CIQ's NSS Module Achieves Critical Certification
CIQ has made significant strides in the realm of cybersecurity by successfully achieving an important certification for its Network Security Services (NSS) module. The NSS, equipped with ML-KEM and ML-DSA algorithms, has undergone stringent lab tests, marking a pivotal moment in securing the digital landscape against emerging threats. This advancement positions Rocky Linux from CIQ as one of the leading Enterprise Linux distributions ensuring FIPS-validated post-quantum cryptography.
Overview of the NSS Module Features
The NSS module is now recognized on the Modules in Process (MIP) list after receiving certification from the National Institute of Standards and Technology (NIST) under the Cryptographic Algorithm Validation Program (CAVP). This recognition makes CIQ a pioneering force in integrating advanced algorithms into enterprise systems, paving the way for full FIPS 140-3 validation.
Central to enhancing security, two NIST-approved post-quantum cryptographic algorithms are implemented in the NSS module: ML-KEM, facilitating secure key exchanges, and ML-DSA, which bolsters digital signature capabilities. Both of these algorithms are purposefully designed to be resilient against potential attacks from classical as well as quantum computing. As technology evolves, such robust measures are crucial for ensuring ongoing data protection.
CIQ's Commitment to Robust Security
The rollout of NSS version 3.112 in September 2025 was a critical step in incorporating ML-KEM and ML-DSA support. Despite being feature-complete, initial release versions did not yet meet FIPS compliance. Under the guidance of CIQ's Distinguished Engineer and Samba Project Co-Creator Jeremy Allison, efforts were intensified to refine NSS, aligning it with FIPS 140-3 standards, a key requirement for submission to NIST.
Jeremy Allison highlighted this transformative effort, stating, "While the ML-KEM and ML-DSA code were initially complete, it required enhancements to achieve FIPS compliance. CIQ's initiative to enable and open-source FIPS 140-3 compliance code greatly enhances security for our clients and helps safeguard them for the post-quantum era."
The Urgency of Post-Quantum Preparedness
The urgency of transitioning to quantum-resistant cryptography is underscored by guidelines from the National Security Agency's CNSA 2.0, which stipulates a timeline for National Security Systems to adopt these advanced measures. Key milestones are set for 2027, with a full transition projected by 2035. However, the looming threat of adversaries utilizing a "harvest now, decrypt later" methodology necessitates immediate preparation. Such tactics allow malicious actors to capture encrypted data with the intent to decrypt it once quantum capabilities are realized.
NSS serves a dual purpose, acting not only for browser session cryptography and SSL/TLS connections but also functioning as the cryptographic provider for Java applications under FIPS mode. The implications of PQC-enabled NSS are significant, as it extends its benefits across various sectors, including government and regulated industries where security is paramount.
Continuous Innovation in Cryptographic Solutions
Gregory Kurtzer, the CEO of CIQ, emphasized the company's focus on delivering quantum-resistant solutions, stating, "Enterprises making decisions regarding their platforms today need to trust their infrastructure partners can provide them with cutting-edge solutions. The MIP status with CAVP-certified PQC algorithms illustrates that CIQ is ready to tackle intricate engineering challenges and instills trust in the future of OpenSSL and other cryptographic modules that support necessary quantum-resistance."
CIQ’s strategic approach transcends just the NSS module, encompassing PQC implementations across all five FIPS cryptographic modules, showcasing an unwavering commitment to security:
CIQ's PQC Implementations
- NSS is leading with ML-KEM and ML-DSA currently achieving MIP certification, with a full FIPS 140-3 validation expected by mid-2027.
- The OpenSSL module is actively evolving, with PQC support being integrated into OpenSSL 3.5 and a FIPS validation process set to begin for both Rocky Linux from CIQ 10.2 and Rocky Linux from CIQ 9.10.
- Continuous monitoring and updates are being pursued for the Kernel to enhance PQC capabilities.
- GnuTLS is also undergoing ongoing stabilization to align with PQC standards.
- Efforts are underway for LibGCrypt as it awaits stable PQC releases.
As these upstream initiatives solidify their PQC technologies, CIQ continues its pursuit of FIPS validation to provide a comprehensive quantum-resistant architecture.
The NSS module featuring ML-KEM and ML-DSA algorithms is currently available to customers using Rocky Linux from CIQ. It’s noteworthy that many compliance frameworks have begun to adopt MIP status while awaiting full validation. The details regarding the MIP listing can be accessed via the NIST Cryptographic Module Validation Program. Furthermore, CIQ's open-source compliance code for FIPS PQC is available on GitHub.
Frequently Asked Questions
What is the significance of CIQ's NSS module certification?
The NSS module's certification indicates it meets stringent security standards necessary for protecting against advanced cyber threats, paving the way for improved data security.
How does the ML-KEM and ML-DSA algorithm work?
ML-KEM and ML-DSA support secure key exchanges and digital signatures, respectively, using advanced techniques resistant to both classical and quantum computer attacks.
When can we expect full FIPS 140-3 validation?
CIQ anticipates achieving full FIPS 140-3 validation for the NSS module by mid-2027 under current development velocity.
Why is quantum-resistant cryptography important?
Quantum-resistant cryptography protects sensitive information from future quantum computing threats, which could potentially break existing encryption methods.
Where can I find more information about CIQ's initiatives?
For more information, CIQ encourages visitors to explore their website and learn about their ongoing projects in post-quantum cryptography.