Red Hat Enterprise Linux 9 NSS Cryptographic Module
Caveat: Interim validation. When operated in approved mode and installed, initialized and configured as specified in section 11 of the Security Policy. The module generates SSPs (e.g., keys) whose strengths are modified by available entropy.
Certificate
| Certificate number | 4774 |
|---|---|
| Standard | FIPS 140-3 |
| Status | historical |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Red Hat(R), Inc. · website |
| Software versions | 4.34.0-a20cd33fbbe14357 |
Module description
Network Security Services (NSS) is a set of open source C libraries designed to support cross-platform development of security-enabled applications. NSS implements major Internet security standards. NSS is available free of charge under a variety of open source compatible licenses. See http://www.mozilla.org/projects/security/pki/nss/.
Security level exceptions
- Physical security: N/A
- Non-invasive security: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES-CBC | A3463 |
| AES-CBC | A3470 |
| AES-CBC-CS1 | A3468 |
| AES-CMAC | A3465 |
| AES-CTR | A3463 |
| AES-CTR | A3470 |
| AES-ECB | A3463 |
| AES-ECB | A3470 |
| AES-GCM | A3463 |
| AES-GCM | A3463 |
| AES-GCM | A3470 |
| AES-GCM | A3470 |
| AES-GCM | A4482 |
| AES-GCM | A4482 |
| AES-KW | A3464 |
| AES-KW | A3469 |
| AES-KWP | A3464 |
| AES-KWP | A3469 |
| DSA SigVer (FIPS186-4) | A3463 |
| ECDSA KeyGen (FIPS186-4) | A3463 |
| ECDSA SigGen (FIPS186-4) | A3463 |
| ECDSA SigVer (FIPS186-4) | A3463 |
| Hash DRBG | A3463 |
| HMAC-SHA2-224 | A3463 |
| HMAC-SHA2-256 | A3463 |
| HMAC-SHA2-384 | A3463 |
| HMAC-SHA2-512 | A3463 |
| KAS-ECC-SSC Sp800-56Ar3 | A3463 |
| KAS-FFC-SSC Sp800-56Ar3 | A3463 |
| KDA HKDF Sp800-56Cr1 | A3462 |
| KDF IKEv2 | A3467 |
| KDF SP800-108 | A3466 |
| KDF TLS | A3463 |
| PBKDF | A3463 |
| RSA KeyGen (FIPS186-4) | A3463 |
| RSA SigGen (FIPS186-4) | A3463 |
| RSA SigVer (FIPS186-2) | A3463 |
| RSA SigVer (FIPS186-4) | A3463 |
| Safe Primes Key Generation | A3463 |
| SHA2-224 | A3463 |
| SHA2-256 | A3463 |
| SHA2-384 | A3463 |
| SHA2-512 | A3463 |
| TLS v1.2 KDF RFC7627 | A3463 |
Tested configurations
- Red Hat Enterprise Linux 9 on IBM 9080 HEX with IBM POWER10 with PAA
- Red Hat Enterprise Linux 9 on IBM 9080 HEX with IBM POWER10 without PAA
- Red Hat Enterprise Linux 9 on IBM z16 3931-A01 with IBM z16 with PAI
- Red Hat Enterprise Linux 9 on IBM z16 3931-A01 with IBM z16 without PAI
- Red Hat Enterprise Linux 9 running on Dell PowerEdge R440 with Intel(R) Xeon(R) Silver 4216 with PAA
- Red Hat Enterprise Linux 9 running on Dell PowerEdge R440 with Intel(R) Xeon(R) Silver 4216 without PAA
Validation history
| Date | Type | Lab |
|---|---|---|
| 2024-08-21 | Initial | atsec information security corporation |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2024-08-21