808bits

Red Hat Enterprise Linux 6.2 dm-crypt Cryptographic Module

FIPS 140-2 certificate #1933 · Red Hat®, Inc. · data as of 2026-08-28
Historical. RNG SP800-131A Revision 1 Transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode with Red Hat Enterprise Linux 6.2 OpenSSL Cryptographic Module validated to FIPS 140-2 under Cert. #1758, Red Hat Enterprise Linux 6.2 Kernel Crypto API Cryptographic Module validated to FIPS 140-2 under Cert. #1901, Red Hat Enterprise Linux 6.2 Libgcrypt Cryptographic Module validated to FIPS 140-2 under Cert. #1757 and NSS Cryptographic Module validated to FIPS 140-2 under Cert. #1837, each module shall be obtained, installed, and initialized as specified in Section 9.1 of the provided Security Policy. Section 1 of the provided Security Policies specifies the precise RPM file containing each module. The integrity of the RPM is automatically verified during the installation and the Crypto officer shall not install the RPM file if the RPM tool indicates an integrity error. Any deviation from the specified verification, installation and initialization procedures will result in a non FIPS 140-2 compliant module

Certificate

Certificate number1933
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-chip standalone
VendorRed Hat®, Inc. · website
Software versions2.0

Module description

Device-mapper is an infrastructure in the Linux kernel that provides a generic way to create virtual layers of block devices on top of real block devices. dm-crypt is a device-mapper target that provides transparent encryption of block devices using the Kernel Crypto API shipped with RHEL 6.2. The user can specify one of the symmetric ciphers, a key (of any allowed size), an IV generation mode which allows the user to create a new block device in /dev. Writes to this device will be encrypted and reads decrypted transparent to the user.

Approved algorithms

AlgorithmCAVP certificate
AES1968, 1969, 1970, 1971, 1972
DSA628, 629, 634, 635
HMAC1128, 1129, 1130, 1131, 1132, 1133, 1134, 1135, 1199, 1200
PBKDFvendor affirmed
RNG988, 991, 992, 993
SHS1657, 1658, 1659, 1660, 1661, 1662, 1663, 1664, 1725, 1726, 1741, 1742
Triple-DES1278, 1279

Other algorithms

DES; AES-CTR (non-compliant); AES-XTS (non-compliant); AES-CBC (non-compliant)

Tested configurations

  • Red Hat Enterprise Linux 6.2 with PAA running on IBM HS22
  • Red Hat Enterprise Linux 6.2 without PAA running on HP ProLiant DL585
  • Red Hat Enterprise Linux 6.2 without PAA running on IBM HS22 (single-user mode)

Validation history

DateTypeLab
2013-04-15Initialatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2013-04-15

Source documents