808bits

Canonical Ltd. Ubuntu 22.04 GnuTLS Cryptographic Module

FIPS 140-3 certificate #4855 · Canonical Ltd. · data as of 2026-09-08

Canonical Ltd. Ubuntu 22.04 GnuTLS Cryptographic Module, from Canonical Ltd., holds FIPS 140-3 certificate #4855 at overall level 1. The validation is active, with a sunset date of 2029-10-27. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Active. Sunset date 2029-10-27, 1143 days away.
Caveat: Interim validation. When operated in the approved mode. When installed, initialized, and configured as specified in section 11.1 of the Security Policy.

Certificate

Certificate number4855
StandardFIPS 140-3
Statusactive
Sunset date2029-10-27
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorCanonical Ltd. · website
Software versions3.7.3-4ubuntu1.2+Fips1.1

Module description

Quoted from the NIST CMVP entry for this certificate.

GnuTLS is a secure communications library implementing the TLS protocol. It provides a simple C language application programming interface to access the secure communications protocols as well as APIs to parse and write X.509, PKCS#12, and other required structures.

Security level exceptions

  • Physical security: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Approved algorithms (36)

AlgorithmCAVP certificates
AES-CBCA3665, A3667, A3708, A3709, A3711, A3712, A3713, A3714
AES-CCMA3665, A3708, A3711
AES-CFB8A3670, A3716, A3717
AES-CMACA3667, A3708, A3711, A3714
AES-GCMA3665, A3667, A3708, A3709, A3711, A3712, A3713
AES-GMACA3667
AES-XTS Testing Revision 2.0A3668
Counter DRBGA3667
ECDSA KeyGen (FIPS186-4)A3667
ECDSA KeyVer (FIPS186-4)A3667
ECDSA SigGen (FIPS186-4)A3667
ECDSA SigVer (FIPS186-4)A3667
HMAC-SHA-1A3665, A3667, A3710, A3714
HMAC-SHA2-224A3665, A3667, A3710, A3714
HMAC-SHA2-256A3665, A3667, A3710, A3714
HMAC-SHA2-384A3665, A3667, A3710, A3714
HMAC-SHA2-512A3665, A3667, A3710, A3714
KAS-ECC-SSC Sp800-56Ar3A3667
KAS-FFC-SSC Sp800-56Ar3A3667
KDA HKDF Sp800-56Cr1A3666
KDF TLSA3667
PBKDFA3667
RSA KeyGen (FIPS186-4)A3667
RSA SigGen (FIPS186-4)A3667
RSA SigVer (FIPS186-4)A3667
Safe Primes Key GenerationA3667
SHA-1A3665, A3667, A3710, A3714
SHA2-224A3665, A3667, A3710, A3714
SHA2-256A3665, A3667, A3710, A3714
SHA2-384A3665, A3667, A3710, A3714
SHA2-512A3665, A3667, A3710, A3714
SHA3-224A3669, A3715
SHA3-256A3669, A3715
SHA3-384A3669, A3715
SHA3-512A3669, A3715
TLS v1.2 KDF RFC7627A3667

Tested configurations

  • Ubuntu 22.04 LTS (Jammy Jellyfish) running on Amazon Web Services (AWS) c6g.metal with AWS Graviton2 with PAA
  • Ubuntu 22.04 LTS (Jammy Jellyfish) running on Amazon Web Services (AWS) c6g.metal with AWS Graviton2 without PAA
  • Ubuntu 22.04 LTS (Jammy Jellyfish) running on IBM z15 with z15 with PAI
  • Ubuntu 22.04 LTS (Jammy Jellyfish) running on IBM z15 with z15 without PAI
  • Ubuntu 22.04 LTS (Jammy Jellyfish) running on Supermicro SYS-1019P-WTR with Intel® Xeon® Gold 6226 with PAA
  • Ubuntu 22.04 LTS (Jammy Jellyfish) running on Supermicro SYS-1019P-WTR with Intel® Xeon® Gold 6226 without PAA

Validation history

DateTypeLab
2024-10-28Initialatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2024-10-28

Source documents