Red Hat Enterprise Linux 9 Kernel Cryptographic API
Red Hat Enterprise Linux 9 Kernel Cryptographic API, from Red Hat(R), Inc., holds FIPS 140-3 certificate #4796 at overall level 1. The validation is active, with a sunset date of 2026-09-10. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.
Caveat: Interim validation. When operated in approved mode. When installed, initialized and configured as specified in section 11 of the Security Policy. The module generates random strings whose strengths are modified by available entropy.
Certificate
| Certificate number | 4796 |
|---|---|
| Standard | FIPS 140-3 |
| Status | active |
| Sunset date | 2026-09-10 |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Red Hat(R), Inc. · website |
| Software versions | 5.14.0-70.53.1.el9_0; 1.3.1-3.el9 |
Module description
Quoted from the NIST CMVP entry for this certificate.
The Red Hat Enterprise Linux 9 Kernel Cryptographic API provides a C language API for use by other (kernel space and user space) processes that require cryptographic functionality
Security level exceptions
- Physical security: N/A
- Non-invasive security: N/A
- Mitigation of other attacks: N/A
Approved algorithms (33)
Tested configurations
- Red Hat Enterprise Linux 9 on IBM z16 3931-A01 with IBM z16 with PAI
- Red Hat Enterprise Linux 9 on IBM z16 3931-A01 with IBM z16 without PAI
- Red Hat Enterprise Linux 9 running on Dell PowerEdge R440 with Intel Xeon Silver 4216 with PAA
- Red Hat Enterprise Linux 9 running on Dell PowerEdge R440 with Intel Xeon Silver 4216 without PAA
- Red Hat Enterprise Linux 9 with PowerVM FW1040.00 with VIOS 3.1.3.00 running on IBM 9080-HEX with IBM POWER10 without PAA
Validation history
| Date | Type | Lab |
|---|---|---|
| 2024-09-11 | Initial | atsec information security corporation |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2024-09-11