All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Juniper Networks EX, QFX and ACX Series with MACsec

Certificate#5136StandardFIPS 140-3Level1TypeHardwareEmbodimentMulti-Chip Stand AloneStatusActiveVendorJuniper Networks
Low review priority  ·  no TCB surface named  ·  last validated 6 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeHardware
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date1/14/2031
CaveatWhen installed, initialized and configured as specified in Section 11.1 of the Security Policy. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs
VendorJuniper Networks

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Juniper Networks EX, QFX and ACX Series with MACsec
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Firmware load<br/>Recovery</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Unauthenticated</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>SSH<br/>HTTPS<br/>library named: openssl</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>kernel</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Juniper Networks EX, QFX and ACX Series with MACsec
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Firmware load<br/>Recovery</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth<br/>Unauthenticated</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>SSH<br/>HTTPS<br/>library named: openssl</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>kernel</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Juniper Networks Juniper Networks EX, QFX and ACX Series with MACsec Version: Junos OS 22.3R2-S1 Prepared for: Juniper Networks, Inc.

1133 Innovation Way
1.888 JUNIPER

www.juniper.net Prepared by: www.teronlabs.com

Page 2
Table of Contents
#SectionPage
Page 4
List of Tables
ItemPage
Table 1: Security Levels6
Table 2: Tested Module Identification – Hardware10
Table 3: Modes List and Description11
Table 4: Approved Algorithms - OpenSSL 1.0.212
Table 5: Approved Algorithms - MACsec12
Table 6: Approved Algorithms - MACsec PHY13
Table 7: Approved Algorithms - OpenSSL 1.1.113
Table 8: Approved Algorithms - Kernel13
Table 9: Approved Algorithms - LibMD13
Table 10: Vendor-Affirmed Algorithms14
Table 11: Security Function Implementations16
Table 12: Entropy Certificates17
Table 13: Entropy Sources17
Table 14: Ports and Interfaces19
Table 15: Authentication Methods19
Table 16: Roles19
Table 17: Approved Services23
Table 18: Mechanisms and Actions Required24
Table 19: Storage Areas25
Table 20: SSP Input-Output Methods25
Table 21: SSP Zeroization Methods25
Table 22: SSP Table 127
Table 23: SSP Table 230
Table 24: Pre-Operational Self-Tests30
Table 25: Conditional Self-Tests33
Table 26: Pre-Operational Periodic Information33
Table 27: Conditional Periodic Information35
Table 28: Error States35
Figure 1 – EX4400-24P Ethernet switch (front)7
Figure 2 –EX4400-24P Ethernet switch (rear)7
Figure 3 –EX4400-24T Ethernet switch (front)7
Figure 4 – EX4400-24T Ethernet switch (rear)8
Figure 5 – EX4400-48T Ethernet switch (front)8
Figure 6 – EX4400-48T Ethernet switch (rear)8
Figure 7 – EX4400-48P Ethernet switch (front)8
Figure 8 – EX4400-48P Ethernet switch (rear)8
Figure 9 – EX4400-48F Ethernet switch (front)8
Figure 10 – EX4400-48F Ethernet switch (rear)8
Figure 11 – EX4400-24MP Ethernet switch (front)9
Figure 12 – EX4400-24MP Ethernet switch (rear)9
Figure 13 – EX4400-48MP Ethernet switch (front)9
Figure 14 – EX4400-48MP Ethernet switch (rear)9
Page 6
SectionTitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication2
5Software/Firmware security1
6Operational environment1
7Physical security1
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacksN/A
Overall Level1
1.1 Overview

This is a non-proprietary Cryptographic Module Security Policy for the Juniper Networks EX, QFX and ACX series network devices running Junos OS 22.3R2-S1.

1.2 Security Levels

The cryptographic module is designed to meet FIPS 140-3 Level 1 overall. The table below shows the security levels claimed for each section of the security requirements. Table 1: Security Levels

2.1 Description

Purpose and Use: The following models are included in this validation and provide network switching and routing functionality:

Page 7

The cryptographic module runs Junos OS, Juniper’s reliable, high-performance, modular network operating system that is supported across all of Juniper’s physical and virtual routing, switching, and security platforms. The cryptographic module provides for an encrypted connection, using SSH, between the management station and the module. The cryptographic modules also provide for an encrypted connection, using MACsec, between devices. All other data input or output from the modules are considered plaintext for this FIPS 140-3 validation. Module Type: The cryptographic module is a Hardware cryptographic module. Module Embodiment: The cryptographic module is defined as a MultiChipStand module that executes Junos OS 22.3R2-S1 firmware on any of the identified Juniper Networks devices. Module Characteristics: There are no additional characteristics relevant to this module. Cryptographic Boundary: The cryptographic boundary encompasses the entire Tested Operational Environment Physical Perimeter (TOEPP), which is defined as the outer edge of the chassis. The chassis is a rigid sheetmetal structure that houses all components of the device. The cryptographic module is FIPS-compliant when installed and configured with Junos OS 22.3R2-S1 validated firmware as specified in section 11.1. The physical form of the module is depicted in Figure 1 to Figure 18. Figure 1 – EX4400-24P Ethernet switch (front) Figure 2 –EX4400-24P Ethernet switch (rear) Figure 3 –EX4400-24T Ethernet switch (front)

Page 8

Figure 4

Page 9

Figure 11

Page 10
Model and/or Part NumberHardware VersionFirmware VersionProcessorsFeatures
EX4400-48FEX4400-48FJUNOS 22.3R2-S1.9Intel Atom C3558R12 x 10GbE SFP+ ports; 36 x 1GbE SFP fiber access ports
QFX5120- 48YMQFX5120- 48YMJUNOS 22.3R2-S1.9Intel Xeon D- 162748 x 1/10/25GbE SFP/SFP+ ports; 8 x 40/100GbE QSFP+/QSFP28
ACX5400-MACX5400-MJUNOS 22.3R2-S1.9Intel Xeon D- 152844 x 1GbE/10GbE SFP+/SFP ports; 6 x 40GbE/100GbE QSFP28 ports.
EX4400-24TEX4400-24TJUNOS 22.3R2-S1.9Intel Atom C3558R24 x 1GbE non-PoE ports
EX4400-24PEX4400-24PJUNOS 22.3R2-S1.9Intel Atom C3558R24 x 1GbE PoE ports
EX4400-48TEX4400-48TJUNOS 22.3R2-S1.9Intel Atom C3558R48 x 1GbE non-PoE ports
EX4400-48PEX4400-48PJUNOS 22.3R2-S1.9Intel Atom C3558R48 x 1GbE PoE ports
EX4400- 24MPEX4400- 24MPJUNOS 22.3R2-S1.9Intel Atom C3558R24 x 100M/1/2.5/5/10GbE PoE ports
EX4400- 48MPEX4400- 48MPJUNOS 22.3R2-S1.9Intel Atom C3558R12 x 100M/1/2.5/5/10GbE and 36 x 100M/1/2.5GbE PoE access ports

Figure 18

2.2 Tested and Vendor Affirmed Module Version and Identification

Tested Module Identification

Page 11
Mode NameDescriptionTypeStatus Indicator
ApprovedApproved mode of operation.ApprovedSuffix string ":fips" in the cli prompt
AlgorithmCAVP CertPropertiesReference
AES-CBCA4210Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
AES-CTRA4210Direction - Decrypt, Encrypt Key Length - 128, 192, 256SP 800-38A
ECDSA KeyGen (FIPS186-4)A4210Curve - P-256, P-384, P-521 Secret Generation Mode - Testing CandidatesFIPS 186-4
ECDSA KeyGen (FIPS186-4)A6440Curve - P-256, P-384, P-521 Secret Generation Mode - Testing CandidatesFIPS 186-4
ECDSA KeyVer (FIPS186-4)A4210Curve - P-256, P-384, P-521FIPS 186-4
ECDSA KeyVer (FIPS186-4)A6440Curve - P-256, P-384, P-521FIPS 186-4
ECDSA SigGen (FIPS186-4)A4210Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512FIPS 186-4
ECDSA SigGen (FIPS186-4)A6440Component - No Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512FIPS 186-4
ECDSA SigVer (FIPS186-4)A4210Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512FIPS 186-4

Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid: N/A There are no vendor-affirmed operational environments claimed.

2.3 Excluded Components

No components are excluded from the requirements of FIPS PUB 140-3. The module supports an Approved mode only. The module enters Approved mode as a result of successful installation, initialization and configuration steps described in section 11. Until these procedures have been followed, the module is non-compliant. Table 3: Modes List and Description

2.5 Algorithms

Approved Algorithms: Although the module may have been tested for additional algorithms or modes, only those listed below are utilized by the module. OpenSSL 1.0.2

Page 12
AlgorithmCAVP CertPropertiesReference
ECDSA SigVer (FIPS186-4)A6440Component - No Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512FIPS 186-4
HMAC-SHA-1A4210Key Length - Key Length: 160FIPS 198-1
HMAC-SHA2-256A4210Key Length - Key Length: 256FIPS 198-1
HMAC-SHA2-512A4210Key Length - Key Length: 512FIPS 198-1
KAS-ECC-SSC Sp800- 56Ar3A4387Domain Parameter Generation Methods - P-256, P- 384, P-521 Scheme - ephemeralUnified - KAS Role - initiator, responderSP 800-56A Rev. 3
KDF SSH (CVL)A4347Cipher - AES-128, AES-192, AES-256 Hash Algorithm - SHA-1, SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
RSA KeyGen (FIPS186- 4)A4210Key Generation Mode - B.3.3 Modulo - 2048, 3072, 4096 Primality Tests - Table C.2 Private Key Format - StandardFIPS 186-4
RSA SigGen (FIPS186- 4)A4210Signature Type - PKCS 1.5 Modulo - 2048, 3072, 4096FIPS 186-4
RSA SigVer (FIPS186-4)A4210Signature Type - PKCS 1.5 Modulo - 2048, 3072, 4096FIPS 186-4
SHA-1A4210Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-256A4210Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-384A4210Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-512A4210Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
AlgorithmCAVP CertPropertiesReference
AES-CBCA4416Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38A
AES-CMACA4416Direction - Generation, Verification Key Length - 128, 256SP 800-38B
AES-KWA4416Direction - Decrypt, Encrypt Key Length - 128SP 800-38F
KDF SP800-108A4416KDF Mode - Counter Supported Lengths - Supported Lengths: 128, 256SP 800-108 Rev. 1
AlgorithmCAVP CertPropertiesReference
AES-GCMAES 3969Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38D
AES-GCMAES 4544Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38D
AES-GCMAES 4545Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38D

Table 4: Approved Algorithms - OpenSSL 1.0.2 MACsec Table 5: Approved Algorithms - MACsec MACsec PHY

Page 13
AlgorithmCAVP CertPropertiesReference
AES-GCMAES 4550Direction - Decrypt, Encrypt Key Length - 128, 256SP 800-38D
AES-GCMC1869Direction - Decrypt, Encrypt IV Generation - External Key Length - 128, 256SP 800-38D
AES-GCMC996Direction - Decrypt, Encrypt IV Generation - External Key Length - 128, 256SP 800-38D
AlgorithmCAVP CertPropertiesReference
ECDSA SigVer (FIPS186- 4)A4211Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-256, SHA2-384, SHA2- 512FIPS 186-4
ECDSA SigVer (FIPS186- 4)A6401Component - No Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-256, SHA2-384, SHA2- 512FIPS 186-4
SHA2-256A4211Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
AlgorithmCAVP CertPropertiesReference
HMAC DRBGA4417Prediction Resistance - Yes Mode - SHA2-256SP 800-90A Rev. 1
HMAC-SHA2- 256A4417Key Length - Key Length: 256FIPS 198-1
SHA2-256A4417Message Length - Message Length: 0-51200 Increment 8FIPS 180-4
SHA2-512A3330Message Length - Message Length: 0-51200 Increment 8FIPS 180-4
SHA2-512A3355Message Length - Message Length: 0-51200 Increment 8FIPS 180-4
SHA2-512A3498Message Length - Message Length: 0-51200 Increment 8FIPS 180-4
AlgorithmCAVP CertPropertiesReference
HMAC-SHA-1A4208Key Length - Key Length: 112, 160FIPS 198-1
HMAC-SHA2- 256A4208Key Length - Key Length: 160, 256FIPS 198-1
SHA-1A4208Message Length - Message Length: 0-51200 Increment 8FIPS 180-4
SHA2-256A4208Message Length - Message Length: 0-51200 Increment 8FIPS 180-4
SHA2-512A4208Message Length - Message Length: 0-65536 Increment 8FIPS 180-4

Table 6: Approved Algorithms - MACsec PHY OpenSSL 1.1.1 Table 7: Approved Algorithms - OpenSSL 1.1.1 Kernel Table 8: Approved Algorithms - Kernel LibMD Table 9: Approved Algorithms - LibMD

Page 14
NamePropertiesImplementationReference
CKGKey type:AsymmetricJunos 22.3R2-S1 - OpenSSL 1.0.2SP 800-133 Rev.2 Section 4, example 1 direct output from DRBG.
NameTypeDescriptionPropertiesAlgorithms
Enc/Dec (SSH)BC-UnAuthUnauthenticated encryption for SSHAES-CBC: (A4210) AES-CTR: (A4210)
KAS-SSC (SSH)KAS-SSCKey Agreement Scheme Shared Secret Computation for SSHKAS-ECC-SSC Sp800-56Ar3: (A4387)
KeyGen (SSH)AsymKeyPair- KeyGenKey Generation used for SSH authentication keysECDSA KeyGen (FIPS186-4): (A4210, A6440) ECDSA KeyVer (FIPS186-4): (A4210, A6440) RSA KeyGen (FIPS186-4): (A4210) HMAC DRBG: (A4417) CKG: ()
SigGen (SSH)DigSig-SigGenSignature Generation for peer authentication in SSHECDSA SigGen (FIPS186-4): (A4210, A6440) RSA SigGen (FIPS186-4): (A4210) SHA2-256: (A4210) SHA2-384: (A4210) SHA2-512: (A4210)

Vendor-Affirmed Algorithms: Table 10: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: N/A for this module. Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. Non-Approved, Not Allowed Algorithms: N/A for this module.

2.6 Security Function Implementations

The module implements the security functions listed in the following table.

Page 15
NameTypeDescriptionPropertiesAlgorithms
SigVer (SSH)DigSig-SigVerSignature Verification for peer authentication in SSHECDSA SigVer (FIPS186-4): (A4210, A6440) RSA SigVer (FIPS186-4): (A4210) SHA2-256: (A4210) SHA2-384: (A4210) SHA2-512: (A4210)
MAC (SSH)MACMessage authentication for SSHHMAC-SHA-1: (A4210) HMAC-SHA2-256: (A4210) HMAC-SHA2-512: (A4210) SHA-1: (A4210) SHA2-256: (A4210) SHA2-512: (A4210)
KAS KeyGen (SSH)KAS-KeyGenKey Generation for Key Agreement in SSHECDSA KeyGen (FIPS186-4): (A4210) ECDSA KeyVer (FIPS186-4): (A4210) CKG: () HMAC DRBG: (A4417)
KDF (SSH)KAS-135KDFKey derivation function for SSHKDF SSH: (A4347) SHA-1: (A4210) SHA2-256: (A4210) SHA2-384: (A4210) SHA2-512: (A4210)
Full KAS (SSH)KAS-FullFull Key Agreement for SSHECDSA KeyGen (FIPS186-4): (A4210, A6440) ECDSA KeyVer (FIPS186-4): (A4210, A6440) KAS-ECC-SSC Sp800-56Ar3: (A4387) SHA-1: (A4210) SHA2-256: (A4210) SHA2-384: (A4210) SHA2-512: (A4210) KDF SSH: (A4347)
KTS (SSH)KTS-WrapKey transport using SSH as per IG D.G provisionsKTS:128, 256, 384, 521, 2048, 3072, 4096 bit keys provide between 112 and 256 bits of encryption strengthAES-CBC: (A4210) AES-CTR: (A4210) HMAC-SHA-1: (A4210) HMAC-SHA2-256: (A4210) HMAC-SHA2-512: (A4210)
SHA (LibMD)SHAMessage Digest GenerationSHA-1: (A4208) SHA2-256: (A4208) SHA2-512: (A4208)
Page 16
NameTypeDescriptionPropertiesAlgorithms
MAC (LibMD)MACMessage AuthenticationHMAC-SHA-1: (A4208) HMAC-SHA2-256: (A4208) SHA-1: (A4208) SHA2-256: (A4208)
DRBG (Kernel)DRBGRandom Bit GenerationHMAC DRBG: (A4417) HMAC-SHA2-256: (A4417) SHA2-256: (A4417)
SHA (Kernel)SHAEntropy source conditioning componentSHA2-512: (A3355, A3498, A3330)
Verify imageDigSig-SigVerVerification of firmware imageECDSA SigVer (FIPS186-4): (A4211, A6401) SHA2-256: (A4211)
Key derivation (MACsec)KAS-56CKDFDerivation of MACsec MKA keysKDF SP800-108: (A4416) AES-CBC: (A4416) AES-CMAC: (A4416)
Key wrap (MACsec)KTS-WrapDistribution of MACsec SAKsKTS:128 and 256 bit keys provide between 128 and 256 bits of encryption strengthAES-KW: (A4416)
Enc/Dec (MACsec)BC-AuthEncryption and decryption of MACsec dataAES-GCM: (AES 3969, AES 4544, AES 4545, AES 4550, C1869, C996)
Integrity (MACsec)MACMACsec protocol data integrity protectionAES-CMAC: (A4416)
Entropy SourceENT-ESVEntropy sourceSHA2-512: (A3355, A3498, A3330)

Table 11: Security Function Implementations

2.7 Algorithm Specific Information

In reference to the MACsec protocol, the modules can take on the role of Peer or Authenticator. The AES GCM IV construction is performed in compliance with IG C.H scenario 1c (MACsec per IEEE 802.1AE and its amendments). The module includes ECDSA algorithms that have been validated using FIPS 186-4 CAVP tests, which are mathematically identical to FIPS 186-5 CAVP tests. Per IG C.K, all RSA and ECDSA algorithms implemented by the module are claimed compliant with FIPS 186-5. The module complies with IG C.F. RSA Key Generation, Signature Generation and Signature Verification have been tested and validated using CAVP testing for all implemented modulus lengths (2048, 3072 and 4096 bits). The number of Miller-Rabin tests used for primality testing as part of RSA Key Generation is consistent with Table C.3.

Page 17
Cert NumberVendor Name
E89Juniper Networks
NameTypeOperational EnvironmentSample SizeEntropy per SampleConditioning Component
EX4400 - Junos OS 22.3 Entropy Source (E89)Non- PhysicalIntel Atom C3558R512 bits448 bitsA3355 (SHA2- 512)
QFX5120-48YM - Junos OS 22.3 Entropy Source (E89)Non- PhysicalIntel Xeon D- 1627512 bits448 bitsA3498 (SHA2- 512)
ACX5448-M - Junos OS 22.3 Entropy Source (E89)Non- PhysicalIntel Xeon D- 1528512 bits448 bitsA3330 (SHA2- 512)

The module implements the following Approved key agreement methods which have been CAVP tested and validated: ⦁ KAS-ECC per SP 800-56A Rev. 3 (FIPS 140-3 IG D.F Scenario 2, path 2). The module obtains the FIPS 140-3 IG D.F required key agreement assurances in accordance with Section 5.6.2 of SP800-56A Rev. 3. All the key agreement protocols implemented by the module are Diffie-Hellman based.

2.8 RBG and Entropy

The tables below indicate the entropy source used by the module and their associated certificates. Table 12: Entropy Certificates Table 13: Entropy Sources The entropy source is used to seed the module’s HMAC DRBG with the minimum required 256bits of entropy. Each 512-bit block of conditioned output from the entropy source contains 448 bits of entropy. The HMAC DRBG is used for all random data required by the module, including key generation. There are no initialization procedures required by the users of the module to operate the entropy source in a compliant manner. The module complies with the ESV Public Use document of the

2.9 Key Generation

The cryptographic module implements the key generation methods listed above in the Security Functions implementation table.

2.10 Key Establishment
Page 18
ProtocolKey ExchangeAuthCipherIntegrity
SSHv2EC Diffie-Hellman P-256 EC Diffie-Hellman P-384 EC Diffie-Hellman P-521ECDSA P-256 ECDSA P-384 ECDSA P-521 RSA 2048 RSA 3072 RSA 4096AES CBC 128/192/256 AES CTR 128/192/256HMAC-SHA-1 HMAC-SHA2-256 HMAC-SHA2-512
MACsecMACsec Key Agreement (SP800-108 KDF, AES-CMAC-128/256, AES-KW 128/256)Shared secretAES-GCM-128 AES-GCM-256
Physical PortLogical Interface(s)Data That Passes
Ethernet (data)Data Input Data Output Control Input Status OutputLAN communications
Ethernet (mgmt.)Data Input Data Output Control Input Status OutputRemote management
SerialData Input Data Output Control Input Status OutputConsole serial port management
PowerPowerPower
Reset buttonControl InputReset
USBData Input Control InputFirmware load port

The cryptographic module implements the key establishment methods listed above in the Security Functions implementation table.

2.11 Industry Protocols

The cryptographic module supports the protocols listed below. No part of these protocols, other than the approved cryptographic algorithms and the KDFs, have been tested by the CAVP and CMVP. The SSH algorithms allow independent selection of key exchange, authentication, cipher, and integrity. In reference to the supported protocols table below, each column of options for a given protocol is independent and may be used in any viable combination.

3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

The following table maps each physical interface to one or more logical interface types defined in the FIPS 140-3 standard. The module does not have a Control Output Interface.

Page 19
Physical PortLogical Interface(s)Data That Passes
LEDStatus OutputStatus indicator lighting
SFP28 (EX4400 only)Data Input Data Output Control Input Status OutputVirtual chassis ports
Timing interface ports: PPS and 10M GPS (ACX5448 and QFX5120 models only)Control InputClock and timing signals from external devices
Method NameDescriptionSecurity MechanismStrength Each AttemptStrength per Minute
Password authenticationUser and CO authentication via SSH or consol. Minimum of 10 ASCII character passwords.SHA (LibMD)Probability of guessing: 1/(96^10) < 1/1,000,000.Timed access mechanism allows max of 10 attempts / min. Probability of guessing: 10/(96^10) < 1/100,000.
Signature authenticationUser/CO authentication via SSHSigVer (SSH)Strength of signature algorithm, minimum 112-bits. Probability of success for random attempt: 1/(2^112) < 1/1,000,000.A rate of 1 CPU cycle per failed authentication for the Intel Xeon D-1627 processor (4 cores, 2.9 GHz) allows for the probability of success by brute- force attack: 60 x 4 x 2.9 x 10^9 x 1/(2^112) < 1/100,000.
NameTypeOperator TypeAuthentication Methods
Crypto OfficerRoleCOPassword authentication Signature authentication
UserRoleMonitorPassword authentication Signature authentication

Table 14: Ports and Interfaces

4 Roles, Services, and Authentication

The module implements two forms of role-based authentication methods, as described in the following table. Table 15: Authentication Methods

4.2 Roles

Table 16: Roles The module supports two roles: Cryptographic Officer (CO) and User. The module supports rolebased operator authentication for assuming these roles, using methods specified in Section 4.1.

Page 20
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
Configure SecuritySecurity relevant configuration':fips' suffix in CLI promptCLI CommandStatusSHA (Kernel) Entropy Source KeyGen (SSH) SHA (LibMD) MAC (LibMD) DRBG (Kernel)Crypto Officer - HMAC DRBG V value: E - HMAC DRBG Key value: E - HMAC DRBG Entropy Input: E - HMAC DRBG Seed: E - User-PW: W - CO-PW: W - Root-PW: W - SSH PUB: G,R,W - SSH PHK: G,R,W - MACsec CAK: W - MACsec CKN: R,W
ConfigureNon-security relevant configurationNoneCLI CommandStatusNoneCrypto Officer
Secure TrafficMACsec encrypted transfer of data, distribution of keys':fips' suffix in CLI promptMACsec traffic framesMACsec traffic framesKey wrap (MACsec) Enc/Dec (MACsec) Integrity (MACsec)Crypto Officer - MACsec KEK: G,E - MACsec SAK: G,E - MACsec ICK: G,E
Show statusShow statusNoneNone':fips' suffix in CLI promptNoneCrypto Officer User
ZeroizeZeroize all CSPsNoneCLI commandNone (completion indicator is implicitly provided by the module rebooting)NoneCrypto Officer - HMAC DRBG V value: Z - HMAC DRBG Key value: Z - HMAC DRBG Entropy Input: Z - HMAC DRBG

The module supports concurrent operators but does not support a maintenance role and/or bypass capability. The module enforces the separation of roles using either of the role-based operator authentication methods in Section 4.1. The Cryptographic Officer role configures and monitors the module via a console or SSH connection. As root or super-user, the Cryptographic Officer has permission to view and edit secrets within the module. The User role monitors the module via the console or SSH. The user role cannot change the

4.3 Approved Services
Page 21
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access Seed: Z - SSH DH Shared Secret: Z - SSH PHK: Z - SSH PUB: Z - SSH DH PRV: Z - SSH DH PUB: Z - SSH DH Pub (peer): Z - SSH-SEKs: Z - CO-PW: Z - Root-PW: Z - User-PW: Z - Auth-CO Pub: Z - Auth-User Pub: Z - Root-CA: Z - Package-CA: Z - MACsec CAK: Z - MACsec CKN: Z - MACsec SAK: Z - MACsec KEK: Z - MACsec ICK: Z
SSH connectInitiate SSH connection for SSH monitoring and control (CLI)':fips' suffix in CLI promptSSH packetsSSH packets, StatusEnc/Dec (SSH) KAS-SSC (SSH) SigGen (SSH) SigVer (SSH) MAC (SSH) KAS KeyGen (SSH) KDF (SSH) Full KAS (SSH) KTS (SSH) SHA (Kernel) Entropy SourceCrypto Officer - HMAC DRBG V value: E - HMAC DRBG Key value: E - HMAC DRBG Entropy Input: E - HMAC DRBG Seed: E - SSH DH Shared Secret: G,E - SSH DH PRV: G,E - SSH DH PUB: G - SSH-SEKs: G,E - SSH DH Pub (peer): E - CO-PW: E User - HMAC DRBG V value: E - HMAC DRBG Key value: E - HMAC DRBG Entropy Input: E - HMAC DRBG Seed: E - SSH DH Shared Secret: G,E - SSH DH PRV: G,E - SSH DH PUB: G
Page 22
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access - SSH-SEKs: G,E - SSH DH Pub (peer): E - User-PW: E
MACsec connectInitiate MACsec connection':fips' suffix in CLI promptMACsec link configuration, CKN, CAKMACsec frames, StatusKey derivation (MACsec) Key wrap (MACsec) Enc/Dec (MACsec) Integrity (MACsec)Crypto Officer - MACsec ICK: E - MACsec SAK: E,W,R - MACsec KEK: E
Console accessConsole monitoring and control (CLI)NoneCLI CommandStatusNoneCrypto Officer - CO-PW: E - Root-PW: E User - User-PW: E
Remote resetSoftware initiated reset, performs self- tests on demand.NoneCLI commandStatusNoneCrypto Officer - HMAC DRBG V value: Z - HMAC DRBG Key value: Z - HMAC DRBG Entropy Input: Z - HMAC DRBG Seed: Z - SSH DH Shared Secret: Z - SSH DH PRV: Z - SSH DH PUB: Z - SSH-SEKs: Z - SSH DH Pub (peer): Z - MACsec SAK: Z - MACsec KEK: Z - MACsec ICK: Z
Local resetHardware reset or power cycleNoneMain power cycleStatusNoneUnauthenticated - HMAC DRBG V value: Z - HMAC DRBG Key value: Z - HMAC DRBG Entropy Input: Z - HMAC DRBG Seed: Z - SSH DH Shared Secret: Z - SSH DH PRV: Z - SSH DH PUB: Z - SSH-SEKs: Z - SSH DH Pub (peer): Z - MACsec SAK: Z - MACsec KEK: Z - MACsec ICK: Z
Page 23
NameDescriptionIndicatorInputsOutputsSecurity FunctionsSSP Access
TrafficTraffic requiring no cryptographic servicesNoneTraffic inTraffic outNoneUnauthenticated
Load ImageLoading of firmware image':fips' suffix in CLI promptCLI CommandStatusVerify imageCrypto Officer - Root-CA: E - Package-CA: Z
Perform self-testOn demand execution of all pre-operational and conditional algorithm self- testsNoneLocal or remote resetStatusNoneCrypto Officer User Unauthenticated
Show module versionShow system information identifying moduleNoneCLI commandStatusNoneCrypto Officer User
4.4 Non-Approved Services

The module does not offer any non-approved services. N/A for this module.

4.5 External Software/Firmware Loaded

The module includes a firmware load service that is used to install the Junos OS firmware image as part of installation of the module, as described in Section 11.1. The loaded firmware is a complete image replacement and constitutes an entirely new module and version of Junos OS which would require a separate FIPS 140-3 validation.

5.1 Integrity Techniques

The cryptographic module implements a firmware integrity self-test that uses ECDSA P-256 with SHA2-256 to ensure the integrity of all Junos OS firmware components. The self-test is automatically run on power-up. The firmware integrity test can be run on demand by the module’s operator by power cycling the

Page 24
MechanismInspection FrequencyInspection Guidance
Opaque metal enclosuren/an/a
Storage Area NameDescriptionPersistence Type
RAMRandom Access MemoryDynamic
FlashInternal flash memory storage driveStatic
6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Non-Modifiable The module consists of hardware containing a non-modifiable operational environment as per the FIPS 140-3 definitions. It includes a firmware load service to support necessary updates. The loaded firmware is a complete image replacement and constitutes an entirely new module and version of Junos OS which would require a separate FIPS 140-3 validation.

6.2 Configuration Settings and Restrictions

There are no security rules, settings, or restrictions to the configuration of the operational environment beyond the initialization instructions to set the module in Approved mode.

7 Physical Security
7.1 Mechanisms and Actions Required

The module’s physical embodiment meets Level 1 Physical Security requirements. The module is completely enclosed in a rectangular nickel or clear zinc coated, cold rolled steel, plated steel and brushed aluminum enclosure. There are no ventilation holes, gaps, slits, cracks, slots, or crevices that would allow for any sort of observation of any component contained within the cryptographic boundary. Table 18: Mechanisms and Actions Required

8 Non-Invasive Security

This section is not applicable, as there are currently no approved non-invasive mitigation techniques specified in ISO/IEC 19790:2012.

9 Sensitive Security Parameters Management
9.1 Storage Areas

The table below lists the areas within the module’s cryptographic boundary where SSPs can be stored.

Page 25
NameFromToFormat TypeDistribution TypeEntry TypeSFI or Algorithm
Manual CLI entryLocal CORAMPlaintextManualDirect
Entry via SSHRemote CORAMEncryptedAutomatedElectronicKTS (SSH)
Entry via consoleLocal CORAMPlaintextManualElectronic
Output via SSHRAMRemote COEncryptedAutomatedElectronicKTS (SSH)
Output via consoleRAMLocal COPlaintextManualElectronic
Entry as part of KASRemote peerRAMPlaintextAutomatedElectronicFull KAS (SSH)
Output as part of KASRAMRemote peerPlaintextAutomatedElectronicFull KAS (SSH)
Pre-loadedManufacturerFlashPlaintextManualDirect
MACsec Key Agreement InputRemote deviceRAMEncryptedAutomatedElectronicKey wrap (MACsec)
MACsec Key Agreement OutputRAMRemote deviceEncryptedAutomatedElectronicKey wrap (MACsec)
Zeroization MethodDescriptionRationaleOperator Initiation
Zeroize CLI commandThis command erases all data, including all configuration information, returning the module to its factory default state The system is then rebooted.This command erases all keys and CSPS from storage. The forced power cycle also zeroizes SSPs in volatile memory.Yes, CO via invocation of zeroize CLI command.
ResetZeroization of SSPs in RAM via invocation of local or remote reset service.RAM is volatile and all data is lost when power is taken off. Zeroization is practically instantaneous.Yes, both User and CO, via invocation of Local Reset or Remote Reset services.
Explicit zeroize functionZeroization of SSPs in memory when no longer needed.Use of explicit zeroization function destroys SSP information immediately by overwriting memory area with zeroes.No. The operator cannot directly initiate this method.

Table 19: Storage Areas Table 20: SSP Input-Output Methods The table below describes the SSP zeroization methods employed by the module. Table 21: SSP Zeroization Methods The completion of zeroization is indicated implicitly. If the zeroization is initiated using a zeroization has successfully completed. If the zeroization is initiated by power cycling the

Page 26
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
HMAC DRBG V valueA critical value of the internal state of DRBG256 - 256DRBG internal state - CSPDRBG (Kernel)DRBG (Kernel)
HMAC DRBG Key valueA critical value of the internal state of DRBG256 - 256DRB internal state - CSPDRBG (Kernel)DRBG (Kernel)
HMAC DRBG Entropy InputA critical value of the internal state of DRBG provided by entropy source256 - 256Entropy source output - CSPEntropy SourceDRBG (Kernel)
HMAC DRBG SeedSeed material used to seed or reseed the HMAC DRBG256 - 256DRBG internal state - CSPDRBG (Kernel)DRBG (Kernel)
SSH DH Shared SecretShared DH value computed from the ephemeral DH key- pairs as part of SSH and used to derive session keys.256, 384, 521 - 128, 192, 256DH shared value - CSPKAS-SSC (SSH)KDF (SSH)
SSH PHKSSH Private host key. 1st time SSH is configured, the keys are generated.2048, 256, 4096, 384, 521 - 112, 128, 152, 192, 256Asymmetric private key - CSPKeyGen (SSH)SigGen (SSH)
SSH PUBSSH Public Host Key2048, 256, 4096, 384, 521 - 112, 128, 152, 192, 256Asymmetric public key - PSPKeyGen (SSH)SigVer (SSH)
SSH DH PRVSSH KAS private key256, 384, 521 - 128, 192, 256Asymmetric private key - CSPKAS KeyGen (SSH)KAS-SSC (SSH) Full KAS (SSH)
SSH DH PUBSSH KAS public key256, 384, 521 - 128, 192, 256Asymmetric public key - PSPKAS KeyGen (SSH)
SSH DH Pub (peer)SSH KAS public key from peer256, 384, 521 - 128, 192, 256Asymmetric public key - PSPKAS-SSC (SSH) Full KAS (SSH)
SSH-SEKsSSH Session Encryption Keys128, 192, 256 - 128, 192, 256Symmetric key - CSPKDF (SSH) Full KAS (SSH)Enc/Dec (SSH) MAC (SSH)

module, then successful reboot of the module indicates that zeroization has completed successfully. In the case of zeroization initiated by session termination, SSPs are zeroized when the session terminates, and session termination is indicated in the log.

9.4 SSPs

All SSPs used by the module are described in this section.

Page 27
NameDescriptionSize - StrengthType - CategoryGenerated ByEstablished ByUsed By
CO-PWPassword used to authenticate the CO.Min 10 characters - n/aAuthentication password - CSPKTS (SSH)SHA (LibMD)
Root-PWPassword used by CO to authenticate as 'root'.Min 10 characters - n/aAuthentication password - CSPKTS (SSH)SHA (LibMD)
User-PWPassword used to authenticate UserMin 10 characters - n/aAuthentication password - CSPKTS (SSH)SHA (LibMD)
Auth-CO PubSSH CO Authentication Public Key2048, 4096, 256, 384, 521 - 112, 128, 152, 192, 256Asymmetric public key - PSPKTS (SSH)SigVer (SSH)
Auth- User PubSSH User Authentication Public Key2048, 4096, 256, 384, 521 - 112, 128, 152, 192, 256Asymmetric public key - PSPKTS (SSH)SigVer (SSH)
Root-CAX.509 Certificate used to verify the validity of the Juniper Package CA256, 384 - 128, 196Asymmetric public key - PSPVerify image
Package- CAX.509 Certificate used to verify the validity the Juniper Image at software load and also at runtime for integrity.256 - 128Asymmetric public key - PSPVerify image
MACsec CAKExternally generated pre-shared key entered when MACsec static connectivity association key (CAK) security mode is enabled.32 (hex) characters for 128-bit AES keys, 64 (hex) characters for 256-bit AES keys - 128, 256Symmetric key - CSP
MACsec CKNExternally generated pre-shared key used to identify the CAK (64 characters)64 characters - n/aIdentifier - PSP
MACsec SAKSecurity Association Key used to encrypt/decrypt traffic for a given session128, 256 - 128, 256Symmetric key - CSPKey derivation (MACsec)Key wrap (MACsec)Enc/Dec (MACsec)
MACsec KEKKey Encryption Key used to transmit SAK to other members of a MACsec connectivity association128, 256 - 128, 256Symmetric key - CSPKey derivation (MACsec)Key wrap (MACsec)
MACsec ICKIntegrity Check Key used to verify the integrity and authenticity of MPDUs.128, 256 - 128, 256Symmetric key - CSPKey derivation (MACsec)Integrity (MACsec)
Page 28
Name HMAC DRBG V value HMAC DRBG Key value HMAC DRBG Entropy Input HMAC DRBG Seed SSH DH Shared SecretInput - OutputStorage RAM:Plaintext RAM:Plaintext RAM:Plaintext RAM:Plaintext RAM:PlaintextStorage Duration Until updated by HMAC_DRBG_Update() Until updated by HMAC_DRBG_Update() Until HMAC_Instantiate_Update() or HMAC_DRBG_Reseed() complete Until HMAC_Instantiate_Update() or HMAC_DRBG_Reseed() complete Until SSH session terminationZeroization Zeroize CLI command Reset Zeroize CLI command Reset Zeroize CLI command Reset Zeroize CLI command Reset Zeroize CLI command Reset Explicit zeroize functionRelated SSPs
SSH PHKEntry via SSH Entry via console Output via SSH Output via consoleRAM:Plaintext Flash:PlaintextUntil SSH session termination (RAM)Zeroize CLI commandSSH PUB:Paired With
SSH PUBEntry via SSH Entry via console Output via SSH Output via consoleRAM:Plaintext Flash:PlaintextZeroize CLI commandSSH PHK:Paired With
SSH DH PRVRAM:PlaintextUntil SSH session terminationReset Explicit zeroize functionSSH DH PUB:Paired With
SSH DH PUBOutput as part of KASRAM:PlaintextUntil SSH session terminationReset Explicit zeroize functionSSH DH PRV:Paired With
SSH DH Pub (peer)Entry as part of KASRAM:PlaintextUntil SSH session terminationReset Explicit zeroize function
SSH-SEKsRAM:PlaintextUntil SSH session terminationReset Explicit zeroize function
Page 29
NameInput - OutputStorageStorage DurationZeroizationRelated SSPs
CO-PWManual CLI entry Entry via SSH Entry via consoleRAM:Plaintext Flash:PlaintextZeroize CLI command
Root-PWManual CLI entry Entry via SSH Entry via consoleRAM:Plaintext Flash:PlaintextZeroize CLI command
User-PWManual CLI entry Entry via SSH Entry via consoleRAM:Plaintext Flash:PlaintextZeroize CLI command
Auth-CO PubEntry via SSH Entry via console Output via SSH Output via consoleRAM:Plaintext Flash:PlaintextZeroize CLI command
Auth-User PubEntry via SSH Entry via console Output via SSH Output via consoleRAM:Plaintext Flash:PlaintextZeroize CLI command
Root-CAPre-loadedRAM:Plaintext Flash:PlaintextZeroize CLI command
Package- CAPre-loadedRAM:Plaintext Flash:PlaintextZeroize CLI command
MACsec CAKEntry via SSH Entry via consoleRAM:Plaintext Flash:ObfuscatedZeroize CLI command
MACsec CKNEntry via SSH Entry via consoleRAM:Plaintext Flash:ObfuscatedZeroize CLI command
MACsec SAKMACsec Key Agreement Input MACsec Key Agreement OutputRAM:PlaintextZeroize CLI command Reset
MACsec KEKRAM:PlaintextZeroize CLI command Reset
Page 30

Name MACsec ICK

Input - Output

Storage RAM:Plaintext

Storage Duration

Zeroization Zeroize CLI command Reset

Related SSPs

Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
Firmware integrity checkECDSA P- 256 with SHA2-256KATSW/FW IntegrityPASS/FAIL console outputECDSA verify
Critical functions testSHA2-256KATCritical FunctionPASS/FAIL console outputChecks that any file that is executed is registered in a manifest of executable files that comes with the firmware. Test verifies the integrity of the operational environment is being enforced by having the kernel attempt to run a specific executable file that does not contain a hash in the manifest file, verifying it cannot be executed.
Algorithm or TestTest Properti esTest Metho dTest TypeIndicatorDetailsConditio ns
Entropy Source (start-up)n/aAPT, RCTCASTPASS/FAIL console outputStart-upOn- power up
9.5 Transitions

The following transitions apply to algorithms used by this module: SHA-1: The SHA-1 hash algorithm will be non-Approved for cryptographic protection purposes after December 31, 2030.

10 Self-Tests

On power up or reset, the module performs the pre-operational self-tests and the indicated conditional cryptographic algorithm self-tests described below. All KATs must be completed successfully prior to any other use of cryptography by the module. The CASTs for algorithms utilized in the pre-operational Firmware integrity check are performed prior to the Firmware

10.1 Pre-Operational Self-Tests

Table 24: Pre-Operational Self-Tests

10.2 Conditional Self-Tests
Page 31
Algorithm or TestTest Properti esTest Metho dTest TypeIndicatorDetailsConditio ns
Entropy Source (continuous)n/aAPT, RCTCASTConsole output / output of entropy sourceContinuo usData output from noise source
AES-CBC (A4210) EncryptKey size: 128, 192, 256KATCASTPASS/FAIL console outputEncryptOn power- up
AES-CBC (A4210) DecryptKey size: 128, 192, 256KATCASTPASS/FAIL console outputDecryptOn power- up
HMAC-SHA-1 (A4210)Key size: 160KATCASTPASS/FAIL console outputMACOn power- up
HMAC-SHA2-256 (A4210)Key size: 256KATCASTPASS/FAIL console outputMACOn power- up
HMAC-SHA2-384 (A4210)Key size: 384KATCASTPASS/FAIL console outputMACOn power- up
HMAC-SHA2-512 (A4210)Key size: 512KATCASTPASS/FAIL console outputMACOn power- up
RSA SigGen (FIPS186-4) (A4210)RSA 2048 w/ SHA2- 256, RSA 4096 w/ SHA2- 256KATCASTPASS/FAIL console outputSignOn power- up
RSA SigVer (FIPS186-4) (A4210)RSA 2048 w/ SHA2- 256, RSA 4096 w/ SHA2- 256KATCASTPASS/FAIL console outputVerifyOn power- up
ECDSA SigGen (FIPS186-4) (A4210)P-256, P-384, P-521KATCASTPASS/FAIL console outputSignOn power- up
ECDSA SigGen (FIPS186-4) (A6440)P-256, P-384, P-521KATCASTPASS/FAIL console outputSignOn power- up
ECDSA SigVer (FIPS186-4) (A4210)P-256, P-384, P-521KATCASTPASS/FAIL console outputVerifyOn power- up
ECDSA SigVer (FIPS186-4) (A6440)P-256, P-384, P-521KATCASTPASS/FAIL console outputVerifyOn power- up
KAS-ECC-SSC Sp800-56Ar3 (A4387)P-256, P-384, P-521KATCASTPASS/FAIL console outputECDH Computat ionOn power- up
Page 32
Algorithm or TestTest Properti esTest Metho dTest TypeIndicatorDetailsConditio ns
KDF SSH (A4347)SHA-1, SHA2- 256, SHA2- 384KATCASTPASS/FAIL console outputKey derivation Computat ionOn power- up
RSA KeyGen (FIPS186-4) (A4210)n/aPCTPCTReturned key/transit ion soft error stateGeneratio n and Verificatio n of signatureOn key generatio n
ECDSA KeyGen (FIPS186-4) (A4210)n/aPCTPCTReturned key/transit ion soft error stateGeneratio n and Verificatio n of signatureOn key generatio n
ECDSA KeyGen (FIPS186-4) (A6440)n/aPCTPCTReturned key/transit ion soft error stateGeneratio n and Verificatio n of signatureOn key generatio n
ECDSA SigVer (FIPS186-4) (A4211)P-256KATCASTPASS/FAIL console outputVerifyOn power- up
FW LoadECDSA P-256 with SHA2- 256KATSW/F W LoadPASS/FAIL console outputVerificatio n of ECDSA signature on FWOn FW load
HMAC DRBG (A4417)256, SHA2- 256KATCASTPASS/FAIL console outputInstantiat e, re-seed, and generateOn power- up
HMAC-SHA-1 (A4417)Key size: 160KATCASTPASS/FAIL console outputMACOn power- up
HMAC-SHA2-256 (A4417)Key size: 256KATCASTPASS/FAIL console outputMACOn power- up
SHA2-384 (A4417)n/aKATCASTPASS/FAIL console outputHashOn power- up
SHA2-512 (A3355)n/aKATCASTPASS/FAIL console outputHashOn power- up
HMAC-SHA2-256 (A4208)Key size: 256KATCASTPASS/FAIL console outputMACOn power- up
HMAC-SHA-1 (A4208)Key size: 256KATCASTPASS/FAIL console outputMACOn power- up
SHA2-512 (A4208)n/aKATCASTPASS/FAIL console outputHashOn power- up
Page 33
Algorithm or TestTest Properti esTest Metho dTest TypeIndicatorDetailsConditio ns
KDF SP800-108 (A4416)Key size: 128KATCASTPASS/FAIL console outputDeriveOn power- up
AES-KW (A4416) WrapKey size: 128, 192, 256KATCASTPASS/FAIL console outputWrapOn power- up
AES-KW (A4416) UnwrapKey size: 128, 192, 256KATCASTPASS/FAIL console outputUnwrapOn power- up
AES-CMAC (A4416)Key size: 128, 256KATCASTPASS/FAIL console outputMACOn power- up
AES-GCM Encrypt (AES3969/AES4544/AES4545/AES4550/C 1869/C996)128,256KATCASTInternal status: power-up continues or errorsEncryptOn power- up
AES-GCM Decrypt (AES3969/AES4544/AES4545/AES4550/C 1869/C996)128,256KATCASTInternal status: power-up continues or errorsDecryptOn power- up
ECDSA SigVer (FIPS186-4) (A6401)P-256KATCASTPASS/FAIL console outputVerifyOn power- up
SHA2-512 (A3498)n/aKATCASTPASS/FAIL console outputhashOn power- up
SHA2-512 (A3330)n/aKATCASTPASS/FAIL console outputhashOn power- up
Manual SSP entryn/aDuplica te entryManu al EntryPASS/FAIL console outputDuplicate entryOn manual, direct entry of SSP
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
Firmware integrity checkKATSW/FW IntegrityOn demandManually
Critical functions testKATCritical FunctionOn demandManually

Table 25: Conditional Self-Tests

10.3 Periodic Self-Test Information

The module does not implement periodic self-testing. Table 26: Pre-Operational Periodic Information

Page 34
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
Entropy Source (start-up)APT, RCTCASTOn demandManually
Entropy Source (continuous)APT, RCTCASTContinuousAutomatically
AES-CBC (A4210) EncryptKATCASTOn DemandManually
AES-CBC (A4210) DecryptKATCASTOn DemandManually
HMAC-SHA-1 (A4210)KATCASTOn DemandManually
HMAC-SHA2-256 (A4210)KATCASTOn DemandManually
HMAC-SHA2-384 (A4210)KATCASTOn DemandManually
HMAC-SHA2-512 (A4210)KATCASTOn DemandManually
RSA SigGen (FIPS186-4) (A4210)KATCASTOn DemandManually
RSA SigVer (FIPS186-4) (A4210)KATCASTOn DemandManually
ECDSA SigGen (FIPS186-4) (A4210)KATCASTOn DemandManually
ECDSA SigGen (FIPS186-4) (A6440)KATCASTOn DemandManually
ECDSA SigVer (FIPS186-4) (A4210)KATCASTOn DemandManually
ECDSA SigVer (FIPS186-4) (A6440)KATCASTOn DemandManually
KAS-ECC-SSC Sp800-56Ar3 (A4387)KATCASTOn DemandManually
KDF SSH (A4347)KATCASTOn DemandManually
RSA KeyGen (FIPS186-4) (A4210)PCTPCTOn trigger conditionAutomatic
ECDSA KeyGen (FIPS186-4) (A4210)PCTPCTOn trigger conditionAutomatic
ECDSA KeyGen (FIPS186-4) (A6440)PCTPCTOn trigger conditionAutomatic
ECDSA SigVer (FIPS186-4) (A4211)KATCASTOn DemandManually
FW LoadKATSW/FW LoadOn FW load requestAutomatic
HMAC DRBG (A4417)KATCASTOn DemandManually
HMAC-SHA-1 (A4417)KATCASTOn DemandManually
HMAC-SHA2-256 (A4417)KATCASTOn DemandManually
SHA2-384 (A4417)KATCASTOn DemandManually
Page 35
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
SHA2-512 (A3355)KATCASTOn DemandManually
HMAC-SHA2-256 (A4208)KATCASTOn DemandManually
HMAC-SHA-1 (A4208)KATCASTOn DemandManually
SHA2-512 (A4208)KATCASTOn DemandManually
KDF SP800-108 (A4416)KATCASTOn DemandManually
AES-KW (A4416) WrapKATCASTOn DemandManually
AES-KW (A4416) UnwrapKATCASTOn DemandManually
AES-CMAC (A4416)KATCASTOn DemandManually
AES-GCM Encrypt (AES3969/AES4544/AES4545/AES4550/C1869/C996)KATCASTOn DemandManually
AES-GCM Decrypt (AES3969/AES4544/AES4545/AES4550/C1869/C996)KATCASTOn DemandManually
ECDSA SigVer (FIPS186-4) (A6401)KATCASTOn demandManually
SHA2-512 (A3498)KATCASTOn demandManually
SHA2-512 (A3330)KATCASTOn demandManually
Manual SSP entryDuplicate entryManual EntryOn condition triggerAutomatic
NameDescriptionConditionsRecovery MethodIndicator
Critical Failure StateThe cryptographic module ceases to perform cryptographic operations, inhibits all data output, and provides status of the error via syslog messages and console status outputOn any power-up self-test errorPower cycleConsole status indicator
Soft Error StateA non-critical self-test failure occurs, causing a failure of the triggering operationPCT, firmware load test, continuous entropy health test failureThe module processes the error, and resumes normal operationConsole displays error

Table 27: Conditional Periodic Information

10.4 Error States
Page 36

user@host> request system software add <package>

user@host> request system reboot

The module enters error state upon failure of any self-tests, causing the kernel to ‘panic‘ and all execution to halt. The only way to exit from this state is to reboot the module, which causes the self-tests to be repeated and pass successfully before the corresponding algorithms are usable.

10.5 Operator Initiation of Self-Tests

Self–tests that are performed at power-up are available on demand by power cycling the module.

11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

The module must be correctly installed and configured to enter a FIPS compliant state and operate in the Approved mode. The required procedures are as follows:

  1. Install the Junos OS firmware image - the procedure is detailed in section 11.2.1
  2. Configure device for the Approved mode - the procedure is section 11.2.2. To continue using the module in a FIPS compliant way, the Module Operation Rules in section
11.4.2 must be followed.
11.2 Administrator Guidance
11.2.1 Installing the Junos OS firmware image
  1. Download the validated firmware image from https://www.juniper.net/support/downloads/junos.html. Log in to the Juniper Networks authentication system using the username (generally your e-mail address) and password supplied by Juniper Networks representatives. Select the validated firmware image. Download the firmware image to a local host or to an internal software distribution site. The cryptographic module devices use the following firmware images EX4400 jinstall-host-ex-4e-x86-64-22.3R2-S1.7-secure-signed.tgz QFX5120 jinstall-host9-qfx-5e-ng-x86-64-22.3R2-S1.7-secure-signed.tgz ACX5448 junos-vmhost-install-acx-x86-64-22.3R2-S1.7.tgz
  2. Connect to the console port on the device from your management device, and log in to the Junos OS CLI.
  3. Install the new package on the device (package may be a local file copied to the device, or a file on a remote server):
  4. Reboot the device to load the installation:
  5. After the reboot has completed, log in and use the show version command to verify that the new version of the software is successfully installed.
Page 37

user@host> show version

root@host# request system zeroize

root@host# set system root-authentication plain-text-password

crypto-officer@host# set system fips chassis level 1

crypto-officer@host# set system fips level 1

crypto-officer@host# commit

crypto-officer@host# run request system reboot

crypto-officer@host# request system zeroize

warning: System will be rebooted and may not boot without configuration

Erase all data, including configuration and log files? [yes, no] (no)

Erase all data, including configuration and log files? [yes, no] (no)

yes

11.2.2 Configure the device for the Approved mode

To configure the device for the Approved mode:

  1. Zeroize the device to delete all CSPs before entering the Approved mode.
  2. After the device comes up, login using username “root” and password blank.
  3. Configure root authentication with password at least 10 characters or more.
  4. Load configuration onto device and commit new configuration. NOTE: SSH key-exchange configuration must not include ‘dh-group14-sha1’. It is not approved for this module.
  5. Configure crypto-officer and login with crypto-officer credentials.
11.2.3 Zeroizing the System

CAUTION: Perform system zeroization with care. After the zeroization process is complete, no data is left on the device. The device is returned to the factory default state, equivalent to a fresh installation of the firmware, without any configured users or configuration files. After zeroizing the system, the module is no longer in a FIPS compliant state. (Installation and configuration as per section 11.1 is required to enter the FIPS compliant state and enable the Approved mode of operation). NOTE: The Crypto-Officer must retain control of the module while zeroization is in progress. To zeroize the device:

  1. Login to the device as Crypto Officer and from CLI, enter
  2. To initiate the zeroization process, type yes at the prompt:
Page 38
11.3 Non-Administrator Guidance

No specific non-administrator guidance is required to operate the module.

11.4 Design and Rules
11.4.1 Module Design Rules

The module design implements the following security rules:

  1. The module clears previous authentications on power cycle.
  2. Power up self-tests do not require any operator action.
  3. Data output is inhibited during key generation, self-tests, zeroization, and error states.
  4. Status information does not contain CSPs or sensitive data that if misused could lead to a compromise of the module.
  5. There are no restrictions on which SSPs are zeroized by the zeroization service.
  6. The module does not support a maintenance interface or role.
  7. The module does not output intermediate key values.
  8. The module requires two independent internal actions to be performed prior to outputting plaintext CSPs.
  9. If the module loses power and then it is restored, then a new key shall be established for use with the AES GCM encryption/decryption processes.
11.4.2 Module Operation Rules

The following are requirements for compliant usage of the module:

  1. The cryptographic officer must retain control of the module while zeroization is in process.
  2. The cryptographic officer shall verify that the firmware image to be loaded on the module is a FIPS validated image.
  3. Before pushing the factory reset button on the device, the cryptographic officer shall perform the zeroize command as described in section 11.2.3.
  4. The password minimum-length must be configured to be at least 10.
  5. Virtual Chassis features must not be configured.
  6. Dynamic CAK mode shall not be configured for MACsec.
  7. Only the AES-GCM cipher suites shall be configured for MACsec.
  8. The module shall only be used with CMVP-validated modules when supporting the MACsec protocol for providing Peer, Authenticator functionality.
  9. The link between the Peer and Authenticator, used in the MACsec communication, shall be secure to prevent the possibility for an attacker to introduce foreign equipment into the local area network.
  10. The module shall not be configured to use a radius server and the radius server capability shall be disabled.
  11. SSH key-exchange must not be configured to include ‘dh-group14-sha1’.
11.5 Maintenance Requirements

No special maintenance requirements are required.

Page 39
11.6 End of Life

When disposing of the cryptographic module, the cryptographic officer shall perform the zeroize command as described in Section 11.2.3.

12 Mitigation of Other Attacks

The module does not implement mechanisms to mitigate other attacks beyond what is described in this security policy.