808bits

IBM® z/OS® Version 2 Release 1 System SSL Cryptographic Module

FIPS 140-2 certificate #2829 · IBM Corporation · data as of 2026-08-28
Historical. Moved to historical list due to dependency on certificate #2763. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode with modules IBM(R) z/OS(R) Version 2 Release 1 Security Server RACF(R) Signature Verification Module version 1.0 validated to FIPS 140-2 under Cert. #2691 operating in FIPS mode and IBM(R) z/OS(R) Version 2 Release 1 ICSF PKCS #11 Cryptographic Module validated to FIPS 140-2 under Cert. #2763 operating in FIPS mode

Certificate

Certificate number2829
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware-Hybrid
EmbodimentMulti-Chip Stand Alone
VendorIBM Corporation · website
Software versionsHCPT410/JCPT411 with APAR OA50589
Hardware versionsCOP chips integrated within processor unit
Firmware versionsFeature 3863 (aka FC3863) with System Driver Level 22H

Module description

z/OS® System SSL provides a rich set of C based application programming interfaces that allow applications to protect data using the SSL/TLS protocols and through PKCS#7 cryptographic messages. z/OS System SSL also enables applications to create and manage X.509 V3 certificates and keys within key database files and PKCS#11 tokens.

Security level exceptions

  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES3958, 4083, 4084
CVL901, 902, 934, 935
DSA1108, 1109, 1119, 1120
HMAC2665, 2666, 2697, 2698
RSA2210, 2211, 2231, 2232, 2240, 2241, 2242, 2243, 2244, 2245, 2246, 2247
SHS3196, 3361, 3362
Triple-DES2214, 2230, 2231

Other algorithms

HMAC-MD5; MD5; RSA (key wrapping; key establishment methodology provides between 112 and 150 bits of encryption strength; non-compliant less than 112 bits of encryption strength)

Tested configurations

  • IBM z/OS Version 2 Release 1 running on an IBM z13 (single-user mode)

Validation history

DateTypeLab
2017-02-01Initialatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2017-02-01

Source documents