Oracle Linux 8 Unbreakable Enterprise Kernel (UEK7) Cryptographic Module and Oracle Linux 9 Unbreakable Enterprise Kernel (UEK7) Cryptographic Module
Oracle Linux 8 Unbreakable Enterprise Kernel (UEK7) Cryptographic Module and Oracle Linux 9 Unbreakable Enterprise Kernel (UEK7) Cryptographic Module, from Oracle Corporation, holds FIPS 140-3 certificate #4739 at overall level 1. The validation is active, with a sunset date of 2029-07-24. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.
Caveat: Interim validation. When operated in Approved mode. When installed, initialized and configured as specified in section 11 of the Security Policy.
Certificate
| Certificate number | 4739 |
|---|---|
| Standard | FIPS 140-3 |
| Status | active |
| Sunset date | 2029-07-24 |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Oracle Corporation · website |
| Software versions | kernel 5.15.0-303.171.5.2.2.el8uek and 5.15.0-303.171.5.2.2.el9uek; libkcapi 1.2.0-2.0.1.el8 and 1.3.1-3.0.1.el9 |
Module description
Quoted from the NIST CMVP entry for this certificate.
Oracle Linux 8 Unbreakable Enterprise Kernel (UEK7) Cryptographic Module and Oracle Linux 9 Unbreakable Enterprise Kernel (UEK7) API provides a C language API for use by other (kernel space and user space) processes that require cryptographic functionality
Security level exceptions
- Physical security: N/A
- Non-invasive security: N/A
- Mitigation of other attacks: N/A
Approved algorithms (37)
Tested configurations
- Oracle Linux 8 running on KVM on Oracle Linux 8 running on ORACLE SERVER A1-2c with Ampere(R) Altra(R) Q80-30 with PAA
- Oracle Linux 8 running on KVM on Oracle Linux 8 running on ORACLE SERVER A1-2c with Ampere(R) Altra(R) Q80-30 without PAA
- Oracle Linux 8 running on KVM on Oracle Linux 8 running on ORACLE SERVER E4-2c with AMD EPYC 7J13 with PAA
- Oracle Linux 8 running on KVM on Oracle Linux 8 running on ORACLE SERVER E4-2c with AMD EPYC 7J13 without PAA
- Oracle Linux 8 running on KVM on Oracle Linux 8 running on ORACLE SERVER X9-2c with Intel(R) Xeon(R) Platinum 8358 with PAA
- Oracle Linux 8 running on KVM on Oracle Linux 8 running on ORACLE SERVER X9-2c with Intel(R) Xeon(R) Platinum 8358 without PAA
- Oracle Linux 9 running on KVM on Oracle Linux 8 running on ORACLE SERVER A1-2c with Ampere(R) Altra(R) Q80-30 with PAA
- Oracle Linux 9 running on KVM on Oracle Linux 8 running on ORACLE SERVER A1-2c with Ampere(R) Altra(R) Q80-30 without PAA
- Oracle Linux 9 running on KVM on Oracle Linux 8 running on ORACLE SERVER E4-2c with AMD EPYC 7J13 with PAA
- Oracle Linux 9 running on KVM on Oracle Linux 8 running on ORACLE SERVER E4-2c with AMD EPYC 7J13 without PAA
- Oracle Linux 9 running on KVM on Oracle Linux 8 running on ORACLE SERVER X9-2c with Intel(R) Xeon(R) Platinum 8358 with PAA
- Oracle Linux 9 running on KVM on Oracle Linux 8 running on ORACLE SERVER X9-2c with Intel(R) Xeon(R) Platinum 8358 without PAA
- Oracle Linux 9 running on Marvell Liquid IO II with OCTEON III
Validation history
| Date | Type | Lab |
|---|---|---|
| 2024-07-25 | Initial | atsec information security corporation |
| 2025-08-22 | Update | atsec information security corporation |
| 2026-04-01 | Update | atsec information security corporation |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2024-07-25