808bits

IBM® z/OS® Version 2 Release 4 System SSL Cryptographic Module

FIPS 140-2 certificate #3937 · IBM Corporation · data as of 2026-09-15

IBM® z/OS® Version 2 Release 4 System SSL Cryptographic Module, from IBM Corporation, holds FIPS 140-2 certificate #3937 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Moved to historical list due to dependency on certificate #3924. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode with modules IBM(R) z/OS(R) Version 2 Release 4 Security Server RACF(R) Signature Verification Module validated to FIPS 140-2 under Cert. #2691 and IBM(R) z/OS(R) Version 2 Release 4 ICSF PKCS #11 Cryptographic Module validated to FIPS 140-2 under Cert. #3924 operating in FIPS mode

Certificate

Certificate number3937
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware-Hybrid
EmbodimentMulti-Chip Stand Alone
VendorIBM Corporation · website
Software versionsHCPT440/JCPT441 with APAR OA59268
Hardware versionsCOP chips integrated within processor unit
Firmware versionsFeature 3863 (aka FC3863) with System Driver Level 41C

Module description

Quoted from the NIST CMVP entry for this certificate.

z/OS® System SSL provides a rich set of C based application programming interfaces that allow applications to protect data using the SSL/TLS protocols and through PKCS#7 cryptographic messages. z/OS System SSL also enables applications to create and manage X.509 V3 certificates and keys within key database files and PKCS#11 tokens.

Security level exceptions

  • Mitigation of Other Attacks: N/A

Approved algorithms (10)

AlgorithmCAVP certificates
AESA389, C1772, C1801, C1803
CVLC1772, C1799, C1801, C1803
DRBGC1772
DSAC1801, C1803
ECDSAC1772
HMACC1801, C1803
KTS
RSAC1766, C1772, C1799, C1801, C1803
SHSA389, C1801, C1803
Triple-DESA389, C1801, C1803

Allowed algorithms

Diffie-Hellman (CVL Certs. #C1772 and #C1799 with CVL Certs. #C1801 and #C1803, key agreement; key establishment methodology provides 112 bits of encryption strength); EC Diffie-Hellman (CVL Cert. #C1772 with CVL Certs. #C1801 and #C1803, key agreement; key establishment methodology provides between 112 and 256 bits of encryption strength); MD5; NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 149 bits of encryption strength)

Tested configurations

  • IBM z/OS Version 2 Release 4 running on an IBM z15 with CP Assist for Cryptographic Functions
  • IBM z/OS Version 2 Release 4 running on an IBM z15 with CP Assist for Cryptographic Functions with CEX7A (single-user mode)

Validation history

DateTypeLab
2021-05-26Initialatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2021-05-26

Source documents