IBM® z/OS® Version 1 Release 13 ICSF PKCS#11 Cryptographic Module
Certificate
| Certificate number | 1672 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 1 |
| Module type | Software-Hybrid |
| Embodiment | Multi-chip standalone |
| Vendor | IBM® Corporation · website |
| Software versions | ICSF level HCR7780 w/ APAR OA36882 and RACF level HRF7780 |
| Hardware versions | CPACF (P/N COP) and optional 4765-001 (P/N 45D6048) |
| Firmware versions | CPACF (FC3863 w/ System Driver Level 86E) and optional 4765-001 (e1ced7a0) |
Module description
The ICSF PKCS #11 module consists of software-based cryptographic algorithms, as well as symmetric and hashing algorithms provided by the CP Assist for Cryptographic Function (CPACF) and RSA Hardware clear key modular math cryptography provided through the Crypto Express3 card (CEX3A). The RSA hardware support is accessed through auxiliary module CSFINPVT which acts as a pipe between ICSF PKCS #11 and the cryptographic cards.
Security level exceptions
- Cryptographic Module Specification: Level 3
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | 1713, 1866 |
| CVL | 9 |
| DRBG | 151 |
| DSA | 584 |
| ECDSA | 261 |
| HMAC | 1112 |
| RSA | 946, 949, 971 |
| SHS | 1497, 1641 |
| Triple-DES | 1103, 1212 |
Other algorithms
Diffie-Hellman (key agreement; key establishment methodology provides 112 bits of encryption strength; non-compliant less than 112 bits of encryption strength); EC Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength; non-compliant less than 112 bits of encryption strength); RSA (key wrapping; key establishment methodology provides between 112 and 150 bits of encryption strength; non-compliant less than 112 bits of encryption strength); DES; Triple-DES (non-compliant); DSA (non-compliant); HMAC (non-compliant); RC4; BLOWFISH; MD5; MD2; RIPE-MD; EC Brainpool
Tested configurations
- IBM® zEnterprise (TM) 196 (z196) with CP Assist for Cryptographic Functions DES/TDES Enablement Feature 3863 [Base GPC, and optional Crypto Express3 Card (Accelerator (CEX3A) is a separately configured version of 4765-001 (P/N 45D6048))] [IBM® zEnterprise (TM) (z196) with CP Assist for Cryptographic Functions DES/TDES Enablement Feature 3863 includes FC3863 w/System Driver Level 86E and z/OS® V1R13] (single-user mode)
Validation history
| Date | Type | Lab |
|---|---|---|
| 2012-02-06 | Initial | atsec information security corporation |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2012-02-06