808bits

SUSE Linux Enterprise Server NSS Cryptographic Module

FIPS 140-2 certificate #3922 · SUSE, LLC · data as of 2026-09-03

SUSE Linux Enterprise Server NSS Cryptographic Module, from SUSE, LLC, holds FIPS 140-2 certificate #3922 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode

Certificate

Certificate number3922
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorSUSE, LLC · website
Software versions3.0

Module description

Quoted from the NIST CMVP entry for this certificate.

SUSE Network Security Services (NSS) is a set of libraries designed to support cross-platform development of security-enabled client and server applications.

Security level exceptions

  • Roles, Services, and Authentication: Level 2
  • Physical Security: N/A
  • Design Assurance: Level 2

Approved algorithms (13)

AlgorithmCAVP certificates
AESA245, A247, A337, A338, A473, A474, A476, A477
CKGvendor affirmed
CVLA245, A246, A473, A475
DRBGA245, A473
DSAA245, A473
ECDSAA245, A473
HMACA245, A473
KAS-SSCA681, A682
KTS
PBKDFA245, A473
RSAA245, A473
SHSA245, A473
Triple-DESA245, A473

Allowed algorithms

NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 256 bits of encryption strength)

Tested configurations

  • SUSE Linux Enterprise Server 15 SP0 running on Dell EMC PowerEdge 640 with Intel Cascade Lake Xeon Gold 6234 with PAA
  • SUSE Linux Enterprise Server 15 SP0 running on Dell EMC PowerEdge 640 with Intel Cascade Lake Xeon Gold 6234 without PAA
  • SUSE Linux Enterprise Server 15 SP2 running on Dell EMC PowerEdge 640 with Intel Cascade Lake Xeon Gold 6234 with PAA
  • SUSE Linux Enterprise Server 15 SP2 running on Dell EMC PowerEdge 640 with Intel Cascade Lake Xeon Gold 6234 without PAA
  • SUSE Linux Enterprise Server 15 SP2 running on Gigabyte R181-T90 with Cavium ThunderX2 CN9975 ARMv8 without PAA (single-user mode)
  • SUSE Linux Enterprise Server 15 SP2 running on IBM System Z/15 with IBM z15 without PAI

Validation history

DateTypeLab
2021-05-09Initialatsec information security corporation
2021-11-28Updateatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2021-05-09, 2021-11-28

Source documents