808bits

IBM Java JCE 140-2 Cryptographic Module

FIPS 140-2 certificate #376 · IBM® Corporation · data as of 2026-09-15

IBM Java JCE 140-2 Cryptographic Module, from IBM® Corporation, holds FIPS 140-2 certificate #376 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: None

Certificate

Certificate number376
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-chip standalone
VendorIBM® Corporation · website
Software versions1.1

Module description

Quoted from the NIST CMVP entry for this certificate.

The IBM« Java« JCE (Java Cryptographic Extension) FIPS provider (IBMJCEFIPS) for Multi-platforms is a scalable, multi-purpose cryptographic module that supports only FIPS approved cryptographic operations via the Java2 Application Programming Interfaces (APIs).

Approved algorithms (6)

AlgorithmCAVP certificates
AES78
DSA91
HMAC-SHA-1vendor affirmed
RSAvendor affirmed
SHA-1170
Triple-DES189

Other algorithms

DES (Cert. #224); Diffie-Hellman (key agreement)

Tested configurations

  • Windows 2000 Professional SP3 (JVM 1.3.1_03 and JVM 1.4.1_04), Windows 2000 Advanced Server SP4 (JVM 1.4.1), Sun Solaris 5.8 (JVM 1.3.1 and 1.4.1), AIX 5.2 (JVM 1.3.1 and 1.4.1), SuSE Linux Enterprise Server 8 (JVM 1.4.1_05), RedHat Linux Advanced Server 2.1 (JVM 1.4.1_05), IBM OS/400 V5R2M0 (JVM 1.4.1), z/OS V1R4 (JVM 1.4.1) (all in single user mode)

Validation history

DateTypeLab
2004-01-30InitialSAIC-VA
2004-04-05Update

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2004-01-30, 2004-04-05

Source documents