808bits

Ubuntu 18.04 Kernel Crypto API Cryptographic Module

FIPS 140-2 certificate #3647 · Canonical Ltd. · data as of 2026-08-28
Historical. SP 800-56Arev3 transition - replaced by certificate #4596. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode

Certificate

Certificate number3647
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorCanonical Ltd. · website
Software versions2.0

Module description

The Ubuntu 18.04 Kernel Crypto API module is a software module running as part of the operating system kernel that provides general purpose cryptographic services.

Security level exceptions

  • Physical Security: N/A
  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AESC79, C755, C756, C757, C758, C759, C760, C761, C762, C763, C764, C765, C769, C770, C771, C772, C773, C774, C775, C776, C777
CVLC755, C771
DRBGC755, C758, C761, C766, C767, C768, C771, C772, C775
HMACC755, C766, C767, C768, C771, C772
KTS
KTS
KTS
RSAC755, C766, C767, C768, C771, C772
SHA-3C755, C771
SHSC79, C755, C766, C767, C768, C771, C772
Triple-DESC79, C755, C758, C771, C772, C775

Allowed algorithms

Diffie-Hellman (Certs. #C755 and #C771; shared secret computation provides between 112 and 256 bits of encryption strength); NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 256 bits of encryption strength)

Tested configurations

  • Ubuntu 18.04 LTS 64-bit on IBM z/VM running on IBM z/14 with z14 with PAI
  • Ubuntu 18.04 LTS 64-bit on IBM z/VM running on IBM z/14 with z14 without PAI (single-user mode)
  • Ubuntu 18.04 LTS 64-bit running on Supermicro SYS-5018R-WR with Intel Xeon CPU E5 with PAA
  • Ubuntu 18.04 LTS 64-bit running on Supermicro SYS-5018R-WR with Intel Xeon CPU E5 without PAA

Validation history

DateTypeLab
2020-04-24Initialatsec information security corporation
2020-06-17Updateatsec information security corporation
2021-09-21Updateatsec information security corporation
2021-10-18Updateatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2020-04-24, 2020-06-17, 2021-09-21, 2021-10-18

Source documents