808bits

Red Hat Enterprise Linux 8 Kernel Cryptographic API

FIPS 140-3 certificate #4804 · Red Hat(R), Inc. · data as of 2026-09-03

Red Hat Enterprise Linux 8 Kernel Cryptographic API, from Red Hat(R), Inc., holds FIPS 140-3 certificate #4804 at overall level 1. The validation is active, with a sunset date of 2026-09-18. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Active. Sunset date 2026-09-18, 14 days away.
Caveat: Interim validation. When operated in approved mode. When installed, initialized and configured as specified in section 11 of the Security Policy. The module generates random strings whose strengths are modified by available entropy.

Certificate

Certificate number4804
StandardFIPS 140-3
Statusactive
Sunset date2026-09-18
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorRed Hat(R), Inc. · website
Software versions4.18.0-372.52.1.el8_6; libkcapi 1.2.0-2.el8

Module description

Quoted from the NIST CMVP entry for this certificate.

The Red Hat Enterprise Linux 8 Kernel Cryptographic API provides a C language API for use by other (kernel space and user space) processes that require cryptographic functionality

Security level exceptions

  • Physical security: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Approved algorithms (32)

AlgorithmCAVP certificates
AES-CBCA3648, A3654, A3657
AES-CBC-CS3A3651, A3661
AES-CCMA3648, A3657
AES-CFB128A3650, A3660
AES-CMACA3648, A3657
AES-CTRA3648, A3654, A3657
AES-ECBA3648, A3652, A3653, A3654, A3655, A3656, A3657, A3658, A3659
AES-GCMA3648, A3652, A3653, A3654, A3655, A3656, A3657, A3658, A3659
AES-GMACA3648, A3657
AES-XTS Testing Revision 2.0A3648, A3654, A3657
Counter DRBGA3648, A3652, A3653, A3654, A3655, A3656, A3657, A3658, A3659
Hash DRBGA3648, A3652, A3653, A3654, A3655, A3656, A3657, A3658, A3659, A3662, A3663, A3664
HMAC DRBGA3648, A3652, A3653, A3654, A3655, A3656, A3657, A3658, A3659, A3662, A3663, A3664
HMAC-SHA-1A3648, A3662, A3663, A3664
HMAC-SHA2-224A3648, A3662, A3663, A3664
HMAC-SHA2-256A3648, A3662, A3663, A3664
HMAC-SHA2-384A3648, A3662, A3663, A3664
HMAC-SHA2-512A3648, A3662, A3663, A3664
HMAC-SHA3-224A3649
HMAC-SHA3-256A3649
HMAC-SHA3-384A3649
HMAC-SHA3-512A3649
RSA SigVer (FIPS186-4)A3648, A3662, A3663, A3664
SHA-1A3648, A3662, A3663, A3664
SHA2-224A3648, A3662, A3663, A3664
SHA2-256A3648, A3662, A3663, A3664
SHA2-384A3648, A3662, A3663, A3664
SHA2-512A3648, A3662, A3663, A3664
SHA3-224A3649
SHA3-256A3649
SHA3-384A3649
SHA3-512A3649

Tested configurations

  • Red Hat Enterprise Linux 8 running on Dell PowerEdge R440 with Intel Xeon Silver 4216 with PAA
  • Red Hat Enterprise Linux 8 running on Dell PowerEdge R440 with Intel Xeon Silver 4216 without PAA

Validation history

DateTypeLab
2024-09-19Initialatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2024-09-19

Source documents