Red Hat Enterprise Linux 8 libgcrypt Cryptographic Module
Red Hat Enterprise Linux 8 libgcrypt Cryptographic Module, from Red Hat®, Inc., holds FIPS 140-2 certificate #4397 at overall level 1. The validation is active, with a sunset date of 2026-09-21. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.
Caveat: When operated in FIPS mode and installed, initialized and configured as specified in Section 10.1 of the Security Policy. The module generates cryptographic keys whose strengths are modified by available entropy applies.
Certificate
| Certificate number | 4397 |
|---|---|
| Standard | FIPS 140-2 |
| Status | active |
| Sunset date | 2026-09-21 |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Red Hat®, Inc. · website |
| Software versions | rhel8.20200615 |
Module description
Quoted from the NIST CMVP entry for this certificate.
The libgcrypt FIPS Runtime Module is a general purpose cryptographic library designed to provide FIPS 140-2 validated cryptographic functionality for use with the high level API of the libgcrypt library delivered with RHEL 8.
Security level exceptions
- Physical Security: N/A
Approved algorithms (12)
| Algorithm | CAVP certificates |
|---|---|
| AES | A1255, A1256, A1258, A1259 |
| DRBG | A1255, A1256, A1257, A1258, A1259 |
| DSA | A1255, A1256, A1257, A1258, A1259 |
| ECDSA | A1255, A1256, A1257, A1258, A1259 |
| ENT | |
| HMAC | A1254, A1255, A1256, A1257, A1258, A1259 |
| KTS | |
| PBKDF | A1255, A1256, A1257, A1258, A1259 |
| RSA | A1255, A1256, A1257, A1258, A1259 |
| SHA-3 | A1257, A1258, A1259 |
| SHS | A1254, A1255, A1256, A1257, A1258, A1259 |
| Triple-DES | A1258 |
Allowed algorithms
RSA (key wrapping; key establishment methodology provides between 112 and 256 bits of encryption strength)
Tested configurations
- Red Hat Enterprise Linux 8 running on Dell PowerEdge R440 with an Intel(R) Xeon(R) Silver 4216 with PAA
- Red Hat Enterprise Linux 8 running on Dell PowerEdge R440 with an Intel(R) Xeon(R) Silver 4216 without PAA (single-user mode)
Validation history
| Date | Type | Lab |
|---|---|---|
| 2022-12-20 | Initial | atsec information security corporation |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2022-12-20