64) without PAA
- ArubaOS 8.10 running on 7220 Mobility Controller with Broadcom XLP432 (MIPS64) without PAA
- ArubaOS 8.10 running on 7280 Mobility Controller with Broadcom XLP (MIPS64) without PAA
- ArubaOS 8.10 running on 9012 Gateway with Intel Atom C3508 (Denverton) without PAA
- ArubaOS 8.10 running on 9240 Gateway with Intel Xeon (Cascade Lake) with PAA
- ArubaOS 8.10 running on 9240 Gateway with Intel Xeon (Cascade Lake) without PAA
- ArubaOS 8.10 running on AP-505 Wireless Access Point with Broadcom BCM47622L (ARM-A7) without PAA
- ArubaOS 8.10 running on AP-515 Wireless Access Point with Broadcom BCM (64-bit ARMv8) without PAA
- ArubaOS 8.10 running on AP-535 Wireless Access Point with Qualcomm IPQ (64-bit ARM Cortex A53) without PAA
- ArubaOS 8.10 running on AP-635 Wireless Access Point with Qualcomm IPQ (64-bit ARM Cortex A53) without PAA
- ArubaOS 8.10 running on AP-655 Wireless Access Point with Qualcomm IPQ (64-bit ARM Cortex A53) without PAA
- ArubaOS 8.10 running on MCR-HW-5K Mobility Conductor Hardware Appliance with Intel Xeon E5-2620v4 (Broadwell) with PAA
Validation history
| Date | Type | Lab |
|---|---|---|
| 2024-12-20 | Initial | Lightship Security, Inc. |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2024-12-20