808bits

Canonical Ltd. Ubuntu 22.04 OpenSSL Cryptographic Module

FIPS 140-3 certificate #4794 · Canonical Ltd. · data as of 2026-09-15

Canonical Ltd. Ubuntu 22.04 OpenSSL Cryptographic Module, from Canonical Ltd., holds FIPS 140-3 certificate #4794 at overall level 1. The validation is active, with a sunset date of 2029-09-10. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Active. Sunset date 2029-09-10, 1090 days away.
Caveat: Interim validation; When operated in approved mode; When installed, initialized and configured as specified in Section 11 of the Security Policy

Certificate

Certificate number4794
StandardFIPS 140-3
Statusactive
Sunset date2029-09-10
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorCanonical Ltd. · website
Software versions3.0.5-0ubuntu0.1+Fips2.1

Module description

Quoted from the NIST CMVP entry for this certificate.

The Canonical Ltd. Ubuntu 22.04 OpenSSL Cryptographic Module provides a C language application program interface (API) for use by other applications that require cryptographic functionality.

Security level exceptions

  • Physical security: N/A
  • Non-invasive security: N/A

Approved algorithms (66)

AlgorithmCAVP certificates
AES-CBCA3958, A3959, A3960, A3973, A3980, A3981, A3982
AES-CBC-CS1A3958, A3959, A3960, A3973, A3980, A3981, A3982
AES-CBC-CS2A3958, A3959, A3960, A3973, A3980, A3981, A3982
AES-CBC-CS3A3958, A3959, A3960, A3973, A3980, A3981, A3982
AES-CCMA3958, A3959, A3960, A3973, A3980, A3981, A3982
AES-CFB1A3958, A3959, A3960, A3973, A3980, A3981, A3982
AES-CFB128A3958, A3959, A3960, A3973, A3980, A3981, A3982
AES-CFB8A3958, A3959, A3960, A3973, A3980, A3981, A3982
AES-CMACA3958, A3959, A3960, A3973, A3980, A3981, A3982
AES-CTRA3958, A3959, A3960, A3973, A3980, A3981, A3982
AES-ECBA3958, A3959, A3960, A3971, A3973, A3978, A3980, A3981, A3982, A3984, A3985, A3986, A3987
AES-GCMA3961, A3974, A3975, A3976, A3988, A3989, A3990, A3994, A3995, A3996, A3997, A3998, A3999, A4000, A4001, A4002
AES-GMACA3961, A3974, A3975, A3976, A3988, A3989, A3990, A3994, A3995, A3996, A3997, A3998, A3999, A4000, A4001, A4002
AES-KWA3958, A3959, A3960, A3973, A3980, A3981, A3982
AES-KWPA3958, A3959, A3960, A3973, A3980, A3981, A3982
AES-OFBA3958, A3959, A3960, A3973, A3980, A3981, A3982
AES-XTS Testing Revision 2.0A3958, A3959, A3960, A3973, A3980, A3981, A3982
Counter DRBGA3970
ECDSA KeyGen (FIPS186-4)A3962, A3966, A3977, A3983, A3993, A4003, A4004, A4005
ECDSA KeyVer (FIPS186-4)A3962, A3966, A3977, A3983, A3993, A4003, A4004, A4005
ECDSA SigGen (FIPS186-4)A3962, A3964, A3966, A3967, A3972, A3977, A3979, A3983, A3993, A4003, A4004, A4005
ECDSA SigVer (FIPS186-4)A3962, A3964, A3966, A3967, A3972, A3977, A3979, A3983, A3993, A4003, A4004, A4005
Hash DRBGA3970
HMAC DRBGA3970
HMAC-SHA-1A3962, A3977, A3983, A3993, A4003, A4004, A4005
HMAC-SHA2-224A3962, A3977, A3983, A3993, A4003, A4004, A4005
HMAC-SHA2-256A3962, A3963, A3977, A3983, A3993, A4003, A4004, A4005
HMAC-SHA2-384A3962, A3977, A3983, A3993, A4003, A4004, A4005
HMAC-SHA2-512A3962, A3977, A3983, A3993, A4003, A4004, A4005
HMAC-SHA2-512/224A3962, A3977, A3983, A3993, A4003, A4004, A4005
HMAC-SHA2-512/256A3962, A3977, A3983, A3993, A4003, A4004, A4005
HMAC-SHA3-224A3964, A3972, A3979
HMAC-SHA3-256A3964, A3972, A3979
HMAC-SHA3-384A3964, A3972, A3979
HMAC-SHA3-512A3964, A3972, A3979
KAS-ECC-SSC Sp800-56Ar3A3962, A3968, A3977, A3983, A3993, A4003, A4004, A4005
KAS-FFC-SSC Sp800-56Ar3A3992
KDA HKDF Sp800-56Cr1A3969
KDA OneStep SP800-56Cr2A3965
KDF ANS 9.42A3962, A3964, A3972, A3977, A3979, A3983, A3993, A4003, A4004, A4005
KDF ANS 9.63A3962, A3977, A3983, A3993, A4003, A4004, A4005
KDF SP800-108A3991
KDF SSHA3971, A3978, A3984, A3985, A3986, A3987
KMAC-128A3964, A3972, A3979
KMAC-256A3964, A3972, A3979
PBKDFA3962, A3964, A3972, A3977, A3979, A3983, A3993, A4003, A4004, A4005
RSA KeyGen (FIPS186-4)A3962, A3977, A3983, A3993, A4003, A4004, A4005
RSA SigGen (FIPS186-4)A3962, A3977, A3983, A3993, A4003, A4004, A4005
RSA SigVer (FIPS186-4)A3962, A3977, A3983, A3993, A4003, A4004, A4005
Safe Primes Key GenerationA3992
Safe Primes Key VerificationA3992
SHA-1A3962, A3977, A3983, A3993, A4003, A4004, A4005
SHA2-224A3962, A3977, A3983, A3993, A4003, A4004, A4005
SHA2-256A3962, A3963, A3977, A3983, A3993, A4003, A4004, A4005
SHA2-384A3962, A3977, A3983, A3993, A4003, A4004, A4005
SHA2-512A3962, A3977, A3983, A3993, A4003, A4004, A4005
SHA2-512/224A3962, A3977, A3983, A3993, A4003, A4004, A4005
SHA2-512/256A3962, A3977, A3983, A3993, A4003, A4004, A4005
SHA3-224A3964, A3972, A3979
SHA3-256A3964, A3972, A3979
SHA3-384A3964, A3972, A3979
SHA3-512A3964, A3972, A3979
SHAKE-128A3964, A3972, A3979
SHAKE-256A3964, A3972, A3979
TLS v1.2 KDF RFC7627A3962, A3977, A3983, A3993, A4003, A4004, A4005
TLS v1.3 KDFA3969

Tested configurations

  • Ubuntu 22.04 on IBM z15 with IBM z15 processor with PAI
  • Ubuntu 22.04 on IBM z15 with IBM z15 processor without PAI
  • Ubuntu 22.04 running on Amazon Web Services (AWS) c6g.metal with AWS Graviton2 processor with PAA
  • Ubuntu 22.04 running on Amazon Web Services (AWS) c6g.metal with AWS Graviton2 processor without PAA
  • Ubuntu 22.04 running on Supermicro SYS-1019P-WTR with Intel Xeon Gold 6226 processor with PAA
  • Ubuntu 22.04 running on Supermicro SYS-1019P-WTR with Intel Xeon Gold 6226 processor without PAA

Validation history

DateTypeLab
2024-09-11Initialatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2024-09-11

Source documents