Cryptographic Algorithms in FIPS Mode

The device in FIPS mode supports the following FIPS 140-3-approved cryptographic algorithms:
  • Advanced Encryption Algorithm (AES)
  • Secure Hash Algorithm (SHA) (including variants the module supports: SHA-256, SHA-384, and SHA-512)
  • Keyed-Hash Message Authentication Code (HMAC)
  • Deterministic Random Bit Generator (DRBG)
  • Rivest, Shamir, and Adleman public key encryption algorithm (RSA)
  • Elliptic curve Digital Signature Algorithm (ECDSA)
  • Key-Based Key Derivation Function (KBKDF)
  • KAS-FFC-SSC
  • KAS-ECC-SSC
  • SP800-135 KDF - TLS, SSH, IKEv2, and SNMP

Allowed exceptions include:

  • --

The device in FIPS mode does not support the following cryptographic algorithms:

  • Message Digest 5 (MD5)
  • Hash Message Authentication Codes - Message Digest 5 (HMAC-MD5) as used in RADIUS
  • Non-Deterministic Random Number Generator (NDRNG)
  • RC4
  • 3-DES