{"id":173537,"date":"2025-06-18T21:11:39","date_gmt":"2025-06-18T21:11:39","guid":{"rendered":"https:\/\/linuxiac.com\/?p=173537"},"modified":"2025-06-18T21:16:00","modified_gmt":"2025-06-18T21:16:00","slug":"amazon-linux-2023-secures-fips-140-3-certification","status":"publish","type":"post","link":"https:\/\/linuxiac.com\/amazon-linux-2023-secures-fips-140-3-certification\/","title":{"rendered":"Amazon Linux 2023 Secures FIPS 140-3 Certification"},"content":{"rendered":"\n<p>AWS has reached a major security milestone with its <a href=\"https:\/\/docs.aws.amazon.com\/linux\/al2023\/ug\/what-is-amazon-linux.html\" target=\"_blank\" rel=\"noreferrer noopener\">Amazon Linux 2023<\/a> (AL2023),  a Fedora-based distro developed and maintained by AWS and specifically optimized for use on Amazon&#8217;s cloud infrastructure, achieving FIPS 140-3 Level 1 validation for its cryptographic modules.<\/p>\n\n\n\n<p>Simply put, this makes the distro a compliant operating system for industries with strict regulatory requirements\u2014think government agencies, healthcare, financial services, and defense contractors.<\/p>\n\n\n\n<p>FIPS 140-3, the latest Federal Information Processing Standards iteration, replaces FIPS 140-2 and sets a higher bar for cryptographic security. The validation, jointly administered by NIST and the Canadian Centre for Cyber Security (CCCS), ensures that cryptographic modules meet stringent government-backed security benchmarks.<\/p>\n\n\n\n<p>In light of this, key modules in AL2023\u2014including OpenSSL, Linux Kernel Cryptographic API, NSS, GnuTLS, and Libgcrypt\u2014have undergone rigorous testing by a NIST-accredited lab. The evaluation verified essential security features such as:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Approved cryptographic algorithms<\/li>\n\n\n\n<li>Secure key management<\/li>\n\n\n\n<li>Strong entropy generation<\/li>\n\n\n\n<li>Protected memory boundaries<\/li>\n<\/ul>\n\n\n\n<p>It&#8217;s important to note that FIPS compliance isn\u2019t just a best practice for organizations handling sensitive or regulated data\u2014it\u2019s often a mandatory requirement. AL2023\u2019s validation simplifies compliance for sectors like U.S. and Canadian government workloads, HIPAA-covered healthcare systems, and financial institutions.<\/p>\n\n\n\n<p>Enabling FIPS mode on AL2023 is straightforward, with AWS providing a <a href=\"https:\/\/docs.aws.amazon.com\/linux\/al2023\/ug\/fips-mode.html\" target=\"_blank\" rel=\"noreferrer noopener\">step-by-step guide<\/a> for configuration. Customers can also access compliance details through the <a href=\"https:\/\/aws.amazon.com\/compliance\/fips\/\" target=\"_blank\" rel=\"noreferrer noopener\">AWS Compliance Programs portal<\/a> and stay updated via the <a href=\"https:\/\/aws.amazon.com\/blogs\/security\/\" target=\"_blank\" rel=\"noreferrer noopener\">AWS Security Blog<\/a>, which offers best practices and FAQs for both Amazon Linux 2 and AL2023.<\/p>\n\n\n\n<p>For more information, see the <a href=\"https:\/\/aws.amazon.com\/blogs\/compute\/amazon-linux-2023-achieves-fips-140-3-validation\/\" target=\"_blank\" rel=\"noreferrer noopener\">official announcement<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Amazon Linux 2023 has earned FIPS 140-3 validation, confirming its cryptographic modules meet top U.S. and Canadian government security standards.<\/p>\n","protected":false},"author":10,"featured_media":173540,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6,5],"tags":[4449],"class_list":["post-173537","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-os","category-news","tag-amazon-linux"],"blocksy_meta":[],"_links":{"self":[{"href":"https:\/\/linuxiac.com\/wp-json\/wp\/v2\/posts\/173537","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/linuxiac.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/linuxiac.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/linuxiac.com\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/linuxiac.com\/wp-json\/wp\/v2\/comments?post=173537"}],"version-history":[{"count":0,"href":"https:\/\/linuxiac.com\/wp-json\/wp\/v2\/posts\/173537\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/linuxiac.com\/wp-json\/wp\/v2\/media\/173540"}],"wp:attachment":[{"href":"https:\/\/linuxiac.com\/wp-json\/wp\/v2\/media?parent=173537"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/linuxiac.com\/wp-json\/wp\/v2\/categories?post=173537"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/linuxiac.com\/wp-json\/wp\/v2\/tags?post=173537"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}