Amazon Linux 2 Kernel Crypto API Cryptographic Module
Caveat: When operated in FIPS mode with module Amazon Linux 2 NSS Cryptographic Module validated to FIPS 140-2 under Cert. #3646 operating in FIPS mode
Certificate
| Certificate number | 3709 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Amazon Web Services, Inc. · website |
| Software versions | 1.0 |
Module description
The Linux kernel Crypto API implemented in the Amazon Linux 2 provides services operating inside the Linux kernel with various ciphers, message digests and an approved random number generator.
Security level exceptions
- Physical Security: N/A
- Mitigation of Other Attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | C911, C912, C913, C914, C915, C917 |
| CVL | C923 |
| DRBG | C911, C913, C915, C918, C919, C920, C921 |
| HMAC | C803, C918, C919, C920, C921, C923 |
| KTS | |
| KTS | |
| RSA | C918, C919, C920, C921, C923 |
| SHA-3 | C923 |
| SHS | C918, C919, C920, C921 |
| Triple-DES | C923 |
Allowed algorithms
Diffie-Hellman (CVL Cert. #C923; shared secret computation provides between 112 and 256 bits of encryption strength); NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 256 bits of encryption strength)
Tested configurations
- Amazon Linux 2 running on Amazon EC2 i3.metal with Intel Xeon E5-2686 with PAA
- Amazon Linux 2 running on Amazon EC2 i3.metal with Intel Xeon E5-2686 without PAA (single-user mode)
Validation history
| Date | Type | Lab |
|---|---|---|
| 2020-09-14 | Initial | atsec information security corporation |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2020-09-14