FIPS 140 (Federal Information Processing Standard, Publication 140) is the US and Canadian government standard that defines security requirements for cryptographic modules — the hardware, software, or firmware components that perform cryptographic operations (encryption, decryption, hashing, signing, key management). It is published by NIST (National Institute of Standards and Technology) and jointly administered with CCCS (Canadian Centre for Cyber Security) through the Cryptographic Module Validation Program (CMVP). The standard has two active versions: FIPS 140-2 (published 2001, no longer accepting new submissions since April 2022) and FIPS 140-3 (effective September 2020, the current standard for all new validations). FIPS 140-2 certificates remain valid until 21 September 2026, after which they move to the Historical list — meaning only FIPS 140-3 validated modules will be accepted for new federal procurements. FIPS 140 defines four security levels (Level 1 through Level 4), with Level 1 being the baseline for software modules and Level 4 requiring physical tamper-active hardware. Compliance is mandatory for all US federal agencies and their contractors under FISMA, for Canadian federal systems, and is widely adopted by regulated industries (finance, healthcare, critical infrastructure) globally. Non-validated cryptography is treated as providing no protection — effectively plaintext — regardless of the algorithm strength. Validation is a formal, lab-based process: vendors submit modules to accredited Cryptographic and Security Testing (CST) laboratories, which test against the standard and submit results to CMVP for certificate issuance.
Red Hat maintains one of the most comprehensive FIPS validation portfolios of any Linux vendor. As of 2025–2026, Red Hat holds active FIPS 140-3 certificates for multiple cryptographic modules across RHEL 8 and RHEL 9: OpenSSL FIPS Provider, NSS Cryptographic Module, libgcrypt, GnuTLS, and the Kernel Cryptographic API — validated on Intel, IBM Z (s390x), and IBM Power architectures. RHEL 9 and RHEL 10 are FIPS 140-3 only releases, while RHEL 8 maintains a mix of FIPS 140-2 and 140-3 certificates. Red Hat enables FIPS mode at the operating system level: when enabled (at install time or via fips-mode-setup), RHEL enforces that only validated cryptographic implementations are used system-wide — disabling non-approved algorithms, configuring TLS to use only FIPS-approved cipher suites, and ensuring the kernel self-tests its crypto on boot. This system-wide FIPS enforcement propagates upward through the stack: OpenShift inherits RHEL’s FIPS boundary, meaning all platform cryptography (etcd encryption, API server TLS, service mesh mTLS, image signing) uses validated modules without per-application configuration. Red Hat’s FIPS strategy follows a “validate once, inherit everywhere” model — because all higher-level Red Hat products (OpenShift, Ansible, RHACS, Quay) rely on RHEL’s cryptographic libraries, a single set of CMVP certificates covers the entire product portfolio. For federal customers, this eliminates the need to independently validate each software component and ensures continuous compliance as FIPS 140-2 certificates expire in September 2026.
