808bits

Red Hat Enterprise Linux 8 OpenSSL Cryptographic Module

FIPS 140-2 certificate #3842 · Red Hat®, Inc. · data as of 2026-08-28
Historical. SP 800-56Arev3 transition - replaced by certificate #4271. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy

Certificate

Certificate number3842
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorRed Hat®, Inc. · website
Software versionsrhel8.20200305.1

Module description

The OpenSSL FIPS Runtime Module is a general purpose cryptographic library designed to provide FIPS 140-2 validated cryptographic functionality for use with the high level API of the OpenSSL library.

Security level exceptions

  • Physical Security: N/A

Approved algorithms

AlgorithmCAVP certificate
AESA549, A550, A551, A552, A554, A555, A556, A562, A563, A564, A565, A566, A567, A568, A569, A570
CVLA549, A550, A551, A552, A558, A559, A560, A561, A580
DRBGA554, A555, A556, A581
DSAA558, A559, A560, A561
ECDSAA558, A559, A560, A561
HMACA546, A547, A548, A558, A559, A560, A561
KDAvendor affirmed
KTS
KTS
KTS
PBKDFvendor affirmed
RSAA558, A559, A560, A561
SHA-3A546, A547, A548
SHSA558, A559, A560, A561
Triple-DES

Allowed algorithms

Diffie-Hellman (CVL Cert. #A580 with CVL Certs. #A558, #A559, #A560 and #A561, key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength); EC Diffie-Hellman (CVL Certs. #A558, #A559, #A560 and #A561 with CVL Certs. #A558, #A559, #A560 and #A561, key agreement; key establishment methodology provides between 128 and 256 bits of encryption strength); MD5; NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 256 bits of encryption strength)

Tested configurations

  • Red Hat Enterprise Linux 8 running on Dell PowerEdge R430 with an Intel(R) Xeon(R) E5 with PAA
  • Red Hat Enterprise Linux 8 running on Dell PowerEdge R430 with an Intel(R) Xeon(R) E5 without PAA (single-user mode)

Validation history

DateTypeLab
2021-03-08Initialatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2021-03-08

Source documents