808bits

IBM® z/OS® Version 1 Release 11 System SSL Cryptographic Module

FIPS 140-2 certificate #1492 · IBM® Corporation · data as of 2026-09-08

IBM® z/OS® Version 1 Release 11 System SSL Cryptographic Module, from IBM® Corporation, holds FIPS 140-2 certificate #1492 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. RNG SP800-131A Revision 1 Transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode

Certificate

Certificate number1492
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware-Hybrid
EmbodimentMulti-chip standalone
VendorIBM® Corporation · website
Software versionsSystem SSL level HCPT3B0/JCPT3B1 with APAR OA31595, RACF level HRF7760 with APAR OA30951 and ICSF level HCR7770 with APAR OA32012
Hardware versionsFC3863 w/System Driver Level 77 and optional CEX3A and CEX3C [CEX3A and CEX3C are separately configured versions of 4765-001 (P/N 45D6048)]
Firmware versions4765-001 (e1ced7a0)

Module description

Quoted from the NIST CMVP entry for this certificate.

System SSL is a set of generic services provided in z/OS to protect TCP/IP communications using the SSL/TLS protocol. System SSL is exploited by many SSL enabled servers and clients in z/OS to meet the transport security constraints required in an On Demand environment. The System SSL APIs are also externalized to customer applications. System SSL has evolved through the latest releases of z/OS to support the new TLS (Transaction Layer Security) standard, to reach an unmatched level of performance and to extend the APIs available to applications to new functions.

Security level exceptions

  • Cryptographic Module Specification: Level 3

Approved algorithms (7)

AlgorithmCAVP certificates
AES976, 1418, 1419
DSA458, 459
HMAC836, 837
RNG775, 776
RSA691, 692, 693, 694, 695
SHS946, 1286, 1287
Triple-DES769, 968, 969

Other algorithms

Diffie-Hellman (key agreement; key establishment methodology provides 112 bits of encryption strength); RSA (key wrapping; key establishment methodology provides between 112 and 150 bits of encryption strength; non-compliant less than 112 bits of encryption strength); DES; RC2; ArcFour; MD5; MD2

Tested configurations

  • Crypto Express3 Card (Accelerator (CEX3A)) and Crypto Express3 Cards (Coprocessor (CEX3C) and Accelerator (CEX3A))] [IBM System z10(TM) Enterprise Class (z10 EC) with CP Assist for Cryptographic Functions DES/TDES Enablement Feature 3863 includes FC3863 w/System Driver Level 77 and z/OS® V1R11] (single-user mode)
  • IBM System z10(TM) Enterprise Class (z10 EC) with CP Assist for Cryptographic Functions DES/TDES Enablement Feature 3863 [Base GPC, optional Crypto Express3 Card (Coprocessor (CEX3C))

Validation history

DateTypeLab
2011-02-04Initialatsec information security corporation
2011-04-12Updateatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2011-02-04, 2011-04-12

Source documents