May 3, 2024
To Whom It May Concern
A compliance review of Cisco IOS XE Release v17.13 ("the Product") deployed in the following platforms:
- Cisco Catalyst Industrial Ethernet 9300 Series Switch
was completed and found that the Product incorporates the following FIPS 140-2 validated cryptographic module:
- FIPS Object Module (FOM) 7.2a (FIPS 140-2 Cert. #4036) https://csrc.nist.gov/projects/cryptographic-module-validation-program/certificate/4036.
Cisco confirms that the cryptographic module listed above provides cryptographic services for the following as applicable:
- SSHv2
- SNMPv3
The review/testing confirmed that:
- The cryptographic module (mentioned above) does initialize in a manner that is compliant with its Security Policy.
- All applicable cryptographic algorithms used for session establishment are handled within the cryptographic module.
- All applicable underlying cryptographic algorithms support each service's key derivation function.
This letter has been generated in accordance with guidance provided by the Cryptographic Module Validation Program (CMVP) https://csrc.nist.gov/Projects/cryptographic-module-validation-program/validated-modules.
In general, a letter will not be generated for subsequent software releases unless a change has been made to the cryptographic module(s) noted in this letter.
The CMVP has not independently reviewed this analysis, testing or the results.
Any questions regarding these statements may be directed via e-mail to the Cisco Global Certification Team (GCT) at certteam@cisco.com.