808bits

SUSE Linux Enterprise Kernel Crypto API Cryptographic Module

FIPS 140-2 certificate #3962 · SUSE, LLC · data as of 2026-09-08

SUSE Linux Enterprise Kernel Crypto API Cryptographic Module, from SUSE, LLC, holds FIPS 140-2 certificate #3962 at overall level 1. The validation is historical: agencies may keep the module in existing systems but not buy it new. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.

Historical. Moved to historical list due to sunsetting. Federal agencies may reference historical validations for existing systems only, not for new procurement.
Caveat: When operated in FIPS mode and installed, initialized and configured as specified in section 10.1 of the Security Policy

Certificate

Certificate number3962
StandardFIPS 140-2
Statushistorical
Overall level1
Module typeSoftware
EmbodimentMulti-Chip Stand Alone
VendorSUSE, LLC · website
Software versions3.2

Module description

Quoted from the NIST CMVP entry for this certificate.

z SUSE Linux Enterprise Kernel Crypto API Module provides cryptographic services to the Linux operating system kernel.

Security level exceptions

  • Physical Security: N/A
  • Mitigation of Other Attacks: N/A

Approved algorithms (10)

Allowed algorithms

NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 256 bits of encryption strength)

Tested configurations

  • (single-user mode)
  • SUSE Linux Enterprise Server 15 SP2 running on Dell EMC PowerEdge 640 with Intel Cascade Lake Xeon Gold 6234 with PAA
  • SUSE Linux Enterprise Server 15 SP2 running on Dell EMC PowerEdge 640 with Intel Cascade Lake Xeon Gold 6234 without PAA
  • SUSE Linux Enterprise Server 15 SP2 running on Gigabyte R181-T90 with Cavium ThunderX2 CN9975 ARMv8 with PAA
  • SUSE Linux Enterprise Server 15 SP2 running on Gigabyte R181-T90 with Cavium ThunderX2 CN9975 ARMv8 without PAA
  • SUSE Linux Enterprise Server 15 SP2 running on IBM System Z z15 with IBM z15 with PAI
  • SUSE Linux Enterprise Server 15 SP2 running on IBM System Z z15 with IBM z15 without PAI

Validation history

DateTypeLab
2021-06-30Initialatsec information security corporation
2021-11-28Updateatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status historical
  • Validation dates on record: 2021-06-30, 2021-11-28

Source documents