808bits

BIG-IP Tenant Cryptographic Module

FIPS 140-3 certificate #4945 · F5, Inc. · data as of 2026-09-03

BIG-IP Tenant Cryptographic Module, from F5, Inc., holds FIPS 140-3 certificate #4945 at overall level 2. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Replaced by certificate #5269. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: Interim validation. When operated in approved mode. When installed, initialized, and configured as specified in Section 11 of the Security Policy. The tamper evident labels contained in F5-ADD-BIG-FIPS140 kit and panel fillers installed as indicated in the Security Policy section 7.

Certificate

Certificate number4945
StandardFIPS 140-3
Statushistorical
Overall level2
Module typeFirmware
EmbodimentMulti-Chip Stand Alone
VendorF5, Inc.
Firmware versions17.1.0.1

Module description

Quoted from the NIST CMVP entry for this certificate.

BIG-IP Tenant Cryptographic Module, Application Delivery Controller and Firewall software running on running on F5 hardware and the underlying platform layer.

Security level exceptions

  • Operational environment: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Approved algorithms (28)

AlgorithmCAVP certificates
AES-CBCA3729, A3730
AES-CCMA3729, A3730
AES-CTRA3729
AES-ECBA3729
AES-GCMA3729, A3730
AES-GMACA3729, A3730
Counter DRBGA3729, A3730
ECDSA KeyGen (FIPS186-4)A3729, A3730
ECDSA KeyVer (FIPS186-4)A3729, A3730
ECDSA SigGen (FIPS186-4)A3729, A3730
ECDSA SigVer (FIPS186-4)A3729, A3730
HMAC-SHA-1A3729, A3730
HMAC-SHA2-256A3729, A3730
HMAC-SHA2-384A3729, A3730
HMAC-SHA2-512A3729, A3730
KAS-ECC-SSC Sp800-56Ar3A3729, A3730
KAS-FFC-SSC Sp800-56Ar3A3729, A3730
KDF SSHA3729
RSA KeyGen (FIPS186-4)A3729
RSA SigGen (FIPS186-4)A3729, A3730
RSA SigVer (FIPS186-4)A3729, A3730
Safe Primes Key GenerationA3729, A3730
Safe Primes Key VerificationA3729, A3730
SHA-1A3729, A3730
SHA2-256A3729, A3730
SHA2-384A3729, A3730
SHA2-512A3729, A3730
TLS v1.2 KDF RFC7627A3729, A3730

Tested configurations

  • BIG-IP 17.1.0.1 Tenant Cryptographic Module on F5OS-A 1.5.1 running on r10900 with Intel® Xeon® Gold 6312U Ice Lake
  • BIG-IP 17.1.0.1 Tenant Cryptographic Module on F5OS-A 1.5.1 running on r10920-DF with Intel® Xeon® Gold 6312U Ice Lake
  • BIG-IP 17.1.0.1 Tenant Cryptographic Module on F5OS-A 1.5.1 running on r4800 with Intel® Atom® P5342 Snow Ridge
  • BIG-IP 17.1.0.1 Tenant Cryptographic Module on F5OS-A 1.5.1 running on r5900 with Intel® Xeon® 4314 Silver Ice Lake
  • BIG-IP 17.1.0.1 Tenant Cryptographic Module on F5OS-A 1.5.1 running on r5920-DF with Intel® Xeon® 4314 Silver Ice Lake
  • BIG-IP 17.1.0.1 Tenant Cryptographic Module on F5OS-A 1.7.0 running on r12900-DS with Intel® Xeon® Platinum 8351N Ice Lake
  • BIG-IP 17.1.0.1 Tenant Cryptographic Module on F5OS-C 1.6.0 running on VELOS CX410 BX110 with Intel® Xeon® D-2177NT Skylake

Validation history

DateTypeLab
2025-01-17Initialatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2025-01-17

Source documents