To Whom It May Concern,
July 31, 2025
A compliance review of Unified Communications Manager version 15 SU3 (the product) was completed and found that the Product integrates the following FIPS 140-3 approved cryptographic modules:
- Cisco FIPS Object Module 7.3a, cert #4747
- BC-FJA (Bouncy Castle FIPS Java API), cert #4743
- Linux Kernel FIPS Object Module (KFOM) Cryptographic Module, cert #4744
Cisco confirms that the cryptographic modules listed above provide cryptographic services for the following as applicable:
- Call processing, CA services, HTTPS, SSH, IKE, IPSec, Strongswan 5.9 (#4747)
- LDAP over SSL, SOAP AXL, Disaster Recovery, Certificate Management (#4743)
- IPSec Control plane (#4744)
The review/testing confirmed that:
- The cryptographic module (mentioned above) does initialize in a manner that is compliant with its Security Policy.
- All applicable cryptographic algorithms used for session establishment are handled within the cryptographic module.
- All applicable underlying cryptographic algorithms support each service's key derivation function.
This letter has been generated in accordance with guidance provided by the Cryptographic Module Validation Program (CMVP) (https://csrc.nist.gov/Projects/cryptographic-module-validation-program/validated-modules). In general, a letter will not be generated for subsequent software releases unless a change has been made to the cryptographic module(s) noted in this letter.
The CMVP has not independently reviewed this analysis, testing or the results.
Any questions regarding these statements may be directed via e-mail to the Cisco Global Certification Team (GCT) at certteam@cisco.com.
Sincerely,
Ed Paradise,
SVP Engineering S&TO
Cisco Confidential