808bits

Red Hat Enterprise Linux 8 Kernel Cryptographic API

FIPS 140-3 certificate #4804 · Red Hat(R), Inc. · data as of 2026-08-28
Active. Sunset date 2026-09-18, 20 days away.
Caveat: Interim validation. When operated in approved mode. When installed, initialized and configured as specified in section 11 of the Security Policy. The module generates random strings whose strengths are modified by available entropy.

Certificate

Certificate number4804
StandardFIPS 140-3
Statusactive
Sunset date2026-09-18
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorRed Hat(R), Inc. · website
Software versions4.18.0-372.52.1.el8_6; libkcapi 1.2.0-2.el8

Module description

The Red Hat Enterprise Linux 8 Kernel Cryptographic API provides a C language API for use by other (kernel space and user space) processes that require cryptographic functionality

Security level exceptions

  • Physical security: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES-CBCA3648
AES-CBCA3654
AES-CBCA3657
AES-CBC-CS3A3651
AES-CBC-CS3A3661
AES-CCMA3648
AES-CCMA3657
AES-CFB128A3650
AES-CFB128A3660
AES-CMACA3648
AES-CMACA3657
AES-CTRA3648
AES-CTRA3654
AES-CTRA3657
AES-ECBA3648
AES-ECBA3652
AES-ECBA3653
AES-ECBA3654
AES-ECBA3655
AES-ECBA3656
AES-ECBA3657
AES-ECBA3658
AES-ECBA3659
AES-GCMA3648
AES-GCMA3652
AES-GCMA3653
AES-GCMA3654
AES-GCMA3655
AES-GCMA3656
AES-GCMA3657
AES-GCMA3658
AES-GCMA3659
AES-GMACA3648
AES-GMACA3657
AES-XTS Testing Revision 2.0A3648
AES-XTS Testing Revision 2.0A3654
AES-XTS Testing Revision 2.0A3657
Counter DRBGA3648
Counter DRBGA3652
Counter DRBGA3653
Counter DRBGA3654
Counter DRBGA3655
Counter DRBGA3656
Counter DRBGA3657
Counter DRBGA3658
Counter DRBGA3659
Hash DRBGA3648
Hash DRBGA3652
Hash DRBGA3653
Hash DRBGA3654
Hash DRBGA3655
Hash DRBGA3656
Hash DRBGA3657
Hash DRBGA3658
Hash DRBGA3659
Hash DRBGA3662
Hash DRBGA3663
Hash DRBGA3664
HMAC DRBGA3648
HMAC DRBGA3652
HMAC DRBGA3653
HMAC DRBGA3654
HMAC DRBGA3655
HMAC DRBGA3656
HMAC DRBGA3657
HMAC DRBGA3658
HMAC DRBGA3659
HMAC DRBGA3662
HMAC DRBGA3663
HMAC DRBGA3664
HMAC-SHA-1A3648
HMAC-SHA-1A3662
HMAC-SHA-1A3663
HMAC-SHA-1A3664
HMAC-SHA2-224A3648
HMAC-SHA2-224A3662
HMAC-SHA2-224A3663
HMAC-SHA2-224A3664
HMAC-SHA2-256A3648
HMAC-SHA2-256A3662
HMAC-SHA2-256A3663
HMAC-SHA2-256A3664
HMAC-SHA2-384A3648
HMAC-SHA2-384A3662
HMAC-SHA2-384A3663
HMAC-SHA2-384A3664
HMAC-SHA2-512A3648
HMAC-SHA2-512A3662
HMAC-SHA2-512A3663
HMAC-SHA2-512A3664
HMAC-SHA3-224A3649
HMAC-SHA3-256A3649
HMAC-SHA3-384A3649
HMAC-SHA3-512A3649
RSA SigVer (FIPS186-4)A3648
RSA SigVer (FIPS186-4)A3662
RSA SigVer (FIPS186-4)A3663
RSA SigVer (FIPS186-4)A3664
SHA-1A3648
SHA-1A3662
SHA-1A3663
SHA-1A3664
SHA2-224A3648
SHA2-224A3662
SHA2-224A3663
SHA2-224A3664
SHA2-256A3648
SHA2-256A3662
SHA2-256A3663
SHA2-256A3664
SHA2-384A3648
SHA2-384A3662
SHA2-384A3663
SHA2-384A3664
SHA2-512A3648
SHA2-512A3662
SHA2-512A3663
SHA2-512A3664
SHA3-224A3649
SHA3-256A3649
SHA3-384A3649
SHA3-512A3649

Tested configurations

  • Red Hat Enterprise Linux 8 running on Dell PowerEdge R440 with Intel Xeon Silver 4216 with PAA
  • Red Hat Enterprise Linux 8 running on Dell PowerEdge R440 with Intel Xeon Silver 4216 without PAA

Validation history

DateTypeLab
2024-09-19Initialatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2024-09-19

Source documents