Introducing modularized kernel cryptography in Amazon Linux
Compute Blog
This article introduces modularized kernel cryptography in Amazon Linux 2023, which separates FIPS 140-3 cryptographic components into an independent kernel module for streamlined certification and reuse.
- Standalone crypto module can be certified once and reused across kernel versions without full re-certification
- Reduces FIPS validation delays from 12-18 months per kernel version to streamlined updates
- Non-cryptographic kernel changes no longer trigger full re-certification cycles
- Module included in AL2023 kernel 6.18 and later; loads automatically at boot
- FIPS 140-3 validation expected to complete in 2027
- Enables regulated industries to apply security patches rapidly while maintaining compliance
Modularized kernel cryptography helps customers in regulated sectors balance security updates with FIPS compliance requirements.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.