808bits

IBM® z/OS® Version 2 Release 4 System SSL Cryptographic Module

FIPS 140-2 certificate #3919 · IBM Corporation · data as of 2026-09-13

IBM® z/OS® Version 2 Release 4 System SSL Cryptographic Module, from IBM Corporation, holds FIPS 140-2 certificate #3919 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. SP 800-56Arev3 transition. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode with modules IBM(R) z/OS(R) Version 2 Release 4 Security Server RACF(R) Signature Verification Module validated to FIPS 140-2 under Cert. #2691 operating in FIPS mode and IBM(R) z/OS(R) Version 2 Release 4 ICSF PKCS #11 Cryptographic Module validated to FIPS 140-2 under Cert. #3909 operating in FIPS mode

Certificate

Certificate number3919
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware-Hybrid
EmbodimentMulti-Chip Stand Alone
VendorIBM Corporation · website
Software versionsHCPT440/JCPT441 with APAR OA59268
Hardware versionsCOP chips integrated within processor unit
Firmware versionsFeature 3863 (aka FC3863) with System Driver Level 32L

Module description

Quoted from the NIST CMVP entry for this certificate.

z/OS® System SSL provides a rich set of C based application programming interfaces that allow applications to protect data using the SSL/TLS protocols and through PKCS#7 cryptographic messages. z/OS System SSL also enables applications to create and manage X.509 V3 certificates and keys within key database files and PKCS#11 tokens.

Security level exceptions

  • Mitigation of Other Attacks: N/A

Approved algorithms (10)

AlgorithmCAVP certificates
AESC79, C1635, C1664, C1665
CVLC1635, C1637, C1664, C1665
DRBGC1633
DSAC1664, C1665
ECDSAC1635
HMACC1664, C1665
KTS
RSAC1634, C1635, C1637, C1664, C1665
SHSC79, C1664, C1665
Triple-DESC79, C1664, C1665

Allowed algorithms

Diffie-Hellman (CVL Certs. #C1635 and #C1637 with CVL Certs. #C1664 and #C1665, key agreement; key establishment methodology provides 112 bits of encryption strength); EC Diffie-Hellman (CVL Cert. #C1635 with CVL Certs. #C1664 and #C1665, key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength); MD5; NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 150 bits of encryption strength)

Tested configurations

  • IBM z/OS Version 2 Release 4 running on an IBM z14 with CP Assist for Cryptographic Functions
  • IBM z/OS Version 2 Release 4 running on an IBM z14 with CP Assist for Cryptographic Functions with CEX6A (single-user mode)

Validation history

DateTypeLab
2021-05-03Initialatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2021-05-03

Source documents