808bits

Red Hat Enterprise Linux 6.6 NSS Module

FIPS 140-2 certificate #2564 · Red Hat®, Inc. · data as of 2026-08-28
Historical. SP 800-131A transition which disallows key wrapping not compliant to SP 800-38F.. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy

Certificate

Certificate number2564
StandardFIPS 140-2
Statushistorical
Overall level2
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorRed Hat®, Inc. · website
Software versions3.14.3-22

Module description

Network Security Services (NSS) is a set of open source C libraries designed to support cross-platform development of security-enabled applications. NSS implements major Internet security standards. NSS is available free of charge under a variety of open source compatible licenses. See http://www.mozilla.org/projects/security/pki/nss/

Security level exceptions

  • Physical Security: N/A

Approved algorithms

AlgorithmCAVP certificate
AES3076, 3077, 3078, 3079, 3080, 3081, 3082, 3083, 3084, 3085, 3086, 3087
CVL368, 369, 370, 371
DRBG603, 604, 605, 606
DSA892, 893, 894, 895
ECDSA554, 555, 556, 557
HMAC1933, 1934, 1935, 1936
RSA1577, 1578, 1579, 1580
SHS2549, 2550, 2551, 2552
Triple-DES1776, 1777, 1778, 1779

Other algorithms

AES (Certs. #3076, #3077, #3078, #3079, #3080, #3081, #3082, #3083, #3084, #3085, #3086 and #3087, key unwrapping); Diffie-Hellman (key agreement; key establishment methodology provides between 112 bits and 256 bits of encryption strength); EC Diffie-Hellman (key agreement; key establishment methodology provides between 128 and 256 bits of encryption strength); RSA (key wrapping; key establishment methodology provides between 112 bits and 256 bits of encryption strength); Triple-DES (Certs. #1776, #1777, #1778 and #1779, key unwrapping)

Tested configurations

  • Red Hat Enterprise Linux 6.6 running on ProLiant DL380p Gen8 with AES-NI
  • Red Hat Enterprise Linux 6.6 running on ProLiant DL380p Gen8 without AES-NI
  • Red Hat Enterprise Linux 6.6 running on System x3500 M4 with AES-NI
  • Red Hat Enterprise Linux 6.6 running on System x3500 M4 without AES-NI (single-user mode)

Validation history

DateTypeLab
2016-02-17Initialatsec information security corporation
2018-08-16Updateatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2016-02-17, 2018-08-16

Source documents