808bits

Amazon Linux 2 OpenSSH Server Cryptographic Module

FIPS 140-2 certificate #3562 · Amazon Web Services, Inc. · data as of 2026-09-15

Amazon Linux 2 OpenSSH Server Cryptographic Module, from Amazon Web Services, Inc., holds FIPS 140-2 certificate #3562 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. SP 800-56Arev3 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode with module Amazon Linux 2 OpenSSL Cryptographic Module validated to FIPS 140-2 under Cert. #3553 operating in FIPS mode

Certificate

Certificate number3562
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorAmazon Web Services, Inc. · website
Software versions1.0

Module description

Quoted from the NIST CMVP entry for this certificate.

Amazon Linux 2 OpenSSH Server Cryptographic Module is a software module implementing the SSH protocol and acts as a server daemon.

Security level exceptions

  • Physical Security: N/A
  • Mitigation of Other Attacks: N/A

Approved algorithms (10)

AlgorithmCAVP certificates
AESC523, C524, C525
CVLC523, C562
DRBGC523, C524, C525
DSAC523
ECDSAC523
HMACC523, C524, C525, C526
KTS
RSAC523
SHSC523, C524, C525, C526
Triple-DESC523

Allowed algorithms

Diffie-Hellman (CVL Cert. #C523 with CVL Cert. #C562, key agreement; key establishment methodology provides between 112 and 202 bits of encryption strength); EC Diffie-Hellman (CVL Cert. #C523 with CVL Cert. #C562, key agreement; key establishment methodology provides between 128 and 256 bits of encryption strength); NDRNG

Tested configurations

  • Amazon Linux 2 running on Amazon EC2 i3.metal with Intel Xeon E5-2686 with PAA
  • Amazon Linux 2 running on Amazon EC2 i3.metal with Intel Xeon E5-2686 without PAA (single-user mode)

Validation history

DateTypeLab
2019-11-14Initialatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2019-11-14

Source documents