Red Hat Enterprise Linux OpenSSH Client Cryptographic Module
Certificate
| Certificate number | 3067 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Red Hat®, Inc. · website |
| Software versions | 5.0 [1], 6.0 [2] |
Module description
The OpenSSH Server cryptographic module provides the server-side component for an SSH protocol version 2 protected communication channel. OpenSSH is the standard SSH implementation and shipped with RHEL 7. Its cryptographic mechanisms use the OpenSSL library in FIPS 140-2 mode.
Security level exceptions
- Physical Security: N/A
- Mitigation of Other Attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | 4644, 4664, 4666, 4667, 4695, 4696, 4697, 4698, 4699, 4700, 5203, 5204, 5205, 5207, 5208, 5209, 5210, 5211, 5212, 5227 |
| CVL | 1298, 1312, 1318, 1320, 1361, 1687, 1689, 1693, 1700, 1718 |
| DRBG | 1567, 1576, 1578, 1579, 1593, 1594, 1595, 1596, 1597, 1598, 1975, 1976, 1977, 1979, 1980, 1981, 1982, 1983, 1984, 1993 |
| ECDSA | 1144, 1148, 1150, 1151, 1347, 1348, 1350, 1353 |
| HMAC | 3076, 3088, 3090, 3091, 3107, 3108, 3109, 3110, 3111, 3112, 3445, 3446, 3447, 3449, 3450, 3451, 3452, 3453, 3454, 3459 |
| RSA | 2535, 2544, 2546, 2547, 2786, 2787, 2789, 2792 |
| SHS | 3807, 3821, 3823, 3824, 3842, 3843, 3844, 3845, 3846, 3847, 4193, 4194, 4195, 4197, 4198, 4199, 4200, 4201, 4202, 4207 |
| Triple-DES | 2471, 2481, 2483, 2484, 2638, 2639, 2641, 2642 |
Allowed algorithms
Diffie-Hellman (CVL Certs. #1298, #1312, #1318, #1320, #1687, #1689, #1693 and #1700 with CVL Certs. #1361 and #1718, key agreement; key establishment methodology provides 112 or 128 bits of encryption strength); EC Diffie-Hellman (CVL Certs. #1298, #1312, #1318, #1320, #1687, #1689, #1693 and #1700 with CVL Certs. #1361 and #1718, key agreement; key establishment methodology provides between 128 and 256 bits of encryption strength); NDRNG
Tested configurations
- Red Hat Enterprise Linux 7.4 running on Dell PowerEdge R630 with PAA[1]
- Red Hat Enterprise Linux 7.4 running on Dell PowerEdge R630 without PAA [1] (single-user mode)
- Red Hat Enterprise Linux 7.5 running on Dell PowerEdge R630 with PAA [2]
- Red Hat Enterprise Linux 7.5 running on Dell PowerEdge R630 without PAA [2] (single-user mode)
Validation history
| Date | Type | Lab |
|---|---|---|
| 2017-11-27 | Initial | atsec information security corporation |
| 2018-06-15 | Update | atsec information security corporation |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2017-11-27, 2018-06-15