808bits

Red Hat Enterprise Linux 9 gnutls

FIPS 140-3 certificate #4846 · Red Hat, Inc. · data as of 2026-09-12

Red Hat Enterprise Linux 9 gnutls, from Red Hat, Inc., holds FIPS 140-3 certificate #4846 at overall level 1. The validation is active, with a sunset date of 2026-10-20. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Active. Sunset date 2026-10-20, 37 days away.
Caveat: Interim validation. When operated in approved mode. When installed, initialized and configured as specified in Section 11 of the Security Policy. The module generates cryptographic keys whose strengths are modified by available entropy.

Certificate

Certificate number4846
StandardFIPS 140-3
Statusactive
Sunset date2026-10-20
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorRed Hat, Inc. · website
Software versions3.7.6-074d015ce201f434

Module description

Quoted from the NIST CMVP entry for this certificate.

GnuTLS is a secure communications library implementing the TLS and DTLS protocols. It provides a simple C language application programming interface to access the secure communications protocols as well as APIs to parse and write X.509, PKCS#12, and other required structures which is shipped with Red Hat Enterprise Linux 9.

Security level exceptions

  • Physical security: N/A
  • Non-invasive security: N/A

Approved algorithms (36)

AlgorithmCAVP certificates
AES-CBCA4827, A4828, A4833, A5572, A5573, A5574
AES-CCMA4827, A5572, A5573
AES-CFB8A4830, A4831, A4836
AES-CMACA4827, A4828, A4833, A5572, A5573
AES-ECBA4842
AES-GCMA4827, A4828, A4833, A5572, A5573, A5574
AES-GMACA4833
AES-XTS Testing Revision 2.0A4834
Counter DRBGA4833
ECDSA KeyGen (FIPS186-4)A4833
ECDSA KeyVer (FIPS186-4)A4833
ECDSA SigGen (FIPS186-4)A4833
ECDSA SigVer (FIPS186-4)A4833
HMAC-SHA-1A4828, A4833, A5575
HMAC-SHA2-224A4828, A4833, A5575
HMAC-SHA2-256A4828, A4833, A5575
HMAC-SHA2-384A4828, A4833, A5575
HMAC-SHA2-512A4828, A4833, A5575
KAS-ECC-SSC Sp800-56Ar3A4833
KAS-FFC-SSC Sp800-56Ar3A4833
KDA HKDF Sp800-56Cr1A4832
PBKDFA4833
RSA KeyGen (FIPS186-4)A4833
RSA SigGen (FIPS186-4)A4833
RSA SigVer (FIPS186-4)A4833
Safe Primes Key GenerationA4833
SHA-1A4828, A4833, A5575
SHA2-224A4828, A4833, A5575
SHA2-256A4828, A4833, A5575
SHA2-384A4828, A4833, A5575
SHA2-512A4828, A4833, A5575
SHA3-224A4829, A4835
SHA3-256A4829, A4835
SHA3-384A4829, A4835
SHA3-512A4829, A4835
TLS v1.2 KDF RFC7627A4833

Tested configurations

  • Red Hat Enterprise Linux 9 running on Dell PowerEdge R440 with Intel® Xeon® Silver 4216 with PAA
  • Red Hat Enterprise Linux 9 running on Dell PowerEdge R440 with Intel® Xeon® Silver 4216 without PAA
  • Red Hat Enterprise Linux 9 running on IBM 9080-HEX with PowerVM FW1040.00 with VIOS 3.1.3.00 with IBM POWER10 POWER10 without PAI
  • Red Hat Enterprise Linux 9 running on IBM 9080-HEX with PowerVM FW1040.00 with VIOS 3.1.3.00 with IBM POWER10 with PAI
  • Red Hat Enterprise Linux 9 running on IBM z16 3931-A01 with IBM z16 with PAI
  • Red Hat Enterprise Linux 9 running on IBM z16 3931-A01 with IBM z16 without PAI

Validation history

DateTypeLab
2024-10-21Initialatsec information security corporation
2025-12-05Updateatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2024-10-21

Source documents