808bits

PIX 525 and PIX 535

FIPS 140-2 certificate #872 · Cisco Systems, Inc. · data as of 2026-08-28
Historical. RNG SP800-131A Revision 1 Transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode

Certificate

Certificate number872
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeHardware
EmbodimentMulti-chip standalone
VendorCisco Systems, Inc. · website
Hardware versions525 and 535
Firmware versions7.2.2.18

Module description

The market-leading Cisco PIX and ASA Security Appliance Series deliver robust user and application policy enforcement, multi-vector attack protection, and secure connectivity services in cost-effective, easy-to-deploy solutions. Cisco PIX Security Appliances and ASA 5500 Series Adaptive Security Appliances provide comprehensive security, performance, and reliability for network environments of all sizes.

Security level exceptions

  • Roles, Services, and Authentication: Level 2
  • Design Assurance: Level 2

Approved algorithms

AlgorithmCAVP certificate
AES209, 536
HMAC15, 283
RNG309
RSA107, 242
SHS285, 606
Triple-DES298, 538

Other algorithms

DES; Diffie-Hellman (key agreement; key establishment methodology provides 80 or 96 bits of encryption strength; non-compliant); EC Diffie-Hellman (key agreement; key establishment methodology provides 80 bits of encryption strength; non-compliant); HMAC MD5; MD5; RC4; RSA (key wrapping; key establishment methodology provides 112 bits of encryption strength; non-compliant less than 112 bits of encryption strength)

Validation history

DateTypeLab
2007-11-27InitialSAIC-VA
2010-05-28Update
2012-02-23Update

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2007-11-27, 2010-05-28, 2012-02-23

Source documents