808bits

SUSE Rancher Kubernetes Cryptographic Library

FIPS 140-3 certificate #4968 · SUSE LLC · data as of 2026-08-28
Active. Sunset date 2029-07-22, 1058 days away.
Caveat: No assurance of the minimum strength of generated SSPs (e.g., keys). When operated in approved mode.

Certificate

Certificate number4968
StandardFIPS 140-3
Statusactive
Sunset date2029-07-22
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorSUSE LLC · website
Software versions2.0

Module description

A software library that contains cryptography to serve SUSE’s Rancher Kubernetes Engine and its ecosystem of supported cloud-native tools written in the Go programming language.

Security level exceptions

  • Physical security: N/A
  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES-CBCA6389
AES-CCMA6389
AES-CTRA6389
AES-ECBA6389
AES-GCMA6389
AES-KWA6389
AES-KWPA6389
Counter DRBGA6389
ECDSA KeyGen (FIPS186-4)A6389
ECDSA KeyVer (FIPS186-4)A6389
ECDSA SigGen (FIPS186-4)A6389
ECDSA SigVer (FIPS186-4)A6389
HMAC-SHA-1A6389
HMAC-SHA2-224A6389
HMAC-SHA2-256A6389
HMAC-SHA2-384A6389
HMAC-SHA2-512A6389
KAS-ECC-SSC Sp800-56Ar3A6389
KDF TLSA6389
RSA KeyGen (FIPS186-4)A6389
RSA SigGen (FIPS186-4)A6389
RSA SigVer (FIPS186-4)A6389
SHA-1A6389
SHA2-224A6389
SHA2-256A6389
SHA2-384A6389
SHA2-512A6389
SHA2-512/256A6389

Tested configurations

  • Red Hat Enterprise Linux 7.6 on Ampere Altra Q80-30 (Ampere Altra) with PAA
  • Red Hat Enterprise Linux 7.6 on Ampere Altra Q80-30 (Ampere Altra) without PAA
  • Red Hat Enterprise Linux 7.9 on Intel Xeon Silver 4214R (Cascade Lake) with PAA
  • Red Hat Enterprise Linux 7.9 on Intel Xeon Silver 4214R (Cascade Lake) without PAA
  • Red Hat Enterprise Linux 8.8 on Ampere Altra Q80-30 (Ampere Altra) with PAA
  • Red Hat Enterprise Linux 8.8 on Ampere Altra Q80-30 (Ampere Altra) without PAA
  • Red Hat Enterprise Linux 8.8 on Intel Xeon Silver 4214R (Cascade Lake) with PAA
  • Red Hat Enterprise Linux 8.8 on Intel Xeon Silver 4214R (Cascade Lake) without PAA
  • Red Hat Enterprise Linux 9.0 on Ampere Altra Q80-30 (Ampere Altra) with PAA
  • Red Hat Enterprise Linux 9.0 on Ampere Altra Q80-30 (Ampere Altra) without PAA
  • Red Hat Enterprise Linux 9.0 on Intel Xeon Silver 4214R (Cascade Lake) with PAA
  • Red Hat Enterprise Linux 9.0 on Intel Xeon Silver 4214R (Cascade Lake) without PAA
  • SLE Micro 5.3 on Ampere Altra Q80-30 (Ampere Altra) with PAA
  • SLE Micro 5.3 on Ampere Altra Q80-30 (Ampere Altra) without PAA
  • SLE Micro 5.3 on Intel Xeon Silver 4214R (Cascade Lake) with PAA
  • SLE Micro 5.3 on Intel Xeon Silver 4214R (Cascade Lake) without PAA
  • SUSE SLES 15SP4 on Intel Xeon Silver 4214R (Cascade Lake) with PAA
  • SUSE SLES 15SP4 on Intel Xeon Silver 4214R (Cascade Lake) without PAA
  • SUSE SLES 15SP5 on Ampere Altra Q80-30 (Ampere Altra) with PAA
  • SUSE SLES 15SP5 on Ampere Altra Q80-30 (Ampere Altra) without PAA

Validation history

DateTypeLab
2025-02-20InitialTeron Labs
2026-05-05UpdateTeron Labs

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2025-02-20

Known CVEs in this module family (heuristic match)

Name-based association with the module's product family, not a statement about the validated boundary. See methodology.

CVECVSSSeverity
CVE-2021-367787.3HIGH
CVE-2021-367847.2HIGH
CVE-2021-253137.1HIGH
CVE-2021-42005.4MEDIUM

Source documents