All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Juniper Networks EX4300-48MP Ethernet Switch

Certificate#4959StandardFIPS 140-3Level1TypeHardwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorJuniper Networks, Inc.
High review priority  ·  no TCB surface named  ·  last validated 17 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeHardware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date2/6/2027
CaveatInterim validation. When operated in Approved mode. When installed, initialized and configured as specified in Section 11 of the Security Policy. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.
VendorJuniper Networks, Inc.

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Juniper Networks EX4300-48MP Ethernet Switch
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>firmware load</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>self-test<br/>Status output<br/>Show status</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>SSH<br/>HTTPS<br/>library named: openssl</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>kernel</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Juniper Networks EX4300-48MP Ethernet Switch
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>firmware load</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>self-test<br/>Status output<br/>Show status</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>SSH<br/>HTTPS<br/>library named: openssl</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>kernel</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Juniper Networks EX4300-48MP Ethernet Switch Firmware Version: Junos OS 22.4R2.8 Document Version: 1.0 Date: December 28th, 2023 Prepared by: www.acumensecurity.net Public Material – May be reproduced only in its original entirety (without revision).

Page 2
Table of Contents
#SectionPage
Page 3

1. General Introduction Federal Information Processing Standards Publication 140-3

Page 4
ISO/IEC 24759 Section 6. [Number Below]FIPS 140-3 Section TitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication3
5Software/Firmware security1
6Operational environment1
7Physical security1
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacksN/A

This document describes the cryptographic module security policy for the Juniper Networks, Inc. Juniper Networks EX4300-48MP Ethernet Switch (Hardware version EX4300-48MP) cryptographic module (also referred to as the “module” hereafter) with firmware version Junos OS 22.4R2.8. The module has a multichip standalone embodiment. It contains specification of the security rules, under which the cryptographic module operates, including the security rules derived from the requirements of the FIPS 140-3 standard. The following table lists the level of validation for each area in FIPS 140-3: Table 1 - Security Levels The module claims an overall Security Level 1. Public Material – May be reproduced only in its original entirety (without revision).

Page 5
ModelHardware [Part Number and Version]Firmware VersionDistinguishing Features
EX4300-48MPJunos OS 22.4R2.8Power PN: JPSU-1400-AC- AFO RE PN: Built-in Routing Engine (EX4300- 48MP RE)

2. Cryptographic Module Specification The version of the module are as follows: Table 2

Page 6

Figure 2 - EX4300-48MP (Rear Panel) Figure 3 - EX4300-48MP Schematic (Front Panel)

1 —QR code 5 — Factory Reset/Mode button

2 —Mini-USB console port 6 — 4-port 1-Gigabit Ethernet/10-Gigabit Ethernet SFP+ uplink module

3 —Chassis status LEDs
4 —Port status mode LEDs

Figure 4 - EX4300-48MP Schematic (Rear Panel) Public Material – May be reproduced only in its original entirety (without revision).

Page 7
1 —Management port7—Empty slot for AC power supply
2 —ESD point8—QSFP+ ports (dedicated Virtual Chassis ports)
3—Fan module9—Console port
4—Serial number label10—Reset button
5—CLEI code label11—USB port

6—AC power supply in slot 0 The module claims an overall Security Level of 1 with all individual sections at a Security Level 1 with the exceptions of Roles, Services and Authentication (claimed at Security Level 3). The module does not implement any non-invasive security mitigations or mitigations of other attacks and thus the requirements per these sections are inapplicable. Figure 5

Page 8

Modes Of Operation The module supports one Approved mode of operation and a non-Approved mode of operation. The module must always be zeroised when switching between the Approved mode of operation and the non-Approved mode of operation and vice versa. Approved Mode The hardware versions contained in Table 2, with Junos OS 22.4R2.8 installed, contain one Approved mode of operation and a non-Approved mode of operation. The Junos OS 22.4R2.8 firmware image must be installed on the module. The module is configured during initialization by the Crypto Officer to operate in the Approved mode or the non-Approved mode. The Crypto Officer can place the module in the Approved mode of operation by following the instructions specified in Section 11 Life-Cyle Assurance in this document (Crypto Officer guidance). The Crypto Officer can verify that the cryptographic module is in the Approved mode by observing the console prompt and running the “show version” command. When operating in the Approved mode, the prompt will read “<operator>@<device name>:fips#” (e.g. crypto-officer@ EX4300-48MP:fips#). The “show version” command will allow the Crypto Officer to verify that the validated firmware version is running on the module. The Crypto Officer can also use the “show system fips chassis level” command (returns “level 1”) to determine if the module is operating in the Approved mode. The Approved mode is entered when the module is configured for it and successfully passes all self-tests (both pre-operational and conditional cryptographic algorithm self-tests (CASTs)). The CASTs must pass in both the routing engine (RE). Non-Approved Mode The cryptographic module supports a non-Approved mode of operation. When operated in the nonApproved mode of operation, the module supports non-Approved algorithms identified below in this section as well as the algorithms supported in the Approved mode of operation. The Crypto Officer can place the module into the non-Approved mode of operation by following the instructions in the Section

11 Life-Cyle Assurance in this document (Crypto Officer guidance).

Degraded Operation The module does not support a degraded mode of operation. Public Material – May be reproduced only in its original entirety (without revision).

Page 9

Overall Security Rules of Operation The module design corresponds to the security rules below. The term shall in this context specifically refers to a requirement for correct usage of the module in the Approved mode; all other statements indicate a security rule implemented by the module.

  1. The module clears previous authentications on power cycle.
  2. When the module has not been placed in a valid role, the operator does not have access to any cryptographic services.
  3. Self-tests do not require any operator action.
  4. Data output is inhibited during SSP generation, self-test execution, zeroisation, and error states.
  5. Status information does not contain SSPs or sensitive data that if misused could lead to a compromise of the module.
  6. There are no restrictions on which SSPs are zeroised by the zeroisation service.
  7. The module does not support a maintenance interface or role.
  8. The module does not output intermediate key values.
  9. The module does not output plaintext CSPs.
  10. The Crypto officer shall verify that the firmware image to be loaded on the module is a FIPS 140-

3 validated image. If any non-validated firmware image is loaded the module will no longer be a

validated module.

  1. The Crypto Officer shall retain control of the module while zeroisation is in process.
  2. The virtual chassis feature is not supported in Approved mode and shall not be configured on the module.
  3. MACsec protocol IV generation: • The AES GCM IV construction is performed internal to the module in compliance with IEEE 802.1AEand its amendments. The IV length is 96 bits (per SP 800-38D). The module ensures the IV is constructed deterministically per Section 8.2 in SP 800-38D and the MACsec standard IEEE 802.1AE as a result of concatenating the fixed field (SCI) and invocation field (PN). • The module can take on the role of Peer or Authenticator in reference to the MACsec protocol. • The module shall only be used with other FIPS 140-3 validated modules when supporting the MACsec protocol in the role of a Peer/Authenticator for providing the remaining functionalities. • If the module loses power and then it is restored, then a new key shall be established for use with the AES GCM encryption/decryption processes. • The link between the Peer and Authenticator, used in the MACsec communication, shall be secure to prevent the possibility for an attacker to introduce foreign equipment into the local area network.
  4. The module shall not be configured to use a radius server and the radius server capability shall be disabled.
  5. No parts of the SSH and MACsec protocols, other than the approved cryptographic algorithms and the KDFs, have been tested by the CAVP and CMVP. Public Material – May be reproduced only in its original entirety (without revision).
Page 10
CAVP Cert1Algorithm and StandardMode/MethodDescription/Key Size/Key StrengthUse/Function
A4301AES-CBCCBCKey sizes 128, 192, 256 with 128 to 256 bits of key strengthEncrypt, Decrypt
A4301AES-CTRCTRKey sizes 128, 192, 256 with 128 to 256 bits of key strengthEncrypt, Decrypt
A4301AES-ECBECBKey sizes 128, 192, 256 with 128 to 256 bits of key strengthEncrypt, Decrypt
A4301AES-GCMGCMKey sizes 128, 192, 256 with 128 to 256 bits of key strengthEncrypt, Decrypt
A4301ECDSA KeyGen (FIPS186-4)ECDSA KeyGenCurve sizes P-256, P-384, P-521 with 128 to 256 bits of strengthKey Generation
A4301ECDSA KeyVer (FIPS186-4)ECDSA KeyVerCurve sizes P-256, P-384, P-521 with 128 to 256 bits of strengthKey Verification
A4301ECDSA SigGen (FIPS186-4)ECDSA SigGenCurve sizes P-256 (SHA2-256), P-384 (SHA2-384), P-521 (SHA2-512) with 128 to 256 bits of strengthSignature Generation
A4301ECDSA SigVer (FIPS186-4)ECDSA SigVerCurve sizes P-256 (SHA2-256), P-384 (SHA2-384), P-521 (SHA2-512) with 128 to 256 bits of strengthSignature Verification
A4301HMAC DRBGHMAC-SHA2- 256Key size 256-bits with 256-bits of key strengthKey size 256-bits with 256-bits of keyRandom Bit Generation
A4301HMAC-SHA-1SHA-1SHA-1: Key size 160Message
bits with 160 bits ofAuthentication, DRBG
key strengthPrimitive

There are algorithms, modes, and key/moduli sizes that have been CAVP-tested but are not used by any approved service of the module. Only the algorithms, modes/methods, and key lengths/curves/moduli shown in this table are used by an approved service of the module. Public Material – May be reproduced only in its original entirety (without revision).

Page 11
CAVP Cert1Algorithm and StandardMode/MethodDescription/Key Size/Key StrengthUse/Function
A4301HMAC-SHA2-256SHA2-256SHA2-256: Key size:Message
256 bits with 256-Authentication, DRBG
bits of key strengthPrimitive
A4301HMAC-SHA2-512SHA2-512SHA2-512: Key size:Message
512 bits with 512-Authentication, DRBG
bits of key strengthPrimitive
A4301KAS-ECC-SSC SP800-56Ar3Ephemeral UnifiedCurve sizes P-256, P-384, P-521 with 128 bits to 256 bits of strengthKey Agreement Shared Secret Computation
A4301KAS-FFC-SSC SP800-56Ar3dhEphemeralDomain Parameter Generation Method: MODP- 2048 with 2048 bits of strengthKey Agreement Shared Secret Computation
A4301KDF SSHSSHKey sizes 128, 192, 256 with 128 to 256 bits of key strengthKey Derivation Function
A4301RSA KeyGen (FIPS186-4)RSA KeyGenModuli 2048, 3072 and 4096 bits with 112, 128 and 152 bits of strengthKey Generation
A4301RSA SigGen (FIPS186-4)RSA SigGenModuli 2048 (SHA2- 256, SHA2-512), 3072 (SHA2-256, SHA2-512) and 4096 (SHA2-256, SHA2- 512) bits with 112, 128 and 152 bits of strengthSignature Generation
A4301RSA SigVer (FIPS186-4)RSA SigVerModuli 2048 (SHA2- 256, SHA2-512), 3072 (SHA2-256, SHA2-512) and 4096 (SHA2-256, SHA2- 512) bits with 112, 128 and 152 bits of strengthSignature Verification
A4301SHA-1SHA-1SHA-1: Key size 160 bits with 160 bits of key strengthMessage Digest Generation
A4301SHA2-256SHA2-256SHA2-256: Key size 256 bits with 256- bits of key strengthMessage Digest Generation

Public Material – May be reproduced only in its original entirety (without revision).

Page 12
CAVP Cert1Algorithm and StandardMode/MethodDescription/Key Size/Key StrengthUse/Function
A4301SHA2-384SHA2-384SHA2-384: Key size 384 bits with 256- bits of key strengthMessage Digest Generation
A4301SHA2-512SHA2-512SHA2-512: Key size 512 bits with 256- bits of key strengthMessage Digest Generation
A4303HMAC DRBGHMAC-SHA2- 256Key size 256-bits with 256-bits of key strengthRandom Bit Generation
A4303HMAC-SHA-1SHA-1SHA-1: Key size 160 bits with 160 bits of key strengthMessage Authentication, DRBG primitive
A4303HMAC-SHA2-256SHA2-256SHA2-256: Key size: 256 bits with 256- bits of key strengthMessage Authentication, DRBG primitive
A4303SHA-1SHA-1SHA-1: Key size 160 bits with 160 bits of key strengthMessage Digest Generation
A4303SHA2-256SHA2-256SHA2-256: Key size 256 bits with 256- bits of key strengthMessage Digest Generation
A4303SHA2-384SHA2-384SHA2-384: Key size 384 bits with 256- bits of key strengthMessage Digest Generation
A4303SHA2-512SHA2-512SHA2-512: Key size 512 bits with 256- bits of key strengthMessage Digest Generation
A4304AES-CBCCBCKey sizes 128, 192, 256 with 128 to 256 bits of key strengthEncrypt, Decrypt
A4304AES-CMACCMACKey sizes 128 and 256 with 128 to 256 bits of key strengthGenerate, Verify
A4304AES-ECBECBKey sizes 128, 192, 256 with 128 to 256 bits of key strengthEncrypt, Decrypt

Public Material – May be reproduced only in its original entirety (without revision).

Page 13
CAVP Cert1Algorithm and StandardMode/MethodDescription/Key Size/Key StrengthUse/Function
A4304AES-KWKWKey size 128 bits with 128 bits of key strengthEncrypt, Decrypt
A4304KDF SP 800-108CounterKey sizes 128 and 256 with 128 to 256 bits of key strengthKey Derivation
A4306HMAC-SHA-1SHA-1SHA-1: Key size 160 bits with 160 bits of key strengthMessage Authentication, DRBG primitive
A4306HMAC-SHA2-256SHA2-256SHA2-256: Key size: 256 bits with 256- bits of key strengthMessage Authentication, DRBG primitive
A4306SHA-1SHA-1SHA-1: Key size 160 bits with 160 bits of key strengthMessage Digest Generation
A4306SHA2-256SHA2-256SHA2-256: Key size 256 bits with 256- bits of key strengthMessage Digest Generation
A4306SHA2-512SHA2-512SHA2-512: Key size 512 bits with 256- bits of key strengthMessage Digest Generation
Vendor AffirmedCKG NIST SP 800-133r2Section 4 Section 5.1 Section 5.2 Section 6.2.1Section 4: Asymmetric seed generation using an unmodified output from an Approved DRBG; Section 5.1: Key Pairs for Digital Signature Schemes; Section 5.2: Key Pairs for Key Establishment; Section 6.2.1: Derivation of symmetric keysCryptographic Key Generation

Public Material – May be reproduced only in its original entirety (without revision).

Page 14
CAVP Cert1Algorithm and StandardMode/MethodDescription/Key Size/Key StrengthUse/Function
KAS-ECC-SSC SP800- 56Ar3/A4301 KDF SSH/A4301KAS-1SP 800-56Arev3 KAS-ECC per IG D.F Scenario 2 path (2)P-256, P-384, P-521 curvesKey Agreement for SSHv2
KAS-FFC-SSC SP800- 56Ar3/A4301 KDF SSH/A4301KAS-2SP 800-56Arev3 KAS-FFC per IG D.F Scenario 2 path (2)MODP-2048Key Agreement for SSHv2
AES- CBC/A4301 AES- CTR/A4301 HMAC-SHA- 1/A4301 HMAC-SHA2- 256/A4301 HMAC-SHA2- 512/A4301KTS-1SP 800-38A AES CBC, CTR and HMAC 198 per IG D.G128, 192, and 256- bit keys providing 128, 192, or 256 bits of encryption strengthKey Transport for SSHv2
AES- KW/A4304KTS-2SP 800-38D and SP 800-38F KTS (key wrapping) per IG D.G128 bit keys providing 128 bits of encryption strengthKey Transport for MACsec

Table 3

Page 15
Algorithm/FunctionUse/Function
RSA with key size less than 2048SSH
ECDSA with ed25519 curveSSH
EC Diffie-Hellman with ed25519 curveSSH
ARCFOURSSH
BlowfishSSH
CASTSSH
DSA (SignGen, SigVer, non-compliant)SSH
HMAC-MD5SSH
HMAC-RIPEMD160SSH
UMACSSH
Page 16
Physical portLogical interfaceData that passes over port/interface
Ethernet (Management Port)Control input interface, Data input interface, Data output interface, Status output interfaceLAN, Communications/remote management
SerialControl input interface, Data input interface, Data output interface, Status output interfaceConsole Serial Port
USBControl input interface, Data input interfaceUSB port, load Junos Image
PowerPower interfacePower connector, Power over Ethernet
Alarm LEDsStatus output interfaceStatus indicator lighting
Reset ButtonControl input interfaceReset signal

3. Cryptographic Module Interfaces Table 5

Page 17
RoleServiceInputOutput
Crypto OfficerConfigure security (security relevant)Commands (SSH configuration: set system services ssh root-login allow; MACsec configuration: set security macsec connectivity-association connectivity-association- name; set security macsec connectivity-association connectivity-association- name security-mode static-cak)Traffic
Configure (non-security relevant)Commands (miscellaneous commands e.g., for IP address configuration, routing protocols, etc.)Traffic
Show statusCommand (show)CLI output
Show status (LED)N/ALED
Show module’s versioning informationCommand (show version)CLI output
Perform zeroisationCommand (request system zeroize)N/A
Perform approved security functions (SSH connection)Command (set system services ssh root-login allow)SSH session
Perform approved security functions (MACsec connection)Commands (set security macsec connectivity-association connectivity-association- name;MACsec session

4. Roles, Services, and Authentication The module supports two roles: Crypto Officer (CO) and User. The module supports concurrent operators but does not support a maintenance role and/or bypass capability. The module enforces the separation of roles using identity-based operator authentication. The module implements two forms of identity-based authentication, username, and password over the console and SSH connections, as well as username and an ECDSA or RSA public key-based authentication over SSH. The Crypto Officer role configures and monitors the module via a console or SSH connection. As root or super-user, the Crypto Officer has permission to view and configure passwords and public keys within the module. The User role monitors the module via the console or SSH. The User role does not have the permission to modify the configuration. Public Material – May be reproduced only in its original entirety (without revision).

Page 18
RoleServiceInputOutput
set security macsec connectivity-association connectivity-association- name security-mode static-cak)
Console accessUsername, password (set system login user <username> class <crypto-officer/user class> operator authentication plaintext- password)N/A
Perform self-tests (remote reset)Control input/reset signal (request system reboot)N/A
Perform self-tests (local reset)Control input/reset signalN/A
Load imageImage, commandsN/A
UserShow statusCommand (show)CLI Output
Show status (LED)N/ALED
Show module’s versioning informationCommand (show version)CLI output
Perform approved security functions (SSH connection)Commands (set system services ssh root-login allow)SSH session
Console accessUsername, password (set system login user <username> class <crypto-officer/user class> operator authentication plaintext- password)N/A
Perform self-tests (remote reset)Control input/reset signal (request system reboot)N/A
Perform self-tests (local reset)Control input/reset signalN/A
RoleAuthentication MethodAuthentication Strength
Crypto Officer (CO), User1. Username and password over the console and SSH 2. Username and ECDSA public key over SSH 3. Username and RSA public key over SSH1. For Password Authentication: The module enforces 10- character passwords (at minimum) chosen from the 96 human readable ASCII characters;

Public Material – May be reproduced only in its original entirety (without revision).

Page 19
RoleAuthentication MethodAuthentication Strength
The maximum password length is 20-characters; Thus, the probability of a successful random attempt is 1/(96^10), which is less than 1/1,000,000 (million) The module enforces a timed access mechanism as follows: For the first two failed attempts (assuming 0 time to process), no timed access is enforced; Upon the third attempt, the module enforces a 5- second delay; Each failed attempt thereafter results in an additional 5-second delay above the previous (e.g., 4th failed attempt = 10- second delay, 5th failed attempt = 15-second delay, 6th failed attempt = 20- second delay, 7th failed attempt = 25- second delay); This leads to a maximum of 7 possible attempts in a one-minute period for each getty; The best approach for the attacker would be to disconnect after 4 failed attempts and wait for a new getty to be spawned; This would allow the attacker to perform roughly 9.6 attempts per minute (576 attempts per hour/60 mins); this would be rounded down to 9 per minute, because there is no such thing as 0.6 attempts; The probability of a success with multiple consecutive attempts in a one-minute period is

Public Material – May be reproduced only in its original entirety (without revision).

Page 20
RoleAuthentication MethodAuthentication Strength
9/(96^10), which is less than 1/100,000 2. ECDSA signature verification: SSH public- key authentication; The module supports ECDSA (P-256, P-384, and P-521), which has a minimum equivalent computational resistance to attack of either 2128, 2192 or 2256 depending on the curve; Thus, the probability of a successful random attempt is 1/(2128), which is less than 1/1,000,000 (million) Configurable SSH connection establishment rate limits the number of connection attempts, and thus failed authentication attempts in a one-minute period to a maximum of 15,000 attempts; The probability of a success with multiple consecutive attempts in a one-minute period is 15,000/(2128), which is less than 1/100,000 3. RSA signature verification: SSH public-key authentication; The module supports RSA (2048, 4096 bits), which has a minimum equivalent computational resistance to attack of 2112 (2048 bits); Thus, the probability of a successful random attempt is 1/ (2112), which is less than 1/1,000,000 (million)

Public Material – May be reproduced only in its original entirety (without revision).

Page 21
RoleAuthentication MethodAuthentication Strength
Configurable SSH connection establishment rate limits the number of connection attempts, and thus failed authentication attempts in a one-minute period to a maximum of 15,000 attempts; The probability of a success with multiple consecutive attempts in a one-minute period is 15,000/(2112), which is less than 1/100,000
ServiceDescriptionApproved Security FunctionsKeys and/or SSP’sRolesAccess rights to Keys and/or SSP’sIndicator
Configure security (security relevant)Security relevant configuratio nAll (per Table 3)SSH Private Host Key SSH ECDH Private Key SSH DH Private Key SSH Session Key User Password CO Password HMAC_DRBG Key Value HMAC_DRBG V value HMAC_DRBG entropy input HMAC_DRBG seed HMAC_DRBG output MACsec PSK MACsec CAK MACsec CKN MACsec SAK MACsec KEK MACsec ICK ECDH Shared Secret DH Shared Secret HMAC Key SSH Public Host Key User Authentication Public KeysCrypto Officer (CO)(G, E) (G, E) (G, E) (G, E) (W, E) (W, E) (G, E) (G, E) (G, E) (G, E) (G, E) (W, E) (W, E) (W, E) (G, E, R) (G, E) (G, E) (G, E) (G, E) (G, E) (G, E) (W, E)Global Approved Mode indicator “fips” at the CLI combined with successful completion of each service

Public Material – May be reproduced only in its original entirety (without revision).

Page 22
ServiceDescriptionApproved Security FunctionsKeys and/or SSP’sRolesAccess rights to Keys and/or SSP’sIndicator
CO Authentication Public Keys JuniperRootCA PackageCA SSH ECDH Public Key SSH DH Public Key(W, E) (W, E) (W, E) (G, E) (G, E)
Configure (non- security relevant)Non- security relevant configuratio nN/AN/ACrypto Officer (CO)N/AGlobal Approved Mode indicator “fips” at the CLI combined with successful completion of each service
Show statusQuery the module statusN/AN/ACrypto Officer (CO), UserN/AGlobal Approved Mode indicator “fips” at the CLI combined with successful completion of each service
Show status (LED)LEDs on the module provide physical status outputN/AN/ACrypto Officer (CO), User, Unauth orisedN/ALED(s) on the chassis turned on
Show module’sQuery the module’sN/AN/ACrypto OfficerN/AGlobal Approved

Public Material – May be reproduced only in its original entirety (without revision).

Page 23
Service versioning informationDescription versioning informationApproved Security FunctionsKeys and/or SSP’sRoles (CO), UserAccess rights to Keys and/or SSP’sIndicator Mode indicator “fips” at the CLI combined with successful completion of each service
Perform zeroisationDestroy all SSPsN/ASSH Private Host Key SSH ECDH Private Key SSH DH Private Key SSH Session Key User Password CO Password HMAC_DRBG Key Value HMAC_DRBG V value HMAC_DRBG entropy input HMAC_DRBG seed HMAC_DRBG output MACsec PSK MACsec CAK MACsec CKN MACsec SAK MACsec KEK MACsec ICK ECDH Shared Secret DH Shared Secret HMAC Key SSH Public Host Key User Authentication Public Keys CO Authentication Public Keys JuniperRootCA PackageCA SSH ECDH Public Key SSH DH Public KeyCrypto Officer (CO)(Z)Global Approved Mode indicator “fips” at the CLI combined with successful completion of each service

Public Material – May be reproduced only in its original entirety (without revision).

Page 24
ServiceDescriptionApproved Security FunctionsKeys and/or SSP’sRolesAccess rights to Keys and/or SSP’sIndicator
Perform approved security functions (SSH connection)Initiate SSH connection for SSH monitoring and control (CLI)ECDSA (P-256, SHA2-256, KeyGen, SIgVer, Cert. #A4301), RSA (2048 bits, SHA2-256, SHA2- 512, KeyGen, SIgVer, Cert. #A4301), KAS- ECC-SSC (P-256, P- 384, P-512, Cert. #A4301), KAS-FFC- SSC (MODP 2048, Cert. #A4301), AES (CBC, CTR 128, 192, 256 bits, Cert. #A4301), KDF SSH (Cert. #A4301), HMAC_DRBG (HMAC-SHA2-256, CAVP Certs. A4303, A4301), HMAC (SHA-1, SHA2-256, SHA2- 512, CAVP Certs. #A4303, #A4301, #A4306; SHA2- 384, CAVP Certs. #A4303); SHA (SHA-1, SHA2-256, SHA2-512, CAVP Certs. #A4303, #A4301, #A4306; SHA2-384, CAVP Certs. #A4303), CKGSSH Private Host Key SSH ECDH Private Key SSH DH Private Key SSH Session Key HMAC_DRBG Key Value HMAC_DRBG V value HMAC_DRBG entropy input HMAC_DRBG seed HMAC_DRBG output ECDH Shared Secret DH Shared Secret HMAC Key SSH Public Host Key User SSH ECDH Public Key SSH DH Public KeyCrypto Officer (CO), User(G, E)Global Approved Mode indicator “fips” at the CLI combined with successful completion of each service

Public Material – May be reproduced only in its original entirety (without revision).

Page 25
ServiceDescriptionApproved Security FunctionsKeys and/or SSP’sRolesAccess rights to Keys and/or SSP’sIndicator
Perform approved security functions (MACsec connection)Initiate MACsec connectionAES (GCM, CMAC, 128, 256 bits, KW, 128 bits, Cert. #4369), SP 800-108 KDF (Cert. #A4304)MACsec PSK MACsec CAK MACsec CKN MACsec SAK, MACsec KEK, MACsec ICKCrypto Officer (CO)(W, E) (W, E) (W, E) (G, R, E) (G, E) (G, E)Global Approved Mode indicator “fips” at the CLI combined with successful completion of each service
Console AccessConsole monitoring and control (CLI)N/AN/ACrypto Officer (CO), UserN/AGlobal Approved Mode indicator “fips” at the CLI combined with successful completion of each service
Perform self-tests (remote reset)Software initiated reset, performs self-tests on demandAll (per Table 3)SSH ECDH Private Key, SSH DH Private Key, SSH Session Key, HMAC_DRBG Key Value HMAC_DRBG V value HMAC_DRBG entropy input HMAC_DRBG seedCrypto Officer (CO), User(Z) (Z) (Z) (G, Z, E) (G, Z, E) (G, Z, E) (G, Z, E) (G, Z, E)Global Approved Mode indicator “fips” at the CLI combined with successful completion of each service

Public Material – May be reproduced only in its original entirety (without revision).

Page 26
ServiceDescriptionApproved Security FunctionsKeys and/or SSP’sRolesAccess rights to Keys and/or SSP’sIndicator
HMAC_DRBG output MACsec PSK (Z) MACsec CAK (Z) MACsec CKN (Z) MACsec SAK (Z) MACsec KEK (Z) MACsec ICK (Z) ECDH Shared Secret DH Shared Secret HMAC Key SSH ECDH Public Key SSH DH Public Key(Z) (Z) (Z) (Z) (Z) (Z) (Z) (Z) (G, Z, E) (G, E) (G, E)
Perform self-tests (local reset)Hardware reset or power cycleAll (per Table 3)SSH ECDH Private Key, SSH DH Private Key, SSH Session Key, HMAC_DRBG Key Value HMAC_DRBG V value HMAC_DRBG entropy input HMAC_DRBG seed HMAC_DRBG output MACsec PSK MACsec CAK MACsec CKN MACsec SAK MACsec KEK MACsec ICK ECDH Shared Secret DH Shared Secret HMAC Key SSH ECDH Public Key SSH DH Public KeyCrypto Officer (CO), User, Unauth orised(Z) (Z) (Z) (G, Z, E) (G, Z, E) (G, Z, E) (G, Z, E) (G, Z, E) (Z) (Z) (Z) (Z) (Z) (Z) (Z) (Z) (G, Z, E) (G, E) (G, E)Global Approved Mode indicator “fips” at the CLI combined with successful completion of each service
Load ImageVerification and loading of a validated firmware image into the router/switc hECDSA (P-256, SHA2-256, SigVer, CAVP Cert. #A4301)N/ACrypto Officer (CO)N/AGlobal Approved Mode indicator “fips” at the CLI combined with successful completion

Public Material – May be reproduced only in its original entirety (without revision).

Page 27

Service

Description

Approved Security Functions

Keys and/or SSP’s

Roles

Access rights to Keys and/or SSP’s

Indicator of each service

ServiceDescriptionAlgorithms AccessedRoleIndicator
Configure security (security relevant)Security relevant configurationAll (per Table 3)Crypto Officer (CO)Lack of the global Approved Mode indicator "fips" at the CLI combined with successful completion of the service
Configure (non- security relevant)Non-security relevant configurationN/ACrypto Officer (CO)Lack of the global Approved Mode indicator "fips" at the CLI combined with successful completion of the service
Show statusQuery the module statusN/ACrypto Officer (CO), UserLack of the global Approved Mode indicator "fips" at the CLI combined with successful completion of the service
Show status (LED)LEDs on the module provide physical status outputN/ACrypto Officer (CO), User, UnauthorisedLED(s) on the chassis turned on
Show module’s versioning informationQuery the module’s versioning informationN/ACrypto Officer (CO), UserLack of the global Approved Mode indicator "fips" at the CLI combined with successful completion of the service
Perform zeroisationDestroy all SSPsN/ACrypto Officer (CO)Lack of the global Approved Mode indicator "fips" at

G = Generate: The module generates or derives the SSP. R = Read: The SSP is read from the module (e.g. the SSP is output). W = Write: The SSP is updated, imported, or written to the module. E = Execute: The module uses the SSP in performing a cryptographic operation. Public Material – May be reproduced only in its original entirety (without revision).

Page 28
ServiceDescriptionAlgorithms AccessedRoleIndicator
the CLI combined with successful completion of the service
Perform approved security functions (SSH connection)Initiate SSH connection for SSH monitoring and control (CLI)AES (CBC, CTR, 128, 192 and 256 bits); KAS-ECC-SSC (P-256, P-384, P-521); KAS-FFC-SSC (MODP 2048) RSA (2048, 4096 bits); ECDSA (P-256); HMAC (SHA-1, SHA2-256, SHA2- 512); SHA (SHA-1, SHA2-256, SHA2- 512); SSH KDF; RSA (key size <= 2048); ECDSA (ed25519 curve); EC DH (ed25519 curve); ARCFOUR ; Blowfish; CAST; DSA (SignGen, SigVer, non- compliant); HMAC-MD5; HMAC-RIPEMD160; UMACCrypto Officer (CO), UserLack of the global Approved Mode indicator "fips" at the CLI combined with successful completion of the service
Perform approved security functions (MACsec connection)Initiate MACsec connectionAES (GCM, 128, 256 bits), SP 800-108 KDF AES (CTR 128, 256 bits), HMAC (SHA2-256) SHA (SHA2-256)Crypto Officer (CO)Lack of the global Approved Mode indicator "fips" at the CLI combined with successful completion of the service
Console AccessConsole monitoring and control (CLI)N/ACrypto Officer (CO), UserLack of the global Approved Mode indicator "fips" at

Public Material – May be reproduced only in its original entirety (without revision).

Page 29
ServiceDescriptionAlgorithms AccessedRoleIndicator
the CLI combined with successful completion of the service
Perform self- tests (remote reset)Software initiated reset, performs self- tests on demandAll (per Table 3)Crypto Officer (CO), UserLack of the global Approved Mode indicator "fips" at the CLI combined with successful completion of the service
Perform self- tests (local reset)Hardware reset or power cycleAll (per Table 3)Crypto Officer (CO), User, UnauthorisedLack of the global Approved Mode indicator "fips" at the CLI combined with successful completion of the service
Load ImageVerification and loading of a validated firmware image into the router/switch.ECDSA (P-256, SHA2-256)Crypto Officer (CO)Lack of the global Approved Mode indicator "fips" at the CLI combined with successful completion of the service

Table 9

Page 30

5. Software/Firmware Security The module performs the firmware integrity check using ECDSA P-256 with SHA2-256. The operator can initiate the integrity test on demand by rebooting the module. The module firmware image is delivered in the form of a pre-compiled tarball (.tgz). The module supports loading of firmware from an external source and a firmware load test using ECDSA P-256 with SHA2-256 is performed in support of the load. Public Material – May be reproduced only in its original entirety (without revision).

Page 31

6. Operational Environment The module contains a limited operational environment. The Junos OS 22.4R2.8 operating system is contained within the module, i.e., the tested configurations listed in Table 2 of this document. Security rules and restrictions for configuration of the operational environment have been specified in Section 2 (Overall Security Rules of Operation) and Section 11 (Installing The Firmware Image and Enabling the Approved Mode of Operation) of this document. Public Material – May be reproduced only in its original entirety (without revision).

Page 32

7. Physical Security The module’s physical embodiment is that of a multi-chip standalone meeting Level 1 Physical Security requirements. The module is completely enclosed in a rectangular nickel or clear zinc coated, cold rolled steel, plated steel and brushed aluminum enclosure. The module enclosure is made of production grade materials. There are no ventilation holes, gaps, slits, cracks, slots, or crevices that would allow for any sort of observation of any component contained within the cryptographic boundary. No actions are required by the operator to ensure that physical security is maintained. Public Material – May be reproduced only in its original entirety (without revision).

Page 33

8. Non-invasive Security The module does not implement any non-invasive security mitigations and thus the requirements per this section do not apply to the module. Public Material – May be reproduced only in its original entirety (without revision).

Page 34
Key/SSP Name/ TypeStrengthSecurity Function and Cert. NumberGener- ationImport /ExportEstablish- mentStorageZero- isationUse & related keys
SSH Private Host Key CSP128 bits for ECDSA, 112 bits for RSAECDSA (P-256, SHA2- 256, KeyGen, Cert. #A4301), RSA (2048 bits, SHA2- 256, SHA2- 512, KeyGen, Cert. #A4301), HMAC_D RBG (HMAC- SHA2- 256, Cert. #A4301) HMAC (SHA2- 256, Cert. #A4301) SHA (SHA2- 256, SHA2- 512, Cert. #A4301), CKGGenerated internally using NIST SP 800- 90Ar1 HMAC_DR BGImport: N/A Export: N/AN/APlaintext: PersistentZeroisation command (request system zeroize)Host keypairs generated, used to identify the host
SSH ECDH Private Key CSP128 bits, 192 bits, 256 bitsKAS-ECC- SSC (P-256, P-384, P-512, Cert. #A4301), HMAC_D RBGGenerated internally using NIST SP 800- 90Ar1 HMAC_DR BGImport: N/A Export: N/AN/APlaintext: RAMZeroisation command (request system zeroize), power-cycleEphemeral EC Diffie- Hellman private key used in SSH

9. Sensitive Security Parameter Management Public Material – May be reproduced only in its original entirety (without revision).

Page 35
Key/SSP Name/ TypeStrengthSecurity Function and Cert. NumberGener- ationImport /ExportEstablish- mentStorageZero- isationUse & related keys
(HMAC- SHA2- 256, Cert. #A4301) HMAC (SHA2- 256, Cert. #A4301) SHA (SHA2- 256, SHA2- 512, Cert. #A4301), CKG
SSH DH Private Key CSP112 bitsKAS-FFC- SSC (MODP 2048, Cert. #A4301), HMAC_D RBG (HMAC- SHA2- 256, Cert. #A4301) HMAC (SHA2- 256, Cert. #A4301) SHA (SHA2- 256, SHA2- 512, Cert. #A4301), CKGGenerated internally using NIST SP 800- 90Ar1 HMAC_DR BGImport: N/A Export: N/AN/APlaintext: RAMZeroisation command (request system zeroize), power-cycleEphemeral Diffie- Hellman private key used in SSH

Public Material – May be reproduced only in its original entirety (without revision).

Page 36
Key/SSP Name/ TypeStrengthSecurity Function and Cert. NumberGener- ationImport /ExportEstablish- mentStorageZero- isationUse & related keys
SSH Session Key CSP128 bits, 192 bits, 256 bitsAES (CBC, CTR 128, 192, 256 bits, Cert. #A4301), KAS-ECC- SSC (P-256, P-384, P-512, Cert. #A4301), KAS-FFC- SSC (MODP 2048, Cert. #A4301), KDF SSH (Cert. #A4301), HMAC_D RBG (HMAC- SHA2- 256, Cert. #A4301), HMAC (SHA-1, SHA2- 256, SHA2- 512, Cert. #A4301), SHA (SHA-1, SHA2- 256, SHA2- 512, Cert. #A4301), CKGN/AImport: N/A Export: N/AKey Agreement Scheme (KAS), Derived using KDF SSHPlaintext: RAMZeroisation command (request system zeroize), power-cycle, session terminationSSH Session keys

Public Material – May be reproduced only in its original entirety (without revision).

Page 37
Key/SSP Name/ TypeStrengthSecurity Function and Cert. NumberGener- ationImport /ExportEstablish- mentStorageZero- isationUse & related keys
User Password CSP256 bits, 512 bitsSHA (SHA2- 256, Cert. #A4306, SHA2- 512, Cert. #A4306)Password hash generated internally (Password is configured by the Crypto Officer)Import: Manual entry via CLI, manual SSP entry test perfor med Export: N/AN/ANon- Plaintext: Persistent (Password Hash)Zeroisation command (request system zeroize) and explicit delete commandUsed to authenticate users to the module
CO Password CSP256 bits, 512 bitsSHA (SHA2- 256, Cert. #A4306, SHA2- 512, Cert. #A4306)Password hash generated internally (Password is configured by the Crypto Officer)Import: Manual entry via CLI, manual SSP entry test perfor med Export: N/AN/ANon- plaintext: Persistent (Password Hash)Zeroisation command (request system zeroize) and explicit delete commandUsed to authenticate COs to the module
HMAC_DR BG V value CSP256 bitsHMAC_D RBG (HMAC- SHA2- 256), HMAC (SHA2- 256), SHA (SHA2- 256, CAVP Certs. A4303, A4301)Generated internally using NIST SP 800- 90Ar1 HMAC_DR BGImport: N/A Export: N/AN/APlaintext: RAMPower cycleA critical value of the internal state of DRBG

N/A N/A Public Material – May be reproduced only in its original entirety (without revision).

Page 38
Key/SSP Name/ TypeStrengthSecurity Function and Cert. NumberGener- ationImport /ExportEstablish- mentStorageZero- isationUse & related keys
HMAC_DR BG Key value CSP256 bitsHMAC_D RBG (HMAC- SHA2- 256), HMAC (SHA2- 256), SHA (SHA2- 256, CAVP Certs. A4303, A4301)Generated internally using NIST SP 800- 90Ar1 HMAC_DR BGImport: N/A Export: N/AN/APlaintext: RAMPower cycleA critical value of the internal state of DRBG
HMAC_DR BG entropy input CSP256 bitsHMAC_D RBG (HMAC- SHA2- 256), HMAC (SHA2- 256), SHA (SHA2- 256, CAVP Certs. A4303, A4301)NIST SP 800-90B ENT (NP) entropy sourceImport: N/A Export: N/AN/APlaintext: RAMPower cycleEntropy input to the HMAC_DRB G
HMAC_DR BG seed CSP256 bitsHMAC_D RBG (HMAC- SHA2- 256), HMAC (SHA2- 256), SHA (SHA2- 256, CAVP Certs. A4303, A4301)NIST SP 800-90B ENT (NP) entropy sourceImport: N/A Export: N/AN/APlaintext: RAMPower cycleSeed provided to the HMAC_DRB G

Public Material – May be reproduced only in its original entirety (without revision).

Page 39
Key/SSP Name/ TypeStrengthSecurity Function and Cert. NumberGener- ationImport /ExportEstablish- mentStorageZero- isationUse & related keys
HMAC_DR BG output CSP256 bitsHMAC_D RBG (HMAC- SHA2- 256), HMAC (SHA2- 256), SHA (SHA2- 256, CAVP Certs. A4303, A4301)Generated internally using NIST SP 800- 90Ar1 HMAC_DR BGImport: N/A Export: N/AN/APlaintext: RAMPower cycleUnmodified output of the HMAC_DRB G used in SSP generation
MACsec PSK CSP128 bits, 256 bitsAES (GCM, 128, 256 bits, Cert. #A4304)N/AImport: Configu red by the Crypto Officer in plainte xt via console port or encrypt ed via SSH connec tion Export: MACse c connec tion establis hmentN/APlaintext: RAMZeroisation command (request system zeroize), power-cycle, session terminationCredential used for device-to- device authenticati on, consists of the CAK and CKN
MACsec CAK CSP128 bits, 256 bitsAES (GCM, 128, 256 bits, Cert. #A4304)N/AImport: Pre- Shared Key entere d by theN/APlaintext: RAMZeroisation command (request system zeroize), power-cycle, session terminationA secret key possessed by members of a MACsec connectivity association

c Public Material – May be reproduced only in its original entirety (without revision).

Page 40
Key/SSP Name/ TypeStrengthSecurity Function and Cert. NumberGener- ationImport /Export Crypto Officer Export: N/AEstablish- mentStorageZero- isationUse & related keys entered as a pre-shared key
MACsec CKN128 bits, 256 bitsAES (GCM, 128, 256 bits, Cert. #A4304)N/AImport: Pre- Shared Key entere d by the Crypto Officer Export: N/AN/APlaintext: RAMZeroisation command (request system zeroize), power-cycle, session terminationConnectivity Key Name: Identifies the CAK Entered as a pre-shared key
MACsec SAK CSP128 bits, 256 bitsAES (GCM, 128, 256 bits, Cert. #A4304) SP 800- 108 KDF (Cert. #A4304)Derived from the CAK using SP 800-108 KDFImport: N/A Export: Encrypt ed with the KEKN/APlaintext: RAMZeroisation command (request system zeroize), power-cycle, session terminationSecurity Association Key used for creating Security Associations for encryption/ decryption of MACsec traffic
MACsec KEK CSP128 bits, 256 bitsAES (GCM, 128, 256 bits, Cert. #4304) SP 800- 108 KDF (Cert. #A4304)Derived from the CAK using SP 800-108 KDFImport: N/A Export: N/AN/APlaintext: RAMZeroisation command (request system zeroize), power-cycle, session terminationUsed to transmit SAKs to other members of a MACsec connectivity association

N/A N/A Public Material – May be reproduced only in its original entirety (without revision).

Page 41
Key/SSP Name/ TypeStrengthSecurity Function and Cert. NumberGener- ationImport /ExportEstablish- mentStorageZero- isationUse & related keys
MACsec ICK CSP128 bits, 256 bitsAES (GCM, 128, 256 bits, Cert. #A4304) SP 800- 108 KDF (Cert. #A4304)Derived from the CAK using SP 800-108 KDFImport: N/A Export: N/AN/APlaintext: RAMZeroisation command (request system zeroize), power-cycle, session terminationUsed to verify the integrity and authenticity of MACsec protocol data units
ECDH Shared Secret CSP128 bits, 192 bits, 256 bitsKAS-ECC- SSC (P-256, P-384, P-521, Cert. #A4301)N/AImport: N/A Export: N/AKAS-ECC- SSC Ephemeral Unified schemePlaintext: RAMZeroisation command (request system zeroize), power-cycle, session terminationUsed in EC Diffie- Hellman (ECDH) exchange
DH Shared Secret CSP112 bitsKAS-FFC- SSC (MODP 2048, Cert. #A4301)N/AImport: N/A Export: N/AKAS-FCC- SSC dhEpheme ral schemePlaintext: RAMZeroisation command (request system zeroize), power-cycle, session terminationUsed in Diffie- Hellman (DH) exchange
HMAC Key CSP160 bits, 256 bits, 384 bits, 512 bitsHMAC_D RBG (HMAC- SHA2- 256, CAVP Certs. A4303, A4301), HMAC (SHA-1, SHA2- 256, SHA2- 512, CAVP Certs. #A4303,Generated internally using NIST SP 800- 90Ar1 HMAC_DR BGImport: N/A Export: N/AN/APlaintext: RAMZeroisation command (request system zeroize), power-cycleHMAC Key

Public Material – May be reproduced only in its original entirety (without revision).

Page 42
Key/SSP Name/ TypeStrengthSecurity Function and Cert. NumberGener- ationImport /ExportEstablish- mentStorageZero- isationUse & related keys
#A4301, #A4306; SHA2- 384, CAVP Certs. #A4303); SHA (SHA-1, SHA2- 256, SHA2- 512, CAVP Certs. #A4303, #A4301, #A4306; SHA2- 384, CAVP Certs. #A4303)
SSH Public Host Key PSP128 bits for ECDSA, 112 bits for RSAECDSA (P-256, SHA2- 256, KeyGen, Cert. #A4301), RSA (2048 bits, SHA2- 256, SHA2- 512, KeyGen, Cert. #A4301), HMAC_D RBG (HMAC- SHA2- 256,Generated internally using NIST SP 800- 90Ar1 HMAC_DR BGImport: N/A Export: N/AN/APlaintext: PersistentZeroisation command (request system zeroize)Host keypairs generated, used to identify the host

Public Material – May be reproduced only in its original entirety (without revision).

Page 43
Key/SSP Name/ TypeStrengthSecurity Function and Cert. NumberGener- ationImport /ExportEstablish- mentStorageZero- isationUse & related keys
Cert. #A4301) HMAC (SHA2- 256, Cert. #A4301) SHA (SHA2- 256, SHA2- 512, Cert. #A4301), CKG
User Authentica tion Public Keys PSP128 bits, 192 bits, 256 bits for ECDSA, 112 bits, 152 bits for RSAECDSA SigVer (P-256, P-384, P- 521, Cert. #A4301); RSA SigVer (2048, 4096 bits, Cert. #A4301)N/AImport: Entere d by the Crypto Officer Export: N/AN/APlaintext: PersistentZeroisation command (request system zeroize)Used to authenticate users to the module
CO Authentica tion Public Keys PSP128 bits, 192 bits, 256 bits for ECDSA, 112 bits, 152 bits for RSAECDSA SigVer (P-256, P-384, P- 521, Cert. #A4301); RSA SigVer (2048, 4096 bits, Cert. #A4301)N/AImport: Entere d by the Crypto Officer Export: N/ANAPlaintext: PersistentZeroisation command (request system zeroize)Used to authenticate the CO to the module

Public Material – May be reproduced only in its original entirety (without revision).

Page 44
Key/SSP Name/ TypeStrengthSecurity Function and Cert. NumberGener- ationImport /ExportEstablish- mentStorageZero- isationUse & related keys
JuniperRo otCA PSP128 bitsECDSA (P-256, Cert. #A4301)N/AImport: Loaded at manufa cture time Export: N/AN/APlaintext: PersistentZeroisation command (request system zeroize)ECDSA prime256v1 X.509 V3 Certificate Used to verify the validity of the PackagCA
PackageCA PSP128 bitsECDSA (P-256, Cert. #A4301)N/AImport: Loaded at manufa cture time Export: N/AN/APlaintext: PersistentZeroisation command (request system zeroize)ECDSA prime256v1 X.509 V3 Certificate Certificate that holds the public key for the signing key used to generate all the signatures used on the packages and signature lists
SSH ECDH Public Key PSP128 bits, 192 bits, 256 bitsKAS-ECC- SSC (P-256, P-384, P-512, Cert. #A4301), HMAC_D RBG (HMAC- SHA2- 256, Cert. #A4301) HMAC (SHA2- 256, Cert. #A4301)Generated internally using NIST SP 800- 90Ar1 HMAC_DR BGImport: N/A Export: N/AN/APlaintext: RAMZeroisation command (request system zeroize), power-cycleEphemeral EC Diffie- Hellman public key used in SSH

Public Material – May be reproduced only in its original entirety (without revision).

Page 45
Key/SSP Name/ TypeStrengthSecurity Function and Cert. NumberGener- ationImport /ExportEstablish- mentStorageZero- isationUse & related keys
SHA (SHA2- 256, SHA2- 512, Cert. #A4301), CKG
SSH DH Public Key PSP112 bitsKAS-FFC- SSC (MODP 2048, Cert. #A4301), HMAC_D RBG (HMAC- SHA2- 256, Cert. #A4301) HMAC (SHA2- 256, Cert. #A4301) SHA (SHA2- 256, SHA2- 512, Cert. #A4301), CKGGenerated internally using NIST SP 800- 90Ar1 HMAC_DR BGImport: N/A Export: N/AN/APlaintext: RAMZeroisation command (request system zeroize), power-cycleEphemeral Diffie- Hellman public key used in SSH

Table 10

Page 46
Entropy sourcesMinimum number of bits of entropyDetails
SP 800-90B ENT (NP) ESV Cert. #E104The module generates a minimum of 448 bits of overall entropy per 512-bit output sample, 0.875 bits of entropy per bit for SSP generationEntropy input for seeding the approved NIST SP 800-90Ar1 DRBGs

Table 11

Page 47

10. Self-tests The module performs the following self-tests:

Page 48
Page 49

Conditional Self-Tests are performed by the module when the corresponding condition is met. The pairwise consistency tests are performed on key pair generation for use in signature generation/verification (ECDSA and/or RSA tests) and/or for use in KAS-ECC SSP agreement (ECDSA tests). The firmware load test is performed when a firmware image is loaded onto the module from an external source. If the conditional self-tests fail, the module enters the soft error state, i.e., it rejects the generated keypair/loaded image, returns an error indicator and resumes normal operation. The error indicator is the return code -1 in case of a pairwise consistency test failure and “ERROR: Failed signature check” for the firmware load test failure. Public Material – May be reproduced only in its original entirety (without revision).

Page 50

11. Life-cycle Assurance The Crypto Officer must follow the procedures defined below for secure installation, initialization, startup and operation of the module. Crypto Officer Guidance The Crypto Officer must check to verify the firmware image being loaded on the module is the FIPS 140-3 validated version/image. If the image is the FIPS 140-3 validated image, then proceed with installation of the image. Installing The Firmware Image Download the validated firmware image from https://www.juniper.net/support/downloads/junos.html. Log in to the Juniper Networks authentication system using the username (generally your e-mail address) and password supplied by Juniper Networks representatives. Select the validated firmware image. Download the firmware image to a local host or to an internal software distribution site. Connect to the console port on the device from your management device and log in to the Junos OS CLI. Copy the firmware package to the device to the /var/tmp/ directory. Install the new package on the device using the following command: operator@device> request system software add /var/tmp/<package>.tgz. NOTE: If you need to terminate the installation, do not reboot your device; instead, finish the installation and then issue the request system software delete package.tgz command, where package.tgz is, for example, junos-install-ex-4300mp-x86-64-22.4R2.8.tgz. This is your last chance to stop the installation. Reboot the device to complete the load and start the installation: operator@device> request system reboot After the reboot has completed, log in and use the show version command to verify that the new version of the firmware is successfully installed. Public Material – May be reproduced only in its original entirety (without revision).

Page 51

Enabling Approved Mode of Operation The Crypto Officer is responsible for initializing the module in the Approved mode of operation. The Approved mode of operation is not automatically enabled. The Crypto Officer shall place the module in the Approved mode by first zeroising it to ensure no SSPs are present. Next, the cryptographic officer shall follow the steps found in the Junos OS FIPS Evaluated Configuration Guide for Juniper Networks EX4300-48MP Ethernet Switch, Release 22.4R2.8 document Chapters 3 & 7 to place the module into an Approved mode of operation. The steps from the before mentioned document have been reiterated below. To enable the Approved mode in Junos OS on the module:

  1. Zeroise the module using the “request system zeroize” command. Once the module comes up in the “amnesiac mode” post zeroisation, connect to it using the console port with username “root”, enter the configuration mode and configure the root-authentication password (i.e., Crypto Officer credentials) as follows: root@device> edit Entering configuration mode [edit] root@device# set system root-authentication plain-text-password New password: Retype new password: [edit] root@device# commit configuration check succeeds commit complete
  2. Enable Approved mode on the device by setting the Approved level to 1, and verify the level: [edit] root@device# set system fips chassis level 1 Public Material – May be reproduced only in its original entirety (without revision).
Page 52

[edit] root@device# show system fips chassis level level 1;

  1. Commit the configuration [edit ] root@device# commit configuration check succeeds Generating RSA key /etc/ssh/fips_ssh_host_key Generating RSA2 key /etc/ssh/fips_ssh_host_rsa_key Generating ECDSA key /etc/ssh/fips_ssh_host_ecdsa_key 'system' reboot is required to transition to fips level 1 commit complete
  2. Reboot the device: [edit] root@device# run request system reboot Reboot the system ? [yes,no] (no) yes During the reboot, the device runs the pre-operational firmware integrity test and all CASTs. It returns a login prompt.
  3. After the reboot has completed, log in and use the show version command to verify the firmware version is the validated version: root@device:fips > show version The tester verified that the prompt contained "fips" indicating it was in the approved mode of operation. No further configuration is required. Public Material – May be reproduced only in its original entirety (without revision).
Page 53

Placing the Module in the Non-Approved Mode of Operation As Crypto Officer, the operator needs to disable the Approved mode of operation on the device to return it to the non-Approved mode of operation. To disable the Approved mode on the device, the module must be zeroised (step 1 defined above). No other maintenance requirements apply for operation of the module in the Approved/non-Approved modes as defined above. For further information and for the Administrator and non-Administrator guidance, please see the Junos OS FIPS Evaluated Configuration Guide for Juniper Networks EX4300-48MP Ethernet Switch, Release 22.4R2.8 document. Public Material – May be reproduced only in its original entirety (without revision).

Page 54

12. Mitigation of Other Attacks The module does not implement any mitigation of other attacks and thus the requirements per this section do not apply to the module. Public Material – May be reproduced only in its original entirety (without revision).