808bits

IBM® z/OS® Version 1 Release 12 System SSL Cryptographic Module

FIPS 140-2 certificate #1600 · IBM® Corporation · data as of 2026-09-08

IBM® z/OS® Version 1 Release 12 System SSL Cryptographic Module, from IBM® Corporation, holds FIPS 140-2 certificate #1600 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. RNG SP800-131A Revision 1 Transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode

Certificate

Certificate number1600
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware-Hybrid
EmbodimentMulti-chip standalone
VendorIBM® Corporation · website
Software versionsSystem SSL level HCPT3C0/JCPT3C1 w/ APAR OA34156, RACF level HRF7770 and ICSF level HCR7770 w/ APAR OA34205
Hardware versionsFC3863 w/System Driver Level 86E, and optional CEX3A and CEX3C [CEX3A and CEX3C are separately configured versions of 4765-001 (P/N 45D6048)]
Firmware versions4765-001 (e1ced7a0)

Module description

Quoted from the NIST CMVP entry for this certificate.

System SSL is a set of generic services provided in z/OS to protect TCP/IP communications using the SSL/TLS protocol. System SSL is exploited by many SSL enabled servers and clients in z/OS to meet the transport security constraints required in an On Demand environment. The System SSL APIs are also externalized to customer applications. System SSL has evolved through the latest releases of z/OS to support the new TLS (Transaction Layer Security) standard, to reach an unmatched level of performance and to extend the APIs available to applications to new functions.

Security level exceptions

  • Cryptographic Module Specification: Level 3

Approved algorithms (7)

AlgorithmCAVP certificates
AES1702, 1703, 1713
DSA526, 527
HMAC986, 987
RNG901, 902
RSA831, 832, 844, 845, 846
SHS1485, 1486, 1497
Triple-DES1093, 1094, 1103

Other algorithms

Diffie-Hellman (key agreement; key establishment methodology provides 112 bits of encryption strength); RSA (key wrapping; key establishment methodology provides between 112 and 150 bits of encryption strength; non-compliant less than 112 bits of encryption strength); DES; RC2; ArcFour; MD5; MD2; ECDSA (non-compliant)

Tested configurations

  • Crypto Express3 Card (Accelerator (CEX3A)) and Crypto Express3 Cards (Coprocessor (CEX3C) and Accelerator (CEX3A))] [IBM® zEnterprise (TM) (z196) with CP Assist for Cryptographic Functions DES/TDES Enablement Feature 3863 includes FC3863 w/System Driver Level 86E and z/OS® V1R12] (single-user mode)
  • IBM® zEnterprise (TM) 196 (z196) with CP Assist for Cryptographic Functions DES/TDES Enablement Feature 3863 [Base GPC, and optional Crypto Express3 Card (Coprocessor (CEX3C))

Validation history

DateTypeLab
2011-09-08Initialatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2011-09-08

Source documents