808bits

Canonical Ltd. Ubuntu 22.04 Strongswan Cryptographic Module

FIPS 140-3 certificate #4911 · Canonical Ltd. · data as of 2026-09-03

Canonical Ltd. Ubuntu 22.04 Strongswan Cryptographic Module, from Canonical Ltd., holds FIPS 140-3 certificate #4911 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Moved to historical list due to dependency on certificate #4894. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: Interim validation. When installed, initialized and configured as specified in Section 11.1 of the Security Policy with module Canonical Ltd. Ubuntu 22.04 OpenSSL Cryptographic Module validated to FIPS 140-3 under Cert. #4794, operating in the approved mode, and with module Canonical Ltd. Ubuntu 22.04 Kernel Crypto API Cryptographic Module validated to FIPS 140-3 under Cert. #4894, operating in the approved mode.

Certificate

Certificate number4911
StandardFIPS 140-3
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorCanonical Ltd. · website
Software versions5.9.5-2ubuntu2.1+Fips1

Module description

Quoted from the NIST CMVP entry for this certificate.

Strongswan IKE daemon implementing the IKEv2 protocol to negotiate the key material for IPSec.

Security level exceptions

  • Physical security: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Approved algorithms (29)

AlgorithmCAVP certificates
AES-CBCA3958, A3959, A3960, A3973, A3980, A3981, A3982
AES-CCMA3958, A3959, A3960, A3973, A3980, A3981, A3982
AES-GCMA3961, A3974, A3975, A3976, A3988, A3989, A3990, A3994, A3995, A3996, A3997, A3998, A3999, A4000, A4001, A4002
Counter DRBGA3970
ECDSA KeyGen (FIPS186-4)A3962, A3977, A3983, A3993, A4003, A4004, A4005
ECDSA KeyVer (FIPS186-4)A3962, A3977, A3983, A3993, A4003, A4004, A4005
ECDSA SigGen (FIPS186-4)A3962, A3964, A3972, A3977, A3979, A3983, A3993, A4003, A4004, A4005
ECDSA SigVer (FIPS186-4)A3962, A3964, A3972, A3977, A3979, A3983, A3993, A4003, A4004, A4005
HMAC-SHA-1A3962, A3977, A3983, A3993, A4003, A4004, A4005, A4017
HMAC-SHA2-224A3962, A3977, A3983, A3993, A4003, A4004, A4005
HMAC-SHA2-256A3812, A3813, A3814, A3832, A3850, A3851, A3852, A3853, A3857, A3858, A3962, A3963, A3977, A3983, A3993, A4003, A4004, A4005, A4017
HMAC-SHA2-384A3962, A3977, A3983, A3993, A4003, A4004, A4005, A4017
HMAC-SHA2-512A3962, A3977, A3983, A3993, A4003, A4004, A4005, A4017
HMAC-SHA2-512/224A3962, A3977, A3983, A3993, A4003, A4004, A4005
HMAC-SHA2-512/256A3962, A3977, A3983, A3993, A4003, A4004
KAS-ECC-SSC Sp800-56Ar3A3962, A3977, A3983, A3993, A4003, A4004, A4005
KAS-FFC-SSC Sp800-56Ar3A3992
KDF IKEv2A4017
RSA SigGen (FIPS186-4)A3962, A3977, A3983, A3993, A4003, A4004, A4005
RSA SigVer (FIPS186-4)A3962, A3977, A3983, A3993, A4003, A4004, A4005
Safe Primes Key GenerationA3992
Safe Primes Key VerificationA3992
SHA-1A3962, A3977, A3983, A3993, A4003, A4004, A4005, A4017
SHA2-224A3962, A3977, A3983, A3993, A4003, A4004, A4005
SHA2-256A3812, A3813, A3814, A3832, A3850, A3851, A3852, A3853, A3857, A3858, A3962, A3963, A3977, A3983, A3993, A4003, A4004, A4005, A4017
SHA2-384A3962, A3977, A3983, A3993, A4003, A4004, A4005, A4017
SHA2-512A3962, A3977, A3983, A3993, A4003, A4004, A4005, A4017
SHA2-512/224A3962, A3977, A3983, A3993, A4003, A4004, A4005
SHA2-512/256A3962, A3977, A3983, A3993, A4003, A4004, A4005

Tested configurations

  • Ubuntu 22.04 on IBM z15 with IBM z15 processor with PAI
  • Ubuntu 22.04 on IBM z15 with IBM z15 processor without PAI
  • Ubuntu 22.04 running on Amazon Web Services (AWS) c6g.metal with AWS Graviton2 processor with PAA
  • Ubuntu 22.04 running on Amazon Web Services (AWS) c6g.metal with AWS Graviton2 processor without PAA
  • Ubuntu 22.04 running on Supermicro SYS-1019P-WTR with Intel Xeon Gold 6226 processor with PAA
  • Ubuntu 22.04 running on Supermicro SYS-1019P-WTR with Intel Xeon Gold 6226 processor without PAA

Validation history

DateTypeLab
2024-12-03Initialatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2024-12-03

Source documents