808bits

Ubuntu Strongswan Cryptographic Module

FIPS 140-2 certificate #2978 · Canonical Ltd. · data as of 2026-08-28
Historical. Moved to historical list due to dependency on certificate #2888. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode with module Ubuntu OpenSSL Cryptographic Module validated to FIPS 140-2 under Cert. #2888 operating in FIPS mode and with module Ubuntu Kernel Crypto API Cryptographic Module validated to FIPS140-2 under Cert. #2962 operating in FIPS mode

Certificate

Certificate number2978
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorCanonical Ltd. · website
Software versions1.0 and 1.1

Module description

Ubuntu Strongswan Cryptographic Module provides cryptographic services for the Internet Key Exchange (IKE) protocol in the Ubuntu Operating System user space.

Security level exceptions

  • Physical Security: N/A
  • Mitigation of Other Attacks: N/A

Approved algorithms

Allowed algorithms

Diffie-Hellman (CVL Certs. #1053, #1056, #1059, #1062, #1065, #1067 and #1069; key agreement; key establishment methodology provides between 112 and 192 bits of encryption strength); EC Diffie-Hellman (CVL Certs. #1053, #1054, #1056, #1057, #1059, #1060, #1063, #1065, #1067, #1068 and #1069; key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength); NDRNG

Tested configurations

  • Ubuntu 16.04 LTS 64-bit Little Endian running on IBM Power System 8001-22C with PAA
  • Ubuntu 16.04 LTS 64-bit Little Endian running on IBM Power System 8001-22C without PAA
  • Ubuntu 16.04 LTS 64-bit Little Endian running on IBM Power System 8247-22L with PAA
  • Ubuntu 16.04 LTS 64-bit Little Endian running on IBM Power System 8247-22L without PAA
  • Ubuntu 16.04 LTS 64-bit Little Endian running on IBM Power System 8335-GTB with PAA
  • Ubuntu 16.04 LTS 64-bit Little Endian running on IBM Power System 8335-GTB without PAA
  • Ubuntu 16.04 LTS 64-bit running on IBM z13 with PAI
  • Ubuntu 16.04 LTS 64-bit running on IBM z13 without PAI (single-user mode)
  • Ubuntu 16.04 LTS 64-bit running on Supermicro SYS-5018R-WR with PAA
  • Ubuntu 16.04 LTS 64-bit running on Supermicro SYS-5018R-WR without PAA

Validation history

DateTypeLab
2017-07-31Initialatsec information security corporation
2019-08-27Updateatsec information security corporation
2021-10-18Updateatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2017-07-31, 2019-08-27, 2021-10-18

Source documents