BIG-IP Tenant Cryptographic Module
Caveat: Interim validation. When operated in approved mode. When installed, initialized, and configured as specified in Section 11 of the Security Policy. The tamper evident labels contained in F5-ADD-BIG-FIPS140 kit and panel fillers installed as indicated in the Security Policy section 7.
Certificate
| Certificate number | 4945 |
|---|---|
| Standard | FIPS 140-3 |
| Status | historical |
| Overall level | 2 |
| Module type | Firmware |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | F5, Inc. |
| Firmware versions | 17.1.0.1 |
Module description
BIG-IP Tenant Cryptographic Module, Application Delivery Controller and Firewall software running on running on F5 hardware and the underlying platform layer.
Security level exceptions
- Operational environment: N/A
- Non-invasive security: N/A
- Mitigation of other attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES-CBC | A3729 |
| AES-CBC | A3730 |
| AES-CCM | A3729 |
| AES-CCM | A3730 |
| AES-CTR | A3729 |
| AES-ECB | A3729 |
| AES-GCM | A3729 |
| AES-GCM | A3730 |
| AES-GMAC | A3729 |
| AES-GMAC | A3730 |
| Counter DRBG | A3729 |
| Counter DRBG | A3730 |
| ECDSA KeyGen (FIPS186-4) | A3729 |
| ECDSA KeyGen (FIPS186-4) | A3730 |
| ECDSA KeyVer (FIPS186-4) | A3729 |
| ECDSA KeyVer (FIPS186-4) | A3730 |
| ECDSA SigGen (FIPS186-4) | A3729 |
| ECDSA SigGen (FIPS186-4) | A3730 |
| ECDSA SigVer (FIPS186-4) | A3729 |
| ECDSA SigVer (FIPS186-4) | A3730 |
| HMAC-SHA-1 | A3729 |
| HMAC-SHA-1 | A3730 |
| HMAC-SHA2-256 | A3729 |
| HMAC-SHA2-256 | A3730 |
| HMAC-SHA2-384 | A3729 |
| HMAC-SHA2-384 | A3730 |
| HMAC-SHA2-512 | A3729 |
| HMAC-SHA2-512 | A3730 |
| KAS-ECC-SSC Sp800-56Ar3 | A3729 |
| KAS-ECC-SSC Sp800-56Ar3 | A3730 |
| KAS-FFC-SSC Sp800-56Ar3 | A3729 |
| KAS-FFC-SSC Sp800-56Ar3 | A3730 |
| KDF SSH | A3729 |
| RSA KeyGen (FIPS186-4) | A3729 |
| RSA SigGen (FIPS186-4) | A3729 |
| RSA SigGen (FIPS186-4) | A3730 |
| RSA SigVer (FIPS186-4) | A3729 |
| RSA SigVer (FIPS186-4) | A3730 |
| Safe Primes Key Generation | A3729 |
| Safe Primes Key Generation | A3730 |
| Safe Primes Key Verification | A3729 |
| Safe Primes Key Verification | A3730 |
| SHA-1 | A3729 |
| SHA-1 | A3730 |
| SHA2-256 | A3729 |
| SHA2-256 | A3730 |
| SHA2-384 | A3729 |
| SHA2-384 | A3730 |
| SHA2-512 | A3729 |
| SHA2-512 | A3730 |
| TLS v1.2 KDF RFC7627 | A3729 |
| TLS v1.2 KDF RFC7627 | A3730 |
Tested configurations
- BIG-IP 17.1.0.1 Tenant Cryptographic Module on F5OS-A 1.5.1 running on r10900 with Intel® Xeon® Gold 6312U Ice Lake
- BIG-IP 17.1.0.1 Tenant Cryptographic Module on F5OS-A 1.5.1 running on r10920-DF with Intel® Xeon® Gold 6312U Ice Lake
- BIG-IP 17.1.0.1 Tenant Cryptographic Module on F5OS-A 1.5.1 running on r4800 with Intel® Atom® P5342 Snow Ridge
- BIG-IP 17.1.0.1 Tenant Cryptographic Module on F5OS-A 1.5.1 running on r5900 with Intel® Xeon® 4314 Silver Ice Lake
- BIG-IP 17.1.0.1 Tenant Cryptographic Module on F5OS-A 1.5.1 running on r5920-DF with Intel® Xeon® 4314 Silver Ice Lake
- BIG-IP 17.1.0.1 Tenant Cryptographic Module on F5OS-A 1.7.0 running on r12900-DS with Intel® Xeon® Platinum 8351N Ice Lake
- BIG-IP 17.1.0.1 Tenant Cryptographic Module on F5OS-C 1.6.0 running on VELOS CX410 BX110 with Intel® Xeon® D-2177NT Skylake
Validation history
| Date | Type | Lab |
|---|---|---|
| 2025-01-17 | Initial | atsec information security corporation |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2025-01-17