808bits

Red Hat Enterprise Linux 9 libgcrypt

FIPS 140-3 certificate #4754 · Red Hat(R), Inc. · data as of 2026-09-03

Red Hat Enterprise Linux 9 libgcrypt, from Red Hat(R), Inc., holds FIPS 140-3 certificate #4754 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Replaced by certificate #5366. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: Interim validation. When operated in approved mode. When installed, initialized and configured as specified in Section 11 of the Security Policy. The module generates SSPs (e.g., keys) whose strengths are modified by available entropy

Certificate

Certificate number4754
StandardFIPS 140-3
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorRed Hat(R), Inc. · website
Software versions1.10.0-8b6840b590cedd43

Module description

Quoted from the NIST CMVP entry for this certificate.

The Red Hat Enterprise Linux 9 libgcrypt is a software library implementing general purpose cryptographic algorithms

Security level exceptions

  • Physical security: N/A
  • Non-invasive security: N/A

Approved algorithms (46)

AlgorithmCAVP certificates
AES-CBCA3757, A3759, A3760, A3762, A4675, A4676
AES-CCMA3757, A3759, A3760, A3762
AES-CFB128A3757, A3759, A3760, A3762, A4675, A4676
AES-CFB8A3757, A3759, A3760, A3762, A4675, A4676
AES-CMACA3757, A3759, A3760, A3762
AES-CTRA3757, A3759, A3760, A3762, A4675, A4676
AES-ECBA3757, A3759, A3760, A3762, A4675, A4676
AES-KWA3757, A3759, A3760, A3762
AES-OFBA3757, A3759, A3760, A3762
AES-XTS Testing Revision 2.0A3757, A3759, A3760, A3762, A4675, A4676
Counter DRBGA3757, A3759, A3760, A3762
ECDSA KeyGen (FIPS186-4)A3757, A3759, A3760, A3761, A3762
ECDSA KeyVer (FIPS186-4)A3757, A3759, A3760, A3761, A3762
ECDSA SigGen (FIPS186-4)A3757, A3759, A3760, A3761, A3762
ECDSA SigVer (FIPS186-4)A3757, A3759, A3760, A3761, A3762
Hash DRBGA3757, A3759, A3760, A3761, A3762
HMAC DRBGA3757, A3759, A3760, A3761, A3762
HMAC-SHA-1A3757, A3758, A3759, A3760, A3761, A3762
HMAC-SHA2-224A3757, A3759, A3760, A3761, A3762
HMAC-SHA2-256A3757, A3759, A3760, A3761, A3762
HMAC-SHA2-384A3757, A3759, A3760, A3761, A3762
HMAC-SHA2-512A3757, A3759, A3760, A3761, A3762
HMAC-SHA2-512/224A3757, A3759, A3760, A3761, A3762
HMAC-SHA2-512/256A3757, A3759, A3760, A3761, A3762
HMAC-SHA3-224A3757, A3761, A3762
HMAC-SHA3-256A3757, A3761, A3762
HMAC-SHA3-384A3757, A3761, A3762
HMAC-SHA3-512A3757, A3761, A3762
PBKDFA3757, A3759, A3760, A3761, A3762
RSA KeyGen (FIPS186-4)A3757, A3759, A3760, A3761, A3762
RSA SigGen (FIPS186-4)A3757, A3759, A3760, A3761, A3762
RSA SigVer (FIPS186-2)A3757, A3759, A3760, A3761, A3762
RSA SigVer (FIPS186-4)A3757, A3759, A3760, A3761, A3762
SHA-1A3757, A3758, A3759, A3760, A3761, A3762
SHA2-224A3757, A3759, A3760, A3761, A3762
SHA2-256A3757, A3759, A3760, A3761, A3762, A4675, A4676
SHA2-384A3757, A3759, A3760, A3761, A3762
SHA2-512A3757, A3759, A3760, A3761, A3762, A4675, A4676
SHA2-512/224A3757, A3759, A3760, A3761, A3762
SHA2-512/256A3757, A3759, A3760, A3761, A3762
SHA3-224A3757, A3761, A3762
SHA3-256A3757, A3761, A3762
SHA3-384A3757, A3761, A3762
SHA3-512A3757, A3761, A3762
SHAKE-128A3757, A3761, A3762
SHAKE-256A3757, A3761, A3762

Tested configurations

  • Red Hat Enterprise Linux 9 running on Dell PowerEdge R440 with Intel(R) Xeon(R) Silver 4216 with PAA
  • Red Hat Enterprise Linux 9 running on Dell PowerEdge R440 with Intel(R) Xeon(R) Silver 4216 without PAA
  • Red Hat Enterprise Linux 9 running on IBM z16 3931-A01 with IBM z16 with PAI
  • Red Hat Enterprise Linux 9 running on IBM z16 3931-A01 with IBM z16 without PAI
  • Red Hat Enterprise Linux 9 with PowerVM FW1040.00 with VIOS 3.1.3.00 running on IBM 9080-HEX with IBM POWER10 with PAA
  • Red Hat Enterprise Linux 9 with PowerVM FW1040.00 with VIOS 3.1.3.00 running on IBM 9080-HEX with IBM POWER10 without PAA

Validation history

DateTypeLab
2024-08-09Initialatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2024-08-09

Source documents