808bits

Red Hat Enterprise Linux OpenSSH Client Cryptographic Module

FIPS 140-2 certificate #2633 · Red Hat®, Inc. · data as of 2026-09-13

Red Hat Enterprise Linux OpenSSH Client Cryptographic Module, from Red Hat®, Inc., holds FIPS 140-2 certificate #2633 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode with module Red Hat Enterprise Linux 7.1 OpenSSL Module validated to FIPS 140-2 under Cert. #2441 operating in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy

Certificate

Certificate number2633
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorRed Hat®, Inc. · website
Software versions4.0

Module description

Quoted from the NIST CMVP entry for this certificate.

The OpenSSH Client cryptographic module provides the client-side component for an SSH protocol version 2 protected communication channel. OpenSSH is the standard SSH implementation and shipped with RHEL 7.1. Its cryptographic mechanisms use the OpenSSL library in FIPS 140-2 mode.

Security level exceptions

  • Physical Security: N/A
  • Mitigation of Other Attacks: N/A

Approved algorithms (1)

AlgorithmCAVP certificates
CVL700, 701, 702

Tested configurations

  • Red Hat Enterprise Linux 7.1 running on IBM Power8 Little Endian 8286-41A
  • Red Hat Enterprise Linux 7.1 running on IBM z13 with CP Assist for Cryptographic Functions (single-user mode)
  • Red Hat Enterprise Linux 7.1 running on ProLiant DL380p Gen8 with PAA
  • Red Hat Enterprise Linux 7.1 running on ProLiant DL380p Gen8 without PAA

Validation history

DateTypeLab
2016-05-12Initialatsec information security corporation
2016-06-17Updateatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2016-05-12, 2016-06-17

Source documents