SUSE Linux Enterprise Kernel Crypto API Cryptographic Module
SUSE Linux Enterprise Kernel Crypto API Cryptographic Module, from SUSE, LLC, holds FIPS 140-2 certificate #4069 at overall level 1. The validation is active, with a sunset date of 2026-09-21. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.
Caveat: When operated in FIPS mode and installed, initialized and configured as specified in section 10.1 of the Security Policy
Certificate
| Certificate number | 4069 |
|---|---|
| Standard | FIPS 140-2 |
| Status | active |
| Sunset date | 2026-09-21 |
| Overall level | 1 |
| Module type | Software |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | SUSE, LLC · website |
| Software versions | 2.1 |
Module description
Quoted from the NIST CMVP entry for this certificate.
SUSE Linux Enterprise Server Kernel Crypto API Module provides cryptographic services to the Linux operating system kernel.
Security level exceptions
- Physical Security: N/A
- Mitigation of Other Attacks: N/A
Approved algorithms (8)
| Algorithm | CAVP certificates |
|---|---|
| AES | A691, A692, A694, A695, A696, A698, A699, A700, A701, A702, A703, A705, A706, A707, A708, A709, A710, A711, A713, A714, A715, A716, A718, A719, A720, A721 |
| DRBG | A692, A694, A695, A696, A698, A699, A701, A702, A703, A706, A707, A708, A709, A710, A711, A714, A715, A716, A719, A720, A721, A723, A724, A725, A726 |
| HMAC | A690, A692, A708, A723, A724, A725 |
| KTS | |
| RSA | A692, A708, A723, A724, A725 |
| SHA-3 | A690 |
| SHS | A692, A708, A722, A723, A724, A725 |
| Triple-DES | A692, A696, A708, A716, A726 |
Allowed algorithms
NDRNG; RSA (key wrapping; key establishment methodology provides between 112 and 256 bits of encryption strength)
Tested configurations
- SUSE Linux Enterprise Server 12 SP4 running on FUJITSU Server PRIMERGY RX4770 M5 with Intel Cascade Lake Xeon Platinum 8268 with PAA
- SUSE Linux Enterprise Server 12 SP4 running on FUJITSU Server PRIMERGY RX4770 M5 with Intel Cascade Lake Xeon Platinum 8268 without PAA
- SUSE Linux Enterprise Server 12 SP4 running on IBM System Z z13 with IBM z13 with PAI
- SUSE Linux Enterprise Server 12 SP4 running on IBM System Z z13 with IBM z13 without PAI
- SUSE Linux Enterprise Server 12 SP5 running on FUJITSU Server PRIMERGY RX4770 M5 with Intel Cascade Lake Xeon Platinum 8268 with PAA
- SUSE Linux Enterprise Server 12 SP5 running on FUJITSU Server PRIMERGY RX4770 M5 with Intel Cascade Lake Xeon Platinum 8268 without PAA
- SUSE Linux Enterprise Server 12 SP5 running on IBM System Z z13 with IBM z13 with PAI
- SUSE Linux Enterprise Server 12 SP5 running on IBM System Z z13 with IBM z13 without PAI (single-user mode)
Validation history
| Date | Type | Lab |
|---|---|---|
| 2021-11-15 | Initial | atsec information security corporation |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2021-11-15