808bits

BIG-IP Tenant Cryptographic Module

FIPS 140-3 certificate #4945 · F5, Inc. · data as of 2026-08-28
Historical. Replaced by certificate #5269. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: Interim validation. When operated in approved mode. When installed, initialized, and configured as specified in Section 11 of the Security Policy. The tamper evident labels contained in F5-ADD-BIG-FIPS140 kit and panel fillers installed as indicated in the Security Policy section 7.

Certificate

Certificate number4945
StandardFIPS 140-3
Statushistorical
Overall level2
Module typeFirmware
EmbodimentMulti-Chip Stand Alone
VendorF5, Inc.
Firmware versions17.1.0.1

Module description

BIG-IP Tenant Cryptographic Module, Application Delivery Controller and Firewall software running on running on F5 hardware and the underlying platform layer.

Security level exceptions

  • Operational environment: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES-CBCA3729
AES-CBCA3730
AES-CCMA3729
AES-CCMA3730
AES-CTRA3729
AES-ECBA3729
AES-GCMA3729
AES-GCMA3730
AES-GMACA3729
AES-GMACA3730
Counter DRBGA3729
Counter DRBGA3730
ECDSA KeyGen (FIPS186-4)A3729
ECDSA KeyGen (FIPS186-4)A3730
ECDSA KeyVer (FIPS186-4)A3729
ECDSA KeyVer (FIPS186-4)A3730
ECDSA SigGen (FIPS186-4)A3729
ECDSA SigGen (FIPS186-4)A3730
ECDSA SigVer (FIPS186-4)A3729
ECDSA SigVer (FIPS186-4)A3730
HMAC-SHA-1A3729
HMAC-SHA-1A3730
HMAC-SHA2-256A3729
HMAC-SHA2-256A3730
HMAC-SHA2-384A3729
HMAC-SHA2-384A3730
HMAC-SHA2-512A3729
HMAC-SHA2-512A3730
KAS-ECC-SSC Sp800-56Ar3A3729
KAS-ECC-SSC Sp800-56Ar3A3730
KAS-FFC-SSC Sp800-56Ar3A3729
KAS-FFC-SSC Sp800-56Ar3A3730
KDF SSHA3729
RSA KeyGen (FIPS186-4)A3729
RSA SigGen (FIPS186-4)A3729
RSA SigGen (FIPS186-4)A3730
RSA SigVer (FIPS186-4)A3729
RSA SigVer (FIPS186-4)A3730
Safe Primes Key GenerationA3729
Safe Primes Key GenerationA3730
Safe Primes Key VerificationA3729
Safe Primes Key VerificationA3730
SHA-1A3729
SHA-1A3730
SHA2-256A3729
SHA2-256A3730
SHA2-384A3729
SHA2-384A3730
SHA2-512A3729
SHA2-512A3730
TLS v1.2 KDF RFC7627A3729
TLS v1.2 KDF RFC7627A3730

Tested configurations

  • BIG-IP 17.1.0.1 Tenant Cryptographic Module on F5OS-A 1.5.1 running on r10900 with Intel® Xeon® Gold 6312U Ice Lake
  • BIG-IP 17.1.0.1 Tenant Cryptographic Module on F5OS-A 1.5.1 running on r10920-DF with Intel® Xeon® Gold 6312U Ice Lake
  • BIG-IP 17.1.0.1 Tenant Cryptographic Module on F5OS-A 1.5.1 running on r4800 with Intel® Atom® P5342 Snow Ridge
  • BIG-IP 17.1.0.1 Tenant Cryptographic Module on F5OS-A 1.5.1 running on r5900 with Intel® Xeon® 4314 Silver Ice Lake
  • BIG-IP 17.1.0.1 Tenant Cryptographic Module on F5OS-A 1.5.1 running on r5920-DF with Intel® Xeon® 4314 Silver Ice Lake
  • BIG-IP 17.1.0.1 Tenant Cryptographic Module on F5OS-A 1.7.0 running on r12900-DS with Intel® Xeon® Platinum 8351N Ice Lake
  • BIG-IP 17.1.0.1 Tenant Cryptographic Module on F5OS-C 1.6.0 running on VELOS CX410 BX110 with Intel® Xeon® D-2177NT Skylake

Validation history

DateTypeLab
2025-01-17Initialatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2025-01-17

Source documents