Overview
Aviatrix version 9.0 transitions from FIPS 140-2 to FIPS 140-3. The FIPS 140-3 implementation uses the OpenSSL 3.x FIPS provider for cryptographic operations, replacing the OpenSSL 1.x FIPS module used in previous versions. Starting in version 10.1, Aviatrix holds its own FIPS 140-3 certification covering the full IPsec data plane, VPN, and control plane. See FIPS 140-3 Certification Scope for what this certification covers and the Compliance Statement for certificate details.FIPS 140-3 Certification Scope
FIPS 140-3 certification coverage has expanded across releases:- Version 9.0 does not carry an Aviatrix-owned FIPS certification.
- Version 10.0 covers VPN and part, but not all, of the IPsec data plane under certificate #5231.
- Starting in version 10.1, certification covers the full IPsec data plane, VPN,
and the control plane under certificate #5231:
- Gateway-to-gateway IPsec tunnels
- Site2Cloud (S2C) IPsec connections
- VPN (UserVPN/OpenVPN)
- Controller and CoPilot control plane
Aviatrix previously held a separate FIPS 140-2 certificate covering VPN only,
on versions prior to 9.0. That certificate expired in October 2025.
Compliance Statement
Aviatrix holds a FIPS 140-3 validation certificate for the IPsec data plane, VPN, and control plane scope described in FIPS 140-3 Certification Scope:
For the full list of FIPS 140-3 approved algorithms and other certificate
details, see the certificate on the
NIST Cryptographic Module Validation Program
site.
Starting in version 9.0, the FIPS toggle at Settings > Configuration >
General displays “FIPS 140-3”. For Controller versions below 9.0, the toggle
continues to display “FIPS 140-2”.
For information about FIPS 140-2 (applicable to versions prior to 9.0), see the
FIPS 140-2 reference page
.
Enabling FIPS Mode Requires Gateway Replacement
To bring a gateway into FIPS 140-3 mode, deploy a new gateway with FIPS mode enabled instead of enabling FIPS mode on a gateway that is already deployed. See Per-Gateway FIPS Mode to check whether a specific gateway is currently running in FIPS 140-3 mode.Upgrade Requirements for FIPS-Enabled Gateways
If you attempt a software upgrade on a FIPS-enabled gateway to version 9.0, the upgrade fails with the following error:FIPS mode is enabled, and this is an upgrade to 9.0. You must perform an image upgrade to enable FIPS 140-3.The dry-run check detects this condition before the upgrade proceeds. Always run a dry-run check before upgrading FIPS-enabled gateways to version 9.0.
UserVPN CA Certificate Rotation
When the Controller is initialized, it generates a Certificate Authority (CA) that issues certificates to UserVPN gateways. Controllers originally initialized on version 7.1 or earlier generated this CA with a 1024-bit RSA key. The CA is preserved across upgrades to avoid disrupting active UserVPN users. The FIPS 140-3 TLS provider does not accept 1024-bit RSA keys, so a UserVPN gateway whose certificate chains to a 1024-bit CA cannot complete TLS handshakes after the upgrade. For instructions on rotating the UserVPN CA, see UserVPN CA Rotation (legacy docs). This procedure is distinct from Internal Service CA Rotation , which covers the CA used for control-plane and Site2Cloud (S2C) gateway identities.Per-Gateway FIPS Mode
Starting in version 9.0, FIPS mode is tracked per-gateway in addition to the global setting. Each gateway has a FIPS flag that indicates whether it was deployed with FIPS enabled. You can view the FIPS mode status for each gateway in the Gateway Details view in CoPilot.VPN Client Compatibility
FIPS 140-3 gateways require OpenVPN clients running version 2.6.0 or later.Older VPN clients that use legacy TLS settings may fail to connect to FIPS
140-3 gateways. Ensure all VPN clients are updated to OpenVPN 2.6.0 or later
before enabling FIPS 140-3.