All modules
CMVP Validated Module · FIPS 140-3 Security Policy

PL-4000M and PL-4000T

Certificate#5055StandardFIPS 140-3Level2TypeHardwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorPacketLight Networks Ltd.
Low review priority  ·  exposes firmware-update authentication  ·  last validated 11 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level2
Module typeHardware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date8/17/2030
CaveatWhen installed, initialized and configured as specified in Section 11 of the Security Policy. The tamper evident seals installed as indicated in the Security Policy.
VendorPacketLight Networks Ltd.

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for PL-4000M and PL-4000T
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Firmware Load<br/>Update</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>SSH<br/>IPSEC</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for PL-4000M and PL-4000T
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Firmware Load<br/>Update</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>SSH<br/>IPSEC</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

PacketLight Networks Ltd. PL-4000M and PL-4000T Document Version 1.0 July 2025 Prepared by: www.lightshipsec.com PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 2
Table of Contents
#SectionPage
Page 3

PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 4
List of Tables
ItemPage
Table 1: Security Levels5
Table 2: Tested Module Identification – Hardware7
Table 3: Modes List and Description7
Table 4: Approved Algorithms9
Table 5: Vendor-Affirmed Algorithms9
Table 6: Security Function Implementations12
Table 7: Entropy Certificates13
Table 8: Entropy Sources13
Table 9: Ports and Interfaces17
Table 10: Authentication Methods19
Table 11: Roles19
Table 12: Approved Services33
Table 13: Mechanisms and Actions Required37
Table 14: Storage Areas41
Table 15: SSP Input-Output Methods41
Table 16: SSP Zeroization Methods41
Table 17: SSP Table 145
Table 18: SSP Table 246
Table 19: Pre-Operational Self-Tests47
Table 20: Conditional Self-Tests48
Table 21: Pre-Operational Periodic Information48
Table 22: Conditional Periodic Information49
Table 23: Error States50
Figure 1: PL-4000M6
Figure 2: PL-4000T7
Figure 3: PL-4000M (Front)15
Figure 4: PL-4000T (Front)15
Figure 5: PL-4000M and PL-4000T (Rear)15
Figure 6: PL-40000M (Front, Rear, Left, Right, Bottom)38
Figure 7: PL-40000T (Front, Rear, Left, Right, Bottom)39
Page 5
SectionTitleSecurity Level
1General2
2Cryptographic module specification2
3Cryptographic module interfaces2
4Roles, services, and authentication2
5Software/Firmware security2
6Operational environmentN/A
7Physical security2
8Non-invasive securityN/A
9Sensitive security parameter management2
10Self-tests2
11Life-cycle assurance2
12Mitigation of other attacksN/A
Overall Level2
1.1 Overview

This document is the non-proprietary FIPS 140-3 Security Policy for the PacketLight Networks Ltd. PL-4000M and PL-4000T cryptographic modules (also referred to as “the module(s)” hereafter) running firmware version 2.1.0. It contains specification of the security rules, under which the cryptographic module operates, including the security rules derived from the requirements of the FIPS 140-3 standard

1.2 Security Levels

The table below describes the individual security areas of FIPS 140-3, as well as the Security Levels of those individual areas. Table 1: Security Levels PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 6
2 Cryptographic Module Specification
2.1 Description

Purpose and Use: The PL-4000M and PL-4000T are two product variations of the PL-4000x clone. The hardware modules run the same firmware and provide the same cryptographic security services. The PL-4000M is a cost-effective solution for rolling out multi-rate 10/25/100GbE, 16G FC, OTU2/2e/4 services, or increasing existing network capacity. The device delivers up to 600G in a 1U chassis using dual 400G CFP2-DCO Open ROADM standards-based pluggable coherent modules for metro and long-haul applications. The PL-4000M provides a full demarcation point between the service and the OTN/DWDM network and is interoperable with any third-party switch or router. This provides full visibility and performance monitoring of both line optical transport layer (OTN) and 10/25/100GbE, 16G FC, and OTU2/2e/4 service interfaces. The PL-4000M can be configured to work in the following system modes: - Single 400G Muxponder: mix of client interfaces aggregated into a 400G uplink - Dual 100/200/300G Muxponder: mix of client interfaces aggregated into two 100/200/300G uplinks - Optical Amplifiers: Up to two EDFA modules (optional) - Optical Switch: 1+1 facility protection (optional) The PL-4000T is a cost-effective high-capacity solution for rolling out 400GbE and 100GbE services or increasing existing network capacity. The device has four 400G pluggable uplink optical modules, delivering up to 1.6T in a 1U chassis. The PL-4000T integrates mux/demux, EDFA and OSW and delivers the entire optical layer. This flexible solution enables pay-as-you-grow architecture. The solution provides a full demarcation point between the service and the DWDM network and is interoperable with any third-party switch or router. This provides full visibility and performance monitoring of both the optical transport layer (OTN) and 100GbE/400GbE/OTU4 service interfaces. The PL-4000T can be configured to work in the following system modes: - Muxponder: 4x100G clients per 200G/300G/400G slice - Transponder: 1x400G per 400G - Optical Amplifiers: Up to two EDFA modules (optional) - Mux/Demux: 4ch mux/demux module (optional) - Optical Switch: 1+1 optical switch, 4 x 1+1 optical switches Module Type: Hardware Module Embodiment: MultiChipStand Cryptographic Boundary: The cryptographic boundary of the modules is defined as the entire outer casing of the chassis as pictured below. The PL-4000T’s cryptographic boundary includes uplink module(s) which are protected by Tamper-evident Seals (see Section 7.1). Figure 1: PL-4000M PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 7
Model and/or Part NumberHardware VersionFirmware VersionProcessorsFeatures
PL-4000MPL-4000M2.1.0NXP Layerscape LS1026AAC/DC PSU
PL-4000TPL-4000T2.1.0NXP Layerscape LS1026AAC/DC PSU
Mode NameDescriptionTypeStatus Indicator
Approved ModeWhen installed, initialized and configured as specified in Section 11 of the Security Policy, and with the tamper evident seals installed as indicated in Section 7 of the Security Policy, the module only runs in the approved mode of operation.ApprovedGlobal
AlgorithmCAVP CertPropertiesReference
AES-CFB128A4261Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CTRA4136Direction - Decrypt, Encrypt Key Length - 256SP 800-38A
2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification

2.3 Excluded Components

None. Modes List and Description: The table below details the Mode of Operation supported by the module. Table 3: Modes List and Description

2.5 Algorithms

Approved Algorithms: The table below lists all the Approved Algorithms supported by the module. PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 8
AlgorithmCAVP CertPropertiesReference
AES-CTRA4261Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-ECBA2709Direction - Encrypt Key Length - 256SP 800-38A
AES-ECBA4261Direction - Decrypt, Encrypt Key Length - 128SP 800-38A
AES-GCMA2709Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 256SP 800-38D
AES-GCMA4261Direction - Decrypt, Encrypt IV Generation - Internal IV Generation Mode - 8.2.1 Key Length - 128, 256SP 800-38D
AES-GMACA4136Direction - Decrypt, Encrypt IV Generation - External IV Generation Mode - 8.2.1 Key Length - 256SP 800-38D
Counter DRBGA4261Prediction Resistance - Yes Mode - AES-256 Derivation Function Enabled - NoSP 800-90A Rev. 1
ECDSA KeyGen (FIPS186-5)A4261Curve - P-384 Secret Generation Mode - testing candidatesFIPS 186-5
ECDSA KeyVer (FIPS186-5)A4261Curve - P-384FIPS 186-5
ECDSA SigGen (FIPS186-5)A4261Curve - P-384 Hash Algorithm - SHA2-384, SHA2-512/224FIPS 186-5
ECDSA SigVer (FIPS186-5)A4261Curve - P-384 Hash Algorithm - SHA2-384FIPS 186-5
HMAC-SHA2-256A4261Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2-384A4261Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2-512A4261Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
KAS-ECC-SSC Sp800- 56Ar3A4261Domain Parameter Generation Methods - P-256, P-384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KAS-FFC-SSC Sp800- 56Ar3A4261Domain Parameter Generation Methods - ffdhe2048, ffdhe3072, MODP-2048, MODP-3072, MODP-4096 Scheme - dhEphem - KAS Role - initiator, responderSP 800-56A Rev. 3
KDA OneStep SP800-56Cr2A4261Derived Key Length - 2048 Shared Secret Length - Shared Secret Length: 224-8192 Increment 8SP 800-56C Rev. 2
KDF SNMP (CVL)A4261Password Length - Password Length: 64-160 Increment 8SP 800-135 Rev. 1

PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 9
AlgorithmCAVP CertPropertiesReference
KDF SSH (CVL)A4261Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA2-256, SHA2-512SP 800-135 Rev. 1
RSA KeyGen (FIPS186-5)A4261Key Generation Mode - probableWithProbableAux Modulo - 2048 Primality Tests - 2powSecStr Private Key Format - standardFIPS 186-5
Safe Primes Key GenerationA4261Safe Prime Groups - ffdhe2048, ffdhe3072, MODP-2048, MODP- 3072, MODP-4096SP 800-56A Rev. 3
Safe Primes Key VerificationA4261Safe Prime Groups - ffdhe2048, ffdhe3072, MODP-2048, MODP- 3072, MODP-4096SP 800-56A Rev. 3
SHA2-256A4261Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-384A4261Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-512A4261Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
TLS v1.2 KDF RFC7627 (CVL)A4261Hash Algorithm - SHA2-256, SHA2-384SP 800-135 Rev. 1
TLS v1.3 KDF (CVL)A4261HMAC Algorithm - SHA2-256, SHA2-384 KDF Running Modes - DHESP 800-135 Rev. 1
NamePropertiesImplementationReference
CKGKey Type:AsymmetricPacketLight Cryptographic ImplementationIG D.H, SP800-133r2 (Section 4/example 1) The seed used in asymmetric key generation is the unmodified output from a NIST SP 800- 90A DRBG.

Table 4: Approved Algorithms Vendor-Affirmed Algorithms: The table below lists all the Vendor-Affirmed Algorithms supported by the module. Table 5: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: The module does not support any Non-Approved, Allowed Algorithms. N/A for this module. Non-Approved, Allowed Algorithms with No Security Claimed: The module does not support any Non-Approved, Allowed Algorithms with No Security Claimed. N/A for this module. Non-Approved, Not Allowed Algorithms: The module does not support any Non-Approved Algorithms that are not Allowed in the Approved Mode of Operation. N/A for this module.

2.6 Security Function Implementations

The table below lists the Security Function Implementations supported by the module. PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 10
NameTypeDescriptionPropertiesAlgorithms
Config File Encrypt/DecryptBC-UnAuthEncryption/Decryption of respective SSPs in configuration filesAES-CTR: (A4261) Key Length: 256
Key File Encrypt/DecryptBC-UnAuthEncryption/Decryption of respective SSPs in key filesAES-ECB: (A4261)
SNMPv3 Encrypt/DecryptBC-UnAuthEncryption/Decryption of SNMPv3 packetsAES-CFB128: (A4261)
SSH Encrypt/Decrypt 1BC-UnAuthEncryption/Decryption of SSH session packetsAES-CTR: (A4261)
SSH Encrypt/Decrypt 2BC-AuthEncryption/Decryption of SSH session packetsAES-GCM: (A4261)
TLS Encrypt/DecryptBC-AuthEncryption/Decryption of TLS session packetsAES-GCM: (A4261)
Client Data Encrypt/Decrypt 1BC-AuthEncryption/Decryption of Client Data (PL- 4000M hardware block)AES-CTR: (A4136) AES-GMAC: (A4136)
Client Data Encrypt/Decrypt 2BC-AuthEncryption/Decryption of Client Data (DCO transceiver hardware block, inserted into 4000T)AES-GCM: (A2709) AES-ECB: (A2709)
TLS Key Pair/Certificate GenerationAsymKeyPair-KeyGenGeneration of certificate and keys for TLS server authenticationECDSA KeyGen (FIPS186-5): (A4261) Counter DRBG: (A4261)
SSH Key Pair GenerationAsymKeyPair-KeyGenGeneration of keys for SSH server authenticationRSA KeyGen (FIPS186- 5): (A4261) Counter DRBG: (A4261)
TLS Key Pair VerificationAsymKeyPair-KeyVerTLS Key Pair VerificationECDSA KeyVer (FIPS186-5): (A4261)
TLS Digital Signature GenerationDigSig-SigGenTLS Digital Signature GenerationECDSA SigGen (FIPS186-5): (A4261)
TLS Digital Signature VerificationDigSig-SigVerTLS Digital Signature VerificationECDSA SigVer (FIPS186-5): (A4261)
SSH Message Authentication 1MACSSH Message AuthenticationHMAC-SHA2-256: (A4261)
SSH Message Authentication 2MACSSH Message AuthenticationHMAC-SHA2-512: (A4261) SHA2-512: (A4261)
TLS Message Authentication 1MACTLS Message AuthenticationHMAC-SHA2-256: (A4261)

PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 11
NameTypeDescriptionPropertiesAlgorithms
TLS Message Authentication 2MACTLS Message AuthenticationHMAC-SHA2-384: (A4261) SHA2-384: (A4261)
SNMP Message Authentication 1MACSNMP Message AuthenticationHMAC-SHA2-256: (A4261)
SNMP Message Authentication 2MACSNMP Message AuthenticationHMAC-SHA2-384: (A4261) SHA2-384: (A4261)
SNMP Message Authentication 3MACSNMP Message AuthenticationHMAC-SHA2-512: (A4261) SHA2-512: (A4261)
Data Plane KEX Message AuthenticationMACData Plane KEX Message Authentication (prevents man-in-the- middle)HMAC-SHA2-384: (A4261) SHA2-384: (A4261)
Verify Firmware IntegrityMACVerify Firmware IntegrityHMAC-SHA2-384: (A4261) SHA2-384: (A4261)
Verify Firmware LoadMACVerify Firmware LoadHMAC-SHA2-384: (A4261) SHA2-384: (A4261)
KAS 1KAS-FullData exchange keys generation and distributionIG:D.F Scenario 2 path (2) Bit Strength Caveat:provides between 128 and 256 bits of encryption strengthKAS-ECC-SSC Sp800- 56Ar3: (A4261) KDA OneStep SP800- 56Cr2: (A4261)
KAS 2KAS-FullKey Agreement for SSHIG:D.F Scenario 2 path (2) Bit Strength Caveat:provides between 128 and 256 bits of encryption strengthKAS-ECC-SSC Sp800- 56Ar3: (A4261) KDF SSH: (A4261)
KAS 3KAS-FullKey Agreement for SSHIG:D.F Scenario 2 path (2) Bit Strength Caveat:provides between 112 and 152 bits of encryption strengthKAS-FFC-SSC Sp800- 56Ar3: (A4261) Domain Parameter Generation Methods: MODP-2048, MODP- 3072 and MODP-4096 KDF SSH: (A4261)
KAS 4KAS-FullKey Agreement for TLSv1.2IG:D.F Scenario 2 path (2) Bit StrengthKAS-ECC-SSC Sp800- 56Ar3: (A4261)

PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 12
NameTypeDescriptionPropertiesAlgorithms
Caveat:provides between 128 and 256 bits of encryption strengthTLS v1.2 KDF RFC7627: (A4261)
KAS 5KAS-FullKey Agreement for TLSv1.3IG:D.F Scenario 2 path (2) Bit Strength Caveat:provides between 128 and 256 bits of encryption strengthKAS-ECC-SSC Sp800- 56Ar3: (A4261) TLS v1.3 KDF: (A4261)
KAS 6KAS-FullKey Agreement for TLS v1.3IG:D.F Scenario 2 path (2) Bit Strength Caveat:provides 112 or 128 bits of encryption strengthKAS-FFC-SSC Sp800- 56Ar3: (A4261) Domain Parameter Generation Methods: ffdhe2048, ffdhe3072 TLS v1.3 KDF: (A4261)
SNMP Key DerivationKAS-135KDFDerives SNMPv3 KeysKDF SNMP: (A4261)
SSH Key DerivationKAS-135KDFDerives SSH KeysKDF SSH: (A4261)
TLS Key DerivationKAS-135KDFDerives TLS 1.2/3 KeysTLS v1.2 KDF RFC7627: (A4261) TLS v1.3 KDF: (A4261)
Password ObfuscationSHAOperator Password obfuscation in config fileSHA2-256: (A4261)
Entropy SourceENT-ESVEntropy Source
KAS Key Pair Generation 1KAS-KeyGenKAS Key Pair Generation (ECDH)ECDSA KeyGen (FIPS186-5): (A4261) ECDSA KeyVer (FIPS186-5): (A4261) Counter DRBG: (A4261)
KAS Key Pair Generation 2KAS-KeyGenKAS Key Pair Generation (DH)Safe Primes Key Generation: (A4261) Safe Primes Key Verification: (A4261) Counter DRBG: (A4261)
DRBGDRBGDeterministic Random Bit GenerationCounter DRBG: (A4261)

Table 6: Security Function Implementations PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 13
Cert NumberVendor Name
E63ID QUANTIQUE SA
NameTypeOperational EnvironmentSample SizeEntropy per SampleConditioning Component
IDQ Quantis IID QRNGPhysicalIDQ250C22 bits1.75 bits
2.7 Algorithm Specific Information

The module's TLS v1.2 firmware AES-GCM implementation conforms to FIPS 140-3 IG C.H Scenario #1. The module is compatible with TLS v1.2 and provides support for the acceptable GCM ciphersuites from SP 800-52 Rev2, Section 3.3.1. The counter portion of the IV is set by the module within its cryptographic boundary. When the IV exhausts the maximum number of possible values for a given session key, the first party, client or server, to encounter this condition will trigger a handshake to establish a new encryption key (in accordance with RFC 5246). In case the module’s power is lost and then restored, a new key for use with the AES GCM encryption/decryption shall be established. The module's TLS v1.3 firmware AES-GCM implementation conforms to FIPS 140-3 IG C.H Scenario #5. The TLS v1.3 protocol, and specifically the use of the AES-GCM encryption within the TLS v1.3 protocol is defined in RFC 8446. The module supports the acceptable GCM ciphersuites from SP 800-52 Rev2, Section 3.3.1. The IV is generated and used within this protocol’s implementation. The module's SSHv2 firmware AES-GCM implementation conforms to FIPS 140-3 IG C.H Scenario #1. The SSHv2 implementation is compliant with RFC 4252 and RFC 4253, and the IV generation of SSHv2 AES-GCM implementation is compliant with RFC 5647. The module's hardware AES-GCM implementations conform to IG C.H, scenario #4. The module uses a 96-bit IV, which is constructed deterministically per SP 800-38D Section 8.2.1 from a nonce and counter. PL-4000T - from a Frame Block Counter, Multi-Frame Index (MFI), Multi Frame Alignment Signal (MFAS) and nonce. PL-4000M - from Frame Counter (which is comprised of MFAS and MFI-38 bits and 26 zero pads), and Frame Block Counter (32-bits). Per the requirements specified in Section 8 in NIST SP 800-38D, the probability that the authenticated encryption function ever will be invoked with the same IV and the same key on two (or more) distinct sets of input data is no greater than 2-32. In all cases the module enforces FIPS 140-3 IG C.H, which states, “In case the module’s power is lost and then restored, a new key for use with the AES GCM encryption/decryption shall be established.”

2.8 RBG and Entropy

The tables below detail the modules ESV information. Table 7: Entropy Certificates Table 8: Entropy Sources

2.9 Key Generation

Please see SFI table.

2.10 Key Establishment

Please see SFI table. The module implements the DH and ECDH key agreement schemes specified in NIST SP 800-56Arev3. This specification requires that certain checks are performed to provide assurances regarding the keys being used. The following assurance checks are performed by the cryptographic module: PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 14
2.11 Industry Protocols

No parts of the SSH protocol, other than the approved cryptographic algorithms and the KDFs, have been tested by the CAVP and CMVP. No parts of the TLS protocol, other than the approved cryptographic algorithms and the KDFs, have been tested by the CAVP and CMVP. No parts of the SNMP protocol, other than the approved cryptographic algorithms and the KDFs, have been tested by the CAVP and CMVP. PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 15
Physical PortLogical Interface(s)Data That Passes
LC ports (4000M)NoneNot in use
CFP2 400G Uplink ports (4000M)Data Input Data Output Control Input Status OutputMuxponded/Transponded data, Inband management
SFP+/SFP28 10G/25G Service ports (4000M)Data Input Data Output Status OutputData
OSC ports (4000M)NoneNot in use
3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

Figure 3: PL-4000M (Front) Figure 4: PL-4000T (Front) Figure 5: PL-4000M and PL-4000T (Rear) The table below details the modules Ports and Interfaces. PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 16
Physical PortLogical Interface(s)Data That Passes
SFP 100/1000M Base-X MNG ports (4000M)Control Input Status OutputManagement
RJ-45 Control port (4000M)Control Input Status OutputLocal CLI
RJ-45 Alarm port (4000M)Status OutputExternal alarms dry contacts
QSFP28 100G Service ports (4000M)Data Input Data Output Status OutputData
Interlaken RJ-45 port (4000M)NoneNot in use
RJ-45 100/1000M Base-T LAN ports (4000M)Control Input Status OutputManagement
LEDs (4000M)Status OutputStatus
Power connectors (4000M)PowerPower
Mux/Demux MPO port (4000T)NoneNot in use
LC ports (4000T)NoneNot in use
QSFP-DD 400G Uplink ports (4000T)NoneNot in use
CFP2 400G Uplink ports (4000T)Data Input Data Output Control Input Status OutputTransponded data, Inband management
SFP 100/1000M Base-X MNG ports (4000T)Control Input Status OutputManagement
RJ-45 Control port (4000T)Control Input Status OutputLocal CLI
RJ-45 Alarm port (4000T)Status OutputExternal alarms dry contacts
QSFP28 100G ports QSFP28 100G/ QSFP-DD 400G ports (4000T)Data Input Data Output Control Input Status OutputData
RJ-45 100/1000M Base-T LAN ports (4000T)Control Input Status OutputManagement
LEDs (4000T)Status OutputStatus

PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 17
Physical PortLogical Interface(s)Data That Passes
Power connectors (4000T)PowerPower

Table 9: Ports and Interfaces PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 18
Method NameDescriptionSecurity MechanismStrength Each AttemptStrength per Minute
WebGUI (HTTPS) AuthGrants access to GUI according to roleUsername and PasswordPasswords are required to be at minimum 8 characters in length, and at maximum 20 bytes. Accepted characters are a-z, A-Z, 0-9, and [$@#&_!%^*]. An 8-character password allowing all legal characters (73) with repetition equates to a 1:(73^8), or 1: 806,460,091,894,081 chance of false acceptance.Assuming 10 attempts per second via a scripted or automatic attack, the probability of a success with multiple attempts in a one- minute period is 600/73^8, which is less than 1/100,000.
SSH/SFTP AuthGrants access to CLI according to roleUsername and PasswordPasswords are required to be at minimum 8 characters in length, and at maximum 20 bytes. Accepted characters are a-z, A-Z, 0-9, and [$@#&_!%^*]. An 8-character password allowing all legal characters (73) with repetition equates to a 1:(73^8), or 1: 806,460,091,894,081 chance of false acceptance.Assuming 10 attempts per second via a scripted or automatic attack, the probability of a success with multiple attempts in a one- minute period is 600/73^8, which is less than 1/100,000.
Console AuthGrants access to CLI according to roleUsername and PasswordPasswords are required to be at minimum 8 characters in length, and at maximum 20 bytes. Accepted characters are a-z, A-Z, 0-9, and [$@#&_!%^*]. An 8-character password allowing all legal characters (73) with repetition equates to a 1:(73^8), or 1: 806,460,091,894,081 chance of false acceptance.The fastest data rate for the serial port is 115,200 bps. Each ASCII character is 10 bits (1 Start, 8 data, 1 Stop), so that is (115,200 / 10 =) 115,20 characters per second or (115,20 * 60 =) 691,200 characters per minute. Running 100,000 trials in a minute will require a minimum of (4 * 10 * 100,000 =) 4,000,000 characters to be sent. This exceeds the 691,200 limit imposed by the data rate of the serial port. Therefore, the probability that a random attempt will succeed in one minute is less than 1/100,000.
SNMPv3 AuthVerifying the rights of SNMP based processes to access forUsername and PasswordPasswords are required to be at minimum 8 characters in length, and at maximum 20 bytes. Accepted characters are a-z, A-Z, 0-9, and [$@#&_!%^*]. An 8-characterAssuming 10 attempts per second via a scripted or automatic attack, the probability of a success with multiple attempts in a one-
4 Roles, Services, and Authentication
4.1 Authentication Methods

The table below details the modules Authentication Methods. PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 19

Method Name

Description monitoring and management

Security Mechanism

Strength Each Attempt password allowing all legal characters (73) with repetition equates to a 1:(73^8), or 1: 806,460,091,894,081 chance of false acceptance.

Strength per Minute minute period is 600/73^8, which is less than 1/100,000.

NameTypeOperator TypeAuthentication Methods
AdminRoleCOWebGUI (HTTPS) Auth SSH/SFTP Auth Console Auth SNMPv3 Auth
CryptoRoleCOWebGUI (HTTPS) Auth SSH/SFTP Auth Console Auth
Read-WriteRoleCOWebGUI (HTTPS) Auth SSH/SFTP Auth Console Auth SNMPv3 Auth
Read-OnlyRoleCOWebGUI (HTTPS) Auth SSH/SFTP Auth Console Auth SNMPv3 Auth
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
InitializationInitial ConfigurationN/ACommand and parametersCommand response/ statusNoneAdmin
4.2 Roles

The module supports four different roles: Admin, Crypto, Read-Write and Read-Only, which are detailed in the table below. Table 11: Roles

4.3 Approved Services

The table below lists all approved services supported by the module. The abbreviations of the access rights to keys and SSPs have the following interpretation: G = Generate: The module generates or derives the SSP. R = Read: The SSP is read from the module (e.g., the SSP is output). W = Write: The SSP is updated, imported, or written to the module. E = Execute: The module uses the SSP in performing a cryptographic operation. Z = Zeroise: The module zeroises the SSP. PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 20
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
Manage AccountsAdd, Edit, Delete, View user accountsGlobal ("FIPS Compliant Mode") in combination with successful completion of serviceCommand and parametersCommand response/ statusPassword ObfuscationAdmin - Operator Passwords: W
Change PasswordAdmin to any except Crypto, each user its ownGlobal ("FIPS Compliant Mode") in combination with successful completion of serviceCommand and parametersCommand response/ statusPassword ObfuscationAdmin - Operator Passwords: W Crypto - Operator Passwords: W Read-Write - Operator Passwords: W Read-Only - Operator Passwords: W
Encryption ServiceTransfer of encryption dataGlobal ("FIPS Compliant Mode") in combination with successful completion of serviceCommand and parametersCommand response/ statusClient Data Encrypt/Decrypt 1 Client Data Encrypt/Decrypt 2 Data Plane KEX Message Authentication KAS 1 KAS Key Pair Generation 1Admin - EC DH Key Pair for DEK: G,E - ECC CDH primitive for DEK: G,E - Data Encryption Key (DEK): G,E - Peer- Authentication Pre-Shared Secret: R,W,E Read-Write - EC DH Key Pair for DEK: G,E - ECC CDH primitive for DEK: G,E - Data Encryption Key (DEK): G,E - Peer- Authentication Pre-Shared Secret: R,W,E

PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 21
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
Add/Change Pre-Shared SecretAdd/Changes the pre-shared secret used for the authentication of the key exchange messages.Global ("FIPS Compliant Mode") in combination with successful completion of serviceCommand and parametersCommand response/ statusConfig File Encrypt/DecryptCrypto - Peer- Authentication Pre-Shared Secret: W
Lock Encrypted ServiceLocks the encrypted uplink port.N/ACommandCommand response/ statusNoneCrypto
Change Provisioning TypeProvisions the service port or remove provisioning from the selected portN/ACommandCommand response/ statusNoneAdmin Read-Write
View System InformationView system specific informationN/ACommandCommand response/ statusNoneAdmin Crypto Read-Write Read-Only
View Performance MonitoringView port performance monitoring infoN/ACommandCommand response/ statusNoneAdmin Crypto Read-Write Read-Only
View Faults or AlarmsUsed to localize and identify problems in the networkN/ACommandCommand response/ statusNoneAdmin Crypto Read-Write Read-Only
Configure FirewallConfigure Firewall rules/policiesN/ACommand and parametersCommand response/ statusNoneAdmin
Show StatusOutputs current module statusN/ACommandCommand response/ statusNoneAdmin Crypto Read-Write Read-Only
Show Versioning informationReturns module name/identifier and versioning informationN/ACommandModule versioning informationNoneAdmin Crypto Read-Write Read-Only
Set Configuration dataDevice configuration toolN/ACommand and parametersCommand response/ statusNoneAdmin Read-Write
Establish SSH sessionEstablish an SSH sessionGlobal ("FIPS Compliant Mode") in combinationCommandCommand response/ statusKey File Encrypt/Decrypt SSH Encrypt/DecryptAdmin - Operator Passwords: W - Diffie-Hellman

PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 22
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
with successful completion of service1 SSH Encrypt/Decrypt 2 SSH Key Pair Generation SSH Message Authentication 1 SSH Message Authentication 2 KAS 2 KAS 3 SSH Key Derivation KAS Key Pair Generation 1 KAS Key Pair Generation 2(DH) Key Pair: G,E - Diffie-Hellman Shared Secret: G,E - Elliptic Curve Diffie-Hellman (ECDH) Key Pair: G,E - EC Diffie- Hellman Shared Secret: G,E - SSH/SFTP Host Key Pair: G,E - SSH/SFTP Session Encryption Key: G,E - SSH/SFTP Session Authentication key: G,E Crypto - Operator Passwords: W - Diffie-Hellman (DH) Key Pair: G,E - Diffie-Hellman Shared Secret: G,E - Elliptic Curve Diffie-Hellman (ECDH) Key Pair: G,E - EC Diffie- Hellman Shared Secret: G,E - SSH/SFTP Host Key Pair: G,E - SSH/SFTP Session Encryption Key: G,E - SSH/SFTP Session

G,E G,E G,E PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 23

Name

Description

Indicator

Inputs

Outputs

Security Functions

SSP Access Authentication key: G,E Read-Write - Operator Passwords: W - Diffie-Hellman (DH) Key Pair: G,E - Diffie-Hellman Shared Secret: G,E - Elliptic Curve Diffie-Hellman (ECDH) Key Pair: G,E - EC Diffie- Hellman Shared Secret: G,E - SSH/SFTP Host Key Pair: G,E - SSH/SFTP Session Encryption Key: G,E - SSH/SFTP Session Authentication key: G,E Read-Only - Operator Passwords: W - Diffie-Hellman (DH) Key Pair: G,E - Diffie-Hellman Shared Secret: G,E - Elliptic Curve Diffie-Hellman (ECDH) Key Pair: G,E - EC Diffie- Hellman Shared Secret: G,E - SSH/SFTP Host Key Pair: G,E

G,E G,E G,E G,E G,E PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 24
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access - SSH/SFTP Session Encryption Key: G,E - SSH/SFTP Session Authentication key: G,E
Establish TLS sessionEstablish a web session using TLS protocolGlobal ("FIPS Compliant Mode") in combination with successful completion of serviceCommandCommand response/ statusKey File Encrypt/Decrypt TLS Encrypt/Decrypt TLS Key Pair/Certificate Generation TLS Key Pair Verification TLS Digital Signature Generation TLS Digital Signature Verification TLS Message Authentication 1 TLS Message Authentication 2 KAS 4 KAS 5 KAS 6 TLS Key Derivation KAS Key Pair Generation 1 KAS Key Pair Generation 2Admin - Operator Passwords: W - Diffie-Hellman (DH) Key Pair: G,E - Diffie-Hellman Shared Secret: G,E - Elliptic Curve Diffie-Hellman (ECDH) Key Pair: G,E - EC Diffie- Hellman Shared Secret: G,E - TLS Key Pair: G,E - TLS Premaster Secret: G,E - TLS Master Secret: G,E - TLS Session Encryption Key: G,E - TLS Session Authentication Key: G,E Crypto - Operator Passwords: W - Diffie-Hellman (DH) Key Pair: G,E - Diffie-Hellman Shared Secret: G,E - Elliptic Curve

G,E G,E G,E PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 25

Name

Description

Indicator

Inputs

Outputs

Security Functions

SSP Access Diffie-Hellman (ECDH) Key Pair: G,E - EC Diffie- Hellman Shared Secret: G,E - TLS Key Pair: G,E - TLS Premaster Secret: G,E - TLS Master Secret: G,E - TLS Session Encryption Key: G,E - TLS Session Authentication Key: G,E Read-Write - Operator Passwords: W - Diffie-Hellman (DH) Key Pair: G,E - Diffie-Hellman Shared Secret: G,E - Elliptic Curve Diffie-Hellman (ECDH) Key Pair: G,E - EC Diffie- Hellman Shared Secret: G,E - TLS Key Pair: G,E - TLS Premaster Secret: G,E - TLS Master Secret: G,E - TLS Session Encryption Key: G,E - TLS Session Authentication Key: G,E

G,E G,E G,E G,E G,E G,E PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 26
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access Read-Only - Operator Passwords: W - Diffie-Hellman (DH) Key Pair: G,E - Diffie-Hellman Shared Secret: G,E - Elliptic Curve Diffie-Hellman (ECDH) Key Pair: G,E - EC Diffie- Hellman Shared Secret: G,E - TLS Key Pair: G,E - TLS Premaster Secret: G,E - TLS Master Secret: G,E - TLS Session Encryption Key: G,E - TLS Session Authentication Key: G,E
Configure SNMPv3Configure SNMPv3 security profile, authentication, privacy, etc. settingsGlobal ("FIPS Compliant Mode") in combination with successful completion of serviceCommand and parametersCommand response/ statusSNMPv3 Encrypt/Decrypt SNMP Message Authentication 1 SNMP Message Authentication 2 SNMP Message Authentication 3 SNMP Key DerivationAdmin - SNMP Privacy Key: G,E - SNMP Authentication Key: G,E - SNMPv3 Passwords (Privacy and Auth): W
SNMPv3 trapsProvide system condition informationGlobal ("FIPS Compliant Mode") in combination with successful completion of serviceCommandCommand response/ statusNoneAdmin - SNMPv3 Passwords (Privacy and Auth): W Read-Write - SNMPv3 Passwords

G,E G,E G,E G,E PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 27
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access (Privacy and Auth): W
Export Backup of Configuration file over HTTPS/SFTPSave device and services configuration into fileGlobal ("FIPS Compliant Mode") in combination with successful completion of serviceCommandCommand response/ statusConfig File Encrypt/Decrypt Password ObfuscationAdmin - Operator Passwords: R - Peer- Authentication Pre-Shared Secret: R - SNMPv3 Passwords (Privacy and Auth): R
Restore Configuration file over HTTPS/SFTPRestore device and services configuration into fileGlobal ("FIPS Compliant Mode") in combination with successful completion of serviceCommandCommand response/ statusConfig File Encrypt/Decrypt Password ObfuscationAdmin - Operator Passwords: W - Peer- Authentication Pre-Shared Secret: W - SNMPv3 Passwords (Privacy and Auth): W
View Network TopologyView the structure of a networkN/ACommandCommand response/ statusNoneAdmin Crypto Read-Write Read-Only
Random Number GenerationRandom Number GenerationGlobal ("FIPS Compliant Mode") in combination with successful completion of serviceCommandCommand response/ statusEntropy Source DRBGAdmin - SP 800-90A CTR_DRBG Entropy Input: E - SP 800-90A CTR_DRBG Seed: E - SP 800-90A CTR_DRBG key value: E - SP 800-90A CTR_DRBG V value: E Crypto - SP 800-90A CTR_DRBG Entropy Input: E

PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 28
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access - SP 800-90A CTR_DRBG Seed: E - SP 800-90A CTR_DRBG key value: E - SP 800-90A CTR_DRBG V value: E Read-Write - SP 800-90A CTR_DRBG Entropy Input: E - SP 800-90A CTR_DRBG Seed: E - SP 800-90A CTR_DRBG key value: E - SP 800-90A CTR_DRBG V value: E Read-Only - SP 800-90A CTR_DRBG Entropy Input: E - SP 800-90A CTR_DRBG Seed: E - SP 800-90A CTR_DRBG key value: E - SP 800-90A CTR_DRBG V value: E
Perform Self- Tests On- DemandRun self-testsN/ACommandCommand response/ statusVerify Firmware IntegrityAdmin Read-Write
Factory ResetSee Section 9.3StatusCommandCommand response/ statusNoneAdmin - Operator Passwords: Z - EC DH Key Pair for DEK: Z - ECC CDH primitive for DEK: Z

PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 29

Name

Description

Indicator

Inputs

Outputs

Security Functions

SSP Access - Data Encryption Key (DEK): Z - Peer- Authentication Pre-Shared Secret: Z - Diffie-Hellman (DH) Key Pair: Z - Diffie-Hellman Shared Secret: Z - Elliptic Curve Diffie-Hellman (ECDH) Key Pair: Z - EC Diffie- Hellman Shared Secret: Z - SNMP Privacy Key: Z - SNMP Authentication Key: Z - SNMPv3 Passwords (Privacy and Auth): Z - TLS Key Pair: Z - TLS Premaster Secret: Z - TLS Master Secret: Z - TLS Session Encryption Key: Z - TLS Session Authentication Key: Z - SSH/SFTP Host Key Pair: Z - SSH/SFTP Session Encryption Key: Z - SSH/SFTP

Z Z Z PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 30

Name

Description

Indicator

Inputs

Outputs

Security Functions

SSP Access Session Authentication key: Z - Firmware Update Key: Z - SP 800-90A CTR_DRBG Seed: Z - SP 800-90A CTR_DRBG Entropy Input: Z - SP 800-90A CTR_DRBG key value: Z - SP 800-90A CTR_DRBG V value: Z Read-Write - Operator Passwords: Z - EC DH Key Pair for DEK: Z - ECC CDH primitive for DEK: Z - Data Encryption Key (DEK): Z - Peer- Authentication Pre-Shared Secret: Z - Diffie-Hellman (DH) Key Pair: Z - Diffie-Hellman Shared Secret: Z - Elliptic Curve Diffie-Hellman (ECDH) Key Pair: Z - EC Diffie- Hellman Shared Secret: Z - SNMP Privacy Key: Z

Z PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 31
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access - SNMP Authentication Key: Z - SNMPv3 Passwords (Privacy and Auth): Z - TLS Key Pair: Z - TLS Premaster Secret: Z - TLS Master Secret: Z - TLS Session Encryption Key: Z - TLS Session Authentication Key: Z - SSH/SFTP Host Key Pair: Z - SSH/SFTP Session Encryption Key: Z - SSH/SFTP Session Authentication key: Z - Firmware Update Key: Z - SP 800-90A CTR_DRBG Seed: Z - SP 800-90A CTR_DRBG Entropy Input: Z - SP 800-90A CTR_DRBG key value: Z - SP 800-90A CTR_DRBG V value: Z
ZeroizationSee Section 9.3 (Zeroization)StatusCommandCommand response/ statusNoneAdmin - Operator Passwords: Z - EC DH Key Pair

Z Z PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 32

Name

Description

Indicator

Inputs

Outputs

Security Functions

SSP Access for DEK: Z - ECC CDH primitive for DEK: Z - Data Encryption Key (DEK): Z - Peer- Authentication Pre-Shared Secret: Z - Diffie-Hellman (DH) Key Pair: Z - Diffie-Hellman Shared Secret: Z - Elliptic Curve Diffie-Hellman (ECDH) Key Pair: Z - EC Diffie- Hellman Shared Secret: Z - SNMP Privacy Key: Z - SNMP Authentication Key: Z - SNMPv3 Passwords (Privacy and Auth): Z - TLS Key Pair: Z - TLS Premaster Secret: Z - TLS Master Secret: Z - TLS Session Encryption Key: Z - TLS Session Authentication Key: Z - SSH/SFTP Host Key Pair: Z - SSH/SFTP

Z Z PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 33
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access Session Encryption Key: Z - SSH/SFTP Session Authentication key: Z - Firmware Update Key: Z - SP 800-90A CTR_DRBG Seed: Z - SP 800-90A CTR_DRBG Entropy Input: Z - SP 800-90A CTR_DRBG key value: Z - SP 800-90A CTR_DRBG V value: Z
Firmware UpdateUpload and deploy firmwareGlobal ("FIPS Compliant Mode") in combination with successful completion of serviceCommandCommand response/ statusVerify Firmware LoadAdmin - Firmware Update Key: G,E Read-Write - Firmware Update Key: G,E
4.4 Non-Approved Services

The module does not support any Non-Approved Services. N/A for this module.

4.5 External Software/Firmware Loaded

The version signature is verified by HMAC-SHA-384. Any firmware loaded into this module that is not shown on the module certificate, is out of the scope of this validation and requires a separate FIPS 140-3 validation.

4.6 Bypass Actions and Status

The Bypass capability is the ability of a service to partially or wholly circumvent a cryptographic function or process. The following two independent internal actions are required to activate the bypass capability, to prevent the inadvertent bypass of plaintext data due to a single error: 1. The admin shuts down the interface. PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 34

2. Then switches the interface to non-encrypted mode. *Both actions are accompanied by a service impact warning The module shows status to indicate that the bypass capability is alternately activated and deactivated, and that the module is providing some services with cryptographic processing and some services without cryptographic processing, as follows: If the bypass service indicator is “Bypass is in effect”, it means that at least one active service is not encrypted. If the bypass service indicator is “Bypass in not in effect”, it means that all active services are encrypted.

4.7 Cryptographic Output Actions and Status

The Self-initiated cryptographic output capability is the ability of the module to perform cryptographic operations and other approved security functions or SSP management techniques without external operator request. The following two independent internal actions are required to activate the self-Initiated cryptographic output capability to prevent the inadvertent output due to a single error:

  1. The admin selects the service type and turns on the interface.
  2. The admin confirms the changes. The module shows status to indicate whether the self-Initiated cryptographic output capability is activated through the Admin Status of the respective channel. If the self-Initiated cryptographic output service indicator is “Up” for a respective channel, it means that the capability is activated. If the self-Initiated cryptographic output service indicator is “Down” for a respective channel, it means that the capability is not activated. PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.
Page 35
5 Software/Firmware Security
5.1 Integrity Techniques

The firmware is delivered as an executable file and the module implements a HMAC-SHA2-384 keyed hash firmware integrity test.

5.2 Initiate on Demand

The Firmware Integrity Test can be invoked by rebooting the module. PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 36
6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Limited PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 37
MechanismInspection FrequencyInspection Guidance
Tamper- evident SealsMinimum of every 30 days.The CO shall inspect the enclosure and tamper-evident seals for physical signs of tampering or attempted access to the cryptographic module. The physical security of the module is intact if there is no evidence of tampering with the tamper-evident seals.
7.1 Mechanisms and Actions Required

The table below details the Physical Security Mechanisms supported by the module. Table 13: Mechanisms and Actions Required The module has a multi-chip standalone embodiment and is made of commercially available, production grade components meeting commercial specifications for power, temperature, reliability, shock and vibration. All production-grade components include standard passivation techniques, in the form of a coating applied over the module’s circuitry to protect against environmental and other physical damage. The production grade metal enclosure is opaque to the visible spectrum, and all openings are designed in such a way to obscure

7.2 User Placed Tamper Seals

Number: The PL-4000M is sealed with 4-5 tamper-evident seals, and the PL-4000T is sealed with 4-7 tamper-evident seals. Placement: The locations of the tamper-evident seals are indicated by the red rectangles in Figures 6 and 7. PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 38

Figure 6: PL-40000M (Front, Rear, Left, Right, Bottom) PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 39

Figure 7: PL-40000T (Front, Rear, Left, Right, Bottom) Surface Preparation: For optimum adhesion, surfaces must be cleaned with alcohol to remove surface contaminants before affixing the tamper-evident seals:

Page 40
8 Non-Invasive Security

Currently, the ISO/IEC 19790:2012 non-invasive security area is not required by FIPS 140-3 (see NIST SP 800-140F). The requirements of this area are not applicable to the module. PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 41
Storage Area NameDescriptionPersistence Type
DDR4 SDRAMRandom memory accessDynamic
QSPI FLASHFlash file systemStatic
NameFromToFormat TypeDistribution TypeEntry TypeSFI or Algorithm
SSP Input 1ExternalQSPI FLASHPlaintextManualElectronic
SSP Input 2ExternalQSPI FLASHEncryptedManualElectronic
SSP Input 3ExternalDDR4 SDRAMPlaintextAutomatedElectronic
SSP Output 1QSPI FLASHExternalEncryptedManualElectronic
SSP Output 2DDR4 SDRAMExternalPlaintextAutomatedElectronic
Zeroization MethodDescriptionRationaleOperator Initiation
Session TerminationAll session ephemeral keys are zeroized.Loss of contentsBy closing of HTTPS/SSH session.
Key LifetimeData Plane ephemeral keys are zeroized.Loss of contentsN/A
Power CycleAll session ephemeral keys are zeroized.Loss of contentsPower cycle
Zeroization CommandAll SSPs are zeroized. System IP is restored to default.Loss of contentsInput zeroization command in console.
Factory ResetAll SSPs are zeroized. System IP is kept.Loss of contentsInput factory reset command in console.
9 Sensitive Security Parameters Management
9.1 Storage Areas

The table below lists Sensitive Security Parameters (SSPs) storage areas for the module. Section 9.4 below selects from the storage areas listed and specifies the appropriate parameter in the “Storage” column if applicable to a specific SSP. Table 14: Storage Areas The table below lists SSP input and output methods for the module. Section 9.4 below selects from the input and output methods listed and specifies the appropriate parameter in the “Inputs/Outputs” column if applicable to a specific SSP. Table 15: SSP Input-Output Methods The table below lists SSP zeroization methods for this module. Section 9.4 below selects from the zeroization methods listed and specifies the appropriate parameter in the “Zeroization” column if applicable to a specific SSP. Table 16: SSP Zeroization Methods The following table summarizes the keys and Sensitive Security Parameters (SSPs) that are used by the cryptographic services implemented in the module: PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 42
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
Operator PasswordsAuthentication for the Admin, Crypto, Read- Write and Read- Only rolesMinimum of 8 bytes (64 bits) and maximum of 20 bytes (160 bits) string value - Minimum of 8 bytes (64 bits) and maximum of 20 bytes (160 bits) string valueAuthentication string - CSP
EC DH Key Pair for DEKKey pair used in NIST SP 800- 56Arev3 (Section 5.7.1.2) ECC CDH Primitive computationP-384 - 192 bitsPublic/Private - CSPKAS Key Pair Generation 1KAS 1
ECC CDH primitive for DEKShared Secret (Z) value that will be used to derive the DEK384-bit string - 192 bitsKey Material - CSPKAS 1KAS 1
Data Encryption Key (DEK)Used for encrypting or decrypting payload data256-bit - 256 bitsSymmetric key - CSPKAS 1Client Data Encrypt/Decrypt 1 Client Data Encrypt/Decrypt 2
Peer- Authentication Pre-Shared SecretEntered by Crypto. Parameter used for Peer- Authentication during key exchange384-bit string - 384 bitsAuthentication hex string - CSPData Plane KEX Message Authentication
Diffie-Hellman (DH) Key PairNegotiating TLS/HTTPS or SSH/SFTP sessionsPublic: 2048- bit, 3072-bit, 4096-bit / Private: 224- bit, 256-bit, 325-bit - 112Public/Private - CSPKAS Key Pair Generation 2KAS 3 KAS 6

PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 43
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
bits, 128 bits, 152 bits
Diffie-Hellman Shared SecretDiffie-Hellman Shared Secret2048-bit, 3072-bit, 4096-bit - 112 bits, 128 bits, 152 bitsShared Secret - CSPKAS 3 KAS 6KAS 3 KAS 6
Elliptic Curve Diffie-Hellman (ECDH) Key PairNegotiating TLS/HTTPS or SSH/SFTP sessionsP-256, P-384, P-521 - 128 bits, 192 bits, 256 bitsPublic/Private - CSPKAS Key Pair Generation 1KAS 2 KAS 4 KAS 5
EC Diffie- Hellman Shared SecretEC Diffie- Hellman Shared SecretP-256, P-384, P-521 - 128 bits, 192 bits, 256 bitsShared Secret - CSPKAS 2 KAS 4 KAS 5KAS 2 KAS 4 KAS 5
SNMP Privacy KeyEncryption / Decryption of SNMP traffic128-bit, 192- bit, 256-bit - 128 bits, 192 bits, 256 bitsSymmetric key - CSPSNMP Key DerivationSNMPv3 Encrypt/Decrypt
SNMP Authentication KeyMessage authentication and verification in SNMPHMAC-SHA2- 256, HMAC- SHA2-384, HMAC-SHA2- 512 - 256 bits, 384 bits, 512 bitsSymmetric key - CSPSNMP Key DerivationSNMP Message Authentication 1 SNMP Message Authentication 2 SNMP Message Authentication 3
SNMPv3 Passwords (Privacy and Auth)SNMPv3 PasswordsMinimum of 8 bytes (64 bits) and maximum of 20 bytes (160 bits) string value - Minimum of 8 bytes (64 bits) and maximum of 20 bytes (160 bits) string valueAuthentication string - CSPSNMP Key Derivation
TLS Key PairKey Pair used for TLS authenticationP-384 - 192 bitsPublic/Private - CSPTLS Key Pair/Certificate GenerationTLS Digital Signature Generation TLS Digital

PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 44
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By Signature Verification
TLS Premaster SecretEstablish the TLS Master Secret384-bit string - 192 bitsKey material - CSPKAS 4 KAS 5 KAS 6TLS Key Derivation
TLS Master SecretEstablish the TLS Session Keys384-bit string - 192 bitsKey material - CSPTLS Key DerivationTLS Key Derivation
TLS Session Encryption KeyUsed for encrypting/ decrypting TLS messages128-bit, 256- bit - 128 bits, 256 bitsSymmetric Key - CSPTLS Key DerivationTLS Encrypt/Decrypt
TLS Session Authentication KeyUsed for authenticating TLS messagesHMAC SHA2- 256, HMAC SHA2-384 - 256 bits, 384 bitsSymmetric Key - CSPTLS Key DerivationTLS Message Authentication 1 TLS Message Authentication 2
SSH/SFTP Host Key PairKey Pair used for SSH/SFTP authentication2048-bit - 112 bitsPublic/Private - CSPSSH Key Pair Generation
SSH/SFTP Session Encryption KeyUsed for Encrypting SSH/SFTP messages128-bit, 192- bit, 256-bit - 128 bits, 192 bits, 256 bitsSymmetric Key - CSPSSH Key DerivationSSH Encrypt/Decrypt 1 SSH Encrypt/Decrypt 2
SSH/SFTP Session Authentication keyData authentication for SSH/SFTP sessionsHMAC SHA2- 256, HMAC SHA2-512 - 256 bits, 512 bitsSymmetric Key - CSPSSH Key DerivationSSH Message Authentication 1 SSH Message Authentication 2
Firmware Update KeyFirmware Update KeyHMAC SHA2- 384 - 384 bitsSymmetric Key - CSPFactoryVerify Firmware Load
SP 800-90A CTR_DRBG SeedSeeding material for the SP800- 90A CTR_DRBG384-bit value - 384-bit valueKey material - CSPEntropy SourceDRBG
SP 800-90A CTR_DRBG Entropy InputEntropy Input for the SP800- 90A CTR_DRBG384-bit value - 384-bit valueKey material - CSPEntropy SourceDRBG
SP 800-90A CTR_DRBG key valueUsed for the SP 800-90A CTR_DRBGInternal state value - Internal state valueInternal state value - CSPDRBGDRBG
SP 800-90A CTR_DRBG V valueUsed for the SP 800-90A CTR_DRBGInternal state value -Internal state value - CSPDRBGDRBG

PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 45
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
Internal state value
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
Operator PasswordsSSP Input 1 SSP Input 2 SSP Output 1QSPI FLASH:ObfuscatedZeroization Command Factory Reset
EC DH Key Pair for DEKSSP Input 3 SSP Output 2DDR4 SDRAM:PlaintextKey Lifetime Power CycleECC CDH primitive for DEK:Derives
ECC CDH primitive for DEKDDR4 SDRAM:PlaintextKey Lifetime Power CycleEC DH Key Pair for DEK:Derived From
Data Encryption Key (DEK)DDR4 SDRAM:PlaintextKey Lifetime Power CycleECC CDH primitive for DEK:Derived From
Peer-Authentication Pre- Shared SecretSSP Input 1 SSP Input 2 SSP Output 1QSPI FLASH:EncryptedZeroization Command Factory Reset
Diffie-Hellman (DH) Key PairSSP Input 3 SSP Output 2DDR4 SDRAM:PlaintextSession Termination Power CycleDiffie-Hellman Shared Secret:Derives
Diffie-Hellman Shared SecretDDR4 SDRAM:PlaintextSession Termination Power CycleDiffie-Hellman (DH) Key Pair:Derived From
Elliptic Curve Diffie- Hellman (ECDH) Key PairSSP Input 3 SSP Output 2DDR4 SDRAM:PlaintextSession Termination Power CycleEC Diffie-Hellman Shared Secret:Derives
EC Diffie-Hellman Shared SecretDDR4 SDRAM:PlaintextSession Termination Power CycleElliptic Curve Diffie-Hellman (ECDH) Key Pair:Derived From
SNMP Privacy KeyDDR4 SDRAM:PlaintextPower CycleSNMPv3 Passwords (Privacy and Auth):Derived From
SNMP Authentication KeyDDR4 SDRAM:PlaintextPower CycleSNMPv3 Passwords (Privacy and Auth):Derived From

Table 17: SSP Table 1 PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 46
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
SNMPv3 Passwords (Privacy and Auth)SSP Input 1 SSP Input 2 SSP Output 1QSPI FLASH:EncryptedZeroization Command Factory ResetSNMP Privacy Key:Derives SNMP Authentication Key:Derives
TLS Key PairQSPI FLASH:EncryptedZeroization Command Factory Reset
TLS Premaster SecretDDR4 SDRAM:PlaintextSession Termination Power CycleTLS Master Secret:Derives
TLS Master SecretDDR4 SDRAM:PlaintextSession Termination Power CycleTLS Premaster Secret:Derived From TLS Session Encryption Key:Derives TLS Session Authentication Key:Derives
TLS Session Encryption KeyDDR4 SDRAM:PlaintextSession Termination Power CycleTLS Master Secret:Derived From
TLS Session Authentication KeyDDR4 SDRAM:PlaintextSession Termination Power CycleTLS Master Secret:Derived From
SSH/SFTP Host Key PairQSPI FLASH:EncryptedZeroization Command Factory Reset
SSH/SFTP Session Encryption KeyDDR4 SDRAM:PlaintextSession Termination Power Cycle
SSH/SFTP Session Authentication keyDDR4 SDRAM:PlaintextSession Termination Power Cycle
Firmware Update KeyQSPI FLASH:EncryptedN/A
SP 800-90A CTR_DRBG SeedDDR4 SDRAM:PlaintextPower CycleSP 800-90A CTR_DRBG Entropy Input:Derived From
SP 800-90A CTR_DRBG Entropy InputDDR4 SDRAM:PlaintextPower Cycle
SP 800-90A CTR_DRBG key valueDDR4 SDRAM:PlaintextPower CycleSP 800-90A CTR_DRBG Seed:Derived From
SP 800-90A CTR_DRBG V valueDDR4 SDRAM:PlaintextPower CycleSP 800-90A CTR_DRBG Seed:Derived From

Table 18: SSP Table 2 PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 47
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
HMAC-SHA2-384 (A4261)384-bitIntegrity TestSW/FW IntegrityStatusKeyed message authentication code-based firmware integrity verification
SHA2-384 (A4261)384-bitBypass TestBypassStatusEnsures the correct operation of the logic governing activation of the bypass capability.
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-CTR (A4136)256-bitKATsCASTStatusSeparate Encrypt and DecryptPower Up
AES-GMAC (A4136)256-bitKATsCASTStatusSeparate Encrypt and DecryptPower Up
AES-ECB (A2709)256-bitKATsCASTStatusSeparate Encrypt and DecryptPower Up
AES-GCM (A2709)256-bitKATsCASTStatusSeparate Encrypt and DecryptPower Up
AES-ECB (A4261)128-bitKATsCASTStatusSeparate Encrypt and DecryptPower Up
AES-GCM (A4261)256-bitKATsCASTStatusSeparate Encrypt and DecryptPower Up
Counter DRBG (A4261)128-bitKATCASTStatusSP 800-90 A Section 11.3Power Up
ECDSA KeyGen (FIPS186-5) (A4261)P-384, SHA2-384PCTPCTStatus-Key Pair Generation
ECDSA SigGen (FIPS186-5) (A4261)P-384, SHA2-384KATCASTStatusSignPower Up
ECDSA SigVer (FIPS186-5) (A4261)P-384, SHA2-384KATCASTStatusVerifyPower Up
HMAC-SHA2-384 (A4261)384-bitKATCASTStatus-Power Up
10 Self-Tests

This section specifies the pre-operational and conditional self-tests performed by the module. The pre-operational and conditional selftests ensure that the module is not corrupted and that the cryptographic algorithms work as expected.

10.1 Pre-Operational Self-Tests

Pre-operational Self-Tests are run upon the power up/initialization of the module. The module transitions to the operational state only after the pre-operational self-tests (and the cryptographic algorithm self-tests (CASTs)) are passed successfully. The design of the modules ensures that all data output, via the data output interface, is inhibited whenever the module is in a pre-operational self-test condition. The Pre-Operational Self-Tests are detailed in the table below. Table 19: Pre-Operational Self-Tests

10.2 Conditional Self-Tests

Conditional Self-Tests are run when an applicable security function or process is invoked. The Conditional Self-Tests are detailed in the table below. PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 48
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
KAS-ECC-SSC Sp800-56Ar3 (A4261)P-256KATCASTStatusEphemeral Unified Shared Secret (Z) ComputationPower Up
KAS-FFC-SSC Sp800- 56Ar3 (A4261)2048-bitKATCASTStatusEphemeral Unified Shared Secret (Z) ComputationPower Up
KDA OneStep SP800-56Cr2 (A4261)SHA2-384KATCASTStatus-Power Up
KDF SNMP (A4261)-KATCASTStatus-Power Up
KDF SSH (A4261)SHA2-256KATCASTStatus-Power Up
RSA KeyGen (FIPS186-5) (A4261)2048-bitPCTPCTStatus-Key Pair Generation
Safe Primes Key Generation (A4261)MODP-2048, MODP- 3072, MODP-4096, ffdhe2048, ffdhe3072PCTPCTStatus-Key Pair Generation
SHA2-256 (A4261)256-bitKATCASTStatus-Power Up
SHA2-512 (A4261)512-bitKATCASTStatus-Power Up
TLS v1.2 KDF RFC7627 (A4261)SHA2-256KATCASTStatus-Power Up
TLS v1.3 KDF (A4261)SHA2-256KATCASTStatus-Power Up
Firmware Load Test (HMAC-SHA2-384 (A4261)HMAC-SHA2-384-SW/FW LoadStatus-Firmware Loading
SHA2-384 (A4261)384-bit-BypassStatus-Bypass modification
Adaptive Proportion Test (APT)-FDCASTStatusSP 800-90B Section 4Continuous
Repetition Count Test (RCT)-FDCASTStatusSP 800-90B Section 4Continuous
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2-384 (A4261)Integrity TestSW/FW IntegrityOn DemandPower Cycle
SHA2-384 (A4261)Bypass TestBypassOn DemandPower Cycle

Table 20: Conditional Self-Tests

10.3 Periodic Self-Test Information

Pre-operational self-tests can be run on-demand, for periodic testing, by rebooting the module. Table 21: Pre-Operational Periodic Information PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 49
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-CTR (A4136)KATsCASTOn DemandPower Cycle
AES-GMAC (A4136)KATsCASTOn DemandPower Cycle
AES-ECB (A2709)KATsCASTOn DemandPower Cycle
AES-GCM (A2709)KATsCASTOn DemandPower Cycle
AES-ECB (A4261)KATsCASTOn DemandPower Cycle
AES-GCM (A4261)KATsCASTOn DemandPower Cycle
Counter DRBG (A4261)KATCASTOn DemandPower Cycle
ECDSA KeyGen (FIPS186-5) (A4261)PCTPCTOn DemandPower Cycle
ECDSA SigGen (FIPS186-5) (A4261)KATCASTOn DemandPower Cycle
ECDSA SigVer (FIPS186-5) (A4261)KATCASTOn DemandPower Cycle
HMAC-SHA2-384 (A4261)KATCASTOn DemandPower Cycle
KAS-ECC-SSC Sp800- 56Ar3 (A4261)KATCASTOn DemandPower Cycle
KAS-FFC-SSC Sp800- 56Ar3 (A4261)KATCASTOn DemandPower Cycle
KDA OneStep SP800- 56Cr2 (A4261)KATCASTOn DemandPower Cycle
KDF SNMP (A4261)KATCASTOn DemandPower Cycle
KDF SSH (A4261)KATCASTOn DemandPower Cycle
RSA KeyGen (FIPS186- 5) (A4261)PCTPCTOn DemandPower Cycle
Safe Primes Key Generation (A4261)PCTPCTOn DemandPower Cycle
SHA2-256 (A4261)KATCASTOn DemandPower Cycle
SHA2-512 (A4261)KATCASTOn DemandPower Cycle
TLS v1.2 KDF RFC7627 (A4261)KATCASTOn DemandPower Cycle
TLS v1.3 KDF (A4261)KATCASTOn DemandPower Cycle
Firmware Load Test (HMAC-SHA2-384 (A4261)-SW/FW LoadOn DemandProvided Service
SHA2-384 (A4261)-BypassOn DemandProvided Service
Adaptive Proportion Test (APT)FDCASTOn Demand & ContinuousPower Cycle
Repetition Count Test (RCT)FDCASTOn Demand & ContinuousPower Cycle

Table 22: Conditional Periodic Information PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 50
NameDescriptionConditionsRecovery MethodIndicator
Critical Error-Pre-Operational, A4261 CAST, A4136 CAST or 4261 PCT failsAttempt reboot, if reboot does not clear error return to manufacturer."...Self-Test FAILED"
Data Plane Critical Error-A2709 CAST or Conditional Bypass self-test failsAttempt reboot, if reboot does not clear error return to manufacturer."...Self-Test FAILED"
Soft Error-RCT or APT self-test failsModule returns to operational state once error is logged."...Self-Test FAILED"
10.4 Error States

If any of the Pre-operational Self-Tests or Cryptographic Algorithm Self-Tests fail, the module will output an error status and enter a critical error state, where all data output is inhibited. Upon entering a critical error state, an operator can attempt to clear the critical error state by rebooting the module. If the critical error state cannot be cleared, the module must be returned to the manufacturer. The action taken upon failure of a conditional self-test is context dependent. The table below shows the different causes that lead to the Error States and the status indicators reported. Table 23: Error States PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 51
11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

The secure delivery of the modules is guaranteed by the trusted courier (DHL). Upon receipt of the module, the Crypto-Officer is responsible for verifying the packaging information slip and checking the delivery packaging for any irregularities (such as openings or tears). If the Crypto-Officer suspects any tampering, they should immediately contact PacketLight Networks Ltd. If the Crypto-Officer does not suspect tampering upon delivery of the module, they shall follow the steps defined in the Installation section of the PacketLight PL4000M/PL-4000T Security Guides (shipped with the cryptographic module). The operator shall set up the device as defined in the PacketLight PL-4000M/PL-4000T Security Guides

11.2 Administrator Guidance

The following steps are required to enable the secure operation of the Module:

Verify that the firmware version of the module is 2.1.0.
The default password of the Admin and Crypto shall be changed upon first use.
All operator passwords shall be a minimum of 8 characters in length.
The default Pre-Shared Secret for Data Plane Encryption shall be changed by Crypto prior to enabling the Data Plane Encryption Service.
Admin shall configure firewall to only allow secure protocols. o Ensure HTTPS is enabled. o Ensure SSH/SFTP is enabled. o Ensure that SNMPv3 is enabled, and Authentication is not set to use “No Auth” or “No Priv”.
Telnet shall be disabled and not be used in the Approved mode of operation.
HTTP shall be disabled and not be used in the Approved mode of operation.
SNMPv1 and SNMPv2 shall be disabled and not be used in the Approved mode of operation.
RADIUS shall be disabled and not be used in the Approved mode of operation.
TACACS+ shall be disabled and not be used in the Approved mode of operation.
FTP shall be disabled and not be used in the Approved mode of operation.
TFTP shall be disabled and not be used in the Approved mode of operation.
Ensure Encryption License is installed.
The Crypto-Officer shall be aware that performing the “Lock Encrypted Service” command will prevent the module from zeroizing SSPs.
RSA keys shall be at least 2048-bits.
The Crypto Officer shall ensure the Key Exchange Period for OTU4 traffic does not exceed 24 hours.
Ensure all traffic is encapsulated in a TLS tunnel as appropriate. Ensure use of Approved algorithms for TLS: 1.2: o TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 o TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 1.3: o TLS_AES_128_GCM_SHA256 o TLS_AES_256_GCM_SHA384 o Curves: P-256:P-384:P-521: ffdehe3072: ffdhe2048

PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 52
Table, extracted as text (did not parse into structured rows)
•    Ensure use of Approved algorithms for SSH: o    Key Exchange Algorithms:     ecdh-sha2-nistp256     ecdh-sha2-nistp384     ecdh-sha2-nistp521     diffie-hellman-group-exchange-sha256 (use modulus size 2048 or greater) o    Encryption Algorithms:     AES128-CTR     AES192-CTR     AES256-CTR     AES128-GCM     AES256-GCM o    Mac Algorithms:     HMAC-SHA2-256     HMAC-SHA2-512 •    Ensure use of Approved algorithms for SNMP: o    Authentication Algorithms:     SHA-256     SHA-384     SHA-512 o    Privacy Algorithms:     AES-CFB128-128     AES-CFB128-192     AES-CFB128-256
11.3 Non-Administrator Guidance

PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.

Page 53
12 Mitigation of Other Attacks

The module does not claim mitigation of other attacks. PacketLight Networks Ltd. 2025 This document may be reproduced and distributed only in its original entirety without revision.