On Tuesday, AlmaLinux announced that it has obtained FIPS 140-3 security certification for its Linux distro which is primarily used in data centers by enterprises.

On Tuesday the eponymous foundation behind the Red Hat Enterprise Linux compatible distribution AlmaLinux announced that the distro’s latest and greatest, AlmaLinux 9.2, now has FIPS 140-3 certification, which means it has passed the Federal Information Processing Standard’s latest benchmark for validating the effectiveness of cryptographic hardware.
Basically, this means that the operating system is certified secure. According to the financial security company Entrust, “If a product has a FIPS 140-3 certificate you know that it has been tested and formally validated by the U.S. and Canadian Governments.”
Although gaining this certification has been a goal of AlmaLinux since its beginning about three years ago, when the foundation made the decision in July to no longer necessarily be a line-by-line copy of RHEL (which already has FIPS certification) there became added pressure to obtain certification sooner rather than later.
In fact, when I spoke with the foundation’s board chair, benny Vasquez, in late July, she told me, “When we talk to the people that are using Alma, the things that they listed as the most important things were make sure my my applications still run and make sure that if I need to, I can pass any government requirements. So, we’ll have FIPS compliance lined up sometime very soon, and we’ll continue to be as close to RHEL as possible so that all of the applications will work.”
Indeed, FIPS certification is essential for operating systems such as AlmaLinux that are usually deployed in data centers by enterprise users that are often in highly regulated businesses.







