808bits

Red Hat Enterprise Linux 8 NSS Cryptographic Module

FIPS 140-2 certificate #4413 · Red Hat®, Inc. · data as of 2026-08-28
Active. Sunset date 2026-09-21, 23 days away. This is the FIPS 140-2 sunset: after it, agencies may keep the module only in existing systems.
Caveat: When operated in FIPS mode and installed, initialized and configured as specified in Section 9.1 of the Security Policy. The module generates cryptographic keys whose strengths are modified by available entropy applies.

Certificate

Certificate number4413
StandardFIPS 140-2
Statusactive
Sunset date2026-09-21
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorRed Hat®, Inc. · website
Software versionsrhel8.20201215

Module description

Network Security Services (NSS) is a set of open source C libraries designed to support cross-platform development of security-enabled applications. NSS implements major Internet security standards. NSS is available free of charge under a variety of open source compatible licenses. See http://www.mozilla.org/projects/security/pki/nss/.

Security level exceptions

  • Roles, Services, and Authentication: Level 2
  • Physical Security: N/A
  • Design Assurance: Level 2

Approved algorithms

AlgorithmCAVP certificate
AESA1173, A1174, A1175, A1176, A1177
CKGvendor affirmed
CVLA1173, A1178
DRBGA1173
DSAA1173
ECDSAA1173
ENT
HMACA1173
KAS-SSCA1173
KDAA1172
KTS
KTS
KTS
KTS-RSA
PBKDFA1173
RSAA1173
SHSA1173
Triple-DESA1173

Allowed algorithms

RSA (key wrapping; key establishment methodology provides between 112 and 256 bits of encryption strength)

Tested configurations

  • Red Hat Enterprise Linux 8 running on Dell PowerEdge R440 with an Intel(R) Xeon(R) Silver 4216 with PAA
  • Red Hat Enterprise Linux 8 running on Dell PowerEdge R440 with an Intel(R) Xeon(R) Silver 4216 without PAA (single-user mode)

Validation history

DateTypeLab
2023-01-16Initialatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2023-01-16

Source documents