IBM® z/OS® Version 1 Release 11 System SSL Cryptographic Module
Certificate
| Certificate number | 1492 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 1 |
| Module type | Software-Hybrid |
| Embodiment | Multi-chip standalone |
| Vendor | IBM® Corporation · website |
| Software versions | System SSL level HCPT3B0/JCPT3B1 with APAR OA31595, RACF level HRF7760 with APAR OA30951 and ICSF level HCR7770 with APAR OA32012 |
| Hardware versions | FC3863 w/System Driver Level 77 and optional CEX3A and CEX3C [CEX3A and CEX3C are separately configured versions of 4765-001 (P/N 45D6048)] |
| Firmware versions | 4765-001 (e1ced7a0) |
Module description
System SSL is a set of generic services provided in z/OS to protect TCP/IP communications using the SSL/TLS protocol. System SSL is exploited by many SSL enabled servers and clients in z/OS to meet the transport security constraints required in an On Demand environment. The System SSL APIs are also externalized to customer applications. System SSL has evolved through the latest releases of z/OS to support the new TLS (Transaction Layer Security) standard, to reach an unmatched level of performance and to extend the APIs available to applications to new functions.
Security level exceptions
- Cryptographic Module Specification: Level 3
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | 976, 1418, 1419 |
| DSA | 458, 459 |
| HMAC | 836, 837 |
| RNG | 775, 776 |
| RSA | 691, 692, 693, 694, 695 |
| SHS | 946, 1286, 1287 |
| Triple-DES | 769, 968, 969 |
Other algorithms
Diffie-Hellman (key agreement; key establishment methodology provides 112 bits of encryption strength); RSA (key wrapping; key establishment methodology provides between 112 and 150 bits of encryption strength; non-compliant less than 112 bits of encryption strength); DES; RC2; ArcFour; MD5; MD2
Tested configurations
- Crypto Express3 Card (Accelerator (CEX3A)) and Crypto Express3 Cards (Coprocessor (CEX3C) and Accelerator (CEX3A))] [IBM System z10(TM) Enterprise Class (z10 EC) with CP Assist for Cryptographic Functions DES/TDES Enablement Feature 3863 includes FC3863 w/System Driver Level 77 and z/OS® V1R11] (single-user mode)
- IBM System z10(TM) Enterprise Class (z10 EC) with CP Assist for Cryptographic Functions DES/TDES Enablement Feature 3863 [Base GPC, optional Crypto Express3 Card (Coprocessor (CEX3C))
Validation history
| Date | Type | Lab |
|---|---|---|
| 2011-02-04 | Initial | atsec information security corporation |
| 2011-04-12 | Update | atsec information security corporation |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2011-02-04, 2011-04-12