Key differences between FIPS 140-2 and FIPS 140-3

In Cloudera Runtime 7.3.2 SP1and higher versions, you must upgrade to FIPS 140-3. The transition from FIPS 140-2 to FIPS 140-3 represents a major evolution in security standards designed to address modern infrastructure vulnerabilities.

Table 1. Differences between FIPS 140-2 and FIPS 140-3
Category FIPS 140-2 FIPS 140-3
Status and validation lifecycle Relies on legacy modules reaching their expiration dates.

For example, standard SafeLogic and RHEL 8 modules expire through 2026.

Enforces active FIPS 140-3 validated cryptographic modules across all federal deployments.
Operating system integration Leverages legacy operating systems such as RHEL 8 or CentOS 7. Requires modern operating system infrastructure such as RHEL 9.
Cryptographic modules (SafeLogic) Uses SafeLogic CryptoComply modules (CCS, CCJ, and Libgcrypt) validated under legacy FIPS 140-2 security criteria. Upgrades to the SafeLogic CCJ 4.x module, to maintain compliance as legacy certificates transition to the historical list.
Container and image standards Relies heavily on Red Hat Universal Base Images (UBI 8) running standard open-source library wrappers. Shifts container deployments toward Chainguard images to reduce CVE exposure while using built-in FIPS 140-3 Go or OpenSSL modules.