808bits

Red Hat Enterprise Linux 9 gnutls

FIPS 140-3 certificate #4780 · Red Hat, Inc. · data as of 2026-08-28
Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement. Observed moving to historical on 2026-08-25.
Caveat: Interim validation. When operated in approved mode. When installed, initialized and configured as specified in Section 11 of the Security Policy. The module generates cryptographic keys whose strengths are modified by available entropy.

Certificate

Certificate number4780
StandardFIPS 140-3
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorRed Hat, Inc. · website
Software versions3.7.6-66803fa128d6a6e5

Module description

GnuTLS is a secure communications library implementing the TLS and DTLS protocols. It provides a simple C language application programming interface to access the secure communications protocols as well as APIs to parse and write X.509, PKCS#12, and other required structures which is shipped with Red Hat Enterprise Linux 9.

Security level exceptions

  • Physical security: N/A
  • Non-invasive security: N/A

Approved algorithms

AlgorithmCAVP certificate
AES-CBCA3472
AES-CBCA3473
AES-CBCA3478
AES-CBCA3550
AES-CBCA3551
AES-CCMA3472
AES-CCMA3550
AES-CFB8A3475
AES-CFB8A3476
AES-CFB8A3481
AES-CMACA3472
AES-CMACA3473
AES-CMACA3478
AES-CMACA3550
AES-ECBA3478
AES-GCMA3472
AES-GCMA3473
AES-GCMA3478
AES-GCMA3550
AES-GCMA3551
AES-GMACA3478
AES-XTS Testing Revision 2.0A3479
Counter DRBGA3478
ECDSA KeyGen (FIPS186-4)A3478
ECDSA KeyVer (FIPS186-4)A3478
ECDSA SigGen (FIPS186-4)A3478
ECDSA SigVer (FIPS186-4)A3478
HMAC-SHA-1A3473
HMAC-SHA-1A3478
HMAC-SHA-1A3552
HMAC-SHA2-224A3473
HMAC-SHA2-224A3478
HMAC-SHA2-224A3552
HMAC-SHA2-256A3473
HMAC-SHA2-256A3478
HMAC-SHA2-256A3552
HMAC-SHA2-384A3473
HMAC-SHA2-384A3478
HMAC-SHA2-384A3552
HMAC-SHA2-512A3473
HMAC-SHA2-512A3478
HMAC-SHA2-512A3552
KAS-ECC-SSC Sp800-56Ar3A3478
KAS-FFC-SSC Sp800-56Ar3A3478
KDA HKDF Sp800-56Cr1A3477
PBKDFA3478
RSA KeyGen (FIPS186-4)A3478
RSA SigGen (FIPS186-4)A3478
RSA SigVer (FIPS186-4)A3478
Safe Primes Key GenerationA3478
SHA-1A3473
SHA-1A3478
SHA-1A3552
SHA2-224A3473
SHA2-224A3478
SHA2-224A3552
SHA2-256A3473
SHA2-256A3478
SHA2-256A3552
SHA2-384A3473
SHA2-384A3478
SHA2-384A3552
SHA2-512A3473
SHA2-512A3478
SHA2-512A3552
SHA3-224A3474
SHA3-224A3480
SHA3-256A3474
SHA3-256A3480
SHA3-384A3474
SHA3-384A3480
SHA3-512A3474
SHA3-512A3480
TLS v1.2 KDF RFC7627A3478

Tested configurations

  • Red Hat Enterprise Linux 9 running on Dell PowerEdge R440 with Intel® Xeon® Silver 4216 with PAA
  • Red Hat Enterprise Linux 9 running on Dell PowerEdge R440 with Intel® Xeon® Silver 4216 without PAA
  • Red Hat Enterprise Linux 9 running on IBM z16 3931-A01 with IBM z16 with PAI
  • Red Hat Enterprise Linux 9 running on IBM z16 3931-A01 with IBM z16 without PAI
  • Red Hat Enterprise Linux 9 with PowerVM FW1040.00 with VIOS 3.1.3.00 running on IBM 9080-HEX with IBM POWER10 with PAA
  • Red Hat Enterprise Linux 9 with PowerVM FW1040.00 with VIOS 3.1.3.00 running on IBM 9080-HEX with IBM POWER10 without PAA

Validation history

DateTypeLab
2024-08-26Initialatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical at the time of the earliest snapshot
  • 2026-08-25: observed moving from active to historical
  • Validation dates on record: 2024-08-26

Source documents