808bits

Red Hat Enterprise Linux 9 - OpenSSL FIPS Provider

FIPS 140-3 certificate #4857 · Red Hat(R), Inc. · data as of 2026-09-15

Red Hat Enterprise Linux 9 - OpenSSL FIPS Provider, from Red Hat(R), Inc., holds FIPS 140-3 certificate #4857 at overall level 1. The validation is active, with a sunset date of 2029-10-28. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Active. Sunset date 2029-10-28, 1138 days away.
Caveat: Interim validation. When operated in approved mode. When installed, initialized and configured as specified in Section 11.2 of the Security Policy. The module generates SSPs (e.g., keys) whose strengths are modified by available entropy.

Certificate

Certificate number4857
StandardFIPS 140-3
Statusactive
Sunset date2029-10-28
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorRed Hat(R), Inc. · website
Software versions3.0.7-395c1a240fbfffd8

Module description

Quoted from the NIST CMVP entry for this certificate.

The Red Hat Enterprise Linux 9 - OpenSSL FIPS Provider provides a C language application program interface (API) for use by other applications that require cryptographic functionality.

Security level exceptions

  • Physical security: N/A
  • Non-invasive security: N/A

Approved algorithms (67)

AlgorithmCAVP certificates
AES-CBCA4809, A4810, A4811, A5560, A5576, A5580
AES-CBC-CS1A4809, A4810, A4811, A5560, A5576, A5580
AES-CBC-CS2A4809, A4810, A4811, A5560, A5576, A5580
AES-CBC-CS3A4809, A4810, A4811, A5560, A5576, A5580
AES-CCMA4809, A4810, A4811, A5560, A5576, A5580
AES-CFB1A4809, A4810, A4811, A5560, A5576, A5580
AES-CFB128A4809, A4810, A4811, A5560, A5576, A5580
AES-CFB8A4809, A4810, A4811, A5560, A5576, A5580
AES-CMACA4809, A4810, A4811, A5560, A5576, A5580
AES-CTRA4809, A4810, A4811, A5560, A5576, A5580
AES-ECBA4809, A4810, A4811, A4837, A4838, A4839, A4840, A4841, A5560, A5576, A5579, A5580, A5586
AES-GCMA4812, A4815, A4816, A4817, A4818, A4819, A4820, A4821, A4822, A5577, A5581, A5582, A5583, A5584
AES-GMACA4812, A4815, A4816, A4817, A4818, A4819, A4820, A4821, A4822, A5577, A5581, A5582, A5583, A5584
AES-KWA4809, A4810, A4811, A5560, A5576, A5580
AES-KWPA4809, A4810, A4811, A5560, A5576, A5580
AES-OFBA4809, A4810, A4811, A5560, A5576, A5580
AES-XTS Testing Revision 2.0A4809, A4810, A4811, A5560, A5576, A5580
Counter DRBGA4808
ECDSA KeyGen (FIPS186-5)A4813, A4823, A4824, A4825, A4826, A5578, A5585
ECDSA KeyVer (FIPS186-5)A4813, A4823, A4824, A4825, A4826, A5578, A5585
ECDSA SigGen (FIPS186-5)A4813, A4814, A4823, A4824, A4825, A4826, A5578, A5585, A5587
ECDSA SigVer (FIPS186-5)A4813, A4814, A4823, A4824, A4825, A4826, A5578, A5585, A5587
Hash DRBGA4808
HMAC DRBGA4808
HMAC-SHA-1A4813, A4823, A4824, A4825, A4826, A5578, A5585
HMAC-SHA2-224A4813, A4823, A4824, A4825, A4826, A5578, A5585
HMAC-SHA2-256A4813, A4823, A4824, A4825, A4826, A5578, A5585
HMAC-SHA2-384A4813, A4823, A4824, A4825, A4826, A5578, A5585
HMAC-SHA2-512A4813, A4823, A4824, A4825, A4826, A5578, A5585
HMAC-SHA2-512/224A4813, A4823, A4824, A4825, A4826, A5578, A5585
HMAC-SHA2-512/256A4813, A4823, A4824, A4825, A4826, A5578, A5585
HMAC-SHA3-224A4814, A5587
HMAC-SHA3-256A4814, A5587
HMAC-SHA3-384A4814, A5587
HMAC-SHA3-512A4814, A5587
KAS-ECC-SSC Sp800-56Ar3A4813, A4823, A4824, A4825, A4826, A5578, A5585
KAS-FFC-SSC Sp800-56Ar3A4845
KAS-IFC-SSCA4813, A4823, A4824, A4825, A4826, A5578, A5585
KDA HKDF Sp800-56Cr1A4807
KDA OneStep SP800-56Cr2A4844
KDF ANS 9.42A4813, A4814, A4823, A4824, A4825, A4826, A5578, A5585, A5587
KDF ANS 9.63A4813, A4814, A4823, A4824, A4825, A4826, A5578, A5585, A5587
KDF SP800-108A4843
KDF SSHA4837, A4838, A4839, A4840, A4841, A5579, A5586
KTS-IFCA4813, A4823, A4824, A4825, A4826, A5578, A5585
PBKDFA4813, A4814, A4823, A4824, A4825, A4826, A5578, A5585, A5587
RSA KeyGen (FIPS186-5)A4813, A4823, A4824, A4825, A4826, A5578, A5585
RSA SigGen (FIPS186-5)A4813, A4823, A4824, A4825, A4826, A5578, A5585
RSA SigVer (FIPS186-4)A4813, A4823, A4824, A4825, A4826, A5578, A5585
RSA SigVer (FIPS186-5)A4813, A4823, A4824, A4825, A4826, A5578, A5585
Safe Primes Key GenerationA4845
Safe Primes Key VerificationA4845
SHA-1A4813, A4823, A4824, A4825, A4826, A5578, A5585
SHA2-224A4813, A4823, A4824, A4825, A4826, A5578, A5585
SHA2-256A4813, A4823, A4824, A4825, A4826, A5578, A5585
SHA2-384A4813, A4823, A4824, A4825, A4826, A5578, A5585
SHA2-512A4813, A4823, A4824, A4825, A4826, A5578, A5585
SHA2-512/224A4813, A4823, A4824, A4825, A4826, A5578, A5585
SHA2-512/256A4813, A4823, A4824, A4825, A4826, A5578, A5585
SHA3-224A4814, A5587
SHA3-256A4814, A5587
SHA3-384A4814, A5587
SHA3-512A4814, A5587
SHAKE-128A4814, A5587
SHAKE-256A4814, A5587
TLS v1.2 KDF RFC7627A4813, A4823, A4824, A4825, A4826, A5578, A5586
TLS v1.3 KDFA4807

Tested configurations

  • Red Hat Enterprise Linux 9 on PowerVM FW1040.00 with VIOS 3.1.3.00 running on IBM 9080-HEX with IBM POWER10 with PAI
  • Red Hat Enterprise Linux 9 on PowerVM FW1040.00 with VIOS 3.1.3.00 running on IBM 9080-HEX with IBM POWER10 without PAI
  • Red Hat Enterprise Linux 9 running on Dell PowerEdge R440 with Intel(R) Xeon(R) Silver 4216 with PAA
  • Red Hat Enterprise Linux 9 running on Dell PowerEdge R440 with Intel(R) Xeon(R) Silver 4216 without PAA
  • Red Hat Enterprise Linux 9 running on IBM z16 3931-A01 with IBM z16 with PAI
  • Red Hat Enterprise Linux 9 running on IBM z16 3931-A01 with IBM z16 without PAI

Validation history

DateTypeLab
2024-10-29Initialatsec information security corporation
2025-11-28Updateatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2024-10-29

Source documents