808bits

IBM Java JCE FIPS 140-2 Cryptographic Module with CPACF

FIPS 140-2 certificate #2837 · IBM Corporation · data as of 2026-08-28
Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode

Certificate

Certificate number2837
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware-Hybrid
EmbodimentMulti-Chip Stand Alone
VendorIBM Corporation · website
Software versions1.8
Hardware versionsCOP chips integrated within processor unit
Firmware versions3863 (aka FC3863) with System Driver Level 22H

Module description

The IBM Java JCE (Java Cryptographic Extension) FIPS provider (IBMJCEFIPS) for multi-platforms is a scalable, multipurpose cryptographic module that supports many FIPS approved cryptographic operations. This gives Java applications access to the FIPS algorithms via the standard JCE framework.

Approved algorithms

AlgorithmCAVP certificate
AES3909, 3910
CVL768, 769, 770, 771
DRBG1124, 1125
DSA1067, 1068
ECDSA852, 853
HMAC2538, 2539
KTSvendor affirmed
RSA1993, 1994
SHS3221, 3222
Triple-DES2145, 2146

Other algorithms

Diffie-Hellman (CVL Certs. #769 and #771; key agreement; key establishment methodology provides 112 bits of encryption strength; non-compliant less than 112 bits of encryption strength); EC Diffie-Hellman (CVL Certs. #769 and #771; key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength; non-compliant less than 112 bits of encryption strength); NDRNG; RSA (key wrapping; key establishment methodology provides 112 or 128 bits of encryption strength; non-compliant less than 112 bits of encryption strength); AES (non-compliant); MD5; Triple-DES (non-compliant)

Tested configurations

  • Red Hat Enterprise Linux Server release 7.2 running on IBM z13 model N63 (single-user mode)
  • z/OS version 2 release 2 running on IBM z13 model N63

Validation history

DateTypeLab
2017-02-13Initialatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2017-02-13

Source documents