Hewlett Packard Enterprise OpenSSL Cryptographic Module on Red Hat Enterprise Linux
Caveat: When operated in FIPS mode and installed, initialized and configured as specified in Section 9.1 of the Security Policy. The module generates cryptographic keys whose strengths are modified by available entropy.
Certificate
| Certificate number | 4473 |
|---|---|
| Standard | FIPS 140-2 |
| Status | active |
| Sunset date | 2026-09-21 |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Aruba, a Hewlett Packard Enterprise Company · website |
| Software versions | rhel8.20210325 |
Module description
The OpenSSL FIPS Runtime Module is a general purpose cryptographic library designed to provide FIPS 140-2 validated cryptographic functionality for use with the high level API of the OpenSSL library.
Security level exceptions
- Physical Security: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | A1117, A1118, A1119, A1121, A1122, A1123, A1124, A1130, A1131, A1132, A1137, A1138, A1139, A1140, A1141, A1142 |
| CVL | A1121, A1122, A1123, A1124, A1133, A1134, A1135, A1136 |
| DRBG | A1117, A1118, A1119 |
| DSA | A1133, A1134, A1135, A1136 |
| ECDSA | A1133, A1134, A1135, A1136 |
| ENT | |
| HMAC | A1125, A1126, A1127, A1133, A1134, A1135, A1136 |
| KAS | |
| KAS-SSC | A1133, A1134, A1135, A1136, A1144 |
| KBKDF | A1143 |
| KDA | A1120 |
| KTS | |
| KTS | |
| KTS | |
| PBKDF | A1125, A1126, A1127, A1133, A1134, A1135, A1136 |
| RSA | A1133, A1134, A1135, A1136 |
| SHA-3 | A1125, A1126, A1127 |
| SHS | A1133, A1134, A1135, A1136 |
| Triple-DES | A1116, A1121, A1122, A1123, A1124 |
Allowed algorithms
RSA (key wrapping; key establishment methodology provides between 112 and 256 bits of encryption strength)
Tested configurations
- Red Hat Enterprise Linux 8 running on Dell PowerEdge R440 with an Intel(R) Xeon(R) Silver 4216 with PAA
- Red Hat Enterprise Linux 8 running on Dell PowerEdge R440 with an Intel(R) Xeon(R) Silver 4216 without PAA (single-user mode)
Validation history
| Date | Type | Lab |
|---|---|---|
| 2023-04-14 | Initial | atsec information security corporation |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2023-04-14