808bits

SUSE Linux Enterprise Server GnuTLS Cryptographic Module

FIPS 140-2 certificate #3957 · SUSE, LLC · data as of 2026-09-03

SUSE Linux Enterprise Server GnuTLS Cryptographic Module, from SUSE, LLC, holds FIPS 140-2 certificate #3957 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode. The module generates cryptographic keys whose strengths are modified by available entropy

Certificate

Certificate number3957
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorSUSE, LLC · website
Software versions1.0

Module description

Quoted from the NIST CMVP entry for this certificate.

GnuTLS is a secure communications library implementing the TLS protocol. It provides a simple C language application programming interface to access the secure communications protocols as well as APIs to parse and write X.509, PKCS#12, and other required structures which is shipped with SUSE Linux Enterprise Server.

Security level exceptions

  • Physical Security: N/A
  • Mitigation of Other Attacks: N/A

Approved algorithms (14)

AlgorithmCAVP certificates
AESA408, A410, A411, A412, A414, A415, A416, A417
CKGvendor affirmed
CVLA408
DRBGA408
DSAA408
ECDSAA408
HMACA408, A412, A417
KAS
KTS
PBKDFvendor affirmed
RSAA408
SHA-3A409, A413
SHSA408, A412, A417
Triple-DESA408

Allowed algorithms

MD5; NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 256 bits of encryption strength)

Tested configurations

  • (single-user mode)
  • SUSE Linux Enterprise Server 15 SP2 running on Dell EMC PowerEdge 640 with Intel Cascade Lake Xeon Gold 6234 with PAA
  • SUSE Linux Enterprise Server 15 SP2 running on Dell EMC PowerEdge 640 with Intel Cascade Lake Xeon Gold 6234 without PAA
  • SUSE Linux Enterprise Server 15 SP2 running on Gigabyte R181-T90 with Cavium ThunderX2 CN9975 ARMv8 with PAA
  • SUSE Linux Enterprise Server 15 SP2 running on Gigabyte R181-T90 with Cavium ThunderX2 CN9975 ARMv8 without PAA
  • SUSE Linux Enterprise Server 15 SP2 running on IBM System Z/15 with IBM z15

Validation history

DateTypeLab
2021-06-17Initialatsec information security corporation
2021-11-28Updateatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2021-06-17, 2021-11-28

Source documents