Red Hat Enterprise Linux 9 gnutls
Caveat: Interim validation. When operated in approved mode. When installed, initialized and configured as specified in Section 11 of the Security Policy. The module generates cryptographic keys whose strengths are modified by available entropy.
Certificate
| Certificate number | 4780 |
|---|---|
| Standard | FIPS 140-3 |
| Status | historical |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Red Hat, Inc. · website |
| Software versions | 3.7.6-66803fa128d6a6e5 |
Module description
GnuTLS is a secure communications library implementing the TLS and DTLS protocols. It provides a simple C language application programming interface to access the secure communications protocols as well as APIs to parse and write X.509, PKCS#12, and other required structures which is shipped with Red Hat Enterprise Linux 9.
Security level exceptions
- Physical security: N/A
- Non-invasive security: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES-CBC | A3472 |
| AES-CBC | A3473 |
| AES-CBC | A3478 |
| AES-CBC | A3550 |
| AES-CBC | A3551 |
| AES-CCM | A3472 |
| AES-CCM | A3550 |
| AES-CFB8 | A3475 |
| AES-CFB8 | A3476 |
| AES-CFB8 | A3481 |
| AES-CMAC | A3472 |
| AES-CMAC | A3473 |
| AES-CMAC | A3478 |
| AES-CMAC | A3550 |
| AES-ECB | A3478 |
| AES-GCM | A3472 |
| AES-GCM | A3473 |
| AES-GCM | A3478 |
| AES-GCM | A3550 |
| AES-GCM | A3551 |
| AES-GMAC | A3478 |
| AES-XTS Testing Revision 2.0 | A3479 |
| Counter DRBG | A3478 |
| ECDSA KeyGen (FIPS186-4) | A3478 |
| ECDSA KeyVer (FIPS186-4) | A3478 |
| ECDSA SigGen (FIPS186-4) | A3478 |
| ECDSA SigVer (FIPS186-4) | A3478 |
| HMAC-SHA-1 | A3473 |
| HMAC-SHA-1 | A3478 |
| HMAC-SHA-1 | A3552 |
| HMAC-SHA2-224 | A3473 |
| HMAC-SHA2-224 | A3478 |
| HMAC-SHA2-224 | A3552 |
| HMAC-SHA2-256 | A3473 |
| HMAC-SHA2-256 | A3478 |
| HMAC-SHA2-256 | A3552 |
| HMAC-SHA2-384 | A3473 |
| HMAC-SHA2-384 | A3478 |
| HMAC-SHA2-384 | A3552 |
| HMAC-SHA2-512 | A3473 |
| HMAC-SHA2-512 | A3478 |
| HMAC-SHA2-512 | A3552 |
| KAS-ECC-SSC Sp800-56Ar3 | A3478 |
| KAS-FFC-SSC Sp800-56Ar3 | A3478 |
| KDA HKDF Sp800-56Cr1 | A3477 |
| PBKDF | A3478 |
| RSA KeyGen (FIPS186-4) | A3478 |
| RSA SigGen (FIPS186-4) | A3478 |
| RSA SigVer (FIPS186-4) | A3478 |
| Safe Primes Key Generation | A3478 |
| SHA-1 | A3473 |
| SHA-1 | A3478 |
| SHA-1 | A3552 |
| SHA2-224 | A3473 |
| SHA2-224 | A3478 |
| SHA2-224 | A3552 |
| SHA2-256 | A3473 |
| SHA2-256 | A3478 |
| SHA2-256 | A3552 |
| SHA2-384 | A3473 |
| SHA2-384 | A3478 |
| SHA2-384 | A3552 |
| SHA2-512 | A3473 |
| SHA2-512 | A3478 |
| SHA2-512 | A3552 |
| SHA3-224 | A3474 |
| SHA3-224 | A3480 |
| SHA3-256 | A3474 |
| SHA3-256 | A3480 |
| SHA3-384 | A3474 |
| SHA3-384 | A3480 |
| SHA3-512 | A3474 |
| SHA3-512 | A3480 |
| TLS v1.2 KDF RFC7627 | A3478 |
Tested configurations
- Red Hat Enterprise Linux 9 running on Dell PowerEdge R440 with Intel® Xeon® Silver 4216 with PAA
- Red Hat Enterprise Linux 9 running on Dell PowerEdge R440 with Intel® Xeon® Silver 4216 without PAA
- Red Hat Enterprise Linux 9 running on IBM z16 3931-A01 with IBM z16 with PAI
- Red Hat Enterprise Linux 9 running on IBM z16 3931-A01 with IBM z16 without PAI
- Red Hat Enterprise Linux 9 with PowerVM FW1040.00 with VIOS 3.1.3.00 running on IBM 9080-HEX with IBM POWER10 with PAA
- Red Hat Enterprise Linux 9 with PowerVM FW1040.00 with VIOS 3.1.3.00 running on IBM 9080-HEX with IBM POWER10 without PAA
Validation history
| Date | Type | Lab |
|---|---|---|
| 2024-08-26 | Initial | atsec information security corporation |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical at the time of the earliest snapshot
- 2026-08-25: observed moving from active to historical
- Validation dates on record: 2024-08-26