---
title: 'FIPS 140-2: Stay compliant and secure with Canonical'
description: Ubuntu lets you choose the way to implement FIPS-certified cryptographic
  modules with two distinct FIPS alternatives to choose from
url: https://canonical.com/blog/fips-140-2-stay-compliant-and-secure-with-canonical?format=md
---

1. [Blog](https://canonical.com/blog)
2. Article

---

[Lech Sandecki](https://canonical.com/blog/author/lsandecki "More about Lech Sandecki")

1 April 2020

# FIPS 140-2: Stay compliant and secure with Canonical

[20.04](https://canonical.com/blog/tag/20-04)
[cryptography](https://canonical.com/blog/tag/cryptography)
[CVE](https://canonical.com/blog/tag/cve)
[FIPS](https://canonical.com/blog/tag/fips)
[Open source](https://canonical.com/blog/tag/open-source)
[Security](https://canonical.com/blog/tag/security)
[Security certifications and compliance](https://canonical.com/blog/tag/security-certifications-and-compliance)
[Ubuntu Advantage for infrastructure](https://canonical.com/blog/tag/ubuntu-advantage-for-infrastructure)

---

Share the article

[FIPS 140-2](https://ubuntu.com/security/fips) is a set of publicly announced cryptographic standards developed by the National Institute of Standards and Technology. It is an essential part of FEDRamp requirements for many governmental agencies in the US and Canada, as well as their business partners from all around the world. Furthermore, as a well established and verified security standard, an increasing number of large companies and financial institutions are asking for FIPS compliance.

Yet, FIPS certification process introduces challenges that could impact your security. Ubuntu lets you choose the way to implement FIPS-certified cryptographic modules with two distinct FIPS alternatives to choose from to overcome those challenges.

## FIPS 140-2 certification vs CVE patching

[FIPS 140-2](https://csrc.nist.gov/publications/detail/fips/140/2/final) is a great way to assure that the best practices in cryptography are met. The rules that each organisation needs to follow to achieve the FIPS 140-2 certification are very strict. Each component needs to be designed, documented, tested and then validated by the NIST Testing Laboratory. Once a component becomes certified, it cannot be further modified without requiring a re-certification. This individual module validation can take weeks, and so the overall process can easily stretch to over 6 months.

The apparent drawback of that situation appears when a new security patch becomes available.

Imagine that a new critical CVE ([Common Vulnerability and Exposure](https://ubuntu.com/blog/securing-open-source-through-cve-prioritisation)) was discovered in the OpenSSH module, but thankfully there is a USN ([Ubuntu Security Notice](https://usn.ubuntu.com/)) available to fix it. With a security fix applied  – the module will change and hence will no longer be certified; without it – the module’s security can be compromised by an exploitable vulnerability.

## FIPS Certified or FIPS Compliant

You might be wondering which [Ubuntu FIPS](https://ubuntu.com/security/fips) version should be used in your organisation. That depends. If you work for a federal government department that collects, stores, transfers and shares sensitive but unclassified information, it’s likely that you’re required to use FIPS Certified modules without any modifications. In other cases – we recommend using FIPS Certified modules that include all security patches. We call it UbuntuFIPS Compliant*.*

## Maintaining FIPS Certified modules security

To keep your FIPS Certified Ubuntu secure we will re-certify all modules every year.

Today, Ubuntu 18.04 LTS and 16.04 LTS has certifications for 5 distinct modules:

**Ubuntu 18.04 LTS**

| Component | Description | Version | CMVP Certificate |
| --- | --- | --- | --- |
| Linux kernel (generic) | The Linux kernel cryptographic library | 4.15.0 | [3647](https://csrc.nist.gov/Projects/Cryptographic-Module-Validation-Program/Certificate/3647) |
| OpenSSL | General purpose cryptographic library that includes TLS implementation | 1.1.1 | [3622](https://csrc.nist.gov/projects/cryptographic-module-validation-program/Certificate/3622) |
| OpenSSH client | SSH server application for operating systems | 7.9p1 | [3633](https://csrc.nist.gov/Projects/cryptographic-module-validation-program/Certificate/3633) |
| OpenSSH server | SSH client application for operating systems | 7.9p1 | [3632](https://csrc.nist.gov/Projects/cryptographic-module-validation-program/Certificate/3632) |
| StrongSWAN | IPSec based VPN solution library | 5.6.2 | [3648](https://csrc.nist.gov/Projects/cryptographic-module-validation-program/Certificate/3648) |

**Ubuntu 16.04 LTS**

| Component | Description | Version | CMVP Certificate |
| --- | --- | --- | --- |
| Linux kernel (generic) | The Linux kernel cryptographic library | 4.4.0.1002 | [2962](https://csrc.nist.gov/projects/cryptographic-module-validation-program/Certificate/2962) |
| OpenSSL | General purpose cryptographic library that includes TLS implementation | 1.0.2g | [2888](https://csrc.nist.gov/projects/cryptographic-module-validation-program/Certificate/2888) |
| OpenSSH client | SSH client application for operating systems | 7.2p2 | [2907](https://csrc.nist.gov/projects/cryptographic-module-validation-program/Certificate/2907) |
| OpenSSH server | SSH server application for operating systems | 7.2p2 | [2906](https://csrc.nist.gov/projects/cryptographic-module-validation-program/Certificate/2906) |
| StrongSWAN | IPSec based VPN solution library | 5.3.5 | [2978](https://csrc.nist.gov/projects/cryptographic-module-validation-program/Certificate/2978) |

## Start using FIPS 140-2 and other Ubuntu security products

Both Ubuntu FIPS-certified and Ubuntu FIPS-compliant modules are offered under a comprehensive [Ubuntu Advantage for Infrastructure](https://assets.ubuntu.com/v1/1a8fb1b3-UA-I_datasheet_2019-Oct.pdf?_ga=2.150242614.1442100177.1584963314-1246940982.1572873304) package, starting at $75 per VM per year. Check out the full list of [Ubuntu security certifications and hardening standards](https://ubuntu.com/security/certifications).

[Get in touch

Interested in running Ubuntu in your organization?](https://ubuntu.com/about/contact-us/form)

## Sign up for our newsletter

Get the latest Canonical news and updates in your inbox.

Work email:

\*I agree to receive information about Canonical's
products and services.

By submitting this form, I confirm that I have read and agree to [Canonical's Privacy Policy](https://canonical.com/legal/dataprivacy).

Sign up

## Share on

---

## Related posts

[### Canonical joins the Open Secure AI Alliance](https://canonical.com/blog/open-secure-ai-alliance)

Canonical is now part of the Open Secure AI Alliance, announced by NVIDIA with partners across cloud computing, cybersecurity, enterprise software, open source foundations, and...

[Canonical](https://canonical.com/blog/author/canonical)

28 August 2026

[### Januscape vulnerability CVE-2026-53359 mitigations available](https://canonical.com/blog/januscape-linux-vulnerability-mitigations-available)

Introduction A local privilege escalation (LPE) vulnerability affecting the Linux kernel was publicly disclosed on July 6, 2026. The vulnerability was assigned CVE ID...

[seth-arnold](https://canonical.com/blog/author/seth-arnold)

11 July 2026

[### DirtyClone Linux kernel local privilege escalation vulnerability fixes available](https://canonical.com/blog/dirtyclone-linux-vulnerability-fixes-available)

On June 25, 2026, JFrog published their research into CVE-2026-43503, referring to the vulnerability as DirtyClone. The vulnerability had previously been responsibly disclosed...

[Luci Stanescu](https://canonical.com/blog/author/lucistanescu)

1 July 2026

[### pedit COW kernel local privilege escalation vulnerability mitigations](https://canonical.com/blog/pedit-cow-linux-vulnerability-fixes-available)

Mitigations are available for the Linux vulnerability with CVE ID CVE-2026-46331. The CVE ID was assigned on June 16 2026 and highlighted as a local privilege escalation (LPE)...

[Luci Stanescu](https://canonical.com/blog/author/lucistanescu)

1 July 2026
