808bits

Red Hat Enterprise Linux 9 NSS Cryptographic Module

FIPS 140-3 certificate #4774 · Red Hat(R), Inc. · data as of 2026-08-28
Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: Interim validation. When operated in approved mode and installed, initialized and configured as specified in section 11 of the Security Policy. The module generates SSPs (e.g., keys) whose strengths are modified by available entropy.

Certificate

Certificate number4774
StandardFIPS 140-3
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorRed Hat(R), Inc. · website
Software versions4.34.0-a20cd33fbbe14357

Module description

Network Security Services (NSS) is a set of open source C libraries designed to support cross-platform development of security-enabled applications. NSS implements major Internet security standards. NSS is available free of charge under a variety of open source compatible licenses. See http://www.mozilla.org/projects/security/pki/nss/.

Security level exceptions

  • Physical security: N/A
  • Non-invasive security: N/A

Approved algorithms

AlgorithmCAVP certificate
AES-CBCA3463
AES-CBCA3470
AES-CBC-CS1A3468
AES-CMACA3465
AES-CTRA3463
AES-CTRA3470
AES-ECBA3463
AES-ECBA3470
AES-GCMA3463
AES-GCMA3463
AES-GCMA3470
AES-GCMA3470
AES-GCMA4482
AES-GCMA4482
AES-KWA3464
AES-KWA3469
AES-KWPA3464
AES-KWPA3469
DSA SigVer (FIPS186-4)A3463
ECDSA KeyGen (FIPS186-4)A3463
ECDSA SigGen (FIPS186-4)A3463
ECDSA SigVer (FIPS186-4)A3463
Hash DRBGA3463
HMAC-SHA2-224A3463
HMAC-SHA2-256A3463
HMAC-SHA2-384A3463
HMAC-SHA2-512A3463
KAS-ECC-SSC Sp800-56Ar3A3463
KAS-FFC-SSC Sp800-56Ar3A3463
KDA HKDF Sp800-56Cr1A3462
KDF IKEv2A3467
KDF SP800-108A3466
KDF TLSA3463
PBKDFA3463
RSA KeyGen (FIPS186-4)A3463
RSA SigGen (FIPS186-4)A3463
RSA SigVer (FIPS186-2)A3463
RSA SigVer (FIPS186-4)A3463
Safe Primes Key GenerationA3463
SHA2-224A3463
SHA2-256A3463
SHA2-384A3463
SHA2-512A3463
TLS v1.2 KDF RFC7627A3463

Tested configurations

  • Red Hat Enterprise Linux 9 on IBM 9080 HEX with IBM POWER10 with PAA
  • Red Hat Enterprise Linux 9 on IBM 9080 HEX with IBM POWER10 without PAA
  • Red Hat Enterprise Linux 9 on IBM z16 3931-A01 with IBM z16 with PAI
  • Red Hat Enterprise Linux 9 on IBM z16 3931-A01 with IBM z16 without PAI
  • Red Hat Enterprise Linux 9 running on Dell PowerEdge R440 with Intel(R) Xeon(R) Silver 4216 with PAA
  • Red Hat Enterprise Linux 9 running on Dell PowerEdge R440 with Intel(R) Xeon(R) Silver 4216 without PAA

Validation history

DateTypeLab
2024-08-21Initialatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2024-08-21

Source documents