All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Juniper Networks MX Series 3D Universal Edge Routers

Certificate#5134StandardFIPS 140-3Level1TypeHardwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorJuniper Networks, Inc.
High review priority  ·  no TCB surface named  ·  last validated 6 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeHardware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date1/14/2031
CaveatWhen installed, initialized and configured as specified in Section 11.1 of the Security Policy
VendorJuniper Networks, Inc.

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Juniper Networks MX Series 3D Universal Edge Routers
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>firmware load<br/>Recovery</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Unauthenticated</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>SSH<br/>IPSEC</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>kernel</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Juniper Networks MX Series 3D Universal Edge Routers
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>firmware load<br/>Recovery</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Unauthenticated</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>SSH<br/>IPSEC</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>kernel</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Juniper Networks, Inc. Juniper Networks MX Series 3D Universal Edge Routers Version: Junos OS 22.2R3-S1 Juniper Networks, Inc.

1133 Innovation Way
1.888 JUNIPER

www.juniper.net Prepared by: www.teronlabs.com

Page 2
Table of Contents
#SectionPage
Page 4
List of Tables
ItemPage
Table 1: Security Levels6
Table 2: Tested Module Identification – Hardware9
Table 3: Modes List and Description10
Table 4: Approved Algorithms - OpenSSL Approved Cryptographic Functions11
Table 5: Approved Algorithms - Kernel Approved Cryptographic Functions11
Table 6: Approved Algorithms - OpenSSH Approved Cryptographic Functions12
Table 7: Vendor-Affirmed Algorithms12
Table 8: Security Function Implementations14
Table 9: Entropy Certificates15
Table 10: Entropy Sources15
Table 11: Ports and Interfaces17
Table 12: Authentication Methods18
Table 13: Roles18
Table 14: Approved Services22
Table 15: Mechanisms and Actions Required25
Table 16: Storage Areas27
Table 17: SSP Input-Output Methods27
Table 18: SSP Zeroization Methods28
Table 19: SSP Table 130
Table 20: SSP Table 232
Table 21: Pre-Operational Self-Tests33
Table 22: Conditional Self-Tests36
Table 23: Pre-Operational Periodic Information36
Table 24: Conditional Periodic Information38
Table 25: Error States38
Page 6
SectionTitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication2
5Software/Firmware security1
6Operational environment1
7Physical security1
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacksN/A
Overall Level1
1.1 Overview

This is a non-proprietary Cryptographic Module Security Policy for the Juniper Networks MX Series 3D Universal Edge Routers, consisting of the MX240, MX480 and MX960 models, with MX-SPC3 Services Processing Card, running Junos OS 22.2R3-S1.

1.2 Security Levels

The cryptographic module meets requirements applicable to Level 1 of FIPS 140-3. The following table lists the security levels claimed by the cryptographic module for each security requirements area of the FIPS 140-3 standard. Table 1: Security Levels

Page 7
2 Cryptographic Module Specification
2.1 Description

Purpose and Use: The MX series universal routing modular platforms MX240, MX480 and MX960 provide dedicated high-performance processing for flows and sessions and integrates advanced security capabilities that protect the network infrastructure as well as user data. The MX-SPC3 services card provides security services such as carrier-grade NAT (CGNAT), IPsec, stateful firewall, deep packet inspection, IDS, traffic load balancing, Web filtering, and DNS sinkhole. Module Type: Hardware Module Embodiment: MultiChipStand Module Characteristics: Cryptographic Boundary: This Security Policy covers the following models:

Page 8
Model and/or Part NumberHardware VersionFirmware VersionProcessorsFeatures
MX240MX240JUNOS 22.2R3- S1.9Intel Xeon C5518, Intel Xeon E5-2658 v4, Intel Xeon CPU E5-2608L v3Routing Engine (RE): RE-S-X6-64G, RE-S-X6- 128G; Switch control board (SCB): SCBE3-MX; Services Processing Card (SPC): MX-SPC3; Modular Port Concentrator (MPC): MPC10E-10C, MPC10E-15C

The cryptographic module provides for an encrypted connection, using SSH, between the management station and the module. All other data input or output from the module are considered plaintext for this FIPS 140-3 validation. The module does not rely on external devices for input and output of security sensitive parameters (SSPs). Figure 1 Physical Cryptographic Boundary (Left to Right: MX240, MX480, MX960)

2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification – Hardware:

Page 9
Model and/or Part NumberHardware VersionFirmware VersionProcessorsFeatures
MX480MX480JUNOS 22.2R3- S1.9Intel Xeon C5518, Intel Xeon E5-2658 v4, Intel Xeon CPU E5-2608L v3Routing Engine (RE): RE-S-X6-64G, RE-S-X6- 128G; Switch control board (SCB): SCBE3-MX; Services Processing Card (SPC): MX-SPC3; Modular Port Concentrator (MPC): MPC10E-10C, MPC10E-15C
MX960MX960JUNOS 22.2R3- S1.9Intel Xeon C5518, Intel Xeon E5-2658 v4, Intel Xeon CPU E5-2608L v3Routing Engine (RE): RE-S-X6-64G, RE-S-X6- 128G; Switch control board (SCB): SCBE3-MX; Services Processing Card (SPC): MX-SPC3; Modular Port Concentrator (MPC): MPC10E-10C, MPC10E-15C

Table 2: Tested Module Identification

2.3 Excluded Components

No components are excluded from the requirements of FIPS 140-3.

2.4 Modes of Operation

Modes List and Description:

Page 10
Mode NameDescriptionTypeStatus Indicator
JUNOS-FIPS- MODEApproved mode of operation enabled by following the configuration commands in Section 11.1ApprovedSuffix string ":fips" in the cli prompt
AlgorithmCAVP CertPropertiesReference
AES-CBCA3693Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CTRA3693Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
ECDSA KeyGen (FIPS186-4)A3693Curve - P-256, P-384, P-521 Secret Generation Mode - Testing CandidatesFIPS 186-4
ECDSA KeyVer (FIPS186-4)A3693Curve - P-256, P-384, P-521FIPS 186-4
ECDSA SigGen (FIPS186-4)A3693Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512FIPS 186-4
ECDSA SigVer (FIPS186-4)A3693Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512FIPS 186-4
HMAC-SHA-1A3693Key Length - Key Length: 160FIPS 198-1
HMAC-SHA2-256A3693Key Length - Key Length: 256FIPS 198-1
HMAC-SHA2-512A3693Key Length - Key Length: 512FIPS 198-1
KAS-ECC-SSC Sp800- 56Ar3A3610Domain Parameter Generation Methods - P-256, P- 384, P-521 Scheme -SP 800-56A Rev. 3

Table 3: Modes List and Description Once the module has been securely initialized following the instructions provided in Section 11.1, the module is in approved mode of operation. Failure to follow the secure initialization instructions results in the module being in a non-compliant state which is out of scope of the validation.

2.5 Algorithms

Approved Algorithms: Although the module may have been tested for additional algorithms or modes, only those listed below are utilized by the module. OpenSSL Approved Cryptographic Functions

Page 11
AlgorithmCAVP CertPropertiesReference
ephemeralUnified - KAS Role - initiator
RSA KeyGen (FIPS186- 4)A3693Key Generation Mode - B.3.3 Modulo - 2048, 4096 Primality Tests - Table C.2 Private Key Format - StandardFIPS 186-4
RSA SigGen (FIPS186- 4)A3693Signature Type - PKCS 1.5 Modulo - 2048, 4096FIPS 186-4
RSA SigVer (FIPS186-4)A3693Signature Type - PKCS 1.5 Modulo - 2048, 4096FIPS 186-4
SHA-1A3693Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-256A3693Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-384A3693Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-512A3693Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
AlgorithmCAVP CertPropertiesReference
HMAC DRBGA3493Prediction Resistance - Yes Mode - SHA2-256SP 800-90A Rev. 1
HMAC-SHA2- 256A3493Key Length - Key Length: 160, 256FIPS 198-1
SHA2-256A3493Message Length - Message Length: 0-51200 Increment 8FIPS 180-4
SHA2-512A3361Message Length - Message Length: 0-51200 Increment 8FIPS 180-4
AlgorithmCAVP CertPropertiesReference
KDF SSH (CVL)A4271Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-256, SHA2-384, SHA2- 512SP 800-135 Rev. 1

Table 4: Approved Algorithms - OpenSSL Approved Cryptographic Functions Kernel Approved Cryptographic Functions Table 5: Approved Algorithms - Kernel Approved Cryptographic Functions OpenSSH Approved Cryptographic Functions

Page 12
NamePropertiesImplementationReference
CKGKey type:AsymmetricJunos 22.2R1 - OpenSSLSP 800-133 Rev.2 Section 4, example 1 direct output from DRBG.
NameTypeDescriptionPropertiesAlgorithms
Enc/Dec (SSH)BC-UnAuthUnauthenticated encryption for SSHAES-CBC: (A3693) AES-CTR: (A3693)
KAS-SSC (SSH)KAS-SSCKey Agreement Scheme Shared Secret Computation for SSHKAS-ECC-SSC Sp800-56Ar3: (A3610)
ECDSA SigGen (SSH)DigSig-SigGenSignature Generation for peer authentication in SSHECDSA SigGen (FIPS186-4): (A3693) SHA2-256: (A3693) SHA2-384: (A3693) SHA2-512: (A3693) HMAC DRBG: (A3493)
ECDSA SigVer (SSH)DigSig-SigVerSignature Verification for peer authentication in SSHECDSA SigVer (FIPS186-4): (A3693) SHA2-256: (A3693)

Table 6: Approved Algorithms - OpenSSH Approved Cryptographic Functions Vendor-Affirmed Algorithms: Table 7: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: N/A for this module. Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. Non-Approved, Not Allowed Algorithms: N/A for this module.

2.6 Security Function Implementations

The module implements the security functions listed in the following table.

Page 13
NameTypeDescriptionPropertiesAlgorithms
SHA2-384: (A3693) SHA2-512: (A3693)
MAC (SSH)MACMessage Authentication for SSHHMAC-SHA-1: (A3693) HMAC-SHA2-256: (A3693) HMAC-SHA2-512: (A3693)
KDF (SSH)KAS-135KDFKey derivation Function for SSHKDF SSH: (A4271) SHA-1: (A3693) SHA2-256: (A3693) SHA2-384: (A3693)
SHA (LibMD)SHAMessage Digest GenerationSHA-1: (A3367) SHA2-256: (A3367) SHA2-512: (A3367)
MAC (LibMD)MACMessage authenticationHMAC-SHA-1: (A3367) HMAC-SHA2-256: (A3367)
DRBG (Kernel)DRBGRandom Bit GenerationHMAC DRBG: (A3493) HMAC-SHA2-256: (A3493) SHA2-256: (A3493)
ECDSA KeyGen (PKID)AsymKeyPair- KeyGenECDSA Key Generation used for SSH when authentication keys are internally generatedECDSA KeyGen (FIPS186-4): (A3693) ECDSA KeyVer (FIPS186-4): (A3693) CKG: () Key type: Asymmetric HMAC DRBG: (A3493)
RSA KeyGen (PKID)AsymKeyPair- KeyGenRSA Key generation used for SSH when authentication keys are internally generatedRSA KeyGen (FIPS186-4): (A3693) CKG: () Key type: Asymmetric HMAC DRBG: (A3493)
Page 14
NameTypeDescriptionPropertiesAlgorithms
RSA SigGen (SSH)DigSig-SigGenRSA Signature Generation for SSHRSA SigGen (FIPS186-4): (A3693)
RSA SigVer (SSH)DigSig-SigVerRSA Signature verification for SSHRSA SigVer (FIPS186-4): (A3693)
Verify imageDigSig-SigVerVerification of software imageECDSA SigVer (FIPS186-4): (A3693) SHA2-256: (A3693) SHA2-384: (A3693)
Full KAS (SSH)KAS-FullFull Key Agreement for SSHKAS-ECC-SSC Sp800-56Ar3: (A3610) KDF SSH: (A4271) SHA-1: (A3693) SHA2-256: (A3693) SHA2-384: (A3693)
KAS-ECC KeyGen (SSH)AsymKeyPair- KeyGenKAS-ECC Key Pair Generation for SSHECDSA KeyGen (FIPS186-4): (A3693) ECDSA KeyVer (FIPS186-4): (A3693) CKG: () Key type: Asymmetric HMAC DRBG: (A3493)
ENTENT-ESVEntropy sourceSHA2-512: (A3361)

Table 8: Security Function Implementations

2.7 Algorithm Specific Information

The module includes RSA and ECDSA algorithms that have been validated using FIPS 186-4 CAVP tests, which are mathematically identical to FIPS 186-5 CAVP tests. Per IG C.K, all RSA and ECDSA algorithms implemented by the module are claimed compliant with FIPS 186-5. The module complies with IG C.F. RSA Key Generation, Signature Generation and Signature Verification have been tested and validated using CAVP testing for all implemented modulus lengths (2048, 3072 and 4096 bits). The number of Miller-Rabin tests used for primality testing as part of RSA Key Generation is consistent with Table C.3.

Page 15
Cert NumberVendor Name
E56Juniper Networks
NameTypeOperational EnvironmentSample SizeEntropy per SampleConditioning Component
Junos OS Non-Physical Entropy SourceNon- PhysicalIntel Xeon C5518512 bits448 bitsA3361 (SHA2- 512)

The module implements the following Approved key agreement methods which have been CAVP tested and validated: • KAS-ECC-SSC per SP 800-56A Rev. 3 (FIPS 140-3 IG D.F Scenario 2, path 1). The module obtains the FIPS 140-3 IG D.F required key agreement assurances in accordance with Section 5.6.2 of SP800-56A Rev. 3. All the key agreement protocols implemented by the module are Diffie-Hellman based. The module includes approved KDF algorithms for the SSH protocol. No parts of the protocol, other than the approved cryptographic algorithms and the KDFs, have been tested by the CAVP and CMVP.

2.8 RBG and Entropy

Table 9: Entropy Certificates Table 10: Entropy Sources The entropy source is used to seed the module’s HMAC DRBG with the minimum required 256bits of entropy. Each 512-bit block of conditioned output from the entropy source contains 448 bits of entropy. The HMAC DRBG is used for all random data required by the module, including key generation. There are no initialization procedures required by the users of the module to operate the entropy source in a compliant manner. The module complies to the ESV Public Use document of the

2.9 Key Generation

The cryptographic module implements the key generation methods listed above in the Security Functions implementation table.

Page 16
ProtocolKey ExchangeAuthCipherIntegrity
SSHv2KAS-ECC (P-256, P-384, P-521)RSA 2048 ECDSA P-256AES CBC 128/192/256 AES CTR 128/192/256HMAC-SHA-1 HMAC-SHA2-256 HMAC-SHA2-512
2.10 Key Establishment

The cryptographic module implements the key establishment methods listed above in the Security Functions implementation table.

2.11 Industry Protocols

The cryptographic module supports the protocols listed below. No part of these protocols, other than the approved cryptographic algorithms and the KDFs, have been tested by the CAVP and CMVP. The SSH algorithms allow independent selection of key exchange, authentication, cipher, and integrity. In reference to the supported protocols table below, each column of options for a given protocol is independent and may be used in any viable combination.

Page 17
Physical PortLogical Interface(s)Data That Passes
Ethernet (data)Data Input Data Output Control Input Status OutputLAN Communications
Ethernet (mgmt.)Data Input Data Output Control Input Status OutputRemote management
SerialControl Input Status OutputLocal management
Reset ButtonControl InputReset
LEDStatus OutputStatus indicator lighting
PowerPowerPower
3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

The following table maps each physical interface to one or more logical interface types defined in the FIPS 140-3 standard. Table 11: Ports and Interfaces

Page 18
Method NameDescriptionSecurity MechanismStrength Each AttemptStrength per Minute
Password authenticationUser and CO authentication via SSH or console. Minimum of 10 ASCII character passwords.SHA (LibMD)Probability of guessing: 1/(96^10) < 1/1,000,000.Timed access mechanism allows max of 9 attempts / min. Probability of guessing: 9/(96^10) < 1/100,000.
Signature authenticationUser/CO authentication via SSHECDSA SigVer (SSH)Strength of signature algorithm, minimum 112-bits. Probability of success for random attempt: 1/(2^112) < 1/1,000,000.A rate of 1 CPU cycle per failed authentication for the Intel Xeon E5-2658 v4 processor (14 cores, 2.3 GHz) allows for the probability of success by brute- force attack: 60 x 14 x 2.3 x 10^9 x 1/(2^112) < 1/100,000.
NameTypeOperator TypeAuthentication Methods
UserRoleMonitorPassword authentication Signature authentication
Cryptographic OfficerRoleCOPassword authentication Signature authentication
4 Roles, Services, and Authentication

Table 12: Authentication Methods The module enforces the separation of roles using either password-based authentication or

4.2 Roles

Table 13: Roles based operator authentication for assuming these roles, using methods specified in Section 4.1. The module supports concurrent operators but does not support a maintenance role and/or bypass capability. connection. As root or super-user, the Cryptographic Officer has permission to view and edit secrets within the module and establish VPN tunnels.

Page 19
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
Configure securitySecurity relevant configuration':fips' suffix in CLI promptCLI commandsStatusSHA (LibMD) MAC (LibMD) DRBG (Kernel) ECDSA KeyGen (PKID) RSA KeyGen (PKID) ENTCryptographic Officer - HMAC DRBG V value: E - HMAC DRBG Key value: E - HMAC DRBG Entropy Input: E - HMAC DRBG Seed: E - CO-PW: W,R - User-PW: W,R - SSH-Priv: G,R,W
ConfigureNon-security relevant configurationNoneCLI commandsStatusNoneCryptographic Officer
Show statusShow statusNoneCLI commandStatusNoneCryptographic Officer User
ZeroizeZeroize/destroy all CSPsNoneCLI commandNone (completion indicator is implicitly provided by the module rebooting)NoneCryptographic Officer - HMAC DRBG V value: Z - HMAC DRBG Key value: Z - HMAC DRBG Seed: Z - HMAC DRBG Entropy Input: Z - SSH-DH- Shared-Secret: Z - SSH-Priv: Z - SSH-SEKs: Z - CO-PW: Z - User-PW: Z - SSH-PUB: Z - Auth-User Pub: Z

The User role monitors the router via the console or SSH. The user role cannot change the

4.3 Approved Services
Page 20
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access - Root-CA: Z - Package-CA: Z - SSH-DH-PUB (self): Z - SSH-DH-PUB (peer): Z
SSH connectInitiate SSH connection for SSH monitoring and control (CLI)':fips' suffix in CLI promptSSH packetsSSH packets, statusEnc/Dec (SSH) KAS-SSC (SSH) ECDSA SigGen (SSH) ECDSA SigVer (SSH) MAC (SSH) KDF (SSH) RSA SigGen (SSH) RSA SigVer (SSH) Full KAS (SSH) KAS-ECC KeyGen (SSH) ENTCryptographic Officer - HMAC DRBG V value: E - HMAC DRBG Key value: E - HMAC DRBG Entropy Input: E - HMAC DRBG Seed: E - SSH-DH- Shared-Secret: G,E - SSH-DH-Priv: G,E - SSH-SEKs: G,E - Auth-CO Pub: E - SSH-Priv: E - CO-PW: E - SSH-DH-PUB (self): G - SSH-DH-PUB (peer): E User - HMAC DRBG V value: E - HMAC DRBG Key value: E - HMAC DRBG Entropy Input: E - HMAC DRBG Seed: E - SSH-Priv: E - User-PW: E - SSH-DH- Shared-Secret: G,E - SSH-DH-Priv: G,E - SSH-SEKs: G
Page 21
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access - SSH-DH-PUB (self): G - SSH-DH-PUB (peer): E - Auth-User Pub: E
Console accessConsole monitoring and control (CLI)NoneCLI commandStatusNoneCryptographic Officer - CO-PW: E User - User-PW: R,E
Remote resetSoftware initiated resetNoneCLI commandStatusNoneCryptographic Officer - HMAC DRBG V value: Z - HMAC DRBG Key value: Z - HMAC DRBG Entropy Input: Z - HMAC DRBG Seed: Z - SSH-DH- Shared-Secret: Z - SSH-DH-Priv: Z - SSH-SEKs: Z - SSH-DH-PUB (self): Z - SSH-DH-PUB (peer): Z
Local resetHardware reset or power cycleNoneManual power cycleStatusNoneUnauthenticated - HMAC DRBG V value: Z - HMAC DRBG Key value: Z - HMAC DRBG Entropy Input: Z - HMAC DRBG Seed: Z - SSH-DH- Shared-Secret: Z - SSH-SEKs: Z - SSH-DH-PUB (self): Z
Page 22
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access - SSH-DH-PUB (peer): Z
TrafficTraffic requiring no cryptographic servicesNoneTraffic inTraffic outNoneUnauthenticated
Load ImageLoading of firmware image':fips' suffix in CLI promptCLI commandstatusVerify imageCryptographic Officer - Root-CA: E - Package-CA: E
Perform self-testsOn-demand execution of all pre- operational and conditional algorithm self-testsNoneLocal or remote resetstatusNoneCryptographic Officer User Unauthenticated
Show versionShow firmware versionNoneCLI commandStatusNoneCryptographic Officer User
4.4 Non-Approved Services
4.5 External Software/Firmware Loaded

The module includes a firmware load service to support necessary updates. Only the CO can install the new image using the CLI as described in Section 11.1. The loaded firmware is a complete image replacement and constitutes an entirely new module and version of Junos OS which would require a separate FIPS 140-3 validation.

Page 23
5.1 Integrity Techniques

The cryptographic module implements an approved firmware integrity self-test that uses ECDSA P-256 with SHA2-256 to ensure the integrity of all Junos OS firmware components. The selftest is automatically run on power-up. It can also be run on demand by the module’s operator by power cycling the module. When the integrity check fails, the module enters an error state (kernel panic) which can only be exited by power-cycling the module.

5.2 Initiate on Demand

The self-test is automatically run on power-up. It can also be run on demand by the module’s operator by power cycling the module.

Page 24
6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Non-Modifiable How Requirements are Satisfied: The module consists of hardware containing a non-modifiable operational environment as per the FIPS 140-3 definitions. It includes a firmware load service to support necessary updates. The loaded firmware is a complete image replacement and constitutes an entirely new module and version of Junos OS which would require a separate FIPS 140-3 validation.

6.2 Configuration Settings and Restrictions

There are no security rules, settings, or restrictions to the configuration of the operational environment beyond the initialization instructions to set the module in approved mode.

Page 25
MechanismInspection FrequencyInspection Guidance
Production-grade components with standard passivationN/AN/A
7 Physical Security
7.1 Mechanisms and Actions Required

Table 15: Mechanisms and Actions Required The module’s physical embodiment is that of a multi-chip standalone device that meets Level 1 Physical Security requirements. The module consists of production-grade components with

Page 26
8 Non-Invasive Security

This section is not applicable, as there are currently no approved non-invasive mitigation techniques specified in ISO/IEC 19790:2012.

Page 27
Storage Area NameDescriptionPersistence Type
RAMRandom Access MemoryDynamic
SSDSolid-Stated DriveDynamic
NameFromToFormat TypeDistribution TypeEntry TypeSFI or Algorithm
Manual CLI entryLocal CORAMPlaintextManualDirect
Entry via SSHRemote CORAMEncryptedAutomatedElectronicEnc/Dec (SSH)
Entry via consoleLocal CORAMPlaintextManualElectronic
Output via SSHRAMRemote COEncryptedAutomatedElectronicEnc/Dec (SSH)
Output via consoleRAMLocal COPlaintextManualDirect
Entry as part of KASRemote peerRAMPlaintextAutomatedElectronic
Output as part of KASRAMRemote peerPlaintextAutomatedElectronic
Pre-loadedManufacturerSSDPlaintextManualDirect
Zeroization MethodDescriptionRationaleOperator Initiation
ResetZeroisation of SSPs in RAM via invocation of local or remote reset serviceRAM is volatile and all data is lost when power is taken off. Zeroisation is practically instantaneous.Yes, both User and CO, via invocation of Local Reset or Remote Reset services
Zeroize CLI commandThese command wipe clean all the SSPs/configs as well as the disk and installs a factory default firmware imageThis command overwrites all data on disk and forces a power cycleYes, CO via invocation of zeroize CLI command
9 Sensitive Security Parameters Management
9.1 Storage Areas
9.2 SSP Input-Output Methods

Table 17: SSP Input-Output Methods

9.3 SSP Zeroization Methods
Page 28
Zeroization MethodDescriptionRationaleOperator Initiation
Explicit zeroize functionZeroisation of SSPs in memory when no longer neededUse of explicit zeroisation function destroys SSP information immediately by overwriting memory area with zeroesNo. The operator cannot directly initiate this method.
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
HMAC DRBG V valueA critical value of the internal state of DRBG per IG D.L256 - 256DRBG internal state - CSPDRBG (Kernel)DRBG (Kernel)
HMAC DRBG Key valueA critical value of the internal state of DRBG per IG D.L256 - 256DRBG internal state - CSPDRBG (Kernel)DRBG (Kernel)
HMAC DRBGA critical value of the internal state of DRBG256 - 256Entropy source output - CSPENTDRBG (Kernel)

Table 18: SSP Zeroization Methods The CO can run the following commands to zeroize the approved mode SSPs: user@host> request vmhost zeroize This command wipes clean all the SSPs/configs as well as the disk and install a factory default firmware image. After zeroizing the system, the module is no longer in a FIPS compliant state. Installation and configuration as per section 11.1 is required to enter the FIPS compliant state and enable the Approved mode of operation. The Cryptographic Officer must retain control of the module while zeroization is in process. Zeroization commands, as described above, and power cycling are initiated by the operator. The module automatically zeroizes all SSPs when no longer required by calling explicit delete commands. Session termination is initiated by the operator or by environmental errors. The completion of zeroization is indicated implicitly. If the zeroization is initiated using a zeroization command or explicit delete command, completion of the command indicates that zeroization has successfully completed. If the zeroization is initiated by power cycling the module, then successful reboot of the module indicates that zeroization has completed successfully. In the case of zeroization initiated by session termination, SSPs are zeroized when the session terminates, and session termination is indicated in the log.

Page 29
Name Entropy InputDescription provided by entropy sourceSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
HMAC DRBG SeedSeed material used to seed or reseed the HMAC DRBG256 - 256DRBG internal state - CSPDRBG (Kernel)DRBG (Kernel)
SSH-DH- Shared- SecretShared DH value computed from the ephemeral DH key-pairs as part of SSH and used to derive session keys. P- 256, P-384 and P-521256, 384, 521 - 128, 192, 256DH shared value - CSPKAS-SSC (SSH)KDF (SSH)
SSH-PrivSSH host authentication key (ECDSA or RSA)2048, 256, 4096, 384, 521 - 112,128, 152, 192, 256Asymmetric private key - CSPECDSA KeyGen (PKID) RSA KeyGen (PKID)ECDSA SigGen (SSH) RSA SigGen (SSH)
SSH-DH- PrivSSH Diffie-Hellman private component. Ephemeral Diffie-Hellman private key used in SSH. P-256, P-384 and P-521256, 384, 521 - 128, 192, 256Asymmetric private key - CSPKAS-ECC KeyGen (SSH)KAS-SSC (SSH)
SSH-SEKsSession keys used with SSH-2.128, 192, 256 - 112,128, 192, 256Symmetric Key - CSPKDF (SSH)Enc/Dec (SSH) MAC (SSH)
CO-PWPassword used to authenticate the COn/a - n/aAuthentication password - CSPSHA (LibMD)
User-PWPassword used to authenticate the User.n/a - n/aAuthentication password - CSP
SSH-PUBSSH Public Host Key2048, 256, 4096, 384, 521 - 112,128, 152, 192, 256Asymmetric key - PSPECDSA KeyGen (PKID) RSA KeyGen (PKID)
Auth-User PubSSH User Authentication Public Key2048, 256, 4096, 384, 521 - 112,128,Asymmetric key - PSPECDSA SigVer (SSH) RSA
Page 30
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
152, 192, 256SigVer (SSH)
Root-CAJuniperRootCA. Used to verify the validity of the PackagCA256, 384 - 128, 196Asymmetric key - PSPVerify image
Package- CACertificate that holds the public key of the signing key that was used to generate all the signatures used on the packages and signatures lists.256 - 128Asymmetric key - PSPVerify image
SSH-DH- PUB (self)ECDH Public Keys generated by module and used with SSH for key establishment256, 384, 521 - 128, 192, 256Asymmetric key - PSPKAS-ECC KeyGen (SSH)
SSH-DH- PUB (peer)ECDH Public Keys provided by protocol peer device and used with SSH for key establishment. P- 256, P-384 and P-521256, 384, 521 - 128, 192, 256Asymmetric key - PSPKAS-SSC (SSH)
Auth-CO PubSSH CO Authentication Public Key2048, 256, 4096, 384, 521 - 112,128, 152, 192, 256Asymmetric key - PSPECDSA SigVer (SSH) RSA SigVer (SSH)

Name HMAC DRBG V value HMAC DRBG Key value HMAC DRBG

Input - Output

Storage RAM:Plaintext RAM:Plaintext RAM:Plaintext

Storage Duration Until updated by HMAC_DRBG_Update() Until updated by HMAC_DRBG_Update() Until HMAC_Instantiate_Update() or HMAC_DRBG_Reseed() complete

Zeroization Reset Reset Reset Explicit

Related SSPs

Page 31
Name Entropy Input HMAC DRBG Seed SSH-DH- Shared- Secret SSH-Priv SSH-DH-Priv SSH-SEKsInput - OutputStorage RAM:Plaintext RAM:Plaintext RAM:Plaintext SSD:Plaintext RAM:Plaintext RAM:PlaintextStorage Duration Until HMAC_Instantiate_Update() or HMAC_DRBG_Reseed() complete Until SSH session termination Until SSH session termination Until SSH session termination Until SSH session terminationZeroization zeroize function Reset Explicit zeroize function Reset Explicit zeroize function Reset Zeroize CLI command Explicit zeroize function Reset Explicit zeroize function Reset Explicit zeroize functionRelated SSPs
CO-PWManual CLI entry Entry via SSH Entry via consoleSSD:Encrypted RAM:PlaintextUntil authentication session terminationZeroize CLI command
User-PWManual CLI entry Entry via SSH Entry via consoleRAM:Plaintext SSD:ObfuscatedUntil authentication session terminationZeroize CLI command
SSH-PUBOutput via SSH Output via console Output asSSD:PlaintextZeroize CLI command
Page 32
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
part of KAS
Auth-User PubEntry via SSH Entry via consoleSSD:PlaintextZeroize CLI command
Root-CAPre-loadedSSD:PlaintextZeroize CLI command
Package-CAPre-loadedSSD:PlaintextZeroize CLI command
SSH-DH- PUB (self)Output as part of KASRAM:PlaintextUntil SSH session terminationReset Explicit zeroize function
SSH-DH- PUB (peer)Entry as part of KASRAM:PlaintextUntil SSH session terminationReset Explicit zeroize function
Auth-CO PubEntry via SSH Entry via consoleZeroize CLI command
9.5 Transitions

The following transitions apply to algorithms used by this module: SHA-1: The SHA-1 hash algorithm will be non-Approved for all cryptographic purposes after December 31, 2030.

Page 33
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
Firmware Integrity checkECDSA P- 256 with SHA2-256KATSW/FW IntegrityPASS/FAIL console outputECDSA Verify
Critical functions testSHA2-256KATCritical FunctionPASS/FAIL console outputThe module implements a critical function that checks that any file that is executed is registered in a manifest of executable files that comes with the firmware. A pre-operational critical function test is implemented that verifies the integrity of the operational environment is being enforced by having the kernel attempt to run a specific executable file that does not contain a hash in the manifest file. The test is successful if it verifies that the specific file cannot be executed.
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
Entropy Source (start-up)n/aAPT, RCTCASTConsole output / output of entropy sourceStart-upOn power-up
Entropy Source (continuous)n/aAPT, RCTCASTConsole output / output of entropy sourceContinuousOn power-up
AES-CBC (A3693) EncryptKey Sizes: 128, 192, 256KATCASTPASS/FAIL console outputEncryptOn power-up
AES-CBC (A3693) DecryptKey Sizes: 128, 192, 256KATCASTPASS/FAIL console outputDecryptOn power-up
10 Self-Tests

On power up or reset, the module performs the pre-operational self-tests and the indicated conditional cryptographic algorithm self-tests described below. All KATs must be completed successfully prior to any other use of cryptography by the module. The algorithms utilized in the

10.1 Pre-Operational Self-Tests

Table 21: Pre-Operational Self-Tests

10.2 Conditional Self-Tests
Page 34
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
AES-CTR (A3693) EncryptKey Sizes: 128, 192, 256KATCASTPASS/FAIL console outputEncryptOn power-up
AES-CTR (A3693) DecryptKey Sizes: 128, 192, 256KATCASTPASS/FAIL console outputDecryptOn power-up
HMAC DRBG (A3693)SHA2-256KATCASTPASS/FAIL console outputHealth-tests initialise, re- seed, and generateOn power-up
KAS-ECC-SSC Sp800-56Ar3 (A3610)P-256 (SHA 256) P-384 (SHA 384) P- 521 (SHA 512)KATCASTPASS/FAIL console outputECDH computationOn power-up
ECDSA SigGen (FIPS186-4) (A3693)P-256, P-384, P-521KATCASTPASS/FAIL console outputSignOn power-up
ECDSA SigVer (FIPS186-4) (A3693)P-256, P-384, P-521KATCASTPASS/FAIL console outputVerifyOn power-up
HMAC-SHA-1 (A3693)Key size: 160 bits, = 160KATCASTPASS/FAIL console outputMACOn power-up
HMAC-SHA2- 256 (A3693)Key size: 256 bits, = 256KATCASTPASS/FAIL console outputMACOn power-up
HMAC-SHA2- 512 (A3693)Key size: 512 bits, = 512KATCASTPASS/FAIL console outputMACOn power-up
RSA SigGen (FIPS186-4) (A3693)RSA 2048 w/ SHA2-256, RSA 4096 w/ SHA2-256KATCASTPASS/FAIL console outputSignOn power-up
RSA SigVer (FIPS186-4) (A3693)RSA 2048 w/ SHA2-256, RSA 4096 w/ SHA2-256KATCASTPASS/FAIL console outputVerifyOn power-up
SHA-1 (A3693)n/aKATCASTPASS/FAIL console outputHashOn power-up
SHA2-256 (A3693)n/aKATCASTPASS/FAIL console outputHashOn power-up
Page 35
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
SHA2-384 (A3693)n/aKATCASTPASS/FAIL console outputHashOn power-up
SHA2-512 (A3693)n/aKATCASTPASS/FAIL console outputHashOn power-up
KDF SSH (A4271)SHA-1, SHA2- 256, SHA2-384KATCASTPASS/FAIL console outputKey derivationOn power-up
SHA-1 (A3367)n/aKATCASTPASS/FAIL console outputHashOn power-up
SHA2-256 (A3367)n/aKATCASTPASS/FAIL console outputHashOn power-up
SHA2-512 (A3367)n/aKATCASTPASS/FAIL console outputHashOn power-up
HMAC-SHA-1 (A3367)Key size: 160 bits, = 160KATCASTPASS/FAIL console outputMACOn power-up
HMAC-SHA2- 256 (A3367)Key size: 256 bits, = 256KATCASTPASS/FAIL console outputMACOn power-up
HMAC DRBG (A3493)SHA2-256KATCASTPASS/FAIL console outputInstantiate, Reseed, GenerateOn power-up
HMAC-SHA2- 256 (A3493)Key size:256 bits, = 256KATCASTPASS/FAIL console outputMACOn power-up
SHA2-256 (A3493)n/aKATCASTPASS/FAIL console outputHashOn power-up
ECDSA KeyGen (FIPS186-4) (A3693)P-256, P-384, P-521PCTPCTReturned key/transition soft error stateGeneration and Verification of ECDSA signatureOn key generation
RSA KeyGen (FIPS186-4) (A3693)RSA 2048, RSA 4096PCTPCTReturned key/transition soft error stateGeneration and Verification of signatureOn key generation
FW loadECDSA P-256 with SHA2-256KATSW/FW LoadPASS/FAIL console outputVerification of ECDSA signature on FWOn FW load
SHA2-512 (A3361)n/aKATCASTPASS/FAIL console outputhashOn power-up
Page 36
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetailsConditions
Manual SSP entry-Duplicate entryManual EntryPASS/FAIL console outputDuplicate entryOn manual, direct entry of SSP
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
Firmware Integrity checkKATSW/FW IntegrityOn demandManually
Critical functions testKATCritical FunctionOn demandManually
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
Entropy Source (start-up)APT, RCTCASTOn demandManually
Entropy Source (continuous)APT, RCTCASTContinuousAutomatically
AES-CBC (A3693) EncryptKATCASTOn demandManually
AES-CBC (A3693) DecryptKATCASTOn demandManually
AES-CTR (A3693) EncryptKATCASTOn demandManually
AES-CTR (A3693) DecryptKATCASTOn demandManually
HMAC DRBG (A3693)KATCASTOn demandManually
KAS-ECC-SSC Sp800-56Ar3 (A3610)KATCASTOn demandManually
ECDSA SigGen (FIPS186-4) (A3693)KATCASTOn demandManually
ECDSA SigVer (FIPS186-4) (A3693)KATCASTOn demandManually

Table 22: Conditional Self-Tests

10.3 Periodic Self-Test Information

Table 23: Pre-Operational Periodic Information

Page 37
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA-1 (A3693)KATCASTOn demandManually
HMAC-SHA2-256 (A3693)KATCASTOn demandManually
HMAC-SHA2-512 (A3693)KATCASTOn demandManually
RSA SigGen (FIPS186-4) (A3693)KATCASTOn demandManually
RSA SigVer (FIPS186-4) (A3693)KATCASTOn demandManually
SHA-1 (A3693)KATCASTOn demandManually
SHA2-256 (A3693)KATCASTOn demandManually
SHA2-384 (A3693)KATCASTOn demandManually
SHA2-512 (A3693)KATCASTOn demandManually
KDF SSH (A4271)KATCASTOn demandManually
SHA-1 (A3367)KATCASTOn demandManually
SHA2-256 (A3367)KATCASTOn demandManually
SHA2-512 (A3367)KATCASTOn demandManually
HMAC-SHA-1 (A3367)KATCASTOn power-upManually
HMAC-SHA2-256 (A3367)KATCASTOn power-upManually
HMAC DRBG (A3493)KATCASTOn power-upManually
HMAC-SHA2-256 (A3493)KATCASTOn power-upManually
SHA2-256 (A3493)KATCASTOn power-upManually
ECDSA KeyGen (FIPS186-4) (A3693)PCTPCTOn condition triggerAutomatic
RSA KeyGen (FIPS186-4) (A3693)PCTPCTOn condition triggerAutomatic
FW loadKATSW/FW LoadOn FW load requestAutomatic
SHA2-512 (A3361)KATCASTOn power-upManually
Manual SSP entryDuplicate entryManual EntryOn condition triggerAutomatic
Page 38
NameDescriptionConditionsRecovery MethodIndicator
Critical Failure stateThe cryptographic module ceases to perform cryptographic operations, inhibits all data output, and provides status of the error via syslog messages and console status outputOn self-test errorPower cycleConsole status output
Soft Error StateA non-critical self-test failure occurs, causing a failure of the triggering operationPCT, firmware load test, continuous entropy health test failureThe module processes the error, and resumes normal operationConsole displays error

Table 24: Conditional Periodic Information

10.4 Error States

Table 25: Error States execution to halt. The only way to exit from this state is to reboot the module, which causes the self-tests to be repeated and pass successfully before the corresponding algorithms are usable.

10.5 Operator Initiation of Self-Tests

Self–tests that are performed at power-up are available on demand by power cycling the

Page 39
11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

Before installation of module firmware, CO must first zeroize any module SSPs by following the instructions in Section 9.3. Once zeroization is complete, the CO must install the JUNOS firmware image on the device using the following CLI command: CO@host> request system software add /<image-path>/<image-filename> no-copy no-validate reboot. The image-filename for the validated firmware is as follows: • junos-vmhost-install-srx-x86-64-22.2R3-S1.9.tgz Next, the CO shall proceed as follows:

  1. Enable the approved mode on the device. CO@host> set system fips chassis level 1
  2. Set the root password. user@host# set system root-authentication plain-text-password New password: <type password here>
  3. Commit and reboot the device. CO@host# commit Once the module is rebooted and the integrity and self-tests have run successfully on initial power-on in, the module is operating in the approved mode of operation. The CO must create a backup image of the firmware to ensure it is also an approved mode Junos OS image by issuing the request system snapshot command. The show version command will display the version of the Junos OS on the device so that the CO can confirm it is the FIPS validated version. The CO should also verify the presence of the suffix string “:fips” in the cli prompt, indicating the module is operating in approved mode. TLS and IKE/IPsec are not enabled by default and must not be enabled for FIPS compliant usage of the module.
11.2 Administrator Guidance

The Cryptographic Officer is the person responsible for enabling, configuring, monitoring, and maintaining the module in approved mode. The Cryptographic Officer securely installs Junos OS on the device, enables the approved of operation, establishes keys and passwords for other users and software modules, and initializes the device before network connection. The

Page 40

Cryptographic Officer can configure and monitor the module through a console or SSH connection.

11.3 Non-Administrator Guidance

No specific non-administrator guidance is required to operate the module.

11.4 Design and Rules

The module design corresponds to the security rules below. The term must in this context specifically refers to a requirement for correct usage of the module in the approved mode; all other statements indicate a security rule implemented by the module.

  1. The module clears previous authentications on power cycle.
  2. Power up self-tests do not require any operator action.
  3. Data output is inhibited during key generation, self-tests, zeroization, and error states.
  4. Status information does not contain CSPs or sensitive data that if misused could lead to a compromise of the module.
  5. There are no restrictions on which SSPs are zeroized by the zeroization service.
  6. The module does not support a maintenance interface or role.
  7. The module does not output intermediate key values.
  8. The module requires two independent internal actions to be performed prior to outputting plaintext CSPs.
  9. The cryptographic officer must invoke the zeroize command (as per Section 9.3) before using the firmware load service to install a new firmware image.
  10. The cryptographic officer must determine whether firmware being loaded is a legacy use of the firmware load service.
  11. The cryptographic officer must retain control of the module while zeroization is in process.
  12. IKE/IPsec and TLS features must not be enabled.
11.5 Maintenance Requirements

No special maintenance requirements and required.

11.6 End of Life

When disposing of the cryptographic module, the CO shall perform the zeroize command described in Section 9.3.

Page 41
12 Mitigation of Other Attacks

The module does not implement mechanisms to mitigate other attacks beyond what is described in this security policy.