Linux Kernel FIPS Object Module (KFOM) Cryptographic Module
Caveat: No assurance of the minimum strength of generated SSPs (e.g., keys). No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs.
Certificate
| Certificate number | 4744 |
|---|---|
| Standard | FIPS 140-3 |
| Status | active |
| Sunset date | 2029-07-28 |
| Overall level | 1 |
| Module type | Firmware-hybrid |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Cisco Systems, Inc. · website |
| Hardware versions | ARMv8 Cortex-A53, Intel Xeon Gold 6138 |
| Firmware versions | 1.0 |
Module description
The Cisco Linux Kernel FIPS Object Module (KFOM) is a firmware hybrid cryptographic library that serves the operating system kernel. It does not implement any security protocols, instead only allowing for Linux kernel applications access to using approved algorithms.
Security level exceptions
- Non-invasive security: N/A
- Mitigation of other attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES-CBC | A1182 |
| AES-CBC | A1185 |
| AES-CBC-CS3 | A1182 |
| AES-CBC-CS3 | A1185 |
| AES-CCM | A1182 |
| AES-CCM | A1185 |
| AES-CMAC | A1182 |
| AES-CMAC | A1185 |
| AES-CTR | A1182 |
| AES-CTR | A1185 |
| AES-ECB | A1182 |
| AES-ECB | A1185 |
| AES-GCM | A1182 |
| AES-GCM | A1185 |
| AES-GMAC | A1182 |
| AES-GMAC | A1185 |
| AES-XTS | A1182 |
| AES-XTS | A1185 |
| Counter DRBG | A1182 |
| Counter DRBG | A1185 |
| Hash DRBG | A1182 |
| Hash DRBG | A1185 |
| HMAC DRBG | A1182 |
| HMAC DRBG | A1185 |
| HMAC-SHA-1 | A1182 |
| HMAC-SHA-1 | A1185 |
| HMAC-SHA2-224 | A1182 |
| HMAC-SHA2-224 | A1185 |
| HMAC-SHA2-256 | A1182 |
| HMAC-SHA2-256 | A1185 |
| HMAC-SHA2-384 | A1182 |
| HMAC-SHA2-384 | A1185 |
| HMAC-SHA2-512 | A1182 |
| HMAC-SHA2-512 | A1185 |
| SHA-1 | A1182 |
| SHA-1 | A1185 |
| SHA2-224 | A1182 |
| SHA2-224 | A1185 |
| SHA2-256 | A1182 |
| SHA2-256 | A1185 |
| SHA2-384 | A1182 |
| SHA2-384 | A1185 |
| SHA2-512 | A1182 |
| SHA2-512 | A1185 |
Tested configurations
- Linux 4.9 running on Cisco Meraki MX68CW with ARMv8 Cortex-A53 with PAA
- Ubuntu 18.04 running on Cisco UCS C220 M5 with Intel Xeon Gold 6138 (Skylake) with PAA
Validation history
| Date | Type | Lab |
|---|---|---|
| 2024-07-29 | Initial | Acumen Security |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2024-07-29