808bits

SAP CommonCryptoLib Crypto Kernel

FIPS 140-2 certificate #3449 · SAP SE · data as of 2026-08-28
Historical. SP 800-56Arev3 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode

Certificate

Certificate number3449
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorSAP SE · website
Software versions8.4.47.0 32-bit [1] and 64-bit [2]

Module description

SAP CommonCryptoLib Crypto Kernel v8.4.47.0 is a shared library, i.e. it consists of software only. SAP CommonCryptoLib Crypto Kernel provides an API in terms of C++ methods for key management and operation of cryptographic functions.

Security level exceptions

  • Physical Security: N/A
  • Mitigation of Other Attacks: N/A

Approved algorithms

AlgorithmCAVP certificate
AES3665, 3666
CVL670, 671, 672, 673, 674, 675
DRBG986, 987
DSA1035, 1036
ECDSA772, 773
HMAC2415, 2416
RSA1898, 1899
SHS3083, 3084
Triple-DES2047, 2048

Allowed algorithms

Diffie-Hellman (key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength); NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 256 bits of encryption strength)

Tested configurations

  • AIX 5.2 64-bit running on a IBM eServer p5 505 without PAA [2]
  • AIX 6.1 64-bit on IBM PowerVM 2.2 running on a IBM Power 750 Express without PAA [1][2]
  • HP-UX 11.11 64-bit running on a HP Server rp3440 [2]
  • HP-UX 11.23 64-bit running on a HP Server rx5670 [2]
  • HP-UX 11.31 64-bit running on a HP Integrity rx6600 [1][2]
  • SunOS 5.10 64-bit running on a Fujitsu PrimePower 650 [1][2]
  • SunOS 5.10 64-bit running on a Sun Fire X4150 without PAA [1][2]
  • SunOS 5.9 64-bit running on a Sun Fire V440 [2]
  • SUSE Linux Enterprise Server 11 SP1 (Linux Kernel 2.6.32) 32-bit running on a HP ProLiant DL385-G2 DC [1]
  • SUSE Linux Enterprise Server 11 SP1 (Linux Kernel 2.6.32) 64-bit on IBM PowerVM 2.2 running on a IBM Power 750 Express without PAA [1][2]
  • SUSE Linux Enterprise Server 11 SP1 (Linux Kernel 2.6.32) 64-bit running on a HP Integrity rx2660 [2]
  • SUSE Linux Enterprise Server 11 SP3 (Linux Kernel 3.0.101) 64-bit on IBM PowerVM 2.2 running on a IBM Power System S824 with PAA [2]
  • SUSE Linux Enterprise Server 11 SP3 (Linux Kernel 3.0.101) 64-bit on Vmware ESXi 5.1.0 running on a HP ProLiant DL580 G7 with PAA [1][2]
  • SUSE Linux Enterprise Server 11 SP4 (Linux Kernel 3.0.101) 64-bit on IBM z/VM 6.2.0 running on a IBM zEnterprise 196 (2817 series) [2]
  • SUSE Linux Enterprise Server 12 SP1 (Linux Kernel 3.12.51) 64-bit on IBM PowerVM 2.2 running on a IBM Power System E870 [2]
  • SUSE Linux Enterprise Server 9 SP2 (Linux Kernel 2.6.5) 64-bit running on a HP ProLiant DL585 without PAA [1][2]
  • Windows Server 2008 R2 SP1 64-bit on Vmware ESXi 5.1.0 running on a HP ProLiant DL580 G7 with PAA [1][2] (single-user mode)
  • Windows Server 2008 SP2 64-bit running on a HP ProLiant DL380 G6 without PAA [1][2]

Validation history

DateTypeLab
2019-05-02InitialTUVIT Evaluation Body for IT Security

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2019-05-02

Source documents