Red Hat Enterprise Linux 5 OpenSSL Cryptographic Module
Caveat: When operated in FIPS mode. When obtained, installed, and initialized as assumed by the Crypto Officer role and specified in Section 9.1 of the provided Security Policy. The Security Policy specifies the precise RPM file containing this module. The integrity of the RPM is automatically verified during the installation and the Crypto officer shall not install the module if the RPM tool indicates an integrity error. Any deviation from the specified verification, installation and initialization procedures will result in a non FIPS 140-2 compliant module.
Certificate
| Certificate number | 1320 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-chip standalone |
| Vendor | Red Hat®, Inc. · website |
| Software versions | 1.1 |
Module description
The OpenSSL FIPS Runtime Module is a general purpose cryptographic library designed to provide FIPS 140-2 validated cryptographic functionality for use with the high level API of the OpenSSL library version 0.9.8 delivered with RHEL 5.4 or RHEL 5.8.
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | 1160, 1161, 1162 |
| DSA | 378, 379, 380 |
| HMAC | 661, 662, 663 |
| RNG | 642, 643, 644 |
| RSA | 549, 550, 551 |
| SHS | 1073, 1074, 1075 |
| Triple-DES | 839, 840, 841 |
Other algorithms
Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 219 bits of encryption strength; non-compliant less than 112 bits of encryption strength); RSA (key wrapping; key establishment methodology provides between 112 and 256 bits of encryption strength; non-compliant less than 112 bits of encryption strength); MD5
Tested configurations
- Red Hat Enterprise Linux 5.4 and Red Hat Enterprise Linux 5.8 (single-user mode)
Validation history
| Date | Type | Lab |
|---|---|---|
| 2010-06-09 | Initial | atsec information security corporation |
| 2012-06-14 | Update | atsec information security corporation |
| 2012-09-06 | Update | atsec information security corporation |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2010-06-09, 2012-06-14, 2012-09-06