Cryptographic Algorithms in FIPS Mode
The device in FIPS mode supports the following FIPS 140-2-approved cryptographic algorithms:
- Advanced Encryption Algorithm (AES)
- Secure Hash Algorithm (SHA) (including variants the module supports: SHA-256, SHA-384, and SHA-512)
- Keyed-Hash Message Authentication Code (HMAC)
- Deterministic Random Bit Generator (DRBG)
- Rivest, Shamir, and Adleman public key encryption algorithm (RSA)
- Elliptic curve Digital Signature Algorithm (ECDSA)
- Key-Based Key Derivation Function (KBKDF)
- SNMPv3
- IKEv2 KDF SP800-135
Allowed exceptions include:
- RSA Key Wrapping
- Diffie-Hellman (DH)
- Message Digest 5 (MD5)
- Hash Message Authentication Codes - Message Digest 5 (HMAC-MD5) as used in RADIUS
- Non-Deterministic Random Number Generator (NDRNG)
- SSHv2 Key Derivation Function (KDF)
The device in FIPS mode does not support the following cryptographic algorithms: