All modules
CMVP Validated Module · FIPS 140-3 Security Policy

Cisco Firepower Threat Defense Virtual Cryptographic Module

Certificate#5137StandardFIPS 140-3Level1TypeFirmware-hybridEmbodimentMulti-Chip Stand AloneStatusActiveVendorCisco Systems, Inc
High review priority  ·  no TCB surface named  ·  last validated 6 months ago. How this is derived →

Certificate

StandardFIPS 140-3
Overall level1
Module typeFirmware-hybrid
EmbodimentMulti-Chip Stand Alone
StatusActive
Sunset date1/14/2031
CaveatWhen installed, initialized and configured as specified in Section Life-Cycle Assurance of the Security Policy
VendorCisco Systems, Inc

Derived Review-Risk Graph (review prompts, not findings)

flowchart LR
  %% Deterministic review-risk graph for Cisco Firepower Threat Defense Virtual Cryptographic Module
  %% Review prompts and evidence gaps, NOT vulnerability findings.
  subgraph CMVP["CMVP-disclosed clues"]
    C2["[low] Firmware update / recovery<br/>/ rollback (referenced in<br/>text)<br/><i>Recovery</i>"]
    C3["[low] Self-test / status surface<br/>(referenced in text)<br/><i>Self-Test<br/>UnAuth</i>"]
    C5["[low] Protocol / secure-channel<br/>references (may be KDF<br/>names, not a live channel)<br/><i>TLS<br/>SSH<br/>IKEV</i>"]
    C6["[low] Operating system / runtime<br/>referenced (boundary<br/>membership not asserted)<br/><i>operating system<br/>linux<br/>application</i>"]
  end
  subgraph Inference["Derived inference"]
    I2["Possible only, trusted<br/>code is reachable through<br/>update and recovery paths."]
    I3["Possible only, some<br/>services may process input<br/>before, or without,<br/>operator authentication."]
    I5["Possible only, a protocol<br/>is referenced, but whether<br/>it is a live channel or<br/>only a KDF/algorithm name<br/>is unconfirmed."]
    I6["Possible only, a<br/>runtime/OS is referenced,<br/>but its membership in the<br/>cryptographic boundary is<br/>not established."]
  end
  subgraph Risk["Reviewer question"]
    R2["Are update images<br/>authenticated before<br/>parsing, and are<br/>downgrade/rollback paths<br/>constrained?"]
    R3["Can unauthenticated<br/>services leak state,<br/>consume resources, or<br/>transition security state?"]
    R5["If a live TLS/SSH/IKE<br/>channel exists, could<br/>library CVEs apply, or is<br/>this only a<br/>KDF/documentation name?"]
    R6["If the OS/runtime is<br/>in-boundary, could its<br/>CVEs be hidden by<br/>firmware-only versioning?"]
  end
  subgraph Evidence["Evidence needed to close"]
    E2["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>update image format ·<br/>signature-before-parse<br/>proof · anti-rollback /<br/>downgrade policy"]
    E3["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>pre-auth reachability<br/>matrix · rate limits and<br/>output redaction ·<br/>abuse-case tests"]
    E5["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>library identity and<br/>version ·<br/>certificate-validation<br/>behaviour · protocol-CVE<br/>disposition"]
    E6["confirm the disclosure<br/>itself (keyword hit,<br/>context unverified) ·<br/>runtime identity and<br/>config · kernel/runtime<br/>hardening profile ·<br/>patch/backport manifest"]
  end
  C2 --> I2 --> R2 --> E2
  C3 --> I3 --> R3 --> E3
  C5 --> I5 --> R5 --> E5
  C6 --> I6 --> R6 --> E6
  classDef clue fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef infer fill:#fff7e6,stroke:#b98500,color:#6b4e00;
  classDef risk fill:#fbe9e9,stroke:#b02a2a,color:#7a1f1f;
  classDef evidence fill:#e6f4ea,stroke:#1e7d34,color:#14532d;
  class C2,C3,C5,C6 clue;
  class I2,I3,I5,I6 infer;
  class R2,R3,R5,R6 risk;
  class E2,E3,E5,E6 evidence;
Underlying clues
flowchart LR
  %% Deterministic clue tier for Cisco Firepower Threat Defense Virtual Cryptographic Module
  %% confidence: high = structured record field; medium = structured but soft; low (dashed) = bare keyword hit, context unverified
  subgraph CMVP["CMVP-disclosed clues (deterministic)"]
    C2["[low] Firmware update / recovery / rollback (referenced in text)<br/><i>Recovery</i><br/>src: text:keyword"]
    C3["[low] Self-test / status surface (referenced in text)<br/><i>Self-Test<br/>UnAuth</i><br/>src: text:keyword"]
    C5["[low] Protocol / secure-channel references (may be KDF names, not a live channel)<br/><i>TLS<br/>SSH<br/>IKEV</i><br/>src: text:keyword"]
    C6["[low] Operating system / runtime referenced (boundary membership not asserted)<br/><i>operating system<br/>linux<br/>application</i><br/>src: text:keyword"]
  end
  classDef clueHigh fill:#eef3f9,stroke:#2f6fb0,stroke-width:2px,color:#1f3a5f;
  classDef clueMedium fill:#eef3f9,stroke:#6f7f91,color:#1f3a5f;
  classDef clueLow fill:#f7f7f7,stroke:#999,stroke-dasharray:4 4,color:#444;
  class C2,C3,C5,C6 clueLow;

Security Policy, page by page

Page 1

Cisco Systems, Inc Cisco Firepower Threat Defense Virtual Cryptographic Module Americas Headquarters: Cisco Systems, Inc., 170 West Tasman Drive, San Jose, CA 95134-1706 USA © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 2
Table of Contents
#SectionPage
Page 3

© 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 4
List of Tables
ItemPage
Table 1: Security Levels5
Table 2: Tested Module Identification – Software, Firmware, Hybrid (Executable Code Sets)7
Table 3: Tested Module Identification – Hybrid Disjoint Hardware7
Table 4: Tested Operational Environments - Software, Firmware, Hybrid7
Table 5: Vendor-Affirmed Operational Environments - Software, Firmware, Hybrid7
Table 6: Modes List and Description8
Table 7: Approved Algorithms9
Table 8: Vendor-Affirmed Algorithms9
Table 9: Security Function Implementations16
Table 10: Entropy Certificates17
Table 11: Entropy Sources17
Table 12: Ports and Interfaces19
Table 13: Roles19
Table 14: Approved Services32
Table 15: Storage Areas34
Table 16: SSP Input-Output Methods34
Table 17: SSP Zeroization Methods35
Table 18: SSP Table 142
Table 19: SSP Table 250
Table 20: Pre-Operational Self-Tests51
Table 21: Conditional Self-Tests55
Table 22: Pre-Operational Periodic Information55
Table 23: Conditional Periodic Information56
Table 24: Error States56
Figure 1 Block Diagram6
Page 5
SectionTitleSecurity Level
1General1
2Cryptographic module specification1
3Cryptographic module interfaces1
4Roles, services, and authentication1
5Software/Firmware security1
6Operational environment1
7Physical security1
8Non-invasive securityN/A
9Sensitive security parameter management1
10Self-tests1
11Life-cycle assurance1
12Mitigation of other attacksN/A
Overall Level1
1.1 Overview

Defense Virtual Cryptographic Module (hereinafter referred to as FTDv or the Module), firmware version 7.4.2 The following details how this module meets the security requirements of FIPS 140-3, SP 800-140 and ISO/IEC 19790 for a Security Level 1 firmware hybrid cryptographic The security requirements cover areas related to the design and implementation of a cryptographic module. These areas include cryptographic module specification; cryptographic indicates the actual security levels for each area of the cryptographic module.

1.2 Security Levels
2.1 Description

Purpose and Use: This module is a multi-chip standalone firmware hybrid cryptographic module deployed as the virtualized version of the Cisco Firepower Threat Defense (FTD) which houses ASA and Firepower solutions with underlying operating system identified as Linux 4 (also referred to as Firepower eXtensible Operating System or FX-OS throughout this document). The Module’s FTD delivers enterprise-class firewall for businesses, improving security at the Internet edge, high performance and throughput for demanding enterprise data centers. This solution offers the combination of the industry's most deployed stateful firewall with a comprehensive range of © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 6

next-generation network security services, intrusion prevention system (IPS), content security and secure unified communications, SSHv2, HTTPS/TLSv1.2, IPsec/IKEv2, SNMPv3 and Cryptographic Cipher Suite B. Module Type: Firmware-hybrid Module Embodiment: MultiChipStand Module Characteristics: Cryptographic Boundary: The cryptographic module (red dash box) is a non-modifiable, multi-chip standalone firmware hybrid cryptographic module providing cryptographic support which takes data in and out from the host application via the API. The block diagram below shows the boundary of the Tested Operational Environment’s Physical Perimeter (TOEPP) being defined as the physical perimeter of the tested platform enclosure around which everything runs. The cryptographic boundary is the module (red dash box) and its interfaces with the operational environment. Processor API Host Platform Hypervisor API FTD FOM API Figure 1 Block Diagram The Block Diagram above comprises the following components

2.2 Tested and Vendor Affirmed Module Version and Identification

© 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 7
Package or File NameSoftware/ Firmware VersionFeaturesIntegrity Test
Cisco_Firepower_Threat_Defense_Virtual- 7.4.2.vmdk7.4.2RSA 2048 SigVer with SHA2-512
Model and/or Part NumberHardware VersionFirmware VersionProcessorsFeatures
UCS C220 M5S SFF Server1.0VMware ESXi 7.0Intel Xeon Platinum 8160 (Skylake)
Operating SystemHardware PlatformProcessorsPAA/PAIHypervisor or Host OSVersion(s)
Linux 4 (FX- OS)UCS C220 M5S SFF ServerIntel Xeon Platinum 8160 (Skylake)YesVMware ESXi 7.07.4.2
Operating SystemHardware Platform
Linux 4 (FX-OS)UCS C220 M6 SFF Server w/ESXi 7.0
Linux 4 (FX-OS)UCS C220 M7 SFF Server w/ESXi 7.0
Linux 4 (FX-OS)UCS C225 M6 SFF Server w/ESXi 7.0
Linux 4 (FX-OS)UCS C240 M5 SFF Server w/ESXi 7.0
Linux 4 (FX-OS)UCS C240 M6 SFF Server w/ESXi 7.0
Linux 4 (FX-OS)UCS C480 M5 SFF Server w/ESXi 7.0
Linux 4 (FX-OS)UCS-E1100D M6 SFF Server w/ESXi 7.0

Tested Module Identification

2.3 Excluded Components

N/A for this module. © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 8
Mode NameDescriptionTypeStatus Indicator
ApprovedThe module is always in the approved mode of operation after initial operations are performed.ApprovedApproved mode indicator: "FIPS is currently enabled."
AlgorithmCAVP CertPropertiesReference
AES-CBCA4595Key Length - 128, 256SP 800-38A
AES-GCMA4595Key Length - 128, 256SP 800-38D
Counter DRBGA4595Prediction Resistance - Yes Mode - AES-256 Derivation Function Enabled - YesSP 800-90A Rev. 1
ECDSA KeyGen (FIPS186-4)A4595Curve - P-256, P-384, P-521FIPS 186-4
ECDSA SigGen (FIPS186-4)A4595Curve - P-256, P-384, P-521FIPS 186-4
ECDSA SigVer (FIPS186-4)A4595Curve - P-256, P-384, P-521 Hash Algorithm - SHA2-256, SHA2-384, SHA2-512FIPS 186-4
HMAC-SHA-1A4595Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2-224A4595Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2-256A4595Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2-384A4595Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
HMAC-SHA2-512A4595Key Length - Key Length: 8-524288 Increment 8FIPS 198-1
KAS-ECC-SSC Sp800-56Ar3A4595Domain Parameter Generation Methods - P- 256, P-384, P-521SP 800-56A Rev. 3

Modes List and Description: Table 6: Modes List and Description The module has one Approved mode of operation and does not implement a Non-Approved following the steps in section 11 of this document, the module will only operate in the Approved mode of operation. The module doesn’t claim the implementation of a degraded mode

2.5 Algorithms

Approved Algorithms: © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 9
AlgorithmCAVP CertPropertiesReference
KAS-FFC-SSC Sp800-56Ar3A4595Domain Parameter Generation Methods - ffdhe2048, ffdhe3072, ffdhe4096, modp-2048, modp-3072, modp-4096SP 800-56A Rev. 3
KDF IKEv2 (CVL)A4595Diffie-Hellman Shared Secret Length - Diffie- Hellman Shared Secret Length: 2048 Derived Keying Material Length - Derived Keying Material Length: 3072 Hash Algorithm - SHA-1SP 800-135 Rev. 1
KDF SNMP (CVL)A4595Password Length - Password Length: 256, 64SP 800-135 Rev. 1
KDF SSH (CVL)A4595Cipher - AES-128, AES-192, AES-256SP 800-135 Rev. 1
RSA KeyGen (FIPS186-4)A4595Modulo - 2048, 3072FIPS 186-4
RSA SigGen (FIPS186-4)A4595Modulo - 2048, 3072FIPS 186-4
RSA SigVer (FIPS186-4)A4595Modulo - 2048, 3072FIPS 186-4
Safe Primes Key GenerationA4595Safe Prime Groups - ffdhe2048, ffdhe3072, ffdhe4096, modp-2048, modp-3072, modp- 4096SP 800-56A Rev. 3
SHA-1A4595Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-224A4595Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-256A4595Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-384A4595Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
SHA2-512A4595Message Length - Message Length: 0-65536 Increment 8FIPS 180-4
TLS v1.2 KDF RFC7627 (CVL)A4595Hash Algorithm - SHA2-256, SHA2-384, SHA2-512SP 800-135 Rev. 1
NamePropertiesImplementationReference
CKGKey Type:AsymmetricN/AThe Module performs Cryptographic Key Generation (CKG) for asymmetric keys as detailed by example 1 in section 4 and section 5 of SP800-133r2

Table 7: Approved Algorithms Vendor-Affirmed Algorithms: Table 8: Vendor-Affirmed Algorithms Non-Approved, Allowed Algorithms: © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 10
NameTypeDescriptionPropertiesAlgorithms
KAS-FFC (SSHv2)CKG KAS-FullFull KAS-FFC Key Agreement used for SSHv2 serviceCaveat:Key establishment methodology provides between 112 and 152 bits of security strength IG : IG D.F Path 2, Scenario 2, Split Key Confirmation : No Key Derivation : IG 2.4.B SP 800- 135rev1 CVLKAS-FFC-SSC Sp800-56Ar3: (A4595) Domain Parameter Generation: MODP-2048, MODP-3072, MODP-4096 Safe Primes Key Generation: (A4595) KDF SSH: (A4595) Counter DRBG: (A4595) CKG: () Key Type: Asymmetric
KAS-ECC (SSHv2)CKG KAS-FullFull KAS-ECC Key Agreement used for SSHv2 serviceCaveat:Key establishment methodology provides between 128 and 256 bits of security strength IG : IG D.F Scenario 2, Path 2, Split Key Confirmation : No Key Derivation : IG 2.4.B SP 800- 135rev1 CVLKAS-ECC-SSC Sp800-56Ar3: (A4595) Curves: P-256, P-384, P-521 KDF SSH: (A4595) Counter DRBG: (A4595) CKG: () Key Type: Asymmetric
KAS-FFC (TLSv1.2)CKG KAS-FullFull KAS-FFC Key Agreement used for TLSv1.2 serviceCaveat:Key establishment methodology provides betweenKAS-FFC-SSC Sp800-56Ar3: (A4595) Domain

N/A for this module. Non-Approved, Allowed Algorithms with No Security Claimed: N/A for this module. Non-Approved, Not Allowed Algorithms: N/A for this module.

2.6 Security Function Implementations

© 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 11
NameTypeDescriptionPropertiesAlgorithms
112 and 152 bits of security strength IG : IG D.F Path 2, Scenario 2, Split Key Confirmation : No Key Derivation : IG 2.4.B SP 800- 135rev1 CVLParameter Generation: ffdhe2048, ffdhe3072, ffdhe4096 Safe Primes Key Generation: (A4595) TLS v1.2 KDF RFC7627: (A4595) Counter DRBG: (A4595) CKG: () Key Type: Asymmetric
KAS-ECC (TLSv1.2)CKG KAS-FullFull KAS-ECC Key Agreement used for TLSv1.2 serviceCaveat:Key establishment methodology provides between 128 and 256 bits of security strength IG : IG D.F Scenario 2, Path 2, Split Key Confirmation : No Key Derivation : IG 2.4.B SP 800- 135rev1 CVLKAS-ECC-SSC Sp800-56Ar3: (A4595) Curves: P-256, P-384, P-521 TLS v1.2 KDF RFC7627: (A4595) Counter DRBG: (A4595) CKG: () Key Type: Asymmetric
KAS-FFC (IKEv2)CKG KAS-FullFull KAS-FFC Key Agreement used for IKEv2 serviceCaveat:Key establishment methodology provides between 112 and 152 bits of security strength IG : IG D.F Path 2, Scenario 2, Split Key Confirmation : No Key Derivation : IG 2.4.B SP 800- 135rev1 CVLKAS-FFC-SSC Sp800-56Ar3: (A4595) Domain Parameter Generation: MODP-2048, MODP-3072, MODP-4096 Safe Primes Key Generation: (A4595) KDF IKEv2: (A4595) Counter DRBG: (A4595) CKG: () Key Type: Asymmetric

© 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 12
NameTypeDescriptionPropertiesAlgorithms
KAS-ECC (IKEv2)CKG KAS-FullFull KAS-ECC Key Agreement used for IKEv2 serviceCaveat:Key establishment methodology provides between 128 and 256 bits of security strength IG : IG D.F Scenario 2, Path 2, Split Key Confirmation : No Key Derivation : IG 2.4.B SP 800- 135rev1 CVLKAS-ECC-SSC Sp800-56Ar3: (A4595) Curves: P-256, P-384, P-521 KDF IKEv2: (A4595) Counter DRBG: (A4595) CKG: () Key Type: Asymmetric
KTS (SSHv2 with AES and HMAC)KTS-Unwrap KTS-WrapKTS via SSHv2 service by using AES and HMACCaveat: Key establishment methodology provides 128 or 256 bits of security strength Standard:SP 800- 38F IG D.G:"combination" method: use any approved symmetric encryption mode together with an approved authentication methodAES-CBC: (A4595) Key Length: 128, 256 HMAC-SHA-1: (A4595) HMAC-SHA2- 256: (A4595) HMAC-SHA2- 384: (A4595) SHA-1: (A4595) SHA2-256: (A4595) SHA2-384: (A4595)
KTS (SSHv2 with AES-GCM)KTS-Unwrap KTS-WrapKTS via SSHv2 service by using AES-GCMCaveat:Key establishment methodology provides 128 or 256 bits of security strength Standard:SP 800- 38F IG D.G:method: use of any approved authenticated symmetric encryption modeAES-GCM: (A4595) Key Length: 128, 256
KTS (TLSv1.2 with AES and HMAC)KTS-Unwrap KTS-WrapKTS via TLSv1.2 service by using AES and HMACCaveat: Key establishment methodology provides 128 orAES-CBC: (A4595) Key Length: 128, 256

© 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 13
NameTypeDescriptionPropertiesAlgorithms
256 bits of security strength Standard:SP 800- 38F IG D.G: "combination" method: use any approved symmetric encryption mode together with an approved authentication methodHMAC-SHA-1: (A4595) HMAC-SHA2- 256: (A4595) HMAC-SHA2- 384: (A4595) SHA-1: (A4595) SHA2-256: (A4595) SHA2-384: (A4595)
KTS (TLSv1.2 with AES-GCM)KTS-Unwrap KTS-WrapKTS via TLSv1.2 service by using AES- GCMCaveat: Key establishment methodology provides 128 or 256 bits of security strength Standard:SP 800- 38F IG D.G: method: use of any approved authenticated symmetric encryption modeAES-GCM: (A4595) Key Length: 128, 256
RSA KeyGen (SSHv2, TLSv1.2, IKEv2)AsymKeyPair- KeyGen CKGRSA KeyGen for IKEv2, SSHv2 and TLSv1.2 servicesRSA KeyGen (FIPS186-4): (A4595) Modulus: 2048, 3072 bits Counter DRBG: (A4595) CKG: () Key Type: Asymmetric
RSA SigGen (SSHv2, TLSv1.2, IKEv2)DigSig-SigGenRSA SigGen for IKEv2, SSHv2 and TLSv1.2 servicesRSA SigGen (FIPS186-4): (A4595) Modulus: 2048, 3072 bits
RSA SigVer (SSHv2, TLSv1.2, IKEv2)DigSig-SigVerRSA SigVer for IKEv2, SSHv2 and TLSv1.2 servicesRSA SigVer (FIPS186-4): (A4595) Modulus: 2048, 3072 bits

© 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 14
NameTypeDescriptionPropertiesAlgorithms
ECDSA KeyGen (SSHv2, TLSv1.2, IKEv2)AsymKeyPair- KeyGen CKGECDSA KeyGen for IKEv2, SSHv2 and TLSv1.2 servicesECDSA KeyGen (FIPS186-4): (A4595) Curves: P-256, P-384, P-521 Counter DRBG: (A4595) CKG: () Key Type: Asymmetric
ECDSA SigGen (SSHv2, TLSv1.2, IKEv2)DigSig-SigGenECDSA SigGen for IKEv2, SSHv2 and TLSv1.2 servicesECDSA SigGen (FIPS186-4): (A4595) Curves: P-256, P-384, P-521
ECDSA SigVer (SSHv2, TLSv1.2, IKEv2)DigSig-SigVerECDSA SigVer for IKEv2, SSHv2 and TLSv1.2 servicesECDSA SigVer (FIPS186-4): (A4595) Curves: P-256, P-384, P-521
SSHv2 Session Encrypt/DecryptBC-Auth BC-UnAuthSSHv2 session protection.AES-CBC: (A4595) Key Length: 128, 256 AES-GCM: (A4595) Key Length: 128, 256
SSHv2 Session AuthenticationMACSSHv2 Session Authentication.SHA-1: (A4595) SHA2-256: (A4595) HMAC-SHA-1: (A4595) HMAC-SHA2- 256: (A4595)
SSHv2 Keying Materials DevelopmentKAS-135KDFSSHv2 session keying materials, used to derive SSHv2 session keys.KDF SSH: (A4595)
TLSv1.2 Session Encrypt/DecryptBC-Auth BC-UnAuthTLSv1.2 session protection.AES-CBC: (A4595) Key Length: 128, 256 AES-GCM: (A4595) Key Length: 128, 256

© 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 15
NameTypeDescriptionPropertiesAlgorithms
TLSv1.2 Session AuthenticationMACTLSv1.2 session authentication.SHA-1: (A4595) SHA2-256: (A4595) SHA2-384: (A4595) HMAC-SHA-1: (A4595) HMAC-SHA2- 256: (A4595) HMAC-SHA2- 384: (A4595)
TLSv1.2 Keying Materials DevelopmentKAS-135KDFTLSv1.2 session keying materials, used to derive TLS session keys.TLS v1.2 KDF RFC7627: (A4595)
IPsec/IKEv2 Session Encrypt/DecryptBC-Auth BC-UnAuthIPsec/IKEv2 session protection.AES-CBC: (A4595) Key Length: 128, 256 AES-GCM: (A4595) Key Length: 128, 256
IPsec/IKEv2 Session AuthenticationMACIPsec/IKEv2 session authentication.SHA2-256: (A4595) SHA2-384: (A4595) SHA2-512: (A4595) HMAC-SHA2- 256: (A4595) HMAC-SHA2- 384: (A4595) HMAC-SHA2- 512: (A4595)
IPsec/IKEv2 Keying Materials DevelopmentKAS-135KDFIPsec/IKEv2 session keying materials, used to derive IPsec/IKEv2 session keys.KDF IKEv2: (A4595)
SNMPv3 Session Encrypt/DecryptBC-UnAuthSNMPv3 session protection.AES-CBC: (A4595) Key Length: 128, 256
SNMPv3 Session AuthenticationMACSNMPv3 session authentication.SHA-1: (A4595) SHA2-224: (A4595)

© 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 16
NameTypeDescriptionPropertiesAlgorithms
SHA2-256: (A4595) SHA2-384: (A4595) HMAC-SHA-1: (A4595) HMAC-SHA2- 224: (A4595) HMAC-SHA2- 256: (A4595) HMAC-SHA2- 384: (A4595)
SNMPv3 Keying Materials DevelopmentKAS-135KDFSNMPv3 session keying materials, used to derive SNMPv3 session keys.KDF SNMP: (A4595)
DRBG FunctionDRBGUsed for DRBG generationCounter DRBG: (A4595)

Table 9: Security Function Implementations

2.7 Algorithm Specific Information
Page 17
CertVendor
NumberName
E3Cisco
NameTypeOperational EnvironmentSample SizeEntropy per SampleConditioning Component
Cisco Jitter Entropy SourceNon- PhysicalIntel Xeon Platinum 8160 (Skylake)256 bitsFull entropyA2810 (SHA3- 256)
4 DSA or RSA X9.31 for Signature Generation or Signature Verification.
2.8 RBG and Entropy

Table 10: Entropy Certificates Table 11: Entropy Sources The module employs a Deterministic Random Bit Generator (DRBG) implementation based on SP800-90Arev1. This DRBG is used internally by the module (e.g. to generate symmetric keys, seeds for asymmetric key pairs, and random numbers for security functions). The DRBG implemented is an AES-256 Counter DRBG, seeded by the entropy source described in the table above. The Counter DRBG utilizes the Derivation Function and employs prediction resistance. The DRBG is instantiated with a 384-bits long entropy input (corresponding to 384 bits of entropy). Additionally, the DRBG is reseeded with a 256-bits long entropy input (corresponding

2.9 Key Generation

The module implements Cryptographic Key Generation (CKG, vendor affirmed), compliant with SP 800- 133r2. When random values are required, they are obtained from the SP 800-90Ar1 approved DRBG, compliant with Section 4 of SP 800-133r2. The following methods are implemented:

Page 18
2.10 Key Establishment

The module provides the following key/SSP establishment services in the approved mode of operation: KAS-FFC Shared Secret Computation:

7919 (TLS) and RFC 3526 (IKE). Note that the module only implements domain

parameter generation, key pair generation and verification, and shared secret computation.

Page 19
Physical PortLogical Interface(s)Data That Passes
N/AData InputArguments for an API that provide the data to be used for processed by the module.
N/AData OutputArguments output from an API call.
N/AControl InputArguments for an API call used to control and configure module operation.
N/AControl OutputN/A
N/AStatus OutputReturn values, and/or log messages.
N/APowerProvide the Power Supply to the module.
NameTypeOperator TypeAuthentication Methods
Crypto OfficerRoleCrypto OfficerNone

• Key wrapping using AES-CBC with a security strength of 128 or 256 bits with HMACSHA-1, HMAC-SHA2-256 or HMAC-SHA2-384.

2.11 Industry Protocols

The module supports SSHv2, TLSv1.2, IPsec/IKEv2 and SNMPv3 industrial protocols. No parts of SSHv2, TLSv1.2, IPsec/IKEv2 or SNMPv3 protocols, other than the KDFs, have been tested by the CAVP and CMVP. Please refer to SSPs Table for more information.

3 Cryptographic Module Interfaces
3.1 Ports and Interfaces

Table 12: Ports and Interfaces The module’s physical perimeter encompasses the case of the tested platform mentioned in Table 2. The module provides its logical interfaces via Application Programming Interface (API) calls. The logical interfaces provided by the module are mapped onto the FIPS 140-3 interfaces

4 Roles, Services, and Authentication
4.2 Roles

Table 13: Roles The module supports Crypto Officer (CO) role. The module does not allow concurrent operators. The Crypto Officer is implicitly assumed based on the service requested. © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 20
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Access
Show StatusProvide Module's current statusNoneAPI command to show status.Module's current status.NoneCrypto Officer
Show VersionProvide Module's name/ID and versioning informatio n.NoneAPI command "show version"Module's name "Cisco Firepower Threat Defense for VMware" and versioning informationNoneCrypto Officer
Perform Self-TestsPerform Self-Tests (Pre- operationa l self-tests and Condition al Self- Tests)NoneAPI command s to conduct on- demand Self- Tests.Status of the self- tests results.NoneCrypto Officer
Perform Zeroizatio nPerform Zeroizatio n.NoneAPI command s to conduct Zeroizatio n operation or Power down the tested platform.Status of the SSPs zeroization.NoneCrypto Officer - DRBG Entropy Input: Z - DRBG Seed: Z - DRBG Internal State V value: Z - DRBG Key: Z - SSH DH
4.3 Approved Services

The following tables detail the types of approved services available to each role in approved mode of operation, the types of access for each role and the Keys or SSPs they affect.

Page 21
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Access
Private Key: Z - SSH DH Public Key: Z - SSH Peer DH Public Key: Z - SSH DH Shared Secret: Z - SSH ECDH Private Key: Z - SSH ECDH Public Key: Z - SSH Peer ECDH Public Key: Z - SSH ECDH Shared Secret: Z - SSH RSA Private Key: Z - SSH RSA Public Key: Z - SSH ECDSA Private Key: Z - SSH ECDSA Public Key: Z - SSH Session Encryption Key: Z - SSH Session Authenticati

Z Z Z Z Z Z Z Z Z © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 22
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Access
on Key: Z - TLS DH Private Key: Z - TLS DH Public Key: Z - TLS Peer DH Public Key: Z - TLS DH Shared Secret: Z - TLS ECDH Private Key: Z - TLS ECDH Public Key: Z - TLS Peer ECDH Public Key: Z - TLS ECDH Shared Secret: Z - TLS RSA Private Key: Z - TLS RSA Public Key: Z - TLS ECDSA Private Key: Z - TLS ECDSA Public Key: Z - TLS Master Secret: Z - TLS Session

Z Z Z Z Z Z Z Z Z © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 23
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Access
Encryption Key: Z - TLS Session Authenticati on Key: Z - IPsec/IKEv2 DH Private Key: Z - IPsec/IKEv2 DH Public Key: Z - IPsec/IKEv2 Peer DH Public Key: Z - IPsec/IKEv2 DH Shared Secret: Z - IPsec/IKEv2 ECDH Private Key: Z - IPsec/IKEv2 ECDH Public Key: Z - IPsec/IKEv2 Peer ECDH Public Key: Z - IPsec/IKEv2 ECDH Shared Secret: Z - IPsec/IKEv2 RSA Private Key: Z -

Z Z Z Z © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 24
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Access
IPsec/IKEv2 RSA Public Key: Z - IPsec/IKEv2 ECDSA Private Key: Z - IPsec/IKEv2 ECDSA Public Key: Z - IPsec/IKEv2 Pre-Shared Key: Z - SKEYSEED : Z - IPsec/IKEv2 Session Encryption Key: Z - IPsec/IKEv2 Authenticati on Key: Z - SNMPv3 Authenticati on/ Privacy Password: Z - SNMPv3 Encryption Key: Z - SNMPv3 Authenticati on Key: Z
Configure NetworkSets configurati on of the systems.NoneAPI command s to configure the module.Status of the completion of network related configuratio n.NoneCrypto Officer

Z Z :Z Z n. © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 25
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Access
Configure SSHv2 FunctionConfigure SSHv2 FunctionGlobal Indicator and SSHv2 configurati on success status message.API command s to configure SSHv2.Status of the completion of SSHv2 configuratio n.KTS (SSHv2 with AES and HMAC) KTS (SSHv2 with AES- GCM) RSA KeyGen (SSHv2, TLSv1.2, IKEv2) ECDSA KeyGen (SSHv2, TLSv1.2, IKEv2) DRBG FunctionCrypto Officer - SSH RSA Private Key: G,W,E - SSH RSA Public Key: G,R,W - SSH ECDSA Private Key: G,W,E - SSH ECDSA Public Key: G,R,W - DRBG Entropy Input: G,W,E - DRBG Seed: G,W,E - DRBG Internal State V value: G,W,E - DRBG Key: G,W,E
Configure HTTPS over TLSv1.2 FunctionConfigure HTTPS over TLSv1.2 Function.Global Indicator and HTTPS over TLSv1.2 configurati on success status message.API command s to configure HTTPS over TLSv1.2Status of the completion of HTTPS over TLSv1.2 configuratio n.KTS (TLSv1.2 with AES and HMAC) KTS (TLSv1.2 with AES- GCM) RSA KeyGen (SSHv2, TLSv1.2, IKEv2) ECDSA KeyGen (SSHv2, TLSv1.2, IKEv2)Crypto Officer - TLS RSA Private Key: G,W,E - TLS RSA Public Key: G,R,W - TLS ECDSA Private Key: G,W,E - TLS ECDSA Public Key: G,R,W - DRBG Entropy

G,W,E G,W,E G,W,E © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 26
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Access
DRBG FunctionInput: G,W,E - DRBG Seed: G,W,E - DRBG Internal State V value: G,W,E - DRBG Key: G,W,E
Configure IPsec/IKE v2 FunctionsGlobal Indicator with IPsec/IKE v2 configurati on success status message.API command s to configure IPsec/IKE v2.Status of the completion of IPsec/IKEv 2 secure tunnel configuratio n.KTS (TLSv1.2 with AES and HMAC) KTS (TLSv1.2 with AES- GCM) RSA KeyGen (SSHv2, TLSv1.2, IKEv2) ECDSA KeyGen (SSHv2, TLSv1.2, IKEv2) DRBG FunctionCrypto Officer - IPsec/IKEv2 RSA Private Key: G,W,E - IPsec/IKEv2 RSA Public Key: G,W,E - IPsec/IKEv2 ECDSA Private Key: G,W,E - IPsec/IKEv2 ECDSA Public Key: G,W,E - IPsec/IKEv2 Pre-Shared Key: G,W,E - DRBG Entropy Input: G,W,E - DRBG Seed: G,W,E - DRBG Internal State V value: G,W,E

G,W,E G,W,E G,W,E G,W,E G,W,E © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 27
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Access
- DRBG Key: G,W,E
Configure SNMPv3 FunctionConfigure SNMPv3 FunctionGlobal Indicator and SNMPv3 configurati on success status message.API command s to configure SNMPv3.Status of the completion of SNMPv3 configuratio n.KTS (TLSv1.2 with AES and HMAC) KTS (TLSv1.2 with AES- GCM) SNMPv3 Keying Materials DevelopmentCrypto Officer - SNMPv3 Authenticati on/ Privacy Password: W,E - SNMPv3 Encryption Key: G,W,E - SNMPv3 Authenticati on Key: G,W,E
Run SSHv2 FunctionExecute SSHv2 FunctionGlobal Indicator and Successfu l SSHv2 log message.API command s to execute SSHv2 service.Status of SSHv2 secure tunnel establishme nt.KAS-FFC (SSHv2) KAS-ECC (SSHv2) KTS (SSHv2 with AES and HMAC) KTS (SSHv2 with AES- GCM) RSA SigGen (SSHv2, TLSv1.2, IKEv2) RSA SigVer (SSHv2, TLSv1.2, IKEv2) ECDSA SigGen (SSHv2, TLSv1.2, IKEv2) ECDSA SigVer (SSHv2, TLSv1.2, IKEv2) SSHv2 Session Encrypt/Decr yptCrypto Officer - SSH DH Private Key: G,W,E - SSH DH Public Key: G,R,W - SSH Peer DH Public Key: W,E - SSH DH Shared Secret: G,W,E - SSH ECDH Private Key: G,W,E - SSH ECDH Public Key: G,R,W - SSH Peer ECDH Public Key: W,E - SSH ECDH Shared Secret: G,W,E

G,W,E © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 28
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Access
SSHv2 Session Authenticatio n SSHv2 Keying Materials Development DRBG Function- SSH RSA Private Key: G,W,E - SSH RSA Public Key: G,R,W - SSH ECDSA Private Key: G,W,E - SSH ECDSA Public Key: G,R,W - SSH Session Encryption Key: G,W,E - SSH Session Authenticati on Key: G,W,E - DRBG Entropy Input: G,W,E - DRBG Seed: G,W,E - DRBG Internal State V value: G,W,E - DRBG Key: G,W,E
Run HTTPS over TLSv1.2 FunctionExecute HTTPS over TLSv1.2 Function.Global Indicator and Successfu l HTTPS over TLSv1.2 log message.API command to execute HTTPS over TLSv1.2 service.Status of HTTPS over TLSv1.2 establishme nt.KAS-FFC (TLSv1.2) KAS-ECC (TLSv1.2) KTS (TLSv1.2 with AES and HMAC) KTS (TLSv1.2 with AES-Crypto Officer - TLS DH Private Key: G,W,E - TLS DH Public Key: G,R,W - TLS Peer DH Public Key: W,E

G,R,W G,W,E G,W,E G,W,E G,W,E © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 29
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Access
GCM) RSA SigGen (SSHv2, TLSv1.2, IKEv2) RSA SigVer (SSHv2, TLSv1.2, IKEv2) ECDSA SigGen (SSHv2, TLSv1.2, IKEv2) ECDSA SigVer (SSHv2, TLSv1.2, IKEv2) TLSv1.2 Session Encrypt/Decr ypt TLSv1.2 Session Authenticatio n TLSv1.2 Keying Materials Development DRBG Function- TLS DH Shared Secret: G,W,E - TLS ECDH Private Key: G,W,E - TLS ECDH Public Key: G,R,W - TLS Peer ECDH Public Key: W,E - TLS ECDH Shared Secret: G,W,E - TLS RSA Private Key: G,W,E - TLS RSA Public Key: G,R,W - TLS ECDSA Private Key: G,W,E - TLS ECDSA Public Key: G,R,W - TLS Master Secret: G,W,E - TLS Session Encryption Key: G,W,E - TLS Session Authenticati on Key: G,W,E

n G,R,W G,R,W G,W,E G,W,E © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 30
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Access
- DRBG Entropy Input: G,W,E - DRBG Seed: G,W,E - DRBG Internal State V value: G,W,E - DRBG Key: G,W,E
Run IPsec/IKE v2 FunctionsExecute IPsec/IKE v2 FunctionsGlobal Indicator and Successfu l IPsec/IKE v2 log message.API command to execute IPsec/IKE v2Status of IPsec/IKEv 2 secure tunnel establishme ntKAS-FFC (IKEv2) KAS-ECC (IKEv2) RSA SigGen (SSHv2, TLSv1.2, IKEv2) RSA SigVer (SSHv2, TLSv1.2, IKEv2) ECDSA SigGen (SSHv2, TLSv1.2, IKEv2) ECDSA SigVer (SSHv2, TLSv1.2, IKEv2) IPsec/IKEv2 Session Encrypt/Decr ypt IPsec/IKEv2 Session Authenticatio n IPsec/IKEv2 Keying Materials DevelopmentCrypto Officer - IPsec/IKEv2 DH Private Key: G,W,E - IPsec/IKEv2 DH Public Key: G,R,W - IPsec/IKEv2 Peer DH Public Key: W,E - IPsec/IKEv2 DH Shared Secret: G,W,E - IPsec/IKEv2 ECDH Private Key: G,W,E - IPsec/IKEv2 ECDH Public Key: G,R,W - IPsec/IKEv2 Peer ECDH Public Key:

G,W,E G,W,E G,W,E n G,R,W © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 31
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Access
DRBG FunctionW,E - IPsec/IKEv2 ECDH Shared Secret: G,W,E - IPsec/IKEv2 RSA Private Key: G,W,E - IPsec/IKEv2 RSA Public Key: G,W,E - IPsec/IKEv2 ECDSA Private Key: G,W,E - IPsec/IKEv2 ECDSA Public Key: G,W,E - IPsec/IKEv2 Pre-Shared Key: G,W,E - SKEYSEED : G,W,E - IPsec/IKEv2 Session Encryption Key: G,W,E - IPsec/IKEv2 Authenticati on Key: G,W,E - DRBG Entropy Input: G,W,E - DRBG Seed:

G,W,E G,W,E G,W,E : G,W,E G,W,E G,W,E © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 32
NameDescripti onIndicatorInputsOutputsSecurity FunctionsSSP Access
G,W,E - DRBG Internal State V value: G,W,E - DRBG Key: G,W,E
Run SNMPv3 FunctionsExecute SNMPv3 Function.Global Indicator and Successfu l SNMPv3 log message.API command to execute SNMPv3 service.Status of SNMPv3 service.SNMPv3 Session Encrypt/Decr ypt SNMPv3 Session Authenticatio n SNMPv3 Keying Materials DevelopmentCrypto Officer - SNMPv3 Authenticati on/ Privacy Password: W,E - SNMPv3 Encryption Key: G,W,E - SNMPv3 Authenticati on Key: G,W,E
4.4 Non-Approved Services
4.5 External Software/Firmware Loaded
4.6 Bypass Actions and Status
4.7 Cryptographic Output Actions and Status

The module implements Self-initiated cryptographic output capability without external operator request. The Crypto Officer shall configure self-initiated cryptographic output capability. Prior to executing the self-initiated cryptographic output capability, the module conducts two independent internal actions to activate the capability to prevent the inadvertent output due to a single error. © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 33
5 Software/Firmware Security
5.1 Integrity Techniques

The module is provided in the form of binary executable code. To ensure firmware security, the library is protected by RSA 2048 SigVer with SHA-512 (RSA and SHA-512 Cert. #A4595) signature calculated at build time. At crypto module library initialization, the signature is recalculated and compared to the hardcoded build-time generated signature value. If at load time the signature does not match, the crypto module library exits with error. If failure occurs during self-test, all crypto functionality is disabled.

5.2 Initiate on Demand

Integrity test is performed as part of the Pre-Operational Self-Tests. It is automatically executed at power-on. The operator can power-cycle or reboot the tested platform to initiate the integrity test on-demand.

6 Operational Environment
6.1 Operational Environment Type and Requirements

Type of Operational Environment: Non-Modifiable The module is a firmware hybrid module, which is operated in a non-modifiable operational environment per FIPS 140-3 level 1 specifications. The module’s firmware version running on each tested platform 7.4.2. The module has control over its own SSPs. The process and memory management functionality of the host device’s OS prevent unauthorized access to plaintext private and secret keys, intermediate key generation values and other SSPs by external processes during module execution. The module only allows access to SSPs through its well-defined API. The operational environments provide the capability to separate individual application processes from each other by preventing uncontrolled access to CSPs and uncontrolled modifications of SSPs regardless of whether this data is in the process memory or stored on persistent storage within the operational environment. Processes that are spawned by the module are owned by the module and are not owned by external processes/operators.

7 Physical Security

The module is running on the multi-chip standalone production grade platform to meet physical security requirements from FIPS 140-3 level

  1. The module’s Tested Operational Environment’s Physical Perimeter (TOEPP) is drawn at the casing of the tested platforms in Table
  2. The module’s tested platforms consist of production-grade components.
8 Non-Invasive Security

N/A for this module. © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 34
Storage Area NameDescriptionPersistence Type
DRAMVolatile memory provided by the ESXi host for the module temporary.Dynamic
FlashNon-Volatile memory provided by the ESXi host for the module to retain memory across power-cycles.Static
NameFromToFormat TypeDistribution TypeEntry TypeSFI or Algorithm
Peer Public Key InputExternal (Outside of the TOEPP)TOEPPPlaintextAutomatedElectronic
Module Public Key OutputTOEPPExternal (Outside of the TOEPP)PlaintextAutomatedElectronic
Secret Input via SSHv2 encrypted by GCMExternal (Outside of the TOEPP)TOEPPEncryptedAutomatedElectronicKTS (SSHv2 with AES- GCM)
Secret Input via SSHv2 encrypted by AES and HMACExternal (Outside of the TOEPP)TOEPPEncryptedAutomatedElectronicKTS (SSHv2 with AES and HMAC)
Secret Input via TLS encrypted by GCMExternal (Outside of the TOEPP)TOEPPEncryptedAutomatedElectronicKTS (TLSv1.2 with AES- GCM)
Secret Input via TLS encrypted by AES and HMACExternal (Outside of the TOEPP)TOEPPEncryptedAutomatedElectronicKTS (TLSv1.2 with AES and HMAC)
9 Sensitive Security Parameters Management
9.1 Storage Areas
9.2 SSP Input-Output Methods

Table 16: SSP Input-Output Methods

9.3 SSP Zeroization Methods

© 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 35
Zeroization MethodDescriptionRationaleOperator Initiation
Zeroization CommandCO issues zeroization serviceThe zeroization command will erase all SSPs stored in the DRAM and Flash of the module.Delete the virtual machine from the VMware ESXi host.
Session TerminationZeroization upon session terminationSession termination will automatically zeroize all session based temporary SSPsTerminate session
RebootZeroization upon rebooting the moduleReboot to zeroize all temporary SSPs stored in volatile memoryReboot
NameDescriptio nSize - Strengt hType - CategoryGenerat ed ByEstablishe d ByUsed By
DRBG Entropy InputUsed to seed the DRBG384 bits - at least 256 bitsEntropy Input - CSPDRBG Function
DRBG SeedUsed in DRBG Generation256 bits - 256 bitsDRBG Seed - CSPDRBG Function
DRBG Internal State V valueUsed in DRBG Generation256 bits - 256 bitsDRBG Internal State V value - CSPDRBG Function
DRBG KeyUsed in DRBG Generation256 bits - 256 bitsDRBG Key - CSPDRBG Function
SSH DH Private KeyUsed to derive the SSH DH Shared SecretMODP- 2048, MODP- 3072, MODP- 4096 - 112 to 152 bitsPrivate Key - CSPKAS- FFC (SSHv2)KAS-FFC (SSHv2)
SSH DH Public KeyUsed to derive SSH DH Shared SecretMODP- 2048, MODP- 3072, MODP- 4096 - 112 to 152 bitsPublic Key - PSPKAS-FFC (SSHv2)

Table 17: SSP Zeroization Methods h © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 36
NameDescriptio nSize - Strengt hType - CategoryGenerat ed ByEstablishe d ByUsed By
SSH Peer DH Public KeyUsed to derive SSH DH Shared SecretMODP- 2048, MODP- 3072, MODP- 4096 - 112 to 152 bitsPublic Key - PSPKAS-FFC (SSHv2)
SSH DH Shared SecretUsed to derive SSH Session Encryption Keys, SSH Session Authenticati on KeysMODP- 2048, MODP- 3072, MODP- 4096 - 112 to 152 bitsShared Secret - CSPKAS-FFC (SSHv2)KAS-FFC (SSHv2)
SSH ECDH Private KeyUsed to derive the SSH ECDH Shared SecretCurves: P-256, P-384, P-521 - 128 to 256 bitsPrivate Key - CSPKAS- ECC (SSHv2)KAS-ECC (SSHv2)
SSH ECDH Public KeyUsed to derive the SSH ECDH Shared SecretCurves: P-256, P-384, P-521 - 128 to 256 bitsPublic Key - PSPKAS-ECC (SSHv2)
SSH Peer ECDH Public KeyUsed to derive SSH DH Shared SecretCurves: P-256, P-384, P-521 - 128 to 256 bitsPublic Key - PSPKAS-ECC (SSHv2)
SSH ECDH Shared SecretUsed to derive SSH Session Encryption Keys, SSH Session Authenticati on KeysCurves: P-256, P-384, P-521 - 128 to 256 bitsShared Secret - CSPKAS-ECC (SSHv2)KAS-ECC (SSHv2)
SSH RSA Private KeyUsed for SSH session authenticati onModulus 2048 and 3072 bits -Private Key - CSPRSA KeyGen (SSHv2, TLSv1.2, IKEv2)RSA SigGen (SSHv2, TLSv1.2, IKEv2)

h © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 37
NameDescriptio nSize - Strengt hType - CategoryGenerat ed ByEstablishe d ByUsed By
112 to 128 bits
SSH RSA Public KeyUsed for SSH session authenticati onModulus 2048 and 3072 bits - 112 to 128 bitsPublic Key - PSPRSA KeyGen (SSHv2, TLSv1.2, IKEv2)
SSH ECDSA Private KeyUsed for SSH session authenticati onCurves: P-256, P-384, P-521 - 128 to 256 bitsPrivate Key - CSPECDSA KeyGen (SSHv2, TLSv1.2, IKEv2)ECDSA SigGen (SSHv2, TLSv1.2, IKEv2)
SSH ECDSA Public KeyUsed for SSH session authenticati onCurves: P-256, P-384, P-521 - 128 to 256 bitsPublic Key - PSPECDSA KeyGen (SSHv2, TLSv1.2, IKEv2)
SSH Session Encryption KeyUsed for SSH session confidentiali ty protection128, 256 bits - 128, 256 bitsSymmetric Key - CSPSSHv2 Keying Materials Developm entSSHv2 Session Encrypt/Decr ypt
SSH Session Authenticati on KeyUsed for SSH Session integrity protectionAt least 160 bits - At least 160 bitsSession Key - CSPSSHv2 Keying Materials Developm entSSHv2 Session Authenticatio n
TLS DH Private KeyUsed to Derive TLS DH Shared Secretffdhe204 8, ffdhe307 2, ffdhe409 6 - 112 to 152 bitsPrivate Key - CSPKAS- FFC (TLSv1.2 )KAS-FFC (TLSv1.2)
TLS DH Public KeyUsed to Derive TLS DH Shared Secretffdhe204 8, ffdhe307 2, ffdhe409 6 - 112Public Key - PSPKAS-FFC (TLSv1.2)

h © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 38
NameDescriptio nSize - Strengt hType - CategoryGenerat ed ByEstablishe d ByUsed By
to 152 bits
TLS Peer DH Public KeyUsed to derive TLS DH Shared Secretffdhe204 8, ffdhe307 2, ffdhe409 6 - 112 to 152 bitsPublic Key - PSPKAS-FFC (TLSv1.2)
TLS DH Shared SecretUsed to Derive TLS Session Encryption Key and TLS Session Authenticati on Keyffdhe204 8, ffdhe307 2, ffdhe409 6 - 112 to 152 bitsShared Secret - CSPKAS-FFC (TLSv1.2)KAS-FFC (TLSv1.2)
TLS ECDH Private KeyUsed to Derive TLS ECDH Shared SecretCurves: P-256, P-384, P-521 - 128 to 256 bitsPrivate Key - CSPKAS- ECC (TLSv1.2 )KAS-ECC (TLSv1.2)
TLS ECDH Public KeyUsed to Derive TLS ECDH Shared SecretCurves: P-256, P-384, P-521 - 128 to 256 bitsPublic Key - PSPKAS-ECC (TLSv1.2)
TLS Peer ECDH Public KeyUsed to derive TLS ECDH Shared SecretCurves: P-256, P-384, P-521 - 128 to 256 bitsPublic Key - PSPKAS-ECC (TLSv1.2)
TLS ECDH Shared SecretUsed to Derive TLS Session Encryption Key and TLS Session Authenticati on KeyCurves: P-256, P-384, P-521 - 128 to 256 bitsShared Secret - CSPKAS-ECC (TLSv1.2)KAS-ECC (TLSv1.2)

h © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 39
NameDescriptio nSize - Strengt hType - CategoryGenerat ed ByEstablishe d ByUsed By
TLS RSA Private KeyUsed to support CO HTTPS interfacesModulus 2048 and 3072 bits - 112 to 128 bitsPrivate Key - CSPRSA KeyGen (SSHv2, TLSv1.2, IKEv2)RSA SigGen (SSHv2, TLSv1.2, IKEv2)
TLS RSA Public KeyUsed to support CO HTTPS interfacesModulus 2048 and 3072 bits - 112 to 128 bitsPublic Key - PSPRSA KeyGen (SSHv2, TLSv1.2, IKEv2)
TLS ECDSA Private KeyUsed to support CO HTTPS interfacesCurves: P-256, P-384, P-521 - 128 to 256 bitsPrivate Key - CSPECDSA KeyGen (SSHv2, TLSv1.2, IKEv2)ECDSA SigGen (SSHv2, TLSv1.2, IKEv2)
TLS ECDSA Public KeyUsed to support CO HTTPS interfacesCurves: P-256, P-384, P-521 - 128 to 256 bitsPublic Key - PSPECDSA KeyGen (SSHv2, TLSv1.2, IKEv2)
TLS Master SecretUsed to protect HTTPS Session384 bits - 384 bitsMaster Secret - CSPTLSv1.2 Keying Materials Developm entTLSv1.2 Session Encrypt/Decr ypt TLSv1.2 Session Authenticatio n
TLS Session Encryption KeyUsed to protect HTTPS Session128, 256 bits - 128, 256 bitsSymmetric Key - CSPTLSv1.2 Keying Materials Developm entTLSv1.2 Session Encrypt/Decr ypt
TLS Session Authenticati on KeyUsed to authenticat e HTTPS Session160, 256, 384 bits - 160, 256, 384 bitsMessage Authenticati on Key - CSPTLSv1.2 Keying Materials Developm entTLSv1.2 Session Authenticatio n

h n © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 40
NameDescriptio nSize - Strengt hType - CategoryGenerat ed ByEstablishe d ByUsed By
IPsec/IKEv2 DH Private KeyUsed to derive IPsec/IKEv 2 DH Shared SecretMODP- 2048, MODP- 3072, MODP- 4096 - 112 to 152 bitsPrivate Key - CSPKAS- FFC (IKEv2)KAS-FFC (IKEv2)
IPsec/IKEv2 DH Public KeyUsed to derive IPsec/IKEv 2 DH Shared SecretMODP- 2048, MODP- 3072, MODP- 4096 - 112 to 152 bitsPublic Key - PSPKAS-FFC (IKEv2)
IPsec/IKEv2 Peer DH Public KeyUsed to derive IPsec/IKEv 2 DH Shared SecretMODP- 2048, MODP- 3072, MODP- 4096 - 112 to 152 bitsPublic Key - PSPKAS-FFC (IKEv2)
IPsec/IKEv2 DH Shared SecretUsed to derive IPsec/IKEv 2 Session Shared SecretMODP- 2048, MODP- 3072, MODP- 4096 - 112 to 152 bitsShared Secret - CSPKAS-FFC (IKEv2)KAS-FFC (IKEv2)
IPsec/IKEv2 ECDH Private KeyUsed to derive IPsec/IKEv 2 ECDH Shared SecretCurves: P-256, P-384, P-521 - 128 to 256 bitsPrivate key - CSPKAS- ECC (IKEv2)KAS-ECC (IKEv2)
IPsec/IKEv2 ECDH Public KeyUsed to derive IPsec/IKEv 2 ECDH Shared SecretCurves: P-256, P-384, P-521 - 128 to 256 bitsPublic Key - PSPKAS-ECC (IKEv2)
IPsec/IKEv2 Peer ECDH Public KeyUsed to derive IPsec/IKEvCurves: P-256, P-384,Public Key - PSPKAS-ECC (IKEv2)

h © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 41
NameDescriptio nSize - Strengt hType - CategoryGenerat ed ByEstablishe d ByUsed By
2 ECDH Shared SecretP-521 - 128 to 256 bits
IPsec/IKEv2 ECDH Shared SecretUsed to derive IPsec/IKEv 2 ECDH Shared SecretCurves: P-256, P-384, P-521 - 128 to 256 bitsShared Secret - CSPKAS-ECC (IKEv2)KAS-ECC (IKEv2)
IPsec/IKEv2 RSA Private KeyUsed for IPsec/IKEv 2 authenticati onModulus 2048 and 3072 bits - 112 to 128 bitsPrivate Key - CSPRSA KeyGen (SSHv2, TLSv1.2, IKEv2)RSA SigGen (SSHv2, TLSv1.2, IKEv2)
IPsec/IKEv2 RSA Public KeyUsed for IPsec/IKEv 2 authenticati onModulus 2048 and 3072 bits - 112 to 128 bitsPublic Key - PSPRSA KeyGen (SSHv2, TLSv1.2, IKEv2)
IPsec/IKEv2 ECDSA Private KeyUsed for IPsec/IKEv 2 authenticati onCurves: P-256, P-384, P-521 - 128 to 256 bitsPrivate Key - CSPECDSA KeyGen (SSHv2, TLSv1.2, IKEv2)ECDSA SigGen (SSHv2, TLSv1.2, IKEv2)
IPsec/IKEv2 ECDSA Public KeyUsed for IPsec/IKEv 2 authenticati onCurves: P-256, P-384, P-521 - 128 to 256 bitsPublic Key - PSPECDSA KeyGen (SSHv2, TLSv1.2, IKEv2)
IPsec/IKEv2 Pre-Shared KeyUsed for IPsec/IKEv 2 authenticati on16-32 characte rs - 128 to 256 bitsShared Secret - CSP
SKEYSEEDKeying material used to derive the IPSec/IKE Session Encryption160 bits - 160 bitsKeying Material - CSPIPsec/IKEv 2 Keying Materials Developm entIPsec/IKEv2 Session Encrypt/Decr ypt IPsec/IKEv2 Session

h © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 42
NameDescriptio n Key and IPSec/IKE Authenticati on KeySize - Strengt hType - CategoryGenerat ed ByEstablishe d ByUsed By Authenticatio n
IPsec/IKEv2 Session Encryption KeyUsed to secure IPsec/IKEv 2 session confidentiali ty128, 192, 256 bits - 128, 192, 256 bitsSymmetric Key - CSPIPsec/IKEv 2 Keying Materials Developm entIPsec/IKEv2 Session Encrypt/Decr ypt
IPsec/IKEv2 Authenticati on KeyUsed to secure IPsec/IKEv 2 session authenticati onat least 160 bits - at least 160 bitsMessage Authenticati on Key - CSPIPsec/IKEv 2 Keying Materials Developm entIPsec/IKEv2 Session Authenticatio n
SNMPv3 Authenticati on/ Privacy PasswordUsed for SNMPv3 user authenticati on8-32 characte rs - 64 to 256 bitsAuthenticati on Password - CSP
SNMPv3 Encryption KeyUsed for SNMPv3 confidentiali ty128 bits - 128 bitsSymmetric Key - CSPSNMPv3 Keying Materials Developm entSNMPv3 Session Encrypt/Decr ypt
SNMPv3 Authenticati on KeyUsed for SNMPv3 authenticati onAt least 112 bits - At least 112 bitsAuthenticati on Key - CSPSNMPv3 Keying Materials Developm entSNMPv3 Session Authenticatio n
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
DRBG Entropy InputDRAM:Plaintex tUntil RebootZeroization Command RebootDRBG Seed:Used With DRBG Internal State V value:Used With DRBG Key:Used With
DRBG SeedDRAM:Plaintex tUntil RebootZeroization Command RebootDRBG Entropy Input:Used With DRBG Internal State V value:Used

h Table 18: SSP Table 1 © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 43
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs With DRBG Key:Used With
DRBG Internal State V valueDRAM:Plaintex tUntil RebootZeroization Command RebootDRBG Entropy Input:Used With DRBG Seed:Used With DRBG Key:Used With
DRBG KeyDRAM:Plaintex tUntil RebootZeroization Command RebootDRBG Entropy Input:Used With DRBG Seed:Used With DRBG Internal State V value:Used With
SSH DH Private KeyDRAM:Plaintex tWhile SSH session is activeZeroization Command Session Terminatio n RebootSSH DH Public Key:Paired With SSH Peer DH Public Key:Used With
SSH DH Public KeyModule Public Key OutputDRAM:Plaintex tWhile SSH session is activeZeroization Command Session Terminatio n RebootSSH DH Private Key:Paired With
SSH Peer DH Public KeyPeer Public Key InputDRAM:Plaintex tWhile SSH session is activeZeroization Command Session Terminatio n RebootSSH DH Private Key:Used With
SSH DH Shared SecretDRAM:Plaintex tWhile SSH session is activeZeroization Command Session Terminatio n RebootSSH DH Private Key:Derived From SSH Peer DH Public Key:Derived From
SSH ECDH Private KeyDRAM:Plaintex tWhile SSH session is activeZeroization Command Session Terminatio n RebootSSH ECDH Public Key:Paired With SSH Peer ECDH Public Key:Used With

n n © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 44
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
SSH ECDH Public KeyModule Public Key OutputDRAM:Plaintex tWhile SSH session is activeZeroization Command Session Terminatio n RebootSSH ECDH Private Key:Paired With
SSH Peer ECDH Public KeyPeer Public Key InputDRAM:Plaintex tWhile SSH session is activeZeroization Command Session Terminatio n RebootSSH ECDH Private Key:Used With
SSH ECDH Shared SecretDRAM:Plaintex tWhile SSH session is activeZeroization Command Session Terminatio n RebootSSH ECDH Private Key:Derived From SSH Peer ECDH Public Key:Derived From
SSH RSA Private KeyFlash:PlaintextZeroization CommandSSH RSA Public Key:Paired With
SSH RSA Public KeyModule Public Key Output Secret Input via SSHv2 encrypte d by GCM Secret Input via SSHv2 encrypte d by AES and HMACFlash:PlaintextZeroization CommandSSH RSA Private Key:Paired With
SSH ECDSA Private KeyFlash:PlaintextZeroization CommandSSH ECDSA Public Key:Paired With
SSH ECDSA Public KeyModule Public Key Output Secret Input via SSHv2 encrypte d byFlash:PlaintextZeroization CommandSSH ECDSA Private Key:Paired With

n n © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 45
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
GCM Secret Input via SSHv2 encrypte d by AES and HMAC
SSH Session Encryption KeyDRAM:Plaintex tWhile SSH session is activeZeroization Command Session Terminatio n RebootSSH Session Authentication Key:Used With
SSH Session Authentication KeyDRAM:Plaintex tWhile SSH session is activeZeroization Command Session Terminatio n RebootSSH Session Encryption Key:Used With
TLS DH Private KeyDRAM:Plaintex tWhile TLS session is activeZeroization Command Session Terminatio n RebootTLS DH Public Key:Paired With TLS Peer DH Public Key:Used With
TLS DH Public KeyModule Public Key OutputDRAM:Plaintex tWhile TLS session is activeZeroization Command Session Terminatio n RebootTLS DH Private Key:Paired With
TLS Peer DH Public KeyPeer Public Key InputDRAM:Plaintex tWhile TLS session is activeZeroization Command Session Terminatio n RebootTLS DH Private Key:Used With
TLS DH Shared SecretDRAM:Plaintex tWhile TLS session is activeZeroization Command Session Terminatio n RebootTLS DH Private Key:Derived From TLS Peer DH Public Key:Derived From
TLS ECDH Private KeyDRAM:Plaintex tWhile TLS session is activeZeroization Command Session TerminatioTLS ECDH Public Key:Paired With TLS Peer ECDH

n n n n © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 46
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
n RebootPublic Key:Used With
TLS ECDH Public KeyModule Public Key OutputDRAM:Plaintex tWhile TLS session is activeZeroization Command Session Terminatio n RebootTLS ECDH Private Key:Paired With
TLS Peer ECDH Public KeyPeer Public Key InputDRAM:Plaintex tWhile TLS session is activeZeroization Command Session Terminatio n RebootTLS ECDH Private Key:Used With
TLS ECDH Shared SecretDRAM:Plaintex tWhile TLS session is activeZeroization Command Session Terminatio n RebootTLS ECDH Private Key:Derived From TLS Peer ECDH Public Key:Derived From
TLS RSA Private KeyFlash:PlaintextZeroization CommandTLS RSA Public Key:Paired With
TLS RSA Public KeyModule Public Key Output Secret Input via TLS encrypte d by GCM Secret Input via TLS encrypte d by AES and HMACFlash:PlaintextZeroization CommandTLS RSA Private Key:Paired With
TLS ECDSA Private KeyFlash:PlaintextZeroization CommandTLS ECDSA Public Key:Paired With
TLS ECDSA Public KeyModule Public Key Output Secret Input via TLSFlash:PlaintextZeroization CommandTLS ECDSA Private Key:Paired With

n n © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 47
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
encrypte d by GCM Secret Input via TLS encrypte d by AES and HMAC
TLS Master SecretDRAM:Plaintex tWhile TLS session is activeZeroization Command Session Terminatio n RebootTLS DH Shared Secret:Derived From TLS ECDH Shared Secret:Derived From
TLS Session Encryption KeyDRAM:Plaintex tWhile TLS session is activeZeroization Command Session Terminatio n RebootTLS Session Authentication Key:Used With TLS Master Secret:Derived From
TLS Session Authentication KeyDRAM:Plaintex tWhile TLS session is activeZeroization Command Session Terminatio n RebootTLS Session Encryption Key:Used With TLS Master Secret:Derived From
IPsec/IKEv2 DH Private KeyDRAM:Plaintex tWhile IPsec/IKEv 2 tunnel is activeZeroization Command Session Terminatio n RebootIPsec/IKEv2 DH Public Key:Paired With IPsec/IKEv2 Peer DH Public Key:Used With
IPsec/IKEv2 DH Public KeyModule Public Key OutputDRAM:Plaintex tWhile IPsec/IKEv 2 tunnel is activeZeroization Command Session Terminatio n RebootIPsec/IKEv2 DH Private Key:Paired With
IPsec/IKEv2 Peer DH Public KeyPeer Public Key InputDRAM:Plaintex tWhile IPsec/IKEv 2 tunnel is activeZeroization Command Session Terminatio n RebootIPsec/IKEv2 DH Private Key:Used With

n n © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 48
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
IPsec/IKEv2 DH Shared SecretDRAM:Plaintex tWhile IPsec/IKEv 2 tunnel is activeZeroization Command Session Terminatio n RebootSKEYSEED:Used With
IPsec/IKEv2 ECDH Private KeyDRAM:Plaintex tWhile IPsec/IKEv 2 tunnel is activeZeroization Command Session Terminatio n RebootIPsec/IKEv2 ECDH Public Key:Paired With IPsec/IKEv2 Peer ECDH Public Key:Used With
IPsec/IKEv2 ECDH Public KeyModule Public Key OutputDRAM:Plaintex tWhile IPsec/IKEv 2 tunnel is activeZeroization Command Session Terminatio n RebootIPsec/IKEv2 ECDH Private Key:Paired With
IPsec/IKEv2 Peer ECDH Public KeyPeer Public Key InputDRAM:Plaintex tWhile IPsec/IKEv 2 tunnel is activeZeroization Command Session Terminatio n RebootIPsec/IKEv2 ECDH Private Key:Used With
IPsec/IKEv2 ECDH Shared SecretDRAM:Plaintex tWhile IPsec/IKEv 2 tunnel is activeZeroization Command Session Terminatio n RebootIPsec/IKEv2 ECDH Private Key:Derived From IPsec/IKEv2 Peer ECDH Public Key:Derived From SKEYSEED:Used With
IPsec/IKEv2 RSA Private KeyFlash:PlaintextZeroization CommandIPsec/IKEv2 RSA Public Key:Paired With
IPsec/IKEv2 RSA Public KeyModule Public Key Output Secret Input via TLS encrypte d by GCM Secret Input via TLSFlash:PlaintextZeroization CommandIPsec/IKEv2 RSA Private Key:Paired With

n n n © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 49
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
encrypte d by AES and HMAC
IPsec/IKEv2 ECDSA Private KeyFlash:PlaintextZeroization CommandIPsec/IKEv2 ECDSA Public Key:Paired With
IPsec/IKEv2 ECDSA Public KeyModule Public Key Output Secret Input via TLS encrypte d by GCM Secret Input via TLS encrypte d by AES and HMACFlash:PlaintextZeroization CommandIPsec/IKEv2 ECDSA Private Key:Paired With
IPsec/IKEv2 Pre-Shared KeySecret Input via TLS encrypte d by GCM Secret Input via TLS encrypte d by AES and HMACFlash:PlaintextZeroization CommandSKEYSEED:Derive d to
SKEYSEEDDRAM:Plaintex tWhile IPsec/IKEv 2 tunnel is activeZeroization Command Session Terminatio n RebootIPsec/IKEv2 DH Shared Secret:Derived From IPsec/IKEv2 ECDH Shared Secret:Derived From IPsec/IKEv2 Pre- Shared Key:Derived From

© 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 50
NameInput - OutputStorageStorage DurationZeroizatio nRelated SSPs
IPsec/IKEv2 Session Encryption KeyDRAM:Plaintex tWhile IPsec/IKEv 2 tunnel is activeZeroization Command Session Terminatio n RebootSKEYSEED:Derive d From
IPsec/IKEv2 Authentication KeyDRAM:Plaintex tWhile IPsec/IKEv 2 tunnel is activeZeroization Command Session Terminatio n RebootSKEYSEED:Derive d From
SNMPv3 Authentication / Privacy PasswordSecret Input via TLS encrypte d by GCM Secret Input via TLS encrypte d by AES and HMACFlash:PlaintextZeroization CommandSNMPv3 Encryption Key:Derived to SNMPv3 Authentication Key:Derived to
SNMPv3 Encryption KeyDRAM:Plaintex tWhile SNMPv3 tunnel is activeZeroization Command Session Terminatio n RebootSNMPv3 Authentication/ Privacy Password:Derived From SNMPv3 Authentication Key:Used With
SNMPv3 Authentication KeyDRAM:Plaintex tWhile SNMPv3 tunnel is activeZeroization Command Session Terminatio n RebootSNMPv3 Authentication/ Privacy Password:Derived From SNMPv3 Encryption Key:Used With
9.5 Transitions

SHA-1 © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 51
Algorithm or TestTest PropertiesTest MethodTest TypeIndicatorDetails
RSA SigVer (FIPS186-4) (A4595)RSA 2048 SigVer with SHA2-512KATSW/FW IntegrityModule is in normal stateRSA SigVer
Algorithm or TestTest Propertie sTest Metho dTest TypeIndicat orDetailsCondition s
AES-CBC encrypt KAT (A4595)256 bitsKATCAS TModule is in normal stateEncryptPower up
AES-CBC decrypt KAT (A4595)256 bitsKATCAS TModule is in normal stateDecryptPower up

The module includes an implementation of SHA-1 for hashing and digital signature verification. This implementation will be non-Approved for all uses starting January 1, 2031 FIPS 186-4/186-5 As of February 5, 2024, the CMVP does not accept module submissions that implement DSA or RSA X9.31 in the approved mode, other than for signature verification which is approved for legacy use. This module does not implement DSA or RSA X9.31 for signature generation and therefore is unaffected by the current transition from 186-4 to 186-5. As detailed in section 2.7, the CAVP testing performed on the 186-4 algorithms is mathematically similar to the testing performed on the 186-5 algorithms and therefore this module claims compliance with 186-5. This means that no timeline exists in which any of the implemented algorithms will transition from approved to non-approved.

10 Self-Tests
10.1 Pre-Operational Self-Tests

Table 20: Pre-Operational Self-Tests The module performs the following self-tests, including Pre-operational and Conditional selftests. Prior to the module providing any data output via the data output interface, the module performs and passes the pre-operational self-tests. Following the successful pre-operational self-tests, the module executes the Conditional Cryptographic Algorithm Self-tests (CASTs). The self-test success or failure results are an output of the return value of the library load API call, which is functioning as the self-test status indicator. If anyone of the self-tests fails, the module transitions into an error state and outputs the error message via the module’s status output interface. While the module is in the error state, all data through the data output interface and all cryptographic operations are disabled. The error state can only be cleared by reloading the module. All self-tests must be completed successfully before the module transitions to the operational state.

10.2 Conditional Self-Tests

s d © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 52
Algorithm or TestTest Propertie sTest Metho dTest TypeIndicat orDetailsCondition s
AES-GCM authenticated encrypt KAT (A4595)256 bitsKATCAS TModule is in normal stateAuthenticat ed EncryptPower up
AES-GCM authenticated decrypt KAT (A4595)256 bitsKATCAS TModule is in normal stateAuthenticat ed DecryptPower up
Counter DRBG Instantiate/Generate/Res eed KAT (A4595)AES-128KATCAS TModule is in normal stateInstantiate, Generate, and Reseed KATsPower up
ECDSA SigGen (FIPS186-4) KAT (A4595)Curve P- 256 with SHA2- 256KATCAS TModule is in normal stateECDSA SigGen KATPower up
ECDSA SigVer (FIPS186-4) KAT (A4595)Curve P- 256 with SHA2- 256KATCAS TModule is in normal stateECDSA SigVer KATPower up
Entropy Source RCT Start-up Health TestsRepetitio n Count Test (RCT)RCTCAS TModule is in normal stateN/APower up
Entropy Source APT Start-up Health TestsAdaptive Proportio n Test (APT)APTCAS TModule is in normal stateN/APower up
Entropy Source RCT Continuous Health TestsRepetitio n Count Test (RCT)RCTCAS TModule is in normal stateN/APerformed continuous ly as entropy source is active
Entropy Source APT Continuous Health TestsAdaptive Proportio n Test (APT)APTCAS TModule is in normal stateN/APerformed continuous ly as entropy source is active
HMAC-SHA-1 KAT (A4595)SHA-1KATCAS TModule is in normal stateN/APower up
HMAC-SHA2-224 KAT (A4595)SHA2- 224KATCAS TModule is inN/APower up

s d © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 53
Algorithm or TestTest Propertie sTest Metho dTest TypeIndicat or normal stateDetailsCondition s
HMAC-SHA2-256 KAT (A4595)SHA2- 256KATCAS TModule is in normal stateN/APower up
HMAC-SHA2-384 KAT (A4595)SHA2- 384KATCAS TModule is in normal stateN/APower up
HMAC-SHA2-512 KAT (A4595)SHA2- 512KATCAS TModule is in normal stateN/APower up
KAS-ECC-SSC Sp800- 56Ar3 KAT (A4595)Curve P- 256KATCAS TModule is in normal statePrimitive Z KATPower up
KAS-FFC-SSC Sp800- 56Ar3 KAT (A4595)MODP- 2048KATCAS TModule is in normal statePrimitive Z KATPower up
KDF IKEv2 KAT (A4595)N/AKATCAS TModule is in normal stateN/APower up
KDF SNMP KAT (A4595)N/AKATCAS TModule is in normal stateN/APower up
KDF SSH KAT (A4595)N/AKATCAS TModule is in normal stateN/APower up
RSA SigGen (FIPS186-4) KAT (A4595)2048 bit modulus with SHA2- 256KATCAS TModule is in normal stateRSA SigGen KATPower up
RSA SigVer (FIPS186-4) KAT (A4595)2048 bit modulus with SHA2- 256KATCAS TModule is in normal stateRSA SigVer KATPower up
TLS v1.2 KDF RFC7627 KAT (A4595)N/AKATCAS TModule is inN/APower up

s d © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 54
Algorithm or TestTest Propertie sTest Metho dTest TypeIndicat or normal stateDetailsCondition s
ECDSA KeyGen (FIPS186-4) PCT (A4595)Curve P- 256 with SHA2- 256PCTPCTModule is in normal stateECDSAPerforms all required pair-wise consistenc y tests on the newly generated key pairs before the first operational use.
KAS-ECC-SSC Sp800- 56Ar3 PCT (A4595)Curve P- 256 with SHA2- 256PCTPCTModule is in normal stateN/APerforms all required pair-wise consistenc y tests on the newly generated key pairs before the first operational use.
KAS-FFC-SSC Sp800- 56Ar3 PCT (A4595)MODP- 2048PCTPCTModule is in normal stateN/APerforms all required pair-wise consistenc y tests on the newly generated key pairs before the first operational use.
RSA KeyGen (FIPS186- 4) PCT (A4595)2048 bit modulusPCTPCTModule is in normal stateRSAPerforms all required pair-wise consistenc y tests on the newly generated key pairs before the

s d © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 55

Algorithm or Test

Test Propertie s

Test Metho d

Test Type

Indicat or

Details

Condition s first operational use.

Algorithm or TestTest MethodTest TypePeriodPeriodic Method
RSA SigVer (FIPS186-4) (A4595)KATSW/FW IntegrityRecommend 60 DaysReboot
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
AES-CBC encrypt KAT (A4595)KATCASTRecommend 60 DaysReboot
AES-CBC decrypt KAT (A4595)KATCASTRecommend 60 DaysReboot
AES-GCM authenticated encrypt KAT (A4595)KATCASTRecommend 60 DaysReboot
AES-GCM authenticated decrypt KAT (A4595)KATCASTRecommend 60 DaysReboot
Counter DRBG Instantiate/Generate/Reseed KAT (A4595)KATCASTRecommend 60 DaysReboot
ECDSA SigGen (FIPS186-4) KAT (A4595)KATCASTRecommend 60 DaysReboot
ECDSA SigVer (FIPS186-4) KAT (A4595)KATCASTRecommend 60 DaysReboot
Entropy Source RCT Start- up Health TestsRCTCASTRecommend 60 DaysReboot
Entropy Source APT Start- up Health TestsAPTCASTRecommend 60 DaysReboot
Entropy Source RCT Continuous Health TestsRCTCASTN/AN/A
Entropy Source APT Continuous Health TestsAPTCASTN/AN/A
HMAC-SHA-1 KAT (A4595)KATCASTRecommend 60 DaysReboot

s d Table 21: Conditional Self-Tests The module performs on-demand self-tests initiated by the operator, by powering off and powering the module back on. The full suite of self-tests is then executed. The same procedure may be employed by the operator to perform periodic self-tests.

10.3 Periodic Self-Test Information

Table 22: Pre-Operational Periodic Information © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 56
Algorithm or TestTest MethodTest TypePeriodPeriodic Method
HMAC-SHA2-224 KAT (A4595)KATCASTRecommend 60 DaysReboot
HMAC-SHA2-256 KAT (A4595)KATCASTRecommend 60 DaysReboot
HMAC-SHA2-384 KAT (A4595)KATCASTRecommend 60 DaysReboot
HMAC-SHA2-512 KAT (A4595)KATCASTRecommend 60 DaysReboot
KAS-ECC-SSC Sp800- 56Ar3 KAT (A4595)KATCASTRecommend 60 DaysReboot
KAS-FFC-SSC Sp800- 56Ar3 KAT (A4595)KATCASTRecommend 60 DaysReboot
KDF IKEv2 KAT (A4595)KATCASTRecommend 60 DaysReboot
KDF SNMP KAT (A4595)KATCASTRecommend 60 DaysReboot
KDF SSH KAT (A4595)KATCASTRecommend 60 DaysReboot
RSA SigGen (FIPS186-4) KAT (A4595)KATCASTRecommend 60 DaysReboot
RSA SigVer (FIPS186-4) KAT (A4595)KATCASTRecommend 60 DaysReboot
TLS v1.2 KDF RFC7627 KAT (A4595)KATCASTRecommend 60 DaysReboot
ECDSA KeyGen (FIPS186- 4) PCT (A4595)PCTPCTRecommend 60 DaysReboot
KAS-ECC-SSC Sp800- 56Ar3 PCT (A4595)PCTPCTRecommend 60 DaysReboot
KAS-FFC-SSC Sp800- 56Ar3 PCT (A4595)PCTPCTRecommend 60 DaysReboot
RSA KeyGen (FIPS186-4) PCT (A4595)PCTPCTRecommend 60 DaysReboot
NameDescriptionConditionsRecovery MethodIndicator
Error StateIf self-test tests fail, the module is put into an error state.Self-test failureReboot the moduleSystem halt

Table 23: Conditional Periodic Information The module performs on-demand self-tests initiated by the operator, by powering off and powering the module back on. The full suite of self-tests is then executed. The same procedure may be employed by the operator to perform periodic self-tests.

10.4 Error States

Table 24: Error States © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.

Page 57

If any of the above-mentioned self-tests fail, the module reports the error and enters the Error state. In the Error State, no cryptographic services are provided, and data output is prohibited. The only method to recover from the error state is to reboot the module and perform the selftests, including the pre-operational integrity test and the conditional CASTs. The module will only enter into the operational state after successfully passing the pre-operational integrity test and the conditional CASTs.

11 Life-Cycle Assurance
11.1 Installation, Initialization, and Startup Procedures

The module meets all the Level 1 requirements for FIPS 140-3. The Crypto Officer must configure and enforce the following initialization steps. Operating this module without maintaining the following settings will put the module into a non-compliant state. Step 1: Log in with the default username admin and the password Admin123. Step 2: The first time you log in to the Module, you are prompted to accept the End User License Agreement (EULA) and to change the admin password. You will be prompted with the CLI setup wizard. See the following guidelines:

Page 58
11.2 Administrator Guidance

No specific Administrator guidance.

11.3 Non-Administrator Guidance

No specific Non-Administrator guidance.

12 Mitigation of Other Attacks

N/A for this module. © 2021-2026 Cisco Systems, Inc. Cisco Systems logo is registered trademark of Cisco Systems, Inc.