Linux Kernel FIPS Object Module (KFOM) Cryptographic Module
Caveat: No assurance of the minimum strength of generated SSPs (e.g., keys). No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs
Certificate
| Certificate number | 5261 |
|---|---|
| Standard | FIPS 140-3 |
| Status | active |
| Sunset date | 2031-05-10 |
| Overall level | 1 |
| Module type | Firmware-hybrid |
| Embodiment | MultiChipStand |
| Vendor | Cisco Systems, Inc. · website |
Module description
The Cisco Linux Kernel FIPS Object Module (KFOM) is a firmware hybrid cryptographic library that serves the operating system kernel. It does not implement any security protocols, instead only allowing for Linux kernel applications access to using approved algorithms.
Security level exceptions
- Non-invasive security: N/A
- Mitigation of other attacks: N/A
Validation history
| Date | Type | Lab |
|---|---|---|
| 2026-05-11 | Initial | Gossamer Security Solutions |
| 2026-08-03 | Update | Gossamer Security Solutions |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2026-05-11