808bits

Canonical Ltd. Ubuntu 22.04 GnuTLS Cryptographic Module

FIPS 140-3 certificate #4855 · Canonical Ltd. · data as of 2026-08-28
Active. Sunset date 2029-10-27, 1155 days away.
Caveat: Interim validation. When operated in the approved mode. When installed, initialized, and configured as specified in section 11.1 of the Security Policy.

Certificate

Certificate number4855
StandardFIPS 140-3
Statusactive
Sunset date2029-10-27
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorCanonical Ltd. · website
Software versions3.7.3-4ubuntu1.2+Fips1.1

Module description

GnuTLS is a secure communications library implementing the TLS protocol. It provides a simple C language application programming interface to access the secure communications protocols as well as APIs to parse and write X.509, PKCS#12, and other required structures.

Security level exceptions

  • Physical security: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES-CBCA3665
AES-CBCA3667
AES-CBCA3708
AES-CBCA3709
AES-CBCA3711
AES-CBCA3712
AES-CBCA3713
AES-CBCA3714
AES-CCMA3665
AES-CCMA3708
AES-CCMA3711
AES-CFB8A3670
AES-CFB8A3716
AES-CFB8A3717
AES-CMACA3667
AES-CMACA3708
AES-CMACA3711
AES-CMACA3714
AES-GCMA3665
AES-GCMA3667
AES-GCMA3708
AES-GCMA3709
AES-GCMA3711
AES-GCMA3712
AES-GCMA3713
AES-GMACA3667
AES-XTS Testing Revision 2.0A3668
Counter DRBGA3667
ECDSA KeyGen (FIPS186-4)A3667
ECDSA KeyVer (FIPS186-4)A3667
ECDSA SigGen (FIPS186-4)A3667
ECDSA SigVer (FIPS186-4)A3667
HMAC-SHA-1A3665
HMAC-SHA-1A3667
HMAC-SHA-1A3710
HMAC-SHA-1A3714
HMAC-SHA2-224A3665
HMAC-SHA2-224A3667
HMAC-SHA2-224A3710
HMAC-SHA2-224A3714
HMAC-SHA2-256A3665
HMAC-SHA2-256A3667
HMAC-SHA2-256A3710
HMAC-SHA2-256A3714
HMAC-SHA2-384A3665
HMAC-SHA2-384A3667
HMAC-SHA2-384A3710
HMAC-SHA2-384A3714
HMAC-SHA2-512A3665
HMAC-SHA2-512A3667
HMAC-SHA2-512A3710
HMAC-SHA2-512A3714
KAS-ECC-SSC Sp800-56Ar3A3667
KAS-FFC-SSC Sp800-56Ar3A3667
KDA HKDF Sp800-56Cr1A3666
KDF TLSA3667
PBKDFA3667
RSA KeyGen (FIPS186-4)A3667
RSA SigGen (FIPS186-4)A3667
RSA SigVer (FIPS186-4)A3667
Safe Primes Key GenerationA3667
SHA-1A3665
SHA-1A3667
SHA-1A3710
SHA-1A3714
SHA2-224A3665
SHA2-224A3667
SHA2-224A3710
SHA2-224A3714
SHA2-256A3665
SHA2-256A3667
SHA2-256A3710
SHA2-256A3714
SHA2-384A3665
SHA2-384A3667
SHA2-384A3710
SHA2-384A3714
SHA2-512A3665
SHA2-512A3667
SHA2-512A3710
SHA2-512A3714
SHA3-224A3669
SHA3-224A3715
SHA3-256A3669
SHA3-256A3715
SHA3-384A3669
SHA3-384A3715
SHA3-512A3669
SHA3-512A3715
TLS v1.2 KDF RFC7627A3667

Tested configurations

  • Ubuntu 22.04 LTS (Jammy Jellyfish) running on Amazon Web Services (AWS) c6g.metal with AWS Graviton2 with PAA
  • Ubuntu 22.04 LTS (Jammy Jellyfish) running on Amazon Web Services (AWS) c6g.metal with AWS Graviton2 without PAA
  • Ubuntu 22.04 LTS (Jammy Jellyfish) running on IBM z15 with z15 with PAI
  • Ubuntu 22.04 LTS (Jammy Jellyfish) running on IBM z15 with z15 without PAI
  • Ubuntu 22.04 LTS (Jammy Jellyfish) running on Supermicro SYS-1019P-WTR with Intel® Xeon® Gold 6226 with PAA
  • Ubuntu 22.04 LTS (Jammy Jellyfish) running on Supermicro SYS-1019P-WTR with Intel® Xeon® Gold 6226 without PAA

Validation history

DateTypeLab
2024-10-28Initialatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2024-10-28

Source documents