Red Hat Enterprise Linux Kernel Crypto API Cryptographic Module v4.0 with CPACF
Caveat: When operated in FIPS mode with modules Red Hat Enterprise Linux NSS Cryptographic Module v4.0 validated to FIPS 140-2 under Cert. #2711 operating in FIPS mode and Red Hat Enterprise Linux Libreswan Cryptographic Module v4.0 validated to FIPS 140-2 under Cert. #2721 operating in FIPS mode. The module generates random strings whose strengths are modified by available entropy
Certificate
| Certificate number | 2798 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 1 |
| Module type | Software-Hybrid |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Red Hat®, Inc. · website |
| Software versions | 4.0 |
| Hardware versions | COP chips integrated within processor unit |
| Firmware versions | Feature 3863 (aka FC3863) with System Driver Level 22H |
Module description
The Linux kernel Crypto API implemented in Red Hat Enterprise Linux 7.1 provides services operating inside the Linux kernel with various ciphers, message digests and an approved random number generator.
Security level exceptions
- Mitigation of Other Attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | 3570, 3591, 3861, 3862, 3863 |
| DRBG | 916, 925, 1095, 1096, 1097 |
| HMAC | 2276, 2508 |
| RSA | 1838, 1971 |
| SHS | 2938, 3183 |
| Triple-DES | 1990, 2129, 2130 |
Other algorithms
DES; GHASH; PRNG; SHS (non-compliant)
Tested configurations
- Red Hat Enterprise Linux 7.1 running on IBM z13 (single-user mode)
Validation history
| Date | Type | Lab |
|---|---|---|
| 2016-11-23 | Initial | atsec information security corporation |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2016-11-23