Red Hat Enterprise Linux 9 gnutls
Caveat: Interim validation. When operated in approved mode. When installed, initialized and configured as specified in Section 11 of the Security Policy. The module generates cryptographic keys whose strengths are modified by available entropy.
Certificate
| Certificate number | 4846 |
|---|---|
| Standard | FIPS 140-3 |
| Status | active |
| Sunset date | 2026-10-20 |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Red Hat, Inc. · website |
| Software versions | 3.7.6-074d015ce201f434 |
Module description
GnuTLS is a secure communications library implementing the TLS and DTLS protocols. It provides a simple C language application programming interface to access the secure communications protocols as well as APIs to parse and write X.509, PKCS#12, and other required structures which is shipped with Red Hat Enterprise Linux 9.
Security level exceptions
- Physical security: N/A
- Non-invasive security: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES-CBC | A4827 |
| AES-CBC | A4828 |
| AES-CBC | A4833 |
| AES-CBC | A5572 |
| AES-CBC | A5573 |
| AES-CBC | A5574 |
| AES-CCM | A4827 |
| AES-CCM | A5572 |
| AES-CCM | A5573 |
| AES-CFB8 | A4830 |
| AES-CFB8 | A4831 |
| AES-CFB8 | A4836 |
| AES-CMAC | A4827 |
| AES-CMAC | A4828 |
| AES-CMAC | A4833 |
| AES-CMAC | A5572 |
| AES-CMAC | A5573 |
| AES-ECB | A4842 |
| AES-GCM | A4827 |
| AES-GCM | A4828 |
| AES-GCM | A4833 |
| AES-GCM | A5572 |
| AES-GCM | A5573 |
| AES-GCM | A5574 |
| AES-GMAC | A4833 |
| AES-XTS Testing Revision 2.0 | A4834 |
| Counter DRBG | A4833 |
| ECDSA KeyGen (FIPS186-4) | A4833 |
| ECDSA KeyVer (FIPS186-4) | A4833 |
| ECDSA SigGen (FIPS186-4) | A4833 |
| ECDSA SigVer (FIPS186-4) | A4833 |
| HMAC-SHA-1 | A4828 |
| HMAC-SHA-1 | A4833 |
| HMAC-SHA-1 | A5575 |
| HMAC-SHA2-224 | A4828 |
| HMAC-SHA2-224 | A4833 |
| HMAC-SHA2-224 | A5575 |
| HMAC-SHA2-256 | A4828 |
| HMAC-SHA2-256 | A4833 |
| HMAC-SHA2-256 | A5575 |
| HMAC-SHA2-384 | A4828 |
| HMAC-SHA2-384 | A4833 |
| HMAC-SHA2-384 | A5575 |
| HMAC-SHA2-512 | A4828 |
| HMAC-SHA2-512 | A4833 |
| HMAC-SHA2-512 | A5575 |
| KAS-ECC-SSC Sp800-56Ar3 | A4833 |
| KAS-FFC-SSC Sp800-56Ar3 | A4833 |
| KDA HKDF Sp800-56Cr1 | A4832 |
| PBKDF | A4833 |
| RSA KeyGen (FIPS186-4) | A4833 |
| RSA SigGen (FIPS186-4) | A4833 |
| RSA SigVer (FIPS186-4) | A4833 |
| Safe Primes Key Generation | A4833 |
| SHA-1 | A4828 |
| SHA-1 | A4833 |
| SHA-1 | A5575 |
| SHA2-224 | A4828 |
| SHA2-224 | A4833 |
| SHA2-224 | A5575 |
| SHA2-256 | A4828 |
| SHA2-256 | A4833 |
| SHA2-256 | A5575 |
| SHA2-384 | A4828 |
| SHA2-384 | A4833 |
| SHA2-384 | A5575 |
| SHA2-512 | A4828 |
| SHA2-512 | A4833 |
| SHA2-512 | A5575 |
| SHA3-224 | A4829 |
| SHA3-224 | A4835 |
| SHA3-256 | A4829 |
| SHA3-256 | A4835 |
| SHA3-384 | A4829 |
| SHA3-384 | A4835 |
| SHA3-512 | A4829 |
| SHA3-512 | A4835 |
| TLS v1.2 KDF RFC7627 | A4833 |
Tested configurations
- Red Hat Enterprise Linux 9 running on Dell PowerEdge R440 with Intel® Xeon® Silver 4216 with PAA
- Red Hat Enterprise Linux 9 running on Dell PowerEdge R440 with Intel® Xeon® Silver 4216 without PAA
- Red Hat Enterprise Linux 9 running on IBM 9080-HEX with PowerVM FW1040.00 with VIOS 3.1.3.00 with IBM POWER10 POWER10 without PAI
- Red Hat Enterprise Linux 9 running on IBM 9080-HEX with PowerVM FW1040.00 with VIOS 3.1.3.00 with IBM POWER10 with PAI
- Red Hat Enterprise Linux 9 running on IBM z16 3931-A01 with IBM z16 with PAI
- Red Hat Enterprise Linux 9 running on IBM z16 3931-A01 with IBM z16 without PAI
Validation history
| Date | Type | Lab |
|---|---|---|
| 2024-10-21 | Initial | atsec information security corporation |
| 2025-12-05 | Update | atsec information security corporation |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2024-10-21