OpenSSL FIPS Provider
Caveat: When operated in FIPS mode. No assurance of the minimum strength of generated keys.
Certificate
| Certificate number | 4282 |
|---|---|
| Standard | FIPS 140-2 |
| Status | active |
| Sunset date | 2026-09-21 |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | The OpenSSL Project · website |
| Software versions | 3.0.8, 3.0.9 |
Module description
The OpenSSL FIPS Provider is a software library providing a C-language application program interface (API) for use by applications that require cryptographic functionality.
Security level exceptions
- Physical Security: N/A
- Design Assurance: Level 3
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | A3500, A4086 |
| CKG | vendor affirmed |
| CVL | A3500, A4086 |
| DRBG | A3500, A4086 |
| DSA | A3500, A4086 |
| ECDSA | A3500, A4086 |
| HMAC | A3500, A4086 |
| KAS-RSA-SSC | A3500, A4086 |
| KAS-SSC | A3500, A4086 |
| KBKDF | A3500, A4086 |
| KDA | A3500, A4086 |
| KMAC | A3500, A4086 |
| KTS | |
| KTS | |
| KTS | |
| KTS | |
| KTS-RSA | |
| PBKDF | A3500, A4086 |
| RSA | A3500, A4086 |
| SHA-3 | A3500, A4086 |
| SHS | A3500, A4086 |
| Triple-DES | A3500, A4086 |
Tested configurations
- Debian 11.5 running on Dell Inspiron 7591 with Intel i7 (x64) with PAA
- Debian 11.5 running on Dell Inspiron 7591 with Intel i7 (x64) without PAA
- FreeBSD 13.1 running on Dell Inspiron 7591 with Intel i7 (x64) with PAA
- FreeBSD 13.1 running on Dell Inspiron 7591 with Intel i7 (x64) without PAA
- macOS 11.5.2 running on Apple i7 Mac Mini with Intel i7 (x64) with PAA
- macOS 11.5.2 running on Apple i7 Mac Mini with Intel i7 (x64) without PAA
- macOS 11.5.2 running on Apple M1 Mac Mini with M1 with PAA
- macOS 11.5.2 running on Apple M1 Mac Mini with M1 without PAA
- Ubuntu Linux 22.04.1 LTS running on Dell Inspiron 7591 with Intel i7 (x64) with PAA
- Ubuntu Linux 22.04.1 LTS running on Dell Inspiron 7591 with Intel i7 (x64) without PAA
- Windows 10 running on Dell Inspiron 7591 with Intel i7 (x64) with PAA
- Windows 10 running on Dell Inspiron 7591 with Intel i7 (x64) without PAA (single-user mode)
Validation history
| Date | Type | Lab |
|---|---|---|
| 2022-08-23 | Initial | Acumen Security |
| 2023-03-10 | Update | Acumen Security |
| 2023-05-23 | Update | Acumen Security |
| 2024-01-22 | Update | Acumen Security |
| 2024-07-10 | Update | Acumen Security |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2022-08-23, 2023-03-10, 2023-05-23, 2024-01-22, 2024-07-10
Known CVEs in this module family (heuristic match)
Name-based association with the module's product family, not a statement about the validated boundary. See methodology.
| CVE | CVSS | Severity |
|---|---|---|
| CVE-2026-31789 | 9.8 | CRITICAL |
| CVE-2026-34182 | 9.1 | CRITICAL |
| CVE-2025-15467 | 8.8 | HIGH |
| CVE-2026-45447 | 8.8 | HIGH |
| CVE-2026-28387 | 8.1 | HIGH |
| CVE-2026-7383 | 8.1 | HIGH |
| CVE-2023-4807 | 7.8 | HIGH |
| CVE-2023-0464 | 7.5 | HIGH |
| CVE-2023-5363 | 7.5 | HIGH |
| CVE-2024-6119 | 7.5 | HIGH |
| CVE-2025-69420 | 7.5 | HIGH |
| CVE-2025-69421 | 7.5 | HIGH |
| CVE-2026-28388 | 7.5 | HIGH |
| CVE-2026-28389 | 7.5 | HIGH |
| CVE-2026-28390 | 7.5 | HIGH |
| CVE-2026-31790 | 7.5 | HIGH |
| CVE-2026-34180 | 7.5 | HIGH |
| CVE-2026-45445 | 7.5 | HIGH |
| CVE-2026-9076 | 7.5 | HIGH |
| CVE-2025-69419 | 7.4 | HIGH |
| CVE-2023-2650 | 6.5 | MEDIUM |
| CVE-2023-6129 | 6.5 | MEDIUM |
| CVE-2023-1255 | 5.9 | MEDIUM |
| CVE-2026-42766 | 5.9 | MEDIUM |
| CVE-2026-42767 | 5.9 | MEDIUM |
| CVE-2024-0727 | 5.5 | MEDIUM |
| CVE-2026-22795 | 5.5 | MEDIUM |
| CVE-2023-0465 | 5.3 | MEDIUM |
| CVE-2023-0466 | 5.3 | MEDIUM |
| CVE-2023-2975 | 5.3 | MEDIUM |
| CVE-2023-3817 | 5.3 | MEDIUM |
| CVE-2023-5678 | 5.3 | MEDIUM |
| CVE-2026-22796 | 5.3 | MEDIUM |
| CVE-2026-45446 | 4.8 | MEDIUM |
| CVE-2025-68160 | 4.7 | MEDIUM |
| CVE-2025-69418 | 4 | MEDIUM |
| CVE-2026-42770 | 3.7 | LOW |