808bits

Linux Kernel FIPS Object Module (KFOM) Cryptographic Module

FIPS 140-3 certificate #5261 · Cisco Systems, Inc. · data as of 2026-08-28
Active. Sunset date 2031-05-10, 1715 days away.
Caveat: No assurance of the minimum strength of generated SSPs (e.g., keys). No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs

Certificate

Certificate number5261
StandardFIPS 140-3
Statusactive
Sunset date2031-05-10
Overall level1
Module typeFirmware-hybrid
EmbodimentMultiChipStand
VendorCisco Systems, Inc. · website

Module description

The Cisco Linux Kernel FIPS Object Module (KFOM) is a firmware hybrid cryptographic library that serves the operating system kernel. It does not implement any security protocols, instead only allowing for Linux kernel applications access to using approved algorithms.

Security level exceptions

  • Non-invasive security: N/A
  • Mitigation of other attacks: N/A

Validation history

DateTypeLab
2026-05-11InitialGossamer Security Solutions
2026-08-03UpdateGossamer Security Solutions

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2026-05-11

Source documents