---
title: FIPS 140-2 Certified Modules for Ubuntu 16.04 LTS
description: We are pleased to announce that officially certified FIPS 140-2 level
  1 cryptographic packages are now available for Ubuntu 16.04 LTS for Ubuntu Advantage
  Advanced customers and as a separate, stand-alone product. In 2016 Canonical began
  the process of completing the Cryptographic Module Validation Program to obtain
  FIPS 140-2 validation  […]
url: https://canonical.com/blog/fips-140-2-certified-modules-for-ubuntu-16-04-lts?format=md
---

1. [Blog](https://canonical.com/blog)
2. Article

---

[Chris Johnston](https://canonical.com/blog/author/cjohnston "More about Chris Johnston")

13 December 2017

# FIPS 140-2 Certified Modules for Ubuntu 16.04 LTS

[FIPS](https://canonical.com/blog/tag/fips)
[Security](https://canonical.com/blog/tag/security)
[Security certifications and compliance](https://canonical.com/blog/tag/security-certifications-and-compliance)
[Ubuntu 16.04](https://canonical.com/blog/tag/ubuntu-16-04)
[Ubuntu Advantage](https://canonical.com/blog/tag/ubuntu-advantage)
[Ubuntu Advantage for infrastructure](https://canonical.com/blog/tag/ubuntu-advantage-for-infrastructure)

---

Share the article

We are pleased to announce that officially certified FIPS 140-2 level 1 cryptographic packages are now available for Ubuntu 16.04 LTS for Ubuntu Advantage Advanced customers and as a separate, stand-alone product.

In 2016 Canonical began the process of completing the [Cryptographic Module Validation Program](https://csrc.nist.gov/Projects/Cryptographic-Module-Validation-Program) to obtain FIPS 140-2 validation for Ubuntu 16.04 LTS. This has been successfully completed and Canonical now offers key components of Ubuntu 16.04 LTS compliant with the FIPS 140-2 level 1 standard. The FIPS compliant modules are available to [Ubuntu Advantage Advanced](https://www.ubuntu.com/pricing) subscribers in the Ubuntu Advantage private archive.

> We currently use Ubuntu Linux because of its superior development environment and frequent LTS releases. As a business that develops software, one of our customer’s requirements is to utilize FIPS 140-2 validated software. We have been able to start rolling out the Ubuntu FIPS modules without needing to reinstall the operating system. This keeps our developers happy and productive as Ubuntu is their preferred environment and minimizes transition cost. The FIPS modules also include a VPN solution which we look forward to implementing to allow our developers to work remotely but still meet our customer’s requirements.

**-Alex Stuart, North Point Defense**

Users interested in FIPS 140-2 compliant modules on Ubuntu 16.04 can purchase Ubuntu Advantage at <https://buy.ubuntu.com/> or by contacting the [Canonical Sales Team](https://www.ubuntu.com/support/contact-us).

For further information please visit <https://www.ubuntu.com/security>.

# FAQ

### What is FIPS?

FIPS stands for Federal Information Processing Standards which is a set of publications developed and maintained by the National Institute of Standards and Technology (NIST), a United States federal agency. These publications define the security criteria required for government computers and telecommunication systems.

### What is the FIPS 140-2 standard?

[According to NIST](https://www.google.com/url?q=http://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.140-2.pdf&sa=D&ust=1509546492466000&usg=AFQjCNGJd1nIoNCG-4UYV7VxBGE3Z0pnRA), FIPS 140-2 “specifies the security requirements that will be satisfied by a cryptographic module used within a security system protecting sensitive but unclassified information.”

### Why should I use the FIPS 140-2 modules?

Government, defence, healthcare, and finance organizations worldwide operate in highly regulated industries and are required to meet the security requirements defined in the FIPS 140-2 standard. This includes the United States, Canadian, and United Kingdom governments as well as government contractors.

### Where can I find out more about FIPS?

General information about the Federal Information Processing Standards can be found on the [NIST website](https://www.nist.gov/information-technology-laboratory/fips-general-information). More detailed information about FIPS 140-2 itself can be found in the [Federal Information Processing Standards Publication 140-2 document](https://csrc.nist.gov/csrc/media/publications/fips/140/2/final/documents/fips1402.pdf).

### Which modules are included?

* [Kernel Crypto API](https://csrc.nist.gov/csrc/media/projects/cryptographic-module-validation-program/documents/security-policies/140sp2962.pdf)
* [OpenSSL](https://csrc.nist.gov/csrc/media/projects/cryptographic-module-validation-program/documents/security-policies/140sp2888.pdf)
* [OpenSSH Client](https://csrc.nist.gov/csrc/media/projects/cryptographic-module-validation-program/documents/security-policies/140sp2907.pdf)
* [OpenSSH Server](https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/security-policies/140sp2906.pdf)
* [Strongswan](https://csrc.nist.gov/csrc/media/projects/cryptographic-module-validation-program/documents/security-policies/140sp2978.pdf)

### What versions of Ubuntu have FIPS certified modules?

Currently only Ubuntu 16.04 LTS has FIPS certified modules.

### How Can I Find Out More?

[Click here](https://www.ubuntu.com/support/contact-us?utm_source=insights&utm_medium=blog&utm_campaign=fips) to make an inquiry, and somebody from our team will get back to you!

[Get in touch

Interested in running Ubuntu in your organization?](https://ubuntu.com/about/contact-us/form)

## Sign up for our newsletter

Get the latest Canonical news and updates in your inbox.

Work email:

\*I agree to receive information about Canonical's
products and services.

By submitting this form, I confirm that I have read and agree to [Canonical's Privacy Policy](https://canonical.com/legal/dataprivacy).

Sign up

## Share on

---

## Related posts

[### Canonical joins the Open Secure AI Alliance](https://canonical.com/blog/open-secure-ai-alliance)

Canonical is now part of the Open Secure AI Alliance, announced by NVIDIA with partners across cloud computing, cybersecurity, enterprise software, open source foundations, and...

[Canonical](https://canonical.com/blog/author/canonical)

28 August 2026

[### Januscape vulnerability CVE-2026-53359 mitigations available](https://canonical.com/blog/januscape-linux-vulnerability-mitigations-available)

Introduction A local privilege escalation (LPE) vulnerability affecting the Linux kernel was publicly disclosed on July 6, 2026. The vulnerability was assigned CVE ID...

[seth-arnold](https://canonical.com/blog/author/seth-arnold)

11 July 2026

[### DirtyClone Linux kernel local privilege escalation vulnerability fixes available](https://canonical.com/blog/dirtyclone-linux-vulnerability-fixes-available)

On June 25, 2026, JFrog published their research into CVE-2026-43503, referring to the vulnerability as DirtyClone. The vulnerability had previously been responsibly disclosed...

[Luci Stanescu](https://canonical.com/blog/author/lucistanescu)

1 July 2026

[### pedit COW kernel local privilege escalation vulnerability mitigations](https://canonical.com/blog/pedit-cow-linux-vulnerability-fixes-available)

Mitigations are available for the Linux vulnerability with CVE ID CVE-2026-46331. The CVE ID was assigned on June 16 2026 and highlighted as a local privilege escalation (LPE)...

[Luci Stanescu](https://canonical.com/blog/author/lucistanescu)

1 July 2026
