Reference Guide

20|
Aruba 3000, 6000/M3 Mobility Controller FIPS 140-2 Level 2 Security Policy
Note:
o RSA (Cert. #1376; non-compliant with the functions from the CAVP Historical RSA List)
FIPS186-2:
ALG[ANSIX9.31]: Key(gen)(MOD: 1024 PubKey Values: 65537)
ALG[RSASSA-PKCS1_V1_5]: SIG(gen): 1024, SHS: SHA-1/SHA-256/SHA-384/SHA-
512, 2048, SHS: SHA-1
o ECDSA (Cert. #466; non-compliant with the functions from the CAVP Historical ECDSA List)
FIPS186-2:
SIG(gen): CURVES(P-256 P-384), SHS: SHA-1
ArubaOS UBOOT Bootloader implements the following FIPS-approved algorithms:
o RSA (Cert. #1380)
o SHS (Cert. #2250)
Non-FIPS Approved Algorithms Allowed in FIPS Mode
Diffie-Hellman (key agreement; key establishment methodology provides 112 bits of encryption
strength; non-compliant less than 112 bits of encryption strength)
EC Diffie-Hellman (key agreement; key establishment methodology provides 128 or 192 bits of
encryption strength)
NDRNGs
RSA (key wrapping; key establishment methodology provides 112 bits of encryption strength;
non-compliant less than 112 bits of encryption strength)
Non-FIPS Approved Algorithms
The cryptographic module implements the following non-approved algorithms that are not permitted for
use in the FIPS 140-2 mode of operations:
DES
HMAC-MD5
MD5
RC4