SUSE Linux Enterprise Kernel Crypto API Cryptographic Module
Caveat: When operated in FIPS mode and installed, initialized and configured as specified in section 10.1 of the Security Policy
Certificate
| Certificate number | 3962 |
|---|---|
| Standard | FIPS 140-2 |
| Status | historical |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | SUSE, LLC · website |
| Software versions | 3.2 |
Module description
z SUSE Linux Enterprise Kernel Crypto API Module provides cryptographic services to the Linux operating system kernel.
Security level exceptions
- Physical Security: N/A
- Mitigation of Other Attacks: N/A
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | A418, A419, A420, A422, A423, A424, A425, A426, A428, A429, A430, A431, A432, A433, A434, A435, A436, A437, A438, A439, A440, A441, A442, A443, A444, A446, A447, A448, A449, A450, A451, A452, A455, A456, A457, A458, A459, A460, A461, A462, A463, A464, A465, A466, A467, A469, A470, A472 |
| DRBG | A418, A419, A420, A422, A423, A424, A426, A428, A429, A431, A432, A433, A436, A439, A441, A447, A449, A450, A451, A452, A453, A454, A457, A461, A462, A464, A465, A467, A468, A471 |
| ECDSA | A447 |
| HMAC | A420, A421, A427, A436, A438, A445, A447, A451, A453, A468, A471, A472 |
| KAS-SSC | A776 |
| KTS | |
| KTS | |
| KTS | |
| RSA | A436, A451, A453, A468, A471 |
| SHA-3 | A421, A445 |
| SHS | A420, A427, A436, A438, A447, A451, A453, A468, A471, A472 |
| Triple-DES | A423, A425, A436, A443, A446, A449, A451, A454, A459, A463, A466 |
Allowed algorithms
NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 256 bits of encryption strength)
Tested configurations
- (single-user mode)
- SUSE Linux Enterprise Server 15 SP2 running on Dell EMC PowerEdge 640 with Intel Cascade Lake Xeon Gold 6234 with PAA
- SUSE Linux Enterprise Server 15 SP2 running on Dell EMC PowerEdge 640 with Intel Cascade Lake Xeon Gold 6234 without PAA
- SUSE Linux Enterprise Server 15 SP2 running on Gigabyte R181-T90 with Cavium ThunderX2 CN9975 ARMv8 with PAA
- SUSE Linux Enterprise Server 15 SP2 running on Gigabyte R181-T90 with Cavium ThunderX2 CN9975 ARMv8 without PAA
- SUSE Linux Enterprise Server 15 SP2 running on IBM System Z z15 with IBM z15 with PAI
- SUSE Linux Enterprise Server 15 SP2 running on IBM System Z z15 with IBM z15 without PAI
Validation history
| Date | Type | Lab |
|---|---|---|
| 2021-06-30 | Initial | atsec information security corporation |
| 2021-11-28 | Update | atsec information security corporation |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status historical
- Validation dates on record: 2021-06-30, 2021-11-28