808bits

Red Hat Enterprise Linux Kernel Crypto API Cryptographic Module v4.0 with CPACF

FIPS 140-2 certificate #2798 · Red Hat®, Inc. · data as of 2026-08-28
Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode with modules Red Hat Enterprise Linux NSS Cryptographic Module v4.0 validated to FIPS 140-2 under Cert. #2711 operating in FIPS mode and Red Hat Enterprise Linux Libreswan Cryptographic Module v4.0 validated to FIPS 140-2 under Cert. #2721 operating in FIPS mode. The module generates random strings whose strengths are modified by available entropy

Certificate

Certificate number2798
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware-Hybrid
EmbodimentMulti-Chip Stand Alone
VendorRed Hat®, Inc. · website
Software versions4.0
Hardware versionsCOP chips integrated within processor unit
Firmware versionsFeature 3863 (aka FC3863) with System Driver Level 22H

Module description

The Linux kernel Crypto API implemented in Red Hat Enterprise Linux 7.1 provides services operating inside the Linux kernel with various ciphers, message digests and an approved random number generator.

Security level exceptions

  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES3570, 3591, 3861, 3862, 3863
DRBG916, 925, 1095, 1096, 1097
HMAC2276, 2508
RSA1838, 1971
SHS2938, 3183
Triple-DES1990, 2129, 2130

Other algorithms

DES; GHASH; PRNG; SHS (non-compliant)

Tested configurations

  • Red Hat Enterprise Linux 7.1 running on IBM z13 (single-user mode)

Validation history

DateTypeLab
2016-11-23Initialatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2016-11-23

Source documents