Red Hat Enterprise Linux 6.6 Kernel Crypto API Cryptographic Module
Red Hat Enterprise Linux 6.6 Kernel Crypto API Cryptographic Module, from Red Hat®, Inc., holds FIPS 140-2 certificate #2582 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.
Caveat: When operated in FIPS mode with Network Security Services (NSS) Module validated to FIPS 140-2 under Cert. #2564 operating in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy
Certificate
| Certificate number | 2582 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Red Hat®, Inc. · website |
| Software versions | 3.1 |
Module description
Quoted from the NIST CMVP entry for this certificate.
The Linux kernel Crypto API implemented in Red Hat Enterprise Linux 6.6 provides services operating inside the Linux kernel with various ciphers, message digests and an approved random number generator.
Security level exceptions
- Physical Security: N/A
- Mitigation of Other Attacks: N/A
Approved algorithms (6)
| Algorithm | CAVP certificates |
|---|---|
| AES | 3145, 3146, 3147, 3148, 3149, 3150, 3151, 3152, 3218, 3219 |
| DRBG | 639, 640, 641, 642, 643, 644, 645, 646 |
| DSA | 892, 893, 894, 895, 909, 910 |
| HMAC | 1933, 1934, 1935, 1936, 1985, 1986 |
| SHS | 2607, 2608 |
| Triple-DES | 1797, 1798 |
Other algorithms
DES; SHA-256/SHA-512 (SSSE3/AVX/AVX2 implementation; non-compliant); HMAC SHA-256/SHA-512 (SSSE3/AVX/AVX2 implementation; non-compliant)
Tested configurations
- Red Hat Enterprise Linux 6.6 running on HP ProLiant DL380p Gen8 with PAA
- Red Hat Enterprise Linux 6.6 running on HP ProLiant DL380p Gen8 without PAA
- Red Hat Enterprise Linux 6.6 running on IBM System x3500 M4 with PAA
- Red Hat Enterprise Linux 6.6 running on IBM System x3500 M4 without PAA (single-user mode)
Validation history
| Date | Type | Lab |
|---|---|---|
| 2016-03-16 | Initial | atsec information security corporation |
| 2016-04-12 | Update | atsec information security corporation |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2016-03-16, 2016-04-12