808bits

IBM® z/OS® Version 2 Release 3 System SSL Cryptographic Module

FIPS 140-2 certificate #3557 · IBM Corporation · data as of 2026-09-03

IBM® z/OS® Version 2 Release 3 System SSL Cryptographic Module, from IBM Corporation, holds FIPS 140-2 certificate #3557 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. SP 800-56Arev3 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode with modules IBM(R) z/OS(R) Version 2 Release 3 Security Server RACF(R) Signature Verification Module validated to FIPS 140-2 under Cert. #2691 operating in FIPS mode and IBM(R) z/OS(R) Version 2 Release 3 ICSF PKCS #11 Cryptographic Module validated to FIPS 140-2 under Cert. #3555 operating in FIPS mode

Certificate

Certificate number3557
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware-Hybrid
EmbodimentMulti-Chip Stand Alone
VendorIBM Corporation · website
Software versionsHCPT430/JCPT431 with APAR OA57026
Hardware versionsCOP chips integrated within processor unit
Firmware versionsFeature 3863 (aka FC3863) with System Driver Level 32L

Module description

Quoted from the NIST CMVP entry for this certificate.

z/OS® System SSL provides a rich set of C based application programming interfaces that allow applications to protect data using the SSL/TLS protocols and through PKCS#7 cryptographic messages. z/OS System SSL also enables applications to create and manage X.509 V3 certificates and keys within key database files and PKCS#11 tokens.

Security level exceptions

  • Mitigation of Other Attacks: N/A

Approved algorithms (9)

AlgorithmCAVP certificates
AESC79, C424, C540, C541
CVLC424, C507, C508, C540, C541
DRBGC436
DSAC540, C541
ECDSAC424
HMACC540, C541
RSAC219, C424, C507, C508, C540, C541
SHSC79, C540, C541
Triple-DESC79, C540, C541

Allowed algorithms

Diffie-Hellman (CVL Certs. #C424, #C507 and #C508 with CVL Certs. #C540 and #C541, key agreement; key establishment methodology provides 112 bits of encryption strength); EC Diffie-Hellman (CVL Cert. #C424 with CVL Certs. #C540 and #C541, key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength); HMAC-MD5; NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 150 bits of encryption strength)

Tested configurations

  • IBM z/OS Version 2 Release 3 running on an IBM z14 with CP Assist for Cryptographic Functions
  • IBM z/OS Version 2 Release 3 running on an IBM z14 with CP Assist for Cryptographic Functions with CEX5A
  • IBM z/OS Version 2 Release 3 running on an IBM z14 with CP Assist for Cryptographic Functions with CEX6A (single-user mode)

Validation history

DateTypeLab
2019-10-25Initialatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2019-10-25

Source documents