Cryptographic Algorithms in FIPS Mode

The device in FIPS mode supports the following FIPS 140-2-approved cryptographic algorithms:
  • Advanced Encryption Algorithm (AES)
  • Secure Hash Algorithm (SHA) (including variants the module supports: SHA-256, SHA-384, and SHA-512)
  • Keyed-Hash Message Authentication Code (HMAC)
  • Deterministic Random Bit Generator (DRBG)
  • Rivest, Shamir, and Adleman public key encryption algorithm (RSA)
  • Elliptic curve Digital Signature Algorithm (ECDSA)
  • Key-Based Key Derivation Function (KBKDF)
  • SNMPv3
  • IKEv2 KDF SP800-135

Allowed exceptions include:

  • RSA Key Wrapping
  • Diffie-Hellman (DH)
  • Message Digest 5 (MD5)
  • Hash Message Authentication Codes - Message Digest 5 (HMAC-MD5) as used in RADIUS
  • Non-Deterministic Random Number Generator (NDRNG)
  • SSHv2 Key Derivation Function (KDF)

The device in FIPS mode does not support the following cryptographic algorithms:

  • RC4
  • 3-DES