808bits

Red Hat Enterprise Linux NSS Cryptographic Module v4.0

FIPS 140-2 certificate #2711 · Red Hat®, Inc. · data as of 2026-08-28
Historical. SP 800-56Arev3 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy

Certificate

Certificate number2711
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorRed Hat®, Inc. · website
Software versions4.0

Module description

Network Security Services (NSS) is a set of open source C libraries designed to support cross-platform development of security-enabled applications. NSS implements major Internet security standards. NSS is available free of charge under a variety of open source compatible licenses. See http://www.mozilla.org/projects/security/pki/nss/

Security level exceptions

  • Roles, Services, and Authentication: Level 2
  • Physical Security: N/A
  • Design Assurance: Level 2

Approved algorithms

AlgorithmCAVP certificate
AES3604, 3605, 3606, 3607, 3608, 3609, 3610
CVL625, 626, 627, 628, 629
DRBG935, 936, 937, 938, 940
DSA1001, 1002, 1003, 1004, 1005
ECDSA738, 739, 740, 741, 742
HMAC2299, 2300, 2301, 2303, 2305
RSA1853, 1854, 1855, 1856, 1857, 2031, 2032, 2033, 2034, 2035
SHS2965, 2966, 2967, 2969, 2971
Triple-DES2006, 2007, 2008, 2009, 2010

Other algorithms

AES (Certs. #3604, #3605, #3606, #3607, #3608, #3609 and #3610, key unwrapping); Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength; non-compliant less than 112 bits of encryption strength); EC Diffie-Hellman (key agreement; key establishment methodology provides between 128 and 256 bits of encryption strength); RSA (key wrapping; key establishment methodology provides between 112 and 256 bits of encryption strength; non-compliant less than 112 bits of encryption strength); Triple-DES (Certs. #2006, #2007, #2008, #2009 and #2010, key unwrapping)

Tested configurations

  • Red Hat Enterprise Linux 7.1 running on HP ProLiant DL380p Gen8 with PAA
  • Red Hat Enterprise Linux 7.1 running on HP ProLiant DL380p Gen8 without PAA
  • Red Hat Enterprise Linux 7.1 running on IBM POWER8 Little Endian 8286-41A
  • Red Hat Enterprise Linux 7.1 running on IBM z13 (single-user mode)

Validation history

DateTypeLab
2016-08-15Initialatsec information security corporation
2016-12-19Updateatsec information security corporation
2018-01-30Updateatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2016-08-15, 2016-12-19, 2018-01-30

Source documents