Juniper Express 4 MACsec Cryptographic Module
Caveat: When operated with module Junos® OS Evolved OpenSSL Cryptographic Module version 3.0.8 validated to FIPS 140-3 under Cert. #5400 operating in approved mode, and module Junos® OS Evolved Kernel Cryptographic Module version 2.0 validated to FIPS 140-3 under Cert. #5399, operating in approved mode. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs
Certificate
| Certificate number | 5489 |
|---|---|
| Standard | FIPS 140-3 |
| Status | active |
| Sunset date | 2029-11-12 |
| Overall level | 1 |
| Module type | Software-hybrid |
| Embodiment | MultiChipStand |
| Vendor | Juniper Networks, Inc. · website |
Module description
Juniper Express 4 MACsec Cryptographic Module is composed by the MACsec blocks that are part of the Juniper Networks® Express 4 processor in hardware, which provides the AES GCM and XPN algorithm implementations for encrypting and decrypting MACsec traffic, and a device driver in software, which provides the functionality to comply with FIPS 140-3 requirements (i.e. integrity test, self-tests), as well as the API to configure the hardware component.
Security level exceptions
- Non-invasive security: N/A
- Mitigation of other attacks: N/A
Validation history
| Date | Type | Lab |
|---|---|---|
| 2026-08-17 | Initial | atsec information security corporation |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2026-08-17