Page 1
Dell W-AP134 and W-AP135 Wireless Access Points with Dell AOS FIPS Firmware Non-Proprietary Security Policy FIPS 140-2 January 26, 2015 This is to advise that the Aruba Networks document entitled “FIP...
Page 2
Dell Networking W-AP134 and W-AP135 Product Images (no rebranding of the exterior, except labeling): Aruba Networks AP-134 and AP-135 Product Images: If you have questions or concerns, please contact ...
Page 3
FIPS 140-2 Non-Proprietary Security Policy for Aruba AP-134 and AP-135 Wireless Access Points Version 2.1 August 2014 Aruba Networks™ 1322 Crossman Ave. Sunnyvale, CA 94089-1113
Page 4
Copyright © 2014 Aruba Networks, Inc. Aruba Networks trademarks include ,Aruba Networks®, Aruba Wireless Networks®, the registered Aruba the Mobile Edge Company logo, Aruba Mobility Management System®...
Page 5
1 INTRODUCTION ................................................................................................................................. 5 1.1 ACRONYMS AND ABBREVIATIONS ......................
Page 6
5 CRYPTOGRAPHIC ALGORITHMS .............................................................................................. 22 6 CRITICAL SECURITY PARAMETERS ............................................
Page 7
1 Introduction This document constitutes the non-proprietary Cryptographic Module Security Policy for the Aruba AP- 134 and AP-135 Wireless Access Points with FIPS 140-2 Level 2 validation from Aruba ...
Page 8
2 Product Overview This section introduces the various Aruba Wireless Access Points, providing a brief overview and summary of the physical features of each model covered by this FIPS 140-2 security p...
Page 9
The module provides the following power interfaces: 48V DC via Power-over-Ethernet (POE) 12V DC power supply 2.1.1.3 Indicator LEDs There are 5 bicolor (power, ENET and WLAN) LEDs which operate as...
Page 10
The Aruba AP-135 is a high-performance 802.11n (3x3:3) MIMO, dual-radio (concurrent 802.11a/n + b/g/n) indoor wireless access point capable of delivering combined wireless data rates of up to 900Mbps....
Page 11
Table 2- AP-135 Indicator LEDs Label Function Action Status PWR AP power / ready status Off No power to AP Red Initial power-up condition Flashing – Green Device booting, not ready On – Green Device r...
Page 12
3 Module Objectives This section describes the assurance levels for each of the areas described in the FIPS 140-2 Standard. . 3.1 Security Levels Table 3- Security Levels Section Section Title Level 1...
Page 13
Allow 24 hours for the TEL adhesive seal to completely cure. Record the position and serial number of each applied TEL in a security log. Once applied, the TELs included with the AP cannot be surr...
Page 14
Figure 3 - AP-134 Left View Figure 4 - AP-134 Top View Figure 5 - AP-134 Right View Figure 6 - AP-134 Bottom View
Page 15
3.2.3 AP-135 TEL Placement This section displays all the TEL locations of the Aruba AP-135. The AP-135 requires a minimum of 5 TELs to be applied as follows: 3.2.3.1 To detect opening of the chassis c...
Page 16
Figure 8: AP-135 Back view Figure 9: AP-135 Left view Figure 10: AP-135 Right view Figure 11: AP-135 Top view
Page 17
Figure 12: AP-135 Bottom View 3.2.4 Inspection/Testing of Physical Security Mechanisms Table 4 - Inspection/Testing of Physical Security Mechanisms Physical Security Mechanism Recommended Test Frequen...
Page 18
Data Output Interface 10/100/1000 Ethernet Ports 802.11a/b/g/n/ac Antenna Interfaces USB 2.0 port Control Input Interface 10/100/1000 Ethernet Ports 802.11a/b/g/n/ac Antenna Interfaces Res...
Page 19
4 Roles, Authentication and Services 4.1 Roles The module supports the roles of Crypto Officer, User, and Wireless Client; no additional roles (e.g., Maintenance) are supported. Administrative operati...
Page 20
o Wireless Client role: in Mesh Remote Mesh Point FIPS AP configuration, a wireless client can create a connection to the module using WPA2 and access wireless network access services. 4.1.1 Crypto Of...
Page 21
Authentication Mechanism Strength Mechanism RSA Certificate The module supports 2048-bit RSA keys. RSA 2048 bit keys correspond to based authentication 112 bits of security. Assuming the low end of th...
Page 22
Service Description CSPs Accessed (see section 6 below for complete description of CSPs) Creation/use of secure The module supports use of 14, 21, 22, 23, 24 (read) management session between IPSec fo...
Page 23
Use of WPA pre-shared key for When the module is in advanced 25 (read) establishment of IEEE 802.11i Remote AP configuration, the keys links between the module and the wireless client are secured with...
Page 24
5 Cryptographic Algorithms FIPS-approved cryptographic algorithms have been implemented in hardware and firmware. The firmware supports the following cryptographic implementations. Aruba OS Open SSL...
Page 25
FIPS186-2: ALG[ANSIX9.31]: Key(gen)(MOD: 1024 Pub Key Values: 65537) ALG[RSASSA-PKCS1_V1_5]: SIG(gen): 1024, SHS: SHA-1/SHA-256/SHA- 384/SHA-512, 2048, SHS: SHA-1 o ECDSA (Cert. #466; non-compliant ...
Page 26
6 Critical Security Parameters The following Critical Security Parameters (CSPs) are used by the module: Table 10 - Critical Security Parameters Storage and Name CSPs type Generation Use Zeroization 1...
Page 27
7 RNG seed key FIPS 186-2 RNG Seed Derived using NON- Stored in plaintext in Seed 186-2 General key (512 bits) FIPS approved HW volatile memory. purpose (x-change RNG Zeroized on reboot. Notice); SHA-...
Page 28
14 IKEv1/IKEv2 Pre- 8-64 character pre- CO configured Stored encrypted in User and module shared key shared key Flash with the KEK. authentication during Zeroized by changing IKEv1/IKEv2 (updating) th...
Page 29
21 RSA Private Key RSA 2048 bits private Generated at time of Stored in non-volatile Used by key manufacturing by the memory (Trusted IKEv1/IKEv2 for TPM. Platform Module). device authentication Zeroi...
Page 30
30 802.11i Group 256-bit shared secret Internally derived by Stored in plaintext in Used to derive Transient Key (GTK) used to derive group AP which assumes volatile memory; multicast (multicast) encr...
Page 31
7 Self-Tests The module performs the following Self Tests after being configured into either Remote AP mode or Remote Mesh Portal mode. The module performs both power-up and conditional self-tests. In...
Page 32
o Aruba OS Crypto Module o CRNG Test to Approved RNG (FIPS 186-2 RNG) o ECDSA Pairwise Consistency Test o RSA Pairwise Consistency Test o Aruba OS Uboot Boot Loader Module o Firmware Load Test - RSA P...
Page 33
8 Secure Operation The module can be configured to be in the following FIPS approved modes of operations via corresponding Aruba Mobility Controllers that have been certificated to FIPS level 2: • Rem...
Page 34
6. If the staging controller does not provide Po E, either ensure the presence of a Po E injector for the LAN connection between the module and the controller, or ensure the presence of a DC power sup...
Page 35
represents the only exception. That is, nothing other than a Po E injector should be present between the module and the staging controller. 8. Once the module is connected to the controller by the Eth...
Page 36
a. During the provisioning process as Remote Mesh Portal, if Pre-shared key is selected to be the Remote IP Authentication Method, the IKE pre-shared key (which is at least 8 characters in length) is ...
Page 37
8. Once the module is connected to the controller by the Ethernet cable, navigate to the Configuration > Wireless > AP Installation page, where you should see an entry for the AP. Select that AP...