808bits

SAP CommonCryptoLib Crypto Kernel

FIPS 140-2 certificate #2900 · SAP SE · data as of 2026-09-03

SAP CommonCryptoLib Crypto Kernel, from SAP SE, holds FIPS 140-2 certificate #2900 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode

Certificate

Certificate number2900
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorSAP SE · website
Software versions8.4.47.0 32-bit [1] and 64-bit [2]

Module description

Quoted from the NIST CMVP entry for this certificate.

SAP CommonCryptoLib Crypto Kernel v8.4.47.0 is a shared library, i.e. it consists of software only. SAP CommonCryptoLib Crypto Kernel provides an API in terms of C++ methods for key management and operation of cryptographic functions.

Security level exceptions

  • Physical Security: N/A
  • Mitigation of Other Attacks: N/A

Approved algorithms (9)

AlgorithmCAVP certificates
AES3665, 3666
CVL671, 672, 673, 674, 675
DRBG986, 987
DSA1035, 1036
ECDSA772, 773
HMAC2415, 2416
RSA1898, 1899
SHS3083, 3084
Triple-DES2047, 2048

Other algorithms

Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength; non-compliant less than 112 bits of encryption strength); RSA (key wrapping; key establishment methodology provides between 112 and 256 bits of encryption strength; non-compliant less than 112 bits of encryption strength); DES; ElGamal; IDEA; MD2; MD4; MD5; RC2; RC4; RC5-32; RIPEMD-128; RIPEMD-160

Tested configurations

  • AIX 5.2 64-bit running on a IBM eServer p5 505 without PAA [2]
  • AIX 6.1 64-bit on IBM PowerVM 2.2 running on a IBM Power 750 Express without PAA [1][2]
  • HP-UX 11.11 64-bit running on a HP Server rp3440 [2]
  • HP-UX 11.23 64-bit running on a HP Server rx5670 [2]
  • HP-UX 11.31 64-bit running on a HP Integrity rx6600 [1][2]
  • Linux 2.6.32 32-bit running on a HP ProLiant DL385-G2 DC [1]
  • Linux 2.6.32 64-bit on IBM PowerVM 2.2 running on a IBM Power 750 Express without PAA [1][2]
  • Linux 2.6.32 64-bit running on a HP Integrity rx2660 [2]
  • Linux 2.6.5 64-bit running on a HP ProLiant DL585 without PAA [1][2]
  • Linux 3.0.101 64-bit on IBM PowerVM 2.2 running on a IBM Power System S824 with PAA [2]
  • Linux 3.0.101 64-bit on IBM z/VM 6.2.0 running on a IBM zEnterprise 196 (2817 series) [2]
  • Linux 3.0.101 64-bit on Vmware ESXi 5.1.0 running on a HP ProLiant DL580 G7 with PAA [1][2]
  • SunOS 5.10 64-bit running on a Fujitsu PrimePower 650 [1][2]
  • SunOS 5.10 64-bit running on a Sun Fire X4150 without PAA [1][2]
  • SunOS 5.9 64-bit running on a Sun Fire V440 [2]
  • Windows Server 2008 R2 SP1 64-bit on Vmware ESXi 5.1.0 running on a HP ProLiant DL580 G7 with PAA [1][2] (single-user mode)
  • Windows Server 2008 SP2 64-bit running on a HP ProLiant DL380 G6 without PAA [1][2]

Validation history

DateTypeLab
2017-05-05InitialTUVIT Evaluation Body for IT Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2017-05-05

Source documents