808bits

Red Hat Enterprise Linux 9 Kernel Cryptographic API

FIPS 140-3 certificate #4796 · Red Hat(R), Inc. · data as of 2026-09-03

Red Hat Enterprise Linux 9 Kernel Cryptographic API, from Red Hat(R), Inc., holds FIPS 140-3 certificate #4796 at overall level 1. The validation is active, with a sunset date of 2026-09-10. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Active. Sunset date 2026-09-10, 6 days away.
Caveat: Interim validation. When operated in approved mode. When installed, initialized and configured as specified in section 11 of the Security Policy. The module generates random strings whose strengths are modified by available entropy.

Certificate

Certificate number4796
StandardFIPS 140-3
Statusactive
Sunset date2026-09-10
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorRed Hat(R), Inc. · website
Software versions5.14.0-70.53.1.el9_0; 1.3.1-3.el9

Module description

Quoted from the NIST CMVP entry for this certificate.

The Red Hat Enterprise Linux 9 Kernel Cryptographic API provides a C language API for use by other (kernel space and user space) processes that require cryptographic functionality

Security level exceptions

  • Physical security: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Approved algorithms (33)

AlgorithmCAVP certificates
AES-CBCA3629, A3636, A3639, A3719, A3722, A4549
AES-CBC-CS3A3633, A3644, A3727
AES-CCMA3629, A3639, A3719, A3722
AES-CFB128A3631, A3642, A3725
AES-CMACA3629, A3639, A3719, A3722
AES-CTRA3629, A3636, A3639, A3719, A3722, A4549
AES-ECBA3629, A3634, A3635, A3636, A3637, A3638, A3639, A3640, A3641, A3719, A3720, A3721, A3722, A3723, A3724
AES-GCMA3629, A3634, A3635, A3636, A3637, A3638, A3639, A3640, A3641, A3719, A3720, A3721, A3722, A3723, A3724
AES-GMACA3629, A3639, A3719, A3722
AES-OFBA3632, A3643, A3726
AES-XTS Testing Revision 2.0A3629, A3636, A3639, A3719, A3722, A4549
Counter DRBGA3629, A3634, A3635, A3636, A3637, A3638, A3639, A3640, A3641, A3719, A3720, A3721, A3722, A3723, A3724
Hash DRBGA3629, A3634, A3635, A3636, A3637, A3638, A3639, A3640, A3641, A3645, A3646, A3647, A3720, A3721, A3722, A3723, A3724
HMAC DRBGA3629, A3634, A3635, A3636, A3637, A3638, A3639, A3640, A3641, A3645, A3646, A3647, A3720, A3721, A3722, A3723, A3724
HMAC-SHA-1A3629, A3645, A3646, A3647, A3722
HMAC-SHA2-224A3629, A3645, A3646, A3647, A3722
HMAC-SHA2-256A3629, A3645, A3646, A3647, A3722
HMAC-SHA2-384A3629, A3645, A3646, A3647, A3722
HMAC-SHA2-512A3629, A3645, A3646, A3647, A3722
HMAC-SHA3-224A3630, A3728
HMAC-SHA3-256A3630, A3728
HMAC-SHA3-384A3630, A3728
HMAC-SHA3-512A3630, A3728
RSA SigVer (FIPS186-4)A3629, A3645, A3646, A3647, A3722
SHA-1A3629, A3645, A3646, A3647, A3722
SHA2-224A3629, A3645, A3646, A3647, A3722
SHA2-256A3629, A3645, A3646, A3647, A3722
SHA2-384A3629, A3645, A3646, A3647, A3722
SHA2-512A3629, A3645, A3646, A3647, A3722
SHA3-224A3630, A3728
SHA3-256A3630, A3728
SHA3-384A3630, A3728
SHA3-512A3630, A3728

Tested configurations

  • Red Hat Enterprise Linux 9 on IBM z16 3931-A01 with IBM z16 with PAI
  • Red Hat Enterprise Linux 9 on IBM z16 3931-A01 with IBM z16 without PAI
  • Red Hat Enterprise Linux 9 running on Dell PowerEdge R440 with Intel Xeon Silver 4216 with PAA
  • Red Hat Enterprise Linux 9 running on Dell PowerEdge R440 with Intel Xeon Silver 4216 without PAA
  • Red Hat Enterprise Linux 9 with PowerVM FW1040.00 with VIOS 3.1.3.00 running on IBM 9080-HEX with IBM POWER10 without PAA

Validation history

DateTypeLab
2024-09-11Initialatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2024-09-11

Source documents