Ubuntu OpenSSH Client Cryptographic Module
Certificate
| Certificate number | 2907 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Canonical Ltd. · website |
| Software versions | 1.0[1], 1.1[2] and 1.2[3] |
Module description
Ubuntu OpenSSH Client cryptographic module provides the client-side component for an SSH protocol version 2 protected communication channel. Its cryptographic mechanisms use the OpenSSL library in FIPS 140-2 mode.
Security level exceptions
- Physical Security: N/A
- Mitigation of Other Attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | 4354, 4355, 4356, 4357, 4358, 4359, 4360, 4361, C1258, C1259, C1260, C1261, C1264, C1265, C1266, C1267, C1270 |
| CVL | 1053, 1054, 1056, 1057, 1059, 1060, 1062, 1063, 1065, 1067, 1068, 1069, 1085, 1086, 1087, 1088, 1089, 1090, 1091, C1269, C1304, C1305 |
| DRBG | 1390, 1391, 1392, 1393, 1394, 1395, 1396, 1397, C1269, C1304, C1305 |
| DSA | 1156, 1157, 1158, 1159, 1160, 1161, 1162, C1269, C1304, C1305 |
| ECDSA | 1031, 1032, 1033, 1034, 1035, 1036, 1037, C1269, C1304, C1305 |
| HMAC | 2895, 2896, 2897, 2898, 2899, 2900, 2901, C1269, C1304, C1305 |
| RSA | 2351, 2352, 2353, 2354, 2355, 2356, 2357, C1269, C1304, C1305 |
| SHS | 3593, 3594, 3595, 3596, 3597, 3598, 3599, C1269, C1304, C1305 |
| Triple-DES | 2355, 2356, 2357, C1257 |
Other algorithms
Diffie-Hellman (CVL Certs. #1053, #1056, #1059, #1062, #1065, #1067, #1069, #C1269, #C1304 and #C1305 with CVL Certs. #1085, #1086, #1087, #1088, #1089, #1090 #1091 key agreement; key establishment methodology provides between 112 and 192 bits of encryption strength); EC Diffie-Hellman (CVL Certs. #1053, #1054, #1056, #1057, #1059, #1060, #1063, #1065, #1067, #1068, #1069, #C1269, #C1304 and #C1305 with CVL Certs. #1085, #1086, #1087, #1088, #1089, #1090 and #1091 key agreement; key establishment methodology provides between 128 and 256 bits of encryption strength); NDRNG
Tested configurations
- Ubuntu 16.04 LTS 64-bit Little Endian running on IBM Power System 8001-22C with PAA [1][2]
- Ubuntu 16.04 LTS 64-bit Little Endian running on IBM Power System 8001-22C without PAA [1][2]
- Ubuntu 16.04 LTS 64-bit Little Endian running on IBM Power System 8247-22L with PAA [1][2]
- Ubuntu 16.04 LTS 64-bit Little Endian running on IBM Power System 8247-22L without PAA [1][2]
- Ubuntu 16.04 LTS 64-bit Little Endian running on IBM Power System 8335-GTB with PAA [1][2]
- Ubuntu 16.04 LTS 64-bit Little Endian running on IBM Power System 8335-GTB without PAA [1][2]
- Ubuntu 16.04 LTS 64-bit running on IBM z13 with PAI [1][2]
- Ubuntu 16.04 LTS 64-bit running on IBM z13 without PAI [1][2] (single-user mode)
- Ubuntu 16.04 LTS 64-bit running on Supermicro SYS-5018R-WR with PAA [1][2][3]
- Ubuntu 16.04 LTS 64-bit running on Supermicro SYS-5018R-WR without PAA [1][2][3]
Validation history
| Date | Type | Lab |
|---|---|---|
| 2017-05-10 | Initial | atsec information security corporation |
| 2019-08-09 | Update | atsec information security corporation |
| 2021-03-23 | Update | atsec information security corporation |
| 2021-10-18 | Update | atsec information security corporation |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2017-05-10, 2019-08-09, 2021-03-23, 2021-10-18