808bits

Oracle Linux 9 NSS Cryptographic Module

FIPS 140-3 certificate #4801 · Oracle Corporation · data as of 2026-09-15

Oracle Linux 9 NSS Cryptographic Module, from Oracle Corporation, holds FIPS 140-3 certificate #4801 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Replaced by certificate #5339. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: Interim validation. When operated in approved mode. When installed, initialized and configured as specified in section 11 of the Security Policy.

Certificate

Certificate number4801
StandardFIPS 140-3
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorOracle Corporation · website
Software versions4.35.0-381552536e763d0c

Module description

Quoted from the NIST CMVP entry for this certificate.

Network Security Services (NSS) is a set of open source C libraries designed to support cross-platform development of security-enabled applications. NSS implements major Internet security standards. NSS is available free of charge under a variety of open source compatible licenses. See http://www.mozilla.org/projects/security/pki/nss/.

Security level exceptions

  • Physical security: N/A
  • Non-invasive security: N/A

Approved algorithms (35)

AlgorithmCAVP certificates
AES-CBCA4760, A4767, A4769
AES-CBC-CS1A4765
AES-CMACA4762
AES-CTRA4760, A4769
AES-ECBA4760, A4767, A4769
AES-GCMA4760, A4767, A4769
AES-KWA4761, A4766, A4768
AES-KWPA4761, A4766, A4768
DSA SigVer (FIPS186-4)A4760
ECDSA KeyGen (FIPS186-4)A4760
ECDSA KeyVer (FIPS186-4)A4760
ECDSA SigGen (FIPS186-4)A4760
ECDSA SigVer (FIPS186-4)A4760
Hash DRBGA4760
HMAC-SHA2-224A4760
HMAC-SHA2-256A4760
HMAC-SHA2-384A4760
HMAC-SHA2-512A4760
KAS-ECC-SSC Sp800-56Ar3A4760
KAS-FFC-SSC Sp800-56Ar3A4760
KDA HKDF Sp800-56Cr1A4759
KDF IKEv2A4764
KDF SP800-108A4763
KDF TLSA4760
PBKDFA4760
RSA KeyGen (FIPS186-4)A4760
RSA SigGen (FIPS186-4)A4760
RSA SigVer (FIPS186-2)A4760
RSA SigVer (FIPS186-4)A4760
Safe Primes Key GenerationA4760
SHA2-224A4760
SHA2-256A4760
SHA2-384A4760
SHA2-512A4760
TLS v1.2 KDF RFC7627A4760

Tested configurations

  • Oracle Linux 9 on KVM on Oracle Linux 8 running on ORACLE SERVER A1-2c with Ampere® Altra® Q80-30 with PAA
  • Oracle Linux 9 on KVM on Oracle Linux 8 running on ORACLE SERVER A1-2c with Ampere® Altra® Q80-30 without PAA
  • Oracle Linux 9 on KVM on Oracle Linux 8 running on ORACLE SERVER E4-2c with AMD EPYC 7J13 with PAA
  • Oracle Linux 9 on KVM on Oracle Linux 8 running on ORACLE SERVER E4-2c with AMD EPYC 7J13 without PAA
  • Oracle Linux 9 on KVM on Oracle Linux 8 running on ORACLE SERVER X9-2c with Intel® Xeon® Platinum 8358 with PAA
  • Oracle Linux 9 on KVM on Oracle Linux 8 running on ORACLE SERVER X9-2c with Intel® Xeon® Platinum 8358 without PAA

Validation history

DateTypeLab
2024-09-16Initialatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2024-09-16

Source documents