808bits

Red Hat Enterprise Linux 8 NSS Cryptographic Module

FIPS 140-3 certificate #5513 · Red Hat, Inc. · data as of 2026-09-08

Red Hat Enterprise Linux 8 NSS Cryptographic Module, from Red Hat, Inc., holds FIPS 140-3 certificate #5513 at overall level 1. The validation is active, with a sunset date of 2031-09-07. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Active. Sunset date 2031-09-07, 1824 days away.
Caveat: When operated in approved mode and installed, initialized and configured as specified in Section 11 of the Security Policy. No assurance of minimum security of SSPs (e.g., keys, bit strings) that are externally loaded, or of SSPs established with externally loaded SSPs. The module generates random numbers whose strengths are modified by available entropy.

Certificate

Certificate number5513
StandardFIPS 140-3
Statusactive
Sunset date2031-09-07
Overall level1
Module typeSoftware
EmbodimentMultiChipStand
VendorRed Hat, Inc. · website

Module description

Quoted from the NIST CMVP entry for this certificate.

Red Hat Enterprise Linux 8 NSS Cryptographic Module consists of the Softoken and Freebl libraries offering various cryptographic mechanisms.

Security level exceptions

  • Physical security: N/A
  • Non-invasive security: N/A

Approved algorithms (34)

AlgorithmCAVP certificates
AES-CBCA6443, A6445
AES-CBC-CS1A6443, A6445
AES-CMACA6443, A6445
AES-CTRA6443, A6445
AES-ECBA6443, A6445
AES-GCMA6443, A6445, A6446
AES-KWA6443, A6445
AES-KWPA6443, A6445
ECDSA KeyGen (FIPS186-5)A6443
ECDSA SigGen (FIPS186-5)A6443
ECDSA SigVer (FIPS186-5)A6443
Hash DRBGA6443
HMAC-SHA2-224A6443, A6447
HMAC-SHA2-256A6443, A6447
HMAC-SHA2-384A6443, A6447
HMAC-SHA2-512A6443, A6447
KAS-ECC-SSC Sp800-56Ar3A6443
KAS-FFC-SSC Sp800-56Ar3A6443
KDA HKDF SP800-56Cr2A6442
KDF IKEv2A6444
KDF SP800-108A6443
KTS-IFCA6443
PBKDFA6443
RSA KeyGen (FIPS186-5)A6443
RSA SigGen (FIPS186-5)A6443
RSA SigVer (FIPS186-2)A6443
RSA SigVer (FIPS186-4)A6443
RSA SigVer (FIPS186-5)A6443
Safe Primes Key GenerationA6443
SHA2-224A6443, A6447
SHA2-256A6443, A6447
SHA2-384A6443, A6447
SHA2-512A6443, A6447
TLS v1.2 KDF RFC7627A6443

Validation history

DateTypeLab
2026-09-08Initialatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-09-08: first observed by this tracker, status active
  • Validation dates on record: 2026-09-08

Source documents