FIPS Certification Status
Cryptographic module status
Every RLC Pro cryptographic module is CMVP-validated except the RLC Pro 9.6 kernel, which is currently in process (MIP). The tables below track current status.
Status definitions
- CMVP (Validated/Certified): The module has completed NIST validation and holds an active FIPS 140-3 certificate. It can be used to meet FIPS 140-3 requirements when deployed and operated in the module's approved mode per its security policy.
- MIP (Modules In Process): The module has been approved by the testing lab and submitted to NIST for validation. The NIST review process typically takes at least 12 months. MIP modules have completed lab testing but are awaiting final NIST certification.
Certified modules (CMVP)
The following modules have completed NIST validation and hold active FIPS 140-3 certificates.
| Certificate # | Module Name | RLC Pro Versions | Validation Date | Sunset |
|---|---|---|---|---|
| 5350 | Rocky Linux 8 and 9 GnuTLS Cryptographic Module | 8.6, 8.10, 9.2, 9.6 | June 23, 2026 | June 22, 2031 |
| 5337 | Rocky Linux 8 and 9 NSS Cryptographic Module | 8.6, 8.10, 9.2, 9.6 | June 17, 2026 | June 16, 2031 |
| 5200 | Rocky Linux 8 OpenSSL Cryptographic Module | 8.6, 8.10 | March 18, 2026 | March 17, 2031 |
| 5117 | Rocky Linux 8 and 9 libgcrypt Cryptographic Module | 8.6, 8.10, 9.2, 9.6 | January 6, 2026 | January 5, 2031 |
| 5116 | Rocky Linux 9 OpenSSL FIPS Provider | 9.2, 9.6 | January 6, 2026 | January 5, 2031 |
| 5113 | Rocky Linux 9 Kernel Cryptographic API | 9.2 | December 18, 2025 | December 17, 2030 |
| 5095 | Rocky Linux 8 Kernel Cryptographic API | 8.6, 8.10 | November 24, 2025 | November 23, 2030 |
Modules In Process (MIP)
The following modules have completed testing and have been submitted to NIST for validation.
| Module | RLC Pro Versions | Submitted to NIST |
|---|---|---|
| Kernel | 9.6 | October 2025 |
Coverage by version
| Module | RLC Pro 8.6 | RLC Pro 8.10 | RLC Pro 9.2 | RLC Pro 9.6 |
|---|---|---|---|---|
| Kernel | Certified | Certified | Certified | MIP |
| OpenSSL | Certified | Certified | Certified | Certified |
| libgcrypt | Certified | Certified | Certified | Certified |
| GnuTLS | Certified | Certified | Certified | Certified |
| NSS | Certified | Certified | Certified | Certified |
Last updated: July 13, 2026. For authoritative, real-time status, use the CMVP Validated Modules Search and the Modules In Process List.
Entropy source validation
FIPS 140-3 requires validated entropy sources for random number generation (SP 800-90B). CIQ's entropy sources have been independently validated by NIST:
| Certificate | Entropy Source | Availability | Validation Date |
|---|---|---|---|
| E117 | Kernel CPU Time Jitter RNG | Rocky 8 and 9 | February 9, 2024 |
| E205 | Kernel CPU Time Jitter RNG | Rocky 8 and 9 | November 4, 2024 |
| E208 | OpenSSL 3 CPU Time Jitter RNG | Rocky 9 | November 15, 2024 |
| E210 | Userspace CPU Time Jitter RNG | Rocky 8 and 9 | November 18, 2024 |
| E219 | OpenSSL 1 CPU Time Jitter RNG | Rocky 8 | December 13, 2024 |
All entropy sources are validated to SP 800-90B, provide 256-bit full entropy output, and are classified as non-physical noise sources using CPU timing jitter.