808bits

IBM® z/OS® Version 2 Release 1 Security Server RACF® Signature Verification Module [1], IBM® z/OS® Version 2 Release 2 Security Server RACF® Signature Verification Module [2], IBM® z/OS® Version 2 Release 3 Security Server RACF® Signature Verification Module [3] and IBM® z/OS® Version 2 Release 4 Security Server RACF® Signature Verification Module [4][5]

FIPS 140-2 certificate #2691 · IBM® Corporation · data as of 2026-08-28
Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: None

Certificate

Certificate number2691
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware-Hybrid
EmbodimentMulti-Chip Stand Alone
VendorIBM® Corporation · website
Software versionsRACF level HRF7790 [1], RACF level HRF77A0 [2], RACF level HRF77B0 [3] and RACF level HRF77C0 [4][5]
Hardware versionsFC 3863 EC N98775 Drv 22H [1], FC 3863 EC P00339 Drv D27I [2], FC 3863 EC P42601 Drv D32L [3], FC 3863 EC P42601 Drv D32L [4] and FC 3863 EC P46601 D41C [5]

Module description

The z/OS RACF Program Signature Verification package consists of the core module (IRRPVERS) that is utilized when verifying signed code as it is loaded as well as an auxiliary module responsible for driving the initialization of IRRPVERS. The RACF Program Signature Verification module consists of software-based cryptographic algorithms, as well as hashing algorithms provided by the CP Assist for Cryptographic Function (CPACF).

Security level exceptions

  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
RSA1979, 2283, C219, C1634, C1766
SHS3196, 3661, C79, A389

Tested configurations

  • IBM z/OS Version 2 Release 1 running on an IBM z13 [1]
  • IBM z/OS Version 2 Release 2 running on an IBM z13 [2]
  • IBM z/OS Version 2 Release 3 running on an IBM z14 [3]
  • IBM z/OS Version 2 Release 4 running on an IBM z14 [4]
  • IBM z/OS Version 2 Release 4 running on an IBM z15 [5] (single-user mode)

Validation history

DateTypeLab
2016-07-28Initialatsec information security corporation
2017-04-25Updateatsec information security corporation
2017-05-09Updateatsec information security corporation
2017-06-01Updateatsec information security corporation
2017-10-31Updateatsec information security corporation
2019-02-07Updateatsec information security corporation
2019-02-19Updateatsec information security corporation
2020-04-22Updateatsec information security corporation
2020-09-08Updateatsec information security corporation
2021-08-13Updateatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2016-07-28, 2017-04-25, 2017-05-09, 2017-06-01, 2017-10-31, 2019-02-07, 2019-02-19, 2020-04-22, 2020-09-08, 2021-08-13

Source documents