808bits

Ubuntu Kernel Crypto API Cryptographic Module

FIPS 140-2 certificate #2962 · Canonical Ltd. · data as of 2026-09-03

Ubuntu Kernel Crypto API Cryptographic Module, from Canonical Ltd., holds FIPS 140-2 certificate #2962 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode

Certificate

Certificate number2962
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorCanonical Ltd. · website
Software versions1.0

Module description

Quoted from the NIST CMVP entry for this certificate.

Ubuntu Kernel Crypto API module is a software module running as part of the operating system kernel that provides general purpose cryptographic services.

Security level exceptions

  • Physical Security: N/A
  • Mitigation of Other Attacks: N/A

Approved algorithms (7)

Allowed algorithms

NDRNG

Tested configurations

  • Ubuntu 16.04 LTS 64-bit Little Endian running on IBM Power System 8001-22C with PAA
  • Ubuntu 16.04 LTS 64-bit Little Endian running on IBM Power System 8001-22C without PAA
  • Ubuntu 16.04 LTS 64-bit Little Endian running on IBM Power System 8247-22L with PAA
  • Ubuntu 16.04 LTS 64-bit Little Endian running on IBM Power System 8247-22L without PAA
  • Ubuntu 16.04 LTS 64-bit Little Endian running on IBM Power System 8335-GTB with PAA
  • Ubuntu 16.04 LTS 64-bit Little Endian running on IBM Power System 8335-GTB without PAA
  • Ubuntu 16.04 LTS 64-bit running on IBM z13 with PAI
  • Ubuntu 16.04 LTS 64-bit running on IBM z13 without PAI
  • Ubuntu 16.04 LTS 64-bit running on Supermicro SMX11SPL-F with PAA
  • Ubuntu 16.04 LTS 64-bit running on Supermicro SMX11SPL-F without PAA (single-user mode)
  • Ubuntu 16.04 LTS 64-bit running on Supermicro Supermicro A1SAi with PAA
  • Ubuntu 16.04 LTS 64-bit running on Supermicro Supermicro A1SAi without PAA
  • Ubuntu 16.04 LTS 64-bit running on Supermicro SYS-5018R-WR with PAA
  • Ubuntu 16.04 LTS 64-bit running on Supermicro SYS-5018R-WR without PAA

Validation history

DateTypeLab
2017-07-18Initialatsec information security corporation
2020-03-24Updateatsec information security corporation
2021-10-18Updateatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2017-07-18, 2020-03-24, 2021-10-18

Source documents