U.S. flag   An unofficial archive of your favorite United States government website
Dot gov

Official websites do not use .rip
We are an unofficial archive, replace .rip by .gov in the URL to access the official website. Access our document index here.

Https

We are building a provable archive!
A lock (Dot gov) or https:// don't prove our archive is authentic, only that you securely accessed it. Note that we are working to fix that :)

This is an archive
(replace .gov by .rip)

Cryptographic Module Validation Program CMVP

Certificate #3474

Details

Module Name
Oracle Linux OpenSSL Cryptographic Module
Standard
FIPS 140-2
Status
Active
Sunset Date
6/11/2024
Validation Dates
06/12/2019;05/06/2020;05/28/2021
Overall Level
1
Caveat
When operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy
Security Level Exceptions
  • Physical Security: N/A
  • Design Assurance: Level 3
Module Type
Software
Embodiment
Multi-Chip Stand Alone
Description
Oracle Linux is a set of cryptographic libraries, services, and user level cryptographic applications that are validated at FIPS 140-2 level 1, providing a secure foundation for vendor use in developing dependent services, applications, and even purpose built appliances that may be FIPS 140-2 validated.
Tested Configuration(s)
  • Oracle Linux 7.5 64 bit running on Oracle Server X7-2 with a Intel® Xeon® Silver 4114 with PAA
  • Oracle Linux 7.5 64 bit running on Oracle Server X7-2 with a Intel® Xeon® Silver 4114 without PAA
  • Oracle Linux 7.6 64 bit running on Oracle Server X7-2 with a Intel® Xeon® Silver 4114 with PAA
  • Oracle Linux 7.6 64 bit running on Oracle Server X7-2 with a Intel® Xeon® Silver 4114 without PAA
  • Oracle Linux 7.6 64 bit running on Oracle X7-2 Server with AMD® EPYC® 7551 with PAA
  • Oracle Linux 7.6 64 bit running on Oracle X7-2 Server with AMD® EPYC® 7551 without PAA (single user mode)
FIPS Algorithms
AES Certs. #C117, #C118, #C119, #C422, #C423 and #C429
CKG Vendor Affirmed
CVL Certs. #C117 and #C429
DRBG Certs. #C117, #C118, #C119, #C422, #C423 and #C429
DSA Certs. #C117 and #C429
ECDSA Certs. #C117 and #C429
HMAC Certs. #C117, #C118, #C119, #C422, #C423 and #C429
KTS AES Certs. #C117, #C118, #C119, #C422, #C423 and #C429; key establishment methodology provides between 128 and 256 bits of encryption strength
RSA Certs. #C117 and #C429
SHS Certs. #C117, #C118, #C119, #C422, #C423 and #C429
Triple-DES Certs. #C117, #C118, #C119, #C422, #C423 and #C429
Allowed Algorithms
Diffie-Hellman (CVL Certs. #C117 and #C429, key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength); EC Diffie-Hellman (CVL Certs. #C117 and #C429, key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength); MD5; NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 256 bits of encryption strength)
Software Versions
R7-3.0.0 [1] and R7-4.0.0 [2]

Vendor

Oracle Corporation
500 Oracle Parkway
Redwood Shores, CA 94065
USA

Honglin Su
honglin.su@oracle.com
Phone: +1 650-607-0970
Fax: N/A

Lab

ACUMEN SECURITY, LLC
NVLAP Code: 201029-0