1 Introduction to FIPS 140-2 Level 1 Cryptography in Oracle Solaris

FIPS 140-2, a U.S. Federal Information Processing Standard, is a requirement for many regulated industries and U.S. government agencies that process sensitive but unclassified information. The aim of FIPS 140-2 is to provide a degree of assurance that the system has implemented the cryptography correctly. Providing FIPS 140-2 Level 1 cryptography on a computer system is called "running in FIPS 140-2 mode".

In September 2021 and February 2022, the U.S. National Institute of Standards and Technology (NIST) issued two certificates that validate the Cryptographic Framework feature of Oracle Solaris to the FIPS 140-2 Level 1 standard. The Oracle Solaris certificates are numbered 2698 and 2699. The Oracle Solaris 11.4 release in FIPS 140-2 mode uses the same algorithms.

New Feature – Oracle Solaris 11.4 ships with FIPS 140-2 capable OpenSSL libraries which statically link to the Oracle OpenSSL FIPS Provider. For more information, see About OpenSSL in FIPS 140-2 Mode in Oracle Solaris.