808bits

IBM® z/VM® Version 6 Release 3 System SSL Cryptographic Module

FIPS 140-2 certificate #2139 · IBM® Corporation · data as of 2026-09-03

IBM® z/VM® Version 6 Release 3 System SSL Cryptographic Module, from IBM® Corporation, holds FIPS 140-2 certificate #2139 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. RNG SP800-131A Revision 1 Transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: The module generates cryptographic keys whose strengths are modified by available entropy

Certificate

Certificate number2139
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware-Hybrid
EmbodimentMulti-chip standalone
VendorIBM® Corporation · website
Software versions5735FAL00: z/VM Version 6 Release 3 plus APAR PM95516
Hardware versionsz10 CP Assist for Cryptographic Functions DES/TDES Enablement Feature 3863

Module description

Quoted from the NIST CMVP entry for this certificate.

Module Description: z/VM System SSL provides cryptographic functions which allows z/VM to protect data using the SSL/TLS protocols. z/VM System SSL also enables administrators to create and manage X.509 V3 certificates and keys within key database files.

Security level exceptions

  • Cryptographic Module Specification: Level 3
  • Mitigation of Other Attacks: N/A

Approved algorithms (8)

AlgorithmCAVP certificates
AES976, 2627
CVL110
DSA792
HMAC1624
RNG1241
RSA1344
SHS946, 2203
Triple-DES769, 1577

Other algorithms

Diffie-Hellman (key agreement; key establishment methodology provides 112 bits of encryption strength); RSA (key wrapping; key establishment methodology provides between 112 and 150 bits of encryption strength); HMAC-MD5

Tested configurations

  • z/VM Version 6 Release 3 running on IBM System z10 (TM) Enterprise Class (z10 EC) with CP Assist for Cryptographic Functions DES/TDES Enablement Feature 3863 (single-user mode)

Validation history

DateTypeLab
2014-04-30Initialatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2014-04-30

Source documents