808bits

Red Hat Enterprise Linux 8 NSS Cryptographic Module

FIPS 140-2 certificate #4458 · Red Hat®, Inc. · data as of 2026-08-28
Active. Sunset date 2026-09-21, 23 days away. This is the FIPS 140-2 sunset: after it, agencies may keep the module only in existing systems.
Caveat: When operated in FIPS mode and installed, initialized and configured as specified in Section 9.1 of the Security Policy. The module generates cryptographic keys whose strengths are modified by available entropy

Certificate

Certificate number4458
StandardFIPS 140-2
Statusactive
Sunset date2026-09-21
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorRed Hat®, Inc. · website
Software versionsrhel8.20211124

Module description

Network Security Services (NSS) is a set of open source C libraries designed to support cross-platform development of security-enabled applications. NSS implements major Internet security standards. NSS is available free of charge under a variety of open source compatible licenses. See http://www.mozilla.org/projects/security/pki/nss/.

Security level exceptions

  • Roles, Services, and Authentication: Level 2
  • Physical Security: N/A
  • Design Assurance: Level 2

Approved algorithms

AlgorithmCAVP certificate
AESA1923, A1924, A1925, A1927, A1928, A3020
CKGvendor affirmed
CVLA1922, A1923, A1926
DRBGA1923
DSAA1923
ECDSAA1923
ENT
HMACA1923
KAS
KAS-SSCA1923
KBKDFA2055
KTS
KTS
KTS
KTS-RSA
PBKDFA1923
RSAA1923
SHSA1923
Triple-DESA1923

Allowed algorithms

RSA (key wrapping; key establishment methodology provides between 112 and 256 bits of encryption strength)

Tested configurations

  • Red Hat Enterprise Linux 8 running on an IBM System z15 with an IBM z15
  • Red Hat Enterprise Linux 8 running on Dell PowerEdge R440 with an Intel(R) Xeon(R) Silver 4216 with PAA
  • Red Hat Enterprise Linux 8 running on Dell PowerEdge R440 with an Intel(R) Xeon(R) Silver 4216 without PAA
  • Red Hat Enterprise Linux 8 with PowerVM FW1010.22 with VIOS 3.1.3.00 running on an IBM 9080-HEX with an IBM POWER10 (single-user mode)
  • Red Hat Enterprise Linux 8 with PowerVM FW950.00 with VIOS 3.1.2.00 running on an IBM 9009-42A with an IBM POWER9 with PAA
  • Red Hat Enterprise Linux 8 with PowerVM FW950.00 with VIOS 3.1.2.00 running on an IBM 9009-42A with an IBM POWER9 without PAA

Validation history

DateTypeLab
2023-03-24Initialatsec information security corporation
2023-10-13Updateatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2023-03-24, 2023-10-13

Source documents