808bits

Ubuntu 20.04 AWS Kernel Crypto API Cryptographic Module

FIPS 140-2 certificate #4132 · Canonical Ltd. · data as of 2026-09-08

Ubuntu 20.04 AWS Kernel Crypto API Cryptographic Module, from Canonical Ltd., holds FIPS 140-2 certificate #4132 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode. The module generates random strings whose strengths are modified by available entropy

Certificate

Certificate number4132
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorCanonical Ltd. · website
Software versions3.0

Module description

Quoted from the NIST CMVP entry for this certificate.

The Ubuntu 20.04 AWS Kernel Crypto API module is a software module running as part of the operating system kernel that provides general purpose cryptographic services.

Security level exceptions

  • Physical Security: N/A
  • Mitigation of Other Attacks: N/A

Approved algorithms (8)

AlgorithmCAVP certificates
AESA623, A624, A625, A626, A627, A628, A629, A630, A631, A632, A633, A634, A635, A636, A637, A638, A639, A640, A641, A642, A644
DRBGA616, A617, A618, A619, A622, A626, A627, A628, A629, A630, A631, A635, A636, A637, A638, A639, A644
HMACA616, A617, A618, A643, A644
KTS
RSAA616, A617, A618, A644
SHA-3A643
SHSA616, A617, A618, A644
Triple-DESA619, A620, A621, A622, A641, A642, A644

Allowed algorithms

NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 256 bits of encryption strength)

Tested configurations

  • Ubuntu 20.04 LTS 64-bit running on Supermicro SYS-1019P-WTR with Intel(R) Xeon(R) Gold 6226 CPU with PAA
  • Ubuntu 20.04 LTS 64-bit running on Supermicro SYS-1019P-WTR with Intel(R) Xeon(R) Gold 6226 CPU without PAA (single-user mode)

Validation history

DateTypeLab
2022-01-13Initialatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2022-01-13

Source documents