808bits

IBM® z/OS® Version 2 Release 4 ICSF PKCS #11 Cryptographic Module

FIPS 140-2 certificate #3909 · IBM Corporation · data as of 2026-09-03

IBM® z/OS® Version 2 Release 4 ICSF PKCS #11 Cryptographic Module, from IBM Corporation, holds FIPS 140-2 certificate #3909 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. SP 800-56Arev3 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode with module IBM(R) z/OS(R) Version 2 Release 4 Security Server RACF(R) Signature Verification Module validated to FIPS 140-2 under Cert. #2691 operating in FIPS mode

Certificate

Certificate number3909
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware-Hybrid
EmbodimentMulti-Chip Stand Alone
VendorIBM Corporation · website
Software versionsICSF level HCR77D0 with APAR OA58593
Hardware versionsCOP chips integrated within processor unit [1] and COP chips integrated within processor unit and P/N 01PP167 [2]
Firmware versionsFeature 3863 (aka FC3863) with System Driver Level 32L [1], and Feature 3863 (aka FC3863) with System Driver Level 32L and CCA 6.0.8z [2]

Module description

Quoted from the NIST CMVP entry for this certificate.

ICSF is a software element of z/OS that works with hardware cryptographic features and the Security Server (RACF) to provide secure, high-speed cryptographic services in the z/OS environment. ICSF, which runs as a started task, provides the application programming interfaces by which applications request the cryptographic services.

Security level exceptions

  • Mitigation of Other Attacks: N/A

Approved algorithms (11)

AlgorithmCAVP certificates
AESC79, C1635
CKGvendor affirmed
CVLC1635, C1637
DRBGC1633, C1635
DSAC1635
ECDSAC1635
HMACC1635
KTS
RSAC1634, C1635, C1637
SHSC79, C1635
Triple-DESC79

Allowed algorithms

AES (Cert. #C79, key unwrapping; key establishment methodology provides between 128 and 256 bits of encryption strength); MD5; NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 149 bits of encryption strength); Triple-DES (Cert. #C79, key unwrapping; key establishment methodology provides 112 bits of encryption strength)

Tested configurations

  • IBM z/OS Version 2 Release 4 running on an IBM z14 with CP Assist for Cryptographic Functions [1]
  • IBM z/OS Version 2 Release 4 running on an IBM z14 with CP Assist for Cryptographic Functions with CEX6A [2] (single-user mode)

Validation history

DateTypeLab
2021-04-26Initialatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2021-04-26

Source documents